“Do I Know This Already?” Quiz

The “Do I Know This Already?” quiz helps you determine your level of knowledge of this chapter’s topics before you begin. Table 10-1 details the major topics discussed in this chapter and their corresponding quiz questions.

Image

Table 10-1 “Do I Know This Already?” Section-to-Question Mapping

1. Which of the following is not a core element addressed by NFP (Network Foundation Protection)?

a. Management plane

b. Control plane

c. Data plane

d. Executive plane

2. If you add authentication to your routing protocol so that only trusted authorized routers share information, which plane in the NFP are you securing?

a. Management plane

b. Control plane

c. Data plane

d. Executive plane

3. If you use authentication and authorization services to control which administrators can access which networked devices and control what they are allowed to do, which primary plane of NFP are you protecting?

a. Management plane

b. Control plane

c. Data plane

d. Executive plane

4. Which of the following is not a best practice to protect the management plane? (Choose all that apply.)

a. HTTP

b. Telnet

c. HTTPS

d. SSH

5. Which of the following is a way to implement role-based access control related to the management plane? (Choose all that apply.)

a. Views

b. AAA services

c. Access lists

d. IPS

6. What do CoPP and CPPr have in common? (Choose all that apply.)

a. They both focus on data plane protection.

b. They both focus on management plane protection.

c. They both focus on control plane protection.

d. They both can identify traffic destined for the router that will likely require direct CPU resources to be used by the router.

7. Which type of attack can you mitigate by authenticating a routing protocol? (Choose all that apply.)

a. Man-in-the-middle attack

b. Denial-of-service attack

c. Reconnaissance attack

d. Spoofing attack

8. What is a significant difference between CoPP and CPPr?

a. One works at Layer 3, and the other works at Layer 2.

b. CPPr can classify and act on more-specific traffic than CoPP.

c. CoPP can classify and act on more-specific traffic than CPPr.

d. One protects the data plane, and the other protects the management plane.

9. Which of the following enables you to protect the data plane?

a. IOS zone-based firewall

b. IPS

c. Access lists

d. Port security

10. DHCP snooping protects which component of NFP?

a. Management plane

b. Control plane

c. Data plane

d. Executive plane

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset