Which command is used when configuring web management on the VLAN1 interface for a client connected to an e3 interface in the DMZ zone?
A. set int eth3 manage web
B. set zone v1-dmz manage web
C. set int dmz zone manage web
D. set int VLAN1 zone dmz manage web
What is a virtual router?
A. A NetScreen device that has been configured for route mode
B. The interconnection between a NetScreen device and a 3rd party router
C. The logical separation of one physical NetScreen device into multiple separate router tables
D. The physical connection between two separate NetScreen devices into a single logical router
Which ScreenOS CLI command would be used to verify WebAuth authentication?
A. get webauth
B. get auth users
C. get auth table
D. get webauth users
You have a host that is assigned an IP from a private address space, but needs to access systems within the public address space. What form of NAT should you use to minimize configuration requirements?
A. VIP
B. MIP
C. NAT-dst
D. NAT-src
You enter the following command set int e8 mip 1.1.8.32 host 10.1.10.32 netmask 255.255.255.248 How many MIP address translations have you just configured?
A. 1
B. 6
C. 8
D. 30
E. 32
Which two statements are accurate about AH packets? (Choose two.)
A. AH authenticates the complete packet.
B. AH offers enhanced security over ESP.
C. AH allows the creation of unencrypted VPN networks.
D. AH cannot traverse NAT devices when operating in transport mode.
Which item is different when configuring a route-based VPN gateway than a policy-based VPN gateway?
A. Gateway
B. Security Proposal
C. Outgoing interface
D. Binding a tunnel interface
Which is NOT a component of a tunnel interface configuration?
A. zone
B. virtual router
C. subnet mask
D. IP addressing
You have created a route-based VPN in your ScreenOS device. When the remote device tries to connect
you see the following message in your event log:
No policy exists for the proxy id received.
Which two would cause this to occur? (Choose two.)
A. a proxy-id conflict
B. an unbound tunnel interface
C. the remote device is a policy-based VPN
D. the tunnel interface is configured in a different zone than the physical interface
-- Exhibit -
-- Exhibit -Click the Exhibit button.
In the exhibit, why is the packet dropped?
A. interface down
B. route not configured
C. policy not configured
D. denied by policy 1005