SYSTEM ADMINISTRATION COMPLETE
STUDY GUIDE WITH QUESTIONS AND
ANSWERS 2026
▶ Regarding the Common IETF Attributes in RADIUS what attribute
number is Message-Authenticator?. Answer: Type: 80
Description: Used to verify the authenticity and integrity of RADIUS
packets, ensuring that the message has not been tampered with.
Usage: Essential for securing RADIUS communications.
▶ Regarding the Common IETF Attributes in RADIUS what attribute
number is Error-Cause?. Answer: Type: 101
Description: Typically included in a RADIUS response message to inform
the RADIUS client (such as a Network Access Server, NAS) about the
reason for the rejection or failure of a request. Usage: Helps in diagnosing
issues and allows for appropriate corrective actions to be taken.
▶ When a transparent authentication fails on the Web Security Appliance,
which type of access does the end user get?
A. guest
B. limited Internet
C. blocked
D. full Internet. Answer: A. Guest
If transparent authentication fails, you can configure how to handle the
transaction: you can grant the user guest access, or you can force an
authentication prompt to appear to the user.
https://www.cisco.com/c/en/us/td/docs/security/wsa/wsa11-
0/user_guide/b_WSA_UserGuide/b_WSA_UserGuide_chapter_01001.html
#con_1442362
▶ NAD. Answer: Network Access Device:
Any network device that controls access to the network. This includes
switches, wireless access points (APs), VPN concentrators, and other
devices that manage how users and devices connect to the network.
▶ CoS. Answer: Class of Service:
, A method of managing traffic in a network by assigning different levels of
priority to different types of traffic. This allows network administrators to
ensure that more important or time-sensitive data, such as voice or video,
receives preferential treatment over less critical traffic, like email or file
downloads.
▶ Error: CRYPTO-4-IKMP_BAD_MESSAGE: IKE message from x.x.x.x
failed its sanity check or is malformed.
What is the most likely cause of this error?
A) Network latency causing packet loss
B) Incorrect NAT configuration
C) Mismatched Pre-Shared Keys (PSKs) on the peer routers
D) Unsupported encryption algorithm. Answer: Correct Answer: C)
Mismatched Pre-Shared Keys (PSKs) on the peer routers
▶ Error: CRYPTO-6-IKMP_NO_SA: IKE message from x.x.x.x has no SA
and is not an initialization offer.
What is the most likely cause of this error?
A) The VPN policy parameters are mismatched between the peers
B) The PSKs are mismatched on the peer routers
C) The certificate is not trusted
D) The peer device is unreachable. Answer: Correct Answer: A) The VPN
policy parameters are mismatched between the peers
▶ Error: CRYPTO-4-IKMP_INVALID_PAYLOAD_TYPE: Invalid payload
type 20 received from x.x.x.x.
What is the most likely cause of this error?
A) Mismatch in IKE policy configurations
B) Expired certificates
C) Incorrect NAT-T configuration
D) Network congestion. Answer: Correct Answer: A) Mismatch in IKE
policy configurations
▶ Error: CRYPTO-6-IKMP_SA_NOTFOUND: IKE message from x.x.x.x
failed its sanity check or is malformed.
What is the most likely cause of this error?
STUDY GUIDE WITH QUESTIONS AND
ANSWERS 2026
▶ Regarding the Common IETF Attributes in RADIUS what attribute
number is Message-Authenticator?. Answer: Type: 80
Description: Used to verify the authenticity and integrity of RADIUS
packets, ensuring that the message has not been tampered with.
Usage: Essential for securing RADIUS communications.
▶ Regarding the Common IETF Attributes in RADIUS what attribute
number is Error-Cause?. Answer: Type: 101
Description: Typically included in a RADIUS response message to inform
the RADIUS client (such as a Network Access Server, NAS) about the
reason for the rejection or failure of a request. Usage: Helps in diagnosing
issues and allows for appropriate corrective actions to be taken.
▶ When a transparent authentication fails on the Web Security Appliance,
which type of access does the end user get?
A. guest
B. limited Internet
C. blocked
D. full Internet. Answer: A. Guest
If transparent authentication fails, you can configure how to handle the
transaction: you can grant the user guest access, or you can force an
authentication prompt to appear to the user.
https://www.cisco.com/c/en/us/td/docs/security/wsa/wsa11-
0/user_guide/b_WSA_UserGuide/b_WSA_UserGuide_chapter_01001.html
#con_1442362
▶ NAD. Answer: Network Access Device:
Any network device that controls access to the network. This includes
switches, wireless access points (APs), VPN concentrators, and other
devices that manage how users and devices connect to the network.
▶ CoS. Answer: Class of Service:
, A method of managing traffic in a network by assigning different levels of
priority to different types of traffic. This allows network administrators to
ensure that more important or time-sensitive data, such as voice or video,
receives preferential treatment over less critical traffic, like email or file
downloads.
▶ Error: CRYPTO-4-IKMP_BAD_MESSAGE: IKE message from x.x.x.x
failed its sanity check or is malformed.
What is the most likely cause of this error?
A) Network latency causing packet loss
B) Incorrect NAT configuration
C) Mismatched Pre-Shared Keys (PSKs) on the peer routers
D) Unsupported encryption algorithm. Answer: Correct Answer: C)
Mismatched Pre-Shared Keys (PSKs) on the peer routers
▶ Error: CRYPTO-6-IKMP_NO_SA: IKE message from x.x.x.x has no SA
and is not an initialization offer.
What is the most likely cause of this error?
A) The VPN policy parameters are mismatched between the peers
B) The PSKs are mismatched on the peer routers
C) The certificate is not trusted
D) The peer device is unreachable. Answer: Correct Answer: A) The VPN
policy parameters are mismatched between the peers
▶ Error: CRYPTO-4-IKMP_INVALID_PAYLOAD_TYPE: Invalid payload
type 20 received from x.x.x.x.
What is the most likely cause of this error?
A) Mismatch in IKE policy configurations
B) Expired certificates
C) Incorrect NAT-T configuration
D) Network congestion. Answer: Correct Answer: A) Mismatch in IKE
policy configurations
▶ Error: CRYPTO-6-IKMP_SA_NOTFOUND: IKE message from x.x.x.x
failed its sanity check or is malformed.
What is the most likely cause of this error?