Which type of Layer 2 attack causes a switch to flood all incoming traffic to all ports?
A. MAC spoofing attack
B. CAM overflow attack
C. VLAN hopping attack
D. STP attack
Answer: B
What is the best way to prevent a VLAN hopping attack?
A. Encapsulate trunk ports with IEEE 802.1Q.
B. Physically secure data closets.
C. Disable DTP negotiations.
D. Enable BDPU guard.
Answer: C
Home |
CCNA Exam Questions | News |
Showing posts with label CCNA Exam Questions. Show all posts
Showing posts with label CCNA Exam Questions. Show all posts
Thursday, 1 September 2016
Pass4sure 640-554 Question Answer
Which type of Layer 2 attack causes a switch to flood all incoming traffic to all ports?
A. MAC spoofing attack
B. CAM overflow attack
C. VLAN hopping attack
D. STP attack
Answer: B
What is the best way to prevent a VLAN hopping attack?
A. Encapsulate trunk ports with IEEE 802.1Q.
B. Physically secure data closets.
C. Disable DTP negotiations.
D. Enable BDPU guard.
Answer: C
A. MAC spoofing attack
B. CAM overflow attack
C. VLAN hopping attack
D. STP attack
Answer: B
What is the best way to prevent a VLAN hopping attack?
A. Encapsulate trunk ports with IEEE 802.1Q.
B. Physically secure data closets.
C. Disable DTP negotiations.
D. Enable BDPU guard.
Answer: C
Monday, 9 May 2016
Pass4sure 640-554 Question Answer
Which statement describes a best practice when configuring trunking on a switch port?
A. Disable double tagging by enabling DTP on the trunk port.
B. Enable encryption on the trunk port.
C. Enable authentication and encryption on the trunk port.
D. Limit the allowed VLAN(s) on the trunk to the native VLAN only.
E. Configure an unused VLAN as the native VLAN.
Answer: E
A. Disable double tagging by enabling DTP on the trunk port.
B. Enable encryption on the trunk port.
C. Enable authentication and encryption on the trunk port.
D. Limit the allowed VLAN(s) on the trunk to the native VLAN only.
E. Configure an unused VLAN as the native VLAN.
Answer: E
Tuesday, 5 April 2016
Pass4sure 640-554 Question Answer
Which statement is true about vishing?
A. Influencing users to forward a call to a toll number (for example, a long distance or international number)
B. Influencing users to provide personal information over a web page
C. Using an inside facilitator to intentionally forward a call to a toll number (for example, a long distance or international number)
D. Influencing users to provide personal information over the phone
Answer: D
Which item is the great majority of software vulnerabilities that have been discovered?
A. Stack vulnerabilities
B. Heap overflows
C. Software overflows
D. Buffer overflows
Answer: D
A. Influencing users to forward a call to a toll number (for example, a long distance or international number)
B. Influencing users to provide personal information over a web page
C. Using an inside facilitator to intentionally forward a call to a toll number (for example, a long distance or international number)
D. Influencing users to provide personal information over the phone
Answer: D
Which item is the great majority of software vulnerabilities that have been discovered?
A. Stack vulnerabilities
B. Heap overflows
C. Software overflows
D. Buffer overflows
Answer: D
Wednesday, 2 March 2016
Pass4sure 640-554 Question Answer
What Cisco Security Agent Interceptor is in charge of intercepting all read/write requests to the rc files in UNIX?
A. Configuration interceptor
B. Network interceptor
C. File system interceptor
D. Execution space interceptor
Answer: A
Information about a managed device’s resources and activity is defined by a series of objects. What defines the structure of these management objects?
A. MIB
B. FIB
C. LDAP
D. CEF
Answer: A
A. Configuration interceptor
B. Network interceptor
C. File system interceptor
D. Execution space interceptor
Answer: A
Information about a managed device’s resources and activity is defined by a series of objects. What defines the structure of these management objects?
A. MIB
B. FIB
C. LDAP
D. CEF
Answer: A
Thursday, 28 January 2016
Pass4sure 640-554 Question Answer
In a brute-force attack, what percentage of the keyspace must an attacker generally search through until he or she finds the key that decrypts the data?
A. Roughly 50 percent
B. Roughly 66 percent
C. Roughly 75 percent
D. Roughly 10 percent
Answer: A
Which three items are Cisco best-practice recommendations for securing a network? (Choose three.)
A. Routinely apply patches to operating systems and applications.
B. Disable unneeded services and ports on hosts.
C. Deploy HIPS software on all end-user workstations.
D. Require strong passwords, and enable password expiration.
Answer: A, B, D
A. Roughly 50 percent
B. Roughly 66 percent
C. Roughly 75 percent
D. Roughly 10 percent
Answer: A
Which three items are Cisco best-practice recommendations for securing a network? (Choose three.)
A. Routinely apply patches to operating systems and applications.
B. Disable unneeded services and ports on hosts.
C. Deploy HIPS software on all end-user workstations.
D. Require strong passwords, and enable password expiration.
Answer: A, B, D
Monday, 28 December 2015
Pass4sure 640-554 Question Answer
Which four methods are used by hackers? (Choose four.)
A. footprint analysis attack
B. privilege escalation attack
C. buffer Unicode attack
D. front door attacks
E. social engineering attack
F. Trojan horse attack
Answer: A, B, E, F
Which characteristic is the foundation of Cisco Self-Defending Network technology?
A. secure connectivity
B. threat control and containment
C. policy management
D. secure network platform
Answer: D
A. footprint analysis attack
B. privilege escalation attack
C. buffer Unicode attack
D. front door attacks
E. social engineering attack
F. Trojan horse attack
Answer: A, B, E, F
Which characteristic is the foundation of Cisco Self-Defending Network technology?
A. secure connectivity
B. threat control and containment
C. policy management
D. secure network platform
Answer: D
Monday, 7 December 2015
Pass4sure 640-554 Question Answer
Which type of security control is defense in depth?
A. threat mitigation
B. risk analysis
C. botnet mitigation
D. overt and covert channels
Answer: A
A. threat mitigation
B. risk analysis
C. botnet mitigation
D. overt and covert channels
Answer: A
Friday, 9 October 2015
Pass4sure 640-554 Question Answer
Which two features are supported by Cisco IronPort Security Gateway? (Choose two.)
A. Spam protection
B. Outbreak intelligence
C. HTTP and HTTPS scanning
D. Email encryption
E. DDoS protection
Answer: A, D
Which two characteristics represent a blended threat? (Choose two.)
A. man-in-the-middle attack
B. trojan horse attack
C. pharming attack
D. denial of service attack
E. day zero attack
Answer: B, E
A. Spam protection
B. Outbreak intelligence
C. HTTP and HTTPS scanning
D. Email encryption
E. DDoS protection
Answer: A, D
Which two characteristics represent a blended threat? (Choose two.)
A. man-in-the-middle attack
B. trojan horse attack
C. pharming attack
D. denial of service attack
E. day zero attack
Answer: B, E
Thursday, 10 September 2015
Pass4sure 640-554 Question Answer
Which two options represent a threat to the physical installation of an enterprise network? (Choose two.)
A. surveillance camera
B. security guards
C. electrical power
D. computer room access
E. change control
Answer: C, D
Which option represents a step that should be taken when a security policy is developed?
A. Perform penetration testing.
B. Determine device risk scores.
C. Implement a security monitoring system.
D. Perform quantitative risk analysis.
Answer: D
Wednesday, 22 April 2015
CCNA 640-554 Practice Question
Question No : 1
Which two features are supported by Cisco IronPort Security Gateway? (Choose two.)
A. Spam protection
B. Outbreak intelligence
C. HTTP and HTTPS scanning
D. Email encryption
E. DDoS protection
Answer: A,D
Explanation:http://www.cisco.com/en/US/prod/collateral/vpndevc/ps10128/ps10154/datasheet-c78-729751.html
Product Overview
Over the past 20 years, email has evolved from a tool used primarily by technical and research professionals to become the backbone of corporate communications. Each day, more than 100 billion corporate email messages are exchanged. As the level of use rises, security becomes a greater priority. Mass spam campaigns are no longer the only concern.Today, spam and malware are just part of a complex picture that includes inbound threats and outbound risks. Cisco® Email Security solutions defend mission-critical email systems with appliance,virtual, cloud, and hybrid solutions. The industry leader in email security solutions, Cisco delivers:
Fast, comprehensive email protection that can block spam and threats before they even hit your network Flexible cloud, virtual, and physical deployment options to meet your everchanging business needs Outbound message control through on-device data-loss prevention (DLP), email encryption, and optional integration with the RSA enterprise DLP solution One of the lowest total cost of ownership (TCO) email security solutions available
Question No : 2
Which option is a feature of Cisco ScanSafe technology?
A. spam protection
B. consistent cloud-based policy
C. DDoS protection
D. RSA Email DLP
Answer: B
Explanation:
http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6525/ps6538/ps6540/data_sheet_c78-655324.htmlCisco Enterprise Branch Web Security
The Cisco® Integrated Services Router G2 (ISR G2) Family delivers numerous security services, including firewall, intrusion prevention, and VPN. These security capabilities have been extended with Cisco ISR Web Security with Cisco ScanSafe for a simple, costeffective, on-demand web security solution that requires no additional hardware. Organizations can deploy and enable market-leading web security quickly and easily, and can enable secure local Internet access for all sites and users, saving bandwidth, money, and resources.
Figure 1. Typical Cisco ISR Web Security with Cisco ScanSafe Deployment Cisco ISR Web Security with Cisco ScanSafe enables branch offices to intelligently redirect web traffic to the cloud to enforce granular security and control policy over dynamic Web 2.0 content, protecting branch office users from threats such as Trojans, back doors, rogue scanners, viruses, and worms. The Cisco ISR Web Security with Cisco ScanSafe feature will be available in the Security SEC K9 license bundle
Sunday, 1 February 2015
CCNA 100-101 Question Answer
QUESTION NO:1
Which three statements are true about the operation of a full-duplex Ethernet network? (Choose three.)A.There are no collisions in full-duplex mode.
B.A dedicated switch port is required for each full-duplex node.
C.Ethernet hub ports are preconfigured for full-duplex mode.
D.In a full-duplex environment, the host network card must check for the availability of the network media before transmitting.
E.The host network card and the switch port must be capable of operating in full-duplex mode.
Answer: ABE
QUESTION NO:2
Which OSI layer header contains the address of a destination host that is on another network?
A.application
B.session
C.transport
D.network
E.datalink
F.physical
Answer: D
Subscribe to:
Posts (Atom)
