100% Guarantee to Pass Your CCNA exam and get your CCNA Certification if you choice Pass4side
We guarantee your success in the first attempt. If you do not pass the Cisco 642-504 on your first attempt we will give you a FULL REFUND of your purchasing fee AND send you another same value product for free.
5. Which three statements correctly describe the GET VPN policy management? (Choose three.)
A. A central policy is defined at the ACS (AAA) server.
B. A local policy is defined on each group member.
C. A global policy is defined on the key server, and it is distributed to the group members.
D. The key server and group member policy must match.
E. The group member appends the global policy to its local policy.
Answer: BCE
6. The CPU and Memory Threshold Notifications of the Network Foundation Protection feature protects which
router plane?
A. control plane
B. management plane
C. data plane
D. network plane
Answer: B
7. In DMVPN, the NHRP process allows which requirement to be met?
A. dynamic physical interface IP address at the spoke routers
B. high-availability DMVPN designs
C. dynamic spoke-to-spoke on-demand tunnels
D. dynamic routing over the DMVPN
E. dual DMVPN hub designs
Answer: A
8. Which is correct regarding the Management Plane Protection feature?
A. By default, Management Plane Protection is enabled on all interfaces.
Pass4Side Cisco 642-504
B. Management Plane Protection provides for a default management interface.
C. Only SSH and SNMP management will be allowed on nondesignated management interfaces.
D. All incoming packets through the management interface are dropped except for those from the allowed
management protocols.
Answer: D
9. What are the two enrollment options when using the SDM Certificate Enrollment wizard? (Choose two.)
A. SCEP
B. LDAP
C. OCSP
D. Cut-and-Paste/Import from PC
Answer: AD
10. Refer to the exhibit.
Which two configuration commands are used to apply an inspect policy map for traffic traversing from the E0 or
E1 interface to the S3 interface? (Choose two.)
A. zone-pair security test source Z1 destination Z2
B. interface E0
C. policy-map myfwpolicy
class class-default
inspect
D. ip inspect myfwpolicy out
E. ip inspect myfwpolicy in
F. service-policy type inspect myfwpolicy
Answer: AF
