“Do I Know This Already?” Quiz

The “Do I Know This Already?” quiz helps you determine your level of knowledge of this chapter’s topics before you begin. Table 3-1 details the major topics discussed in this chapter and their corresponding quiz questions.

Image

Table 3-1 “Do I Know This Already?” Section-to-Question Mapping

1. Which of the following are most likely to be used for authentication of a network administrator accessing the CLI of a Cisco router? (Choose all that apply.)

a. TACACS+

b. Diameter

c. RADIUS

d. ACS

2. Which of the following allows for granular control related to authorization of specific Cisco IOS commands that are being attempted by an authenticated and authorized Cisco router administrator?

a. RADIUS

b. Diameter

c. TACACS+

d. ISE

3. Which devices or users would be clients of an ACS server? (Choose all that apply.)

a. Routers

b. Switches

c. VPN users

d. Administrators

4. On the router, what should be created and applied to a vty line to enforce a specific set of methods for identifying who a user is?

a. RADIUS server

b. TACACS+ server

c. Authorization method list

d. Authentication method list

5. What is the minimum size for an effective TACACS+ group of servers?

a. 1

b. 2

c. 5

d. 6

6. With what can you configure AAA on the router? (Choose all that apply.)

a. ACS

b. CCP

c. CLI

d. TACACS+

7. Which statement is true for ACS 5.x and later?

a. User groups are nested in network device groups.

b. Authorization policies can be associated with user groups that are accessing specific network device groups.

c. There must be at least one user in a user group.

d. User groups can be used instead of device groups for simplicity.

8. Where in the ACS do you go to create a new group of administrators?

a. Users and Identity Stores > Identity Groups

b. Identity Stores > Identity Groups

c. Identity Stores and Groups > Identity Groups

d. Users and Groups > Identity Groups

9. From the router, which method tests the most about the ACS configuration, without forcing you to log in again at the router?

a. ping

b. traceroute

c. test aaa

d. telnet

10. Which of the following could likely cause an ACS authentication failure, even when the user is using the correct credentials? (Choose all that apply.)

a. Incorrect secret on the ACS

b. Incorrect IP address of the ACS configured on the router

c. Incorrect routing

d. Incorrect filtering between the ACS and the router

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
18.227.46.229