Font size
WorksheetsModule 8 - VPN and IPsec Concepts Review
Total questions: 20
Worksheet time: 11mins
What is the function of the Hashed Message Authentication Code (HMAC) algorithm in setting up an IPsec VPN?
guarantees message integrity
authenticates the IPsec peers
protects IPsec keys during session negotiation
creates a secure channel for key negotiation
What are two hashing algorithms used with IPsec AH to guarantee authenticity? (Choose two.)
MD5
SHA
AES
DH
RSA
What two algorithms can be part of an IPsec policy to provide encryption and hashing to protect interesting traffic? (Choose two.)
AES
SHA
DH
RSA
PSK
Which protocol creates a virtual point-to-point connection to tunnel unencrypted traffic between Cisco routers from a variety of protocols?
OSPF
IPsec
IKE
GRE
Which two end points can be on the other side of an ASA site-to-site VPN? (Choose two.)
DSL switch
router
another ASA
multilayer switch
Frame Relay switch
Which VPN solution allows the use of a web browser to establish a secure, remote-access VPN tunnel to the ASA?
clientless SSL
client-based SSL
site-to-site using a preshared key
site-to-site using an ACL
Which IPsec security function provides assurance that the data received via a VPN has not been modified in transit?
confidentiality
integrity
authentication
secure key exchange
Which two technologies provide enterprise-managed VPN solutions? (Choose two.)
Frame Relay
site-to-site VPN
Layer 2 MPLS VPN
Layer 3 MPLS VPN
remote access VPN
Which two types of VPNs are examples of enterprise-managed remote access VPNs? (Choose two.)
IPsec VPN
clientless SSL VPN
GRE over IPsec VPN
client-based IPsec VPN
IPsec Virtual Tunnel Interface VPN
Which is a requirement of a site-to-site VPN?
It requires a client/server architecture.
It requires the placement of a VPN server at the edge of the company network.
It requires hosts to use VPN client software to encapsulate traffic.
It requires a VPN gateway at each end of the tunnel to encrypt and decrypt traffic.
What is the function of the Diffie-Hellman algorithm within the IPsec framework?
allows peers to exchange shared keys
provides strong data encryption
guarantees message integrity
provides authentication
How is "tunneling" accomplished in a VPN?
New headers from one or more VPN protocols encapsulate the original packets.
All packets between two hosts are assigned to a single physical medium to ensure that the packets are kept private.
Packets are disguised to look like other types of traffic so that they will be ignored by potential attackers.
A dedicated circuit is established between the source and destination devices for the duration of the connection.
Which statement describes a VPN?
VPNs use dedicated physical connections to transfer data between remote users.
VPNs use logical connections to create public networks through the Internet.
VPNs use open source virtualization software to create the tunnel through the Internet.
VPNs use virtual connections to create a private network through a public network.
Which type of VPN supports multiple sites by applying configurations to virtual interfaces instead of physical interfaces?
IPsec virtual tunnel interface
dynamic multipoint VPN
MPLS VPN
GRE over IPsec
Which type of VPN connects using the Transport Layer Security (TLS) feature?
SSL VPN
GRE over IPsec
dynamic multipoint VPN
IPsec virtual tunnel interface
Which type of VPN has both Layer 2 and Layer 3 implementations?
MPLS VPN
IPsec virtual tunnel interface
dynamic multipoint VPN
GRE over IPsec
Which type of VPN allows multicast and broadcast traffic over a secure site-to-site VPN?
GRE over IPsec
SSL VPN
dynamic multipoint VPN
IPsec virtual tunnel interface
Which type of VPN uses the public key infrastructure and digital certificates?
SSL VPN
GRE over IPsec
dynamic multipoint VPN
IPsec virtual tunnel interface
Which type of VPN involves a nonsecure tunneling protocol being encapsulated by IPsec?
GRE over IPsec
dynamic multipoint VPN
IPsec virtual tunnel interface
SSL VPN
Which type of VPN routes packets through virtual tunnel interfaces for encryption and forwarding?
IPsec virtual tunnel interface
MPLS VPN
dynamic multipoint VPN
GRE over IPsec
