Cisco Security Solutions for Systems Engineers Sample Questions:
1. You work as a network operator for an IT company. You have just detected a distributed DoS attack which appears to have sources from many hosts in network X/24. You must take preventive action to block all offending traffic, so you announce a BGP route, with the next-hop attribute of 172.31.1.1, for the X/24 network of the attacker. Which two methods will be adopted by the routers at the regional office, branch office, and telecommuter location to prevent traffic going to and from the attacker? (Choose two.)
A) a dynamic ACL entry to block any traffic that is sourced from the X/24 network
B) strict uRPF
C) a prefix list to block routing updates about the X/24 network
D) a static route to 172.31.1.1/32, which points to a null interface
2. Deploying the NAC appliance in in-band mode is better than out-of-band mode. Why?
A) NAC Appliance Agent deployment
B) Higher number of users per NAC Appliance
C) Bandwidth enforcement policy
D) Nessus scanning
3. In multi-tier applications and multi-tier firewall designs, which additional security control can be used to force an attacker to compromise the exposed server before the attacker attempts to penetrate the more protected domains?
A) Implement host IPS on the exposed servers in the DMZs.
B) Implement in-band network admission control at the first tier.
C) Make exposed servers in the DMZs dual homed.
D) At each tier, implement a transparent proxy component within the firewall system.
4. Which two components should be included in a detailed design documents for a security solution? (Choose two.)
A) Data Source
B) Organizational Chart
C) Existing Network Infrastructure
D) Weak-link description
E) Proof of concept
F) Traffic growth forecast
5. Which Cisco ASA configuration is needed to perform active/active failover?
A) Redundant interfaces
B) Virtual contexts
C) VLANs
D) Policy-based routing
Solutions:
| Question # 1 Answer: B,D | Question # 2 Answer: C | Question # 3 Answer: C | Question # 4 Answer: C,E | Question # 5 Answer: B |
We're so confident of our products that we provide no hassle product exchange.


By Parker

