The CCNA Security v2.0 Final Exam assesses advanced knowledge in network security, focusing on control plane protection, authentication methods, and security tools like Nmap. This quiz is essential for learners aiming to master security protocols and configurations in Cisco networks.
Local AAA authentication provides a way to configure backup methods of authentication, but login local does not
The login local command requires the administrator to manually configure the usernames and passwords, but local AAA authentication does not
Local AAA authentication allows more than one user account to be configured, but login local does not.
The login local command uses local usernames and passwords stored on the router, but local AAA authentication does not.
Rate this question:
The enable secret password could be used in the next login attempt.
The authentication process stops.
The username and password of the local user database could be used in the next login attempt.
The enable secret password and a random username could be used in the next login attempt.
Rate this question:
Password recovery
Password auditing
Identification of Layer 3 protocol support on hosts
TCP and UDP port scanning
Validation of IT system configuration
Rate this question:
Retired true
Event-action produce-alert
Retired false
Event-action deny-attacker-inline
They are more resource intensive.
DES weak keys use very long key sizes.
They produce identical subkeys.
DES weak keys are difficult to manage.
Rate this question:
Reactive protection against Internet attacks
Granularity control within applications
Support of TCP-based packet filtering
Support for logging
Rate this question:
When the router boots up, the Cisco IOS image is loaded from a secured FTP location.
The Cisco IOS image file is not visible in the output of the show flash command.
The Cisco IOS image is encrypted and then automatically backed up to the NVRAM.
The Cisco IOS image is encrypted and then automatically backed up to a TFTP server.
Rate this question:
MPLS
Hairpinning
GRE
Split tunneling
Rate this question:
The ASAs must all be running the same ASDM version.
Each ASA must have the same enable secret password.
Each ASA must have the same master passphrase enabled.
The ASAs must be connected to each other through at least one inside interface.
ASDM must be run as a local application.
Rate this question:
ISAKMP SA policy
DH groups
Interesting traffic
Transform sets
Rate this question:
ZPF allows interfaces to be placed into zones for IP inspection.
The ZPF is not dependent on ACLs.
Multiple inspection actions are used with ZPF.
ZPF policies are easy to read and troubleshoot.
With ZPF, the router will allow packets unless they are explicitly blocked.
Rate this question:
Step-by-step details regarding methods to deploy company switches
Recommended best practices for placement of all company switches
Required steps to ensure consistent configuration of all company switches
List of suggestions regarding how to quickly configure all company switches
Rate this question:
RSA
DH
AES
HMAC
Rate this question:
An uplink port to another switch
On any port where DHCP snooping is disabled 2
Any untrusted port
Access ports only
Rate this question:
A router interface can belong to only one zone at a time.
Service policies are applied in interface configuration mode.
Router management interfaces must be manually assigned to the self zone.
The pass action works in multiple directions.
Rate this question:
The Telnet connection between RouterA and RouterB is not working correctly.
The password cisco123 is wrong.
The administrator does not have enough rights on the PC that is being used.
The enable password and the Telnet password need to be the same.
Rate this question:
DHCP spoofing
DHCP starvation
STP manipulation
MAC and IP address spoofing
Rate this question:
The crypto map has not yet been applied to an interface.
The current peer IP address should be 172.30.2.1.
There is a mismatch between the transform sets.
The tunnel configuration was established and can be tested with extended pings.
Rate this question:
Symmetric algorithms
Hashing algorithms
Asymmetric algorithms
Public key algorithms
Rate this question:
Packet filters perform almost all the tasks of a high-end firewall at a fraction of the cost.
Packet filters provide an initial degree of security at the data-link and network layer.
Packet filters represent a complete firewall solution.
Packet filters are not susceptible to IP spoofing.
Rate this question:
Aaa accounting network start-stop group tacacs+
Aaa accounting network start-stop group radius
Aaa accounting connection start-stop group radius
Aaa accounting exec start-stop group radius
Aaa accounting connection start-stop group tacacs+
Aaa accounting exec start-stop group tacacs+
Rate this question:
Allows a new TCP session to be established for every authorization request
Authorizes connections based on a list of IP addresses configured in an ACL on a Cisco ACS server
Allows a Cisco ACS server to minimize delay by establishing persistent TCP connections
Allows the device to establish only a single connection with the AAA-enabled server
Rate this question:
Install a UPS.
Keep a secure copy of router operating system images.
Configure the router with the maximum amount of memory possible.
Disable default router services that are not necessary.
Reduce the number of ports that can be used to access the router.
Rate this question:
It uses UDP port 500 to exchange IKE information between the security gateways.
IKE Phase 1 can be implemented in three different modes: main, aggressive, or quick.
It allows for the transmission of keys directly across a network.
The purpose of IKE Phase 2 is to negotiate a security association between two IKE peers.
Rate this question:
209.165.201.1
192.168.1.3
172.16.3.1
172.16.3.3
192.168.1.1
Rate this question:
Traffic that is sent from the LAN and the Internet to the DMZ is considered inbound.
Traffic that is sent from the DMZ and the Internet to the LAN is considered outbound.
Traffic that is sent from the LAN to the DMZ is considered is considered inbound.
Traffic that is sent from the DMZ and the LAN to the Internet is considered outbound.
Rate this question:
The code contains no errors.
The code contains no viruses.
The code has not been modified since it left the software publisher.
The code is authentic and is actually sourced by the publisher.
The code was encrypted with both a private and public key.
Rate this question:
Default route
Access list
VLAN ID
NAT/PAT
Rate this question:
Uses connection information maintained in a state table
Uses static packet filtering techniques
Analyzes traffic at Layers 3, 4 and 5 of the OSI model
Uses complex ACLs which can be difficult to configure
Prevents Layer 7 attacks
Rate this question:
Can be implemented as software or as a service
Microsoft port scanning tool designed for Windows
Examines logs and events from systems and applications to detect security threats
Consolidates duplicate event data to minimize the volume of gathered data
Uses penetration testing to determine most network vulnerabilities
Provides real-time reporting for short-term security event analysis
Rate this question:
Public Internet to inside
Public Internet to DMZ
Inside to DMZ
DMZ to inside
Rate this question:
Honey pot-based
Anomaly-based
Signature-based
Policy-based
Rate this question:
Reset UDP connection
Reset TCP connection
Alert
Isolate
Inoculate
Drop
Rate this question:
Telnet
SSH
SSL
ESP
IPsec
Rate this question:
When a superview is deleted, the associated CLI views are deleted.
A single CLI view can be shared within multiple superviews.
A CLI view has a command hierarchy, with higher and lower views.
Only a superview user can configure a new view and add or remove commands from the existing views.
Rate this question:
A class 5 certificate is more trustworthy than a class 4 certificate.
Email security is provided by the vendor, not by a certificate.
The lower the class number, the more trusted the certificate.
A vendor must issue only one class of certificates when acting as a CA.
Rate this question:
Because the login delay command was not used, a one-minute delay between login attempts is assumed.
The hosts that are identified in the ACL will have access to the device.
The login block-for command permits the attacker to try 150 attempts before being stopped to try again.
These enhancements apply to all types of login connections.
Rate this question:
Register the destination website on the Cisco ASA.
Use the Cisco AnyConnect Secure Mobility Client first.
Use a web browser to visit the destination website.
First visit a website that is located on a web server in the Cisco CWS infrastructure.
Rate this question:
The user can execute all subcommands under the show ip interfaces command.
The user can issue the show version command.
The user can only execute the subcommands under the show ip route command.
The user can issue all commands because this privilege level can execute all Cisco IOS commands.
The user can issue the ip route command.
Rate this question:
Network Address Translation
Access control lists
Security zones
Stateful packet inspection
Rate this question:
DSL switch
Frame Relay switch
ISR router
Another ASA
Multilayer switch
Rate this question:
DHCP spoofing
ARP spoofing
VLAN hopping
ARP poisoning
Rate this question:
Authorization
Authentication
Auditing
Accounting
Rate this question:
A counter starts and a summary alert is issued when the count reaches a preconfigured number.
The TCP connection is reset.
An alert is triggered each time a signature is detected.
The interface that triggered the alert is shutdown.
Rate this question:
PSK
DH
RSA
AES
SHA
Rate this question:
Hashes are never sent in plain text.
It is easy to generate data with the same CRC.
It is virtually impossible for two different sets of data to calculate the same hash output.
Hashing always uses a 128-bit digest, whereas a CRC can be variable length.
Rate this question:
Vulnerability scanning
Password cracking
Network scanning
Integrity checker
Rate this question:
This message is a level five notification message.
This message indicates that service timestamps have been globally enabled.
This message indicates that enhanced security was configured on the vty ports.
This message appeared because a major error occurred that requires immediate action.
This message appeared because a minor error occurred that requires further investigation.
Rate this question:
Quiz Review Timeline (Updated): Sep 4, 2023 +
Our quizzes are rigorously reviewed, monitored and continuously updated by our expert board to maintain accuracy, relevance, and timeliness.
Wait!
Here's an interesting quiz for you.