IPSec VPN is a widely-acknowledged solution for enterprise network. What are the four steps tosetup an IPsec VPN?()
A.A
B.B
C.C
D.D
您可能感興趣的試卷
你可能感興趣的試題
A.The cypto isakmp keepalive command is used to configure the Stateful Switchover (SSO)protocol
B.Reverse Route Injection (RRI) is configured on at the remote site to inject the central sitenetworks
C.Each Hot Standby Routing Protocol (HSRP) standby group has two well-known MACaddresses and a virtual IP address
D.The cypto isakmp keepalive command is used to configure stateless failover
A.The crypto ACL number
B.The IPSEC mode (tunnel or transport)
C.The GRE tunnel interface IP address
D.The GRE tunnel source interface or IP address, and tunnel destination IP address
E.The MTU size of the GRE tunnel interface
Refer to the exhibit. Which two statements about the AAA configuration are true?()
A.A good security practice is to havethe none parameter configured as the final method used toensure that no other authentication method will be used
B.If a TACACS+ server is not available, then a user connecting via the console port would not beable to gain access since no other authentication method has been defined
C.If a TACACS+ server is not available, then the user Bob could be able to enter privileged modeas long as the proper enable password is entered
D.Theaaa new-model command forces the router to override every other authentication methodpreviously configured for the router lines
E.To increase security, group radius should be used instead of group tacacs+
F.Two authentication options are prescribed by the displayedaaa authentication command
A.If the radius server returns an error, the enable password will be used
B.If the radius server returns a ’failed’ message, the enable password will be used
C.The command login authentication group will associate the AM authentication to a specifiedinterface
D.If the group database is unavailable, the radius server will be used
Authentication is the process of determining if a user or identity is who they claim to be. Refer tothe exhibit. Which statement about the authentication process is correct?()
A.The LIST1 list will disable authentication on the console port
B.All login requests will be authenticated using the group tacacs+ method
C.The default login authentication will automatically be applied to all login connections
D.Because no method list is specified, the LIST1 list will not authenticate anyone on the consoleport
A.to provide a keepalive mechanism
B.to pull event logs from the router
C.to extract relevant SNMP information
D.to perform application-level accounting
A.Disable post scan
B.Use SSH or SSL
C.Enable trust levels
D.Deny echo replies on all edge routers
Network Topology Exhibit:
Configuration Exhibit:
NET(config)# access-list 112 deny icmp any any echo log
NET(config)# access-list 112 deny imp any any redirect log
NET(config)# access-list 112 deny icmp any any mask-request log
NET(config)# access-list 112 permit icmp any 10.1.1.0 0.0.0.255
NET(config)# interface Fa0/1
NET(config-if)# ip access-group 112 in
You work as a network administrator at networkTut.com, study the exhibit carefully. The
configuration has been applied to router NET to mitigate the threat of certain types of ICMPbasedattacks while allowing some ICMP traffic to the corporate LAN to work. However, the configurationis incorrect. On the basis of the information in the exhibit, which configuration option wouldcorrectly configure router NET?()
A.The first three statements of ACL 112 should have permitted the ICMP traffic and the laststatement should deny the identified traffic
B.The last statement of ACL 112 should have been "access-list 112deny icmp any 10.2.1.00.0.0.255"
C.The last statement of ACL 112 should have been "access-list 112permit icmp any 10.2.1.00.0.0.255"
D.ACL 112 should have been applied to interface Fa0/0 in an inbound direction
E.The last statement of ACL 112 should have been "access-list 112deny icmp any 10.1.1.00.0.0.255"
F.ACL 112 should have been applied to interface Fa0/1 in an outbound direction
G.None of the above
A.The dsl operating-mode auto command is required if the default mode has been changed
B.The ip mtu 1496 command must be applied on the dialer interface
C.The encapsulation ppp command is required
D.The ip mtu 1492 command must be applied on the dialer interface
As a network engineer, study the exhibit carefully. Router Net is unable to establish an ADSLconnection with its provider. Which action would correct this problem?()
A.On the Dialer0 interface, add the pppoe enable command
B.On the Dialer0 Interface, add the ip mtu 1496 command
C.On the ATM0/0 interface, add the dialer pool-member 1 command
D.On the ATM0/0 interface, add the dialer pool-member 0 command
最新試題
IPSec VPN is a widely-acknowledged solution for enterprise network. What are the four steps tosetup an IPsec VPN?()
In computer security, AAA stands for authentication, authorization and accounting. Which optionabout the AAA authentication enable default group radius enable command is correct?()
Drag the IOS commands from the left that would be used to implement a GRE tunnel using the10.1.1.0.30 network on interface serial 0/0 to the correct target area on the right.
Study this exhibit carefully. What information can be derived from the SDM firewall configurationdisplayed?()
Match the xDSL type on the above to the most appropriate implementation on the below.
Drag and drop each management protocol on the above to the correct category on the below.
Drag and drop the xDSL type on the above to the appropriate xDSL description on the below.
Which three statements accurately describe IOS Firewall configurations?()
This item contains several questions that you must answer. You can view these questions byclicking on the Questions button to the left. Changing questions can be accomplished by clicking the numbers to the left of each question. In order to complete the questions, you will need to referto the SDM and the topology, neither of which is currently visible.To gain access to either the topology or the SDK click on the button to left side of the screen thatcorresponds to the section you wish to access. When you have finished viewing the topology theSDK you can return to your questions by clicking on the Questions button to the left.Which defined peer IP address an local subnet belong to Crete?()
Which two encapsulation methods require that an 827 ADSL router be configured with a PPPusername and CHAP password?()