DCOM 211 Final Exam Guide questions with answers 2024 actual exam 100%
DCOM 211 Final Exam Guide questions with answers 2024 actual exam 100% _____ ____ _____ _____ is when the security appliance acts as a secured bridge that switches traffic from one interface to another. - ANSWERS Single-Mode Transparent Firewalls _____ _____ _____ _____ is a protocol developed by Cisco that provides secure issuance of certificates to users & network nodes in a scalable environmnet - ANSWERS Simple Certificate Enrollment Protocol _____ _____ _____ can be accessed by any entity trying to check the validity of any given certificate - ANSWERS Local Certificate Authority _____ _____ _____ does not support the sharing of interfaces between multiple contexts - ANSWERS Multimode Transparent Firewalls _____ _____ _____ enables the generation of pause frames toward the adjacent switch when interface subscription is detected. - ANSWERS flowcontrol send on _____ _____ _____ matches a policy on the VPN client that has a priority between 1 & 65535 - ANSWERS Phase 1 Policy _____ _____ acts & behaves as an independent entity with its own configuration - ANSWERS Virtual Firewalls _____ _____ are defined as a device or entity that can issue a certificate to a user or network - ANSWERS Certificate Authority _____ _____ can optionally inspect layer 2 traffic & filter unwanted traffic - ANSWERS Transparent Firewalls _____ _____ connection profile is used to terminate all types of remote-access VPN tunnels - ANSWERS Remote Access _____ _____ connections use analog signals - ANSWERS base band _____ _____ connections use digital signals - ANSWERS broad band _____ _____ connections usually do not require much bandwidth, however management access should be maintained at all times. - ANSWERS Management Interfaces _____ _____ establishes a secure channel for both VPN peers to use for communication - ANSWERS Phase 1 _____ _____ has a priority of 65535 - ANSWERS crypto map _____ _____ makes use of profiles that describe the services & resources each authorized user or group normally accesses - ANSWERS anomaly detection _____ _____ segregate protected networks from unprotected ones by acting as an extra hop in the network design - ANSWERS Routed Firewalls _____ _____ triggers alarms based on characteristic code syntax of external attacks - ANSWERS signature detection _____ _____ uses Diffie-Hellman groups 1, 2, & 5 for PFS to generate keys - ANSWERS Phase 2 _____ _____ utilizes algorithms to identify certain types of attacks to detect suspicious traffic - ANSWERS heuristic detection _____ are commonly used to authenticate & validate users & devices while simultaneously securing information exchanged over unsecured networks - ANSWERS Certificates _____ has a preconfigured VPN policy priority of 1 & 5 - ANSWERS ASDM _____ is an American Standard Code for Information Interchange (ASCII) comment of upto 200 characters - ANSWERS description 2 components required to establish a VPN connection would include the VPN concentrator & VPN client - ANSWERS True A Certficate Authority (CA) identification value must correspond to the ultimate root certificate from which it was originated - ANSWERS True A system execution space (customer context) does not have any Layer 2 or Layer 3 interfaces or any network settings. - ANSWERS True Administrative privileges are required on local workstations for port forwarding to be enabled. - ANSWERS True An admin context is created after the System Execution Space and all (customer contexts) have been created - ANSWERS False Any interface not defined as an admin context is a customer context - ANSWERS True AnyConnect Essentials License is designed solely to support AnyConnect clients in full tunnel mode. - ANSWERS True AnyConnect Mobile License designed as an independent license similar to AnyConnect Premium & AnyConnect Essentials licenses - ANSWERS False AnyConnect Premium License does not support CSD, Host Scanning, and clientless SSL VPN tunnels. - ANSWERS False Attack Relevance Rating (AAR) is a metric associated with the relevancy of the targeted victim & is rated as relevant, unknwon, or not relevant. - ANSWERS True Attack Severity Rating (ASR) is a value related with the severity of a successful exploit - ANSWERS False Based upon Asymmetric public key encryption - ANSWERS - Private key is used to decrypt - Public key is used to encrypt Based upon Traffic Prioritization he lower the class the lower the importance the higher the likelihood it might be dropped in the times of high network traffic utilization. - ANSWERS True Certificate Information Contents include: - ANSWERS - Entity's public key - Issuer's information - CRL distribution list - Entity's identifier information - Validity period Cisco ASA is set up in transparent mode: - ANSWERS - Only one site-to-site IPsec tunnel can be configured. - The IPsec tunnel could be terminated on either the internal or external interface - An IPsec tunnel for traversing traffic can be established Cisco ASA security appliances that c
Escuela, estudio y materia
- Institución
- DCOM
- Grado
- DCOM
Información del documento
- Subido en
- 6 de junio de 2024
- Número de páginas
- 9
- Escrito en
- 2023/2024
- Tipo
- Examen
- Contiene
- Preguntas y respuestas
Temas
-
dcom 211 final exam guide questions with answer
-
dcom 211 final exam guide questions with answers