
CiscoCertified Network Associate (CCNA)
Domain 5Objective 5
5.5 Describe IPsec Remote Access and Site-To-Site VPNs 200-301 Practice Questions (Page 3)
Part of the Security Fundamentals domain, which accounts for 15% of the 200-301 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–1 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
7concepts
15%of the exam
Questions 11–15
- 11
A company has a main office and 50 branch offices. Each branch office has a router with a dynamic public IP address. The company wants to connect all branch offices to the main office using IPsec VPNs. The main office has a static public IP address. Which VPN architecture is most appropriate?
Select an answer first - 12
In a site-to-site IPsec VPN, what is typically required on each VPN gateway to allow traffic to be routed through the tunnel?
Select an answer first - 13
What is a common method used to authenticate users in an IPsec remote access VPN?
Select an answer first - 14
A network engineer is configuring a site-to-site IPsec VPN between two routers. The engineer wants to ensure that the original source and destination IP addresses of the internal hosts are not visible on the public internet. Which mode and protocol combination should be used?
Select an answer first - 15
Which IPsec protocol provides authentication and integrity for the entire IP packet, including the IP header, but does NOT provide encryption?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-301” is a trademark of its owner, used for identification only.