SNSP EXAM BEST PRACTICES AND OTHER BASICS ALL 85
sh
QUESTIONS AND CORRECT DETAILED ANSWERS
ne
|ALREADY GRADED A+la
tz
sh
Sp
ne
Why must you enable load balancing with only 1 WAN
la
connection - ANSWER--To access the LB Groups and LB
sh
Sp
Statistics sections of Failover and Load Balancing configuration
ne
la
tz
sh
Sp
Which Probe menu should you select when configuring WAN
ne
probes - ANSWER--Probe Succeeds when either main or
la
alternate target responds
sh
Sp
ne
la
tz
Why should you always use X0 as a backup heartbeat link -
sh
Sp
ANSWER--Because it is hardcoded in SonicOS
ne
la
sh
Sp
True or False: You should always configure X0's monitoring IP -
ne
ANSWER--True
la
tz
sh
Sp
ne
What happens if the WAN interface does not have the
la
monitoring IP configured - ANSWER--The secondary/Standby
sh
Sp
unit directs the path to the Internet for GRID and License
ne
Manager communication
a
tz
l
sh
Sp
ne
la
sh
Sp
la
Sp
, ne
SNSP EXAM BEST PRACTICES AND OTHER BASICS ALL 85
sh
QUESTIONS AND CORRECT DETAILED ANSWERS
ne
|ALREADY GRADED A+la
tz
sh
True or False: The secondary unit is licensed automatically -
Sp
ANSWER--False
ne
la
sh
Sp
ne
Why would you want to use Virtual MAC with an HA pair -
la
ANSWER--To reduce ARP convergence time during a failover
tz
sh
Sp
ne
la
When using an HA pair what should you ensure is disabled on
sh
the switchports on the switch - ANSWER--Spanning Tree
Sp
ne
Protocol which can cause flapping effects when virtual MAC is
la
seen on multiple interfaces
tz
sh
Sp
ne
la
True or False: Ensure all security services are enabled on proper
sh
zones - ANSWER--True
Sp
ne
la
tz
sh
If you do not plan on using BWM, should it still be enabled -
Sp
ne
ANSWER--No
la
sh
Sp
ne
What settings use BWM - ANSWER--Access Rules with BWM
a
setting use the throttles, interface BWM settings, and priority
tz
l
sh
queues
Sp
ne
la
sh
Sp
la
Sp
, ne
SNSP EXAM BEST PRACTICES AND OTHER BASICS ALL 85
sh
QUESTIONS AND CORRECT DETAILED ANSWERS
ne
|ALREADY GRADED A+
la
tz
sh
True or False: Do not disable Allow Fragmented Packets on
Sp
ne
access rules - ANSWER--True
la
sh
Sp
ne
What application firewall rules should be created to prevent
la
malware - ANSWER--Rules that restrict DNS, SSH, and Proxy-
tz
sh
Access applications
Sp
ne
la
sh
What can malicious applications leverage to redirect traffic to
Sp
ne
illegitmate sites - ANSWER--DNS Cache Poisoning
la
tz
sh
Sp
ne
True or False: You should create an Address Object and
la
AppRule to restrict the DNS protocol to only the Trusted DNS
sh
Host - ANSWER--True
Sp
ne
la
tz
What is the recommend way to restrict SSH Protocol -
sh
Sp
ne
ANSWER--By using an Application Firewall rule since it's
la
possible to deviate from the standard SSH TCP 22
sh
Sp
configuration
ne
a
tz
l
sh
What additional CFS categories should be blocked - ANSWER--
Sp
ne
CAT28 Hacking/Proxy Avoidence
la
sh
Sp
la
Sp