Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Pass the Cisco CCNP Security 300-730 Questions and answers with ValidTests

Exam 300-730 All Questions
Exam 300-730 Premium Access

View all detail and faqs for the 300-730 exam

Viewing page 3 out of 5 pages
Viewing questions 21-30 out of questions
Questions # 21:

An administrator must guarantee that remote access users are able to reach printers on their local LAN after a VPN session is established to the headquarters. All other traffic should be sent over the tunnel. Which split-tunnel policy reduces the configuration on the ASA headend?

Options:

A.

include specified

B.

exclude specified

C.

tunnel specified

D.

dynamic exclude

Expert Solution
Questions # 22:

Refer to the exhibit.

Question # 22

An engineer is diagnosing an issue that occurred after a router at a branch site was assigned a new address. Based on the debugs, what must be done to resolve this issue?

Options:

A.

Add the remote peer’s IP address to the server's IKEv2 keyring.

B.

Ensure that the correct preshared keys are set on both sides.

C.

Ensure that the UDP 500 packets between devices are not dropped.

D.

Add the remote peer’s identity to the server’s IKEv2 profile.

Expert Solution
Questions # 23:

A network administrator wants the Cisco ASA to automatically start downloading the Cisco AnyConnect client without prompting the user to select between WebVPN or AnyConnect. Which command accomplishes this task?

Options:

A.

anyconnect ssl df-bit-ignore enable

B.

anyconnect ask none default anyconnect

C.

anyconnect ask enable default anyconnect

D.

anyconnect modules value default

Expert Solution
Questions # 24:

A network engineer must design a remote access solution to allow contractors to access internal servers. These contractors do not have permissions to install applications on their computers. Which VPN solution should be used in this design?

Options:

A.

IKEv2 AnyConnect

B.

Clientless

C.

Port forwarding

D.

SSL AnyConnect

Expert Solution
Questions # 25:

Users cannot log in to a Cisco ASA using clientless SSLVPN. Troubleshooting reveals the error message "WebVPN session terminated: Client type not supported". Which step does the administrator take to resolve this issue?

Options:

A.

Enable the Cisco AnyConnect premium license on the Cisco ASA.

B.

Have the user upgrade to a supported browser.

C.

Increase the simultaneous logins on the group policy.

D.

Enable the clientless VPN protocol on the group policy.

Expert Solution
Questions # 26:

A user is experiencing delays on audio calls over a Cisco AnyConnect VPN. Which implementation step resolves this issue?

Options:

A.

Change to 3DES Encryption.

B.

Shorten the encryption key lifetime.

C.

Install the Cisco AnyConnect 2.3 client for the user to download.

D.

Enable DTLS.

Expert Solution
Questions # 27:

A second set of traffic selectors is negotiated between two peers using IKEv2. Which IKEv2 packet will contain details of the exchange?

Options:

A.

IKEv2 IKE_SA_INIT

B.

IKEv2 INFORMATIONAL

C.

IKEv2 CREATE_CHILD_SA

D.

IKEv2 IKE_AUTH

Expert Solution
Questions # 28:

Refer to the exhibit.

Question # 28

Which two tunnel types produce the show crypto ipsec sa output seen in the exhibit? (Choose two.)

Options:

A.

crypto map

B.

DMVPN

C.

GRE

D.

FlexVPN

E.

VTI

Expert Solution
Questions # 29:

Drag and drop the correct commands from the night onto the blanks within the code on the left to implement a design that allow for dynamic spoke-to-spoke communication. Not all comments are used.

Question # 29

Options:

Expert Solution
Questions # 30:

Which two parameters help to map a VPN session to a tunnel group without using the tunnel-group list? (Choose two.)

Options:

A.

group-alias

B.

certificate map

C.

optimal gateway selection

D.

group-url

E.

AnyConnect client version

Expert Solution
Viewing page 3 out of 5 pages
Viewing questions 21-30 out of questions