when one of the tunnel peers has a dynamic IP address
when one of the tunnel peers wants to force main mode to be used
when fragmentation of the IKE packet is required between the two peers
when one of the tunnel peers wants to specify a different phase 1 proposal
第1题:
When configuring a multipoint GRE (mGRE) tunnel interface, which one of the following is NOT a valid configuration option:()
第2题:
Which of the following is true when considering the Server load-balancing design within the E-Commerce Module of the Enterprise Campus network?()
第3题:
Two VPN peers are negotiating IKE phase 1 using main mode. Which message pair in the negotiation contains the phase 1 proposal for the peers?()
第4题:
For the following items ,which one can be used to authenticate the IPsec peers during IKE Phase 1?()
第5题:
Which of the following explains the relationship between a physical and logical partition?()
第6题:
For IKE phase 1 negotiations, when is aggressive mode typically used?()
第7题:
Which attribute is required for all IKE phase 2 negotiations?()
第8题:
mode configuration
the VPN client establishment of an ISAKMP SA
IPsec quick mode completion of the connection
VPN client initiation of the IKE phase 1 process
第9题:
Routed mode requires the ACE run OSPF or EIGRP
Bridged mode switches a packet between the public and the private subnets when it sees itsMAC address as the destination
Two-armed mode will place the SLB inline to the servers, with different client-side and a server-side VLANs
One-armed mode, which uses the same VLAN for the client, the ACE, and the servers, requiresa traffic-diversion mechanism to ensure the traffic return from the server passes though the ACE
第10题:
The crypto ACL number
The IPSEC mode (tunnel or transport)
The GRE tunnel interface IP address
The GRE tunnel source interface or IP address, and tunnel destination IP address
The MTU size of the GRE tunnel interface
第11题:
To ensure the router has the correct time when generating its private/public key pairs.
To ensure the router has the correct time when checking certificate validity from the remote peers
To ensure the router time is sync with the remote peers for encryption keys generation
To ensure the router time is sync with the remote peers during theDH exchange
To ensure the router time is sync with the remote peers when generating the cookies during IKE phase 1
第12题:
when one of the tunnel peers has a dynamic IP address
when one of the tunnel peers wants to force main mode to be used
when fragmentation of the IKE packet is required between the two peers
when one of the tunnel peers wants to specify a different phase 1 proposal
第13题:
IPSec VPN is a widely-acknowledged solution for enterprise network. Which three IPsec VPNstatements are true?()
第14题:
You need to configure a GRE tunnel on a IPSec router. When you are using the SDM to configurea GRE tunnel over IPsec, which two parameters are required when defining the tunnel interfaceinformation?()
第15题:
A policy-based IPsec VPN is ideal for which scenario?()
第16题:
Why is NTP an important component when implementing IPSec VPN in a PKI environment?()
第17题:
Which two statements are true about L2TP tunnel switching?()
第18题:
An IPsec tunnel is established on an SRX Series Gateway on an interface whose IP address was obtained using DHCP.Which two statements are true? ()(Choose two.)
第19题:
A route-based VPN is required for which scenario?()
第20题:
message 1 and 2
message 3 and 4
message 5 and 6
message 7 and 8
第21题:
proxy-ID
preshared key
Diffie-Hellman group key
main or aggressive mode
第22题:
tunnel source
tunnel destination
tunnel key
ip address
tunnelvrf
第23题:
pre-shared key
integrity check value
XAUTH
Diffie-Hellman Nonce
第24题:
IKE keepalives are unidirectional and sent every ten seconds
IPsec uses the Encapsulating Security Protocol (ESP) or the Authentication Header (AH)protocol for exchanging keys
To establish IKE SA, main mode utilizes six packets while aggressive mode utilizes only threepackets
IKE uses the Diffie-Hellman algorithm to generate symmetrical keys to be used by IPsec peers