300-730 SVPN: Implementing Secure Solutions with Virtual Private NetworksDemo
By Cisco · Browse Mode
//
300-730 SVPN: Implementing Secure Solutions with V… Practice Exam
QuestionQ1
Site-to-site Virtual Private Networks on Routers and Firewalls
Save question
An engineer is troubleshooting a new DMVPN configuration on a Cisco IOS router. After issuing the show crypto isakmp sa command, the returned response is MM_NO_STATE. Why does this failure occur?
AThe ISAKMP policy priority values are invalid.
BESP traffic is being dropped.
CThe Phase 1 policy does not match on both devices.
DTunnel protection is not applied to the DMVPN tunnel.
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ2
Remote access VPNs
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ3
Remote access VPNs
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ4
Troubleshooting using ASDM and CLI
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ5
Site-to-site Virtual Private Networks on Routers and Firewalls
0
Community Discussion
No comments yet. Be the first to start the discussion!
It's free
100% of the questions are free for all users. No strings attached.
Which two web-resource types or protocols are enabled by default on the Cisco ASA Clientless SSL VPN portal?
Choose two
AHTTP
BICA (Citrix)
CVNC
DRDP
ECIFS
A Cisco AnyConnect client creates an SSL VPN connection to an ASA at the corporate office. An engineer must make sure that the client computer complies with the enterprise security policy. Which feature can update the client so it meets an enterprise security policy?
AEndpoint Assessment
BCisco Secure Desktop
CBasic Host Scan
DAdvanced Endpoint Assessment
Refer to the exhibit. Which two tunnel types generate the displayed show crypto ipsec sa output?
Choose two
Acrypto map
BDMVPN
CGRE
DFlexVPN
EVTI
Refer to the exhibit. What does this command set configure?
AFlexVPN client profile for IPv6
BFlexVPN server to authorize groups by using an IPv6 external AAA
CFlexVPN server for an IPv6 dVTI session
DFlexVPN server to authenticate IPv6 peers by using EAP
QuestionQ6
Remote access VPNs
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ7
Site-to-site Virtual Private Networks on Routers and Firewalls
QuestionQ8
Remote access VPNs
QuestionQ9
Troubleshooting using ASDM and CLI
QuestionQ10
Remote access VPNs
QuestionQ11
Site-to-site Virtual Private Networks on Routers and Firewalls
QuestionQ12
Remote access VPNs
QuestionQ13
Troubleshooting using ASDM and CLI
QuestionQ16
Troubleshooting using ASDM and CLI
QuestionQ17
Remote access VPNs
QuestionQ18
Remote access VPNs
QuestionQ19
Site-to-site Virtual Private Networks on Routers and Firewalls
QuestionQ20
Site-to-site Virtual Private Networks on Routers and Firewalls
QuestionQ21
Remote access VPNs
QuestionQ22
Remote access VPNs
QuestionQ23
Site-to-site Virtual Private Networks on Routers and Firewalls
QuestionQ24
Remote access VPNs
QuestionQ25
Site-to-site Virtual Private Networks on Routers and Firewalls
QuestionQ27
Remote access VPNs
QuestionQ28
Remote access VPNs
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Ad
Want a break from the ads?
Go ad-free and unlock Learn Mode, Exam Mode, AstroTutor AI and every premium tool — everything you need to walk in prepared, and confident.
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
In which section must a bookmark or URL list be configured on a Cisco ASA so that it is available to clientless SSLVPN users?
Atunnel-group (general-attributes)
Btunnel-group (webvpn-attributes)
Cwebvpn (group-policy)
Dwebvpn (global configuration)
Which technology is used for sending multicast traffic across a site-to-site VPN?
AGRE over IPsec on IOS router
BGRE over IPsec on FTD
CIPsec tunnel on FTD
DGRE tunnel on ASA
Refer to the exhibit. Which VPN technology is permitted for users who connect to the Employee tunnel group?
ASSL AnyConnect
BIKEv2 AnyConnect
Ccrypto map
Dclientless
Refer to the exhibit. Based on the debug output, what type of mismatch is preventing the VPN from establishing?
Ainteresting traffic
Blifetime
Cpreshared key
DPFS
Refer to the exhibit. Based on it, why can users not access the CCNP Webserver bookmark?
AThe URL is being blocked by a WebACL.
BThe ASA cannot resolve the URL.
CThe bookmark has been disabled.
DThe user cannot access the URL.
Refer to the exhibit. The DMVPN spoke fails to establish a session with the hub. Which two actions resolve this problem?
Choose two
AChange the spoke nhs to 172.16.18.1 and the nbma to 10.0.0.1.
BChange the transform set to mode tunnel.
CChange the ISAKMP policy authentication on the spoke to pre-shared.
DChange the ISAKMP key address on the spoke to 0.0.0.0.
EChange the nhrp authentication key on the spoke to cisco123.
Refer to the exhibit. A network engineer is configuring a remote-access SSL VPN and cannot complete the connection with local credentials. What must be done to correct this issue?
AEnable the client protocol in the Cisco AnyConnect profile.
BConfigure a AAA server group to authenticate the client.
CChange the authentication method to local.
DConfigure the group policy to force local authentication.
Refer to the exhibit. After a tunnel is configured between two sites, users report that connections to applications across the VPN do not work consistently.
The output from show crypto ipsec sa was captured on one of the VPN devices. Based on this output, what should be done to resolve the issue?
ALower the tunnel MTU.
BEnable perfect forward secrecy.
CSpecify the application networks in the remote identity.
DMake an adjustment to IPSec replay window.
Which two commands help identify why the NHRP registration process is still incomplete even though the IPsec tunnel is up?
Choose two
Ashow crypto isakmp sa
Bshow ip traffic
Cshow crypto ipsec sa
Dshow ip nhrp traffic
Eshow dmvpn detail
An engineer is configuring a clientless SSL VPN. The finance department has a database server that only it should be able to access, but the sales department can currently reach it. Finance and sales are configured as separate group policies. What must be added to ensure that sales department users cannot access the finance department server?
Atunnel group lock
Bsmart tunnel
Cport forwarding
Dwebtype ACL
Refer to the exhibit. Which two commands in tunnel-group webvpn-attributes cause a Cisco AnyConnect user to receive the AnyConnect prompt shown?
Choose two
Agroup-url https://172.16.31.10/General enable
Bgroup-policy General internal
Cauthentication aaa
Dauthentication certificate
Egroup-alias General enable
Refer to the exhibit. DMVPN spoke-to-spoke traffic works, but it traverses the hub and never sends traffic directly between spokes. Based on the tunnel interface configuration shown, what must be configured on the hub to resolve the issue?
AEnable NHRP redirect.
BEnable split horizon.
CEnable IP redirects.
DEnable NHRP shortcut.
In a FlexVPN hub-and-spoke topology in which spoke-to-spoke tunnels are not permitted, which command is required so that the hub can terminate FlexVPN tunnels?
Ainterface virtual-access
Bip nhrp redirect
Cinterface tunnel
Dinterface virtual-template
Where is split tunneling configured for IKEv2 remote-access clients on a Cisco router?
AIKEv2 authorization policy
BGroup Policy
Cvirtual template
Dwebvpn context
An engineer needs to configure remote desktop access for offsite administrators to Windows Vista workstations through clientless SSL VPN on a Cisco ASA.
Which two configurations deliver the required access?
Choose two
ATelnet bookmark via the Telnet plugin
BRDP2 bookmark via the RDP2 plugin
CVNC bookmark via the VNC plugin
DCitrix bookmark via the ICA plugin
ESSH bookmark via the SSH plugin
A second set of traffic selectors is negotiated between two peers by using IKEv2. Which IKEv2 packet contains the exchange details?
AIKEv2 IKE_SA_INIT
BIKEv2 INFORMATIONAL
CIKEv2 CREATE_CHILD_SA
DIKEv2 IKE_AUTH
Refer to the exhibit. Which value must be configured in the User Group field when creating a Cisco AnyConnect Profile that connects to an ASA headend with IPsec as the primary protocol?
Aaddress-pool
Bgroup-alias
Cgroup-policy
Dtunnel-group
Refer to the exhibit. An IKEv2 site-to-site tunnel between an ASA and a remote peer is failing to establish. Based on the debug output, what will resolve the issue?
AEnsure crypto IPsec policy matches on both VPN devices.
BInstall the correct certificate to validate the peer.
CCorrect crypto access list on both VPN devices.
DSpecify the peer IP address in the tunnel group name.
A network engineer must create a clientless VPN solution for a company. VPN users must be able to access several internal web servers. Testing reachability to those web servers found that the ASA is not rewriting one website correctly. What is a potential solution to this issue while retaining a clientless VPN setup?
ASet up a smart tunnel with the IP address of the web server.
BSet up a NAT rule that translates the ASA public address to the web server private address on port 80.
CSet up Cisco AnyConnect with a split tunnel that has the IP address of the web server.
DSet up a WebACL to permit the IP address of the web server.
Refer to the exhibit. All internal clients behind the ASA are port-address translated to the public outside interface with IP address 3.3.3.3. Client 1 and Client 2 have successfully established SSL VPN connections to the ASA. What must be implemented so that an IP-address browser search returns 3.3.3.3?
ASame-security-traffic permit inter-interface under Group Policy
Community Discussion