Implementing Cisco Threat Control Solutions

Question No: 61

Refer to the following.

Router (config) #username admin secret cisco Router (config) #no service password-encryption

How is the “cisco” password stored?

  1. As Type 0

  2. As Type 7

  3. As Clear Text

Answer: A

Question No: 62

Which three functions can Cisco Application Visibility and Control perform? (Choose three.)

  1. Validation of malicious traffic

  2. Traffic control

  3. Extending Web Security to all computing devices

  4. Application-level classification

  5. Monitoring

  6. Signature tuning

Answer: B,D,E

Question No: 63

Which three search parameters are supported by the Email Security Monitor? (Choose three.)

  1. Destination domain

  2. Network owner

  3. MAC address

  4. Policy requirements

  5. Internal sender IP address

  6. Originating domain

Answer: A,B,E

Question No: 64

Which option is a benefit of Cisco Email Security virtual appliance over the Cisco ESA appliance?

  1. reduced space and power requirements

  2. outbound message protection

  3. automated administration

  4. global threat intelligence updates from Talos

Answer: A

Question No: 65

Which commands are required to configure SSH on router? (Choose two.)

  1. Configure domain name using ip domain-name command

  2. Generate a key using crypto key generate rsa

  3. Configure a DHCP host for the router using dhcpname#configure terminal

  4. Generate enterprise CA self-sign certificate

Answer: A,B Explanation:

Here are the steps:

->Configure a hostname for the router using these commands. yourname#configure terminal

Enter configuration commands, one per line. End with CNTL/Z. yourname (config)#hostname LabRouter


->Configure a domain name with the ip domain-name command followed by whatever you would like your domain name to be. I used CiscoLab.com.

LabRouter(config)#ip domain-name CiscoLab.com

->We generate a certificate that will be used to encrypt the SSH packets using the crypto key generate rsa command.

Take note of the message that is displayed right after we enter this command: quot;The name for the keys will be: LabRouter.CiscoLab.comquot; – it combines the hostname of the router

along with the domain name we configured to get the name of the encryption key generated; this is why it was important for us to, first of all, configure a hostname then a domain name before we generated the keys.

Reference: https://www.pluralsight.com/blog/tutorials/configure-secure-shell-ssh-on-cisco- router

Question No: 66

When does the Cisco ASA send traffic to the Cisco ASA IPS module for analysis?

  1. after outgoing VPN traffic is encrypted

  2. after firewall policies are applied

  3. before incoming VPN traffic is decrypted.

Answer: B

Question No: 67

Which Cisco technology prevents targeted malware attacks, provides data loss prevention and spam protection, and encrypts email?

  1. SBA

  2. secure mobile access

  3. IPv6 DMZ web service

  4. ESA

Answer: D

Question No: 68

Which set of commands changes the FTP client timeout when the sensor is communicating with an FTP server?

  1. sensor# configure terminal sensor(config)# service sensor sensor(config-hos)# network-settings sensor(config-hos-net)# ftp-timeout 500

  2. sensor# configure terminal sensor(config)# service host

    sensor(config-hos)# network-settings parameter ftp sensor(config-hos-net)# ftp-timeout 500

  3. sensor# configure terminal sensor(config)# service host sensor(config-hos)# network-settings sensor(config-hos-net)# ftp-timeout 500

  4. sensor# configure terminal sensor(config)# service network sensor(config-hos)# network-settings sensor(config-hos-net)# ftp-timeout 500

Answer: C

Question No: 69

When centralized message tracking is enabled on the Cisco ESA, over which port does the communication to the SMA occur by default?

  1. port 2222/TCP

  2. port 443/TCP

  3. port 25/TCP

  4. port 22/TCP

Answer: D

Question No: 70

Which Cisco IPS deployment mode is best suited for bridged interfaces?

  1. inline interface pair mode

  2. inline VLAN pair mode

  3. inline VLAN group mode

  4. inline pair mode

Answer: B

