Worksheetsmod 8
Total questions: 53
Worksheet time: 13hrs 15mins
Which two statements describe a remote access VPN? (Choose two.)
It connects entire networks to each other.
It requires hosts to send TCP/IP traffic through a VPN gateway.
It is used to connect individual hosts securely to a company network over the Internet.
It requires static configuration of the VPN tunnel.
It may require VPN client software on hosts.
The use of 3DES within the IPsec framework is an example of which of the five IPsec building blocks?
integrity
Diffie-Hellman
confidentiality
nonrepudiation
authentication
Which type of VPN may require the Cisco VPN Client software?
MPLS VPN
site-to-site VPN
SSL VPN
remote access VPN
Which technique is necessary to ensure a private transfer of data using a VPN?
scalability
encryption
authorization
virtualization
What are the two fundamental Dynamic Multipoint VPN tunnel types? (Choose two.)
client-to-site
server-to-client
site-to-site
hub-to-spoke
spoke-to-spoke
What are two reasons a company would use a VPN? (Choose two.)
to test network connections to remote users
to connect remote users to the network
to eliminate the need of having a gateway
to increase bandwidth to the network
to allow suppliers to access the network
True or False? All VPNs securely transmit clear text across the Internet.
true
false
Which solution allows workers to telecommute effectively and securely?
dial-up connection
site-to-site VPN
DSL connection
remote-access VPN
Which VPN type is a service provider managed VPN?
Layer 3 MPLS VPN
GRE over IPsec VPN
site-to-site VPN
remote access VPN
Which IPsec framework protocol provides data integrity and data authentication, but does not provide data confidentiality?
AH
DH
ESP
IP protocol 50
What algorithm is used to provide data integrity of a message through the use of a calculated hash value?
DH
HMAC
AES
RSA
Which statement describes the effect of key length in deterring an attacker from hacking through an encryption key?
The shorter the key, the harder it is to break.
The length of a key will not vary between encryption algorithms.
The length of a key does not affect the degree of security.
The longer the key, the more key possibilities exist.
What is a type of VPN that is generally transparent to the end user?
public
remote access
site-to-site
remote access
A network design engineer is planning the implementation of a cost-effective method to interconnect multiple networks securely over the internet. Which type of technology is required?
a dedicated ISP
a VPN gateway
a GRE IP tunnel
a leased line
Which statement is true of site-to-site VPNs?
Individual hosts can enable and disable the VPN connection.
Internal hosts send normal, unencapsulated packets.
The VPN connection is not statically defined.
VPN client software is installed on each host.
How is the hash message authentication code (HMAC) algorithm used in an IPsec VPN?
to authenticate the IPsec peers
to create a secure channel for key negotiation
to guarantee message integrity
to protect IPsec keys during session negotiation
What IPsec algorithm is used to provide data confidentiality?
AES
Diffie-Hellman
MD5
RSA
SHA
What are two hashing algorithms used with IPsec to guarantee authenticity? (Choose two.)
AES
DH
MD5
RSA
SHA
What two IPsec algorithms provide encryption and hashing to protect interesting traffic? (Choose two.)
AES
DH
IKE
PSK
SHA
Which protocol creates a virtual unencrypted pointto-point VPN tunnel between Cisco routers?
IKE
IPsec
GRE
OSPF
Which VPN solution allows the use of a web browser to establish a secure, remote-access VPN tunnel to a VPN gateway?
client-based SSL
clientless SSL
site-to-site using a pre-shared key
site-to-site using an ACL
Which IPsec security function utilizes encryption to protect data transfers with a key?
authentication
confidentiality
integrity
secure key exchange
Which of the following are service provider managed VPN solutions? (Choose two.)
client-based IPsec VPN
clientless SSL VPN
Frame Relay
Layer 3 MPLS VPN
remote-access VPN
Which of the following are enterprise-managed remote-access VPNs? (Choose two.)
client-based IPsec VPN
clientless SSL VPN
Frame Relay
Layer 3 MPLS VPN
remote-access VPN
Which is a requirement of a site-to-site VPN?
Hosts connected using a web browser and an SSL connection
Hosts connected using client-based VPN software
A client/server architecture
VPN server at the edge of the company network
VPN gateways at each end of the tunnel
How is the Diffie-Hellman algorithm used in the IPsec framework?
allows peers to exchange shared keys
guarantees message integrity
provides authentication
provides strong data encryption
Which type of VPN involves passenger, carrier, and transport protocols?
DMVPN
GRE over IPsec
IPsec virtual tunnel interface
MPLS VPN
Which type of VPN supports multiple sites by applying configurations to virtual interfaces instead of physical interfaces?
DMVPN
MPLS VPN
IPsec virtual tunnel interface
GRE over IPsec
Which type of VPN connects using the Transport Layer Security (TLS) feature?
GRE over IPsec
SSL VPN
DMVPN
MPLS VPN
IPsec virtual tunnel interface
Which description correctly identifies an MPLS VPN?
allows multicast and broadcast traffic over a secure site-to-site VPN
involves a nonsecure tunneling protocol being encapsulated by IPsec
routes packets through virtual tunnel interfaces for encryption and forwarding.
uses the public key infrastructure and digital certificates.
has both Layer 2 and Layer 3 implementations
Which description correctly identifies an SSL VPN?
allows multicast and broadcast traffic over a secure site-to-site VPN
has both Layer 2 and Layer 3 implementations
involves a nonsecure tunneling protocol being encapsulated by IPsec
routes packets through virtual tunnel interfaces for encryption and forwarding
uses the public key infrastructure and digital certificates
Which two descriptions correctly identify an IPsec VTI VPN? (Choose two.)
allows multicast and broadcast traffic over a secure site-to-site VPN
has both Layer 2 and Layer 3 implementations
involves a nonsecure tunneling protocol being encapsulated by IPsec
routes packets through virtual tunnel interfaces for encryption and forwarding
uses the public key infrastructure and digital certificates
Which two descriptions correctly identify a GRE over IPsec VPN? (Choose two.)
allows multicast and broadcast traffic over a secure site-to-site VPN
involves a nonsecure tunneling protocol being encapsulated by IPsec
has both Layer 2 and Layer 3 implementations
routes packets through virtual tunnel interfaces for encryption and forwarding
uses the public key infrastructure and digital certificates
Which two scenarios are examples of remote access VPNs? (Choose two.)
All users at a large branch office can access company resources through a single VPN connection.
A small branch office with three employees has a Cisco ASA that is used to create a VPN connection to the HQ.
A toy manufacturer has a permanent VPN connection to one of its parts suppliers.
A mobile sales agent is connecting to the company network via the Internet connection at a hotel.
An employee who is working from home uses VPN client software on a laptop in order to connect to the company network.
Which two IPsec protocols are used to provide data integrity?
MD5
DH
AES
RSA
SHA
If an outside host does not have the Cisco AnyConnect client preinstalled, how would the host gain access to the client image?
The Cisco AnyConnect client is installed by default on most major operating systems.
The host initiates a clientless VPN connection using a compliant web browser to download the client.
The host initiates a clientless connection to a TFTP server to download the client.
The host initiates a clientless connection to an FTP server to download the client.
What are the two types of VPN connections? (Choose two.)
PPPoE
leased line
site-to-site
Frame Relay
remote access
What functionality does mGRE provide to the DMVPN technology?
It allows the creation of dynamically allocated tunnels through a permanent tunnel source at the hub and dynamically allocated tunnel destinations at the spokes.
It provides secure transport of private information over public networks, such as the Internet.
It is a Cisco software solution for building multiple VPNs in an easy, dynamic, and scalable manner.
It creates a distributed mapping database of public IP addresses for all VPN tunnel spokes.
A network technician is configuring SNMPv3 and has set a security level of auth . What is the effect of this setting?
authenticates a packet by a string match of the username or community string
authenticates a packet by using either the HMAC with MD5 method or the SHA method
authenticates a packet by using either the HMAC MD5 or 3.HMAC SHA algorithms and encrypts the packet with either the DES, 3DES or AES algorithms
authenticates a packet by using the SHA algorithm only
Which protocol provides authentication, integrity, and confidentiality services and is a type of VPN?
MD5
AES
IPsec
ESP
Which statement accurately describes a characteristic of IPsec?
IPsec works at the application layer and protects all application data.
IPsec is a framework of standards developed by Cisco that relies on OSI algorithms.
IPsec is a framework of proprietary standards that depend on Cisco specific algorithms.
IPsec works at the transport layer and protects data at the network layer.
IPsec is a framework of open standards that relies on existing algorithms.
Which statement describes a VPN?
VPNs use logical connections to create public networks through the Internet.
VPNs use open source virtualization software to create the tunnel through the Internet.
VPNs use open source virtualization software to create the tunnel through the Internet.
VPNs use virtual connections to create a private network through a public network.
Two corporations have just completed a merger. The network engineer has been asked to connect the two corporate networks without the expense of leased lines. Which solution would be the most cost effective method of providing a proper and secure connection between the two corporate networks?
Cisco Secure Mobility Clientless SSL VPN
Cisco AnyConnect Secure Mobility Client with SSL
site-to-site VPN
remote access VPN using IPsec
Frame Relay
Which type of VPN allows multicast and broadcast traffic over a secure site-to-site VPN?
dynamic multipoint VPN
SSL VPN
GRE over IPsec
IPsec virtual tunnel interface
Which type of VPN connects using the Transport Layer Security (TLS) feature?
SSL VPN
GRE over IPsec
IPsec virtual tunnel interface
dynamic multipoint VPN
Which three types of VPNs are examples of enterprise-managed site-to-site VPNs? (Choose three.)
clientless SSL VPN
client-based IPsec VPN
IPsec VPN
GRE over IPsec VPN
Cisco Dynamic Multipoint VPN
Which type of VPN uses a hub-and-spoke configuration to establish a full mesh topology?
MPLS VPN
GRE over IPsec
dynamic multipoint VPN
IPsec virtual tunnel interface
Which type of VPN is the preferred choice for support and ease of deployment for remote access?
SSL VPN
GRE over IPsec
dynamic multipoint VPN
IPsec virtual tunnel interface
Which type of VPN provides a flexible option to connect a central site with branch sites?
MPLS VPN
GRE over IPsec
dynamic multipoint VPN
Psec virtual tunnel interface
Which type of VPN involves the forwarding of traffic over the backbone through the use of labels distributed among core routers?
MPLS VPN
GRE over IPsec
dynamic multipoint VPN
IPsec virtual tunnel interface
Which type of VPN involves a nonsecure tunneling protocol being encapsulated by IPsec?
SSL VPN
GRE over IPsec
dynamic multipoint VPN
IPsec virtual tunnel interface
Which type of VPN routes packets through virtual tunnel interfaces for encryption and forwarding?
MPLS VPN
GRE over IPsec
dynamic multipoint VPN
IPsec virtual tunnel interface
A network technician is configuring SNMPv3 and has set a security level of SNMPv3 authPriv. What is a feature of using this level?
authenticates a packet by using the SHA algorithm only
authenticates a packet by a string match of the username or community string
authenticates a packet by using either the HMAC with MD5 method or the SHA method
authenticates a packet by using either the HMAC MD5 or HMAC SHA algorithms and a username
