exam questions

Exam MD-100 All Questions

View all questions & answers for the MD-100 exam

Exam MD-100 topic 4 question 4 discussion

Actual exam question from Microsoft's MD-100
Question #: 4
Topic #: 4
[All MD-100 Questions]

HOTSPOT -
You have a computer named Computer1 that runs Windows 10.
On Computer1, you create a VPN connection as shown in the following exhibit.

The corporate network contains a single IP subnet.
Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Anthony_2770
Highly Voted 4 years, 5 months ago
VPN1 Protocols 1.Answer has to be revolve around what Tunnels support Mschapv2 authentication methods Tunnelling is automatic but the choice of using PAP, CHAP, or MSCHAPv2 applies only to PPTP, L2TP/IPsec, and SSTP tunnels; IKEv2 tunnels can only use EAP-MSCHAPv2 or certificates from my research. Microsoft PPTP VPN is using a weak algorithm (MS-CHAP v2) L2TP decides between PAP, CHAP, or MS-CHAPv2 authentication for users. SSTP accepts MSchapV2 on Microsoft win 10 vpns. Option 1 and 2 appear to be correct, therefore I would choose all 4 protocols but I cannot find anything to suggest that Microsoft vpns on win 10 machines can use Mschapv2 for an iEKv2 tunnel Accept option 4 (all protocols) 2.Only traffic for the corporate network Split-tunnelling is true. Corporate network goes through the vpn and internet access is routed from the local host.
upvoted 16 times
Anthony_2770
4 years, 4 months ago
Additionally on another sites sample questions : The TunnelType parameter is set to Automatic. The Automatic option means that the device will try each of the built-in tunneling protocols until one succeeds. It will attempt from most secure to least secure. I would accept all 4 protocols for part 1.
upvoted 4 times
Balena
4 years, 3 months ago
IKE-V2 requires EAP with MSCHAPv2. So only PPTP-L2TP/IPSEC-SSTP. From my lab: .... AuthenticationMethod : {EAP} .... +ref: https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/ff687731(v=ws.10)
upvoted 2 times
Balena
4 years, 3 months ago
But there is only answer 1 and 2 without IKEv2. So I don't know here. You obviously cannot choose 3 or 4, and choosing 1 or 2 is wrong since all 3 protocols would work.
upvoted 1 times
...
...
tonytones
4 years, 1 month ago
See mllerena's comment
upvoted 1 times
...
...
...
hokieman91
Highly Voted 4 years, 5 months ago
Disagree with first answer since Tunnel Type is set to: Automatic – this should allow the host as being able to support all protocols for connection since the connection protocol was not predefined. Second answer is correct since the split tunnel: true means VPN traffic is split to the remote network (remote files, remote printers, RDP, etc.) while internet traffic will remain routed through the local host (opposite of full tunnel where all traffic tunnels through the remote connection, including internet)
upvoted 9 times
eufdf12342
4 years, 3 months ago
Opposite would be false since its boolean https://docs.microsoft.com/en-us/powershell/module/vpnclient/set-vpnconnection?view=win10-ps
upvoted 1 times
...
...
[Removed]
Most Recent 2 years, 9 months ago
all are supported: https://docs.microsoft.com/en-us/windows/security/identity-protection/vpn/vpn-connection-type
upvoted 1 times
...
fxc119
2 years, 10 months ago
The Automatic option means that the device will try each of the built-in tunneling protocols until one succeeds. It will attempt from most secure to least secure
upvoted 1 times
...
veteran_tech
2 years, 10 months ago
I just tested this on Win10 v1809. Here are my results: All tunnel types (PPTP, L2TP with Machine Cert, L2TP with Pre-Shared Key, SSTP, IKEv2, and Auto) ALL support EAP. They also all support MS-CHAPv2, EXCEPT IKEv2 does NOT support it. Incidentally, you can only select MS-CHAPv2 if the user authentication type ("Type of sign-in info") is set to "User name and password". So IKEv2 is the only one that does NOT support MS-CHAPv2.
upvoted 1 times
veteran_tech
2 years, 10 months ago
This question must be older because you CAN choose MsChapv2 for PPTP, both types of L2TP, and SSTP in Win10 v1809.
upvoted 1 times
...
...
CARIOCA
3 years, 8 months ago
What would be the final answer and justification?
upvoted 2 times
...
Perycles
4 years ago
Q1 : All Protocol tested (from best to least secure : IKev2 - L2TP - SSPT -PPTP) because on Automatic (https://docs.microsoft.com/fr-fr/windows/security/identity-protection/vpn/vpn-connection-type) Q2 :Only intranet traffic
upvoted 4 times
...
mllerena
4 years, 2 months ago
SSTP-> SSL Certifcate IKE-V2 -> Certificate Box 1 PPTP, L2TP/IPsec
upvoted 8 times
...
TestTaker72
4 years, 3 months ago
I suspect they are going for all four since TunnelType it is set to Automatic (vs a specific tunnel type) https://docs.microsoft.com/en-us/powershell/module/vpnclient/add-vpnconnection?view=win10-ps
upvoted 2 times
...
Dom20
4 years, 5 months ago
can someone explain how to find the answer on this one?
upvoted 6 times
[Removed]
4 years, 5 months ago
I believe you look at the previous question. That question specifies the answer for this question on the first line. Bit of a shame that they don't mention this is a multipart question (unless I'm also missing something)
upvoted 3 times
51007
3 years ago
Looks like different connections. Q4-3 says conn. Name is 'Contoso VPN' and SplitTunneling is False. This question (4-4) says Name 'VPN1' and SplitTunneling is True.
upvoted 1 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago