网友您好, 请在下方输入框内输入要搜索的题目:

题目内容 (请给出正确答案)
单选题
When is an IPSec SA built on the Teleworker Router?()
A

when the router is booted up

B

when the router administratively does a no shutdown on the IPSec SA 

C

when traffic matches a line of the access-list tied into the crypto-map in the router configuration, and that particular IPSec SA is not already up 

D

when the ISAKMP SA completes negotiation of all IPSec SAs (one per access-list line in the crypto ACL), it will be brought up immediately


参考答案

参考解析
解析: 暂无解析
更多 “单选题When is an IPSec SA built on the Teleworker Router?()A when the router is booted upB when the router administratively does a no shutdown on the IPSec SA C when traffic matches a line of the access-list tied into the crypto-map in the router configuration, and that particular IPSec SA is not already up D when the ISAKMP SA completes negotiation of all IPSec SAs (one per access-list line in the crypto ACL), it will be brought up immediately” 相关考题
考题 关于安全联盟SA,说法正确的是()。 A.IKE SA是单向的B.IPSEC SA是双向的C.IKE SA是双向的D.IPSEC SA是单向的

考题 Router R1, a branch router, connects to the Internet using DSL. Some traffic flows through a GRE and IPsec tunnel, over the DSL connection, destined for an Enterprise network.Which of the following answers best describes the router‘s logic that tells the router, for a given packet, to apply GRE encapsulation to the packet?()A. When the packet received on the LAN interface is permitted by the ACL listed on the tunnel greacl command under the incoming interfaceB. When routing the packet, matching a route whose outgoing interface is the GRE tunnel interfaceC. When routing the packet, matching a route whose outgoing interface is the IPsec tunnel interfaceD. When permitted by an ACL that was referenced in the associated crypto map

考题 IPSECSA和IKESA的主要区别是() A.IPSEC SA是单向的,IKE SA是双向的B.通道两端只有一个IKE SA但IPSEC SA不止一对C.IKE SA没有生存期D.IPSEC SA有对端地址

考题 Which of the following commands will display a router’s crypto map IPsec security associationsettings?()A、show crypto map ipsec saB、show crypto mapC、show crypto engine connections activeD、show ipsec crypto mapE、show crypto map saF、show ipsec crypto map sa

考题 下列关于IPSec与IKE的说法正确的是()。A、IPSec只能通过与IKE配合方式才能建立起安全联盟B、IKE只能与IPSec配合使用C、IKE只负责为IPSec建立提供安全密钥,不参与IPSec SA协商D、IPSec SA建立后,数据转发与IKE无关

考题 A customer wants to TFTP a new image from the corporate network to Flash on the Teleworker router through the IPSec tunnel. How should you configure the Teleworker router?()A、No additional steps are required. B、Add the appropriate source-interface command. C、The router cannot access a server in the Enterprise Campus network. D、The Teleworker Router does not have any client applications; therefore this type of request is not possible.

考题 Router R1, a branch router, connects to the Internet using DSL. Some traffic flows through a GRE and IPsec tunnel, over the DSL connection, destined for an Enterprise network. Which of the following answers best describes the router's logic that tells the router, for a given packet, to apply GRE encapsulation to the packet?()A、When the packet received on the LAN interface is permitted by the ACL listed on the tunnel greacl command under the incoming interfaceB、When routing the packet, matching a route whose outgoing interface is the GRE tunnel interfaceC、When routing the packet, matching a route whose outgoing interface is the IPsec tunnel interfaceD、When permitted by an ACL that was referenced in the associated crypto map

考题 When should you enable Network Address Translation Transparency (NAT-T) on the Teleworker?()A、when a router between the Teleworker router and the head-end VPN router is doing NAT/pNAT and does not support IPSec pass-through B、when the Teleworker router itself is doing NAT/pNATC、alwaysD、never

考题 You need to configure a GRE tunnel on a IPSec router. When you are using the SDM to configurea GRE tunnel over IPsec, which two parameters are required when defining the tunnel interfaceinformation?()A、The crypto ACL numberB、The IPSEC mode (tunnel or transport)C、The GRE tunnel interface IP addressD、The GRE tunnel source interface or IP address, and tunnel destination IP addressE、The MTU size of the GRE tunnel interface

考题 The LAN-side of the Teleworker router is assigned private IP address space (RFC1918), and the VPN topology is IPSec-only (no GRE protocol). When is it required to configure NAT/pNAT on the Teleworker router?()A、when all access to the Internet is through the IPSec tunnelB、when there is direct Internet access via split-tunnelingC、when there is no Internet access configured through the Teleworker routerD、whenever you have IOS-Firewall (CBAC) configured

考题 When is an IPSec SA built on the Teleworker Router?()A、when the router is booted upB、when the router administratively does a no shutdown" on the IPSec SA C、when traffic matches a line of the access-list tied into the crypto-map in the router configuration, and that particular IPSec SA is not already up D、when the ISAKMP SA completes negotiation of all IPSec SAs (one per access-list line in the crypto ACL), it will be brought up immediately

考题 下列关于IPSec与IKE的说法不正确的是()。A、IPSec只能通过与IKE配合方式才能建立起安全联盟B、IKE只能与IPSec配合使用C、IKE只负责为IPSec建立提供安全密钥,不参与IPSec SA协商D、IPSec SA建立后,数据转发与IKE无关

考题 关于安全联盟SA,说法正确的是()  A、 IKE SA 是单向的B、 IPSEC SA 是双向的C、 IKE SA 是双向的D、 IPSEC SA 是单向的

考题 关于IPSec SA和IKE SA的说法,正确的是()A、IPSec SA是双向的,IKE SA是单向的B、IPSec SA是双向的,IKE SA是双向的C、IPSec SA是单向的,IKE SA是单向的D、IPSec SA是单向的,IKE SA是双向的

考题 In a Teleworker deployment with a single IP phone connected to a Cisco 831 router, select the true statement regarding Call Admission Control.()A、RSVP is a required configuration to support conference calls without voice packet loss. B、The QoS configuration on the 831 router must always provision sufficient bandwidth for two RTP streams. C、Call admission control is an issue only when using hardware DSP resources. D、When using the conference call features on a 7960 IP phone, only one RTP stream is present regardless of how many extensions are on the conference.

考题 Why is NTP an important component when implementing IPSec VPN in a PKI environment?()A、 To ensure the router has the correct time when generating its private/public key pairs.B、 To ensure the router has the correct time when checking certificate validity from the remote peersC、 To ensure the router time is sync with the remote peers for encryption keys generationD、 To ensure the router time is sync with the remote peers during theDH exchangeE、 To ensure the router time is sync with the remote peers when generating the cookies during IKE phase 1

考题 An Enterprise customer wants to reduce the configuration effort for their Teleworker router deployments. What is one way to simplify the IPSec-related configuration in the remote routers?()A、CiscoWorks VPN Manager B、deploy Linksys routers with menu-driven configurationC、Easy VPN client mode D、disable 802.1x and Auth Proxy on the Teleworker router

考题 Regarding an IPsec security association (SA), which two statements are true?()A、IKE SA is bidirectional.B、IPsec SA is bidirectional.C、IKE SA is established during phase 2 negotiations.D、IPsec SA is established during phase 2 negotiations.

考题 单选题Refer to the exhibit. Which Virtual Router Redundancy Protocol (VRRP) statement is true about the roles of the master virtual router and the backup virtual router?()A Router A is the master virtual router, and Router B is the backup virtual router. When Router A fails, Router B will become the master virtual router. When Router A recovers, Router B will maintain the role of master virtual routeB Router A is the master virtual router, and Router B is the backup virtual router. When Router A fails, Router B will become the master virtual router. When Router A recovers, it will regain the master virtual router roleC Router B is the master virtual router, and Router A is the backup virtual router. When Router B fails, Router A will become the master virtual router. When Router B recovers, Router A will maintain the role of master virtual router.D Router B is the master virtual router, and Router A is the backup virtual router. When Router B fails, Router A will become the master virtual router. When Router B recovers, it will regain the master virtual router role

考题 单选题Refer to the exhibit. With an IPSec tunnel established between remote Router A and head-end router B, with Compressed Real-Time Protocol (cRTP) configured on the serial interface of Router A, what impact will the cRTP configuration have on the Voice over IP packets flowing through the IPSec tunnel from a Cisco 7960 IP phone?()A Twenty bytes of header will be replaced with five bytes. B If the IPSec transform set includes Authentication Header, the receiving IPSec peer will discard the packets. C The IPSec packets will be dropped by Router A's compression logic.D The voice packets will not be compressed.

考题 单选题When is an IPSec SA built on the Teleworker Router?()A when the router is booted upB when the router administratively does a no shutdown on the IPSec SA C when traffic matches a line of the access-list tied into the crypto-map in the router configuration, and that particular IPSec SA is not already up D when the ISAKMP SA completes negotiation of all IPSec SAs (one per access-list line in the crypto ACL), it will be brought up immediately

考题 单选题Which of the following commands will display a router’s crypto map IPsec security associationsettings?()A show crypto map ipsec saB show crypto mapC show crypto engine connections activeD show ipsec crypto mapE show crypto map saF show ipsec crypto map sa

考题 多选题You need to configure a GRE tunnel on a IPSec router. When you are using the SDM to configurea GRE tunnel over IPsec, which two parameters are required when defining the tunnel interfaceinformation?()AThe crypto ACL numberBThe IPSEC mode (tunnel or transport)CThe GRE tunnel interface IP addressDThe GRE tunnel source interface or IP address, and tunnel destination IP addressEThe MTU size of the GRE tunnel interface

考题 单选题Why is NTP an important component when implementing IPSec VPN in a PKI environment?()A  To ensure the router has the correct time when generating its private/public key pairs.B  To ensure the router has the correct time when checking certificate validity from the remote peersC  To ensure the router time is sync with the remote peers for encryption keys generationD  To ensure the router time is sync with the remote peers during theDH exchangeE  To ensure the router time is sync with the remote peers when generating the cookies during IKE phase 1

考题 单选题The LAN-side of the Teleworker router is assigned private IP address space (RFC1918), and the VPN topology is IPSec-only (no GRE protocol). When is it required to configure NAT/pNAT on the Teleworker router?()A when all access to the Internet is through the IPSec tunnelB when there is direct Internet access via split-tunnelingC when there is no Internet access configured through the Teleworker routerD whenever you have IOS-Firewall (CBAC) configured

考题 单选题What is the best way to ensure that IKE/ISAKMP packets are not dropped when QoS is enabled on the uplink interface of the Teleworker router?()A QoS and IPSec should never be used together. B IKE/ISAKMP packets are DiffSERV codepoint CS6, so the traffic is never dropped.C Source IKE/ISAKMP packets off the loop-back address. D Classify IKE/ISAKMP packets so they are appropriately prioritized.

考题 单选题A customer wants to TFTP a new image from the corporate network to Flash on the Teleworker router through the IPSec tunnel. How should you configure the Teleworker router?()A No additional steps are required. B Add the appropriate source-interface command. C The router cannot access a server in the Enterprise Campus network. D The Teleworker Router does not have any client applications; therefore this type of request is not possible.

考题 单选题When should you enable Network Address Translation Transparency (NAT-T) on the Teleworker?()A when a router between the Teleworker router and the head-end VPN router is doing NAT/pNAT and does not support IPSec pass-through B when the Teleworker router itself is doing NAT/pNATC alwaysD never