Nortel test 920-468 exam dumps Exam 920-468 Nortel VPN Router Rls.7.0 Advanced Configuration & Mgmt 920-468 Testing Engine - Test4pass

920-468 Exam

Nortel VPN Router Rls.7.0 Advanced Configuration & Mgmt

  • Exam Number/Code : 920-468
  • Exam Name : Nortel VPN Router Rls.7.0 Advanced Configuration & Mgmt
  • Questions and Answers : 59 Q&As
  • Update Time: 2011-09-21
  • Price: $ 119.00 $ 69.00

Free 920-468 Demo Download

Test4pass offers free demo for NCSE 920-468 exam (Nortel VPN Router Rls.7.0 Advanced Configuration & Mgmt). You can check out the interface, question quality and usability of our practice exams before you decide to buy it. We are the only one site can offer demo for almost all products.


 

Exam Description

It is well known that 920-468 exam test is the hot exam of Nortel certification. Test4pass offer you all the Q&A of the 920-468 real test . It is the examination of the perfect combination and it will help you pass 920-468 exam at the first time!

Why choose Test4pass 920-468 braindumps

Quality and Value for the 920-468 Exam
100% Guarantee to Pass Your 920-468 Exam
Downloadable, Interactive 920-468 Testing engines
Verified Answers Researched by Industry Experts
Drag and Drop questions as experienced in the Actual Exams
Practice Test Questions accompanied by exhibits
Our Practice Test Questions are backed by our 100% MONEY BACK GUARANTEE.

Nortel NCSE 920-468 exam braindumps questions and answers

¡¡
¡¡
Exam : Nortel 920-468
Title : Nortel VPN Router Rls.7.0 Advanced Configuration & Mgmt


1. Virtual Router Redundancy Protocol (VRRP) has been configured on the VPN Routers of a customer's network. However, all of the traffic is being routed to the Backup and not the Master. What could be a possible reason for this problem?
A. The Virtual Router ID (VRID) is not configured correctly.
B. The Backup and Master VPN Routers are running two different versions of code.
C. The Priority Value of the Master is set to 100, and the Backup is set to a higher value.
D. The authentication string in the Authentication Data field is not set.
Answer: C

2. A customer's VPN Router is configured to authenticate users by their user certificates. Each user is placed into a default group upon successful authentication. Since the customer's user base is growing rapidly, they would like to create a user group for each department within the company and have each user be placed into respective groups upon successful authentication.
Which approach will support this solution?
A. Configure a 'User Access Policy' from the user's group IPsec configuration screen.
B. Configure a 'User Access Policy' in the Certification Authority certificate details section to determine group membership.
C. Use a separate Certification Authority (CA) for each group, and set each group as the 'Default Group' for its respective CA certificate.
D. Configure 'Group Access Control' in the Certification Authority certificate details section to use the Subject DN of the user certificate to determine group membership.
Answer: D

3. Virtual Router Redundancy Protocol (VRRP) has been configured to run as master on a physical interface of a VPN Router. Three additional interfaces, each in a separate interface group, have been associated with this master VRRP interface. Assume one of the three additional interface has gone down. How will the VPN Router react?
A. It will force a VRRP fail-over.
B. It will reroute traffic to the associated VRRP master interface.
C. It will reroute traffic to one of the two remaining additional interface groups.
D. No action necessary, since two additional interfaces are available to the master.
Answer: A

4. A customer has eight VPN Router 5000 systems that share an external LDAP server. Users are authenticated by the switch, which requires a valid user certificate and a user account in the LDAP database. The IT Director is concerned that someone may gain access to confidential employee information during LDAP authentication between the VPN Router and the external LDAP server. What can be done to ensure security?
A. Transfer the user accounts from the external LDAP database to an external RADIUS server.
B. Create a separate subnet just for the external LDAP database server to isolate its network traffic.
C. Configure the VPN Router and the external LDAP server to communicate via Secure Socket Layer (SSL).
D. Switch the external LDAP database to an internal LDAP database on each switch to avoid authentication over the network.
Answer: C

5. In a VPN Router network, a technician has enabled the Fail-over feature so that all remote users working offsite using the Nortel VPN Client will attempt to connect to one or more alternate VPN Router devices if the primary VPN Router fails. Which statement is true regarding the IP addresses specified for the alternate VPN Router devices in the Fail-over?
A. The IP addresses must be for public interfaces.
B. The IP addresses must be for private interfaces.
C. The IP addresses must match the VPN Router management interface address.
D. The IP addresses must match the primary VPN Router interface address.
Answer: A

6. A customer would like their remote users to be able to establish a VPN tunnel with an alternate VPN Router, if the primary VPN Router fails.
What would need to be configured to ensure Fail-over protection?
A. Demand Services
B. Firewall and DHCP settings on the remote PC
C. Only LDAP group parameters
D. VPN Router user tunnel for IPSec fail-over service
Answer: D

7. A customer needs to provide fail-over support capability on their statically routed branch office tunnels and would like to configure the VPN Routers with redundant static routes. Which step can be used to configure static tunnels for fail-over?
A. Create a single static tunnel.
B. Give subsequent static routes a lower cost.
C. Configure static tunnel fail-over using keep-alive and/or idle time out.
D. Give the primary static route a higher cost.
Answer: C

8. A merchant requires the most stringent proof of identity requirements because its certificate is used in the Server Secure Sockets Layer (SSL) protocol to both authenticate the merchant site and is also used as part of the keying material used to encrypt customer credit card information. Which class of certification would you recommend for this merchant?
A. Class One
B. Priority Class
C. Class A1
D. Class Three
Answer: D

9. Employees at the company headquarters and out in the field have found that they are moving from an Ethernet connection to a wireless connection and back, on a regular basis while still having a VPN tunnel established. A network administrator has been tasked with finding a solution that preserves the IPSec tunnel while roaming within the LAN, without affecting applications that use the VPN tunnel. Which solution would you recommend for this customer?
A. IPSec fail-over
B. Nortel IPSec Mobility
C. Tunnel Persistance Mode
D. Virtual Router Redundancy Protocol (VRRP)
Answer: B

10. A customer would like to implement an authentication method that can verify both devices involved with each secure connection. Which scenario would require the use of digital certificates?
A. The LDAP Server Secure Sockets layer (SSL) encryption that provides privacy between the VPN Router and an external LDAP server.
B. The setup of an IPSec tunnel when token security is used in place of user ID and password authentication.
C. A distributed security system that uses an authentication server to verify dial-up connection attributes and authenticate connections.
D. The setup of the IPSec connection between a VPN Router and a Windows 2000 client.
Answer: A

11. To enable Fail-over support in a VPN Router configuration, a technician is setting up Static Tunnel Fail-over for Branch Office Tunnels. Primary and subsequent static routes will be created. To provide the required Fail-over support, how will the primary tunnel be configured?
A. It must be nailed up.
B. It must use RIP only.
C. It must use OSPF only.
D. It must be a virtual tunnel.
Answer: A

12. A high-profile customer dealing with electronic commerce requires non-repudiation of a signature and needs a way to guarantee both the integrity of the data and the authenticity of a sender. You recommend the use of digital certificates and the associated digital signature algorithm. Which statement about the digital signature algorithm is false?
A. The digital signature is computed using a set of rules and a set of parameters such that the identity of the signatory and integrity of the data
can be verified.
B. Each user possesses a private and public key pair. Anyone can verify the signature of a user by employing that user's public key.
C. The digital signature shows who actually ordered the merchandise and but cannot guarantee that the information on the order has not been changed.
D. A private key is restricted for signature use.
Answer: C

13. A VPN Router customer is using certificate authentication for user and branch office tunnels. A supervisor has suggested configuring Certificate Management Protocol (CMP) on the VPN Routers company wide in order to reduce the administrator's workload. In what way would the configuration of CMP benefit the administrator?
A. CMP automates the processes of Certificate Revocation List (CRL) updates and CRL distributions to all VPN Routers.
B. CMP allows the VPN Router to act as a Certification Authority (CA) for other VPN Routers on the network.
C. CMP automates the process of client certificate distribution, so the clients do not need to generate a certificate request.
D. CMP offers management of the entire certificate and key life cycle for the server of the VPN Router.
Answer: D

14. Virtual Router Redundancy Protocol (VRRP) has been configured to run as master on a physical interface of a VPN Router. Two additional interface groups have been associated with this master VRRP interface by use of an interface group. Assume these two additional interface groups have gone down. Which statement describes the state of the VRRP master interface in this scenario?
A. The VRRP master interface remains in the up state as long as the master physical interface is up.
B. The VRRP master interface stays in the down state until all associated interface groups come up.
C. The VRRP master interface goes into a hold state until at least one of the two interface groups comes up.
D. The VRRP master interface goes into a down state until at least one of the two interface groups comes up.
Answer: B


Click Online chat to talk with us , get more informations about Nortel NCSE 920-468 practice exam study guides questions and answers

Test4pass 920-468 Exam Features

Quality and Value for the 920-468 Exam

Test4pass Practice Exams for Nortel 920-468 are written to the highest standards of technical accuracy, using only certified subject matter experts and published authors for development.

100% Guarantee to Pass Your 920-468 Exam

If you prepare for the exam using our Test4pass testing engine, we guarantee your success in the first attempt. If you do not pass the NCSE 920-468 exam (ProCurve Secure WAN) on your first attempt we will give you a FULL REFUND of your purchasing fee AND send you another same value product for free.

Nortel 920-468 Downloadable, Printable Exams (in PDF format)

Our Exam 920-468 Preparation Material provides you everything you will need to take your 920-468 Exam. The 920-468 Exam details are researched and produced by Professional Certification Experts who are constantly using industry experience to produce precise, and logical. You may get questions from different web sites or books, but logic is the key. Our Product will help you not only pass in the first try, but also save your valuable time.

920-468 Downloadable, Interactive Testing engines

We are all well aware that a major problem in the IT industry is that there is a lack of quality study materials. Our Exam Preparation Material provides you everything you will need to take a certification examination. Like actual certification exams, our Practice Tests are in multiple-choice (MCQs) Our Nortel 920-468 Exam will provide you with free 920-468 dumps questions with verified answers that reflect the actual exam. These questions and answers provide you with the experience of taking the actual test. High quality and Value for the 920-468 Exam:100% Guarantee to Pass Your NCSE exam and get your NCSE Certification.

Test4pass 920-468 exam
Test4pass 920-468 pdf exam
Test4pass 920-468 braindumps
Test4pass 920-468 study guides
Test4pass 920-468 trainning materials
Test4pass 920-468 simulations
Test4pass 920-468 testing engine
Test4pass 920-468 vce
Test4pass 920-468 torrent
Test4pass 920-468 dumps
free download 920-468
Test4pass 920-468 practice exam
Test4pass 920-468 preparation files
Test4pass 920-468 questions
Test4pass 920-468 answers

http://www.test4pass.com/920-468-exam.html The safer.easier way to get NCSE Certification .


Guarantee | Buying Process | F.A.Q. | Payment | Refundment Term | Semples | Testing Engine | privacy | Contact | Sitemap 1 2 3 4

Copyright©2006-2009 sale test4pass Limited. All Rights Reserved

sale test4pass materials do not contain actual questions and answers from Microsoft's Cisco's Certification Exams.