Cisco Deploying Cisco ASA Firewall Solutions (FIREWALL v1.0) - 642-617 FREE EXAM DUMPS QUESTIONS & ANSWERS
Which statement about the Cisco ASA 5505 configuration is true?
Correct Answer: D
Vote an answer
By default, how does the Cisco ASA authenticate itself to the Cisco ASDM users?
Correct Answer: C
Vote an answer

On the Cisco ASA, tcp-map can be applied to a traffic class using which MPF CLI configuration command?
Correct Answer: E
Vote an answer
Which Cisco ASA feature enables the ASA to do these two things?
1) Act as a proxy for the server and generate a SYN-ACK response to the client SYN request.
2) When the Cisco ASA receives an ACK back from the client, the Cisco ASA authenticates the client and allows the connection to the server.
1) Act as a proxy for the server and generate a SYN-ACK response to the client SYN request.
2) When the Cisco ASA receives an ACK back from the client, the Cisco ASA authenticates the client and allows the connection to the server.
Correct Answer: B
Vote an answer
Which Cisco ASA object group type offers the most flexibility for grouping different services together based on arbitrary protocols?
Correct Answer: B
Vote an answer
CORRECT TEXT
Instructions
This item contains a simulation task. Refer to the scenario and topology before you start.
When you are ready, open the Topology window and click the required device to open the
GUI window on a virtual terminal. Scroll to view all parts of the Cisco ASDM screens.
Scenario
Click the PC icon to launch Cisco ASDM. You have access to a Cisco ASA 5505 via Cisco
ASDM. Use Cisco ASDM to edit the Cisco ASA 5505 configurations to enable Advanced
HTTP Application inspection by completing the following tasks:
1. Enable HTTP inspection globally on the Cisco ASA
2. Create a new HTTP inspect Map named: http-inspect-map to:
a. Enable the dropping of any HTTP connections that encounter HTTP protocol violations b. Enable the dropping and logging of any HTTP connections when the content type in the
HTTP response does not match one of the MIME types in the accept filed of the HTTP request
Note: In the simulation, you will not be able to test the HTTP inspection policy after you complete your configuration. Not all Cisco ASDM screens are fully functional.





Instructions
This item contains a simulation task. Refer to the scenario and topology before you start.
When you are ready, open the Topology window and click the required device to open the
GUI window on a virtual terminal. Scroll to view all parts of the Cisco ASDM screens.
Scenario
Click the PC icon to launch Cisco ASDM. You have access to a Cisco ASA 5505 via Cisco
ASDM. Use Cisco ASDM to edit the Cisco ASA 5505 configurations to enable Advanced
HTTP Application inspection by completing the following tasks:
1. Enable HTTP inspection globally on the Cisco ASA
2. Create a new HTTP inspect Map named: http-inspect-map to:
a. Enable the dropping of any HTTP connections that encounter HTTP protocol violations b. Enable the dropping and logging of any HTTP connections when the content type in the
HTTP response does not match one of the MIME types in the accept filed of the HTTP request
Note: In the simulation, you will not be able to test the HTTP inspection policy after you complete your configuration. Not all Cisco ASDM screens are fully functional.





Correct Answer:
Here are the step by step Solution for this:


Which Cisco ASA feature enables the ASA to do these two things? 1) Act as a proxy for the server and generate a SYN-ACK response to the client SYN request. 2) When the Cisco
ASA receives an ACK back from the client, the Cisco ASA authenticates the client and allows the connection to the server.
ASA receives an ACK back from the client, the Cisco ASA authenticates the client and allows the connection to the server.
Correct Answer: B
Vote an answer
A Cisco ASA is operating in transparent firewall mode, but the MAC address table of the
Cisco ASA is always empty, which causes connectivity issues. What should you verify to troubleshoot this issue?
Cisco ASA is always empty, which causes connectivity issues. What should you verify to troubleshoot this issue?
Correct Answer: C
Vote an answer
A Cisco ASA requires an additional feature license to enable which feature?
Correct Answer: E
Vote an answer