Font size
Worksheetsunit 20: NAT , VPN
Total questions: 18
Worksheet time: 11mins
In IPsec, which mode adds additional protection because it encapsulates the original packet?
Transport mode only
Tunnel mode
all the previous
None of the previous
What must be configured to identify the interesting traffic for building an IPsec tunnel?
Access Control list
ISAKMP
IPSEC
Crypto MAP
How does a VPN shield your data from your ISP and attackers?
provide a specific leased line
By encrypting data in the tunnel
provide limited privilege to the service provider
all the previous
Site to Site VPN is Essential for secure inter-office communication across distances.
True
False
client-to-site for office networks, site-to-site for individual remote access.
True
False
IPsec consists of various protocols and services that provide protection for IP-based networks.
true
false
GRE tunnels allow OSPF to traverse IPsec by encapsulating multicast packets.
True
False
At which layer does IPsec function to provide encryption and authentication for data packets?
Data link layer
session Layer
Application Layer
Packet Layer
What is the command for verifying IPsec security association states?
show running-config
show crypto map
show crypto ipsec sa
show ip route
Which option does not belong to the ISAKMP policy configuration used in IKE Phase 1?
Transform-set selection
Access control list
setting IP address
Applying the crypto map to the router interface
With NAT Overload (PAT), both the IP address and port numbers are translated so multiple hosts can share a single public IP while keeping their flows separate.
True
False
outside local address is the address of the destination as seen from the
outside network.
True
False
What type of address represents the public IP assigned to a NAT device?
inside local
inside global
outside local
outside global
PAT enables one inside global IP to manage more than 65,000 simultaneous flows.
True
False
The actual, routable IP address assigned to an external host on the Internet.
(a)
The translated address of an external host as it appears to the inside network.
(a)
The translated IP address of an inside host as it appears to the outside world.
(a)
The actual IP address of an inside host before translation, used inside the local network.
(a)
