Thursday, 20 July 2017
Cisco Plugs Command-Injection Hole In WebEx Chrome, Firefox Plugins
Cisco has settled its Chrome and Firefox WebEx modules to butcher a bug that empowers treacherous site pages to execute summons on PCs.
A dangerous page, when gone to by a defenseless Windows machine, can abuse the security imperfection (CVE-2017-6753) to run optional accuses and code of a vague advantages from the program. In a manner of speaking, the page can misuse the acquainted modules with grab the PC.
The crevice is accessible in the Chrome and Firefox modules for Cisco WebEx Meetings Server and Cisco WebEx Centers, and impacts things including WebEx Meeting Center, Event Center, Training Center and Support Center. Web Explorer and Edge are not seen as defenseless, and both OS X and Linux versions of Chrome and Firefox are in like manner protected.
The bug was found by Google Project Zero authority Tavis Ormandy and Divergent Security's Cris Neckar.
"A lack of protection in Cisco WebEx program increases for Google Chrome and Mozilla Firefox could allow an unauthenticated, remote attacker to execute self-self-assured code with the advantages of the affected program on an impacted system," Cisco said on Monday.
"This lack of protection impacts the program enlargements for Cisco WebEx Meetings Server, Cisco WebEx Centers (Meeting Center, Event Center, Training Center, and Support Center), and Cisco WebEx Meetings when they are running on Microsoft Windows.
"The defenselessness is a result of a blueprint defect in the development. An attacker who can convince an affected customer to visit an aggressor controlled site page or take after an attacker furnished associate with an impacted program could abuse the shortcoming. In case productive, the assailant could execute optional code with the advantages of the affected program."
Those running Chrome and Firefox modules for WebEx ought to starting at now have the patches running on their machines. Cisco kicked out the modified revive for Chrome on July 12 and Firefox on July 13. Customers can check whether their variations are the settled release (1.0.12) by taking off to the extensions menu in the program and, if a more settled adjustment is run, picking the "revive expansions now" (Chrome) or "check for invigorates" (Firefox) elective.
Cisco says that while simply the Chrome and Firefox modules on Windows boxes are feeble against the flaw portrayed, shared code between those projects and the Internet Explorer/Edge modules suggests that an invigorate for Microsoft programs has been released as well. ®
Sunday, 28 May 2017
Cisco 300-209 Study Material
Question: 26
Which technology can you implement to reduce latency issues associated with a Cisco AnyConnect VPN?
A. DTLS
B. SCTP
C. DCCP
D. SRTP
Answer: A
Question: 27
Which feature enforces the corporate policy for Internet access to Cisco AnyConnect VPN users?
A. Trusted Network Detection
B. Datagram Transport Layer Security
C. Cisco AnyConnect Customization
D. banner message
Answer: A
Question: 28
In which situation would you enable the Smart with clientless SSL VPN?
A. when a user is using an outdated version of a web browser
B. when an application is failing in the rewrite process
C. when IPsec should be used over SSL VPN
D. when a user has a nonsupported Java version installed
E. when cookies are disabled
Answer: B
Question: 29
Which three parameters must match on all routers in a DMVPN Phase 3 cloud? (Choose three.)
A. NHRP network ID
B. GRE tunnel key
C. NHRP authentication string
D. tunnel VRF
E. EIGRP process name
F. EIGRP split-horizon setting
Answer: A,B,C
Which technology can you implement to reduce latency issues associated with a Cisco AnyConnect VPN?
A. DTLS
B. SCTP
C. DCCP
D. SRTP
Answer: A
Question: 27
Which feature enforces the corporate policy for Internet access to Cisco AnyConnect VPN users?
A. Trusted Network Detection
B. Datagram Transport Layer Security
C. Cisco AnyConnect Customization
D. banner message
Answer: A
Cisco 300-209 CCNP Security Practice Exam PDF
Question: 28
In which situation would you enable the Smart with clientless SSL VPN?
A. when a user is using an outdated version of a web browser
B. when an application is failing in the rewrite process
C. when IPsec should be used over SSL VPN
D. when a user has a nonsupported Java version installed
E. when cookies are disabled
Answer: B
Question: 29
Which three parameters must match on all routers in a DMVPN Phase 3 cloud? (Choose three.)
A. NHRP network ID
B. GRE tunnel key
C. NHRP authentication string
D. tunnel VRF
E. EIGRP process name
F. EIGRP split-horizon setting
Answer: A,B,C
Thursday, 27 April 2017
Cisco 300-209 CCNP Security Practice Exam
Question: 21
Regarding licensing, which option will allow IKEv2 connections on the adaptive security appliance?
A. AnyConnect Essentials can be used for Cisco AnyConnect IKEv2 connections.
B. IKEv2 sessions are not licensed.
C. The Advanced Endpoint Assessment license must be installed to allow Cisco AnyConnect IKEv2 sessions.
D. Cisco AnyConnect Mobile must be installed to allow AnyConnect IKEv2 sessions.
Answer: A
Question: 22
Which command enables IOS SSL VPN Smart Tunnel support for PuTTY?
A. appl ssh putty.exe win
B. appl ssh putty.exe windows
C. appl ssh putty
D. appl ssh putty.exe
Answer: B
Question: 23
Which cryptographic algorithms are approved to protect Top Secret information?
A. HIPPA DES
B. AES-128
C. RC4-128
D. AES-256
Answer: D
Question: 24
Which three plugins are available for clientless SSL VPN? (Choose three.)
A. CIFS
B. RDP2
C. SSH
D. VNC
E. SQLNET
F. ICMP
Correct Answer: B,C,D
Question: 25
Which DAP endpoint attribute checks for the matching MAC address of a client machine?
A. device
B. process
C. antispyware
D. BIA
Answer: A
Regarding licensing, which option will allow IKEv2 connections on the adaptive security appliance?
A. AnyConnect Essentials can be used for Cisco AnyConnect IKEv2 connections.
B. IKEv2 sessions are not licensed.
C. The Advanced Endpoint Assessment license must be installed to allow Cisco AnyConnect IKEv2 sessions.
D. Cisco AnyConnect Mobile must be installed to allow AnyConnect IKEv2 sessions.
Answer: A
Question: 22
Which command enables IOS SSL VPN Smart Tunnel support for PuTTY?
A. appl ssh putty.exe win
B. appl ssh putty.exe windows
C. appl ssh putty
D. appl ssh putty.exe
Answer: B
Cisco 300-209 CCNP Security Test Questions PDF
Question: 23
Which cryptographic algorithms are approved to protect Top Secret information?
A. HIPPA DES
B. AES-128
C. RC4-128
D. AES-256
Answer: D
Question: 24
Which three plugins are available for clientless SSL VPN? (Choose three.)
A. CIFS
B. RDP2
C. SSH
D. VNC
E. SQLNET
F. ICMP
Correct Answer: B,C,D
Question: 25
Which DAP endpoint attribute checks for the matching MAC address of a client machine?
A. device
B. process
C. antispyware
D. BIA
Answer: A
Thursday, 6 April 2017
300-209 Sample Question
QUESTION: 20
What are two forms of SSL VPN? (Choose two.)
A. port forwarding
B. Full Tunnel Mode
C. Cisco IOS WebVPN
D. Cisco AnyConnect
Answer: A,B
What are two forms of SSL VPN? (Choose two.)
A. port forwarding
B. Full Tunnel Mode
C. Cisco IOS WebVPN
D. Cisco AnyConnect
Answer: A,B
Friday, 17 March 2017
300-209 Sample Question
QUESTION: 19
What are two variables for configuring clientless SSL VPN single sign-on? (Choose two.)
A. CSCO_WEBVPN_OTP_PASSWORD
B. CSCO_WEBVPN_INTERNAL_PASSWORD
C. CSCO_WEBVPN_USERNAME
D. CSCO_WEBVPN_RADIUS_USER
Answer: B,C
What are two variables for configuring clientless SSL VPN single sign-on? (Choose two.)
A. CSCO_WEBVPN_OTP_PASSWORD
B. CSCO_WEBVPN_INTERNAL_PASSWORD
C. CSCO_WEBVPN_USERNAME
D. CSCO_WEBVPN_RADIUS_USER
Answer: B,C
Monday, 6 February 2017
300-209 Sample Question
QUESTION: 18
Consider this scenario. When users attempt to connect via a Cisco AnyConnect VPN session, the certificate has changed and the connection fails. What is a possible cause of the connection failure?
A. An invalid modulus was used to generate the initial key.
B. The VPN is using an expired certificate.
C. The Cisco ASA appliance was reloaded.
D. The Trusted Root Store is configured incorrectly.
Answer: C
Consider this scenario. When users attempt to connect via a Cisco AnyConnect VPN session, the certificate has changed and the connection fails. What is a possible cause of the connection failure?
A. An invalid modulus was used to generate the initial key.
B. The VPN is using an expired certificate.
C. The Cisco ASA appliance was reloaded.
D. The Trusted Root Store is configured incorrectly.
Answer: C
Monday, 23 January 2017
300-209 Sample Question
QUESTION: 17
A network is configured to allow clientless access to resources inside the network. Which feature must be enabled and configured to allow SSH applications to respond on the specified port 8889?
A. auto applet download
B. port forwarding
C. web-type ACL
D. HTTP proxy
Answer: B
A network is configured to allow clientless access to resources inside the network. Which feature must be enabled and configured to allow SSH applications to respond on the specified port 8889?
A. auto applet download
B. port forwarding
C. web-type ACL
D. HTTP proxy
Answer: B
Subscribe to:
Posts (Atom)


