Site-to-Site IPSec VPN II

Description

NSE4 6.0 NSE4 6.0 Quiz on Site-to-Site IPSec VPN II, created by Marcos Avila on 22/07/2018.
Marcos Avila
Quiz by Marcos Avila, updated more than 1 year ago
Marcos Avila
Created by Marcos Avila over 6 years ago
144
1

Resource summary

Question 1

Question
ADVPN
Answer
  • Auto discovery VPN
  • Active Directory VPN
  • Active Direct VPN

Question 2

Question
Which VPN topology does not allow direct communication between spokes?
Answer
  • a. Partial mesh
  • b. Hub-and-spoke

Question 3

Question
Which VPN topology is the most fault tolerant?
Answer
  • a. Full mesh
  • b. Hub-and-spoke

Question 4

Question
FortiGate operation mode: NAT and transparent L2TP-over—lPsec: Yes GRE—over—lPsec: No Routing protocols: No Number of policies per VPN: One policy controls both traffic directions
Answer
  • Policy-based
  • Route-based

Question 5

Question
FortiGate operation mode: Only NAT L2TP-over—lPsec: Yes GRE—over—lPsec: Yes Routing protocols: Yes Number of policies per VPN: Two policies (usually)—one for each direction
Answer
  • Policy-based
  • Route-based

Question 6

Question
Transparent mode supports only policy-based VPNs
Answer
  • True
  • False

Question 7

Question
Generally, try to use policy-based because it offers more flexibility and control.
Answer
  • True
  • False

Question 8

Question
Traffic must be routed to the lPsec virtual network interface. Usually two firewall policies with the Action set to ACCEPT are required (one per direction).
Answer
  • Route-based (interface-based)
  • Policy-based (tunnel-based)

Question 9

Question
One firewall policy with the Action set to lPsec is required. By default, hidden on the GUI. To show.
Answer
  • Route-based (interface-based)
  • Policy-based (tunnel-based)

Question 10

Question
Wizard vpn creates only route-based VPNs
Answer
  • True
  • False

Question 11

Question
SD-WAN feature can also be used for VPN redundancy.
Answer
  • True
  • False

Question 12

Question
[blank_start]1-[blank_end] Add one phase 1 configuration for each tunnel. Dead peer detection (DPD) must be enabled on both ends. [blank_start]2-[blank_end] Add at least one phase 2 definition for each phase 1. [blank_start]3-[blank_end] Add one static route for each path. Use distance or priority to select primary routes over backup routes. Alternatively, use dynamic routing. [blank_start]4-[blank_end] Configure firewall policies for each lPsec interface.
Answer
  • 1-
  • 2-
  • 3-
  • 4-

Question 13

Question
When configuring policy-based VPN, what option do you need to select for the Action setting?
Answer
  • a. IPsec
  • b. Authenticate

Question 14

Question
Which of the following statements about route-based VPN is correct?
Answer
  • a. It usually requires two firewall policies—one for each direction.
  • b. One policy controls both traffic directions.

Question 15

Question
diagnose vpn tunnel list - command to verify if traffic is offloaded.
Answer
  • True
  • False

Question 16

Question
Keeping a real-time debug running on the background of a FortiGate for a long time it is necessary some times.
Answer
  • True
  • False

Question 17

Question
?
Answer
  • vpn debug
  • ipsec vpn policy-based debug
  • ipsec vpn routed-based debug

Question 18

Question
Which one of the following messages indicates that both ingress and egress ESP packets will be offloaded?
Answer
  • a.npu_flag=00
  • b.npu_flag=03

Question 19

Question
If you enable NAT in the firewall policy for VPN, which of the following issues may occur?
Answer
  • a. Quick mode selector may mismatch
  • b. Traffic may not be routed to the tunnel
Show full summary Hide full summary

Similar

BIOLOGY B1 2
x_clairey_x
Practice For First Certificate Grammar I
Alice McClean
IB Chem Flashcards
j. stu
Atomic Structure
Jenni
GCSE AQA Chemistry - Unit 3
James Jolliffe
Biology B2.2
Jade Allatt
Edexcel Additional Science Biology Topic 2- Life Processes
hchen8nrd
Conferences of the Cold War
Alina A
Germany 1918-39
Cam Burke
1PR101 2.test - Část 5.
Nikola Truong
1PR101 2.test - Část 18.
Nikola Truong