Question 1:

Which of the following is the TSM system “illegal outreach” strategy has the function?(Choose two)

A. Allows connection to external networks through the legal route

B. Prohibit access to the Internet

C. Prohibit access to corporate resources critical business systems

D. Prohibit terminal visits

Correct Answer: AB

Question 2:

How to see the number of matches the ACL()

A. display current-configuration

B. display ACL all

C. display startup saved-configuration

D. display device

Correct Answer: B

Question 3:

In the TCP three-way handshake,for packet SYN (seq = b, ack = a 1), the following statement is there?

A. Confirmation of the number of data packets is b

B. A 1 on the number of packets that are recognized

C. A desired number of the next data packet received is b

D. A desired number of the received packet is a 1

Correct Answer: D

Question 4:

As a kind of generic GRE VPN encapsulation protocol encapsulated in the VPN can include multicast packets,including all L3 packets.

A. True

B. False

Correct Answer: A

Question 5:

What are Web proxy implementations?(Choose two)

A. Web-link

B. Web rewritten

C. Web Forwarding

D. Web pass-through

Correct Answer: AB

Question 6:

GRE encapsulation is a work in which of the following interfaces (protected data stream arriving at the interface)?

A. interface tunnel 1

B. interface Ethernet 0/0(within the network)

C. interface Ethernet 0/0(external network)

D. interface loopback 1

Correct Answer: A

Question 7:

As illustrated connection : PC1 —– SW1 ———— SW2 —– PC2; SW1 two ports defined for VLAN1 access type port,SW2 two ports defined as VLAN 2 access port type,(PC1 and PC2 in the same subnet)then the following description is correct?

A. Because all access port,in fact, do not pass VLAN tag information, so you can access PC1 PC2.

B. Because VLAN SW2 SW1 and the ends are different, so youcannotcommunicate between two PC.

C. If two switches are connected to the port is set to trunk ports, two PC can communicate.

D. Because PVID default port on the switch is VLAN 1, so the PC can be both visits.

Correct Answer: A

Question 8:

TSM systems enable the “Monitoring DHCP settings” strategy, end users will be forced to only use DHCP to obtain an IP address automatically.

A. True

B. False

Correct Answer: A

Question 9:

L2TP VPN configuration on the following statement in the precautionsare:(Choose three)

A. The LNS L2TP client must be configured virtual interface template (Virtual-Template) the IP address of the virtual interface template needs to join the domain

B. The default firewall requires authentication of the tunnel. If you do not configure authentication,you need to undo tunnel authentication command

C. To enable L2TP dial-up users can normally access the network address, the address assigned to L2TP users can dial up the network and the user\’s address on the same network segment or need to enable proxy ARP

D. LNS side is not allowed to configure multiple L2TP-Group

Correct Answer: ABC

Question 10:

Stateful inspection firewall can detect TCP protocol,butcannotdetect UDP, since UDP is a connectionless protocol face.

A. True

B. False

Correct Answer: B

Question 11:

In order to ensure the confidentiality of information,the need for confidentiality encryption algorithm:

A. True

B. False

Correct Answer: B

Question 12:

Which of the following are the first stage of IKE exchange mode?(Choose two)

A. Master Mode

B. Aggressive Mode

C. Fast mode

D. Passive mode

Correct Answer: AB

Question 13:

What is the purpose IPSec IKE pre-shared key configuration is?

A. Do the encryption key messages

B. The key to decrypt the packets do

C. Do key authentication algorithm

D. Do negotiate key exchange material

Correct Answer: D

Question 14:

In L2TP scenario, private address allocation is done by the user which of the following components?



C. VPN Client

D. User-configurable

Correct Answer: B

Question 15:

SVN3000 business functions include?(Choose three)

A. Web Proxy

B. Network expansion

C. Port Sharing

D. File Sharing

Correct Answer: ABD

