Free Testinside- Best IT Certifications PDF Test Braindumps » Page 'Testinside cisco CCSP 642-551'

Testinside cisco CCSP 642-551

Securing Cisco Network Devices Exam(SND) : 642-551 Exam

642-551 SND
Securing Cisco Network Devices Exam

Last day to test 01/31/07
Exam Number: 642-551
Associated Certifications: CCSP, Cisco Firewall, Cisco IPS, and Cisco VPN Specialist
Duration: 90 minutes (60-70 questions)
Available Languages: English
Click Here to Register: Pearson VUE or Prometric
Exam Policies: Read current policies and requirements
Exam Tutorial: Review type of exam questions

Exam Description Exam Topics Recommended Training Additional Resources
Exam Description
The Securing Cisco Network Devices 642-551 SND exam forms the foundation of the Cisco Certified Security Professional, Cisco Firewall Specialist, Cisco IPS Specialist, and Cisco VPN Specialist certifications. Candidates can prepare for this exam by taking the SND course. This exam includes simulations and tests a candidate’s knowledge and ability to describe, configure, and verify basic security features of Cisco Layer 2 devices, Cisco Routers, Cisco IDS/IPS Sensors, Cisco VPN 3000 Concentrators, and Cisco PIX Security Appliances.

Exam Topics
The following information provides general guidelines for the content likely to be included on the exam. However, other related topics may also appear on any specific delivery of the exam. In order to better reflect the contents of the exam and for clarity purposes the guidelines below may change at any time without notice.

Describe the products in the Cisco security portfolio and explain how they mitigate security threats to a network
Identify the appropriate devices to secure a network
Identify the appropriate device feature to secure a network
Describe the difference in functionality and capabilities of the different security devices
Identify security issues with common management protocols
Describe threats to a network and network devices
Identify different techniques to deal with security threats

Describe the security features available for a Cisco Layer 2 device in a secure network
Identify security features on a Layer 2 device
Describe basic security feature configurations on a Layer 2 device

Implement security on a Cisco IOS Router
Identify mitigation techniques for common physical router security threats
Configure router for secure administrative access
Implement basic AAA for router administrative authentication
Configure AutoSecure to harden Cisco routers
Configure router access lists to secure networks
Configure security for router services and interfaces
Implement Syslog logging
Identify major components of the SDM

Describe and configure Cisco IPS and HIPS
Configure user accounts
Describe and configure Network Access lists
Describe how the sensor device is secure by default
Install the sensor on the network
Describe the methods used to access a sensor
Describe the process for displaying the sensor configuration
Identify major components of IDM
Describe basic sensor operations
Describe the process of using alarms to identify network attacks
Identify the appropriate platform required to install the CSA MC
Configure the default group
Describe the process of agent kit deployment and verifying management of the agent
Describe key features and concepts of VMS
Describe the interoperability of the components of VMS
Describe the hardware and software requirements of VMS

Configure and verify basic remote access on a Cisco VPN 3000 Concentrator
Perform an initial configuration
Configure users and groups
Configure VPN clients
Verify IPSec tunnel establishment

Implement a Cisco PIX security appliance
Describe basic PIX security appliance hardware and software architecture
Identify appropriate PIX security appliance hardware and software configuration
Configure basic network settings using CLI
Configure basic interface features on a PIX security appliance
Verify initial configurations
Identify major components of the PDM
Configure static address translation
Configure Network Address Translation
Configure firewall to secure inbound traffic
Verify inbound traffic restrictions
Describe basic IPSec topologies
Define the services provided by IPSec
Describe the IPSec protocol framework
Describe the IPSec algorithm framework
Describe the concepts of split tunneling
Describe the various authentication methods
Describe how the PIX security appliance uses IPSec to secure networks

“Securing Cisco Network Devices Exam(SND)”, also known as 642-551 exam, is a Cisco certification.
Preparing for the 642-551 exam? Searching 642-551 Test Questions, 642-551 Practice Exam, 642-551 Dumps?

Free 642-551 Demo Download
TestInside offers free demo for 642-551 exam ( Securing Cisco Network Devices Exam(SND)). You can check out the interface, question quality and usability of our practice exams before you decide to buy it. We are the only one site can offer demo for almost all products.

QUESTION 21:
At which location in an access control list is it recommended that you place the
more specific entries?
A. in the middle of the access control list?
B. higher in the access control list
C. lower in the access control list
D. at the bottom of the access control list
Answer: B
Explanation:
Place more specific access list statements higher in the access list. Ensure statements at
the top of the access list do not negate any statements found lower in the list.
For example; blocking all UDP traffic at the top of the list negates the blocking of SNMP
packets lower in the list.
Care must be taken that statements at the top of the access list do not negate any
statements found lower in the list.
QUESTION 22:
How does HIPS inspect for attacks?
A. by intercepting traffic that is incoming to the network interface card
B. by inspecting syslog messages
C. by inspecting traffic that is outgoing from the network interface card
D. by intercepting calls to the OS kernel
E. by inspecting API message between applications
Answer: D
Explanation:
HIPS operates by detecting attacks occurring on a host on which it is installed.

HIPS works by intercepting operating system and application calls, securing the
operating system and application configurations, validating incoming service requests,
and analyzing local log files for after-the-fact suspicious activity.
QUESTION 23:
Which component within the Cisco Network Admission Control architecture acts as
the policy server for evaluating the endpoint security information that is relayed
from network devices, and for determining the appropriate access policy to apply?
A. CiscoWorks
B. CiscoWorks VMS
C. Cisco Secure ACS
D. Cisco Trust Agent
E. Cisco Security Agent
Answer: C

Testinside cisco 6 CCSP 642-551 Questions and Answers : 62 Q&As
Updated: October 2nd , 2008
Price: $125.99 $89.99

Free download:pass4sure CCSP 642-551
Free download:testking CCSP 642-551
password : www.ciscoexams.org

Bookmark and Share

Leave a comment

XHTML - You can use:<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>