642-552  Exam

Exam # of questions Description  Update
642-552 51 Securing Cisco Networking Devices (SND)... 12/04/2008
[Practice Test]    [Download Study Guide(PDF)]   [Update Exam]

642-552 - Exam Information
  • Description: Securing Cisco Networking Devices (SND)
  • Passing Score: 0%
  • Practice Test - Number of questions: 51 questions
  • Simulation Test - Number of questions: 51 questions
  • Simulation Test Duration: 120 minutes
  • Has explanations: No

Question of the day

Which of these is true regarding IKE Phase 2?

Answer(s)

  1. The SAs used by IPsec are unidirectional, so a separate key exchange is required for each data flow.
  2. Either main or aggressive mode can be used to establish the SAs.
  3. Quick mode is used to establish the unidirectional IKE SA and the bidirectional IPsec SAs.
  4. XAUTH can be optionally used to reauthenticate the IPsec peers.
  5. The Diffie-Hellman protocol is used to exchange the public and private keys between the two IPsec peers.
Correct Answer

The SAs used by IPsec are unidirectional, so a separate key exchange is required for each data flow.