A.If the VPN server is configured for Xauth, the VPN client waits for a username / password challenge.
B.The Cisco Easy VPN feature only supports transform sets that provide authentication and encryption.
C.The VPN client initiates aggressive mode (AM) if a pre-shared key is used for authentication during the IKE phase 1 process.
D.The VPN client verifies a server username/password challenge by using a AAA authentication server that supports TACACS+ or RADIUS.
E.The VPN server can only be enabled on Cisco PIX Firewalls and Cisco VPN 3000 series concentrators.
F.When connecting with a VPN client,the VPN server must be configured for ISAKMP group 1,2 or 5.
您可能感興趣的試卷
你可能感興趣的試題
Refer to the exhibit.
Which statement about the authentication process is true?()
A.The LIST1 list will disable authentication on the console port.
B.Because no method list is specified, the LIST1 list will not authenticate anyone on the console port.
C.All login requests will be authenticated using the group tacacs+ method.
D.All login requests will be authenticated using the local database method.
E.The default login authentication will automatically be applied to all login connections.
Refer to the exhibit. What type of security solution will be provided for the inside network?()
A.The TCP connection that matches the defined ACL will be reset by the router if the connection does not complete the three-way handshake within the defined time period.
B.The router will reply to the TCP connection requests. If the three-way handshake completes successfully, the router will establish a TCP connection between itself and the server.
C.The TCP traffic that matches the ACL will be allowed to pass through the router and create a TCP connection with the server.
D.The router will intercept the traceroute messages. It will validate the connection requests before forwarding the packets to the inside network.
Refer to the exhibit.
What are the two options that are used to provide High Availability IPsec?()
A.RRI
B.IPsec Backup Peerings
C.Dynamic Crypto Ma
D.HSRP
E.IPsec Stateful Switchover (SSO)
F.Dual Router Mode (DRM) IPsec
A.Cisco Express Forwarding (CEF) must be enabled as a prerequisite to running MPLS on a Cisco router.
B.Frame-mode MPLS inserts a 32-bit label between the Layer 3 and Layer 4 headers.
C.MPLS is designed for use with frame-based Layer 2 encapsulation protocols such as Frame Relay, but is not supported by ATM because of ATM fixed-length cells.
D.OSPF, EIGRP, IS-IS, RIP, and BGP can be used in the control plane.
E.The control plane is responsible for forwarding packets.
F.The two major components of MPLS include the control plane and the data plane.
Refer to the exhibit, which shows a PPPoA diagram and partial SOHO77 configuration.
Which command needs to be applied to the SOHO77 to complete the configuration?()
A.encapsulation aal5snap applied to the PVC
B.encapsulation aal5ciscoppp applied to the PVC
C.encapsulation aal5ciscoppp applied to the ATM0 interface
D.encapsulation aal5mux ppp dialer applied to the ATM0 interface
E.encapsulation aal5mux ppp dialer applied to the PVC
最新試題
During the Easy VPN Remote connection process,which phase involves pushing the IP address, Domain Name System (DNS),and split tunnel attributes to the client?()
Which three statements about IOS Firewall configurations are true?()
Refer to the exhibit, which shows a PPPoA diagram and partial SOHO77 configuration.Which command needs to be applied to the SOHO77 to complete the configuration?()
Which three MPLS statements are true?()
Which three statements about the Cisco Easy VPN feature are true?()
What is a reason for implementing MPLS in a network?()
What are the four fields in an MPLS label?()
Which statement is true when ICMP echo and echo-reply are disabled on edge devices?()
Which two mechanisms can be used to detect IPsec GRE tunnel failures?()
Refer to the exhibit. MPLS has been configured on all routers in the domain. In order for R2 and R3 to forward frames between them with label headers, what additional configuration will be required on devices that are attached to the LAN segment?()