Certday Cisco 642-503 Exam Download

Most Hottest Cisco 642-503 Exam Free Download, Pass Securing Networks with Cisco Routers and Switches.

Cisco 642-503 Exam Download

Flydumps ensures Cisco 642-503 study guide are the newest and valid enough to help you pass the test.Please visit Flydumps.com and get valid Cisco 642-503 PDF and VCE exam dumps with free new version.100% valid and success.

 

QUESTION 91
You are configuring the authentication feature on a new Certkiller router. Which of the following configures an authentication proxy rule for the IOS Firewall?
A. ip inspect-proxy name proxyname http
B. ip auth-proxy name proxyname http
C. ip auth-rule proxyname http
D. ip proxy-name proxyname http

Correct Answer: B Section: (none) Explanation
Explanation/Reference:
Explanation:
Create an authentication proxy rule with the global configuration mode command ip auth-proxy name
(name) http. Apply the proxy rule to an interface to force users to authenticate through the firewall.

QUESTION 92
The authentication proxy feature has been configured on one of the Certkiller routers. Where are access profiles stored with the authentication proxy features of the Cisco IOS Firewall?
A. PIX Firewall
B. Cisco router
C. Cisco VPN Concentrator
D. Cisco Secure ACS authentication server

Correct Answer: D Section: (none) Explanation
Explanation/Reference:
Explanation:
With the authentication proxy feature, users can log in to the network or access the Internet via HTTP, and
their specific access profiles are automatically retrieved and applied from a CiscoSecureACS, or other
RADIUS, or TACACS+ authentication server. The user profiles are active only when there is active traffic
from the authenticated users.
Reference:
 

QUESTION 93
Refer to the output of a "sh ip auth-proxy cache" command issued on a Certkiller router below. Which port is being used by the client? CK2 # sh ip auth-proxy cache Authentication Proxy Cache Client Name aaauser, Client IP 10.0.2.12, Port 2636, timeout 5, Time Remaining 3, state ESTAB Based on this information, which port is being used by the client?
A. 1645
B. 1646
C. 1812
D. 2636
E. 2640
F. 8080

Correct Answer: D Section: (none) Explanation
Explanation/Reference:
Explanation: Use the "show ip auth-proxy" to display either the authentication proxy entries or the running authentication proxy configuration. Use the cache keyword to list the host IP address, the source port number, the timeout value for the authentication proxy, and the state for connections using authentication proxy. If authentication proxy state is HTTP_ESTAB, the user authentication was successful. In this example, the client was established using port 2636.
QUESTION 94
How does a user on the Certkiller LAN trigger the authentication proxy after the idle timer has expired?
A. The proxy authenticates the user
B. The user initiates another HTTP session
C. The user enters a new username and password
D. The user enters a valid username and password
E. None of the above

Correct Answer: B Section: (none) Explanation
Explanation/Reference:
Explanation:
How the Authentication Proxy Works:
When a user initiates an HTTP session through the firewall, the authentication proxy is triggered. The
authentication proxy first checks to see if the user has been authenticated. If a valid authentication entry
exists for the user, the connection is completed with no further intervention by the authentication proxy. If
no entry exists, the authentication proxy responds to the HTTP connection request by prompting the user
for a username and password.
Reference:
 

f:id:Cisco642-503exam:20160926104824p:plain


QUESTION 95
Router CK1 has been configured for authentication proxy. What is the default idle time of an enabled IOS Firewall authentication proxy?
A. 5 seconds
B. 50 seconds
C. 5 minutes
D. 60 minutes
E. 3600 minutes
F. 1 Day

Correct Answer: D Section: (none) Explanation
Explanation/Reference:
Explanation: To set the authentication proxy idle timeout value (the length of time an authentication cache entry, along with its associated dynamic user ACL, is managed after a period of inactivity), use the "ipauth-proxy auth-cache-time" command in global configuration mode. To set the default value, use the no form of this command. ip auth-proxy auth-cache-time min Syntax Description
 
QUESTION 96
A new Certkiller router is being configured for IDS services. Choose the two types of signature implementations that the IOS Firewall IDS can detect. (Choose two.)
A. Atomic
B. Dynamic
C. Regenerative
D. Cyclical
E. Compound
F. Complex

Correct Answer: AE Section: (none) Explanation
Explanation/Reference:
Explanation:
The Cisco IOS firewall IDS can detect atomic and compound signatures:
Atomic signatures detect simple patterns (ie: attempt on a specific host or within a single packet) while
compound signatures detect complex patterns (ie: attack on multiple hosts, over extended time periods
with multiple packets).

QUESTION 97
On router R2, the "show ip ips config" command was issued as shown below: Refer to the exhibit. Given the output of the show ip ips configuration command, how many signatures are active?

A. 0
B. 50
C. 83
D. 100
E. 183
F. 1107
G. None of the above.

Correct Answer: E Section: (none) Explanation
Explanation/Reference:
Explanation:
From the output shown above the total number of active signatures that this router is monitoring is 183.
Note: The 1107:0 signature is a specific signature ID, which has been manually disabled in this example.
This value does not refer to the total number of signatures.

QUESTION 98
Select two issues that you should consider when implementing IOS Firewall IDS. (Choose two)
A. The memory usage
B. The number of DMZs
C. The signature coverage
D. The number of router interfaces
E. The signature length

Correct Answer: AC Section: (none) Explanation Explanation/Reference:
Explanation: The performance impact of intrusion detection will depend on the configuration of the signatures, the level of traffic on the router, the router platform, and other individual features enabled on the router such as encryption, source route bridging, and so on. Enabling or disabling individual signatures will not alter performance significantly; however, signatures that are configured to use Access Control Lists will have a significant performance impact. Because this router is being used as a security device, no packet will be allowed to bypass the security mechanisms. The IDS process in the Cisco IOS Firewall router sits directly in the packet path and thus will search each packet for signature matches. In some cases, the entire packet will need to be searched, and state information and even application state and awareness must be maintained by the router. For auditing atomic signatures, there is no traffic-dependent memory requirement, but the memory usage should be monitored with IDS. For auditing compound signatures, CBAC allocates memory to maintain the state of each session for each connection. Memory is also 
QUESTION 99
To prevent against attacks on your network, you have enabled your router for Intrusion Detection Services. What are the three actions that the IOS Firewall IDS router may perform when a packet, or a number of packets in a session, match a signature? (Choose three)
A. Forward packet to the Cisco IDS Host Sensor for further analysis
B. Send an alarm to the Cisco IDS Directory or Syslog server
C. Send an alarm to Cisco Secure ACS
D. Set the packet reset flag and forward the packet through
E. Drop the packet immediately
F. Return the packet to the sender

Correct Answer: BDE Section: (none) Explanation
Explanation/Reference:
Explanation: The Cisco IOS firewall IDS can be configured to react to suspected malicious traffic in any combination of three ways: 1) Send an alarm - The Cisco IOS firewall IDS can be configured to send an alarm to a syslog server or a centralized management system such as the Cisco Secure IDS Director, the IDS Management Console (IDS MC), the Cisco IDS Event Viewer, or the Cisco Secure Policy Manager (CSPM). 2) Drop the packet - The Cisco IOS firewall can dynamically create an access list that allows the system to drop the incoming packet. 3) Reset the TCP connection - The Cisco IOS firewall can forward packets to both source and destination with the RESET flag set. Reference: CCSP student guide, p.283
QUESTION 100
A packet is passing through a Certkiller IOS IDS system. Which module is audited first when packets enter an IOS Firewall IDS and match a specific audit rule?
A. TCP
B. ICMP
C. IP
D. Application level
E. UDP
Correct Answer: C Section: (none) Explanation

Explanation/Reference:
Packets going through the interface that match the audit rule are audited by a series of modules, starting
with IP; and then either ICMP, TCP, or UDP (as appropriate); and finally, the Application level.
Reference:
 

QUESTION 101
The IOS Firewall is capable of taking certain types of action in cases where a packet or a number of packets in a session, match a signature. What are these actions? (Choose all that apply)
A. It will drop the packet immediately
B. It can return the packet to the sender
C. It can forward packet to the Cisco Ids Host Sensor for further analysis
D. It will the Cisco IDS Director or Syslog server by sending an alarm to it
E. It will send an alarm to Cisco Secure ACS
F. It can set the packets' reset flag and forward the packet through

Correct Answer: ADF Section: (none) Explanation
Explanation/Reference:
Explanation: The Cisco IOS firewall IDS can be configured to react to suspected malicious traffic in any combination of three ways: 1) Send an alarm - The Cisco IOS firewall IDS can be configured to send an alarm to a syslog server or a centralized management system such as the Cisco Secure IDS Director, the IDS Management Console (IDS MC), the Cisco IDS Event Viewer, or the Cisco Secure Policy Manager (CSPM). 2) Drop the packet - The Cisco IOS firewall can dynamically create an access list that allows the system to drop the incoming packet. 3) Reset the TCP connection - The Cisco IOS firewall can forward packets to both source and destination with the RESET flag set. Reference: CCSP student guide, p.283
QUESTION 102
A new Cisco IDS system has been installed to protect the Certkiller network from outside attacks. What kind of signatures trigger on a single packet? (Choose one)
A. Regenerative
B. Cyclical
C. Atomic
D. Dynamic
E. Compound
F. None of the above

Correct Answer: C Section: (none) Explanation
Explanation/Reference:
Explanation:
An atomic attack represents exploits contained within a single packet. For example, the "ping of death"
attack is a single, abnormally large ICMP packet.

QUESTION 103
A perimeter router configured for TCP Intercept is being installed in the Certkiller network to prevent TCP based attacks. What is the default mode TCP Intercept operates in?
A. Intercept
B. Aggressive
C. 3-way
D. Responsive
E. Watch

Correct Answer: A Section: (none) Explanation
Explanation/Reference:
Explanation: TCP Intercept can be in either intercept mode or passive watch mode. In intercept mode, each TCP SYN packet will be intercepted and responded to on behalf of the server it is protecting. With passive watch mode, TCP Intercept monitors the connection to the server to make sure the connection becomes complete. If the server cannot complete the connection within a configurable time period, TCP Intercept will send a reset packet to the server, clearing up the server's resources.
QUESTION 104
You are configuring a new Certkiller router to prevent SPAM attacks. Which of the following commands correctly sets the IOS Firewall IDS spam threshold?
A. ip audit smtp spam 500
B. ip audit smtp spam 500 notify
C. ip audit smtp name spam 500
D. ip audit ids spam 500
E. None of the above

Correct Answer: A Section: (none) Explanation
Explanation/Reference:
Explanation:
Set the threshold at which a spam alarm is triggered for the number of recipients in an email with the "ip
audit smtp spam (number)" command.

QUESTION 105
While logged into a Certkiller router, which of the following commands can be used to verify your IOS Firewall IDS configuration? (Select all that apply)
A. show ip audit attack
B. show ip audit statistics
C. show ip audit all
D. show ip audit tcp
E. show ip audit info

Correct Answer: BC Section: (none) Explanation
Explanation/Reference:
Explanation:
To verify your IOS Firewall IDS configuration there are six options with the show ip audit command: all,
configuration, interfaces, name, sessions, and statistics.

QUESTION 106
While logged into a Certkiller router, which of the following commands specifies that the IOS Firewall IDS engine drops packets and resets TCP connections for information signatures?
A. ip audit name audit1 info attack drop reset
B. ip audit name audit1 info action drop reset
C. ip audit name audit1 info sig action drop reset
D. ip audit name audit1 sig info drop reset
E. None of the above

Correct Answer: D Section: (none) Explanation
Explanation/Reference:
Explanation:
Firstly:
An IDS cannot drop packets or reset connections and here is an excerpt from the 642-502 study guide
which is the old exam: "Cisco IOS IPS enhances the features of Cisco IOS IDS from a passive device that
monitors traffic, to an inline reactive and prevention device. The capability of Cisco IOS IPS to drop traffic
or reset connections is the primary difference between the two solutions."
The question refers to a "IOS Firewall IDS engine"
Secondly:
In the question it shows the "ip audit" command which has changed to "ip ips", below is an excerpt from
the Cisco IOS Security Configuration Guide Release 12.4:
" The latest IPS image will read and convert all commands that begin with the words "ip audit" to "ip
ips."For example, the ip audit name command will become the ip ips name command. Although IPS will
accept the audit keyword, it will generate the ips keyword when you show the configuration. Also, if you
issue the help character (?), the CLI will display the ips keyword instead of the audit keyword, and the Tab
key used for command completion will not recognize the audit keyword."
Thirdly:
Even in the 642-502 (SNRS v1) study guide it was already not possible to configure the action (drop /
reset) from the CLI, it was configured in the SDF.
Excerpt from the 642-502 Study Guide:
"Unsupported CLI Features: Cisco IOS IPS actions (such as resetting the TCP connection) are no longer
configurable via the command-line interface (CLI). The signatures are now preset with actions to mitigate
the attack."

QUESTION 107
Which of the following commands disables an IOS Firewall IDS signature from being scanned in a Certkiller Cisco router?
A. ip audit ids attack signature (sig#) disable
B. ip audit ids signature (sig#) disable
C. ip audit attack signature (sig#) disable
D. ip audit signature (sig#) disable
E. ip ips signature (sig#) disable
F. None of the above

Correct Answer: E Section: (none) Explanation
Explanation/Reference:
Explanation:
The command is no longer "ip audit" as it was for IDS but "ip ips", and it is also no longer IDS but IPS.
Installing Cisco IOS IPS on a New Router
SUMMARY STEPS

1.
 enable

2.
 configure terminal

3.
 ip ips sdf location url

4.
 ip ips name ips-name [list acl]

5.
 ip ips signature signature-id [:sub-signature-id] {delete | disable | list acl-list}

6.
 ip ips deny-action ips-interface

7.
 interface type name

8.
 ip ips ips-name {in | out}9. exit


10. show ip ips configuration Reference: Cisco IOS Security Configuratin Guide, Release 12.4
QUESTION 108
Kathy the security administrator is working on the IOS Firewall IDS feature. She needs to select the command used to configure the IOS Firewall IDS to globally disable a specific signature.
A. ip audit signature sig-id global
B. ip audit signature sig-id disable
C. ip audit disable sig-id
D. ip audit disable signature sig-id

Correct Answer: B Section: (none) Explanation
Explanation/Reference:
Explanation To attach a policy to a signature, use the ip audit signature command in global configuration mode. To remove the policy, use the no form of this command. If the policy disabled a signature, then the no form of this command reenables the signature. If the policy attached an access list to the signature, the no form of this command removes the access list. ipaudit signature signature-id {disable | list acl-list} noip audit signature signature-id Syntax Description: signature-id - Unique integer specifying a signature as defined in the NetRanger Network Security Database. Disable - Disables the ACL associated with the signature. List - Specifies an ACL to associate with the signature. acl-list - Unique integer specifying a configured ACL on the router. Use with the list keyword. Reference: 
QUESTION 109
You need to configure a Certkiller router to support IPS features. What is the purpose of the "ip ips sdf builtin" command?
A. to load IPS on a router using the built-in signatures
B. to load IP on a router using the attack-drop signatures
C. to unload IPS built-in signatures
D. to delete the IPS built-in signatures
E. to load IPS on a router using the built-in micro-engine
F. to disable IPS on a router using the built-in micro-engine

Correct Answer: A Section: (none) Explanation
Explanation/Reference:
Explanation:
Normally, when an IPS router boots up, the built-in signature files are loaded. To instruct the router not to
load the built-in signatures if it cannot find the specified signature definition files (SDFs), use the "no ip ips
sdf builtin" command in global configuration mode. To instruct the router to use the pre-built signature files
upon startup, use the "ip ips sdf builtin" command.
Note:
If the no ip ips sdf builtin command is issued and the router running Intrusion Prevention System (IPS) fails
to load the SDF, you will receive an error message stating that IPS is completely disabled.
Reference:

 

There are a lot of sites provide the Cisco 642-503 exam certification and other training materials for you . Passcert is only website which can provide you Cisco 642-503 exam certification with high quality. In the guidance and help of Flydumps, you can through your Cisco 642-503 exam the first time. The Cisco 642-504 practice test provided by Flydumps are IT experts use their extensive knowledge and experience manufacturing out. It can help your future in the IT industry to the next level.