|
1. |
Which one of the following is not one
of the tasks required to configure IPSec for Preshared Keys?
-
Configure IPSec
-
Prepare for IKE and IPSec
-
Test and verify IPSec
-
Configure the crypto map |
|
|
2. |
Which of the following VPN products would be common for
mobile users?
-
Cisco 1700 router
-
Cisco 900 Cable/DSL router
-
Cisco VPN Software Client
-
Cisco VPN Hardware Client |
|
|
3. |
Which one of the following is a hybrid protocol that
implements the Oakley key exchange?
-
IPSec
-
Crypto map
-
IKE
-
Hash algorithm |
|
|
4. |
Which of the following is a peer authentication method?
-
3DES
-
SHA-1
-
MD5
-
Preshared keys |
|
|
5. |
Which of the following preparation steps is done using the
ping command?
-
Identify IPSec peers
-
Check the current configuration
-
Ensure the network works without encryption
-
Ensure access control lists are compatible with
IPSec |
|
|
6. |
Which one of the following is not an
IKE Phase 1 parameter?
-
Encryption algorithm
-
Traffic to protect
-
Authentication method
-
DH key exchange group |
|
|
7. |
To make sure the router ACLs are IPSec-compatible, which is
not required to be permitted?
-
Port 500
-
Port 510
-
Protocol 51
-
Protocol 50 |
|
|
8. |
If the crypto isakmp policy command were
used to create policies with the following priorities, which would be processed
first?
-
1000
-
500
-
12
-
25 |
|
|
9. |
If the crypto isakmp policy lifetime is set to 43,200, to
what does the 43,200 refer?
-
43,200 bytes of protected throughput
-
43,200 hours
-
half a day
-
43,200 lines of protected throughput |
|
|
10. |
Which command shows the IKE policies and default values?
-
show running-config
-
show isakmp policy
-
show crypto ike policy
-
show crypto isakmp policy |
|
|
11. |
A transform set can contain up to how many transforms?
-
4
-
6
-
3
-
1 |
|
|
12. |
Which is not a function of a crypto
ACL?
-
Define the dataflow to be protected by IPSec
-
Discard inbound traffic that should have been protected by
IPSec
-
Filter outbound traffic for access to the Internet
-
Define the data flow to pass unprotected by
IPSec |
|
|
13. |
Which of the following is not
true?
-
The crypto ACL determines the traffic to be protected
-
The global crypto map command ties
together the IPSec parameters
-
The interface crypto map command applies
the crypto map to an interface
-
The global crypto map policy command sets
the implementation priority |
|
|
14. |
Which command shows IPSec performance indicators?
-
show crypto map
-
show crypto ipsec sa
-
show crypto ipsec transform-set
-
show crypto isakmp policy |
|
|
15. |
Which statement is not true about the
ipsec-manual form of the crypto map command?
-
It doesn’t scale well
-
The result can be insecure because of difficulty in manually
creating secure keying material
-
It enhances the flexibility of the crypto ACLs
-
Manually established SAs never expire |
|