Zusammenfassung der Ressource
Frage 1
Frage
The three most used protocols in the suite are the following: (Select 3)
Antworten
-
lnternet Key Exchange (IKE)
-
Encapsulation Security Payload (ESP)
-
Authentication Header (AH)
-
Point – to – Point Tunneling Protocol (PPTP)
-
Secure Sockets Layer (SSL)
Frage 2
Frage
[blank_start]lnternet Key Exchange (IKE)[blank_end], which does the handshake, tunnel maintenance, and disconnection.
[blank_start]Encapsulation Security Payload (ESP)[blank_end], which ensures data integrity andencryption.
[blank_start]Authentication Header (AH)[blank_end], which offers only data integrity-not encryption.
Antworten
-
lnternet Key Exchange (IKE)
-
Encapsulation Security Payload (ESP)
-
Authentication Header (AH)
Frage 3
Frage
FortiGate uses ESP to transport the packet payload and authenticate.
Frage 4
Antworten
-
UDP 500
-
TCP 500
-
UDP 4500
-
TCP 4500
Frage 5
Frage
IKE uses if NAT-T is enabled in a NAT scenario:
Antworten
-
UDP port 4500
-
TCP port 4500
-
UDP port 5000
-
TCP port 5000
Frage 6
Antworten
-
Security Association
-
Security Access
Frage 7
Frage
For phase 1, there are two possible negotiation modes that can be used:
Antworten
-
main mode
-
aggressive mode
-
quick mode
Frage 8
Frage
Phase 2 uses only one negotiation mode:
Antworten
-
quick mode
-
main mode
-
aggressive mode
Frage 9
Frage
AH is used by FortiGate
Frage 10
Antworten
-
Internet Key Exchange
-
Internal Key Exchange
-
Internal Keep Exchange
Frage 11
Antworten
-
UDP encapsulated
-
TCP encapsulated
Frage 12
Frage
Authenticates or encrypts packets using the following protocols:
(Select 3)
Antworten
-
Internet Key Exchange (IKE)
-
Encapsulation Security Payload (ESP)
-
Authentication Header (AH)
-
Point-to-Point Tunneling Protocol (PPTP)
-
Layer 2 Tunneling Protocol (L2TP)
Frage 13
Frage
Provides both data integrity and encryption:
Antworten
-
Encapsulation Security Payload (ESP)
-
Internet Key Exchange (IKE)
-
Authentication Header (AH)
Frage 14
Frage
Easy configuration
Few tunnels
High central bandwidth
Not fault tolerant
Low system requirements on average,
but high for center
Scalable
No direct communication between
spokes
Antworten
-
Hub-and-Spoke
-
Partial Mesh
-
Full Mesh
Frage 15
Frage
Moderate configuration
Medium number of tunnels
Medium bandwidth in hub sites
Some fault tolerance
Medium system requirements
Somewhat scalable
Direct communication between some
sites
Antworten
-
Hub-and-Spoke
-
Partial Mesh
-
Full Mesh
Frage 16
Frage
Complex configuration
Many tunnels
Low bandwidth
Fault tolerant
High system requirements
Difficult to scale
Direct communication between all sites
Antworten
-
Hub-and-Spoke
-
Partial Mesh
-
Full Mesh
Frage 17
Frage
FortiOS provides two options for IPsec VPNs:
route-based (also known as [blank_start]interface-based[blank_end]) or policy-based (also known as [blank_start]tunnel-mode[blank_end]).
Antworten
-
interface-based
-
tunnel-mode