Questão 1
Questão
Protocol RFC 2409 (__V1) RFC 4305 (__V2)
NAT IP protocol 17: UDP port 500 (UDP 4500 for rekey, quick mode. mode-cfg)
No NAT IP protocol 17: UDP port 500
Questão 2
Questão
Protocol RFC 4303
NAT IP protocol 17: UDP port 4500
No NAT IP protocol 50
Questão 3
Responda
-
Internet Key Exchange
-
Internet Key Extend
-
Internet Key Expert
Questão 4
Responda
-
Authentication Header
-
Authentication Helpers
Questão 5
Questão 6
Questão
is used to authenticate peers, exchange keys, and negotiate the encryption and checksums that will be used; essentially, it is the control channel.
Questão 7
Questão
contains the authentieetion header—the checksums that verify the integrity of the data.
Questão 8
Questão
is the encapsulated security payload—the encrypted payload, essentially, the data channel.
Questão 9
Questão
Authentication Header (AH) does not offer encryption. So AH is not used by Fortigate.
Questão 10
Questão
IPsec provides services at the:
Responda
-
Network layer
-
Transport layer
-
Session layer
-
Data link layer
Questão 11
Questão
IPsec can operate in two modes:
Questão 12
Questão
directly encapsulates and protects the fourth layer (transport) and above. The original IP header is not protected and no additional lP header is added.
Responda
-
Transport mode
-
Tunnel mode
Questão 13
Questão
is a true tunnel. The whole lP packet is encapsulated and a new IP header is added at the beginning. After the lPsec packet reaches the remote LAN, and is unwrapped, the original packet can continue on its journey.
Responda
-
Tunnel mode
-
Transport mode
Questão 14
Responda
-
Security Association
-
System Association
-
Security Access
Questão 15
Questão
IKE no uses phases
Questão 16
Questão
In which encapsulation mode is the original IP header protected?
Responda
-
A. Tunnel mode
-
B. Transport mode
Questão 17
Questão
Which encapsulation mode is used for end—to-end (or client-to-client) VPNS?
Responda
-
Tunnel mode
-
Transport mode