The SAFE Implementation Exam is based on the principles and
technologies contained in the “SAFE: Extending the Security
Blueprint to Small, Midsize, and Remote-User Networks” (SMR) white paper.
This document is available as a PDF that can be downloaded from www.cisco.com/go/safe.
The exam topics provide an overview that can be used to guide the
study process while the skills required for a successful exam can be used as a
checklist to measure progress.
Questions
The following questions are based on the PDFs from the
chapter. The actual exam can also include anything from the other four
exams.
|
1. |
Which one of the following is not one of the Cisco SAFE
Axioms?
-
Switches Are Targets
-
VPNs Are Targets
-
Routers Are Targets
-
Hosts Are Targets
-
Networks Are Targets
-
Applications Are Targets |
|
2. |
Why must IDS be tuned when deployed?
-
To learn the network devices
-
To learn the protocols running in the network
-
To reduce false positives
-
To ensure compatibility with other security
devices |
|
3. |
To reduce the chances of DoS attacks, filtering should be
configured on which two of the following RFCs?
-
2827
-
1518
-
1814
-
1918 |
|
4. |
OTP mitigates which of the following common attacks?
-
Man-in-the-middle attacks
-
Network reconnaissance attacks
-
Brute force password attacks
-
Trojan horse attacks |
|
5. |
What are the correct first initials for the Cisco Security
Wheel?
-
SMTI
-
PITR
-
ISPB
-
BPIM
|
|
6. |
The SAFE document considers which of the following
architectures to be most secure?
-
In-Band
-
SSL
-
HTTPS
-
Out-of-Band |
|
7. |
SAFE as a security policy template for company networks
provides which one of the following?
-
An all-encompassing design for providing full security for
corporate networks
-
A materials list for security purchases
-
A single-vendor approach to end-to-end network security
designs
-
The original statement is false; SAFE is not a security
policy template |
|
8. |
According to SAFE, what two reasons account for the
increasing threat hackers pose to networks?
-
Computers and networking devices continually becoming less
complex
-
Ubiquity of the Internet
-
Pervasiveness of easy-to-use operating systems and
development environments
-
Darwin’s theory of evolution and natural
selection |
|
9. |
VPN remote users using split tunneling to connect to the
Internet outside the VPN tunnel should use which of the following technologies
to protect access to the local network?
-
Access lists
-
Layer 2 tunneling
-
PIX failover
-
Personal firewall |
|
10. |
Which of the following can’t mitigate the threat of packet
sniffers in the network?
-
Replacing hubs with Layer 2 switches
-
Cryptography
-
Using only static routes in the LAN routers
-
Strong authentication
|
|
11. |
The central theme of Cisco AVVID and Cisco AVVID Network
Infrastructure can be split into four general layers of emphasis. Which of the
following doesn’t belong?
-
Applications resilience
-
Business resilience
-
Hardware resilience
-
Network resilience
-
Communications resilience |
|
12. |
Which is not one of the five primary concerns of network
deployment addressed by Cisco AVVID Network Infrastructure?
-
Quality of service (QoS)
-
Security
-
Mobility
-
Interoperability
-
High availability
-
Scalability |
|
13. |
According to AVVID, Cisco’s security suite emphasizes three
key areas. Which of the following is not one of them?
-
External Network Security
-
Device Security
-
Internal Network Security
-
Network Identity |
|
14. |
What is frequently the only way to thwart a DoS attack?
-
A strong perimeter router backed up by a firewall
-
Cooperation with the Internet service provider (ISP)
-
A strong perimeter firewall backed up by a router
-
Running TCP Intercept on the perimeter
router |
|
15. |
Which two of the following are advantages of using a VPN
hardware client device?
-
Lower cost than a router
-
Access and authentication centrally administered
-
More secure than a firewall device
-
Individual PCs on the remote-site network do not need VPN
client software |
Answers
|
1. |
B. VPNs Are Targets |
|
2. |
C. To reduce false positives |
|
3. |
A. and D. 2827 and 1918 |
|
4. |
C. Brute force password
attacks |
|
5. |
A. SMTI—Secure, Monitor, Test,
Improve |
|
6. |
D. Out-of-Band |
|
7. |
D. The original statement is false, SAFE
is not a security policy template |
|
8. |
B. and C. Ubiquity of the Internet, and
pervasiveness of easy-to-use operating systems and development
environments |
|
9. |
D. Personal firewall |
|
10. |
C. Use only static routes in the LAN
routers |
|
11. |
C. Hardware resilience |
|
12. |
D. Interoperability |
|
13. |
B. Device Security |
|
14. |
B. Cooperation with the Internet service
provider (ISP) |
|
15. |
B. and D. Access and authentication can be
centrally administered, and individual PCs on the remote-site network do not
need VPN client software |