DCOM 211 Final Exam Guide questions and answers 2024
A system execution space (customer context) does not have any Layer 2 or Layer 3 interfaces or any network settings. - True An admin context is created after the System Execution Space and all (customer contexts) have been created - False Any interface not defined as an admin context is a customer context - True Stealth firewalls do not provide a way to filter packets that traverse from one host to another on the same LAN segment - False Traditional firewalls require a new network segment to be created when they are inserted into a network - True The alias command is not supported in transparent firewall mode. - True Reverse Routing Injection (RRI) is supported when a Cisco ASA is configured as a transparent firewall mode - False Network Address Translation Traversal (NAT-T) & Public Key Infrastructure (PKI) are partially supported in transparent mode for the management tunnel - False In a scenario where all security contexts in the Cisco ASA use unique physical or logical subinterfaces, the packet classification becomes more difficult because the security appliance labels the packets based upon the source interface - False In a scenario where an interface is shared between multiple security contexts, then the interface may be assigned the same mac address across all virtual firewalls - True _____ ____ _____ _____ is when the security appliance acts as a secured bridge that switches traffic from one interface to another. - Single-Mode Transparent Firewalls _____ _____ _____ does not support the sharing of interfaces between multiple contexts - Multimode Transparent Firewalls _____ _____ can optionally inspect layer 2 traffic & filter unwanted traffic - Transparent Firewalls _____ _____ segregate protected networks from unprotected ones by acting as an extra hop in the network design - Routed Firewalls _____ _____ acts & behaves as an independent entity with its own configuration - Virtual Firewalls Remote management for Admin Context is conducted through: - Port 22 or port 23 The Bridge Group Virtual Interface (BVI) Bridge group feature) - Up to four physical interfaces or subinterfaces can be assigned to this bridge group. Three important settings configured for each context in the system execution space include: - - Context Name - Location of context's startup configuration (Configlet) - Interface allocation Cisco ASA is set up in transparent mode: - - Only one site-to-site IPsec tunnel can be configured. - The IPsec tunnel could be terminated on either the internal or external interface - An IPsec tunnel for traversing traffic can be established
Document information
- Uploaded on
- June 16, 2024
- Number of pages
- 14
- Written in
- 2023/2024
- Type
- Exam (elaborations)
- Contains
- Questions & answers