Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

C7 - Quiz

Total questions: 21

Worksheet time: 21mins

Name
Class
Date
1.

Which protocol creates a virtual point-to-point connection to tunnel unencrypted traffic between Cisco routers from a variety of protocols?

a)

OSPF

b)

IPsec

c)

IKE

d)

GRE

2.

Which is a requirement of a site-to-site VPN?

a)


It requires a client/server architecture.

b)


It requires the placement of a VPN server at the edge of the company network.

c)


It requires hosts to use VPN client software to encapsulate traffic.

d)

It requires a VPN gateway at each end of the tunnel to encrypt and decrypt traffic.

3.

Which two statements describe a remote access VPN? (Choose two.)

a)


It connects entire networks to each other.

b)


It requires hosts to send TCP/IP traffic through a VPN gateway.

c)


It is used to connect individual hosts securely to a company network over the Internet.

d)


It may require VPN client software on hosts.

e)

It requires static configuration of the VPN tunnel.

4.

Two corporations have just completed a merger. The network engineer has been asked to connect the two corporate networks without the expense of leased lines. Which solution would be the most cost effective method of providing a proper and secure connection between the two corporate networks?

a)

Cisco AnyConnect Secure Mobility Client with SSL

b)


Cisco Secure Mobility Clientless SSL VPN

c)

Frame Relay

d)

remote access VPN using IPsec

e)


site-to-site VPN

5.


Which two scenarios are examples of remote access VPNs? (Choose two.)

a)

A toy manufacturer has a permanent VPN connection to one of its parts suppliers.

b)

All users at a large branch office can access company resources through a single VPN connection.

c)

A mobile sales agent is connecting to the company network via the Internet connection at a hotel.

d)

A small branch office with three employees has a Cisco ASA that is used to create a VPN connection to the HQ.

e)

An employee who is working from home uses VPN client software on a laptop in order to connect to the company network.

6.

Which statement describes the effect of key length in deterring an attacker from hacking through an encryption key?

a)

The length of a key will not vary between encryption algorithms.

b)


The length of a key does not affect the degree of security.

c)

The shorter the key, the harder it is to break.

d)


The longer the key, the more key possibilities exist.

7.

Which statement accurately describes a characteristic of IPsec?

a)

IPsec works at the application layer and protects all application data.

b)


IPsec works at the transport layer and protects data at the network layer.

c)


IPsec is a framework of open standards that relies on existing algorithms.

d)


IPsec is a framework of proprietary standards that depend on Cisco specific algorithms.

e)

IPsec is a framework of standards developed by Cisco that relies on OSI algorithms.

8.

How is "tunneling" accomplished in a VPN?

a)


New headers from one or more VPN protocols encapsulate the original packets.

b)


All packets between two hosts are assigned to a single physical medium to ensure that the packets are kept private.

c)

Packets are disguised to look like other types of traffic so that they will be ignored by potential attackers.

d)

A dedicated circuit is established between the source and destination devices for the duration of the connection.

9.


Which two statements describe the IPsec protocol framework? (Choose two.)

a)


AH uses IP protocol 51.

b)


AH provides encryption and integrity.

c)


AH provides integrity and authentication.

d)


ESP uses UDP protocol 51.

e)


AH provides both authentication and encryption.

10.

What technology is used to negotiate security associations and calculate shared keys for an IPsec VPN tunnel?

a)

3DES

b)

IKE

c)

PSK

d)

SHA

11.

What are the two modes used in IKE Phase 1? (Choose two.)

a)


aggressive

b)

main

c)

passive

d)

primary

e)

secondary

12.

What takes place during IKE Phase 2 when establishing an IPsec VPN?

a)

IPsec security associations are exchanged.

b)


Traffic is exchanged between IPsec peers.

c)


ISAKMP security associations are exchanged.

d)


Interesting traffic is identified.

13.

What is a function of the GRE protocol?

a)


to configure the set of encryption and hashing algorithms that will be used to transform the data sent through the IPsec tunnel

b)


to encapsulate multiple OSI Layer 3 protocol packet types inside an IP tunnel

c)

to configure the IPsec tunnel lifetime

d)

to provide encryption through the IPsec tunnel​

14.


What type of traffic is supported by IPsec?

a)

IPsec supports all traffic permitted through an ACL.

b)


IPsec only supports unicast traffic.

c)


IPsec supports all IPv4 traffic.

d)


IPsec supports layer 2 multicast traffic.

15.

Refer to the exhibit. What HMAC algorithm is being used to provide data integrity?

a)

SHA

b)

MD5

c)

DH

d)

AES

16.

Refer to the exhibit. A VPN tunnel is configured on the WAN between R1 and R2. On which R1 interface(s) would a crypto map be applied in order to create a VPN between R1 and R2?

a)

G0/0

b)

G0/0 and G0/1

c)

S0/0/0

d)

all R1 interfaces

17.

Router R1 has configured ISAKMP policies numbered 1, 5, 9, and 203. Router R2 only has default policies. How will R1 attempt to negotiate the IKE Phase 1 ISAKMP tunnel with R2?

a)


R1 and R2 cannot match policies because the policy numbers are different.

b)

R1 will attempt to match policy #1 with the most secure matching policy on R2.

c)

R1 will begin to try to match policy #1 with policy #65514 on R2.

d)


R1 will try to match policy #203 with the most secure default policy on R2.

18.

Consider the following configuration on a Cisco ASA:

crypto ipsec transform-set ESP-DES-SHA esp-des esp-sha-hmac

What is the purpose of this command?

a)

to define only the allowed encryption algorithms

b)

to define the ISAKMP parameters that are used to establish the tunnel

c)


to define what traffic is allowed through and protected by the tunnel

d)

to define the encryption and integrity algorithms that are used to build the IPsec tunnel

19.

What is needed to define interesting traffic in the creation of an IPsec tunnel?

a)

access list

b)

security associations

c)


transform set

d)


hashing algorithm

20.

When the CLI is used to configure an ISR for a site-to-site VPN connection, what is the purpose of the crypto map command in interface configuration mode?

a)


to bind the interface to the ISAKMP policy

b)

to configure the transform set

c)

to force IKE Phase 1 negotiations to begin

d)


to negotiate the SA policy

21.

Refer to the exhibit. What show command displays whether the securityk9 software is installed on the router and whether the EULA license has been activated?

a)


show running-config

b)


show version

c)

show interfaces s0/0/0

d)

show crypto isakmp policy 1