A1: | b,d,e |
A2: | b |
A3: | a,c,e |
A4: | b,c,d |
A5: | b,e |
A6: | b |
A7: | a |
A8: | b,e,g,h |
A9: | b,c,d |
A10: | b |
A11: | c |
A12: | a |
1: | What modules are found within the medium-sized network design? |
A1: | Corporate Internet module Campus module WAN module |
2: | At what locations in the medium-sized network design are private VLANs used? |
A2: | On the public services segment Within the campus module |
3: | What devices in a medium-sized network design provide VPN connectivity? |
A3: | Firewall VPN concentrator |
4: | Where would you use intrusion detection in the medium-sized network design? |
A4: | HIDS is used on servers that are located on the public services segment and within the campus module on the corporate intranet and management servers. A NIDS is used on both the public services and inside segments of the firewall. It is also used on the core switch of the campus module. Optionally, a NIDS can be used on the outside of the firewall. |
5: | Traditional dial-in users are terminated in which module of the medium-sized network design? |
A5: | Corporate Internet module |
6: | What type of filter is used to prevent IP spoofing attacks? |
A6: | RFC 2827 filtering mitigates IP spoofing attacks |
7: | In the medium-sized network design, the ACS is located in which module? |
A7: | The ACS is located within the campus module |
8: | What is facilitated by the use of a Layer 3 switch within the Campus module? |
A8: | Because multiple VLANs are used within the Campus module, a Layer 3 switch provides the functionality to route between each VLAN. |
9: | What services does the Campus module provide? |
A9: | End-user workstations, corporate servers, management servers, Layer 2 services, and Layer 3 services |
10: | In the SAFE medium-sized network design, what are the recommended IPSec policy parameters? |
A10: | Tunnel everything, use 3DES, and use SHA/HMAC |
11: | What services does the Corporate Internet module provide? |
A11: | Internet, corporate public servers, VPN, and dial-in connectivity |