Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Pass the Cisco CCNP Security 300-730 Questions and answers with ValidTests

Exam 300-730 All Questions
Exam 300-730 Premium Access

View all detail and faqs for the 300-730 exam

Viewing page 2 out of 5 pages
Viewing questions 11-20 out of questions
Questions # 11:

Refer to the exhibit.

Question # 11

The DMVPN tunnel is dropping randomly and no tunnel protection is configured. Which spoke configuration mitigates tunnel drops?

Question # 11

Question # 11

Question # 11

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Expert Solution
Questions # 12:

Which method dynamically installs the network routes for remote tunnel endpoints?

Options:

A.

policy-based routing

B.

CEF

C.

reverse route injection

D.

route filtering

Expert Solution
Questions # 13:

Refer to the exhibit.

Question # 13

An engineer is troubleshooting a new GRE over IPsec tunnel. The tunnel is established but the engineer cannot ping from spoke 1 to spoke 2. Which type of traffic is being blocked?

Options:

A.

ESP packets from spoke2 to spoke1

B.

ISAKMP packets from spoke2 to spoke1

C.

ESP packets from spoke1 to spoke2

D.

ISAKMP packets from spoke1 to spoke2

Expert Solution
Questions # 14:

Which statement about GETVPN is true?

Options:

A.

The configuration that defines which traffic to encrypt originates from the key server.

B.

TEK rekeys can be load-balanced between two key servers operating in COOP.

C.

The pseudotime that is used for replay checking is synchronized via NTP.

D.

Group members must acknowledge all KEK and TEK rekeys, regardless of configuration.

Expert Solution
Questions # 15:

Refer to the exhibit.

Question # 15

Which VPN technology is allowed for users connecting to the Employee tunnel group?

Options:

A.

SSL AnyConnect

B.

IKEv2 AnyConnect

C.

crypto map

D.

clientless

Expert Solution
Questions # 16:

Which VPN technology minimizes the impact on VPN performance when encrypting multicast traffic on a Private WAN?

Options:

A.

DMVPN

B.

IPsec VPN

C.

FlexVPN

D.

GETVPN

Expert Solution
Questions # 17:

An engineer is requesting an SSL certificate for a VPN load-balancing cluster in which two Cisco ASAs provide clientless SSLVPN access. The FQDN that users will enter to access the clientless VPN is asa.example.com, and users will be redirected to either asa1.example.com or asa2.example.com. The cluster FQDN and individual Cisco ASAs FQDNs resolve to IP addresses 192.168.0.1, 192.168.0.2, and 192.168.0.3 respectively. The issued certificate must be able to be used to validate the identity of either ASA in the cluster without returning any certificate validation errors. Which fields must be included in the certificate to meet these requirements?

Options:

A.

CN=*.example.com, SAN=asa.example.com

B.

CN=192.168.0.1, SAN=asa1.example.com, asa2.example.com

C.

CN=asa.example.com, SAN=asa.example.com, asa1.example.com, asa2.example.com

D.

CN=192.168.0.1, SAN=192.168.0.1, 192.168.0.2, 192.168.0.3

Expert Solution
Questions # 18:

Refer to the exhibit.

Question # 18

An engineer has configured two new VPN tunnels to 172.18.1.1 and 172.19.1.1. However, communication between 10.1.0.10 and 10.1.11.10 does not function. Which action should be taken to resolve this issue?

Options:

A.

Remove and reapply the crypto map to the interface.

B.

Insert routes for the 10.1.9.0/24 and 10.1.10.0/24 subnets.

C.

Modify the transform set to use transport mode.

D.

Adjust the network objects to match the appropriate subnets.

Expert Solution
Questions # 19:

An engineer is using DMVPN to provide secure connectivity between a data center and remote sites. Which two routing protocols should be used between the routers? (Choose two.)

Options:

A.

IS-IS

B.

BGP

C.

RIPv2

D.

OSPF

E.

EIGRP

Expert Solution
Questions # 20:

Over the weekend, an administrator upgraded the Cisco ASA image on the firewalls and noticed that users cannot connect to the headquarters site using Cisco AnyConnect. What is the solution for this issue?

Options:

A.

Upgrade the Cisco AnyConnect client version to be compatible with the Cisco ASA software image.

B.

Upgrade the Cisco AnyConnect Network Access module to be compatible with the Cisco ASA software image.

C.

Upgrade the Cisco AnyConnect client driver to be compatible with the Cisco ASA software image.

D.

Upgrade the Cisco AnyConnect Start Before Logon module to be compatible with the Cisco ASA software image.

Expert Solution
Viewing page 2 out of 5 pages
Viewing questions 11-20 out of questions