Cisco Deploying Cisco ASA VPN Solutions (VPN v2.0) Sample Questions:
1. Which two statements about the Cisco ASA cluster load-balancing feature are correct?
(Choose two.)
A) The Cisco ASA load-balances IPsec VPN tunnels only.
B) The Cisco ASA load-balances IPsec VPN and Cisco AnyConnect SSL VPN tunnels only.
C) The Cisco ASA load-balances IPsec VPN, clientless, and Cisco AnyConnect SSL VPN tunnels.
D) The Cisco ASA load-balances remote-access VPN tunnels only.
E) The Cisco ASA load-balances both site-to-site and remote-access VPN tunnels.
2. Refer to following Exhibit and answer the following question below:


The user, contractor1, will receive an IP address when the VPN connection is established.
Which statement regarding the IP address is true?
A) Is a dedicated address (10.0.4.1 20)
B) Is sourced from the contractor pool
C) Is sourced from the management pool
D) Is sourced from the employee pool
E) Is sourced from the engineering pool
3. Authorization of a clientless SSL VPN defines the actions that a user may perform within a clientless SSL VPN session. Which statement is correct concerning the SSL VPN authorization process?
A) Remote clients can be authorized by applying a dynamic access policy, which is configured on an external AAA server.
B) Remote clients can be authorized externally by applying group parameters from an external database.
C) Remote client authorization is supported by RADIUS and TACACS+ protocols.
D) To configure external authorization, you must configure the Cisco ASA for cut-through proxy.
4. The LAN-to-LAN tunnel is not established, but an administrator can ping the remote Cisco ASA.
Which three IPsec LAN-to-LAN configuration parameters should the administrator verify at both ends of the tunnel? (Choose three.)
A) pre-shared key
B) extended authentication password
C) crypto ACL source IP address
D) extended authentication username
E) tunnel connection-typE. originate or answer
F) crypto ACL destination IP address
5. You have been using pre-shared keys for IKE authentication on your VPN. Your network has grown rapidly, and now you need to create VPNs with numerous IPsec peers. How can you enable scaling to numerous IPsec peers?
A) Migrate from IPsec to SSL VPN client extended authentication.
B) Migrate to a shared license server.
C) Migrate to external CA-based digital certificate authentication.
D) Migrate to a load-balancing server.
Solutions:
| Question # 1 Answer: C,D | Question # 2 Answer: B | Question # 3 Answer: B | Question # 4 Answer: A,C,F | Question # 5 Answer: C |
We're so confident of our products that we provide no hassle product exchange.


By Alexander

