Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 350-501 Exam - Topic 7 Question 78 Discussion

Refer to the exhibit.Refer to the exhbit. ISP A has a BGP peering with ISP C with the maximum-prefix 150 configuration on R1. After a recent security breach on the ISP A network, a network engineer has been asked to enable a lightweight security mechanism to protect the R1 CPU and BGP membership from spoofing attacks. Which solution must ISP A implement?
D) Configure neighbor 10.163.83.55 ttl-stcurity hops 2 under the global BGP configuration.
A) Configure bgp maxas-limit 1 in the IPv4 address family urateUhe global BGP configuration.
B) Configure neighbor 10.163.83.54 enable-connected-check under the BGP IPv4 address family.
C) Configure neighbor 10.163.83.55 password Cisco under the global BGP IPv4 address family.

Cisco 350-501 Exam - Topic 7 Question 78 Discussion

Actual exam question for Cisco's 350-501 exam
Question #: 78
Topic #: 7
[All 350-501 Questions]

Refer to the exhibit.

Refer to the exhbit. ISP A has a BGP peering with ISP C with the maximum-prefix 150 configuration on R1. After a recent security breach on the ISP A network, a network engineer has been asked to enable a lightweight security mechanism to protect the R1 CPU and BGP membership from spoofing attacks. Which solution must ISP A implement?

Show Suggested Answer Hide Answer
Suggested Answer: D

Contribute your Thoughts:

0/2000 characters
Buddy
9 months ago
Not sure about D, seems a bit overkill for this situation.
upvoted 0 times
...
Jeannetta
10 months ago
Definitely going with B, it makes the most sense.
upvoted 0 times
...
Alysa
10 months ago
Surprised there's no mention of encryption here!
upvoted 0 times
...
Deandrea
10 months ago
I think A could work too, but not as effective.
upvoted 0 times
...
Stefan
10 months ago
Option B is the best choice for security.
upvoted 0 times
...
Shawnda
10 months ago
I believe the maxas-limit command is more about prefix limits rather than security, so I don't think that's the right choice for this scenario.
upvoted 0 times
...
Noel
11 months ago
I practiced a similar question about BGP security last week, and I feel like the TTL security option could be relevant here, but I'm not confident.
upvoted 0 times
...
Brandee
11 months ago
I think the "enable-connected-check" option might be related to ensuring that only valid neighbors can establish a session, but I can't recall the exact details.
upvoted 0 times
...
Melodie
11 months ago
I remember studying BGP security features, but I'm not entirely sure which option specifically addresses spoofing attacks.
upvoted 0 times
...
Carey
11 months ago
Ah, I see now. The question is asking about a lightweight security mechanism, so option D with the TTL security seems like the best choice to mitigate spoofing without adding too much complexity.
upvoted 0 times
...
Lauryn
11 months ago
Hmm, I'm a bit unsure about this one. The exhibit doesn't provide much detail, and the question is asking about a specific security mechanism. I'll have to read through the options closely.
upvoted 0 times
...
Juan
11 months ago
This looks like a tricky BGP security question. I'll need to carefully review the options and think through the potential solutions.
upvoted 0 times
...
Raul
11 months ago
Okay, I think I've got this. The key is to protect the BGP session and router CPU from spoofing attacks. Based on that, I'd go with option D to configure the TTL security hop count.
upvoted 0 times
...
Rossana
11 months ago
Okay, I've got an idea. Since the question is asking about checking the risk management process, I think the audit meeting would be the best option. That would allow the project manager to formally review and evaluate the risk management activities on a regular basis.
upvoted 0 times
...
Tiffiny
11 months ago
I remember something about economies of scale being important for cost reduction in acquisitions. That might be a valid point here.
upvoted 0 times
...
Celia
2 years ago
Haha, I bet the network engineer who had to deal with that security breach is not feeling too great right now. But hey, at least they get to test our BGP security knowledge!
upvoted 0 times
...
Bernardo
2 years ago
Hmm, I'm not sure about this one. The exhibit doesn't provide a lot of context, and I'm not familiar with the specific configuration on R1. But I'll give it my best shot.
upvoted 0 times
...
Nikita
2 years ago
I agree, this seems like a straightforward question. The key is understanding the different security mechanisms that can be used to protect the BGP control plane from spoofing attacks.
upvoted 0 times
Queen
2 years ago
Enable BGP Neighbor session password on R1
upvoted 0 times
...
Melynda
2 years ago
Use BGP Maximum Prefix threshold on R1
upvoted 0 times
...
Serina
2 years ago
Apply inbound BGP prefix filters on R1
upvoted 0 times
...
Valentin
2 years ago
Implement BGP Route Refresh capability
upvoted 0 times
...
Michell
2 years ago
Enable BGP TTL security check on R1
upvoted 0 times
...
...
Lavera
2 years ago
This question seems to be testing our understanding of BGP and security best practices. I think it's a pretty straightforward one, as long as we know the different options available for securing BGP sessions.
upvoted 0 times
...

Save Cancel