Frank wants to know why users on the corporate network cannot receive multicast transmission from the Internet. An NGX Security Gateway protects the corporate network from the Internet. Which of the following is a possible cause for the connection problem?
A. Anti-spoofing is enabled. NGX cannot pass multicast traffic, if anti-spoofing is enabled.
B. Frank did not install the necessary multicast license with SmartUpdate, when he upgraded to NGX.
C. NGX does not support multicast routing protocols and streaming media through the Security Gateway.
D. Multicast restrictions are not configured properly on the corporate internal network interface properties of the Security Gateway object.
E. The Multicast Rule is below the Stealth Rule. NGX can only pass multicast traffic, if the Multicast Rule is above the Stealth Rule.
正解:D
質問 2:
The following is cphaprob state command output from a ClusterXL New mode High Auailability member:

When member 192.168.1.2 fails over and restarts, which member will become active?
A. Both members' state will be active
B. Both member's state will be standby
C. 192.168.1.2
D. 192.168.1.1
正解:D
質問 3:
Your VPN Community includes three Security Gateways. Each Gateway has its own internal network defined as a VPN Domain. You must test the VPN-1 NGX route-based VPN feature, without stopping the VPN. What is the correct order of steps?
A. 1.Add a new interface on each Gateway.
2.Remove the newly added network from the current VPN Domain in each gateway object.
3.Create VPN Tunnel Interfaces (VTI) on each gateway object, to point to the other two peers.
4.Add static routes on three Gateways, to route the new network to each peer's VTI interface.
B. 1.Add a new interface on each Gateway.
2.Remove the newly added network from the current VPN Domain for each Gateway.
3.Create VTIs on each Gateway, to point to the other two peers
4.Enable advanced routing on all three Gateways.
C. 1.Add a new interface on each Gateway.
2.Add the newly added network into the existing VPN Domain for each Gateway.
3.Create VTIs on each gateway object, to point to the other two peers.
4.Enable advanced routing on all three Gateways.
D. 1.Add a new interface on each Gateway.
2.Add the newly added network into the existing VPN Domain for each gateway object.
3.Create VTIs on each gateway object, to point to the other two peers.
9.Add static routes on three Gateways, to route the new networks to each peer's VTI interface.
正解:A
質問 4:
Stephanie wants to reduce the encryption overhead and improve performance for her mesh VPN Community. The Advanced VPN Properties screen below displays adjusted page settings:

What can Stephanie do to achieve her goal?
A. Check the box "Support IP compression".
B. Check the box "Use aggressive mode".
C. Change the setting "Use Diffie-Hellman group" to "Group 5 (1536 bit)".
D. Check the box "Use Perfect Forward Secrecy".
E. Reduce the setting "Renegotiate IKE security associations every" to "720".
正解:A
質問 5:
You want upgrade a SecurePlatform NG with Application Intelligence (AI) R55 Gateway to SecurePlatform NGX R60 via SmartUpdate. Which package is needed in the repository before upgrading?
A. SVN Foundation and VPN-1 Express/Pro
B. SecurePlatform NGX R60
C. SVN Foundation
D. VPN-1 Pro/Express NGX R60
E. VPN-1 and FireWall-1
正解:B
Kirimura -
必要十分な知識をギュッとまとめた完成度の高いテキストで156-915試験に挑めると思います。