ExamGecko
Home Home / Cisco / 300-730

Cisco 300-730 Practice Test - Questions Answers, Page 10

Question list
Search
Search

List of questions

Search

Related questions











In order to enable FlexVPN to use a AAA attribute list, which two tasks must be performed? (Choose two.)

A.

Define the RADIUS server.

A.

Define the RADIUS server.

Answers
B.

Verify that clients are using the correct authorization policy.

B.

Verify that clients are using the correct authorization policy.

Answers
C.

Define the AAA server.

C.

Define the AAA server.

Answers
D.

Assign the list to an authorization policy.

D.

Assign the list to an authorization policy.

Answers
E.

Set the maximum segment size.

E.

Set the maximum segment size.

Answers
Suggested answer: B, D

Which technology and VPN component allows a VPN headend to dynamically learn post NAT IP addresses of remote routers at different sites?

A.

DMVPN with ISAKMP

A.

DMVPN with ISAKMP

Answers
B.

GETVPN with ISAKMP

B.

GETVPN with ISAKMP

Answers
C.

DMVPN with NHRP

C.

DMVPN with NHRP

Answers
D.

GETVPN with NHRP

D.

GETVPN with NHRP

Answers
Suggested answer: C

An engineer must configure remote desktop connectivity for offsite admins via clientless SSL VPN, configured on a Cisco ASA to Windows Vista workstations. Which two configurations provide the requested access? (Choose two.)

A.

Telnet bookmark via the Telnet plugin

A.

Telnet bookmark via the Telnet plugin

Answers
B.

RDP2 bookmark via the RDP2 plugin

B.

RDP2 bookmark via the RDP2 plugin

Answers
C.

VNC bookmark via the VNC plugin

C.

VNC bookmark via the VNC plugin

Answers
D.

Citrix bookmark via the ICA plugin

D.

Citrix bookmark via the ICA plugin

Answers
E.

SSH bookmark via the SSH plugin

E.

SSH bookmark via the SSH plugin

Answers
Suggested answer: B, C

A network engineer must design a clientless VPN solution for a company. VPN users must be able to access several internal web servers. When reachability to those web servers was tested, it was found that one website is not being rewritten correctly by the AS

A.

What is a potential solution for this issue while still allowing it to be a clientless VPN setup?

A.

What is a potential solution for this issue while still allowing it to be a clientless VPN setup?

Answers
B.

Set up a smart tunnel with the IP address of the web server.

B.

Set up a smart tunnel with the IP address of the web server.

Answers
C.

Set up a NAT rule that translates the ASA public address to the web server private address on port 80.

C.

Set up a NAT rule that translates the ASA public address to the web server private address on port 80.

Answers
D.

Set up Cisco AnyConnect with a split tunnel that has the IP address of the web server.

D.

Set up Cisco AnyConnect with a split tunnel that has the IP address of the web server.

Answers
E.

Set up a WebACL to permit the IP address of the web server.

E.

Set up a WebACL to permit the IP address of the web server.

Answers
Suggested answer: B

Which two types of SSO functionality are available on the Cisco ASA without any external SSO servers? (Choose two.)

A.

SAML

A.

SAML

Answers
B.

NTLM

B.

NTLM

Answers
C.

Kerberos

C.

Kerberos

Answers
D.

OAuth 2.0

D.

OAuth 2.0

Answers
E.

HTTP Basic

E.

HTTP Basic

Answers
Suggested answer: B, E

Explanation:

The auto-signon command is a single sign-on method for users of clientless SSL VPN sessions. It passesthe login credentials (username and password) to internal servers for authentication using NTLMauthentication, basic authentication, or both. Multiple auto-signon commands can be entered and areprocessed according to the input order (early commands take precedence) https://www.cisco.com/c/en/us/td/docs/security/asa/asa916/configuration/vpn/asa-916-vpn-config/webvpn-configure-policy-groups.html#ID-2439-00001438

Refer to the exhibit.

Which type of VPN implementation is displayed?

A.

IKEv1 cluster

A.

IKEv1 cluster

Answers
B.

IKEv2 backup gateway

B.

IKEv2 backup gateway

Answers
C.

IKEv2 load balancer

C.

IKEv2 load balancer

Answers
D.

IKEv2 reconnect

D.

IKEv2 reconnect

Answers
Suggested answer: C

A network engineer is setting up a clientless SSLVPN on a Cisco AS

A.

Remote users must be able to access an internal webserver via the URL example.com. Which two steps accomplish this task? (Choose two.)

A.

Remote users must be able to access an internal webserver via the URL example.com. Which two steps accomplish this task? (Choose two.)

Answers
B.

Configure a bookmark for the webserver.

B.

Configure a bookmark for the webserver.

Answers
C.

Configure routing so that the user's computer can reach the webserver.

C.

Configure routing so that the user's computer can reach the webserver.

Answers
D.

Configure a DNS server that can resolve the webserver URL.

D.

Configure a DNS server that can resolve the webserver URL.

Answers
E.

Configure a browser plugin on the Cisco ASA.

E.

Configure a browser plugin on the Cisco ASA.

Answers
F.

Configure routing so that the Cisco ASA can reach the webserver.

F.

Configure routing so that the Cisco ASA can reach the webserver.

Answers
Suggested answer: A, C

A network engineer has set up a FlexVPN server to terminate multiple FlexVPN clients. The VPN tunnels are established without issue. However, when a Change of Authorization is issued by the RADIUS server, the FlexVPN server does not update the authorization of connected FlexVPN clients.

Which action resolves this issue?

A.

Add the aaa server radius dynamic-author command on the FlexVPN clients.

A.

Add the aaa server radius dynamic-author command on the FlexVPN clients.

Answers
B.

Fix the RADIUS key mismatch between the RADIUS server and FlexVPN server.

B.

Fix the RADIUS key mismatch between the RADIUS server and FlexVPN server.

Answers
C.

Add the aaa server radius dynamic-author command on the FlexVPN server.

C.

Add the aaa server radius dynamic-author command on the FlexVPN server.

Answers
D.

Fix the RADIUS key mismatch between the RADIUS server and FlexVPN clients.

D.

Fix the RADIUS key mismatch between the RADIUS server and FlexVPN clients.

Answers
Suggested answer: C

A company needs to ensure only corporate issued laptops and devices are allowed to connect with the Cisco AnyConnect client. The solution should be applicable to multiple operating systems, including Windows, MacOS, and Linux, and should allow for remote remediation if a corporate issued device is stolen. Which solution should be used to accomplish these goals?

A.

Use a DAP registry check on the system to determine the relationship with the corporate domain.

A.

Use a DAP registry check on the system to determine the relationship with the corporate domain.

Answers
B.

Use a DAP file check on the system to determine the relationship with the corporate domain.

B.

Use a DAP file check on the system to determine the relationship with the corporate domain.

Answers
C.

Install and authenticate user certificates on the corporate devices.

C.

Install and authenticate user certificates on the corporate devices.

Answers
D.

Install and authenticate machine certificates on the corporate devices

D.

Install and authenticate machine certificates on the corporate devices

Answers
Suggested answer: A

Explanation:

https://www.cisco.com/c/en/us/td/docs/security/asa/asa98/asdm78/vpn/asdm-78-vpn-config/vpnasdm-dap.html#ID-2184-00000017

When a FlexVPN is configured, which two components must be configured for IKEv2? (Choose two.)

A.

method

A.

method

Answers
B.

profile

B.

profile

Answers
C.

proposal

C.

proposal

Answers
D.

preference

D.

preference

Answers
E.

persistence

E.

persistence

Answers
Suggested answer: B, C
Total 175 questions
Go to page: of 18