Question No.41

When configuring a new context on a Cisco ASA device, which command creates a domain for the context?

  1. domain config name

  2. domain-name

  3. changeto/domain name change

  4. domain context 2

Correct Answer: B

Question No.42

Which two options are two purposes of the packet-tracer command? (Choose two.)

  1. to filter and monitor ingress traffic to a switch

  2. to configure an interface-specific packet trace

  3. to inject virtual packets into the data path

  4. to debug packet drops in a production network

  5. to correct dropped packets in a production network

Correct Answer: CD

Question No.43

Which two web browsers are supported for the Cisco ISE GUI? (Choose two.)

  1. HTTPS-enabled Mozilla Firefox version 3.x

  2. Netscape Navigator version 9

  3. Microsoft Internet Explorer version 8 in Internet Explorer 8-only mode

  4. Microsoft Internet Explorer version 8 in all Internet Explorer modes

  5. Google Chrome (all versions)

Correct Answer: AC

Question No.44

Which two voice protocols can the Cisco ASA inspect? (Choose two.)

  1. MGCP

  2. IAX

  3. Skype


Correct Answer: AD

Question No.45



In your role as network security administrator, you have installed syslog server software on a server whose IP address is According to the exhibits, why isn#39;t the syslog server receiving any syslog messages?

  1. Logging is not enabled globally on the Cisco ASA.

  2. The syslog server has failed.

  3. There have not been any events with a severity level of seven.

  4. The Cisco ASA is not configured to log messages to the syslog server at that IP address.

Correct Answer: B


By process of elimination, we know that the other answers choices are not correct so that only leaves us with the server must have failed. We can see from the following screen shots, that events are being generated with severity level of debugging and below, The IP address has been configured as a syslog server, and that logging has been enabled globally:


Question No.46

Which Cisco TrustSec role does a Cisco ASA firewall serve within an identity architecture?

  1. Access Requester

  2. Policy Decision Point

  3. Policy Information Point

  4. Policy Administration Point

  5. Policy Enforcement Point

Correct Answer: E

Question No.47

Which set of commands creates a message list that includes all severity 2 (critical) messages on a Cisco security device?

  1. logging list critical_messages level 2 console logging critical_messages

  2. logging list critical_messages level 2 logging console critical_messages

  3. logging list critical_messages level 2 logging console enable critical_messages

  4. logging list enable critical_messages level 2 console logging critical_messages

Correct Answer: B

Question No.48

When it is configured in accordance to Cisco best practices, the switchport port-security maximum command can mitigate which two types of Layer 2 attacks? (Choose two.)

  1. rogue DHCP servers

  2. ARP attacks

  3. DHCP starvation

  4. MAC spoofing

  5. CAM attacks

  6. IP spoofing

Correct Answer: CE

Question No.49

What are two reasons to implement Cisco IOS MPLS Bandwidth-Assured Layer 2 Services? (Choose two.)

  1. guaranteed bandwidth and peak rates as well as low cycle periods, regardless of which systems access the device

  2. increased resiliency through MPLS FRR for AToM circuits and better bandwidth utilization through MPLS TE

  3. enabled services over an IP/MPLS infrastructure, for enhanced MPLS Layer 2 functionality

  4. provided complete proactive protection against frame and device spoofing

Correct Answer: BC

Question No.50

When a Cisco ASA is configured in transparent mode, how can ARP traffic be controlled?

  1. By enabling ARP inspection; however, it cannot be controlled by an ACL

  2. By enabling ARP inspection or by configuring ACLs

  3. By configuring ACLs; however, ARP inspection is not supported

  4. By configuring NAT and ARP inspection

Correct Answer: A

