CertCities.com -- The Ultimate Site for Certified IT Professionals
Listen, See, Win! Register for a Free Tech Library Webcast Share share | bookmark | e-mail
  Microsoft®
  Cisco®
  Security
  Oracle®
  A+/Network+"
  Linux/Unix
  More Certs
  Newsletters
  Salary Surveys
  Forums
  News
  Exam Reviews
  Tips
  Columns
  Features
  PopQuiz
  RSS Feeds
  Press Releases
  Contributors
  About Us
  Search
 

Advanced Search
  Free Newsletter
  Sign-up for the #1 Weekly IT
Certification News
and Advice.
Subscribe to CertCities.com Free Weekly E-mail Newsletter
CertCities.com

See What's New on
Redmondmag.com!

Cover Story: IE8: Behind the 8 Ball

Tech-Ed: Let's (Third) Party!

A Secure Leap into the Cloud

Windows Mobile's New Moves

SQL Speed Secrets


CertCities.com
Let us know what you
think! E-mail us at:



 
 
...Home ... Editorial ... Pop Quiz ..Pop Quiz Article Friday: April 4, 2014


Cisco Exam # 642-551 SND Exam (Cisco Press)
Test your knowledge of securing Cisco network devices for the CCSP or Cisco VPN and Security Specialist certs with these 10 sample questions.


courtesy of   Cisco Press

Question:
Questions

1. What is the main technology that comprises Identity Based Networking Services (IBNS)?

··? read answer

2. Describe CSA's reliance on signatures.

··? read answer

3. After an ACL is created, what is the next step to place it into production?

··? read answer

4. What is Cisco's recommendation for securing trunks?

··? read answer

5. Which AAA protocol encrypts the client to server password but not the AAA payload?

··? read answer

6. What type of an attack involves an intruder attempting to discover and map systems, services, and vulnerabilities?

··? read answer

7. What system layers are protected by CSA’s defense-in-depth approach?

··? read answer

8. On what layer of the OSI model do packet filtering firewalls operate?

··? read answer

9. Which IPSec mode of operation does not require the host to perform any encryption?

··? read answer

10. What services does IPSec provide?

··? read answer

Answers

1. IBNS technology operates at Layer 2 on both wired and wireless networks by utilizing 802.1x/EAP, the IEEE standard for port-level strong user authentication.


2. CSA does not rely on signatures and does not inspect content but rather analyzes system behavior for abnormal activity.


3. Apply it to an interface with the "ip access-group" interface configuration command or the "access-class" line configuration command.


4. Only allow the VLANs that must traverse the trunk should be configured on the trunk. Prune all other VLANs from the trunk. Assign dedicated VLAN numbers as the native VLAN number.


5. RADIUS


6. Reconnaissance attacks.


7. The system layers are:

  • Network
  • File system
  • Configuration
  • Execution space

8. Packet filtering firewalls operate on the network or transport layer (OSI model layers 3 and 4).


9. Tunnel mode is typically implemented between two VPN devices that perform encryption and decryption tasks, eliminating the need for the host to perform such operations.


10. The services IPSec provides are:

  • Data confidentiality - Packets are encrypted before transmission across network.
  • Data integrity - IPSec receiver authenticates IPSec peers and packets sent by the IPSec sender to ensure that the data has not been altered during transmission.
  • Data origin authentication - IPSec receiver authenticates the source of the IPSec packets sent. This service depends on the data integrity service.
  • Anti-replay - IPSec receiver can detect and reject replayed packets, helping prevent spoofing and man-in-the-middle attacks.

Questions and answers provided by Cisco Press. To order the full version of this exam simulation, click here.


More Pop Quiz:


There are 69 CertCities.com user Comments for “Cisco Exam # 642-551 SND Exam (Cisco Press)”
Page 1 of 7
8/31/06: DEEPAK KUMAR SINGH from HYDERABAD says: i want to learn thats course securing Cisco network devices for the CCSP or Cisco VPN and Security Specialist cert. what is the eligibility for that cousre and exam fees.
9/22/12: ÃÀ¹úvpn from [email protected] says: ÐèÒªÒ»¸öVPNÕʺŻòÕßÊÇSSHÕʺÅ=¡£=£¬ÅóÓѽéÉÜÁËÒ»¸öhttp://www.35vpn.com/£¬Ã²ËÆ»¹²»´í http://www.35vpn.com/
7/1/13: michael kors outlet online from [email protected] says: ths michael kors outlet online http://www.michaelkorsioutlet.org/
7/1/13: louisvuittonttoutlet.com from [email protected] says: nice articles louisvuittonttoutlet.com http://www.louisvuittonttoutlet.com
7/5/13: gucci outlet store from [email protected] says: nice articles gucci outlet store http://www.guccioutletstore-online.com
7/5/13: christianlouboutinoutleta.com from [email protected] says: ths christianlouboutinoutleta.com http://www.christianlouboutinoutleta.com
7/23/13: Fake Oakley Glasses from [email protected] says: sunglass enjoys free turbocharge... via a civic action ensemble!! Fake Oakley Glasses http://www.fakeoakleysglasses.com
7/23/13: Toms Outlet from [email protected] says: Remember Each time You Could simply get a brand new shoes for free, And You Still did not?? Toms Outlet http://www.tomsoutlets-usa.com
7/23/13: ReplicaOakleySunglas from [email protected] says: The way in which sunglass sneak up on you Replica Oakley Sunglasses http://www.replica-oakleysunglassesusa.com
7/25/13: Gucci Leder Handtaschen from [email protected] says: good articles Gucci Leder Handtaschen http://www.gucci-online.de/
First Page   Next Page   Last Page
Your comment about: “Cisco Exam # 642-551 SND Exam (Cisco Press)”
Name: (optional)
Location: (optional)
E-mail Address: (optional)
Comment:
   

-- advertisement (story continued below) --

top