100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4.2 TrustPilot
logo-home
Exam (elaborations)

CCNA Security Ch 9 Exam Questions And Answers | Verified A+ Pass Brand New!!

Rating
-
Sold
-
Pages
6
Grade
A+
Uploaded on
03-07-2025
Written in
2024/2025

CCNA Security Ch 9 Exam Questions And Answers | Verified A+ Pass Brand New!! ASA - Answer- Helps provide high performance connectivity and protection for critical assets. ASA integrates: Firewall technology. IPS. High performance VPNs with always on remote access. Failover. NGFW - Answer- Next generation firewalls. Deliver threat defence across the entire attack continuum. ASA Models - Answer- SOHO; 5505,5506,5512,5515. Medium business; 5525,5555. Data center; 5585. ASA models - Answer- All models provide stateful firewall features, the difference between models is the traffic throughput which can be handled. ASA firewall features. - Answer- ASA virtualisation. High availability with failover. Identity firewall. ASA virtualisation - Answer- Can be partitioned into multiple virtual devices. Each virtual device known as security context. Each context is an independent device, it has its own security policy, interfaces and administrator. High availability with failover. - Answer- Identical ASAs can be paired into an active failover cofiguration for device redundancy. Identity firewall - Answer- Provides granular access control based on an association of IP addresses to active directory. Threat control and containment services - Answer- Supports IPS features. Advanced IPS can only be used by integrating special hardware modules with the asa architecture. Use advanced inspection and prevention modules. Antimalware capabilities integrated using the content security and control. Outside network - Answer- Network or zone that is outside the protection of the firewall. ASA treats a defined outside network as Untrusted. Inside network - Answer- Network or zone that is protected and behind the firewall. Firewalls protect inside networks from unauthorised access. Also protect users from each other. Can keep users separate from one another. ASA treats inside interfaces as a trusted network. DMZ - Answer- Demilitarized zone allows both inside and outside users access to protected network resources. Interfaces - Answer- Interfaces have security levels. These enables ASA to implement Security policies. Resources that may be needed by outside users such as a web or FTP server. can be located in a DMZ. Firewalls alllow limited access to the DMZ while protecting the inside network. Firewall modes - Answer- Two types of firewall modes: Routed Mode, Transport mode. Routed mode - Answer- Two or more interfaces on separate networks. Routed mode supports multiple interfaces. Each interface is on a different subnet and requires an IP address on that subnet. ASA considered a router Hop Transport mode - Answer- ASA not considered as a router hop. ASA assigned an IP on local network for management. Simplifies network configuration.No support for dynamic routing protocols, VPNs, QoS or DHCP. License - Answer- Specifies the options that are enabled on an ASA. Upgrading licences supports higher connection capacity. Security Levels - Answer- Used to distinguish between inside and outside networks. Security levels define trustworthiness of interface. The higher the level the more trusted the the interface. 0 = Untrustworthy. 100 = Very trustworthy. Lavel 100 - Answer- Assigned to most secure network, the inside interface. Level 0 - Answer- Assigned to an outside interface. Level 0 - 100 - Answer- Assigned to a network DMZ. Security level rules - Answer- Traffic moving from an interface with high security level to a interface with a lower security level is outbound traffic. Traffic moving from an interface with lower security level to an interface with a higher security level is considered inbound traffic. Network access - Answer- Implicit permit from a high security level to a low security level. Hosts on high security level can access hosts on a low security interface. Can have multiple interfaces with the same level. If communication enabled for interfaces with the same security level, Implicit permit for traffic between the interfaces. Inspection engines - Answer- Application inspection engines are dependant on security levels. Interfaces with the same level as the ASA inspects traffic in either direction.

Show more Read less
Institution
CCNA Security Ch 9
Course
CCNA Security Ch 9









Whoops! We can’t load your doc right now. Try again or contact support.

Written for

Institution
CCNA Security Ch 9
Course
CCNA Security Ch 9

Document information

Uploaded on
July 3, 2025
Number of pages
6
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

Content preview

CCNA Security Ch 9 Exam Questions
And Answers | Verified A+ Pass Brand
New!!
ASA - Answer- Helps provide high performance connectivity and protection for critical
assets. ASA integrates:
Firewall technology. IPS. High performance VPNs with always on remote access.
Failover.

NGFW - Answer- Next generation firewalls. Deliver threat defence across the entire
attack continuum.

ASA Models - Answer- SOHO; 5505,5506,5512,5515.
Medium business; 5525,5555.
Data center; 5585.

ASA models - Answer- All models provide stateful firewall features, the difference
between models is the traffic throughput which can be handled.

ASA firewall features. - Answer- ASA virtualisation. High availability with failover.
Identity firewall.

ASA virtualisation - Answer- Can be partitioned into multiple virtual devices. Each virtual
device known as security context. Each context is an independent device, it has its own
security policy, interfaces and administrator.

High availability with failover. - Answer- Identical ASAs can be paired into an active
failover cofiguration for device redundancy.

Identity firewall - Answer- Provides granular access control based on an association of
IP addresses to active directory.

Threat control and containment services - Answer- Supports IPS features. Advanced
IPS can only be used by integrating special hardware modules with the asa
architecture. Use advanced inspection and prevention modules. Antimalware
capabilities integrated using the content security and control.

Outside network - Answer- Network or zone that is outside the protection of the firewall.
ASA treats a defined outside network as Untrusted.

Inside network - Answer- Network or zone that is protected and behind the firewall.
Firewalls protect inside networks from unauthorised access. Also protect users from

, each other. Can keep users separate from one another. ASA treats inside interfaces as
a trusted network.

DMZ - Answer- Demilitarized zone allows both inside and outside users access to
protected network resources.

Interfaces - Answer- Interfaces have security levels. These enables ASA to implement
Security policies. Resources that may be needed by outside users such as a web or
FTP server. can be located in a DMZ. Firewalls alllow limited access to the DMZ while
protecting the inside network.

Firewall modes - Answer- Two types of firewall modes: Routed Mode, Transport mode.

Routed mode - Answer- Two or more interfaces on separate networks. Routed mode
supports multiple interfaces. Each interface is on a different subnet and requires an IP
address on that subnet. ASA considered a router Hop

Transport mode - Answer- ASA not considered as a router hop. ASA assigned an IP on
local network for management. Simplifies network configuration.No support for dynamic
routing protocols, VPNs, QoS or DHCP.

License - Answer- Specifies the options that are enabled on an ASA. Upgrading
licences supports higher connection capacity.

Security Levels - Answer- Used to distinguish between inside and outside networks.
Security levels define trustworthiness of interface. The higher the level the more trusted
the the interface. 0 = Untrustworthy. 100 = Very trustworthy.

Lavel 100 - Answer- Assigned to most secure network, the inside interface.

Level 0 - Answer- Assigned to an outside interface.

Level 0 - 100 - Answer- Assigned to a network DMZ.

Security level rules - Answer- Traffic moving from an interface with high security level to
a interface with a lower security level is outbound traffic. Traffic moving from an
interface with lower security level to an interface with a higher security level is
considered inbound traffic.

Network access - Answer- Implicit permit from a high security level to a low security
level. Hosts on high security level can access hosts on a low security interface. Can
have multiple interfaces with the same level. If communication enabled for interfaces
with the same security level, Implicit permit for traffic between the interfaces.

Inspection engines - Answer- Application inspection engines are dependant on security
levels. Interfaces with the same level as the ASA inspects traffic in either direction.

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Stuviaascorers University of Washington
Follow You need to be logged in order to follow users or courses
Sold
339
Member since
2 year
Number of followers
185
Documents
9998
Last sold
6 days ago
StuviaAscorers | Top Study Notes & Exam Solutions

Stuviaascorers – Your #1 Source for Top-Quality Study Materials! Struggling with exams? Stuviaascorers has got you covered! I provide expertly crafted study notes, summaries, past papers, and exam-ready answers to help you pass with flying colors. My materials are designed for clarity, accuracy, and success—so you can study smarter, not harder! Why Choose My Study Materials? Well-structured & easy to understand – No fluff, just what you need! Exam-focused & high-scoring content – Get straight to the point! Accurate answers & clear explanations – Learn with confidence! Save time & boost your grades – Study efficiently! Don’t leave your success to chance! Browse my documents and start acing your exams today!

Read more Read less
3,8

61 reviews

5
29
4
11
3
10
2
1
1
10

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their exams and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can immediately select a different document that better matches what you need.

Pay how you prefer, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card or EFT and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Frequently asked questions