Tuesday, 9 June 2015

400-101 CCIE Routing and Switching

400-101 CCIE Routing and Switching
Exam Description
The CCIE written exam is a two-hour qualification exam. The exam uses a combination of 90-110 multiple choice questions and simulations to assess skills. Exams are closed book and no reference materials are allowed.
The following topics are general guidelines for the content likely to be included on the exam. However, other related topics may also appear on any specific delivery of the exam. In order to better reflect the contents of the exam and for clarity purposes, the guidelines below may change at any time without notice.
1.0 Network Principles 10%
1.1 Network theory
1.1.a Describe basic software architecture differences between IOS and IOS XE
1.1.a [i] Control plane and Forwarding plane
1.1.a [ii] Impact to troubleshooting and performances
1.1.a [iii] Excluding specific platform’s architecture
1.1.b Identify Cisco express forwarding concepts
1.1.b [i] RIB, FIB, LFIB, Adjacency table
1.1.b [ii] Load balancing Hash
1.1.b [iii] Polarization concept and avoidance
1.1.c Explain general network challenges
1.1.c [i] Unicast flooding
1.1.c [ii] Out of order packets
1.1.c [iii] Asymmetric routing
1.1.c [iv] Impact of micro burst
1.1.d Explain IP operations
1.1.d [i] ICMP unreachable, redirect
1.1.d [ii] IPv4 options, IPv6 extension headers
1.1.d [iii] IPv4 and IPv6 fragmentation
1.1.d [iv] TTL
1.1.d [v] IP MTU
1.1.e Explain TCP operations
1.1.e [i] IPv4 and IPv6 PMTU
1.1.e [ii] MSS
1.1.e [iii] Latency
1.1.e [iv] Windowing
1.1.e [v] Bandwidth delay product
1.1.e [vi] Global synchronization
1.1.e [vii] Options
1.1.f Explain UDP operations
1.1.f [i] Starvation
1.1.f [ii] Latency
1.1.f [iii] RTP/RTCP concepts
1.2 Network implementation and operation
1.2.a Evaluate proposed changes to a network
1.2.a [i] Changes to routing protocol parameters
1.2.a [ii] Migrate parts of a network to IPv6
1.2.a [iii] Routing protocol migration
1.2.a [iv] Adding multicast support
1.2.a [v] Migrate spanning tree protocol
1.2.a [vi] Evaluate impact of new traffic on existing QoS design
1.3 Network troubleshooting
1.3.a Use IOS troubleshooting tools
1.3.a [i] debug, conditional debug
1.3.a [ii] ping, traceroute with extended options
1.3.a [iii] Embedded packet capture
1.3.a [iv] Performance monitor
1.3.b Apply troubleshooting methodologies
1.3.b [i] Diagnose the root cause of networking issue [analyze symptoms, identify and describe root cause]
1.3.b [ii] Design and implement valid solutions according to constraints
1.3.b [iii] Verify and monitor resolution
1.3.c Interpret packet capture
1.3.c [i] Using Wireshark trace analyzer
1.3.c [ii] Using IOS embedded packet capture
2.0 Layer 2 Technologies 15%
2.1 LAN switching technologies
2.1.a Implement and troubleshoot switch administration
2.1.a [i] Managing MAC address table
2.1.a [ii] errdisable recovery
2.1.a [iii] L2 MTU
2.1.b Implement and troubleshoot layer 2 protocols
2.1.b [i] CDP, LLDP
2.1.b [ii] UDLD
2.1.c Implement and troubleshoot VLAN
2.1.c [i] Access ports
2.1.c [ii] VLAN database
2.1.c [iii] Normal, extended VLAN, voice VLAN
2.1.d Implement and troubleshoot trunking
2.1.d [i] VTPv1, VTPv2, VTPv3, VTP pruning
2.1.d [ii] dot1Q
2.1.d [iii] Native VLAN
2.1.d [iv] Manual pruning
2.1.e Implement and troubleshoot EtherChannel
2.1.e [i] LACP, PAgP, manual
2.1.e [ii] Layer 2, layer 3
2.1.e [iii] Load-balancing
2.1.e [iv] Etherchannel misconfiguration guard
2.1.f Implement and troubleshoot spanning-tree
2.1.f [i] PVST+/RPVST+/MST
2.1.f [ii] Switch priority, port priority, path cost, STP timers
2.1.f [iii] port fast, BPDUguard, BPDUfilter
2.1.f [iv] loopguard, rootguard
2.1.g Implement and troubleshoot other LAN switching technologies
2.1.g [i] SPAN, RSPAN, ERSPAN
2.1.h Describe chassis virtualization and aggregation technologies
2.1.h [i] Multichassis
2.1.h [ii] VSS concepts
2.1.h [iii] Alternative to STP
2.1.h [iv] Stackwise
2.1.h [v] Excluding specific platform implementation
2.1.i Describe spanning-tree concepts
2.1.i [i] Compatibility between MST and RSTP
2.1.i [ii] STP dispute, STP bridge assurance
2.2 Layer 2 multicast
2.2.a Implement and troubleshoot IGMP
2.2.a [i] IGMPv1, IGMPv2, IGMPv3
2.2.a [ii] IGMP snooping
2.2.a [iii] IGMP querier
2.2.a [iv] IGMP filter
2.2.a [v] IGMP proxy
2.2.b Explain MLD
2.2.c Explain PIM snooping
2.3 Layer 2 WAN circuit technologies
2.3.a Implement and troubleshoot HDLC
2.3.b Implement and troubleshoot PPP
2.3.b [i] Authentication [PAP, CHAP]
2.3.b [ii] PPPoE
2.3.b [iii] MLPPP
2.3.c Describe WAN rate-based ethernet circuits
2.3.c [i] Metro and WAN Ethernet topologies
2.3.c [ii] Use of rate-limited WAN ethernet services
3.0 Layer 3 Technologies 40%

3.1 Addressing technologies
3.1.a Identify, implement and troubleshoot IPv4 addressing and subnetting
3.1.a [i] Address types, VLSM
3.1.a [ii] ARP
3.1.b Identify, implement and troubleshoot IPv6 addressing and subnetting
3.1.b [i] Unicast, multicast
3.1.b [ii] EUI-64
3.1.b [iii] ND, RS/RA
3.1.b [iv] Autoconfig/SLAAC, temporary addresses [RFC4941]
3.1.b [v] Global prefix configuration feature
3.1.b [vi] DHCP protocol operations
3.1.b [vii] SLAAC/DHCPv6 interaction
3.1.b [viii] Stateful, stateless DHCPv6
3.1.b [ix] DHCPv6 prefix delegation
3.2 Layer 3 multicast
3.2.a Troubleshoot reverse path forwarding
3.2.a [i] RPF failure
3.2.a [ii] RPF failure with tunnel interface
3.2.b Implement and troubleshoot IPv4 protocol independent multicast
3.2.b [i] PIM dense mode, sparse mode, sparse-dense mode
3.2.b [ii] Static RP, auto-RP, BSR
3.2.b [iii] BiDirectional PIM
3.2.b [iv] Source-specific multicast
3.2.b [v] Group to RP mapping
3.2.b [vi] Multicast boundary
3.2.c Implement and troubleshoot multicast source discovery protocol
3.2.c [i] Intra-domain MSDP [anycast RP]
3.2.c [ii] SA filter
3.2.d Describe IPv6 multicast
3.2.d [i] IPv6 multicast addresses
3.2.d [ii] PIMv6
3.3 Fundamental routing concepts
3.3.a Implement and troubleshoot static routing
3.3.b Implement and troubleshoot default routing
3.3.c Compare routing protocol types
3.3.c [i] Distance vector
3.3.c [ii] Link state
3.3.c [iii] Path vector
3.3.d Implement, optimize and troubleshoot administrative distance
3.3.e Implement and troubleshoot passive interface
3.3.f Implement and troubleshoot VRF lite
3.3.g Implement, optimize and troubleshoot filtering with any routing protocol
3.3.h Implement, optimize and troubleshoot redistribution between any routing protocol
3.3.i Implement, optimize and troubleshoot manual and auto summarization with any routing protocol
3.3.j Implement, optimize and troubleshoot policy-based routing
3.3.k Identify and troubleshoot sub-optimal routing
3.3.l Implement and troubleshoot bidirectional forwarding detection
3.3.m Implement and troubleshoot loop prevention mechanisms
3.3.m [i] Route tagging, filtering
3.3.m [ii] Split horizon
3.3.m [iii] Route poisoning
3.3.n Implement and troubleshoot routing protocol authentication
3.3.n [i] MD5
3.3.n [ii] Key-chain
3.3.n [iii] EIGRP HMAC SHA2-256bit
3.3.n [iv] OSPFv2 SHA1-196bit
3.3.n [v] OSPFv3 IPsec authentication
3.4 RIP [v2 and v6]
3.4.a Implement and troubleshoot RIPv2
3.4.b Describe RIPv6 [RIPng]
3.5 EIGRP [for IPv4 and IPv6]
3.5.a Describe packet types
3.5.a [i] Packet types [hello, query, update, and such]
3.5.a [ii] Route types [internal, external]
3.5.b Implement and troubleshoot neighbor relationship
3.5.b [i] Multicast, unicast EIGRP peering
3.5.b [ii] OTP point-to-point peering
3.5.b [iii] OTP route-reflector peering
3.5.b [iv] OTP multiple service providers scenario
3.5.c Implement and troubleshoot loop free path selection
3.5.c [i] RD, FD, FC, successor, feasible successor
3.5.c [ii] Classic metric
3.5.c [iii] Wide metric
3.5.d Implement and troubleshoot operations
3.5.d [i] General operations
3.5.d [ii] Topology table, update, query, active, passive
3.5.d [iii] Stuck in active
3.5.d [iv] Graceful shutdown
3.5.e Implement and troubleshoot EIGRP stub
3.5.e [i] Stub
3.5.e [ii] Leak-map
3.5.f Implement and troubleshoot load-balancing
3.5.f [i] equal-cost
3.5.f [ii] unequal-cost
3.5.f [iii] add-path
3.5.g Implement EIGRP [multi-address] named mode
3.5.g [i] Types of families
3.5.g [ii] IPv4 address-family
3.5.g [iii] IPv6 address-family
3.5.h Implement, troubleshoot and optimize EIGRP convergence and scalability
3.5.h [i] Describe fast convergence requirements
3.5.h [ii] Control query boundaries
3.5.h [iii] IP FRR/fast reroute [single hop]
3.5.8 [iv] Summary leak-map
3.5.h [v] Summary metric
3.6 OSPF [v2 and v3]
3.6.a Describe packet types
3.6.a [i] LSA yypes [1, 2, 3, 4, 5, 7, 9]
3.6.a [ii] Route types [N1, N2, E1, E2]
3.6.b Implement and troubleshoot neighbor relationship
3.6.c Implement and troubleshoot OSPFv3 address-family support
3.6.c [i] IPv4 address-family
3.6.c [ii] IPv6 address-family
3.6.d Implement and troubleshoot network types, area types and router types
3.6.d [i] Point-to-point, multipoint, broadcast, non-broadcast
3.6.d [ii] LSA types, area type: backbone, normal, transit, stub, NSSA, totally stub
3.6.d [iii] Internal router, ABR, ASBR
3.6.d [iv] Virtual link
3.6.e Implement and troubleshoot path preference
3.6.f Implement and troubleshoot operations
3.6.f [i] General operations
3.6.f [ii] Graceful shutdown
3.6.f [iii] GTSM [Generic TTL Security Mechanism]
3.6.g Implement, troubleshoot and optimize OSPF convergence and scalability
3.6.g [i] Metrics
3.6.g [ii] LSA throttling, SPF tuning, fast hello
3.6.g [iii] LSA propagation control [area types, ISPF]
3.6.g [iv] IP FRR/fast reroute [single hop]
3.6.g [v] LFA/loop-free alternative [multi hop]
3.6.g [vi] OSPFv3 prefix suppression
3.7 BGP
3.7.a Describe, implement and troubleshoot peer relationships
3.7.a [i] Peer-group, template
3.7.a [ii] Active, passive
3.7.a [iii] States, timers
3.7.a [iv] Dynamic neighbors
3.7.b Implement and troubleshoot IBGP and EBGP
3.7.b [i] EBGP, IBGP
3.7.b [ii] 4 bytes AS number
3.7.b [iii] Private AS
3.7.c Explain attributes and best-path selection
3.7.d Implement, optimize and troubleshoot routing policies
3.7.d [i] Attribute manipulation
3.7.d [ii] Conditional advertisement
3.7.d [iii] Outbound route filtering
3.7.d [iv] Communities, extended communities
3.7.d [v] Multi-homing
3.7.e Implement and troubleshoot scalability
3.7.e [i] Route-reflector, cluster
3.7.e [ii] Confederations
3.7.e [iii] Aggregation, AS set
3.7.f Implement and troubleshoot multiproctocol BGP
3.7.f [i] IPv4, IPv6, VPN address-family
3.7.g Implement and troubleshoot AS path manipulations
3.7.g [i] Local AS, allow AS in, remove private AS
3.7.g [ii] Prepend
3.7.g [iii] Regexp
3.7.h Implement and troubleshoot other features
3.7.h [i] Multipath
3.7.h [ii] BGP synchronization
3.7.h [iii] Soft reconfiguration, route refresh
3.7.i Describe BGP fast convergence features
3.7.i [i] Prefix independent convergence
3.7.i [ii] Add-path
3.7.i [iii] Next-hop address tracking
3.8 ISIS [for IPv4 and IPv6]
3.8.a Describe basic ISIS network
3.8.a [i] Single area, single topology
3.8.b Describe neighbor relationship
3.8.c Describe network types, levels and router types
3.8.c [i] NSAP addressing
3.8.c [ii] Point-to-point, broadcast
3.8.d Describe operations
3.8.e Describe optimization features
3.8.e [i] Metrics, wide metric
4.0 VPN Technologies 15%

4.1 Tunneling
4.1.a Implement and troubleshoot MPLS operations
4.1.a [i] Label stack, LSR, LSP
4.1.a [ii] LDP
4.1.a [iii] MPLS ping, MPLS traceroute
4.1.b Implement and troubleshoot basic MPLS L3VPN
4.1.b [i] L3VPN, CE, PE, P
4.1.b [ii] Extranet [route leaking]
4.1.c Implement and troubleshoot encapsulation
4.1.c [i] GRE
4.1.c [ii] Dynamic GRE
4.1.c [iii] LISP encapsulation principles supporting EIGRP OTP
4.1.d Implement and troubleshoot DMVPN [single hub]
4.1.d [i] NHRP
4.1.d [ii] DMVPN with IPsec using preshared key
4.1.d [iii] QoS profile
4.1.d [iv] Pre-classify
4.1.e Describe IPv6 tunneling techniques
4.1.e [i] 6in4, 6to4
4.1.e [ii] ISATAP
4.1.e [iii] 6RD
4.1.e [iv] 6PE/6VPE
4.1.g Describe basic layer 2 VPN —wireline
4.1.g [i] L2TPv3 general principals
4.1.g [ii] ATOM general principals
4.1.h Describe basic L2VPN — LAN services
4.1.h [i] MPLS-VPLS general principals
4.1.h [ii] OTV general principals
4.2 Encryption
4.2.a Implement and troubleshoot IPsec with preshared key
4.2.a [i] IPv4 site to IPv4 site
4.2.a [ii] IPv6 in IPv4 tunnels
4.2.a [iii] Virtual tunneling Interface [VTI]
4.2.b Describe GET VPN
5.0 Infrastructure Security 5%

5.1 Device security
5.1.a Implement and troubleshoot IOS AAA using local database
5.1.b Implement and troubleshoot device access control
5.1.b [i] Lines [VTY, AUX, console]
5.1.b [ii] SNMP
5.1.b [iii] Management plane protection
5.1.b [iv] Password encryption
5.1.c Implement and troubleshoot control plane policing
5.1.d Describe device security using IOS AAA with TACACS+ and RADIUS
5.1.d [i] AAA with TACACS+ and RADIUS
5.1.d [ii] Local privilege authorization fallback
5.2 Network security
5.2.a Implement and troubleshoot switch security features
5.2.a [i] VACL, PACL
5.2.a [ii] Stormcontrol
5.2.a [iii] DHCP snooping
5.2.a [iv] IP source-guard
5.2.a [v] Dynamic ARP inspection
5.2.a [vi] port-security
5.2.a [vii] Private VLAN
5.2.b Implement and troubleshoot router security features
5.2.b [i] IPv4 access control lists [standard, extended, time-based]
5.2.b [ii] IPv6 traffic filter
5.2.b [iii] Unicast reverse path forwarding
5.2.c Implement and troubleshoot IPv6 first hop security
5.2.c [i] RA guard
5.2.c [ii] DHCP guard
5.2.c [iii] Binding table
5.2.c [iv] Device tracking
5.2.c [v] ND inspection/snooping
5.2.c [vii] Source guard
5.2.c [viii] PACL
5.2.d Describe 802.1x
5.2.d [i] 802.1x, EAP, RADIUS
5.2.d [ii] MAC authentication bypass
6.0 Infrastructure Services 15%

6.1 System management
6.1.a Implement and troubleshoot device management
6.1.a [i] Console and VTY
6.1.a [ii] telnet, HTTP, HTTPS, SSH, SCP
6.1.a [iii] [T]FTP
6.1.b Implement and troubleshoot SNMP
6.1.b [i] v2c, v3
6.1.c Implement and troubleshoot logging
6.1.c [i] Local logging, syslog, debug, conditional debug
6.1.c [ii] Timestamp
6.2 Quality of service
6.2.a Implement and troubleshoot end-to-end QoS
6.2.a [i] CoS and DSCP mapping
6.2.b Implement, optimize and troubleshoot QoS using MQC
6.2.b [i] Classification
6.2.b [ii] Network based application recognition [NBAR]
6.2.b [iii] Marking using IP precedence, DSCP, CoS, ECN
6.2.b [iv] Policing, shaping
6.2.b [v] Congestion management [queuing]
6.2.b [vi] HQoS, sub-rate ethernet link
6.2.b [vii] Congestion avoidance [WRED]
6.2.c Describe layer 2 QoS
6.2.c [i] Queuing, scheduling
6.2.c [ii] Classification, marking
6.3 Network services
6.3.a Implement and troubleshoot first-hop redundancy protocols
6.3.a [i] HSRP, GLBP, VRRP
6.3.a [ii] Redundancy using IPv6 RS/RA
6.3.b Implement and troubleshoot network time protocol
6.3.b [i] NTP master, client, version 3, version 4
6.3.b [ii] NTP Authentication
6.3.c Implement and troubleshoot IPv4 and IPv6 DHCP
6.3.c [i] DHCP client, IOS DHCP server, DHCP relay
6.3.c [ii] DHCP options
6.3.c [iii] DHCP protocol operations
6.3.c [iv] SLAAC/DHCPv6 interaction
6.3.c [v] Stateful, stateless DHCPv6
6.3.c [vi] DHCPv6 prefix delegation
6.3.d Implement and troubleshoot IPv4 network address translation
6.3.d [i] Static NAT, dynamic NAT, policy-based NAT, PAT
6.3.d [ii] NAT ALG
6.3.e Describe IPv6 network address translation
6.3.e [i] NAT64
6.3.e [ii] NPTv6
6.4 Network optimization
6.4.a Implement and troubleshoot IP SLA
6.4.a [i] ICMP, UDP, Jitter, VoIP
6.4.b Implement and troubleshoot tracking object
6.4.b [i] Tracking object, tracking list
6.4.b [ii] Tracking different entities [e.g. interfaces, routes, IPSLA, and such]
6.4.c Implement and troubleshoot netflow
6.4.c [i] Netflow v5, v9
6.4.c [ii] Local retrieval
6.4.c [iii] Export [configuration only]
6.4.d Implement and troubleshoot embedded event manager
6.4.d [i] EEM policy using applet
6.4.e Identify performance routing [PfR]
6.4.e [i] Basic load balancing
6.4.e [ii] Voice optimization



QUESTION 1
Refer to the exhibit.

If you change the Spanning Tree Protocol from pvst to rapid-pvst, what is the effect on the
interface Fa0/1 port state?
A. It transitions to the listening state, and then the forwarding state.
B. It transitions to the learning state and then the forwarding state.
C. It transitions to the blocking state, then the learning state, and then the forwarding state.
D. It transitions to the blocking state and then the forwarding state.
Answer: C
Explanation:

QUESTION 2
Refer to the exhibit.

Which configuration is missing that would enable SSH access on a router that is running Cisco
IOS XE Software?
A. int Gig0/0/0
management-interface
B. class-map ssh-class
match access-group protect-ssh
policy-map control-plane-in
class ssh-class
police 80000 conform transmit exceed drop
control-plane
service-policy input control-plane-in
C. control-plane host
management-interface GigabitEthernet0/0/0 allow ssh
D. interface Gig0/0/0
ip access-group protect-ssh in
Answer: C
Explanation:

QUESTION 3
Which two options are causes of out-of-order packets? (Choose two.)
A. a routing loop
B. a router in the packet flow path that is intermittently dropping packets
C. high latency
D. packets in a flow traversing multiple paths through the network
E. some packets in a flow being process-switched and others being interrupt-switched on a transit
router
Answer: D,E
Explanation:

QUESTION 4
A TCP/IP host is able to transmit small amounts of data (typically less than 1500 bytes), but
attempts to transmit larger amounts of data hang and then time out. What is the cause of this
problem?
A. A link is flapping between two intermediate devices.
B. The processor of an intermediate router is averaging 90 percent utilization.
C. A port on the switch that is connected to the TCP/IP host is duplicating traffic and sending it to a
port that has a sniffer attached.
D. There is a PMTUD failure in the network path.
Answer: D
Explanation:

QUESTION 5
Refer to the exhibit.

ICMP Echo requests from host A are not reaching the intended destination on host B. What is the
problem?
A. The ICMP payload is malformed.
B. The ICMP Identifier (BE) is invalid.
C. The negotiation of the connection failed.
D. The packet is dropped at the next hop.
E. The link is congested.
Answer: D
Explanation:

Wednesday, 27 May 2015

4 new access points deliver super-fast Wi-Fi

Linksys, Xclaim, Amped and ZyXel bring 802.11ac to SMB, enterprise markets.
access points fast wifi 1

Access points put to the test
We put four new access points to the test, from Linksys, Xclaim, Amped and ZyXel, using the same test-bed and methods as our last review. The Linksys LAPAC1750PRO performed best in the throughput tests and was a feature-rich product. The Amped Wireless AP was a close second in the speed tests and is a solid business-class access point. The Xclaim unit did well given it’s only a two stream (2x2) AP. The ZyXEL unit was last in throughput, but has a number of advanced features in the areas of configuration, management and security. (Read our full review.)

Amped Wireless APR175P
Targeted at the SMB market, the Amped Wireless APR175P bills itself as a high-power long range access point. Priced at $299.99, it is a dual-band three stream (3x3) 802.11ac AP, offering theoretical data rates up to 1,300Mbps for 802.11ac. In our testing, the maximum throughput was 335.6Mbps. This is the only access point in the review that sports external antennas, which provides for either ceiling or wall mounting. In addition to the three external antenna, it has six high power amplifiers and six wireless reception (low noise) amplifiers.

This access point is the only one in the review that supports a router mode. Additionally, it's the only one that specifically touts being long range and high-power at 500mW output. The built-in controller functionality supports the central management of up to seven access points. This access point allows you to create up to 32 SSIDs with VLAN support. This unit offers load balancing and an intrusion detection system (when in router mode). It also offers an internal RADIUS server supporting the PEAP and TLS methods of 802.1X authentication, enabling the use of the Enterprise mode of WPA2 security.

Linksys LAPAC1750PRO
The Linksys LAPAC1750PRO is targeted towards small and midsized businesses (SMBs) and is priced at $499.99. It is a dual-band three stream (3x3) 802.11ac AP, offering theoretical data rates up to 1,300Mbps for 802.11ac. In our testing, it maxxed out at 436.3Mbps. Inside the unit are three 4.4 dBi internal antennas for 2.4GHz and three 5.2 dBi gain antennas for 5GHz. On the back of the unit are two PoE Gigabit Ethernet ports (one with PoE), AC power jack, and a small reset button.
access points fast wifi 5

When using the Cluster feature, you can centrally manage up to 16 access points using the built-in controller functionality. Once you enable the clustering feature on one access point, others access points will join that cluster. You can centrally change the configuration settings of the cluster via any access point in the cluster. This unit supports the use of up to 16 SSIDs with VLAN support. In addition to traditional AP mode, you can use the unit in WDS and workgroup bridge modes. Its Captive Portal feature supports guest, local, and external RADIUS authentication and can do URL redirection upon authentication. This access point supports rogue AP detection, band steering, and beamforming. It also has basic load balancing functionality.

Xclaim Xi-3
The Xclaim Xi-3 from Ruckus Wireless retails for $199 and is targeted towards small businesses and small office/home office (SOHO) environments and to the non-IT users. It's the only two stream (2x2) AP in this review, thus naturally offering lower maximum data rates than the other APs: up to 867Mbps for 802.11ac. It hit 315.7 Mbps in our testing. The Xclaim unit has a look and feel between a consumer router and a business access point. On the back/bottom of the access point you'll find one PoE LAN port, a secondary Ethernet port, small reset button, and an AC power jack. On the back/bottom of the Xclaim AP are the typical AP ports and buttons.

Unlike most other business-class products, this unit is primarily designed to be setup and managed via a mobile app, called Harmony for Xclaim. This unit only provides the traditional AP mode; no WDS or wireless bridging supported. The built-in controller functionality offers central management via the mobile app with a recommended maximum of 10 APs. You can create up to four SSIDs per access point with VLAN support. As far as advanced features, the unit has band steering, an enhanced QoS functionality called automatic traffic prioritization, and a feature called airtime fairness to help curve the negative impact from older or slower devices.

ZyXEL WAC6503D-S
The ZyXel WAC6503D-S, priced at $899, is targeted towards the enterprise-level market. It is a three stream (3x3) 802.11ac AP and offers theoretical data rates up to 1,300Mbps for 802.11ac. However, in our testing, it only reached 232.6Mbps. The unit is designed for ceiling mounting, with the smoke detector look and feel.

On the front/top of the AP you'll find seven LED status lights. On the back/bottom you'll find three Ethernet ports: PoE port for uplink, secondary LAN port, and one for console access. You'll find a small reset button and AC power jack as well.

A separate NXC Series WLAN controller is required for full central management capabilities. In addition to the regular AP mode, this access point supports WDS and a monitor mode for rogue access point detection. This ZyXEL AP supports up to 16 SSIDs with VLAN support. It has load balancing and band steering functionality. This AP series has what the company calls its Smart Antenna technology, which dynamically chooses the best of more than 700 antenna patterns to use for transmitting to individual clients

Included free of charge is the ZyXEL Wireless Optimizer (ZWO) software, which is a mapped-based Wi-Fi simulation, planning, and surveying tool.




13 must-have security tools

13 must-have security tools
The experts weigh in on their top picks for protecting enterprise networks.

Security tools
Network World asked security pros to name their No. 1, must-have, go-to security tool. We received responses from industry analysts, enterprise security practitioners, academics, and members of industry associations. Many of the experts we interviewed pointed out that there is no silver bullet when it comes to security, so your best bet is a defense in depth strategy that combines as many of these approaches as possible. Read the full story.

SysInternals and Windows GodMode
Ron Woerner, director of CyberSecurity Studies at Bellevue University: "There are certain things all network, IT, and security professionals should have in their toolbag. The most important is knowledge; i.e., where to learn more about a particular topic, technique, or tool. It’s impossible to know everything; so focus on where to get quality instruction and information."

Woerner recommends two websites: www.howtogeek.com and blogs.msdn.com/ for reference; and two toolkits: SysInternals and Windows GodMode. The former is a grouping of simple Windows tools and the latter is administration applications already available in the Control Panel.

Microsoft EMET
Yier Jin, assistant professor of computer science and electrical engineering at the University of Central Florida, says knowledge is the key. "I would say cybersecurity awareness is the one, best tool. Many breaches are caused by internal workers who lack cybersecurity awareness and; therefore, click links from spam email, which often initiates the breach. For tools, I recommend Microsoft Enhanced Mitigation Emergency Toolkit (EMET), an excellent toolkit that every company should have."

Secure@Source, Q-Radar, ArcSight, Splunk
Jeff Northrop, CTO at International Association of Privacy Professionals, uses the term data security intelligence to describe tools that help IT understand their data landscape. "Currently, we have business intelligence tools, data integration tools, data discovery tools, data encryption tools, compliance tools, and SIEM tools. All require an understanding of what data is collected; where it's located; how it's structured, categorized, and used. Most vendors operate in one or two of these areas; but a few companies have recognized a need for better information on the data they're responsible for protecting; extending their products to meet this need." Northrop lists Informatica’s Secure@Source; IBM’s Q-Radar, HP’s ArcSight, and Splunk.

Insider threat protection
Mike Papay, vice president and CISO at Northrop Grumman says, "In the context of destructive malware and insider-enabled data loss, businesses should invest in security tools that protect from the inside out. Similar to a broken windows policing strategy, security tools that can baseline, and then detect and alert on anomalies in network and client behavior helps businesses mitigate problem-activity early in the threat cycle.”
Privileged identity management

Privileged identity management
"I recommend Privileged Identity Management (PIM) tools that control the administrative password and, in some cases, shared business passwords and credentials," says Andras Cser, vice president and principal security/risk analyst at Forrester. "These tools are absolutely critical to ent data breaches by making always-on system administrator access to on-premises and cloud workloads a thing of the past. PIM tools check out and change passwords for critical workloads, which makes attackers' snooped administrator and root passwords worthless. Also, PIM (generally) enforces close monitoring and recording of all programmatic and/or human administrative access to machines."

Patch management
"There are three tools that all companies should have," says Gary Hayslip, deputy director and CISO for the City of San Diego, "patch management, data backup, and full disk encryption. These tools provide the basic cyber-hygiene foundation, which enables companies to continue to grow safely and respond to incidents. Then, as the revenue stream increases, they can add more security controls to the organization. If I had to choose just one, I'd say patch management. Having a patch management solution in place reduces risk exposure to the organization by keeping its IT assets up-to-date, which makes it harder for the bad guys. However, there's no guarantee that any, one solution will resolve all issues."

Cyphort
David Giambruno, senior vice president and CIO at Tribune Media, suggests that enterprises should move toward the concept of a software defined data center. "We're using VMware’s solution stack for its micro-segmentation capabilities—summarized as security at the element layer," he says. "Historically, this was incredibly challenging with hardware but, in the software world—where everything is a file—you can wrap everything with a security posture. Security follows wherever the element goes either internal or external. The audit-ability, operational automation, and visibility changes defensive capabilities." Giambruno deployed Cyphort for its capabilities to see east/west traffic in the cloud.

Bluebox
"One interesting new area is using technology to provide a layer between the user and SaaS solutions, so the enterprise can manage authentication and encryption and hold its keys, while maintaining close-to-full functionality with the software as a service (SaaS) solution," says Dr. John D. Johnson, global security strategist and security architect for John Deere. "There are also new solutions for cloud file storage and sync (like Box) that add encryption, data loss protection, and granular reports." For BYOD, he recommends products that keep corporate data in a container and ent it from moving, such as Bluebox, which puts a flexible walled garden around certain data and apps, and applies corporate rules.

Endpoint detection and response
Neil MacDonald, vice president and distinguished analyst at Gartner, advises clients to first remove administrative rights from Windows users, then invest in an endpoint detection and response (EDR) solution that continuously monitors and analyzes the state of the endpoint for indications of compromise. MacDonald emphasizes that EDR solutions provide continuous visibility that, when combined with continuous analytics, can help enterprises shorten the time that an attack goes undetected "For server workloads, I’d replace anti-malware scanning with an application-control solution to ent the execution of all unauthorized code, which keeps the vast majority of malware off the system and, also, reinforces good operational and change management hygiene.

FireEye
Randy Marchany, IT security lab director & security officer at Virginia Tech, says the flaw with static perimeter defense is that most organizations focus on inbound traffic rather than outbound traffic. Continuous Monitoring , also known as Network Security Monitoring or Extrusion Detection, focuses on traffic and log analysis. He recommends the FireEye Malware Detection appliance, Netflow data (which provides invaluable information that determines if internal machines have been compromised), and tools such as ARGUS Software, SiLK , the System for Internet-Level Knowledge, a collection of traffic analysis tools developed by the CERT Network Situational Awareness Team, and/or the Bro network security analyzer.

Advanced security analytics
Johna Till Johnson, CEO at Nemertes Research, recommends Advanced Security Analytics (ASA), which provide real-time insight into—and, increasingly, proactive responses to—situations that indicate a potential breach, compromise, or vulnerability. ASA merges security event/incident management and monitoring (SEIM) with analytical capabilities often derived from Big Data technologies. It also includes forensics and Intrusion Detection Systems/Intrusion ention Systems. Johnson recommends tools from vendors such as Agiliance, Blue Coat, Damballa, FireEye, Guidance, HP ArcSight, IBM, Lastline, LogRhythm, McAfee/Intel, and Splunk.

Collaboration Tools
"My vote for security's best option is collaboration tools. Yes, we have plenty of silver bullets; what we really need are more tools that allow communication and collaboration for our distributed workforce. We need to capture tribal knowledge to make staff more effective. We need to invest in tools that make staff more agile," says Rick Holland, principal security/risk analyst at Forrester Research.

Threat Intelligence
Frank Kim, CISO at the SANS Institute, believes security capabilities that detect attackers and anomalous activity are even more important in the face of advanced threats which bypass traditional, entative mechanisms. As a result, threat intelligence and robust information sharing are key aspects of modern cyber defense. But it's also about advanced analytics and the ability to mine internal and external sources of data. Building a data science capability to intelligently analyze large amounts of information provides organizations with actionable information that allows security teams to respond more quickly.



Monday, 25 May 2015

350-018 CCIE Security

350-018 CCIE Security

CCIE Security
Exam Number 350-018 CCIE Security
Associated Certifications CCIE Security
Duration 120 minutes (90 - 110 questions)

Exam Description
The Cisco CCIE® Security Written Exam (350-018) version 4.0 is a 2-hour test with 90–110 questions. This exam tests the skills and competencies of security professionals in terms of describing, implementing, deploying, configuring, maintaining, and troubleshooting Cisco network security solutions and products, as well as current industry best practices and internetworking fundamentals.

Topics include networking fundamentals and security-related concepts and best practices, as well as Cisco network security products and solutions in areas such as VPNs, intrusion prevention, firewalls, identity services, policy management, and device hardening. Content includes both IPv4 and IPv6 concepts and solutions.

The exam is closed book, and no outside reference materials are allowed.

The following topics are general guidelines for the content likely to be included on the exam. However, other related topics may also appear on any specific delivery of the exam. In order to better reflect the contents of the exam and for clarity purposes, the guidelines below may change at any time without notice.

1.0 Infrastructure, Connectivity, Communications, and Network Security 20%
1.1 Network addressing basics
1.2 OSI layers
1.3 TCP/UDP/IP protocols
1.4 LAN switching (for example, VTP, VLANs, spanning tree, and trunking)
1.5 Routing protocols (for example, RIP, EIGRP, OSPF, and BGP)
1.5.a Basic functions and characteristics
1.5.b Security features
1.6 Tunneling protocols
1.6.a GRE
1.6.b NHRP
1.6.c IPv6 tunnel types
1.7 IP multicast
1.7.a PIM
1.7.b MSDP
1.7.c IGMP and CGMP
1.7.d Multicast Listener Discovery
1.8 Wireless
1.8.a SSID
1.8.b Authentication and authorization
1.8.c Rogue APs
1.8.d Session establishment
1.9 Authentication and authorization technologies
1.9.a Single sign-on
1.9.b OTPs
1.9.c LDAP and AD
1.9.d RBAC
1.10 VPNs
1.10.a L2 vs L3
1.10.b MPLS, VRFs, and tag switching
1.11 Mobile IP networks

2.0 Security Protocols 15%
2.1 RSA
2.2 RC4
2.3 MD5
2.4 SHA
2.5 DES
2.6 3DES
2.7 AES
2.8 IPsec
2.9 ISAKMP
2.10 IKE and IKEv2
2.11 GDOI
2.12 AH
2.13 ESP
2.14 CEP
2.15 TLS and DTLS
2.16 SSL
2.17 SSH
2.18 RADIUS
2.19 TACACS+
2.20 LDAP
2.21 EAP methods (for example, EAP-MD5, EAP-TLS, EAP-TTLS, EAP-FAST, PEAP, and LEAP)
2.22 PKI, PKIX, and PKCS
2.23 IEEE 802.1X
2.24 WEP, WPA, and WPA2
2.25 WCCP
2.26 SXP
2.27 MACsec
2.28 DNSSEC

3.0 Application and Infrastructure Security 10%
3.1 HTTP
3.2 HTTPS
3.3 SMTP
3.4 DHCP
3.5 DNS
3.6 FTP and SFTP
3.7 TFTP
3.8 NTP
3.9 SNMP
3.10 syslog
3.11 Netlogon, NetBIOS, and SMB
3.12 RPCs
3.13 RDP and VNC
3.14 PCoIP
3.15 OWASP
3.16 Manage unnecessary services

4.0 Threats, Vulnerability Analysis, and Mitigation 10%
4.1 Recognize and mitigate common attacks
4.1.a ICMP attacks and PING floods
4.1.b MITM
4.1.c Replay
4.1.d Spoofing
4.1.e Backdoor
4.1.f Botnets
4.1.g Wireless attacks
4.1.h DoS and DDoS attacks
4.1.i Virus and worm outbreaks
4.1.j Header attacks
4.1.k Tunneling attacks
4.2 Software and OS exploits
4.3 Security and attack tools
4.4 Generic network intrusion prevention concepts
4.5 Packet filtering
4.6 Content filtering and packet inspection
4.7 Endpoint and posture assessment
4.8 QoS marking attacks

5.0 Cisco Security Products, Features, and Management 20%
5.1 Cisco Adaptive Security Appliance (ASA)
5.1.a Firewall functionality
5.1.b Routing and multicast capabilities
5.1.c Firewall modes
5.1.d NAT (before and after version 8.4)
5.1.e Object definition and ACLs
5.1.f MPF functionality (IPS, QoS, and application awareness)
5.1.g Context-aware firewall
5.1.h Identity-based services
5.1.i Failover options
5.2 Cisco IOS firewalls and NAT
5.2.a CBAC
5.2.b Zone-based firewall
5.2.c Port-to-application mapping
5.2.d Identity-based firewalling
5.3 Cisco Intrusion Prevention Systems (IPS)
5.4 Cisco IOS IPS
5.5 Cisco AAA protocols and application
5.5.a RADIUS
5.5.b TACACS+
5.5.c Device administration
5.5.d Network access
5.5.e IEEE 802.1X
5.5.f VSAs
5.6 Cisco Identity Services Engine (ISE)
5.7 Cisco Secure ACS Solution Engine
5.8 Cisco Network Admission Control (NAC) Appliance Server
5.9 Endpoint and client
5.9.a Cisco AnyConnect VPN Client
5.9.b Cisco VPN Client
5.9.c Cisco Secure Desktop
5.9.d Cisco NAC Agent
5.10 Secure access gateways (Cisco IOS router or ASA)
5.10.a IPsec
5.10.b SSL VPN
5.10.c PKI
5.11 Virtual security gateway
5.12 Cisco Catalyst 6500 Series ASA Services Modules
5.13 ScanSafe functionality and components
5.14 Cisco Web Security Appliance and Cisco Email Security Appliance
5.15 Security management
5.15.a Cisco Security Manager
5.15.b Cisco Adaptive Security Device Manager (ASDM)
5.15.c Cisco IPS Device Manager (IDM)
5.15.d Cisco IPS Manager Express (IME)
5.15.e Cisco Configuration Professional
5.15.f Cisco Prime

6.0 Cisco Security Technologies and Solutions 17%
6.1 Router hardening features (for example, CoPP, MPP, uRPF, and PBR)
6.2 Switch security features (for example, anti-spoofing, port, STP, MACSEC, NDAC, and NEAT)
6.3 NetFlow
6.4 Wireless security
6.5 Network segregation
6.5.a VRF-aware technologies
6.5.b VXLAN
6.6 VPN solutions
6.6.a FlexVPN
6.6.b DMVPN
6.6.c GET VPN
6.6.d Cisco EasyVPN
6.7 Content and packet filtering
6.8 QoS application for security
6.9 Load balancing and failover

7.0 Security Policies and Procedures, Best Practices, and Standards 8%
7.1 Security policy elements
7.2 Information security standards (for example, ISO/IEC 27001 and ISO/IEC 27002)
7.3 Standards bodies (for example, ISO, IEC, ITU, ISOC, IETF, IAB, IANA, and ICANN)
7.4 Industry best practices (for example, SOX and PCI DSS)
7.5 Common RFC and BCP (for example, RFC2827/BCP38, RFC3704/BCP84, and RFC5735)
7.6 Security audit and validation
7.7 Risk assessment
7.8 Change management process
7.9 Incident response framework
7.10 Computer security forensics
7.11 Desktop security risk assessment and desktop security risk management




QUESTION 1
In order to reassemble IP fragments into a complete IP datagram, which three IP header fields are
referenced by the receiver? (Choose three.)

A. don't fragment flag
B. packet is fragmented flag
C. IP identification field
D. more fragment flag
E. number of fragments field
F. fragment offset field

Answer: C,D,F

Explanation:


QUESTION 2
Which VTP mode allows the Cisco Catalyst switch administrator to make changes to the VLAN
configuration that only affect the local switch and are not propagated to other switches in the VTP
domain?

A. transparent
B. server
C. client
D. local
E. pass-through

Answer: A

Explanation:


QUESTION 3
Which type of VPN is based on the concept of trusted group members using the GDOI key
management protocol?

A. DMVPN
B. SSLVPN
C. GETVPN
D. EzVPN
E. MPLS VPN
F. FlexVPN

Answer: C

Explanation:


QUESTION 4
Based on RFC 4890, what is the ICMP type and code that should never be dropped by the firewall
to allow PMTUD?

A. ICMPv6 Type 1 – Code 0 – no route to host
B. ICMPv6 Type 1 – Code 1 – communication with destination administratively prohibited
C. ICMPv6 Type 2 – Code 0 – packet too big
D. ICMPv6 Type 3 – Code 1 – fragment reassembly time exceeded
E. ICMPv6 Type 128 – Code 0 – echo request
F. ICMPv6 Type 129 – Code 0 – echo reply

Answer: C

Explanation:


QUESTION 5
A firewall rule that filters on the protocol field of an IP packet is acting on which layer of the OSI
reference model?

A. network layer
B. application layer
C. transport layer
D. session layer

Answer: A

Explanation:

Saturday, 16 May 2015

70-341: Core Solutions of Microsoft Exchange Server 2013

70-341: Core Solutions of Microsoft Exchange Server 2013
Published: 15 January 2013
Languages: English, Chinese (Simplified), French, German, Japanese, Portuguese (Brazil)
Audiences: IT professionals
Technology: Microsoft Exchange Server 2013
Credit towards certification: MCP, MCSE

Skills measured
This exam measures your ability to accomplish the technical tasks listed below. The percentages indicate the relative weight of each major topic area in the exam. The higher the percentage, the more questions you are likely to see on that content area in the exam.

From July 2014, the questions on this exam include content covering Microsoft Exchange Server 2013 Service Pack 1.

Please note that the questions may test on, but will not be limited to, the topics described in the bulleted text.

Plan, install, configure and manage transport (25%)

Plan a high availability solution for common scenarios

Set up redundancy for intra-site scenarios; plan for SafetyNet; plan for shadow redundancy; plan for redundant MX records

Design a transport solution

Design inter-site mail flow; design inter-org mail flow; plan for Domain Secure/TLS; design Edge transport; design message hygiene solutions; design shared namespace scenarios

Configure and manage transport

Configure Edge servers; configure Send/Receive connectors; configure transport rules; configure accepted domains; configure email policies; configure Address Rewriting

Troubleshoot and monitor transport

Interpret message tracking logs and protocol logs; troubleshoot a shared namespace environment; troubleshoot SMTP mail flow; given a failure scenario, predict mail flow and identify how to recover; troubleshoot Domain Secure/TLS; troubleshoot the new transport architecture

Configure and manage hygiene

Manage content filtering; manage recipient filtering; manage SenderID; manage connection filtering; manage Spam Confidence Level (SCL) thresholds; manage anti-malware

Preparation resources

Transport high availability
Use an Edge Transport Server in Exchange 2013
Hygiene management

Install, configure and manage the mailbox role (25%)

Plan the mailbox role

Plan for database size and storage performance requirements; plan for virtualisation requirements and scenarios; plan mailbox role capacity and placement; design public folder placement strategy; validate storage by running JetStress

Configure and manage the mailbox role

Create and configure Offline Address Book (OAB); create and configure public folders; deploy mailbox server roles; design and create hierarchical address lists

Deploy and manage high availability solutions for the mailbox role

Create and configure a Database Availability Group (DAG); identify failure domains; manage DAG networks; configure proper placement of a file share witness; manage mailbox database copies

Monitor and troubleshoot the mailbox role

Troubleshoot database replication and replay; troubleshoot database copy activation; troubleshoot mailbox role performance; troubleshoot database failures; monitor database replication and content indexing

Develop backup and recovery solutions for the mailbox role and public folders

Manage lagged copies; determine most appropriate backup solution/strategy; perform a dial tone restore; perform item-level recovery; recover the public folder hierarchy; recover a mailbox server role

Create and configure mail-enabled objects

Configure resource mailboxes and scheduling; configure team mailboxes; configure distribution lists; configure moderation; configure a linked mailbox

Manage mail-enabled object permissions

Configure mailbox folder permissions; configure mailbox permissions; set up room mailbox delegates; set up team mailbox membership; set up auto-mapping; determine when to use Send As and Send On Behalf permissions

Preparation resources

Mailbox server
Database availability groups
Perform a dial tone recovery

Plan, install, configure and manage client access (25%)

Plan, deploy and manage a Client Access Server (CAS)

Design to account for differences between legacy CAS and Exchange CAS/CAF; configure Office web application

Plan and configure namespaces and client services

Design namespaces for client connectivity; configure URLs; plan for certificates; configure authentication methods; implement auto-discover for a given namespace

Deploy and manage mobility solutions

Deploy OWA for Devices; configure OWA policies; configure mobile device mailbox policies; configure Allow Block Quarantine (ABQ); deploy and manage Office Apps

Implement load balancing

Configure namespace load balancing; configure Session Initiation Protocol (SIP) load balancing; plan for differences between layer seven and layer four load balancing methods; configure Windows Network Load Balancing (WNLB)

Troubleshoot client connectivity

Troubleshoot Outlook Anywhere connectivity; troubleshoot POP/IMAP; troubleshoot authentication; troubleshoot web services; troubleshoot AutoDiscover; troubleshoot mobile devices

Preparation resources

Client access server
Clients and mobile
Load balancing

Design and manage an Exchange infrastructure (25%)

Plan for impact of Exchange on Active Directory services

Plan the number of domain controllers; plan placement of Global Catalogue (GC); determine DNS changes required for Exchange; prepare domains for Exchange; evaluate impact of schema changes required for Exchange; plan around Active Directory site topology

Administer Exchange workload management

Configure user workload policies; configure system workload policies; monitor system workload events; monitor user workload events

Plan and manage Role Based Access Control (RBAC)

Determine appropriate RBAC roles and cmdlets; limit administration using existing role groups; evaluate differences between RBAC and Active Directory split permissions; configure a custom-scoped role group; configure delegated setup

Design an appropriate Exchange solution for a given SLA

Plan for updates; plan for change management; design a solution that meets SLA requirements around scheduled downtime; design a solution that meets SLA requirements around RPO/RTO; design a solution that meets SLA requirements around message delivery

Preparation resources

Prepare Active Directory and domains
Exchange workload management
Planning for role-based access control




QUESTION 1
You need to prepare the environment for the implementation of phase 1.
What changes must be made to the environment before you can install Exchange Server 2013?

A. The operating system or service pack level of TexDC1 needs to be upgraded.
B. The Windows 2008 R2 domain controllers in Washington and Boston need to be upgraded.
C. A server running Exchange Server 2007 or Exchange Server 2010 needs to be installed in
Texas.
D. The PDC emulator role needs to be transferred to a domain controller in Washington or Boston.

Answer: A

Explanation:


QUESTION 2
You are evaluating whether the proposed Exchange solution will meet the current and future
capacity requirements.
You want to gather statistics about the current Exchange environment.
Which of the following tools would you use to determine the number of emails sent to and received
by the current users?

A. Remote Server Administration Tools.
B. Microsoft Exchange Server Profile Analyzer.
C. Microsoft Exchange Server Deployment Assistant.
D. ESEUtil.exe.
E. Microsoft Exchange Server Jetstress.

Answer: B

Explanation:


QUESTION 3
You need to apply the required size restriction to the mailboxes in the new environment.
Which of the following commands should you run?

A. Get-MailboxDatabase | Set-MailboxDatabase –ProhibitSendReceiveQuota
B. Get-MailboxDatabase | Set-Mailbox –ProhibitSendReceiveQuota
C. Get-Mailbox | Set-Mailbox –ProhibitSendReceiveQuota
D. Get-MailboxDatabase | Get-Mailbox | Set-Mailbox –ProhibitSendReceiveQuota

Answer: A

Explanation:


QUESTION 4
You are evaluating whether the proposed Exchange solution will meet the current and future
capacity requirements.
You want to gather statistics about the current Exchange environment.
Which of the following tools would you use to determine the number of IOPS (Input/Output
Operations Per Second) required for the mailbox database storage?

A. ESEUtil.exe.
B. Microsoft Exchange Server Jetstress.
C. Microsoft Exchange Server Deployment Assistant.
D. Exchange Mailbox Server Role Requirements Calculator.
E. SQL Server Analysis Services.

Answer: D

Explanation:


QUESTION 5
You need to install and configure anti-spam and antimalware filtering.
Which servers should you install the anti-spam agents and enable the anti-spam and antimalware
filtering? (Choose two).

A. You should install the anti-spam agents on the Client Access Servers only.
B. You should install the anti-spam agents on the Mailbox serversonly.
C. You should install the anti-spam agents on the Client Access Servers and the Mailbox Servers.
D. You should enable antimalware filtering on the Client Access Serversonly.
E. You should enable antimalware filtering on the Mailbox serversonly.
F. You enable antimalware filtering on the Client Access Servers and the Mailbox Servers.

Answer: B,E

Explanation:

Wednesday, 29 April 2015

Microsoft to webcast Build keynote Wednesday morning

Two-and-a-half hour presentation begins at 8:30 a.m. PT, 11:30 a.m. ET

Microsoft will live stream the opening keynote address of its Build developers conference on Wednesday starting at 8:30 PT (11:30 ET).

The webcast can be viewed from the Build news website and Microsoft's Channel 9.

Microsoft, as usual, has not listed the keynote speakers, but undoubtedly CEO Satya Nadella will participate -- probably as the opening act before handing off demos and other bits to executives like Terry Myerson, who leads the operating systems group; Joe Belfiore, chief of Windows' design; and Julie White, lead on Office product management. Those three have been prominent speakers at recent Microsoft press events.

Build 2015 runs through Friday at San Francisco's Moscone Center, the locale for the third straight year.

Microsoft is expected to spend much of its time tomorrow talking up Windows 10 and the next generation of Office, both the semi-cloud Office 365 and the on-premises Office 2016, as well as development tools for apps on all three platforms. The Redmond, Wash. company will also probably tout -- again -- the benefits of creating desktop applications and mobile apps for Windows 10.

Microsoft has so far painted its Windows 10 monetization plan in only the broadest terms: Tomorrow would be a good time to have that conversation, as the company must persuade developers that it's in their financial interest to jump on the bandwagon.

It's possible that Microsoft will use the conference keynote to flesh out Windows 10, including a more specific release date. Other information, however, ranging from support timeline to details on the two update tempos offered enterprises, will probably be left for another day.

Executives typically focus on the topic at hand, in this case, development, rather than stray into those other subjects.

Build in general, and the keynote in particular, will be one of the most important pre-launch opportunities for Microsoft to make the Windows 10 case to the media and non-developer enthusiasts, not only for personal computers -- which have been in a sales slump since 2012's June quarter -- but also for mobile.

Gartner last month laid out Microsoft's problem when it estimated that Windows' device operating system share will slip slightly this year to 13.3%, and climb only a percentage point or so -- to 14.4% -- by the end of 2017.

Microsoft has scheduled the Build keynote to run two and a half hours.



Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com


Thursday, 9 April 2015

How Connecticut set itself up to be the first gigabit state

Connecticut is moving ahead with a statewide gigabit broadband initiative after resolving a surprisingly simple, but common, issue standing in the way of fiber deployment.

Connecticut needed this. Lately, the only noteworthy contribution my home state has made to the national news is Aaron Hernandez, an apparent psychopath who earned millions of dollars playing football while (allegedly) murdering anyone who looked at him the wrong way.

But it looks like the third smallest state in the country is on its way to becoming the first to offer ubiquitous 1-Gigabit internet to its residents. The website EfficientGov.com has a pretty comprehensive breakdown on the project: 46 municipalities that make up about half of the state's population have agreed to endorse a plan for public/private partnerships to expand 1-Gig broadband internet access.

The "pubic/private partnerships" part of the plan likely makes it more achievable. In other areas, attempts at municipal-run broadband projects have created mountains of debt in their worst cases and have led to heated legislative battles in their best.

Chattanooga, Tennessee, is a good example of how difficult municipal broadband can be. The city's broadband is among the fastest in the country, and its network was built and operated by the city after it had difficulty attracting investment from private ISPs. When the city looked to expand its 1-Gig service to other regions, state lawmakers imposed strict regulations, ultimately culminating in the state of Tennessee filing a lawsuit against the FCC late last month.

The Connecticut State Broadband Initiative attempts to side step the messy political issues by paving the way for private companies to lay the fiber throughout the state and allowing ISPs to use it to provide services.

"It's like building the road — and anyone can drive their cars on it," Connecticut's consumer counsel Elin Katz recently told Backchannel.

It's not always that simple, though. What's different about the Connecticut plan is how it handled what Backchannel contributor Susan Crawford called "the unbelievably difficult issue of attaching wires to poles." She briefly explained how Connecticut addressed this issue:

"Rather than letting pole owners hold up every requestor by creating delays and making demands for special payments (seriously: pole-attachment scuffles are the long-running soap operas of telecom), Connecticut requires pole owners to obey a Single Pole Administrator, adhere to uniform pricing agreements, and act to make way for new wires in a set time. Dramatic stuff. And Connecticut already had passed a statute giving municipalities the right to use a part of a pole, or 'gain,' for any purpose. These two elements made Connecticut an extremely attractive place to string a network."

In fact, the obstacles that pole owners can create for projects like fiber deployment have been well-documented. An article published last May at BroadbandLawAdvisor.com provides detailed instructions on how to deal with pole owners who maybe imposing "fees and charges that are not permitted or exceed permitted regulated levels."

The FCC's National Broadband Plan includes a section that warns that "delays can also result from existing attachers' action (or inaction) to move equipment to accommodate a new attacher, potentially a competitor." Basically, those who own the utility poles can levy fees on any company or organization that tries to work on them, or they can just flat out deny access. The FCC acknowledged that reform is needed in how access to poles is handled.

Connecticut may be an example of how to implement this reform. A Request for Qualifications issued in September explained how the state accomplished this:

"All the utility poles across the state are subject to the central statutory jurisdiction of the Connecticut Public Utilities Regulatory Authority," the RFQ read, according to BroadbandAndBreakfast.com. "The established and firm timelines for the entire pole attachment process that the Connecticut regulator has ordered and manages … thus facilitat[es] the deployment of broadband."

Of course, Connecticut faces the same kinds of pushback seen in the states that are embroiled in legal battles over municipal broadband, i.e. lobbyist groups highlighting the risks and occasionally stepping into propaganda territory to sway public opinion. But, as Backchannel's Crawford pointed out, the initiative has already garnered majority support in the state, and it is designed to facilitate competition between private companies, rather than to threaten competition from the state. When pro-business lobbyists argue against a pro-business plan, few people are going to bother listening.

Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com