Labour Day Sale Limited Time 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 713PS592

300-730 Implementing Secure Solutions with Virtual Private Networks (SVPN) Questions and Answers

Questions 4

Which two changes must be made in order to migrate from DMVPN Phase 2 to Phase 3 when EIGRP is configured? (Choose two.)

Options:

A.

Add NHRP shortcuts on the hub.

B.

Add NHRP redirects on the spoke.

C.

Disable EIGRP next-hop-self on the hub.

D.

Enable EIGRP next-hop-self on the hub.

E.

Add NHRP redirects on the hub.

Buy Now
Questions 5

A network engineer must design a remote access solution to allow contractors to access internal servers. These contractors do not have permissions to install applications on their computers. Which VPN solution should be used in this design?

Options:

A.

IKEv2 AnyConnect

B.

Clientless

C.

Port forwarding

D.

SSL AnyConnect

Buy Now
Questions 6

Which remote access VPN technology requires the use of the IPsec-proposal configuration option?

Options:

A.

clientless SSLVPN

B.

SSLVPN Full Tunnel

C.

IKEv2-based VPN

D.

IKEv1-based VPN

Buy Now
Questions 7

Refer to the exhibit.

300-730 Question 7

An IPsec Cisco AnyConnect client is failing to connect and generates these debugs every time a connection to an IOS headend is attempted. Which action resolves this issue?

Options:

A.

Correct the DH group setting.

B.

Correct the PFS setting.

C.

Correct the integrity setting.

D.

Correct the encryption setting.

Buy Now
Questions 8

What are two advantages of using GETVPN to traverse over the network between corporate offices? (Choose two.)

Options:

A.

It has unique session keys for improved security.

B.

It supports multicast.

C.

It has QoS support.

D.

It is a highly scalable any to any mesh topology.

E.

It supports a hub-and-spoke topology.

Buy Now
Questions 9

On a FlexVPN hub-and-spoke topology where spoke-to-spoke tunnels are not allowed, which command is needed for the hub to be able to terminate FlexVPN tunnels?

Options:

A.

interface virtual-access

B.

ip nhrp redirect

C.

interface tunnel

D.

interface virtual-template

Buy Now
Questions 10

Which two parameters help to map a VPN session to a tunnel group without using the tunnel-group list? (Choose two.)

Options:

A.

group-alias

B.

certificate map

C.

optimal gateway selection

D.

group-url

E.

AnyConnect client version

Buy Now
Questions 11

Refer to the exhibit.

300-730 Question 11

Cisco AnyConnect must be set up on a router to allow users to access internal servers 192.168.0.10 and 192.168.0.11. All other traffic should go out of the client's local NIC. Which command accomplishes this configuration?

Options:

A.

svc split include 192.168.0.0 255.255.255.0

B.

svc split exclude 192.168.0.0 255.255.255.0

C.

svc split include acl CCNP

D.

svc split exclude acl CCNP

Buy Now
Questions 12

Which VPN solution uses TBAR?

Options:

A.

GETVPN

B.

VTI

C.

DMVPN

D.

Cisco AnyConnect

Buy Now
Questions 13

Which technology is used to send multicast traffic over a site-to-site VPN?

Options:

A.

GRE over IPsec on IOS router

B.

GRE over IPsec on FTD

C.

IPsec tunnel on FTD

D.

GRE tunnel on ASA

Buy Now
Questions 14

Which two commands help determine why the NHRP registration process is not being completed even after the IPsec tunnel is up? (Choose two.)

Options:

A.

show crypto isakmp sa

B.

show ip traffic

C.

show crypto ipsec sa

D.

show ip nhrp traffic

E.

show dmvpn detail

Buy Now
Questions 15

Which VPN does VPN load balancing on the ASA support?

Options:

A.

VTI

B.

IPsec site-to-site tunnels

C.

L2TP over IPsec

D.

Cisco AnyConnect

Buy Now
Questions 16

Which two features provide headend resiliency for Cisco AnyConnect clients? (Choose two.)

Options:

A.

AnyConnect Auto Reconnect

B.

AnyConnect Network Access Manager

C.

AnyConnect Backup Servers

D.

ASA failover

E.

AnyConnect Always On

Buy Now
Questions 17

What uses an Elliptic Curve key exchange algorithm?

Options:

A.

ECDSA

B.

ECDHE

C.

AES-GCM

D.

SHA

Buy Now
Questions 18

Cisco AnyConnect clients need to transfer large files over the VPN sessions. Which protocol provides the best throughput?

Options:

A.

SSL/TLS

B.

L2TP

C.

DTLS

D.

IPsec IKEv1

Buy Now
Questions 19

Which two statements about the Cisco ASA Clientless SSL VPN solution are true? (Choose two.)

Options:

A.

When a client connects to the Cisco ASA WebVPN portal and tries to access HTTP resources through the URL bar, the client uses the local DNS to perform FQDN resolution.

B.

The rewriter enable command under the global webvpn configuration enables the rewriter functionality because that feature is disabled by default.

C.

A Cisco ASA can simultaneously allow Clientless SSL VPN sessions and AnyConnect client sessions.

D.

When a client connects to the Cisco ASA WebVPN portal and tries to access HTTP resources through the URL bar, the ASA uses its configured DNS servers to perform FQDN resolution.

E.

Clientless SSLVPN provides Layer 3 connectivity into the secured network.

Buy Now
Questions 20

Refer to the exhibit.

300-730 Question 20

The customer must launch Cisco AnyConnect in the RDP machine. Which IOS configuration accomplishes this task?

300-730 Question 20

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 21

Cisco AnyConnect Secure Mobility Client has been configured to use IKEv2 for one group of users and SSL for another group. When the administrator configures a new AnyConnect release on the Cisco ASA, the IKEv2 users cannot download it automatically when they connect. What might be the problem?

Options:

A.

The XML profile is not configured correctly for the affected users.

B.

The new client image does not use the same major release as the current one.

C.

Client services are not enabled.

D.

Client software updates are not supported with IKEv2.

Buy Now
Questions 22

Where is split tunneling defined for IKEv2 remote access clients on a Cisco router?

Options:

A.

IKEv2 authorization policy

B.

Group Policy

C.

virtual template

D.

webvpn context

Buy Now
Questions 23

Which two remote access VPN solutions support SSL? (Choose two.)

Options:

A.

FlexVPN

B.

clientless

C.

EZVPN

D.

L2TP

E.

Cisco AnyConnect

Buy Now
Questions 24

Which technology works with IPsec stateful failover?

Options:

A.

GLBR

B.

HSRP

C.

GRE

D.

VRRP

Buy Now
Questions 25

Under which section must a bookmark or URL list be configured on a Cisco ASA to be available for clientless SSLVPN users?

Options:

A.

tunnel-group (general-attributes)

B.

tunnel-group (webvpn-attributes)

C.

webvpn (group-policy)

D.

webvpn (global configuration)

Buy Now
Questions 26

Refer to the exhibit.

300-730 Question 26

Which two commands under the tunnel-group webvpn-attributes result in a Cisco AnyConnect user receiving the AnyConnect prompt in the exhibit? (Choose two.)

Options:

A.

group-url https://172.16.31.10/General enable

B.

group-policy General internal

C.

authentication aaa

D.

authentication certificate

E.

group-alias General enable

Buy Now
Questions 27

Refer to the exhibit.

300-730 Question 27

Which value must be configured in the User Group field when the Cisco AnyConnect Profile is created to connect to an ASA headend with IPsec as the primary protocol?

Options:

A.

address-pool

B.

group-alias

C.

group-policy

D.

tunnel-group

Buy Now
Questions 28

Which statement about GETVPN is true?

Options:

A.

The configuration that defines which traffic to encrypt originates from the key server.

B.

TEK rekeys can be load-balanced between two key servers operating in COOP.

C.

The pseudotime that is used for replay checking is synchronized via NTP.

D.

Group members must acknowledge all KEK and TEK rekeys, regardless of configuration.

Buy Now
Questions 29

A second set of traffic selectors is negotiated between two peers using IKEv2. Which IKEv2 packet will contain details of the exchange?

Options:

A.

IKEv2 IKE_SA_INIT

B.

IKEv2 INFORMATIONAL

C.

IKEv2 CREATE_CHILD_SA

D.

IKEv2 IKE_AUTH

Buy Now
Questions 30

Which two protocols does DMVPN leverage to build dynamic VPNs to multiple destinations? (Choose two.)

Options:

A.

IKEv2

B.

NHRP

C.

mGRE

D.

mBGP

E.

GDOI

Buy Now
Questions 31

Which two types of web resources or protocols are enabled by default on the Cisco ASA Clientless SSL VPN portal? (Choose two.)

Options:

A.

HTTP

B.

ICA (Citrix)

C.

VNC

D.

RDP

E.

CIFS

Buy Now
Questions 32

Refer to the exhibit.

300-730 Question 32

What is configured as a result of this command set?

Options:

A.

FlexVPN client profile for IPv6

B.

FlexVPN server to authorize groups by using an IPv6 external AAA

C.

FlexVPN server for an IPv6 dVTI session

D.

FlexVPN server to authenticate IPv6 peers by using EAP

Buy Now
Questions 33

Refer to the exhibit.

300-730 Question 33

Which VPN technology is allowed for users connecting to the Employee tunnel group?

Options:

A.

SSL AnyConnect

B.

IKEv2 AnyConnect

C.

crypto map

D.

clientless

Buy Now
Questions 34

Refer to the exhibit.

300-730 Question 34

Which type of Cisco VPN is shown for group Cisc012345678?

Options:

A.

Cisco AnyConnect Client VPN

B.

DMVPN

C.

Clientless SSLVPN

D.

GETVPN

Buy Now
Questions 35

Which feature allows a DMVPN Phase 3 spoke to switch to an alternate hub when the primary hub is unreachable?

Options:

A.

multicast PIM

B.

backup NHS

C.

per-tunnel jitter probes

D.

NHRP shortcut

Buy Now
Questions 36

Refer to the exhibit.

300-730 Question 36

The IKEv2 site-to-site VPN tunnel between two routers is down. Based on the debug output, which type of mismatch is the problem?

Options:

A.

preshared key

B.

peer identity

C.

transform set

D.

ikev2 proposal

Buy Now
Questions 37

Which configuration construct must be used in a FlexVPN tunnel?

Options:

A.

EAP configuration

B.

multipoint GRE tunnel interface

C.

IKEv1 policy

D.

IKEv2 profile

Buy Now
Questions 38

Refer to the exhibit.

300-730 Question 38

Which two tunnel types produce the show crypto ipsec sa output seen in the exhibit? (Choose two.)

Options:

A.

crypto map

B.

DMVPN

C.

GRE

D.

FlexVPN

E.

VTI

Buy Now
Questions 39

Drag and drop the correct commands from the night onto the blanks within the code on the left to implement a design that allow for dynamic spoke-to-spoke communication. Not all comments are used.

300-730 Question 39

Options:

Buy Now
Questions 40

Which command must be configured on the tunnel interface of a FlexVPN spoke to receive a dynamic IP address from the hub?

Options:

A.

ip address negotiated

B.

ip unnumbered

C.

ip address dhcp

D.

ip address pool

Buy Now
Questions 41

300-730 Question 41

Which component must be configured on routers for a GETVPN deployment work properly?

Options:

A.

PE3: Key Server – Customer 2 CEs: Group Members

B.

Customer 1 CE1: Key Server – R1 and Customer 1 CE2: Group Members

C.

R1: Key Server – Customer 1 CEs: Group Members

D.

PE3: Key Server – all CEs: Group Members

Buy Now
Questions 42

A network engineer must configure the Cisco ASA so that Cisco AnyConnect clients establishing an SSL VPN connection create an additional tunnel for real-time traffic that is sensitive to packet delays. If this additional tunnel experiences any issues, it must fall back to a TLS connection. Which two Cisco AnyConnect features must be configured to accomplish this task? (Choose two.)

Options:

A.

DTLS

B.

DSCP Preservation

C.

DPD

D.

SSL Rekey

E.

OMTU

Buy Now
Questions 43

While troubleshooting, an engineer finds that the show crypto isakmp sa command indicates that the last state of the tunnel is MM_KEY_EXCH. What is the next step that should be taken to resolve this issue?

Options:

A.

Verify that the ISAKMP proposals match.

B.

Ensure that UDP 500 is not being blocked between the devices.

C.

Correct the peer's IP address on the crypto map.

D.

Confirm that the pre-shared keys match on both devices.

Buy Now
Questions 44

What are two functions of ECDH and ECDSA? (Choose two.)

Options:

A.

nonrepudiation

B.

revocation

C.

digital signature

D.

key exchange

E.

encryption

Buy Now
Exam Code: 300-730
Exam Name: Implementing Secure Solutions with Virtual Private Networks (SVPN)
Last Update: Apr 30, 2024
Questions: 175

PDF + Testing Engine

$70  $174.99

Testing Engine

$54  $134.99
buy now 300-730 testing engine

PDF (Q&A)

$48  $119.99
buy now 300-730 pdf