juniper认证考试

Regarding an IPsec security association (SA), which two statements are true?()A、IKE SA is bidirectional.B、IPsec SA is bidirectional.C、IKE SA is established during phase 2 negotiations.D、IPsec SA is established during phase 2 negotiations.

题目

Regarding an IPsec security association (SA), which two statements are true?()

  • A、IKE SA is bidirectional.
  • B、IPsec SA is bidirectional.
  • C、IKE SA is established during phase 2 negotiations.
  • D、IPsec SA is established during phase 2 negotiations.
如果没有搜索结果,请直接 联系老师 获取答案。
如果没有搜索结果,请直接 联系老师 获取答案。
相似问题和答案

第1题:

Which statement is true regarding IPsec VPNs?()

A. There are five phases of IKE negotiation.

B. There are two phases of IKE negotiation.

C. IPsec VPN tunnels are not supported on SRX Series devices.

D. IPsec VPNs require a tunnel PIC in SRX Series devices.


参考答案:D

第2题:

关于安全联盟SA,说法正确的是()。

A.IKE SA是单向的

B.IPSEC SA是双向的

C.IKE SA是双向的

D.IPSEC SA是单向的


答案CD

第3题:

()是IPSec规定的一种用来自动管理SA的协议,包括建立、协商、修改和删除SA等。

A.SSL

B.IKE

C.AHC

D.ESP


正确答案:B

第4题:

During the Easy VPN Remote connection process,which phase involves pushing the IP address, Domain Name System (DNS),and split tunnel attributes to the client?()

  • A、mode configuration
  • B、the VPN client establishment of an ISAKMP SA
  • C、IPsec quick mode completion of the connection
  • D、VPN client initiation of the IKE phase 1 process

正确答案:A

第5题:

Which of the following commands will display a router’s crypto map IPsec security associationsettings?()

  • A、show crypto map ipsec sa
  • B、show crypto map
  • C、show crypto engine connections active
  • D、show ipsec crypto map
  • E、show crypto map sa
  • F、show ipsec crypto map sa

正确答案:A

第6题:

An IPsec tunnel is established on an SRX Series Gateway on an interface whose IP address was obtained using DHCP.Which two statements are true? ()(Choose two.)

A. Only main mode can be used for IKE negotiation

B. A local-identity must be defined

C. It must be the initiator for IKE

D. A remote-identity must be defined


参考答案:B, C

第7题:

IPSECSA和IKESA的主要区别是()

A.IPSEC SA是单向的,IKE SA是双向的

B.通道两端只有一个IKE SA但IPSEC SA不止一对

C.IKE SA没有生存期

D.IPSEC SA有对端地址


参考答案:A, B

第8题:

Click the Exhibit button.[A] establishes an IPsec tunnel with [B]. The NAT device translates the IP address 1.1.1.1 to 2.1.1.1.On which port is the IKE SA established?()

A.TCP 500

B.UDP 500

C.TCP 4500

D.UDP 4500


参考答案:D

第9题:

下列关于IPSec与IKE的说法正确的是()。

  • A、IPSec只能通过与IKE配合方式才能建立起安全联盟
  • B、IKE只能与IPSec配合使用
  • C、IKE只负责为IPSec建立提供安全密钥,不参与IPSec SA协商
  • D、IPSec SA建立后,数据转发与IKE无关

正确答案:D

第10题:

IPSec VPN is a widely-acknowledged solution for enterprise network. Which three IPsec VPNstatements are true?()

  • A、IKE keepalives are unidirectional and sent every ten seconds
  • B、IPsec uses the Encapsulating Security Protocol (ESP) or the Authentication Header (AH)protocol for exchanging keys
  • C、To establish IKE SA, main mode utilizes six packets while aggressive mode utilizes only threepackets
  • D、IKE uses the Diffie-Hellman algorithm to generate symmetrical keys to be used by IPsec peers

正确答案:A,C,D

更多相关问题