Online Cisco Certification Exam Braindumps

Archive for June 11th, 2007

Filed Under (Cisco certification exam dumps) by verygoodchang on June-11-2007

All guys who wanted to get any IT exam certifications,the cisco exam blog which you are visiting specially provided the pass4sure cisco certification exam braindumps, including the newest pass4sure exam information, p4s product update and so on. in a word, any p4s cisco information can get on this cisco test blog. paying attention to this blog as your cisco certification exam guides. of course, if having any questions, don’t leave word,just send email to support@pass4sure.com. in addition, the following listed the latest released p4s cisco exams:
Cisco 642-415 UCAD Exam
642-181 PRSDI Exam
Cisco 646-363 CXFA
642-373 Cisco CXFS Exam
642-383 CXFF Exam


Filed Under (Cisco certification exam dumps) by verygoodchang on June-11-2007

When I issued other exam material just now,my colleague tell me that pass4sure 646-590 material have prepared,the page for 646-590 exam published later.The 646-590 objective details can be known from pass4sure exam certer.


Filed Under (CCSP) by verygoodchang on June-11-2007

The cisco 646-551 SND exam forms the foundation of the Cisco Certified Security Professional, Cisco Firewall Specialist, Cisco IPS Specialist, and Cisco VPN Specialist certifications. Candidates can prepare for??642-551 exam by taking the SND course.??The 642-551??exam includes simulations and tests a candidate’s knowledge and ability to describe, configure, and verify basic security features of Cisco Layer 2 devices, Cisco Routers, Cisco IDS/IPS Sensors, Cisco VPN 3000 Concentrators, and Cisco PIX Security Appliances.

?????????????????????????????????????????????????????????????????????? 642-502?????????????????????????? 642-503

?????????????????????????????????????????????????????????????????????? 642-521???????????????????????? ??642-522

?????????????????????????????????????????????????????????????????????? 642-542???????????????????????? ??642-551

???????????????????????????????????????????????????????????????????????????????????????????????? 642-552

1.Which authentication method is based on the 802.1x authentication framework, and mitigates several of the weaknesses by using dynamic WEP and sophisticated key management on a per-packet basis?
A: PAP
B: CHAP
C: LEAP
D: ARAP

Correct Answers:?? C
2.Which command sets the minimum length of all Cisco IOS passwords?
A: password min-length length
B: min-length security length
C: enable secret min-length
D: security passwords min-length length

Correct Answers:?? D


Filed Under (CCSP) by verygoodchang on June-11-2007

Exam 642-542 test every examinee the knowledge and skills needed to use the principles and axioms presented in the SAFE SMR, Enterprise, IP Telephony and Wireless LAN White Papers, and to implement them on specific security devices. The primary focus about 642-542 exam is on the labs, which allows the student to build complete end-to-end security solutions using SAFE White Papers as the blueprint. The configuration and functionality of the following devices for 642-542 in a SAFE SMR network are described in detail: IOS routers, PIX Firewalls, VPN Concentrators, Cisco IDS Sensors, Cisco Security Agent and the Cisco VPN Client. Basic implementation of a SAFE wireless LAN is also covered.

???????????????????????????????????????????????????????????????????? 642-502???????????????????? 642-503

???????????????????????????????????????????????????????????????????? 642-521??????????????????????642-522

???????????????????????????????????????????????????????????????????? 642-542???????????????????? 642-551

???????????????????????????????????????????????????????????????????????????????????????? 642-552

1.What is the primary method of mitigating port redirection attacks?
A: keep firewalls up to date with the latest patches and fixes
B: do not allow trust models
C: keep OS and applications up to date with the latest patches and fixes
D: use proper trust models
Correct Answers:?? D
2.How are password attacks mitigated in the SAFE SMR midsize network design corporate Internet module?
A: filtering at the ISP, edge router, and corporate firewall
B: RFC 2827 and 1918 filtering at ISP edge and midsize network edge router
C: e-mail content filtering, HIDS, and host-based virus scanning
D: OS and IDS detection
E: CAR at the ISP edge and TCP setup controls at the firewall
Correct Answers:?? D

Filed Under (CCSP) by verygoodchang on June-11-2007

The Securing Networks with PIX and ASA exam is one of the exams associated with the Cisco Certified Security Professional and the Cisco Firewall Specialist certifications. Candidates can prepare for??642-522 exam by taking the SNPA v4.0 course. This exam includes simulations and tests a candidate’s knowledge and ability to describe, configure, verify and manage the Cisco PIX and ASA security appliance products. The 642-552 exam objective details???Install and configure a security appliance for basic network connectivity,Configure a security appliance to restrict inbound traffic from untrusted sources,Configure a security appliance to provide secure connectivity using site-to-site VPNs,Configure a security appliance to provide secure connectivity using remote access VPNs,Configure transparent firewall, virtual firewall, and high availability firewall features on a security appliance,Configure AAA services for access through a security appliance,Configure routing and switching on a security appliance,Configure a modular policy on a security appliance,Monitor and manage an installed security appliance.

????????????????????????????????????????????????????????????????642-502?????????????????????? 642-503

?????????????????????????????????????????????????????????????? 642-521????????????????????????642-522

?????????????????????????????????????????????????????????????? 642-542????????????????????????642-551

???????????????????????????????????????????????????????????????????????????????????? 642-552

1.In the Cisco ASA 5500 series, what is the flash keyword aliased to?
A: Disk0
B: Disk1
C: both Disk0 and Disk1
D: Flash0
E: Flash1
Correct Answers:?? A
2.During failover, which security appliance attribute does not change?
A: failover unit status-active and standby
B: active and standby interfaces-IP address
C: failover unit type-primary and secondary
D: active and standby interfaces-MAC address
Correct Answers:?? C

Filed Under (CCSP) by verygoodchang on June-11-2007

The Cisco Secure PIX Firewall Advanced exam (CSPFA 642-521) is one of the exams associated with the Cisco Certified Security Professional and the Cisco Firewall Specialist certifications. Candidates can prepare for this exam by taking the CSPFA v3.2 course.??The 642-521??exam includes simulations and tests a candidate’s knowledge and ability to describe, configure, verify and manage the PIX Firewall product family. CCNA or CCDA recertification candidates who pass the 642-521 CSPFA exam will be considered recertified at the CCNA or CCDA level. The exam 642-521 register URL???Pearson VUE or Prometric.

???????????????????????????????????????????????????????????????????? 642-502???????????????????? 642-503

???????????????????????????????????????????????????????????????????? 642-521??????????????????????642-522

???????????????????????????????????????????????????????????????????? 642-542??????????????????????642-551

???????????????????????????????????????????????????????????????????????????????????????????? 642-552

1.What is the primary type of intrusion prevention technology used by Cisco IPS security appliances?
A: profile-based
B: rule-based
C: signature-based
D: protocol analysis-based
Correct Answers:?? C
2.A mission critical server application embeds a private IP address and port number in the payload of packets that is used by the client to reply to the server. Why is implementing NAT over the Internet supporting this type of application an issue?
A: Embedded IP addresses causes NAT to do extensive packet manipulation. This process is very time intensive and the added delay causes the connection in these types of applications to time out and fail.
B: When the client attempts to reply to the server using the embedded private IP address instead of the public IP address mapped by NAT, the embedded private IP address will not be routable over the Internet.
C: NAT traversal can’t be used for embedded IP addresses. Mission critical applications typically use NAT transversal to ensure stable timely connections, but not when embedded IP addresses and ports are used.
D: Using NAT makes troubleshooting difficult. You must know the IP address assigned to a device on its NIC and its translated address; it takes too long to determine the source and destination of an embedded IP address, and this delay is not appropriate for mission critical applications.
Correct Answers:?? B
3.What is the first step you need to perform on a router when configuring role-based CLI?
A: place the router in global configuration mode
B: create a parser view called root view
C: enable role-based CLI globally on the router using the privilege exec level Cisco IOS command.
D: enable the root view on the router
E: log in to the router as the “root” user

Correct Answers:?? D


Filed Under (CCSP) by verygoodchang on June-11-2007

The Gateway Gatekeeper 642-453 GWGK is the exam associated with the CCVP certification. Candidates can prepare for this exam by taking the Gateway Gatekeeper (GWGK) course.??The 642-503??exam tests a candidate’s knowledge of the implementation of Cisco gateways and gatekeepers, including integration of a VoIP network to both PSTN and TDM equipment. Topics for exam 642-503 covered include implementing dial plans and advanced gateway features such as SRST and DSP resources, implementing gatekeepers and directory gatekeepers to provide hierarchical dial plan resolution, and call admission control.

?????????????????????????????????????????????????????????????????????????? 642-502???????????????????????????????? 642-503

?????????????????????????????????????????????????????????????????????????? 642-521??????????????????????????????????642-522

?????????????????????????????????????????????????????????????????????????? 642-542??????????????????????????????????642-551

???????????????????????????????????????????????????????????????????????????????????????????????????? 642-552

1.When configuring ACS 4.0 Network Access Profiles (NAPs), which three things can be used to determine how an access request is classified and mapped to a profile? (Choose three.)
A:Network Access Filters (NAFs)
B:RADIUS Authorization Components (RACs)
C:the authentication method
D:the protocol types
E:advance filtering
F:RADIUS VSAs
Correct Answers:?? A, D, E
2.When you configure a site-to-site IPsec VPN tunnel, which configuration must be the exact reverse (mirror image) of the other IPsec peer?
A: IPsec transform set
B: ISAKMP policy
C: crypto ACL
D: pre-shared key
E: crypto map
F: static route
Correct Answers:?? C
3.When configuring FPM, what should be the next step after the PHDFs have been loaded?
A: Define a stack of protocol headers.
B: Define a traffic policy.
C: Define a service policy.
D: Define a class map of type “access-control” for classifying packets.
E: Reload the router.
F: Save the PHDFs to startup-config.
Correct Answers:?? A
4.When you implement IBNS (802.1x authentication), what is defined using the Tunnel-Private-Group-ID (81) RADIUS attribute?
A: the EAP type
B: the shared secret key
C: the ACL name
D: the VLAN name
E: the NAP
F: the NAF

Correct Answers:?? D


Filed Under (CCSP) by verygoodchang on June-11-2007

Cisco 642-502 exam name:Securing Networks with Cisco Routers and Switches Exam(SNRS).The Securing Networks with Cisco Routers and Switches exam is one of the exams associated with the Cisco Certified Security Professional certification. Candidates can prepare for this exam by taking the SNRS v1.0 course.??The 642-502??exam includes simulations and tests a candidate’s knowledge and ability to secure networks using Cisco routers and switches.

???????????????????????????????????????????????????? 642-502???????????????????????? 642-503

???????????????????????????????????????????????????? 642-521?????????????????????? ??642-522

???????????????????????????????????????????????????? 642-542???????????????????????? 642-551

???????????????????????????????????????????????????????????? ??642-552