642-532 考试题库
Securing Networks Using Intrusion Prevention Systems Exam (IPS)
- 科目编号 : 642-532
- 科目名称 : Securing Networks Using Intrusion Prevention Systems Exam (IPS)
- 考题数目 : 67 Q&As
- 更新日期 : 2010-05-19
- 价格 :
¥ 403.00¥ 296.00
免费下载642-532认证考题Demo
下载 642-532 Pdf 认证考试题库
Exam : Cisco 642-532
Title : Securing Networks Using Intrusion Prevention Systems Exam (IPS)
1. Which two are necessary to take into consideration when preparing to tune your sensor? (Choose two.)
A. the security policy
B. the network topology
C. which outside addresses are statically assigned to the servers and which are DHCP addresses
D. the IP addresses of your inside gateway and outside gateway
E. which traffic the sensor denies by default
F. the current configuration for each virtual sensor
Answer: AB
2. How does a Cisco network sensor detect malicious network activity?
A. by using a blend of intrusion detection technologies
B. by performing in-depth analysis of the protocols that are specified in the packets that are traversing the network
C. by comparing network activity to an established profile of normal network activity
D. by using behavior-based technology that focuses on the behavior of applications
Answer: A
3. What are three differences between inline and promiscuous sensor functionality? (Choose three.)
A. A sensor that is operating in inline mode can drop the packet that triggers a signature before it reaches its target, but a sensor that is operating in promiscuous mode cannot.
B. A sensor that is operating in inline mode supports more signatures than a sensor that is operating in promiscuous mode.
C. Deny actions are available only to inline sensors, but blocking actions are available only to promiscuous mode sensors.
D. A sensor that is operating in promiscuous mode can perform TCP resets, but a sensor that is operating in inline mode cannot.
E. Inline operation provides more protection from Internet worms than promiscuous mode does.
F. Inline operation provides more protection from atomic attacks than promiscuous mode does.
Answer: AEF
4. In which three ways does a Cisco network sensor protect network devices from attacks? (Choose three.)
A. It uses a blend of intrusion detection technologies to detect malicious network activity.
B. It can generate an alert when it detects traffic that matches a set of rules that pertain to typical intrusion activity.
C. It permits or denies traffic into the protected network that is based on access lists that you create on the sensor.
D. It can take a variety of actions when it detects traffic that matches a set of rules that pertain to typical intrusion activity.
E. It uses behavior-based technology that focuses on the behavior of applications to protect network devices from known attacks and from new attacks for which there is no known signature.
Answer: ABD
5. Which two statements are true about Cisco IPS signatures? (Choose two.)
A. A signature is a set of rules that pertain to typical intrusion activity.
B. When network traffic matches a signature, the signature must generate an alert, but it can also initiate a response action.
C. Some signatures can be triggered by the contents of a single packet.
D. Signatures trigger alerts only when they match a specific pattern of traffic.
E. You can disable signatures and later re-enable them; however, this process requires the sensing engines to rebuild their configuration, which takes time and could delay the processing of traffic.
F. You can enable and modify built-in signatures, but you cannot disable them.
Answer: AC
选择 QuickPass 642-532 题库
642-532 考试是 Cisco 公司的 CCSP 认证考试官方代号,QuickPass 的 642-532 权威考试题库软件是 Cisco 认证厂商的授权产品,QuickPass 绝对保证第一次参加 642-532 考试的考生即可顺利通过,否则承诺全额退款!
CCSP 认证作为全球IT领域专家 Cisco 热门认证之一,是许多大中IT企业选择人才标准的必备条件。 如果你正在准备 642-532 考试,为 Cisco CCSP认证做最后冲刺,又苦于没有绝对权威的考试真题模拟, QuickPass 希望能助你成功。
Quickpass 642-532 Exam Features
1、QuickPass考题大师642-532试题都是考试原题的完美组合,覆盖率95%以上,答案由多位专业资深讲师原版破解得出,正确率100%,只要您使用本站的考试题库参加642-532 考试,我们保证您一次轻松通过考试;
2、售后服务第一!我们相信要想在当今时代取得成功,必须为广大用户提供全套的周到细致的全程优质售后服务,只有客户满意了,我们才能发展。客户至上是我们QuickPass考题大师的一贯宗旨;
3、QuickPass实行“一次不过全额退款”承诺。如果您购买我们642-532的考题,只要不是首次通过,凭盖有PROMETRIC或VUE考试中心钢印的考试成绩单,我们将退还您购买642-532考题大师的全部费用,绝对保证您的利益不受到任何的损失;
4、本站642-532题库根据642-532考试的变化动态更新,在厂家考题每次发生变化后,我们承诺2天内更新642-532题库。在您购买我们的产品之后,我们将提供90天的免费更新。确保642-532考题的覆盖率始终都在95%以上;我们提供2种 642-532考题大师版本供你选择。
5、软件版本642-532考试题库
优点:具有学习模式,测试模式,线上自动升级
缺点:仅限固定电脑使用,不可打印为文本,只能PC阅读
6、PDF 格式642-532 考试题库(部分最新更新科目已不提供PDF)
优点:不需下载安装软件,方便用户打印和携带,但也带来了可随意制的弊端,因此我们提醒用户不得随意公开或出售本站的642-532题库,一经发现立即取消其升级资格,且不予退款。
缺点:不具备测试模式,通过查看 QuickPass.cn网站及查收我们的更新E-MAIL获取更新信息。
http://www.quickpass.cn The safer.easier way to get CCSP Certification.
