An administrator is designing a VPN with a partner's non-Cisco VPN solution. The partner's VPN device will negotiate an IKEv2 tunnel that will only encrypt subnets 192.168.0.0/24 going to 10.0.0.0/24. Which technology must be used to meet these requirements?
AVTI
Bcrypto map
CGETVPN
DDMVPN
An administrator is setting up AnyConnect for the first time for a few users. Currently, the router does not have access to a RADIUS server. Which AnyConnect protocol must be used to allow users to authenticate?
AEAP-GTC
BEAP-MSCHAPv2
CEAP-MD5
DEAP-AnyConnect
A network engineer has been tasked with configuring SSL VPN to provide remote users with access to the corporate network. Traffic destined to the enterprise IP range should go through the tunnel, and all other traffic should go directly to the Internet. Which feature should be configured to achieve this?
AU-turning
Bhairpinning
Csplit-tunnel
Ddual-homing
DRAG DROP -
Drag and drop the correct commands from the right onto the blanks within the code on the left to implement a design that allow for dynamic spoke-to-spoke communication. Not all commands are used.
Select and Place:
Question 6
Site-to-site Virtual Private Networks on Routers and Firewalls
0
Question 7
Site-to-site Virtual Private Networks on Routers and Firewalls
Question 8
Secure Communications Architectures
Question 9
Remote access VPNs
Question 10
Remote access VPNs
Question 11
Site-to-site Virtual Private Networks on Routers and Firewalls
Question 12
Remote access VPNs
Question 13
Remote access VPNs
Question 14
Secure Communications Architectures
Question 15
Remote access VPNs
Question 16
Site-to-site Virtual Private Networks on Routers and Firewalls
Question 17
Site-to-site Virtual Private Networks on Routers and Firewalls
Question 18
Site-to-site Virtual Private Networks on Routers and Firewalls
Question 19
Remote access VPNs
Question 20
Site-to-site Virtual Private Networks on Routers and Firewalls
Question 21
Secure Communications Architectures
Question 22
Site-to-site Virtual Private Networks on Routers and Firewalls
Question 23
Troubleshooting using ASDM and CLI
Question 24
Remote access VPNs
Question 25
Site-to-site Virtual Private Networks on Routers and Firewalls
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ad
Want a break from the ads?
Become a Supporter and enjoy a completely ad-free experience, plus unlock Learn Mode, Exam Mode, AstroTutor AI, and more.
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Which VPN does VPN load balancing on the ASA support?
AVTI
BIPsec site-to-site tunnels
CL2TP over IPsec
DCisco AnyConnect
A Cisco IOS router is reconfigured to connect to an additional DMVPN hub that is a part of a different DMVPN phase 3 cloud. After this change was made, users begin to experience problems accessing corporate resources over both tunnels. Before the additional tunnel was created, users could access resources over the first tunnel without any issues. Both tunnels terminate on the same interface of the router and use the same IPsec proposals. Which two actions resolve the issue without affecting spoke-to-spoke traffic in either DMVPN cloud? (Choose two.)
AEnable dead peer detection for both tunnels.
BUse the same shared IPsec profile for both tunnels.
CConfigure the same NHRP network IDs for both tunnels.
DSpecify the tunnel destination in each tunnel.
EAssign a unique tunnel key to each tunnel.
Which Diffie Hellman group should be used when ECDH is required in a VPN configuration?
A24
B19
C16
D15
Refer to the exhibit. Based on this ASDM output, which remote access technologies are allowed on the ASA?
ASSLAnyConnect VPN
BIKEv2 and SSL AnyConnect VPN
CSSL clientless VPN
DIKEv2 AnyConnect VPN
On an ASA with multiple connection profiles for different departments, what is the best design to ensure that AnyConnect users are assigned the correct connection profile based on their department and do not have the ability to choose a different connection profile?
Agroup URL
Bgroup alias
Cdynamic access policy
Dcertificate mapping
A user at a company HQ is having trouble accessing a network share at a branch site that is connected with a L2L IPsec VPN. While troubleshooting, a network security engineer runs a packet tracer on the Cisco ASA to simulate the user traffic and discovers that the encryption counter is increasing but the decryption counter is not. What must be configured to correct this issue?
AAdjust the routing on the remote peer device to direct traffic back over the tunnel.
BAdjust the preshared key on the remote peer to allow traffic to flow over the tunnel.
CAdjust the transform set to allow bidirectional traffic.
DAdjust the peer IP address on the remote peer to direct traffic back to the ASA.
A user is experiencing delays on audio calls over a Cisco AnyConnect VPN. Which implementation step resolves this issue?
AChange to 3DES Encryption.
BShorten the encryption key lifetime.
CInstall the Cisco AnyConnect 2.3 client for the user to download.
DEnable DTLS.
Refer to the exhibit.
Users cannot connect via AnyConnect SSLVPN. Which action resolves this issue?
AConfigure the ASA to act as a DHCP server.
BConfigure the HTTP server to listen on port 443.
CAdd an IPsec preshared key to the group policy.
DAdd ssl-client to the allowed list of VPN protocols.
Which two components are required in a Cisco IOS GETVPN key server configuration? (Choose two.)
ARSA key
BIKE policy
CSSL cipher
DGRE tunnel
EL2TP protocol
A network administrator deployed IKEv2 Cisco AnyConnect on a Cisco ASA. The current configuration tunnels all traffic through the VPN. Users report poor performance with cloud-based applications, but no issues have been reported about connections to on-premises servers. Packet analysis on Cisco Webex traffic shows very few duplicate ACKs, high RTT, and no IP fragments. Which action improves Webex performance for VPN users?
AConfigure QoS on the outside interface of the ASA.
BConfigure Cisco AnyConnect to use DTLS.
CConfigure a dynamic split tunnel exclusion.
DReduce the Cisco AnyConnect tunnel MTU.
Refer to the exhibit. Which type of VPN is used in the configuration?
AGETVPN
BFlexVPN
CDMVPN
DIPSec
What are two advantages of using GETVPN to traverse over the network between corporate offices? (Choose two.)
AIt has unique session keys for improved security.
BIt supports multicast.
CIt has QoS support.
DIt is a highly scalable any to any mesh topology.
EIt supports a hub-and-spoke topology.
A company is setting up a dynamic crypto map on the Cisco ASA at the headquarters to accept connections from the branch offices. There will be no IP subnet overlap between the branch offices, but the engineer does not know which encryption domains will be requested by the branch offices. Additionally, the company security policy states that routing protocol traffic should not leave the HQ network. Which solution should be used to route traffic back to the branches from the Cisco ASA with minimal administrative effort?
AConfigure Reverse Route Injection on the dynamic crypto map.
BConfigure a default route with the tunneled keyword on all branch routers.
CConfigure static routes for remote subnets.
DConfigure snapshot routing with EIGRP to send out of band routing updates.
A network engineer must design a remote access solution to allow contractors to access internal servers. These contractors do not have permissions to install applications on their computers. Which VPN solution should be used in this design?
AIKEv2 AnyConnect
BClientless
CPort forwarding
DSSL AnyConnect
Refer to the exhibit. Which type of VPN is being configured, based on the partial configuration snippet?
AGET VPN with COOP key server
BGET VPN with dual group member
CFlexVPN load balancer
DFlexVPN backup gateway
A company's remote locations connect to the data centers via MPLS. A new request requires that unicast and multicast traffic that exits in the remote locations be encrypted. Which non-tunneled technology should be used to satisfy this requirement?
ASSL
BFlexVPN
CDMVPN
DGETVPN
An engineer is troubleshooting a new DMVPN setup on a Cisco IOS router. After the show crypto isakmp sa command is issued, a response is returned of
"MM_NO_STATE." Why does this failure occur?
AThe ISAKMP policy priority values are invalid.
BESP traffic is being dropped.
CThe Phase 1 policy does not match on both devices.
DTunnel protection is not applied to the DMVPN tunnel.
Refer to the exhibit. Which two tunnel types produce the show crypto ipsec sa output seen in the exhibit? (Choose two.)
Acrypto map
BDMVPN
CGRE
DFlexVPN
EVTI
Which two types of web resources or protocols are enabled by default on the Cisco ASA Clientless SSL VPN portal? (Choose two.)
AHTTP
BICA (Citrix)
CVNC
DRDP
ECIFS
Refer to the exhibit. What is configured as a result of this command set?
AFlexVPN client profile for IPv6
BFlexVPN server to authorize groups by using an IPv6 external AAA
CFlexVPN server for an IPv6 dVTI session
DFlexVPN server to authenticate IPv6 peers by using EAP