Networking Fundamentals: Firewalls and Appliances
54 Questions
0 Views

Choose a study mode

Play Quiz
Study Flashcards
Spaced Repetition
Chat to lesson

Podcast

Play an AI-generated podcast conversation about this lesson

Questions and Answers

In its primary functionality, a network-attached storage (NAS) device is most closely associated with which of the following devices?

  • RAID
  • Failover cluster
  • File server (correct)
  • JBOD
  • Which of the following statements about the differences between network-attached storage (NAS) and storage area networks (SANs) are true? (Choose all that apply.)

  • NAS provides file-level storage access, whereas SAN provides block-level storage access. (correct)
  • NAS devices typically contain integrated iSCSI targets.
  • SAN devices have an operating system, whereas NAS devices do not.
  • NAS devices typically provide a filesystem, whereas SAN devices do not. (correct)
  • Which of the following specify advantages of FCoE over the original Fibre Channel standard? (Choose all that apply.)

  • FCoE uses standard Ethernet networking hardware. (correct)
  • FCoE can share a network with standard IP traffic, whereas Fibre Channel cannot. (correct)
  • FCoE is routable over IP networks, whereas Fibre Channel is not. (correct)
  • FCoE is less expensive to implement than Fibre Channel.
  • Which of the following are Application layer protocols that network-attached storage (NAS) devices can use to serve shared files to clients on the network? (Choose all that apply.)

    <p>NFS</p> Signup and view all the answers

    Which of the following is not one of the advantages of iSCSI over Fibre Channel?

    <p>iSCSI can share the same network as standard local area network traffic, whereas Fibre Channel cannot.</p> Signup and view all the answers

    Which of the following is the term for the client that accesses an iSCSI device on a storage area network?

    <p>Initiator</p> Signup and view all the answers

    Which of the following protocols are included in an iSCSI packet on a storage area network (SAN)? (Choose all that apply.)

    <p>IP</p> Signup and view all the answers

    Which of the following protocols are included in a Fibre Channel packet?

    <p>None of the above</p> Signup and view all the answers

    Which of the following protocol standards defines a layered implementation that does not correspond to the layers of the Open Systems Interconnection (OSI) model?

    <p>PPP</p> Signup and view all the answers

    Which of the following protocols are included in an FCoE packet?

    <p>Ethernet</p> Signup and view all the answers

    Ralph, the administrator of a 500-node private internetwork, is devising a plan to connect the network to the Internet. Which of the following statements about Ralph's proposed Internet access solution is true?

    <p>The proposal satisfies the primary objective and one of the secondary objectives.</p> Signup and view all the answers

    Which of the following is not a mechanism for distributing incoming network traffic among multiple servers?

    <p>VPN headend</p> Signup and view all the answers

    Which of the following is not a function typically provided by a unified threat management (UTM) appliance?

    <p>Network-attached storage</p> Signup and view all the answers

    A multilayer switch can operate at which layers of the Open Systems Interconnection (OSI) model? (Choose all that apply.)

    <p>Transport</p> Signup and view all the answers

    Control plane policing (CPP or CoPP) is a feature on some routers and switches that limits the rate of traffic on the device's processor to prevent denial-of-service (DoS) and reconnaissance attacks. It uses which of the following technologies?

    <p>QoS</p> Signup and view all the answers

    Which of the following is a device that switches calls between endpoints on the local IP network and provides access to external Internet lines?

    <p>VoIP gateway</p> Signup and view all the answers

    What is the true definition of the term modem?

    <p>A device that converts analog signals to digital signals and back again</p> Signup and view all the answers

    Which of the following terms are used to describe the device used to place calls on a Voice over Internet Protocol (VoIP) installation?

    <p>Gateway</p> Signup and view all the answers

    Which of the following devices enables you to use a standard analog telephone to place calls using the Internet instead of the public switched telephone network (PSTN)?

    <p>VoIP gateway</p> Signup and view all the answers

    Which of the following prevents packets on a TCP/IP internetwork from being transmitted endlessly from router to router?

    <p>Time to live (TTL)</p> Signup and view all the answers

    Which of the following is the abbreviation for a network of Internet data centers supplying end users with localized access to their data?

    <p>CDN</p> Signup and view all the answers

    Which of the following best describes the function of a firewall?

    <p>A device located between two networks that enables administrators to restrict incoming and outgoing traffic</p> Signup and view all the answers

    Which of the following terms is used to describe the method by which a firewall examines the port numbers in Transport layer protocol headers?

    <p>Service-dependent filtering</p> Signup and view all the answers

    Which of the following physical network devices can conceivably be implemented as software in a computer's operating system? (Choose all that apply.)

    <p>Router</p> Signup and view all the answers

    Which of the following criteria does a firewall capable of service-dependent filtering use to block traffic?

    <p>Port numbers</p> Signup and view all the answers

    Ralph is a freelance network consultant installing a small business network. Which solution would enable Ralph to protect the network from unauthorized Internet traffic and attacks against open ports with minimum cost?

    <p>Install a hardware firewall between the multifunction device and the cable modem</p> Signup and view all the answers

    Which of the following statements are true about hubs and switches? (Choose all that apply.)

    <p>All of the devices connected to a hub are part of a single collision domain, whereas each device connected to a switch has its own collision domain</p> Signup and view all the answers

    Which of the following devices perform essentially the same function? (Choose two.)

    <p>Bridges</p> Signup and view all the answers

    Which of the following switch types immediately forwards frames after looking at only the destination address?

    <p>Cut-through</p> Signup and view all the answers

    Which of the following is something that only a firewall capable of stateful packet inspection can do?

    <p>Scan Transport layer header fields for evidence of SYN floods</p> Signup and view all the answers

    Which of the following are methods typically used by intrusion detection systems (IDSs) to analyze incoming network traffic? (Choose all that apply.)

    <p>Anomaly-based detection</p> Signup and view all the answers

    Which of the following is another term for a multiport bridge?

    <p>Switch</p> Signup and view all the answers

    Which of the following statements about switches and routers are true? (Choose all that apply.)

    <p>All of the devices connected to a switch are part of a single broadcast domain, whereas the networks connected to a router form separate broadcast domains</p> Signup and view all the answers

    Which of the following types of systems are frequently used to collect information from intrusion detection systems (IDSs)?

    <p>SIEM</p> Signup and view all the answers

    Which of the following explains why splitting a large, switched Ethernet LAN into two LANs by adding a router can help alleviate traffic congestion and improve performance? (Choose all that apply.)

    <p>Adding a router reduces the amount of broadcast traffic on each of the two LANs</p> Signup and view all the answers

    Which of the following statements about traditional bridges and switches is true?

    <p>Bridges and switches are Data link layer devices that use media access control (MAC) addresses to forward frames</p> Signup and view all the answers

    Which of the following is a correct term describing the function of a traditional switch?

    <p>Multiport bridge</p> Signup and view all the answers

    Which of the following is the primary reason why replacing hubs with layer 2 switches on an Ethernet LAN improves its performance?

    <p>Layer 2 switches reduce the number of collisions on the network</p> Signup and view all the answers

    Which of the following statements about routers are true? (Choose all that apply.)

    <p>Routers are Network layer devices that use IP addresses to forward frames</p> Signup and view all the answers

    The network administrator is installing a firewall. At which of the following locations should the administrator install the firewall system?

    <p>Between the Internet access router and the rest of the private internetwork</p> Signup and view all the answers

    Proxy servers operate at which layer of the OSI reference model?

    <p>Application</p> Signup and view all the answers

    Which of the following is a feature that is not found in a traditional firewall product, but which might be found in a next-generation firewall (NGFW)?

    <p>Deep packet inspection (DPI)</p> Signup and view all the answers

    Which of the following statements about content filtering in firewalls is true?

    <p>Content filters examine the data carried within packets for potentially objectionable materials</p> Signup and view all the answers

    In its primary functionality, a network-attached storage (NAS) device is most closely associated with which of the following devices?

    <p>File server</p> Signup and view all the answers

    Which of the following statements about the differences between network-attached storage (NAS) and storage area networks (SANs) are true? (Choose all that apply.)

    <p>NAS provides file-level storage access, whereas SAN provides block-level storage access.</p> Signup and view all the answers

    Which of the following statements specify advantages of FCoE over the original Fibre Channel standard? (Choose all that apply.)

    <p>FCoE can share a network with standard IP traffic, whereas Fibre Channel cannot.</p> Signup and view all the answers

    Which of the following are Application layer protocols that network-attached storage (NAS) devices can use to serve shared files to clients on the network? (Choose all that apply.)

    <p>NFS</p> Signup and view all the answers

    Which of the following is not one of the advantages of iSCSI over Fibre Channel?

    <p>iSCSI includes its own internal flow control mechanism, whereas Fibre Channel does not.</p> Signup and view all the answers

    Which of the following is the term for the client that accesses an iSCSI device on a storage area network?

    <p>Initiator</p> Signup and view all the answers

    Which of the following protocols are included in an iSCSI packet on a storage area network (SAN)? (Choose all that apply.)

    <p>IP</p> Signup and view all the answers

    Which of the following is the abbreviation for a network of Internet data centers supplying end users with localized access to their data?

    <p>CDN</p> Signup and view all the answers

    Which of the following best describes the function of a firewall?

    <p>A device located between two networks that enables administrators to restrict incoming and outgoing traffic</p> Signup and view all the answers

    Which of the following terms is used to describe the method by which a firewall examines the port numbers in Transport layer protocol headers?

    <p>Service-dependent filtering</p> Signup and view all the answers

    Which of the following physical network devices can conceivably be implemented as software in a computer's operating system?

    <p>Router</p> Signup and view all the answers

    Study Notes

    Networking Appliances, Applications, and Functions

    • A firewall is a device that restricts incoming and outgoing traffic between two networks.
    • Service-dependent filtering is a method used by firewalls to block traffic based on port numbers.
    • Deep packet inspection (DPI) is a method used by firewalls to examine the contents of packets.
    • A router is a device that connects multiple networks together and forwards traffic between them.
    • A switch is a device that connects multiple devices on a network and forwards traffic between them.
    • A hub is a simple network device that connects multiple devices together.
    • Network address translation (NAT) is a technique used to allow multiple devices to share a single public IP address.
    • Intrusion detection systems (IDSs) are used to monitor network traffic for signs of unauthorized access or attacks.

    Switching and Routing

    • Cut-through switching is a technique used by switches to forward frames immediately after reading the destination address.
    • Store-and-forward switching is a technique used by switches to forward frames after receiving the entire frame.
    • Routers operate at the Network layer and use IP addresses to forward packets.
    • Switches operate at the Data link layer and use MAC addresses to forward frames.
    • Routers can connect multiple networks with different Data link layer protocols and media.

    Firewalls and Network Security

    • Next-generation firewalls (NGFWs) are firewalls that can perform deep packet inspection and other advanced security features.
    • Proxy servers are used to access Internet resources on behalf of a network user.
    • Content filtering is a technique used by firewalls to block traffic based on the contents of packets.
    • Load balancers are used to distribute incoming traffic among multiple servers.
    • Unified threat management (UTM) appliances are devices that provide multiple security features, including firewalling, antivirus, and intrusion prevention.

    Storage Area Networks (SANs)

    • iSCSI is a protocol used to connect storage devices to a network.
    • Fibre Channel is a high-speed protocol used to connect storage devices to a network.
    • Fibre Channel over Ethernet (FCoE) is a protocol used to connect storage devices to a network over Ethernet.
    • Network-attached storage (NAS) devices are used to provide shared file access to a network.

    Internet Access and Voice over IP (VoIP)

    • Proxy servers can be used to provide Internet access to a network.
    • VoIP gateways are used to connect VoIP phones to the Internet.
    • VoIP PBX is a device that connects VoIP phones to a network and provides call management features.

    Miscellaneous

    • Time to live (TTL) is a field in a packet that prevents packets from being transmitted endlessly from router to router.
    • Content delivery networks (CDNs) are networks of data centers that provide localized access to data.
    • Control plane policing (CPP) is a feature used to prevent denial-of-service attacks on network devices.

    Networking Appliances, Applications, and Functions

    • A firewall is a device that restricts incoming and outgoing traffic between two networks.
    • Service-dependent filtering is a method used by firewalls to block traffic based on port numbers.
    • Deep packet inspection (DPI) is a method used by firewalls to examine the contents of packets.
    • A router is a device that connects multiple networks together and forwards traffic between them.
    • A switch is a device that connects multiple devices on a network and forwards traffic between them.
    • A hub is a simple network device that connects multiple devices together.
    • Network address translation (NAT) is a technique used to allow multiple devices to share a single public IP address.
    • Intrusion detection systems (IDSs) are used to monitor network traffic for signs of unauthorized access or attacks.

    Switching and Routing

    • Cut-through switching is a technique used by switches to forward frames immediately after reading the destination address.
    • Store-and-forward switching is a technique used by switches to forward frames after receiving the entire frame.
    • Routers operate at the Network layer and use IP addresses to forward packets.
    • Switches operate at the Data link layer and use MAC addresses to forward frames.
    • Routers can connect multiple networks with different Data link layer protocols and media.

    Firewalls and Network Security

    • Next-generation firewalls (NGFWs) are firewalls that can perform deep packet inspection and other advanced security features.
    • Proxy servers are used to access Internet resources on behalf of a network user.
    • Content filtering is a technique used by firewalls to block traffic based on the contents of packets.
    • Load balancers are used to distribute incoming traffic among multiple servers.
    • Unified threat management (UTM) appliances are devices that provide multiple security features, including firewalling, antivirus, and intrusion prevention.

    Storage Area Networks (SANs)

    • iSCSI is a protocol used to connect storage devices to a network.
    • Fibre Channel is a high-speed protocol used to connect storage devices to a network.
    • Fibre Channel over Ethernet (FCoE) is a protocol used to connect storage devices to a network over Ethernet.
    • Network-attached storage (NAS) devices are used to provide shared file access to a network.

    Internet Access and Voice over IP (VoIP)

    • Proxy servers can be used to provide Internet access to a network.
    • VoIP gateways are used to connect VoIP phones to the Internet.
    • VoIP PBX is a device that connects VoIP phones to a network and provides call management features.

    Miscellaneous

    • Time to live (TTL) is a field in a packet that prevents packets from being transmitted endlessly from router to router.
    • Content delivery networks (CDNs) are networks of data centers that provide localized access to data.
    • Control plane policing (CPP) is a feature used to prevent denial-of-service attacks on network devices.

    Studying That Suits You

    Use AI to generate personalized quizzes and flashcards to suit your learning preferences.

    Quiz Team

    Related Documents

    Description

    Compare and contrast networking appliances, applications, and functions, including firewalls, routers, and more. Understand their roles in network security and connectivity.

    More Like This

    Firewalls and Network Security
    16 questions
    Packet Filtering in Network Security
    9 questions
    Use Quizgecko on...
    Browser
    Browser