Header
Home | Set as homepage | Add to favorites
  Search the Site     » Advanced Search
Sections
Syndication


Blogroll:

||||| ALL Cisco-Network ARTICLES |||||  
CCIE Journey,
The CCIE Journey,


Cisco IOS IPSec Certificate Authority Support Questions Answers

Oct 02,2009 by alperen

image

Questions

1. 

A digital certificate is conceptually most like which type of document?

  1. Event admission ticket

  2. Vehicle license plate

  3. Passport

  4. Social Security card


2. 

Which of the following is not a common name for a database service running on an existing or dedicated server that allows users to submit and retrieve digital certificates?

  1. Certificate server

  2. CRL

  3. Cert server

  4. Key server


3. 

What does the acronym PKI stand for?

  1. PIX Key Interchange

  2. Private Key Interchange

  3. Public Key Infrastructures

  4. PIX Key Interface


4. 

Digital certificates are generated by which of the following?

  1. Sending peer

  2. Certificate authority

  3. Receiving peer

  4. The government


5. 

When checking a certificate against a CRL, what happens if a match occurs?

  1. The certificate is accepted

  2. A new CRL is requested

  3. The certificate is rejected

  4. The request is sent to the CA


6. 

Which of the following is a server that acts as a proxy for the CA, so CA functions can continue when the CA is offline or otherwise unavailable?

  1. CRL

  2. CAR

  3. CA

  4. RA


7. 

Which of the following is an initiative for furthering open development for certificate-handling protocols that can help ensure interoperability with devices from many vendors?

  1. PKI

  2. CA

  3. LDAP

  4. SCEP


8. 

Which of the following is not a CA provider supported by the Cisco IOS?

  1. Entrust Technologies, Inc.

  2. Symantic

  3. VeriSign

  4. Microsoft


9. 

Which is the IKE keyword for CA support authentication method?

  1. rsa-sig

  2. pki

  3. rsa-encr

  4. preshare


10. 

Which command specifies that certificates and CRLs should not be stored locally, but should be retrieved from the CA as needed?

  1. no ntp peer ip-address

  2. crypto key generate rsa

  3. crypto ca identity

  4. crypto ca certificate query


11. 

In the following command, what does the word “six” represent?

Rtr1(config)#clock timezone CST -6 
  1. The number six is a sequence number

  2. Six hours behind NY standard time

  3. Six hours behind UTC/GMT

  4. Six hours ahead of UTC/GMT


12. 

Given the following command, how many RSA key pairs will be generated?

Rtr1(config)#crypto key generate rsa usage-keys
  1. 1

  2. 2

  3. 3

  4. 4


13. 

Which command is used to define the CA?

  1. crypto ca enroll

  2. crypto ca identity

  3. crypto ca authenticate

  4. crypto key zeroize rsa


14. 

Which command removes all certificates associated with the CA—the router’s certificate, the CA certificate, and any RA certificates?

  1. no named-key key-name

  2. no crypto ca identity

  3. crypto key zeroize rsa

  4. no certificate


15. 

Which of the following is not required for CA support on Cisco IOS devices?

  1. Hostname defined

  2. Special-usage keys ordered

  3. Domain name defined

  4. Software clock set


Answers

1. 

C. Passport

2. 

B. CRL

3. 

C. Public Key Infrastructures

4. 

B. Certificate authority

5. 

C. The certificate is rejected—it has been revoked

6. 

D. RA

7. 

D. SCEP—Simple Certificate Enrollment Protocol

8. 

B. Symantic

9. 

A. rsa-sig

10. 

D. crypto ca certificate query

11. 

C. Six hours behind UTC/GMT

12. 

B. 2

13. 

B. crypto ca identity

14. 

B. no crypto ca identity

15. 

B. Special-usage keys ordered


531 times read

Related news

» Step 2–6 Authenticate the CA
by alperen posted on Sep 29,2009
» Step 2–9 Monitor and Maintain CA Interoperability (Optional)
by alperen posted on Sep 29,2009
» Step 2–1 Manage the NVRAM Memory Usage (Optional)
by alperen posted on Sep 29,2009
» Cisco IOS IPSec Certificate Authority Support Review
by alperen posted on Oct 02,2009
» Step 2–7 Request Your Own Certificate
by alperen posted on Sep 29,2009
Did you enjoy this article?
(total 0 votes)

comment Comments (0 posted) 

More Top News
CCSP-Cisco Certified Security Professional
Most Popular
Most Commented
Featured Author