Site-to-Site IPSec VPN II

Beschreibung

NSE4 6.0 NSE4 6.0 Quiz am Site-to-Site IPSec VPN II, erstellt von Marcos Avila am 22/07/2018.
Marcos Avila
Quiz von Marcos Avila, aktualisiert more than 1 year ago
Marcos Avila
Erstellt von Marcos Avila vor fast 6 Jahre
139
1

Zusammenfassung der Ressource

Frage 1

Frage
ADVPN
Antworten
  • Auto discovery VPN
  • Active Directory VPN
  • Active Direct VPN

Frage 2

Frage
Which VPN topology does not allow direct communication between spokes?
Antworten
  • a. Partial mesh
  • b. Hub-and-spoke

Frage 3

Frage
Which VPN topology is the most fault tolerant?
Antworten
  • a. Full mesh
  • b. Hub-and-spoke

Frage 4

Frage
FortiGate operation mode: NAT and transparent L2TP-over—lPsec: Yes GRE—over—lPsec: No Routing protocols: No Number of policies per VPN: One policy controls both traffic directions
Antworten
  • Policy-based
  • Route-based

Frage 5

Frage
FortiGate operation mode: Only NAT L2TP-over—lPsec: Yes GRE—over—lPsec: Yes Routing protocols: Yes Number of policies per VPN: Two policies (usually)—one for each direction
Antworten
  • Policy-based
  • Route-based

Frage 6

Frage
Transparent mode supports only policy-based VPNs
Antworten
  • True
  • False

Frage 7

Frage
Generally, try to use policy-based because it offers more flexibility and control.
Antworten
  • True
  • False

Frage 8

Frage
Traffic must be routed to the lPsec virtual network interface. Usually two firewall policies with the Action set to ACCEPT are required (one per direction).
Antworten
  • Route-based (interface-based)
  • Policy-based (tunnel-based)

Frage 9

Frage
One firewall policy with the Action set to lPsec is required. By default, hidden on the GUI. To show.
Antworten
  • Route-based (interface-based)
  • Policy-based (tunnel-based)

Frage 10

Frage
Wizard vpn creates only route-based VPNs
Antworten
  • True
  • False

Frage 11

Frage
SD-WAN feature can also be used for VPN redundancy.
Antworten
  • True
  • False

Frage 12

Frage
[blank_start]1-[blank_end] Add one phase 1 configuration for each tunnel. Dead peer detection (DPD) must be enabled on both ends. [blank_start]2-[blank_end] Add at least one phase 2 definition for each phase 1. [blank_start]3-[blank_end] Add one static route for each path. Use distance or priority to select primary routes over backup routes. Alternatively, use dynamic routing. [blank_start]4-[blank_end] Configure firewall policies for each lPsec interface.
Antworten
  • 1-
  • 2-
  • 3-
  • 4-

Frage 13

Frage
When configuring policy-based VPN, what option do you need to select for the Action setting?
Antworten
  • a. IPsec
  • b. Authenticate

Frage 14

Frage
Which of the following statements about route-based VPN is correct?
Antworten
  • a. It usually requires two firewall policies—one for each direction.
  • b. One policy controls both traffic directions.

Frage 15

Frage
diagnose vpn tunnel list - command to verify if traffic is offloaded.
Antworten
  • True
  • False

Frage 16

Frage
Keeping a real-time debug running on the background of a FortiGate for a long time it is necessary some times.
Antworten
  • True
  • False

Frage 17

Antworten
  • vpn debug
  • ipsec vpn policy-based debug
  • ipsec vpn routed-based debug

Frage 18

Frage
Which one of the following messages indicates that both ingress and egress ESP packets will be offloaded?
Antworten
  • a.npu_flag=00
  • b.npu_flag=03

Frage 19

Frage
If you enable NAT in the firewall policy for VPN, which of the following issues may occur?
Antworten
  • a. Quick mode selector may mismatch
  • b. Traffic may not be routed to the tunnel
Zusammenfassung anzeigen Zusammenfassung ausblenden

ähnlicher Inhalt

Kognitive Lerntheorien
Inés Fernandez
2C Entwicklungspsychologie
petra.drewitz
Dramenanalyse
sysa
WERB Uni Wien 2017/18
Denise Schmid
KPOL-Fragen (sofort überprüfbar)
Tim Schröder
GESKO JOUR Karteikarten
Sascha Walter
Veti Pharma
Anna Leps
Vetie Tierhaltung und -hygiene Quiz 2012
Elisabeth Tauscher
Geometrie 33-48
Christoph Affolter
Vetie Immunologie
Katrin Harles
Vetie Tierseuchen 2018
Johanna Müller