Cisco Deploying Cisco ASA Firewall Solutions (FIREWALL v1.0) Sample Questions:
1. 
Refer to the exhibits. Which five options should be entered into the five fields in the Cisco
ASDM Add Static Policy NAT Rule screen? (Choose five.)
access-list POLICY_NAT_ACL extended permit ip host 172.16.0.10 10.0.1.0
255.255.255.0 static (dmz,outside) 192.168.2.10 access-list POLICY_NAT_ACL
A) 172.16.0.10 = Original Source
B) outside = Original Interface
C) 192.168.2.10 = Original Source
D) 192.168.2.10 = Translated Use IP Address
E) outside = Translated Interface
F) 192.168.2.10 = Original Destination
G) 10.0.1.0/24 = Original Destination
H) 172.16.0.10 = Translated Use IP Address
I) dmz = Translated Interface
J) dmz = Original Interface
2. Which Cisco ASA feature enables the ASA to do these two things?
1) Act as a proxy for the server and generate a SYN-ACK response to the client SYN request.
2) When the Cisco ASA receives an ACK back from the client, the Cisco ASA authenticates the client and allows the connection to the server.
A) botnet traffic filter
B) TCP normalize
C) TCP intercept
D) TCP state bypass
E) basic threat detection
F) advanced threat detection
3. Refer to the exhibit.
Which two statements about the class maps are true? (Choose two.)
A) These class maps are all type inspect http class maps.
B) These class maps are referenced within the global policy by default for HTTP inspection.
C) These class maps are Layer 3/4 class maps.
D) These class maps classify traffic using regular expressions.
E) These class maps are used within the inspection_default class map for matching the default inspection traffic.
4. A Cisco ASA requires an additional feature license to enable which feature?
A) botnet traffic filtering
B) TCP normalizer
C) transparent firewall
D) cut-thru proxy
E) threat detection
5. By default, how does the Cisco ASA authenticate itself to the Cisco ASDM users?
A) The Cisco ASA automatically creates and uses a persistent self-signed X.509 certificate to authenticate itself to the administrator
B) The Cisco ASA authenticates itself to the administrator using a one-time password.
C) The administrator validates the Cisco ASA by examining the factory built-in identity certificate thumbprint of the Cisco AS
D) The Cisco ASA automatically creates a self-signed X.509 certificate on each reboot to authenticate itself to the administrator.
E) The Cisco ASA and the administrator use a mutual password to authenticate each other.
Solutions:
| Question # 1 Answer: A,D,E,G,J | Question # 2 Answer: C | Question # 3 Answer: A,E | Question # 4 Answer: A | Question # 5 Answer: D |
We're so confident of our products that we provide no hassle product exchange.


By Godfery

