ExamGecko
Home Home / Cisco / 300-730

Cisco 300-730 Practice Test - Questions Answers, Page 13

Question list
Search
Search

List of questions

Search

Related questions











Which DMVPN feature allows spokes to be deployed with dynamically assigned public IP addresses?

A.

2547oDMVPN

A.

2547oDMVPN

Answers
B.

NHRP

B.

NHRP

Answers
C.

OSPF

C.

OSPF

Answers
D.

NAT Traversal

D.

NAT Traversal

Answers
Suggested answer: B

Refer to the exhibit.

An engineer is building an IKEv1 tunnel to a peer Cisco ASA, but the tunnel is failing. Based on the configuration in the exhibit, which action must be taken to allow the VPN tunnel to come up?

A.

Add a route for the 10.7.7.0/24 network to egress the outside interface.

A.

Add a route for the 10.7.7.0/24 network to egress the outside interface.

Answers
B.

Enable IKEv1 on the outside interface.

B.

Enable IKEv1 on the outside interface.

Answers
C.

Change the IKEv1 policy number to be at least 256.

C.

Change the IKEv1 policy number to be at least 256.

Answers
D.

Change the transform set mode to transport.

D.

Change the transform set mode to transport.

Answers
Suggested answer: B

An engineer has successfully established a Phase 1 and Phase 2 tunnel between two sites. Site A has internal subnet 192.168.0.0/24 and Site B has internal subnet 10.0.0.0/24. The engineer notices that no packets are decrypted at Site B.

Pings to 192.168.0.1 from internal Site B devices make it to the Site B router, and the Site A router has incrementing encrypt and decrypt counters. What must be done to ensure bidirectional communication between both sites?

A.

Modify the routing at Site B so that traffic is sent to Site A.

A.

Modify the routing at Site B so that traffic is sent to Site A.

Answers
B.

Configure the correct DH group on both devices.

B.

Configure the correct DH group on both devices.

Answers
C.

Allow protocol ESP or AH on the firewall in front of the Site B router.

C.

Allow protocol ESP or AH on the firewall in front of the Site B router.

Answers
D.

Enable PFS on the headend device.

D.

Enable PFS on the headend device.

Answers
Suggested answer: C

Refer to the exhibit.

A Cisco ASA is configured as a client to a router running as a FlexVPN server. The router is configured with a virtual template to terminate FlexVPN clients. Traffic between networks 192.168.0.0/24 and 172.16.20.0/24 does not work as expected. Based on the show crypto ikev2 sa output collected from the Cisco ASA in the exhibit, what is the solution to this issue?

A.

Modify the crypto ACL on the router to permit network 192.168.0.0/24 to network 172.16.20.0/24.

A.

Modify the crypto ACL on the router to permit network 192.168.0.0/24 to network 172.16.20.0/24.

Answers
B.

Modify the crypto ACL on the ASA to permit network 192.168.0.0/24 to network 172.16.20.0/24.

B.

Modify the crypto ACL on the ASA to permit network 192.168.0.0/24 to network 172.16.20.0/24.

Answers
C.

Modify the crypto ACL on the ASA to permit network 172.16.20.0/24 to network 192.168.0.0/24.

C.

Modify the crypto ACL on the ASA to permit network 172.16.20.0/24 to network 192.168.0.0/24.

Answers
D.

Modify the crypto ACL on the router to permit network 172.16.20.0/24 to network 192.168.0.0/24.

D.

Modify the crypto ACL on the router to permit network 172.16.20.0/24 to network 192.168.0.0/24.

Answers
Suggested answer: B

Explanation:

the show crypto ukev2 sa output from the ASA, the local selector is 192.168.0.0/24 the remote selector is 172.16.2.0/24 ( which is wrong , should be .20.0/24) . so , the ACL in the ASA should be to permit 192.168.0.0/24 to 172.16.20.0/24

A user is trying to log in to a Cisco ASA using the clientless SSLVPN feature and receives the error message "clientless (browser) SSLVPN access is not allowed". Which step should the Cisco ASA administrator take to resolve this issue?

A.

Enable the clientless VPN protocol on the group policy.

A.

Enable the clientless VPN protocol on the group policy.

Answers
B.

Validate that the correct license is in use on the ASA for WebVPN.

B.

Validate that the correct license is in use on the ASA for WebVPN.

Answers
C.

Increase the number of simultaneous logins allowed on the group policy.

C.

Increase the number of simultaneous logins allowed on the group policy.

Answers
D.

Verify that a user account exists in the local AAA database for the user.

D.

Verify that a user account exists in the local AAA database for the user.

Answers
Suggested answer: B

Explanation:

https://www.cisco.com/c/en/us/support/docs/security-vpn/webvpn-ssl-vpn/119417-config-asa-00.html#anc12

Which feature allows a DMVPN Phase 3 spoke to switch to an alternate hub when the primary hub is unreachable?

A.

multicast PIM

A.

multicast PIM

Answers
B.

backup NHS

B.

backup NHS

Answers
C.

per-tunnel jitter probes

C.

per-tunnel jitter probes

Answers
D.

NHRP shortcut

D.

NHRP shortcut

Answers
Suggested answer: B

Explanation:

The DMVPN-Tunnel Health Monitoring and Recovery (Backup NHS) feature allows you to control the number of connections to the Dynamic Multipoint Virtual Private Network (DMVPN) hub and allows you to switch to alternate hubs in case of a connection failure to the primary hubs.

https://www.cisco.com/en/US/docs/ios-xml/ios/sec_conn_dmvpn/configuration/15-2mt/sec-conndmvpn-backupnhs.html#:~:text=The%20DMVPN%2DTunnel%20Health%20Monitoring%20and%20Recovery%20(Backup%20NHS),failure%20to%20the%20primary%20hubs.

Backup NHS, or Next Hop Server, is a feature of DMVPN Phase 3 that allows a spoke router to switch to an alternate hub when the primary hub is unreachable. This is accomplished by using a secondary IP address for the hub router, which is used as the next hop for any traffic sent by the spoke router to the hub.

An engineer is using DMVPN to provide secure connectivity between a data center and remote sites.

Which two routing protocols should be used between the routers? (Choose two.)

A.

IS-IS

A.

IS-IS

Answers
B.

BGP

B.

BGP

Answers
C.

RIPv2

C.

RIPv2

Answers
D.

OSPF

D.

OSPF

Answers
E.

EIGRP

E.

EIGRP

Answers
Suggested answer: B, E

Which remote access VPN technology requires the use of the IPsec-proposal configuration option?

A.

clientless SSLVPN

A.

clientless SSLVPN

Answers
B.

SSLVPN Full Tunnel

B.

SSLVPN Full Tunnel

Answers
C.

IKEv2-based VPN

C.

IKEv2-based VPN

Answers
D.

IKEv1-based VPN

D.

IKEv1-based VPN

Answers
Suggested answer: C

Explanation:

https://www.cisco.com/c/en/us/td/docs/security/asa/asa96/configuration/vpn/asa-96-vpnconfig/vpn-remote-access.html

Over the weekend, an administrator upgraded the Cisco ASA image on the firewalls and noticed that users cannot connect to the headquarters site using Cisco AnyConnect. What is the solution for this issue?

A.

Upgrade the Cisco AnyConnect client version to be compatible with the Cisco ASA software image.

A.

Upgrade the Cisco AnyConnect client version to be compatible with the Cisco ASA software image.

Answers
B.

Upgrade the Cisco AnyConnect Network Access module to be compatible with the Cisco ASA software image.

B.

Upgrade the Cisco AnyConnect Network Access module to be compatible with the Cisco ASA software image.

Answers
C.

Upgrade the Cisco AnyConnect client driver to be compatible with the Cisco ASA software image.

C.

Upgrade the Cisco AnyConnect client driver to be compatible with the Cisco ASA software image.

Answers
D.

Upgrade the Cisco AnyConnect Start Before Logon module to be compatible with the Cisco ASA software image.

D.

Upgrade the Cisco AnyConnect Start Before Logon module to be compatible with the Cisco ASA software image.

Answers
Suggested answer: A

Explanation:

https://www.cisco.com/c/en/us/td/docs/security/asa/compatibility/asa-vpn-compatibility.html#Cisco_Reference.dita_60cec583-01b8-4cb2-a6e3-2fe87a6b0f82


Which two components are required in a Cisco IOS GETVPN key server configuration? (Choose two.)

A.

RSA key

A.

RSA key

Answers
B.

IKE policy

B.

IKE policy

Answers
C.

SSL cipher

C.

SSL cipher

Answers
D.

GRE tunnel

D.

GRE tunnel

Answers
E.

L2TP protocol

E.

L2TP protocol

Answers
Suggested answer: A, B
Total 175 questions
Go to page: of 18