Cisco 300-730 Practice Test - Questions Answers, Page 14
List of questions
Related questions
Refer to the exhibit.
The network administrator must allow the Cisco AnyConnect Secure Mobility Client to securely access the corporate resources via IKEv2 and print locally. Traffic that is destined for the Internet must still be tunneled to the Cisco AS
Which configuration does the administrator use to accomplish this goal?
Split exclude policy with a deny for 192.168.0.3/32.
Split exclude policy with a permit for 0.0.0.0/32.
Tunnel all policy.
Split include policy with a permit for 192.168.0.0/24.
An organization wants to distribute remote access VPN load across 12 VPN headend locations supporting 25,000 simultaneous users. Which load balancing method meets this requirement?
one VPN profile per site
DNS-based load balancing
AnyConnect native load balancing
equal cost, multipath load balancing
What are two advantages of using GETVPN to traverse over the network between corporate offices?
(Choose two.)
It has unique session keys for improved security.
It supports multicast.
It has QoS support.
It is a highly scalable any to any mesh topology.
It supports a hub-and-spoke topology.
Why must a network engineer avoid usage of the default X.509 certificate when implementing clientless SSLVPN on an ASA?
The certificate must be managed by the local CA.
The certificate is regenerated at each reboot.
The default X.509 certificate is not supported for SSLVPN.
The certificate is too weak to provide adequate security.
An engineer has configured Cisco AnyConnect VPN using IKEv2 on a Cisco IOS router. The user cannot connect in the Cisco AnyConnect client, but receives an alert message "Use a browser to gain access." Which action does the engineer take to resolve this issue?
Reset user login credentials.
Correct the URL address.
Connect using HTTPS.
Disable the HTTP server.
A router is being configured for IKEv2 AnyConnect using AnyConnect-EAP. How would the administrator separate profiles for administrators and employees so that authorization differs when they connect?
Define group aliases on the headend and have the user pick the appropriate alias when they connect
Define group-urls on the headend and create two XML profiles to match the administrator and user group urls
Create a certificate map and match on the appropriate certificate fields
Upgrade the Cisco AnyConnect Start Before Logon module to be compatible with the Cisco ASA software image.
Which parameter in IPsec VPN tunnel configurations is optional?
hash
lifetime
encryption
Perfect Forward Secrecy
A company is setting up a dynamic crypto map on the Cisco ASA at the headquarters to accept connections from the branch offices. There will be no IP subnet overlap between the branch offices, but the engineer does not know which encryption domains will be requested by the branch offices.
Additionally, the company security policy states that routing protocol traffic should not leave the HQ network. Which solution should be used to route traffic back to the branches from the Cisco ASA with minimal administrative effort?
Configure Reverse Route Injection on the dynamic crypto map.
Configure a default route with the tunneled keyword on all branch routers.
Configure static routes for remote subnets.
Configure snapshot routing with EIGRP to send out of band routing updates.
A network engineer is implementing a FlexVPN tunnel between two Cisco IOS routers. The FlexVPN tunnels will terminate on encrypted traffic on an interface configured with an IP MTU of 1500, and the company has a security policy to drop fragmented traffic coming into or leaving the network. The tunnel will be used to transfer TFTP data between users and internal servers. When the TFTP traffic is not traversing a VPN, it can have a maximum IP packet size of 1500.
Assuming the encrypted payload will add 90 bytes, which configuration allows TFTP traffic to traverse the FlexVPN tunnel without being dropped?
Set the tunnel IP MTU to 1500.
Set the tunnel tcp adjust-mss to 1460.
Set the tunnel IP MTU to 1400.
Set the tunnel tcp adjust-mss to 1360.
Which VPN technology minimizes the impact on VPN performance when encrypting multicast traffic on a Private WAN?
DMVPN
IPsec VPN
FlexVPN
GETVPN
Question