フリー問題

Designing and Implementing Secure Cloud Access for Users and Endpoints v2.0 のフリー問題 9 / 20 問目

問題文

A network team plans an IPsec tunnel from its edge router to Secure Access and asks which negotiation settings are safe to keep. What does the documentation state about the supported parameters?

選択肢

  1. Only IKEv1 is supported for the first phase, and Dead Peer Detection is left to the remote end as Secure Access does not send those probes.
  2. Both IKEv1 and IKEv2 are supported, and Perfect Forward Secrecy has to be enabled on the peer end, before the tunnel is allowed to come up at all.
  3. Only IKEv2 is supported, and a tunnel that enables Perfect Forward Secrecy can come up yet fail to rekey on a reconnection, which costs service until it is rebuilt.
  4. Any parameter combination that the remote device offers is accepted, as Secure Access negotiates down to whatever the device supports.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。