Cisco ASA Express Security Sample Questions:
1. The Cisco ASA software image has been erased from flash memory. Which two statements about the process to recover the Cisco ASA software image are true? (Choose two.)
A) The Cisco ASA appliance must have connectivity to the TFTP server where the Cisco ASA image is stored through the Management 0/0 interface.
B) The server command is necessary to set the TFTP server IP address.
C) The copy tftp flash command is necessary to start the TFTP file transfer.
D) Cisco ASA password recovery must be enabled.
E) Access to the ROM monitor mode is required.
2. In one custom dynamic application, the inside client connects to an outside server using TCP port 4444 and negotiates return client traffic in the port range of 5000 to 5500. The server then starts streaming UDP data to the client on the negotiated port in the specified range. Which Cisco ASA feature or command supports this custom dynamic application?
A) ip verify command
B) tcp-map and tcp-options commands
C) set connection advanced-options command
D) established command
E) TCP normalizer
F) TCP intercept
3. Which statement best describes application recognition on the Cisco ASA NGFW?
A) Application recognition is based on custom signatures based on URL, FQDN, user agent strings in the HTTP stream, and IP addresses and ports.
B) Application recognition is based on PRSM that supports quick filtering capabilities to search for a particular application.
C) Application recognition is based on signatures, heuristics, and content scanning, which removes the need to tie applications to ports.
D) Application recognition is based only on signatures that are constantly updated, which are usually released at a monthly cadence.
4. DRAG DROP
5. When establishing a Cisco AnyConnect SSL VPN tunnel, a system administrator wants to restrict remote home office users to either print to their local printer or send the remaining traffic down the Cisco AnyConnect SSL VPN tunnel (with restricted Internet access).
Choose both a tunnel policy option and an ACL type to accomplish this design goal. (Choose two.)
A) extended ACL
B) standard ACL
C) web ACL
D) exclude network list from the tunnel
E) tunnel all networks
F) tunnel network list below
Solutions:
| Question # 1 Answer: B,E | Question # 2 Answer: D | Question # 3 Answer: C | Question # 4 Answer: Only visible for members | Question # 5 Answer: B,D |
We're so confident of our products that we provide no hassle product exchange.


By Joy

