Thursday, 29 March 2018

Cisco 642-887 Exam Questions

Question: 25

A DSCP value of 41 in decimal corresponds to which IP precedence value?

A. 3 ?Flash
B. 4 ?Flash Override
C. 5 ?Critical
D. 6 ?Internet Control
E. 7 ?Network Control

Answer: C

Sunday, 4 March 2018

Cisco 642-887 Practice Exam Questions

Question: 24

Which two statements are correct in describing ISP environments that are running IP/MPLS in the core network? (Choose two.)

A. On the PE routers, each BGP route must use a unique label to reach the BGP next hop.
B. The BGP next hops point to the PE routers, and only the PE routers are required to run BGP.
C. A full mesh of IBGP sessions are required between all of the PE and P routers to ensure proper packets forwarding.
D. The PE and P routers run LDP to learn the labels for reaching the BGP next-hop addresses.

Answer: BD

Thursday, 1 March 2018

Cisco 642-887 Exam Questions

Question: 23

Which two statements are correct in describing ISP environments that are running IP/MPLS in the core network? (Choose two.)

A. On the PE routers, each BGP route must use a unique label to reach the BGP next hop.
B. The BGP next hops point to the PE routers, and only the PE routers are required to run BGP.
C. A full mesh of IBGP sessions are required between all of the PE and P routers to ensure proper packets forwarding.
D. The PE and P routers run LDP to learn the labels for reaching the BGP next-hop addresses.

Answer: BD

https://testcollection.us/642-887-vce-download.html

Thursday, 1 February 2018

If Your Businesses Uses a Cisco VPN, Patch It Now To Avoid Critical Flaw


  • Cisco has issued a patch for a critical vulnerability in the SSL VPN functionality of the Cisco Adaptive Security Appliance Software.
  • A Cisco VPN bug achieved a CVSS Score of 10 out of 10, and could have affected as many as 200,000 devices.


Cisco is inviting users of its Cisco Adaptive Security Appliance to patch their systems to protect them from a critical VPN vulnerability. In a security advisory, Cisco noted that the failure received a Common Vulnerability Score System (CVSS) score of 10 out of 10, the highest possible score.

cisco news 2018 The vulnerability specifically affects devices that are running the vulnerable version of the device software that also has the webvpn feature enabled, says the notice. In this case, webvpn must be configured globally, but it must also be "an enabled interface via enable <if_name> in the configuration", says the notice. To determine if this is the case in your organization, an administrator must "use the show running-config webvpn command in the CLI and verify that the command returns at least one enable line <if_name>," the notice says.

Obviously, IT administrators in a vulnerable organization must immediately patch their systems. The urgency in the patch is particularly important now, as a security researcher will show how to exploit it next weekend, as reported by Liam Tung of our ZDNet site.

SEE: System Update Policy (Tech Pro Research)

According to the notice, the affected software works on the following systems:

3000 Series Industrial Safety Device (ISA)
ASA 5500 Series Adaptive Security Devices
Next-generation ASA 5500-X Series Firewall
ASA Service Module for Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers
ASA 1000V cloud firewall
Adaptive Security Virtual Appliance (ASAv)
Safety device of the Firepower 2100 series
Safety device Firepower 4110
Firepower 9300 ASA Security Module
Firepower Threat Defense Software (FTD)
Vulnerabilities in this vulnerability occur when an attacker sends specialized XML packages to the interface configured by webvpn. If successful, the exploit "could allow the attacker to execute arbitrary code and take full control of the system, or cause reloading of the affected device," the notice says.

The vulnerability was reported for the first time by Cedric Halbronn of the NCC group, and security researcher Kevin Beaumont posted on Twitter that there could be up to 200,000 affected devices.

If you are thinking about skipping the correction process, do not do it. According to Cisco, there is no other solution known today than just updating the software. Follow the instructions in the notice to determine if the version of your software is vulnerable.

Wednesday, 20 December 2017

Apple and Cisco just improved security in the iOS enterprise

Apple and Cisco have struck yet another blow for big business IT. They realize that iOS is the most secure portable arrangement, however that is not everything in light of the fact that versatile dangers are unfathomably perplexing nowadays.



The puzzle code 

Here's a situation: You work in an endeavor with maybe 1,000 different representatives. One morning, maybe you 50 woke to locate a real appearing email in your in-box that solicitations you tap on a connection to refresh some framework identified with the work you do. While numerous workers recollected not to tap on that connection, a modest number clicked. Nobody thought excessively of the email — spam is visit and most just idea the mail was gone for them.

It wasn't. 

The assault was arranged, and the assailants have now assembled somewhat more insight about a portion of the organization's representatives, including passwords.

This data enables assailants to make sense of secret key structure and maybe empowers them to make another accumulation of endeavors that utilization those stolen subtle elements to help infiltrate somewhat more profound into the venture's IT frameworks.

They will search for privileged insights they can offer, dollars they can take, and information they can mishandle. They may even be sitting in neighborhood bistros utilizing Wi-Fi organize sniffers to screen and split inside the venture frameworks when gotten to by representatives on their meal break.

What's occurred here is that while traditional security frameworks can ensure end clients against a considerable measure of things, it's less extraordinary at securing against multi-faceted dangers.

Visibility is everything 

Apple's iOS gadgets are presently profoundly dug in big business IT.

Effectively, more than 70 percent of big business clients give workers cell phones, yet traditional security strategies don't really see all the distinctive assaults that do exist. The as of late distinguished Blueborne Bluetooth defenselessness is a decent case of an assault that current security insurances most likely wouldn't perceive.

Note that heaps of endeavors utilize iPhones and iPads on the grounds that Apple's gadgets are as yet the most secure in the business.

That stage multiplication implies assailants who do prevail with regards to undermining that security could profit. That is the reason it is a little interesting that Apple pays only $200,000 to individuals who distinguish vulnerabilities on its stages, even while private firms pay $500,000 for a similar data. There's cash in question and nobody ought to be smug.

Cisco's Security Connector helps discover assaults you can't see 

The huge issue is that a few assaults are very straightforward. The greater part of us would not know they were occurring.

They occur at a profound gadget level that doesn't appear to meddle with our client experience, and they are not effortlessly spotted by more conventional security insurances.

That is the reason the Apple/Cisco bargain bodes well. To enable better to ensure iOS gadgets against assault, Cisco has presented Security Connector, an application that screens organize action on gadgets, with no huge effect on gadget execution or battery life. Cisco's iOS security application offers security usefulness from Cisco Umbrella and Cisco Clarity.

"Ransomware and malware are spreading over the web and progressively focusing on cell phones. Together with Apple, we are helping ventures turn into the most associated, synergistic, and secure organizations on the planet," said David Ulevitch, senior VP and general administrator of Cisco's Security Business Group.

There's a Cisco blog that reveals to you somewhat more about how this functions here, yet at its most straightforward on the off chance that one of those workers at the highest point of this story had clicked a phishing join, Security Connector would have kept the association.

Astute risk administration 

The energy of this approach is that the arrangement can screen organize movement for the sorts of abnormalities that deceive an effective hack, for example, a lot of active information being created by an unapproved application.

The arrangement likewise keeps iOS clients from getting to noxious web destinations, and causes them abstain from sharing basic information utilizing unsecured Wi-Fi systems. You can likewise utilize Security Connector to distinguish what happened, who was influenced, and what information was in danger, in the occasion an organization endures an assault.

The thought behind arrangements like these is that by checking action and recognizing dangers that may somehow or another be less unmistakable, security groups can help enhance the insurance around big business tech. In a setting in which security abuses are winding up perpetually unpredictable and progressively less noticeable, Cisco's answer bodes well.

It's not exactly the venture IT security protection bargain Apple CEO Tim Cook proposed recently, yet it's a positive development.

Thursday, 6 April 2017

642-887 Sample Question: 23

Question: 23

What is the term that is used for the label that an LSR assigns and distributes to other LSRs in MPLS?

A. Local
B. Remote
C. Explicit
D. Explicit Null
E. Aggregate

Answer: A

Friday, 17 March 2017

642-887 Sample Question: 22

Question: 22

When troubleshooting LDP operations on the Cisco IOS and IOS XE routers, what is one of the first things that should be verified?

A. if running OSPF as the IGP, ensure that OSPFv3 has been enabled
B. check if the ip cef command has been enabled
C. verify in the running configurations that all of the required LDP interfaces are defined under the mpls ldp command configuration mode
D. verify if there are any access lists that are denying TCP and UDP port 464 packets

Answer: B

Wednesday, 8 February 2017

642-887 Sample Question: 21

Question: 21

LDP session protection uses which one to maintain the LDP session between LDP neighbors?

A. LDP NSF
B. LDP NSR
C. backup-targeted LDP hellos
D. BFD
E. LDP-IGP synchronization

Answer: C

Tuesday, 24 January 2017

642-887 Sample Question: 20

Question: 20

When troubleshooting LDP operations on the Cisco IOS and IOS XE routers, what is one of the first things that should be verified?

A. if running OSPF as the IGP, ensure that OSPFv3 has been enabled
B. check if the ip cef command has been enabled
C. verify in the running configurations that all of the required LDP interfaces are defined under the mpls ldp command configuration mode
D. verify if there are any access lists that are denying TCP and UDP port 464 packets

Answer: B

Sunday, 1 January 2017

642-887 Sample Question: 19

Question: 19

What is the term that is used for the label that an LSR assigns and distributes to other LSRs in MPLS?

A. Local
B. Remote
C. Explicit
D. Explicit Null
E. Aggregate

Answer: A

Thursday, 15 December 2016

642-887 Sample Question: 18

Question: 18

Within the service provider core network, which two QoS mechanisms are typically deployed on the P routers? (Choose two.)

A. LLQ
B. traffic policing and remarking
C. WRED
D. traffic shaping
E. traffic classification and markings
F. link fragmentation and interleaving

Answer: A,C

Wednesday, 10 August 2016

642-887 Sample Question: 17

Question: 17

On the Cisco IOS XR, which MQC configuration is different than on the Cisco IOS and IOS XE?

A. On the Cisco IOS XR, WRED can only be applied in the output direction.
B. On the Cisco IOS XR, marking can only be applied in the input direction.
C. On the Cisco IOS XR, LLQ can be applied in the input or output direction.
D. On the Cisco IOS XR, LLQ can use up to four priority queues: level 1, level 2, level 3, and level 4.

Answer : C

Tuesday, 26 July 2016

642-887 Sample Question: 16

Question: 16

On a Cisco IOS XR router, which mechanism protects the router resources by filtering and policing the packets flows that are destined to the router that is based on defined flow-type rates?

A. LLQ
B. LPTS
C. Committed Access Rate
D. Control Plane Policing
E. Management Plane Protection
F. NetFlow
G. ACL

Answer : B

Friday, 1 July 2016

642-887 Sample Question: 15

Question: 15

Which of the following three statements are correct regarding IPv6 QoS? (Choose three.)

A. The traffic class field in the IPv6 header can be used to set specific precedence or DSCP values.
B. A 20-bit flow label field enables per-flow processing.
C. DS-TE is not supported by IPv6.
D. Per-hop behavior in IPv6 networks is based on EXP bits.
E. IPv6 QoS features are configured using the modular QoS CLI on Cisco routers.

Answer: A,B,E

Thursday, 16 June 2016

642-887 Sample Question: 14

Question: 14

Which three steps are required to configure QPPB on Cisco IOS XR routers? (Choose three.)

A. Apply a QPPB route policy to the BGP process using the table-policy command.
B. Apply a QPPB route policy to the BGP neighbor using the route-policy command.
C. Define a QPPB route policy to match the customer routes, then set the IP precedence or qos- group.
D. Define a QPPB route policy to match the customer IP precedence or qos-group markings, then set
the BGP community.
E. Enable QPPB on an interface using the ipv4 bgp policy propagation input ip-precedence|qos- group destination|source command.
F. Enable QPPB on an interface using the ipv4 bgp policy propagation output ip-precedence|qos- group destination|source command.

Answer: A,C,E

Wednesday, 4 May 2016

642-887 Sample Question: 13

Question: 13

Which Cisco IOS XR command should be used in order to enable LDP on all interfaces for which the IGP protocol is enabled?

A. RP/0/0/CPU0:R1(config-ospf)#mpls ldp auto-config
B. RP/0/0/CPU0:R1(config-ospf)#mpls ldp interface all enable
C. RP/0/0/CPU0:R1(config-ospf)#enable all
D. RP/0/0/CPU0:R1(config-ldp)#enable all

Answer: A

Thursday, 7 April 2016

642-887 Sample Question: 12

Question: 12

Which Cisco IOS XR command should be used to identify if MPLS TE FRR is enabled?

A. show mpls traffic-eng tunnel <tunnel#>
B. show mpls frr
C. show mpls traffic-eng protection
D. show mpls protection
E. show mpls fast-reroute

Correct Answer: A

Friday, 1 April 2016

642-887 Sample Question: 11

Question: 11

When configuring class-based WRED on Cisco routers, which WRED parameter is not user configurable on a Cisco IOS XR but is user configurable on a Cisco IOS and IOS XE?

A. the ingress or egress direction where the class-based WRED policy will be applied
B. the maximum threshold
C. the minimum threshold
D. the mark probability denominator

Correct Answer: D

Wednesday, 10 February 2016

Cisco Composition Swells To Emerging Work Loads





Cisco logo
Additions to Catalyst, handbags and ASR Aironet Series are designed to help businesses cope with the changing demands of BYOD, cloud and IO.

Cisco Systems launches new offerings in various product lines switching that officials say will help companies keep pace with the change being driven by trends such as consumerization of IT and the Internet rapidly growing things.

The networking giant is growing its Aironet, Catalyst and ASR switching families give network administrators the technology they need to cope with the rapid growth of mobile traffic running infrastructure and accelerate its ability to introduce new applications and services .

The Internet of Things (IOT), increasing the expected increase in the number of connected devices and become bring- your own device (BYOD) trend is promising to push large amounts of network traffic of companies and service providers. The new switching products are designed to help companies address these challenges, according Prashanth Shenoy, senior director of product marketing and solutions for enterprise networking and mobility of Cisco.

Shenoy networking professionals regularly say their main concern is the inability of their network infrastructures to keep pace with the rate of change.

"I know exactly what they are talking about," Shenoy wrote in a post on the company blog. "Unfortunately, you are directed to things, go with the idea of" always worked, why change it? It is increasingly untenable. Sorry ... pros of the net, but the performance and reliability of its existing network is considered more than ever. "

The 13 new products in the portfolio of switching come a week after officials Cisco launched the latest edition of the company's annual report on trends in traffic growth of the mobile network. According to company figures, mobile data traffic worldwide each year by 2020 it will reach 366.8 exabytes, a huge leap of 44.2 exabytes a year ago. This will be driven by a significant increase in the number of users of mobile phones, connected devices and the speed of mobile networks in the world in the next five years.

"Not only multiple devices connect to the network, but will have access to business critical applications that require more performance, reliability and user experience than ever," says Shenoy.

In the range of Catalyst, Cisco says the Catalyst 6K supervisor Supervisor 6T-8L Series E Series Catalyst 4K, which are designed to help customers who are already using Catalyst 6500 and 6800 switches with improved performance. The Catalyst 3650-Mini is 24/48 Gigabit Ethernet Power-over-Ethernet (PoE) switch that is designed to give smaller, and performance that large enterprises get the Catalyst 3650 organizations.

On the wireless front, Cisco launched the Aironet 2800 and 3800 access points that support the standard 802.11ac wave 2 and come with features such as flexible radio stations, which automatically adapts to environmental changes. In addition, access points come with smart antenna ports that recognize and antenna devices are configured automatically. Both features are designed to make it easier for customers to manage their wireless networks, Shenoy wrote.

The ASR 1006-X and 1009-X are designed for high availability at a time when the edge of the network is under the pressure of these demanding applications bandwidth cloud computing, software-as-a-service , high-definition video and mobile work loads, Shenoy said. These workloads focus on scalability and speed and new switches offer high availability, full redundancy and a modular design with up to 100G bps form factor 6U (10.5 inches).

They also offer a pay-as-you-go licensing model.

"When you need more speed, simply select the appropriate software license," Shenoy wrote. "Software updates are made to use No need update hardware disconnection Weather unplanned objectives chassis-x: .... High availability and resilience"

Other new offerings include Connect Mobile (CMX) Cloud wireless networks over ideas, new access points, switches experience and management capabilities for the range of Meraki enterprise and the latest version Wide Area Application Services of (WAAS) Cisco software to improve the optimization of mobile applications.

Tuesday, 19 January 2016

642-887 Sample Question: 10

Question: 10

What is the correct formula for determining the CIR?

A. CIR = Bc/Tc
B. CIR = Bc x Tc
C. CIR = Tc/Bc
D. CIR = Bc + Be
E. CIR = Tc/(Bc+Be)
F. CIR = (Bc+Be)/Tc

Answer:  A