JN0-332

多选题Which three security concerns can be addressed by a tunnel mode IPsec VPN secured by AH?() (Choose three.)Adata integrityBdata confidentialityCdata authenticationDouter IP header confidentialityEouter IP header authentication

题目
多选题
Which three security concerns can be addressed by a tunnel mode IPsec VPN secured by AH?() (Choose three.)
A

data integrity

B

data confidentiality

C

data authentication

D

outer IP header confidentiality

E

outer IP header authentication

如果没有搜索结果,请直接 联系老师 获取答案。
如果没有搜索结果,请直接 联系老师 获取答案。
相似问题和答案

第1题:

Which three firewall user authentication objects can be referenced in a security policy? ()(Choose three.)

A. access profile

B. client group

C. client

D. default profile

E. external


参考答案:A, B, C

第2题:

IPSec VPN is a widely-acknowledged solution for enterprise network. Which three IPsec VPNstatements are true?()

  • A、IKE keepalives are unidirectional and sent every ten seconds
  • B、IPsec uses the Encapsulating Security Protocol (ESP) or the Authentication Header (AH)protocol for exchanging keys
  • C、To establish IKE SA, main mode utilizes six packets while aggressive mode utilizes only threepackets
  • D、IKE uses the Diffie-Hellman algorithm to generate symmetrical keys to be used by IPsec peers

正确答案:A,C,D

第3题:

Which three security concerns can be addressed by a tunnel mode IPsec VPN secured by ESP?() (Choose three.)

A. data integrity

B. data confidentiality

C. data authentication

D. outer IP header confidentiality

E. outer IP header authentication


参考答案:A, B, C

第4题:

Which three security concerns can be addressed by a tunnel mode IPsec VPN secured by ESP?() (Choose three.)

  • A、data integrity
  • B、data confidentiality
  • C、data authentication
  • D、outer IP header confidentiality
  • E、outer IP header authentication

正确答案:A,B,C

第5题:

What is not a difference between VPN tunnel authentication and per-user authentication?()

  • A、VPN tunnel authentication is part of the IKE specification. 
  • B、VPN tunnel authentication does not control which end user can use the IPSec SA (VPN tunnel).
  • C、User authentication is used to control access for a specific user ID, and can be used with or without a VPN tunnel for network access authorization. 
  • D、802.1X with EAP-TLS (X.509 certificates) can be used to authenticate an IPSec tunnel.

正确答案:D

第6题:

Which three security concerns can be addressed by a tunnel mode IPsec VPN secured by AH?() (Choose three.)

A. data integrity

B. data confidentiality

C. data authentication

D. outer IP header confidentiality

E. outer IP header authentication


参考答案:A, C, E

第7题:

Which three features are benefits of using GRE tunnels in conjunction with IPsec for building site-to-site VPNs?()

  • A、allows dynamic routing over the tunnel
  • B、supports multi-protocol (non-IP) traffic over the tunnel
  • C、reduces IPsec headers overhead since tunnel mode is used
  • D、simplifies the ACL used in the crypto map
  • E、uses Virtual Tunnel Interface (VTI) to simplify the IPsec VPN configuration

正确答案:A,B,D

第8题:

Which three advanced permit actions within security policies are valid?() (Choose three.)

A. Mark permitted traffic for firewall user authentication.

B. Mark permitted traffic for SCREEN options.

C. Associate permitted traffic with an IPsec tunnel.

D. Associate permitted traffic with a NAT rule.

E. Mark permitted traffic for IDP processing.


参考答案:A, C, E

第9题:

Which QoS preclassification option will require the use of the qos pre-classify command for the VPN traffic? ()

  • A、VPN traffic needs to be classified based on the Layer2 header information
  • B、VPN traffic needs to be classified based on the IP precedence or DSCP
  • C、VPN traffic needs to be classified based on IP flow or Layer 3 information, such as source and destination IP address
  • D、VPN traffic with Authentication Header (AH) needs to preserve the ToS byte

正确答案:C

第10题:

What is true about Quality of Service (QoS) for VPNs?()

  • A、QoS preclassification is only supported on generic routing encapsulation (GRE) and IPsec VPNs
  • B、QoS preclassification is not required in Layer 2 Tunneling Protocol (L2TP), Layer2 Forwarding (L2F), and Point-to-Point Tunneling Protocol (PPTP) VPNs
  • C、QoS preclassification is supported on IPsec AH VPNs, but not on IPsec ESP VPNs
  • D、the QoS-for-VPNs feature (QoS preclassification) is designed for VPN transport interfaces
  • E、with IPsec tunnel mode, the type of service (ToS) byte value is copied automatically from the original IP header to the tunnel header

正确答案:C

更多相关问题