<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Cisco CCSP  Exams &#187; Practice Tests</title>
	<atom:link href="http://www.ccsp.name/tests/practice-tests/feed" rel="self" type="application/rss+xml" />
	<link>http://www.ccsp.name</link>
	<description>PassGuide materials:Successful for Cisco Certification or Full Refund for you</description>
	<lastBuildDate>Thu, 09 Sep 2010 08:32:18 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>actualtest 642-384 vce</title>
		<link>http://www.ccsp.name/actualtest-642-384-vce</link>
		<comments>http://www.ccsp.name/actualtest-642-384-vce#comments</comments>
		<pubDate>Thu, 09 Sep 2010 08:32:18 +0000</pubDate>
		<dc:creator>Cisco</dc:creator>
				<category><![CDATA[Practice Tests]]></category>

		<guid isPermaLink="false">http://www.ccsp.name/?p=168</guid>
		<description><![CDATA[Free 642-384 vce Dumps &#124; Download Cisco 642-384 vce pdf
26 Jun 2010 &#8230; VCE file extensions are files that run with the Visual CertExam 642-384 software. This 642-384 software allows users to design, &#8230;
www.examcollection.biz/642-384-vce.html &#8211; Cached
Download Free passguide 642-384 Dumps &#124; Latest Cisco 642-384 &#8230;
8 Aug 2010 &#8230; Free 642-384 vce Dumps &#124; Download Cisco [...]]]></description>
			<content:encoded><![CDATA[<p>Free 642-384 vce Dumps | Download Cisco 642-384 vce pdf<br />
26 Jun 2010 &#8230; VCE file extensions are files that run with the Visual CertExam 642-384 software. This 642-384 software allows users to design, &#8230;<span id="more-168"></span><br />
www.examcollection.biz/642-384-vce.html &#8211; Cached<br />
Download Free passguide 642-384 Dumps | Latest Cisco 642-384 &#8230;<br />
8 Aug 2010 &#8230; Free 642-384 vce Dumps | Download Cisco 642-384 vce pdf 26 Jun 2010 … Try PassGuide 642-384 demo and see for yourself! &#8230;</p>
<p><a href="http://www.actualtest.org/cisco/642-384">actualtest 642-384</a><br />
www.ciscoexams.org/passguide-642-384/ &#8211; Cached<br />
Download Free 642-384 Dumps | Latest Cisco 642-384 Certification Exams<br />
15 Apr 2010 &#8230; It obtained its leadership and trust of the users from the very beginning of its work on the 642-384 vce training materials market. &#8230;<br />
www.ciscoexams.org/642-384/ &#8211; Cached<br />
Free 642-384 dumps | Best Cisco 642-384 Practice Tests<br />
5 May 2010 &#8230; Examcollection 642-384 VCE examcollection uploads all 642-384 dumps, meanwhile you are able to find direct links,the files ere compressed in &#8230;<br />
www.sadikhov.us/642-384.html &#8211; Cached<br />
Free 642-374 dumps | Best Cisco 642-374 Practice Tests<br />
20 May 2010 &#8230; Request real 642-384(Rational Quality Manager v2.0) test braindumps?, you should choose the latest actualtests 642-384 vce format file,The &#8230;<br />
www.sadikhov.us/642-374-2.html &#8211; Cached<br />
Free Download Actualtest 642-384 Certification Exam<br />
29 May 2010 &#8230; Recommended Cisco Training about 642-384 PDF: The following courses are the recommended training for 642-384 vce exam. 642-384 Q &#038; A with &#8230;<br />
www.actualtest.org/cisco/642-384/ &#8211; Cached<br />
Download Cisco.CertifyMe.642-383.v2010-03-04.by.Taylor.77q.vce<br />
5 Mar 2010 &#8230; Do you have any exam or tesking for dump 642-384&#8230;.please ? &#8230; Files with VCE extension can be opened with Visual CertExam Suite. &#8230;<br />
www.examcollection.com/&#8230;/Cisco.CertifyMe.642-383.v2010-03-04.by.Taylor.77q.vce.file.html?&#8230; &#8211; Cached<br />
Free PassGuide Cisco 642-384 exam Braindumps | Download cisco &#8230;<br />
5 May 2010 &#8230; Actualtests 642-384 vce provides actual test questions and answers, which combines with the original tests, overing 96% of the real paper &#8230;<br />
www.braindumps.cc/cisco-642-384-exam.html &#8211; Cached<br />
Free Testinside 642-384 exam Download | Testinside Cisco 642-384 &#8230;<br />
cisco 642-384 testking free cisco 642-384 vce version cisco 642-384 paper cisco 642-384 testking review cisco 642-384 video training cisco 642-384 latest &#8230;<br />
www.testinside.biz/642-384-exam/ &#8211; Cached<br />
Free Download PassGuide 642-384 Practice Test Dumps | Latest &#8230;<br />
17 Jun 2010 &#8230; You will be 100% guaranteed to pass your exam with our unparalleled quality Cisco 642-384 VCE tests. passguide &#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ccsp.name/actualtest-642-384-vce/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>000-202 Exam</title>
		<link>http://www.ccsp.name/000-202-exam</link>
		<comments>http://www.ccsp.name/000-202-exam#comments</comments>
		<pubDate>Tue, 27 Apr 2010 05:54:14 +0000</pubDate>
		<dc:creator>Cisco</dc:creator>
				<category><![CDATA[Practice Tests]]></category>

		<guid isPermaLink="false">http://www.ccsp.name/?p=165</guid>
		<description><![CDATA[Itcerthome remains one of these most updated websites which is popular all over the world for its manifold characteristics. It keeps excellent information on IT Certifications and provides the current data. It has not only thorough information on every
certification but also provides you your required study material for your targeted certification.
The range of the contents [...]]]></description>
			<content:encoded><![CDATA[<p>Itcerthome remains one of these most updated websites which is popular all over the world for its manifold characteristics. It keeps excellent information on IT Certifications and provides the current data. It has not only thorough information on every<br />
certification but also provides you your required study material for your targeted certification.<br />
The range of the contents of IBM 000-202 exam tests the skills of the candidate in installing, operating, and solving problems related to troubleshoot in any network system.<br />
On account of the significant topics covered in IBM <strong><a href="http://www.passguide.com/000-202.html">000-202 exam</a></strong>, it is necessary on the part of the students to give thorough attention to the study contents of the<br />
certification exam. They should try their best to expand their knowledge on various complexities of the field, so that they should be capable in handling troubleshoot problems<br />
in practical situations.<br />
The IT professionals having certification in IBM 000-202 exam are given serious tasks in medium and large and medium-ranged companies. Any deficiency on their part may cause<br />
problems for their own career. Moreover, IBM 000-202 exam itself requires a thorough study of the IT field. You can achieve success in the exam only if you have fully prepared<br />
yourself for the evaluation.<br />
Itcerthome offers free demo for IBM 000-202 exam . You can check out the interface, question quality and usability of our practice exams before you decide to buy it. We are the only one site can offer demo for almost all products. </p>
<p>If you prepare for the 000-202 exam using our Itcerthome testing engine, we guarantee your success in the first attempt. If<br />
you do not pass the IBM 000-202 exam on your first attempt we will give you a FULL REFUND of your purchasing fee AND send you<br />
another same value product for free. </p>
<p>Here are some of the basic tips for you to pass this 000-202 exam.<br />
1. Online Study Materials<br />
There are a lot of online materials that are helpful in passing this 000-202 exam. Do a lot of questions to improve yourself and<br />
at the same time preparing for the exam. Make sure that you review all types of questions before sitting for the exam.<br />
2. Additional Study References<br />
You will not be guaranteed with a passing mark if you rely 100% on the theory part. You need to gain extra knowledge by doing<br />
practical work. There are some additional study documents that are useful for you to refer such as Itcerthome&#8217;s resoures.<br />
3. Ask the Expert<br />
You can always ask your senior IT experts if you face difficulties while doing your practical work. This will definitely<br />
accelerate your learning capability.<br />
After knowing all these steps, get yourself ready with the 000-202 exam. Remember to plan for your exam few months ahead. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.ccsp.name/000-202-exam/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Passguide 642-983 for Cisco certification exam are your ultimate source of success</title>
		<link>http://www.ccsp.name/passguide-642-983-for-cisco-certification-exam-are-your-ultimate-source-of-success</link>
		<comments>http://www.ccsp.name/passguide-642-983-for-cisco-certification-exam-are-your-ultimate-source-of-success#comments</comments>
		<pubDate>Fri, 16 Apr 2010 05:59:41 +0000</pubDate>
		<dc:creator>Cisco</dc:creator>
				<category><![CDATA[Practice Tests]]></category>
		<category><![CDATA[642-983]]></category>

		<guid isPermaLink="false">http://www.ccsp.name/?p=163</guid>
		<description><![CDATA[642-983 exam has increased in popularity in recent years. this exam ranks high. At Passguide, you will find the best training materials for 642-983 exam. We are continuously updating the 642-983, be sure to keep checking back for the updates.
Passguide 642-983 for Cisco certification exam are your ultimate source of success. You will find them [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.passguide.com/642-983.html"><strong>642-983 exam</strong></a> has increased in popularity in recent years. this exam ranks high. At Passguide, you will find the best training materials for 642-983 exam. We are continuously updating the 642-983, be sure to keep checking back for the updates.</p>
<p>Passguide <a href="http://www.passguide.com/642-983.html"><strong>642-983</strong></a> for Cisco certification exam are your ultimate source of success. You will find them rich in learning and knowledge, guaranteeing 100% success. The Passguide 642-983 cover all content of Cisco 642-983 exam,therefore, they are able to assure you success in your certification exam. These easily understood questions and answers in PDF make it simple for you to download and utilize. Great faith has been shown to Passguide 642-983 questions and answers by more and more successful candidates.</p>
<p>At Passguide we are committed to you ongoing success. Our exams and questions are constantly being updated and compared to industry standards.</p>
<p>Passguide &#8217;s Cisco 642-983 Study Guide provide comprehensive coverage of Cisco 642-983 Exam Objectives while keeping it all still simple enough for you to understand it easily. Our Cisco 642-983 Study Guide is prepared keeping in mind a beginner and don&#8217;t use complex wordings or terms. It is easy to pass your Cisco 642-983 Exam in your first attempt using our Cisco 642-983 Study Guide.</p>
<p>We update our Cisco 642-983 Study Guide as soon as the Exam Objectives change. Our Certified Experts and Professionals prepare this Cisco 642-983 Study Guide for you combining all the knowledge and keeping in view the latest Cisco 642-983 Exam Objectives. Your success is guaranteed in Cisco 642-983 Exam using our Study Guide because you always get the latest and most accurate Cisco 642-983 Study Guide for us. Try our Cisco 642-983 Study Guide today.</p>
<p>642-983 Practice Questions &#038; Answers and 642-983 Practice Testing Software at Passguide is comprehensive and updated regularly as well in line with the latest Cisco 642-983 Exam Objectives and gives you 100% success in 642-983 exam. It doesn’t cost you too much to buy Passguide 642-983 Exam while letting you pass your Cisco 642-983 Certification Exam on your first attempt.</p>
<p>With the help of Passguide, you can pass Cisco 642-983 exam easily!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ccsp.name/passguide-642-983-for-cisco-certification-exam-are-your-ultimate-source-of-success/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>passguide 642-515 demo</title>
		<link>http://www.ccsp.name/passguide-642-515-demo</link>
		<comments>http://www.ccsp.name/passguide-642-515-demo#comments</comments>
		<pubDate>Sat, 19 Dec 2009 13:45:04 +0000</pubDate>
		<dc:creator>Cisco</dc:creator>
				<category><![CDATA[Practice Tests]]></category>
		<category><![CDATA[642-515]]></category>
		<category><![CDATA[passguide]]></category>

		<guid isPermaLink="false">http://www.ccsp.name/?p=148</guid>
		<description><![CDATA[QUESTION: 22
Refer to the exhibit. You have been asked to verify the Cisco ASA security appliance interfaces that are used for a web connection from the Internet to a DMZ web server. Based on the Configuration > Device Setup > Interfaces pane that is shown, which two interfaces will a connection traverse when it is [...]]]></description>
			<content:encoded><![CDATA[<p>QUESTION: 22<br />
Refer to the exhibit. You have been asked to verify the Cisco ASA security appliance interfaces that are used for a web connection from the Internet to a DMZ web server. Based on the Configuration > Device Setup > Interfaces pane that is shown, which two interfaces will a connection traverse when it is coming from the Internet and connecting to the web server with the IP address 172.16.20.10? (Choose two.)<span id="more-148"></span></p>
<p>A. GigabitEthernet0/0<br />
B. GigabitEthernet0/1<br />
C. GigabitEthernet0/2.10<br />
D. GigabitEthernet0/2.20<br />
E. GigabitEthernet0/2.30<br />
F. Management0/0</p>
<p>Answer: A, D</p>
<p>QUESTION: 23<br />
Refer to the exhibit. Based on the Configuration > Device Setup > Interfaces pane that is shown, what is the model number of this Cisco ASA security appliance?<br />
***Exhibit Missing***</p>
<p>A. Cisco ASA 5505 Adaptive Security Appliance<br />
B. Cisco ASA 5510 Adaptive Security Appliance<br />
C. Cisco ASA 5520 Adaptive Security Appliance<br />
D. Cisco ASA 5540 Adaptive Security Appliance<br />
E. Cisco ASA 5550 Adaptive Security Appliance F. Cisco ASA 5580 Adaptive Security Appliance</p>
<p>Answer: A</p>
<p>QUESTION: 24<br />
Refer to the exhibit. You are reviewing the configuration of the clientssl SSL VPN connection profile, which was created by a junior administrator. In the clientssl profile, which authentication method is configured?</p>
<p>A. The Cisco ASA security appliance requires AAA authenticate to the external AAA server<br />
LOCAL if the remote user does not have an identity certificate for authentication.<br />
B. The Cisco ASA security appliance accepts an identity certificate or a username and password for authentication of remote users, but not both.<br />
C. The Cisco ASA security appliance requires a username and password if the remote user does not have an identity certificate for authentication.<br />
D. The Cisco ASA security appliance requires both an identity certificate and username and password for authentication of remote users.</p>
<p>Answer: D</p>
<p>QUESTION: 25<br />
You are the administrator of a Cisco ASA security appliance. Your management has asked you to configure the Cisco ASA security appliance, using Modular Policy Framework to block executables with the .exe file extension from being downloaded. Which regular expression must you create to match the .exe file extension?<br />
A. .*\.[Ee][Xx][Ee.<br />
B. .*.[Ee][Xx][Ee]<br />
C. .+\.[Ee][Xx][Ee]<br />
D. *.exe<br />
E. +.exe<br />
F. .+.[Ee][Xx][Ee]</p>
<p>Answer: C</p>
<p>QUESTION: 26<br />
Which of these commands causes the Cisco CSC-SSM to load a new software image from a remote TFTP server, via the CLI?</p>
<p>A. hw module 1 recover boot<br />
B. hw module 1 recover config<br />
C. hw module 1 recover reload<br />
D. copy tftp hardware:module1</p>
<p>Answer: A</p>
<p>QUESTION: 27<br />
Refer to the exhibit. The HTTP inspection map named MY_HTTP_MAP is applied to the outside interface of the security appliance. As a result of this configuration, which action does the security appliance take on HTTP traffic entering its outside interface? NOTE: The CLI version of this configuration is provided here.<br />
regex URL_ABC &#8220;.+abc\.com&#8221; regex URL_DEF &#8220;.+def\.com&#8221; regex URL_XYZ &#8220;.+xyz\.com&#8221;<br />
. . .<br />
class-map OUTSIDE_CLASS<br />
match any<br />
class-map type regex match-any URLs match regex URL_ABC<br />
match regex URL_XYZ<br />
class-map type inspect http match-all<br />
RESTRICTED_HTTP<br />
match request body length gt 1000 match not request uri regex class URLs<br />
. . .<br />
policy-map type inspect http MY_HTTP_MAP<br />
parameters<br />
protocol-violation action drop-connection class RESTRICTED_HTTP<br />
drop-connection<br />
policy-map OUTSIDE_POLICY class OUTSIDE_CLASS inspect http MY_HTTP_MAP<br />
. . .<br />
service-policy OUTSIDE_POLICY interface outside</p>
<p>A. Drops any HTTP packet that is destined for def.com and has a header length greater than<br />
1000 bytes<br />
B. Drops any HTTP packet destined for abc.com that has a header length greater than 1000 bytes<br />
C. Drops any HTTP request for xyz.com that has a body length greater than 1000 bytes<br />
D. Drops any HTTP request for def.com that has a body length greater than 1000 bytes<br />
E. Drops any HTTP packet that is destined for abc.com or has a body length greater than 1000 bytes<br />
F. Drops any HTTP request that is destined for xyz.com or has a header length greater than<br />
1000 bytes</p>
<p>Answer: D</p>
<p>QUESTION: 28<br />
Refer to the exhibit. You are the administrator of a Cisco ASA security appliance with a Cisco ASA CSC-SSM. You have upgraded the CSC-SSM with a new version of software. When the upgrade has finished, you issue the show module 1 detail command; the results of the command are shown in the exhibit. Why does the command output show that the status of the CSC-SSM is &#8220;Up&#8221; when it is not activated?</p>
<p>A. The software upgrade image has failed to load properly.<br />
B. The software upgrade image is not the correct software image for the CSC-SSM.<br />
C. The software upgrade image loaded successfully but the CSC-SSM has not had its license applied.<br />
D. The CSC-SSM cannot communicate with the network and therefore cannot apply its configuration to network traffic.<br />
E. The CSC-SSM is in the administrative down state and is waiting to be changed to the administrative up state.</p>
<p>Answer: C</p>
<p>QUESTION: 29<br />
Refer to the exhibit. You installed a digital certificate for a Cisco VPN Client on a laptop for a user. Which reason explains why the certificate is in an &#8220;invalid:not active&#8221; state?</p>
<p>A. The user has not attempted a VPN connection to the Cisco ASA security appliance.<br />
B. The time on the CA server and the time on the laptop are out of sync.<br />
C. The user has not clicked the Verify button within the Cisco VPN Client.<br />
D. The certificate passphrase must be sent to the CA for validation.<br />
E. The certificate number of &#8220;0&#8243; indicates that the certificate has expired.</p>
<p>Answer: B</p>
<p>QUESTION: 30<br />
Refer to the exhibit. You are the administrator of a new Cisco ASA security appliance with a Cisco ASA CSC-SSM. You are using the CSC Setup Wizard from within Cisco ASDM to configure the CSC-SSM for traffic selection. During the configuration of traffic selection, the CSC Setup Wizard asks If CSC card fails and provides two options. What will each of these options do if chosen? (Choose two.)</p>
<p>A. The Permit option allows traffic that is configured for CSC inspection to continue through the Cisco ASA security appliance, if the CSC card fails.<br />
B. The Close option allows traffic that is configured for CSC inspection to bypass the CSC if the CSC card fails.<br />
C. The Permit option allows the Cisco ASA security appliance to apply the CSC inspection configuration through the Cisco Modular Policy Framework, even if the CSC card fails.<br />
D. The Close option does not allow traffic that is configured for CSC inspection to continue when the CSC card fails.<br />
E. The Permit option allows traffic to continue to flow to the CSC for inspection, even when a hardware failure has been detected.<br />
F. The Close option does not allow any traffic that is traversing the Cisco ASA security appliance to continue when the CSC card fails.</p>
<p>Answer: A, D</p>
<p>QUESTION: 31<br />
Which three types of encapsulation does the Cisco ASA security appliance support for IPsec<br />
NAT transparency? (Choose three.)<br />
A. L2TP over IPsec<br />
B. IPsec over GRE<br />
C. IPsec over TCP<br />
D. IPsec over UDP<br />
E. IPsec over PPTP<br />
F. NAT-T</p>
<p>Answer: C, D, F</p>
<p>QUESTION: 32<br />
Refer to the exhibit. The HTTP inspection map named HTTP_POLICY is applied to the partnernet interface of the security appliance. Which of these actions does the security appliance take as a result of its configuration for HTTP traffic that enters its partnernet interface?</p>
<p>A. Drops and logs HTTP request messages for which the request method is put or the request header host field contains either the string example1.com or the string example2.com<br />
B. Drops and logs HTTP request messages for which the request method is put and the request header host field contains either the string example1.com or the string example2.com C. Drops and logs HTTP request messages for which the request method is put and the request header host field contains the strings example1.com and example2.com<br />
D. Drops and logs HTTP request messages for which the request method is put or the request header host field contains the strings example1.com and example2.com<br />
E. Drops HTTP request messages for which the request method is put, and logs HTTP request messages for which the request header host field contains either the string example1.com or the string example2.com<br />
F. Logs HTTP request messages for which the request method is put, and drops HTTP request messages for which the request header host field contains either the string example1.com or the string example2.com</p>
<p>Answer: B</p>
<p>QUESTION: 33<br />
A recent network upgrade at a branch office has changed the network topology of the branch, and the site-to-site VPN tunnel that runs between the branch and the corporate office has been reconfigured to perform Reverse Route Injection to accommodate the recent change. You are running OSPF between the corporate Cisco ASA security appliance and routers on the internal network. Assuming that the VPN configuration is correct, which step do you need to perform on the corporate Cisco ASA security appliance to ensure that these new routes are visible to internal routers that are running OSPF?<br />
A. Reverse Route Injection requires that you configure a new OSPF process that will add these routes to the Cisco ASA security appliance routing table.<br />
B. Reverse route injection requires that you add a static route for each branch-office network to the Cisco ASA security appliance routing table.<br />
C. Reverse Route Injection uses static routes, so you must configure OSPF to redistribute the static routes.<br />
D. Reverse Route Injection uses RIP, so you must add a RIP process and redistribute the learned RIP routes into OSPF.<br />
E. Reverse Route Injection uses EIGRP, so you must add an EIGRP process and redistribute the learned EIGRP routes into OSPF.</p>
<p>Answer: C</p>
<p>QUESTION: 34<br />
Using a valid identity certificate from her certificate authority, an administrator of a Cisco ASA security appliance has used the IPsec VPN Wizard to create the necessary configuration for remote-access VPN tunnels. When she tests the remote-access VPN, the VPN tunnel does not come up. Assuming that the remote-access VPN configuration created by the wizard is correct and that valid certificates are being used by the Cisco ASA security appliance and Cisco VPN Client, which corrective action must be configured or corrected for the VPN tunnel to come up properly?<br />
A. The IKE phase one configuration is not part of the IPsec VPN Wizard configuration and must be configured.<br />
B. The IKE phase two configuration is not part of the IPsec VPN Wizard configuration and must be configured.<br />
C. The crypto ACL configuration is not part of the IPsec VPN Wizard configuration and must be configured.<br />
D. The mapping of digital certificates to connection profile is not part of the IPsec VPN Wizard configuration and must be configured.<br />
E. NAT-Transparency configuration is not part of the IPsec VPN Wizard configuration and must be configured.</p>
<p>Answer: D</p>
<p>QUESTION: 35<br />
You are configuring a Cisco ASA 5520 Adaptive Security Appliance as a Easy VPN hardware client. But from within Cisco ASDM, you cannot find the Easy VPN Remote configuration option within the Remote Access VPN menu. Why would you not be able to find this configuration option within Cisco ASDM on the ASA 5520 Adaptive Security Appliance?<br />
A. The version of Cisco ASDM software loaded on the Cisco ASA security appliance does not support the Easy VPN feature.<br />
B. The version of Cisco ASDM software loaded on the Cisco ASA security appliance is corrupt.<br />
C. Only the Cisco ASA 5505 Adaptive Security Appliance can be a Easy VPN hardware client.<br />
D. The Easy VPN feature with the BIOS of the ASA 5520 Adaptive Security Appliance was not enabled.</p>
<p>Answer: C</p>
<p>QUESTION: 36<br />
Refer to the exhibit. You have been tasked to configure your Cisco ASA security appliance for port forwarding access to the internal e-mail server that is running POP3 (TCP port 110) and SMTP (TCP port 25). Which two configurations of the port forwarding list will allow remote users to access the internal email server through port forwarding? (Choose two.)</p>
<p>Answer: Pending </p>
<p>QUESTION: 37<br />
You have configured Cisco Secure Desktop on your Cisco ASA security appliance. You need to configure Cisco Secure Desktop to perform Host Scan checks on the remote endpoint. Which three available Basic Host Scan checks can you configure? (Choose three.)<br />
A. Registry<br />
B. User rights<br />
C. File<br />
D. Groups E. Process F. Shares</p>
<p>Answer: A, C, E</p>
<p>QUESTION: 38<br />
As the administrator of a Cisco ASA security appliance, you have been tasked to configure SSL VPNs to require digital certificates. Which four configuration options are available on the Cisco ASA security appliance for digital certificate management for SSL VPNs ? (Choose four.)<br />
A. The Cisco ASA security appliance can be configured to have a local CA that is subordinate to an external CA.<br />
B. The subordinate local CA on the Cisco ASA security appliance can issue certificates to users who require a certificate for their SSL VPN connections.<br />
C. The Cisco ASA security appliance can generate a self-signed certificate to be used as its identity certificate for SSL VPN connections.<br />
D. The Cisco ASA security appliance can be configured to retrieve its identity certificate from an external CA.<br />
E. The Cisco ASA security appliance can be configured as a standalone local CA.<br />
F. The local CA on the Cisco ASA security appliance can issue certificates to users who require certificates for SSL VPN connections.<br />
G. An external CA must be used for SSL VPN users who require certificates for their SSL VPN connections.<br />
H. The Cisco ASA security appliance must be configured to retrieve its identity certificate from an external CA.</p>
<p>Answer: C, D, E, F</p>
<p>QUESTION: 39<br />
Which two types of digital certificate enrollment processes are available for the Cisco ASA<br />
security appliance? (Choose two.)<br />
A. LDAP<br />
B. FTP<br />
C. HTTP<br />
D. SCEP<br />
E. Manual<br />
F. TFTP</p>
<p>Answer: D, E</p>
<p>QUESTION: 40<br />
With Cisco ASA Adaptive Security Appliance Software Version 7.x and later, which IPsec standard is not supported on the Cisco ASA security appliance?<br />
A. SHA-1<br />
B. DES C. MD5<br />
D. ESP E. AH F. AES</p>
<p>Answer: E</p>
<p>QUESTION: 41<br />
Refer to the exhibit. You have configured Telnet port forwarding to a specific server on the clientless SSL VPN portal. A clientless SSL VPN user has called to complain that after she starts the application helper, her attempts to establish a Telnet connection to 10.0.4.3 time out. Assuming that the clientless SSL VPN configuration is correct, which type of Telnet connection would you have the end user make?</p>
<p>A. To 10.0.4.3 on TCP port 2300<br />
B. To 10.0.4.3 on TCP port 23<br />
C. To 127.0.0.1 on TCP port 23<br />
D. To 127.0.0.1 on TCP port 2300</p>
<p>Answer: D</p>
<p>QUESTION: 42<br />
Refer to the exhibit. You are configuring a DAP for SSL VPN connections to your Cisco ASA security appliance. You add an Endpoint Attribute Type of &#8220;File&#8221; and select the Endpoint ID of &#8220;10,&#8221; based on the configuration that is shown. Within which area of the Cisco ASA security appliance configuration is this endpoint attribute defined?</p>
<p>A. DAP policy<br />
B. SSL VPN group policy<br />
C. SSL VPN connection profile<br />
D. user-specific policy<br />
E. Cisco Secure Desktop</p>
<p>Answer: E</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ccsp.name/passguide-642-515-demo/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>[offer] latest p4s 642-533 pdf Format</title>
		<link>http://www.ccsp.name/offer-latest-p4s-642-533-pdf-format</link>
		<comments>http://www.ccsp.name/offer-latest-p4s-642-533-pdf-format#comments</comments>
		<pubDate>Sat, 19 Dec 2009 13:28:38 +0000</pubDate>
		<dc:creator>Cisco</dc:creator>
				<category><![CDATA[Practice Tests]]></category>
		<category><![CDATA[642-533]]></category>

		<guid isPermaLink="false">http://www.ccsp.name/?p=142</guid>
		<description><![CDATA[ [offer] latest p4s 642-533 pdf Format
To download 642-533 in pdf format please follow below link
http://www.megaupload.com/?d=Q2PMSL92
Product Description Exam Number/Code: 642-533
Exam Number/Code: 642-533
Exam Name:Implementing Cisco Intrusion Prevention System (IPS)
&#8220;Implementing Cisco Intrusion Prevention System (IPS)&#8221;, also known as 642-533 exam, is a Cisco certification.With the complete collection of questions and answers, Pass4sure has assembled to take you [...]]]></description>
			<content:encoded><![CDATA[<p> [offer] latest p4s 642-533 pdf Format<br />
To download 642-533 in pdf format please follow below link</p>
<p>http://www.megaupload.com/?d=Q2PMSL92</p>
<p>Product Description Exam Number/Code: 642-533<br />
Exam Number/Code: 642-533<br />
Exam Name:Implementing Cisco Intrusion Prevention System (IPS)<br />
&#8220;Implementing Cisco Intrusion Prevention System (IPS)&#8221;, also known as <a href="http://www.ccsp.name/tag/642-533">642-533 exam</a>, is a Cisco certification.With the complete collection of questions and answers, Pass4sure has assembled to take you through 118 Q&#038;As to your 642-533 Exam preparation. In the 642-533 exam resources, you will cover every field and category in CCSP helping to ready you for your successful Cisco Certification.<br />
[OFFER] 642-533 latest P4S v 4.18 w/ 118q<br />
Hey Guys,</p>
<p>Here is the latest IPS 642-533 P4S that I know that many people were after, including me! Its the real deal with 118q because I had to go and buy it &#8211; I just ask for a bit of &#8216;quid pro quo&#8217; if possible guys, if anyone has the latest P4S SNRS 642-504 version could you please share it so I can keep my costs down!</p>
<p>I&#8217;ve put in powerpoint format and it looks fine on testing.</p>
<p>Enjoy and good luck!!</p>
<p>http://www.4shared.com/file/121273953/213ef41f/P4S-642533-v4-18.html</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ccsp.name/offer-latest-p4s-642-533-pdf-format/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>[Offer]SNAF 642-524 Study Material</title>
		<link>http://www.ccsp.name/offersnaf-642-524-study-material</link>
		<comments>http://www.ccsp.name/offersnaf-642-524-study-material#comments</comments>
		<pubDate>Sat, 19 Dec 2009 13:24:25 +0000</pubDate>
		<dc:creator>Cisco</dc:creator>
				<category><![CDATA[Practice Tests]]></category>

		<guid isPermaLink="false">http://www.ccsp.name/?p=140</guid>
		<description><![CDATA[SNAF Quick Refrence
Code:
http://rapidshare.com/files/187394780/SNAF.pdf
P4$ 642-524
Code:
http://rapidshare.com/files/187386181/4P_642-524.zip
]]></description>
			<content:encoded><![CDATA[<p>SNAF Quick Refrence<br />
Code:</p>
<p>http://rapidshare.com/files/187394780/SNAF.pdf</p>
<p>P4$ 642-524<br />
Code:</p>
<p>http://rapidshare.com/files/187386181/4P_642-524.zip</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ccsp.name/offersnaf-642-524-study-material/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>passguide ccsp 642-515 test questions</title>
		<link>http://www.ccsp.name/passguide-ccsp-642-515-test-questions</link>
		<comments>http://www.ccsp.name/passguide-ccsp-642-515-test-questions#comments</comments>
		<pubDate>Sat, 19 Dec 2009 13:10:29 +0000</pubDate>
		<dc:creator>Cisco</dc:creator>
				<category><![CDATA[Practice Tests]]></category>
		<category><![CDATA[642-515]]></category>
		<category><![CDATA[passguide]]></category>

		<guid isPermaLink="false">http://www.ccsp.name/?p=132</guid>
		<description><![CDATA[
Questions and Answers : 91 Q&#038;AsLatest Update: December-14th 2009Price: $125.99 $69.99
Product Description

Exam Number/Code: 642-515
Exam Name: Securing Networks with ASA Advanced
For candidates making preparation for the Cisco 642-515 exam, what they most desire is to easily pass the 642-515 (Securing Networks with ASA Advanced) exam. PassGuide 642-515 includes 91 questions and answers, which are collected and [...]]]></description>
			<content:encoded><![CDATA[<p>
Questions and Answers : 91 Q&#038;AsLatest Update: December-14th 2009Price: $125.99 $69.99<br />
Product Description<br />
<span id="more-132"></span><br />
Exam Number/Code: 642-515<br />
Exam Name: Securing Networks with ASA Advanced<br />
For candidates making preparation for the <a href="http://www.passguide.com/642-515.html">Cisco 642-515 exam</a>, what they most desire is to easily pass the 642-515 (Securing Networks with ASA Advanced) exam. PassGuide 642-515 includes 91 questions and answers, which are collected and collated by experts of Cisco. With our 642-515 study materials, you can successfully take Cisco certification of 642-515 exam and go further on Cisco career path.<br />
Free 642-515 Demo<br />
Download Demo of Cisco 642-515 exam for free (in PDF format ) before you decide to purchase it. Thus,you can know better about the quality of our practice exam and then make your right decision.<br />
Cisco 642-515</p>
<p>Securing Networks with ASA Advanced</p>
<p>Q&#038;A V3.20</p>
<p>www.PassGuide.com</p>
<p>(C) Copyright 2006-2009 CertBible Tech LTD,All Rights Reserved.<br />
Important Note<br />
Please Read Carefully </p>
<p>Study Tips </p>
<p>This product will provide you questions and answers carefully compiled and written by our experts. Try to understand the concepts behind the questions instead of cramming the questions. </p>
<p>Go through the entire document at least twice so that you make sure that you are not<br />
missing anything. </p>
<p>Latest Version </p>
<p>We are constantly reviewing our products. New material is added and old material is<br />
revised. Free updates are available for 120 days after the purchase. You should check your<br />
member zone at PassGuide an update 3-4 days before the scheduled exam date. </p>
<p>Feedback</p>
<p>If you spot a possible improvement then please let us know. We always interested in<br />
improving product quality.<br />
Feedback should be send to feedback@passguide.com. You should include the following:<br />
Exam number, version, page number, question number, and your login ID.<br />
Our experts will answer your mail promptly.</p>
<p>Be Prepared. Be Confident. Get Certified.<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Sales and Support Manager<br />
Sales Team: sales@passguide.com Support Team: support@passguide.com<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>Copyright </p>
<p>Each pdf file contains a unique serial number associated with your particular name and<br />
contact information for security purposes. So if we find out that a particular pdf file is<br />
being distributed by you, CertBible reserves the right to take legal action against you<br />
according to the International Copyright Laws.<br />
QUESTION: 1<br />
Refer to the exhibit. You are configuring a Cisco ASA security appliance to participate in a VPN cluster. Based on the exhibit, to which value would you set the priority to increase the chances of this Cisco ASA security appliance becoming the cluster master?</p>
<p>A. 0<br />
B. 1<br />
C. 10<br />
D. 100</p>
<p>Answer: C</p>
<p>QUESTION: 2<br />
Refer to the exhibit. You are the administrator of multiple remote Cisco ASA security appliances, which are administered through Cisco ASDM. You recently configured one of these Cisco ASA security appliances for SSL VPNs and are requiring a client certificate, as shown. How would this configuration affect your next ASDM connection to this Cisco ASA security appliance?</p>
<p>A. You would be asked to present an identity certificate. If you did not have one, the Cisco ASA security appliance would prompt you for authentication credentials, consisting of a username and password.<br />
B. Your connection would be handled the way it is always handled by this Cisco ASA security appliance.<br />
C. You would be required to download the identity certificate of the remote Cisco ASA security appliance.<br />
D. You would be required to have an identity certificate that the Cisco ASA security appliance can use for authentication.</p>
<p>Answer: D</p>
<p>QUESTION: 3<br />
Refer to the exhibit. You are the administrator of a corporate Cisco ASA security appliance with a Cisco ASA AIP-SSM. You have been tasked to deploy the AIP-SSM to protect corporate DMZ web servers. The AIP-SSM has been configured, and a service policy has been configured to identify the traffic that is to be passed to the AIP-SSM. On which two interfaces would application of the service policy for the AIP-SSM be most effective while causing the least amount of impact to Cisco ASA security appliance performance? (Choose two.)</p>
<p>A. Inside interface<br />
B. Dmz interface<br />
C. Internet interface<br />
D. Globally on all interfaces<br />
E. Outside interface</p>
<p>Answer: B, E</p>
<p>QUESTION: 4<br />
Refer to the exhibit. You are configuring the Cisco ASA security appliance as the hub in a hub- and-spoke site-to-site VPN. Which of these configurations will enable traffic to flow between spokes?</p>
<p>A.<br />
B. </p>
<p>C.</p>
<p>D</p>
<p>Answer: D</p>
<p>QUESTION: 5<br />
Refer to the exhibit. You have configured a Layer 7 policy map to match the size of HTTP header fields that are traversing the network. Based on this configuration, will HTTP headers that are greater than 200 bytes be logged?</p>
<p>A. No, because the reset action for headers greater than 100 bytes would be the first match.<br />
B. Yes, because the reset action for headers greater than 100 bytes and the log action for headers greater than 200 bytes would both be applied.<br />
C. No, because reset or log actions are a part of the service policy and the Layer 7 policy map.<br />
D. Yes, because the log action for headers greater than 200 bytes would be the last match.</p>
<p>Answer: A</p>
<p>QUESTION: 6<br />
Refer to the exhibit. The network security administrator for XYZ Corporation wants to configure the corporate Cisco ASA security appliance to take the following actions on its outside interface:<br />
&#8211;rate limit all IP traffic from telecommuting system engineers to the insidehost<br />
&#8211;drop all HTTP requests from the Internet to the web server that have a body length greater than 1000 bytes</p>
<p>&#8211;prevent users on network 192.168.6.0/24 from using the FTP PUT command to store .exe files on the FTP server Which set of Modular Policy Framework components will be involved in accomplishing this goal?</p>
<p>A. One Layer 7 class map, two Layer 7 policy maps, three Layer 3/4 class maps, one Layer ¾<br />
policy map<br />
B. One Layer 7 class map, one Layer 7 policy map, three Layer 3/4 class maps, one Layer ¾<br />
policy map<br />
C. Two Layer 7 class maps, one Layer 7 policy map, three Layer 3/4 class maps, one Layer ¾<br />
policy map<br />
D. Three Layer 7 policy maps, one Layer 3/4 class map, one Layer 3/4 policy map</p>
<p>Answer: A</p>
<p>QUESTION: 7<br />
Refer to the exhibit. You have configured a Cisco ASA 5505 Adaptive Security Appliance as an Easy VPN hardware client. During the configuration, you defined a list of backup servers for the security appliance to use. After a few hours of being connected to the primary VPN server, the security appliance fails. You notice that your Easy VPN hardware client has now connected to a backup server that is not defined within the configuration of the client. Where did your Easy VPN hardware client get this backup server?</p>
<p>A. The backup servers that you listed were no longer available, so the Easy VPN hardware client used the list of backup servers that it retrieved from the primary server.<br />
B. The group policy that was configured on the primary VPN server was pushed to your Easy<br />
VPN client and overwrote the list of backup servers that you had configured.<br />
C. The connection profile that was configured on the primary VPN server was pushed to your Easy VPN hardware client and overwrote the list of backup servers that you had configured. D. The backup servers that you listed were not configured as VPN servers, so the Easy VPN hardware client used the list of backup servers retrieved from the primary server.</p>
<p>Answer: B</p>
<p>QUESTION: 8<br />
Refer to the exhibit. You are the administrator of a Cisco ASA security appliance that is configured with a local CA. Based on the exhibit, for which purpose would the user student1 use this password?</p>
<p>A. Authentication to the SSL VPN server<br />
B. Retrieval of the digital certificate from the local CA on the Cisco ASA security appliance<br />
C. Retrieval of the Cisco ASA security appliance identity certificate<br />
D. The initial authentication to the SSL VPN server</p>
<p>Answer: B</p>
<p>QUESTION: 9<br />
Refer to the exhibit. When TCP connections are tunneled over another TCP connection and latency exists between the two endpoints, each TCP session will trigger a retransmission, which can quickly spiral out of control when the latency issues persist. This issue is often referred to as TCP-over-TCP meltdown. Based on the Cisco ASDM configuration that is shown, which Cisco ASA security appliance configuration will help alleviate this problem?</p>
<p>A. Keepalive Messages<br />
B. Compression<br />
C. MTU size of 500<br />
D. Datagram TLS</p>
<p>Answer: D</p>
<p>QUESTION: 10<br />
Refer to the exhibit. You have been tasked with configuring your Cisco ASA security appliance for EIGRP routing. Based on the information that is provided in the exhibit, which two Cisco ASDM configurations will add these networks to the configuration of EIGRP?</p>
<p>A.</p>
<p>B.</p>
<p>C.</p>
<p>Answer: A</p>
<p>QUESTION: 11<br />
Which two of these choices are types of queues available on the Cisco ASA security appliance when implementing QoS? (Choose two.)<br />
A. Weighted fair queue<br />
B. Last in first out queue<br />
C. Policing queue<br />
D. Low latency queue<br />
E. Custom queue<br />
F. Best effort queue<br />
G. Round robin queue</p>
<p>Answer: D, F</p>
<p>QUESTION: 12<br />
Refer to the exhibit. The FTP inspection map named L7FTPPOLICY is applied to the outside interface of the security appliance. As a result of this configuration, which of the following actions does the security appliance take on FTP traffic entering its outside interface?</p>
<p>A. Resets and logs connections from any user who attempts to retrieve files via FTP; resets connections from xyz.com users who attempt to deliver files via FTP<br />
B. Resets connections from abc.com and xyz.com users when they attempt to retrieve files via<br />
FTP; logs any user connections that attempt to deliver files via FTP<br />
C. Resets and logs connections from abc.com users when they attempt to retrieve files via FTP; resets all FTP connections from xyz.com users; resets any user connections that attempt to deliver files via FTP<br />
D. Resets and logs connections from abc.com users only when they attempt to retrieve files via FTP: resets connections from xyz.com users only when they attempt to deliver files via FTP</p>
<p>Answer: C</p>
<p>QUESTION: 13<br />
Which two internal channels are used for communication between the Cisco ASA AIP-SSM<br />
and the Cisco ASA security appliance? (Choose two.)<br />
A. Session channel<br />
B. Command channel<br />
C. Inline channel<br />
D. Promiscuous channel<br />
E. Control channel<br />
F. Data channel</p>
<p>Answer: E, F</p>
<p>QUESTION: 14<br />
Refer to the exhibit. An administrator is editing user-specific policy. The administrator has configured a group policy for Sales to use the IP address pool that is defined by the pool VPNPOOL and to allow as many as three simultaneous logins. Based on the exhibit, when this user connects, what will be the IP address assigned to the connection and what will be the number of simultaneous logins allowed for this user? (Choose two.)</p>
<p>A. The user will receive an IP address from the VPNPOOL.<br />
B. The user will be allowed to make only one connection.<br />
C. The user will be allowed to make connections up to the limit that is defined in the default group policy.<br />
D. The user will be assigned the IP address from the user-specific policy.<br />
E. The user will be allowed to make as many as three simultaneous connections.<br />
F. The user will receive an IP address from the address pool that is defined in the default group policy.</p>
<p>Answer: B, D</p>
<p>QUESTION: 15<br />
Which three Cisco Modular Policy Framework features are bidirectional? (Choose three.)<br />
A. AIP policy<br />
B. QoS input policing<br />
C. CSC policy<br />
D. QoS priority queue<br />
E. Application inspection<br />
F. QoS output policing</p>
<p>Answer: A, C, E</p>
<p>QUESTION: 16<br />
You have been tasked to configure your Cisco ASA security appliance for multiple VLANs that use one physical interface. You must make sure that the switch in which the physical Cisco ASA security appliance interface is connected has been configured for the appropriate VLAN tagging protocol. Which VLAN tagging protocol will the Cisco ASA security appliance use to communicate with this switch?<br />
A. IEEE 802.1X<br />
B. IEEE 802.1Q<br />
C. IEEE 802.1AE<br />
D. ISL<br />
E. IEEE 802.3</p>
<p>Answer: B</p>
<p>QUESTION: 17<br />
Refer to the exhibit. If a host on the inside network attempted an HTTP connection to a host at IP address 172.26.10.100, which address pool would the Cisco ASA security appliance use for the NAT?</p>
<p>A. 192.168.8.101 &#8211; 192.168.8.105<br />
B. 192.168.8.106 &#8211; 192.168.8.110<br />
C. 192.168.8.20 &#8211; 192.168.8.110<br />
D. 192.168.8.20 &#8211; 192.168.8.100</p>
<p>Answer: D</p>
<p>QUESTION: 18<br />
You are the administrator for Cisco ASA security appliances that are used for site-to-site VPNs between remote and corporate offices. You have used the Service Policy Rule Wizard within ASDM to configure low-latency queuing for unified communications on all the appropriate ASAs. Users are still having issues with unified communications between the remote and corporate offices. Assuming that the Cisco Unified Communications equipment is functioning properly and that the VPN configurations are correct, which of these choices is most likely the cause of the problems?<br />
A. A priority queue must be created on the interface where the site-to-site VPN tunnel is terminated.<br />
B. The DSCP, expedite forward, ef (46), was used to determine unified communications traffic within the Service Policy Rule Wizard.<br />
C. The tunnel group and DSCP traffic matching criteria were configured within the Service<br />
Policy Rule Wizard.<br />
D. Both a policing and priority queue must be applied on the interface to expedite the voice and control data flows.</p>
<p>Answer: A</p>
<p>QUESTION: 19<br />
What are the three main components of Cisco Modular Policy Framework? (Choose three.)<br />
A. Security policy<br />
B. Policy map<br />
C. Security map<br />
D. Route map<br />
E. Class map<br />
F. Interface map<br />
G.Traffic policy<br />
H. Service policy</p>
<p>Answer: B, E, H</p>
<p>QUESTION: 20<br />
When configuring port forwarding for a clientless SSL VPN connection, which end user privilege level is required at the endpoint if port forwarding is to work?<br />
A. Guest level<br />
B. Administrator level<br />
C. System level<br />
D. User level</p>
<p>Answer: B</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ccsp.name/passguide-ccsp-642-515-test-questions/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>passguide cisco ccsp 642-504 pdf</title>
		<link>http://www.ccsp.name/passguide-cisco-ccsp-642-504-pdf</link>
		<comments>http://www.ccsp.name/passguide-cisco-ccsp-642-504-pdf#comments</comments>
		<pubDate>Sat, 19 Dec 2009 13:08:05 +0000</pubDate>
		<dc:creator>Cisco</dc:creator>
				<category><![CDATA[Practice Tests]]></category>
		<category><![CDATA[642-504]]></category>
		<category><![CDATA[passguide]]></category>

		<guid isPermaLink="false">http://www.ccsp.name/?p=130</guid>
		<description><![CDATA[	Cisco 642-524
Securing Networks with ASA Foundation

Q&#038;A V3.21
www.PassGuide.com
(C) Copyright 2006-2009 CertBible Tech LTD,All Rights Reserved.
Important Note
Please Read Carefully 
Study Tips 
This product will provide you questions and answers carefully compiled and written by our experts. Try to understand the concepts behind the questions instead of cramming the questions. 
Go through the entire document at least twice [...]]]></description>
			<content:encoded><![CDATA[<p>	<a href="http://www.passguide.com/642-504.html">Cisco 642-524</a></p>
<p>Securing Networks with ASA Foundation</p>
<p><span id="more-130"></span></p>
<p>Q&#038;A V3.21</p>
<p>www.PassGuide.com</p>
<p>(C) Copyright 2006-2009 CertBible Tech LTD,All Rights Reserved.</p>
<p>Important Note<br />
Please Read Carefully </p>
<p>Study Tips </p>
<p>This product will provide you questions and answers carefully compiled and written by our experts. Try to understand the concepts behind the questions instead of cramming the questions. </p>
<p>Go through the entire document at least twice so that you make sure that you are not<br />
missing anything. </p>
<p>Latest Version </p>
<p>We are constantly reviewing our products. New material is added and old material is<br />
revised. Free updates are available for 120 days after the purchase. You should check your<br />
member zone at PassGuide an update 3-4 days before the scheduled exam date. </p>
<p>Feedback</p>
<p>If you spot a possible improvement then please let us know. We always interested in<br />
improving product quality.<br />
Feedback should be send to feedback@passguide.com. You should include the following:<br />
Exam number, version, page number, question number, and your login ID.<br />
Our experts will answer your mail promptly.</p>
<p>Be Prepared. Be Confident. Get Certified.<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Sales and Support Manager<br />
Sales Team: sales@passguide.com Support Team: support@passguide.com<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>Copyright </p>
<p>Each pdf file contains a unique serial number associated with your particular name and<br />
contact information for security purposes. So if we find out that a particular pdf file is<br />
being distributed by you, CertBible reserves the right to take legal action against you<br />
according to the International Copyright Laws.<br />
1.Tom works as a network administrator for the PG company. The primary adaptive security appliance in an active/standby failover configuration failed, so the secondary adaptive security appliance was automatically activated. Tom then fixed the problem. Now he would like to restore the primary to active status. Which one of the following commands can reactivate the primary adaptive security appliance and restore it to active status while issued on the primary adaptive security appliance?A.failover resetB.failover primary activeC.failover activeD.failover exec standby<br />
Answer:C<br />
2.For the following commands, which one enables the DHCP server on the DMZ interface of the Cisco ASA with an address pool of 10.0.1.100-10.0.1.108 and a DNS server of 192.168.1.2?A.dhcpd address 10.0.1.100-10.0.1.108 DMZ dhcpd dns 192.168.1.2 dhcpd enable DMZB.dhcpd address range 10.0.1.100-10.0.1.108 dhcpd dns server 192.168.1.2 dhcpd enable DMZC.dhcpd range 10.0.1.100-10.0.1.108 DMZ dhcpd dns server 192.168.1.2 dhcpd DMZD.dhcpd address range 10.0.1.100-10.0.1.108 dhcpd dns 192.168.1.2 dhcpd enable<br />
Answer:A<br />
3.Look at the following exhibit carefully, which one of the four diagrams displays a correctly configured network for a transparent firewall?A.1B.2C.3D.4<br />
Answer:D<br />
4.What is the effect of the per-user-override option when applied to the access-group command syntax?A.The log option in the per-user access list overrides existing interface log options.B.It allows for extended authentication on a per-user basis.C.It allows downloadable user access lists to override the access list applied to the interface.D.It increases security by building upon the existing access list applied to the interface. All subsequent users are also subject to the additional access list entries.<br />
Answer:C<br />
5.John works as a network administrator for the PG company. According to the exhibit, the only traffic that John would like to allow through the corporate Cisco ASA adaptive security appliance is inbound HTTP to the DMZ network and all traffic from the inside network to the outside network. John also has configured the Cisco ASA adaptive security appliance, and access through it is now working as expected with one exception: contractors working on the DMZ servers have been surfing the Internet from the DMZ servers, which (unlike other Company XYZ hosts) are using public, routable IP addresses. Neither NAT statements nor access lists have been configured for the DMZ interface. What is the reason that the contractors are able to surf the Internet from the DMZ servers? (Note: The 192.168.X.X IP addresses are used to represent routable public IP addresses even though the 192.168.1.0 network is not actually a public routable network.)A.An access list on the outside interface permits this traffic.B.NAT control is not enabled.C.The DMZ servers are using the same global pool of addresses that is being used by the inside hosts.D.HTTP inspection is not enabled.<br />
Answer:B<br />
6.In order to recover the Cisco ASA password, which operation mode should you enter?A.configureB.unprivilegedC.privilegedD.monitor<br />
Answer:D<br />
7.Which three statements correctly describe protocol inspection on the Cisco ASA adaptive security appliance? (Choose three.)A.For the security appliance to inspect packets for signs of malicious application misuse, you must enable advanced (application layer) protocol inspection.B.If you want to enable inspection globally for a protocol that is not inspected by default or if you want to globally disable inspection for a protocol, you can edit the default global policy.C.The protocol inspection feature of the security appliance securely opens and closes negotiated ports and IP addresses for legitimate client-server connections through the security appliance.D.If inspection for a protocol is not enabled, traffic for that protocol may be blocked.<br />
Answer:B C D<br />
8.Observe the following commands, which one verifies that NAT is working normally and displays active NAT translations?A.show ip nat allB.show running-configuration natC.show xlateD.show nat translation<br />
Answer:C<br />
9.Multimedia applications transmit requests on TCP, get responses on UDP or TCP, use dynamic ports, and use the same port for source and destination, so they can pose challenges to a firewall. Which three items are true about how the Cisco ASA adaptive security appliance handles multimedia applications? (Choose three.)A.It dynamically opens and closes UDP ports for secure multimedia connections, so you do not need to open a large range of ports.B.It supports SIP with NAT but not with PAT.C.It supports multimedia with or without NAT.D.It supports RTSP, H.323, Skinny, and CTIQBE.<br />
Answer:A C D<br />
10.What is the result if the WebVPN url-entry parameter is disabled?A.The end user is unable to access pre-defined URLs.B.The end user is unable to access any CIFS shares or URLs.C.The end user is able to access CIFS shares but not URLs.D.The end user is able to access pre-defined URLs.<br />
Answer:D<br />
11.You work as a network engineer at Pass4sure.com, you are asked to examine the current Modular Policy Framework configurations on the LA-ASA Adaptive Security Appliances using the Cisco Adaptive Security Device Manager (ASDM) utility. You need to answer the multiple-choice questions in this simulation by use of the appropriate Cisco ASDM configuration screens. A host on the partnernet network attempts to use FTP to download a file from InsideHost,which resides on the inside interface of the security appliance.What does the security appliance do with the traffic from the partnernet host?A.Sends it to the Cisco ASA Advanced Inspection and Prevention(AIP)-Security Services Module(SSM)for inspection before forwarding it to its destinationB.Sends it to the Cisco ASA 5500 Series Content Security and Control(CSC)SSM for inspection before forwarding it to its destinationC.Forwards it directly to its destinationD.Forwards it directly to its destination unless the connection limit is already met<br />
Answer:D<br />
12.You work as a network engineer at PassGuide.com, you are asked to examine the current Modular Policy Framework configurations on the LA-ASA Adaptive Security Appliances using the Cisco Adaptive Security Device Manager (ASDM) utility. You need to answer the multiple-choice questions in this simulation by use of the appropriate Cisco ASDM configuration screens. Which traffic does the security appliance inspect globally(regardless of the interface on which the traffic enters the security appliance)?(Choose 3)A.HTTPB.DNSC.GTPD.H.323 H.225<br />
Answer:A B D<br />
13.You work as a network engineer at PassGuidecom, you are asked to examine the current Modular Policy Framework configurations on the LA-ASA Adaptive Security Appliances using the Cisco Adaptive Security Device Manager (ASDM) utility. You need to answer the multiple-choice questions in this simulation by use of the appropriate Cisco ASDM configuration screens. A host on the partnernet network makes a VoIP call to 172.20.1.15,which is statically mapped to an IP phone on the inside network.What does the security appliance do with the VoIP traffic between host 172.20.1.15 and the host on the partnernet network?A.Sends it to the AIP-SSM for inspection before forwarding it to its destinationB.Sends it to the CSC-SSM for inspection before forwarding it to its destinationC.Forwards it directly to its destination unless the connection limit is already metD.Applies low latency queuing as it exits the partnernet interface<br />
Answer:D<br />
14.You work as a network engineer at PaGuide.com, you are asked to examine the current Modular Policy Framework configurations on the LA-ASA Adaptive Security Appliances using the Cisco Adaptive Security Device Manager (ASDM) utility. You need to answer the multiple-choice questions in this simulation by use of the appropriate Cisco ASDM configuration screens. A host on the outside network sends e-mail to the public e-mail server.What does the security appliance do with the traffic from the outside host?A.Sends it to the AIP-SSM for inspection before forwarding it to its destinationB.Sends it to the CSC-SSM for inspection before forwarding it to its destinationC.Forwards it directly to its destinationD.Forwards it directly to its destination unless the connection limit is already met<br />
Answer:A<br />
15.You work as a network engineer at PassGuide.com, you are asked to examine the current Modular Policy Framework configurations on the LA-ASA Adaptive Security Appliances using the Cisco Adaptive Security Device Manager (ASDM) utility. You need to answer the multiple-choice questions in this simulation by use of the appropriate Cisco ASDM configuration screens. A host on the partnernet network attempts to access the public web server via HTTP.What does the security appliance do with traffic from the partnernet?A.Sends it to the AIP-SSM for inspection before forwarding it to its destinationB.Sends it to the CSC-SSM for inspection before forwarding it to its destinationC.Forwards it directly to its destinationD.Forwards it directly to its destination unless the connection limit is already met<br />
Answer:C<br />
16.You work as a network engineer at PassGuide.com, you are asked to examine the current Modular Policy Framework configurations on the LA-ASA Adaptive Security Appliances using the Cisco Adaptive Security Device Manager (ASDM) utility. You need to answer the multiple-choice questions in this simulation by use of the appropriate Cisco ASDM configuration screens. A host on the outside network makes a VoIP call to a host on the inside network.What does the security appliance do with the traffic from the host on the outside network?A.Sends it to the AIP-SSM for inspection before forwarding it to its destinationB.Sends it to the CSC-SSM for inspection before forwarding it to its destinationC.Forwards it directly to its destinationD.Drops it<br />
Answer:D<br />
17.Which three tunneling protocols and methods are supported by the Cisco VPN Client? (Choose three.)A.IPsec over TCPB.IPsec over UDPC.ESPD.AH<br />
Answer:A B C<br />
18.Which two options are correct about the impacts of this configuration? (Choose two.) class-map INBOUND_HTTP_TRAFFIC<br />
match access-list TOINSIDEHOST<br />
class-map OUTBOUND_HTTP_TRAFFIC<br />
match access-list TOOUTSIDEHOST<br />
policy-map MYPOLICY<br />
class INBOUND_HTTP_TRAFFIC<br />
inspect http<br />
set connection conn-max 100<br />
policy-map MYOTHERPOLICY<br />
class OUTBOUND_HTTP_TRAFFIC<br />
inspect http<br />
service-policy MYOTHERPOLICY interface inside<br />
service-policy MYPOLICY interface outsideA.Traffic that matches access control list TOINSIDEHOST is subject to HTTP inspection and maximum connection limits.B.Traffic that enters the security appliance through the inside interface is subject to HTTP inspection.C.Traffic that enters the security appliance through the outside interface and matches access control list TOINSIDEHOST is subject to HTTP inspection and maximum connection limits.D.Traffic that enters the security appliance through the inside interface and matches access control list TOOUTSIDEHOST is subject to HTTP inspection.<br />
Answer:C D<br />
19.Take the following configuration shown in the exhibit carefully, what traffic will be logged to the AAA server?A.Only authenticated and authorized console connection information will be logged in the accounting database.B.All outbound TCP connection information will be logged in the accounting database.C.No information will be logged. This is not a valid configuration because TACACS+ connection information cannot be captured and logged.D.All connection information will be logged in the accounting database.<br />
Answer:B<br />
20.What are the two purposes of the same-security-traffic permit intra-interface command? (Choose two.)A.It allows all of the VPN spokes in a hub-and-spoke configuration to be terminated on a single interface.B.It enables Dynamic Multipoint VPN.C.It permits communication in and out of the same interface when the traffic is IPSec protected.D.It allows communication between different interfaces that have the same security level<br />
Answer:A C<br />
21.How many unique transforms will included in a single transform set while configuring a crypto ipsec transform-set command?A.threeB.twoC.fourD.one<br />
Answer:B<br />
22.Study the following exhibit carefully, the Cisco ASA adaptive security appliance is using software version 8.0 with the default configuration. Configure the interfaces displayed in the exhibit with the security levels that are shown, and enable the interfaces. Management-only mode is disabled on m0/0. Which two statements correctly describe these interfaces? (Choose two.)A.Interface m0/0 can access interface g0/2, but interface g0/2 cannot access interface m0/0 unless it is given permission.B.Interface g0/1 can access interface m0/0, and interface m0/0 can access interface g0/1.C.Interface g0/1 cannot access interface m0/0 unless it is given permission, and interface m0/0 cannot access interface g0/1 unless it is given permission.D.No traffic can flow between the g0/2 and g0/3 interfaces.<br />
Answer:A D<br />
23.John works as a network administrator , according to the following exhibit. Descriptions are added to class maps for each part of the modular policy framework. Which text should John add to the description command to describe the TO_SERVER class map?<br />
PG-asa1(config)#access-list UDP permit udp any any<br />
PG-asa1(config)#access-list TCP permit tcp any any<br />
PG-asa1(config)#access-list PUBLIC_WEB permit ip any 10.10.10.100 255.255.255.255 PG-asa1(config)#class-map ALL_VDP<br />
PG-asa1(config-cmap)#description &#8220;This class-map matches all UDP traffic&#8221;<br />
PG-asa1(config-cmap)#match access-list VDP<br />
PG-asa1(config-cmap)#class-map ALL_TCP<br />
PG-asa1(config-cmap)#description &#8220;This class-map matches all TCP traffic&#8221;<br />
PG-asa1(config-cmap)#match access-list TCP<br />
PG-asa1(config-cmap)#class-map ALL_WEB_SERVER<br />
PG-asa1(config-cmap)#description &#8220;This class-map matches all HTTP traffic&#8221;<br />
PG-asa1(config-cmap)#match port tcp eq http<br />
PG-asa1(config-cmap)#class-map TO_SERVER<br />
PG-asa1(config-cmap)#match access-list PUBLIC_WEBA.description &#8220;This class-map matches all TCP traffic for the public web server.&#8221;B.description &#8220;This class-map matches all HTTP traffic for the public web server.&#8221;C.description &#8220;This class-map matches all HTTPS traffic for the public web server.&#8221;D.description &#8220;This class-map matches all IP traffic for the public web server.&#8221;<br />
Answer:D<br />
24.What is the reason that you want to configure VLANs on a security appliance interface?A.for use in conjunction with device-level failover to increase the reliability of your security applianceB.for use in transparent firewall mode, where only VLAN interfaces are usedC.to increase the number of interfaces available to the network without adding additional physical interfaces or security appliancesD.for use in multiple context mode, where you can map only VLAN interfaces to contexts<br />
Answer:C<br />
25.By default, the AIP-SSM IPS software is accessible from the management port at IP address 10.1.9.201/24. Which CLI command should an administrator use to change the default AIP-SSM management port IP address?A.interfaceB.hw module 1 recoverC.setupD.hw module 1 setup<br />
Answer:C<br />
26.Which one of the following commands can provide detailed information about the crypto map configurations of a Cisco ASA adaptive security appliance?A.show ipsec saB.show crypto mapC.show run ipsec saD.show run crypto map<br />
Answer:D<br />
27.Which three potential groups are of users for WebVPN? (Choose three.)A.employees accessing specific internal applications from desktops and laptops not managed by ITB.administrators who need to manage servers and networking equipmentC.employees that only need occasional corporate access to a few applicationsD.users of a customer service kiosk placed in a retail store<br />
Answer:A C D<br />
28.Which three features can the Cisco ASA adaptive security appliance support? (Choose three.)A.BGP dynamic routingB.802.1Q VLANsC.OSPF dynamic routingD.static routes<br />
Answer:B C D<br />
29.Which one of the following commands will prevent all SIP INVITE packets, such as calling-party and request-method, from specific SIP endpoints?A.Use the match calling-party command in a class map. Apply the class map to a policy map that contains the match request-methods command.B.Group the match commands in a SIP inspection class map.C.Use the match request-methods command in an inspection class map. Apply the inspection class map to an inspection policy map that contains the match calling-party command.D.Group the match commands in a SIP inspection policy map.<br />
Answer:B<br />
30.Which two statements are true about multiple context mode? (Choose two.)A.Multiple context mode does not support IPS, IPsec, and SSL VPNs, or dynamic routing protocols.B.Multiple context mode enables you to create multiple independent virtual firewalls with their own security policies and interfaces.C.Multiple context mode enables you to add to the security appliance a hardware module that supports up to four independent virtual firewalls.D.When you convert from single mode to multiple mode, the security appliance automatically adds an entry for the admin context to the system configuration with the name &#8220;admin.&#8221;<br />
Answer:B D<br />
31.How do you ensure that the main interface does not pass untagged traffic when using subinterfaces?A.Use the vlan command on the main interface.B.Use the shutdown command on the main interfaceC.Omit the nameif command on the subinterfaceD.Omit the nameif command on the main interface.<br />
Answer:D<br />
32.For creating and configuring a security context, which three tasks are mandatory? (Choose three.)A.allocating interfaces to the contextB.assigning MAC addresses to context interfacesC.creating a context nameD.specifying the location of the context startup configuration<br />
Answer:A C D<br />
33.Study the exhibit carefully. Which two types of failover is this adaptive security appliance configured for? (Choose two.)<br />
PG-asa1# show failover Failover On Cable status:<br />
N/A-LAN-based failover enabled Failover unit Primary Failover LAN Interface:<br />
Ianfail GigabitEthernet0/2 (up) Unit Poll frequency 15 seconds, holdtime 45 seconds Interface Poll frequency 15 seconds Interface Policy 1 Monitored Interfaces 4 of 250 maximum Group 1 last failover at:<br />
15:54:49 UTC Sept 17 2006 Group 2 last failover at:<br />
15:55:00 UTC Sept 17 2006A.stateful failoverB.LAN-based failoverC.cable-based failoverD.Active/Active failover<br />
Answer:B D<br />
34.Which two descriptions are correct about configuring passive RIP on the security appliance based on the following exhibit? (Choose two.)A.You must specify a classful network IP address to define a network for the RIP routing process.B.If you enable passive RIP, all interfaces must operate in passive mode.C.There is no limit to the number of networks you can specify for the RIP routing process.D.Enabling passive RIP mode causes the security appliance to receive all RIP routing updates but send only a default route to neighboring routers.<br />
Answer:A C<br />
35.Which of these identifies basic settings for the security appliance, including a list of contexts?A.network configurationB.admin configurationC.system configurationD.primary configuration<br />
Answer:C<br />
36.Study the exhibit carefully. The security policy for PG Corporation allows only the following traffic through the corporate adaptive security appliance: &#8211;outbound NTP traffic from the inside network to any outside destination &#8211;FTP traffic from the inside network to the FTP server on the DMZ &#8211;outbound HTTP traffic from the inside network to any outside destination &#8211;FTP traffic from the outside 192.168.6.0/24 network to the FTP server on the DMZ &#8211;any HTTP traffic from the outside to the web server on the DMZ The network administrator configured access rules according to the security policy requirements but made two mistakes. Which are two mistakes? (Choose two.)A.missing ACEB.incorrect destination addressC.missing ACLD.incorrect order of ACLs<br />
Answer:B D<br />
37.An administrator wants to protect a DMZ web server from SYN flood attacks. Which command does not allow the administrator to place limits on the number of embryonic connections?A.set connectionB.natC.staticD.HTTP-map<br />
Answer:D<br />
38.Which option correctly describes the order to upgrade the license (activation key) for your security appliance from Cisco ASDM?A.Step 1 Obtain an activation key from http://www.cisco.com/go/license by providing the serial number for the security appliance as it appears on the chassis of the security appliance.<br />
Step 2 Reboot the security appliance to ensure that the image in flash and the running image are the same.<br />
Step 3 Go to Configuration > Device Management > System Image/Configuration > Activation Key in Cisco ASDM and enter the activation key as a four- or five-element hexadecimal string with no spaces.<br />
Step 4 Click Update Activation Key in the Activation Key panel.<br />
Step 5 Reload the security appliance to activate the flash activation key.B.Step 1 Obtain an activation key from http://www.cisco.com/go/license by providing the serial number for the security appliance as it appears in the show version command output. Step 2 Reboot the security appliance to ensure that the image in flash and the running image are the same.<br />
Step 3 Go to Configuration > Device Management > System Image/Configuration > Activation Key in Cisco ASDM and enter the activation key as a four- or five-element hexadecimal string with one space between each element.<br />
Step 4 Click Update Activation Key in the Activation Key panel.<br />
Step 5 Reload the security appliance to activate the flash activation key.C.Step 1 Obtain an activation key from http://www.cisco.com/go/license by providing the serial number for the security appliance as it appears in the show version command output. Step 2 Go to Configuration > Device Management > System Image/Configuration > Activation Key in Cisco ASDM and enter the activation key as a three- or four-element hexadecimal string with one space between each element.<br />
Step 3 Click Update Activation Key in the Activation Key panel.<br />
Step 4 Click Save in the Cisco ASDM toolbar.D.Step 1 Obtain an activation key from http://www.cisco.com/go/license by providing the serial number for the security appliance as it appears on the chassis of the security appliance.<br />
Step 2 Go to Configuration > Device Management > System Image/Configuration > Activation Key in Cisco ASDM and enter the activation key as a four- or five-element hexadecimal string with no spaces.<br />
Step 3 Click Update Activation Key in the Activation Key panel.<br />
Step 4 Click Save in the Cisco ASDM toolbar.<br />
Answer:B<br />
39.You are a network administrator for the PG company. After the primary adaptive security appliance failed, the secondary adaptive security appliance was automatically activated. You fixed the problem. Now you would like to restore the primary to &#8220;active&#8221; status. When issued on the primary adaptive security appliance, which command would reactivate the primary adaptive security appliance and return it to &#8220;active&#8221; status?A.failover secondary standby group 1B.failover primary activeC.failover active group 1D.failover secondary group 1<br />
Answer:C<br />
40.Which two scenarios correctly describe the impact of the configuration shown in the exhibit? (Choose two.)A.User addison enters the login command at the > prompt and logs in with the correct username and password when prompted. User addison can then enter the global configuration mode on the security appliance.B.User carter enters the enable command at the > prompt and logs in with the correct username and password when prompted. User carter can then enter the global configuration mode.C.User carter enters the login command at the > prompt and logs in with the correct username and password when prompted. User carter can then enter the global configuration mode on the security appliance.D.User kenny enters the enable command at the > prompt and logs in with the correct username and password when prompted. User kenny can then enter the global configuration mode.<br />
Answer:A D<br />
41.While configuring a crypto map, which command will be used to specify the peer to which IPsec-protected traffic could be forwarded?A.crypto-map policy 10 set 192.168.7.2B.crypto map set peer 192.168.7.2C.crypto map 20 set-peer insidehostD.crypto map peer7 10 set peer 192.168.7.2<br />
Answer:D </p>
]]></content:encoded>
			<wfw:commentRss>http://www.ccsp.name/passguide-cisco-ccsp-642-504-pdf/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>passguide ccsp 642-524 pdf demo</title>
		<link>http://www.ccsp.name/passguide-ccsp-642-524-pdf-demo</link>
		<comments>http://www.ccsp.name/passguide-ccsp-642-524-pdf-demo#comments</comments>
		<pubDate>Sat, 19 Dec 2009 13:05:02 +0000</pubDate>
		<dc:creator>Cisco</dc:creator>
				<category><![CDATA[Practice Tests]]></category>
		<category><![CDATA[642-524]]></category>
		<category><![CDATA[passguide]]></category>

		<guid isPermaLink="false">http://www.ccsp.name/?p=128</guid>
		<description><![CDATA[	Cisco 642-524
Securing Networks with ASA Foundation
Q&#038;A V3.21

www.PassGuide.com
(C) Copyright 2006-2009 CertBible Tech LTD,All Rights Reserved.
Important Note
Please Read Carefully 
Study Tips 
This product will provide you questions and answers carefully compiled and written by our experts. Try to understand the concepts behind the questions instead of cramming the questions. 
Go through the entire document at least twice [...]]]></description>
			<content:encoded><![CDATA[<p>	<a href="http://www.passguide.com/642-524.html">Cisco 642-524</a></p>
<p>Securing Networks with ASA Foundation</p>
<p>Q&#038;A V3.21</p>
<p><span id="more-128"></span></p>
<p>www.PassGuide.com</p>
<p>(C) Copyright 2006-2009 CertBible Tech LTD,All Rights Reserved.</p>
<p>Important Note<br />
Please Read Carefully </p>
<p>Study Tips </p>
<p>This product will provide you questions and answers carefully compiled and written by our experts. Try to understand the concepts behind the questions instead of cramming the questions. </p>
<p>Go through the entire document at least twice so that you make sure that you are not<br />
missing anything. </p>
<p>Latest Version </p>
<p>We are constantly reviewing our products. New material is added and old material is<br />
revised. Free updates are available for 120 days after the purchase. You should check your<br />
member zone at PassGuide an update 3-4 days before the scheduled exam date. </p>
<p>Feedback</p>
<p>If you spot a possible improvement then please let us know. We always interested in<br />
improving product quality.<br />
Feedback should be send to feedback@passguide.com. You should include the following:<br />
Exam number, version, page number, question number, and your login ID.<br />
Our experts will answer your mail promptly.</p>
<p>Be Prepared. Be Confident. Get Certified.<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Sales and Support Manager<br />
Sales Team: sales@passguide.com Support Team: support@passguide.com<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>Copyright </p>
<p>Each pdf file contains a unique serial number associated with your particular name and<br />
contact information for security purposes. So if we find out that a particular pdf file is<br />
being distributed by you, CertBible reserves the right to take legal action against you<br />
according to the International Copyright Laws.<br />
1.Tom works as a network administrator for the PG company. The primary adaptive security appliance in an active/standby failover configuration failed, so the secondary adaptive security appliance was automatically activated. Tom then fixed the problem. Now he would like to restore the primary to active status. Which one of the following commands can reactivate the primary adaptive security appliance and restore it to active status while issued on the primary adaptive security appliance?A.failover resetB.failover primary activeC.failover activeD.failover exec standby<br />
Answer:C<br />
2.For the following commands, which one enables the DHCP server on the DMZ interface of the Cisco ASA with an address pool of 10.0.1.100-10.0.1.108 and a DNS server of 192.168.1.2?A.dhcpd address 10.0.1.100-10.0.1.108 DMZ dhcpd dns 192.168.1.2 dhcpd enable DMZB.dhcpd address range 10.0.1.100-10.0.1.108 dhcpd dns server 192.168.1.2 dhcpd enable DMZC.dhcpd range 10.0.1.100-10.0.1.108 DMZ dhcpd dns server 192.168.1.2 dhcpd DMZD.dhcpd address range 10.0.1.100-10.0.1.108 dhcpd dns 192.168.1.2 dhcpd enable<br />
Answer:A<br />
3.Look at the following exhibit carefully, which one of the four diagrams displays a correctly configured network for a transparent firewall?A.1B.2C.3D.4<br />
Answer:D<br />
4.What is the effect of the per-user-override option when applied to the access-group command syntax?A.The log option in the per-user access list overrides existing interface log options.B.It allows for extended authentication on a per-user basis.C.It allows downloadable user access lists to override the access list applied to the interface.D.It increases security by building upon the existing access list applied to the interface. All subsequent users are also subject to the additional access list entries.<br />
Answer:C<br />
5.John works as a network administrator for the PG company. According to the exhibit, the only traffic that John would like to allow through the corporate Cisco ASA adaptive security appliance is inbound HTTP to the DMZ network and all traffic from the inside network to the outside network. John also has configured the Cisco ASA adaptive security appliance, and access through it is now working as expected with one exception: contractors working on the DMZ servers have been surfing the Internet from the DMZ servers, which (unlike other Company XYZ hosts) are using public, routable IP addresses. Neither NAT statements nor access lists have been configured for the DMZ interface. What is the reason that the contractors are able to surf the Internet from the DMZ servers? (Note: The 192.168.X.X IP addresses are used to represent routable public IP addresses even though the 192.168.1.0 network is not actually a public routable network.)A.An access list on the outside interface permits this traffic.B.NAT control is not enabled.C.The DMZ servers are using the same global pool of addresses that is being used by the inside hosts.D.HTTP inspection is not enabled.<br />
Answer:B<br />
6.In order to recover the Cisco ASA password, which operation mode should you enter?A.configureB.unprivilegedC.privilegedD.monitor<br />
Answer:D<br />
7.Which three statements correctly describe protocol inspection on the Cisco ASA adaptive security appliance? (Choose three.)A.For the security appliance to inspect packets for signs of malicious application misuse, you must enable advanced (application layer) protocol inspection.B.If you want to enable inspection globally for a protocol that is not inspected by default or if you want to globally disable inspection for a protocol, you can edit the default global policy.C.The protocol inspection feature of the security appliance securely opens and closes negotiated ports and IP addresses for legitimate client-server connections through the security appliance.D.If inspection for a protocol is not enabled, traffic for that protocol may be blocked.<br />
Answer:B C D<br />
8.Observe the following commands, which one verifies that NAT is working normally and displays active NAT translations?A.show ip nat allB.show running-configuration natC.show xlateD.show nat translation<br />
Answer:C<br />
9.Multimedia applications transmit requests on TCP, get responses on UDP or TCP, use dynamic ports, and use the same port for source and destination, so they can pose challenges to a firewall. Which three items are true about how the Cisco ASA adaptive security appliance handles multimedia applications? (Choose three.)A.It dynamically opens and closes UDP ports for secure multimedia connections, so you do not need to open a large range of ports.B.It supports SIP with NAT but not with PAT.C.It supports multimedia with or without NAT.D.It supports RTSP, H.323, Skinny, and CTIQBE.<br />
Answer:A C D<br />
10.What is the result if the WebVPN url-entry parameter is disabled?A.The end user is unable to access pre-defined URLs.B.The end user is unable to access any CIFS shares or URLs.C.The end user is able to access CIFS shares but not URLs.D.The end user is able to access pre-defined URLs.<br />
Answer:D<br />
11.You work as a network engineer at Pass4sure.com, you are asked to examine the current Modular Policy Framework configurations on the LA-ASA Adaptive Security Appliances using the Cisco Adaptive Security Device Manager (ASDM) utility. You need to answer the multiple-choice questions in this simulation by use of the appropriate Cisco ASDM configuration screens. A host on the partnernet network attempts to use FTP to download a file from InsideHost,which resides on the inside interface of the security appliance.What does the security appliance do with the traffic from the partnernet host?A.Sends it to the Cisco ASA Advanced Inspection and Prevention(AIP)-Security Services Module(SSM)for inspection before forwarding it to its destinationB.Sends it to the Cisco ASA 5500 Series Content Security and Control(CSC)SSM for inspection before forwarding it to its destinationC.Forwards it directly to its destinationD.Forwards it directly to its destination unless the connection limit is already met<br />
Answer:D<br />
12.You work as a network engineer at PassGuide.com, you are asked to examine the current Modular Policy Framework configurations on the LA-ASA Adaptive Security Appliances using the Cisco Adaptive Security Device Manager (ASDM) utility. You need to answer the multiple-choice questions in this simulation by use of the appropriate Cisco ASDM configuration screens. Which traffic does the security appliance inspect globally(regardless of the interface on which the traffic enters the security appliance)?(Choose 3)A.HTTPB.DNSC.GTPD.H.323 H.225<br />
Answer:A B D<br />
13.You work as a network engineer at PassGuidecom, you are asked to examine the current Modular Policy Framework configurations on the LA-ASA Adaptive Security Appliances using the Cisco Adaptive Security Device Manager (ASDM) utility. You need to answer the multiple-choice questions in this simulation by use of the appropriate Cisco ASDM configuration screens. A host on the partnernet network makes a VoIP call to 172.20.1.15,which is statically mapped to an IP phone on the inside network.What does the security appliance do with the VoIP traffic between host 172.20.1.15 and the host on the partnernet network?A.Sends it to the AIP-SSM for inspection before forwarding it to its destinationB.Sends it to the CSC-SSM for inspection before forwarding it to its destinationC.Forwards it directly to its destination unless the connection limit is already metD.Applies low latency queuing as it exits the partnernet interface<br />
Answer:D<br />
14.You work as a network engineer at PaGuide.com, you are asked to examine the current Modular Policy Framework configurations on the LA-ASA Adaptive Security Appliances using the Cisco Adaptive Security Device Manager (ASDM) utility. You need to answer the multiple-choice questions in this simulation by use of the appropriate Cisco ASDM configuration screens. A host on the outside network sends e-mail to the public e-mail server.What does the security appliance do with the traffic from the outside host?A.Sends it to the AIP-SSM for inspection before forwarding it to its destinationB.Sends it to the CSC-SSM for inspection before forwarding it to its destinationC.Forwards it directly to its destinationD.Forwards it directly to its destination unless the connection limit is already met<br />
Answer:A<br />
15.You work as a network engineer at PassGuide.com, you are asked to examine the current Modular Policy Framework configurations on the LA-ASA Adaptive Security Appliances using the Cisco Adaptive Security Device Manager (ASDM) utility. You need to answer the multiple-choice questions in this simulation by use of the appropriate Cisco ASDM configuration screens. A host on the partnernet network attempts to access the public web server via HTTP.What does the security appliance do with traffic from the partnernet?A.Sends it to the AIP-SSM for inspection before forwarding it to its destinationB.Sends it to the CSC-SSM for inspection before forwarding it to its destinationC.Forwards it directly to its destinationD.Forwards it directly to its destination unless the connection limit is already met<br />
Answer:C<br />
16.You work as a network engineer at PassGuide.com, you are asked to examine the current Modular Policy Framework configurations on the LA-ASA Adaptive Security Appliances using the Cisco Adaptive Security Device Manager (ASDM) utility. You need to answer the multiple-choice questions in this simulation by use of the appropriate Cisco ASDM configuration screens. A host on the outside network makes a VoIP call to a host on the inside network.What does the security appliance do with the traffic from the host on the outside network?A.Sends it to the AIP-SSM for inspection before forwarding it to its destinationB.Sends it to the CSC-SSM for inspection before forwarding it to its destinationC.Forwards it directly to its destinationD.Drops it<br />
Answer:D<br />
17.Which three tunneling protocols and methods are supported by the Cisco VPN Client? (Choose three.)A.IPsec over TCPB.IPsec over UDPC.ESPD.AH<br />
Answer:A B C<br />
18.Which two options are correct about the impacts of this configuration? (Choose two.) class-map INBOUND_HTTP_TRAFFIC<br />
match access-list TOINSIDEHOST<br />
class-map OUTBOUND_HTTP_TRAFFIC<br />
match access-list TOOUTSIDEHOST<br />
policy-map MYPOLICY<br />
class INBOUND_HTTP_TRAFFIC<br />
inspect http<br />
set connection conn-max 100<br />
policy-map MYOTHERPOLICY<br />
class OUTBOUND_HTTP_TRAFFIC<br />
inspect http<br />
service-policy MYOTHERPOLICY interface inside<br />
service-policy MYPOLICY interface outsideA.Traffic that matches access control list TOINSIDEHOST is subject to HTTP inspection and maximum connection limits.B.Traffic that enters the security appliance through the inside interface is subject to HTTP inspection.C.Traffic that enters the security appliance through the outside interface and matches access control list TOINSIDEHOST is subject to HTTP inspection and maximum connection limits.D.Traffic that enters the security appliance through the inside interface and matches access control list TOOUTSIDEHOST is subject to HTTP inspection.<br />
Answer:C D<br />
19.Take the following configuration shown in the exhibit carefully, what traffic will be logged to the AAA server?A.Only authenticated and authorized console connection information will be logged in the accounting database.B.All outbound TCP connection information will be logged in the accounting database.C.No information will be logged. This is not a valid configuration because TACACS+ connection information cannot be captured and logged.D.All connection information will be logged in the accounting database.<br />
Answer:B<br />
20.What are the two purposes of the same-security-traffic permit intra-interface command? (Choose two.)A.It allows all of the VPN spokes in a hub-and-spoke configuration to be terminated on a single interface.B.It enables Dynamic Multipoint VPN.C.It permits communication in and out of the same interface when the traffic is IPSec protected.D.It allows communication between different interfaces that have the same security level<br />
Answer:A C<br />
21.How many unique transforms will included in a single transform set while configuring a crypto ipsec transform-set command?A.threeB.twoC.fourD.one<br />
Answer:B<br />
22.Study the following exhibit carefully, the Cisco ASA adaptive security appliance is using software version 8.0 with the default configuration. Configure the interfaces displayed in the exhibit with the security levels that are shown, and enable the interfaces. Management-only mode is disabled on m0/0. Which two statements correctly describe these interfaces? (Choose two.)A.Interface m0/0 can access interface g0/2, but interface g0/2 cannot access interface m0/0 unless it is given permission.B.Interface g0/1 can access interface m0/0, and interface m0/0 can access interface g0/1.C.Interface g0/1 cannot access interface m0/0 unless it is given permission, and interface m0/0 cannot access interface g0/1 unless it is given permission.D.No traffic can flow between the g0/2 and g0/3 interfaces.<br />
Answer:A D<br />
23.John works as a network administrator , according to the following exhibit. Descriptions are added to class maps for each part of the modular policy framework. Which text should John add to the description command to describe the TO_SERVER class map?<br />
PG-asa1(config)#access-list UDP permit udp any any<br />
PG-asa1(config)#access-list TCP permit tcp any any<br />
PG-asa1(config)#access-list PUBLIC_WEB permit ip any 10.10.10.100 255.255.255.255 PG-asa1(config)#class-map ALL_VDP<br />
PG-asa1(config-cmap)#description &#8220;This class-map matches all UDP traffic&#8221;<br />
PG-asa1(config-cmap)#match access-list VDP<br />
PG-asa1(config-cmap)#class-map ALL_TCP<br />
PG-asa1(config-cmap)#description &#8220;This class-map matches all TCP traffic&#8221;<br />
PG-asa1(config-cmap)#match access-list TCP<br />
PG-asa1(config-cmap)#class-map ALL_WEB_SERVER<br />
PG-asa1(config-cmap)#description &#8220;This class-map matches all HTTP traffic&#8221;<br />
PG-asa1(config-cmap)#match port tcp eq http<br />
PG-asa1(config-cmap)#class-map TO_SERVER<br />
PG-asa1(config-cmap)#match access-list PUBLIC_WEBA.description &#8220;This class-map matches all TCP traffic for the public web server.&#8221;B.description &#8220;This class-map matches all HTTP traffic for the public web server.&#8221;C.description &#8220;This class-map matches all HTTPS traffic for the public web server.&#8221;D.description &#8220;This class-map matches all IP traffic for the public web server.&#8221;<br />
Answer:D<br />
24.What is the reason that you want to configure VLANs on a security appliance interface?A.for use in conjunction with device-level failover to increase the reliability of your security applianceB.for use in transparent firewall mode, where only VLAN interfaces are usedC.to increase the number of interfaces available to the network without adding additional physical interfaces or security appliancesD.for use in multiple context mode, where you can map only VLAN interfaces to contexts<br />
Answer:C<br />
25.By default, the AIP-SSM IPS software is accessible from the management port at IP address 10.1.9.201/24. Which CLI command should an administrator use to change the default AIP-SSM management port IP address?A.interfaceB.hw module 1 recoverC.setupD.hw module 1 setup<br />
Answer:C<br />
26.Which one of the following commands can provide detailed information about the crypto map configurations of a Cisco ASA adaptive security appliance?A.show ipsec saB.show crypto mapC.show run ipsec saD.show run crypto map<br />
Answer:D<br />
27.Which three potential groups are of users for WebVPN? (Choose three.)A.employees accessing specific internal applications from desktops and laptops not managed by ITB.administrators who need to manage servers and networking equipmentC.employees that only need occasional corporate access to a few applicationsD.users of a customer service kiosk placed in a retail store<br />
Answer:A C D<br />
28.Which three features can the Cisco ASA adaptive security appliance support? (Choose three.)A.BGP dynamic routingB.802.1Q VLANsC.OSPF dynamic routingD.static routes<br />
Answer:B C D<br />
29.Which one of the following commands will prevent all SIP INVITE packets, such as calling-party and request-method, from specific SIP endpoints?A.Use the match calling-party command in a class map. Apply the class map to a policy map that contains the match request-methods command.B.Group the match commands in a SIP inspection class map.C.Use the match request-methods command in an inspection class map. Apply the inspection class map to an inspection policy map that contains the match calling-party command.D.Group the match commands in a SIP inspection policy map.<br />
Answer:B<br />
30.Which two statements are true about multiple context mode? (Choose two.)A.Multiple context mode does not support IPS, IPsec, and SSL VPNs, or dynamic routing protocols.B.Multiple context mode enables you to create multiple independent virtual firewalls with their own security policies and interfaces.C.Multiple context mode enables you to add to the security appliance a hardware module that supports up to four independent virtual firewalls.D.When you convert from single mode to multiple mode, the security appliance automatically adds an entry for the admin context to the system configuration with the name &#8220;admin.&#8221;<br />
Answer:B D<br />
31.How do you ensure that the main interface does not pass untagged traffic when using subinterfaces?A.Use the vlan command on the main interface.B.Use the shutdown command on the main interfaceC.Omit the nameif command on the subinterfaceD.Omit the nameif command on the main interface.<br />
Answer:D<br />
32.For creating and configuring a security context, which three tasks are mandatory? (Choose three.)A.allocating interfaces to the contextB.assigning MAC addresses to context interfacesC.creating a context nameD.specifying the location of the context startup configuration<br />
Answer:A C D<br />
33.Study the exhibit carefully. Which two types of failover is this adaptive security appliance configured for? (Choose two.)<br />
PG-asa1# show failover Failover On Cable status:<br />
N/A-LAN-based failover enabled Failover unit Primary Failover LAN Interface:<br />
Ianfail GigabitEthernet0/2 (up) Unit Poll frequency 15 seconds, holdtime 45 seconds Interface Poll frequency 15 seconds Interface Policy 1 Monitored Interfaces 4 of 250 maximum Group 1 last failover at:<br />
15:54:49 UTC Sept 17 2006 Group 2 last failover at:<br />
15:55:00 UTC Sept 17 2006A.stateful failoverB.LAN-based failoverC.cable-based failoverD.Active/Active failover<br />
Answer:B D<br />
34.Which two descriptions are correct about configuring passive RIP on the security appliance based on the following exhibit? (Choose two.)A.You must specify a classful network IP address to define a network for the RIP routing process.B.If you enable passive RIP, all interfaces must operate in passive mode.C.There is no limit to the number of networks you can specify for the RIP routing process.D.Enabling passive RIP mode causes the security appliance to receive all RIP routing updates but send only a default route to neighboring routers.<br />
Answer:A C<br />
35.Which of these identifies basic settings for the security appliance, including a list of contexts?A.network configurationB.admin configurationC.system configurationD.primary configuration<br />
Answer:C<br />
36.Study the exhibit carefully. The security policy for PG Corporation allows only the following traffic through the corporate adaptive security appliance: &#8211;outbound NTP traffic from the inside network to any outside destination &#8211;FTP traffic from the inside network to the FTP server on the DMZ &#8211;outbound HTTP traffic from the inside network to any outside destination &#8211;FTP traffic from the outside 192.168.6.0/24 network to the FTP server on the DMZ &#8211;any HTTP traffic from the outside to the web server on the DMZ The network administrator configured access rules according to the security policy requirements but made two mistakes. Which are two mistakes? (Choose two.)A.missing ACEB.incorrect destination addressC.missing ACLD.incorrect order of ACLs<br />
Answer:B D<br />
37.An administrator wants to protect a DMZ web server from SYN flood attacks. Which command does not allow the administrator to place limits on the number of embryonic connections?A.set connectionB.natC.staticD.HTTP-map<br />
Answer:D<br />
38.Which option correctly describes the order to upgrade the license (activation key) for your security appliance from Cisco ASDM?A.Step 1 Obtain an activation key from http://www.cisco.com/go/license by providing the serial number for the security appliance as it appears on the chassis of the security appliance.<br />
Step 2 Reboot the security appliance to ensure that the image in flash and the running image are the same.<br />
Step 3 Go to Configuration > Device Management > System Image/Configuration > Activation Key in Cisco ASDM and enter the activation key as a four- or five-element hexadecimal string with no spaces.<br />
Step 4 Click Update Activation Key in the Activation Key panel.<br />
Step 5 Reload the security appliance to activate the flash activation key.B.Step 1 Obtain an activation key from http://www.cisco.com/go/license by providing the serial number for the security appliance as it appears in the show version command output. Step 2 Reboot the security appliance to ensure that the image in flash and the running image are the same.<br />
Step 3 Go to Configuration > Device Management > System Image/Configuration > Activation Key in Cisco ASDM and enter the activation key as a four- or five-element hexadecimal string with one space between each element.<br />
Step 4 Click Update Activation Key in the Activation Key panel.<br />
Step 5 Reload the security appliance to activate the flash activation key.C.Step 1 Obtain an activation key from http://www.cisco.com/go/license by providing the serial number for the security appliance as it appears in the show version command output. Step 2 Go to Configuration > Device Management > System Image/Configuration > Activation Key in Cisco ASDM and enter the activation key as a three- or four-element hexadecimal string with one space between each element.<br />
Step 3 Click Update Activation Key in the Activation Key panel.<br />
Step 4 Click Save in the Cisco ASDM toolbar.D.Step 1 Obtain an activation key from http://www.cisco.com/go/license by providing the serial number for the security appliance as it appears on the chassis of the security appliance.<br />
Step 2 Go to Configuration > Device Management > System Image/Configuration > Activation Key in Cisco ASDM and enter the activation key as a four- or five-element hexadecimal string with no spaces.<br />
Step 3 Click Update Activation Key in the Activation Key panel.<br />
Step 4 Click Save in the Cisco ASDM toolbar.<br />
Answer:B<br />
39.You are a network administrator for the PG company. After the primary adaptive security appliance failed, the secondary adaptive security appliance was automatically activated. You fixed the problem. Now you would like to restore the primary to &#8220;active&#8221; status. When issued on the primary adaptive security appliance, which command would reactivate the primary adaptive security appliance and return it to &#8220;active&#8221; status?A.failover secondary standby group 1B.failover primary activeC.failover active group 1D.failover secondary group 1<br />
Answer:C<br />
40.Which two scenarios correctly describe the impact of the configuration shown in the exhibit? (Choose two.)A.User addison enters the login command at the > prompt and logs in with the correct username and password when prompted. User addison can then enter the global configuration mode on the security appliance.B.User carter enters the enable command at the > prompt and logs in with the correct username and password when prompted. User carter can then enter the global configuration mode.C.User carter enters the login command at the > prompt and logs in with the correct username and password when prompted. User carter can then enter the global configuration mode on the security appliance.D.User kenny enters the enable command at the > prompt and logs in with the correct username and password when prompted. User kenny can then enter the global configuration mode.<br />
Answer:A D<br />
41.While configuring a crypto map, which command will be used to specify the peer to which IPsec-protected traffic could be forwarded?A.crypto-map policy 10 set 192.168.7.2B.crypto map set peer 192.168.7.2C.crypto map 20 set-peer insidehostD.crypto map peer7 10 set peer 192.168.7.2<br />
Answer:D </p>
]]></content:encoded>
			<wfw:commentRss>http://www.ccsp.name/passguide-ccsp-642-524-pdf-demo/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Actualtest cisco ccsp 642-545</title>
		<link>http://www.ccsp.name/actualtest-cisco-ccsp-642-545</link>
		<comments>http://www.ccsp.name/actualtest-cisco-ccsp-642-545#comments</comments>
		<pubDate>Mon, 15 Dec 2008 12:43:51 +0000</pubDate>
		<dc:creator>Cisco</dc:creator>
				<category><![CDATA[Practice Tests]]></category>

		<guid isPermaLink="false">http://www.ccsp.name/?p=99</guid>
		<description><![CDATA[CCSP 642-545 Simulation
Actualtests  642-545 Exam will provide you with exam simulation questions and actual answers that reflect the actual exam. These Actualtests  642-545 simulation questions and answers provide you with the experience of taking the actual test. Actualtests  642-545 Exam is not just simulation questions and answers. They are your access to [...]]]></description>
			<content:encoded><![CDATA[<p>CCSP 642-545 Simulation<br />
Actualtests  642-545 Exam will provide you with exam simulation questions and actual answers that reflect the actual exam. These Actualtests  642-545 simulation questions and answers provide you with the experience of taking the actual test. Actualtests  642-545 Exam is not just simulation questions and answers. They are your access to high technical expertise and accelerated learning capacity. Actualtests  642-545 questions have detailed explanations for every answer and thus ensures that you fully understand the questions and the concept behind the questions.</p>
<p>Product 642-545 Description</p>
<p>Exam Number:642-545<br />
Exam Name:Implementing Cisco Security Monitoring, Analysis and Response System : 642-545 Exam<br />
Market Price:$129.99<br />
Member Price:$99.99<br />
Where can you buy the 642-545 exam online?<br />
We recommend Pass4sure 642-545 Testing Engine which will help you pass the 642-545 exam.</p>
<p>Actualtests Demo 642-545 Exam Details<br />
Comprehensive questions with complete details about Actualtests  642-545 exam<br />
Tested by many real exams before publishing<br />
Verified Actualtests  642-545 Answers Researched by Industry Experts<br />
Actualtests  642-545 exam questions accompanied by exhibits<br />
Drag and Drop questions as experienced in the Real Actualtests  642-545 Exams<br />
How to prepare for 642-545 exam?<br />
We designed Actualtests  642-545 Simulation kit to help you get certified effortlessly. Now you don&#8217;t need to spend your time and money searching for Actualtests  642-545 certification materials, books, etc., Actualtests  642-545 exam simulation contains everything you need to get certified. Just follow the instructions, focus on the study material and getting certified will be easy.<br />
Free down:<a href="http://www.ccsp.name/pass4sure-cisco-ccsp-642-545-295/">pass4sure 642-545</a><br />
Free down:<a href="http://www.ccsp.name/testking-cisco-ccsp-642-545/">testking 642-545</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ccsp.name/actualtest-cisco-ccsp-642-545/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
