ASA Info Flashcards

1
Q

Which Cisco security management solution provides the means to identify, isolate and counter security threats?

A) Adaptive Security Device Manager
B) Intrusion Prevention Device Manager
C) Security Device Manager
D) Cisco Security Manager
E) Cisco Security Monitoring, Analysis and Response System
A

Answer:

E) Cisco Security Monitoring, Analysis and Response System

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What four types of ACL object group are supported on the ASA (release 8.2)? - Choose 4

A) Protocol B) Network
C) Port D) Service
E) ICMP-type F) Host

A

Answer:

A) Protocol B) Network
D) Service E) ICMP-type

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

By default, which traffic can pass through an ASA that is operating in Transparent mode without explicitly allowing it using an ACL?

A) ARP B) BPDU
C) CDP D) DHCP

A

Answer:

A) ARP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Which ASA feature enable the ASA do to these two things? 1) Act as a proxy-server and generate a SYN-ACK response to a client SYN-Request? 2) When the ASA receives an ACK back from the client, the Cisco ASA authenticates the client and allows connection to the server?

A) TCP normalizer
B) TCP State by-pass
C) TCP Intercept
D) Basic threat detection
E) Bonnet traffic filter
A

Answer:

C) TCP Intercept

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

In which type of environment is the Cisco ASA Modular Policy Framework (MPF) set connection advance-option tcp-state-bypass option the most useful?

A) SIP Proxy 
B) WCCP
C) BGP peering through the Cisco ASA
D) Asymmetric traffic flow
E) Transparent firewall
A

Answer:

D) Asymmetric traffic flow

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

When ordering the licenses for a Cisco ASA, which two license must be ordered that are “platform specifics” to the Cisco ASA 5505?

A) Any Connect Essential License
B) Per-User Premium SSL VPN License
C) VPN Shared License
D) Internal User License
E) Security Plus License
A

Answer:

D) Internal User License

E) Security Plus License

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

By default, which access rule is applied to the inside interface of an ASA?

A) All IP traffic is denied.
B) All IP traffic is permitted.
C) All IP traffic sourced from any source to any less secure network destination is permitted.
D) All IP traffic sourced from any source to any more secure network destination is permitted.

A

Answer:

C) All IP traffic sourced from any source to any less secure network destination is permitted.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

The Cisco ASA must support dynamic routing and terminating VPN traffic. Which three (3) Cisco ASA options will NOT support these requirements?

A) Transparent mode
B) Multiple context mode
C) Active / standby fail-over mode
D) Active / active fail-over mode
E) Routed mode
F) No-NAT-control
A

Answer:

A) Transparent mode

B) Multiple context mode

D) Active / active fail-over mode

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Which Cisco ASA platform should be selected if the requirements are to support 35,000 connections per second, 600,000 maximum connections, and traffic shaping?

A) 5540
B) 5550
C) 5580 - 20
D) 5580 - 40

A

Answer:

B) 5550

How well did you know this?
1
Not at all
2
3
4
5
Perfectly