What are two protocols within the IPsec suite? (Choose two.)
- A3DES
- BAES
- CESP (correct answer)
- DTLS
- EAH (correct answer)
Reveal answer & explanationHide answer
The correct answer is C, E. Option C: ESP Option E: AH
Page 45 of 60 Β· 1182 total questions.
What are two protocols within the IPsec suite? (Choose two.)
The correct answer is C, E. Option C: ESP Option E: AH
Refer to the exhibit. Local access for R4 must be established and these requirements must be met: β’ Only Telnet access is allowed. β’ The enable password must be stored securely. β’ The enable password must be applied in plain text. β’ Full access to R4 must be permitted upon successful login. Which configuration script meets the requirements?

The correct answer is A. Option A: !conf t!username test1 password testpass1enable secret level 15 0 Test123!line vty 0 15login localtransport input telnet
Explanation
Spanning Tree Protocol prevents Layer 2 loops by placing redundant paths into blocking states. This option keeps traffic private / properly secured as required.
What is a characteristic of RSA?
The correct answer is B. Option B: It is an asymmetric encryption algorithm.
What are two differences between WPA2 and WPA3 wireless security? (Choose two.)
The correct answer is C, D. Option C: WPA2 uses 128-bit key encryption, and WPA3 supports 128-bit and 192-bit key encryption. Option D: WPA3 uses SAE for stronger protection than WPA2, which uses AES.
Explanation
WPA2 uses AES-based CCMP to protect wireless traffic. WPA3 strengthens wireless authentication, including SAE for personal networks. This option keeps traffic private / properly secured as required.
What is an enhancement implemented in WPA3?
The correct answer is D. Option D: defends against deauthentication and disassociation attacks
Which action must be taken when password protection is implemented?
The correct answer is B. Option B: Include special characters and make passwords as long as allowed.
An engineer must configure R1 for a new user account. The account must meet these requirements: β’ It must be configured in the local database. β’ The username is engineer2. β’ It must use the strongest password configurable. Which command must the engineer configure on the router?
The correct answer is C. Option C: R1(config)# username engineer2 algorithm-type scrypt secret test2021
Which two VPN technologies are recommended by Cisco for multiple branch offices and large-scale deployments? (Choose two.)
The correct answer is A, B. Option A: GETVPN Option B: DMVPN This option scales automatically to match demand.
What is a characteristic of RSA?
The correct answer is B. Option B: It is a public-key cryptosystem.
What is used as a solution for protecting an individual network endpoint from attack?
The correct answer is A. Option A: antivirus software
Which security method is used to prevent man-in-the-middle attacks?
The correct answer is A. Option A: authentication This option keeps traffic private / properly secured as required.
Which cipher is supported for wireless encryption only with the WPA2 standard?
The correct answer is B. Option B: AES This option keeps traffic private / properly secured as required.
Refer to the exhibit. This ACL is configured to allow client access only to HTTP, HTTPS, and DNS services via UDP. The new administrator wants to add TCP access to the ONS service. Which configuration updates the ACL efficiently?

The correct answer is B. Option B: ip access-list extended Services35 permit tcp 10.0.0.0 0.255.255.255 host 198.51.100.11 eq domain
Which WPA mode uses PSK authenticaton?
The correct answer is B. Option B: Personal
An engineer is configuring remote access to a router from IP subnet 10.139.58.0/28. The domain name, crypto keys, and SSH have been configured. Which configuration enables the traffic on the destination router?
The correct answer is A. Option A: interface FastEthernet0/0ip address 10.122.49.1 255.255.255.252ip access-group 110 inip access-list extended 110permit tcp 10.139.58.0 0.0.0.15 host 10.122.49.1 eq 22
Explanation
OSPF elects a designated router on multiaccess networks to reduce adjacency and LSA exchange overhead.
To improve corporate security, an organization is planning to implement badge authentication to limit access to the data center. Which element of a security program is being deployed?
The correct answer is C. Option C: physical access control This option keeps traffic private / properly secured as required.
Which benefit does Cisco DNA Center provide over traditional campus management?
The correct answer is C. Option C: Cisco DNA Center leverages APIs, and traditional campus management requires manual data gathering.
How does Chef configuration management enforce a required device configuration?
The correct answer is B. Option B: The installed agent on the device connects to the Chef Infra Server and pulls its required configuration from the cookbook.
What is the PUT method within HTTP?
The correct answer is A. Option A: It replaces data at the destination.
Explanation
NAT translates addresses between network domains, commonly conserving public IPv4 addresses.
Which advantage does the network assurance capability of Cisco DNA Center provide over traditional campus management?
The correct answer is D. Option D: Cisco DNA Center correlates information from different management protocols to obtain insights, and traditional campus management requires manual analysis.
Showing questions 881β900 of 1182 Β· Page 45 of 60