ExamGecko
Home Home / Cisco / 300-730

Cisco 300-730 Practice Test - Questions Answers, Page 15

Question list
Search
Search

List of questions

Search

Related questions











What are two differences between ECC and RSA? (Choose two.)

A.

Key generation in ECC is slower and more CPU intensive than RSA.

A.

Key generation in ECC is slower and more CPU intensive than RSA.

Answers
B.

ECC can have the same security as RSA but with a shorter key size.

B.

ECC can have the same security as RSA but with a shorter key size.

Answers
C.

ECC cannot have the same security as RSA, even with an increased key size.

C.

ECC cannot have the same security as RSA, even with an increased key size.

Answers
D.

Key generation in ECC is faster and less CPU intensive than RSA.

D.

Key generation in ECC is faster and less CPU intensive than RSA.

Answers
E.

ECC lags in performance when compared with RSA.

E.

ECC lags in performance when compared with RSA.

Answers
Suggested answer: B, D

Refer to the exhibit.

Based on the output of the show run command, which remote access VPN technology is configured?

A.

PPTP

A.

PPTP

Answers
B.

SSLVPN Full Tunnel

B.

SSLVPN Full Tunnel

Answers
C.

FlexVPN

C.

FlexVPN

Answers
D.

clientless SSLVPN

D.

clientless SSLVPN

Answers
Suggested answer: C

Refer to the exhibit.

Which component must be configured on routers for a GETVPN deployment work properly?

A.

PE3: Key Server – Customer 2 CEs: Group Members

A.

PE3: Key Server – Customer 2 CEs: Group Members

Answers
B.

Customer 1 CE1: Key Server – R1 and Customer 1 CE2: Group Members

B.

Customer 1 CE1: Key Server – R1 and Customer 1 CE2: Group Members

Answers
C.

R1: Key Server – Customer 1 CEs: Group Members

C.

R1: Key Server – Customer 1 CEs: Group Members

Answers
D.

PE3: Key Server – all CEs: Group Members

D.

PE3: Key Server – all CEs: Group Members

Answers
Suggested answer: A

Refer to the exhibit.

An engineer is diagnosing an issue that occurred after a router at a branch site was assigned a new address. Based on the debugs, what must be done to resolve this issue?

A.

Add the remote peer’s IP address to the server's IKEv2 keyring.

A.

Add the remote peer’s IP address to the server's IKEv2 keyring.

Answers
B.

Ensure that the correct preshared keys are set on both sides.

B.

Ensure that the correct preshared keys are set on both sides.

Answers
C.

Ensure that the UDP 500 packets between devices are not dropped.

C.

Ensure that the UDP 500 packets between devices are not dropped.

Answers
D.

Add the remote peer’s identity to the server’s IKEv2 profile.

D.

Add the remote peer’s identity to the server’s IKEv2 profile.

Answers
Suggested answer: D

DRAG DROP

Drag and drop the correct commands from the right onto the blanks within the code on the left to implement a design that allow for dynamic spoke-to-spoke communication. Not all commands are used.


Question 145
Correct answer: Question 145

Explanation:

Reference: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_dmvpn/configuration/xe-16/sec-conn-dmvpn-xe-16-book/sec-conn-dmvpn-summ-maps.html

DRAG DROP

Drag and drop the code snippets from the right onto the blanks in the configuration to implement FlexVPN. Not all snippets are used.


Question 146
Correct answer: Question 146

Explanation:


The corporate network security policy requires that all internet and network traffic must be tunneled to the corporate office. Remote workers have been provided with printers to use locally at home while they are remotely connected to the corporate network. Which two steps must be executed to allow printing to the local printers? (Choose two.)

A.

Configure the split-tunnel-policy on the Cisco ASA to tunnelall.

A.

Configure the split-tunnel-policy on the Cisco ASA to tunnelall.

Answers
B.

Check the Allow Local LAN access checkbox in the Cisco AnyConnect client.

B.

Check the Allow Local LAN access checkbox in the Cisco AnyConnect client.

Answers
C.

Add a persistent static route in the client OS for the local LAN network.

C.

Add a persistent static route in the client OS for the local LAN network.

Answers
D.

Configure the split-tunnel-policy on the Cisco ASA to excludespecified.

D.

Configure the split-tunnel-policy on the Cisco ASA to excludespecified.

Answers
E.

Configure the split-tunnel-policy on the Cisco ASA to tunnelspecified.

E.

Configure the split-tunnel-policy on the Cisco ASA to tunnelspecified.

Answers
Suggested answer: B, D

Explanation:

https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/70847-local-lan-pix-asa.html

A TCP based application that should be accessible over the VPN tunnel is not working. Pings to the appropriate IP address are failing.

Based on the output, what is a fix for this issue?

A.

Add a route on the remote peer for 209.165.201.0/27.

A.

Add a route on the remote peer for 209.165.201.0/27.

Answers
B.

Add a route on the local peer for 10.1.1.0/24.

B.

Add a route on the local peer for 10.1.1.0/24.

Answers
C.

Add a permit for TCP traffic going to 10.1.1.0/24.

C.

Add a permit for TCP traffic going to 10.1.1.0/24.

Answers
D.

Add a permit for TCP traffic going to 209.165.201.0/27.

D.

Add a permit for TCP traffic going to 209.165.201.0/27.

Answers
Suggested answer: A

When troubleshooting FlexVPN spoke-to-spoke tunnels, what should be verified first?

A.

NHRP redirect is enabled on the hub.

A.

NHRP redirect is enabled on the hub.

Answers
B.

The spokes have sent a resolution request.

B.

The spokes have sent a resolution request.

Answers
C.

NHRP cache entries exist on the spoke.

C.

NHRP cache entries exist on the spoke.

Answers
D.

NHO routes exist on the spokes.

D.

NHO routes exist on the spokes.

Answers
Suggested answer: A

Explanation:

https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_ike2vpn/configuration/15-mt/sec-flex-vpn-15-mt-book/sec-flex-spoke.html

An engineer is building an IKEv1 tunnel to a peer Cisco ASA, but the tunnel is failing. Based on the configuration in the exhibit, which action must be taken to allow the VPN tunnel to come up?

A.

Add a route for the 10.7.7.0/24 network to egress the outside interface.

A.

Add a route for the 10.7.7.0/24 network to egress the outside interface.

Answers
B.

Enable IKEv1 on the outside interface.

B.

Enable IKEv1 on the outside interface.

Answers
C.

Change the IKEv1 policy number to be at least 256.

C.

Change the IKEv1 policy number to be at least 256.

Answers
D.

Change the transform set mode to transport.

D.

Change the transform set mode to transport.

Answers
Suggested answer: B

Explanation:

https://www.cisco.com/c/en/us/support/docs/security-vpn/ipsec-negotiation-ike-protocols/119425-configure-ipsec-00.html

Total 175 questions
Go to page: of 18