Home > Drag and Drop Questions

Drag and Drop Questions

July 14th, 2010 in CCNA Security Go to comments

Here you will find answers to Drag and Drop Questions

Notice: In the exam, some Drag and Drop Questions may be represented as multiple-choice questions.

Question 1

On the basis of the description of SSL-based VPN, place the correct descriptions in the proper locations.

SSL_based_VPN.jpg


Answer:

+ The authentication process uses hashing technologies.
+ Asymmetric algorithms are used for authentication and key exchange.
+ Symmetric algorithms are used for bulk encryption.

Question 2

Which three common examples are of AAA implementation on Cisco routers? Please place the correct descriptions in the proper locations.

AAA_Implementation.jpg


Answer:

+ performing router commands authorization using TACACS+
+ authenticating remote users who are accessing the corporate LAN through IPSec VPN connections
+ authenticating administrator access to the router console port, auxiliary port, and vty ports

Question 3

Drag two characteristics of the SDM Security Audit wizard on the above to the list on the below.

SDM_Security_Audit.jpg


Answer:

+ requires users to first identify which router interfaces connect to the inside network and which connect to the outside network
+ displays a screen with Fix-it check boxes to let you choose which potential security-related configuration changes to implement

Question 4

On the basis of the Cisco IOS Zone-Based Policy Firewall, by default, which three types of traffic are permitted by the router when some interfaces of the routers are assigned to a zone?

Drag three proper characterizations on the above to the list on the below.

Cisco_IOS_Zone_Based_Policy_Firewall.jpg

 

Answer:

+ traffic flowing among the interfaces that are members of the same zone
+ traffic flowing among the interfaces that are not assigned to any zone
+ traffic flowing to and from the router interfaces (the self zone)

Question 5

Drag three proper statements about the IPsec protocol on the above to the list on the below.

IPSec_Protocol.jpg

 

Answer:

Three correct statements are:

+ IPsec is a framework of open standards.
+ IPsec ensures data integrity by using checksums.
+ IPsec authenticates users and devices that can carry out communication independently.

Comments
  1. iamkhan
    September 26th, 2010

    got exam on 1st of oct. hope I pass.

  2. Darsafar
    September 29th, 2010

    1st of October too. thanks a million tut

  3. Sergey
    September 30th, 2010

    Good luck! Don’t forget to comment this at 2nd october ;)

  4. Saurabh Bassi
    October 6th, 2010

    Q.4 .. The answer is wrong. It must be the first 3 options.
    Refer to OFFICIAL EXAM GUIDE by Kevin Wallace & Michael Watkins.
    Pg. 376. Below Fig 10.24 . Return traffic is always allowed by default, whether a policy is configured or not!!

    And , btw, when you configure a zone based firewall, all traffic FROM the self zone is allowed by policy map “sdm-permit-icmpreply” and all traffic TO the self zone is denied by “sdm-permit” policy map.

    PLEASE CORRECT THE ANSWER!!

  5. Patrick
    October 12th, 2010

    Whats withc Q4?? Ist the securitytut answer true or not????

    Tomorrow I have my exam!

    Thanks in advance for the clarification of the answer

  6. Andriesh
    October 25th, 2010

    Patrick, did you took the exam?

  7. nonamed
    October 27th, 2010

    Q4 {2,3,4} seems to be OK. In the book commented by Saurabh Bassi is the explanation (pages 371-372):

    “The only exception to the default deny-all policy is the self zone. Traffic to any router interface is allowed until traffic is explicitly denied.”

    “The one exception to the preceding deny-by-default approach is traffic to and from the router, which is permitted by default.”

  8. Anonymous
    October 29th, 2010

    I’ve taken the exam today scoring a 1000. Question 4 is OK.

  9. Axicos
    October 30th, 2010

    Also got 1000 on 29 Oct. All answers are correct.

  10. ivan
    November 3rd, 2010

    I passed the exam last week scoring a 1000! Question 4 is correct! I agree that Return traffic is always allowed by default, but only if you have an inspect policy (e.g. from inside to outside) configured first for that kind of traffic! I think you need to read the question carefully! Cisco only said that some interfaces of the router are assigned to a zone and nothing else! And so there can not be a returning traffic that’s allowed by default.

  11. MR x
    December 9th, 2010

    new drag and drop on 8/12/2010

    Q129 from link below
    http://www.scribd.com/doc/32103017/640-553-CCNAS-Certification-Tests

  12. Nishant
    December 28th, 2010

    Hey all…i passed this exam today scoring 1000 marks…thnks securitytut…p4s 138q (4.38)dumps are still valid…

  13. sahar
    December 30th, 2010

    Thanks for securitytut ….i passed this exam today scoring 1000 marks…testinside ver6.11 are still valid :)

  14. unnamed
    February 25th, 2011

    hi all,
    what about question nº 5?
    + i asume IPsec is implemented at layer 3, not layer 4
    + i also asume digital certificates are used for authentication, not for confidentiality
    + and i asume data integrity is implemented by using hashing algorithms, not checksums

    therefore i guess the remaining answers are the good ones:
    ** IPsec is a framework of open standards
    ** IPsec is bound to specific encryption algorithms, such as 3DES and AES
    ** IPsec authenticates users and devices that can carry out communication independently.

    What do you all think?

  15. Umar
    February 26th, 2011

    @unnamed,
    Hashing uses checksums for integrity.

  16. unnamed
    February 27th, 2011

    @umar
    thanks umar. just one more question?
    i cannot understand why the statement: “IPsec is bound to specific encryption algorithms, such as 3DES and AES” is not true, as the confidentiality part is implemented by using simmetric algorithms, such as DES, 3DES, AES, or SEAL. can you tell me why?

  17. Monex
    March 2nd, 2011

    requires users to first identify which router interfaces connect to the inside network and which connect to the outside network. On the basis of the Cisco IOS Zone-Based Policy Firewall by default which three types of traffic are permitted by the router when some interfaces of the routers are assigned to a zone?.

  18. Ladak
    March 17th, 2011

    In CCNA Security exam, is there any LAB to design VPN on routers???
    Please confirm
    Thanks
    Ladak

  19. Arun MK
    May 11th, 2011

    Am going to write the exam on May 11th . Hope i’ll pass the exam.

  20. Rohann
    May 21st, 2011

    Hi Experts,

    just to know, has any1 cleared this paper on April-may 2011 ? p4s 138q (4.38)dumps are still valid…?

  21. PSterh
    May 23rd, 2011

    to Unnamed regarding Q.5

    “Because IPsec is not bound to specific algorithms, IPsec allows newer and better algorithms
    to be implemented without patching the existing IPsec standards.”

    “IPsec ensures data integrity by using checksums, which are a simple redundancy check.
    The IPsec protocol adds up the basic components of a message, typically the number
    of bytes, and stores the total value. IPsec performs a checksum operation on received
    data and compares the result to the authentic checksum. If the sums match, the assumption
    is that the data has not been manipulated.”

    CCNA Security exam 640-553 Authorized Self-Study Guide. page 382

    So upper answers is correct.

  22. Rohann
    June 4th, 2011

    Hi All,

    I have given exam and passed with 1000/1000. Studied as follows-
    1. Simlets and lab – used securitytut (100 % valid)
    2. Questions- Testinside Ver 6.12 (Q.137)
    3. CISCO Official certification guide/CCNA Security Authorized Self-Study Guide.
    Passing score – 804/1000
    Time- 120 mins (India)

  23. nelson
    June 15th, 2011

    Hi Rohan

    Ver 6.12 is still valid or not, I want to give the exam next week

  24. cisco
    August 11th, 2011

    Hi, I’ve my exam on 19th august 2011. Is P4S 4.38 still valid? Questions shown here are still valid? Has anyone given exam recently?

  25. n0n
    August 17th, 2011

    questions are still good

  26. Ratan Bhattacharya
    September 1st, 2011

    Hi Admin,
    Please share something about CCNP Security exam……

  27. ossu7
    September 23rd, 2011

    Need help from the community,
    would you mind if any one have some exam questions for the SANS – GSEC exam

  28. shk
    October 17th, 2011

    Thanks a lot for securitytut.com.. I request to up date the questions.. wish u an all success..

  29. cisco
    December 4th, 2011

    woohoo got them all right first try

  30. ccnp (sam)
    December 10th, 2011

    dont undestand how to start …?

    am ccnp certified and more intrested toward security…

    please guide me through this ..

  31. Silas
    February 15th, 2012

    Hi Guys! Am busy preparing my IINS, can anyone help where to download IOS for GNS3. My e-mail: nissy357@yahoo.com

  1. No trackbacks yet.
Add a Comment