Dumps4cert.com : Latest Dumps with PDF and VCE Files
2018 July VMware Official New Released 2V0-642
100% Free Download! 100% Pass Guaranteed!
CCIE Security Exam (v4.1)
Question No: 171 – (Topic 2)
What are two enhancements in WCCP V2.0 over WCCP V1.0? (Choose two.)
-
support for HTTP redirection
-
multicast support
-
authentication support
-
IPv6 support
-
encryption support
Answer: B,C
Explanation: WCCP V2.0 supports the following enhancements to the WCCP V1.0 Protocol:
* Multi-Router Support.
WCCP V2.0 allows a farm of web-caches to be attached to more than one router.
-
Multicast Support.
WCCP V2.0 supports multicasting of protocol messages between web-caches and routers.
-
Improved Security.
WCCP V2.0 provides optional authentication of protocol packets received by web- caches and routers.
-
Support for redirection of non-HTTP traffic.
WCCP V2.0 supports the redirection of traffic other than HTTP traffic through the concept of Service Groups.
-
Packet return.
WCCP V2.0 allows a web-cache to decline to service a redirected packet and to return it to a router to be forwarded. The method by which packets are returned to a router is negotiable.
Reference: https://tools.ietf.org/id/draft-wilson-wrec-wccp-v2-01.txt
Question No: 172 – (Topic 2)
What are the three probes supported by Cisco ISE profiling services? (Choose three)
-
NetFlow (NetFlow Probe)
-
DHCP (DHCP Probe)
-
DHCP SPAN (DHCP SPAN Probe)
-
HTTP (HTTP Probe)
-
HTTP SPAN (HTTP SPAN Probe)
-
RADIUS (RADIUS Probe)
-
Network Scan (Network Scan Probe)
-
DNS (DNS Probe)
-
SNMP Query (SNMP Query Probe)
-
SNMP Trap (SNMP Trap Probe)
Answer: A,B,D
Question No: 173 – (Topic 2)
Which two statements about TrustSec are true? (Choose two)
-
It can simplify the management and configuration of security policies
-
It can simplify the ASA management and configuration
-
It can simplify SG-ACL provisioning to network router and switches
-
It can apply access-control policies throughout the network
-
It is a part of Cisco commerce work space
Answer: C,D
Question No: 174 – (Topic 2)
What is the default communication port used by RSA SDI and ASA?
-
UDP 5500
-
UDP 848
-
UDP 500
-
UDP 4500
Answer: A
Question No: 175 – (Topic 2)
Which two statements about ISO 27001 are true? (Choose two.)
-
It is closely aligned to ISO 22000 standards.
-
It is an ISO 17799 code of practice.
-
It is an Information Security Management Systems specification.
-
It is a code of practice for Informational Social Management.
-
It was formerly known as BS7799-2.
Answer: C,E
Question No: 176 – (Topic 2)
Which statement describes RA?
-
The RA is not responsible to verify users request for digital certificates.
-
The RA is part of private key infrastructure.
-
The RA has the power to accept registration requests and to issue certificates.
-
The RA only forwards the requests to the CA to issue certificates.
Answer: D
Question No: 177 – (Topic 2)
Refer to the exhibit.
What is the effect of the given service policy configuration?
-
It blocks cisco.com, msn.com, and facebook.com and permits all other domains.
-
It blocks all domains except facebook.com, msn.com, cisco.com and google.com
-
It blocks all domains except cisco.com, msn.com, and facebook.com
-
It blocks facebook.com, msn.com, cisco.com and google.com, and permits all other domains
Answer: B
Question No: 178 – (Topic 2)
Your coworker is working on a project to prevent DDoS and ingress filtering and needs advice on the standard and associated process for a single-homed network. Which two options do you suggest? (Choose two.)
-
RFC 5735
-
RFC 3704
-
BCP 84
-
BCP 38
-
RFC 2827
Answer: D,E
Question No: 179 – (Topic 2)
Refer to the exhibit.
What is the purpose of the command in the NAT-PT for IPv6 implementation on a Cisco IOS device?
-
It defines address pool used by the IPv6 access-list.
-
It defines the IPv4 address pool used by the NAT-PT for dynamic address mapping.
-
It defines address pool used by the IPv4 access-list.
-
It defines the IPv6 address pool used by the NAT-PT for dynamic address mapping.
-
It defines the IPv4 address pool used by the NAT-PT for static address mapping
Answer: B Explanation:
ipv6 nat v6v4 pool name start-ipv4 end-ipv4 prefix-length prefix-length Example:
Device(config)# ipv6 nat v6v4 pool v4pool 10.21.8.1 10.21.8.10 prefix-length 24
Specifies a pool of IPv4 addresses to be used by NAT-PT for dynamic address mapping.
Reference: http://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipaddr_nat/configuration/15- mt/nat-15-mt-book/ip6-natpt.html
Question No: 180 – (Topic 2)
Which two of the following pieces of information are communicated by the ASA in version
8.4 or later when the Stateful Failover is enabled? (Choose two.)
-
DHCP server address leases.
-
dynamic routing tables
-
power status
-
NAT translation table
-
user authentication
Answer: B,D
Reference: http://www.cisco.com/c/en/us/td/docs/security/asa/asa84/configuration/guide/asa_84_cli_co nfig/ha_overview.html#wp1078922
100% Dumps4cert Free Download!
–Download Free Demo:2V0-642 Demo PDF
100% Dumps4cert Pass Guaranteed!
–2V0-642 Dumps
Dumps4cert | ExamCollection | Testking | |
---|---|---|---|
Lowest Price Guarantee | Yes | No | No |
Up-to-Dated | Yes | No | No |
Real Questions | Yes | No | No |
Explanation | Yes | No | No |
PDF VCE | Yes | No | No |
Free VCE Simulator | Yes | No | No |
Instant Download | Yes | No | No |