|
The
exam is tough but the guide from
www.exam.ws was really helpful.
Q.1 How is user authentication enabled on the Cisco VPN 3002?
A. Checked on the Cisco VPN
Concentrator and pushed down to the Cisco VPN 3002.
B. Unchecked on the Cisco
VPN Concentrator and pushed down to the Cisco VPN 3002.
C. Checked on the Cisco VPN
3002.
D. Unchecked on the Cisco
VPN 3002.
Answer:
Q.2 Configuring a bandwidth policing policy is a two-step process:
configuring, then applying the policy.
Where are the configured bandwidth policies applied on the VPN
Concentrator? (Choose two)
A. Must be applied to an
interface.
B. Optionally applied to an
interface..
C. Must be applied to a group.
D. Optionally applied to a
group.
E. Must be applied to a
LAN-to-LAN tunnel.
F. Optionally applied to a
LAN-to-LAN tunnel.
Answer:
Q.3 What are three functions of IKE Phase 2? (Choose three)
A. Uses aggressive mode.
B. Uses main mode.
C. Optionally performs an
additional DH exchange.
D. Verifies the other side's
identity.
E. Periodically renegotiates
IPSec SAs to ensure security.
F. Negotiates IPSec SA
parameter protected by an existing IKE S
Answer:
Q.4 Which is true about the Cisco VPN 3002 unit authentication
option?
A. The username and
password are pushed down to the Cisco VPN 3002 during tunnel
establishment.
B. The Cisco VPN 3002
prompts the user for a unit password before a tunnel is established.
C. The Cisco VPN 3002
prompts the user for the username and password before a tunnel is
established.
D. The tunnel is
established without user intervention.
Answer:
Q.5 For network extension RRI, which IP address does the Cisco VPN
Concentrator advertise?
A. Cisco VPN Client NIC IP
address
B. Cisco VPN 3002 assigned IP
address
C. Cisco VPN 3002 public
interface IP address
D. Cisco VPN 3002 private
interface network address.
Answer:
Q.6 Which feature allows an administrator to edit the reachable
subnets at both ends of the LAN-to- LAN tunnel?
A. Network auto-discovery
B. Cisco VPN configuration
tool
C. Network lists
D. LAN-to-LAN wizard
Answer:
Q.7 What type of keys does DES and 3DES require for encryption and
decryption?
A. Elliptical curve keys
B. Exponentiation keys
C. Symmetrical keys
D. Asymmetrical keys
Answer:
Q.8 What are the three steps in the auto-update configuration
process? (Choose three)
A. Enable the client update
functionality in the Cisco VPN 3002.
B. Enable the client update
functionality in the Cisco VPN Concentrator.
C. Modify the group-client,
auto-update parameter.
D. Configure the IKE
auto-update message parameters.
E. Send an update message.
F. Configure the IPSec
auto-update message parameters.
Answer: B, C, E
Q.9 Which Cisco IOS VPN feature allows the sender to encrypt packets
before transmitting them across a network?
A. Anti-replay
B. Data confidentiality
C. Data integrity
D. Data original
authentication
Answer: B
Q.10 How is data authentication achieved?
A. Using DES
B. Using ESP
C. Using MD5
D. Using 3DES
Answer: C
Q.11 What is the name of the application that must be added to the
Concentrator to perform load balancing?
A. Virtual Termination Point (VTP)
B. Virtual Designated
Concentrator (VDC)
C. Virtual Cluster Agent (VCA)
D. Virtual Access Point (VAP)
Answer: C
Q.12 What does the backup server feature enable the Cisco VPN 3002
to access?
A. Backup DHCP server
B. Backup Cisco VPN
Concentrator
C. Backup authentication
server
D. Backup certificate server
Answer: B
Q.13 What are three functions of IKE Phase 2? (Choose three)
A. Uses aggressive mode.
B. Uses main mode.
C. Optionally performs an
additional DH exchange.
D. Verifies the other side's
identity..
E. Periodically renegotiates
IPSec SAs to ensure security.
F. Negotiates IPSec SA
parameters protected by an existing IKE SA.
Answer: C, E, F
Q.14 Which feature is supported on the Cisco VPN 3005?
A. It supports up to 3 network
ports.
B. It supports up to 100
sessions
C. Its hardware is
upgradeable.
D. 64 MB of memory is
standard.
Answer: B
Q.15 If the primary role of the VPN product is to perform
site-to-site VPN with a few remote access connections, which product
should you choose?
A. PIX Firewall 515
B. 2900
C. 3030
D. 3660
Answer: D
|