SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
MCTS: Protepcting Network Traffic With IPsec
Start Test
Study First
Subjects
:
certifications
,
mcts
,
it-skills
Instructions:
Answer 42 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. You can use IPsec to encrypt network data so that the data is unreadable if captured in transit. This describes what?
filter list
Group Policy
certificate
Encryption
2. To establish SAs dynamically between IPsec peers - the ______ protocol is used.
Internet Key Exchange (IKE)
Windows Firewall with Advanced Security (WFAS) - WFAS
data authentication
ignores any
3. You can assign an IPsec Policy either to an individual computer by using Local Security Policy or to a group of computers by using ______.
Group Policy
filter lists
quick mode
Authentication Header (AH) and Encapsulating Security Payload (ESP)
4. If Group Policy assigns an IPsec Policy to a computer - the computer ______ IPsec Policy assigned in its Local Security Policy.
ignores any
Server (Request Security)
rules
Kerberos (Active Directory) - Certificates - Preshared key
5. You can use any of these three methods to authenticate the hosts communicating through IPsec:
Internet Key Exchange (IKE)
negotiate
Kerberos (Active Directory) - Certificates - Preshared key
specific
6. In Win Vista - Win 7 - Win Srvr 2008 and Win Srvr 2008 R2 - IPsec is enforced either by ______ or ______.
certificate
IPsec Policies or Connection Security Rules
Data integrity
simpler to configure
7. You can assign only one IPsec Policy to a computer at a time. If you assign a second IPsec Policy to a computer - the first IPsec Policy ______.
filter lists
automatically becomes unassigned
rules
Layer Two Tunneling Protocol (L2TP)
8. You can use an Isolation rule to configure "domain isolation." This simply means that you can use Connection Security Rules to block traffic from computers originating from outside the local ______.
Data origin authentication
transport
Active Directory domain
specific
9. Security for an SA is provided by the two IPsec protocols: ______ and ______.
specific
Authentication Header (AH) and Encapsulating Security Payload (ESP)
Data origin authentication
Internet Key Exchange (IKE)
10. Phase 1 negotiation is known as main mode negotiation - and Phase 2 is known as ______ negotiation.
Data integrity
Active Directory domain
quick mode
filter list
11. You should assign the ______ policy to intranet servers that require secure communications - such as a server that transmits highly sensitive data.
simpler to configure
ESP
Secure Server (Require Security)
Windows Firewall with Advanced Security (WFAS) - WFAS
12. Like IPsec Policies - ______ evaluate network traffic and then block - allow - or negotiate security for messages based on the criteria you establish.
ignores any
Kerberos
Connection Security Rules
simpler to configure
13. Possible filter actions for a rule include block - permit - or ______ security.
negotiate
Secure Server (Require Security)
ESP
rules
14. If you need encryption - use ______. If you just need to authenticate the data origin or verify data integrity - use ______.
ESP
specific
simpler to configure
ESP - AH
15. Transport mode is also used in most IPsec-based VPNs - for which the ______is used to tunnel the IPsec connection through the public network.
Layer Two Tunneling Protocol (L2TP)
Group Policy
Data origin authentication
Authentication Header (AH) and Encapsulating Security Payload (ESP)
16. After two computers negotiate an IPsec connection - whether through IPsec Policies or Connection Security Rules - the data sent between those computers is secured in what is known as a ______.
Data authentication - Encryption
Security Association (SA)
Secure Server (Require Security)
IPsec Policies
17. Note that when matching a source or destination address - the most ______ IPsec filter always takes precedence.
certificate
A filter action
specific
Client (Respond Only) - Server (Request Security) - Secure Server (Require Security)
18. Each policy rule - in turn - is associated with one IP ______ and one filter action.
certificate
filter list
two-phase
Kerberos
19. You configure Connection Security Rules for any one computer in the ______ console or the ______node in Server Manager.
Data origin authentication
Windows Firewall with Advanced Security (WFAS) - WFAS
Kerberos (Active Directory) - Certificates - Preshared key
ESP
20. Determines whether the traffic captured by an IP filter in a given policy rule is permitted - blocked - encrypted - or authenticated.
Data integrity
rules
two-phase
A filter action
21. In Group Policy - three IPsec Policies are predefined. You can thus configure an IPsec Policy for a domain or an OU by assigning any one of the following predefined policies:
Active Directory domain
Client (Respond Only) - Server (Request Security) - Secure Server (Require Security)
Authentication Header (AH) and Encapsulating Security Payload (ESP)
specific
22. IP ______ contain a set of one or more IP filters that capture IP traffic for an IPsec Policy.
filter lists
certificate
list has only one IP filter
Active Directory domain
23. ______ by default attempt to negotiate only authentication services.
Data origin authentication
Kerberos
negotiate
Connection Security Rules
24. When you assign ______ policy to a computer through a GPO - that computer will never initiate a request to establish an IPsec communications channel with another computer.
filter list
Client (Respond Only)
Data integrity
Security Association (SA)
25. You should assign the ______ policy to computers for which encryption is preferred but not required.
Server (Request Security)
ESP
Data origin authentication
data authentication
26. ______ by default attempt to negotiate both authentication and encryption services.
Data origin authentication
IPsec Policies
ESP - AH
quick mode
27. The main advantage of using Connection Security Rules is that they are ______.
Connection Security Rules
Encryption
Connection Security Rules
simpler to configure
28. If you need to implement IPsec in a production environment in which Kerberos authentication is not available - you should use a ______ infrastructure to authenticate the IPsec peers.
certificate
Security Association (SA)
A filter action
tunnel
29. To ensure successful and secure communication - IKE performs a ______ negotiation operation - each with its own SAs.
Client (Respond Only) - Server (Request Security) - Secure Server (Require Security)
Internet Key Exchange (IKE)
two-phase
Server (Request Security)
30. Every IPsec Policy is composed of one or more IPsec Policy ______ that determine when and how IP traffic should be protected.
AH
IPsec Policies
rules
A filter action
31. IPsec by default operates in ______ mode - which is used to provide end-to-end security between computers.
filter lists
transport
ESP
negotiate
32. IPsec protects data between two IP addresses by providing the following services:
data authentication
AH
Server (Request Security)
Data authentication - Encryption
33. You can summarize the steps for establishing an IPsec connection in the following way:
Internet Key Exchange (IKE)
filter lists
certificate
1. Set up a main mode SA. 2. Agree upon the terms of communication and encryption algorithm. 3. Create a quick mode SA. 4. Send data.
34. Remember that ______ authentication is preferable in an AD environment. Outside of an AD environment - a certificate infrastructure is your best option.
Kerberos
IPsec Policies
A filter action
Group Policy
35. ______ provides data origin authentication - data integrity - and anti-replay protection for the entire IP packet.
data authentication
AH
transport
two-phase
36. IPsec provides ______ in the form of data origin authentication - data integrity - and anti-replay protection.
Authentication Header (AH) and Encapsulating Security Payload (ESP)
filter list
1. Set up a main mode SA. 2. Agree upon the terms of communication and encryption algorithm. 3. Create a quick mode SA. 4. Send data.
data authentication
37. You can configure IPsec to ensure that each packet you receive from a trusted party in fact originates from that party and is not spoofed. This describes what?
data authentication
Client (Respond Only)
Connection Security Rules
Data origin authentication
38. You can use IPsec to ensure that data is not altered in transit. This describes what?
Windows Firewall with Advanced Security (WFAS) - WFAS
Data integrity
IPsec Policies or Connection Security Rules
transport
39. ______ provides data encryption - data origin authentication - data integrity - and anti-replay protection for the ESP payload.
ESP
Client (Respond Only) - Server (Request Security) - Secure Server (Require Security)
Anti-replay protection
Connection Security Rules
40. You can configure IPsec to verify that each packet received is unique and not duplicated. This describes what?
Anti-replay protection
data authentication
Kerberos
A filter action
41. With IPsec ______ mode - an entire IP packet is protected and then encapsulated with an additional - unprotected IP header.
quick mode
IPsec Policies or Connection Security Rules
tunnel
filter list
42. Every IPsec Policy rule have an IP filter list even if the ________________.
two-phase
list has only one IP filter
Client (Respond Only)
ignores any