CCNA 4 Chapter 7 v5.0 Exam Answers 2015 100
CCNA 4 Chapter 7 v5.0 Exam Answers 2015 100
CCNA 4 Chapter 7 v5.0 Exam Answers 2015 100
Net
o a GRE IP tunnel
o a leased line
o a VPN gateway
o a dedicated ISP
o New headers from one or more VPN protocols encapsulate the original packets.
o All packets between two hosts are assigned to a single physical medium to ensure
that the packets are kept private.
o Packets are disguised to look like other types of traffic so that they will be ignored by
potential attackers.
o A dedicated circuit is established between the source and destination devices for the
duration of the connection.
4. Two corporations have just completed a merger. The network engineer has
been asked to connect the two corporate networks without the expense of
leased lines. Which solution would be the most cost effective method of
providing a proper and secure connection between the two corporate
networks?
5. Which two scenarios are examples of remote access VPNs? (Choose two.)
o A toy manufacturer has a permanent VPN connection to one of its parts suppliers.
CCNA 5 Page 1
CCNA 4 Chapter 7 v5.0 Exam Answers 2015 (100%) WWW.CCNA-v5.Net
o All users at a large branch office can access company resources through a single
VPN connection.
o A mobile sales agent is connecting to the company network via the Internet
connection at a hotel.
o A small branch office with three employees has a Cisco ASA that is used to create a
VPN connection to the HQ.
o An employee who is working from home uses VPN client software on a laptop in
order to connect to the company network.
8. Which remote access implementation scenario will support the use of generic
routing encapsulation tunneling?
CCNA 5 Page 2
CCNA 4 Chapter 7 v5.0 Exam Answers 2015 (100%) WWW.CCNA-v5.Net
o This tunnel mode is not the default tunnel interface mode for Cisco IOS software.
o This tunnel mode provides encryption.
o The data that is sent across this tunnel is not secure.
o This tunnel mode does not support IP multicast tunneling.
o A GRE tunnel is being used.
10. Refer to the exhibit. Which IP address would be configured on the tunnel
interface of the destination router
o 172.16.1.1
o 172.16.1.2
o 209.165.200.225
o 209.165.200.226
CCNA 5 Page 3
CCNA 4 Chapter 7 v5.0 Exam Answers 2015 (100%) WWW.CCNA-v5.Net
o IPsec works at Layer 3, but can protect traffic from Layer 4 through Layer 7.
o IPsec uses algorithms that were developed specifically for that protocol.
o IPsec implements its own method of authentication.
o IPsec is a Cisco proprietary standard.
12. Which function of IPsec security services allows the receiver to verify that the
data was transmitted without being changed or altered in any way?
o anti-replay protection
o authentication
o data integrity
o confidentiality
14. What is an IPsec protocol that provides data confidentiality and authentication
for IP packets?
o AH
o ESP
o RSA
o IKE
15. What two encryption algorithms are used in IPsec VPNs? (Choose two.)
o DH
o PSK
o IKE
o AES
o 3DES
o RSA
o AES
o 3DES
o DES
CCNA 5 Page 4
CCNA 4 Chapter 7 v5.0 Exam Answers 2015 (100%) WWW.CCNA-v5.Net
17. Which two algorithms use Hash-based Message Authentication Code for
message authentication? (Choose two.)
o 3DES
o DES
o AES
o MD5
o SHA
18. Which three statements describe the building blocks that make up the IPsec
protocol framework? (Choose three.)
o IPsec uses encryption algorithms and keys to provide secure transfer of data.
o IPsec uses Diffie-Hellman algorithms to encrypt data that is transferred through the
VPN.
o IPsec uses 3DES algorithms to provide the highest level of security for data that is
transferred through a VPN.
o IPsec uses secret key cryptography to encrypt messages that are sent through a
VPN.
o IPsec uses Diffie-Hellman as a hash algorithm to ensure integrity of data that is
transmitted through a VPN.
o IPsec uses ESP to provide confidential transfer of data by encrypting IP packets.
o SHA-1
o MD5
o AES
o 512-bit SHA
20. What is the purpose of utilizing Diffie-Hellman (DH) algorithms as part of the
IPsec standard?
o DH algorithms allow unlimited parties to establish a shared public key that is used by
encryption and hash algorithms.
o DH algorithms allow two parties to establish a shared secret key that is used by
encryption and hash algorithms.
o DH algorithms allow unlimited parties to establish a shared secret key that is used by
encryption and hash algorithms.
o DH algorithms allow two parties to establish a shared public key that is used by
encryption and hash algorithms.
CCNA 5 Page 5
CCNA 4 Chapter 7 v5.0 Exam Answers 2015 (100%) WWW.CCNA-v5.Net
22. Which Cisco VPN solution provides limited access to internal network
resources by utilizing a Cisco ASA and provides browser-based access only?
23. What key question would help determine whether an organization should use
an SSL VPN or an IPsec VPN for the remote access solution of the
organization?
24. Open the PT Activity. Perform the tasks in the activity instructions and then
answer the question.
What problem is preventing the hosts from communicating across the VPN
tunnel?
CCNA 5 Page 6