|
|

|
№ 3350, Checkpoint 156-210: Susanto
|
00.00.0000
|
1. Which of the following are the valid modules of the FireWall-1 Single Gateway Product (Choose all that
apply)?
A. Management Module
B. Encryption Module
C. Firewall Module
D. Inspection Module
E. Router Security Management
Answer :
ACD
2. Where does the FireWall-1 Kernel Module reside?
A. between the NIC and the TCP/IP stack
B. inside the TCP/IP stack
C. in the driver
memory area
D. in RAM
E. None of the choices.
Answer : A
3. Which of the following are functions provided by the Firewall Module (Choose
all that apply)?
A. session authentication
B. None of the choices.
C. NAT
D. user authentication
E. access control
F. client
authentication
Answer : ACDEF
4. With FW-1, which module provides centralized security management of all your Cisco firewalls (Choose all
that apply)?
A. Open Security Manager
B. Management Module
C. Router Security Management
D. Firewall Module
E. Encryption Module
Answer
: A
5. With FW-1, the Inspection Module is included in which of the following modules (Choose all that apply)?
A. Management Module
B.
Firewall Module
C. Open Security Manager
D. Encryption Module
E. Router Security Management
Answer : B
6. How does FW-1 obtain a
communication's application state?
A. derive from the server RPC bind
B. derive from the server process
C. derive from other applications
D.
derive from past communications
E. derive from the server
Answer : C
7. Stateful inspection engine takes into consideration which of the
following information in its decision process (Choose all that apply)?
A. communication state
B. application state
C. port buffer state
D. user
state
E. OS memory state
Answer : AB
8. Which of the following are the reasons for deploying a firewall product such as FW-1 that uses
stateful inspection (Choose all that apply)?
A. Transparency
B. High performance
C. Application-layer awareness
D. Scalability
E. Good
security
F. Extensible
Answer : ABCDEF
9. FW-1's Inspection Module inspects communications at which layer for maximum security?
A. at
and above the network layer
B. None of the choices.
C. only at the network layer
D. below the network layer
E. above the network
layer
Answer : D
10. Where does the FireWall-1 Inspection Module reside?
A. in RAM
B. None of the choices.
C. in the operating system
kernel
D. outside of the operating system kernel
E. in the driver memory area
Answer : C
11. Which of the following correctly describe an
application layer gateway firewall (Choose all that apply)?
A. Transparent to users
B. Cannot provide for RPC support
C. Implementation is
detrimental to performance
D. Each service requires its own application layer gateway
E. Cannot provide for UDP support
Answer : BCDE
12.
When defining a workstation's interface properties, what are the valid address options available (Choose all that apply)?
A. Internal
B.
Any
C. Others
D. External
E. This net
F. No security policy
Answer : BCEF
13. Why would you consider to use an application layer gateway
rather than a packet filter?
A. Full application-layer awareness
B. Inexpensive
C. Efficient
D. Less overhead
E. Good security
Answer :
AE
14. Which of the following firewall technologies bring context information into considerations (Choose all that apply)?
A. Circuit level
gateway
B. Packet filter
C. Application layer gateway
D. Stateful inspection engine
Answer : CD
15. A proxy implements firewall mainly
at which layer?
A. transport
B. network
C. session
D. datalink
E. application
Answer : E
16. With a packet filtering firewall, what
actions are available towards the outbound FTP connections (Choose all that apply)?
A.leave the entire upper range of ports close
B.leave part of
the entire upper range of ports close
C.leave part of the entire upper range of ports open
D.leave the entire upper range of ports open
Answer : AD
17. Which of the following correctly describe the reason you do not use packet filtering technology (Choose all that apply)?
A.Inadequate logging
B.Difficult to manage
C.Inadequate alerting
D.Difficult to monitor
E.Difficult to configure
F.Subject to IP spoofing
Answer : ABCDEF
18. What are the advantages of the packet filtering technology (Choose all that apply)?
A.High
security
B.Efficient
C.Access to the entire packet header
D.Inexpensive
E.Transparency
F.screening above the network layer
Answer :
BDE
19. Within FW-1 System Status GUI, the icon represents that (Choose all that apply):
A.there is no response
B.the security policy is not
loaded.
C.IP address resolution problem
D.the security policy is installed
E.the system is being protected
Answer : DE
20. At which
layer does the packet filtering method work at?
A. application
B. datalink
C. network
D. transport
E. session
Answer : C
|
|
|
|
|
|
gen. 0.303
|
Server date 03:20 22-11-2008
|
Developed by Zip © 2006
|
|
 |
|
|