Complete networking bank

All 5,000 questions.

Search the curriculum, filter by level, check your saved status, or open any question in revision mode.

0 answered overall

Showing 2,151–2,200 of 5,000 matching questions

50 per page
2151
Level 3 · Intermediate NAT Unanswered

For a cloud migration threat model, why is understanding "PAT" technically important?

View answer choices
  1. Every inside host receives a dedicated public address permanently.
  2. Many inside sessions share one public IP by using distinct transport port mappings.
  3. A router exchanges link-state databases.
  4. A switch tags frames with a VLAN ID.
Practice
2152
Level 3 · Intermediate NAT Unanswered

For a cloud migration threat model, why is understanding "static NAT" technically important?

View answer choices
  1. A fixed one-to-one mapping between an inside and an outside address.
  2. A many-to-one mapping selected per port.
  3. A DNS alias with no address translation.
  4. A dynamic routing neighbor.
Practice
2153
Level 3 · Intermediate Access Control Unanswered

For a cloud migration threat model, why is understanding "standard ACL" technically important?

View answer choices
  1. A table that maps IP addresses to MAC addresses.
  2. A routing protocol database.
  3. A filter that always matches source and destination ports.
  4. An access list that typically filters IPv4 traffic using only the source address.
Practice
2154
Level 3 · Intermediate Access Control Unanswered

For a cloud migration threat model, why is understanding "extended ACL" technically important?

View answer choices
  1. A physical port expansion module.
  2. A DNS zone transfer.
  3. An access list that can match protocol, source, destination, and transport ports.
  4. A list that can match only a source IP.
Practice
2155
Level 3 · Intermediate Access Control Unanswered

For a cloud migration threat model, why is understanding "implicit deny" technically important?

View answer choices
  1. All unmatched traffic is automatically permitted.
  2. The first ACL entry is ignored.
  3. Traffic not matched by a permit rule is denied at the end of an ACL.
  4. Only broadcast traffic is denied.
Practice
2156
Level 3 · Intermediate Security Unanswered

For a cloud migration threat model, why is understanding "stateful firewall" technically important?

View answer choices
  1. A firewall that tracks connection state and can allow valid return traffic.
  2. A firewall that examines only cable voltages.
  3. A stateless Ethernet repeater.
  4. A DNS server that stores no cache.
Practice
2157
Level 3 · Intermediate VPN Unanswered

For a cloud migration threat model, why is understanding "site-to-site VPN" technically important?

View answer choices
  1. A cable that directly connects two laptops.
  2. A public Wi-Fi SSID.
  3. A VLAN carried across one switch.
  4. An encrypted tunnel that securely connects networks at separate locations.
Practice
2158
Level 3 · Intermediate VPN Unanswered

For a cloud migration threat model, why is understanding "remote-access VPN" technically important?

View answer choices
  1. A secure connection that gives an individual user access to a private network.
  2. A public DNS delegation.
  3. A trunk between two switches.
  4. A routing protocol adjacency between providers.
Practice
2159
Level 3 · Intermediate VPN Unanswered

For a cloud migration threat model, why is understanding "IPsec" technically important?

View answer choices
  1. A Wi-Fi channel-selection algorithm.
  2. A suite that authenticates and/or encrypts IP packets, commonly for VPNs.
  3. A protocol for assigning IP addresses.
  4. A Layer 2 discovery protocol only.
Practice
2160
Level 3 · Intermediate Subnetting Unanswered

For a cloud migration threat model, why is understanding "VLSM" technically important?

View answer choices
  1. Using different prefix lengths to create subnets sized for different requirements.
  2. Using one fixed subnet size everywhere.
  3. Translating private addresses to public addresses.
  4. Tagging Ethernet frames with one VLAN.
Practice
2161
Level 3 · Intermediate NAT Unanswered

A security engineer documents "PAT" during an industrial network security review. Which definition belongs in the report?

View answer choices
  1. A switch tags frames with a VLAN ID.
  2. A router exchanges link-state databases.
  3. Every inside host receives a dedicated public address permanently.
  4. Many inside sessions share one public IP by using distinct transport port mappings.
Practice
2162
Level 3 · Intermediate NAT Unanswered

A security engineer documents "static NAT" during an industrial network security review. Which definition belongs in the report?

View answer choices
  1. A fixed one-to-one mapping between an inside and an outside address.
  2. A DNS alias with no address translation.
  3. A dynamic routing neighbor.
  4. A many-to-one mapping selected per port.
Practice
2163
Level 3 · Intermediate Access Control Unanswered

A security engineer documents "standard ACL" during an industrial network security review. Which definition belongs in the report?

View answer choices
  1. A filter that always matches source and destination ports.
  2. An access list that typically filters IPv4 traffic using only the source address.
  3. A routing protocol database.
  4. A table that maps IP addresses to MAC addresses.
Practice
2164
Level 3 · Intermediate Access Control Unanswered

A security engineer documents "extended ACL" during an industrial network security review. Which definition belongs in the report?

View answer choices
  1. A physical port expansion module.
  2. A list that can match only a source IP.
  3. An access list that can match protocol, source, destination, and transport ports.
  4. A DNS zone transfer.
Practice
2165
Level 3 · Intermediate Access Control Unanswered

A security engineer documents "implicit deny" during an industrial network security review. Which definition belongs in the report?

View answer choices
  1. Only broadcast traffic is denied.
  2. The first ACL entry is ignored.
  3. All unmatched traffic is automatically permitted.
  4. Traffic not matched by a permit rule is denied at the end of an ACL.
Practice
2166
Level 3 · Intermediate Security Unanswered

A security engineer documents "stateful firewall" during an industrial network security review. Which definition belongs in the report?

View answer choices
  1. A stateless Ethernet repeater.
  2. A DNS server that stores no cache.
  3. A firewall that tracks connection state and can allow valid return traffic.
  4. A firewall that examines only cable voltages.
Practice
2167
Level 3 · Intermediate VPN Unanswered

A security engineer documents "site-to-site VPN" during an industrial network security review. Which definition belongs in the report?

View answer choices
  1. A cable that directly connects two laptops.
  2. A VLAN carried across one switch.
  3. An encrypted tunnel that securely connects networks at separate locations.
  4. A public Wi-Fi SSID.
Practice
2168
Level 3 · Intermediate VPN Unanswered

A security engineer documents "remote-access VPN" during an industrial network security review. Which definition belongs in the report?

View answer choices
  1. A trunk between two switches.
  2. A routing protocol adjacency between providers.
  3. A secure connection that gives an individual user access to a private network.
  4. A public DNS delegation.
Practice
2169
Level 3 · Intermediate VPN Unanswered

A security engineer documents "IPsec" during an industrial network security review. Which definition belongs in the report?

View answer choices
  1. A protocol for assigning IP addresses.
  2. A Layer 2 discovery protocol only.
  3. A Wi-Fi channel-selection algorithm.
  4. A suite that authenticates and/or encrypts IP packets, commonly for VPNs.
Practice
2170
Level 3 · Intermediate Subnetting Unanswered

A security engineer documents "VLSM" during an industrial network security review. Which definition belongs in the report?

View answer choices
  1. Using one fixed subnet size everywhere.
  2. Tagging Ethernet frames with one VLAN.
  3. Using different prefix lengths to create subnets sized for different requirements.
  4. Translating private addresses to public addresses.
Practice
2171
Level 3 · Intermediate NAT Unanswered

While mapping attack paths in a managed-service-provider audit, the team discusses "PAT". What is the accurate meaning?

View answer choices
  1. Many inside sessions share one public IP by using distinct transport port mappings.
  2. A router exchanges link-state databases.
  3. A switch tags frames with a VLAN ID.
  4. Every inside host receives a dedicated public address permanently.
Practice
2172
Level 3 · Intermediate NAT Unanswered

While mapping attack paths in a managed-service-provider audit, the team discusses "static NAT". What is the accurate meaning?

View answer choices
  1. A many-to-one mapping selected per port.
  2. A DNS alias with no address translation.
  3. A dynamic routing neighbor.
  4. A fixed one-to-one mapping between an inside and an outside address.
Practice
2173
Level 3 · Intermediate Access Control Unanswered

While mapping attack paths in a managed-service-provider audit, the team discusses "standard ACL". What is the accurate meaning?

View answer choices
  1. An access list that typically filters IPv4 traffic using only the source address.
  2. A filter that always matches source and destination ports.
  3. A table that maps IP addresses to MAC addresses.
  4. A routing protocol database.
Practice
2174
Level 3 · Intermediate Access Control Unanswered

While mapping attack paths in a managed-service-provider audit, the team discusses "extended ACL". What is the accurate meaning?

View answer choices
  1. A DNS zone transfer.
  2. An access list that can match protocol, source, destination, and transport ports.
  3. A list that can match only a source IP.
  4. A physical port expansion module.
Practice
2175
Level 3 · Intermediate Access Control Unanswered

While mapping attack paths in a managed-service-provider audit, the team discusses "implicit deny". What is the accurate meaning?

View answer choices
  1. Traffic not matched by a permit rule is denied at the end of an ACL.
  2. The first ACL entry is ignored.
  3. Only broadcast traffic is denied.
  4. All unmatched traffic is automatically permitted.
Practice
2176
Level 3 · Intermediate Security Unanswered

While mapping attack paths in a managed-service-provider audit, the team discusses "stateful firewall". What is the accurate meaning?

View answer choices
  1. A firewall that examines only cable voltages.
  2. A DNS server that stores no cache.
  3. A stateless Ethernet repeater.
  4. A firewall that tracks connection state and can allow valid return traffic.
Practice
2177
Level 3 · Intermediate VPN Unanswered

While mapping attack paths in a managed-service-provider audit, the team discusses "site-to-site VPN". What is the accurate meaning?

View answer choices
  1. An encrypted tunnel that securely connects networks at separate locations.
  2. A public Wi-Fi SSID.
  3. A cable that directly connects two laptops.
  4. A VLAN carried across one switch.
Practice
2178
Level 3 · Intermediate VPN Unanswered

While mapping attack paths in a managed-service-provider audit, the team discusses "remote-access VPN". What is the accurate meaning?

View answer choices
  1. A public DNS delegation.
  2. A secure connection that gives an individual user access to a private network.
  3. A routing protocol adjacency between providers.
  4. A trunk between two switches.
Practice
2179
Level 3 · Intermediate VPN Unanswered

While mapping attack paths in a managed-service-provider audit, the team discusses "IPsec". What is the accurate meaning?

View answer choices
  1. A suite that authenticates and/or encrypts IP packets, commonly for VPNs.
  2. A Wi-Fi channel-selection algorithm.
  3. A Layer 2 discovery protocol only.
  4. A protocol for assigning IP addresses.
Practice
2180
Level 3 · Intermediate Subnetting Unanswered

While mapping attack paths in a managed-service-provider audit, the team discusses "VLSM". What is the accurate meaning?

View answer choices
  1. Using one fixed subnet size everywhere.
  2. Translating private addresses to public addresses.
  3. Tagging Ethernet frames with one VLAN.
  4. Using different prefix lengths to create subnets sized for different requirements.
Practice
2181
Level 3 · Intermediate NAT Unanswered

An analyst validating a government zero-trust rollout sees "PAT". Which technical explanation should be used?

View answer choices
  1. Many inside sessions share one public IP by using distinct transport port mappings.
  2. Every inside host receives a dedicated public address permanently.
  3. A switch tags frames with a VLAN ID.
  4. A router exchanges link-state databases.
Practice
2182
Level 3 · Intermediate NAT Unanswered

An analyst validating a government zero-trust rollout sees "static NAT". Which technical explanation should be used?

View answer choices
  1. A many-to-one mapping selected per port.
  2. A dynamic routing neighbor.
  3. A fixed one-to-one mapping between an inside and an outside address.
  4. A DNS alias with no address translation.
Practice
2183
Level 3 · Intermediate Access Control Unanswered

An analyst validating a government zero-trust rollout sees "standard ACL". Which technical explanation should be used?

View answer choices
  1. A table that maps IP addresses to MAC addresses.
  2. A routing protocol database.
  3. An access list that typically filters IPv4 traffic using only the source address.
  4. A filter that always matches source and destination ports.
Practice
2184
Level 3 · Intermediate Access Control Unanswered

An analyst validating a government zero-trust rollout sees "extended ACL". Which technical explanation should be used?

View answer choices
  1. A list that can match only a source IP.
  2. A physical port expansion module.
  3. A DNS zone transfer.
  4. An access list that can match protocol, source, destination, and transport ports.
Practice
2185
Level 3 · Intermediate Access Control Unanswered

An analyst validating a government zero-trust rollout sees "implicit deny". Which technical explanation should be used?

View answer choices
  1. Traffic not matched by a permit rule is denied at the end of an ACL.
  2. Only broadcast traffic is denied.
  3. All unmatched traffic is automatically permitted.
  4. The first ACL entry is ignored.
Practice
2186
Level 3 · Intermediate Security Unanswered

An analyst validating a government zero-trust rollout sees "stateful firewall". Which technical explanation should be used?

View answer choices
  1. A DNS server that stores no cache.
  2. A firewall that tracks connection state and can allow valid return traffic.
  3. A firewall that examines only cable voltages.
  4. A stateless Ethernet repeater.
Practice
2187
Level 3 · Intermediate VPN Unanswered

An analyst validating a government zero-trust rollout sees "site-to-site VPN". Which technical explanation should be used?

View answer choices
  1. A public Wi-Fi SSID.
  2. A VLAN carried across one switch.
  3. An encrypted tunnel that securely connects networks at separate locations.
  4. A cable that directly connects two laptops.
Practice
2188
Level 3 · Intermediate VPN Unanswered

An analyst validating a government zero-trust rollout sees "remote-access VPN". Which technical explanation should be used?

View answer choices
  1. A trunk between two switches.
  2. A public DNS delegation.
  3. A routing protocol adjacency between providers.
  4. A secure connection that gives an individual user access to a private network.
Practice
2189
Level 3 · Intermediate VPN Unanswered

An analyst validating a government zero-trust rollout sees "IPsec". Which technical explanation should be used?

View answer choices
  1. A suite that authenticates and/or encrypts IP packets, commonly for VPNs.
  2. A protocol for assigning IP addresses.
  3. A Layer 2 discovery protocol only.
  4. A Wi-Fi channel-selection algorithm.
Practice
2190
Level 3 · Intermediate Subnetting Unanswered

An analyst validating a government zero-trust rollout sees "VLSM". Which technical explanation should be used?

View answer choices
  1. Translating private addresses to public addresses.
  2. Tagging Ethernet frames with one VLAN.
  3. Using different prefix lengths to create subnets sized for different requirements.
  4. Using one fixed subnet size everywhere.
Practice
2191
Level 3 · Intermediate NAT Unanswered

During lessons learned from a multinational enterprise breach simulation, which statement about "PAT" is correct?

View answer choices
  1. A router exchanges link-state databases.
  2. Many inside sessions share one public IP by using distinct transport port mappings.
  3. Every inside host receives a dedicated public address permanently.
  4. A switch tags frames with a VLAN ID.
Practice
2192
Level 3 · Intermediate NAT Unanswered

During lessons learned from a multinational enterprise breach simulation, which statement about "static NAT" is correct?

View answer choices
  1. A fixed one-to-one mapping between an inside and an outside address.
  2. A many-to-one mapping selected per port.
  3. A DNS alias with no address translation.
  4. A dynamic routing neighbor.
Practice
2193
Level 3 · Intermediate Access Control Unanswered

During lessons learned from a multinational enterprise breach simulation, which statement about "standard ACL" is correct?

View answer choices
  1. A filter that always matches source and destination ports.
  2. A routing protocol database.
  3. A table that maps IP addresses to MAC addresses.
  4. An access list that typically filters IPv4 traffic using only the source address.
Practice
2194
Level 3 · Intermediate Access Control Unanswered

During lessons learned from a multinational enterprise breach simulation, which statement about "extended ACL" is correct?

View answer choices
  1. A physical port expansion module.
  2. A DNS zone transfer.
  3. An access list that can match protocol, source, destination, and transport ports.
  4. A list that can match only a source IP.
Practice
2195
Level 3 · Intermediate Access Control Unanswered

During lessons learned from a multinational enterprise breach simulation, which statement about "implicit deny" is correct?

View answer choices
  1. All unmatched traffic is automatically permitted.
  2. Traffic not matched by a permit rule is denied at the end of an ACL.
  3. The first ACL entry is ignored.
  4. Only broadcast traffic is denied.
Practice
2196
Level 3 · Intermediate Security Unanswered

During lessons learned from a multinational enterprise breach simulation, which statement about "stateful firewall" is correct?

View answer choices
  1. A stateless Ethernet repeater.
  2. A firewall that examines only cable voltages.
  3. A firewall that tracks connection state and can allow valid return traffic.
  4. A DNS server that stores no cache.
Practice
2197
Level 3 · Intermediate VPN Unanswered

During lessons learned from a multinational enterprise breach simulation, which statement about "site-to-site VPN" is correct?

View answer choices
  1. A cable that directly connects two laptops.
  2. A VLAN carried across one switch.
  3. A public Wi-Fi SSID.
  4. An encrypted tunnel that securely connects networks at separate locations.
Practice
2198
Level 3 · Intermediate VPN Unanswered

During lessons learned from a multinational enterprise breach simulation, which statement about "remote-access VPN" is correct?

View answer choices
  1. A secure connection that gives an individual user access to a private network.
  2. A public DNS delegation.
  3. A trunk between two switches.
  4. A routing protocol adjacency between providers.
Practice
2199
Level 3 · Intermediate VPN Unanswered

During lessons learned from a multinational enterprise breach simulation, which statement about "IPsec" is correct?

View answer choices
  1. A Wi-Fi channel-selection algorithm.
  2. A suite that authenticates and/or encrypts IP packets, commonly for VPNs.
  3. A protocol for assigning IP addresses.
  4. A Layer 2 discovery protocol only.
Practice
2200
Level 3 · Intermediate Subnetting Unanswered

During lessons learned from a multinational enterprise breach simulation, which statement about "VLSM" is correct?

View answer choices
  1. Using different prefix lengths to create subnets sized for different requirements.
  2. Using one fixed subnet size everywhere.
  3. Translating private addresses to public addresses.
  4. Tagging Ethernet frames with one VLAN.
Practice