Cisco Security Solutions for Systems Engineers - 642-583 Exam Practice Test

Using Cisco ASA active/active stateful failover, what happens if the return packet of an existing connection is not found in the local Cisco ASA connection table?
Correct Answer: A
DRAG DROP
Correct Answer:

Explanation:

MPLS VPN does not provide or support which of the following?
Correct Answer: E
Which two Cisco products/features offer the best security controls for a web server which has applications running on it that perform inadequate input data validation? (Choose two.)
Correct Answer: B,D
Which uRPF option allows for asymmetrical routing?
Correct Answer: A
What are the four main deployment options to consider when implementing Cisco NAC Appliance design? (Choose four.)
Correct Answer: A,B,C,D
Which key benefit does DTLS offer over TLS?
Correct Answer: A
Refer to the exhibit.

A distributed DoS attack has been detected. The attack appears to have sources from many hosts in network X/24. An operator in the network operation center is notified of this attack and must take preventive action. To block all offending traffic, the network operator announces a BGP route, with the next-hop attribute of 172.31.1.1, for the X/24 network of the attacker.
Which two methods do the routers at the regional office, branch office, and telecommuter location use to prevent traffic going to and from the attacker? (Choose two.)
Correct Answer: B,C
Which statement is true?
Correct Answer: A
Refer to the exhibit. Which statement correctly describes this security architecture, which is used to protect the multi-tiered web application?
Correct Answer: A