Do I Know This Already

1. RFC 1700 defines what well-known ports for DNS?

Answer: e. TCP/UDP port 53

DNS is permitted by RFC 1700 to use both TCP and UDP port 53. DNS applications use TCP port 53 for zone transfers and when the DNS replies are greater than 512 bytes.

2. What supplies DNS security? Answer: e. None of these

DNS has no form of security, so any device can request name-to-IP address mappings.

3. What Cisco IOS command will stop a Cisco router from querying a DNS server when an invalid Cisco IOS command is entered at the EXEC or PRIV prompt?

Answer: a. no ip domain-lookup

To disable DNS query lookup, the Cisco IOS command in global configuration mode is no ip domain-lookup.

4. What does the following Cisco IOS global configuration mode line accomplish?

ip host SimonisaCCIE 131.108.1.1 131.108.1.2

Answer: a. Defines a local host name, SimonisaCCIE, mapped to IP addresses 131.108.1.1 and 131.108.1.2

The ip host name ipaddress1 [ipaddress2 ipaddress3 ipaddress4 ipaddress5 ipaddress6 ipaddress7 ipaddress8] command configures a local address lookup for the name SimonisaCCIE. Up to eight addresses can be used. The router will try 131.108.1.1 first and, if no response is made by the remote host, the second address, 131.108.1.2, will be attempted from the command-line interface (CLI).

5. TFTP uses what predefined UDP port number? Answer: e. 69

TFTP uses UDP port number 69 for the initial connection, and then data transfer occurs between two random higher-numbered UDP ports.

6. What Cisco IOS command will copy a Cisco IOS image from the current system flash to a TFTP server?

Answer: b. copy flash tftp

To copy a Cisco IOS image from the routers to system flash, the correct Cisco IOS command is copy flash tftp.

7. Suppose a client calls and advises you that an FTP data transaction is not allowing the client to view the host's directory structure. What are the most likely causes of the problem? (Choose all that apply.)

Answers: b. The client's FTP data port is not connected.

e. An access list is stopping port 20 from detailing the directory list.

The FTP data port is used to view the directory and could be blocked because of an access list or a fault with the client's software when establishing the FTP 20 connection.

8. FTP runs over what Layer 4 protocol? Answer: b. TCP

The FTP application is a connection-orientated protocol and is part of the TCP/IP protocol suite. FTP ensures that data is delivered by using TCP, which is another connection-oriented protocol.

9. HTTPs traffic uses what TCP port number? Answer: b. 443

HTTPs runs over TCP port 443.

10. SNMP is restricted on Cisco routers by what Cisco IOS command? Answer: b. snmp-server community string

To restrict SNMP access, the correct Cisco IOS command is snmp-server community string. Without the correct string, network management system (NMS) stations cannot access a router with SNMP queries. You can disable SNMP on a router and restrict SNMP access with the Cisco IOS command no snmp-server. Access lists can be applied to further restrict access to certain hosts and IP subnet ranges.

11. TFTP uses which of the following? Answer: d. Can use UDP/TCP and port 69

The TFTP port number is defined in RFC 1700 (the protocol is defined in RFC 1350) and TFTP is permitted to use TCP/UDP port 69 only. Most applications, such as Cisco TFTP Server, use UDP port 69. Beware of such tricky questions for the examination.

12. Which of the following statements is true regarding SSL?

Answer: b. Encryption is used after a simple handshake is completed; that is, after the client is authenticated.

After the hosts have negotiated with valid username/password pairs, SSL starts to encrypt all data. After the handshake, packets are not authenticated. SSL uses TCP port 443.

13. What is the HELO SMTP command used for? Answer: b. To identify SMTP clients.

The HELO command identifies the client to the SMTP server.

14. POP3 clients can do what? Answer: b. Retrieve mail.

POP3 clients retrieve mail from POP3 servers. SMTP is not part of the POP3 standard. POP3 allows a client to retrieve e-mail from a POP3 server. There is no provision to send e-mail in POP3.

15. NTP uses what well-known TCP port as defined by RFC 1700? Answer: e. 123

NTP uses UDP or TCP, and the port number is 123. Typically, however, NTP applications only use UDP port 123; RFC 1700 allows for either TCP or UDP to be applied. All applications in use today use UDP.

16. Secure Shell (SSH) is used to do what?

Answer: c. Protect the TCP/IP host with an encrypted channel.

SSH is used to establish a secure session to a TCP/IP host, thereby ensuring it is protected against packet-snooping tools. SSH provides an encrypted communication channel between the client and server device.

17. Which of the following protocols can be authenticated? (Select the best four answers.) Answers: a. Telnet b. HTTP

c. HTTPs f. FTP

Telnet, HTTP, HTTPs, and FTP require the user to enter a username and password pair to gain access to restricted hosts. Spanning tree is a Layer 2 mechanism with no authentication mechanism, and TFTP has no username/password pair requirement.

18. What is the community string value when the following Cisco IOS commands are entered in global configuration mode?

snmp-server community public RO snmp-server enable traps config snmp-server host 131.108.255.254 isdn

Answer: c. publiC

The community string is defined by command snmp-server community community string, which, in this case, is set to publiC. The community string is case sensitive.

19. Which of the following best describes an SNMP inform request?

Answer: c. Requires an acknowledgment from the SNMP manager.

SNMP inform requests require an acknowledgment from the SNMP manager. SNMP hosts will continue sending the SNMP inform request until an acknowledgment is received.

20. What UDP port number will SNMP traps be sent from? Answer: d. 162

SNMP traps are sent by SNMP agents (such as routers) over UDP port 162.

21. What TCP port number will an SNMP inform acknowledgment packet be sent to? Answer: f. None of these

SNMP inform acknowledgments are sent over UDP (not TCP) port number 161.

22. To restrict SNMP managers from the source network 131.108.1.0/30, what Cisco IOS command is required?

Answer: c.

snmp-server community SimonisCool ro 4 access-list 4 permit 131.108.1.0 0.0.0.3

The SNMP server community name must be defined with the following command:

snmp-server community string ro access-list-number

The access list number definition must follow (in this case, number 4). The access list range is between 1 and 99 only.

23. Cisco IOS SSH supports what version of SSH? Answer: c. Both versions 1 and 2

Cisco IOS 12.2 or later supports SSH versions 1 and 2. You should be aware that 12.3T and higher versions of Cisco IOS only support SSH 2. Exam hot tip: If the question in the written exam does not mention Cisco IOS revisions, then select both SSH 1 and 2 as the examination may not be up to date.

24. When enabling Cisco IOS SSH on a Cisco IOS router, which of the following is not a required step?

Answer: c. Generate a secret and enable password.

Cisco IOS does not require a secret and enable password when enabling SSH; the DNS name and the hostname and transport commands are mandatory. SSH requires a crypto Cisco IOS image loaded on the router. You must also configure a username/password pair locally.

25. What Cisco IOS command will enable a SSH client session with the username cisco, encryption 3DES, and target IP address 10.1.1.1/24?

The Cisco IOS SSH client command syntax is ssh [-l userid] [-c {des | 3des}] [-o numberofpasswordprompts n] [-p portnum] {ipaddr | hostname} [command]

26. SSH provides a security mechanism but lacks one certain feature. What feature is that? Answer: c. Each transmission requires authentication

SSH provides a secure private channel for all messages. The end client to server is fact authenticated and an integrity check is made. The only limiting factor is that not every individual transmission is authenticated—just the initial request after a simple handshake using a secret key for data encryption.

27. What protocol allows network administrators to monitor IDS sensors and what two protocols can be used?

Answer: a. RDEP and HTTP/SSL

Remote Data Exchange Protocol (RDEP) allows the operator to monitor the network IDS sensors in place and communicate via a protocol named RDEP. RDEP uses HTTP and SSL to pass Extensible Markup Language (XML) documents over an encrypted session, between the sensor and the external system. If the session is encrypted, then only SSL can be used.

Continue reading here: Do I Know This Already Klo

Was this article helpful?

0 0

Readers' Questions

  • gebre
    Which two of the following lists accurately describes tcp and udp?
    8 months ago
  • A) Acknowledging packets, connection-oriented, low latency B) Connectionless, unordered, low reliability C) Connection-oriented, low latency, unreliable D) Acknowledging packets, connectionless, high reliability A) Acknowledging packets, connection-oriented, low latency B) Connectionless, unordered, low reliability