Cisco 300-730 Practice Test - Questions Answers, Page 5

List of questions
Question 41

Which technology works with IPsec stateful failover?
GLBR
HSRP
GRE
VRRP
HSRP (Hot Standby Router Protocol). HSRP is a Cisco proprietary protocol that provides stateful failover for IPsec virtual private networks (VPNs). It is used to create a virtual router in order to provide redundancy in the event of an IPsec VPN failure. HSRP works by assigning a single primary router to manage the connection and forwarding traffic to the secondary router if the primary router fails.
Question 42

What are two functions of ECDH and ECDSA? (Choose two.)
nonrepudiation
revocation
digital signature
key exchange
encryption
Reference: https://tools.cisco.com/security/center/resources/next_generation_cryptography
Question 43

What uses an Elliptic Curve key exchange algorithm?
ECDSA
ECDHE
AES-GCM
SHA
Reference: https://blog.cloudflare.com/a-relatively-easy-to-understand-primer-on-elliptic-curvecryptography/
Question 44

Which two remote access VPN solutions support SSL? (Choose two.)
FlexVPN
clientless
EZVPN
L2TP
Cisco AnyConnect
Question 45

Which VPN solution uses TBAR?
GETVPN
VTI
DMVPN
Cisco AnyConnect
Reference: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_getvpn/configuration/xe-3s/sec-get- vpn-xe-3s-book/sec-get-vpn.html
Question 46

Which two commands help determine why the NHRP registration process is not being completed even after the IPsec tunnel is up? (Choose two.)
show crypto isakmp sa
show ip traffic
show crypto ipsec sa
show ip nhrp traffic
show dmvpn detail
https://www.cisco.com/c/en/us/support/docs/security/dynamic-multipoint-vpn-dmvpn/111976-dmvpn-troubleshoot-00.html
Question 47

Refer to the exhibit.
All internal clients behind the ASA are port address translated to the public outside interface that has an IP address of 3.3.3.3. Client 1 and client 2 have established successful SSL VPN connections to the ASA. What must be implemented so that "3.3.3.3" is returned from a browser search on the IP address?
Same-security-traffic permit inter-interface under Group Policy
Exclude Network List Below under Group Policy
Tunnel All Networks under Group Policy
Tunnel Network List Below under Group Policy
The reason is that by default, the SSL VPN clients use split tunneling, which means they only send trafficdestined for the corporate network through the VPN tunnel, and use their local gateway for other
traffic, such as browsing the internet. This means that when they search for their IP address on abrowser, they will see their local IP address, not the IP address of the ASA.To change this behavior, you need to configure the Group Policy on the ASA to tunnel all networks,which means that all traffic from the SSL VPN clients will go through the VPN tunnel, regardless of thedestination. This way, when they search for their IP address on a browser, they will see the IP address ofthe ASA, which is 3.3.3.3.To configure tunnel all networks under Group Policy, you can use either ASDM or CLI.For example, usingASDM, you can follow these steps1:Choose Configuration > Remote Access VPN > Network (Client) Access > Group Policies.Select the group policy that you want to modify and click Edit.In the Edit Internal Group Policy window, choose Advanced > Split Tunneling.In the Policy drop-down list, choose Tunnel All Networks.Click OK and then Apply.Using CLI, you can enter these commands:ciscoasa(config)# group-policy <group_policy_name> attributes ciscoasa(config-group-policy)# split-tunnel-policy tunnelall
Question 48

Cisco AnyConnect clients need to transfer large files over the VPN sessions. Which protocol provides the best throughput?
SSL/TLS
L2TP
DTLS
IPsec IKEv1
Question 49

Refer to the exhibit.
Which VPN technology is used in the exhibit?
DVTI
VTI
DMVPN
GRE
Reference: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_vpnips/configuration/zZArchive/IPsec_Virtual_Tunnel_Interface.html#GUID-EB8C433B-2394-42B9-997F-B40803E58A91
Question 50

Which VPN does VPN load balancing on the ASA support?
VTI
IPsec site-to-site tunnels
L2TP over IPsec
Cisco AnyConnect
Question