多选题Which three security concerns can be addressed by a tunnel mode IPsec VPN secured by AH?()Adata integrityBdata confidentialityCdata authenticationDouter IP header confidentialityEouter IP header authentication

题目
多选题
Which three security concerns can be addressed by a tunnel mode IPsec VPN secured by AH?()
A

data integrity

B

data confidentiality

C

data authentication

D

outer IP header confidentiality

E

outer IP header authentication

如果没有搜索结果或未解决您的问题,请直接 联系老师 获取答案。
相似问题和答案

第1题:

What does qos pre-classify provides inregardto implementing QoS over GRE/IPSec VPN tunnels?()

  • A、 enables IOS to copy the ToS field from the inner (original) IPheader to theouter tunnel IP header
  • B、 enables IOS to make a copy of the inner (original) IP header and to run a QoS classification before encryption, based on fields in the inner IP header.
  • C、 enables IOS to classify packets based on the ToS field in the inner (original) IP header
  • D、 enables IOS to classify packets based on the ToS field in the outer tunnel IP header
  • E、 enables the IOS classification engine to only see a single encrypted and tunneledflow to reduce classification complexity

正确答案:B

第2题:

What is the port number of the IPsec Authentication Header packet?()

  • A、IP protocol 50
  • B、TCP port 51
  • C、UDP port 50
  • D、IP protocol 51
  • E、UDP port 51
  • F、TCP port 50

正确答案:D

第3题:

Which three security concerns can be addressed by a tunnel mode IPsec VPN secured by ESP?() (Choose three.)

A. data integrity

B. data confidentiality

C. data authentication

D. outer IP header confidentiality

E. outer IP header authentication


参考答案:A, B, C

第4题:

What is not a difference between VPN tunnel authentication and per-user authentication?()

  • A、VPN tunnel authentication is part of the IKE specification. 
  • B、VPN tunnel authentication does not control which end user can use the IPSec SA (VPN tunnel).
  • C、User authentication is used to control access for a specific user ID, and can be used with or without a VPN tunnel for network access authorization. 
  • D、802.1X with EAP-TLS (X.509 certificates) can be used to authenticate an IPSec tunnel.

正确答案:D

第5题:

You need to configure a GRE tunnel on a IPSec router. When you are using the SDM to configurea GRE tunnel over IPsec, which two parameters are required when defining the tunnel interfaceinformation?()

  • A、The crypto ACL number
  • B、The IPSEC mode (tunnel or transport)
  • C、The GRE tunnel interface IP address
  • D、The GRE tunnel source interface or IP address, and tunnel destination IP address
  • E、The MTU size of the GRE tunnel interface

正确答案:C,D

第6题:

During the Easy VPN Remote connection process,which phase involves pushing the IP address, Domain Name System (DNS),and split tunnel attributes to the client?()

  • A、mode configuration
  • B、the VPN client establishment of an ISAKMP SA
  • C、IPsec quick mode completion of the connection
  • D、VPN client initiation of the IKE phase 1 process

正确答案:A

第7题:

IPSec VPN is a widely-acknowledged solution for enterprise network. Which three IPsec VPNstatements are true?()

  • A、IKE keepalives are unidirectional and sent every ten seconds
  • B、IPsec uses the Encapsulating Security Protocol (ESP) or the Authentication Header (AH)protocol for exchanging keys
  • C、To establish IKE SA, main mode utilizes six packets while aggressive mode utilizes only threepackets
  • D、IKE uses the Diffie-Hellman algorithm to generate symmetrical keys to be used by IPsec peers

正确答案:A,C,D

第8题:

Which three security concerns can be addressed by a tunnel mode IPsec VPN secured by AH?() (Choose three.)

A. data integrity

B. data confidentiality

C. data authentication

D. outer IP header confidentiality

E. outer IP header authentication


参考答案:A, C, E

第9题:

Which three features are benefits of using GRE tunnels in conjunction with IPsec for building site-to-site VPNs?()

  • A、allows dynamic routing over the tunnel
  • B、supports multi-protocol (non-IP) traffic over the tunnel
  • C、reduces IPsec headers overhead since tunnel mode is used
  • D、simplifies the ACL used in the crypto map
  • E、uses Virtual Tunnel Interface (VTI) to simplify the IPsec VPN configuration

正确答案:A,B,D

第10题:

Which QoS preclassification option will require the use of the qos pre-classify command for the VPN traffic? ()

  • A、VPN traffic needs to be classified based on the Layer2 header information
  • B、VPN traffic needs to be classified based on the IP precedence or DSCP
  • C、VPN traffic needs to be classified based on IP flow or Layer 3 information, such as source and destination IP address
  • D、VPN traffic with Authentication Header (AH) needs to preserve the ToS byte

正确答案:C

更多相关问题