Archive for December, 2009

Free TestKing Juniper JN0-532 FWV, Specialist (JNCIS -FWV)

Tuesday, December 29th, 2009

I’m a graduating student and aiming to hunt a satisfactory career in the IT field. Due to the lack of working experience, I am badly in need of a TestKing.cc Juniper exam certification to prove my capability and to compete with other candidates in the job-hunting market. Although I have made up my mind to get the Juniper certification certification, difficulties prevent my study process.
I took the training class for my preparation, though it is very expensive for me. What made very angry was that the objectives mentioned in the class were still too general to catch the points.
Any changes happened to the JN0-532 examination exam will be caught by us immediately through some particular channel. So we always reflect the latest trends ahead of our rivals.
The quality is the key of  TestKing.cc’s development and success. Many efforts have been made to ensure that the TK products can assistant the students to pass the JN0-532 test exam without any other stuff.
If you have bought TestKing.cc products and failed to pass the TestKing.cc Juniper certification exam at the first try, TestKing.cc will provide you with the FULL REFUND of your purchasing expense after checking the information.
By using TestKing.cc, do not worry about the accident that you fail the JN0-532 exam, for TestKing.cc has safeguard for customers. TestKing.cc provide you not only with a 100% pass guarantee but also a 100% refund!

Related Exams:
642-072 – Cisco Unity Design and Networking (CUDN)
350-029 – CCIE Service Provider Written exam
000-200 – IBM Storage Sales V1
1z0-042 – oracle database 10g:administration i
350-001 – CCIE ROUTING AND SWITCHING QUALIFICATION (Written exam)

TestKing Cisco 640-553 free practice test questions and answers

Friday, December 11th, 2009

Exam Name: IINS Implementing Cisco IOS Network Security
Exam Type: Cisco Case Studies
Exam Code: 640-553

Question: 1
Which consideration is important when implementing Syslogging in your network?
A. Use SSH to access your Syslog information.
B. Enable the highest level of Syslogging available to ensure you log all possible event messages.
C. Log all messages to the system buffer so that they can be displayed when accessing the router.
D. Syncronize clocks on the network with a protocol such as Network Time Protocol.
Answer: D

Question: 2
Which statement is true when you have generated RSA keys on your Cisco router to prepare for secure device management?
A. You must then zeroize the keys to reset secure shell before configuring other parameters.
B. The SSH protocol is automatically enabled.
C. You must then specify the general-purpose key size used for authentication with the crypto key generate rsa general-keys modulus command.
D. All vty ports are automatically enabled for SSH to provide secure management.
Answer: B

Question: 3
What does level 5 in the following enable secret global configuration mode command indicate?
router# enable secret level 5 password
A. The enable secret password is hashed using MD5.
B. The enable secret password is hashed using SHA.
C. The enable secret password is encrypted using Cisco proprietary level 5 encryption.
D. Set the enable secret command to privilege level 5.
E. The enable secret password is for accessing exec privilege level 5.
Answer: E

Question: 4
What is the key difference between host-based and network-based intrusion prevention?
A. Network-based IPS is better suited for inspection of SSL and TLS encrypted data flows.
B. Network-based IPS provides better protection against OS kernel-level attacks against hosts and servers.
C. Network-based IPS can provide protection to desktops and servers without the need of installing specialized software on the end hosts and servers.
D. Host-based IPS can work in promiscuous mode or inline mode.
E. Host-based IPS is more scalable then network-based IPS.
F. Host-based IPS deployment requires less planning than network-based IPS.
Answer: C

Question: 5
You suspect an attacker in your network has configured a rogue layer 2 device to intercept traffic from multiple VLANS, thereby allowing the attacker to capture potentially sensitive data. Which two methods will help to mitigate this type of activity? (Choose two.)
A. Turn off all trunk ports and manually configure each VLAN as required on each port
B. Disable DTP on ports that require trunking
C. Secure the native VLAN, VLAN 1 with encryption
D. Set the native VLAN on the trunk ports to an unused VLAN E. Place unused active ports in an unused VLAN
Answer: B, D

Question: 6
Which three statements about SSL-based VPNs are true? (Choose three.)
A. Asymmetric algorithms are used for authentication and key exchange.
B. SSL VPNs and IPsec VPNs cannot be configured concurrently on the same router.
C. Symmetric algorithms are used for bulk encryption.
D. The authentication process uses hashing technologies.
E. SSL VPNs require special-purpose client software to be installed on the client machine.
F. You can also use the application programming interface to extensively modify the SSL client software for use in special applications.
Answer: A, C, D

Question: 7
When configuring AAA login authentication on Cisco routers, which two authentication methods should be used as the final method to ensure that the administrator can still log in to the router in case the external AAA server fails? (Choose two.)
A. Group RADIUS
B. Group TACACS+ C. Local
D. Krb5
E. Enable
F. If-authenticated
Answer: C, E

Question: 8
What is a result of securing the Cisco IOS image using the Cisco IOS image resilience feature?
A. The show version command will not show the Cisco IOS image file location.
B. The Cisco IOS image file will not be visible in the output from the show flash command.
C. When the router boots up, the Cisco IOS image will be loaded from a secured FTP location.
D. The running Cisco IOS image will be encrypted and then automatically backed up to the NVRAM.
E. The running Cisco IOS image will be encrypted and then automatically backed up to a TFTP server.
Answer: B

350-050 : CCIE Wireless Written Exam
350-001 : CCIE Written — Routing & Switching
642-892 : Composite Exam
642-825 : ISCW – Implementing Secure Converged Wide Area Networks
640-863 : Designing for Cisco Internetwork Solutions
640-816 : Interconnecting Cisco Networking Devices Part 2
350-018 : Cisco CCIE Security
642-901 : BSCI – Building Scaleable Cisco Internetworks
642-845 : ONT – Optimizing Converged Cisco Networks
642-812 : Building Cisco Multilayer Switched Networks
640-822 : Interconnecting Cisco Networking Devices Part 1
640-802 : Cisco Certified Network Associate