Cisco Secure PIX Firewall Advanced Version 4.0 - Pdf 67

9E0-111 (CSPFA)

Cisco Secure PIX Firewall Advanced

Version 4.0
We are constantly reviewing our products. New material is added and old material is revised.
Free updates are available for 90 days after the purchase. You should check your member
zone at TestKing an update 3-4 days before the scheduled exam date.

Here is the procedure to get the latest version:

1. Go to www.testking.com

2. Click on Member zone/Log in
3. The latest versions of all purchased products are downloadable from here. Just click
the links.

For most updates, it is enough just to print the new questions at the end of the new version,
not the whole document.

Feedback
Feedback on specific questions should be send to You should state:
Exam number and version, question number, and login ID.

Our experts will answer your mail promptly.

Explanations
Currently this product does not include explanations. If you are interested in providing
TestKing with explanations contact
. Include the following
information: exam, your background regarding this exam in particular, and what you consider
a reasonable compensation for the work.

Copyright
Each pdf file contains a unique serial number associated with your particular name and

C. Turbo ACLs
D. IP helper
E. Object grouping Answer: E
QUESTION NO: 2
IPSec works with which switching paths:

A. Process switching
B. Optimum switching
C. Fast switching
D. Flow switching Answer: A
QUESTION NO: 3
Speaking of Security Association requirements, which of the following statements is
true?

A. A set of SAs are needed, one per direction, per protected data pipe.
B. A set of SAa are needed, one per direction, per protocol, per protected data pipe.
9E0 - 111
Leading the way in IT testing and certification tools, www.testking.com


A. If disabled, can be enabled by the command: fixed protocol dns 53
B. The default UDP time expires in two minutes.
C. Immediately tears down the UDP conduit on the PIX Firewall as soon as the DNS
response is received.
D. Prevents against UDP session hijacking and denial of service attacks. Answer: A
QUESTION NO: 6
In helping the user to choose the right IPSec transforms combinations, the following
rules apply: (Choose all that apply)

A. To provide authentication services for the transform set, include an AH transform.
B. For authentication services include an ESP authentication transform.
C. To provide data authentication for the data and the outer IP header, include an AH
transform.
D. For data confidentiality include an ESP encryption transform.
E. ND5 is stronger than SHA.

9E0 - 111
Leading the way in IT testing and certification tools, www.testking.com - 5 -

Answer: A, B, C, D

Answer: C
QUESTION NO: 9
Which of the following statements are not true: (Choose all that apply)

A. DMZ interface can be considered an inside, or outside interface.
B. DMZ interface is always considered inside.
C. Traffic originating from the inside interface to the outside interface of the PIX Firewall
will be allowed to flow unless restricted by access lists.
D. Traffic originating from the outside interface to the inside interface of the PIX Firewall
will be dropped unless specifically allowed.
E. DMZ interface is always considered outside. Answer: B, E

9E0 - 111
Leading the way in IT testing and certification tools, www.testking.com - 6 - QUESTION NO: 10
Adaptive Security Algorithm (ASA) is the heart of the PIX Firewall. Choose the strict
rules that ASA follows: (Choose all that apply)

A. The highest security interface is the inside interface.

Your organization’s web traffic has come to a halt because your PIX Firewall is
dropping all new connection attempts. Why?

A. You are running a software version older than 5.2, and the embryonic threshold you
set in the static command was reached.
B. The shun feature of the PIX Firewall has taken effect because the embryonic threshold
you set in the nat command was reached.
C. The TCP Intercept feature of the PIX Firewall has taken affect because the embryonic
threshold you set in the static command was reached.
D. The intrusion detection feature of the PIX Firewall has taken effect because the
embryonic threshold you set in the conduit command was reached. 9E0 - 111
Leading the way in IT testing and certification tools, www.testking.com - 7 -
Answer: A
QUESTION NO: 13
Which tasks can be performed from the Access Rules tab? (Choose three)

A. Configure translation rules.
B. Configure Cisco Secure ACS.
C. Configure access rules.
D. Define Java and ActiveX filtering rules.
E. Configure command authorization.

E. Specify the peer to which IPSec-protected traffic can be forwarded. Answer: C
QUESTION NO: 16
9E0 - 111
Leading the way in IT testing and certification tools, www.testking.com - 8 -
Which type of downloadable ACLs are best when there are frequent requests for
downloading a large ACL?

A. Named ACLs
B. Unnamed ACLs
C. Dynamic ACLs
D. Static ACLs Answer: A
QUESTION NO: 17
Why is the group tag in the aaa-server command important?

A. The aaa command references the group tag to know where to direct authentication,

A. Monitoring
B. Hosts or networks
C. Access rules
9E0 - 111
Leading the way in IT testing and certification tools, www.testking.com - 9 -
D. System properties
E. Preferences
F. Translation rules Answer: A, B, C, D, F
QUESTION NO: 20
How does the PIX Firewall know where to get the addresses to use for any NAT
configuration?

A. From the nat_id in the static command.
B. You can have only one global pool of addresses, so the PIX Firewall knows that NAT
uses the addresses in the global pool established by the global command.
C. From the nat_id in the nat command.
D. From the nat_id in the dhcp address command. Answer: C

- 10 -
QUESTION NO: 23
Which statements about the PIX Firewall’s DHCP capabilities are true? (Choose two)

A. It can be a DHCP server.
B. It cannot be a DHCP client.
C. You must remove a configured domain name.
D. It can be a DHCP server and client simultaneously.
E. It cannot pass configuration parameters it receives from another DHCP server to its
own DHCP clients.
F. The PIX Firewall’s DHCP server can be configured to distribute the IP address of up
to four DNS servers to its clients. Answer: A, D
QUESTION NO: 24
The LAN-based failover your configured does not work. Why? (Choose two)

A. You used a hub for failover operation.
B. You used a switch for failover operation.
C. You used a dedicated VLAN for failover operation.
D. You did not set a failover IP address.

E. Both provide stateful failover. Answer: E
QUESTION NO: 26
Choose the correct statements regarding ACLs & Conduits:

A. A conduit creates a rule on the PIX Firewall Adaptive Security Algorithm by denying
connections from one interface to access hosts on another.
B. An ACL applies to a single interface, affecting all traffic entering that interface
regardless of its security level.
C. An ACL applies to a single interface, affecting all traffic entering that interface based
in its security level.
D. A conduit creates an exception to the PIX Firewall Adaptive Security Algorithm by
permitting connections from one interface to access hosts on another. Answer: A
QUESTION NO: 27
What is the command to remove a group of previously defined object-group commands?

A. Both answers are correct.
B. clear object-group
C. Both answers are incorrect.

IPSec security associations will never time out for a given IPSec session.

The encryption keys never change during IPSec sessions between peers.

Anti-replay services will not be available between the peers.

CA support cannot be used.

To disable IKE, use the following command:

no crypto isakmp enable interface-name
QUESTION NO: 29
This security protocol provides data confidentiality and protection with optional
authentication and replay-detection services.

A. What is ESP
B. What is DES
C. What is IKE
D. What is AH
E. What is RSA Answer: A
QUESTION NO: 30

QUESTION NO: 32
Speaking of the translation table of a PIX Firewall, by default, if there is no translated
packets for a particular IP address, the entry times out and gets removes from the table.
This timeout period is:

A. User- Configurable and by default is 5 minutes
B. User- Configurable and by default is 60 minutes.
C. User- Configurable and by default is 180 minutes.
D. not User- Configurable and by default is 5 minutes.
E. not User- Configurable and by default is 2 Minutes.
F. not User- Configurable and by default is 60 Minutes. Answer: C
QUESTION NO: 33
Firewall operations are based on one of the following technologies:
- Packet filtering
- Proxy Server
- Stateful packet filtering

Which is the method used by PIX Firewall?

A. Packet Filtering
B. Stateful Packet Filtering
C. All answers are incorrect
D. Proxy server



A. For valid users.
B. For misconfiguration.
C. For incorrect address.
D. For malicious application misuse. Answer: D
QUESTION NO: 36
What command reassigns a specific command to a different privilege level?

A. privilege
B. command auth
C. level-priv
D. curpriv Answer: A
QUESTION NO: 37
Which command enables IKE on the outside interface?

A. ike enable outside
B. ipsec enable outside
C. isakmp enable outside

A. You have not enabled HTTP, Telnet, and FTP authorization, which is required for
HTTP authentication.
B. You have not enabled HTTP authorization, which is required for HTTP authentication.
C. HTTP authentication is not supported.
D. Re-authentication maybe taking place with the web browser sending the cached
username and password back to the PIX Firewall. Answer: D
QUESTION NO: 40
Which are functions of the object-group command? (Choose two)

A. Defines members of an object group.
B. Names an object group.
C. Enables sub-command mode.
D. Inserts an object group in an ACL.
E. Displays a list of the current configured object groups of the specified type.
F. Describes the object group. Answer: B, C
QUESTION NO: 41
9E0 - 111
Leading the way in IT testing and certification tools, www.testking.com
QUESTION NO: 43
Which statement about the configuration mode for the PIX Firewall is true?

A. Privileged mode commands, unprivileged mode commands, and configuration mode
commands all work in configuration mode.
B. Only configuration mode commands work in configuration mode.
C. Unprivileged mode commands and configuration mode commands work in
configuration mode, but you must exit the configuration mode in order to execute
privileged mode commands.
D. Privileged mode commands and configuration mode commands work in configuration
mode, but you must exit both these modes in order to execute unprivileged mode
commands. Answer: A
QUESTION NO: 44
Which statement about the PIX Firewall Syslog is true?

9E0 - 111
Leading the way in IT testing and certification tools, www.testking.com - 17 -
A. Syslog messages can be used to create log files, and can be displayed on the console of
a designated Syslog host, but they cannot be used to create e-mail alerts.

What change did the administrator make?

A. He disabled the PIX Firewall’s mailpor fixup.
B. He disabled the PIX Firewall’s smtp fixup.
C. He enabled the Pix Firewall’s ils fixup on port 25.
D. He defined the port on which to activate Mail Guard. Answer: B
QUESTION NO: 47
What is the command that clears all IPSec security associations at the router?

A. clear crypto sa
B. clear isakmp
C. no crypto sa
9E0 - 111
Leading the way in IT testing and certification tools, www.testking.com - 18 -
D. crypto sa disable Answer: A
Explanation:
clear [crypto] ipsec sa


D. The peer must also have the same transform set name and parameters specified. Answer: B
QUESTION NO: 49
Which of the following statements are true regarding the sanity check of PIX Firewall’s
failover feature? (Choose all that apply)

A. Both PIX Firewalls exchange failover HELLO packets over failover cable every 15
seconds.
9E0 - 111
Leading the way in IT testing and certification tools, www.testking.com - 19 -
B. With Network Activity test, the PIX Firewall counts all received packets for up to 5
seconds.
If no traffic is received, the PIX is declared nonoperational and the standby takes over.
C. Both PIX Firewalls exchange failover HELLO packets over all network interfaces.
D. PIX Firewall performs a broadcast and checks the responses. Answer: A, C, D
QUESTION NO: 50

The software configuration decides which one is the outside and which one is the
inside interface.
B. Ethernet 0 is always the outside network connection and Ethernet 1 is always the
inside network connection.
C. Ethernet 0 is always the inside network connection and Ethernet 1 is always the
outside network connection.
D. There is no general rule.
9E0 - 111
Leading the way in IT testing and certification tools, www.testking.com - 20 -
The priority command applied to the interface decides which interface is the outside
and which interface is the inside. Answer: B
QUESTION NO: 53
How does the PIX Firewall handle multimedia applications? (Choose two)

A. It supports multimedia only with NAT.
B. It supports multimedia only without NAT.
C. It supports multimedia with or without NAT.
D. Multimedia applications are not allowed because they pose a security risk.
E. It dynamically opens and closes UDP ports for secure multimedia connections.
F. It opens a large range of ports for these applications if you configure the PIX Firewall
to support multimedia.
9E0 - 111
Leading the way in IT testing and certification tools, www.testking.com - 21 -
QUESTION NO: 56
Which statement about AAA and the PIX Firewall is true?

A. Authorization is valid without authentication, but authentication is never valid without
authorization.
B. Authorization is valid without authentication, and authentication is valid without
authorization.
C. Authentication is valid without authorization, but authorization is never valid without
authentication.
D. Authentication and authorization are never valid without accounting. Answer: C
QUESTION NO: 57
Which three problems can ActiveX cause for network clients using the PIX Firewall?
(Choose three)

A. It can attack servers.
B. It can block HTML commands.
C. It can block HTML comments.


- 22 -
You primary PIX Firewall is currently the active unit in your failover topology.
What will happen to the current IP addresses on the primary PIX Firewall if it fails?

A. They become those of the standby PIX Firewall.
B. The ones on the primary PIX Firewall remain the same, but the current IP addresses of
the secondary become the virtual IP addresses you configured.
C. They are deleted.
D. The ones on both the primary and secondary PIX Firewalls are deleted and both
assume the failover IP addresses you configured. Answer: A
QUESTION NO: 60
IPSec enables PIX Firewall VPN features. At what OSI layer does IPSec funtion?

A. 3 & 4
B. 7
C. 2
D. 3
E. 5 Answer: A
Explanation:
IPSec Framework

Associations. QUESTION NO: 61
You existing IPSec network comprises of 6 peers. Due to company expansion, one more
peer is added to your network. As a key administrator, how many 2-part key
configurations would you have to create?

A. 1
B. 6
C. 5
D. None
E. 2 Answer: B
QUESTION NO: 62
The hardware requirements of the Stateful Failover are: (Choose all that apply)

A. Two identical PIX Firewall units.
FIX 520 or later model is recommended by Cisco.
B. The LAN ports for Stateful Failover on both PIX Firewall units should be connected
with a crossover cable or through a hub or switch.
C. A failover cable with the correct terminals.
D. Dedicated 10BaseT Ethernet ports on both PIX Firewall units must be connected and
fully functional in full Duplex mode.


What is the command you use?

A. show interface *
B. show controllers
C. show ip address
D. show interfaces Answer: C
QUESTION NO: 65
In a recent survey conducted by the Computer Security Institute, what percent of the
organizations polled stated that their network security defenses had been breached?

A. 70 percent
B. 37 percent
C. 7 percent
D. 27 percent Answer: A
QUESTION NO: 66
When do you have access to the interactive setup dialog that helps you perform initial
configuration required to use PDM?


Answer: D, F
QUESTION NO: 68
Which statement about the PIX Firewall and virtual HTTP is true?

A. The PIX Firewall enables web browsers to work correctly with its HTTP
authentication.
The PIX Firewall redirects the web browser’s initial connection to an IP address,
which resides on it, authenticates the user, and the redirects the browser back to the
URL the user originally requested.
B. The PIX Firewall supports virtual Telnet, but not virtual HTTP.
C. The PIX Firewall enables RADIUS authorization by redirecting the web browser’s
initial connection to an IP address which resides on a web server you specify,
authorizing the user, and then redirecting the browser back to the URL the user
originally requested.
D. The PIX Firewall enables you to access URLs from its console. Answer: A
QUESTION NO: 69
Which statement about object groups is true?

A. Duplicate objects are allowed in object groups unless they are due to the inclusion of
group objects.
B. An object group cannot be a member of another object group.


Nhờ tải bản gốc
Music ♫

Copyright: Tài liệu đại học © DMCA.com Protection Status