70-350 Implementing Microsoft Internet Security and Acceleration (ISA) Server 2004 Certification Exam


Microsoft ™

70-350 Implementing Microsoft Internet Security and Acceleration (ISA) Server 2004



Note 1: 70-350 Exhibit and all related diagrams are not shown in demo questions.
Note 2: 70-350 Answers are not shown in demo questions.
Exhibits and Answers are only provided in the Full Version.


Demo Question 11.


You work as the network administrator at EliteCertify.com. The EliteCertify.com network consists of a single Active Directory domain named EliteCertify.com. The client computers at EliteCertify.com are running Windows XP Professional. EliteCertify.com consists of a Development department. The EliteCertify.com network contains an ISA Server 2004 computer named EliteCertify -SR12 which functions as a remote access VPN server for the network. EliteCertify -SR12 is configured to accept PPTP and L2TP over IPSec for remote access VPN clients to connect to. One morning you have received a compliant that the users cannot connect to the EliteCertify.com network. You then open the log file on EliteCertify -SR12 and notice that the users with failed connection attempts are all using L2TP over IPSec. You need to ensure that the users can connect to the network. What should you do?

A. You need to disable IP fragment blocking.
B. You need to disable IP routing.
C. You need to disable IP options filtering
D. You need to disable verification of incoming client certificates.


Display Answer


Purchase Full Version:


70-350 Printable PDF Prep Guide $49.95 BUY NOW!

70-350 Test Simulation Engine $69.95 BUY NOW!

70-350 PDF & Test Simulation Engine $99.95 BUY NOW!




Answer: A

Explanation: You can also configure ISA Server to drop all IP fragments. If you enable this option, then all fragmented packets are dropped when ISA Server filters packet fragments. A common attack that uses IP fragments is the teardrop. The Layer Two Tunneling Protocol (L2TP) over IPSec connections may not be successfully established because packet fragmentation may take place during certificate exchange. This scenario has IP fragment blocking enabled; therefore you must disable it to allow L2TP over Ipsec communication.



  • Based on the latest 70-350 exam objectives!
  • Designed like actual 70-350 exam questions!
  • 100% Verified Realistic 70-350 Exam Questions and Answers!
  • Exhibits, Drag&Drop and Simulation 70-350 Questions Included!
  • Constantly Updated Guide to Reflect the Current 70-350 Exams!
  • Detailed Explanations for Most Guide Practice Exams!
 Sponsored Links
Japan Exam



SCSI
310-330
$49.95 Get Detail

MCED
1D0-430 1D0-435
1D0-437 1D0-441
1D0-442 1D0-538

$179 Get Detail

SSBB
310-600
$49.95 Get Detail

SCDME
310-100
$49.95 Get Detail

SCBCD
310-090
$49.95 Get Detail


Australia
Great thanks to EliteCertify for such excellent products! It really helped me a lot for passing 3Com 3M0-212. The practice ...


Demark
Took my last CCNP test last Friday. EliteCertify tests really made the difference, I passed every one on the first ...


England
Many thanks to your complete solution in 3Com Test Simulation Engine, Study Guides and PDF practice exams which are very ...





Keyword
This site is both PayPal and VeriSign Verified. 128-bit SSL Encryption!
More questions about Order Security?