Monday, October 12, 2009

CCNA 640-553 dumps, Cisco 640-553 exam, 640-553 study guide, 640-553 torrent, 640-553 testking, 640-553 vce

Cisco 640-553 Exam - Certifysky.com

Free 640-553 Sample Questions:

1. As a network engineer at XXYYinc.com, you are responsible for XXYYinc network. Which will be necessarily taken into consideration when implementing Syslogging in your network?
A. Log all messages to the system buffer so that they can be displayed when accessing the router.
B. Use SSH to access your Syslog information.
C. Enable the highest level of Syslogging available to ensure you log all possible event messages.
D. Syncronize clocks on the network with a protocol such as Network Time Protocol.
Answer: D

2. Which classes does the U.S. government place classified data into? (Choose three.)
A. SBU
B. Confidential
C. Secret
D. Top­secret
Answer: B, C, D

3. You are a network technician at XXYYinc.com. Which description is correct when you have generated RSA keys on your Cisco router to prepare for secure device management?
A. All vty ports are automatically enabled for SSH to provide secure management.
B. The SSH protocol is automatically enabled.
C. You must then zeroize the keys to reset secure shell before configuring other parameters.
D. You must then specify the general­purpose key size used for authentication with the crypto key generate rsa general­keys modulus command.
Answer: B

4. Which method is of gaining access to a system that bypasses normal security measures?
A. Creating a back door
B. Starting a Smurf attack
C. Conducting social engineering
D. Launching a DoS attack
Answer: A

5. As a candidate for CCNA examination, when you are familiar with the basic commands, if you input the command "enable secret level 5 password" in the global mode , what does it indicate?
A. Set the enable secret command to privilege level 5.
B. The enable secret password is hashed using SHA.
C. The enable secret password is hashed using MD5.
D. The enable secret password is encrypted using Cisco proprietary level 5 encryption. E.The enable secret password is for accessing exec privilege level 5.
Answer: E

6. Which statement is true about a Smurf attack?
A. It sends ping requests to a subnet, requesting that devices on that subnet send ping replies to a target system.
B. It intercepts the third step in a TCP three­way handshake to hijack a session.
C. It uses Trojan horse applications to create a distributed collection of "zombie" computers, which can be used to launch a coordinated DDoS attack.
D. It sends ping requests in segments of an invalid size.
Answer: A

7. Please choose the correct description about Cisco Self­Defending Network characteristics.

A. INTEGRATED ­ XY1 COLLABORATIVE ­ XY2 ADAPTIVE ­ XY3
B. INTEGRATED ­ XY2 COLLABORATIVE ­ XY1 ADAPTIVE ­ XY3
C. INTEGRATED ­ XY2 COLLABORATIVE ­ XY3 ADAPTIVE ­ XY1
D. INTEGRATED ­ XY3 COLLABORATIVE ­ XY2 ADAPTIVE ­ XY1
Answer: B

8. Which three items are Cisco best­practice recommendations for securing a network? (Choose three.)
A. Deploy HIPS software on all end­user workstations.
B. Routinely apply patches to operating systems and applications.
C. Disable unneeded services and ports on hosts.
D. Require strong passwords, and enable password expiration.
Answer: B, C, D

9. With the increasing development of network, various network attacks appear. Which statement best describes the relationships between the attack method and the result?

A. Ping Sweep ­ XY1 and XY3 Port Scan ­ XY2, XY4 and XY5
B. Ping Sweep ­ XY2 and XY4 Port Scan ­ XY1, XY3 and XY5
C. Ping Sweep ­ XY1 and XY5 Port Scan ­ XY2, XY3 and XY4
D. Ping Sweep ­ XY2 and XY3 Port Scan ­ XY1, XY4 and XY5
Answer: B

10. For the following attempts, which one is to ensure that no one employee becomes a pervasive security threat, that data can be recovered from backups, and that information system changes do not compromise a system's security?
A. Disaster recovery
B. Strategic security planning
C. Implementation security
D. Operations security
Answer: D

11. For the following options ,which one accurately matches the CLI command(s) to the equivalent SDM wizard that performs similar configuration functions?
A. setup exec command and the SDM Security Audit wizard
B. auto secure exec command and the SDM One­Step Lockdown wizard
C. aaa configuration commands and the SDM Basic Firewall wizard
D. Cisco Common Classification Policy Language configuration commands and the SDM Site­to­Site VPN wizard
Answer: B

12. Which three options are network evaluation techniques? (Choose three.)
A. Scanning a network for active IP addresses and open ports on those IP addresses
B. Using password­cracking utilities
C. Performing end­user training on the use of antispyware software
D. Performing virus scans
Answer: A, B, D

13. Which is the main difference between host­based and network­based intrusion prevention?
A. Network­based IPS is better suited for inspection of SSL and TLS encrypted data flows.
B. Host­based IPS can work in promiscuous mode or inline mode.
C. Network­based IPS can provide protection to desktops and servers without the need of installing specialized software on the end hosts and servers.
D. Host­based IPS deployment requires less planning than network­based IPS.
Answer: C

14. Which one is the most important based on the following common elements of a network design?
A. Business needs
B. Best practices
C. Risk analysis
D. Security policy
Answer: A

15. Given the exhibit below. You are a network manager of your company. You are reading your Syslog server reports. On the basis of the Syslog message shown, which two descriptions are correct? (Choose two.)

A. This message is a level 5 notification message.
B. This message is unimportant and can be ignored.
C. This is a normal system­generated information message and does not require further investigation.
D. Service timestamps have been globally enabled.
Answer: A, D

16. Examine the following items, which one offers a variety of security solutions, including firewall, IPS, VPN, antispyware, antivirus, and antiphishing features?
A. Cisco 4200 series IPS appliance
B. Cisco ASA 5500 series security appliance
C. Cisco IOS router
D. Cisco PIX 500 series security appliance
Answer: B

17. The enable secret password appears as an MD5 hash in a router's configuration file, whereas the enable password is not hashed (or encrypted, if the password­encryption service is not enabled). What is the reason that Cisco still support the use of both enable secret and enable passwords in a router's configuration?
A. The enable password is used for IKE Phase I, whereas the enable secret password is used for IKE Phase II.
B. The enable password is considered to be a router's public key, whereas the enable secret password is considered to be a router's private key.
C. Because the enable secret password is a hash, it cannot be decrypted. Therefore, the enable password is used to match the password that was entered, and the enable secret is used to verify that the enable password has not been modified since the hash was generated.
D. The enable password is present for backward compatibility.
Answer: D

18 .How does CLI view differ from a privilege level?
A. A CLI view supports only commands configured for that specific view, whereas a privilege level supports commands available to that level and all the lower levels.
B. A CLI view supports only monitoring commands, whereas a privilege level allows a user to make changes to an IOS configuration.
C. A CLI view and a privilege level perform the same function. However, a CLI view is used on a Catalyst switch, whereas a privilege level is used on an IOS router.
D. A CLI view can function without a AAA configuration, whereas a privilege level requires AAA to be configured.
Answer: A

19. When configuring Cisco IOS login enhancements for virtual connections, what is the "quiet period"?
A. A period of time when no one is attempting to log in
B. The period of time in which virtual logins are blocked as security services fully initialize
C. The period of time in which virtual login attempts are blocked, following repeated failed login attempts
D. The period of time between successive login attempts
Answer: C

20. Which result is of securing the Cisco IOS image by use of the Cisco IOS image resilience feature?
A. When the router boots up, the Cisco IOS image will be loaded from a secured FTP location.
B. The Cisco IOS image file will not be visible in the output from the show flash command.
C. The show version command will not show the Cisco IOS image file location.
D. The running Cisco IOS image will be encrypted and then automatically backed up to a TFTP server.
Answer: B

21. Which three statements are valid SDM configuration wizards? (Choose three.)
A. Security Audit
B. VPN
C. STP
D. NAT
Answer: A, B, D

22. How do you define the authentication method that will be used with AAA?
A. With a method list
B. With the method command
C. With the method aaa command
D. With a method statement
Answer: A

23. Which one of the following commands can be used to enable AAA authentication to determine if a user can access the privilege command level?
A. aaa authentication enable default local
B. aaa authentication enable level
C. aaa authentication enable method default
D. aaa authentication enable default
Answer: D

24. What is the objective of the aaa authentication login console­in local command?
A. It specifies the login authorization method list named console­in using the local RADIUS username­password database.
B. It specifies the login authorization method list named console­in using the local username­password database on the router.
C. It specifies the login authentication method list named console­in using the local user database on the router.
D. It specifies the login authentication list named console­in using the local username­ password database on the router.
Answer: C

25. Which description is true about the show login command output displayed in the exhibit?

A. All logins from any sources are blocked for another 193 seconds.
B. The login block­for command is configured to block login hosts for 93 seconds.
C. When the router goes into quiet mode, any host is permitted to access the router via Telnet, SSH, and HTTP, since the quiet­mode access list has not been configured.
D. Three or more login requests have failed within the last 100 seconds.
Answer: D

More Free 640-553 exam questions

640-553 Exam Prep

Learn what you need to know to pass the 640-553 exam easily

Guarantee your 640-553 success with our 640-553 Exam Resources. Our exams are developed by experiences IT Professionals working in today's prospering companies and date centers. All our practice exams including 640-553 exam guarantee you the exam success you need.

CertifySky offers free demo for 640-553 exam. You can check out the interface, question quality and usability of our practice exams before you decide to buy it. We are the only one site can offer demo for almost all products. If you want to try 640-553 Exam Prep Demo, Click the "Try Demo" button.

640-553 Certification Exam and Study Guide

There are many online resources for preparing for the 640-553 exam. Read below to discover why Certifysky.com is your premier source for practice tests, and true testing environment.

CertifySky is the online Certification Expert recognized by a worldwide audience of IT professionals and executives alike as the definitive source of training materials for the candidate seeking insight, updates and resources for vendor certifications.

640-553 Practice Test Questions, Printable PDF Braindumps
We are all well aware that a major problem in the IT industry is that there is a lack of quality study materials. Our 640-553 Preparation Exam Material provides you everything you will need to take a certification examination. Details are researched and produced by Certification Experts who are constantly using industry experience to produce precise, logical and verified explanations for the answers. You may get questions from different web sites or books, but logic is the key.

640-553 Exam Preparation from Certifysky.com include:

  • Comprehensive questions with complete details
  • Questions accompanied by exhibits (when applicable)
  • Verified Answers Researched by Industry Experts
  • Drag and Drop questions as experienced in the Actual Exams (when applicable)
  • Questions updated on regular basis
  • These questions and answers are backed by our GUARANTEE
  • Like actual certification exams our product is in multiple-choice questions (MCQs)

    Our 640-553 Exam will provide you with exam questions and verified answers that reflect the actual exam. These questions and answers provide you with the experience of taking the actual test. Our 640-553 Exam is not just questions and answers. They are your access to high technical expertise and accelerated learning capacity. Certification Experts, Certified Computer Trainers, Technical Coworker and Comprehensive Language Masters, who have a solid, verified and certified background and high technical expertise, have compiled these detailed questions and answers. 640-553 Certification preparation Q and A provided by Certifysky.com will make you feel like you are taking an actual exam at a Prometric or VUE center.

    Furthermore, we are constantly updating our 640-553 Exam. These 640-553 Exam updates are supplied free of charge to Certify Sky.com customers- hereby becoming an investment rather than a disposable product. Our clients receive the most reliable and up-to-date information when they decide to take the exam, just contact us. Our candidates walk into the Testing Room as confident as a Certification Administrator.

    Like actual certification exams our 640-553 Exam is in multiple-choice questions (MCQs). After purchasing our products you are just a step away from testing for certification. Still not convinced? Try our free samples or choose to buy your 640-553 Practice Exam now!

    Our 640-553 practice exam features:

  • Comprehensive questions with complete details, answers and references
  • Exhibits and graphical representations (when applicable)
  • Verified Answers Researched by Industry Experts
  • Questions updated on regular basis
  • Like actual certification exams our product is in multiple-choice questions (MCQs).
  • Our questions and answers are backed by our GUARANTEE.

    Our 640-553 practice exams and study questions are composed by current and active Information Technology experts, who use their experience in preparing you for your future in IT.

    Commitment to Your Success:
    At Certifysky.com we are committed to you ongoing success. Our exams and questions are constantly being updated and compared to industry standards.

    You are not about to purchase a disposable product. 640-553 practice exam updates are supplied free of charge. Regardless of how soon you decide to take the actual 640-553 examination certification, you will be able to walk into the testing room as confident as the Certification Administrator.

    The CertifySky 640-553 study guide is guaranteed to be 100% braindump free. We value the quality of training you receive through the 640-553 study guide and will never support 640-553 braindumps, or any 640-553 brain dump site. 640-553 braindump sites cannot compare to the understanding, learning and comprehension you will gain from a non-640-553 braindumps site, based on facts and case studies, like Certify Sky.

    When selecting the CertifySky 640-553 exam study preparation materials, you are purchasing the highest quality CertifySky 640-553 products available through the web today. The 640-553 CertifySky practice exams and study guides are current and updated monthly, providing you with the highest 640-553 Certify Sky ROI. Start you road to 640-553 CertifySky success today, buy purchasing the CertifySky 640-553 training materials today!
  •