100% Pass Guaranteed Accurate 1D0-671 Answers 365 Days Free Updates [Q31-Q52]

Share

100% Pass Guaranteed Accurate 1D0-671 Answers 365 Days Free Updates

1D0-671 DUMPS Q&As with Explanations Verified & Correct Answers

NEW QUESTION # 31
Requests for Web-based resources have become unacceptably slow. You have been assigned to implement a solution that helps solve this problem.
Which of the following would you recommend?

  • A. Enable stateful multi-layer inspection on the packet filter
  • B. Enable authentication on the network proxy server
  • C. Implement a screening router on the network DMZ
  • D. Implement caching on the network proxy server

Answer: D


NEW QUESTION # 32
Which ICMP message type is sent whenever the destination cannot handle the amount of traffic being received?

  • A. Source Quench
  • B. Echo Reply
  • C. Redirect Message
  • D. Source Quench

Answer: A


NEW QUESTION # 33
Which term describes a firewall topology element that consists of a subnet of computers?

  • A. Firewall box
  • B. Security strategy
  • C. Zone
  • D. Demilitarized zone (DMZ)

Answer: D


NEW QUESTION # 34
What is the primary strength of symmetric-key encryption?

  • A. It can encrypt large amounts of data very quickly.
  • B. It provides non-repudiation services more efficiently than asymmetric-key encryption.
  • C. It creates a ash?of a text, enabling data integrity.It creates a ?ash?of a text, enabling data integrity.
  • D. It allows easy and secure exchange of the secret key.

Answer: A


NEW QUESTION # 35
Which security standard consists of 11 titles that are designed to improve the accuracy and reliability of corporate disclosure to reinforce investment confidence and protect investors?

  • A. Sarbanes-Oxley (SOX)
  • B. ISO 17799
  • C. The Common Criteria (CC)
  • D. Gramm-Leach-Bliley Act (GLBA)

Answer: A


NEW QUESTION # 36
You have been assigned to configure a DMZ that uses multiple firewall components. Specifically, you must configure a router that will authoritatively monitor and, if necessary, block traffic. This device will be the last one that inspects traffic before it passes to the internal network.
Which term best describes this device?

  • A. Choke router
  • B. Proxy server
  • C. Screening router
  • D. Bastion host

Answer: A


NEW QUESTION # 37
You are using a PKI solution that is based on Secure Sockets Layer (SSL).
Which of the following describes the function of the asymmetric-key-encryption algorithm used?

  • A. It encrypts the X.509 key.
  • B. It encrypts the hash code used for data integrity.
  • C. It encrypts the symmetric key.
  • D. It encrypts all of the data.

Answer: C


NEW QUESTION # 38
Consider the following image of a packet capture:
This packet capture has recorded two types of attacks.
Which choice lists both attack types?

  • A. A dictionary attack and a worm-based attackA.A dictionary attack and a worm-based attack
  • B. A worm attack and a botnet attack C.A worm attack and a botnet attack
  • C. A syn flood attack and a spoofing attackB.A syn flood attack and a spoofing attack
  • D. A SQL injection attack and a virus attackD.A SQL injection attack and a virus attack

Answer: C


NEW QUESTION # 39
Which symmetric algorithm created by the RSA Security Corporation is a stream cipher that encrypts messages as a whole, in real time?

  • A. RC5
  • B. RC4
  • C. RC2
  • D. RC6

Answer: B


NEW QUESTION # 40
Which two protocols can be found at the transport layer of the TCP/IP stack?

  • A. Post Office Protocol 3 (POP3) and Simple Mail Transfer Protocol (SMTP)
  • B. File Transfer Protocol (FTP) and Hypertext Transfer Protocol (HTTP)
  • C. Internet Protocol (IP) and Internet Control Message Protocol (ICMP)
  • D. Transmission Control Protocol (TCP) and User Datagram Protocol (UDP)

Answer: D


NEW QUESTION # 41
You want to create a certificate for use in a Secure Sockets Layer (SSL) session.
Which of the following is responsible for verifying the identity of an individual and also issuing the certificate?

  • A. Kerberos server
  • B. Certificate repository
  • C. Certificate authority
  • D. Certificate revocation entity

Answer: C


NEW QUESTION # 42
Which of the following is the simplest, most common firewall design?

  • A. A dual-homed bastion host
  • B. A screened subnet
  • C. A single-homed bastion host
  • D. A screening router

Answer: D


NEW QUESTION # 43
Which of the following can specify the route by which a packet of information has traveled?

  • A. A physical line trace
  • B. A reverse scan
  • C. A phone line trace
  • D. A packet trace

Answer: D


NEW QUESTION # 44
An effective way to prevent a user from becoming the victim of a malicious bot is to use a technique in which the user must view a distorted text image, and then type it before he or she is allowed to proceed with a transaction.
This technique is known as a:

  • A. SQL injection.
  • B. CAPTCHA.
  • C. zombie.
  • D. botnet.

Answer: B


NEW QUESTION # 45
Which of the following causes problems with firewalls

  • A. Control FTP
  • B. Data FTP
  • C. Passive FTP
  • D. Active FTP

Answer: D


NEW QUESTION # 46
Which of the following is a typical target of a trojan on a Linux system?

  • A. Shared libraries
  • B. Boot sector files
  • C. System32 DLL files
  • D. Kernel modules

Answer: D


NEW QUESTION # 47
Your organization has made a particularly unpopular policy decision. Your supervisor fears that a series of attacks may occur as a result. You have been assigned to increase automated auditing on a server.
When fulfilling this request, which of the following resources should you audit the most aggressively?

  • A. Intrusion detection systems, especially those placed on sensitive networks
  • B. Firewall settings for desktop systems
  • C. Log files on firewall systems
  • D. Authentication databases, including directory servers

Answer: D


NEW QUESTION # 48
What is the primary use of hash (one-way) encryption in networking?

  • A. User authentication, for non-repudiation
  • B. Encrypting files, for data confidentiality
  • C. Key exchange, for user authentication
  • D. Signing files, for data integrity

Answer: D


NEW QUESTION # 49
Which of the following can effectively thwart VLAN hopping?

  • A. Enabling multiple firewalls on your broadcast domain
  • B. Ensuring that each trunk port retains its default VLAN setting (VLAN1)
  • C. Enabling your network's autotrunking capability
  • D. Removing the default VLAN setting (VLAN1) from any trunk port

Answer: D


NEW QUESTION # 50
Consider the following image of a packet capture:
Which of the following best describes the protocol used, along with its primary benefit?

  • A. It is an active FTP session, which is supported by all FTP clients.
  • B. It is a passive FTP session, which is easier for firewalls to process.
  • C. It is an active FTP session, which is necessary in order to support IPv6.
  • D. It is an extended passive FTP session, which is necessary to support IPv6.

Answer: B


NEW QUESTION # 51
Which of the following accurately describes an aspect of an access control list (ACL)?

  • A. The ACL cannot determine whether a user has access to an object, but can define exactly what the user can do with that object.
  • B. The ACL lists entities that can access a database server, but does not provide access levels.
  • C. The ACL defines users that have access to a resource on a database server.
  • D. The ACL defines the database roles that users have on a database server.

Answer: D


NEW QUESTION # 52
......

1D0-671 dumps Exam Material with 126 Questions: https://www.lead1pass.com/CIW/1D0-671-practice-exam-dumps.html

1D0-671 Questions and Answers Guarantee you Oass the Test Easily: https://drive.google.com/open?id=12rOytinVHYrR7K961hXga4fCee928sfo