Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Module 8 Questions

Total questions: 51

Worksheet time: 26mins

Name
Class
Date
1.
Which VPN benefit allows an enterprise to easily add more users to the network?
a)
Cost Savings
b)
Security
c)
Scalability
d)
Compatibility
2.
Which VPN benefit allows an enterprise to increase the bandwidth for remote sites without necessarily adding more equipment or WAN links?
a)
Cost Savings
b)
Security
c)
Scalability
d)
Compatibility
3.
Which VPN benefit uses advanced encryption and authentication protocols to protect data from unauthorized access?
a)
Cost Savings
b)
Security
c)
Scalability
d)
Compatibility
4.
Which type of VPN is used to connect a mobile user?
a)
Site-to-site
b)
Remote-access
c)
GRE
d)
IPsec
5.
Which VPN solutions are typically managed by an enterprise? (Choose three)
a)
MPLS Layer 2
b)
MPLS Layer 3
c)
IPsec
d)
SSL
e)
DMVPN
6.
What type of VPN can be established with a web browser using HTTPS?
a)
IPsec
b)
Client-based VPN
c)
Site-to-Site VPN
d)
Clientless VPN
7.
Which feature describes SSL VPNs?
a)
All IP-based applications are supported
b)
Only requires a web browser on a host
c)
Specific devices with specific configurations can connect
d)
Uses two-way authentication with shared keys or digital certificates
8.
What type of protocol is GRE?
a)
Security protocol
b)
Passenger protocol
c)
Carrier protocol
d)
Transport protocol
9.
What type of VPN enables an enterprise to rapidly scale secure access across the organization?
a)
DMVPN
b)
Remote-access VPN
c)
Site-to-Site VPN
d)
MPLS VPN
10.
What type of VPN enables an enterprise to emulate an Ethernet multiaccess LAN with remote sites?
a)
DMVPN
b)
Remote-access VPN
c)
Site-to-Site VPN
d)
MPLS VPN
11.
IPsec can protect traffic in which OSI layers? (Choose four.)
a)
Layer 3
b)
Layer 4
c)
Layer 5
d)
Layer 6
e)
Layer 7
12.
Which IPsec function uses pre-shared passwords, digital certificates, or RSA certificates?
a)
IPsec protocol
b)
Confidentiality
c)
Integrity
d)
Authentication
e)
Diffie-Hellman
13.
True or False: The IPsec framework must be updated each time a new standard is developed.
a)
True
b)
False
14.
Which choices are packet encapsulation options supported by IPsec? (Choose two.)
a)
AES
b)
AH
c)
DH24
d)
ESP
e)
PSK
15.
Which choices provide for the Confidentiality function in the IPsec framework? (Choose three.)
a)
3DES
b)
AES
c)
AH
d)
SEAL
e)
PSK
16.
Which choices provide for the Integrity function in the IPsec framework? (Choose two.)
a)
AES
b)
AH
c)
DH24
d)
MD5
e)
SHA
17.
Which choices are available for the Authentication function in the IPsec framework? (Choose two.)
a)
AES
b)
AH
c)
DH24
d)
PSK
e)
RSA
18.
Which Diffie-Hellman group choices are no longer recommended?
a)
DH groups 1, 2, and 5
b)
DH groups 14, 15, and 16
c)
DH groups 19, 20, 21 and 24
19.
Which two statements describe a remote access VPN? (Choose two.)
a)
It connects entire networks to each other.
b)
It requires hosts to send TCP/IP traffic through a VPN gateway.
c)
It is used to connect individual hosts securely to a company network over the Internet.
d)
It may require VPN client software on hosts.
e)
It requires static configuration of the VPN tunnel.
20.
The use of 3DES within the IPsec framework is an example of which of the five IPsec building blocks?
a)
Diffie-Hellman
b)
integrity
c)
authentication
d)
nonrepudiation
e)
Confidentiality
21.
Which type of VPN may require the Cisco VPN Client software?
a)
MPLS VPN
b)
site-to-site VPN
c)
remote access VPN
d)
SSL VPN
22.
Which technique is necessary to ensure a private transfer of data using a VPN?
a)
scalability
b)
authorization
c)
virtualization
d)
Encryption
23.
What are the two fundamental Dynamic Multipoint VPN tunnel types? (Choose two.)
a)
client-to-site
b)
server-to-client
c)
site-to-site
d)
hub-to-spoke
e)
Spoke-to-spoke
24.
What are two reasons a company would use a VPN? (Choose two.)
a)
to test network connections to remote users
b)
to increase bandwidth to the network
c)
to eliminate the need of having a gateway
d)
to connect remote users to the network
e)
to allow suppliers to access the network
25.
True or False? All VPNs securely transmit clear text across the Internet.
a)
true
b)
False
26.
Which solution allows workers to telecommute effectively and securely?
a)
dial-up connection
b)
site-to-site VPN
c)
DSL connection
d)
remote-access VPN
27.
Which VPN type is a service provider managed VPN?
a)
GRE over IPsec VPN
b)
site-to-site VPN
c)
remote access VPN
d)
Layer 3 MPLS VPN
28.
Which IPsec framework protocol provides data integrity and data authentication, but does not provide data confidentiality?
a)
DH
b)
ESP
c)
AH
d)
IP protocol 50
29.
What algorithm is used to provide data integrity of a message through the use of a calculated hash value?
a)
AES
b)
RSA
c)
DH
d)
HMAC
30.
Which statement describes the effect of key length in deterring an attacker from hacking through an encryption key?
a)
The shorter the key, the harder it is to break.
b)
The length of a key will not vary between encryption algorithms.
c)
The length of a key does not affect the degree of security.
d)
The longer the key, the more key possibilities exist.
31.
What is a type of VPN that is generally transparent to the end user?
a)
public
b)
remote access
c)
private
d)
site-to-site
32.
A network design engineer is planning the implementation of a cost-effective method to interconnect multiple networks securely over the internet. Which type of technology is required?
a)
a dedicated ISP
b)
a GRE IP tunnel
c)
a leased line
d)
a VPN gateway
33.
Which statement is true of site-to-site VPNs?
a)
Individual hosts can enable and disable the VPN connection.
b)
Internal hosts send normal, unencapsulated packets.
c)
The VPN connection is not statically defined.
d)
VPN client software is installed on each host.
34.
How is the hash message authentication code (HMAC) algorithm used in an IPsec VPN?
a)
to authenticate the IPsec peers
b)
to create a secure channel for key negotiation
c)
to guarantee message integrity
d)
to protect IPsec keys during session negotiation
35.
What IPsec algorithm is used to provide data confidentiality?
a)
AES
b)
Diffie-Hellman
c)
MD5
d)
RSA
e)
SHA
36.
What are two hashing algorithms used with IPsec to guarantee authenticity? (Choose two.)
a)
AES
b)
DH
c)
MD5
d)
RSA
e)
SHA
37.
What two IPsec algorithms provide encryption and hashing to protect interesting traffic? (Choose two.)
a)
AES
b)
DH
c)
IKE
d)
PSK
e)
SHA
38.
Which protocol creates a virtual unencrypted point-to-point VPN tunnel between Cisco routers?
a)
GRE
b)
IKE
c)
IPsec
d)
OSPF
39.
Which VPN solution allows the use of a web browser to establish a secure, remote-access VPN tunnel to a VPN gateway?
a)
client-based SSL
b)
clientless SSL
c)
site-to-site using a pre-shared key
d)
site-to-site using an ACL
40.
Which IPsec security function utilizes encryption to protect data transfers with a key?
a)
Authentication
b)
Confidentiality
c)
Integrity
d)
secure key exchange
41.
Which of the following are service provider managed VPN solutions? (Choose two.)
a)
client-based IPsec VPN
b)
clientless SSL VPN
c)
Frame Relay
d)
Layer 3 MPLS VPN
e)
remote-access VPN
42.
Which of the following are enterprise-managed remote-access VPNs? (Choose two.)
a)
client-based IPsec VPN
b)
clientless SSL VPN
c)
Frame Relay
d)
Layer 3 MPLS VPN
e)
remote-access VPN
43.
Which is a requirement of a site-to-site VPN?
a)
Hosts connected using a web browser and an SSL connection
b)
Hosts connected using client-based VPN software
c)
A client/server architecture
d)
VPN gateways at each end of the tunnel
e)
VPN server at the edge of the company network
44.
How is the Diffie-Hellman algorithm used in the IPsec framework?
a)
allows peers to exchange shared keys
b)
guarantees message integrity
c)
provides authentication
d)
provides strong data encryption
45.
Which type of VPN involves passenger, carrier, and transport protocols?
a)
DMVPN
b)
GRE over IPsec
c)
IPsec virtual tunnel interface
d)
MPLS VPN
46.
Which type of VPN supports multiple sites by applying configurations to virtual interfaces instead of physical interfaces?
a)
IPsec virtual tunnel interface
b)
DMVPN
c)
MPLS VPN
d)
GRE over IPsec
47.
Which type of VPN connects using the Transport Layer Security (TLS) feature?
a)
SSL VPN
b)
GRE over IPsec
c)
DMVPN
d)
IPsec virtual tunnel interface
e)
MPLS VPN
48.
Which description correctly identifies an MPLS VPN?
a)
allows multicast and broadcast traffic over a secure site-to-site VPN
b)
has both Layer 2 and Layer 3 implementations
c)
involves a nonsecure tunneling protocol being encapsulated by IPsec
d)
routes packets through virtual tunnel interfaces for encryption and forwarding.
e)
uses the public key infrastructure and digital certificates.
49.
Which description correctly identifies an SSL VPN?
a)
allows multicast and broadcast traffic over a secure site-to-site VPN
b)
has both Layer 2 and Layer 3 implementations
c)
involves a nonsecure tunneling protocol being encapsulated by IPsec
d)
routes packets through virtual tunnel interfaces for encryption and forwarding
e)
uses the public key infrastructure and digital certificates
50.
Which two descriptions correctly identify an IPsec VTI VPN? (Choose two.)
a)
allows multicast and broadcast traffic over a secure site-to-site VPN
b)
has both Layer 2 and Layer 3 implementations
c)
involves a nonsecure tunneling protocol being encapsulated by IPsec
d)
routes packets through virtual tunnel interfaces for encryption and forwarding
e)
uses the public key infrastructure and digital certificates
51.
Which two descriptions correctly identify a GRE over IPsec VPN? (Choose two.)
a)
allows multicast and broadcast traffic over a secure site-to-site VPN
b)
has both Layer 2 and Layer 3 implementations
c)
involves a nonsecure tunneling protocol being encapsulated by IPsec
d)
routes packets through virtual tunnel interfaces for encryption and forwarding
e)
uses the public key infrastructure and digital certificates