SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
MCTS: Protepcting Network Traffic With IPsec
Start Test
Study First
Subjects
:
certifications
,
mcts
,
it-skills
Instructions:
Answer
42
questions in
15 minutes
.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. To ensure successful and secure communication - IKE performs a ______ negotiation operation - each with its own SAs.
Connection Security Rules
Kerberos
Security Association (SA)
two-phase
2. You can use IPsec to ensure that data is not altered in transit. This describes what?
A filter action
Data integrity
1. Set up a main mode SA. 2. Agree upon the terms of communication and encryption algorithm. 3. Create a quick mode SA. 4. Send data.
Data authentication - Encryption
3. When you assign ______ policy to a computer through a GPO - that computer will never initiate a request to establish an IPsec communications channel with another computer.
Connection Security Rules
Client (Respond Only)
Layer Two Tunneling Protocol (L2TP)
Windows Firewall with Advanced Security (WFAS) - WFAS
4. In Group Policy - three IPsec Policies are predefined. You can thus configure an IPsec Policy for a domain or an OU by assigning any one of the following predefined policies:
Client (Respond Only) - Server (Request Security) - Secure Server (Require Security)
specific
IPsec Policies or Connection Security Rules
two-phase
5. In Win Vista - Win 7 - Win Srvr 2008 and Win Srvr 2008 R2 - IPsec is enforced either by ______ or ______.
ignores any
A filter action
IPsec Policies or Connection Security Rules
Encryption
6. You can configure IPsec to ensure that each packet you receive from a trusted party in fact originates from that party and is not spoofed. This describes what?
filter lists
simpler to configure
tunnel
Data origin authentication
7. You can use any of these three methods to authenticate the hosts communicating through IPsec:
Secure Server (Require Security)
Encryption
Kerberos (Active Directory) - Certificates - Preshared key
certificate
8. You should assign the ______ policy to computers for which encryption is preferred but not required.
specific
transport
Connection Security Rules
Server (Request Security)
9. After two computers negotiate an IPsec connection - whether through IPsec Policies or Connection Security Rules - the data sent between those computers is secured in what is known as a ______.
Security Association (SA)
specific
tunnel
Kerberos (Active Directory) - Certificates - Preshared key
10. Security for an SA is provided by the two IPsec protocols: ______ and ______.
certificate
data authentication
two-phase
Authentication Header (AH) and Encapsulating Security Payload (ESP)
11. IPsec provides ______ in the form of data origin authentication - data integrity - and anti-replay protection.
Client (Respond Only)
data authentication
Connection Security Rules
Group Policy
12. Every IPsec Policy is composed of one or more IPsec Policy ______ that determine when and how IP traffic should be protected.
rules
Kerberos
certificate
Security Association (SA)
13. If Group Policy assigns an IPsec Policy to a computer - the computer ______ IPsec Policy assigned in its Local Security Policy.
filter lists
specific
Kerberos (Active Directory) - Certificates - Preshared key
ignores any
14. IPsec protects data between two IP addresses by providing the following services:
Windows Firewall with Advanced Security (WFAS) - WFAS
Data authentication - Encryption
Kerberos
Group Policy
15. Determines whether the traffic captured by an IP filter in a given policy rule is permitted - blocked - encrypted - or authenticated.
Data origin authentication
Windows Firewall with Advanced Security (WFAS) - WFAS
A filter action
Client (Respond Only)
16. Every IPsec Policy rule have an IP filter list even if the ________________.
Secure Server (Require Security)
A filter action
Windows Firewall with Advanced Security (WFAS) - WFAS
list has only one IP filter
17. To establish SAs dynamically between IPsec peers - the ______ protocol is used.
Internet Key Exchange (IKE)
A filter action
Encryption
Secure Server (Require Security)
18. ______ provides data encryption - data origin authentication - data integrity - and anti-replay protection for the ESP payload.
data authentication
Layer Two Tunneling Protocol (L2TP)
ESP
Data integrity
19. Transport mode is also used in most IPsec-based VPNs - for which the ______is used to tunnel the IPsec connection through the public network.
Connection Security Rules
specific
Layer Two Tunneling Protocol (L2TP)
ESP
20. Possible filter actions for a rule include block - permit - or ______ security.
negotiate
Data integrity
Client (Respond Only)
Active Directory domain
21. ______ provides data origin authentication - data integrity - and anti-replay protection for the entire IP packet.
automatically becomes unassigned
Windows Firewall with Advanced Security (WFAS) - WFAS
Kerberos
AH
22. You can use IPsec to encrypt network data so that the data is unreadable if captured in transit. This describes what?
negotiate
Encryption
filter list
Secure Server (Require Security)
23. If you need to implement IPsec in a production environment in which Kerberos authentication is not available - you should use a ______ infrastructure to authenticate the IPsec peers.
simpler to configure
ESP - AH
certificate
data authentication
24. IP ______ contain a set of one or more IP filters that capture IP traffic for an IPsec Policy.
Connection Security Rules
Layer Two Tunneling Protocol (L2TP)
Client (Respond Only) - Server (Request Security) - Secure Server (Require Security)
filter lists
25. You can use an Isolation rule to configure "domain isolation." This simply means that you can use Connection Security Rules to block traffic from computers originating from outside the local ______.
1. Set up a main mode SA. 2. Agree upon the terms of communication and encryption algorithm. 3. Create a quick mode SA. 4. Send data.
Client (Respond Only)
Group Policy
Active Directory domain
26. Phase 1 negotiation is known as main mode negotiation - and Phase 2 is known as ______ negotiation.
quick mode
Security Association (SA)
transport
IPsec Policies
27. ______ by default attempt to negotiate both authentication and encryption services.
IPsec Policies
Client (Respond Only)
Data origin authentication
AH
28. IPsec by default operates in ______ mode - which is used to provide end-to-end security between computers.
ESP - AH
transport
Data integrity
IPsec Policies or Connection Security Rules
29. If you need encryption - use ______. If you just need to authenticate the data origin or verify data integrity - use ______.
ESP - AH
Kerberos (Active Directory) - Certificates - Preshared key
list has only one IP filter
Authentication Header (AH) and Encapsulating Security Payload (ESP)
30. With IPsec ______ mode - an entire IP packet is protected and then encapsulated with an additional - unprotected IP header.
filter lists
tunnel
quick mode
ignores any
31. Remember that ______ authentication is preferable in an AD environment. Outside of an AD environment - a certificate infrastructure is your best option.
Windows Firewall with Advanced Security (WFAS) - WFAS
IPsec Policies or Connection Security Rules
Kerberos
Data integrity
32. You should assign the ______ policy to intranet servers that require secure communications - such as a server that transmits highly sensitive data.
Client (Respond Only)
ESP - AH
rules
Secure Server (Require Security)
33. Note that when matching a source or destination address - the most ______ IPsec filter always takes precedence.
specific
simpler to configure
Client (Respond Only) - Server (Request Security) - Secure Server (Require Security)
Security Association (SA)
34. You configure Connection Security Rules for any one computer in the ______ console or the ______node in Server Manager.
Authentication Header (AH) and Encapsulating Security Payload (ESP)
Connection Security Rules
A filter action
Windows Firewall with Advanced Security (WFAS) - WFAS
35. Like IPsec Policies - ______ evaluate network traffic and then block - allow - or negotiate security for messages based on the criteria you establish.
ESP - AH
Client (Respond Only)
Connection Security Rules
Kerberos (Active Directory) - Certificates - Preshared key
36. You can assign an IPsec Policy either to an individual computer by using Local Security Policy or to a group of computers by using ______.
1. Set up a main mode SA. 2. Agree upon the terms of communication and encryption algorithm. 3. Create a quick mode SA. 4. Send data.
Group Policy
negotiate
automatically becomes unassigned
37. Each policy rule - in turn - is associated with one IP ______ and one filter action.
certificate
filter list
ESP
filter lists
38. ______ by default attempt to negotiate only authentication services.
ESP - AH
Anti-replay protection
Connection Security Rules
A filter action
39. The main advantage of using Connection Security Rules is that they are ______.
simpler to configure
Client (Respond Only)
tunnel
automatically becomes unassigned
40. You can configure IPsec to verify that each packet received is unique and not duplicated. This describes what?
Anti-replay protection
two-phase
list has only one IP filter
Data origin authentication
41. You can assign only one IPsec Policy to a computer at a time. If you assign a second IPsec Policy to a computer - the first IPsec Policy ______.
automatically becomes unassigned
1. Set up a main mode SA. 2. Agree upon the terms of communication and encryption algorithm. 3. Create a quick mode SA. 4. Send data.
Connection Security Rules
tunnel
42. You can summarize the steps for establishing an IPsec connection in the following way:
IPsec Policies
negotiate
transport
1. Set up a main mode SA. 2. Agree upon the terms of communication and encryption algorithm. 3. Create a quick mode SA. 4. Send data.