Search Header Logo

Module 8 - VPN and IPsec Concepts Review

Authored by Alicia Pierce

Computers

12th Grade

Used 49+ times

Module 8 - VPN and IPsec Concepts Review
AI

AI Actions

Add similar questions

Adjust reading levels

Convert to real-world scenario

Translate activity

More...

    Content View

    Student View

20 questions

Show all answers

1.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

What is the function of the Hashed Message Authentication Code (HMAC) algorithm in setting up an IPsec VPN?

guarantees message integrity

authenticates the IPsec peers

protects IPsec keys during session negotiation

creates a secure channel for key negotiation

Answer explanation

The IPsec framework uses various protocols and algorithms to provide data confidentiality, data integrity, authentication, and secure key exchange. The Hashed Message Authentication Code (HMAC) is a data integrity algorithm that uses a hash value to guarantee the integrity of a message.

2.

MULTIPLE SELECT QUESTION

45 sec • 1 pt

What are two hashing algorithms used with IPsec AH to guarantee authenticity? (Choose two.)

MD5

SHA

AES

DH

RSA

Answer explanation

The IPsec framework uses various protocols and algorithms to provide data confidentiality, data integrity, authentication, and secure key exchange. Two popular algorithms used to ensure that data is not intercepted and modified (data integrity and authenticity) are MD5 and SHA.

3.

MULTIPLE SELECT QUESTION

45 sec • 1 pt

What two algorithms can be part of an IPsec policy to provide encryption and hashing to protect interesting traffic? (Choose two.)

AES

SHA

DH

RSA

PSK

Answer explanation

The IPsec framework uses various protocols and algorithms to provide data confidentiality, data integrity, authentication, and secure key exchange. Two algorithms that can be used within an IPsec policy to protect interesting traffic are AES, which is an encryption protocol, and SHA, which is a hashing algorithm.

4.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Which protocol creates a virtual point-to-point connection to tunnel unencrypted traffic between Cisco routers from a variety of protocols?

OSPF

IPsec

IKE

GRE

Answer explanation

Generic Routing Encapsulation (GRE) is a tunneling protocol developed by Cisco that encapsulates multiprotocol traffic between remote Cisco routers. GRE does not encrypt data. OSPF is a open source routing protocol. IPsec is a suite of protocols that allow for the exchange of information that can be encrypted and verified. Internet Key Exchange (IKE) is a key management standard used with IPsec.

5.

MULTIPLE SELECT QUESTION

45 sec • 1 pt

Which two end points can be on the other side of an ASA site-to-site VPN? (Choose two.)

DSL switch

router

another ASA

multilayer switch

Frame Relay switch

Answer explanation

In a site-to-site VPN, end hosts send and receive normal unencrypted TCP/IP traffic through a VPN terminating device, typically called a VPN gateway. A VPN gateway device could be a router or a firewall. A Cisco Adaptive Security Appliance (ASA) is a standalone firewall device that combines firewall, VPN concentrator, and intrusion prevention functionality into one software image.

6.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Which VPN solution allows the use of a web browser to establish a secure, remote-access VPN tunnel to the ASA?

clientless SSL

client-based SSL

site-to-site using a preshared key

site-to-site using an ACL

Answer explanation

When a web browser is used to securely access the corporate network, the browser must use a secure version of HTTP to provide SSL encryption. A VPN client is not required to be installed on the remote host, so a clientless SSL connection is used.

7.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Which IPsec security function provides assurance that the data received via a VPN has not been modified in transit?

confidentiality

integrity

authentication

secure key exchange

Answer explanation

Integrity is a function of IPsec and ensures data arrives unchanged at the destination through the use of a hash algorithm. Confidentiality is a function of IPsec and utilizes encryption to protect data transfers with a key. Authentication is a function of IPsec and provides specific access to users and devices with valid authentication factors. Secure key exchange is a function of IPsec and allows two peers to maintain their private key confidentiality while sharing their public key.

Access all questions and much more by creating a free account

Create resources

Host any resource

Get auto-graded reports

Google

Continue with Google

Email

Continue with Email

Classlink

Continue with Classlink

Clever

Continue with Clever

or continue with

Microsoft

Microsoft

Apple

Apple

Others

Others

Already have an account?