Cisco 300-730 Practice Test - Questions Answers, Page 6
List of questions
Related questions
Which parameter must match on all routers in a DMVPN Phase 3 cloud?
GRE tunnel key
NHRP network ID
tunnel VRF
EIGRP split-horizon setting
Which parameter is initially used to elect the primary key server from a group of key servers?
code version
highest IP address
highest-priority value
lowest IP address
A Cisco ASA is configured in active/standby mode. What is needed to ensure that Cisco AnyConnect users can connect after a failover event?
AnyConnect images must be uploaded to both failover ASA devices.
The vpnsession-db must be cleared manually.
Configure a backup server in the XML profile.
AnyConnect client must point to the standby IP address.
Which benefit of FlexVPN is a limitation of DMVPN using IKEv1?
GRE encapsulation allows for forwarding of non-IP traffic.
IKE implementation can install routes in routing table.
NHRP authentication provides enhanced security.
Dynamic routing protocols can be configured.
What is a requirement for smart tunnels to function properly?
Java or ActiveX must be enabled on the client machine.
Applications must be UDP.
Stateful failover must not be configured.
The user on the client machine must have admin access.
Where is split tunneling defined for IKEv2 remote access clients on a Cisco router?
IKEv2 authorization policy
Group Policy
virtual template
webvpn context
Which technology is used to send multicast traffic over a site-to-site VPN?
GRE over IPsec on IOS router
GRE over IPsec on FTD
IPsec tunnel on FTD
GRE tunnel on ASA
Which feature of GETVPN is a limitation of DMVPN and FlexVPN?
sequence numbers that enable scalable replay checking
enabled use of ESP or AH
design for use over public or private WAN
no requirement for an overlay routing protocol
Refer to the exhibit.
Cisco AnyConnect must be set up on a router to allow users to access internal servers 192.168.0.10 and 192.168.0.11. All other traffic should go out of the client's local NIC. Which command accomplishes this configuration?
svc split include 192.168.0.0 255.255.255.0
svc split exclude 192.168.0.0 255.255.255.0
svc split include acl CCNP
svc split exclude acl CCNP
An engineer is configuring clientless SSL VPN. The finance department has a database server that only they should access, but the sales department can currently access it. The finance and the sales departments are configured as separate group-policies. What must be added to the configuration to make sure the users in the sales department cannot access the finance department server?
tunnel group lock
smart tunnel
port forwarding
webtype ACL
Question