351-018 CCIE Security Written Certified Practice Exam (Beta)

所在平台: Udemy

课程主页: https://www.udemy.com/course/351-018-ccie-security-written-certified-practice-exam-beta/

课程评论:没有评论

第一个写评论        关注课程

课程简介

这门名为“351-018 CCIE Security Written Certified Practice Exam (Beta)”的课程是一个模拟考试,旨在帮助学员准备CCIE安全笔试认证。课程内容涵盖了安全网络领域的多个关键技术和协议,通过一系列示例问题来考察学员的理解和应用能力。 **主要考察内容包括:** * **IPv6和PMTUD:** 涉及ICMPv6报文类型和代码,特别是在防火墙策略中,哪些报文(如ICMPv6 Type 2 Code 0 "packet too big")不应被阻止,以支持路径MTU发现(PMTUD)。 * **IP报文处理:** 考察Cisco IOS路由器如何处理TTL值低于或等于1的TCP报文,以及其可能触发的ICMP错误类型(如Type 11 Code 0 "Time Exceeded")。 * **Mobile IP:** 对比Mobile IPv6和Mobile IPv4,重点突出它们在代理(foreign agent)需求、路由优化支持、地址发现方法、封装方式以及邻居发现机制(如IPv6 ND)上的差异。 * **AES加密算法:** 考察AES作为FIPS批准的对称分组密码的特性,包括其支持的块大小(128位)和密钥大小(128、192、256位),以及与其他加密算法(如基于大整数分解的RSA)的区别。 * **IKEv2与IKEv1:** 比较IKEv2相比IKEv1在部署远程访问IPsec VPN时的优点,例如对EAP认证的支持、内置NAT穿越能力、消息ID的随机性、建立SA的消息数量减少以及消息的加密保护。 * **MACsec:** 探讨MACsec(IEEE 802.1AE)的特性,包括其支持的AES GCM模式、提供跳对跳的二层加密、对帧顺序的要求(防止重放攻击)以及MKA(MACsec Key Agreement)在会话和加密密钥管理中的作用。 * **SSH协议:** 考察SSH协议的特性,如其工作在TCP端口22,提供安全远程登录和网络服务,以及在身份验证(支持公钥、密码等)和传输层(提供身份验证、密钥交换、保密性和完整性)方面的功能。 总的来说,该课程模拟了CCIE安全认证考试的真实场景,通过多项选择题的形式,全面检测学员在网络安全协议、加密技术、IPv6和移动IP等核心领域的知识掌握程度。

课程评论(0条)

课程详情

Sample Questions:Based on RFC 4890, what is the ICMP type and code that should never be dropped by the firewall to allow PMTUD?ICMPv6 Type 1 Code 0 no route to hostICMPv6 Type 1 Code 1 communication with destination administratively prohibitedICMPv6 Type 2 Code 0 packet too bigICMPv6 Type 3 Code 1 fragment reassembly time exceededICMPv6 Type 128 Code 0 echo requestICMPv6 Type 129 Code 0 echo replyWhen a Cisco IOS Router receives a TCP packet with a TTL value less than or equal to 1, what will it do?Route the packet normallyDrop the packet and reply with an ICMP Type 3, Code 1 (Destination Unreachable, Host Unreachable)Drop the packet and reply with an ICMP Type 11, Code 0 (Time Exceeded, Hop Count Exceeded)Drop the packet and reply with an ICMP Type 14, Code 0 (Timestamp Reply)Which three statements are correct when comparing Mobile IPv6 and Mobile IPv4 support? (Choose three.)Mobile IPv6 does not require a foreign agent, but Mobile IPv4 does.Mobile IPv6 supports route optimization as a fundamental part of the protocol; IPv4 requires extensions.Mobile IPv6 and Mobile IPv4 use a directed broadcast approach for home agent address discovery.Mobile IPv6 makes use of its own routing header; Mobile IPv4 uses only IP encapsulation.Mobile IPv6 and Mobile IPv4 use ARP for neighbor discovery.Mobile IPv4 has adopted the use of IPv6 ND.Which two statements are correct regarding the AES encryption algorithm? (Choose two.)It is a FIPS-approved symmetric block cipher.It supports a block size of 128, 192, or 256 bits.It supports a variable length block size from 16 to 448 bits.It supports a cipher key size of 128, 192, or 256 bits.The AES encryption algorithm is based on the presumed difficulty of factoring large integers.What are two benefits of using IKEv2 instead of IKEv1 when deploying remote-access IPsec VPNs? (Choose two.)IKEv2 supports EAP authentication methods as part of the protocol.IKEv2 inherently supports NAT traversal.IKEv2 messages use random message IDs.The IKEv2 SA plus the IPsec SA can be established in six messages instead of nine messages.All IKEv2 messages are encryption-protected.Which three statements are true about MAC sec? (Choose three.)It supports GCM modes of AES and 3DES.It is defined under IEEE 802.1AE.It provides hop-by-hop encryption at Layer 2.MAC sec expects a strict order of frames to prevent anti-replay.MKA is used for session and encryption key management.It uses EAP PACs to distribute encryption keys.Which three statements are true about the SSH protocol? (Choose three.)SSH protocol runs over TCP port 23.SSH protocol provides for secure remote login and other secure network services over an insecure network.Telnet is more secure than SSH for remote terminal access.SSH protocol runs over UDP port 22.SSH transport protocol provides for authentication, key exchange, confidentiality, and integrity.SSH authentication protocol supports public key, password, host based, or none as authentication methods.

课程标签

0人关注该课程

主题相关的课程