133You have installed a web server on a private network. Which type of NAT must you implement to enable access to the web server for public Internet users?A. static NATB. dynamic NATC. network object NATD. twice NATAnswer: AQUESTION 134Which type of object group will allow configuration for both TCP 80 and TCP 443?A. serviceB. networkC. time rangeD. user groupAnswer: AQUESTION 135When you configure a Botnet Traffic Filter on a Cisco firewall, what are two optional tasks? (Choose two.)A. Enable the use of dynamic databases.B. Add static entries to the database.C. Enable DNS snooping.D. Enable traffic classification and actions.E. Block traffic manually based on its syslog information.Answer: BEQUESTION 136Refer to the exhibit. What is the effect of this configuration? A. The firewall will inspect IP traffic only between networks and The firewall will inspect all IP traffic except traffic to and The firewall will inspect traffic only if it is defined within a standard ACL.D. The firewall will inspect all IP traffic.Answer: AQUESTION 137When you configure a Cisco firewall in multiple context mode, where do you allocate interfaces?A. in the system execution spaceB. in the admin contextC. in a user-defined contextD. in the global configurationAnswer: AQUESTION 138At which layer does Dynamic ARP Inspection validate packets?A. Layer 2B. Layer 3C. Layer 4D. Layer 7Answer: AQUESTION 139Which feature can suppress packet flooding in a network?A. PortFastB. BPDU guardC. Dynamic ARP InspectionD. storm controlAnswer: DQUESTION 140What is the default violation mode that is applied by port security?A. restrictB. protectC. shutdownD. shutdown VLANAnswer: CQUESTION 141What are two security features at the access port level that can help mitigate Layer 2 attacks? (Choose two.)A. DHCP snoopingB. IP Source GuardC. TelnetD. Secure ShellE. SNMPAnswer: ABQUESTION 142At which layer does MACsec provide encryption?A. Layer 1B. Layer 2C. Layer 3D. Layer 4Answer: BQUESTION 143What are two enhancements of SSHv2 over SSHv1? (Choose two.)A. VRF-aware SSH supportB. DH group exchange supportC. RSA supportD. keyboard-interactive authenticationE. SHA supportAnswer: AB