100-160 exam dumps

100-160 practice question 68 of 265

Cisco Certified Support Technician (CCST) Cybersecurity. Associate level, Cisco. Free question with the correct answer and a full explanation.

100-160 Question 68

Select 3

A company has noticed unusual activity on its network. After investigation, it was discovered that attackers used IP spoofing to bypass firewall rules and gain unauthorized access to internal systems. Which of the following measures can help mitigate this type of attack?

  1. A

    Implement ingress filtering to verify the legitimacy of incoming IP addresses.

  2. B

    Enable MAC address filtering on all network devices.

  3. C

    Use private IP addresses for internal systems and employ Network Address Translation (NAT).

  4. D

    Configure the firewall to block all traffic originating from external IP addresses.

  5. E

    Enable logging and monitoring of all outgoing and incoming traffic.

Show answer and explanation

Correct answers: A, C, E

Explanation

IP spoofing is a technique where attackers forge the source IP address to bypass security measures and gain unauthorized access. Mitigating this requires verifying the authenticity of incoming IP addresses (ingress filtering), reducing the exposure of internal systems through NAT, and monitoring traffic for suspicious behavior. These measures collectively strengthen the network's defense against such attacks.

  • A. Correct.

    Ingress filtering helps prevent IP spoofing by verifying that incoming packets come from legitimate sources, reducing the risk of spoofed IPs bypassing security measures.

  • B. Incorrect.

    While MAC address filtering can add a layer of security, it is not effective against IP spoofing, as MAC addresses operate at a different layer of the OSI model and are not related to IP address verification.

  • C. Correct.

    Using private IP addresses with NAT ensures that internal systems are not directly exposed to the internet, reducing the attack surface and mitigating risks associated with spoofed external IPs.

  • D. Incorrect.

    Blocking all traffic from external IP addresses is not practical for most networks as it would disrupt legitimate communication and is not a specific countermeasure for IP spoofing.

  • E. Correct.

    Logging and monitoring traffic can help identify patterns of suspicious activity, including IP spoofing attempts, and assist in taking corrective actions promptly.

Timed practice exam

Take a 100-160 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam