Exam A
SSL stands for Secure Sockets Layer, though IETF has renamed it TLS (Transport Layer Security). TLS is documented in RFC 2246 and identifies itself in the protocol version field as SSL 3.1. When initiating a new SSL/TLS session, the client receives the server SSL certificate and validates it. What does the client use the certificate for after validating it?
A. The server creates a separate session key and sends it to the client. The client has to decrypt the session key using the server public key from the certificate.
B. The client creates a separate session key and encrypts it with the server public key from the certificate before sending it to the server.
C. Nothing, the client and server switch to symmetric encryption using IKE to exchange keys.
D. The client generates a random string, encrypts it with the server public key from the certificate, and sends it to the server. Both the client and server derive the session key from the random data sent by the client.
Correct Answer: D
After entering debug ip packet, no messages appear on your Telnet session. What is the likely cause?
A. OSPF routing is required.
B. The console port does not support debug output.
C. The terminal monitor command is required.
D. IP packets are not supported with the debug command.
Correct Answer: C
Comparing symmetric ciphers to asymmetric ciphers, which statement is not correct?
A. Symmetric ciphers are less computationally intensive.
B. Asymmetric ciphers are in general more difficult to break.
C. Asymmetric ciphers require a shared secret called the private key.
D. Symmetric ciphers are faster.
Correct Answer: C
Which two statements indicate how Cisco IPS Sensor Software Version 5.0 differs from Version 4.0? (Choose two.)
A. The sensor pushes events to the monitoring system.
B. The sensor supports intrusion prevention functionality
C. The monitoring system pulls events from the sensor.
D. The sensor software calculates a risk rating for alerts to reduce false positives.
Correct Answer: BD
On the basis of the Cisco ASA Software Version 7.x configuration. Which scenario best describes the reason you would deploy this configuration on your Cisco ASA adaptive security appliance?

A. to ensure that any HTTP session that has a URL with the string “X-Counter” or “X-Session” is reset and logged
B. to ensure that HTTP traffic follows RFC compliance
C. to ensure that any HTTP session that has a URL with the string “X-Counter” or “X-Session” is blocked and logged
D. to ensure that connections from any custom web applications that use “X-Counter” or “X- Session” are reset and logged
Correct Answer: D
When managing a Cisco IOS device by use of Cisco SDM, which configuration statement is necessary to be able to use Cisco SDM?
A. ip http server
B. ip http secure-server sdm location X.X.X.X
C. ip http secure-server
D. ip http server sdm location X.X.X.X
Correct Answer: A

SNMP is restricted on Cisco routers by what IOS command?
A. snmp-server enable
B. snmp-server community string
C. snmp-server ip-address
D. snmp-server no access permitted
Correct Answer: B
Which two statements best describe the reason that TACACS+ is more desirable from a security standpoint than RADIUS? (Choose two.)
A. It encrypts the password field with a unique key between server and requester.
B. It uses TCP as its transport
C. It uses UDP as its transport.
D. Encrypting the whole data payload is optional.
Correct Answer: BD
Which three statements are correct concerning AES? (Choose three.)
A. AES is faster to compute than 3DES.
B. AES is not subject to known-plaintext attacks, while DES is subject to them.
C. AES is a block cipher, while 3DES and DES are stream ciphers.
D. AES can be used with longer keys than 3DES.
Correct Answer: ABD
The AS5300 series router can support which of the following incoming connections?
A. Voice
B. Dialup users via PSTN
D. All the above
Correct Answer: D