Exit demo 642-542 Cisco SAFE Implementation PDF format · free preview

Cisco 642-542 - Questions & Answers

Free preview · every answer includes a full explanation

Product page: https://prepkeys.com/642-542.html

Question 1
Single choice

How many attacks should the NIDS appliance detect in the SAFE SMR midsize network design midsize network campus module?

A.

a large amount, due to outside placement of the edge router

B.

a moderate amount, depending on access through the Internet module

C.

a large amount, due to outside placement of the Internet firewall

D.

very few

Question 2
Multiple choice

Which threats are expected in the SAFE SMR remote user network environment? Choose two.

A.

port redirection attacks

B.

trust exploitation

C.

man in the middle attacks

D.

network reconnaissance

Question 3
Multiple choice

According to SAFE guidelines for implementing VPN IPSec, which of these statements are true? (Select two.)

A.

Wildcard preshared keys should be used for site-to-site device authentication.

B.

Digital certificates are not tied to IP addresses but to unique, signed information on the device that is validated by the CA.

C.

Digital certificates provide nonrepudiation but no public/private key pair aging.

D.

Digital certificates scale better but require additional administrative resources to deploy and manage.

E.

Unique preshared keys are recommended between two devices and can scale in a large network.

Question 4
Multiple choice

The ip verify reverse-path command implements which of the following on the PIX Firewall? Choose two.

A.

provides session state information based on destination address

B.

performs a route lookup based on the source address

C.

provides ingress filtering

D.

performs a route lookup based on the destination address

E.

provides session state information based on source address

Question 5
Multiple choice

How are DoS attacks mitigated in the SAFE SMR small network corporate Internet module? Choose two.

A.

CAR at ISP edge

B.

virus scanning at the host level

C.

NIDS

D.

HIDS on the public servers

E.

TCP setup controls at the firewall to limit exposure

Question 6
Single choice

Which IDS guidelines should be followed, according to SAFE SMR?

A.

use shunning no longer than 15 minutes

B.

use shunning on only UDP traffic, as it is more difficult to spoof than TCP

C.

use shunning on only TCP traffic, as it is more difficult to spoof than UDP

D.

use TCP shunning as opposed to TCP resets

Question 7
Multiple choice

Which are key devices in the SAFE SMR remote user network? Choose two.

A.

broadband access device

B.

Layer 2 switch

C.

Layer 3 switch

D.

firewall with VPN support

E.

NIDS

Question 8
Single choice

According to SAFE SMR, which Cisco router is best suited for a remote office?

A.

7100 and 7200 series

B.

800 and 900 series

C.

1700 series

D.

2600 and 3600 series

Question 9
Single choice

What method helps mitigate the threat of IP spoofing?

A.

SNMP polling

B.

logging

C.

Layer 2 switching

D.

access control

Question 10
Single choice

What is the primary identity component in a Cisco security solution?

A.

Cisco IOS Firewalls

B.

Cisco VPN Concentrators

C.

Cisco IDS Sensors

D.

Cisco PIX Firewalls

E.

Cisco Access Control servers

Showing 10 of 218 questions · Unlock the full set