Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 2 out of 9 pages
Exam (elaborations)

DCOM 211 FINAL EXAM GUIDE

Document preview thumbnail
Preview 2 out of 9 pages

A system execution space (customer context) does not have any Layer 2 or Layer 3 interfaces or any network settings. - ANSWER True An admin context is created after the System Execution Space and all (customer contexts) have been created - ANSWER False Any interface not defined as an admin context is a customer context - ANSWER True Stealth firewalls do not provide a way to filter packets that traverse from one host to another on the same LAN segment - ANSWER False Traditional firewalls require a new network segment to be created when they are inserted into a network - ANSWER True

Content preview

A system execution space (customer context) does not have any Layer 2 or Layer 3
interfaces or any network settings. - ANSWER True

An admin context is created after the System Execution Space and all (customer
contexts) have been created - ANSWER False

Any interface not defined as an admin context is a customer context - ANSWER
True

Stealth firewalls do not provide a way to filter packets that traverse from one host to
another on the same LAN segment - ANSWER False

Traditional firewalls require a new network segment to be created when they are
inserted into a network - ANSWER True

The alias command is not supported in transparent firewall mode. - ANSWER True

Reverse Routing Injection (RRI) is supported when a Cisco ASA is configured as a
transparent firewall mode - ANSWER False

Network Address Translation Traversal (NAT-T) & Public Key Infrastructure (PKI)
are partially supported in transparent mode for the management tunnel - ANSWER
False

In a scenario where all security contexts in the Cisco ASA use unique physical or
logical subinterfaces, the packet classification becomes more difficult because the
security appliance labels the packets based upon the source interface - ANSWER
False

In a scenario where an interface is shared between multiple security contexts, then
the interface may be assigned the same mac address across all virtual firewalls -
ANSWER True

_____ ____ _____ _____ is when the security appliance acts as a secured bridge
that switches traffic from one interface to another. - ANSWER Single-Mode
Transparent Firewalls

_____ _____ _____ does not support the sharing of interfaces between multiple
contexts - ANSWER Multimode Transparent Firewalls

_____ _____ can optionally inspect layer 2 traffic & filter unwanted traffic -
ANSWER Transparent Firewalls

_____ _____ segregate protected networks from unprotected ones by acting as an
extra hop in the network design - ANSWER Routed Firewalls

_____ _____ acts & behaves as an independent entity with its own configuration -
ANSWER Virtual Firewalls

, Remote management for Admin Context is conducted through: - ANSWER Port 22
or port 23

The Bridge Group Virtual Interface (BVI) Bridge group feature) - ANSWER Up to
four physical interfaces or subinterfaces can be assigned to this bridge group.

Three important settings configured for each context in the system execution space
include: - ANSWER - Context Name
- Location of context's startup configuration (Configlet)
- Interface allocation

Cisco ASA is set up in transparent mode: - ANSWER - Only one site-to-site IPsec
tunnel can be configured.
- The IPsec tunnel could be terminated on either the internal or external interface
- An IPsec tunnel for traversing traffic can be established

Transparent firewalls & NAT - ANSWER - Static routes established on the
upstream router are used to translate IP addresses if the network node resides on a
different subnet/network as the global IP address
- Address Resolution Protocol (ARP) requests are used to translate if the network
node resides on the same subnet/network as the global IP address
- Address Resolution Protocol (ARP) inspection is not used when the source's IP
address is translated on the same side of the firewall prior to contacting the node on
the other side of the firewall.

no shutdown command is used to disable & enable a redundant interfaces, even
though the system enables a redundant interface by default at the time of creation. -
ANSWER False

The two interfaces used in a redundant pair are not required to be identical. -
ANSWER False

Management0/0 & Management0/1 interfaces are supported for use as dedicated
physical management interfaces. - ANSWER False

Cisco ASA security appliances that contain a built-in switch are supported as
support dedicated redundant interface capable. - ANSWER False

Software IPS modules require a logical management network connection -
ANSWER False

Internal zone contains all of the downstream network nodes to be protected. -
ANSWER True

Illegal zone contains the IP addresses that Cisco ASA IPS should never see in
transit traffic - ANSWER True

External zone contains all IP addresses that do not belong to the internal or illegal
zonex - ANSWER True

Document information

Uploaded on
September 3, 2024
Number of pages
9
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$11.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Sold
4
Followers
0
Items
289
Last sold
1 year ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions