A.The IP inspection rule can be applied in the inbound direction on the secured interface
B.The IP inspection rule can be applied in the outbound direction on the unsecured interface
C.The ACL applied in the inbound direction on the unsecured interface should be an extendedACL.
D.For temporary openings to be created dynamically by Cisco IOS Firewall, the access-list for thereturning traffic must be a standard ACL
您可能感興趣的試卷
你可能感興趣的試題
Study this exhibit carefully. What information can be derived from the SDM firewall configurationdisplayed?()
A.Access-list 101 was configured for the trusted interface, and access-list 100 was configured forthe untrusted interface
B.Access-list 100 was configured for the trusted interface, and access-list 101 was configured forthe untrusted interface
C.Access-list 100 was configured for the inbound direction, and access-list 101 was configured forthe outbound direction on the trusted interface
D.Access-list 100 was configured for the inbound direction, and access-list 101 was configured forthe outbound direction on the untrusted interface
This item contains several questions that you must answer. You can view these questions byclicking on the Questions button to the left. Changing questions can be accomplished by clickingthe numbers to the left of each question. In order to complete the questions, you will need to referto the SDM and the topology, neither of which is currently visible. To gain access to either thetopology or the SDK click on the button to left side of the screen that corresponds to the sectionyou wish to access. When you have finished viewing the topology the SDK you can return to yourquestions by clicking on the Questions button to the left.
Which IPSec rule is used for the Olympia branch and what does it define?()
A.102
B.116
C.127
D.IP traffic sourced from 10.10.10.0/24 destined to 10.5.15.0/24 will use the VPN
E.IP traffic sourced from 10.10.10.0/24 destined to 10.8.28.0/24 will use the VPN
F.IP traffic sourced from 10.10.10.0/24 destined to 10.5.33.0/24 will use the VPN
This item contains several questions that you must answer. You can view these questions byclicking on the Questions button to the left. Changing questions can be accomplished by clicking the numbers to the left of each question. In order to complete the questions, you will need to referto the SDM and the topology, neither of which is currently visible.
To gain access to either the topology or the SDK click on the button to left side of the screen thatcorresponds to the section you wish to access. When you have finished viewing the topology theSDK you can return to your questions by clicking on the Questions button to the left.
Which defined peer IP address an local subnet belong to Crete?()
A.peer address 192.168.55.159
B.peer address 192.168.89.192
C.peer address 192.168.195.23
D.subnet 10.5.15.0/24
E.subnet 10.7.23.0/24
F.subnet 10.4.38.0/24
This item contains several questions that you must answer. You can view these questions byclicking on the Questions button to the left. Changing questions can be accomplished by clickingthe numbers to the left of each question. In order to complete the questions, you will need to referto the SDM and the topology, neither of which is currently visible. To gain access to either thetopology or the SDK click on the button to left side of the screen that corresponds to the sectionyou wish to access. When you have finished viewing the topology the SDK you can return to yourquestions by clicking on the Questions button to the left.
Which algorithm as defined by the transform set is used for providing data confidentiality whenconnected to Tyre?()
A.ESP-3DES-SHA
B.ESP-3DES-SHA1
C.ESP-3DES-SHA2
D.ESP-3DES
E.ESP-SHA-HMAC
This item contains several questions that you must answer. You can view these questions byclicking on the Questions button to the left. Changing questions can be accomplished by clickingthe numbers to the left of each question. In order to complete the questions, you will need to referto the SDM and the topology, neither of which is currently visible.
To gain access to either the topology or the SDK click on the button to left side of the screen that Cisco 642-832: Practice Exam corresponds to the section you wish to access. When you have finished viewing the topology theSDK you can return to your questions by clicking on the Questions button to the left.
Which peer authentication method and which IPSEC mode is used to connect to the branchlocations?()
A.Digital Certificate
B.Pre-Shared Key
C.Transport Mode
D.Tunnel Mode
E.GRE/IPSEC Transport Mode
F.GRE/IPSEC Tunnel Mode
You are working as a network technician, study the exhibit carefully. Your boss has informed youthat there have been problems with the WAN that is using EIGRP routing protocol. You arerequired to troubleshoot these problems.
Before going to the questions of this sim, we should have a quick review about GRE tunneling:GRE Quick Summary.
The picture below shows how to configure a GRE Tunnel between two routers, notice that the"tunnel destination" must be the IP address of the interface, not of the opposite tunnel.
Notice: The tunnel source on one router must be specified as the tunnel destination on the otherrouter.
Below are the questions of this lab-sim.
What is the reason for the ping between the HQ router and the 192.168.1.193 interface on theBranch2 router failing?()
A.The default route is missing from the Branch2 router
B.When running EIGRP over GRE tunnels, you must manually configure the neighbor addressusing the eigrp neighbor ip address command
C.The tunnel numbers for the tunnel between the HQ router and the Branch2 router do not match
D.The tunnel source is incorrect on the Branch2 router It should be serial 2/0
E.The AS number for the EIGRP process on Branch2 should be 1 and not 11
You are working as a network technician, study the exhibit carefully. Your boss has informed youthat there have been problems with the WAN that is using EIGRP routing protocol. You arerequired to troubleshoot these problems.
Before going to the questions of this sim, we should have a quick review about GRE tunneling:GRE Quick Summary.
The picture below shows how to configure a GRE Tunnel between two routers, notice that the"tunnel destination" must be the IP address of the interface, not of the opposite tunnel.
Notice: The tunnel source on one router must be specified as the tunnel destination on the otherrouter.
Below are the questions of this lab-sim.
For the following statements, what is preventing a successful ping between the HQ router and the192.168.1.10 interface on the Branch3 router?()
A.The default route is missing from the Branch3 router
B.The tunnel interface numbers for the tunnel between the HQ router and the Branch3 router donot match
C.The tunnel source is incorrect on the Branch3 router. It should be serial 2/0
D.The IP address on the tunnel interface for the Branch3 router has wrong IP mask. It should be255.255.255.252
E.The network statement under router EIGRP on the Branch3 router is incorrect. It should benetwork 192.168.2.0.0.0.0.255
You are working as a network technician, study the exhibit carefully. Your boss has informed youthat there have been problems with the WAN that is using EIGRP routing protocol. You arerequired to troubleshoot these problems.
Before going to the questions of this sim, we should have a quick review about GRE tunneling:GRE Quick Summary.
The picture below shows how to configure a GRE Tunnel between two routers, notice that the"tunnel destination" must be the IP address of the interface, not of the opposite tunnel.
Notice: The tunnel source on one router must be specified as the tunnel destination on the otherrouter.
Below are the questions of this lab-sim.
What is preventing the HQ router and the Branch1 router from building up an EIGRP neighborrelationship?()
A.When running EIGRP over GRE tunnels, you must manually configure the neighbor addressusing the eigrp neighbor ipaddress command
B.The tunnel destination address is incorrect on the HQ router. It should be 10.2.1.1 to match theinterface address of the Branch1 router
C.The tunnel source is incorrect on the Branch1 router. It should be serial 2/0
D.The default route is missing from the Branch1 router
E.The tunnel interface numbers for the tunnel between the HQ router and Branch1 router do notmatch
You are working as a network technician, study the exhibit carefully. Your boss has informed youthat there have been problems with the WAN that is using EIGRP routing protocol. You arerequired to troubleshoot these problems.
Before going to the questions of this sim, we should have a quick review about GRE tunneling:GRE Quick Summary.
The picture below shows how to configure a GRE Tunnel between two routers, notice that the"tunnel destination" must be the IP address of the interface, not of the opposite tunnel.
Notice: The tunnel source on one router must be specified as the tunnel destination on the otherrouter.
Below are the questions of this lab-sim.
What is the reason that tunnel 5 on the HQ router is down when its companion tunnel on theBranch5 router is up?()
A.The IP address on the tunnel interface on Branch5 is incorrect. It should be 192.168.1.16255.255.255.252
B.The tunnel source for tunnel 5 is incorrect on the HQ router. It should be serial 2/0
C.The tunnel numbers for tunnel between the HQ router and the Branch5 router do not match
D.The tunnel destination address for tunnel 5 is incorrect on the HQ router. It should be 10.2.5.1to match the interface address of the Branch5 router
E.The tunnel interface for tunnel 5 on the HQ router is in the administrative down state
You are working as a network technician, study the exhibit carefully. Your boss has informed youthat there have been problems with the WAN that is using EIGRP routing protocol. You arerequired to troubleshoot these problems.
Before going to the questions of this sim, we should have a quick review about GRE tunneling:GRE Quick Summary The picture below shows how to configure a GRE Tunnel between tworouters, notice that the "tunnel destination" must be the IP address of the interface, not of theopposite tunnel.
Notice: The tunnel source on one router must be specified as the tunnel destination on the otherrouter.
Below are the questions of this lab-sim.
What is preventing the 192.168.1.150 network from appearing in the HQ router’s routing table?()
A.The default route is missing from the Branch4 router
B.The IP address on the E0/0 interface for the Branch4 router has the wrong IP mask. It shouldbe 255.255.255.252
C.The network statement under router EIGRP on the Branch4 router is incorrect. It should benetwork 192.168.1.0 0.0.0.255.
D.When running EIGRP over GRE tunnels, you must manually configure the neighbor addressusing the eigrp neighbor ipaddress command.
E.The IP address on the tunnel interface on P4S-Branch4 is incorrect. It should be 192.168.1.12255.255.255.252
最新試題
Drag the IPsec protocol description from the above to the correct protocol type on the below.(Notall descriptions will be used)Drag and Drop question, drag each item to its proper location.
Which statement about PPPoA configuration is correct?()
Drag and drop each function on the above to the hybrid fiber-coaxial architecture component that itdescribes on the below.
Drag and drop the xDSL type on the above to the appropriate xDSL description on the below.
In computer security, AAA stands for authentication, authorization and accounting. Which optionabout the AAA authentication enable default group radius enable command is correct?()
Authentication is the process of determining if a user or identity is who they claim to be. Refer tothe exhibit. Which statement about the authentication process is correct?()
Refer to the exhibit. Which two statements about the AAA configuration are true?()
As a network technician, do you know what is a recommended practice for secure configurationmanagement?()
Drag the DSL technologies on the left to their maximum(down/up) data rate values on the below.
Network Topology Exhibit:Configuration Exhibit:NET(config)# access-list 112 deny icmp any any echo logNET(config)# access-list 112 deny imp any any redirect logNET(config)# access-list 112 deny icmp any any mask-request logNET(config)# access-list 112 permit icmp any 10.1.1.0 0.0.0.255NET(config)# interface Fa0/1NET(config-if)# ip access-group 112 inYou work as a network administrator at networkTut.com, study the exhibit carefully. Theconfiguration has been applied to router NET to mitigate the threat of certain types of ICMPbasedattacks while allowing some ICMP traffic to the corporate LAN to work. However, the configurationis incorrect. On the basis of the information in the exhibit, which configuration option wouldcorrectly configure router NET?()