Refer to the exhibit.
Two hub-and-spoke groups are connected through a site-to-site IPsec VPN between Hub 1 and Hub 2.
Which two configuration settings are required for Toronto and London spokes to establish an ADVPN shortcut? (Choose two.)
A. On the hubs, net-device must be enabled on all IPsec VPNs.
B. On the spokes, auto-discovery-receiver must be enabled on the IPsec VPN to the hub.
C. On the hubs, auto-discovery-sender must be enabled on the IPsec VPNs to spokes.
D. auto-discovery-forwarder must be enabled on all IPsec VPNs.
正解:B,C
質問 2:
Refer to the exhibit.
In a dual-hub hub-and-spoke SD-WAN deployment, which is a benefit of disabling the anti-replay setting on the hubs?
A. It instructs the hub to disable TCP sequence number check, which is required for TCP sessions originated from spokes to fail over back and forth between the hubs.
B. It instructs the hub to not check the ESP sequence numbers on IPsec traffic, to improve performance.
C. It instructs the hub to disable the reordering of TCP packets on behalf of the receiver, to improve performance.
D. It instructs the hub to skip content inspection on TCP traffic, to improve performance.
正解:A
質問 3:
Which statement is correct about SD-WAN and ADVPN?
A. Routes for ADVPN shortcuts must be manually configured.
B. SD-WAN can steer traffic to ADVPN shortcuts, established over IPsec overlays, configured as SD-WAN members.
C. You must use IKEv2 on IPsec tunnels.
D. SD-WAN does not monitor the health and performance of ADVPN shortcuts.
正解:B
質問 4:
What are two benefits of using the Internet service database (ISDB) in an SD-WAN rule? (Choose two.)
A. The ISDB contains the IP addresses and port ranges of well-known internet services.
B. The ISDB requires application control to maintain signatures and perform load balancing.
C. The ISDB is dynamically updated and reduces administrative overhead.
D. The ISDB applies rules to traffic from specific sources, based on application type.
正解:A,C
質問 5:
Refer to the exhibits.
Two hub-and-spoke groups are connected through a site-to-site IPsec VPN between Hub 1 and Hub 2. The administrator configured ADVPN on both hub-and-spoke groups.
Which two outcomes are expected if a user in Toronto sends traffic to London? (Choose two.)
A. London generates an IKE information message that contains the Toronto public IP address.
B. The first packets from Toronto to London are routed through Hub 1 then to Hub 2.
C. Toronto needs to establish a site-to-site tunnel with Hub 2 to bypass Hub 1.
D. Traffic from Toronto to London triggers the dynamic negotiation of a direct site-to-site VPN.
正解:B,D
立浪** -
Pass4Testさんの問題集を使って学生の私にもNSE7_SDW-7.0に合格することができました。本当に助かりました。誠に有難うございます