ExamGecko
Home / Cisco / 300-730 / List of questions
Ask Question

Cisco 300-730 Practice Test - Questions Answers, Page 6

Add to Whishlist

List of questions

Question 51

Report Export Collapse

Which parameter must match on all routers in a DMVPN Phase 3 cloud?

GRE tunnel key

GRE tunnel key

NHRP network ID

NHRP network ID

tunnel VRF

tunnel VRF

EIGRP split-horizon setting

EIGRP split-horizon setting

Suggested answer: A
Explanation:

NHRP network IDs are locally significant and can be different. It makes sense from a deployment andmaintenance perspective to use unique network ID numbers (using the ip nhrp network-id command)across all routers in a DMVPN network, but it is not necessary that they be the same.https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_dmvpn/configuration/15-mt/sec-conn-dmvpn-15-mt-book/sec-conn-dmvpn-dmvpn.html

asked 10/10/2024
Emmanuel Esquivel Guzman
37 questions

Question 52

Report Export Collapse

Which parameter is initially used to elect the primary key server from a group of key servers?

code version

code version

highest IP address

highest IP address

highest-priority value

highest-priority value

lowest IP address

lowest IP address

Suggested answer: C
Explanation:

Reference: https://www.cisco.com/c/en/us/products/collateral/security/group-encrypted-transportvpn/deployment_guide_c07_554713.html

asked 10/10/2024
Ivan Ramirez
45 questions

Question 53

Report Export Collapse

A Cisco ASA is configured in active/standby mode. What is needed to ensure that Cisco AnyConnect users can connect after a failover event?

AnyConnect images must be uploaded to both failover ASA devices.

AnyConnect images must be uploaded to both failover ASA devices.

The vpnsession-db must be cleared manually.

The vpnsession-db must be cleared manually.

Configure a backup server in the XML profile.

Configure a backup server in the XML profile.

AnyConnect client must point to the standby IP address.

AnyConnect client must point to the standby IP address.

Suggested answer: A
Explanation:

Reference:

https://www.cisco.com/c/en/us/td/docs/security/asa/asa90/configuration/guide/asa_90_cli_config/ha_active_standby.html

asked 10/10/2024
AJ Foraker
43 questions

Question 54

Report Export Collapse

Which benefit of FlexVPN is a limitation of DMVPN using IKEv1?

GRE encapsulation allows for forwarding of non-IP traffic.

GRE encapsulation allows for forwarding of non-IP traffic.

IKE implementation can install routes in routing table.

IKE implementation can install routes in routing table.

NHRP authentication provides enhanced security.

NHRP authentication provides enhanced security.

Dynamic routing protocols can be configured.

Dynamic routing protocols can be configured.

Suggested answer: B
asked 10/10/2024
Andres Montero
42 questions

Question 55

Report Export Collapse

What is a requirement for smart tunnels to function properly?

Java or ActiveX must be enabled on the client machine.

Java or ActiveX must be enabled on the client machine.

Applications must be UDP.

Applications must be UDP.

Stateful failover must not be configured.

Stateful failover must not be configured.

The user on the client machine must have admin access.

The user on the client machine must have admin access.

Suggested answer: A
Explanation:

Reference: https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-nextgeneration-firewalls/111007-smart-tunnel-asa-00.html

asked 10/10/2024
VEDA VIKASH Matam Shashidhar
46 questions

Question 56

Report Export Collapse

Where is split tunneling defined for IKEv2 remote access clients on a Cisco router?

IKEv2 authorization policy

IKEv2 authorization policy

Group Policy

Group Policy

virtual template

virtual template

webvpn context

webvpn context

Suggested answer: A
Explanation:

https://www.cisco.com/c/en/us/support/docs/routers/3600-series-multiservice-platforms/91193-rtr-ipsec-internet-connect.html

asked 10/10/2024
Judith Persons
48 questions

Question 57

Report Export Collapse

Which technology is used to send multicast traffic over a site-to-site VPN?

GRE over IPsec on IOS router

GRE over IPsec on IOS router

GRE over IPsec on FTD

GRE over IPsec on FTD

IPsec tunnel on FTD

IPsec tunnel on FTD

GRE tunnel on ASA

GRE tunnel on ASA

Suggested answer: A
Explanation:

https://www.cisco.com/c/en/us/support/docs/security-vpn/ipsec-negotiation-ike-protocols/216276-configure-route-based-site-to-site-vpn-t.html#anc6

asked 10/10/2024
David Wilson
43 questions

Question 58

Report Export Collapse

Which feature of GETVPN is a limitation of DMVPN and FlexVPN?

sequence numbers that enable scalable replay checking

sequence numbers that enable scalable replay checking

enabled use of ESP or AH

enabled use of ESP or AH

design for use over public or private WAN

design for use over public or private WAN

no requirement for an overlay routing protocol

no requirement for an overlay routing protocol

Suggested answer: D
asked 10/10/2024
Asad yaseen
44 questions

Question 59

Report Export Collapse

Refer to the exhibit.

Cisco 300-730 image Question 59 114577 10102024232758000000

Cisco AnyConnect must be set up on a router to allow users to access internal servers 192.168.0.10 and 192.168.0.11. All other traffic should go out of the client's local NIC. Which command accomplishes this configuration?

svc split include 192.168.0.0 255.255.255.0

svc split include 192.168.0.0 255.255.255.0

svc split exclude 192.168.0.0 255.255.255.0

svc split exclude 192.168.0.0 255.255.255.0

svc split include acl CCNP

svc split include acl CCNP

svc split exclude acl CCNP

svc split exclude acl CCNP

Suggested answer: C
Explanation:

https://www.cisco.com/c/en/us/support/docs/security/anyconnect-secure-mobility-client/200533-AnyConnect-Configure-Basic-SSLVPN-for-I.html

asked 10/10/2024
Nestor Maitin
31 questions

Question 60

Report Export Collapse

An engineer is configuring clientless SSL VPN. The finance department has a database server that only they should access, but the sales department can currently access it. The finance and the sales departments are configured as separate group-policies. What must be added to the configuration to make sure the users in the sales department cannot access the finance department server?

tunnel group lock

tunnel group lock

smart tunnel

smart tunnel

port forwarding

port forwarding

webtype ACL

webtype ACL

Suggested answer: D
Explanation:

https://www.cisco.com/c/en/us/td/docs/security/asa/asa92/configuration/general/asa-generalcli/acl-webtype.pdf

asked 10/10/2024
Brandy Butman
38 questions
Total 175 questions
Go to page: of 18

Related questions