- Which security test is appropriate for detecting system weaknesses such as misconfiguration, default passwords, and potential DoS targets?
- vulnerability scanning
- network scanning
- integrity checkers
- penetration testing
- How does network scanning help assess operations security?
- It can simulate attacks from malicious sources.
- It can log abnormal activity.
- It can detect open TCP ports on network systems.
- It can detect weak or blank passwords.
- What is the objective of the governing policy in the security policy hierarchy structure?
- It covers all rules pertaining to information security that end users should know about and follow.
- It outlines the company’s overall security goals for managers and technical staff.
- It provides general policies on how the technical staff should perform security functions.
- It defines system and issue-specific policies that describe what the technical staff does.
- Which type of security policy document is it that includes implementation details that usually contain step-by-step instructions and graphics?
- best practices document
- procedure document
- standards document
- guideline document
- What is the purpose of a security awareness campaign?
- to teach skills so employees can perform security tasks
- to focus the attention of employees on security issues
- to provide users with a training curriculum that can ultimately lead to a formal degree
- to integrate all the security skills and competencies into a single body of knowledge
- What is the goal of network penetration testing?
- detecting configuration changes on network systems
- detecting potential weaknesses in systems
- determining the feasibility and the potential consequences of a successful attack
- detecting weak passwords
- What network security testing tool has the ability to provide details on the source of suspicious network activity?
- SIEM
- SuperScan
- Zenmap
- Tripwire
- What network scanning tool has advanced features that allows it to use decoy hosts to mask the source of the scan?
- Nessus
- Metasploit
- Tripwire
- Nmap
- What network testing tool can be used to identify network layer protocols running on a host?
- SIEM
- Nmap
- L0phtcrack
- Tripwire
- What type of network security test would be used by network administrators for detection and reporting of changes to network systems?
- penetration testing
- vulnerability scanning
- integrity checking
- network scanning
- What testing tool is available for network administrators who need a GUI version of Nmap?
- Nessus
- SIEM
- Zenmap
- SuperScan
- Which initial step should be followed when a security breach is found on a corporate system?
- Create a drive image of the system.
- Isolate the infected system.
- Establish a chain of custody.
- Photograph the system.
- What step should be taken after data is collected, but before equipment is disconnected, if a security breach is found on a system?
- Create a drive image of the system.
- Isolate the infected system.
- Photograph the system.
- Determine if data tampering has occurred.
- Which security program is aimed at all levels of an organization, including end users and executive staff?
- educational degree programs
- certificate programs
- awareness campaigns
- firewall implementation training courses
- What is implemented by administration to instruct end users in how to effectively conduct business safely within an organization?
- security awareness program
- governing policy
- noncompliance consequences
- technical policy
- What are two major components of a security awareness program? (Choose two.)
- technical policy
- procedure documents
- awareness campaigns
- guideline documents
- education and training
- Which type of documents include implementation details that usually contain step-by-step instructions and graphics?
- standards documents
- procedure documents
- guideline documents
- end-user policy documents
- Which type of documents help an organization establish consistency in the operations of the network by specifying criteria that must be followed?
- guidelines
- standards
- procedures
- end user policies
- Which policy outlines the overall security goals for managers and technical staff within a company?
- acceptable use policy
- technical policy
- governing policy
- end-user policy
- Which type of security policy includes network access standards and server security policies?
- end user policy
- technical policy
- governing policy
- acceptable use policy
- Which type of security policy includes acceptable encryption methods?
- governing policy
- acceptable use policy
- technical policy
- end-user policy
- What is the determining factor in the content of a security policy within an organization?
- the security staff
- the audience
- the chief executive officer
- the best practices
- Which executive position is ultimately responsible for the success of an organization?
- Chief Technology Officer
- Chief Executive Officer
- Chief Security Officer
- Chief Information Officer
- Match the network security testing tool with the correct function. (Not all options are used.)
CCNA Security - Chapter 11 Exam Answers Download PDF Test Online
CCNA Security - Chapter 10 Exam Answers Download PDF Test Online
- Which statement describes the function provided to a network administratorwho uses the Cisco Adaptive Security Device Manager (ASDM) GUI that runs as a Java Web Start application?
- The administrator can connect to and manage a single ASA.
- The administrator can connect to and manage multiple ASA devices.
- The administrator can connect to and manage multiple ASA devices and Cisco routers.
- The administrator can connect to and manage multiple ASA devices, Cisco routers, and Cisco switches.
- What is one benefit of using ASDM compared to using the CLI to configure the Cisco ASA?
- It does not require any initial device configuration.
- It hides the complexity of security commands.
- ASDM provides increased configuration security.
- It does not require a remote connection to a Cisco device.
- Which type of security is required for initial access to the Cisco ASDM by using the local application option?
- SSL
- WPA2 corporate
- biometric
- AES
- Which minimum configuration is required on most ASAs before ASDM can be used?
- SSH
- a dedicated Layer 3 management interface
- a logical VLAN interface and an Ethernet port other than 0/0
- Ethernet 0/0
- What must be configured on an ASA before it can be accessed by ASDM?
- web server access
- Telnet or SSH
- an Ethernet port other than 0/0
- Ethernet 0/0 IP address
- How is an ASA interface configured as an outside interface when using ASDM?
- Select a check box from the Interface Type option that shows inside, outside, and DMZ.
- Select outside from the Interface Type drop-down menu.
- Enter the name “outside” in the Interface Name text box.
- Drag the interface to the port labeled “outside” in the ASA drawing.
- Refer to the exhibit. Which Device Management menu item would be used to access theASA command line from within Cisco ASDM?
- Licensing
- System Image/Configuration
- Management Access
- Advanced
- Which ASDM configuration option is used to configure the ASA enable secret password?
- Device Setup
- Monitoring
- Interfaces
- Device Management
- Refer to the exhibit. Which Device Setup ASDM menu option would be used to configure the ASA for an NTP server?
- Startup Wizard
- Device Name/Password
- Routing
- Interfaces
- System Time
- True or False?
The ASA can be configured through ASDM as a DHCP server.- false
- true
- Which ASDM interface option would be used to configure an ASA as a DHCP server for local corporate devices?
- DMZ
- outside
- local
- inside
- Which ASDM configuration option re-encrypts all shared keys and passwords on an ASA?
- security master
- super encryption
- master passphrase
- device protection
- Which type of encryption is applied to shared keys and passwords when the master passphrase option is enabled through ASDM for an ASA?
- 3DES
- public/private key
- AES
- 128-bit
- When the CLI is used to configure an ISR for a site-to-site VPN connection, which two items must be specified to enable a crypto map policy? (Choose two.)
- the hash
- the peer
- encryption
- the ISAKMP policy
- a valid access list
- IP addresses on all active interfaces
- What is the purpose of the ACL in the configuration of an ISR site-to-site VPN connection?
- to permit only secure protocols
- to log denied traffic
- to identify the peer
- to define interesting traffic
- When ASDM is used to configure an ASA site-to-site VPN, what can be customized to secure traffic?
- ISAKMP
- IKE
- IKE and ISAKMP
- preshared key
- Which VPN solution allows the use of a web browser to establish a secure, remote-access VPN tunnel to the ASA?
- clientless SSL
- site-to-site using an ACL
- site-to-site using a preshared key
- client-based SSL
- Which remote-access VPN connection allows the user to connect by using a web browser?
- IPsec (IKEv2) VPN
- site-to-site VPN
- clientless SSL VPN
- IPsec (IKEv1) VPN
- Which remote-access VPN connection allows the user to connect using Cisco AnyConnect?
- IPsec (IKEv2) VPN
- site-to-site VPN
- clientless SSL VPN
- IPsec (IKEv1) VPN
- Which statement describes available user authentication methods when using an ASA 5505 device?
- The ASA 5505 can use either a AAA server or a local database.
- The ASA 5505 only uses a AAA server for authentication.
- The ASA 5505 only uses a local database for authentication.
- The ASA 5505 must use both a AAA server and a local database.
- Which remote-access VPN connection needs a bookmark list?
- IPsec (IKEv1) VPN
- IPsec (IKEv2) VPN
- site-to-site VPN
- clientless SSL VPN
- What occurs when a user logs out of the web portal on a clientless SSL VPN connection?
- The browser cache is cleared.
- Downloaded files are deleted.
- The user no longer has access to the VPN.
- The web portal times out.
- If an outside host does not have the Cisco AnyConnect client preinstalled, how would the host gain access to the client image?
- The host initiates a clientless connection to a TFTP server to download the client.
- The host initiates a clientless VPN connection using a compliant web browser to download the client.
- The Cisco AnyConnect client is installed by default on most major operating systems.
- The host initiates a clientless connection to an FTP server to download the client.
- What is an optional feature that is performed during the Cisco AnyConnect Secure Mobility Client VPN establishment phase?
- security optimization
- host-based ACL installation
- posture assessment
- quality of service security
- Which item describes secure protocol support provided by Cisco AnyConnect?
- neither SSL nor IPsec
- SSL only
- both SSL and IPsec
- IPsec only
- What is the purpose of configuring an IP address pool to be used for client-based SSL VPN connections?
- to assign addresses to the interfaces on the ASA
- to identify which users are allowed to download the client image
- to assign IP addresses to clients when they connect
- to identify which clients are allowed to connect












