MikroTik Certified Security Engineer (MTCSE) Certification
The MTCSE certification validates skills in implementing security measures for MikroTik networks, focusing on firewall management, cryptography, and secure tunneling.
Certification Overview
- Exam name: MTCSE
- Vendor: MikroTik
- Exam code: mtcse
- Duration: 60 minutes
- Total questions: 25
- Passing score: 60%
About This Certification
The MikroTik Certified Security Engineer (MTCSE) certification is designed to validate the skills needed to plan and implement security measures for networks using MikroTik devices. The certification encompasses several key areas, starting with an introduction to various types of network attacks, security mechanisms, and services. It addresses common threats and the deployment of RouterOS security features. Participants will gain hands-on experience through laboratory exercises. The certification covers comprehensive firewall management, including packet flow, firewall chains, stateful firewalls, and the use of the RAW table for SYN flood mitigation. It also emphasizes best practices for managing access, detecting attacks on critical infrastructure, and advanced firewall filter options. Another critical domain is the understanding and prevention of OSI Layer attacks, such as MNDP, DHCP starvation, TCP SYN, UDP, and ICMP Smurf attacks. The certification also covers brute-force attacks on FTP, telnet, and SSH, as well as port scan detection. Cryptography is another essential component, where candidates learn about encryption methods, symmetric and asymmetric algorithms, public key infrastructure, and the use of certificates within RouterOS. Securing the router involves techniques such as port knocking and establishing secure connections using HTTPS, SSH, and WinBox. Lastly, the certification explores secure tunneling methods, including IPsec, L2TP with IPsec, and SSTP with certificates, ensuring that candidates can implement secure communication channels.
Who Should Take This Exam?
Network Engineer, Network Technician, Security Analyst, IT Administrator, Systems Engineer, Security Consultant, Network Security Specialist, Technical Support Engineer
Prerequisites
Valid MTCNA certification
Topics Covered
- Topics to be announced
Question Types
- Multiple Choice (Single Answer)
- Multiple Choice (Multiple Answers)
- True / False
MTCSE Practice Questions
Our question bank contains 459+ practice questions for this certification. Sample questions from each exam chapter. Expand a question to see the answer choices. With a subscription, you get unlimited practice exams with randomized questions from our full question bank.
Introduction
There are six routers employing OSPF and linked through point-to-point network configurations.How many routers act as Designated Routers among them?
- 1
- 6
- 15
- 0
Which of the following CIDR notations represents a single host address (a /32 network), rather than a subnet?
- 192.168.1.1/24
- 192.168.1.1/32
- 192.168.1.1/16
- 192.168.1.1/8
The wireless security mode vulnerable to the KRACK attack is:
- WEP
- WPA
- WPA2
- WPA3
Firewall
The firewall action that drops the packet without sending any response to the source is:
- accept
- reject
- drop
- jump
The NAT masquerade rule in MikroTik RouterOS serves the function of:
- translate the source IP address to the public IP address
- translate the destination IP address to the private IP address
- translate the source port number to a random high port number
- translate the destination port number to a different port number
The firewall chain that processes packets destined to the router in MikroTik RouterOS is:
- input
- output
- forward
- prerouting
OSI Layer Attacks
Which command is used to monitor traffic that may indicate an OSI Layer 3 attack on a MikroTik router?
- /interface monitor-traffic
- /ip firewall filter
- /log print
- /system resource
How can a security analyst ensure that a MikroTik router is protected against OSI Layer 4 attacks while minimizing latency for legitimate traffic?
- Implementing deep packet inspection on all traffic
- Configuring rate limiting for specific services
- Blocking all traffic except for necessary ports
- Enabling logging for all incoming connections
An administrator is tasked with securing a MikroTik router against OSI Layer 3 attacks. Given the need for minimal performance impact, which filtering method is the MOST effective?
- Implementing IPsec for all traffic
- Using connection tracking to filter traffic
- Configuring MAC address filtering on all interfaces
- Applying rate limiting on all incoming traffic
Cryptography
The wireless authentication mode that utilizes a shared secret key for authentication among the options provided is:
- WEP
- WPA
- WPA2
- all of the above
Among the listed wireless encryption modes, the one that offers the highest level of security is:
- TKIP
- AES-CCMP
- WEP
- all of the above
The wireless security mode that utilizes 802.1X authentication and AES encryption among the options provided is:
- WPA
- WPA2
- WPA3
- all of the above
Securing the Router
The default port number for the SSH service in MikroTik RouterOS is:
- 21
- 23
- 22
- 25
What protocol is utilized for securing remote file transfers in MikroTik routerOS?
- SSH
- Telnet
- FTP
- all of the above
Your organization needs to implement a secure method for transferring files over the internet using MikroTik devices. Which cryptographic technologies should be utilized to ensure confidentiality and integrity of the transmitted files?
- SFTP using SSH for secure file transfer
- FTP without encryption
- Using GPG for encrypting files before transfer
- HTTP for transferring files
Secure Tunnels
The protocol used for remote access VPN in MikroTik RouterOS is:
- PPTP
- L2TP
- OpenVPN
- all of the above
The authentication protocol used for PPPoE in MikroTik RouterOS is:
- CHAP
- MS-CHAP
- PAP
- all of the above
Among the listed VPN protocols, the one considered the most secure is:
- PPTP
- L2TP
- SSTP
- OpenVPN
Frequently Asked Questions
How many questions are on the exam?
The MTCSE exam contains 25 questions.
What is the passing score?
You need 60% to pass.
How long is the exam?
You have 60 minutes to complete the exam.
Practice with realistic mock exams to prepare for your MikroTik certification.