Cisco 642-515 - Questions & Answers
Free preview · every answer includes a full explanation
Product page: https://prepkeys.com/642-515.html
The following exhibit shows a Cisco ASA security appliance configured to participate in a VPN cluster.
According to the exhibit, to which value will you set the priority to increase the chances of this Cisco ASA security appliance becoming the cluster master?

You work as a network administrator for your company. Study the exhibit carefully. ASDM is short for Adaptive Security Device Manager. You are responsible for multiple remote Cisco ASA security appliances administered through Cisco ASDM. Recently, you have been tasked to configure one of these Cisco ASA security appliances for SSL VPNs and are requiring a client certificate, as shown.
How will this configuration affect your next ASDM connection to this Cisco ASA security appliance?

Study the following exhibit carefully. You work as the network administrator of a corporate Cisco ASA security appliance with a Cisco ASA AIP-SSM. You are asked to use the AIP-SSM to protect corporate DMZ web servers. The AIP-SSM has been configured, and a service policy has been configured to identify the traffic to be passed to the AIP-SSM.
On which two interfaces would application of the service policy for the AIP-SSM be most effective while causing the least amount of impact to Cisco ASA security appliance performance? (Choose two.)

Observe the exhibit below carefully. You have been tasked to configure the Cisco ASA security appliance as the hub in a hub-and-spoke site-to-site VPN.
Which configurations can enable traffic to flow between spokes?

Refer to the exhibit. You have configured a Layer 7 policy map to match the size of HTTP header fields that are traversing the network.
Based on this configuration, will HTTP headers that are greater than 200 bytes be logged?

You work as a network security administrator for your company. Now, you are asked to configure the corporate Cisco ASA security appliance to take the following steps on its outside interface:
--rate limit all IP traffic from telecommuting system engineers to the insidehost
--drop all HTTP requests from the Internet to the web server that have a body length greater than 1000 bytes
--prevent users on network 192.168.6.0/24 from using the FTP PUT command to store .exe files on the
FTP server
In order to achieve this objective, which set of Modular Policy Framework components will be included?

Cisco ASA 5500 Series Adaptive Security Appliances are easy-to-deploy solutions that integrate world-class firewall, Unified Communications (voice/video) security, SSL and IPsec VPN, intrusion prevention (IPS), and content security services in a flexible, modular product family. You are asked to configure a Cisco ASA 5505 Adaptive Security Appliance as an Easy VPN hardware client. In the process of configuration, you defined a list of backup servers for the security appliance to use. After several hours of being connected to the primary VPN server, the security appliance fails. You notice that your Easy VPN hardware client has now connected to a backup server that is not defined within the configuration of the client.
Where did your Easy VPN hardware client get this backup server?

You are the network administrator for your company. Study the exhibit carefully. You are responsible for a Cisco ASA security appliance configured with a local CA.
According to the exhibit below, what is the reason that the user student1 will use this password?

Observe the following exhibit carefully. When TCP connections are tunneled over another TCP connection and latency exists between the two endpoints, each TCP session would trigger a retransmission, which can quickly spiral out of control when the latency issues persist. This issue is often called TCP-over-TCP meltdown.
According to the presented Cisco ASDM configuration, which Cisco ASA security appliance configuration will most likely solve this problem?

You are a network engineer of your company. Recently, you have been tasked to configure Cisco ASA security appliance for EIGRP routing.
Which two Cisco ASDM configurations will add these networks to the configuration of EIGRP according to the information displayed in the exhibit? (Choose two.)










