单选题Which attribute is required for all IKE phase 2 negotiations?()A proxy-IDB preshared keyC Diffie-Hellman group keyD main or aggressive mode

题目
单选题
Which attribute is required for all IKE phase 2 negotiations?()
A

proxy-ID

B

preshared key

C

Diffie-Hellman group key

D

main or aggressive mode


相似考题
更多“单选题Which attribute is required for all IKE phase 2 negotiations?()A proxy-IDB preshared keyC Diffie-Hellman group keyD main or aggressive mode”相关问题
  • 第1题:

    IPSec VPN is a widely-acknowledged solution for enterprise network. Which three IPsec VPNstatements are true?()

    • A、IKE keepalives are unidirectional and sent every ten seconds
    • B、IPsec uses the Encapsulating Security Protocol (ESP) or the Authentication Header (AH)protocol for exchanging keys
    • C、To establish IKE SA, main mode utilizes six packets while aggressive mode utilizes only threepackets
    • D、IKE uses the Diffie-Hellman algorithm to generate symmetrical keys to be used by IPsec peers

    正确答案:A,C,D

  • 第2题:

    Which operational mode command displays all active IPsec phase 2 security associations?()

    • A、show ike security-associations
    • B、show ipsec security-associations
    • C、show security ike security-associations
    • D、show security ipsec security-associations

    正确答案:D

  • 第3题:

    Two VPN peers are negotiating IKE phase 1 using main mode. Which message pair in the negotiation contains the phase 1 proposal for the peers?()

    • A、message 1 and 2
    • B、message 3 and 4
    • C、message 5 and 6
    • D、message 7 and 8

    正确答案:B

  • 第4题:

    EAP-FAST provides a secure tunnel during Phase One to protect the user’s authentication credentials. Which of these entities initializes the secure tunnel?()

    • A、x.509 certificate
    • B、generic token card
    • C、preshared key
    • D、Protected Access Credential

    正确答案:D

  • 第5题:

    Which three parameters are configured in the IKE policy? ()(Choose three.)

    • A、mode
    • B、preshared key
    • C、external interface
    • D、security proposals
    • E、dead peer detection settings

    正确答案:A,B,D

  • 第6题:

    Which attribute is optional for IKE phase 2 negotiations?()

    • A、proxy-ID
    • B、phase 2 proposal
    • C、Diffie-Hellman group key
    • D、security protocol (ESP or AH)

    正确答案:C

  • 第7题:

    Regarding an IPsec security association (SA), which two statements are true?()

    • A、IKE SA is bidirectional.
    • B、IPsec SA is bidirectional.
    • C、IKE SA is established during phase 2 negotiations.
    • D、IPsec SA is established during phase 2 negotiations.

    正确答案:A,C

  • 第8题:

    单选题
    During the Easy VPN Remote connection process,which phase involves pushing the IP address, Domain Name System (DNS),and split tunnel attributes to the client?()
    A

    mode configuration

    B

    the VPN client establishment of an ISAKMP SA

    C

    IPsec quick mode completion of the connection

    D

    VPN client initiation of the IKE phase 1 process


    正确答案: C
    解析: 暂无解析

  • 第9题:

    单选题
    Two VPN peers are negotiating IKE phase 1 using main mode. Which message pair in the negotiation contains the phase 1 proposal for the peers?()
    A

    message 1 and 2

    B

    message 3 and 4

    C

    message 5 and 6

    D

    message 7 and 8


    正确答案: C
    解析: 暂无解析

  • 第10题:

    单选题
    During which phase of the boot process is the rootvg volume group varied on and the root file system (hd4) checked?()
    A

    Boot phase 1

    B

    Boot phase 2

    C

    Boot phase 3

    D

    Boot phase 4


    正确答案: D
    解析: 暂无解析

  • 第11题:

    单选题
    Which operational mode command displays all active IPsec phase 2 security associations?()
    A

    show ike security-associations

    B

    show ipsec security-associations

    C

    show security ike security-associations

    D

    show security ipsec security-associations


    正确答案: D
    解析: 暂无解析

  • 第12题:

    单选题
    Which one of the following is NOT a supported IKE attribute?()
    A

     PFS group.

    B

     Encryption algorithm.

    C

     Hashing Algorithm.

    D

     Authenticationmethod.

    E

     Lifetime duration.


    正确答案: A
    解析: 暂无解析

  • 第13题:

    EAP-FAST provides a secure tunnel during Phase One to protect the user’s authenticationcredentials. Which of these entities initializes the secure tunnel?()

    • A、x.509 certificate
    • B、generic token card
    • C、preshared key
    • D、Protected Access Credential

    正确答案:D

  • 第14题:

    Which three parameters are configured in the IKE policy?()

    • A、mode
    • B、preshared key
    • C、external interface
    • D、security proposals
    • E、dead peer detection settings

    正确答案:A,B,D

  • 第15题:

    用IKE为IPSec提供自动协商交换密钥,建立SA的服务时,在IKE协商的第一阶段定义了哪种IKE交换模式()。

    • A、主模式(Main Mode)
    • B、快速模式(New Group Mode)
    • C、野蛮模式(Aggressive Mode)
    • D、信息交换模式(Informational Exchange Mode)

    正确答案:A,C

  • 第16题:

    For the following items ,which one can be used to authenticate the IPsec peers during IKE Phase 1?()

    • A、pre-shared key
    • B、integrity check value
    • C、XAUTH
    • D、Diffie-Hellman Nonce

    正确答案:A

  • 第17题:

    For IKE phase 1 negotiations, when is aggressive mode typically used?()

    • A、when one of the tunnel peers has a dynamic IP address
    • B、when one of the tunnel peers wants to force main mode to be used
    • C、when fragmentation of the IKE packet is required between the two peers
    • D、when one of the tunnel peers wants to specify a different phase 1 proposal

    正确答案:A

  • 第18题:

    Which attribute is required for all IKE phase 2 negotiations?()

    • A、proxy-ID
    • B、preshared key
    • C、Diffie-Hellman group key
    • D、main or aggressive mode

    正确答案:A

  • 第19题:

    For which two constraints does the Oracle Server implicitly create a unique index?()

    • A、NOT NULL
    • B、PRIMARY KEY
    • C、FOREIGN KEY
    • D、CHECK
    • E、UNIQUE

    正确答案:B,E

  • 第20题:

    单选题
    Which attribute is optional for IKE phase 2 negotiations?()
    A

    proxy-ID

    B

    phase 2 proposal

    C

    Diffie-Hellman group key

    D

    security protocol (ESP or AH)


    正确答案: C
    解析: 暂无解析

  • 第21题:

    多选题
    Regarding an IPsec security association (SA), which two statements are true?()
    A

    IKE SA is bidirectional.

    B

    IPsec SA is bidirectional.

    C

    IKE SA is established during phase 2 negotiations.

    D

    IPsec SA is established during phase 2 negotiations.


    正确答案: D,C
    解析: 暂无解析

  • 第22题:

    单选题
    Which attribute is required for all IKE phase 2 negotiations?()
    A

    proxy-ID

    B

    preshared key

    C

    Diffie-Hellman group key

    D

    main or aggressive mode


    正确答案: D
    解析: 暂无解析

  • 第23题:

    单选题
    For IKE phase 1 negotiations, when is aggressive mode typically used?()
    A

    when one of the tunnel peers has a dynamic IP address

    B

    when one of the tunnel peers wants to force main mode to be used

    C

    when fragmentation of the IKE packet is required between the two peers

    D

    when one of the tunnel peers wants to specify a different phase 1 proposal


    正确答案: A
    解析: 暂无解析

  • 第24题:

    多选题
    IPSec VPN is a widely-acknowledged solution for enterprise network. Which three IPsec VPNstatements are true?()
    A

    IKE keepalives are unidirectional and sent every ten seconds

    B

    IPsec uses the Encapsulating Security Protocol (ESP) or the Authentication Header (AH)protocol for exchanging keys

    C

    To establish IKE SA, main mode utilizes six packets while aggressive mode utilizes only threepackets

    D

    IKE uses the Diffie-Hellman algorithm to generate symmetrical keys to be used by IPsec peers


    正确答案: D,B
    解析: 暂无解析