exam questions

Exam 300-410 All Questions

View all questions & answers for the 300-410 exam

Exam 300-410 topic 1 question 365 discussion

Actual exam question from Cisco's 300-410
Question #: 365
Topic #: 1
[All 300-410 Questions]



Refer to the exhibit. An engineer must configure a LAN-to-LAN IPsec VPN between R1 and the remote router. Which IPsec Phase 1 configuration must the engineer use for the local router?

  • A. crypto isakmp policy 5
    authentication pre-share
    encryption 3des
    hash sha
    group 2
    !
    crypto isakmp key cisco123 address 200.1.1.3
  • B. crypto isakmp policy 5
    authentication pre-share
    encryption 3des
    hash md5
    group 2
    !
    crypto isakmp key cisco123! address 199.1.1.1
  • C. crypto isakmp policy 5
    authentication pre-share
    encryption 3des
    hash md5
    group 2
    !
    crypto isakmp key cisco123 address 199.1.1.1
  • D. crypto isakmp policy 5
    authentication pre-share
    encryption 3des
    hash md5
    group 2
    !
    crypto isakmp key cisco123 address 200.1.1.3
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
HarwinderSekhon
Highly Voted 1 year, 9 months ago
Selected Answer: A
A and D both are correct but remember to smoke before exam :P vIOS(config-isakmp)#hash ? md5 Message Digest 5 sha Secure Hash Standard sha256 Secure Hash Standard 2 (256 bit) sha384 Secure Hash Standard 2 (384 bit) sha512 Secure Hash Standard 2 (512 bit)
upvoted 10 times
...
sayed_2908
Highly Voted 2 years, 3 months ago
Selected Answer: A
A & D is correct but SHA is safer than MD5. hence I choose A.
upvoted 7 times
...
[Removed]
Most Recent 9 months, 4 weeks ago
Selected Answer: A
A is correct SHA is safer than MD5
upvoted 2 times
...
ZamanR
1 year, 5 months ago
A is correct answer Explanation In the “crypto isakmp key … address ” command, the address must be of the IP address of the other end (which is 200.1.1.3 in this case) so Option A and Option B are correct. The difference between these two options are in the hash SHA or MD5 method but both of them can be used although SHA is better than MD5 so we choose Option A the best answer. Note: Cisco no longer recommends using 3DES, MD5 and DH groups 1, 2 and 5. Reference: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_imgmt/configuration/xe-16- 5/sec-ipsec-management-xe-16-5-book/sec-ipsec-usability-enhance.html
upvoted 2 times
...
guy276465281819372
1 year, 9 months ago
Selected Answer: D
D would be fast and simple, A more secure. no way to choose.
upvoted 2 times
...
inteldarvid
1 year, 10 months ago
Selected Answer: A
100 % "A", because sha is more safe than md5
upvoted 5 times
...
pepgua
1 year, 10 months ago
Selected Answer: D
SHA or SHA1 ? A doesn't look correct?
upvoted 1 times
...
HungarianDish_111
2 years ago
Selected Answer: A
Agree with others. https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_ikevpn/configuration/xe-16-5/sec-ike-for-ipsec-vpns-xe-16-5-book/sec-key-exch-ipsec.html Cisco no longer recommends using DES, 3DES, MD5 (including HMAC variant), and Diffie-Hellman (DH) groups 1, 2 and 5; instead, you should use AES, SHA-256 and DH Groups 14 or higher.
upvoted 3 times
...
azzawim
2 years, 1 month ago
Selected Answer: A
correct answer A
upvoted 4 times
...
dq28
2 years, 4 months ago
I agree ... I think there is something missing in the question. Sha is safer, md5 is faster. Which one should be chosen? Only Cisco (if any) knows.
upvoted 4 times
...
mitosenoriko
2 years, 4 months ago
A and D is correct. i dont select one.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago