VPN Flashcards

1
Q

What is a Virtual Private Network?

A

A logical “overlay” on top of an existing network that can provide security to the traffic going over the VPN.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is one protocol built-in to Windows Server 2016 to build a VPN tunnel?

A

Point-to-Point Tunneling Protocol (PPTP).

Worst option for VPN security.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are better options/protocols to use to build VPNs?

A

L2TP/IPSec (Layer 2 Tunneling Protocol), SSTP (Secure Socket Tunneling Protocol), and IKEv2 (Internet Key Exchange Version 2)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What protocols are supported in Server 2016 to provide Authentication services?

A

PAP (Password Authentication Protocol): Sends passwords in plain text

CHAP (Challenge Handshake Authentication Protocol): Challenge and response method. Uses MD5 Hash

MS-CHAP-v2

EAP (Extensible Authentication Protocol)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Which Role allows a server to provide VPN services?

A

Remote Access.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What command is used to verify network connectivity, as well as verify the local interface used for the connection?

A

Test-NetConnection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the management tool used to configure DirectAccess?

A

Remote Access Management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are two different implementation methods of VPNs?

A

Remote Access VPNs and Site-to-Site VPNs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Within the Routing and Remote Access management tool, in the properties of the VPN server, what tab allows you to upgrade your VPN protocol (e.g., L2TP/IPsec)?

A

Security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

On a VPN client, in the properties of the VPN network adapter (Network Connections window), what tab is used to force a client to use a specific VPN protocol; PPTP, L2TP/IPSec, SSTP, IKEv2.

A

Security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

On a VPN client, what VPN type is configured by default?

A

Automatic. Requires the least amount of configuration but also the least amount of security (PPTP).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What VPN protocol requires a pre-shared key?

A

IPSec (L2TP/IPSec)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

DirectAccess is an IPv6 solution that can leverage IPv4 infrastructure. True or False?

A

True.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

When installing DirectAccess on your server, you need to be logged in as the _____ administrator.

A

Domain

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What role is required to install for DirectAccess?

A

Remote Access

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What PowerShell command is used to view currently applied GPOs?

A

gpresult /r

17
Q

What command gets the IP-HTTPS configuration from a computer or GPO as well as displays the configuration type and ServerURL?

A

Get-NetIPHTTPSConfiguration

18
Q

What could be possible causes of DirectAccess not functioning correctly?

A
  1. No IPv4 connectivity to the Access server.
  2. IPv6 is not correctly configured in the infrastructure.
  3. DNS is not working for both IPv4 and IPv6.
  4. A Group Policy did not get applied. This can be checked with the gpresult /r.
19
Q

What does CMAK stand for?

A

Connection Manager Administration Kit

20
Q

In creating a Site-to-Site VPN, what tab is used regarding a user’s properties to allow Network Access Permission?

A

Dial-in

21
Q

With an empty local DNS cache to begin with, a successful ping from a client at site 1 to hostname at site 2 verifies which of the following are working?

A

DNS, VPN, and IP Connectivity.

22
Q

Both sides of a VPN tunnel need to have the same authentication protocols configured. True or False?

A

True.

23
Q

What are some causes as to why a site-to-site VPN will fail?

A
  1. Remote access has not been allowed.
  2. Static routes have not been configured.
  3. User accounts have not been configured.
  4. Authentication protocols are not the same on both sides.
24
Q

Machine certificates are commonly used to identify end users. True or False.

A

False.