Site-to-Site IPSec VPN II

Descrição

NSE4 6.0 NSE4 6.0 Quiz sobre Site-to-Site IPSec VPN II, criado por Marcos Avila em 22-07-2018.
Marcos Avila
Quiz por Marcos Avila, atualizado more than 1 year ago
Marcos Avila
Criado por Marcos Avila quase 6 anos atrás
138
1

Resumo de Recurso

Questão 1

Questão
ADVPN
Responda
  • Auto discovery VPN
  • Active Directory VPN
  • Active Direct VPN

Questão 2

Questão
Which VPN topology does not allow direct communication between spokes?
Responda
  • a. Partial mesh
  • b. Hub-and-spoke

Questão 3

Questão
Which VPN topology is the most fault tolerant?
Responda
  • a. Full mesh
  • b. Hub-and-spoke

Questão 4

Questão
FortiGate operation mode: NAT and transparent L2TP-over—lPsec: Yes GRE—over—lPsec: No Routing protocols: No Number of policies per VPN: One policy controls both traffic directions
Responda
  • Policy-based
  • Route-based

Questão 5

Questão
FortiGate operation mode: Only NAT L2TP-over—lPsec: Yes GRE—over—lPsec: Yes Routing protocols: Yes Number of policies per VPN: Two policies (usually)—one for each direction
Responda
  • Policy-based
  • Route-based

Questão 6

Questão
Transparent mode supports only policy-based VPNs
Responda
  • True
  • False

Questão 7

Questão
Generally, try to use policy-based because it offers more flexibility and control.
Responda
  • True
  • False

Questão 8

Questão
Traffic must be routed to the lPsec virtual network interface. Usually two firewall policies with the Action set to ACCEPT are required (one per direction).
Responda
  • Route-based (interface-based)
  • Policy-based (tunnel-based)

Questão 9

Questão
One firewall policy with the Action set to lPsec is required. By default, hidden on the GUI. To show.
Responda
  • Route-based (interface-based)
  • Policy-based (tunnel-based)

Questão 10

Questão
Wizard vpn creates only route-based VPNs
Responda
  • True
  • False

Questão 11

Questão
SD-WAN feature can also be used for VPN redundancy.
Responda
  • True
  • False

Questão 12

Questão
[blank_start]1-[blank_end] Add one phase 1 configuration for each tunnel. Dead peer detection (DPD) must be enabled on both ends. [blank_start]2-[blank_end] Add at least one phase 2 definition for each phase 1. [blank_start]3-[blank_end] Add one static route for each path. Use distance or priority to select primary routes over backup routes. Alternatively, use dynamic routing. [blank_start]4-[blank_end] Configure firewall policies for each lPsec interface.
Responda
  • 1-
  • 2-
  • 3-
  • 4-

Questão 13

Questão
When configuring policy-based VPN, what option do you need to select for the Action setting?
Responda
  • a. IPsec
  • b. Authenticate

Questão 14

Questão
Which of the following statements about route-based VPN is correct?
Responda
  • a. It usually requires two firewall policies—one for each direction.
  • b. One policy controls both traffic directions.

Questão 15

Questão
diagnose vpn tunnel list - command to verify if traffic is offloaded.
Responda
  • True
  • False

Questão 16

Questão
Keeping a real-time debug running on the background of a FortiGate for a long time it is necessary some times.
Responda
  • True
  • False

Questão 17

Questão
?
Responda
  • vpn debug
  • ipsec vpn policy-based debug
  • ipsec vpn routed-based debug

Questão 18

Questão
Which one of the following messages indicates that both ingress and egress ESP packets will be offloaded?
Responda
  • a.npu_flag=00
  • b.npu_flag=03

Questão 19

Questão
If you enable NAT in the firewall policy for VPN, which of the following issues may occur?
Responda
  • a. Quick mode selector may mismatch
  • b. Traffic may not be routed to the tunnel

Semelhante

Filmes Sobre História
Alessandra S.
Inglês resumo
Felipe Penha
Sociologia - Origem
Malu Miralha
Phrasal Verbs II
GoConqr suporte .
Macetes para Fórmulas de Física
Marina Faria
II GUERRA MUNDIAL
Luis Augusto Oliveira
Phrasal Verbs - Inglês #9
Eduardo .
GEOGRAFIA - GEOPOLITICA
neusamiotto
TRIBUTAÇÃO E ORÇAMENTO
Jualvesm
Gestão de Pessoas: 6 dicas para ser mais eficiente
Liliane Tubino
Características do Trovadorismo
gvitoriaaraujp12