Questions
The following is a short list of review questions to help reinforce your learning and help you identify areas that require some improvement. The answers to these questions can be found in the Assessments section at the end of this book:
- Which type of device provides automation for handling security incidents?
A. SIEM
B. IPS
C. SOAR
D. Firewall
- How can a firewall filter traffic on a network?
A. Through the source IP address
B. Through the service port number
C. Through the protocol
D. All of the above
- How can a security professional capture traffic on a network?
A. By configuring SPAN
B. By configuring Spanning Tree Protocol (STP)
C. By configuring port security
D. None of the above
- Which of the following alert types means there is an intrusion on the network but no alarms were triggered?
A. False positive
B. False negative
C. True positive
D. True negative
- Which of the following is not an element of the five tuples?
A. Destination server port number
B. Protocol
C. Source...