C
Cert2Hire
Your Fastest Path to Certification

Welcome to the Cert2Hire Security+ Simulation

Read the question carefully, follow all instructions, then click Submit.

TEST QUESTION

Scenario

GlobalTech Industries, a mid-sized financial services firm headquartered in Austin, Texas, recently suffered a series of coordinated cyberattacks targeting their public-facing web infrastructure. Over the course of three weeks, the organization's external web servers were subjected to multiple intrusion attempts, resulting in unauthorized data access affecting approximately 4,200 customer records. The board of directors, led by CEO Margaret Holloway, mandated an immediate and comprehensive security overhaul of all network-facing systems.

In response, IT Director James Whitfield engaged a certified security consultant who implemented a full Demilitarized Zone (DMZ) architecture, physically and logically separating the organization's public-facing servers from the internal corporate network. The DMZ was configured with dedicated subnets, updated Access Control Lists on the perimeter router, and new firewall policies designed to restrict unauthorized lateral movement. The implementation was completed and signed off on a Friday evening.

Two weeks after the reconfiguration, executive assistant Sandra Park reported that senior executive Mr. David Chen on the second floor is unable to access any external websites, including https://certificationbody.org, a regulatory compliance portal used daily in his role. Mr. Chen confirmed he can still send and receive internal email, access the company intranet, use shared network drives, and print to the local network printer. All other second floor staff have not reported issues. IT Director Whitfield suspects the issue may be related to the ACL rules configured on the perimeter router during the DMZ implementation and has escalated to your team for immediate resolution.

Instructions

  1. Click each workstation to open its command prompt terminal. Run appropriate network diagnostic commands to determine which workstation is experiencing the connectivity issue and identify exactly where in the network path the failure occurs.
  2. Click the Router to open its configuration panel. Review the interface addresses to understand the network topology. Then review the Access Control List rules to identify which rule is incorrectly blocking legitimate traffic.
  3. Modify only the rule that is causing the connectivity issue. Do not change any other rules. The router implements an implicit deny on all unmatched traffic.
  4. After correcting the ACL, verify your fix makes logical sense given the interface addressing scheme.
  5. Click Submit when you have completed your changes.

If at any time you would like to return this question to its initial state, click the Reset All Answers button.

FLOOR 2 — EXECUTIVE OFFICESFLOOR 1 — NETWORK CLOSETDMZeth1eth2h1eth3
Printer
Switch
Floor 2
Workstation 1
192.168.0.65
Click to Open
Workstation 2
192.168.0.70
Click to Open
Router
Perimeter
Click to Open
Switch
DMZ
DNS Server
192.168.0.35
File Server
192.168.0.38
Email Server
192.168.0.41
Web Server
192.168.0.44