wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

mod 8

Total questions: 53

Worksheet time: 13hrs 15mins

Name
Class
Date
1.

Which two statements describe a remote access VPN? (Choose two.)

a)

It connects entire networks to each other.

b)

It requires hosts to send TCP/IP traffic through a VPN gateway.

c)

It is used to connect individual hosts securely to a company network over the Internet.

d)

It requires static configuration of the VPN tunnel.

e)

It may require VPN client software on hosts.

2.

The use of 3DES within the IPsec framework is an example of which of the five IPsec building blocks?

a)

integrity

b)

Diffie-Hellman

c)

confidentiality

d)

nonrepudiation

e)

authentication

3.

Which type of VPN may require the Cisco VPN Client software?

a)

MPLS VPN

b)

site-to-site VPN

c)

SSL VPN

d)

remote access VPN

4.

Which technique is necessary to ensure a private transfer of data using a VPN?

a)

scalability

b)

encryption

c)

authorization

d)

virtualization

5.

What are the two fundamental Dynamic Multipoint VPN tunnel types? (Choose two.)

a)

client-to-site

b)

server-to-client

c)

site-to-site

d)

hub-to-spoke

e)

spoke-to-spoke

6.

What are two reasons a company would use a VPN? (Choose two.)

a)

to test network connections to remote users

b)

to connect remote users to the network

c)

to eliminate the need of having a gateway

d)

to increase bandwidth to the network

e)

to allow suppliers to access the network

7.

True or False? All VPNs securely transmit clear text across the Internet.

a)

true

b)

false

8.

Which solution allows workers to telecommute effectively and securely?

a)

dial-up connection

b)

site-to-site VPN

c)

DSL connection

d)

remote-access VPN

9.

Which VPN type is a service provider managed VPN?

a)

Layer 3 MPLS VPN

b)

GRE over IPsec VPN

c)

site-to-site VPN

d)

remote access VPN

10.

Which IPsec framework protocol provides data integrity and data authentication, but does not provide data confidentiality?

a)

AH

b)

DH

c)

ESP

d)

IP protocol 50

11.

What algorithm is used to provide data integrity of a message through the use of a calculated hash value?

a)

DH

b)

HMAC

c)

AES

d)

RSA

12.

Which statement describes the effect of key length in deterring an attacker from hacking through an encryption key?

a)

The shorter the key, the harder it is to break.

b)

The length of a key will not vary between encryption algorithms.

c)

The length of a key does not affect the degree of security.

d)

The longer the key, the more key possibilities exist.

13.

What is a type of VPN that is generally transparent to the end user?

a)

public

b)

remote access

c)

site-to-site

d)

remote access

14.

A network design engineer is planning the implementation of a cost-effective method to interconnect multiple networks securely over the internet. Which type of technology is required?

a)

a dedicated ISP

b)

a VPN gateway

c)

a GRE IP tunnel

d)

a leased line

15.

Which statement is true of site-to-site VPNs?

a)

Individual hosts can enable and disable the VPN connection.

b)

Internal hosts send normal, unencapsulated packets.

c)

The VPN connection is not statically defined.

d)

VPN client software is installed on each host.

16.

How is the hash message authentication code (HMAC) algorithm used in an IPsec VPN?

a)

to authenticate the IPsec peers

b)

to create a secure channel for key negotiation

c)

to guarantee message integrity

d)

to protect IPsec keys during session negotiation

17.

What IPsec algorithm is used to provide data confidentiality?

a)

AES

b)

Diffie-Hellman

c)

MD5

d)

RSA

e)

SHA

18.

What are two hashing algorithms used with IPsec to guarantee authenticity? (Choose two.)

a)

AES

b)

DH

c)

MD5

d)

RSA

e)

SHA

19.

What two IPsec algorithms provide encryption and hashing to protect interesting traffic? (Choose two.)

a)

AES

b)

DH

c)

IKE

d)

PSK

e)

SHA

20.

Which protocol creates a virtual unencrypted pointto-point VPN tunnel between Cisco routers?

a)

IKE

b)

IPsec

c)

GRE

d)

OSPF

21.

Which VPN solution allows the use of a web browser to establish a secure, remote-access VPN tunnel to a VPN gateway?

a)

client-based SSL

b)

clientless SSL

c)

site-to-site using a pre-shared key

d)

site-to-site using an ACL

22.

Which IPsec security function utilizes encryption to protect data transfers with a key?

a)

authentication

b)

confidentiality

c)

integrity

d)

secure key exchange

23.

Which of the following are service provider managed VPN solutions? (Choose two.)

a)

client-based IPsec VPN

b)

clientless SSL VPN

c)

Frame Relay

d)

Layer 3 MPLS VPN

e)

remote-access VPN

24.

Which of the following are enterprise-managed remote-access VPNs? (Choose two.)

a)

client-based IPsec VPN

b)

clientless SSL VPN

c)

Frame Relay

d)

Layer 3 MPLS VPN

e)

remote-access VPN

25.

Which is a requirement of a site-to-site VPN?

a)

Hosts connected using a web browser and an SSL connection

b)

Hosts connected using client-based VPN software

c)

A client/server architecture

d)

VPN server at the edge of the company network

e)

VPN gateways at each end of the tunnel

26.

How is the Diffie-Hellman algorithm used in the IPsec framework?

a)

allows peers to exchange shared keys

b)

guarantees message integrity

c)

provides authentication

d)

provides strong data encryption

27.

Which type of VPN involves passenger, carrier, and transport protocols?

a)

DMVPN

b)

GRE over IPsec

c)

IPsec virtual tunnel interface

d)

MPLS VPN

28.

Which type of VPN supports multiple sites by applying configurations to virtual interfaces instead of physical interfaces?

a)

DMVPN

b)

MPLS VPN

c)

IPsec virtual tunnel interface

d)

GRE over IPsec

29.

Which type of VPN connects using the Transport Layer Security (TLS) feature?

a)

GRE over IPsec

b)

SSL VPN

c)

DMVPN

d)

MPLS VPN

e)

IPsec virtual tunnel interface

30.

Which description correctly identifies an MPLS VPN?

a)

allows multicast and broadcast traffic over a secure site-to-site VPN

b)

involves a nonsecure tunneling protocol being encapsulated by IPsec

c)

routes packets through virtual tunnel interfaces for encryption and forwarding.

d)

uses the public key infrastructure and digital certificates.

e)

has both Layer 2 and Layer 3 implementations

31.

Which description correctly identifies an SSL VPN?

a)

allows multicast and broadcast traffic over a secure site-to-site VPN

b)

has both Layer 2 and Layer 3 implementations

c)

involves a nonsecure tunneling protocol being encapsulated by IPsec

d)

routes packets through virtual tunnel interfaces for encryption and forwarding

e)

uses the public key infrastructure and digital certificates

32.

Which two descriptions correctly identify an IPsec VTI VPN? (Choose two.)

a)

allows multicast and broadcast traffic over a secure site-to-site VPN

b)

has both Layer 2 and Layer 3 implementations

c)

involves a nonsecure tunneling protocol being encapsulated by IPsec

d)

routes packets through virtual tunnel interfaces for encryption and forwarding

e)

uses the public key infrastructure and digital certificates

33.

Which two descriptions correctly identify a GRE over IPsec VPN? (Choose two.)

a)

allows multicast and broadcast traffic over a secure site-to-site VPN

b)

involves a nonsecure tunneling protocol being encapsulated by IPsec

c)

has both Layer 2 and Layer 3 implementations

d)

routes packets through virtual tunnel interfaces for encryption and forwarding

e)

uses the public key infrastructure and digital certificates

34.

Which two scenarios are examples of remote access VPNs? (Choose two.)

a)

All users at a large branch office can access company resources through a single VPN connection.

b)

A small branch office with three employees has a Cisco ASA that is used to create a VPN connection to the HQ.

c)

A toy manufacturer has a permanent VPN connection to one of its parts suppliers.

d)

A mobile sales agent is connecting to the company network via the Internet connection at a hotel.

e)

An employee who is working from home uses VPN client software on a laptop in order to connect to the company network.

35.

Which two IPsec protocols are used to provide data integrity?

a)

MD5

b)

DH

c)

AES

d)

RSA

e)

SHA

36.

If an outside host does not have the Cisco AnyConnect client preinstalled, how would the host gain access to the client image?

a)

The Cisco AnyConnect client is installed by default on most major operating systems.

b)

The host initiates a clientless VPN connection using a compliant web browser to download the client.

c)

The host initiates a clientless connection to a TFTP server to download the client.

d)

The host initiates a clientless connection to an FTP server to download the client.

37.

What are the two types of VPN connections? (Choose two.)

a)

PPPoE

b)

leased line

c)

site-to-site

d)

Frame Relay

e)

remote access

38.

What functionality does mGRE provide to the DMVPN technology?

a)

It allows the creation of dynamically allocated tunnels through a permanent tunnel source at the hub and dynamically allocated tunnel destinations at the spokes.

b)

It provides secure transport of private information over public networks, such as the Internet.

c)

It is a Cisco software solution for building multiple VPNs in an easy, dynamic, and scalable manner.

d)

It creates a distributed mapping database of public IP addresses for all VPN tunnel spokes.

39.

A network technician is configuring SNMPv3 and has set a security level of auth . What is the effect of this setting?

a)

authenticates a packet by a string match of the username or community string

b)

authenticates a packet by using either the HMAC with MD5 method or the SHA method

c)

authenticates a packet by using either the HMAC MD5 or 3.HMAC SHA algorithms and encrypts the packet with either the DES, 3DES or AES algorithms

d)

authenticates a packet by using the SHA algorithm only

40.

Which protocol provides authentication, integrity, and confidentiality services and is a type of VPN?

a)

MD5

b)

AES

c)

IPsec

d)

ESP

41.

Which statement accurately describes a characteristic of IPsec?

a)

IPsec works at the application layer and protects all application data.

b)

IPsec is a framework of standards developed by Cisco that relies on OSI algorithms.

c)

IPsec is a framework of proprietary standards that depend on Cisco specific algorithms.

d)

IPsec works at the transport layer and protects data at the network layer.

e)

IPsec is a framework of open standards that relies on existing algorithms.

42.

Which statement describes a VPN?

a)

VPNs use logical connections to create public networks through the Internet.

b)

VPNs use open source virtualization software to create the tunnel through the Internet.

c)

VPNs use open source virtualization software to create the tunnel through the Internet.

d)

VPNs use virtual connections to create a private network through a public network.

43.

Two corporations have just completed a merger. The network engineer has been asked to connect the two corporate networks without the expense of leased lines. Which solution would be the most cost effective method of providing a proper and secure connection between the two corporate networks?

a)

Cisco Secure Mobility Clientless SSL VPN

b)

Cisco AnyConnect Secure Mobility Client with SSL

c)

site-to-site VPN

d)

remote access VPN using IPsec

e)

Frame Relay

44.

Which type of VPN allows multicast and broadcast traffic over a secure site-to-site VPN?

a)

dynamic multipoint VPN

b)

SSL VPN

c)

GRE over IPsec

d)

IPsec virtual tunnel interface

45.

Which type of VPN connects using the Transport Layer Security (TLS) feature?

a)

SSL VPN

b)

GRE over IPsec

c)

IPsec virtual tunnel interface

d)

dynamic multipoint VPN

46.

Which three types of VPNs are examples of enterprise-managed site-to-site VPNs? (Choose three.)

a)

clientless SSL VPN

b)

client-based IPsec VPN

c)

IPsec VPN

d)

GRE over IPsec VPN

e)

Cisco Dynamic Multipoint VPN

47.

Which type of VPN uses a hub-and-spoke configuration to establish a full mesh topology?

a)

MPLS VPN

b)

GRE over IPsec

c)

dynamic multipoint VPN

d)

IPsec virtual tunnel interface

48.

Which type of VPN is the preferred choice for support and ease of deployment for remote access?

a)

SSL VPN

b)

GRE over IPsec

c)

dynamic multipoint VPN

d)

IPsec virtual tunnel interface

49.

Which type of VPN provides a flexible option to connect a central site with branch sites?

a)

MPLS VPN

b)

GRE over IPsec

c)

dynamic multipoint VPN

d)

Psec virtual tunnel interface

50.

Which type of VPN involves the forwarding of traffic over the backbone through the use of labels distributed among core routers?

a)

MPLS VPN

b)

GRE over IPsec

c)

dynamic multipoint VPN

d)

IPsec virtual tunnel interface

51.

Which type of VPN involves a nonsecure tunneling protocol being encapsulated by IPsec?

a)

SSL VPN

b)

GRE over IPsec

c)

dynamic multipoint VPN

d)

IPsec virtual tunnel interface

52.

Which type of VPN routes packets through virtual tunnel interfaces for encryption and forwarding?

a)

MPLS VPN

b)

GRE over IPsec

c)

dynamic multipoint VPN

d)

IPsec virtual tunnel interface

53.

A network technician is configuring SNMPv3 and has set a security level of SNMPv3 authPriv. What is a feature of using this level?

a)

authenticates a packet by using the SHA algorithm only

b)

authenticates a packet by a string match of the username or community string

c)

authenticates a packet by using either the HMAC with MD5 method or the SHA method

d)

authenticates a packet by using either the HMAC MD5 or HMAC SHA algorithms and a username