getcertified4sure.com

4A0-N02 Exam

Top Tips Of Update 4A0-N02 Training




Pass4sure 4A0-N02 Questions are updated and all 4A0-N02 answers are verified by experts. Once you have completely prepared with our 4A0-N02 exam prep kits you will be ready for the real 4A0-N02 exam without a problem. We have Refresh Nokia 4A0-N02 dumps study guide. PASSED 4A0-N02 First attempt! Here What I Did.

Free 4A0-N02 Demo Online For Nokia Certifitcation:

NEW QUESTION 1
Which of the following statements is NOT correct about the communication between two NSGs in different branch offices?

  • A. These two NSGs exchange OpenFlow-TLS with their controller to establish the tunnel for overlay traffic.
  • B. These two NSGs must be managed by the same VSD/VSD HA cluster.
  • C. The overlay tunnels established between the NSGs must be VXLAN encapsulation.
  • D. The overlay tunnels are established during bootstrapping.

Answer: C

NEW QUESTION 2
Which of the following is true regarding the VLAN-based VPN on Nuage Networks NSG?

  • A. The NSGs use OpenFlow to exchange routing information between each other.
  • B. The NSGs use VXLAN to exchange routing information between each other.
  • C. The NSGs forward overlay traffic between each other by using an OpenFlow tunnel.
  • D. The NSGs forward overlay traffic between each other by using a VXLAN tunnel.

Answer: D

NEW QUESTION 3
Which of the following is a challenge facing enterprise WAN?

  • A. Manual provisioning slows down the new site turn-up.
  • B. There is no Internet access at the remote office.
  • C. OPEX is very high whereas CAPEX is low.
  • D. MPLS VPN is not supported on CPEs.

Answer: A

NEW QUESTION 4
Which of the following is NOT defined in the NSG infrastructure G/W profile?

  • A. Identify the VSD proxy
  • B. Enable two-factor installer authentication
  • C. Port speed and mode
  • D. NTP, stats, syslog server

Answer: B

NEW QUESTION 5
Which one of the following is TRUE regarding the implementation of network egress QoS policy on NSG?

  • A. The network egress and access egress QoS policies are created at different places.
  • B. Rate limiters need to be created in advance to the egress QoS policy.
  • C. It supports hierarchical policing per port/VLAN.
  • D. It supports one parent scheduler at port level and up to eight children queues.

Answer: C

NEW QUESTION 6
Which of the following is false regarding overlay solutions?

  • A. An ‘overlay network’ is a virtual abstraction built on top of an existing physical network.
  • B. Both VXLAN and TRILL are host-centric overlay solutions.
  • C. Nuage Networks VNS uses a VXLAN-based overlay solution.
  • D. Overlay networks are totally transparent to their physical underlay network.

Answer: B

NEW QUESTION 7
What will happen when a virtual/physical appliance in a subnet with encryption enabled is trying to communicate with a virtual/physical appliance in a subnet with encryption disabled?

  • A. The communication is not possible and traffic will be dropped.
  • B. Traffic will be forwarded in an unencrypted VXLAN tunnel.
  • C. Traffic will be forwarded in an unencrypted VXLAN over IPsec tunnel.
  • D. The communication between these two subnets is only possible through service chaining.

Answer: C

NEW QUESTION 8
Which of the following is true regarding the IPsec VPN between the NSGs?

  • A. It encrypts and encapsulates the VXLAN traffic.
  • B. The key for IPsec needs be manually configured on NSGs and must match each other.
  • C. The IPsec tunnel can be directly terminated by VRS in a data center.
  • D. To have IPsec VPN, an encryption function needs to be enabled at each individual NSG.

Answer: C

NEW QUESTION 9
Which of the following is true regarding the certificate needed for VNS deployment?

  • A. CA (Certificate Authority) runs as a service on the utility host.
  • B. CA (Certificate Authority) only generates a certificate for the VSC.
  • C. With the certificate, the communication between the VSD and VSC can be encrypted in IPsec.
  • D. With the certificate, the communication between the VSC and NSG can be encrypted in TLS.

Answer: B

NEW QUESTION 10
Which of the following is correct about the NAT/PAT function on the NSG?

  • A. Only one mode (either NAT or PAT) is supported, depending on administrative configuration.
  • B. NAP/PAT is used to offload the Internet traffic.
  • C. By default, NAT/PAT is enabled.
  • D. NAT/PAT is enabled at the NSG level and applied to all network ports.

Answer: B

NEW QUESTION 11
Which statement about ACL entries is FALSE?

  • A. They can track both TCP and UDP flows.
  • B. They can be created in either ingress or egress directions.
  • C. A packet in the direction of the stateful ACL rules will automatically create a “related” rule in the reverse direction.
  • D. The automatically created rules will not go away until the ACL is manually deactivated and reactivated.

Answer: D

NEW QUESTION 12
Which of the following features is NOT supported by Nuage Networks VNS?

  • A. Service chaining
  • B. Centralized control plane
  • C. MPLS VPN
  • D. IPsec encryption

Answer: A

NEW QUESTION 13
Which component of the VNS solution belongs to the data plane?

  • A. VSD (Virtualized Services Directory)
  • B. VSC (Virtualized Services Controller)
  • C. VRS (Virtual Routing and Switching)
  • D. NSG (Network Services Gateway)

Answer: D

NEW QUESTION 14
Which of the following statements about the NSG vports is TRUE?

  • A. The NSG responds to DHCP requests on a host vport by default.
  • B. A host MAC address is dynamically leaned on a host vport.
  • C. A host vport allows multiple devices to be connected through a switch.
  • D. IP address assignment is handled by the NSG for a host on a host vport.

Answer: D

NEW QUESTION 15
Which of the following statements about uplink ingress policing is FALSE?

  • A. It can be applied to the overlay.
  • B. It can be applied to the underlay.
  • C. VSD raises an alarm when the policing threshold is crossed.
  • D. The policer can be configured by enterprise admin.

Answer: B

NEW QUESTION 16
Which of the following statements about the NSG support for NAT-T is TRUE?

  • A. NAT-T is a network port level attribute.
  • B. NAT-T NPM probes are disabled by default.
  • C. Direct Symmetric to Symmetric mapping is supported.
  • D. Address restricted mapping requires the use of two NPM probes.

Answer: A

NEW QUESTION 17
Which of the following VSD service abstractions maps to a VRF instance in standard networking terminology?

  • A. Domain
  • B. Zone
  • C. Subnet
  • D. L2 domain

Answer: A

NEW QUESTION 18
What type of NAT is used so that any external host can send to iAddr: iPort by sending traffic to eAddr: ePort? (i=internal, e=external)

  • A. Full-cone NAT
  • B. Address-restricted NAT
  • C. Port-restricted NAT
  • D. Symmetric NAT

Answer: A

NEW QUESTION 19
Which protocol is used between VSAP and the VSC?

  • A. XMPP
  • B. OpenFlow
  • C. BGP and OSPF or ISIS
  • D. SNMP

Answer: D

NEW QUESTION 20
Which of the following statements about the Nuage Networks SD-WAN portal is TRUE?

  • A. It runs directly on any Linux-based bare metal server.
  • B. It is packaged as a docker container.
  • C. It is deployed as a KVM, Hyper-V or ESXi virtual machine.
  • D. It must be hosted in a public cloud such as AWS.

Answer: A

NEW QUESTION 21
......

Recommend!! Get the Full 4A0-N02 dumps in VCE and PDF From Dumps-hub.com, Welcome to Download: https://www.dumps-hub.com/4A0-N02-dumps.html (New 40 Q&As Version)