Filters
Question type

Study Flashcards

What are the primary and secondary goals of modern proxy servers?

Correct Answer

verifed

verified

The primary goal of modern proxy servers...

View Answer

MATCHING -a firewall with separate interfaces connected to an untrusted network,a semitrusted network,and a trusted network


A) dual-homed host
B) load-balancing software
C) many-to-one NAT
D) one-to-one NAT
E) proxy server
F) reverse firewall
G) screened host
H) screening router
I) server farm
J) three-pronged firewall

K) A) and B)
L) B) and C)

Correct Answer

verifed

verified

A screened host has a router as part of the configuration.

A) True
B) False

Correct Answer

verifed

verified

Describe the process of network address translation.What are the two primary types of NAT?

Correct Answer

verifed

verified

The NAT process begins with an internal ...

View Answer

Which type of security device can speed up Web page retrieval and shield hosts on the internal network?


A) caching firewall
B) proxy server
C) caching-only DNS server
D) DMZ intermediary

E) C) and D)
F) B) and D)

Correct Answer

verifed

verified

What do you call a firewall that is connected to the Internet,the internal network,and the DMZ?


A) multi-homed proxy
B) three-pronged firewall
C) three-way packet filter
D) multi-zone host

E) A) and B)
F) None of the above

Correct Answer

verifed

verified

What is a step you can take to harden a bastion host?


A) enable additional services to serve as honeypots
B) open several ports to confuse attackers
C) configure several extra accounts with complex passwords
D) remove unnecessary services

E) B) and C)
F) None of the above

Correct Answer

verifed

verified

Which of the following is true about a screening router?


A) it examines the data in the packet to make filtering decisions
B) it can stop attacks from spoofed addresses
C) it maintains a state table to determine connection information
D) it should be combined with a firewall for better security

E) C) and D)
F) B) and D)

Correct Answer

verifed

verified

Which of the following is true about a dual-homed host?


A) serves as a single point of entry to the network
B) its main objective is to stop worms and viruses
C) uses a single NIC to manage two network connections
D) it is used as a remote access server in some configurations

E) B) and D)
F) A) and B)

Correct Answer

verifed

verified

A dual-homed host has a single NIC with two MAC addresses.

A) True
B) False

Correct Answer

verifed

verified

What is a critical step you should take on the OS you choose for a bastion host?


A) ensure all security patches are installed
B) make sure it is the latest OS version
C) choose an obscure OS with which attackers are unfamiliar
D) customize the OS for bastion operation

E) A) and D)
F) None of the above

Correct Answer

verifed

verified

Which network device works at the Application layer by reconstructing packets and forwarding them to Web servers?


A) Layer 7 switch
B) translating gateway
C) proxy server
D) ICMP redirector

E) None of the above
F) B) and C)

Correct Answer

verifed

verified

C

Reverse firewalls allow all incoming traffic except what the ACLs are configured to deny.

A) True
B) False

Correct Answer

verifed

verified

What should you consider installing if you want to inspect packets as they leave the network?


A) security workstation
B) RIP router
C) filtering proxy
D) reverse firewall

E) None of the above
F) A) and D)

Correct Answer

verifed

verified

Which type of firewall configuration protects public servers by isolating them from the internal network?


A) screened subnet DMZ
B) dual-homed host
C) screening router
D) reverse firewall

E) A) and B)
F) A) and C)

Correct Answer

verifed

verified

A

MATCHING -a process that uses the source and destination TCP and UDP port addresses to map traffic between internal and external hosts


A) dual-homed host
B) load-balancing software
C) many-to-one NAT
D) one-to-one NAT
E) proxy server
F) reverse firewall
G) screened host
H) screening router
I) server farm
J) three-pronged firewall

K) A) and I)
L) H) and I)

Correct Answer

verifed

verified

Which of the following is true about private IP addresses?


A) they are assigned by the IANA
B) they are not routable on the Internet
C) they are targeted by attackers
D) NAT was designed to conserve them

E) A) and D)
F) A) and B)

Correct Answer

verifed

verified

B

What is the term used for a computer placed on the network perimeter that is meant to attract attackers?


A) bastion host
B) honeypot
C) proxy decoy
D) virtual server

E) A) and D)
F) A) and B)

Correct Answer

verifed

verified

Which type of NAT is typically used on devices in the DMZ?


A) one-to-one NAT
B) port address translation
C) one-to-many NAT
D) many-to-one NAT

E) B) and C)
F) A) and B)

Correct Answer

verifed

verified

The TCP normalization feature forwards abnormal packets to an administrator for further inspection.

A) True
B) False

Correct Answer

verifed

verified

Showing 1 - 20 of 50

Related Exams

Show Answer