单选题Which attribute is required for all IKE phase 2 negotiations?()A proxy-IDB preshared keyC Diffie-Hellman group keyD main or aggressive mode

题目
单选题
Which attribute is required for all IKE phase 2 negotiations?()
A

proxy-ID

B

preshared key

C

Diffie-Hellman group key

D

main or aggressive mode

参考答案和解析
正确答案: D
解析: 暂无解析
如果没有搜索结果或未解决您的问题,请直接 联系老师 获取答案。
相似问题和答案

第1题:

Which one of the following is NOT a supported IKE attribute?()

  • A、 PFS group.
  • B、 Encryption algorithm.
  • C、 Hashing Algorithm.
  • D、 Authenticationmethod.
  • E、 Lifetime duration.

正确答案:A

第2题:

IPSec VPN is a widely-acknowledged solution for enterprise network. Which three IPsec VPNstatements are true?()

  • A、IKE keepalives are unidirectional and sent every ten seconds
  • B、IPsec uses the Encapsulating Security Protocol (ESP) or the Authentication Header (AH)protocol for exchanging keys
  • C、To establish IKE SA, main mode utilizes six packets while aggressive mode utilizes only threepackets
  • D、IKE uses the Diffie-Hellman algorithm to generate symmetrical keys to be used by IPsec peers

正确答案:A,C,D

第3题:

Which three parameters are configured in the IKE policy? ()(Choose three.)

A. mode

B. preshared key

C. external interface

D. security proposals

E. dead peer detection settings


参考答案:A, B, D

第4题:

Two VPN peers are negotiating IKE phase 1 using main mode. Which message pair in the negotiation contains the phase 1 proposal for the peers?()

  • A、message 1 and 2
  • B、message 3 and 4
  • C、message 5 and 6
  • D、message 7 and 8

正确答案:B

第5题:

Which operational mode command displays all active IPsec phase 2 security associations?()

  • A、show ike security-associations
  • B、show ipsec security-associations
  • C、show security ike security-associations
  • D、show security ipsec security-associations

正确答案:D

第6题:

During the Easy VPN Remote connection process,which phase involves pushing the IP address, Domain Name System (DNS),and split tunnel attributes to the client?()

  • A、mode configuration
  • B、the VPN client establishment of an ISAKMP SA
  • C、IPsec quick mode completion of the connection
  • D、VPN client initiation of the IKE phase 1 process

正确答案:A

第7题:

EAP-FAST provides a secure tunnel during Phase One to protect the user’s authenticationcredentials. Which of these entities initializes the secure tunnel?()

  • A、x.509 certificate
  • B、generic token card
  • C、preshared key
  • D、Protected Access Credential

正确答案:D

第8题:

Which three statements about the Cisco Easy VPN feature are true?()

  • A、If the VPN server is configured for Xauth, the VPN client waits for a username / password challenge.
  • B、The Cisco Easy VPN feature only supports transform sets that provide authentication and encryption.
  • C、The VPN client initiates aggressive mode (AM) if a pre-shared key is used for authentication during the IKE phase 1 process.
  • D、The VPN client verifies a server username/password challenge by using a AAA authentication server that supports TACACS+ or RADIUS.
  • E、The VPN server can only be enabled on Cisco PIX Firewalls and Cisco VPN 3000 series concentrators.
  • F、When connecting with a VPN client,the VPN server must be configured for ISAKMP group 1,2 or 5.

正确答案:A,B,C

第9题:

Which three parameters are configured in the IKE policy?()

  • A、mode
  • B、preshared key
  • C、external interface
  • D、security proposals
  • E、dead peer detection settings

正确答案:A,B,D

第10题:

用IKE为IPSec提供自动协商交换密钥,建立SA的服务时,在IKE协商的第一阶段定义了哪种IKE交换模式()。

  • A、主模式(Main Mode)
  • B、快速模式(New Group Mode)
  • C、野蛮模式(Aggressive Mode)
  • D、信息交换模式(Informational Exchange Mode)

正确答案:A,C

更多相关问题