CCNA Security V2 Final Exam (Part 1)
Which two practices are associated with securing the features and performance of router operating systems? (Choose two.) - Install a UPS. - Keep a secure copy of router operating system images. - Configure the router with the maximum amount of memory possible. - Disable default router services that are not necessary. Reduce the number of ports that can be used to access the router.
- Keep a secure copy of router operating system images. - Configure the router with the maximum amount of memory possible.
Which two conditions must be met in order for a network administrator to be able to remotely manage multiple ASAs with Cisco ASDM? (Choose two.) - The ASAs must all be running the same ASDM version. - Each ASA must have the same enable secret password. - Each ASA must have the same master passphrase enabled. - The ASAs must be connected to each other through at least one inside interface. - ASDM must be run as a local application.
- The ASAs must all be running the same ASDM version. - ASDM must be run as a local application.
What are two benefits of using a ZPF rather than a Classic Firewall? (Choose two.) - ZPF allows interfaces to be placed into zones for IP inspection. - The ZPF is not dependent on ACLs. - Multiple inspection actions are used with ZPF. - ZPF policies are easy to read and troubleshoot. - With ZPF, the router will allow packets unless they are explicitly blocked.
- The ZPF is not dependent on ACLs. - ZPF policies are easy to read and troubleshoot.
What are two tasks that can be accomplished with the Nmap and Zenmap network tools? (Choose two.) - password recovery - password auditing - identification of Layer 3 protocol support on hosts - TCP and UDP port scanning - validation of IT system configuration
- identification of Layer 3 protocol support on hosts - TCP and UDP port scanning
What is a feature of a Cisco IOS Zone-Based Policy Firewall? - A router interface can belong to only one zone at a time. - Service policies are applied in interface configuration mode. - Router management interfaces must be manually assigned to the self zone. - The pass action works in multiple directions.
A router interface can belong to only one zone at a time.
What algorithm is used to provide data integrity of a message through the use of a calculated hash value? - RSA - DH - AES - HMAC
HMAC
What is negotiated in the establishment of an IPsec tunnel between two IPsec hosts during IKE Phase 1? - ISAKMP SA policy - DH groups - interesting traffic - transform sets
ISAKMP SA policy
Which statement describes a characteristic of the IKE protocol? - It uses UDP port 500 to exchange IKE information between the security gateways. - IKE Phase 1 can be implemented in three different modes: main, aggressive, or quick. - It allows for the transmission of keys directly across a network. - The purpose of IKE Phase 2 is to negotiate a security association between two IKE peers.
It uses UDP port 500 to exchange IKE information between the security gateways.
What is the one major difference between local AAA authentication and using the login local command when configuring device access authentication? - Local AAA authentication provides a way to configure backup methods of authentication, but login local does not. - The login local command requires the administrator to manually configure the usernames and passwords, but local AAA authentication does not. - Local AAA authentication allows more than one user account to be configured, but login local does not. - The login local command uses local usernames and passwords stored on the router, but local AAA authentication does not.
Local AAA authentication provides a way to configure backup methods of authentication, but login local does not.
http://ccnav6.com/wp-content/uploads/2016/02/Q18-1.jpg Refer to the exhibit. The ip verify source command is applied on untrusted interfaces. Which type of attack is mitigated by using this configuration? - DHCP spoofing - DHCP starvation - STP manipulation - MAC and IP address spoofing
MAC and IP address spoofing
What is an advantage in using a packet filtering firewall versus a high-end firewall appliance? - Packet filters perform almost all the tasks of a high-end firewall at a fraction of the cost. - Packet filters provide an initial degree of security at the data-link and network layer. - Packet filters represent a complete firewall solution. - Packet filters are not susceptible to IP spoofing.
Packet filters perform almost all the tasks of a high-end firewall at a fraction of the cost.
Which security implementation will provide control plane protection for a network device? - Encryption for remote access connection - AAA for authenticating management access - Routing protocol authentication - NTP for consistent timestamps on logging messages
Routing protocol authentication
What is a result of securing the Cisco IOS image using the Cisco IOS Resilient Configuration feature? - When the router boots up, the Cisco IOS image is loaded from a secured FTP location. - The Cisco IOS image file is not visible in the output of the show flash command. - The Cisco IOS image is encrypted and then automatically backed up to the NVRAM. - The Cisco IOS image is encrypted and then automatically backed up to a TFTP server.
The Cisco IOS image file is not visible in the output of the show flash command.
http://ccnav6.com/wp-content/uploads/2016/02/Q3.jpg Refer to the exhibit. A network administrator configures AAA authentication on R1. The administrator then tests the configuration by telneting to R1. The ACS servers are configured and running. What will happen if the authentication fails? - The enable secret password could be used in the next login attempt. - The authentication process stops. - The username and password of the local user database could be used in the next login attempt. - The enable secret password and a random username could be used in the next login attempt.
The authentication process stops.
http://ccnav6.com/wp-content/uploads/2016/02/Q19-1.jpg - The crypto map has not yet been applied to an interface. - The current peer IP address should be 172.30.2.1. - There is a mismatch between the transform sets. - The tunnel configuration was established and can be tested with extended pings.
The crypto map has not yet been applied to an interface.
http://ccnav6.com/wp-content/uploads/2016/02/Q17-1.jpg Refer to the exhibit. The administrator can ping the S0/0/1 interface of RouterB but is unable to gain Telnet access to the router by using the password cisco123. What is a possible cause of the problem? - The Telnet connection between RouterA and RouterB is not working correctly. - The password cisco123 is wrong. - The administrator does not have enough rights on the PC that is being used. - The enable password and the Telnet password need to be the same.
The password cisco123 is wrong.
Why are DES keys considered weak keys? - They are more resource intensive. - DES weak keys use very long key sizes. - They produce identical subkeys. - DES weak keys are difficult to manage.
They produce identical subkeys.
http://ccnav6.com/wp-content/uploads/2016/02/Q22.jpg Refer to the exhibit. In the network that is shown, which AAA command logs the use of EXEC session commands? - aaa accounting network start-stop group tacacs+ - aaa accounting network start-stop group radius - aaa accounting connection start-stop group radius - aaa accounting exec start-stop group radius - aaa accounting connection start-stop group tacacs+ - aaa accounting exec start-stop group tacacs+
aaa accounting exec start-stop group radius
A network administrator enters the single-connection command. What effect does this command have on AAA operation? - allows a new TCP session to be established for every authorization request - authorizes connections based on a list of IP addresses configured in an ACL on a Cisco ACS server - allows a Cisco ACS server to minimize delay by establishing persistent TCP connections - allows the device to establish only a single connection with the AAA-enabled server
allows a Cisco ACS server to minimize delay by establishing persistent TCP connections
On which port should Dynamic ARP Inspection (DAI) be configured on a switch? - an uplink port to another switch - on any port where DHCP snooping is disabled - any untrusted port - access ports only
an uplink port to another switch
What is a benefit of using a next-generation firewall rather than a stateful firewall? - reactive protection against Internet attacks - granularity control within applications - support of TCP-based packet filtering - support for logging
granularity control within applications
Which security policy characteristic defines the purpose of standards? - step-by-step details regarding methods to deploy company switches - recommended best practices for placement of all company switches - required steps to ensure consistent configuration of all company switches - list of suggestions regarding how to quickly configure all company switches
required steps to ensure consistent configuration of all company switches
Which Cisco IOS subcommand is used to compile an IPS signature into memory? - retired true - event-action produce-alert - retired false - event-action deny-attacker-inline
retired false
The corporate security policy dictates that the traffic from the remote-access VPN clients must be separated between trusted traffic that is destined for the corporate subnets and untrusted traffic destined for the public Internet. Which VPN solution should be implemented to ensure compliance with the corporate policy? - MPLS - hairpinning - GRE - split tunneling
split tunneling
What type of algorithms require sender and receiver to exchange a secret key that is used to ensure the confidentiality of messages? - symmetric algorithms - hashing algorithms - asymmetric algorithms - public key algorithms
symmetric algorithms