Free Cisco Certification

 Print this Page

Search the Web
Google
Web This Site




350-018 : CCIE Pre-Qualification Test for Security

QUESTION 141 What is the purpose of BRI ISDN D channels?

A. Data transfer

B. Loop backs

C. Control signals

D. None of the above Answer: C

QUESTION 142 You are the network administrator at Cisco Highway. The Cisco Highway network is using two remote LANs that are connected via a serial connection are exchanging routing updates via RIP. An alternate oath exists with a higher hop count. When the serial link fails, users complain of the time it takes to transfer to the alternate path. How will you be able to ameliorate this situation?

A. Change the hop count on an alternate path to be the same cost.

B. Reduce or disable the hold down timer through the timers basic command.

C. Increase the bandwidth of the alternate serial connection.

D. Configure a static route with an appropriate administrative cost, via the alternate route. Answer: B

QUESTION 143 What is the reason why file level permissions are not available with Windows 95 shares?

A. Windows 95 is a 16-bit operating system and file level permissions require a 32-bit operating system.

B. Windows 95 machines use FAT partitions and they cannot be upgraded to VFAT which is the NT format.

C. Windows 95 machines is incapable off being configured as network share points.

D. NTFS is not supported in Windows 95 and File level permissions are only available on NTFS partitions.

E. None of the above; File level permissions are configurable only by going to the file properties and selecting "Permissions" on the "Security" tab. Answer: D

QUESTION 144 Which of the following represents a definition of Cipher text?

A. Cipher text can be defined as the key to encrypt a message.

B. Cipher text can be defined as the public key that has been changed with a peer to determine the original message.

C. Cipher text can be defined as the result of an already decrypted message on the receiving end.

D. Cipher text can be defined as the post-encrypted message that travels on the wire.

E. Cipher text can be defined as the key used for a one way hash in an IPSec Phase Two exchange. Answer: C

QUESTION 145 What is the advantage of using Secure Shell instead of Telnet?

A. Secure Shell offers native accounting.

B. Secure Shell requires IPSec.

C. Secure Shell qualifies for C1 security under TCSEC guidelines.

D. Secure Shell provides an encrypted tunnel.

E. Secure Shell offers increased key length for encryption. Answer: D

QUESTION 146 Which of the following statements regarding MPPE (Microsoft Point to Point Encryption) is valid?

A. MPPE is the Microsoft implementation of RFC's 2409 and 2402.

B. MPPE has an encryption mechanism that is independent of the user's password.

C. MPPE uses the RC4 encryption algorithm.

D. MPPE uses 768 or 1024-bit encryption keys. Answer: A

QUESTION 147 Which of the following commands is NOT a Kerberos executable on a Kerberos Version 5 Unix system?

A. kadmin

B. key tab

C. kdb5_util

D. krb5kdc Answer: B

QUESTION 148 A router learns about an IP network via RIP and OSPF. What mechanism is used for the selection of the preferred route?

A. Default metrics

B. Routing priority

C. Type of service

D. Lambic pentameter

E. Administrative distance Answer: E

QUESTION 149 Why would you advice the new Cisco Highway trainee technician to configure a "clients" file on a RADIUS server?

A. To define a list of remote node devices that users may use for connectivity to the network.

B. To define a list of IP hosts that are granted permissions to administer the RADIUS database.

C. To define a list of users and their access profiles.

D. To define a list of NASs the RADIUS server for communication purposes.

E. All of the above. Answer: E

QUESTION 150 Exhibit: CA Certificate Status: Available Certificate Serial Number: 68690A1A21B65B343679274B37E7BB Key Usage: Signature CN = Version CertServer OU = user O = user L = User City ST = CA C = US EA =<16> user@anyone.com Validity Date: start stae: 14.32.48 PST Mar 17 2000 end date: 14:41:28 PST Mar 17 2002 You are the network administrator at Cisco Highway. You are experiencing problems getting two IPSec routers to authenticate using RSA-sig as an authentication method. The output of the IOS command show crypto ca cert yields the above output. What is the most probable reason for this authentication failure?

A. The certificate has a leading one in the serial number field which violated the x.509 certificate standard.

B. The router has not yet obtained an identity certificate from the root CA.

C. The current data of the router is out of the range of the certificate's validity date.

D. The root CA has rejected the other routers attempt to authenticate.

E. None of the above. Answer: D

Top of pageTop of page Back 15 of 37 Next
Search and Find Anything Here
Google