Drag each element of the Cisco IOS Firewall Feature Set from the above and drop onto itsdescription on the below.
您可能感興趣的試卷
你可能感興趣的試題
Study the exhibit carefully.
Routers A and B are customer routers. Routers 1, 2, 3 and 4 are provider routers. The routers areoperating with various IOS versions. Which frame mode MPLS configuration statement is true?()
A.Before MPLS is enabled, the ip cef command is only requited on routers 1 and 4
B.After MPLS is enabled, the ip cef command is only required on routers 1 and 4
C.Before MPLS is enabled, the ip cef command is only required on the Ethernet 0 interfaces ofrouters 1 and 4
D.After MPLS is enabled, the ip cef command is only required on the Ethernet 0 interfaces ofrouters 1 and 4
E.Before MPLS is enabled, the ip cef command must be applied to all provider routers
A new router was configured with the following commands:
The configuration above was found on an Internet Service Provider’s (ISP) Multiprotocol LabelSwitching (MPLS) network. What is its purpose?()
A.To prevent customers from running TDP with the ISP routers
B.To prevent customers from running LDP with the ISP routers
C.To prevent other ISPs from running LDP with the ISP routers
D.To prevent man-in-the-middle attacks
E.To use CBAC to shut down Distributed Denial of Service attacks
F.To use IPS to protect against session-replay attacks
G.None of the above
A.IKE keepalives are unidirectional and sent every ten seconds
B.IPsec uses the Encapsulating Security Protocol (ESP) or the Authentication Header (AH)protocol for exchanging keys
C.To establish IKE SA, main mode utilizes six packets while aggressive mode utilizes only threepackets
D.IKE uses the Diffie-Hellman algorithm to generate symmetrical keys to be used by IPsec peers
Study the exhibit carefully. The Cisco IOS IPsec High Availability (IPsec HA) Enhancementsfeature provides an infrastructure for reliable and secure networks to provide transparent availability of the VPN gateways - that is, Cisco IOS Software-based routers. What are the twooptions that are used to provide High Availability IPsec?()
A.HSRP
B.Dual Router Mode (DRM) IPsec
C.IPsec Backup Peerings
D.RRI
IPSec VPN is a widely-acknowledged solution for enterprise network. What are the four steps tosetup an IPsec VPN?()
A.A
B.B
C.C
D.D
A.The cypto isakmp keepalive command is used to configure the Stateful Switchover (SSO)protocol
B.Reverse Route Injection (RRI) is configured on at the remote site to inject the central sitenetworks
C.Each Hot Standby Routing Protocol (HSRP) standby group has two well-known MACaddresses and a virtual IP address
D.The cypto isakmp keepalive command is used to configure stateless failover
A.The crypto ACL number
B.The IPSEC mode (tunnel or transport)
C.The GRE tunnel interface IP address
D.The GRE tunnel source interface or IP address, and tunnel destination IP address
E.The MTU size of the GRE tunnel interface
Refer to the exhibit. Which two statements about the AAA configuration are true?()
A.A good security practice is to havethe none parameter configured as the final method used toensure that no other authentication method will be used
B.If a TACACS+ server is not available, then a user connecting via the console port would not beable to gain access since no other authentication method has been defined
C.If a TACACS+ server is not available, then the user Bob could be able to enter privileged modeas long as the proper enable password is entered
D.Theaaa new-model command forces the router to override every other authentication methodpreviously configured for the router lines
E.To increase security, group radius should be used instead of group tacacs+
F.Two authentication options are prescribed by the displayedaaa authentication command
最新試題
This item contains several questions that you must answer. You can view these questions byclicking on the Questions button to the left. Changing questions can be accomplished by clicking the numbers to the left of each question. In order to complete the questions, you will need to referto the SDM and the topology, neither of which is currently visible.To gain access to either the topology or the SDK click on the button to left side of the screen thatcorresponds to the section you wish to access. When you have finished viewing the topology theSDK you can return to your questions by clicking on the Questions button to the left.Which defined peer IP address an local subnet belong to Crete?()
Drag and drop the xDSL type on the above to the appropriate xDSL description on the below.
cisco ios command to interface dialer 0
Authentication is the process of determining if a user or identity is who they claim to be. Refer tothe exhibit. Which statement about the authentication process is correct?()
Drag the IPsec protocol description from the above to the correct protocol type on the below.(Notall descriptions will be used)Drag and Drop question, drag each item to its proper location.
Drag each element of the Cisco IOS Firewall Feature Set from the above and drop onto itsdescription on the below.
IPSec VPN is a widely-acknowledged solution for enterprise network. What are the four steps tosetup an IPsec VPN?()
You need to configure a GRE tunnel on a IPSec router. When you are using the SDM to configurea GRE tunnel over IPsec, which two parameters are required when defining the tunnel interfaceinformation?()
Identify the recommended steps for worm attack mitigation by dragging and dropping them into thetarget area in the correct order.
In computer security, AAA stands for authentication, authorization and accounting. Which optionabout the AAA authentication enable default group radius enable command is correct?()