Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 350-701 Exam - Topic 1 Question 96 Discussion

What are two functions of IKEv1 but not IKEv2? (Choose two)
D) IKEv1 uses EAP authentication and E) IKEv1 conversations are initiated by the IKE_SA_INIT message
A) NAT-T is supported in IKEv1 but rot in IKEv2.
B) With IKEv1, when using aggressive mode, the initiator and responder identities are passed cleartext
C) With IKEv1, mode negotiates faster than main mode

Cisco 350-701 Exam - Topic 1 Question 96 Discussion

Actual exam question for Cisco's 350-701 exam
Question #: 96
Topic #: 1
[All 350-701 Questions]

What are two functions of IKEv1 but not IKEv2? (Choose two)

Show Suggested Answer Hide Answer
Suggested Answer: D, E

In a Cisco Secure Workload implementation, telemetry data can be generated from IPFIX (Internet Protocol Flow Information Export) records using NetFlow connectors and Cisco Secure Workload itself. NetFlow provides insights into network traffic flow and volume, while Cisco Secure Workload uses this data for visibility, segmentation, and security analytics within the data center.


Contribute your Thoughts:

0/2000 characters
Portia
9 months ago
IKEv1 does initiate with IKE_SA_INIT, that's a fact!
upvoted 0 times
...
Carisa
9 months ago
IKEv1's aggressive mode is a cleartext risk, though.
upvoted 0 times
...
Elinore
10 months ago
Wait, are you sure about that EAP thing?
upvoted 0 times
...
Fidelia
10 months ago
Totally agree, IKEv1 is faster in some cases!
upvoted 0 times
...
Odette
10 months ago
IKEv1 supports NAT-T, but IKEv2 doesn't.
upvoted 0 times
...
Erinn
10 months ago
I feel like EAP authentication is more associated with IKEv2, but IKEv1 might have some support for it too.
upvoted 0 times
...
Nieves
11 months ago
IKEv1 does negotiate faster in some scenarios, but I can't remember if that's specifically tied to main mode or aggressive mode.
upvoted 0 times
...
Leonardo
11 months ago
I remember something about aggressive mode in IKEv1, but I can't recall if it really sends identities in cleartext.
upvoted 0 times
...
Precious
11 months ago
I think NAT-T is definitely a feature of IKEv1, but I'm not sure if it's the only one.
upvoted 0 times
...
Shalon
11 months ago
I'm pretty confident that IKEv1 uses EAP authentication, while IKEv2 does not. That's a clear distinction between the two versions.
upvoted 0 times
...
Bette
11 months ago
I'm a bit unsure about the negotiation speed between main mode and aggressive mode in IKEv1. I'll need to review that part to make sure I have it right.
upvoted 0 times
...
Virgie
11 months ago
The aggressive mode in IKEv1 passing identities in cleartext is definitely a key difference from IKEv2. I remember learning about that in class.
upvoted 0 times
...
Gerry
11 months ago
Okay, let's think this through. I know IKEv1 supports NAT-T, but I'm not sure if that's a feature that IKEv2 lacks. I'll need to double-check that.
upvoted 0 times
...
Barrett
11 months ago
This question seems straightforward, but I want to make sure I understand the differences between IKEv1 and IKEv2 correctly.
upvoted 0 times
...
Octavio
11 months ago
Ah, I think I've got it! Deviations from the baseline should be investigated and documented, so I'm going with option B.
upvoted 0 times
...
Aaron
1 year ago
Wait, IKEv1 uses the IKE_SA_INIT message? No wonder it's so much faster than IKEv2 - it's like they're playing a game of 'Whose protocol can be more confusing?'
upvoted 0 times
...
Helene
1 year ago
I'd rather have my identities passed in cleartext than have to remember all these weird IKE version numbers. Back in my day, we just used IPsec and liked it!
upvoted 0 times
Lavera
1 year ago
I think one function of IKEv1 but not IKEv2 is aggressive mode, but I'm not sure about the second one.
upvoted 0 times
...
Maryann
1 year ago
It's true, sometimes simpler is better when it comes to security protocols.
upvoted 0 times
...
Ruth
1 year ago
I agree, IKEv2 may be more secure but it lacks those two functions.
upvoted 0 times
...
Tayna
1 year ago
I agree, it can get confusing with all these different IKE versions.
upvoted 0 times
...
Cassandra
1 year ago
Yeah, IKEv1 also has the ability to use digital signatures for authentication.
upvoted 0 times
...
Evangelina
1 year ago
I prefer the simplicity of just using IPsec without all these different versions.
upvoted 0 times
...
Avery
1 year ago
I prefer IKEv1 because it supports aggressive mode and uses pre-shared keys.
upvoted 0 times
...
...
Kris
1 year ago
I'm tempted to pick E just to see if the exam writer is trying to trick us. But B and D are the real winners here.
upvoted 0 times
Salome
1 year ago
Let's go with B and D then, sounds like the safest bet.
upvoted 0 times
...
Tayna
1 year ago
I agree, those are the two functions of IKEv1 but not IKEv2.
upvoted 0 times
...
Richelle
1 year ago
I think B and D are the correct answers.
upvoted 0 times
...
...
Hyun
1 year ago
A and C seem like the obvious choices here. NAT-T support and faster mode negotiation are clear advantages of IKEv1 over IKEv2.
upvoted 0 times
Sharee
1 year ago
A) and C) are the correct functions of IKEv1 but not IKEv2.
upvoted 0 times
...
Salome
1 year ago
C) With IKEv1, mode negotiates faster than main mode.
upvoted 0 times
...
Brice
1 year ago
A) NAT-T is supported in IKEv1 but not in IKEv2.
upvoted 0 times
...
...
Dana
1 year ago
Definitely going with B and D. Aggressive mode in IKEv1 is a security risk, and EAP authentication is a key feature that's missing in IKEv2.
upvoted 0 times
Moira
1 year ago
IKEv1 conversations starting with IKE_SA_INIT message is a nice touch.
upvoted 0 times
...
Evelynn
1 year ago
I prefer IKEv1 for its faster mode negotiation and NAT-T support.
upvoted 0 times
...
Reynalda
1 year ago
Yes, EAP authentication is a key feature missing in IKEv2.
upvoted 0 times
...
Aleta
1 year ago
Agreed, aggressive mode in IKEv1 is definitely a security risk.
upvoted 0 times
...
Dalene
1 year ago
I think EAP authentication is crucial, it's a shame IKEv2 doesn't support it.
upvoted 0 times
...
Gilma
1 year ago
Agreed, aggressive mode in IKEv1 is definitely a security risk.
upvoted 0 times
...
...
Amber
1 year ago
I'm not sure about option B, but I think option A is definitely one of the functions of IKEv1.
upvoted 0 times
...
Kenia
1 year ago
I agree with Edwin, NAT-T and cleartext identities are unique to IKEv1.
upvoted 0 times
...
Edwin
1 year ago
I think option A and B are the correct answers.
upvoted 0 times
...

Save Cancel