kaab00m from Vietnam -
Aug 23 2012, 8:11 AMReport Spam
PASS my exam. 1 New Question from Cisco.ActualTests.642-637.v2012-08-03.by.Neil.133q.vce
All the simlet and lab, question are the same, but the answer may be not like exactly from the vce.
My score 878 after 30 mintues.
Thanks all, special thanks to Neil.
tunde odubanjo from Nigeria -
Aug 22 2012, 7:48 AMReport Spam
passed the exam on friday 17th August..............thanks a lot
cro@ from Croatia -
Aug 14 2012, 6:24 PMReport Spam
@ahmed - what was your score on the exam?
@sashans - jesi izlazio na ispit? Vrijedi li ovaj vce?
sashans from Serbia -
Aug 12 2012, 12:40 PMReport Spam
@muhha
the class-default drop command is not necessery in the ZBFW sim,i think.
look at this
The policy-map applies firewall policy actions to one or more class-maps to define the service-policy that will be applied to a security zone-pair. When an inspect-type policy-map is created, a default class named class class-default is applied at the end of the class. The class class-default’s default policy action is drop, but can be changed to pass. The log option can be added with the drop action. Inspect cannot be applied on class class-default.
sorurce: http://www.cisco.com/en/US/products/sw/secursw/ps1018/products_tech_note09186a00808bc994.shtml
pozz iz srbije :)
ahmed from Saudi Arabia -
Aug 10 2012, 2:52 PMReport Spam
Hi Neil, thanks for your great job, could you please send me the latest version at a.samir.1010@gmail.com, i'm going to take my exam 14 Aug
thanks,
ksiva55 from Unknown -
Aug 10 2012, 2:19 PMReport Spam
Hi Friends,
Passed today with 860 dump still valid...
CiscoKid from South Africa -
Aug 10 2012, 9:16 AMReport Spam
Thanks Neil. I am writing this on the 14th So i am really looking forward to getting my hands on your "Cisco.ActualTests.642-637.v2012-08-09.by.dd.129q.vce" as i can not see it up here yet. Please mail me a copy at danie.swart@gmail.com.
Thanks for your great work man.
neil from United Kingdom -
Aug 09 2012, 10:40 PMReport Spam
Hi Guys, I uploded letase release of actual tests. wish you all sucess..!!
nubie from Indonesia -
Aug 08 2012, 7:01 AMReport Spam
pass today, thx to all in this forum
muhha from Bosnia and Herzegovina -
Aug 07 2012, 2:11 PMReport Spam
Hi All,
I passed yesterday the exam. It was about 10 new Drag & Drop but those questions are similar to those in neils dump. Thanks to all of you for your contribution!
@nubie this is how I answered yesterday this Drag & Drop question, I hope this is helpful I would suggest to go thru Cisco Press Book you have all explanations there.
- MAB
-this method is used when clients dont support the 802.1x supplicant but need to be authenticated to an 802.1x network
- Restricted VLAN
-this solution is used when users fail authentication and have an 802.1x – compliant device
- Guest VLAN
-this method offers limited access for users without an 802.1x client. by default, it takes 90 seconds for the machine to get assigned to this specific VLAN
- WEB auth
-Clients that use this method can be reauthenticated. if reauthentication fails, then the switch can assign the port to the guest VLAN if its not configured
serji from Unknown -
Aug 07 2012, 2:11 PMReport Spam
Hi, nubie, i believe the answers are as follows:
MAB -this method is used when clients dont support the 802.1x supplicant but need to be authenticated to an 802.1x network
Restricted VLAN -this solution is used when users fail authentication and have an 802.1x – compliant device
Guest VLAN - -this method offers limited access for users without an 802.1x client. by default, it takes 90 seconds for the machine to get assigned to this specific VLAN
WEB auth Clients that use this method can be reauthenticated. if reauthentication fails, then the switch can assign the port to the guest VLAN if its not configured
nubie from Indonesia -
Aug 06 2012, 8:44 AMReport Spam
anyone can help me to answer this drag and drop question??i really appreciate your help guys,thx
-Guest VLAN
-Restricted VLAN
-MAB
-WEB auth
——————————
-this method is used when clients dont support the 802.1x supplicant but need to be authenticated to an 802.1x network
-this solution is used when users fail authentication and have an 802.1x – compliant device
-this method offers limited access for users without an 802.1x client. by default, it takes 90 seconds for the machine to get assigned to this specific VLAN
-Clients that use this method can be reauthenticated. if reauthentication fails, then the switch can assign the port to the guest VLAN if its not configured
Mohammed from Yemen -
Aug 02 2012, 1:30 PMReport Spam
passed today 898, still valid. thanks
Emma from United States -
Aug 01 2012, 12:03 AMReport Spam
I managed to pass today. My score Scored was 827. Guys nt sure why the command #inspect is not accepted after issuing # class type inspect HTTP_POLICY
Pls can any one tell me why
I also tried
Class Class-default as Muhha suggested not accepted too. I think i got 78% on the Lab though.
Thanks to you guys....all the way to CCIE
Luigi Gagarin from Brazil -
Jul 30 2012, 4:23 PMReport Spam
PASSED!!!!!!!
Score 837 points. This exam is very stressed. A lot of new D&D and few new questions. The questions have a inverse order but with Neil contend you will pass!! Make shure that you will answer all 122 Neil questions because you will fail.
The lab is the same and the Simlet is the same.
A special thanks for Neil for your correction and a kick on ass to Actualtests that offer a dump with a lot of wrong questions
gerard from Unknown -
Jul 28 2012, 12:49 PMReport Spam
This dump still valid thks to neil. The most stressing exam i wrote 3 news questions and 10 news drag n drop in the exam take in consideration everybody comments below it will helps. Thks to all
Loopback from Germany -
Jul 26 2012, 2:16 PMReport Spam
I have done the exam and the Neil´s dump is still valid.
I received 890 points and it was 9 additional questions in my test.
some of questions have the sequence or wording of answer changed, but the sense is thesame.
I have received 70 questions as well.
If you do your preparation well those 9 questions will not be an issue…
almost all of them are mentioned by colleagues before, like the reason to err-disable or EAP types and how they work..
Pay attention to this information here, below,
do preparation well and every thing will be ok.
thank to every body again for your help and particularly to Neil.
Major Tom from United Kingdom -
Jul 25 2012, 8:39 PMReport Spam
In the real exam's lab it's being requested for dropping all the traffic that left and doesn't match HTTP. Perhaps Neil's figures are still accurate, but muhha's comments make sense for me. Anyhow I am over to VPN now :)
Mr.Security from United States -
Jul 25 2012, 3:16 PMReport Spam
I would configure the SIM exactly what they ask for. There's nothing in the objects about configure "default class". It's your test so do whatever you like.
The SIM is always the same and if you look back to Neil's dump there is an 989 score using the same configuration for the SIM. Just my two cents. Good luck!
Major Tom from United States -
Jul 25 2012, 10:38 AMReport Spam
Guys, the sim was the same as in dump: creation of the zone-based firewall. Not sure if I made it correctly. Watch out the policy-map creation, don't confuse "match-any" and "match-all". I guess I screwed it up there. Also please notice the muhha's post for the default class - it sounds he is right.
For about "?" mark - I believe it worked for me.
Anyhow, even though I ruined the lab (assumption) and possible a few new drag-n-drop questions, I still passed with 847. The passing score was 774 which is pretty relaxing and number of questions was 70. Just make sure you've done everything else correctly besides sim.
gerard from Benin -
Jul 25 2012, 8:19 AMReport Spam
Major Tom can you tell us about the sim you done on your exam i'll be writing this friday need your feedback pls
NUK from United Kingdom -
Jul 24 2012, 9:41 PMReport Spam
Major Tom, what sim did you get in the exam? Is it possible to use the ? after typing part of a relevant command?
Major Tom from United Kingdom -
Jul 24 2012, 6:50 PMReport Spam
The dump is valid. Passed today with 847 score. It was stressing. Loads of drag-n-drops plus some new questions as suggested below. Most of the answers in the questions are shuffled! Watch what you click!
muhha from Bosnia and Herzegovina -
Jul 23 2012, 5:48 PMReport Spam
Hi All,
I need help with one of LABs from Neils Dump and I am thinking that Neil missed class class-default command in his configuration.In LAB was requested to match HTTP and drop all other traffic …..Can you please review my configuration its down below, Thanks a lot!!!
LAB:
Note that when performing the configuration, you should use the exact names highlighted in bold below:
- Globally create zones and label them with the following names:
– OUTSIDE
– INSIDE
- Assign interfaces to zones as indicated in the exhibit
- Create a zone pair for traffic flowing from the inside to outside zones named IN-TO-OUT
- Define a zone-based firewall policy named IN-TO-OUT-POLICY
– Use the “match protocol” classification option to statefully inspect HTTP traffic and drop all other traffic
– Use a class-map named HTTP_POLICY
- Apply zone-based firewall policy IN-TO-OUT-POLICY to the zone pair
*** Globally created zones ***
zone security OUTSIDE
exit
zone security INSIDE
exit
*** Assigning zones to the interfaces ***
int fa0/0/0
no shut
zone-member security OUTSIDE
exit
int fa0/0/1
no shut
zone-member security INSIDE
exit
*** Created policy ***
class-map type inspect match-any HTTP_POLICY
match protocol http
exit
policy-map type inspect IN-TO-OUT-POLICY
class type inspect HTTP_POLICY
inspect
class class-default *** This is what I added ***
drop
exit
*** Created zone pair, applied policy. ***
zone-pair security IN-TO-OUT source INSIDE destination OUTSIDE
service-policy type inspect IN-TO-OUT-POLICY
end
copy run start
vhv from Vietnam -
Jul 23 2012, 9:24 AMReport Spam
This dump is valid. I had passed with 857/1000 point. This exam have 8-9 new questions. Some new questions are same Alexis's post.
Major Tom from United Kingdom -
Jul 21 2012, 3:39 PMReport Spam
Derly_Ali, I believe everyone here would appreciate if you could mention those 4 questions with different values... Cheers mate.
NetworkSupaStar from United States -
Jul 21 2012, 12:24 PMReport Spam
Are there any sites similar to networktut for ccnp tshoot for Security ? Any help sites or downloadable labs for CCNP Security track ?
Security from India -
Jul 21 2012, 2:57 AMReport Spam
@derly_ali : Congrats..... so do u remember those 4 questons ?
n abt d 8 questions, hav u chckd wid the othr dump [muhha], was der ny question frm tat......
n were those 8 question D&D or MCQ
Plzzz reply, I'll be writing xam within few days........
n abt d labs, was it same as in this dump.....
nywy congrats once again 4 passing d xam n thnx in advance.......
derly_ali from Mexico -
Jul 20 2012, 8:14 PMReport Spam
Very stressed but i pass with a 878 score; 8 different questions and 4 of the dump with another values.
Need a beer...
BananaRepublic from United States -
Jul 20 2012, 1:25 PMReport Spam
Certainly the longest certification exam ever taken.Dump is valid for the most part
Alexis from Europe -
Jul 19 2012, 1:18 PMReport Spam
I don't think neither autocomplete nor the question mark were supported (usually they are not), however thanks to Neil I didn't feel this time the need to use them ;-)
Loopback from Germany -
Jul 19 2012, 11:27 AMReport Spam
@Alexis:
Thank you for your feedback.
just one other question regarding the exam.
does the autocompete works on the CLI on the simlet in the exam or not?
if the question mark is supported on the CLI of the simlet during the exam?
Thank you!
Alexis from Europe -
Jul 19 2012, 11:00 AMReport Spam
Hi @Loopback, you are right. According to Cisco all these are possible causes for a port to go err-dissabled
Duplex mismatch
Port channel misconfiguration
BPDU guard violation
UniDirectional Link Detection (UDLD) condition
Late-collision detection
Link-flap detection
Security violation
Port Aggregation Protocol (PAgP) flap
Layer 2 Tunneling Protocol (L2TP) guard
DHCP snooping rate-limit
Incorrect GBIC / Small Form-Factor Pluggable (SFP) module or cable
Address Resolution Protocol (ARP) inspection
Inline power
So it may be the specific wording, maybe of the "inline" thing.
BTW, there was one more question I just remembered, it was to match most of these EAP types to its definitions and/or some particular feature of each
■ EAP-MD5
■ PEAPv0-MSCHAPv2
■ LEAP
■ EAP-TLS
■ EAP-TTLS
■ EAP-FAST
Sorry gents. My memory just goes this far :-)
Loopback from Germany -
Jul 19 2012, 10:24 AMReport Spam
@Alexis:
regarding this question posted:
Which of the folling causes a port to go into error disabled status?
BPDU guard violation
inline power disabled, devide req pow
speed mismatch
dhcp snooping rate limit
port channel misconf
as far as I see, all of them are the possible reasons for err-disable state, or?
Alexis from Europe -
Jul 19 2012, 7:17 AMReport Spam
Hi Mr Security, I'd say most of them are in Neil's dump, as for the new ones I have transcribed below some of them as far as I can recall them. There were a couple more about policy based NAT and dhcp snooping.
God bless you all && thanks very much again, Neil
____
Which of the folling causes a port to go into error disabled status?
BPDU guard violation
inline power disabled, devide req pow
speed mismatch
dhcp snooping rate limit
port channel misconf
_____
Which of the following belong to the data plane?
traffic filtering
transport protection
traffic conditioning
protection against attacks
RBAC
routing protocol authentication
_____
Match (not all needed)
1.- when this expires, the net id is no longer valid
2.- this needs to be the same for all mgre tunnels in the network
3.- this is used for NMBA networks
4.- this is used by DMVPN tunnel hubs and spokes to authenticate themselves
A.- tunnel key
B.- nhrp hold time
C.- nhrp nhs
D.- nhrp registration
E.- nhrp net id
F.- nhrp autthentication string
______
who uses PHDF?
Multiple options, one was FPM, which I think was the right one
______
Match 802.1x port states definitions
1.- Forced-Authorized
2.- Forced-Unauthorized
3.- Auto
A.- In this state, 802.1x is disabled on the port. All traffic is allowed as normal without restriction. This is the default port state when 802.1x is not globally enabled.
B.- In this mode, the port begins in the unauthorized state and allows only EAPOL, CDP, and STP traffic. After the supplicant is authenticated, the port transitions to the authorized state and normal traffic is allowed.
C.- In this state, the port ignores all traffic, including any attempts to authenticate.
Mr Security from India -
Jul 18 2012, 4:41 AMReport Spam
@Alexis : thnx 4 d information.
n abt the D&D questions, were all of them new or also frm the dumps ?
Alexis from Spain -
Jul 17 2012, 9:34 PMReport Spam
Hi Mr Security, both sim and lab were the same, however the output of the "shows" in the GDOI thing is rather different than that of Neil's (I think he mentions this anyway). In any case I went with Neil's and I passed. So, like the other Mr. Security wrote "Just study this guide well and practice the sim and lab many many times"
Again, thanks Neil && Good Luck to everybody.
dragito from United States -
Jul 17 2012, 6:00 PMReport Spam
Part 3:
5. When configuring URL filtering with the Trend Micro filtering service. Which of these steps must you take to prepare for configuration?
a. Define blacklists and whitelists
b. Categorize traffic types
c. Synchronize clocks via NTP to ensure accuracy of URL filter updates from the service
d. Install the appropriate root CA certificate on the router
Answer on Chips = D
Answer on Neil = B
6. Which of these correct regarding the functionally of DVTI tunnels?
a. DVTI tunnels are created dynamically from a preconfigured template as tunnels are established to the hub
b. DVTI tunnels appear on the hub as tunnel interfaces
c. The hub router needs a static DVTI tunnel to each spoke router in order to establish remote communications from spoke to spoke
d. Spoke router require a virtual template to clone the configuration on which the DVTI tunnel is established
Answer on Chips = D
Answer on Neil = A
7. When implementing GET VPN, which of these is a characteristic of GDOI IKE?
a. GDOI IKE sessions are established between all peers in the network
b. GDOI IKE uses UDP port 500
c. Security associations do not need to linger between members once a group member has authenticated to the key server and obtained the group policy
d. Each pair of peers has a private set of IPsec security associations that is only shared between the two peers
Answer on Chips = D
Answer on Neil = C
dragito from United States -
Jul 17 2012, 5:58 PMReport Spam
Part 2:
3. Refer to the exhibit. Given the output shown, what can be determined?
%SW_DAI-4-ACL_DENY: 1 Invalid ARPs (Req) on Fa1/1, vlan 200. ([0001.ba21.321c/192.168.1.10/0000.0000.0000/192.168.1.20/12:32:18 UTC Mon Sep 20 2010])
a. An attacker has sent a spoofed DHCP address.
b. An attacker has sent a spoofed ARP response that violates a static mapping.
c. The MAC address has matched a deny rule within the ACL.
d. This is an invalid proxy ARP packet, as indicated by the 0000.0000.0000 MAC address on the destination
Answer on Chips = C. The MAC address has matched a deny rule within the ACL.
Answer on Neil = B. An attacker has sent a spoofed ARP response that violates a static mapping.
4. You have configured Management Plane Protection on an interface on a Cisco router. What is the resulting action on implementing MPP?
a. Inspection of protected management interfaces is automatically configured to ensure that management protocols comply with standards.
b. The router gives preference to the configured management interface. If that interface becomes unavailable, management protocols will be allowed on alternate interfaces.
c. Along with normal user data traffic, management traffic is also allowed only on the protected interface.
d. Only management protocols are allowed on the protected interface.
Answer on Chips = C. Along with normal user data traffic, management traffic is also allowed only on the protected interface.
Answer on Neil = D. Only management protocols are allowed on the protected interface.
dragito from United States -
Jul 17 2012, 5:57 PMReport Spam
Need your feedback on these questions on Neil and Chips Dump:
1. Refer to the exhibit. The INSIDE zone has been configured and assigned to two separate router interfaces. All other zones and interfaces have been properly configured. Given the configuration example shown, what can be determined.
a. Hosts in the INSIDE zone, with addresses in the 10.10.10.0/24 network, can access any host in the 10.10.10.0/24 network using the SSH protocol.
b. If a host in the INSIDE zone attempts to communicate via SSH with another host on a different interface within the INSIDE zone, communications must pass through the router self zone using the INTRAZONE policy.
c. This is an illegal configuration. You cannot have the same source and destination zones.
d. This policy configuration is not needed, traffic within the same zone is allowed to pass by default.
Answer on Chips = C. This is an illegal configuration. You cannot have the same source and destination zones.
Answer on Neil = B. If a host in the INSIDE zone attempts to communicate via SSH with another host on a different interface within the INSIDE zone, communications must pass through the router self zone using the INTRAZONE policy.
2. When using Cisco Easy VPN, what are the three options for entering an XAUTH username and password for establishing a VPN connection from the Cisco Easy VPN remote router? (Choose three.)
a. using an external AAA server
b. entering the information via the router crypto ipsec client ezvpn connect CLI command in privileged EXEC mode
c. using the router local user database
d. entering the information from the PC via a browser
e. storing the XAUTH credentials in the router configuration file
Answer on Chips = B,C,E
Answer on Neil = B,D,E
Mr Security from India -
Jul 17 2012, 1:26 PMReport Spam
@Alexis : Was the lab and simlet same as in the dump ?
Plz tell me bcoz i'll be taking xam nxt week.
Is this dump still valid ?
Alexis from Europe -
Jul 16 2012, 8:48 AMReport Spam
Hi all, just passed with 840, thanks Neil and eveybody here for your great input.
BTW, bought Pass4Sure and flunked first attempt with 750, as of today Pass4sure and Actualtest have the same 122qs, plus quite a few wrong answers and none of the new questions mentioned here... Rely on Neil's.
Gibran from United States -
Jul 13 2012, 1:05 PMReport Spam
Just passed teh 642-637 with score 847..Dump is still valid, a few new D&D questions..Study 802.1x, DHCP snooping, Control Plane..I missed probably 4 D&D questions..Also on the simlet, do not memorize the question order from the dump, they're switched around on the exam..Study the dump and guide, and passing will be a breeze
Neo4c from South Africa -
Jul 12 2012, 11:10 AMReport Spam
Passed, now for the last one. neil's dumps is still valid. Had a few new questions. Good luck to all. Definitely the most difficult one of all ! Study hard.
Neo4c from South Africa -
Jul 12 2012, 7:13 AMReport Spam
I am going to write 642-637 today !
Randeep from India -
Jul 09 2012, 12:24 PMReport Spam
Thanks to all.
Passed the exam today with 880, neil's 122qs dump is still valid with 7-8 new questions.As discussed all the new questions is from
1. control plane and data plane functionality for switch and router
2. Eap types and their working
3. 802.1X port status and design strategy (auto, force-authorized, host multi-domain etc.)
4. DHCP snooping design plan
5. NHRP client and server (NHS, NHRP network ID, registration spoke, NBMA etc.)
6.How will interface changes to error-disable
If you cover these 6 topics along with 122qs dump you can surely get more than 950 in this exam.
Randeep from India -
Jul 09 2012, 12:19 PMReport Spam
Thanks Mr.Security :-)
Mr.Security from United States -
Jul 07 2012, 10:58 PMReport Spam
Just study this guide well and practice the sim and lab many many times. You'll still passed if you miss all new drag/drops questions. Honestly I believes I missed all of them. HAHAHAHA.
Randeep from India -
Jul 07 2012, 4:02 AMReport Spam
@Mr Security,
Any suggestions for the exam,i am going to attend the exam on Monday (9th July).
Mr.Security from United States -
Jul 06 2012, 10:19 PMReport Spam
I passed last week with a 8XX. Don't think I got any of the new drag/drop questions right but still passed with 8XX. This guide is still valid.
kidwitgame from Kenya -
Jul 05 2012, 9:22 AMReport Spam
There is a question somewhere in the dump that asks what transport GET VPN peers use to exchange keys.The answer given in the dump is:
a)Unicast UDP transmission
b)Multicast UDP transmission
However, when reading through the e-book, i came across the following:
Unicast Versus Multicast Rekeying Methods
Unicast
-Might require adjustment of router buffers and queues
if there are a large number of peers
-Use if infrastructure is only unicast capable
*Requires rekey acknowledgment
Multicast
-Must have multicast-capable infrastructure
-Requires rekey acknowledgment Retransmits the key several times
without acknowledgments
-Fastest and most scalable method
The fact that Unicast key transmission requires acknowledgement means that TCP must be the preferred protocol used for Unicast transmission of keys.Somebody correct me if i am wrong
Randeep from India -
Jul 05 2012, 8:06 AMReport Spam
Please help me to answer the question.
1.You are troubleshooting an IPsec VPN problem. During debugging of IPsec operations, you see the message “attributes not acceptable” on the IKE responder after issuing the debug crypto isakmp command. Which step should you take next?
A. verify matching ISAKMP policies on each peer
B. verify that an IKE security association has been established between peers
C. verify that IPsec transform sets match on each peer
D. verify if default IPsec attributes are in place on each peer
2. virtual-access1 unassigned yes unset down down
virtual-access2 192.168.1.1 yes unset up up
When you are using dynamic IPsec VTI tunnels, what can you determine about virtual-access interfaces from the output shown?
A.The Virtual-Access1 interface currently does not have an IPsec peer connection established.
B.The Virtual-Access2 interface does not yet have an IPsec peer defined.
C.The Virtual-Access1 interface is in the down/down state, because the virtual tunnel source physical interface is down.
D.The Virtual-Access1 interface, which is used internally by the Cisco IOS software, is always down.
Randeep from India -
Jul 05 2012, 6:08 AMReport Spam
Thanks shahrian.
I'm planning to take the exam by 7th July, If you guys have any updated dumps,Please share it or mail me @ Zeusrandeep@gmail.com
naksi from United States -
Jul 04 2012, 1:13 PMReport Spam
@Ahmed
there is no way around studying, if you study hard you should have a change...
1. skim the book (only read pages you dont understand by skimming)
2. watch the CBT nuggets and replicate the labs to get the commands in your head
3. take some practise tests like this one, and mere than once
Ahmed from Saudi Arabia -
Jul 03 2012, 1:46 PMReport Spam
HI all,
I have to take the exam at the end of this month but i didn't start studying yet, i have the Cisco press but it is very big and my time is limited because of work.
can any one advice what to do?
thanks
shahrian from Denmark -
Jul 03 2012, 9:04 AMReport Spam
@ Randeep
checking the correct timing is being used is the most accurate, when dealing with CA on cisco routers you should use NTP or hardware clock
if the IOS can't find any NTP the server will not start then you should use hardware clock instead ie: Router# clock set hh:mm:ss day month year
& if you already correctly configured Ca server it should be enabled automatically.
ahmed elfeki from Egypt -
Jul 02 2012, 8:49 PMReport Spam
I have passed the exam 4 days ago but there about 15 new quetions and they are all in the drag and drop
Randeep from India -
Jul 02 2012, 4:12 PMReport Spam
Please help me to answer the question
You have configured a Cisco router to act a PKI certificate server. However,you are experiencing problems starting the server. You have verified that al CA parameters have been correctly configured. What is the next step you should take in troubleshooting this problem?
A. Disable and restart the router’s HTTP server function
B. Verify the RSA key pair and generate new keys
C. Verify that correct time is being used and source are reachable
D. Enable the SCEP interface
Ran_Rising from India -
Jun 29 2012, 11:05 AMReport Spam
Please let me know the correct answer of this question.
1.Refer to the exhibit. The INSIDE zone has been configured and assigned to two separate router interfaces. All other zones and interfaces have been properly configured. Given the configuration example shown, what can be determined.
A.
Hosts in the INSIDE zone, with addresses in the 10.10.10.0/24 network, can access any host in the 10.10.10.0/24 network using the SSH protocol.
B.
If a host in the INSIDE zone attempts to communicate via SSH with another host on a different interface within the INSIDE zone, communications must pass through the router self zone using the INTRAZONE policy.
C.
This is an illegal configuration. You cannot have the same source and destination zones.
D.
This policy configuration is notneeded, traffic within the same zone is allowed to pass by default.
sandrine from Indian from India -
Jun 28 2012, 2:53 PMReport Spam
This is vaild. I pass my exam yesterday and 13 or 15 new question .................... thx
donkey from United Kingdom -
Jun 26 2012, 7:59 PMReport Spam
Hi Guys, Can any one remember new questions?? Planing to take exam..
Crazy from India -
Jun 25 2012, 11:31 AMReport Spam
Can anyone elaborate what is DHCP snooping design plan ?
bfreeze from Switzerland -
Jun 24 2012, 12:30 PMReport Spam
Just passed , I got totally about 10/12 new questions and drag and drop , some questions were changed a bit , I remember that D&D about dmvpn and nhrp was ...confused , anyway I scored over 950 .
Thanks to all
cheers
bfreeze
Nageeb Elsousy from Unknown -
Jun 24 2012, 11:55 AMReport Spam
I Passed with 898 , i got around 10 new questions as everybody said.
and they are the same
1. control plane and data plane functionality for switch and router
2. Eap types and their working
3. 802.1X port status and design strategy (auto, force-authorized, host multi-domain etc.)
4. DHCP snooping design plan
5. NHRP client and server (NHS, NHRP network ID, registration spoke, NBMA etc.)
6.drag and drop - when the interface changes to error-disable
thanks for your contributions
Nageeb Elsousy from Unknown -
Jun 24 2012, 7:54 AMReport Spam
i'm going for the exam in an hour and i'll tell you once i finish :S
Gibran from United States -
Jun 21 2012, 3:29 PMReport Spam
Can someone tell me how many sims are on the exam?? I'm scheduled to take it next month..Thanks
shoneo from Serbia -
Jun 21 2012, 10:47 AMReport Spam
To Mr.Security
I think that most important chapters (for new questions) which you need to read from book are:
- Control plane and data plane functionality for switch and router
- Eap types and their working
- 802.1X port status and design strategy
- DHCP snooping design plan
I've got 857 points and I wasn't sure that I've got correct answers for 5 new questions (mostly drag&drop). Minimum for passing is 776.
I hope It will help you.
Mr.Security from United States -
Jun 21 2012, 12:56 AMReport Spam
To Shoneo,
What did you scored and what chapters did you focus reading on? I thinking about taking this in a few weeks. Thanks!
shoneo from Serbia -
Jun 19 2012, 10:57 AMReport Spam
Yesterday I have passed the exam. This dump is still valid with 7-8 new questions.
##################
@Badorka directed at right target about new questions:
1. control plane and data plane functionality for switch and router
2. Eap types and their working
3. 802.1X port status and design strategy (auto, force-authorized, host multi-domain etc.)
4. DHCP snooping design plan
5. NHRP client and server (NHS, NHRP network ID, registration spoke, NBMA etc.)
6.drag and drop - when the interface changes to error-disable
Drag and drop with 802.1x, nhrp and dhcp snooping and how working types of eap. We must attention and read exactly a question.
##################
Tnx to @Mr.Security for answer.
Mario from Germany -
Jun 19 2012, 10:27 AMReport Spam
There are about 10 new questions(most of them d&d), dhcp starvation, dhcp snooping, a few about eap and dot1x but with this dump you will pass anyway. Passed today 06.19.2012
Mr.Security from United States -
Jun 19 2012, 1:02 AMReport Spam
To shoneo:
The answer to this question is easy. If you read the question carefully, it stated "You have verified that all CA parameters have been correctly configured".
For CA to work you have to enable SCEP interface and since the configurations have been confirmed correct, you don't need to enable SCEP interface again. Make sense?
Second the question asked for troubleshooting steps so the best answer is:
Verify that correct time is being used and source are reachable.
Daemain guide is correct for this question. I hope this helps.
Mariam from United Kingdom -
Jun 13 2012, 11:22 AMReport Spam
Thanks Guys,
today i have passed the exam. this dump is valid
mnone from Unknown -
Jun 11 2012, 6:23 PMReport Spam
can you please know. if it possible to write exam with out lab
badorka from Poland -
Jun 11 2012, 1:09 PMReport Spam
I passed my exam today (11.06.2012). We must studying below topic:
1. control plane and data plane functionality for switch and router
2. Eap types and their working
3. 802.1X port status and design strategy (auto, force-authorized, host multi-domain etc.)
4. DHCP snooping design plan
5. NHRP client and server (NHS, NHRP network ID, registration spoke, NBMA etc.)
6.drag and drop - when the interface changes to error-disable
I have a question drag and drop with 802.1x, nhrp and dhcp snooping and how working types of eap. We must attention and read exactly a question.
shoneo from Serbia -
Jun 11 2012, 8:50 AMReport Spam
What is correct answer for this question?
You have configured a Cisco router to act a PKI certificate server. However, you are experiencing problems starting the server. You have verified that all CA parameters have been correctly configured. What is the next step you should take in troubleshooting this problem?
Enable the SCEP interface or Verify that correct time is being used and source are reachable?
Troubleshooting Flow
In the event of problems with the Cisco IOS Software PKI Client not enrolling, follow these steps to troubleshoot the issue:
Step 1. Verify the reachability between the PKI client and the CA server using standard connectivity testing methods. Also, ensure that the SCEP server is functioning by running the debug crypto pki transactions command.
Step 2. Verify that the time on the PKI client is set properly. Incorrect time can cause devices to reject certificates.
Willy from Unknown -
Jun 10 2012, 8:40 PMReport Spam
Just passed with nearly a 900, still valid. There were about 5 new questions on my exam (some dotx and eap questions).
gerard from Germany -
Jun 10 2012, 7:55 PMReport Spam
helloo guys there is any can helps for exam 642-637 lab i'm getting ready to write it at the end of this month. my addresss ageruid@gmail.com
nico from United States -
Jun 09 2012, 4:39 PMReport Spam
@bfreeze thank you very much for your little advice. I want to encourage you guys to read everything in this dump expecially your lab word for word and configure your lab to work, you will definately pass with a range of 850-870. if your configuration works with the lab.Thanks neil for your dump.
Ayman from Egypt -
Jun 06 2012, 11:01 PMReport Spam
Dears, i got 827 score . and as i told you before the new drag and drop questions was related to Dot1X authentications and transmitting protocols PEAP and EAP.
Muhammad Iqbal Afridi from United Kingdom -
Jun 06 2012, 4:21 AMReport Spam
can anybody upload that 8 to 10 new question please i am going to set in exam end of this month
unknown from United States -
Jun 05 2012, 9:57 PMReport Spam
All questions the same as in the dump but 8-10 new drag and drop questions. I passed today, so the dump is still valid.
@Ayman
Can you pls give some details about the new Drag and Drop questions
mmm from Macedonia -
Jun 05 2012, 12:03 AMReport Spam
Hi Guys,
is there any update on this document since many of you mentioned that there are new questions. I planned to take exam this week but probably will cancel it for now.
10 new questions are too many, I think. Please update it if possible.
Thank's in advance,
cisco from Egypt -
Jun 04 2012, 9:38 PMReport Spam
Hi Ayman , could u please tell me what is the score that u get .
Ayman from Egypt -
Jun 04 2012, 8:58 PMReport Spam
Dears, i passed today, the dump is mostly valid but there is about 8 new drag and drop questions related to DOT1X authentication and DTVPN.
John from United States -
Jun 04 2012, 1:36 PMReport Spam
Hi zoro, thank you very much for the CTB Nugget works great! Awesome! :-)
bfreeze from Italy -
Jun 02 2012, 6:11 PMReport Spam
sorry , I misunderstood :( (:
but if you typed
R1>en
R1#conf t
R1(config)#zone security inside
seems you did alright ......
nico from United States -
Jun 02 2012, 5:24 PMReport Spam
@bfreeze that is what i got from the examination center. I have failed twice because the console is not working for me
bfreeze from Italy -
Jun 02 2012, 5:09 PMReport Spam
@nico
seems ur IOS doesn't support ZBPF....what are u using ?
nico from United States -
Jun 02 2012, 3:57 PMReport Spam
Can somebody explain to me how to configure the lab. I open the console and it gave R1> then i try to write R1>Router(config)# zone security INSIDE, but it is saying unknown command. Can somebody who have passed it explain it to me so that when i go back to write, i will be able to pass
Emma from United States -
Jun 02 2012, 12:47 AMReport Spam
Zoro can you help me too with cbt nuggets? dis is my last paper for ccnp sec. mknmkn08@gmail.com....thanks man
zoro from Netherlands -
Jun 02 2012, 12:38 AMReport Spam
copy & past the link. The like willl expire on 16 june. Hope it help
zoro from Netherlands -
Jun 02 2012, 12:36 AMReport Spam
got it from torrent but the link is not working any more. I use https://www.wetransfer.com/ to transfer large files. Try this
https://www.wetransfer.com/dl/o1I0yDon/95930dbab10d2b908a0df9b1b91ae7bbe5a82946e3dd49f506f16fa87ec66849f3c8fe8d3b35ca0
jose carlos from Peru -
Jun 01 2012, 4:53 PMReport Spam
@zoro can you share links to CBT nuggets that we can use for CCNP Security? (SECURE, FIREWALL, etc), or since firewall and vpn have changed there are no cbt available??...thanks!
zoro from Netherlands -
May 31 2012, 9:09 AMReport Spam
ur mail please, I will send you the SECURE nugget
boloc from United Kingdom -
May 29 2012, 9:49 PMReport Spam
Hi, was just looking for a CBT nuggets for SECURE - anyone has a link?
Cheers,
nubie from Indonesia -
May 29 2012, 6:17 AMReport Spam
dear all, is there anyone can update and share the new D&D questions??thx
Sam from Germany -
May 29 2012, 4:25 AMReport Spam
Hi,
I passed my exam yesterday , a few new questions but the dump from neil is still valid. questions I can remember are DHCP snooping implementation, there was a drag and drop on EAP types, another one for reasons for error disable.
Dragan from Macedonia -
May 28 2012, 6:29 PMReport Spam
Pass today with 817. A lot of new drag & drop from 802.1X and all answers order are mixed up. so you need to learn correct answers very well.
Mariam from United Kingdom -
May 28 2012, 11:09 AMReport Spam
i have just attempted and failed 685, most of the questions from there. but i didn't prepare my self enough... i think it is all my mistake...
All the simlet and lab, question are the same, but the answer may be not like exactly from the vce.
My score 878 after 30 mintues.
Thanks all, special thanks to Neil.
@sashans - jesi izlazio na ispit? Vrijedi li ovaj vce?
the class-default drop command is not necessery in the ZBFW sim,i think.
look at this
Configuring Zone-Based Policy Firewall Policy-Maps
The policy-map applies firewall policy actions to one or more class-maps to define the service-policy that will be applied to a security zone-pair. When an inspect-type policy-map is created, a default class named class class-default is applied at the end of the class. The class class-default’s default policy action is drop, but can be changed to pass. The log option can be added with the drop action. Inspect cannot be applied on class class-default.
sorurce: http://www.cisco.com/en/US/products/sw/secursw/ps1018/products_tech_note09186a00808bc994.shtml
pozz iz srbije :)
thanks,
Passed today with 860 dump still valid...
Thanks for your great work man.
I passed yesterday the exam. It was about 10 new Drag & Drop but those questions are similar to those in neils dump. Thanks to all of you for your contribution!
@nubie this is how I answered yesterday this Drag & Drop question, I hope this is helpful I would suggest to go thru Cisco Press Book you have all explanations there.
- MAB
-this method is used when clients dont support the 802.1x supplicant but need to be authenticated to an 802.1x network
- Restricted VLAN
-this solution is used when users fail authentication and have an 802.1x – compliant device
- Guest VLAN
-this method offers limited access for users without an 802.1x client. by default, it takes 90 seconds for the machine to get assigned to this specific VLAN
- WEB auth
-Clients that use this method can be reauthenticated. if reauthentication fails, then the switch can assign the port to the guest VLAN if its not configured
MAB -this method is used when clients dont support the 802.1x supplicant but need to be authenticated to an 802.1x network
Restricted VLAN -this solution is used when users fail authentication and have an 802.1x – compliant device
Guest VLAN - -this method offers limited access for users without an 802.1x client. by default, it takes 90 seconds for the machine to get assigned to this specific VLAN
WEB auth Clients that use this method can be reauthenticated. if reauthentication fails, then the switch can assign the port to the guest VLAN if its not configured
-Guest VLAN
-Restricted VLAN
-MAB
-WEB auth
——————————
-this method is used when clients dont support the 802.1x supplicant but need to be authenticated to an 802.1x network
-this solution is used when users fail authentication and have an 802.1x – compliant device
-this method offers limited access for users without an 802.1x client. by default, it takes 90 seconds for the machine to get assigned to this specific VLAN
-Clients that use this method can be reauthenticated. if reauthentication fails, then the switch can assign the port to the guest VLAN if its not configured
Pls can any one tell me why
I also tried
Class Class-default as Muhha suggested not accepted too. I think i got 78% on the Lab though.
Thanks to you guys....all the way to CCIE
Score 837 points. This exam is very stressed. A lot of new D&D and few new questions. The questions have a inverse order but with Neil contend you will pass!! Make shure that you will answer all 122 Neil questions because you will fail.
The lab is the same and the Simlet is the same.
A special thanks for Neil for your correction and a kick on ass to Actualtests that offer a dump with a lot of wrong questions
I received 890 points and it was 9 additional questions in my test.
some of questions have the sequence or wording of answer changed, but the sense is thesame.
I have received 70 questions as well.
If you do your preparation well those 9 questions will not be an issue…
almost all of them are mentioned by colleagues before, like the reason to err-disable or EAP types and how they work..
Pay attention to this information here, below,
do preparation well and every thing will be ok.
thank to every body again for your help and particularly to Neil.
The SIM is always the same and if you look back to Neil's dump there is an 989 score using the same configuration for the SIM. Just my two cents. Good luck!
For about "?" mark - I believe it worked for me.
Anyhow, even though I ruined the lab (assumption) and possible a few new drag-n-drop questions, I still passed with 847. The passing score was 774 which is pretty relaxing and number of questions was 70. Just make sure you've done everything else correctly besides sim.
I need help with one of LABs from Neils Dump and I am thinking that Neil missed class class-default command in his configuration.In LAB was requested to match HTTP and drop all other traffic …..Can you please review my configuration its down below, Thanks a lot!!!
LAB:
Note that when performing the configuration, you should use the exact names highlighted in bold below:
- Globally create zones and label them with the following names:
– OUTSIDE
– INSIDE
- Assign interfaces to zones as indicated in the exhibit
- Create a zone pair for traffic flowing from the inside to outside zones named IN-TO-OUT
- Define a zone-based firewall policy named IN-TO-OUT-POLICY
– Use the “match protocol” classification option to statefully inspect HTTP traffic and drop all other traffic
– Use a class-map named HTTP_POLICY
- Apply zone-based firewall policy IN-TO-OUT-POLICY to the zone pair
*** Globally created zones ***
zone security OUTSIDE
exit
zone security INSIDE
exit
*** Assigning zones to the interfaces ***
int fa0/0/0
no shut
zone-member security OUTSIDE
exit
int fa0/0/1
no shut
zone-member security INSIDE
exit
*** Created policy ***
class-map type inspect match-any HTTP_POLICY
match protocol http
exit
policy-map type inspect IN-TO-OUT-POLICY
class type inspect HTTP_POLICY
inspect
class class-default *** This is what I added ***
drop
exit
*** Created zone pair, applied policy. ***
zone-pair security IN-TO-OUT source INSIDE destination OUTSIDE
service-policy type inspect IN-TO-OUT-POLICY
end
copy run start
n abt d 8 questions, hav u chckd wid the othr dump [muhha], was der ny question frm tat......
n were those 8 question D&D or MCQ
Plzzz reply, I'll be writing xam within few days........
n abt d labs, was it same as in this dump.....
nywy congrats once again 4 passing d xam n thnx in advance.......
Need a beer...
Thank you for your feedback.
just one other question regarding the exam.
does the autocompete works on the CLI on the simlet in the exam or not?
if the question mark is supported on the CLI of the simlet during the exam?
Thank you!
Duplex mismatch
Port channel misconfiguration
BPDU guard violation
UniDirectional Link Detection (UDLD) condition
Late-collision detection
Link-flap detection
Security violation
Port Aggregation Protocol (PAgP) flap
Layer 2 Tunneling Protocol (L2TP) guard
DHCP snooping rate-limit
Incorrect GBIC / Small Form-Factor Pluggable (SFP) module or cable
Address Resolution Protocol (ARP) inspection
Inline power
http://www.cisco.com/en/US/tech/tk389/tk621/technologies_tech_note09186a00806cd87b.shtml
So it may be the specific wording, maybe of the "inline" thing.
BTW, there was one more question I just remembered, it was to match most of these EAP types to its definitions and/or some particular feature of each
■ EAP-MD5
■ PEAPv0-MSCHAPv2
■ LEAP
■ EAP-TLS
■ EAP-TTLS
■ EAP-FAST
Sorry gents. My memory just goes this far :-)
regarding this question posted:
Which of the folling causes a port to go into error disabled status?
BPDU guard violation
inline power disabled, devide req pow
speed mismatch
dhcp snooping rate limit
port channel misconf
as far as I see, all of them are the possible reasons for err-disable state, or?
God bless you all && thanks very much again, Neil
____
Which of the folling causes a port to go into error disabled status?
BPDU guard violation
inline power disabled, devide req pow
speed mismatch
dhcp snooping rate limit
port channel misconf
_____
Which of the following belong to the data plane?
traffic filtering
transport protection
traffic conditioning
protection against attacks
RBAC
routing protocol authentication
_____
Match (not all needed)
1.- when this expires, the net id is no longer valid
2.- this needs to be the same for all mgre tunnels in the network
3.- this is used for NMBA networks
4.- this is used by DMVPN tunnel hubs and spokes to authenticate themselves
A.- tunnel key
B.- nhrp hold time
C.- nhrp nhs
D.- nhrp registration
E.- nhrp net id
F.- nhrp autthentication string
______
who uses PHDF?
Multiple options, one was FPM, which I think was the right one
______
Match 802.1x port states definitions
1.- Forced-Authorized
2.- Forced-Unauthorized
3.- Auto
A.- In this state, 802.1x is disabled on the port. All traffic is allowed as normal without restriction. This is the default port state when 802.1x is not globally enabled.
B.- In this mode, the port begins in the unauthorized state and allows only EAPOL, CDP, and STP traffic. After the supplicant is authenticated, the port transitions to the authorized state and normal traffic is allowed.
C.- In this state, the port ignores all traffic, including any attempts to authenticate.
n abt the D&D questions, were all of them new or also frm the dumps ?
Again, thanks Neil && Good Luck to everybody.
5. When configuring URL filtering with the Trend Micro filtering service. Which of these steps must you take to prepare for configuration?
a. Define blacklists and whitelists
b. Categorize traffic types
c. Synchronize clocks via NTP to ensure accuracy of URL filter updates from the service
d. Install the appropriate root CA certificate on the router
Answer on Chips = D
Answer on Neil = B
6. Which of these correct regarding the functionally of DVTI tunnels?
a. DVTI tunnels are created dynamically from a preconfigured template as tunnels are established to the hub
b. DVTI tunnels appear on the hub as tunnel interfaces
c. The hub router needs a static DVTI tunnel to each spoke router in order to establish remote communications from spoke to spoke
d. Spoke router require a virtual template to clone the configuration on which the DVTI tunnel is established
Answer on Chips = D
Answer on Neil = A
7. When implementing GET VPN, which of these is a characteristic of GDOI IKE?
a. GDOI IKE sessions are established between all peers in the network
b. GDOI IKE uses UDP port 500
c. Security associations do not need to linger between members once a group member has authenticated to the key server and obtained the group policy
d. Each pair of peers has a private set of IPsec security associations that is only shared between the two peers
Answer on Chips = D
Answer on Neil = C
3. Refer to the exhibit. Given the output shown, what can be determined?
%SW_DAI-4-ACL_DENY: 1 Invalid ARPs (Req) on Fa1/1, vlan 200. ([0001.ba21.321c/192.168.1.10/0000.0000.0000/192.168.1.20/12:32:18 UTC Mon Sep 20 2010])
a. An attacker has sent a spoofed DHCP address.
b. An attacker has sent a spoofed ARP response that violates a static mapping.
c. The MAC address has matched a deny rule within the ACL.
d. This is an invalid proxy ARP packet, as indicated by the 0000.0000.0000 MAC address on the destination
Answer on Chips = C. The MAC address has matched a deny rule within the ACL.
Answer on Neil = B. An attacker has sent a spoofed ARP response that violates a static mapping.
4. You have configured Management Plane Protection on an interface on a Cisco router. What is the resulting action on implementing MPP?
a. Inspection of protected management interfaces is automatically configured to ensure that management protocols comply with standards.
b. The router gives preference to the configured management interface. If that interface becomes unavailable, management protocols will be allowed on alternate interfaces.
c. Along with normal user data traffic, management traffic is also allowed only on the protected interface.
d. Only management protocols are allowed on the protected interface.
Answer on Chips = C. Along with normal user data traffic, management traffic is also allowed only on the protected interface.
Answer on Neil = D. Only management protocols are allowed on the protected interface.
1. Refer to the exhibit. The INSIDE zone has been configured and assigned to two separate router interfaces. All other zones and interfaces have been properly configured. Given the configuration example shown, what can be determined.
a. Hosts in the INSIDE zone, with addresses in the 10.10.10.0/24 network, can access any host in the 10.10.10.0/24 network using the SSH protocol.
b. If a host in the INSIDE zone attempts to communicate via SSH with another host on a different interface within the INSIDE zone, communications must pass through the router self zone using the INTRAZONE policy.
c. This is an illegal configuration. You cannot have the same source and destination zones.
d. This policy configuration is not needed, traffic within the same zone is allowed to pass by default.
Answer on Chips = C. This is an illegal configuration. You cannot have the same source and destination zones.
Answer on Neil = B. If a host in the INSIDE zone attempts to communicate via SSH with another host on a different interface within the INSIDE zone, communications must pass through the router self zone using the INTRAZONE policy.
2. When using Cisco Easy VPN, what are the three options for entering an XAUTH username and password for establishing a VPN connection from the Cisco Easy VPN remote router? (Choose three.)
a. using an external AAA server
b. entering the information via the router crypto ipsec client ezvpn connect CLI command in privileged EXEC mode
c. using the router local user database
d. entering the information from the PC via a browser
e. storing the XAUTH credentials in the router configuration file
Answer on Chips = B,C,E
Answer on Neil = B,D,E
Plz tell me bcoz i'll be taking xam nxt week.
Is this dump still valid ?
BTW, bought Pass4Sure and flunked first attempt with 750, as of today Pass4sure and Actualtest have the same 122qs, plus quite a few wrong answers and none of the new questions mentioned here... Rely on Neil's.
Passed the exam today with 880, neil's 122qs dump is still valid with 7-8 new questions.As discussed all the new questions is from
1. control plane and data plane functionality for switch and router
2. Eap types and their working
3. 802.1X port status and design strategy (auto, force-authorized, host multi-domain etc.)
4. DHCP snooping design plan
5. NHRP client and server (NHS, NHRP network ID, registration spoke, NBMA etc.)
6.How will interface changes to error-disable
If you cover these 6 topics along with 122qs dump you can surely get more than 950 in this exam.
Any suggestions for the exam,i am going to attend the exam on Monday (9th July).
a)Unicast UDP transmission
b)Multicast UDP transmission
However, when reading through the e-book, i came across the following:
Unicast Versus Multicast Rekeying Methods
Unicast
-Might require adjustment of router buffers and queues
if there are a large number of peers
-Use if infrastructure is only unicast capable
*Requires rekey acknowledgment
Multicast
-Must have multicast-capable infrastructure
-Requires rekey acknowledgment Retransmits the key several times
without acknowledgments
-Fastest and most scalable method
The fact that Unicast key transmission requires acknowledgement means that TCP must be the preferred protocol used for Unicast transmission of keys.Somebody correct me if i am wrong
1.You are troubleshooting an IPsec VPN problem. During debugging of IPsec operations, you see the message “attributes not acceptable” on the IKE responder after issuing the debug crypto isakmp command. Which step should you take next?
A. verify matching ISAKMP policies on each peer
B. verify that an IKE security association has been established between peers
C. verify that IPsec transform sets match on each peer
D. verify if default IPsec attributes are in place on each peer
2. virtual-access1 unassigned yes unset down down
virtual-access2 192.168.1.1 yes unset up up
When you are using dynamic IPsec VTI tunnels, what can you determine about virtual-access interfaces from the output shown?
A.The Virtual-Access1 interface currently does not have an IPsec peer connection established.
B.The Virtual-Access2 interface does not yet have an IPsec peer defined.
C.The Virtual-Access1 interface is in the down/down state, because the virtual tunnel source physical interface is down.
D.The Virtual-Access1 interface, which is used internally by the Cisco IOS software, is always down.
I'm planning to take the exam by 7th July, If you guys have any updated dumps,Please share it or mail me @ Zeusrandeep@gmail.com
there is no way around studying, if you study hard you should have a change...
1. skim the book (only read pages you dont understand by skimming)
2. watch the CBT nuggets and replicate the labs to get the commands in your head
3. take some practise tests like this one, and mere than once
I have to take the exam at the end of this month but i didn't start studying yet, i have the Cisco press but it is very big and my time is limited because of work.
can any one advice what to do?
thanks
checking the correct timing is being used is the most accurate, when dealing with CA on cisco routers you should use NTP or hardware clock
if the IOS can't find any NTP the server will not start then you should use hardware clock instead ie: Router# clock set hh:mm:ss day month year
& if you already correctly configured Ca server it should be enabled automatically.
You have configured a Cisco router to act a PKI certificate server. However,you are experiencing problems starting the server. You have verified that al CA parameters have been correctly configured. What is the next step you should take in troubleshooting this problem?
A. Disable and restart the router’s HTTP server function
B. Verify the RSA key pair and generate new keys
C. Verify that correct time is being used and source are reachable
D. Enable the SCEP interface
1.Refer to the exhibit. The INSIDE zone has been configured and assigned to two separate router interfaces. All other zones and interfaces have been properly configured. Given the configuration example shown, what can be determined.
A.
Hosts in the INSIDE zone, with addresses in the 10.10.10.0/24 network, can access any host in the 10.10.10.0/24 network using the SSH protocol.
B.
If a host in the INSIDE zone attempts to communicate via SSH with another host on a different interface within the INSIDE zone, communications must pass through the router self zone using the INTRAZONE policy.
C.
This is an illegal configuration. You cannot have the same source and destination zones.
D.
This policy configuration is notneeded, traffic within the same zone is allowed to pass by default.
Thanks to all
cheers
bfreeze
and they are the same
1. control plane and data plane functionality for switch and router
2. Eap types and their working
3. 802.1X port status and design strategy (auto, force-authorized, host multi-domain etc.)
4. DHCP snooping design plan
5. NHRP client and server (NHS, NHRP network ID, registration spoke, NBMA etc.)
6.drag and drop - when the interface changes to error-disable
thanks for your contributions
I think that most important chapters (for new questions) which you need to read from book are:
- Control plane and data plane functionality for switch and router
- Eap types and their working
- 802.1X port status and design strategy
- DHCP snooping design plan
I've got 857 points and I wasn't sure that I've got correct answers for 5 new questions (mostly drag&drop). Minimum for passing is 776.
I hope It will help you.
What did you scored and what chapters did you focus reading on? I thinking about taking this in a few weeks. Thanks!
##################
@Badorka directed at right target about new questions:
1. control plane and data plane functionality for switch and router
2. Eap types and their working
3. 802.1X port status and design strategy (auto, force-authorized, host multi-domain etc.)
4. DHCP snooping design plan
5. NHRP client and server (NHS, NHRP network ID, registration spoke, NBMA etc.)
6.drag and drop - when the interface changes to error-disable
Drag and drop with 802.1x, nhrp and dhcp snooping and how working types of eap. We must attention and read exactly a question.
##################
Tnx to @Mr.Security for answer.
The answer to this question is easy. If you read the question carefully, it stated "You have verified that all CA parameters have been correctly configured".
For CA to work you have to enable SCEP interface and since the configurations have been confirmed correct, you don't need to enable SCEP interface again. Make sense?
Second the question asked for troubleshooting steps so the best answer is:
Verify that correct time is being used and source are reachable.
Daemain guide is correct for this question. I hope this helps.
today i have passed the exam. this dump is valid
1. control plane and data plane functionality for switch and router
2. Eap types and their working
3. 802.1X port status and design strategy (auto, force-authorized, host multi-domain etc.)
4. DHCP snooping design plan
5. NHRP client and server (NHS, NHRP network ID, registration spoke, NBMA etc.)
6.drag and drop - when the interface changes to error-disable
I have a question drag and drop with 802.1x, nhrp and dhcp snooping and how working types of eap. We must attention and read exactly a question.
You have configured a Cisco router to act a PKI certificate server. However, you are experiencing problems starting the server. You have verified that all CA parameters have been correctly configured. What is the next step you should take in troubleshooting this problem?
Enable the SCEP interface or Verify that correct time is being used and source are reachable?
Troubleshooting Flow
In the event of problems with the Cisco IOS Software PKI Client not enrolling, follow these steps to troubleshoot the issue:
Step 1. Verify the reachability between the PKI client and the CA server using standard connectivity testing methods. Also, ensure that the SCEP server is functioning by running the debug crypto pki transactions command.
Step 2. Verify that the time on the PKI client is set properly. Incorrect time can cause devices to reject certificates.
Can you pls give some details about the new Drag and Drop questions
is there any update on this document since many of you mentioned that there are new questions. I planned to take exam this week but probably will cancel it for now.
10 new questions are too many, I think. Please update it if possible.
Thank's in advance,
but if you typed
R1>en
R1#conf t
R1(config)#zone security inside
seems you did alright ......
seems ur IOS doesn't support ZBPF....what are u using ?
https://www.wetransfer.com/dl/o1I0yDon/95930dbab10d2b908a0df9b1b91ae7bbe5a82946e3dd49f506f16fa87ec66849f3c8fe8d3b35ca0
Cheers,
I passed my exam yesterday , a few new questions but the dump from neil is still valid. questions I can remember are DHCP snooping implementation, there was a drag and drop on EAP types, another one for reasons for error disable.