Online Cisco Certification Exam Braindumps

Archive for the ‘CCSP’ Category

Filed Under (CCSP) by verygoodchang on July-28-2008

Pass4sure CCSP training program is ideal for anyone looking to pursue a Cisco Certified Security Professional certification designation since cisco CCSP course features everything that you will encounter in the certification exam. Pass4sure CCSP training samples comply with the exam objectives, thus helping you successfully prepare for the big exam that will improve your IT career. Since p4s CCSP training is self-paced and self-guided, you get to choose when you want to learn. Simply pop in our CCSP training into you PC or laptop and begin your learning journey. Busy IT professionals will love the fact that they do not have to miss work to study for the certification exam.

With pass4sure online CCSP training samples, you will be able to learn how to successfully prepare for the Cisco Certified Security Professional certification exam all on you own with the help of certified Cisco subject matter experts, who have years of experience within the IT field. Pass4sure online CCSP training feature our certified instructors in full-motion videos that make it seem as if they are teaching right in front of you. The CCSP online training course also features in-depth discussions, interactive lectures, quizzes and assessments to track and monitor your progress and hands-on experience that gets you working with the software. Take p4s CCSP online training course today and pave the road for a better tomorrow!


Filed Under (CCSP) by verygoodchang on July-16-2007

For cisco exam 642-521 real exam,having 55-65 questions and only single question type,Cisco Secure PIX Firewall Advanced for this exam name.pass4sure 642-521 exam braindump have 192 Q & A specially for this exam.including free download exam samples.quicklily use these examination questions for your cisco real exams.


Filed Under (CCSP) by verygoodchang on June-12-2007

Cisco exam??642-552 Name: Securing Cisco Networking Devices (SND),The Securing Cisco Network Devices 642-552 SND is the CCSP??exam associated with the Cisco Certified Security Professional, Cisco Firewall Specialist, Cisco IPS Specialist, and Cisco VPN Specialist certifications.Preparing for 642-552 exam by taking the Securing Cisco Network Devices v2.0 (SND) course. 642-552 exam??include knowledge of securing Cisco routers and switches and their associated networks. Topics covered include; Security threats facing modern network infrastructures, Securing Cisco routers, Implementing basic AAA, Using ACLs to mitigate router and network threats, Implementing secure management and reporting, Mitigating common Layer 2 attacks, and Implementing Cisco IOS Firewall features, Cisco IOS IPS features, and IPsec VPN features using Cisco Security Device Manager.

?????????????????????????????????????????????????????????????????????????????????????????????? 642-552??????????????????????????????642-564

??????????????????????????????????????????????????????????????????????????????????????????????????642-582?????????????????????????? 642-587

?????????????????????????????????????????????????????????????????????????????????????????????? ??642-642?????????????????????????? 642-691

???????????????????????????????????????????????????????????????????????????????????????????????? 642-825?????????????????????????? 642-845


Filed Under (CCSP) by verygoodchang on June-11-2007

The cisco 646-551 SND exam forms the foundation of the Cisco Certified Security Professional, Cisco Firewall Specialist, Cisco IPS Specialist, and Cisco VPN Specialist certifications. Candidates can prepare for??642-551 exam by taking the SND course.??The 642-551??exam includes simulations and tests a candidate’s knowledge and ability to describe, configure, and verify basic security features of Cisco Layer 2 devices, Cisco Routers, Cisco IDS/IPS Sensors, Cisco VPN 3000 Concentrators, and Cisco PIX Security Appliances.

?????????????????????????????????????????????????????????????????????? 642-502?????????????????????????? 642-503

?????????????????????????????????????????????????????????????????????? 642-521???????????????????????? ??642-522

?????????????????????????????????????????????????????????????????????? 642-542???????????????????????? ??642-551

???????????????????????????????????????????????????????????????????????????????????????????????? 642-552

1.Which authentication method is based on the 802.1x authentication framework, and mitigates several of the weaknesses by using dynamic WEP and sophisticated key management on a per-packet basis?
A: PAP
B: CHAP
C: LEAP
D: ARAP

Correct Answers:?? C
2.Which command sets the minimum length of all Cisco IOS passwords?
A: password min-length length
B: min-length security length
C: enable secret min-length
D: security passwords min-length length

Correct Answers:?? D


Filed Under (CCSP) by verygoodchang on June-11-2007

Exam 642-542 test every examinee the knowledge and skills needed to use the principles and axioms presented in the SAFE SMR, Enterprise, IP Telephony and Wireless LAN White Papers, and to implement them on specific security devices. The primary focus about 642-542 exam is on the labs, which allows the student to build complete end-to-end security solutions using SAFE White Papers as the blueprint. The configuration and functionality of the following devices for 642-542 in a SAFE SMR network are described in detail: IOS routers, PIX Firewalls, VPN Concentrators, Cisco IDS Sensors, Cisco Security Agent and the Cisco VPN Client. Basic implementation of a SAFE wireless LAN is also covered.

???????????????????????????????????????????????????????????????????? 642-502???????????????????? 642-503

???????????????????????????????????????????????????????????????????? 642-521??????????????????????642-522

???????????????????????????????????????????????????????????????????? 642-542???????????????????? 642-551

???????????????????????????????????????????????????????????????????????????????????????? 642-552

1.What is the primary method of mitigating port redirection attacks?
A: keep firewalls up to date with the latest patches and fixes
B: do not allow trust models
C: keep OS and applications up to date with the latest patches and fixes
D: use proper trust models
Correct Answers:?? D
2.How are password attacks mitigated in the SAFE SMR midsize network design corporate Internet module?
A: filtering at the ISP, edge router, and corporate firewall
B: RFC 2827 and 1918 filtering at ISP edge and midsize network edge router
C: e-mail content filtering, HIDS, and host-based virus scanning
D: OS and IDS detection
E: CAR at the ISP edge and TCP setup controls at the firewall
Correct Answers:?? D

Filed Under (CCSP) by verygoodchang on June-11-2007

The Securing Networks with PIX and ASA exam is one of the exams associated with the Cisco Certified Security Professional and the Cisco Firewall Specialist certifications. Candidates can prepare for??642-522 exam by taking the SNPA v4.0 course. This exam includes simulations and tests a candidate’s knowledge and ability to describe, configure, verify and manage the Cisco PIX and ASA security appliance products. The 642-552 exam objective details???Install and configure a security appliance for basic network connectivity,Configure a security appliance to restrict inbound traffic from untrusted sources,Configure a security appliance to provide secure connectivity using site-to-site VPNs,Configure a security appliance to provide secure connectivity using remote access VPNs,Configure transparent firewall, virtual firewall, and high availability firewall features on a security appliance,Configure AAA services for access through a security appliance,Configure routing and switching on a security appliance,Configure a modular policy on a security appliance,Monitor and manage an installed security appliance.

????????????????????????????????????????????????????????????????642-502?????????????????????? 642-503

?????????????????????????????????????????????????????????????? 642-521????????????????????????642-522

?????????????????????????????????????????????????????????????? 642-542????????????????????????642-551

???????????????????????????????????????????????????????????????????????????????????? 642-552

1.In the Cisco ASA 5500 series, what is the flash keyword aliased to?
A: Disk0
B: Disk1
C: both Disk0 and Disk1
D: Flash0
E: Flash1
Correct Answers:?? A
2.During failover, which security appliance attribute does not change?
A: failover unit status-active and standby
B: active and standby interfaces-IP address
C: failover unit type-primary and secondary
D: active and standby interfaces-MAC address
Correct Answers:?? C

Filed Under (CCSP) by verygoodchang on June-11-2007

The Cisco Secure PIX Firewall Advanced exam (CSPFA 642-521) is one of the exams associated with the Cisco Certified Security Professional and the Cisco Firewall Specialist certifications. Candidates can prepare for this exam by taking the CSPFA v3.2 course.??The 642-521??exam includes simulations and tests a candidate’s knowledge and ability to describe, configure, verify and manage the PIX Firewall product family. CCNA or CCDA recertification candidates who pass the 642-521 CSPFA exam will be considered recertified at the CCNA or CCDA level. The exam 642-521 register URL???Pearson VUE or Prometric.

???????????????????????????????????????????????????????????????????? 642-502???????????????????? 642-503

???????????????????????????????????????????????????????????????????? 642-521??????????????????????642-522

???????????????????????????????????????????????????????????????????? 642-542??????????????????????642-551

???????????????????????????????????????????????????????????????????????????????????????????? 642-552

1.What is the primary type of intrusion prevention technology used by Cisco IPS security appliances?
A: profile-based
B: rule-based
C: signature-based
D: protocol analysis-based
Correct Answers:?? C
2.A mission critical server application embeds a private IP address and port number in the payload of packets that is used by the client to reply to the server. Why is implementing NAT over the Internet supporting this type of application an issue?
A: Embedded IP addresses causes NAT to do extensive packet manipulation. This process is very time intensive and the added delay causes the connection in these types of applications to time out and fail.
B: When the client attempts to reply to the server using the embedded private IP address instead of the public IP address mapped by NAT, the embedded private IP address will not be routable over the Internet.
C: NAT traversal can’t be used for embedded IP addresses. Mission critical applications typically use NAT transversal to ensure stable timely connections, but not when embedded IP addresses and ports are used.
D: Using NAT makes troubleshooting difficult. You must know the IP address assigned to a device on its NIC and its translated address; it takes too long to determine the source and destination of an embedded IP address, and this delay is not appropriate for mission critical applications.
Correct Answers:?? B
3.What is the first step you need to perform on a router when configuring role-based CLI?
A: place the router in global configuration mode
B: create a parser view called root view
C: enable role-based CLI globally on the router using the privilege exec level Cisco IOS command.
D: enable the root view on the router
E: log in to the router as the “root” user

Correct Answers:?? D


Filed Under (CCSP) by verygoodchang on June-11-2007

The Gateway Gatekeeper 642-453 GWGK is the exam associated with the CCVP certification. Candidates can prepare for this exam by taking the Gateway Gatekeeper (GWGK) course.??The 642-503??exam tests a candidate’s knowledge of the implementation of Cisco gateways and gatekeepers, including integration of a VoIP network to both PSTN and TDM equipment. Topics for exam 642-503 covered include implementing dial plans and advanced gateway features such as SRST and DSP resources, implementing gatekeepers and directory gatekeepers to provide hierarchical dial plan resolution, and call admission control.

?????????????????????????????????????????????????????????????????????????? 642-502???????????????????????????????? 642-503

?????????????????????????????????????????????????????????????????????????? 642-521??????????????????????????????????642-522

?????????????????????????????????????????????????????????????????????????? 642-542??????????????????????????????????642-551

???????????????????????????????????????????????????????????????????????????????????????????????????? 642-552

1.When configuring ACS 4.0 Network Access Profiles (NAPs), which three things can be used to determine how an access request is classified and mapped to a profile? (Choose three.)
A:Network Access Filters (NAFs)
B:RADIUS Authorization Components (RACs)
C:the authentication method
D:the protocol types
E:advance filtering
F:RADIUS VSAs
Correct Answers:?? A, D, E
2.When you configure a site-to-site IPsec VPN tunnel, which configuration must be the exact reverse (mirror image) of the other IPsec peer?
A: IPsec transform set
B: ISAKMP policy
C: crypto ACL
D: pre-shared key
E: crypto map
F: static route
Correct Answers:?? C
3.When configuring FPM, what should be the next step after the PHDFs have been loaded?
A: Define a stack of protocol headers.
B: Define a traffic policy.
C: Define a service policy.
D: Define a class map of type “access-control” for classifying packets.
E: Reload the router.
F: Save the PHDFs to startup-config.
Correct Answers:?? A
4.When you implement IBNS (802.1x authentication), what is defined using the Tunnel-Private-Group-ID (81) RADIUS attribute?
A: the EAP type
B: the shared secret key
C: the ACL name
D: the VLAN name
E: the NAP
F: the NAF

Correct Answers:?? D


Filed Under (CCSP) by verygoodchang on June-11-2007

Cisco 642-502 exam name:Securing Networks with Cisco Routers and Switches Exam(SNRS).The Securing Networks with Cisco Routers and Switches exam is one of the exams associated with the Cisco Certified Security Professional certification. Candidates can prepare for this exam by taking the SNRS v1.0 course.??The 642-502??exam includes simulations and tests a candidate’s knowledge and ability to secure networks using Cisco routers and switches.

???????????????????????????????????????????????????? 642-502???????????????????????? 642-503

???????????????????????????????????????????????????? 642-521?????????????????????? ??642-522

???????????????????????????????????????????????????? 642-542???????????????????????? 642-551

???????????????????????????????????????????????????????????? ??642-552


Filed Under (CCSP) by verygoodchang on April-24-2007

Cisco exam answers about 642-552

If you want to get the answers of exam 642-552,please enter the site of pass4sure.It can give you the best service.Its product is best of many site about providing exam 642-552 information.

1.What is the primary type of intrusion prevention technology used by Cisco IPS security appliances?

A: profile-based
B: rule-based
C: signature-based
D: protocol analysis-based
Correct Answers:?? C

2.A mission critical server application embeds a private IP address and port number in the payload of packets that is used by the client to reply to the server. Why is implementing NAT over the Internet supporting this type of application an issue?

A: Embedded IP addresses causes NAT to do extensive packet manipulation. This process is very time intensive and the added delay causes the connection in these types of applications to time out and fail.
B: When the client attempts to reply to the server using the embedded private IP address instead of the public IP address mapped by NAT, the embedded private IP address will not be routable over the Internet.
C: NAT traversal can’t be used for embedded IP addresses. Mission critical applications typically use NAT transversal to ensure stable timely connections, but not when embedded IP addresses and ports are used.
D: Using NAT makes troubleshooting difficult. You must know the IP address assigned to a device on its NIC and its translated address; it takes too long to determine the source and destination of an embedded IP address, and this delay is not appropriate for mission critical applications.
Correct Answers:?? B

3.What is the first step you need to perform on a router when configuring role-based CLI?

A: place the router in global configuration mode
B: create a parser view called root view
C: enable role-based CLI globally on the router using the privilege exec level Cisco IOS command.
D: enable the root view on the router
E: log in to the router as the “root” user
Correct Answers:?? D