Securing Cisco Network Devices 試験
試験番号:642-552J
関連資格:CCSP / Cisco Firewall Specialist / Cisco IPS Specialist / Cisco VPN Specialist
試験時間:75分
試験概要
Securing Cisco Network Devices 642-552 SND は、Cisco Certified Security Professional、Cisco Firewall Specialist、Cisco IPS Specialist、および Cisco VPN Specialist 認定資格に関連する試験です。受験者は、受験準備として Securing Cisco Network Devices v2.0(SND)コースを受講できます。この試験では、シスコのルータとスイッチ、および関連するネットワークの保護に関する知識が問われます。出題範囲には、最近のネットワーク インフラストラクチャが直面しているセキュリティの脅威、シスコ ルータの保護、基本的な AAA の実装、ACL を使用したルータとネットワークの脅威の抑制、安全な管理とレポートの実装、一般的なレイヤ2攻撃の抑制、Cisco Security Device Manager を使用した Cisco IOS ファイアウォール機能、Cisco IOS IPS 機能、および IPSec VPN 機能の実装が含まれます。
642-552はCisco の試験科目の一つに属します、全称はSecuring Cisco Network Devices Examで、58の本試験題が含めています。 VPN and Security 642-552(Securing Cisco Network Devices Exam)試験題はtestpassport先輩のIT講師と VPN and Security 製品の専門家によって作り上げて、最も新しい本試験題を含めています
以下は642-552のデモです
http://pdf.testpassport.jp/642-552.pdf
2. Which of these two ways does Cisco recommend that you use to mitigate maintenance-related threats?
(Choose two.)
A. Maintain a stock of critical spares for emergency use.
B. Ensure that all cabling is Category 6.
C. Always follow electrostatic discharge procedures when replacing or working with internal router and
switch device components.
D. Always wear an electrostatic wrist band when handling cabling, including fiber-optic cabling.
E. Always employ certified maintenance technicians to maintain mission-critical equipment and cabling.
Answer: AC
3. Which method of mitigating packet-sniffer attacks is the most effective?
A. implement two-factor authentication
B. deploy a switched Ethernet network infrastructure
C. use software and hardware to detect the use of sniffers
D. deploy network-level cryptography using IPsec, secure services, and secure protocols
Answer: D
4. A malicious program is disguised as another useful program; consequently, when the user executes the
program,files get erased and then the malicious program spreads itself using emails as the delivery
mechanism. Which type of attack best describes how this scenario got started?
A. DoS
B. worm
C. virus
D. trojan horse
E. DDoS
Answer: D
5. What is the key function of a comprehensive security policy?
A. informing staff of their obligatory requirements for protecting technology and information assets
B. detailing the way security needs will be met at corporate and department levels
C. recommending that Cisco IPS sensors be implemented at the network edge
D. detailing how to block malicious network attacks
Answer: A
6. Which building blocks make up the Adaptive Threat Defense phase of Cisco SDN strategy?
A. VoIP services, NAC services, Cisco IBNS
B. network foundation protection, NIDS services, adaptive threat mitigation services
C. firewall services, intrusion prevention, secure connectivity
D. firewall services, IPS and network antivirus services, network intelligence
E. Anti-X defense, NAC services, network foundation protection
Answer: D
7. Why is TACACS+ the preferred AAA protocol to use with Cisco device authentication?
A. TACACS+ encryption algorithm is more recent than other AAA protocols
B. TACACS+ has a more robust programming interface than other AAA protocols
C. TACACS+ was initially developed as open-source software
D. TACACS+ provides true AAA functional separation and encrypts the entire body of the packet
E. TACACS+ maintains authentication information in the local database of each Cisco IOS router
F. TACACS+ combines authentication and authorization to provide more robust functionalities
Answer: D

