Cisco 300-730 Practice Test - Questions Answers, Page 11
List of questions
Related questions
A DMVPN spoke router tunnel is up and passing traffic, but it cannot establish an EIGRP neighbor relationship with the hub router. Which solution resolves this issue?
Enable EIGRP Split Horizon on the hub tunnel interface.
Remove the EIGRP stub configuration on the spoke tunnel interface.
Enable the EIGRP next hop self feature on the hub tunnel interface.
Configure the dynamic NHRP multicast map on the hub tunnel interface.
Refer to the exhibit.
An IPsec Cisco AnyConnect client is failing to connect and generates these debugs every time a connection to an IOS headend is attempted. Which action resolves this issue?
Correct the DH group setting.
Correct the PFS setting.
Correct the integrity setting.
Correct the encryption setting.
Refer to the exhibit.
An engineer must allow Cisco AnyConnect users to access the outside interface using protocol UDP 500/4500. In addition, these clients must be able to establish an SSL connection to update Cisco AnyConnect software over the same connection. Which two actions must be taken to achieve this goal? (Choose two.)
IPsec (IKEv2) Allow Access must be checked on the outside interface.
SSL Enable DTLS must be checked on the outside interface.
Bypass interface access lists for inbound VPN sessions must be unchecked.
IPsec (IKEv2) Enable Client Services must be checked on the outside interface.
SSL Allow Access must be checked on the outside interface.
Refer to the exhibit.
Based on the configuration output, what is the VPN technology?
site-to-site
DMVPN
L2VPN
multicast VPN
A user at a company HQ is having trouble accessing a network share at a branch site that is connected with a L2L IPsec VPN. While troubleshooting, a network security engineer runs a packet tracer on the Cisco ASA to simulate the user traffic and discovers that the encryption counter is increasing but the decryption counter is not. What must be configured to correct this issue?
Adjust the routing on the remote peer device to direct traffic back over the tunnel.
Adjust the preshared key on the remote peer to allow traffic to flow over the tunnel.
Adjust the transform set to allow bidirectional traffic.
Adjust the peer IP address on the remote peer to direct traffic back to the ASA.
A user is experiencing delays on audio calls over a Cisco AnyConnect VPN. Which implementation step resolves this issue?
Change to 3DES Encryption.
Shorten the encryption key lifetime.
Install the Cisco AnyConnect 2.3 client for the user to download.
Enable DTLS.
Users cannot log in to a Cisco ASA using clientless SSLVPN. Troubleshooting reveals the error message "WebVPN session terminated: Client type not supported". Which step does the administrator take to resolve this issue?
Enable the Cisco AnyConnect premium license on the Cisco ASA.
Have the user upgrade to a supported browser.
Increase the simultaneous logins on the group policy.
Enable the clientless VPN protocol on the group policy.
An administrator is setting up a VPN on an ASA for users who need to access an internal RDP server.
Due to security restrictions, the Microsoft RDP client is blocked from running on client workstations via Group Policy. Which VPN feature should be implemented by the administrator to allow these users to have access to the RDP server?
clientless proxy
smart tunneling
clientless plug-in
clientless rewriter
An administrator is planning a VPN configuration that will encrypt traffic between multiple servers that will be passing unicast and multicast traffic. This configuration must be able to be implemented without the need to modify routing within the network. Which VPN technology must be used for this task?
FlexVPN
VTI
GETVPN
DMVPN
Refer to the exhibit.
VPN tunnels between a spoke and two DMVPN hubs are not coming up. The network administrator has verified that the encryption, hashing, and DH group proposals for Phase 1 and Phase 2 match on both ends. What is the solution to this issue?
Ensure bidirectional UDP 500/4500 traffic.
Increase the isakmp phase 1 lifetime.
Add NAT statements for VPN traffic.
Enable shared tunnel protection.
Question