70-291 Implementing, Managing, and Maintaining a Microsoft Windows Server 2003 Network Infrastructure Online Class


Microsoft ™

70-291 Implementing, Managing, and Maintaining a Microsoft Windows Server 2003 Network Infrastructure



Note 1: 70-291 Exhibit and all related diagrams are not shown in demo questions.
Note 2: 70-291 Answers are not shown in demo questions.
Exhibits and Answers are only provided in the Full Version.


Demo Question 9.


Exhibit, Network Topology You work as the network administrator at EliteCertify.com. The EliteCertify.com network consists of a single Active Directory domain named EliteCertify.com. All servers on the EliteCertify.com network run Windows Server 2003 and all client computers run Windows XP Professional. EliteCertify.com has its headquarters in Chicago and a branch office in Dallas. The relevant portion of the network is illustrated in the exhibit. You have received instruction from the CIO to configure an L2TP/IPSec VPN tunnel between EliteCertify -SR24 and EliteCertify -SR25 and configure and assign an IPSec policy named CK_IPSec that requires secure communications. A new EliteCertify.com written security policy requires that you ensure that no unsecured traffic from the Internet reaches the internal network through this VPN whilst ensuring access to the VPN servers from their respective internal networks is not disrupted. Which of the configurations will accomplish this?

A. Input and output L2TP/IPSec packet filters must be configured on the internal interfaces on EliteCertify -SR24 and EliteCertify -SR25.
B. Input and output L2TP/IPSec packet filters must be configured on the external interfaces on EliteCertify -SR24 and EliteCertify -SR25.
C. Edit the All IP Traffic IP Filter list to include the IP addresses for only EliteCertify -SR24 and EliteCertify -SR25 in the properties of CK_IPSec.
D. Edit the All ICMP Traffic IP Filter list to include the IP addresses for only EliteCertify -SR24 and EliteCertify -SR25 in the properties of CK_IPSec.


Display Answer


Purchase Full Version:


70-291 Printable PDF Prep Guide $49.95 BUY NOW!

70-291 Test Simulation Engine $69.95 BUY NOW!

70-291 PDF & Test Simulation Engine $99.95 BUY NOW!




Answer: B

Explanation: Packet filtering is a technology that filters what type of traffic is allowed into and out of the router. One of the most useful features in RRAS is its ability to selectively filter TCP/IP packets in both directions. You can construct filters that allow or deny traffic into or out of your network based on rules that specify source and destination addresses and ports. The basic idea behind packet filtering is simple: You specify filter rules and incoming packets are measured against those rules. You have two choices: Accept all packets except those prohibited by a rule or drop all packets except those permitted by a rule. Filters are normally used to block out undesirable traffic. In general, the idea is to keep out packets that your machines shouldn't see. If you want to ensure that no unsecured traffic from the Internet reaches your internal network through the VPN whilst ensuring access to the VPN servers from their respective internal networks, then you should configure input and output L2TP / IPSec packet filters on the external interfaces on both EliteCertify -SR24 and EliteCertify -SR25. Incorrect answers: A. The filters should be configured on the external interfaces of both EliteCertify -SR24 and EliteCertify -SR25 and not on the internal interfaces. C, D. Editing the All IP Traffic IP Filter to include the EliteCertify -SR24 and EliteCertify -SR25 IP addresses is not going to address the problem that you are trying to avoid. Neither will edit the All ICMP traffic IP Filter list. Reference: James Chellis, Paul Robichaux & Matthew Sheltz, MCSA/MCSE. Windows Server 2003 Network Infrastructure Implementation, Management, and Maintenance Study Guide, Sybex Inc., Alameda, 2003, pp. 422, 447



  • Based on the latest 70-291 exam objectives!
  • Designed like actual 70-291 exam questions!
  • 100% Verified Realistic 70-291 Exam Questions and Answers!
  • Exhibits, Drag&Drop and Simulation 70-291 Questions Included!
  • Constantly Updated Guide to Reflect the Current 70-291 Exams!
  • Detailed Explanations for Most Guide Practice Exams!
 Sponsored Links
Japan Exam



SCSSSE
310-880
$49.95 Get Detail

MCTS
70-235 70-526
70-528 70-529
70-536 70-551
70-552 70-553

$239 Get Detail

SCJP
310-025 310-035
310-055 310-056

$119 Get Detail

8i DBA
1Z0-001 1Z0-023
1Z0-024 1Z0-025
1Z0-026
$149 Get Detail

CCDA
640-863
$49.95 Get Detail


Demark
Took my last CCNP test last Friday. EliteCertify tests really made the difference, I passed every one on the first ...


England
Many thanks to your complete solution in 3Com Test Simulation Engine, Study Guides and PDF practice exams which are very ...


NY, USA
I wanted to take a few minutes to thank EliteCertify for passing 3 exams towards my MCSE. ...





Keyword
This site is both PayPal and VeriSign Verified. 128-bit SSL Encryption!
More questions about Order Security?