IT인증시험문제는 수시로 변경됩니다. 이 점을 해결하기 위해 Pass4Test의 Cisco 642-584 (Security Solutions for Systems Engineers ) 덤프도 시험변경에 따라 업데이트하도록 최선을 다하고 있습니다.시험문제 변경에 초점을 맞추어 업데이트를 진행한후 업데이트된 Cisco 642-584 (Security Solutions for Systems Engineers ) 덤프를 1년간 무료로 업데이트서비스를 드립니다.
NO.1 Which four features are provided by the Cisco AnyConnect client for Windows? (Choose four.)
A. SSL VPN
B. IPsec VPN
C. Host intrusion prevention system
D. Presence
E. MACsec encryption
F. Antivirus
G. Personal firewall
H. Cisco ScanSafe integration
Answer: A,B,E,H
NO.2 The Cisco SecureX Architecture is built on which three foundational principles? (Choose
three.)
A. Context-aware policy
B. Virtual office management
C. Network management
D. Content access control
E. Context-aware security enforcement
F. Network and global intelligence
Answer: A,E,F
NO.3 Which statement describes an advantage of DV?
A. DV increases the complexity of administration.
B. DV simplifies BYOD deployment.
C. DV cannot prevent end users from uploading potentially malicious data to the system.
D. DV can prevent end users from downloading confidential data.
Answer: D
NO.4 Which three are security features that are applicable to the network edge? (Choose three.)
A. Layer 2 encryption service, also known as MACsec firewall service
B. VPN service
C. Email security service
D. WLAN authorization service
Answer: B,C,D
NO.5 Which three are features of an intrusion prevention system? (Choose three.)
A. Attack obfuscation
B. Detection of behavioral anomalies
C. Detection of protocol anomalies
D. Flexible content filtering
E. Forensic capturing
F. VPN termination
Answer: B,C,E
NO.6 What are two advantages of IKEv2 and Cisco FlexVPN? (Choose two.)
A. IKEv2 is backwards compatible with IKEv1.
B. Cisco FlexVPN supports interoperability, dynamic routing, direct spoke-to-spoke
communication, remote access, source failover, per-peer QoS, and Full AAA management.
C. IKEv2 consolidates several VPN key management features and standards into one new
standard.
D. The anticlogging cookie feature from IKEv1 has been improved.
E. IKEv2 uses IP protocol numbers 50 and 51.
Answer: B,C
NO.7 Which two statements about Cisco IPS are true? (Choose two.)
A. Cisco IPS global correlation is performed before Cisco IPS reputation filters.
B. Cisco ASA-integrated IPS and standalone IPS offer the same features.
C. Cisco standalone IPS functionality can be virtualized.
D. The Cisco IPS reputation filter is based on Cisco SIO and allows packets that are received from
known malicious sources to be dropped before performing signature-based inspection.
Answer: B,D
NO.8 Which statement best describes Cisco ISE?
A. Cisco ISE consolidates user AAA, Security Group Access features, and ScanSafe functionality
into one product.
B. Cisco ISE consolidates user authentication with NAC components into one solution.
C. Cisco ISE provides AAA features, guest provisioning, and device profiling features in the base
feature set; link encryption policies, host posture, and security group access require the advanced
feature set.
D. Cisco ISE combines the capabilities of Cisco Secure ACS and Cisco Virtual Security Gateway
into one product.
Answer: B
NO.9 Which statement about IPsec and IPv6 is true?
A. IPsec is available only with IPv6.
B. IPsec support is mandatory in IPv4.
C. IPsec support is mandatory in IPv6.
D. In order to use IPsec with IPv6, IPv6 must be tunneled over IPv4.
Answer: C
NO.10 Which statement about the Cisco IOS Zone-Based Policy Firewall is true?
A. Only virtual interfaces can be added to a Cisco IOS Zone-Based Policy Firewall zone.
B. A Cisco IOS Zone-Based Policy Firewall zone is a set of VLANs that share a certain trust level.
C. Cisco IOS Zone-Based Policy Firewall policies are not unidirectional.
D. The Cisco IOS Zone-Based Policy Firewall applies firewall policies to traffic traversing zones.
Answer: D
Cisco 642-584 (Security Solutions for Systems Engineers ) 덤프
Posted 2013/8/5 7:05:37 | Category: 미분류 | Tag: