mode configuration
the VPN client establishment of an ISAKMP SA
IPsec quick mode completion of the connection
VPN client initiation of the IKE phase 1 process
第1题:
Which three statements about the Cisco Easy VPN feature are true?()
第2题:
During the Easy VPN Remote connection process,which phase involves pushing the IP address, Domain Name System (DNS),and split tunnel attributes to the client?()
第3题:
Which command is needed to change this policy to a tunnel policy for a policy-based VPN?() [edit security policies from-zone trust to-zone untrust] user@host# show policy tunnel-traffic { match { source-address local-net; destination-address remote-net; application any; then { permit; } }
第4题:
An Enterprise customer wants to reduce the configuration effort for their Teleworker router deployments. What is one way to simplify the IPSec-related configuration in the remote routers?()
第5题:
Which of the following protocols would MOST likely be used in the establishment of an IPSec VPN tunnel?()
第6题:
Which three security concerns can be addressed by a tunnel mode IPsec VPN secured by ESP?()
第7题:
Enable the VPN connection to use MS-CHAP.
Change the data encryption setting to Optional Encryption.
Specify a TCP/IP address in the network properties.
Change the IPSec policy setting to Client.
第8题:
data integrity
data confidentiality
data authentication
outer IP header confidentiality
outer IP header authentication
第9题:
data integrity
data confidentiality
data authentication
outer IP header confidentiality
outer IP header authentication
第10题:
RADIUS or LDAP
an internal router running EIGRP
Reverse Route Injection and OSPF or RIPv2
the VPN appliance to be deployed in line with the firewall
第11题:
RADIUS or LDAP
an internal router running EIGRP
Reverse Route Injection and OSPF or RIPv2
the VPN appliance to be deployed in line with the firewall
第12题:
A static route that points towards the Cisco Easy VPN server is created on the remote client.
A static route is created on the Cisco Easy VPN server for the internal IP address of each VPN client.
A default route is injected into the route table of the remote client.
A default route is injected into the route table of the Cisco Easy VPN server.
第13题:
What will an Easy VPN hardware client require in order to insert its protected network address when it connects using network extension mode?()
第14题:
When using the Cisco SDM Quick Setup Siteto-Site VPN wizard, which three parameters do you configure?()
第15题:
Which statement describes Reverse Route Injection (RRI)?()
第16题:
Which of the following protocols would MOST likely be used in the establishment of an IPSec VPN tunnel?()
第17题:
Which three security concerns can be addressed by a tunnel mode IPsec VPN secured by AH?() (Choose three.)
第18题:
You want to configure your Windows 2000 Professional computer to remotely access your company’s Windows 2000 routing and remote access server. You configure a VPN connection. For security purposes, you configure the VPN connection to use MS-CHAP v2 only and to require encryption. You also configure TCP/IP to obtain an IP address automatically, to enable IPSec, and to set IPSec to secure server. When you try to connect, you receive the following error message, “The encryption attempt failed because no valid certificate was found.” What should you do to connect to the server? ()
第19题:
Source interface where encrypted traffic originates
IP address for the remote peer
Transform set for the IPsec tunnel
Interface for the VPN connection
第20题:
set policy tunnel-traffic then tunnel remote-vpn
set policy tunnel-traffic then permit tunnel remote-vpn
set policy tunnel-traffic then tunnel ipsec-vpn remote-vpn permit
set policy tunnel-traffic then permit tunnel ipsec-vpn remote-vpn
第21题:
AES
TKIP
802.1q
ISAKMP
第22题:
The Cisco Easy VPN Server feature and the Cisco software VPN client use the same GUI configuration tool to simplify remote-access VPN configurations.
The Cisco Easy VPN Server feature allows the Cisco software VPN client to receive its security policies from the central site VPN device. This minimizes the configuration requirements at the remote location for large remote access VPN deployments.
The Cisco Easy VPN Server feature and the Cisco software VPN client use hardware-based encryption to reduce the CPU overhead of the central site VPN router.
The Cisco Easy VPN Server feature and the Cisco software VPN client enable scalable remote-access VPNs deployment by using a thick client/thin server model where the central site VPN router can handle thousands of incoming VPN connections.
第23题:
CiscoWorks VPN Manager
deploy Linksys routers with menu-driven configuration
Easy VPN client mode
disable 802.1x and Auth Proxy on the Teleworker router