Endpoint Security and Network Access Control
This test includes security techniques used in organisations for the large networking medium. This test is useful for various competitive aspirants like UGC/GATE or CEH.
Questions
Which of the following statements is incorrect about VLAN (virtual LAN )?
- VLAN has mutually isolated, multiple distinct broadcast domains.
- There can be one or more routers to pass the data packets.
- It is not flexible for the networking requirements.
- VLAN provides broadcast filtering, security and address summarisation.
- It provides scalability and security to the applications.
Which of the following statements is true about 'Symantec control compliance suite' technique in endpoint security?
- It includes scanning of backup images for confidential data.
- It is used to identify systems that may be subject to technical control policies based on the data that is stored in them.
- It includes enforce policy-based encryption of files as they are copied in real-time to USBs.
- It uses messaging gateway to release and route quarantined messages directly from the DLP enforce platform.
- It includes mobile management to enforce virtual private network settings on mobile devices.
Which of the following statements is true about endpoint encryption technique?
- It is used to keep the email confidential, simplify compliance, and reduce management costs.
- It protects PCs, USB devices and removable media with full disk encryption.
- It provides an efficient and easy-to-use encryption service to keep the data safe in public and private clouds.
- It does not belong to enterprise data protection.
- It is used with VMware vSphere virtual environments.
Which of the following security techniques is not included in EDP product set?
- Integrated data loss prevention
- Mobile security
- Endpoint encryption
- VLAN security
- Email encryption gateway
Which of the following statements is false about Trend Micro™ mobile security?
- It is used to provide mobile security for all the data and applications.
- It is an important part of endpoint security.
- It enforces compliance and prevents data loss from lost or stolen mobile devices.
- It provides an efficient and easy-to-use encryption service to keep your data safe in public and private clouds.
- It is a component of the enterprise data protection.
Which of the following statements is false about IRM (information rights management) in endpoint security?
- IRM prevents the leakage of sensitive information to others.
- It uses the encryption techniques to secure the documents.
- The authorised users can have their access revoked at any time.
- IRM protection does not require any document to be encrypted.
- It is suitable to sensitive data and triggers the IRM encryption process.
Which of the following statements is false about file shares, databases and document repositories security?
- It includes discover and protects confidential data stored on file shares, databases, and repositories.
- The policy-based encryption and digital rights management are required for such security.
- Scanning of files or documents is used for that.
- It also uses encryption techniques to secure the files.
- The business data owners can not review such network file policy violations directly from an intuitive online portal.
Which of the following statements is false about integrated DLP technique?
- It extends the existing security with single-click deployment of data loss prevention (DLP).
- It provides device security also.
- It does not provide central management for security and data protection.
- DLP policies can be enforced across multiple layers of security to prevent data loss.
- It also provides security for microsoft sharepoint.
Which of the following statements is false about email and web security?
- Email and the web can cause data loss.
- For email and web security, the detection of the data in the networking medium is needed.
- The users are not informed for the security policy violations while detecting the confidential data.
- Encryption gateways should be separated to secure the emails.
- Web security can be maintained by securing data from the HTTP protocol.
Which of the following statements is false about the symantec data loss prevention for laptops and desktops?
- It is used to protect the data used within the network or in the network.
- This technique is used to scan and protect the confidential data.
- Endpoint agent monitors a wide range of user events on physical endpoints.
- It does not protect the shared data.
- It monitors the data transferred through the microsoft remote desktop protocol (RDP).
Which of the following statements is false about IEEE 802.1X standard for endpoint security?
- It is part of the IEEE 802.1 group of networking protocols.
- It is used to secure the LAN or WLAN.
- It is based on extensible authentication protocol (EAP).
- It includes the server, authenticator and the supplier for the communication.
- It provides IDS/IPS security.
Which of the following statements is false about data loss prevention (DLP)?
- It is used to prevent leaks of sensitive information.
- The monitoring and blocking DLP components run either on the network or on endpoints.
- DLP is used for the organisations that have all internal knowledge about the stored information.
- It can not block access of previously bypass information to the third parties.
- DLP provides decisions about content at a point in time.
Which of the following statements is true about EAP?
- It uses an arbitrary authentication method, such as certificates, smart cards or credentials.
- It is used in certificate-based security environments.
- It uses a mutual authentication method that supports password-based user or computer authentication.
- It uses an authentication method that uses TLS to enhance the security of other authentication protocols.
- It provides security violations.
Which of the following is a false statement about the integration of DLP (Data Loss Prevention) with IRM (Information Rights Management)?
- DLP-monitor and IRM-encrypt data in motion.
- IRM monitoring of DLP-encrypted information in motion.
- DLP discovery of IRM-encrypted information at rest.
- DLP monitoring of IRM-encrypted information in motion.
- DLP-discover and IRM-encrypt data at rest.