单项选择题You are the Cisco Network Designer . Which is not major scaling, sizing, and performance consideration for an IPsec design?()

A. connection speed
B. number of remote sites
C. features to be supported
D. types of devices at the remote site



您可能感兴趣的试卷

你可能感兴趣的试题

2.单项选择题

Please match the Cisco NAC appliance component to its description.()
(1)Cisco NAS
(2)Cisco NAA
(3)Rule-set Lpdates
(4)Cisco NAM
(a) a centralized management point
(b) an in-band cr out-of-band device for network access control
(c) a Windows-based client which allows network access based on the tasks running
(d) a status crecker for operating systems,antivirus,antispyware,etc.

A.(a)-(4);(b)-(1);(c)-(2);(d)-(3)
B.(a)-(3);(b)-(2);(c)-(4);(d)-(1)
C.(a)-(4);(b)-(3);(c)-(1);(d)-(2)
D.(a)-(2);(b)-(4);(c)-(3);(d)-(1)


3.多项选择题

Refer to the exhibit. Which two statements about the topologies shown are correct?()

A. Design 1 is a looped triangle design.
B. Design 2 is a looped triangle design.
C. Design 2 achieves quick convergence using RSTP.
D. Both designs supportstateful services at the aggregation layer.
E. Design 2 is the most widely deployed in enterprise data centers.


6.单项选择题Which of these statements is true of routing protocols in a hub-and-spoke IPsec VPN topology?()

A. EIGRP can summarize per interface.
B. OSPF router databases remain independent.
C. When they are configured with stubs, EIGRP regularly floods the topology.
D. OSPF topology decisions are made independent of hierarchy or area.

7.单项选择题Which of the following is the primary consideration to scale VPNs?()

A. packets per second
B. number of remote sites
C. throughput bandwidth
D. number of tunnels

8.单项选择题In which tunnel-less VPN topology do group members register with a key server in order to receive the security association necessary to communicate with the group?()

A. Easy VPN
B. GRE tunneling
C. Virtual Tunnel Interfaces
D. DynamicMultipoint VPN
E. Group Encrypted Transport VPN

9.多项选择题Which two of these are advantages of placing the VPN device in the DMZ on the firewall?()

A. fewer devices to manage
B. moderate-to-high scalability
C. stateful inspection of decrypted VPN traffic
D. increased bandwidth with additional interfaces
E. decreased complexity as traffic is filtered from the firewall

10.多项选择题Which two of these are advantages of placing the VPN device parallel to the firewall?()

A. high scalability
B. the design supports a layered security model
C. firewall addressing does not need to change
D. IPsec decrypted traffic is inspected by the firewall
E. there is a centralized point for logging and content inspection

最新试题

Which of these statements is true of routing protocols in a hub-and-spoke IPsec VPN topology?()

题型:单项选择题

One of your customers has deployed a Layer 3 gateway in the untrusted network. Which gateway mode is appropriate for this customer?()

题型:单项选择题

The Cisco NAC Appliance is able to check which three items before allowing network access?()

题型:多项选择题

An organization hires a contractor who only needs access to email and a group calendar. They do not need administrator access to the computer. Which VPN model is the most appropriate?()

题型:单项选择题

You are the network consultant from pass4sure.com. One of your customer has six sites, three of which process a large amount of traffic among them. He plans to grow the number of sites in the future. Which is the most appropriate design topology?()

题型:单项选择题

What is the recommended radius of a cell for a voice-ready wireless network?()

题型:单项选择题

Cisco Express Forwarding (CEF) is mainly used to increase packet switching speed, reducing the overhead and delays introduced by other routing techniques, increasing overall performance.Which of the following concerning CEF is recommended by Cisco?()

题型:单项选择题

What is the term for a logical SAN which provides isolation among devices physically connected to the same fabric?()

题型:单项选择题

As an experienced technician, you are responsible for Technical Support. Which of the following descriptions is correct about the characteristic of SLB one arm mode?()

题型:单项选择题

Please match the Cisco STP enahancement term to its definition.()(1) BPDU guard(2) PortFast(3) BackboneFast(4) Loop guard(5) Root guard(a) shuts down a port that receives a BPDU when enabled(b) cuts convergence time by mas-age for indirect failure(c) prevents the aliernate or root port from being designated in absence of BPDUs(d )causes Layer 2 LAN interface access port to immediately enter the forwarding state(e) helps prevent bridging loops due to jni-directional link failures on point-to-point links

题型:单项选择题