Q&A
As mentioned in the introduction, "All About the Cisco Certified Security Professional Certification," you have two choices for review questions. The questions that follow next give you a bigger challenge than the exam itself by using an open-ended question format. By reviewing now with this more difficult question format, you can exercise your memory better and prove your conceptual and factual knowledge of this chapter. The answers to these questions are found in Appendix A.For more practice with exam-like question formats, including questions using a router simulator and multiple choice questions, use the exam engine on the CD-ROM.
1: | What are the two basic methods of mitigating reconnaissance attacks? |
2: | What is network posture visibility reduction? |
3: | What steps should be taken to harden an application against attack? |
4: | DoS and DDoS attacks focus on what part of the network architecture? |
5: | What are the three primary methods of mitigating DoS and DDoS attacks? |
6: | What is RFC 2827 filtering and who does it? |
7: | In addition to traffic-rate limiting, what can be done to mitigate DoS attacks? |
8: | Why is it easy to mitigate unauthorized access attacks? |
9: | Why are application layer attacks always a security risk? |
10: | How can application layer attacks best be mitigated? |
11: | How do NIDSs help to mitigate application layer attacks? |
12: | How can host-based IPSs help to mitigate application layer attacks? |
13: | How can trust exploitation attacks be mitigated? |
