Exam Code : 2B0-104
Exam Name : Enterasys Certified Internetworking Engineer(ECIE)
Vendor Name :
"Enterasys"
2B0-104 Dumps
2B0-104 Braindumps 2B0-104 Real Questions 2B0-104 Practice Test
2B0-104 Actual Questions
killexams.com Enterasys 2B0-104
Enterasys Certified Internetworking Engineer(ECIE)
https://killexams.com/pass4sure/exam-detail/2B0-104
As defined in NetSight Policy Managers demo.pmd file, the Application Provisioning
- Supplemental service is designed to:
Discard malicious traffic
Prioritize mission critical traffic by provisioning on-demand QoS
Discard unsupported protocols
Rate limit traffic associated to DoS attacks
When deploying static policy to the network,:
The NetSight Policy configuration must be enforced to the policy-capable devices before policy roles are assigned to ports
The Phased Implementation Approach should be used to minimize inadvertent negative impact to business-critical applications on the network
Updating the policy configuration across the entire network requires enforcing the altered policy configuration in NetSight Policy Manager and then reassigning the altered policy roles to device ports
A and B
In the deployment of static policy on the network, a policy-capable device, such as the Matrix N-series,:
Classifies ingressed traffic on the network
Centrally defines and pushes out the policy configuration for the network
Periodically updates the policy configuration in NetSight Policy Manager
Maintains periodic contact with other policy-capable switches on the network
Port Groups can be used in NetSight Policy Manager to:
Group ports based on location
Group ports based on speed
Group ports based on whether untrusted users have physical access to these ports
All of the above
When configuring a highly restrictive policy role in NetSight Policy Manager with the highest level of security, such as the Quarantine policy, the default access control setting for the policy role should be set to:
Deny
Allow
Redirect to a remediation server
CoS Priority 0
Which of the following services, as defined by demo.pmd in NetSight Policy
Manager, protects the network from Denial of Service attacks on the network?
Deny Unsupported Protocol Access service
Deny DoS Attacks service
Limit Exposure to DoS Attacks service
Application Provisioning - AUP service
Which of the following services, as defined by demo.pmd in NetSight Policy
Manager, reduces network congestion by removing legacy protocols from the
network such as IPX?
Deny Unsupported Protocol Access service
Deny Spoofing & other Administrative Protocols service
Threat Management service
Limit Exposure to DoS Attacks service
As defined in NetSight Policy Managers demo.pmd file, the Guest Access policy role is associated to:
No services
The Deny Spoofing & Other Administrative Protocols service only
The Deny Unsupported Protocol Access service only
All services grouped under the Secure Guest Access service group
A new virus has been identified on the Internet causing an infected system to listen to TCP port X for allowing remote connections to the infected device. Since port X is used for a business-critical application on the network, the network administrator can most effectively protect his/her network without severely impacting business continuity by configuring and enforcing policy to the Active Edge that:
Discards traffic destined to TCP port X
Discards traffic sourced from TCP port X
Prioritizes traffic destined or sourced to TCP port X to a lower priority with rate limiting
Discards traffic sourced or destined to TCP port X
In a multi-vendor environment, where is the placement of a policy capable device most effective in discarding malicious traffic and protecting the entire network:
At the access layer edge
At the distribution layer
In the DMZ
In the core
A network administrator has identified that a new operating system installed on a large number of end devices on the network natively supports IPv6 as well as IPv4, and these end systems attempt to communicate over IPv4 and IPv6 by default. To improve the network utilization efficiency and avoid reconfiguring each individual
end system, to which service would the network administrator most likely add a drop IPv6 traffic classification rule?
Deny Unsupported Protocol Access service
Deny Spoofing & other Administrative Protocols service
Threat Management service
Limit Exposure to DoS Attacks service
A Policy Profile:
Defines a collection of classification rules and default packet handling logic
Maps to an organizational role within the enterprise for the allocation of network resources
May be assigned to multiple ports on a device
All of the above
As defined in NetSight Policy Managers demo.pmd file, the Guest Access policy role should be assigned to ports where:
Only IT operations may access the network
Only trusted users may access the network
Trusted users may access the network as well as untrusted users
The Guest Access policy role should only be dynamically assigned to ports as a result of successful authentication
As defined in NetSight Policy Managers demo.pmd file, the Enterprise Access policy
role is associated to:
No services
The Deny Spoofing & Other Administrative Protocols service only
The Deny Unsupported Protocol Access service only
All services grouped under the Acceptable Use Policy service group