1.1 Flashcards
- Which security implementation will provide control plane protection for a network device?
encryption for remote access connections
AAA for authenticating management access
routing protocol authentication
NTP for consistent timestamps on logging messages
routing protocol authentication
- What is the one major difference between local AAA authentication and using the login local command when configuring device access authentication?
Local AAA authentication provides a way to configure backup methods of authentication, but login local does not.
The login local command requires the administrator to manually configure the usernames and passwords, but local AAA authentication does not.
Local AAA authentication allows more than one user account to be configured, but login local does not.
The login local command uses local usernames and passwords stored on the router, but local AAA authentication does not.
Local AAA authentication provides a way to configure backup methods of authentication, but login local does not.
- Refer to the exhibit. A network administrator configures AAA authentication on R1. The administrator then tests the configuration by telneting to R1. The ACS servers are configured and running. What will happen if the authentication fails?
The enable secret password could be used in the next login attempt.
The authentication process stops.
The username and password of the local user database could be used in the next login attempt.
The enable secret password and a random username could be used in the next login attempt.
The authentication process stops. [adef]
- What are two tasks that can be accomplished with the Nmap and Zenmap network tools? (Choose two.)
password recovery
password auditing
identification of Layer 3 protocol support on hosts
TCP and UDP port scanning
validation of IT system configuration
identification of Layer 3 protocol support on hosts
TCP and UDP port scanning
5. Which Cisco IOS subcommand is used to compile an IPS signature into memory? retired true event-action produce-alert retired false event-action deny-attacker-inline
retired false
6. Why are DES keys considered weak keys? They are more resource intensive. DES weak keys use very long key sizes. They produce identical subkeys. DES weak keys are difficult to manage.
They produce identical subkeys.
- What is a benefit of using a next-generation firewall rather than a stateful firewall?
reactive protection against Internet attacks
granularity control within applications
support of TCP-based packet filtering
support for logging
granularity control within applications
- What is a result of securing the Cisco IOS image using the Cisco IOS Resilient Configuration feature?
When the router boots up, the Cisco IOS image is loaded from a secured FTP location.
The Cisco IOS image file is not visible in the output of the show flash command.
The Cisco IOS image is encrypted and then automatically backed up to the NVRAM.
The Cisco IOS image is encrypted and then automatically backed up to a TFTP server.
The Cisco IOS image file is not visible in the output of the show flash command.
9. The corporate security policy dictates that the traffic from the remote-access VPN clients must be separated between trusted traffic that is destined for the corporate subnets and untrusted traffic destined for the public Internet. Which VPN solution should be implemented to ensure compliance with the corporate policy? MPLS hairpinning GRE split tunneling
split tunneling
- Which two conditions must be met in order for a network administrator to be able to remotely manage multiple ASAs with Cisco ASDM? (Choose two.)
The ASAs must all be running the same ASDM version.
Each ASA must have the same enable secret password.
Each ASA must have the same master passphrase enabled.
The ASAs must be connected to each other through at least one inside interface.
ASDM must be run as a local application
The ASAs must all be running the same ASDM version.
ASDM must be run as a local application.
11. What is negotiated in the establishment of an IPsec tunnel between two IPsec hosts during IKE Phase 1? ISAKMP SA policy DH groups interesting traffic transform sets
ISAKMP SA policy
- What are two benefits of using a ZPF rather than a Classic Firewall? (Choose two.)
ZPF allows interfaces to be placed into zones for IP inspection.
The ZPF is not dependent on ACLs.
Multiple inspection actions are used with ZPF.
ZPF policies are easy to read and troubleshoot.
With ZPF, the router will allow packets unless they are explicitly blocked.
The ZPF is not dependent on ACLs.
ZPF policies are easy to read and troubleshoot.
- Which security policy characteristic defines the purpose of standards?
step-by-step details regarding methods to deploy company switches
recommended best practices for placement of all company switches
required steps to ensure consistent configuration of all company switches
list of suggestions regarding how to quickly configure all company switches
required steps to ensure consistent configuration of all company switches
14. What algorithm is used to provide data integrity of a message through the use of a calculated hash value? RSA DH AES HMAC
HMAC
- On which port should Dynamic ARP Inspection (DAI) be configured on a switch?
an uplink port to another switch
on any port where DHCP snooping is disabled
any untrusted port
access ports only
an uplink port to another switch