CCSP SECUR FAQ : Configuring Remote Access Using Easy VPN
Q1. What version of Cisco IOS Software supports Easy VPN Server?
A. 12.1(13)
B. 12.2(8)T
C. 12.5
D. 12.0(8)J
E. None of the above
Q2. What device does not support Easy VPN client?
A. Cisco 800 Series router
B. Cisco 3002 hardware VPN client
C. Cisco PIX 535 Firewall
D. Cisco PIX 501 Firewall
E. Cisco 1700 Series router
Q3. What is “group-based policy control”?
A. Group-based policy control enables you to apply policies on a per-user or per-group basis.
B. Group-based policy control enables you to apply policies if you are a member of the administrators group.
C. Group-based policy control enables you to apply policies to users only.
D. Group-based policy control enables you to apply policies to groups only.
E. None of the above.
Q4. What Diffie-Hellman groups are supported by Easy VPN Server?
A. 1, 2, 3, 4, and 5
B. 1 and 2 only
C. 2 and 4 only
D. 1 and 4 only
E. 2 and 5 only
Q5. What configuration mode must you be in to configure the IP address pool?
A. Pool-configuration mode
B. Global configuration mode
C. Privileged EXEC mode
D. Interface configuration mode
E. Enable mode
Q6. What do you not configure when creating the ISAKMP policy for the remote VPN clients?
A. Peer authentication method
B. Policy priority
C. Encryption algorithm
D. Hash algorithm
E. Diffie-Hellman group
Q7. What configuration mode must you be in to configure RRI?
A. Crypto-map configuration mode
B. Global configuration mode
C. Privileged EXEC mode
D. Interface configuration mode
E. Enable mode
Q8. What is the time range (in seconds) for DPD keepalive “retries”?
A. 10 to 3600
B. 60 to 3600
C. 2 to 3600
D. 2 to 60
E. 2 to 1800
Q9. How does the Easy VPN Server control VPN policies for remote clients?
Q10. What is dead peer detection (DPD)?
Q11. How does the command aaa new model prepare the router for Easy VPN Server?
Q12. What must you do before selecting your IKE parameters for remote VPN clients?
Q13. What servers should you designate when defining the group policy for mode configuration push?
Q14. What must you do to make a dynamic crypto map function?
Q15. What is the difference between crypto isakmp keepalive seconds and retries?
Q16. What is xauth?
Q17. How many different remote phase II modes does Easy VPN Server support?
Q18. Which remote phase II mode does not support NAT or PAT?
More Resources