Cisco 300-730 Practice Test - Questions Answers
List of questions
Related questions
A second set of traffic selectors is negotiated between two peers using IKEv2. Which IKEv2 packet will contain details of the exchange?
IKEv2 IKE_SA_INIT
IKEv2 INFORMATIONAL
IKEv2 CREATE_CHILD_SA
IKEv2 IKE_AUTH
Refer to the exhibit.
The DMVPN tunnel is dropping randomly and no tunnel protection is configured. Which spoke configuration mitigates tunnel drops?
Option A
Option B
Option C
Option D
On a FlexVPN hub-and-spoke topology where spoke-to-spoke tunnels are not allowed, which command is needed for the hub to be able to terminate FlexVPN tunnels?
interface virtual-access
ip nhrp redirect
interface tunnel
interface virtual-template
Which statement about GETVPN is true?
The configuration that defines which traffic to encrypt originates from the key server.
TEK rekeys can be load-balanced between two key servers operating in COOP.
The pseudotime that is used for replay checking is synchronized via NTP.
Group members must acknowledge all KEK and TEK rekeys, regardless of configuration.
Refer to the exhibit.
Which two tunnel types produce the show crypto ipsec sa output seen in the exhibit? (Choose two.)
crypto map
DMVPN
GRE
FlexVPN
VTI
Which two changes must be made in order to migrate from DMVPN Phase 2 to Phase 3 when EIGRP is configured? (Choose two.)
Add NHRP shortcuts on the hub.
Add NHRP redirects on the spoke.
Disable EIGRP next-hop-self on the hub.
Enable EIGRP next-hop-self on the hub.
Add NHRP redirects on the hub.
Refer to the exhibit.
A customer cannot establish an IKEv2 site-to-site VPN tunnel between two Cisco ASA devices. Based on the syslog message, which action brings up the VPN tunnel?
Reduce the maximum SA limit on the local Cisco ASA.
Increase the maximum in-negotiation SA limit on the local Cisco ASA.
Remove the maximum SA limit on the remote Cisco ASA.
Correct the crypto access list on both Cisco ASA devices.
Which two parameters help to map a VPN session to a tunnel group without using the tunnel-group list? (Choose two.)
group-alias
certificate map
optimal gateway selection
group-url
AnyConnect client version
Which method dynamically installs the network routes for remote tunnel endpoints?
policy-based routing
CEF
reverse route injection
route filtering
Which command identifies a Cisco AnyConnect profile that was uploaded to the flash of an IOS router?
svc import profile SSL_profile flash:simos-profile.xml
anyconnect profile SSL_profile flash:simos-profile.xml
crypto vpn anyconnect profile SSL_profile flash:simos-profile.xml
webvpn import profile SSL_profile flash:simos-profile.xml
Question