CCNP 642-617 test answers, Deploying Cisco ASA Firewall Solutions (FIREWALL v1.0)

1.Which three parameters are set using the set connection command within a policy map on the Cisco ASA 8.2 release? (Choose three.)¬
A. per-client TCP and/or UDP idle timeout¬
B. per-client TCP and/or UDP maximum session time¬
C. TCP sequence number randomization¬
D. maximum number of simultaneous embryonic connections¬
E. maximum number of simultaneous TCP and/or UDP connections¬
F. fragments reassembly options¬
Answer: C,D,E¬†¬
2.Which Cisco ASA feature enables the ASA to do these two things? 1) Act as a proxy for the server and generate a SYN-ACK response to the client SYN request. 2) When the Cisco ASA receives an ACK back from the client, the Cisco ASA authenticates the client and allows the connection to the server.¬
A. TCPnormalizer¬
B. TCP state bypass¬
C. TCP intercept¬
D. basic threat detection¬
E. advanced threat detection¬
F. botnet traffic filter¬
Answer: C¬†¬
3.By default, which traffic can pass through a Cisco ASA that is operating in transparent mode without explicitly allowing it using an ACL?¬
D. OSPF multicasts¬
Answer: A
