Font size
WorksheetsNWS QUIZ
Total questions: 126
Worksheet time: 1hrs 5mins
Which command will block login attempts on RouterA for a period of 30 seconds if there are 2 failed login attempts within 10 seconds?
RouterA(config)# login block-for 10 attempts 2 within 30
RouterA(config)# login block-for 30 attempts 2 within 10
RouterA(config)# login block-for 2 attempts 30 within 10
RouterA(config)# login block-for 30 attempts 10 within 2
Passwords can be used to restrict access to all or parts of the Cisco IOS. Select the modes and interfaces that can be protected with passwords. (Choose three.)
VTY interface
console interface
Ethernet interface
boot IOS mode
privileged EXEC mode
5. A network administrator enters the service password-encryption command into the configuration mode of a router. What does this command accomplish?
This command encrypts passwords as they are transmitted across serial WAN links
This command prevents someone from viewing the running configuration passwords.
This command enables a strong encryption algorithm for the enable secret password command.
This command automatically encrypts passwords in configuration files that are currently stored in NVRAM.
6. On which two interfaces or ports can security be improved by configuring executive timeouts? (Choose two.)
Fast Ethernet interfaces
console ports
serial interfaces
vty ports
8. When implementing components into an enterprise network, what is the purpose of a firewall?
A firewall is a system that inspects network traffic and makes forwarding decisions based solely on Layer 2 Ethernet MAC addresses.
A firewall is a system that is designed to secure, monitor, and manage mobile devices, including corporate-owned devices and employee-owned devices.
A firewall is a system that stores vast quantities of sensitive and business-critical information.
A firewall is a system that enforces an access control policy between internal corporate networks and external networks.
7. A security service company is conducting an audit in several risk areas within a major corporation. What statement describes an attack vector?
data loss through access to personal or corporate instant messaging and social media sites
the path by which a threat actor can gain access to a server, host, or network
intercepted emails that reveal confidential corporate or personal information
the unauthorized transfer of data containing valuable corporate information to a USB drive
8. What is the purpose of mobile device management (MDM) software?
It is used to create a security policy.
It is used to implement security policies, setting, and software configurations on mobile devices.
It is used to identify potential mobile device vulnerabilities.
It is used by threat actors to penetrate the system.
10. Which type of firewall makes use of a proxy server to connect to remote servers on behalf of clients?
stateless firewall
stateful firewall
application gateway firewall
packet filtering firewall
9. Which security implementation will provide management plane protection for a network device?
antispoofing
routing protocol authentication
role-based access control
access control lists
14. What is provided by the fail open and close functionality of Snort IPS?
provides the ability to automatically disable problematic signatures that routinely cause false positives and pass traffic
blocks the traffic flow or bypasses IPS checking in the event of an IPS engine failure
keeps Snort current with the latest threat protection and term-based subscriptions
keeps track of the health of the Snort engine that is running in the service container
10. A security service company is conducting an audit in several risk areas within a major corporation. What statement describes the risk of access to cloud storage devices?
intercepted emails that reveal confidential corporate or personal information
gaining illegal access to corporate data by stealing passwords or cracking weak passwords
sensitive data lost through access to the cloud that has been compromised due to weak security settings
the retrieval of confidential or personal information from a lost or stolen device that was not configured to use encryption software
11. Which security measure is best used to limit the success of a reconnaissance attack from within a campus area network?
Implement restrictions on the use of ICMP echo-reply messages.
Implement a firewall at the edge of the network.
Implement access lists on the border router.
Implement encryption for sensitive traffic.
16. What is a characteristic of the connectivity policy setting when configuring Snort threat protection?
it attempts to balance network security with network performance
it prioritizes security over connectivity
it provides the lowest level orf protection
it enables the highest number of signatures to be verified
14. Which attack involves threat actors positioning themselves between a source and destination with the intent of transparently monitoring, capturing, and controlling the communication?
man-in-the-middle attack
SYN flood attack
DoS attack
ICMP attack
15. What is the motivation of a white hat attacker?
fine tuning network devices to improve their performance and efficiency
taking advantage of any vulnerability for illegal personal gain
studying operating systems of various platforms to develop a new system
discovering weaknesses of networks and systems to improve the security level of these systems
18. What is a network tap?
a Cisco technology that provides statistics on packets flowing through a router or multilayer switch
a feature supported on Cisco switches that enables the switch to copy frames and forward them to an analysis device
a passive device that forwards all traffic and physical layer errors to an analysis device
a technology used to provide real-time reporting and long-term analysis of security events
1. Why are traditional network security perimeters not suitable for the latest consumer-based network endpoint devices?
These devices are not managed by the corporate IT department.
These devices pose no risk to security as they are not directly connected to the corporate network.
These devices connect to the corporate network through public wireless networks.
These devices are more varied in type and are portable.
19. Which statement describes the function of the SPAN tool used in a Cisco switch?
It is a secure channel for a switch to send logging to a syslog server.
It provides interconnection between VLANs over multiple switches.
It supports the SNMP trap operation on a switch.
It copies the traffic from one switch port and sends it to another switch port that is connected to a monitoring device.
21. What is an advantage of HIPS that is not provided by IDS?
HIPS provides quick analysis of events through detailed logging.
HIPS protects critical system resources and monitors operating system processes.
HIPS monitors network processes and protects critical files.
HIPS deploys sensors at network entry points and protects critical network segments.
20. A network administrator is trying to download a valid file from an internal server. However, the process triggers an alert on a NMS tool. What condition describes this alert?
false negative
false positive
t
true positive
22. What information must an IPS track in order to detect attacks matching a composite signature?
the total number of packets in the attack
the state of packets related to the attack
the attacking period used by the attacker
the network bandwidth consumed by all packets
17. Which security feature or device would more likely be used within a CAN than a SOHO or data center?
security trap
ESA/WSA
virtual security gateway
wireless router
20. Which condition describes the potential threat created by Instant On in a data center?
when the primary firewall in the data center crashes
when an attacker hijacks a VM hypervisor and then launches attacks against other devices in the data center
when the primary IPS appliance is malfunctioning
when a VM that may have outdated security policies is brought online after a long period of inactivity.
21. What functional area of the Cisco Network Foundation Protection framework is responsible for device-generated packets required for network operation, such as ARP message exchanges and routing advertisements?
data plane
control plane
management plane
forwarding plane
22. A security service company is conducting an audit in several risk areas within a major corporation. What statement describes the risk of using social networking?
sensitive data lost through access to the cloud that has been compromised due to weak security settings
gaining illegal access to corporate data by stealing passwords or cracking weak passwords
data loss through access to personal or corporate instant messaging and social media sites
the retrieval of confidential or personal information from a lost or stolen device that was not configured to use encryption software
23. A security service company is conducting an audit in several risk areas within a major corporation. What statement describes the risk of access to removable media?
the potential of causing great damage because of direct access to the building and its infrastructure devices
intercepted emails that reveal confidential corporate or personal information
the unauthorized transfer of data containing valuable corporate information to a USB drive
data loss through access to personal or corporate instant messaging and social media sites
24. What is the purpose of a reconnaissance attack on a computer network?
to gather information about the target network and system
to redirect data traffic so that it can be monitored
to prevent users from accessing network resources
to steal data from the network servers
25. A security service company is conducting an audit in several risk areas within a major corporation. What statement describes an internal threat?
data loss through access to personal or corporate instant messaging and social media sites
the unauthorized transfer of data containing valuable corporate information to a USB drive
the potential of causing great damage because of direct access to the building and its infrastructure devices
gaining illegal access to corporate data by stealing passwords or cracking weak passwords
1. Which privilege level is predefined for the privileged EXEC mode?
level 1
level 0
level 15
level 16
2. What is a requirement to use the Secure Copy Protocol feature?
At least one user with privilege level 1 has to be configured for local authentication.
A command must be issued to enable the SCP server side functionality.
A transfer can only originate from SCP clients that are routers.
The Telnet protocol has to be configured on the SCP server side.
4. Which syslog message type is accessible only to an administrator and only via the Cisco CLI?
errors
alerts
debugging
Emergency
6. An administrator needs to create a user account with custom access to most privileged EXEC commands. Which privilege command is used to create this custom account?
privilege exec level 15
privilege exec level 0
privilege exec level 1
privilege exec level 2
26. A network administrator is configuring DAI on a switch with the command ip arp inspection validate dst-mac . What is the purpose of this configuration command?
to check the destination MAC address in the Ethernet header against the MAC address table
to check the destination MAC address in the Ethernet header against the user-configured ARP ACLs
to check the destination MAC address in the Ethernet header against the target MAC address in the ARP body
to check the destination MAC address in the Ethernet header against the source MAC address in the ARP body
10. What is the one major difference between local AAA authentication and using the login local command when configuring device access authentication?
The login local command requires the administrator to manually configure the usernames and passwords, but local AAA authentication does not.
Local AAA authentication allows more than one user account to be configured, but login local does not.
Local AAA authentication provides a way to configure backup methods of authentication, but login local does not.
The login local command uses local usernames and passwords stored on the router, but local AAA authentication does not.
11. Which two UDP port numbers may be used for server-based AAA RADIUS authentication? (Choose two.)
1812
1645
1813
49
12. Which command will move the show access-lists command to privilege level 14?
router(config)# privilege level 14 command show access-lists
router(config)# privilege exec level 14 show access-lists
router(config)# set privilege level 14 show access-lists
router(config)# show access-lists privilege level 14
13. Which authentication method stores usernames and passwords in the router and is ideal for small networks?
server-based AAA over TACACS+
local AAA over RADIUS
local AAA over TACACS+
local AAA
27. What is the primary function of the aaa authorization command?
limit authenticated user access to AAA client services
permit AAA server access to AAA client services
permit authenticated user access to AAA client services
limit AAA server access to AAA client services
18. What IOS privilege levels are available to assign for custom user-level privileges?
levels 1 through 15
levels 0, 1, and 15
levels 2 through 14
levels 0 and 1
20. What is the biggest issue with local implementation of AAA?
Local implementation cannot provide secure authentication. Local implementation does not scale well.
Local implementation cannot provide secure authentication.
Local implementation supports only RADIUS servers.
Local implementation supports only TACACS+ servers.
11. How does a firewall handle traffic when it is originating from the public network and traveling to the private network?
Traffic that is originating from the public network is usually blocked when traveling to the private network.
Traffic that is originating from the public network is usually permitted with little or no restrictions when traveling to the private network.
Traffic that is originating from the public network is not inspected when traveling to the private network.
Traffic that is originating from the public network is selectively permitted when traveling to the private network.
21. What is the result in the self zone if a router is the source or destination of traffic?
No traffic is permitted
All traffic is permitted
Only traffic that originates in the router is permitted
only traffic that is destined for the router is permitted
1. When creating an ACL, which keyword should be used to document and interpret the purpose of the ACL statement on a Cisco device?
remark
established
eq
description
5. In the creation of an IPv6 ACL, what is the purpose of the implicit final command entries, permit icmp any any nd-na and permit icmp any any nd-ns?
to allow IPv6 to MAC address resolution
to allow forwarding of ICMPv6 packets
to allow automatic address configuration
to allow forwarding of IPv6 multicast packets
26. Which AAA component can be established using token cards?
accounting
authentication
auditing
authorization
21. Which task is necessary to encrypt the transfer of data between the ACS server and the AAA-enabled router?
Use identical reserved ports on the server and the router.
Create a VPN tunnel between the server and the router.
Configure the key exactly the same way on the server and the router.
Specify the single-connection keyword.
13. Designing a ZPF requires several steps. Which step involves dictating the number of devices between most-secure and least-secure zones and determining redundant devices?
design the physical infrastructure
establish policies between zones
identify subsets within zones and merge traffic requirements
23. A student is learning role-based CLI access and CLI view configurations. The student opens Packet Tracer and adds a router. Which command should be used first for creating a CLI view named TECH-View?
Router# enable view
Router(config)# aaa new-model
Router# enable view TECH-view
Router(config)# parser view TECH-view
16. What is the first step in configuring a Cisco IOS zone-based policy firewall via the CLI?
Define traffic classes.
Assign router interfaces to zones
Define firewall policies
Cr
25. Because of implemented security controls, a user can only access a server with FTP. Which AAA component accomplishes this?
authorization
authorization
accounting
authentication
15. When using Cisco IOS zone-based policy firewall, where is the inspection policy applied?
to a zone
to a global service policy
to an interface
to a zone pair
17. What is one benefit of using a stateful firewall instead of a proxy server?
ability to perform user authentication
better performance
ability to perform packet filtering
prevention of Layer 7 attacks
30. To facilitate the troubleshooting process, which inbound ICMP message should be permitted on an outside interface?
echo request
echo reply
time-stamp request
u
18. Which statement describes a typical security policy for a DMZ firewall configuration?
Traffic that originates from the DMZ interface is selectively permitted to the outside interface.
Return traffic from the inside that is associated with traffic originating from the outside is permitted to traverse from the inside interface to the outside interface.
Return traffic from the outside that is associated with traffic originating from the inside is permitted to traverse from the outside interface to the DMZ interface.
Traffic that originates from the outside interface is permitted to traverse the firewall to the inside interface with few or no restrictions.
19. What is one limitation of a stateful firewall?
weak user authentication
cannot filter unnecessary traffic
not as effective with UDP or ICMP based traffic
poor log information
20. Which statement describes Cisco IOS Zone-Based Policy Firewall operation?
The pass action works in only one direction.
Router management interfaces must be manually assigned to the self zone.
A router interface can belong to multiple zones.
Service policies are applied in interface configuration mode.
21. What type of data does the DLP feature of Cisco Email Security Appliance scan in order to prevent customer data from being leaked outside of the company?
inbound messages
outbound messages
messages stored on a client device
messages stored on the email server
22. What is the goal of the Cisco NAC framework and the Cisco NAC appliance?
to ensure that only hosts that are authenticated and have had their security posture examined and approved are permitted onto the network
to monitor data from the company to the ISP in order to build a real-time database of current spam threats from both internal and external sources
to provide anti-malware scanning at the network perimeter for both authenticated and non-authenticated devices
to provide protection against a wide variety of web-based threats, including adware, phishing attacks, Trojan horses, and worms
23. Which Cisco solution helps prevent MAC and IP address spoofing attacks?
Port Security DHCP Snooping
DHCP Snooping
IP Source Guard
Dynamic ARP Inspection
24. What Layer 2 attack is mitigated by disabling Dynamic Trunking Protocol?
VLAN hopping
DHCP spoofing
ARP poisoning
ARP spoofing
34. When implementing a ZPF, what is the default security setting when forwarding traffic between two interfaces in the same zone?
Traffic between interfaces in the same zone is selectively forwarded based on Layer 3 information.
Traffic between interfaces in the same zone is not subject to any policy and passes freely.
Traffic between interfaces in the same zone is blocked.
Traffic between interfaces in the same zone is selectively forwarded based on the default policy restrictions.
7. What is a minimum system requirement to activate Snort IPS functionality on a Cisco router?
at least 4 GB flash
at least 4 GB RAM
ISR 2900 or higher
K9 license
8. What is PulledPork?
an open source network IPS that performs real-time traffic analysis and generates alerts when threats are detected on IP networks
a centralized management tool to push the rule sets based on preconfigured policy, to Cisco routers
a virtual service container that runs on the Cisco ISR router operating system
a rule management application that can be used to automatically download Snort rule updates
11. What situation will generate a true negative IPS alarm type?
a verified security incident that is detected
a known attack that is not detected
normal traffic that is correctly being ignored and forwarded
normal traffic that generates a false alarm
20. What technology has a function of using trusted third-party protocols to issue credentials that are accepted as an authoritative identity?
digital signatures
hashing algorithms
PKI certificates
symmetric keys
4. In an 802.1x deployment, which device is a supplicant?
RADIUS server
access point
switch
end-user station
5. A company implements 802.1X security on the corporate network. A PC is attached to the network but has not authenticated yet. Which 802.1X state is associated with this PC?
err-disabled
disabled
unauthroized
forwarding
7. Which command is used as part of the 802.1X configuration to designate the authentication method that will be used?
dot1x system-auth-control
aaa authentication dot1x
a
d
8. What is involved in an IP address spoofing attack?
A rogue node replies to an ARP request with its own MAC address indicated for the target IP address.
Bogus DHCPDISCOVER messages are sent to consume all the available IP addresses on a DHCP server.
A rogue DHCP server provides false IP configuration parameters to legitimate DHCP clients.
A legitimate network IP address is hijacked by a rogue node.
9. At which layer of the OSI model does Spanning Tree Protocol operate?
Layer 1
Layer 2
L
L
10. A network administrator uses the spanning-tree loopguard default global configuration command to enable Loop Guard on switches. What components in a LAN are protected with Loop Guard?
All Root Guard enabled ports.
All PortFast enabled ports.
All point-to-point links between switches.
All BPDU Guard enabled ports.
17. What is the behavior of a switch as a result of a successful CAM table attack?
The switch will drop all received frames.
The switch interfaces will transition to the error-disabled state.
The switch will forward all received frames to all other ports.
The switch will shut down.
19. What device is considered a supplicant during the 802.1X authentication process?
the router that is serving as the default gateway
the authentication server that is performing client authentication
the client that is requesting authentication
the switch that is controlling network access
21. Which requirement of secure communications is ensured by the implementation of MD5 or SHA hash generating algorithms?
nonrepudiation
authentication
integrity
confidentiality
11. Which procedure is recommended to mitigate the chances of ARP spoofing?
Enable DHCP snooping on selected VLANs.
Enable IP Source Guard on trusted ports.
Enable DAI on the management VLAN.
Enable port security globally.
20. Which term describes the role of a Cisco switch in the 802.1X port-based access control?
agent
supplicant
authenticator
authentication server
13. Which protocol should be used to mitigate the vulnerability of using Telnet to remotely manage network devices?
SNMP
TFTP
SSH
SCP
14. How can DHCP spoofing attacks be mitigated?
by disabling DTP negotiations on nontrunking ports
by the application of the ip verify source command to untrusted ports
by implementing DHCP snooping on trusted ports
by implementing port security
16. Two devices that are connected to the same switch need to be totally isolated from one another. Which Cisco switch security feature will provide this isolation?
PVLAN Edge
DTP
SPAN
BPDU guard
18. Which protocol defines port-based authentication to restrict unauthorized hosts from connecting to the LAN through publicly accessible switch ports?
RADIUS
TACACS+
SSH
802.1x
25. What is the result of a DHCP starvation attack?
The IP addresses assigned to legitimate clients are hijacked.
Legitimate clients are unable to lease IP addresses.
The attacker provides incorrect DNS and default gateway information to clients.
Clients receive IP address assignments from a rogue DHCP server.
to check the destination MAC address in the Ethernet header against the source MAC address in the ARP body
RSA
AES
MD5
PKI
2. What is the keyspace of an encryption algorithm?
the set of procedures used to calculate asymmetric keys
the mathematical equation that is used to create a key
the set of hash functions used to generate a key
the set of all possible values used to generate a key
3. Alice and Bob are using a digital signature to sign a document. What key should Alice use to sign the document so that Bob can make sure that the document came from Alice?
private key from Bob
private key from Alice
public key from Bob
username and password from Alice
7. What popular encryption algorithm requires that both the sender and receiver know a pre-shared key?
PKI
MD5
AES
HMAC
8. In which method used in cryptanalysis does the attacker know a portion of the plaintext and the corresponding ciphertext?
meet-in-the-middle
Ciphertext
brute-force
chosen-plaintext
10. What technology supports asymmetric key encryption used in IPsec VPNs?
3DES
IKE
SEAL
AES
11. What are two symmetric encryption algorithms? (Choose two.)
3DES
HMAC
AES
SHA
12. Which two items are used in asymmetric encryption? (Choose two.)
a token
a private key
a DES key
a public key
13. What are two properties of a cryptographic hash function? (Choose two.)
Complex inputs will produce complex hashes.
Hash functions can be duplicated for authentication purposes.
The hash function is one way and irreversible.
The input for a particular hash algorithm has to have a fixed size.
The output is a fixed length.
14. Which statement describes asymmetric encryption algorithms?
They have key lengths ranging from 80 to 256 bits.
They include DES, 3DES, and AES.
They are also called shared-secret key algorithms.
They are relatively slow because they are based on difficult computational algorithms.
15. An IT enterprise is recommending the use of PKI applications to securely exchange information between the employees. In which two cases might an organization use PKI applications to securely exchange information between users? (Choose two.)
HTTPS web service
802.1x authentication
local NTP server
FTP transfers
16. Two users must authenticate each other using digital certificates and a CA. Which option describes the CA authentication procedure?
The users must obtain the certificate of the CA and then their own certificate.
The CA is always required, even after user verification is complete.
CA certificates are retrieved out-of-band using the PSTN, and the authentication is done in-band over a network.
After user verification is complete, the CA is no longer required, even if one of the involved certificates expires.
17. The following message was encrypted using a Caesar cipher with a key of 2:
fghgpf vjg ecuvng
What is the plaintext message?
invade the castle
defend the castle
defend the region
invade the region
18. In a hierarchical CA topology, where can a subordinate CA obtain a certificate for itself?
from the root CA or another subordinate CA at a higher level
from the root CA or another subordinate CA at the same level
from the root CA or from self-generation
from the root CA or another subordinate CA anywhere in the tree
19. What is the purpose for using digital signatures for code signing?
to establish an encrypted connection to exchange confidential data with a vendor website
to verify the integrity of executable files downloaded from a vendor website
to authenticate the identity of the system with a vendor website
to generate a virtual ID
22. What is an example of the one-time pad cipher?
RC4
rail fence
Caesar
Vigenère
23. A company is developing a security policy for secure communication. In the exchange of critical messages between a headquarters office and a branch office, a hash value should only be recalculated with a predetermined code, thus ensuring the validity of data source. Which aspect of secure communications is addressed?
data integrity
non-repudiation
data confidentiality
origin authentication
24. What is the purpose of a digital certificate?
It guarantees that a website has not been hacked.
It provides proof that data has a traditional signature attached.
It ensures that the person who is gaining access to a network device is authorized.
It authenticates a website and establishes a secure connection to exchange confidential data.
2. What technology is used to negotiate security associations and calculate shared keys for an IPsec VPN tunnel?
PSK
SHA
3DES
IKE
4. What takes place during IKE Phase 2 when establishing an IPsec VPN?
Traffic is exchanged between IPsec peers.
IPsec security associations are exchanged.
ISAKMP security associations are exchanged.
Interesting traffic is identified.
8. When the CLI is used to configure an ISR for a site-to-site VPN connection, what is the purpose of the crypto map command in interface configuration mode?
to configure the transform set
to bind the interface to the ISAKMP policy
to force IKE Phase 1 negotiations to begin
to negotiate the SA policy
9. Which statement describes the effect of key length in deterring an attacker from hacking through an encryption key?
The length of a key does not affect the degree of security.
The shorter the key, the harder it is to break.
The length of a key will not vary between encryption algorithms.
The longer the key, the more key possibilities exist.
10. Which two statements describe a remote access VPN? (Choose two.)
It may require VPN client software on hosts.
It requires hosts to send TCP/IP traffic through a VPN gateway
It connects entire networks to each other.
It is used to connect individual hosts securely to a company network over the Internet.
11. Which protocol creates a virtual point-to-point connection to tunnel unencrypted traffic between Cisco routers from a variety of protocols?
IKE
IPsec
OSPF
GRE
12. How is “tunneling” accomplished in a VPN?
New headers from one or more VPN protocols encapsulate the original packets.
All packets between two hosts are assigned to a single physical medium to ensure that the packets are kept private. Packets are disguised to look like other types of traffic so that they will be ignored by potential attackers.
Packets are disguised to look like other types of traffic so that they will be ignored by potential attackers.
A dedicated circuit is established between the source and destination devices for the duration of the connection.
15. Which is a requirement of a site-to-site VPN?
It requires hosts to use VPN client software to encapsulate traffic.
It requires the placement of a VPN server at the edge of the company network.
It requires a VPN gateway at each end of the tunnel to encrypt and decrypt traffic.
It requires a client/server architecture.
16. Consider the following configuration on a Cisco ASA:
crypto ipsec transform-set ESP-DES-SHA esp-des esp-sha-hmac
What is the purpose of this command?
to define only the allowed encryption algorithms
to define what traffic is allowed through and protected by the tunnel
to define the encryption and integrity algorithms that are used to build the IPsec tunnel
to define the ISAKMP parameters that are used to establish the tunnel
17. What is needed to define interesting traffic in the creation of an IPsec tunnel?
security associations
hashing algorithm
access list
transform set
18. What is a function of the GRE protocol?
to configure the set of encryption and hashing algorithms that will be used to transform the data sent through the IPsec tunnel
to encapsulate multiple OSI Layer 3 protocol packet types inside an IP tunnel
to configure the IPsec tunnel lifetime
to provide encryption through the IPsec tunnel
20. Two corporations have just completed a merger. The network engineer has been asked to connect the two corporate networks without the expense of leased lines. Which solution would be the most cost effective method of providing a proper and secure connection between the two corporate networks?
Cisco AnyConnect Secure Mobility Client with SSL
Cisco Secure Mobility Clientless SSL VPN
remote access VPN using IPsec
site-to-site VPN
22. What type of traffic is supported by IPsec?
IPsec supports all IPv4 traffic.
IPsec supports layer 2 multicast traffic.
IPsec only supports unicast traffic.
IPsec supports all traffic permitted through an ACL.
1. A network analyst wants to monitor the activity of all new interns. Which type of security testing would track when the interns sign on and sign off the network?
vulnerability scanning
password cracking
network scanning
integrity checker
3. What testing tool is available for network administrators who need a GUI version of Nmap?
SuperScan
Zenmap
Nessus
SIEM
4. What is the goal of network penetration testing?
determining the feasibility and the potential consequences of a successful attack
detecting potential weaknesses in systems
detecting configuration changes on network systems
detecting weak passwords
5. How does network scanning help assess operations security?
It can detect open TCP ports on network systems.
It can detect weak or blank passwords.
It can simulate attacks from malicious sources.
It can log abnormal activity.
10. What can be configured as part of a network object?
interface type
IP address and masK
upper layer protocol
source and destination MAC address
11. What is the function of a policy map configuration when an ASA firewall is being configured?
binding a service policy to an interface
binding class maps with actions
identifying interesting traffic
using ACLs to match traffic
12. What is the purpose of configuring an IP address on an ASA device in transparent mode?
management
routing
NAT
VPN connectivity
13. Which license provides up to 50 IPsec VPN users on an ASA 5506-X device?
the most commonly pre-installed Base license
a purchased Security Plus upgrade license
a purchased Base license
a purchased AnyConnect Premium license
14. What mechanism is used by an ASA device to allow inspected outbound traffic to return to the originating sender who is on an inside network?
access control lists
Network Address Translation
security zones
stateful packet inspection
15. When configuring interfaces on an ASA, which two pieces of information must be included? (Choose two.)
group association
service level
security level
name
access list
17. What interface configuration command is used on an ASA to request an IP address from an upstream DSL device?
ip address ip-address netmask
ip address dhcp setroute
dhcpd address IP_address1 [ -IP_address2 ] if_name ip address pppoe
ip address pppoe
19. What is the purpose of the Tripwire network testing tool?
to perform vulnerability scanning
to provide information about vulnerabilities and aid in penetration testing and IDS signature development
to assess configuration against established policies, recommended best practices, and compliance standards
to detect unauthorized wired network access
20. A network analyst is testing the security of the systems and networks of a corporation. What tool could be used to audit and recover passwords?
L0phtCrack
SuperScan
Nessus
Metasploit
