<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CCNA Security</title>
	<atom:link href="http://www.securitytut.com/feed" rel="self" type="application/rss+xml" />
	<link>http://www.securitytut.com</link>
	<description></description>
	<lastBuildDate>Tue, 10 Jan 2012 03:27:15 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Get bolded</title>
		<link>http://www.securitytut.com/uncategorized/get-bolded</link>
		<comments>http://www.securitytut.com/uncategorized/get-bolded#comments</comments>
		<pubDate>Fri, 03 Jun 2011 23:33:11 +0000</pubDate>
		<dc:creator>securitytut</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.securitytut.com/uncategorized/get-bolded</guid>
		<description><![CDATA[Get bolded]]></description>
			<content:encoded><![CDATA[<p>Get bolded</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitytut.com/uncategorized/get-bolded/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Share your CCIE Security Lab Experience</title>
		<link>http://www.securitytut.com/ccie-security-lab/share-your-ccie-security-lab-experience</link>
		<comments>http://www.securitytut.com/ccie-security-lab/share-your-ccie-security-lab-experience#comments</comments>
		<pubDate>Fri, 03 Jun 2011 08:31:51 +0000</pubDate>
		<dc:creator>securitytut</dc:creator>
				<category><![CDATA[CCIE Security Lab]]></category>

		<guid isPermaLink="false">http://www.securitytut.com/?p=606</guid>
		<description><![CDATA[Please share with us your experience after taking the CCIE Security Lab Exam, your materials, the way you learned, your recommendations&#8230;]]></description>
			<content:encoded><![CDATA[<p class="pinkandbold">Please share with us your experience after taking the CCIE Security Lab Exam, your materials, the way you learned, your  recommendations&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitytut.com/ccie-security-lab/share-your-ccie-security-lab-experience/feed</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Share your CCIE Security Written Experience</title>
		<link>http://www.securitytut.com/ccie-security-written/share-your-ccie-security-written-experience</link>
		<comments>http://www.securitytut.com/ccie-security-written/share-your-ccie-security-written-experience#comments</comments>
		<pubDate>Fri, 03 Jun 2011 08:28:06 +0000</pubDate>
		<dc:creator>securitytut</dc:creator>
				<category><![CDATA[CCIE Security Written]]></category>

		<guid isPermaLink="false">http://www.securitytut.com/?p=602</guid>
		<description><![CDATA[Please share with us your experience after taking the CCIE Security Written 350-018 exam, your materials, the way you learned, your recommendations&#8230; 350-018]]></description>
			<content:encoded><![CDATA[<p class="pinkandbold">Please share with us your experience after taking the CCIE Security Written 350-018  exam, your materials, the way you learned, your recommendations&#8230;</p>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow: hidden;">
<table class="cisco-exam-header" style="border-collapse: collapse;">
<tbody>
<tr>
<td class="cisco-examheader-td-first" style="border-collapse: collapse; border: 1px solid #ffffff; background-color: #ffffff;">
</td>
<td style="border-collapse: collapse; border: 1px solid #ffffff; background-color: #ffffff;">350-018</td>
</tr>
</tbody>
</table>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitytut.com/ccie-security-written/share-your-ccie-security-written-experience/feed</wfw:commentRss>
		<slash:comments>13</slash:comments>
		</item>
		<item>
		<title>Share your FIREWALL Experience</title>
		<link>http://www.securitytut.com/firewall-642-617/share-your-firewall-experience</link>
		<comments>http://www.securitytut.com/firewall-642-617/share-your-firewall-experience#comments</comments>
		<pubDate>Mon, 03 Jan 2011 00:15:25 +0000</pubDate>
		<dc:creator>securitytut</dc:creator>
				<category><![CDATA[FIREWALL 642-617]]></category>

		<guid isPermaLink="false">http://www.securitytut.com/?p=586</guid>
		<description><![CDATA[Cisco has made changes for the Security exams by replacing the old CCSP with the new CCNP Security Certification with 4 modules: Secure, Firewall, IPS and VPN. In fact, the old CCSP and the new CCNP Security are very similar. Many candidates have requested us to put up materials for these new exams but it [...]]]></description>
			<content:encoded><![CDATA[<p>Cisco has made changes for the Security exams by replacing the old CCSP with the new CCNP Security Certification with 4 modules: Secure, Firewall, IPS and VPN. In fact, the old CCSP and the new CCNP Security are very similar. Many candidates have requested us to put up materials for these new exams but it is a time-consuming work. In the mean time, we created the &#8220;Share your experience&#8221; for the FIREWALL exam. We really hope anyone who read securitytut, 9tut, digitaltut, certprepare, networktut and voicetut contribute to these sections as your experience is invaluable for CCNP Security learners to complete their goals.</p>
<p class="pinkandbold">Please share with us your experience after taking the FIREWALL 642-617 exam, your materials, the way you learned, your recommendations&#8230;</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-2092096328550054";
/* 728x90, created 8/29/10 */
google_ad_slot = "5545608147";
google_ad_width = 728;
google_ad_height = 90;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitytut.com/firewall-642-617/share-your-firewall-experience/feed</wfw:commentRss>
		<slash:comments>410</slash:comments>
		</item>
		<item>
		<title>Share your SECURE Experience</title>
		<link>http://www.securitytut.com/secure-642-637/share-your-secure-experience</link>
		<comments>http://www.securitytut.com/secure-642-637/share-your-secure-experience#comments</comments>
		<pubDate>Mon, 03 Jan 2011 00:14:04 +0000</pubDate>
		<dc:creator>securitytut</dc:creator>
				<category><![CDATA[SECURE 642-637]]></category>

		<guid isPermaLink="false">http://www.securitytut.com/?p=584</guid>
		<description><![CDATA[Cisco has made changes for the Security exams by replacing the old CCSP with the new CCNP Security Certification with 4 modules: Secure, Firewall, IPS and VPN. In fact, the old CCSP and the new CCNP Security are very similar. Many candidates have requested us to put up materials for these new exams but it [...]]]></description>
			<content:encoded><![CDATA[<p>Cisco has made changes for the Security exams by replacing the old CCSP with the new CCNP Security Certification with 4 modules: Secure, Firewall, IPS and VPN. In fact, the old CCSP and the new CCNP Security are very similar. Many candidates have requested us to put up materials for these new exams but it is a time-consuming work. In the mean time, we created the &#8220;Share your experience&#8221; for the SECURE exam. We really hope anyone who read securitytut, 9tut, digitaltut, certprepare, networktut and voicetut contribute to these sections as your experience is invaluable for CCNP Security learners to complete their goals.</p>
<p class="pinkandbold">Please share with us your experience after taking the SECURE 642-637 exam, your materials, the way you learned, your recommendations&#8230;</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-2092096328550054";
/* 728x90, created 8/29/10 */
google_ad_slot = "5545608147";
google_ad_width = 728;
google_ad_height = 90;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitytut.com/secure-642-637/share-your-secure-experience/feed</wfw:commentRss>
		<slash:comments>373</slash:comments>
		</item>
		<item>
		<title>Share your IPS v7.0 Experience</title>
		<link>http://www.securitytut.com/ips-v7-0-642-627/share-your-ips-v7-0-experience</link>
		<comments>http://www.securitytut.com/ips-v7-0-642-627/share-your-ips-v7-0-experience#comments</comments>
		<pubDate>Mon, 03 Jan 2011 00:12:48 +0000</pubDate>
		<dc:creator>securitytut</dc:creator>
				<category><![CDATA[IPS v7.0 642-627]]></category>

		<guid isPermaLink="false">http://www.securitytut.com/?p=582</guid>
		<description><![CDATA[Cisco has made changes for the Security exams by replacing the old CCSP with the new CCNP Security Certification with 4 modules: Secure, Firewall, IPS and VPN. In fact, the old CCSP and the new CCNP Security are very similar. Many candidates have requested us to put up materials for these new exams but it [...]]]></description>
			<content:encoded><![CDATA[<p>Cisco has made changes for the Security exams by replacing the old CCSP with the new CCNP Security Certification with 4 modules: Secure, Firewall, IPS and VPN. In fact, the old CCSP and the new CCNP Security are very similar. Many candidates have requested us to put up materials for these new exams but it is a time-consuming work. In the mean time, we created the &#8220;Share your experience&#8221; for the IPS v7.0 exam. We really hope anyone who read securitytut, 9tut, digitaltut, certprepare, networktut and voicetut contribute to these sections as your experience is invaluable for CCNP Security learners to complete their goals.</p>
<p class="pinkandbold">Please share with us your experience after taking the IPS v7.0 642-627 exam, your materials, the way you learned, your recommendations&#8230;</p>
<p><!--adsense--></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitytut.com/ips-v7-0-642-627/share-your-ips-v7-0-experience/feed</wfw:commentRss>
		<slash:comments>183</slash:comments>
		</item>
		<item>
		<title>Share your VPN Experience</title>
		<link>http://www.securitytut.com/vpn-642-647/share-your-vpn-experience</link>
		<comments>http://www.securitytut.com/vpn-642-647/share-your-vpn-experience#comments</comments>
		<pubDate>Mon, 03 Jan 2011 00:05:28 +0000</pubDate>
		<dc:creator>securitytut</dc:creator>
				<category><![CDATA[VPN 642-647]]></category>

		<guid isPermaLink="false">http://www.securitytut.com/?p=578</guid>
		<description><![CDATA[Cisco has made changes for the Security exams by replacing the old CCSP with the new CCNP Security Certification with 4 modules: Secure, Firewall, IPS and VPN. In fact, the old CCSP and the new CCNP Security are very similar. Many candidates have requested us to put up materials for these new exams but it [...]]]></description>
			<content:encoded><![CDATA[<p>Cisco has made changes for the Security exams by replacing the old CCSP with the new CCNP Security Certification with 4 modules: Secure, Firewall, IPS and VPN. In fact, the old CCSP and the new CCNP Security are very similar. Many candidates have requested us to put up materials for these new exams but it is a time-consuming work. In the mean time, we created the &#8220;Share your experience&#8221; for the VPN exam. We really hope anyone who read securitytut, 9tut, digitaltut, certprepare, networktut and voicetut contribute to these sections as your experience is invaluable for CCNP Security learners to complete their goals.</p>
<p class="pinkandbold">Please share with us your experience after taking the VPN 642-647 exam, your materials, the way you learned, your recommendations&#8230;</p>
<p><!--adsense--></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitytut.com/vpn-642-647/share-your-vpn-experience/feed</wfw:commentRss>
		<slash:comments>243</slash:comments>
		</item>
		<item>
		<title>Site-to-site VPN SDM Lab Sim</title>
		<link>http://www.securitytut.com/ccna-security/labsim/site-to-site-vpn-sdm-lab-sim</link>
		<comments>http://www.securitytut.com/ccna-security/labsim/site-to-site-vpn-sdm-lab-sim#comments</comments>
		<pubDate>Tue, 14 Sep 2010 16:31:38 +0000</pubDate>
		<dc:creator>securitytut</dc:creator>
				<category><![CDATA[LabSim]]></category>

		<guid isPermaLink="false">http://www.securitytut.com/?p=526</guid>
		<description><![CDATA[Question Next Gen University main campus is located in Santa Cruz. The University has recently established various remote campuses offering e-learning services. The University is using Ipsec VPN connectivity between its main and remote campuses San Jose(SJ), Los Angeles(LA), Sacremento(SAC). As a recent addition to the IT/Networking team, you have been tasked to document the [...]]]></description>
			<content:encoded><![CDATA[<p><span class="ccnaquestionsnumber">Question</span></p>
<p style="text-align: center;"><img src="http://www.securitytut.com/images/CCNASecurity/Labsim/IPsec-SDM-Site-to-site-VPN.jpg" alt="IPsec-SDM-Site-to-site-VPN.jpg" width="600" height="410" /></p>
<p>Next Gen University main campus is located in Santa Cruz. The University  has recently established various remote campuses offering e-learning  services. The University is using Ipsec VPN connectivity between its  main and remote campuses San Jose(SJ), Los Angeles(LA), Sacremento(SAC).  As a recent addition to the IT/Networking team, you have been tasked to  document the Ipsec VPN configurations to the remote campuses using the  Cisco Router and SDM utility. Using the SDM output from VPN Tasks under  the Configure tab to answer this question.</p>
<p><!--adsense--></p>
<p><span id="more-526"></span></p>
<p class="blueandbold">Note:</p>
<p>Before reading the answers and explanations, you can try answering these 4 questions. Below are the screenshots that are necessary to answer all the questions.</p>
<p>Click on the Configure tab on the top menu and then click on the VPN tab on the left-side menu to see these tabs</p>
<p style="text-align: center;"><img src="http://www.securitytut.com/images/CCNASecurity/Labsim/IPsec-SDM-Site-to-site-VPN-Configure_VPN.jpg" alt="IPsec-SDM-Site-to-site-VPN-Configure_VPN.jpg" width="311" height="314" /></p>
<p><strong>+ Tab VPN\Site-to-Site VPN </strong>(notice: you have to click on the &#8220;Edit Site to Site VPN&#8221; tab to see the image below<strong><br />
 </strong></p>
<p><img src="http://www.securitytut.com/images/CCNASecurity/Labsim/IPsec-site-to-site_TabSite_to_site_VPN_scales.jpg" alt="IPsec-site-to-site_TabSite_to_site_VPN_scales.jpg" width="850" height="279" /></p>
<p><strong>+ Tab VPN\VPN Components\IPSec\IPSec Policies</strong></p>
<p style="text-align: center;"><img src="http://www.securitytut.com/images/CCNASecurity/Labsim/IPsec-SDM-Site-to-site-VPN-TabIPsec_Policies_scaled.jpg" alt="IPsec-SDM-Site-to-site-VPN-TabIPsec_Policies_scaled.jpg" width="767" height="525" /></p>
<p>+ Tab Dynamic Crypto is empty so there is no screenshot for this tab</p>
<p>+ Tab IPSec Profiles is empty so there is no screenshot for this tab</p>
<p><strong>+ Tab VPN\VPN Components\IPSec\Transform Sets</strong></p>
<p style="text-align: center;"><img src="http://www.securitytut.com/images/CCNASecurity/Labsim/IPsec-SDM-Site-to-site-VPN-TabTransform_Sets_scaled.jpg" alt="IPsec-SDM-Site-to-site-VPN-TabTransform_Sets_scaled.jpg" width="805" height="437" /></p>
<p><strong>+ Tab VPN\VPN Components\IPSec\IPSec Rules</strong></p>
<p style="text-align: center;"><img src="http://www.securitytut.com/images/CCNASecurity/Labsim/IPsec-SDM-Site-to-site-VPN-TabIPsec_Rules_scaled.jpg" alt="IPsec-SDM-Site-to-site-VPN-TabIPsec_Rules_scaled.jpg" width="784" height="414" /></p>
<p><br class="spacer_" /></p>
<p style="text-align: center;"><img src="http://www.securitytut.com/images/CCNASecurity/Labsim/IPsec-SDM-Site-to-site-VPN-TabIPsec_Rules_2_scaled_acl177.jpg" alt="IPsec-SDM-Site-to-site-VPN-TabIPsec_Rules_2_scaled_acl177.jpg" width="644" height="402" /></p>
<p class="ccnaquestionsnumber">Question 1</p>
<p>Which one of these statements is correct in regards to Next Gen  University Ipsec tunnel between its Santa Cruz main campus and its SJ  remote campus?</p>
<p>A. It is using Ipsec tunnel mode, AES encryption, and SHA HMAC  integrity Check.<br />
 B. It is using Ipsec transport mode, 3DES encryption, and SHA HMAC  integrity Check.<br />
 C. It is using Ipsec tunnel mode to protect the traffic between the  10.10.10.0/24 and the 10.2.54.0/24 subnet.<br />
 D. It is using digital certificate to authenticate between the Ipsec  peers and DH group 2.<br />
 E. It is using pre-shared key to authenticate between the Ipsec peers  and DH group 5.</p>
<p><span class="ccnacorrectanswers">Answer:</span> C</p>
<p class="ccnaexplanation">Explanation</p>
<p>From the Site-to-site VPN tab, we specify that the SJ&#8217;s IP address is 192.168.2.57 with IPsec Rule of 152. Click on the <strong>IPSec Rules</strong> group to see what rule 152 is -&gt; rule 152 is <strong>permit source 10.10.10.0/24 to destination 10.2.54.0/24.</strong></p>
<p><strong><img src="http://www.securitytut.com/images/CCNASecurity/Labsim/IPsec-site-to-site_TabSite_to_site_VPN_scales_answer.jpg" alt="IPsec-site-to-site_TabSite_to_site_VPN_scales_answer.jpg" width="850" height="279" /></strong></p>
<p style="text-align: center;"><strong><img src="http://www.securitytut.com/images/CCNASecurity/Labsim/IPsec-SDM-Site-to-site-VPN-TabIPsec_Rules_scaled_answer.jpg" alt="IPsec-SDM-Site-to-site-VPN-TabIPsec_Rules_scaled_answer.jpg" width="784" height="414" /><br />
 </strong></p>
<p>Also, in the description of the above tab, we can see &#8220;Tunnel to SJ remote campus&#8221; -&gt; it uses Tunnel mode (although it is only the description and can be anything but we can believe it uses Tunnel mode). If you don&#8217;t want to accept this explanation then have a look at the <strong>IPSec Policy</strong> &amp; <strong>Seq No.</strong> columns, which are <strong>SDM_CMAP_1</strong> &amp; <strong>1</strong>. Click on the VPN Components\IPSec\IPSec Policies group we will learn the corresponding <strong>Transform Set</strong> is <strong>ESP-3DES-SHA</strong>. Then click on the <strong>Transform Sets</strong> group we can see the corresponding mode is <strong>TUNNEL</strong>.</p>
<p><br class="spacer_" /></p>
<p class="ccnaquestionsnumber">Question 2</p>
<p>Which one of these statements is correct in regards to Next Gen  University Ipsec tunnel between its Santa Cruz main campus and its SAC  remote campus?</p>
<p>A. The SAC remote campus remote router is using dynamic IP address; therefore, the Santa Cruz router is using a dynamic crypto map.<br />
 B. Dead Peer Detection (DPD) is used to monitor the Ipsec tunnel, so if there is no traffic traversing between the two sites, the Ipsec tunnel will disconnect. <br />
 C. Tunnel mode is used; therefore, a GRE tunnel interface will be configured.<br />
 D. Only the ESP protocol is being used; AH is not being used.</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> D</p>
<p class="ccnaexplanation">Explanation</p>
<p>A is not correct because the VPN Components\IPSec\<strong>Dynamic Crypto Map</strong> group is empty -&gt; the Santa Cruz router is not using a dynamic crypto map.</p>
<p>Not sure about answer B. We can find DPD information in the VPN Components\IKE\<strong>IKE Profiles</strong> group but I am not sure if this group exists in the exam.</p>
<p>C is not correct as we can use Tunnel mode without a GRE tunnel.</p>
<p>D is correct as we can see there is no AH configured under <strong>AH Integrity</strong> column in the VPN Components\IPSec\<strong>Transform Sets</strong> group (while in the ESP Integrity column it is ESP_SHA_HMAC).</p>
<p class="ccnaquestionsnumber">Question 3</p>
<p>Which of these is used to define which traffic will be protected by IPsec between the Next Gen University Santa Cruz main campus and its SAC remote campus?</p>
<p>A. ACL 177<br />
 B. ACL 167<br />
 C. ACL 152<br />
 D. ESP-3DES-SHA1 transform set<br />
 E. ESP-3DES-SHA2 transform set<br />
 F. IKE Phase 1</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer: </span>A</p>
<p class="ccnaexplanation">Explanation</p>
<p>In the VPN\<strong>Site-to-site-VPN</strong> group we can easily see the SAC remote campus is protected by IPSec rule 177, which is an access-list</p>
<p><img src="http://www.securitytut.com/images/CCNASecurity/Labsim/IPsec-site-to-site_TabSite_to_site_VPN_scales.jpg" alt="IPsec-site-to-site_TabSite_to_site_VPN_scales.jpg" width="850" height="279" /></p>
<p class="ccnaquestionsnumber">Question 4</p>
<p>The Ipsec tunnel to the SAC remote campus terminates at which IP address, and what is the protected subnet behind the SAC remote campus router? (Choose two)</p>
<p>A. 192.168.2.57<br />
 B. 192.168.5.48<br />
 C. 192.168.8.58<br />
 D. 10.2.54.0/24<br />
 E. 10.5.66.0/24<br />
 F. 10.8.75.0/24</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer: </span>C F</p>
<p class="ccnaexplanation">Explanation</p>
<p style="text-align: center;"><img src="http://www.securitytut.com/images/CCNASecurity/Labsim/IPsec-SDM-Site-to-site-VPN-TabIPsec_Rules_2_scaled.jpg" alt="IPsec-SDM-Site-to-site-VPN-TabIPsec_Rules_2_scaled.jpg" width="644" height="402" /></p>
<p><!--adsense#AfterContent--></p>
<p><strong>Note:</strong></p>
<p>Some terminologies you should know when configuring SDM</p>
<p><strong>IPSec</strong></p>
<p>A framework of open standards that provides data confidentiality, data integrity, and data authentication between participating peers. IPSec provides these security services at the IP layer. IPSec uses IKE to handle negotiation of protocols and algorithms based on local policy and to generate the encryption and authentication keys to be used by IPSec. IPSec can be used to protect one or more data flows between a pair of hosts, between a pair of security gateways, or between a security gateway and a host.</p>
<p><strong>IPSec Policy</strong></p>
<p>In SDM, an IPSec policy is a named set of crypto map associated with a VPN connection.</p>
<p><strong>Internet Key Exchange (IKE)</strong></p>
<p>Internet Key Exchange (IKE) is a standard method for arranging for secure, authenticated communications. IKE establishes session keys (and associated cryptographic and networking configuration) between two hosts across the network.</p>
<p>Cisco SDM lets you create IKE policies that will protect the identities of peers during authentication. Cisco SDM also lets you create pre-shared keys that peers exchange.</p>
<p><strong>IKE Policies</strong></p>
<p>IKE negotiations must be protected; therefore, each IKE negotiation begins by each peer agreeing on a common (shared) IKE policy. This policy states which security parameters will be used to protect subsequent IKE negotiations. This window shows the IKE policies configured on the router, and allows you to add, edit, or remove an IKE policy from the router&#8217;s configuration. If no IKE policies have been configured on the router, this window shows the default IKE policy.</p>
<p>After the two peers agree on a policy, the security parameters of the policy are identified by a security association established at each peer. These security associations apply to all subsequent IKE traffic during the negotiation.</p>
<p><strong>Hash</strong></p>
<p>The authentication algorithm for negotiation. There are two possible values:<br />
 + Secure Hash Algorithm (SHA)<br />
 <strong>+ Message Digest 5 (MD5) </strong></p>
<p><strong>Authentication</strong></p>
<p>The authentication method to be used.<br />
 + Pre-SHARE: Authentication will be performed using pre-shared keys.<br />
 + RSA_SIG: Authentication will be performed using digital signatures.</p>
<p><strong>D-H Group</strong></p>
<p>Diffie-Hellman (D-H) Group. Diffie-Hellman is a public-key cryptography protocol that allows two routers to establish a shared secret over an unsecure communications channel. The options are as follows:<br />
 + group1 &#8211; 768-bit D-H Group. D-H Group 1.<br />
 + group2 &#8211; 1024-bit D-H Group. D-H Group 2. This group provides more security than group 1, but requires more processing time.<br />
 + group5 &#8211; 1536-bit D-H Group. D-H Group 5. This group provides more security than group 2, but requires more processing time.</p>
<p><strong>AH </strong></p>
<p>Authentication Header. This is an older IPSec protocol that is less  important in most networks than ESP. AH provides authentication services  but does not provide encryption services. It is provided to ensure  compatibility with IPSec peers that do not support ESP, which provides  both authentication and encryption.</p>
<p>AH-MD5-HMAC: Authentication Header with the MD5 (HMAC variant) hash algorithm. <br />
 AH-SHA-HMAC: Authentication Header with the SHA (HMAC variant) hash algorithm.</p>
<p><strong>DES</strong></p>
<p>Data Encryption Standard. Standard cryptographic algorithm developed and standardized by the U.S. National Institute of Standards and Technology (NIST). Uses a secret 56-bit encryption key. The DES algorithm is included in many encryption standards.</p>
<p><strong>3DES</strong></p>
<p>Triple DES. An encryption algorithm that uses three 56-bit DES  encryption keys (effectively 168 bits) in quick succession. An  alternative 3DES version uses just two 56-bit DES keys, but uses one of  them twice, resulting effectively in a 112-bit key length. Legal for use  only in the United States.</p>
<p><strong>ESP</strong></p>
<p>Encapsulating Security Payload. An IPSec protocol that provides both data integrity and confidentiality. Also known as Encapsulating Security Payload, ESP provides confidentiality, data origin authentication, replay-detection, connectionless integrity, partial sequence integrity, and limited traffic flow confidentiality.</p>
<p>+ ESP-MD5-HMAC: ESP (Encapsulating Security Payload) transform using the MD5-variant SHA authentication algorithm. <br />
 + ESP-SHA-HMAC: ESP (Encapsulating Security Payload) transform using the HMAC-variant SHA authentication algorithm.</p>
<p><strong>GRE</strong></p>
<p>Generic routing encapsulation. Tunneling protocol developed by Cisco that can encapsulate a wide variety of protocol packet types inside IP tunnels, creating a virtual point-to-point link to Cisco routers at remote points over an IP internetwork. By connecting multiprotocol subnetworks in a single-protocol backbone environment, IP tunneling using GRE allows network expansion across a single-protocol backbone environment.</p>
<p><strong>HMAC</strong></p>
<p>Hash-based Message Authentication Code. HMAC is a mechanism for message authentication using cryptographic hash functions. HMAC can be used with any iterative cryptographic hash function, e.g., MD5, SHA-1, in combination with a secret shared key. The cryptographic strength of HMAC depends on the properties of the underlying hash function.</p>
<p><strong>MD5</strong></p>
<p>Message Digest 5. A one-way hashing function that produces a 128-bit hash. Both MD5 and Secure Hashing Algorithm (SHA) are variations on MD4 and are designed to strengthen the security of the MD4 hashing algorithm. Cisco uses hashes for authentication within the IPSec framework. MD5 verifies the integrity and authenticates the origin of a communication.</p>
<p><strong>SHA</strong></p>
<p>Some encryption systems use the Secure Hashing Algorithm to generate digital signatures, as an alternative to MD5.</p>
<p><strong>ISAKMP</strong></p>
<p>The Internet Security Association Key Management Protocol is the basis for IKE. ISAKMP authenticates communicating peers, creates and manages security associations, and defines key generation techniques.</p>
<p><strong>Pre-shared Key</strong></p>
<p>One of three authentication methods offered in IPSec, with the other two methods being RSA encrypted nonces, and RSA signatures. Pre-shared keys allow for one or more clients to use individual shared secrets to authenticate encrypted tunnels to a gateway using IKE. Pre-shared keys are commonly used in small networks of up to 10 clients. With pre-shared keys, there is no need to involve a CA for security.</p>
<p>Digital certification and wildcard pre-shared keys (which allow for one or more clients to use a shared secret to authenticate encrypted tunnels to a gateway) are alternatives to pre-shared keys. Both digital certification and wildcard pre-shared keys are more scalable than pre-shared keys.</p>
<p>Reference:</p>
<p>+ <a href="http://www.aboutcisco.biz/en/US/docs/routers/access/cisco_router_and_security_device_manager/25/software/user/guide/IKE.html" target="_blank">http://www.aboutcisco.biz/en/US/docs/routers/access/cisco_router_and_security_device_manager/25/software/user/guide/IKE.html</a></p>
<p>+ <a href="http://docstore.mik.ua/univercd/cc/td/doc/product/software/sdm/22ug/glossary.htm" target="_blank">http://docstore.mik.ua/univercd/cc/td/doc/product/software/sdm/22ug/glossary.htm</a><br class="spacer_" /></p>
<p><!--adsense#AfterContent--></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitytut.com/ccna-security/labsim/site-to-site-vpn-sdm-lab-sim/feed</wfw:commentRss>
		<slash:comments>105</slash:comments>
		</item>
		<item>
		<title>Port Security Lab Sim</title>
		<link>http://www.securitytut.com/ccna-security/labsim/port-security-lab-sim</link>
		<comments>http://www.securitytut.com/ccna-security/labsim/port-security-lab-sim#comments</comments>
		<pubDate>Tue, 14 Sep 2010 15:56:05 +0000</pubDate>
		<dc:creator>securitytut</dc:creator>
				<category><![CDATA[LabSim]]></category>

		<guid isPermaLink="false">http://www.securitytut.com/?p=246</guid>
		<description><![CDATA[Question You are the network security administrator for Big Money Bank Co. You are informed that an attacker has performed a CAM table overflow attack by sending spoofed MAC addresses on one of the switch ports. The attacker has since been identified and escorted out of the campus. You now need to take action to [...]]]></description>
			<content:encoded><![CDATA[<p><span class="ccnaquestionsnumber">Question</span></p>
<p>You are the network security administrator for Big Money Bank Co. You are informed that an attacker has performed a CAM table overflow attack by sending spoofed MAC addresses on one of the switch ports. The attacker has since been identified and escorted out of the campus. You now need to take action to configure the switch port to protect against this kind of attack in the future.</p>
<p>For purposes of this test, the attacker was connected via a hub to the Fa0/12 interface of the switch. The topology is provided for your use. The enable password of the switch is cisco. Your task is to configure the Fa0/12 interface on the switch to limit the maximum number of MAC addresses that are allowed to access the port to two and to shutdown the interface when there is a violation.</p>
<p style="text-align: center;"><img src="http://www.securitytut.com/images/CCNASecurity/Labsim/PortSecuritySim_Title.jpg" alt="PortSecuritySim_Title.jpg" width="500" height="400" /></p>
<p class="ccnaexplanation">Answer and Explanation</p>
<p><!--adsense--></p>
<p><span id="more-246"></span></p>
<p>The purpose of this sim is straightforward:</p>
<ul>
<li>Limit the maximum number of MAC addresses that are allowed to access the  port to two. </li>
<li>Shutdown the interface when there is a violation.</li>
</ul>
<p>Please remember that we have to access interface Fa0/12 to fulfill the requirements. Before making any configuration, we should use the show running-config to check the status of interface Fa0/12</p>
<p><span class="blueandbold">Switch&gt;</span><span class="pinkandbold">enable</span><br />
 Password: cisco</p>
<p><span class="blueandbold">Switch#</span><span class="pinkandbold">show running-config</span></p>
<p style="text-align: center;"><img src="http://www.securitytut.com/images/CCNASecurity/Labsim/show-running-config.jpg" alt="show-running-config.jpg" width="248" height="171" /></p>
<p>The interface Fa0/12 hasn&#8217;t been configured with anything.</p>
<p><span class="blueandbold">Switch#</span><span class="pinkandbold">configure terminal</span><br />
 <span class="blueandbold">Switch(config)#</span><span class="pinkandbold">interface fa0/12</span><br />
 <span class="blueandbold">Switch(config-if)#</span><span class="pinkandbold">switchport mode access</span><br />
 <span class="blueandbold"> </span></p>
<p>First, enable the &#8220;port security&#8221; feature on this interface:</p>
<p><span class="blueandbold">Switch(config-if)#</span><span class="pinkandbold">switchport port-security</span></p>
<p>Set the maximum number of secure MAC addresses for this interface to 2:</p>
<p><span class="blueandbold">Switch(config-if)#</span><span class="pinkandbold">switchport port-security maximum 2</span></p>
<p>Shutdown if the security is violated:</p>
<p><span class="blueandbold">Switch(config-if)#</span><span class="pinkandbold">switchport port-security violation shutdown</span><br />
 <span class="blueandbold">Switch(config-if)#</span><span class="pinkandbold">no shutdown</span><br />
 <span class="blueandbold">Switch(config-if)#</span><span class="pinkandbold">end</span></p>
<p>Now you should check if the configuration is correct or not by typing the command show port-security interface fa0/12</p>
<p><span class="blueandbold">Switch#</span><span class="pinkandbold">show port-security interface fa0/12</span></p>
<p style="text-align: center;"><img src="http://www.securitytut.com/images/CCNASecurity/Labsim/show_port-security_interface.jpg" alt="show_port-security_interface.jpg" width="382" height="226" /></p>
<p>Notice that the parameters should be like this: <br />
 + Port Security: Enabled<br />
 + Violation Mode: Shutdown<br />
 + Maximum MAC Address: 2</p>
<p>Save the configuration<br />
 <span class="blueandbold">Switch#</span><span class="pinkandbold">copy running-config startup-config</span></p>
<p>Just for your information, when the security is violated the port is in the error-disabled state. We can bring it out of this state by entering the &#8220;errdisable recovery cause psecure-violation&#8221; global configuration command or we can manually re-enable it by entering the &#8220;shutdown&#8221; and &#8220;no shutdown&#8221; commands in the interface configuration.</p>
<p><!--adsense#AfterContent--></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitytut.com/ccna-security/labsim/port-security-lab-sim/feed</wfw:commentRss>
		<slash:comments>66</slash:comments>
		</item>
		<item>
		<title>Zone-based Firewall SDM Simlet</title>
		<link>http://www.securitytut.com/ccna-security/labsim/zone-based-firewall-sdm-simlet</link>
		<comments>http://www.securitytut.com/ccna-security/labsim/zone-based-firewall-sdm-simlet#comments</comments>
		<pubDate>Tue, 14 Sep 2010 15:55:48 +0000</pubDate>
		<dc:creator>securitytut</dc:creator>
				<category><![CDATA[LabSim]]></category>

		<guid isPermaLink="false">http://www.securitytut.com/?p=228</guid>
		<description><![CDATA[Instructions To access the Cisco Router and Security Device Manager(SDM) utility click on the console host icon that is connected to a ISR router.You can click on the grey buttons below to view the different windows. Each of the windows can be minimized by clicking on the [-].You can also reposition a window by dragging [...]]]></description>
			<content:encoded><![CDATA[<p class="blueandbold">Instructions</p>
<p>To access the Cisco Router and Security Device Manager(SDM) utility click on the console host icon that is connected to a ISR router.You can click on the grey buttons below to view the different windows.<br />
 Each of the windows can be minimized by clicking on the [-].You can also reposition a window by dragging it by the title bar.<br />
 The &#8220;Tab&#8221; key and most commands that use the &#8220;Control&#8221;or &#8220;Escape&#8221; keys are not supported and are not necessary to complete this simulation.</p>
<p>(Note: If you don&#8217;t understand how Zone-Based-Firewall works, check out my article at <a href="http://www.securitytut.com/ccna-security-knowledge/cisco-ios-zone-based-firewall-tutorial/" target="_blank">http://www.securitytut.com/ccna-security-knowledge/cisco-ios-zone-based-firewall-tutorial/</a>)</p>
<p><strong>(Notice: the access list, class-map, policy-map, zones, zone-pair&#8230;  in the real exam might be different!)</strong></p>
<p><!--adsense--></p>
<p><span id="more-228"></span></p>
<p class="ccnaquestionsnumber">Question 1</p>
<p>Which two options correctly Identify the associated interface with the correct security zone? (Choose two)</p>
<p>A. FastEthernet0/1 is associated to the &#8220;out-zone&#8221; zone.<br />
 B. FastEthernet0/0 is associated to the &#8220;in-zone&#8221; zone.<br />
 C. FastEthernet0/0 and 0/1 are associated to the &#8220;self&#8221; zone.<br />
 D. FastEthernet0/0 and 0/1 are associated to the &#8220;in-zone&#8221; zone.<br />
 E. FastEthernet0/0 and 0/1 are associated to the &#8220;out-zone&#8221; zone.<br />
 F. FastEthernet0/0 and 0/1 are not associated to any zone.</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> A B</p>
<p class="ccnaexplanation">Explanation</p>
<p>Under the Additional Tasks, click on the Zones group. At the right side box we will see the FastEthernet0/0 is assigned to the in-zone and the FastEthernet0/1 is assigned to the out-zone.</p>
<p><img src="http://www.securitytut.com/images/CCNASecurity/Labsim/ZBF_Zones.jpg" alt="ZBF_Zones.jpg" width="736" height="434" /></p>
<p>(Notice: In the real exam, you might see more zones than the image above)</p>
<p class="ccnaquestionsnumber">Question 2</p>
<p>Which statement is correct regarding the &#8220;sdm-permit&#8221; policy map?</p>
<p>A. Traffic not matched by any of the class maps within that policy map will be inspected .<br />
 B. Traffic matching the &#8220;sdm-access&#8221; traffic class will be inspected.<br />
 C. Traffic matching the &#8220;SDM_CA_SERVER&#8221; traffic class will be dropped.<br />
 D. That policy map is applied to traffic sourced from the &#8220;self&#8221; zone and destined to the &#8220;out-zone&#8221; zone.</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer: </span>B or C</p>
<p class="ccnaexplanation">Explanation</p>
<p>A is not correct because there is a default class-map at the end of this policy map named &#8220;class-default&#8221;. This class-map will drop all the traffic that is not matched with the SDM_CA_SERVER class-map (it works in the same way as the implicit &#8220;deny all&#8221; line at the end of each access list). Therefore traffic not matched by any of the class maps within that policy map will be dropped.</p>
<p>D is not correct because the policy map is applied from the source &#8220;out-zone&#8221; to the destination &#8220;self&#8221;.</p>
<p>We haven&#8217;t had enough information about the correct answer yet, hope someone will describe this question clearly after taking the exam.</p>
<p class="ccnaquestionsnumber">Question 3</p>
<p>Which three protocols are matched by the &#8220;sdm-cls-insp-traffic&#8221; class map? (Choose three)</p>
<p>A. sql-net <br />
 B. pop3<br />
 C. 12tp <br />
 D. ftp</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> A B D</p>
<p class="ccnaexplanation">Explanation</p>
<p>Click on the C3PL\Class Map\<strong>Inspection</strong> group and click on the sdm-cls-insp-traffic line at the upper right side box to see which protocols are matched by the &#8220;sdm-cls-insp-traffic&#8221; class map.</p>
<p style="text-align: center;"><img src="http://www.securitytut.com/images/CCNASecurity/Labsim/ZBF_class-map_sdm-cls-insp-traffic.jpg" alt="ZBF_class-map_sdm-cls-insp-traffic.jpg" width="653" height="585" /></p>
<p class="ccnaquestionsnumber">Question 4</p>
<p>Within the &#8220;sdm-permit&#8221; policy map, what is the action assigned to the traffic class &#8220;class-default&#8221;?</p>
<p>A. inspect <br />
 B. pass <br />
 C. drop <br />
 D. police</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer: </span>C</p>
<p class="ccnaexplanation">Explanation</p>
<p>Under the C3PL\Policy Map\<strong>Protocol Inspection</strong> group we can see the policy maps, which class-maps and which actions are assigned to the class-maps.</p>
<p><img src="http://www.securitytut.com/images/CCNASecurity/Labsim/ZBF_sdm-permit_class-default.jpg" alt="ZBF_sdm-permit_class-default.jpg" width="583" height="440" /></p>
<p class="ccnaquestionsnumber">Question 5</p>
<p>Which policy map is associated to the &#8220;sdm-zp-in-out&#8221; security zone pair?</p>
<p>A. sdm-permit-icmpreply<br />
 B. sdm-permit<br />
 C. sdm-inspect<br />
 D. sdm-insp-traffic</p>
<p><span class="ccnacorrectanswers">Answer:</span> C</p>
<p class="ccnaexplanation">Explanation</p>
<p>There are 2 places where you can get information about the policy map associated to the &#8220;sdm-zp-in-out&#8221; security zone pair:</p>
<p>+ At the &#8220;Home&#8221; tab (you might click on the <img src="http://www.securitytut.com/images/CCNASecurity/Labsim/ZBF_doubled_head-down-arrows.jpg" alt="ZBF_doubled_head-down-arrows.jpg" width="15" height="15" /> to see the Firewall policies)</p>
<p><img src="http://www.securitytut.com/images/CCNASecurity/Labsim/ZBF_sdm-zp-in-out-policy.jpg" alt="ZBF_sdm-zp-in-out-policy.jpg" width="797" height="506" /></p>
<p>+ At the Zone-pair group in the Additional Tasks</p>
<p style="text-align: center;"><img src="http://www.securitytut.com/images/CCNASecurity/Labsim/ZBF_sdm-zp-in-out-policy_ZonePairs.jpg" alt="ZBF_sdm-zp-in-out-policy_ZonePairs.jpg" width="642" height="434" /></p>
<p class="ccnaquestionsnumber">Question 6</p>
<p>Within the &#8220;sdm-inspect&#8221; policy map, what is the action assigned to the traffic class &#8220;sdm-invalid-src&#8221;, and which traffic is matched by the traffic class &#8220;sdm-invalid-src&#8221; ? (Choose two)</p>
<p>A. traffic matched by ACL 105<br />
 B. traffic matched by the nested &#8220;sdm-cls-insp-traffic&#8221; class map<br />
 C. drop/log<br />
 D. traffic matched by ACL 104</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer: </span>A C</p>
<p class="ccnaexplanation">Explanation</p>
<p>Under the &#8220;Firewall and ACL&#8221; tab, search for the &#8220;sdm-inspect&#8221; policy map we can see the access list 105 is used by this policy map. We can also see the action assigned to the traffic class &#8220;sdm-invalid-src&#8221; (drop/log).</p>
<p><img src="http://www.securitytut.com/images/CCNASecurity/Labsim/ZBF_Firewall_access_list.jpg" alt="ZBF_Firewall_access_list.jpg" width="764" height="431" /></p>
<p>Notice that the Access list number can be also seen in the C3PL\Class Map\Inspection and the Drop/log action can be seen in the C3PL\Policy  Map\Protocol Inspection group.</p>
<p><!--adsense#AfterContent--></p>
<p>(Reference: <a href="http://www.cisco.com/en/US/products/ps6441/products_feature_guide09186a008060f6dd.html#wp1063104" target="_blank">http://www.cisco.com/en/US/products/ps6441/products_feature_guide09186a008060f6dd.html#wp1063104</a>)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitytut.com/ccna-security/labsim/zone-based-firewall-sdm-simlet/feed</wfw:commentRss>
		<slash:comments>68</slash:comments>
		</item>
		<item>
		<title>Share your CANAC Experience</title>
		<link>http://www.securitytut.com/canac-642-591/share-your-canac-experience</link>
		<comments>http://www.securitytut.com/canac-642-591/share-your-canac-experience#comments</comments>
		<pubDate>Tue, 14 Sep 2010 13:20:36 +0000</pubDate>
		<dc:creator>securitytut</dc:creator>
				<category><![CDATA[CANAC 642-591]]></category>

		<guid isPermaLink="false">http://www.securitytut.com/?p=569</guid>
		<description><![CDATA[As you know, the CCSP certification requires you to pass 3 exams: SNRS, SNAF, SNAF and one of three optional exams CANAC, MARS or SNAA but currently this site has only materials for CCNA Security 640-553. Many candidates have requested us to put up materials for other exams but it is a time-consuming work. In [...]]]></description>
			<content:encoded><![CDATA[<p>As you know, the CCSP certification requires you to pass 3 exams: SNRS, SNAF, SNAF and one of three optional exams CANAC, MARS or SNAA but currently this site has only materials for CCNA Security 640-553. Many candidates have requested us to put up materials for other exams but it is a time-consuming work. In the mean time, we created the &#8220;Share your experience&#8221; for the CANAC exam. We really hope anyone who read securitytut, 9tut, digitaltut, certprepare, networktut and voicetut contribute to these sections as your experience is invaluable for CCSP learners to complete their goals.</p>
<p class="pinkandbold">Please share with us your experience after taking the CANAC exam, your materials, the way you learned, your recommendations&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitytut.com/canac-642-591/share-your-canac-experience/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Share your SNRS Experience</title>
		<link>http://www.securitytut.com/snrs-642-504/share-your-snrs-experience</link>
		<comments>http://www.securitytut.com/snrs-642-504/share-your-snrs-experience#comments</comments>
		<pubDate>Tue, 14 Sep 2010 13:08:12 +0000</pubDate>
		<dc:creator>securitytut</dc:creator>
				<category><![CDATA[SNRS 642-504]]></category>

		<guid isPermaLink="false">http://www.securitytut.com/?p=567</guid>
		<description><![CDATA[As you know, the CCSP certification requires you to pass 3 exams: SNRS, SNAF, SNAF and one of three optional exams CANAC, MARS or SNAA but currently this site has only materials for CCNA Security 640-553. Many candidates have requested us to put up materials for other exams but it is a time-consuming work. In [...]]]></description>
			<content:encoded><![CDATA[<p>As you know, the CCSP certification requires you to pass 3 exams: SNRS, SNAF, SNAF and one of three optional exams CANAC, MARS or SNAA but currently this site has only materials for CCNA Security 640-553. Many candidates have requested us to put up materials for other exams but it is a time-consuming work. In the mean time, we created the &#8220;Share your experience&#8221; for the SNRS exam. We really hope anyone who read securitytut, 9tut, digitaltut, certprepare, networktut and voicetut contribute to these sections as your experience is invaluable for CCSP learners to complete their goals.</p>
<p class="pinkandbold">Please share with us your experience after taking the SNRS exam, your materials, the way you learned, your recommendations&#8230;</p>
<p><!--adsense--></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitytut.com/snrs-642-504/share-your-snrs-experience/feed</wfw:commentRss>
		<slash:comments>50</slash:comments>
		</item>
		<item>
		<title>Share your SNAF Experience</title>
		<link>http://www.securitytut.com/snaf-642-524/share-your-snaf-experience</link>
		<comments>http://www.securitytut.com/snaf-642-524/share-your-snaf-experience#comments</comments>
		<pubDate>Tue, 14 Sep 2010 13:05:22 +0000</pubDate>
		<dc:creator>securitytut</dc:creator>
				<category><![CDATA[SNAF 642-524]]></category>

		<guid isPermaLink="false">http://www.securitytut.com/?p=565</guid>
		<description><![CDATA[As you know, the CCSP certification requires you to pass 3 exams: SNRS, SNAF, IPS and one of three optional exams CANAC, MARS or SNAA but currently this site has only materials for CCNA Security 640-553. Many candidates have requested us to put up materials for other exams but it is a time-consuming work. In [...]]]></description>
			<content:encoded><![CDATA[<p>As you know, the CCSP certification requires you to pass 3 exams: SNRS, SNAF, IPS and one of three optional exams CANAC, MARS or SNAA but currently this site has only materials for CCNA Security 640-553. Many candidates have requested us to put up materials for other exams but it is a time-consuming work. In the mean time, we created the &#8220;Share your experience&#8221; for the SNAF exam. We really hope anyone who read securitytut, 9tut, digitaltut, certprepare, networktut and voicetut contribute to these sections as your experience is invaluable for CCSP learners to complete their goals.</p>
<p class="pinkandbold">Please share with us your experience after taking the SNAF exam, your materials, the way you learned, your recommendations&#8230;</p>
<p><!--adsense--></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitytut.com/snaf-642-524/share-your-snaf-experience/feed</wfw:commentRss>
		<slash:comments>52</slash:comments>
		</item>
		<item>
		<title>Share your SNAA Experience</title>
		<link>http://www.securitytut.com/snaa-642-515/share-your-snaa-experience</link>
		<comments>http://www.securitytut.com/snaa-642-515/share-your-snaa-experience#comments</comments>
		<pubDate>Tue, 14 Sep 2010 13:02:12 +0000</pubDate>
		<dc:creator>securitytut</dc:creator>
				<category><![CDATA[SNAA 642-515]]></category>

		<guid isPermaLink="false">http://www.securitytut.com/?p=562</guid>
		<description><![CDATA[As you know, the CCSP certification requires you to pass 3 exams: SNRS, SNAF, IPS and one of three optional exams CANAC, MARS or SNAA but currently this site has only materials for CCNA Security 640-553. Many candidates have requested us to put up materials for other exams but it is a time-consuming work. In [...]]]></description>
			<content:encoded><![CDATA[<p>As you know, the CCSP certification requires you to pass 3 exams: SNRS, SNAF, IPS and one of three optional exams CANAC, MARS or SNAA but currently this site has only materials for CCNA Security 640-553. Many candidates have requested us to put up materials for other exams but it is a time-consuming work. In the mean time, we created the &#8220;Share your experience&#8221; for the SNAA exam. We really hope anyone who read securitytut, 9tut, digitaltut, certprepare, networktut and voicetut contribute to these sections as your experience is invaluable for CCSP learners to complete their goals.</p>
<p class="pinkandbold">Please share with us your experience after taking the SNAA exam, your materials, the way you learned, your recommendations&#8230;</p>
<p><!--adsense--></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitytut.com/snaa-642-515/share-your-snaa-experience/feed</wfw:commentRss>
		<slash:comments>15</slash:comments>
		</item>
		<item>
		<title>Share your MARS Experience</title>
		<link>http://www.securitytut.com/mars-642-545/share-your-mars-experience</link>
		<comments>http://www.securitytut.com/mars-642-545/share-your-mars-experience#comments</comments>
		<pubDate>Tue, 14 Sep 2010 13:00:33 +0000</pubDate>
		<dc:creator>securitytut</dc:creator>
				<category><![CDATA[MARS 642-545]]></category>

		<guid isPermaLink="false">http://www.securitytut.com/?p=559</guid>
		<description><![CDATA[As you know, the CCSP certification requires you to pass 3 exams: SNRS, SNAF, IPS and one of three optional exams CANAC, MARS or SNAA but currently this site has only materials for CCNA Security 640-553. Many candidates have requested us to put up materials for other exams but it is a time-consuming work. In [...]]]></description>
			<content:encoded><![CDATA[<p>As you know, the CCSP certification requires you to pass 3 exams: SNRS, SNAF, IPS and one of three optional exams CANAC, MARS or SNAA but currently this site has only materials for CCNA Security 640-553. Many candidates have requested us to put up materials for other exams but it is a time-consuming work. In the mean time, we created the &#8220;Share your experience&#8221; for the MARS exam. We really hope anyone who read securitytut, 9tut, digitaltut, certprepare, networktut and voicetut contribute to these sections as your experience is invaluable for CCSP learners to complete their goals.</p>
<p class="pinkandbold">Please share with us your experience after taking the MARS exam, your materials, the way you learned, your recommendations&#8230;</p>
<p><!--adsense--></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitytut.com/mars-642-545/share-your-mars-experience/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Share your IPS Experience</title>
		<link>http://www.securitytut.com/ips-642-533/share-your-ips-experience</link>
		<comments>http://www.securitytut.com/ips-642-533/share-your-ips-experience#comments</comments>
		<pubDate>Tue, 14 Sep 2010 12:58:35 +0000</pubDate>
		<dc:creator>securitytut</dc:creator>
				<category><![CDATA[IPS 642-533]]></category>

		<guid isPermaLink="false">http://www.securitytut.com/?p=557</guid>
		<description><![CDATA[As you know, the CCSP certification requires you to pass 3 exams: SNRS, SNAF, IPS and one of three optional exams CANAC, MARS or SNAA but currently this site has only materials for CCNA Security 640-553. Many candidates have requested us to put up materials for other exams but it is a time-consuming work. In [...]]]></description>
			<content:encoded><![CDATA[<p>As you know, the CCSP certification requires you to pass 3 exams: SNRS, SNAF, IPS and one of three optional exams CANAC, MARS or SNAA but currently this site has only materials for CCNA Security 640-553. Many candidates have requested us to put up materials for other exams but it is a time-consuming work. In the mean time, we created the &#8220;Share your experience&#8221; for the IPS exam. We really hope anyone who read securitytut, 9tut, digitaltut, certprepare, networktut and voicetut contribute to these sections as your experience is invaluable for CCSP learners to complete their goals.</p>
<p class="pinkandbold">Please share with us your experience after taking the IPS exam, your materials, the way you learned, your recommendations&#8230;</p>
<p><!--adsense--></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitytut.com/ips-642-533/share-your-ips-experience/feed</wfw:commentRss>
		<slash:comments>30</slash:comments>
		</item>
		<item>
		<title>Cisco IOS Zone based Firewall Tutorial</title>
		<link>http://www.securitytut.com/ccna-security-knowledge/cisco-ios-zone-based-firewall-tutorial</link>
		<comments>http://www.securitytut.com/ccna-security-knowledge/cisco-ios-zone-based-firewall-tutorial#comments</comments>
		<pubDate>Wed, 08 Sep 2010 03:40:35 +0000</pubDate>
		<dc:creator>securitytut</dc:creator>
				<category><![CDATA[CCNA Security Knowledge Base]]></category>

		<guid isPermaLink="false">http://www.securitytut.com/?p=546</guid>
		<description><![CDATA[In this tutorial we will learn about Zone Based Firewall, but before digging into details let&#8217;s start with basic concepts. Security zone is a group of interfaces to which a policy can be applied. By default, traffic can flow freely within that zone but all traffic to and from that zone is dropped by default. [...]]]></description>
			<content:encoded><![CDATA[<p>In this tutorial we will learn about Zone Based Firewall, but before digging into details let&#8217;s start with basic concepts.</p>
<p><strong>Security zone</strong> is a group of interfaces to which a policy can be applied. By default, traffic can flow freely within that zone but all traffic to and from that zone is dropped by default. To allow traffic pass between zones, administrators must explicitly declare by creating a zone-pair and a policy for that zone. Another notice is that traffic originated from the router itself is allowed to pass freely.</p>
<p><strong>Zone-pair</strong> allows you to specify a uni-directional firewall policy between two  zones. In other words, a zone-pair specifies the direction of the interesting traffic. This direction is defined by specifying a source and destination zone. Notice that we can&#8217;t defined a zone as both source and destination zone.</p>
<p><strong>Zone Policy</strong> defines what we want to allow or deny to go between zones. For example we just want to allow HTTP while dropping SMTP, ICMP&#8230; We have 3 actions &#8220;pass&#8221;, &#8220;drop&#8221; and &#8220;inspect&#8221;. The &#8220;pass&#8221; and &#8220;drop&#8221; actions are self-explanatory. The action &#8220;inspect&#8221; tell the router to use a pre-defined class-map to filter the traffic.</p>
<p><!--adsense--></p>
<p><span id="more-546"></span>Now enough theory! It&#8217;s time for the configuration.</p>
<p>In this scenario, we are going to configure 2 zones &#8220;inside&#8221; and &#8220;outside&#8221;. In this example, we will configure two tasks:</p>
<p>+ Only allow ping (icmp) traffic from the INSIDE Zone to OUTSIDE Zone (not vice versa).</p>
<p style="text-align: center;"><img src="http://www.securitytut.com/images/CCNASecurity/Knowledge/IOS-Zone-Based-Firewall/topology.jpg" alt="topology.jpg" width="250" height="300" /></p>
<p style="text-align: left;">Notice: you need to make sure all the networks are reachable with a routing protocol before configuring zone-based-firewall.</p>
<p style="text-align: left;">First we divide the networks into 2 zones: Inside and Outside.</p>
<p><strong>Create Inside zone and Outside zone</strong></p>
<p class="codesnippet">Router(config)#zone security INSIDE<br />
 Router(config)#zone security OUTSIDE</p>
<p>(In fact, we don&#8217;t need to type &#8220;exit&#8221; before typing &#8220;zone security OUTSIDE&#8221;)</p>
<p><strong>Assign IP addresses and apply zones to interfaces</strong></p>
<p class="codesnippet">Router(config)#interface fa0/0<br />
 Router(config-if)#ip address 10.0.1.1 255.255.255.0<br />
 Router(config-if)#no shutdown<br />
 Router(config-if)#zone-member security INSIDE</p>
<p class="codesnippet">Router(config)#interface fa0/1<br />
 Router(config-if)#ip address 10.0.2.1 255.255.255.0<br />
 Router(config-if)#no shutdown<br />
 Router(config-if)#zone-member security INSIDE</p>
<p class="codesnippet">Router(config)#interface fa1/0<br />
 Router(config-if)#ip address 12.12.12.1 255.255.255.0<br />
 Router(config-if)#no shutdown<br />
 Router(config-if)#zone-member security OUTSIDE</p>
<p><strong>Define &#8220;interesting&#8221; traffic with class-map</strong></p>
<p class="codesnippet">Router(config)#class-map type inspect match-any CLASS_MAP_IN_TO_OUT<br />
 Router(config-cmap)#match protocol icmp</p>
<p>In the class-map configuration, we have two most used parameters: <strong>match-any</strong> and <strong>match-all</strong>. If match-any is used, trafﬁc must meet only one of the match criteria in the class map. In contrast, if match-all is speciﬁed, trafﬁc must match all the criteria of that class-map. In this example we just want to check if it is &#8220;icmp&#8221; protocol or not so we can use either &#8220;match-any&#8221; or &#8220;match-all&#8221;. Maybe you will ask: &#8220;How can I use &#8220;match-all&#8221; as a packet can&#8217;t match 2 or more protocols?&#8221; The answer is we can use &#8220;match-all&#8221; in order from more speciﬁc to less speciﬁc protocol. For example:</p>
<p class="codesnippet">match protocol http<br />
 match protocol tcp</p>
<p>We defined what traffic we want to monitor. Now we need to specify what we want to do with that traffic.</p>
<p class="codesnippet">Router(config)#policy-map type inspect POLICY_MAP_IN_TO_OUT<br />
 Router(config-pmap)#class type inspect CLASS_MAP_IN_TO_OUT<br />
 Router(config-pmap-c)#inspect</p>
<p>I want to explain more about the &#8220;inspect&#8221; action in the policy-map  POLICY_MAP_IN_TO_OUT. Unlike the &#8220;drop&#8221; and &#8220;pass&#8221; actions, when using  this action we need to tell the router which class-map the router must  look up for the &#8220;interesting traffic&#8221;.</p>
<p>Notice that at the end of each policy-map there is a hidden class <strong>class-default</strong> that drops “all  other” traffic by default, just like the implicit &#8220;deny all&#8221; at the end of each access list. Something like this:</p>
<p class="codesnippet">class class-default<br />
 drop</p>
<p>Ok, mostly done! The last thing is specifying the direction of this firewall (recall that the Zone based Firewall is uni-directional). We do this with a zone-pair.</p>
<p class="codesnippet">Router(config)#zone-pair security ZONE_PAIR_IN_TO_OUT source INSIDE destination OUTSIDE<br />
 Router(config-sec-zone-pair)#service-policy type inspect POLICY_MAP_IN_TO_OUT</p>
<p>As you see, we define the direction by specifying the source and destination. Of course traffic will flow from the source to the destination. In this case we only permit traffic from INSIDE to OUTSIDE.</p>
<p>A big notice is &#8220;return trafﬁc is allowed by default&#8221;. So if a policy permits the traffic in the outbound direction, it also permits the return traffic in the inbound direction.</p>
<p>It is not possible for trafﬁc to ﬂow between an interface that is a  member of a security zone and one that is not a member of a security  zone, because a policy can be applied only between two zones. If an interface on a router cannot be part of a security zone or ﬁrewall policy, it may be necessary to put that interface in a security zone and conﬁgure a “pass all” policy between that zone and other zones where trafﬁc should ﬂow.</p>
<p>In conclusion to configure Zone Based Policy Firewall we need to do these steps:</p>
<p>+ Specify zones. <br />
 + Specify what type of traffic (protocol) we want to monitor with a class-map.<br />
 + Specify what action we want to do (drop, permit or inspect) with a policy-map.<br />
 + Specify the direction we want to apply the filter with a zone-pair.</p>
<p>In this example we configured:</p>
<p>+ Zones: INSIDE and OUTSIDE<br />
 + Type of traffic: icmp (ping)<br />
 + Action: inspect (because we don&#8217;t allow or deny all types of traffic so we must use &#8220;inspect&#8221; action)<br />
 + Direction: INSIDE to OUTSIDE</p>
<p>We can say this firewall in plain text: &#8220;only allow icmp traffic from INSIDE to OUTSIDE, drop other traffic&#8221;.</p>
<p>Now if we make a ping from a PC (INSIDE) to 12.12.12.2 (OUTSIDE) then it works well</p>
<p class="codesnippet">(INSIDE)#ping 12.12.12.2<br />
 !!!!!</p>
<p>but a ping from 12.12.12.2 (OUTSIDE) to a PC (INSIDE) will be dropped</p>
<p class="codesnippet">(OUTSIDE)#ping 10.0.1.1<br />
 &#8230;..</p>
<p><!--adsense#AfterContent--></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitytut.com/ccna-security-knowledge/cisco-ios-zone-based-firewall-tutorial/feed</wfw:commentRss>
		<slash:comments>26</slash:comments>
		</item>
		<item>
		<title>IPsec Site-to-site VPN tutorial</title>
		<link>http://www.securitytut.com/ccna-security-knowledge/ipsec-site-to-site-vpn-tutorial</link>
		<comments>http://www.securitytut.com/ccna-security-knowledge/ipsec-site-to-site-vpn-tutorial#comments</comments>
		<pubDate>Sun, 05 Sep 2010 08:36:19 +0000</pubDate>
		<dc:creator>securitytut</dc:creator>
				<category><![CDATA[CCNA Security Knowledge Base]]></category>

		<guid isPermaLink="false">http://www.securitytut.com/?p=521</guid>
		<description><![CDATA[In this article, I want to introduce about the use of IPsec Site-to-site VPN, why we should use and how to configure it. Nowadays, many companies and corporations have their branch offices far away from its headquarters but they need to communicate as if they were in a LAN. This is the place where site-to-site [...]]]></description>
			<content:encoded><![CDATA[<p>In this article, I want to introduce about the use of IPsec Site-to-site VPN, why we should use and how to configure it.</p>
<p>Nowadays, many companies and corporations have their branch offices far away from its headquarters but they need to communicate as if they were in a LAN. This is the place where site-to-site VPN comes into play. Site-to-site VPNs connect entire networks to each other, for example, they can connect a branch office network to a company headquarters network. In the past, a leased line or Frame Relay connection was required to connect sites, but because most corporations now have Internet access, these connections can be replaced with site-to-site VPNs.</p>
<p style="text-align: center;"><img src="http://www.securitytut.com/images/CCNASecurity/Knowledge/Site-to-site_VPN/Site-to-site_VPN_Concept.jpg" alt="Site-to-site_VPN_Concept.jpg" width="550" height="300" /></p>
<p>Organizations use virtual private networks (VPNs) to create an end-to-end private network connection (tunnel) over third-party networks such as the Internet or extranets. The tunnel eliminates the distance barrier and enables remote users to access central site network resources. However, VPNs cannot guarantee that the information remains secure while traversing the tunnel. For this reason, modern cryptographic methods are applied to VPNs to establish secure, end-to-end, private network connections.</p>
<p><!--adsense--></p>
<p><span id="more-521"></span></p>
<p>The IP Security (IPsec) protocol provides a framework for configuring secure VPNs and is commonly deployed over the Internet to connect branch offices, remote employees, and business partners. It is a reliable way to maintain communication privacy while streamlining operations, reducing costs, and allowing flexible network administration.</p>
<p>IPSec VPN negotiation can be broken down into five steps</p>
<p><strong>Step 1.</strong> An IPsec tunnel is initiated when Host A sends “interesting” traffic to Host B. Traffic is considered interesting when it travels between the IPsec peers and meets the criteria that is defined in the crypto access control list (ACL).</p>
<p style="text-align: center;"><img src="http://www.securitytut.com/images/CCNASecurity/Knowledge/Site-to-site_VPN/Site-to-site_VPN_Step1.jpg" alt="Site-to-site_VPN_Step1.jpg" /></p>
<p><strong>Step 2.</strong> Router1 and Router2 negotiate a Security Association (SA) used to form an IKE Phase 1 tunnel, which is also known as an ISAKMP tunnel.</p>
<p style="text-align: center;"><img src="http://www.securitytut.com/images/CCNASecurity/Knowledge/Site-to-site_VPN/IKE_Phase1.jpg" alt="IKE_Phase1.jpg" /></p>
<p><strong>Step 3.</strong> Within the protection of the IKE Phase 1 tunnel, an IKE Phase 2 tunnel is negotiated and set up. An IKE Phase 2 tunnel is also known as an IPsec tunnel.</p>
<p style="text-align: center;"><img src="http://www.securitytut.com/images/CCNASecurity/Knowledge/Site-to-site_VPN/IKE_Phase1_Phase2_Step3.jpg" alt="IKE_Phase1_Phase2_Step3.jpg" width="400" height="110" /></p>
<p><strong>Step 4.</strong> After the IPsec tunnel is established, interesting trafﬁc ﬂows through the protected IPsec tunnel</p>
<p style="text-align: center;"><img src="http://www.securitytut.com/images/CCNASecurity/Knowledge/Site-to-site_VPN/IKE_Phase1_Phase2_Step4.jpg" alt="IKE_Phase1_Phase2_Step4.jpg" /></p>
<p><strong>Step 5.</strong> After no interesting trafﬁc has been seen for a speciﬁed amount of time, or if the IPsec SA is deleted, the IPsec tunnel is torn down.</p>
<p><strong>Elements of a site-to-site VPN:</strong></p>
<p>+ Headend VPN device: Acts as a VPN termination device, located at a primary network location (for example, a headquarters location)</p>
<p>+ VPN access device: Serves as a VPN termination device, located at a remote ofﬁce</p>
<p>+ Tunnel: Provides a logical connection over which trafﬁc ﬂows (for example, an IP Security [IPsec] tunnel and/or a Generic Router Encapsulation [GRE] tunnel)</p>
<p>+ Broadband service: Transports trafﬁc to and from the Internet (for example, over a cable or DSL connection)</p>
<p>Now you understand the fundamental of IPsec site-to-site VPN. In summary, the site-to-site VPN requires Internet or other common environments as the transport so security is the primary concern and this can be protected by IPsec. IPsec operates at Layer 3 of the OSI model (Network layer) and it is independant of the applications. It means that the applications don&#8217;t require any modifications to use IPsec.</p>
<p><strong>IPsec Modes</strong></p>
<p>IPsec uses 2 modes to establish a secure communication channel between network nodes, Transport mode &amp; Tunnel mode.  These 2 modes are different in what parts of IP headers and payloads are to be kept confidential. In Transport mode, security is provided only for the transport layer and above while Tunnel mode will encapsulate the original IP header and creates a new IP header that is sent unencrypted across the untrusted network. We will not go deeper in these modes to keep this tutorial simple.</p>
<p><strong>IPsec Transforms</strong></p>
<p>IPsec delivers data confidentiality services by executing a &#8220;transform&#8221; on plain text data into a block of ciphertext. Common ciphers used in the IPsec transforms are DES, 3DES, and AES. 3DES and AES are considered to be stronger encryption ciphers than DES, as they use longer encryption keys (128-bit key for 3DES and 256-bit key for AES).</p>
<p><strong>Note:</strong></p>
<p><strong>Confidentiality</strong> ensures that only authorized individuals can view sensitive data. Powerful methods of ensuring confidentiality are encryption and access controls.</p>
<p><strong>Integrity</strong> ensures that data has not been changed by an unauthorized individual.</p>
<p><strong>Availability</strong> ensures that access to the data is uninterrupted. Denial-of-service (DoS) attacks attempt to compromise data availability. These attacks typically try to fail a system using an unexpected condition or input, or fail an entire network with a large quantity of information.</p>
<p><!--adsense#AfterContent--></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitytut.com/ccna-security-knowledge/ipsec-site-to-site-vpn-tutorial/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Security Fundamentals</title>
		<link>http://www.securitytut.com/ccna-security/security-fundamentals</link>
		<comments>http://www.securitytut.com/ccna-security/security-fundamentals#comments</comments>
		<pubDate>Fri, 16 Jul 2010 15:57:04 +0000</pubDate>
		<dc:creator>securitytut</dc:creator>
				<category><![CDATA[CCNA Security]]></category>

		<guid isPermaLink="false">http://www.securitytut.com/?p=226</guid>
		<description><![CDATA[Here you will find answers to Security Fundamentals   Question 1 Which classes does the U.S. government place classified data into? (Choose three) A. SBU B. Confidential C. Secret D. Top-secret Answer: B C D Explanation Data should be classified so that administrators can do their best to secure that data. Below is a common [...]]]></description>
			<content:encoded><![CDATA[<p>Here you will find answers to Security Fundamentals</p>
<p><!--adsense--></p>
<p class="ccnaquestionsnumber"> </p>
<p class="ccnaquestionsnumber">Question 1</p>
<p>Which classes does the U.S. government place classified data into? (Choose three)<br />
 A. SBU<br />
 B. Confidential<br />
 C. Secret<br />
 D. Top-secret</p>
<p><span class="ccnacorrectanswers">Answer:</span> B C D</p>
<p class="ccnaexplanation">Explanation</p>
<p>Data should be classified so that administrators can do their best to secure that data. Below is a common way to classify data that many governments, including the military, use:</p>
<ul>
<li>Unclassified: Data that has little or no confidentiality, integrity, or availability requirements and therefore little effort is made to secure it.</li>
</ul>
<ul>
<li>Sensitive But Unclassified (SBU): Data that could prove embarrassing if revealed, but no great security breach will occur.</li>
</ul>
<ul>
<li> Confidential: Data that must comply with confidentiality requirements. This is the lowest level of classified data in this scheme.</li>
</ul>
<ul>
<li> Secret: Data for which you take significant effort to keep secure. The number of individuals who have access to this data is usually considerably fewer than the number of people who are authorized to access confidential data.</li>
</ul>
<ul>
<li> Top secret: Data for which you make great effort and sometimes incur considerable cost to guarantee its secrecy. Usually a small number of individuals have access to top-secret data, on condition that there is a need to know.</li>
</ul>
<p>But in the U.S, the government only classifies data into three levels: Confidential, Secret and Top Secret.</p>
<p class="ccnaquestionsnumber">Question 2</p>
<p>Which method is of gaining access to a system that bypasses normal security measures?</p>
<p>A. Creating a back door <br />
 B. Starting a Smurf attack <br />
 C. Conducting social engineering <br />
 D. Launching a DoS attack</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> A</p>
<p class="ccnaexplanation">Explanation</p>
<p>A back door is a method of bypassing normal authentication to secure remote access to a computer while attempting to remain undetected. The most common backdoor point is a listening port that provides remote access to the system for users (hackers) who do not have, or do not want to use, access or administrative privileges.</p>
<p class="ccnaquestionsnumber">Question 3</p>
<p>Which statement is true about a Smurf attack?</p>
<p>A. It sends ping requests to a subnet, requesting that devices on that subnet send ping replies to a target system. <br />
 B. It intercepts the third step in a TCP three-way handshake to hijack a session.<br />
 C. It uses Trojan horse applications to create a distributed collection of &#8220;zombie&#8221; computers, which can be used to launch a coordinated DDoS attack. <br />
 D. It sends ping requests in segments of an invalid size.</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer: </span>A</p>
<p class="ccnaexplanation">Explanation</p>
<p>Smurf attacks use ICMP echo request packets directed at IP broadcast addresses from a remote site. The intent is to cause DoS. The smurf program builds a network packet that appears to originate from another address (this is known as spoofing an IP address). The packet contains an ICMP ping message that is addressed to an IP broadcast address, meaning all IP addresses in a given network. The echo responses to the ping message are sent back to the &#8220;victim&#8221; address. Enough pings and resultant echoes can flood the network making it unusable for real traffic.</p>
<p class="ccnaquestionsnumber">Question 4</p>
<p>With the increasing development of network, various network attacks appear. Which statement best describes the relationships between the attack method and the result?</p>
<table border="1">
<tbody>
<tr>
<td>1</td>
<td>Identify operating systems</td>
</tr>
<tr>
<td>2</td>
<td>Determine live hosts</td>
</tr>
<tr>
<td>3</td>
<td>Determine potential vulnerabilities</td>
</tr>
<tr>
<td>4</td>
<td>Identify devices</td>
</tr>
<tr>
<td>5</td>
<td>Identify active services</td>
</tr>
</tbody>
</table>
<p>A.<br />
 Ping Sweep &#8211; 1 and 3<br />
 Port Scan &#8211; 2, 4 and 5</p>
<p>B.<br />
 Ping Sweep &#8211; 2 and 4<br />
 Port Scan &#8211; 1, 3 and 5</p>
<p>C.<br />
 Ping Sweep &#8211; 1 and 5<br />
 Port Scan &#8211; 2, 3 and 4</p>
<p>D.<br />
 Ping Sweep &#8211; 2 and 3<br />
 Port Scan &#8211; 1, 4 and 5</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> B</p>
<p class="ccnaexplanation">Explanation</p>
<p><strong>Ping sweep:</strong> ping a series of IP addresses. Ping replies might indicate to an attacker that network resources can be reached at those IP addresses.<strong> </strong></p>
<p><strong>Port scan:</strong> Searching a network host for open ports. A port scan seeks to identify all listening ports on an identiﬁed host. Port scans often help attackers identify the operating system running on the target system. An attacker might perform a port scan to determine what services are available at speciﬁc IP addresses. For example, the Telnet application communicates on TCP port 23, and Simple Mail Transfer Protocol (SMTP) communicates on TCP port 25&#8230;</p>
<p class="ccnaquestionsnumber">Question 5</p>
<p>Which one is the most important based on the following common elements of a network design?</p>
<p>A. Business needs <br />
 B. Best practices <br />
 C. Risk analysis <br />
 D. Security policy</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> A</p>
<p class="ccnaexplanation">Explanation</p>
<p>Business goals and risk analysis drive the need for network security. Regardless of the security implications, business needs must come first. The security system design must accommodate the goals of the business, not hinder them.</p>
<p><strong>Note:</strong></p>
<p>Business needs mean &#8220;what does your organization want to do with the network?&#8221;</p>
<p><!--adsense#MiddleContent--></p>
<p class="ccnaquestionsnumber">Question 6</p>
<p>How does CLI view differ from a privilege level?</p>
<p>A. A CLI view supports only commands configured for that specific view, whereas a privilege level supports commands available to that level and all the lower levels. <br />
 B. A CLJ view supports only monitoring commands, whereas a privilege level allows a user to make changes to an IOS configuration.<br />
 C. A CLI view and a privilege level perform the same function. However, a CU view is used on a Catalyst switch, whereas a privilege level is used on an IOS router.<br />
 D. A CLI view can function without a AAA configuration, whereas a privilege level requires AAA to be configured.</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> A</p>
<p class="ccnaquestionsnumber">Question 7</p>
<p>What are four methods used by hackers? (Choose four)</p>
<p>A.    social engineering attack<br />
 B.    Trojan horse attack<br />
 C.    front door attacks<br />
 D.    buffer Unicode attack<br />
 E.    privilege escalation attack<br />
 F.    footprint analysis attack</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> A B E F</p>
<p class="ccnaexplanation">Explanation</p>
<p><strong>Social engineering:</strong> Using social skills to manipulate people inside the network to provide the information needed to<br />
 access the network. For example, an outside attacker calls a receptionist and pretends to be a member of the company’s IT department, and he convinces the receptionist to tell him her username and password. The attacker then can use those credentials to log into the network.</p>
<p><strong>Trojan horse:</strong> a piece of software that appears to be a legitimate application but that also performs some unseen malicious functions.</p>
<p><strong>Privilege escalation:</strong> An attacker compromises another subsystem and then, through this compromised subsystem, attacks the application.</p>
<p><strong>Footprinting</strong> is the process of gathering all available information  about a target. A simple example is to use google or yahoo search engine to locate information about employees or the organization itself.</p>
<p class="ccnaquestionsnumber">Question 8</p>
<p>Which protocol will use a LUN as a way to differentiate the individual disk drives that comprise a target device</p>
<p>A. iSCSI <br />
 B. ATA<br />
 C. SCSI<br />
 D. HBA</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> C</p>
<p class="ccnaexplanation">Explanation</p>
<p>In computer storage, a logical unit number (LUN) is an address for an individual disk drive and, by extension, the disk device itself. The term is used in the SCSI protocol as a way to differentiate individual disk drives within a common SCSI target device, such as a disk array.</p>
<p class="ccnaquestionsnumber">Question 9</p>
<p>Which VoIP components can permit or deny a call attempt on the basis of a network&#8217;s available bandwidth?</p>
<p>A. MCU <br />
 B. Gatekeeper <br />
 C. Application server <br />
 D. Gateway</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer: </span>B</p>
<p class="ccnaquestionsnumber">Question 10</p>
<p>Which option ensures that data is not modified in transit</p>
<p>A. Authentication <br />
 B. Integrity <br />
 C. Authorization <br />
 D. Confidentiality</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> B</p>
<div id="_mcePaste" style="overflow: hidden; position: absolute; left: -10000px; top: 1374px; width: 1px; height: 1px;">Ping Sweep &#8211; 1 and<br />
 3</p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p>Port<br />
 Scan -<br />
 2, 4<br />
 and 5<br />
 c<br />
 B.<br />
 Ping<br />
 Sweep<br />
 &#8211; 2 and<br />
 4</p>
<p>Port<br />
 Scan -<br />
 1, 3<br />
 and 5<br />
 c<br />
 c.<br />
 Ping<br />
 Sweep<br />
 &#8211; 1 and<br />
 5</p>
<p>Port<br />
 Scan -<br />
 2, 3<br />
 and 4<br />
 r<br />
 D.<br />
 Ping<br />
 Sweep<br />
 &#8211; 2 and<br />
 3</p>
<p>Port<br />
 Scan -<br />
 1, 4<br />
 and 5</p>
</div>
<p><!--adsense#AfterContent--></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitytut.com/ccna-security/security-fundamentals/feed</wfw:commentRss>
		<slash:comments>25</slash:comments>
		</item>
		<item>
		<title>Access list Questions</title>
		<link>http://www.securitytut.com/ccna-security/access-list-questions</link>
		<comments>http://www.securitytut.com/ccna-security/access-list-questions#comments</comments>
		<pubDate>Thu, 15 Jul 2010 15:56:12 +0000</pubDate>
		<dc:creator>securitytut</dc:creator>
				<category><![CDATA[CCNA Security]]></category>

		<guid isPermaLink="false">http://www.securitytut.com/?p=415</guid>
		<description><![CDATA[Here you will find answers to Access list Questions If you are not sure about Access list, please read my Access List tutorial Question 1 Which statement best describes the Turbo ACL feature? (Choose all that apply) A. The Turbo ACL feature processes ACLs into lookup tables for greater efficiency. B. The Turbo ACL feature [...]]]></description>
			<content:encoded><![CDATA[<p>Here you will find answers to Access list Questions</p>
<p><!--adsense--></p>
<p>If you are not sure about Access list, please read my <a href="http://www.9tut.com/access-list-tutorial" target="_blank">Access List tutorial</a></p>
<p class="ccnaquestionsnumber">Question 1</p>
<p>Which statement best describes the Turbo ACL feature? (Choose all  that apply)</p>
<p>A. The Turbo ACL feature processes ACLs into lookup tables for  greater efficiency.<br />
 B. The Turbo ACL feature leads to increased latency, because the time  it takes to match the packet is variable.<br />
 C. The Turbo ACL feature leads to reduced latency, because the time it  takes to match the packet is fixed and consistent.<br />
 D. Turbo ACLs increase the CPU load by matching the packet to a  predetermined list.</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer: </span>A C</p>
<p class="ccnaquestionsnumber">Question 2</p>
<p>Which statement best describes configuring access control lists to  control Telnet traffic destined to the router itself</p>
<p>A. The ACL must be applied to each vty line individually.<br />
 B. The ACL should be applied to all vty lines in the in direction to  prevent an unwanted user from connecting to an unsecured port. <br />
 C. The ACL is applied to the Telnet port with the ip access-group  command. <br />
 D. The ACL applied to the vty lines has no in or out option like ACL  being applied to an interface.</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> B</p>
<p><span class="ccnaquestionsnumber">Question 3</span></p>
<p>Which description is correct based on the exhibit and partial  configuration?</p>
<p style="text-align: center;"><img src="http://www.securitytut.com/images/CCNASecurity/Misc/access-list.jpg" alt="access-list.jpg" width="546" height="320" /></p>
<p>A. All traffic from network 10.0.0.0 will be permitted.<br />
 B. This ACL will prevent any host on the Internet from spoofing the  inside network address as the source address for packets coming into the  router from the Internet. <br />
 C. Access-list 101 will prevent address spoofing from interface E0.<br />
 D. All traffic destined for network 172.16.150.0 will be denied due to  the implicit deny all.</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> C</p>
<p><!--adsense#MiddleContent--></p>
<p><span class="ccnaquestionsnumber">Question 4</span></p>
<p>Examine the following options, which access list will permit HTTP traffic sourced from host 10.1.129.100 port 3030 destined to host 192.168.1.10</p>
<p>A. access-list 101 permit tcp 10.1.129.0 0.0.0.255 eq www 192.168.1.10 0.0.0.0 eq www <br />
 B. access-list 101 permit tcp 10.1.128.0 0.0.1.255 eq 3030 192.168.1.0 0.0.0.15 eq www <br />
 C. access-list 101 permit tcp host 192.168.1.10 eq 80 10.1.0.0 0.0.255.255 eq 3030 <br />
 D. access-list 101 permit tcp any eq 3030</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer: </span>B</p>
<p><span class="ccnaquestionsnumber">Question 5</span></p>
<p>Which three statements about applying access control lists to a Cisco  router are true? (Choose three)</p>
<p>A. Place more specific ACL entries at the top of the ACL.<br />
 B. ACLs always search for the most specific entry before taking any  filtering action.<br />
 C. Router-generated packets cannot be filtered by ACLs on the router.<br />
 D. Place generic ACL entries at the top of the ACL to filter general  traffic and thereby reduce &#8220;noise&#8221; on the network.<br />
 E. If an access list is applied but is not configured, all traffic will  pass.</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer: </span>A C E</p>
<p><span class="ccnaquestionsnumber">Question 6</span></p>
<p>A standard access control list has been configured on a router and applied to interface Serial 0 in an outbound direction. No ACL is applied to Interface Serial 1 on the same router. What will happen when traffic being filtered by the access list does not match the configured ACL statements for Serial0?</p>
<p>A. The source IP address is checked, and, if a match is not found, traffic is routed out interface Serial 1.<br />
 B. The resulting action is determined by the destination IP address.<br />
 C. The resulting action is determined by the destination IP address and port number. <br />
 D. The traffic is dropped.</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> D</p>
<p><span class="ccnaquestionsnumber">Question 7</span></p>
<p>Which location will be recommended for extended or extended named ACLs?</p>
<p>A. a location as close to the destination traffic as possible <br />
 B. an intermediate location to filter as much traffic as possible<br />
 C. when using the established keyword, a location close to the destination point to ensure that return traffic is allowed <br />
 D. a location as dose to the source traffic as possible</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> D</p>
<p><!--adsense#AfterContent--></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitytut.com/ccna-security/access-list-questions/feed</wfw:commentRss>
		<slash:comments>41</slash:comments>
		</item>
		<item>
		<title>Drag and Drop Questions</title>
		<link>http://www.securitytut.com/ccna-security/drag-and-drop-questions</link>
		<comments>http://www.securitytut.com/ccna-security/drag-and-drop-questions#comments</comments>
		<pubDate>Wed, 14 Jul 2010 06:09:19 +0000</pubDate>
		<dc:creator>securitytut</dc:creator>
				<category><![CDATA[CCNA Security]]></category>

		<guid isPermaLink="false">http://www.securitytut.com/?p=318</guid>
		<description><![CDATA[Here you will find answers to Drag and Drop Questions Notice: In the exam, some Drag and Drop Questions may be represented as multiple-choice questions. Question 1 On the basis of the description of SSL-based VPN, place the correct descriptions in the proper locations. Answer: + The authentication process uses hashing technologies. + Asymmetric algorithms [...]]]></description>
			<content:encoded><![CDATA[<p>Here you will find answers to Drag and Drop Questions</p>
<p><!--adsense--></p>
<p>Notice: In the exam, some Drag and Drop Questions may be represented as multiple-choice questions.</p>
<p class="ccnaquestionsnumber">Question 1</p>
<p>On the basis of the description of SSL-based VPN, place the correct descriptions in the proper locations.</p>
<p style="text-align: center;"><img src="http://www.securitytut.com/images/CCNASecurity/DragandDrop/SSL_based_VPN.jpg" alt="SSL_based_VPN.jpg" width="450" height="500" /></p>
<p><br class="spacer_" /></p>
<p class="ccnacorrectanswers">Answer:</p>
<p>+ The authentication process uses hashing technologies.<br />
 + Asymmetric algorithms are used for authentication and key exchange.<br />
 + Symmetric algorithms are used for bulk encryption.</p>
<p class="ccnaquestionsnumber">Question 2</p>
<p>Which three common examples are of AAA implementation on Cisco routers? Please place the correct descriptions in the proper locations.</p>
<p style="text-align: center;"><img src="http://www.securitytut.com/images/CCNASecurity/DragandDrop/AAA_Implementation.jpg" alt="AAA_Implementation.jpg" width="450" height="550" /></p>
<p><br class="spacer_" /></p>
<p class="ccnacorrectanswers">Answer:</p>
<p>+ performing router commands authorization using TACACS+<br />
 + authenticating remote users who are accessing the corporate LAN through IPSec VPN connections<br />
 + authenticating administrator access to the router console port, auxiliary port, and vty ports</p>
<p><!--adsense#MiddleContent--></p>
<p class="ccnaquestionsnumber">Question 3</p>
<p>Drag two characteristics of the SDM Security Audit wizard on the above to the list on the below.</p>
<p style="text-align: center;"><img src="http://www.securitytut.com/images/CCNASecurity/DragandDrop/SDM_Security_Audit.jpg" alt="SDM_Security_Audit.jpg" width="450" height="450" /></p>
<p><br class="spacer_" /></p>
<p class="ccnacorrectanswers">Answer:</p>
<p>+ requires users to first identify which router interfaces connect to the inside network and which connect to the outside network<br />
 + displays a screen with Fix-it check boxes to let you choose which potential security-related configuration changes to implement</p>
<p class="ccnaquestionsnumber">Question 4</p>
<p>On the basis of the Cisco IOS Zone-Based Policy Firewall, by default, which three types of traffic are permitted by the router when some interfaces of the routers are assigned to a zone?</p>
<p>Drag three proper characterizations on the above to the list on the below.</p>
<p style="text-align: center;"><img src="http://www.securitytut.com/images/CCNASecurity/DragandDrop/Cisco_IOS_Zone_Based_Policy_Firewall.jpg" alt="Cisco_IOS_Zone_Based_Policy_Firewall.jpg" width="450" height="500" /></p>
<p style="text-align: left;"> </p>
<p class="ccnacorrectanswers" style="text-align: left;">Answer:</p>
<p style="text-align: left;">+ traffic flowing among the interfaces that are members of the same zone<br />
 + traffic flowing among the interfaces that are not assigned to any zone<br />
 + traffic flowing to and from the router interfaces (the self zone)</p>
<p class="ccnaquestionsnumber" style="text-align: left;">Question 5</p>
<p style="text-align: left;">Drag three proper statements about the IPsec protocol on the above to the list on the below.</p>
<p style="text-align: center;"><img src="http://www.securitytut.com/images/CCNASecurity/DragandDrop/IPSec_Protocol.jpg" alt="IPSec_Protocol.jpg" width="450" height="550" /></p>
<p style="text-align: left;"> </p>
<p class="ccnacorrectanswers" style="text-align: left;">Answer:</p>
<p style="text-align: left;">Three correct statements are:</p>
<p style="text-align: left;">+ IPsec is a framework of open standards.<br />
 + IPsec ensures data integrity by using checksums.<br />
 + IPsec authenticates users and devices that can carry out communication independently.</p>
<p><!--adsense#AfterContent--></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitytut.com/ccna-security/drag-and-drop-questions/feed</wfw:commentRss>
		<slash:comments>31</slash:comments>
		</item>
		<item>
		<title>Modern Network Security Threats</title>
		<link>http://www.securitytut.com/ccna-security/modern-network-security-threats</link>
		<comments>http://www.securitytut.com/ccna-security/modern-network-security-threats#comments</comments>
		<pubDate>Tue, 13 Jul 2010 15:56:39 +0000</pubDate>
		<dc:creator>securitytut</dc:creator>
				<category><![CDATA[CCNA Security]]></category>

		<guid isPermaLink="false">http://www.securitytut.com/?p=224</guid>
		<description><![CDATA[Here you will find answers to Modern Network Security Questions Question 1 Which item is the great majority of software vulnerabilities that have been discovered? A. Stack vulnerabilities B. Software overflows C. Heap overflows D. Buffer overflows Answer: D Question 2 Which statement is true about vishing? A. Influencing users to forward a call to [...]]]></description>
			<content:encoded><![CDATA[<p>Here you will find answers to Modern Network Security Questions</p>
<p><!--adsense--></p>
<p class="ccnaquestionsnumber">Question 1</p>
<p>Which item is the great majority of software vulnerabilities that have been discovered?</p>
<p>A. Stack vulnerabilities <br />
 B. Software overflows <br />
 C. Heap overflows <br />
 D. Buffer overflows</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> D</p>
<p class="ccnaquestionsnumber">Question 2</p>
<p>Which statement is true about vishing?</p>
<p>A. Influencing users to forward a call to a toll number (for example, a long distance or international number) <br />
 B. Influencing users to provide personal information over the phone<br />
 C. Using an inside facilitator to intentionally forward a call to a toll number (for example, a long distance or international number) <br />
 D. Influencing users to provide personal information over a web page</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> B</p>
<p class="ccnaexplanation">Explanation</p>
<p>Vishing (voice phishing) uses telephony to glean information, such as account details, directly from users. Because many users tend to trust the security of a telephone versus the security of the web, some users are more likely to provide conﬁdential information over the telephone. User education is the most effective method to combat vishing attacks.</p>
<p><!--adsense#MiddleContent--></p>
<p class="ccnaquestionsnumber">Question 3</p>
<p>In a brute-force attack, what percentage of the keyspace must an attacker generally search through until he or she finds the key that decrypts the data?</p>
<p>A. Roughly 66 percent <br />
 B. Roughly 10 percent <br />
 C. Roughly 75 percent <br />
 D. Roughly 50 percent</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer: </span>D</p>
<p class="ccnaquestionsnumber">Question 4</p>
<p>Observe the following options carefully, which two attacks focus on RSA? (Choose all that apply.)</p>
<p>A. DDoS attack <br />
 B. BPA attack<br />
 C. Adaptive chosen ciphertext attack <br />
 D. Man-in-the-middle attack</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> B C</p>
<p><!--adsense#AfterContent--></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitytut.com/ccna-security/modern-network-security-threats/feed</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Securing Network Devices</title>
		<link>http://www.securitytut.com/ccna-security/securing-network-devices</link>
		<comments>http://www.securitytut.com/ccna-security/securing-network-devices#comments</comments>
		<pubDate>Mon, 12 Jul 2010 15:56:02 +0000</pubDate>
		<dc:creator>securitytut</dc:creator>
				<category><![CDATA[CCNA Security]]></category>

		<guid isPermaLink="false">http://www.securitytut.com/?p=222</guid>
		<description><![CDATA[Here you will find answers to Securing Network Devices Questions   Question 1 As a network engineer at securitytut.com, you are responsible for the network. Which one will be necessarily taken into consideration when implementing Syslogging in your network? A. Log all messages to the system buffer so that they can be displayed when accessing [...]]]></description>
			<content:encoded><![CDATA[<p>Here you will find answers to Securing Network Devices Questions</p>
<p><!--adsense--></p>
<p class="ccnaquestionsnumber"> </p>
<p class="ccnaquestionsnumber">Question 1</p>
<p>As a network engineer at securitytut.com, you are responsible for the network. Which one will be necessarily taken into consideration when implementing Syslogging in your network?</p>
<p>A. Log all messages to the system buffer so that they can be displayed when accessing the router.<br />
 B. Use SSH to access your Syslog information.<br />
 C. Enable the highest level of Syslogging available to ensure you log all possible event messages.<br />
 D. Syncronize clocks on the network with a protocol such as Network Time Protocol.</p>
<p><span class="ccnacorrectanswers">Answer:</span> D</p>
<p class="ccnaquestionsnumber">Question 2</p>
<p>Which description is correct when you have generated RSA keys on your Cisco router to prepare for secure device management?</p>
<p>A. All vty ports are automatically enabled for SSH to provide secure management.<br />
 B. The SSH protocol is automatically enabled.<br />
 C. You must then zeroize the keys to reset secure shell before configuring other parameters.<br />
 D. You must then specify the general-purpose key size used for authentication with the crypto key generate rsa general-keys modulus command.</p>
<p><span class="ccnacorrectanswers">Answer: </span>B<br class="spacer_" /></p>
<p class="ccnaquestionsnumber">Question 3</p>
<p>As a candidate for CCNA examination, when you are familiar with the basic commands, if you input the command &#8220;enable secret level 5 password&#8221; in the global mode, what does it indicate?</p>
<p>A. Set the enable secret command to privilege level 5. <br />
 B. The enable secret password is hashed using SHA. <br />
 C. The enable secret password is hashed using MD5.<br />
 D. The enable secret password is encrypted using Cisco proprietary level 5 encryption. <br />
 E. The enable secret password is for accessing exec privilege level 5.</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> E</p>
<p class="ccnaquestionsnumber">Question 4</p>
<p>Please choose the correct description about Cisco Self-Defending Network characteristics.</p>
<table border="1" align="center">
<tbody>
<tr>
<td>1</td>
<td>Interaction amongst services and devices to mitigate attacks</td>
</tr>
<tr>
<td>2</td>
<td>Enabling elements in the networks to be a point of policy enforcement</td>
</tr>
<tr>
<td>3</td>
<td>Security technologies that evolve with emerging attacks</td>
</tr>
</tbody>
</table>
<p>A. INTEGRATED &#8211; 1<br />
 COLLABORATIVE &#8211; 2 <br />
 ADAPTIVE &#8211; 3</p>
<p>B. INTEGRATED &#8211; 2 <br />
 COLLABORATIVE &#8211; 1 <br />
 ADAPTIVE &#8211; 3</p>
<p>C. INTEGRATED &#8211; 2 <br />
 COLLABORATIVE &#8211; 3 <br />
 ADAPTIVE &#8211; 1</p>
<p>D. INTEGRATED &#8211; 3 <br />
 COLLABORATIVE &#8211; 2 <br />
 ADAPTIVE &#8211; 1</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> B</p>
<p class="ccnaquestionsnumber">Question 5</p>
<p>Which three items are Cisco best-practice recommendations for securing a network? (Choose three)</p>
<p>A. Deploy HIPS software on all end-user workstations.<br />
 B. Routinely apply patches to operating systems and applications.<br />
 C. Disable unneeded services and ports on hosts.<br />
 D. Require strong passwords, and enable password expiration.</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> B C D</p>
<p><!--adsense#MiddleContent--></p>
<p class="ccnaquestionsnumber">Question 6</p>
<p>Given the exhibit below. You are a network manager of your company. You are reading your Syslog server reports. On the basis of the Syslog message shown, which two descriptions are correct? (Choose two)</p>
<table border="1">
<tbody>
<tr>
<td>Feb 1 10:12:08 PST: %SYS-5-CONFIG_1: Configured from console by vty0  (10.2.2.6)</td>
</tr>
</tbody>
</table>
<p>A.    This message is a level 5 notification message.<br />
 B.    This message is unimportant and can be ignored.<br />
 C.    This is a normal system-generated information message and does not require further investigation.<br />
 D.    Service timestamps have been globally enabled.</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer: </span>A D</p>
<p class="ccnaexplanation">Explanation</p>
<p>Time stamps can be enabled on a router to either debugging or logging messages independently (sometimes it is really important for the administrators to solve the problems)</p>
<p>This Syslog message indicates that someone has configured the router  using the vty 0 port.</p>
<p>Service timestamps have been enabled with the command &#8220;service timestamps&#8221; in the global configuration mode. For example, we can create a similar message as shown above with the command:</p>
<p>Router(config)# <strong>service timestamps log datetime localtime show-timezone </strong></p>
<p>For your information, below are the Cisco Log Severity Messages:</p>
<table border="1">
<tbody>
<tr style="background-color: #ccff66;">
<td><strong>Syslog Level</strong></td>
<td><strong>Definition</strong></td>
<td><strong>Example</strong></td>
</tr>
<tr>
<td>0: LOG_EMERG</td>
<td>A panic condition normally broadcast to all<br />
 users</td>
<td>Cisco IOS Software<br />
 could not load.</td>
</tr>
<tr>
<td>1: LOG_ALERT</td>
<td>A condition that should be corrected immedi-<br />
 ately, such as a corrupted system database</td>
<td>Temperature too high.</td>
</tr>
<tr>
<td>2: LOG_CRIT</td>
<td>Critical conditions; for example, hard device<br />
 errors</td>
<td>Unable to allocate<br />
 memory.</td>
</tr>
<tr>
<td>3 : LOG_ERR</td>
<td>Errors</td>
<td>Invalid memory size.</td>
</tr>
<tr>
<td>4: LOG_WARNING</td>
<td>Warning messages</td>
<td>Crypto operation<br />
 failed.</td>
</tr>
<tr>
<td>5: LOG_NOTICE</td>
<td>Conditions that are not error conditions, but<br />
 should possibly be handled specially</td>
<td>Interface changed<br />
 state, up or down.</td>
</tr>
<tr>
<td>6: LOG_INFO</td>
<td>Informational messages</td>
<td>Packet denied by ACL</td>
</tr>
<tr>
<td>7: LOG_DEBUG</td>
<td>Messages that contain information normally of<br />
 use only when debugging a program</td>
<td>Packet type invalid.</td>
</tr>
</tbody>
</table>
<p>(Reference: Implementing Cisco IOS Network Security Self-Study)</p>
<p class="ccnaquestionsnumber">Question 7</p>
<p>Examine the following items, which one offers a variety of security solutions, including firewall, IPS, VPN, antispyware, antivirus, and antiphishing features?</p>
<p>A. Cisco 4200 series IPS appliance <br />
 B. Cisco ASA 5500 series security appliance <br />
 C. Cisco IOS router<br />
 D. Cisco PIX 500 series security appliance</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer: </span>B</p>
<p class="ccnaexplanation">Explanation</p>
<p><strong>Cisco ASA 5500 series Adaptive Security Appliances</strong> are easy-to-deploy solutions that integrate world-class firewall, Cisco Unified Communications (voice and video) security, Secure Sockets Layer (SSL) and IPsec VPN, IPS, and content security services in a flexible, modular product family.</p>
<p><strong>Cisco IPS 4200 series:</strong> Cisco IPS 4200 series sensors offer significant protection to your network by helping to detect, classify, and stop threats, including worms, spyware and adware, network viruses, and application abuse.</p>
<p><strong>The Cisco PIX 500 series Security Appliances</strong> deliver robust user and application policy enforcement, multivector attack protection, and secure connectivity services in cost-effective, easy-to-deploy solutions.</p>
<p class="ccnaquestionsnumber">Question 8</p>
<p>For the following items, which management topology keeps management traffic isolated from production traffic?</p>
<p>A. OOB <br />
 B. SAFE<br />
 C. MARS<br />
 D. OTP</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> A</p>
<p class="ccnaexplanation">Explanation</p>
<p>Two primary schools of thought exist about how management trafﬁc should be sent between a management station and a managed device. One approach is to allow management trafﬁc to traverse a production data network. The other approach is to use a separate network to transport management trafﬁc. This approach, where management <br />
 trafﬁc is isolated from production data trafﬁc, is called out-of-band (OOB) management.</p>
<p>(Reference: CCNA Security Official Exam Certification Guide)</p>
<p><span class="ccnaquestionsnumber">Question 9</span></p>
<p>Information about a managed device resources and activity is defined by a series of objects. What defines the structure of these management objects?</p>
<p>A. FIB<br />
 B. LDAP <br />
 C. CEF <br />
 D. MIB</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> D</p>
<p><span class="ccnaexplanation">Explanation</span></p>
<p>Management Information Base (MIB) is the database of confguration variables that resides on the networking device.</p>
<p class="ccnaquestionsnumber">Question 10</p>
<p>Which item is correct regarding Cisco IOS IPS on Cisco IOS Release 12.4(11)T and later?</p>
<p>A. uses Cisco IPS 5.x signature format<br />
 B. supports SDEE, SYSLOG, and SNMP for sending Cisco IPS alerts<br />
 C. requires the Basic or Advanced Signature Definition File<br />
 D. uses the built-in signatures that come with the Cisco IOS image as backup</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> A</p>
<p class="ccnaquestionsnumber">Question 11</p>
<p>If a switch is working in the fail-open mode, what will happen when the switch&#8217;s CAM table fills to capacity and a new frame arrives?</p>
<p>A. The switch sends a NACK segment to the frame&#8217;s source MAC address.<br />
 B. A copy of the frame is forwarded out all switch ports other than the port the frame was received on.<br />
 C. The frame is dropped.<br />
 D. The frame is transmitted on the native VLAN.</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer: </span>B</p>
<p class="ccnaexplanation">Explanation</p>
<p>If that component defaults to a mode in which it forwards trafﬁc, rather than performing its previous security function on that trafﬁc, the component is said to be operating in fail-open mode. However, if a security component denies trafﬁc that it cannot inspect, the component is said to be operating in fail-closed (also known as fail-safe) mode, which would be the more secure of the two modes.</p>
<p>(Reference: CCNA Security Official Exam Certification Guide)</p>
<p class="ccnaquestionsnumber">Question 12</p>
<p>What is the purpose of the secure boot-config global configuration?</p>
<p>A. backs up the Cisco IOS image from flash to a TFTP server <br />
 B. enables Cisco IOS image resilience<br />
 C. takes a snapshot of the router running configuration and securely archives it in persistent storage <br />
 D. stores a secured copy of the Cisco IOS image in its persistent storage</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> C</p>
<p class="ccnaquestionsnumber">Question 13</p>
<p>What Cisco Security Agent Interceptor is in charge of intercepting all read/write requests to the rc files in UNIX?</p>
<p>A. Network interceptor <br />
 B. Configuration interceptor <br />
 C. Execution space interceptor <br />
 D. File system interceptor</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer: </span>B</p>
<p class="ccnaexplanation">Explanation</p>
<p>Configuration interceptor: Read/write requests to the Registry in Windows or to <em>rc</em> configuration files on UNIX are intercepted. This interception occurs because modification of the operating system configuration can have serious consequences. Therefore, Cisco Security Agent tightly controls read/write requests to the Registry.</p>
<p class="ccnaquestionsnumber">Question 14</p>
<p>Which two statements are correct regarding a Cisco IP phone&#8217;s web access feature? (Choose two)</p>
<p>A. It is enabled by default.<br />
 B. It uses HTTPS.<br />
 C. It can provide IP address information about other servers in the network. <br />
 D. It requires login credentials, based on the UCM user database.</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer: </span>A C</p>
<p class="ccnaquestionsnumber">Question 15</p>
<p>When configuring role-based CLI on a Cisco router, which action will be taken first?</p>
<p>A. Create a parser view called &#8220;root view&#8221;<br />
 B. Log in to the router as the root user<br />
 C. Enable role-based CLI globally on the router using the privileged EXEC mode Cisco IOS command<br />
 D. Enable the root view on the router</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer: </span>D</p>
<p class="ccnaquestionsnumber">Question 16</p>
<p>Which key method is used to detect and prevent attacks by use of IDS and/or IPS technologies?</p>
<p>A. Signature-based detection <br />
 B. Anomaly-based detection <br />
 C. Honey pot detection <br />
 D. Policy-based detection</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> A</p>
<p class="ccnaquestionsnumber">Question 17</p>
<p>Which one of the following items may be added to a password stored in MD5 to make it more secure?</p>
<p>A. Rainbow table <br />
 B. Cryptotext <br />
 C. Ciphertext <br />
 D. Salt</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> D</p>
<p><!--adsense#AfterContent--></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitytut.com/ccna-security/securing-network-devices/feed</wfw:commentRss>
		<slash:comments>22</slash:comments>
		</item>
		<item>
		<title>Authentication Authorization &amp; Accounting</title>
		<link>http://www.securitytut.com/ccna-security/authentication-authorization-accounting</link>
		<comments>http://www.securitytut.com/ccna-security/authentication-authorization-accounting#comments</comments>
		<pubDate>Sun, 11 Jul 2010 15:55:35 +0000</pubDate>
		<dc:creator>securitytut</dc:creator>
				<category><![CDATA[CCNA Security]]></category>

		<guid isPermaLink="false">http://www.securitytut.com/?p=220</guid>
		<description><![CDATA[Here you will find answers to Authentication Authorization &#38; Accounting Questions Question 1 How do you define the authentication method that will be used with AAA? A. With a method list B. With the method command C. With the method aaa command D. With a method statement Answer: A Explanation A method list is a [...]]]></description>
			<content:encoded><![CDATA[<p>Here you will find answers to Authentication Authorization &amp; Accounting Questions</p>
<p><!--adsense--></p>
<p class="ccnaquestionsnumber">Question 1</p>
<p>How do you define the authentication method that will be used with AAA?</p>
<p>A. With a method list <br />
 B. With the method command <br />
 C. With the method aaa command <br />
 D. With a method statement</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> A</p>
<p class="ccnaexplanation">Explanation</p>
<p>A method list is a sequential list of authentication methods to query to authenticate a user. Method lists enable you to designate one or more security protocols to be used for authentication, thus ensuring a backup system for authentication in case the initial method fails.</p>
<p>When you first enable AAA, there is a default method list named default, which is automatically applied to all interfaces and lines, but which has no authentication methods defined. To configure AAA authentication, you must first either define a list of authentication methods for the default method, or configure your own named method lists and apply them to interfaces or lines. For flexibility, you can apply different method lists to different interfaces and lines. If an interface or line has a nondefault method list applied to it, that method overrides the default method list.</p>
<p>(Reference: Implementing Cisco IOS Network Security &#8211; Self Study)</p>
<p class="ccnaquestionsnumber">Question 2</p>
<p>What is the objective of the aaa authentication login console-in local command?</p>
<p>A. It specifies the login authorization method list named console-in using the local RADIUS username-password database<br />
 B. It specifies the login authorization method list named console-in using the local username-password database on the router<br />
 C. It specifies the login authentication method list named console-in using the local user database on the router<br />
 D. It specifies the login authentication list named console-in using the local username- password database on the router</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> C</p>
<p class="ccnaquestionsnumber">Question 3</p>
<p>Which one of the following commands can be used to enable AAA authentication to determine if a user can access the privilege command level?</p>
<p>A. aaa authentication enable default local <br />
 B. aaa authentication enable level<br />
 C. aaa authentication enable method default<br />
 D. aaa authentication enable default</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> D</p>
<p class="ccnaquestionsnumber">Question 4</p>
<p>Which two ports are used with RADIUS authentication and authorization? (Choose two)</p>
<p>A. TCP port 2002<br />
 B. UDP port 2000<br />
 C. UDP port 1645<br />
 D. UDP port 1812</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer: </span>C D</p>
<p class="ccnaquestionsnumber">Question 5</p>
<p>Which two statements about configuring the Cisco ACS server to perform router command authorization are true? (Choose two)</p>
<p>A. In the ACS User Group setup screen, use the Shell Command Authorization Set options to configure which commands and command arguments to permit or deny.<br />
 B. From the ACS Interface Configuration screen, select RADIUS (Cisco IOS/PIX 6.0), and then enable the Shell (exec) option on the RADIUS Services screen.<br />
 C. When adding the router as an AAA client on the Cisco ACS server, choose the TACACS+ (Cisco IOS) protocol.<br />
 D. Configure the Cisco ACS server to forward authentication of users to an external user databases, like Windows Database.</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> A C</p>
<p class="ccnaquestionsnumber">Question 6</p>
<p>What should be enabled before any user views can be created during role-based CLI configuration?</p>
<p>A. usernames and passwords <br />
 B. secret password for the root user <br />
 C. aaa new-model command <br />
 D. multiple privilege levels</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> C</p>
<p class="ccnaquestionsnumber">Question 7</p>
<p>For the following statements, which one is perceived as a drawback of implementing Fibre Channel Authentication Protocol (FCAP)?</p>
<p>A.    It is restricted in size to only three segments<br />
 B.    It requires the implementation of IKE<br />
 C.    It relies on an underlying Public Key Infrastructure (PKI)<br />
 D.    It requires the use of netBT as the network protocol</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> C</p>
<p class="ccnaexplanation">Explanation</p>
<p>FCAP relies on an underlying public key infrastructure (PKI) to provide enterprise-class security. By using PKI, often present in more security-conscious organizations, as a foundational element, along with a certiﬁcate-based protocol, FCAP provides numerous advantages. Central among these are strong authentication and management data integrity. <br />
 For some organizations, the complexities associated with a PKI can be daunting. This is the only signiﬁcant argument against FCAP.</p>
<p>(Reference: CCNA Security Official Exam Certification Guide)</p>
<p><!--adsense#MiddleContent--></p>
<p class="ccnaquestionsnumber">Question 8</p>
<table style="background-color: #ffff99;" border="1">
<tbody>
<tr>
<td>1</td>
<td>Has no option to authorize router commands</td>
</tr>
<tr>
<td>2</td>
<td>Encrypts the entire packet</td>
</tr>
<tr>
<td>3</td>
<td>Combines authentication and authorization functions</td>
</tr>
<tr>
<td>4</td>
<td>Uses TCP port 49</td>
</tr>
</tbody>
</table>
<p>A. TACACS+ &#8211; 1 and 3 <br />
 RADIUS &#8211; 2 and 4</p>
<p>B. TACACS+ &#8211; 2 and 4 <br />
 RADIUS &#8211; 1 and 3</p>
<p>C. TACACS+ &#8211; 1 and 4 <br />
 RADIUS &#8211; 2 and 3</p>
<p>D. TACACS+ &#8211; 2 and 3 <br />
 RADIUS &#8211; 1 and 4</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer: </span>B</p>
<p class="ccnaquestionsnumber">Question 9</p>
<p>Which statement is correct regarding the aaa configurations based on the exhibit provided?</p>
<table style="background-color: #ffff99;" border="1">
<tbody>
<tr>
<td>R(config)# username admin privilege level 15 secret hardtOcRackPw<br />
 R(config)# aaa new-model<br />
 R(config)# aaa authentication login default tacacs+<br />
 R(config)# aaa authentication login test tacacs+ local<br />
 R(config)# line vty 0 4<br />
 R(config-line)# login authentication test<br />
 R(config-line)# line con 0    <br />
 R(config-line)# end</td>
</tr>
</tbody>
</table>
<p>A. The authentication method list used by the console port is named test<br />
 B. The authentication method list used by the vty port is named test<br />
 C. If the TACACS+ AAA server is not available, console access to the router can be authenticated using the local database<br />
 D. If the TACACS+ AAA server is not available, no users will be able to establish a Telnet session with the router</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer: </span>B</p>
<p class="ccnaquestionsnumber">Question 10</p>
<p>Which one of the aaa accounting commands can be used to enable logging of both the start and stop records for user terminal sessions on the router?</p>
<p>A. aaa accounting connection start-stop tacacs+ <br />
 B. aaa accounting network start-stop tacacs+ <br />
 C. aaa accounting exec start-stop tacacs+ <br />
 D. aaa accounting system start-stop tacacs+</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer: </span>C</p>
<p class="ccnaquestionsnumber">Question 11</p>
<p>For the following items ,which one can be used to authenticate the IPsec peers during IKE Phase 1?</p>
<p>A. XAUTH <br />
 B. pre-shared key <br />
 C. integrity check value <br />
 D. Diffie-Hellman Nonce</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> B</p>
<p class="ccnaexplanation">Explanation</p>
<p>Internet Key Exchange (IKE) executes the following phases:</p>
<p>+ IKE Phase 1: Two IPsec peers perform the initial negotiation of SAs. Phase 1 generates an Internet Security<br />
 Association and Key Management Protocol (ISAKMP) SA, used for management traffic. Public key techniques or, alternatively, a pre-shared key, are used to mutually authenticate the communicating parties. Phase 1 operates in either Main Mode or Aggressive Mode. Main Mode protects the identity of the peers, Aggressive Mode does not.</p>
<p>+ IKE Phase 2: SAs are negotiated by the IKE process ISAKMP on behalf of other services, such as IPsec, that need<br />
 encryption key material for operation. IKE Phase 2 is used to build IPsec SAs, which are for passing end-user data.<br />
 Additional service negotiations occur in IKE Phase 1, DPD, Mode Config, and so on.</p>
<p class="ccnaquestionsnumber">Question 12</p>
<p>Which statement is true about a certificate authority (CA)?</p>
<p>A. A trusted third party responsible for signing the private keys of entities in a PKIbased system <br />
 B. A trusted third party responsible for signing the public keys of entities in a PKIbased system <br />
 C. An entity responsible for registering the private key encryption used in a PKI <br />
 D. An agency responsible for granting and revoking public-private key pairs</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer: </span>B</p>
<p class="ccnaquestionsnumber">Question 13</p>
<p>In computer security, AAA commonly stands for &#8220;authentication, authorization and accounting&#8221;. Which three of the following are common examples of AAA implementation on Cisco routers? (Choose three)</p>
<p>A. authenticating remote users who are accessing the corporate LAN through IPSec VPN connections <br />
 B. authenticating administrator access to the router console port, auxiliary port, and vty ports<br />
 C. securing the router by locking down all unused services <br />
 D. performing router commands authorization using TACACS+</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> A B D</p>
<p class="ccnaquestionsnumber">Question 14</p>
<p>When configuring AAA login authentication on Cisco routers, which two authentication methods should be used as the final method to ensure that the administrator can log in to the router in case the external AAA server fails?</p>
<p>A. Group RADIUS <br />
 B. Group TACACS+ <br />
 C. Local <br />
 D. Krb5 <br />
 E. Enable <br />
 F.  If-authenticated</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer: </span>C E</p>
<p class="ccnaexplanation">Explanation</p>
<p>If you are working with multiple authentication methods, it is a best practice to have either local or enable authentication as the ﬁnal method to recover from a severed link to the chosen method server.</p>
<p>Notice:</p>
<p>+ &#8220;Local authentication&#8221;: login authentication method list named console-in using the local username-password database on the router (command: <strong>aaa authentication login console-in local</strong>)</p>
<p>+ &#8220;Enable authentication&#8221;: specify a default login authentication method list using the enable password (command: <strong>aaa authentication login default enable</strong>)</p>
<p><br class="spacer_" /></p>
<p><!--adsense#AfterContent--></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitytut.com/ccna-security/authentication-authorization-accounting/feed</wfw:commentRss>
		<slash:comments>26</slash:comments>
		</item>
		<item>
		<title>Implementing Firewall Technologies</title>
		<link>http://www.securitytut.com/ccna-security/implementing-firewall-technologies</link>
		<comments>http://www.securitytut.com/ccna-security/implementing-firewall-technologies#comments</comments>
		<pubDate>Sat, 10 Jul 2010 15:54:57 +0000</pubDate>
		<dc:creator>securitytut</dc:creator>
				<category><![CDATA[CCNA Security]]></category>

		<guid isPermaLink="false">http://www.securitytut.com/?p=218</guid>
		<description><![CDATA[Here you will find answers to Implementing Firewall Technologies Questions Question 1 Which kind of table will be used by most firewalls today to keep track of the connections through the firewall? A. queuing B. netflow C. dynamic ACL D. reflexive ACL E. state Answer: E Explanation There are four generations of ﬁrewall technologies developed [...]]]></description>
			<content:encoded><![CDATA[<p>Here you will find answers to Implementing Firewall Technologies Questions</p>
<p><!--adsense--></p>
<p class="ccnaquestionsnumber">Question 1</p>
<p>Which kind of table will be used by most firewalls today to keep track of the connections through the firewall?</p>
<p>A. queuing <br />
 B. netflow <br />
 C. dynamic ACL <br />
 D. reflexive ACL <br />
 E. state</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> E</p>
<p class="ccnaexplanation">Explanation</p>
<p>There are four generations of ﬁrewall technologies developed between 1983 and 1995: static packet-ﬁltering ﬁrewalls, circuit-level ﬁrewalls, application layer ﬁrewalls and dynamic packet-ﬁltering ﬁrewalls.</p>
<p>The dynamic packet-ﬁltering ﬁrewalls, sometimes called stateful ﬁrewalls, keeps track of the actual communication process through the use of a state table. The state table is part of the internal structure of the firewall and tracks all sessions and inspects all packets passing through the firewall. These ﬁrewalls operate at Layers 3, 4 and 5.</p>
<p class="ccnaquestionsnumber">Question 2</p>
<p>On the basis of the show policy-map type inspect zone-pair session command output provided in the exhibit. What can be determined about this Cisco IOS zone based firewall policy?</p>
<p><br class="spacer_" /></p>
<table style="background-color: #ffff99;" border="1">
<tbody>
<tr>
<td>Class-map: TEST-Class (match-all) <br />
 Match: access-group 110 <br />
 Match: protocol http <br />
 Inspect<br />
 Established Sessions<br />
 Session 643BCF88 (10.0.2.12:3364) =&gt;(172.26.26.51:80) http SIS_OPEN <br />
 Created 00:00:10, Last heard 00:00:00 <br />
 Bytes sent (initiator, responder) [1268:64324]<br />
 Session 643BB9C8 (10.0.2.12:3361) =&gt;(172.26.26.51:80) http SIS_OPEN <br />
 Created 00:00:16, Last heard 00:00:06 <br />
 Bytes sent (initiator, responder) [2734:38447]<br />
 Session 643BD240 (10.0.2.12:3362) =&gt;(172.26.26.51:80) http SIS_OPEN <br />
 Created 00:00:14, Last heard 00:00:07 <br />
 Bytes sent (initiator, responder) [2219:39813]<br />
 Session 643BBF38 (10.0.2.12:3363) =&gt;(172.26.26.51:80) http SIS_OPEN <br />
 Created 00:00:14, Last heard 00:00:06 <br />
 Bytes sent (initiator, responder) [2106:19895] <br />
 Class-map: class-default (match-any)<br />
 Match: any <br />
 Drop (default action)<br />
 58 packets, 2104 bytes</td>
</tr>
</tbody>
</table>
<p>A. This is an outbound policy (applied to traffic sourced from the more secured zone destined to the less secured zone).<br />
 B. All packets will be dropped since the class-default traffic class is matching all traffic.<br />
 C. This is an inbound policy (applied to traffic sourced from the less secured zone destined to the more secured zone).<br />
 D. Stateful packet inspection will be applied only to HTTP packets that also match ACL 110.</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> D</p>
<p class="ccnaquestionsnumber">Question 3</p>
<p>Which statement best describes Cisco IOS Zone-Based Policy Firewall?</p>
<p>A. A router interface can belong to multiple zones. <br />
 B. The pass action works in only one direction.<br />
 C. Policy maps are used to classify traffic into different traffic classes, and class maps are used to assign action to the traffic classes. <br />
 D. A zone-pair is bidirectional because it specifies traffic flowing among the interfaces within the zone-pair in both directions.</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> B</p>
<p class="ccnaexplanation">Explanation</p>
<p>The Cisco IOS zone-based policy firewall can take three possible actions when you configure it using Cisco SDM:</p>
<ul>
<li>Inspect: This action configures Cisco IOS stateful packet inspection.</li>
<li>Drop: This action is analogous to deny in an ACL.</li>
<li>Pass: This action is analogous to permit in an ACL. The pass action does not track the state of connections or sessions within the traffic; pass allows the traffic only in <strong>one direction</strong>. A corresponding policy must be applied to allow return traffic to pass in the opposite direction.</li>
</ul>
<p><!--adsense#MiddleContent--></p>
<p class="ccnaquestionsnumber">Question 4</p>
<p>When configuring Cisco IOS Zone-Based Policy Firewall, what are the three actions that can be applied to a traffic class? (Choose three)</p>
<p>A. Pass <br />
 B. Police <br />
 C. Inspect <br />
 D. Drop <br />
 E. Queue <br />
 F. Shape</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer: </span>A C D</p>
<p class="ccnaexplanation">Explanation</p>
<p>Please read the explanation of question 3</p>
<p class="ccnaquestionsnumber">Question 5</p>
<p>Which type of firewall is needed to open appropriate UDP ports required for RTP streams?</p>
<p>A. Proxy firewall <br />
 B. Packet filtering firewall <br />
 C. Stateful firewall <br />
 D. Stateless firewall</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer: </span>C</p>
<p class="ccnaquestionsnumber">Question 6</p>
<p>What is a static packet-filtering firewall used for ?</p>
<p>A. It analyzes network traffic at the network and transport protocol layers.<br />
 B. It validates the fact that a packet is either a connection request or a data packet belonging to a connection. <br />
 C. It keeps track of the actual communication process through the use of a state table. <br />
 D. It evaluates network packets for valid data at the application layer before allowing connections.</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> A</p>
<p class="ccnaquestionsnumber">Question 7</p>
<p>Which information is stored in the stateful session flow table while using a stateful firewall?</p>
<p>A. all TCP and UDP header information only<br />
 B. the source and destination IP addresses, port numbers, TCP sequencing information, and additional flags for each TCP or UDP connection associated with a particular session<br />
 C. the outbound and inbound access rules (ACL entries) <br />
 D. the inside private IP address and the translated inside global IP address</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> B</p>
<p class="ccnaquestionsnumber">Question 8</p>
<p>Which firewall best practices can help mitigate worm and other automated attacks?</p>
<p>A. Restrict access to firewalls <br />
 B. Segment security zones <br />
 C. Use logs and alerts <br />
 D. Set connection limits</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer: </span>D</p>
<p class="ccnaquestionsnumber">Question 9</p>
<p>Refer to Cisco IOS Zone-Based Policy Firewall, where will the inspection policy be applied?</p>
<p>A. to the interface <br />
 B. to the zone-pair <br />
 C. to the global service policy <br />
 D. to the zone</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> B</p>
<p class="ccnaquestionsnumber">Question 10</p>
<p>Which two actions can be configured to allow traffic to traverse an interface when zone-based security is being employed? (Choose two)</p>
<p>A. Flow<br />
 B. Inspect <br />
 C. Pass<br />
 D. Allow</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer: </span>B C</p>
<p class="ccnaquestionsnumber">Question 11</p>
<p>Which feature is a potential security weakness of a traditional stateful firewall?</p>
<p>A. It cannot ensure each TCP connection follows a legitimate TCP three-way handshake<br />
 B. It cannot detect application-layer attacks<br />
 C. It cannot support UDP flows<br />
 D. The status of TCP sessions is retained in the state table after the sessions terminate</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> B</p>
<p><!--adsense#AfterContent--></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitytut.com/ccna-security/implementing-firewall-technologies/feed</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>IPsec Questions</title>
		<link>http://www.securitytut.com/ccna-security/ipsec-questions</link>
		<comments>http://www.securitytut.com/ccna-security/ipsec-questions#comments</comments>
		<pubDate>Fri, 09 Jul 2010 15:54:39 +0000</pubDate>
		<dc:creator>securitytut</dc:creator>
				<category><![CDATA[CCNA Security]]></category>

		<guid isPermaLink="false">http://www.securitytut.com/?p=463</guid>
		<description><![CDATA[Here you will find answers to IPsec Questions Question 1 Internet Protocol Security (IPsec) is a protocol suite for securing Internet Protocol (IP) communications by authenticating and encrypting each IP packet of a data stream. IPsec operation requires which two functions? (Choose two) A. using PKI for pre-shared-key authentication B. using AH protocols for encryption [...]]]></description>
			<content:encoded><![CDATA[<p>Here you will find answers to IPsec Questions</p>
<p><!--adsense--></p>
<p class="ccnaquestionsnumber">Question 1</p>
<p>Internet Protocol Security (IPsec) is a protocol suite for securing Internet Protocol (IP) communications by authenticating and encrypting each IP packet of a data stream. IPsec operation requires which two functions? (Choose two)</p>
<p>A. using PKI for pre-shared-key authentication<br />
 B. using AH protocols for encryption and authentication<br />
 C. using IKE to negotiate the SA<br />
 D. using Diffie-Hellman to establish a shared-secret key</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer: </span>C D</p>
<p><span class="ccnaquestionsnumber">Question 2</span></p>
<p>With which three tasks does the IPS Policies Wizard help you? (Choose three)</p>
<p>A. Selecting the interface to which the IPS rule will be applied<br />
 B. Selecting the direction of traffic that will be inspected<br />
 C. Selecting the inspection policy that will be applied to the interface<br />
 D. Selecting the Signature Definition File (SDF) that the router will use</p>
<p><span class="ccnacorrectanswers">Answer:</span> A B D</p>
<p><span class="ccnaquestionsnumber">Question 3</span></p>
<p>Examine the following options ,when editing global IPS settings, which one determines if the IOS-based IPS feature will drop or permit traffic for a particular IPS signature engine while a new signature for that engine is being compiled?</p>
<p>A. Enable Engine Fail Closed<br />
 B. Enable Fail Opened<br />
 C. Enable Signature Default<br />
 D. Enable Default IOS Signature</p>
<p><span class="ccnacorrectanswers">Answer: </span>A</p>
<p><!--adsense#MiddleContent--></p>
<p><span class="ccnaquestionsnumber">Question 4</span></p>
<p>Based on the following items, which two types of interfaces are found on all network-based IPS sensors? (Choose two)</p>
<p>A. Loopback interface<br />
 B. Monitoring interface<br />
 C. Command and control interface<br />
 D. Management interface</p>
<p><span class="ccnacorrectanswers">Answer: </span>B C</p>
<p><!--adsense#AfterContent--></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitytut.com/ccna-security/ipsec-questions/feed</wfw:commentRss>
		<slash:comments>14</slash:comments>
		</item>
		<item>
		<title>Security  Device  Manager SDM</title>
		<link>http://www.securitytut.com/ccna-security/security-device-manager-sdm</link>
		<comments>http://www.securitytut.com/ccna-security/security-device-manager-sdm#comments</comments>
		<pubDate>Thu, 08 Jul 2010 15:54:37 +0000</pubDate>
		<dc:creator>securitytut</dc:creator>
				<category><![CDATA[CCNA Security]]></category>

		<guid isPermaLink="false">http://www.securitytut.com/?p=279</guid>
		<description><![CDATA[Here you will find answers to Security  Device  Manager SDM Questions   Question 1 For the following options, which one accurately matches the CU command(s) to the equivalent SDM wizard that performs similar configuration functions? A. setup exec command and the SDM Security Audit wizard B. auto secure exec command and the SDM One-Step Lockdown [...]]]></description>
			<content:encoded><![CDATA[<p>Here you will find answers to Security  Device  Manager SDM Questions</p>
<p><!--adsense--></p>
<p class="ccnaquestionsnumber"> </p>
<p class="ccnaquestionsnumber">Question 1</p>
<p>For the following options, which one accurately matches the CU command(s) to the equivalent SDM wizard that performs similar configuration functions?</p>
<p>A. setup exec command and the SDM Security Audit wizard</p>
<p>B. auto secure exec command and the SDM One-Step Lockdown wizard</p>
<p>C. aaa configuration commands and the SDM Basic Firewall wizard</p>
<p>D. Cisco Common Classification Policy Language configuration commands and the SDM Site-to-Site VPN wizard</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> B</p>
<p class="ccnaquestionsnumber">Question 2</p>
<p>Which three statements are valid SDM configuration wizards? (Choose three)</p>
<p>A. Security Audit</p>
<p>B. VPN</p>
<p>C. STP</p>
<p>D. NAT</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> A B D</p>
<p class="ccnaquestionsnumber">Question 3</p>
<p>Which two protocols enable Cisco SDM to pull IPS alerts from a Cisco ISR router? (Choose two)</p>
<p>A:FTP</p>
<p>B:HTTPS</p>
<p>C.TFTP</p>
<p>D.SSH</p>
<p>E.Syslog</p>
<p>F.SDEE</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer: </span>B F</p>
<p class="ccnaquestionsnumber">Question 4</p>
<p>When using the Cisco SDM Quick Setup Site-to-Site VPN wizard, which three parameters do you configure? (Choose three)</p>
<p>A. Interface for the VPN connection</p>
<p>B. IP address for the remote peer</p>
<p>C. Transform set for the IPsec tunnel</p>
<p>D. Source interface where encrypted traffic originates</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer: </span>A B D</p>
<p class="ccnaexplanation">Explanation</p>
<p>The image below shows parameters when using Cisco SDM Quick Setup Site-to-Site VPN wizard</p>
<p style="text-align: center;"><img src="http://www.securitytut.com/images/CCNASecurity/SDM/SDM-Site-to-site-VPN.jpg" alt="SDM-Site-to-site-VPN.jpg" width="580" height="451" /></p>
<p><!--adsense#MiddleContent--></p>
<p class="ccnaquestionsnumber">Question 5</p>
<p>If you click the Configure button along the top of Cisco SDM&#8217;s graphical interface,which Tasks button permits you to configure such features as SSH, NTP, SNMP, and syslog?</p>
<p>A. Additional Tasks</p>
<p>B. Security Audit</p>
<p>C. Intrusion Prevention</p>
<p>D. Interfaces and Connections</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer: </span>A</p>
<p class="ccnaquestionsnumber">Question 6</p>
<p>Cisco SDM (Security Device Manager) is a Web-based device management tool for Cisco routers that can simplify router deployments and reduce ownership costs. Select two protocols from the following to enable Cisco SDM to pull IPS alerts from a Cisco ISR router. (Choose two)</p>
<p>A. TFTP</p>
<p>B. SDEE</p>
<p>C. SSH</p>
<p>D. HTTPS</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> B D</p>
<p class="ccnaexplanation">Explanation</p>
<p>We must also enable HTTP or HTTPS on the router when we enable SDEE. The use of HTTPS ensures that data is secured as it traverses the network.</p>
<p class="ccnaquestionsnumber">Question 7</p>
<p>Refer to the exhibit. You are the network security administrator responsible for router security. Your network uses internal IP addressing according to RFC 1918 specifications. From the default rules shown, which access control list would prevent IP address spoofing of these internal networks?</p>
<p style="text-align: center;"><img src="http://www.securitytut.com/images/CCNASecurity/SDM/IP_address_snooping_RFC.jpg" alt="IP_address_snooping_RFC.jpg" width="600" height="310" /></p>
<p><br class="spacer_" /></p>
<p>A. SDM_Default_196 <br />
 B. SDM_Default_197 <br />
 C. SDM_Default_198<br />
 D. SDM_Default_199</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer: </span>C</p>
<p class="ccnaexplanation">Explanation</p>
<p>Click on each access-list, in the SDM_DEFAULT_198 you will see something like this</p>
<p style="text-align: center;"><img src="http://www.securitytut.com/images/CCNASecurity/SDM/IP_address_snooping_RFC_explain.jpg" alt="IP_address_snooping_RFC_explain.jpg" width="600" height="381" /></p>
<p>To mitigate IP address spooﬁng, do not allow any IP packets containing  the source address of any internal hosts or networks inbound to our  private network. The SDM_DEFAULT_198 denies all packets containing the following IP addresses in their source field:</p>
<p>+ Current network 0.0.0.0/8 (only valid as source address)<br />
 + Any local host addresses (127.0.0.0/8)<br />
 + Any reserved private addresses (RFC 1918, Address Allocation for Private Internets)<br />
 + Any addresses in the IP multicast address range (224.0.0.0/4)</p>
<p>Note: 0.0.0.0/8: addresses in this block refer to source hosts on &#8220;this&#8221; network.</p>
<p>For your information, we will apply this access list to the external interface of the router.</p>
<p class="ccnaquestionsnumber">Question 8</p>
<p>Refer to the exhibit. Based on the VPN connection shown, which statement is true?</p>
<p><img src="http://www.securitytut.com/images/CCNASecurity/SDM/SDM-VPN.jpg" alt="SDM-VPN.jpg" width="900" height="499" /></p>
<p>A. Traffic that matches access list 103 will be protected.<br />
 B. This VPN configuration will not work because the tunnel IP and peer IP are the same.<br />
 C. The tunnel is down as result of being a static rule. It should be configured as a Dynamic IPsec policy.<br />
 D. The tunnel is down because the transform set needs to Include the Authentication Header parameter.</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> A</p>
<p><!--adsense#AfterContent--></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitytut.com/ccna-security/security-device-manager-sdm/feed</wfw:commentRss>
		<slash:comments>29</slash:comments>
		</item>
		<item>
		<title>Implementing Intrusion Prevention</title>
		<link>http://www.securitytut.com/ccna-security/implementing-intrusion-prevention</link>
		<comments>http://www.securitytut.com/ccna-security/implementing-intrusion-prevention#comments</comments>
		<pubDate>Wed, 07 Jul 2010 15:54:23 +0000</pubDate>
		<dc:creator>securitytut</dc:creator>
				<category><![CDATA[CCNA Security]]></category>

		<guid isPermaLink="false">http://www.securitytut.com/?p=216</guid>
		<description><![CDATA[Here you will find answers to Implementing Intrusion Prevention Questions   Question 1 When configuring Cisco IOS login enhancements for virtual connections, what is the &#8220;quiet period&#8221;? A. A period of time when no one is attempting to log in B. The period of time in which virtual logins are blocked as security services fully [...]]]></description>
			<content:encoded><![CDATA[<p>Here you will find answers to Implementing Intrusion Prevention Questions</p>
<p><!--adsense--></p>
<p class="ccnaquestionsnumber"> </p>
<p class="ccnaquestionsnumber">Question 1</p>
<p>When configuring Cisco IOS login enhancements for virtual connections, what is the &#8220;quiet period&#8221;?</p>
<p>A. A period of time when no one is attempting to log in<br />
 B. The period of time in which virtual logins are blocked as security services fully initialize <br />
 C. The period of time in which virtual login attempts are blocked, following repeated failed login attempts<br />
 D. The period of time between successive login attempts</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> C</p>
<p class="ccnaexplanation">Explanation</p>
<p>If the configured number of connection attempts fails within a specified time period, the Cisco IOS device does not accept any additional connections for a period of time that is called the quiet period. This feature is not enabled by default, we can enable its default settings, issue the <strong>login block-for</strong> command in global configuration mode. Administrators can use this feature to protect from DoS and/or dictionary attacks.</p>
<p class="ccnaquestionsnumber">Question 2</p>
<p>Which result is of securing the Cisco IOS image by use of the Cisco IOS image resilience feature?</p>
<p>A. When the router boots up, the Cisco IOS image will be loaded from a secured FTP location. <br />
 B. The Cisco IOS image file will not be visible in the output from the show flash command. <br />
 C. The show version command will not show the Cisco IOS image file location. <br />
 D. The running Cisco IOS image will be encrypted and then automatically backed up to a TFTP server.</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> B</p>
<p class="ccnaexplanation">Explanation</p>
<p>We can enable this feature with the secure boot-image command in the global configuration mode to secure the Cisco IOS image. The running image is secured and the image file is not included in any directory listing of the disk.</p>
<p class="ccnaquestionsnumber">Question 3</p>
<p>Which description is true about the show login command output displayed in the exhibit?</p>
<table style="background-color: #ffff99;" border="1">
<tbody>
<tr>
<td><strong>Router# show login</strong></p>
<p><br class="spacer_" /></p>
<p>A default login delay of 1 seconds is applied.<br />
 No Quiet-Mode access list has been configured.<br />
 All successful login is logged and generate SNMP traps.<br />
 All failed login is logged and generate SNMP traps.<br />
 Router enabled to watch for login Attacks.<br />
 If more than 2 login failures occur in 100 seconds or less, logins will  be disabled<br />
 for 100 seconds. <br />
 Router presently in Quiet-Mode, will remain in Quiet-Mode for 93 seconds.<br />
 Denying logins from all sources.</p>
</td>
</tr>
</tbody>
</table>
<p>A. All logins from any sources are blocked for another 193 seconds. <br />
 B. The login block-for command is configured to block login hosts for 93 seconds.<br />
 C. When the router goes into quiet mode, any host is permitted to access the router via Telnet, SSH, and HTTP, since the quiet-mode access list has not been configured.<br />
 D. Three or more login requests have failed within the last 100 seconds.</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer: </span>D</p>
<p><!--adsense#MiddleContent--></p>
<p><span class="ccnaquestionsnumber">Question 4</span></p>
<p>After enabling port security on a Cisco Catalyst switch, what is the default action when the configured maximum of allowed MAC addresses value is exceeded?</p>
<p>A. The port is shut down. <br />
 B. The port&#8217;s violation mode is set to restrict.<br />
 C. The MAC address table is cleared and the new MAC address is entered into the table. <br />
 D. The port remains enabled, but bandwidth is throttled until old MAC addresses are aged out.</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer: </span>A</p>
<p class="ccnaquestionsnumber">Question 5</p>
<p>When configuring SSH, which is the Cisco minimum recommended modulus value?</p>
<p>A. 2048 bits<br />
 B. 256 bits<br />
 C. 1024 bits<br />
 D. 512 bits</p>
<p><span class="ccnacorrectanswers">Answer: </span>C</p>
<p class="ccnaquestionsnumber">Question 6</p>
<p>Examine the following options , which Spanning Tree Protocol (STP) protection mechanism disables a switch port if the port receives a Bridge Protocol Data Unit (BPDU)?</p>
<p>A. PortFast <br />
 B. BPDU Guard <br />
 C. UplinkFast <br />
 D. Root Guard</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> B</p>
<p class="ccnaquestionsnumber">Question 7</p>
<p>For the following options, which feature is the foundation of Cisco Self-Defending Network technology?</p>
<p>A. policy management<br />
 B. secure connectivity<br />
 C. threat control and containment <br />
 D. secure network platform</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> D</p>
<p class="ccnaquestionsnumber">Question 8</p>
<p>Which type of intrusion prevention technology will be primarily used by the Cisco IPS security appliances?</p>
<p>A. rule-based<br />
 B. protocol analysis-based<br />
 C. signature-based <br />
 D. profile-based</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> C</p>
<p><span class="ccnaquestionsnumber">Question 9</span></p>
<p>What will be enabled by the scanning technology &#8211; The Dynamic Vector Streaming (DVS)?</p>
<p>A. Firmware-level virus detection<br />
 B. Layer 4 virus detection<br />
 C. Signature-based spyware filtering<br />
 D. Signature-based virus filtering</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> C</p>
<p class="ccnaexplanation">Explanation</p>
<p>The DVS engine is a new scanning technology that enables signature-based spyware ﬁltering. This solution is complemented by a comprehensive set of management and reporting tools that provide ease of administration and complete visibility into threat-related activities.</p>
<p class="ccnaquestionsnumber">Question 10</p>
<p>Which statement is not a reason for an organization to incorporate a SAN in its enterprise infrastructure?</p>
<p>A. To increase the performance of long-distance replication, backup, and recovery <br />
 B. To decrease the threat of viruses and worm attacks against data storage devices <br />
 C. To decrease both capital and operating expenses associated with data storage <br />
 D. To meet changing business priorities, applications, and revenue growth</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> B</p>
<p class="ccnaquestionsnumber">Question 11</p>
<p>Which two functions are required for IPsec  operation? (Choose two)</p>
<p>A. using AH protocols for encryption and  authentication<br />
 B. using SHA for encryption<br />
 C. using DifTie-Hellman to establish a shared-secret key<br />
 D. using PKI for pre-shared-key authentication<br />
 E. using IKE to negotiate the SA</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> C E</p>
<p class="ccnaquestionsnumber">Question 12</p>
<p>In your company&#8217;s network, an attacker who has configured a rogue layer 2 device is intercepting traffic from multiple VLANS to capture potentially sensitive data. How to solve this problem? (Choose two)</p>
<p>A.    Secure the native VLAN, VLAN 1 with encryption<br />
 B.    Disable DTP on ports that require trunking<br />
 C.    Place unused active ports in an unused VLAN<br />
 D.    Set the native VLAN on the trunk ports to an unused VLAN</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> B D</p>
<p><!--adsense#AfterContent--></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitytut.com/ccna-security/implementing-intrusion-prevention/feed</wfw:commentRss>
		<slash:comments>19</slash:comments>
		</item>
		<item>
		<title>Securing Local Area Networks</title>
		<link>http://www.securitytut.com/ccna-security/securing-local-area-networks</link>
		<comments>http://www.securitytut.com/ccna-security/securing-local-area-networks#comments</comments>
		<pubDate>Tue, 06 Jul 2010 15:53:47 +0000</pubDate>
		<dc:creator>securitytut</dc:creator>
				<category><![CDATA[CCNA Security]]></category>

		<guid isPermaLink="false">http://www.securitytut.com/?p=214</guid>
		<description><![CDATA[Here you will find answers to Securing Local Area Networks Questions Question 1 You suspect an attacker in your network has configured a rogue layer 2 device to intercept traffic from multiple VLANS, thereby allowing the attacker to capture potentially sensitive data. Which two methods will help to mitigate this type of activity? (Choose two) [...]]]></description>
			<content:encoded><![CDATA[<p>Here you will find answers to Securing Local Area Networks Questions</p>
<p><!--adsense--></p>
<p class="ccnaquestionsnumber">Question 1</p>
<p>You suspect an attacker in your network has configured a rogue layer 2 device to intercept traffic from multiple VLANS, thereby allowing the attacker to capture potentially sensitive data. Which two methods will help to mitigate this type of activity? (Choose two)</p>
<p>A. Turn off all trunk ports and manually configure each VLAN as required on each port<br />
 B. Disable DTP on ports that require trunking<br />
 C. Secure the native VLAN, VLAN 1 with encryption<br />
 D. Set the native VLAN on the trunk ports to an unused VLAN <br />
 E. Place unused active ports in an unused VLAN</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> B D</p>
<p class="ccnaquestionsnumber">Question 2</p>
<p>In an IEEE 802. lx deployment, between which two  devices EAPOL messages typically are sent?</p>
<p>A. Between the RADIUS  server and the authenticator <br />
 B. Between the authenticator and the authentication server <br />
 C. Between the supplicant and the authentication server <br />
 D. Between the supplicant and the authenticator</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer: </span>D</p>
<p class="ccnaexplanation">Explanation</p>
<p>On many networks, a PC sends a DHCP request to obtain an IP address for use on the network. However, with Cisco Identity-Based Networking Services (IBNS), an 802.1x-enabled PC initially sends an Extensible Authentication Protocol over LAN (EAPOL) request. The Cisco Catalyst switch connected to the PC sees the EAPOL request and responds to the PC with a challenge. The challenge asks the PC to provide credentials for network access, such as a valid username and password combination. The switch forwards these credentials to a RADIUS server for veriﬁcation. Upon veriﬁcation of the supplied credentials, the switch grants the PC access to the network.</p>
<p>In this question, the supplicant is the 802.1x-enabled PC and the authenticator is the secured switch.</p>
<p><!--adsense#AfterContent--></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitytut.com/ccna-security/securing-local-area-networks/feed</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Storage Area Network SAN</title>
		<link>http://www.securitytut.com/ccna-security/storage-area-network-san</link>
		<comments>http://www.securitytut.com/ccna-security/storage-area-network-san#comments</comments>
		<pubDate>Mon, 05 Jul 2010 15:53:39 +0000</pubDate>
		<dc:creator>securitytut</dc:creator>
				<category><![CDATA[CCNA Security]]></category>

		<guid isPermaLink="false">http://www.securitytut.com/?p=395</guid>
		<description><![CDATA[Here you will find answers to Storage Area Network SAN Questions Note: A storage-area network (SAN) is a specialized network that enables fast, reliable access among servers and external storage resources. Question 1 Which two primary port authentication protocols are used with VSANs? (Choose two.) A. ESP B. CHAP C. DHCHAP D. SPAP Answer: B [...]]]></description>
			<content:encoded><![CDATA[<p>Here you will find answers to Storage Area Network SAN Questions</p>
<p><!--adsense--></p>
<p><br class="spacer_" /></p>
<p>Note: A storage-area network (SAN) is a specialized network that enables fast, reliable access among servers and external<br />
 storage resources.</p>
<p class="ccnaquestionsnumber">Question 1</p>
<p>Which two primary port authentication protocols are used with VSANs? (Choose two.)</p>
<p>A. ESP <br />
 B. CHAP <br />
 C. DHCHAP <br />
 D. SPAP</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> B C</p>
<p class="ccnaexplanation">Explanation</p>
<p>Two primary port authentication protocols when working with VSANs:</p>
<p>+ Challenge Handshake Authentication Protocol (CHAP): CHAP is the mandatory protocol for iSCCI, as chosen by the Internet Engineering Task Force (IETF). CHAP is based on shared secrets.</p>
<p>+ Difﬁe-Hellman Challenge Handshake Authentication Protocol (DHCHAP): DHCHAP may be used to authenticate devices connecting to a Fibre Channel switch. By using Fibre Channel authentication, you allow only trusted devices to be added to a fabric. This prevents unauthorized devices from accessing the Fibre Channel switch.</p>
<p><!--adsense#AfterContent--></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitytut.com/ccna-security/storage-area-network-san/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Cryptographic Systems</title>
		<link>http://www.securitytut.com/ccna-security/cryptographic-systems</link>
		<comments>http://www.securitytut.com/ccna-security/cryptographic-systems#comments</comments>
		<pubDate>Sun, 04 Jul 2010 15:51:26 +0000</pubDate>
		<dc:creator>securitytut</dc:creator>
				<category><![CDATA[CCNA Security]]></category>

		<guid isPermaLink="false">http://www.securitytut.com/?p=209</guid>
		<description><![CDATA[Here you will find answers to Cryptographic Systems Questions Question 1 Please choose the correct matching relationships between the cryptography algorithms and the type of algorithm. 1 3DES 2 RSA 3 Diffie-Hellman 4 AES 5 IDEA 6 Elliptical Curve A. Symmetric &#8211; 1, 2 and 3 Asymmetric &#8211; 4, 5 and 6 B. Symmetric &#8211; [...]]]></description>
			<content:encoded><![CDATA[<p>Here you will find answers to Cryptographic Systems Questions</p>
<p><!--adsense--></p>
<p><br class="spacer_" /></p>
<p class="ccnaquestionsnumber">Question 1</p>
<p>Please choose the correct matching relationships between the cryptography algorithms and the type of algorithm.</p>
<table border="1">
<tbody>
<tr>
<td>1</td>
<td>3DES</td>
</tr>
<tr>
<td>2</td>
<td>RSA</td>
</tr>
<tr>
<td>3</td>
<td>Diffie-Hellman</td>
</tr>
<tr>
<td>4</td>
<td>AES</td>
</tr>
<tr>
<td>5</td>
<td>IDEA</td>
</tr>
<tr>
<td>6</td>
<td>Elliptical Curve</td>
</tr>
</tbody>
</table>
<p>A. Symmetric &#8211; 1, 2 and 3 <br />
 Asymmetric &#8211; 4, 5 and 6</p>
<p>B. Symmetric &#8211; 1, 4 and 5 <br />
 Asymmetric &#8211; 2, 3 and 6</p>
<p>C. Symmetric &#8211; 2, 4 and 5 <br />
 Asymmetric &#8211; 1, 3 and 6</p>
<p>D. Symmetric &#8211; 2, 5 and 6 <br />
 Asymmetric &#8211; 1, 3 and 4</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer: </span>B</p>
<p class="ccnaquestionsnumber">Question 2</p>
<p>What is the objective of Diffie-Hellman?</p>
<p>A. used for asymmetric public key encryption<br />
 B. used between the initiator and the responder to establish a basic security policy <br />
 C. used to verify the identity of the peer<br />
 D. used to establish a symmetric shared key via a public key exchange process</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer: </span>D</p>
<p class="ccnaquestionsnumber">Question 3</p>
<p>Which description about asymmetric encryption  algorithms is correct?</p>
<p>A. They use different keys for decryption but the same key for  encryption of data<br />
 B. They use the same key for encryption and decryption of data<br />
 C. They use different keys for encryption and decryption of data<br />
 D. They use the same key for decryption but different keys for  encryption of data</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> C</p>
<p class="ccnaquestionsnumber">Question 4</p>
<p>Regarding constructing a good encryption algorithm, what does creating an avalanche effect indicate?</p>
<p>A. Changing only a few bits of a plain-text message causes the ciphertext to be completely different<br />
 B. Changing only a few bits of a ciphertext message causes the plain text to be completely different <br />
 C. Altering the key length causes the plain text to be completely different<br />
 D. Altering the key length causes the ciphertext to be completely different</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer: </span>A</p>
<p><!--adsense#MiddleContent--></p>
<p class="ccnaquestionsnumber">Question 5</p>
<p>Stream ciphers run on which of the following?</p>
<p>A. Individual blocks, one at a time, with the transformations varying during the encryption <br />
 B. Individual digits, one at a time, with the transformations varying during the encryption <br />
 C. Fixed-length groups of digits called blocks <br />
 D. Fixed-length groups of bits called blocks</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> B</p>
<p class="ccnaquestionsnumber">Question 6</p>
<p>Which description is true about ECB mode?</p>
<p>A. ECB mode uses the same 64-bit key to serially encrypt each 56-bit plain-text block.<br />
 B. In ECB mode, each 56-bit plain-text block is exclusive ORed (XORed) bitwise with the previous ciphertext block.<br />
 C. ECB mode uses the same 56-bit key to serially encrypt each 64-bit plain-text block.<br />
 D. In ECB mode, each 64-bit plain-text block is exclusive ORed (XORed) bitwise with the previous ciphertext block.</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> C</p>
<p class="ccnaexplanation">Explanation</p>
<p>ECB mode serially encrypts each 64-bit plaintext block using the same 56-bit key. If two identical plaintext blocks are encrypted using the same key, their ciphertext blocks are the same. Therefore, an attacker could identify similar or identical traffic flowing through a communications channel, and use this information. The attacker could then build a catalogue of messages, which have a certain meaning, and replay them later, without knowing their real meaning. For example, an attacker might capture a login sequence of someone with administrative privilege whose traffic is protected by DES-ECB and then replay it. That risk is undesirable so CBC mode was invented to mitigate this risk.</p>
<p>(Reference: Implementing Cisco IOS Network Security Self Study)</p>
<p class="ccnaquestionsnumber">Question 7</p>
<p>Which example is of a function intended for cryptographic hashing?</p>
<p>A. SHA-135 <br />
 B. MD65 <br />
 C. XR12 <br />
 D. MD5</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer: </span>D</p>
<p class="ccnaquestionsnumber">Question 8</p>
<p>What is the MD5 algorithm used for?</p>
<p>A. takes a variable-length message and produces a 168-bit message digest <br />
 B. takes a fixed-length message and produces a 128-bit message digest <br />
 C. takes a variable-length message and produces a 128-bit message digest <br />
 D. takes a message less than 2A64 bits as input and produces a 160-bit message digest</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> C</p>
<p class="ccnaquestionsnumber">Question 9</p>
<p>Which algorithm was the first to be found suitable for both digital signing and encryption?</p>
<p>A. SHA-1 <br />
 B. MD5 <br />
 C. HMAC <br />
 D. RSA</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> D</p>
<p class="ccnaquestionsnumber">Question 10</p>
<p>Before a Diffie-Hellman exchange may begin, the two parties involved must agree on what?</p>
<p>A. Two nonsecret keys <br />
 B. Two secret numbers <br />
 C. Two secret keys <br />
 D. Two nonsecret numbers</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer: </span>D</p>
<p class="ccnaquestionsnumber">Question 11</p>
<p>Which item is the correct matching relationships associated with IKE Phase?</p>
<table border="1">
<tbody>
<tr>
<td>1</td>
<td>Perform a Diffie-Hellman exchange</td>
</tr>
<tr>
<td>2</td>
<td>Establish Ipsec SAs</td>
</tr>
<tr>
<td>3</td>
<td>Negotiate Ipsec security policies</td>
</tr>
<tr>
<td>4</td>
<td>Negotiate IKE policy sets and authenticate peers</td>
</tr>
<tr>
<td>5</td>
<td>Perform an optional Diffie-Hellman exchange</td>
</tr>
</tbody>
</table>
<p>A.IKE Phase 1 &#8211; 1 and 2<br />
 IKE Phase 2 &#8211; 3, 4 and 5</p>
<p>B. IKE Phase 1 &#8211; 1 and 4<br />
 IKE Phase 2 &#8211; 2, 3 and 5</p>
<p>C. IKE Phase 1 &#8211; 2 and 3<br />
 IKE Phase 2 &#8211; 1, 4 and 5</p>
<p>D. IKE Phase 1 &#8211; 2 and 4<br />
 IKE Phase 2 &#8211; 1, 3 and 5</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer: </span>B</p>
<p class="ccnaquestionsnumber">Question 12</p>
<p>Which three are distinctions between asymmetric and symmetric algorithms? (Choose all that apply)</p>
<p>A. Asymmetric algorithms are based on more complex mathematical computations.<br />
 B. Only symmetric algorithms have a key exchange technology built in. <br />
 C. Only asymmetric algorithms have a key exchange technology built in.<br />
 D. Asymmetric algorithms are used quite often as key exchange protocols for symmetric algorithms.</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer: </span>A C D</p>
<p class="ccnaquestionsnumber">Question 13</p>
<p>For the following statements, which one is the strongest symmetrical encryption algorithm?</p>
<p>A. 3DES <br />
 B. DES <br />
 C. AES <br />
 D. Diffie-Hellman</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> C</p>
<p class="ccnaquestionsnumber">Question 14</p>
<p>Which Public Key Cryptographic Standards (PKCS) defines the syntax for encrypted messages and messages with digital signatures?</p>
<p>A. PKCS #12 <br />
 B. PKCS #10 <br />
 C. PKCS #8 <br />
 D. PKCS #7</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> D</p>
<p><!--adsense#AfterContent--></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitytut.com/ccna-security/cryptographic-systems/feed</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Implementing Virtual Private Networks</title>
		<link>http://www.securitytut.com/ccna-security/implementing-virtual-private-networks</link>
		<comments>http://www.securitytut.com/ccna-security/implementing-virtual-private-networks#comments</comments>
		<pubDate>Sat, 03 Jul 2010 15:50:57 +0000</pubDate>
		<dc:creator>securitytut</dc:creator>
				<category><![CDATA[CCNA Security]]></category>

		<guid isPermaLink="false">http://www.securitytut.com/?p=207</guid>
		<description><![CDATA[Here you will find answers to Implementing Virtual Private Networks Questions Question 1 You work as a network engineer, do you know an IPsec tunnel is negotiated within the protection of which type of tunnel? A. GRE tunnel B. L2TP tunnel C. L2F tunnel D. ISAKMP tunnel Answer: D Question 2 For the following items, [...]]]></description>
			<content:encoded><![CDATA[<p>Here you will find answers to Implementing Virtual Private Networks Questions</p>
<p><!--adsense--></p>
<p class="ccnaquestionsnumber">Question 1</p>
<p>You work as a network engineer, do you know an IPsec tunnel is negotiated within the protection of which type of tunnel?</p>
<p>A. GRE tunnel <br />
 B. L2TP tunnel <br />
 C. L2F tunnel <br />
 D. ISAKMP tunnel</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer: </span>D</p>
<p>Question 2</p>
<p>For the following items, which one acts as a VPN termination device and is located at a primary network location?</p>
<p>A. Headend VPN device <br />
 B. Tunnel <br />
 C. Broadband service <br />
 D. VPN access device</p>
<p><br class="spacer_" /></p>
<p>Answer: A</p>
<p><!--adsense#AfterContent--></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitytut.com/ccna-security/implementing-virtual-private-networks/feed</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Managing a Secure Network</title>
		<link>http://www.securitytut.com/ccna-security/managing-a-secure-network</link>
		<comments>http://www.securitytut.com/ccna-security/managing-a-secure-network#comments</comments>
		<pubDate>Fri, 02 Jul 2010 15:50:24 +0000</pubDate>
		<dc:creator>securitytut</dc:creator>
				<category><![CDATA[CCNA Security]]></category>

		<guid isPermaLink="false">http://www.securitytut.com/?p=205</guid>
		<description><![CDATA[Here you will find answers to Managing a Secure Network Questions Question 1 For the following attempts, which one is to ensure that no employee becomes a pervasive security threat, that data can be recovered from backups, and that information system changes do not compromise a system&#8217;s security? A.    Disaster recovery B.    Strategic security planning [...]]]></description>
			<content:encoded><![CDATA[<p>Here you will find answers to Managing a Secure Network Questions</p>
<p><!--adsense--></p>
<p class="ccnaquestionsnumber">Question 1</p>
<p>For the following attempts, which one is to ensure that no employee becomes a pervasive security threat, that data can be recovered from backups, and that information system changes do not compromise a system&#8217;s security?</p>
<p>A.    Disaster recovery<br />
 B.    Strategic security planning<br />
 C.    Implementation security<br />
 D.    Operations security</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> D</p>
<p><strong>Note:</strong></p>
<p>Operations security: day-to-day security operations entail responding to an incident, monitoring and maintaining a system, and auditing a system (to ensure compliance with an organization’s security policy).</p>
<p class="ccnaquestionsnumber">Question 2</p>
<p>Which three options are network evaluation techniques? (Choose three)</p>
<p>A. Scanning a network for active IP addresses and open ports on those  IP addresses<br />
 B. Using password-cracking utilities<br />
 C. Performing end-user training on the use of antispyware software<br />
 D. Performing virus scans</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> A B D</p>
<p class="ccnaquestionsnumber">Question 3</p>
<p>Which is the main difference between host-based and network-based  intrusion prevention?</p>
<p>A. Network-based IPS is better suited for inspection of SSL and TLS  encrypted data flows.<br />
 B. Host-based IPS can work in promiscuous mode or inline mode.<br />
 C. Network-based IPS can provide protection to desktops and servers  without the need of installing specialized software on the end hosts and  servers. <br />
 D. Host-based IPS deployment requires less planning than network-based  IPS.</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> C</p>
<p class="ccnaquestionsnumber">Question 4</p>
<p>The enable secret password appears as an MD5 hash in a router&#8217;s configuration file, whereas the enable password is not hashed (or encrypted, if the password-encryption service is not enabled). What is the reason that Cisco still support the use of both enable secret and enable passwords in a router&#8217;s configuration?</p>
<p>A. The enable password is used for IKE Phase I, whereas the enable secret password is used for IKE Phase II.<br />
 B. The enable password is considered to be a router&#8217;s public key, whereas the enable secret password is considered to be a router&#8217;s private key.<br />
 C. Because the enable secret password is a hash, it cannot be decrypted. Therefore, the enable password is used to match the password that was entered, and the enable secret is used to verify that the enable password has not been modified since the hash was generated.<br />
 D. The enable password is present for backward compatibility.</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> D</p>
<p><!--adsense#MiddleContent--></p>
<p class="ccnaquestionsnumber">Question 5</p>
<p>Which type of MAC address is dynamically learned by a switch port and then added to the switch&#8217;s running configuration?</p>
<p>A. Pervasive secure MAC address <br />
 B. Static secure MAC address <br />
 C. Sticky secure MAC address <br />
 D. Dynamic secure MAC address</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer: </span>C</p>
<p class="ccnaquestionsnumber">Question 6</p>
<p>Which are the best practices for attack mitigations?</p>
<table border="1">
<tbody>
<tr>
<td>1</td>
<td>Store sensitive data on stand-alone devices</td>
</tr>
<tr>
<td>2</td>
<td>Keep patches up to date</td>
</tr>
<tr>
<td>3</td>
<td>Use password that cannot be broken</td>
</tr>
<tr>
<td>4</td>
<td>Develop a static tested security policy</td>
</tr>
<tr>
<td>5</td>
<td>Inform users about social engineering</td>
</tr>
<tr>
<td>6</td>
<td>Develop a dynamic security policy</td>
</tr>
<tr>
<td>7</td>
<td>Log everything to a syslog server for forensic purposes</td>
</tr>
<tr>
<td>8</td>
<td>Disable unnecessary services</td>
</tr>
</tbody>
</table>
<p>A. 1, 2, 3 and 5<br />
 B. 2, 5, 6 and 8<br />
 C. 2, 5, 6 and 7 <br />
 D. 2, 3, 6 and 8<br />
 E. 3, 4, 6 and 7</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer:</span> B</p>
<p class="ccnaquestionsnumber">Question 7</p>
<p>Which one of the Cisco IOS commands can be used to verify that either the Cisco IOS image, the configuration files, or both have been properly backed up and secured?</p>
<p>A. show flash <br />
 B. show secure bootset <br />
 C. show archive <br />
 D. show file systems</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer: </span>B</p>
<p class="ccnaexplanation">Explanation</p>
<p>We use <strong>secure boot-image</strong> command to protect the IOS image, and the command <strong>secure boot-config</strong> to protect<br />
 the running configuration. These protected files will not even appear in a <strong>dir </strong>listing of flash. To see these protected files, use the<strong> show secure bootset</strong> command.</p>
<p class="ccnaquestionsnumber">Question 8</p>
<p>Which name is of the e-mail traffic monitoring service that underlies that architecture of IronPort?</p>
<p>A. IronPort M-Series <br />
 B. E-Base <br />
 C. TrafMon <br />
 D. SenderBase</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer: </span>D</p>
<p class="ccnaquestionsnumber">Question 9</p>
<p>Based on the username global configuration mode command displayed in the exhibit. What does the option secret 5 indicate about the enable secret password?</p>
<table style="background-color: #ffff99;" border="1">
<tbody>
<tr>
<td><strong>Router# show run | include username<br />
 </strong><br />
 <strong>Username test secret 5 $1$knm. $GOGQBIL8TK77POLWxvX400</strong></td>
</tr>
</tbody>
</table>
<p>A. It is encrypted using DH group 5. <br />
 B. It is hashed using SHA. <br />
 C. It is hashed using MD5.<br />
 D. It is encrypted using a proprietary Cisco encryption algorithm.</p>
<p><br class="spacer_" /></p>
<p><span class="ccnacorrectanswers">Answer: </span>C</p>
<p>Question 10</p>
<p>What will be disabled as a result of the no service password-recovery command?</p>
<p>A. password encryption service <br />
 B. ROMMON<br />
 C. changes to the config-register setting<br />
 D. the xmodem privilege EXEC mode command to recover the Cisco IOS image</p>
<p><br class="spacer_" /></p>
<p>Answer: B</p>
<p><!--adsense#AfterContent--></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitytut.com/ccna-security/managing-a-secure-network/feed</wfw:commentRss>
		<slash:comments>25</slash:comments>
		</item>
		<item>
		<title>Share your CCNA Security Experience</title>
		<link>http://www.securitytut.com/ccna-security/share-ccna-security-experience</link>
		<comments>http://www.securitytut.com/ccna-security/share-ccna-security-experience#comments</comments>
		<pubDate>Thu, 01 Jul 2010 13:52:44 +0000</pubDate>
		<dc:creator>securitytut</dc:creator>
				<category><![CDATA[CCNA Security]]></category>

		<guid isPermaLink="false">http://www.securitytut.com/?p=201</guid>
		<description><![CDATA[Please share with us your experience after taking the CCNA Security 640-553 exam, your materials, the way you learned, your recommendations&#8230; Your posts are warmly welcome! Please don&#8217;t ask for links to download copyright materials here&#8230;]]></description>
			<content:encoded><![CDATA[<p class="pinkandbold">Please share with us your experience after taking  the CCNA Security 640-553 exam, your materials, the way you learned, your  recommendations&#8230;</p>
<p>Your posts are warmly welcome!</p>
<p>Please don&#8217;t ask for links to download copyright materials here&#8230;</p>
<p><!--adsense--></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitytut.com/ccna-security/share-ccna-security-experience/feed</wfw:commentRss>
		<slash:comments>1262</slash:comments>
		</item>
	</channel>
</rss>

