05.03.2013 Views

MCSA/MCSE Self-Paced Training Kit (Exam 70-270): Installing ...

MCSA/MCSE Self-Paced Training Kit (Exam 70-270): Installing ...

MCSA/MCSE Self-Paced Training Kit (Exam 70-270): Installing ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Objective 6.2 Connect to Computers by Using Dial-Up Networking<br />

26-15<br />

Objective 6.2 Answers<br />

1. Correct Answers: A, B, and E<br />

A. Correct: L2TP tunneling supports IPSec authentication. Point-to-Point Tunneling<br />

Protocol (PPTP) tunneling does not support this type of authentication.<br />

B. Correct: L2TP supports header compression, which reduces the number of bytes<br />

consumed by the header to four. PPTP does not perform header compression, and<br />

as a result, IP headers consume six bytes.<br />

C. Incorrect: Only PPTP automatically provides PPP encryption. L2TP can provide<br />

IPSec encryption.<br />

D. Incorrect: PPTP was the only method of tunneling included with Windows NT<br />

4.0. Windows 2000 and later versions of Windows include both PPTP and L2TP<br />

capabilities.<br />

E. Correct: PPTP connections require only user-level authentication. L2TP/IPSec<br />

connections can require the same user-level authentication and, in addition, computer-level<br />

authentication through a computer certificate.<br />

2. Correct Answers: A<br />

A. Correct: Password Authentication Protocol (PAP) does not support encryption.<br />

As a result, PAP is more vulnerable to attack than other protocols and must be<br />

used only when the remote access client does not support any other method of<br />

authentication.<br />

B. Incorrect: The Shiva Password Authentication Protocol (SPAP) does support<br />

encryption. However, SPAP is not as secure as Challenge Handshake Authentication<br />

Protocol (CHAP) or Microsoft Challenge Handshake Authentication Protocol<br />

(MS-CHAP) because it sends the password across the remote access link using<br />

reversible encryption. Use SPAP only when it is the sole method of authentication<br />

that the client supports.<br />

C. Incorrect: The CHAP transmits authentication information using encrypted, oneway<br />

MD5 hashes. Using a one-way hash is more secure than using reversible<br />

encryption because the user can be authenticated without actually sending the<br />

password to the server.<br />

D. Incorrect: The MS-CHAP provides encrypted authentication in a very similar<br />

manner to CHAP. However, MS-CHAP can also use Microsoft Point-to-Point<br />

Encryption (MPPE) to encrypt data to the client or the server.<br />

E. Incorrect: The Microsoft Challenge Handshake Authentication Protocol version 2<br />

(MS-CHAP v2) provides all the features of MS-CHAP, plus authentication of both<br />

the client and server using one-way encryption. Therefore, MS-CHAP v2 provides<br />

the highest level of security available to users of Windows XP Professional.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!