CCNP Security 350-701 SCOR Practice Test 11

CCNP Security 350-701 SCOR Practice Test 11 (Hard) - Site-to-Site VPN - IKEv1/IKEv2 and IPsec Phases

CISCO CCNP Security Exam Logo

1 / 10

In an IPsec VPN, what is the primary purpose of IKE Phase 1?

2 / 10

Which IKE Phase 1 mode uses six messages and exchanges peer identity information in the clear before the channel is protected, making it less commonly used for security-sensitive deployments with dynamic peer addressing?

3 / 10

What is the primary purpose of IKE Phase 2 (Quick Mode) in an IPsec VPN negotiation?

4 / 10

Which improvement does IKEv2 provide over IKEv1 in terms of negotiation efficiency for establishing a VPN tunnel?

5 / 10

Which built-in IKEv2 feature improves VPN resiliency for mobile or dynamically addressed peers by allowing an active IPsec session to survive a change in the peer's IP address without a full renegotiation?

6 / 10

Which IPsec mechanism periodically verifies that a VPN peer is still reachable and responsive, allowing a router to detect a failed peer and tear down or fail over a stale tunnel?

7 / 10

Which IPsec protocol provides both confidentiality (encryption) and integrity/authentication for the encapsulated payload, and is the most commonly deployed IPsec protocol for VPNs requiring encryption?

8 / 10

A site-to-site VPN tunnel is established but traffic fails specifically during Phase 2 negotiation, with Phase 1 completing successfully. Which configuration area is most likely mismatched between the two peers?

9 / 10

Which scenario would require NAT-Traversal (NAT-T) to be enabled for a site-to-site IPsec VPN to function correctly?

10 / 10

Which design consideration would be most important when planning a site-to-site VPN between two organizations that need strong forward secrecy, ensuring that a future compromise of long-term keys cannot decrypt previously captured traffic?

Your score is

The average score is 0%

0%