You are configuring a VPN with IKE between headquarters and a branch office that uses a dynamic public IP address. Which IKE mode should you use?
A. quick mode
B. main mode
C. aggressive mode
D. wizard mode
You want to copy an external configuration file to your ScreenOS device and have it become active only after the device reboots. How would you accomplish this goal?
A. From the device, copy the configuration from an external TFTP server to the device's flash memory.
B. From the device, copy the configuration from an external TFTP server to the device's RAM.
C. From the device, copy the configuration from an external TFTP server and merge it with the current configuration.
D. From the device, copy the configuration from the device's flash memory to an external TFTP server.
You want to centralize the logging for all your ScreenOS devices and you must be able to synchronize the log. Which two actions would you perform to accomplish this? (Choose two.)
A. Enable logging to the console.
B. Enable logging to syslog.
C. Enable NTP and set to UTC/GMT time.
D. Enable logging to the USB.
Referring to the exhibit, what does this output show?
A. the number of supported physical interfaces on the device
B. the number of supported route tables on the device
C. the number of supported VRs on the device
D. the amount of system memory on the device
A routing table contains an IBGP route, a RIP route, an OSPF external Type 2 route, and an EBGP route for 192.168.0.0/16. When the router receives traffic destined for, which route will the router use by default?
A. the EBGP route
B. the IBGP route
C. the OSPF route
D. the RIP route
FTP connections from host 10.20.1.10 to server 192.168.1.100 are not working. You produce the output shown in the exhibit. What is causing the traffic problem?
ssg20-> set address "Trust" "192.168.1.0/32" 10.20.1.0 255.255.255.0 ssg20-> set address "Untrust" "10.204.1.0/24" 10.204.1.0 255.255.255.0 ssg20-> set address "Untrust" "192.168.1.0/24" 192.168.1.0 255.255.255.255 ssg20-> get policy id 1 name:"none" (id 1), zone Trust -> Untrust,action Permit, status "enabled" src "192.168.1.0/32", dst "192.168.1.0/24", serv "FTP" Rules on this VPN policy: 0 nat off, Web filtering : disabled vpn unknown vpn, policy flag 00000000, session backup: on, idle reset: on traffic shaping off, scheduler n/a, serv flag 00 log no, log count 0, alert no, counter no(0) byte rate(sec/min) 0/0 total octets 0, counter(session/packet/ octet) 0/0/0 priority 7, diffserv marking Off tadapter: state off, gbw/mbw 0/0 policing (no) No Authentication No User, User Group or Group expression set
A. The policy's source address is incorrect.
B. The policy's destination address is incorrect.
C. The policy's service is incorrect.
D. The policy does not have the FTP ALG enabled.
What are three required policy elements? (Choose three.)
A. source address
B. protocol
C. service
D. log
E. destination address
You are using NSRP and enable preempt on a device with a priority of 120. The other device has the default priority set. What will be the result of this action?
A. The device will become master immediately.
B. The device will only become master if the device with default priority fails.
C. The device will wait the defined holdtime period and then take over as master.
D. The device will enter a pending state until the next maintenance window and then assume the master role.
What is an aggregate interface?
A. An aggregate interface binds two physical interfaces together to create a redundant interface.
B. An aggregate interface is used for VPN tunnels.
C. An aggregate interface is the management interface.
D. An aggregate interface binds two or more physical interfaces that share the traffic load.