Header
Home | Set as homepage | Add to favorites
  Search the Site     » Advanced Search
Sections
Syndication


Blogroll:

||||| ALL Cisco-Network ARTICLES |||||  
CCIE Journey,
The CCIE Journey,


Firewalls and VPN Features Questions and answers

Feb 10,2010 by alperen

image

Questions

1. 

Which two of the following are PIX Firewall IPSec implementations?

  1. Remote access

  2. Host-to-host

  3. Site-to-site

  4. Lock and key

2. 

Which IPSec mode runs between two security gateways, such as PIX Firewall units?

  1. Remote access

  2. Transport

  3. Tunnel

  4. VPN Free Client

3. 

Which command enables IKE on a PIX Firewall?

  1. IKE enable

  2. isakmp enable

  3. isakmp policy

  4. isakmp identity

4. 

Which command defines the Diffie–Hellman configuration?

  1. Pix(config)# isakmp policy 100 encryption des

  2. Pix(config)# isakmp policy 100 hash md5

  3. Pix(config)# isakmp policy 100 authentication rsa-sig

  4. Pix(config)# isakmp policy 100 group 2

5. 

In the isakmp policy 100 authentication rsa-sig command, what does rsa-sig mean?

  1. Preshared keys will be used for authentication

  2. Hash keys will be used for authentication

  3. CAs will be used for authentication

  4. RSA keys will be used for authentication

6. 

Of the following IKE policies, which is the highest priority?

  1. 100

  2. 200

  3. 500

  4. 1000

7. 

Which VPN feature requires device times to be set to GMT?

  1. Preshared keys

  2. Tunnel mode

  3. Transport mode

  4. CAs

8. 

Which command is not required to configure IPSec CAs?

  1. pixfirewall(config)# hostname Pix

  2. Pix(config)# domain-name test.com

  3. Pix(config)# ca generate rsa key 512

  4. Pix(config)# show ca mypubkey rsa

9. 

What does the sysopt connection permit-ipsec command do?

  1. Enables IPSec on the PIX unit

  2. Logs IPSec connection info to a Syslog server

  3. Permits IPSec traffic to pass through the firewall without inspection by the interface ACLs

  4. Activates remote IPSec configuration

10. 

Which is not a function performed by crypto access lists?

  1. Filters inbound traffic and discards any traffic that should have been protected by IPSec

  2. Determines whether to accept requests for IPSec SAs for the requested dataflows when processing IKE negotiations

  3. Deny statements that specify any matching packets will be discarded

  4. Defines the data traffic to be protected by IPSec

11. 

Which is an example of a Cisco VPN Client implementation?

  1. PIX Remote VPN

  2. Easy VPN Remote device

  3. Easy VPN Server

  4. PIX ISAKMP

12. 

Which command specifies a Syslog server for logging messages?

  1. logging trap

  2. logging history

  3. logging on

  4. logging host

13. 

Which is Cisco’s flagship-integrated security-management solution?

  1. CiscoWorks VMS

  2. Cisco Secure Policy Manager (CSPM)

  3. AVVID

  4. Cisco PIX Device Manager (PDM)

14. 

Point-to-Point Protocol over Ethernet (PPPoE) uses which default authentication protocol?

  1. AAA

  2. CHAP

  3. PAP

  4. MS-CHAP

15. 

Which statement is true about PPPoE on PIX Firewalls?

  1. It’s an industry standard that has been supported since PIX OS 5.1

  2. It encapsulates PPP traffic in Ethernet frames to travel across the LAN

  3. It’s only supported on the outside interface of the PIX

  4. PPPoE implementation is specifically targeted for larger links and devices

Answers

1. 

A. and C. Remote access and Site-to-site

2. 

C. Tunnel

3. 

B. isakmp enable

4. 

D. Pix(config)# isakmp policy 100 group 2

5. 

C. CAs will be used for authentication

6. 

A. 100

7. 

D. CAs

8. 

D. Pix(config)# show ca mypubkey rsa

9. 

C. Permits IPSec traffic to pass through the firewall without inspection by the interface ACLs

10. 

C. Denies statements that specify any matching packets will be discarded

11. 

B. Easy VPN Remote device

12. 

D. logging host

13. 

A. CiscoWorks VMS

14. 

C. PAP

15. 

C. It’s only supported on the outside interface of the PIX cp22


343 times read

Related news

» Cisco IOS IPSec for Preshared Keys Questions and Answers
by alperen posted on Sep 29,2009
» Step 2-3 Configure Preshared Keys
by alperen posted on Sep 27,2009
» Creating a VPN Between a Workstation and a Router
by admin posted on Jul 21,2008
» Cisco IOS IPSec for Preshared Keys Review
by alperen posted on Sep 29,2009
» CiscoSecure PIX Firewalls Review
by alperen posted on Feb 10,2010
Did you enjoy this article?
(total 0 votes)

comment Comments (0 posted) 

More Top News
CCSP-Cisco Certified Security Professional
Most Popular
Most Commented
Featured Author