Labour Day - Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dpm65

300-730 Implementing Secure Solutions with Virtual Private Networks (SVPN) Questions and Answers

Questions 4

Which feature of GETVPN is a limitation of DMVPN and FlexVPN?

Options:

A.

sequence numbers that enable scalable replay checking

B.

enabled use of ESP or AH

C.

design for use over public or private WAN

D.

no requirement for an overlay routing protocol

Buy Now
Questions 5

What are two differences between ECC and RSA? (Choose two.)

Options:

A.

Key generation in ECC is slower and more CPU intensive than RSA.

B.

ECC can have the same security as RSA but with a shorter key size.

C.

ECC cannot have the same security as RSA, even with an increased key size.

D.

Key generation in ECC is faster and less CPU intensive than RSA.

E.

ECC lags in performance when compared with RSA.

Buy Now
Questions 6

An engineer is creating an URL object on Cisco FMC. How must it be configured so that the object will match for HTTPS traffic in an access control policy?

Options:

A.

Specify the protocol to match (HTTP or HTTPS).

B.

Use the FQDN including the subdomain for the website.

C.

Use the subject common name from the website certificate.

D.

Define the path to the individual webpage that uses HTTPS.

Buy Now
Questions 7

Which technology and VPN component allows a VPN headend to dynamically learn post NAT IP addresses of remote routers at different sites?

Options:

A.

DMVPN with ISAKMP

B.

GETVPN with ISAKMP

C.

DMVPN with NHRP

D.

GETVPN with NHRP

Buy Now
Questions 8

Refer to the exhibit.

300-730 Question 8

Which type of VPN is used?

Options:

A.

GETVPN

B.

clientless SSL VPN

C.

Cisco Easy VPN

D.

Cisco AnyConnect SSL VPN

Buy Now
Questions 9

Which command automatically initiates a smart tunnel when a user logs in to the WebVPN portal page?

Options:

A.

auto-upgrade

B.

auto-connect

C.

auto-start

D.

auto-run

Buy Now
Questions 10

A router is being configured for IKEv2 AnyConnect using AnyConnect-EAP. How would the administrator separate profiles for administrators and employees so that authorization differs when they connect?

Options:

A.

Define group aliases on the headend and have the user pick the appropriate alias when they connect

B.

Define group-urls on the headend and create two XML profiles to match the administrator and user group urls

C.

Create a certificate map and match on the appropriate certificate fields

D.

Define key-ids on the headend and create two XML profiles to match the administrator and user key-ids.

Buy Now
Questions 11

A network engineer has set up a FlexVPN server to terminate multiple FlexVPN clients. The VPN tunnels are established without issue. However, when a Change of Authorization is issued by the RADIUS server, the FlexVPN server does not update the authorization of connected FlexVPN clients. Which action resolves this issue?

Options:

A.

Add the aaa server radius dynamic-author command on the FlexVPN clients.

B.

Fix the RADIUS key mismatch between the RADIUS server and FlexVPN server.

C.

Add the aaa server radius dynamic-author command on the FlexVPN server.

D.

Fix the RADIUS key mismatch between the RADIUS server and FlexVPN clients.

Buy Now
Questions 12

Refer to the exhibit.

300-730 Question 12

An engineer has configured two new VPN tunnels to 172.18.1.1 and 172.19.1.1. However, communication between 10.1.0.10 and 10.1.11.10 does not function. Which action should be taken to resolve this issue?

Options:

A.

Remove and reapply the crypto map to the interface.

B.

Insert routes for the 10.1.9.0/24 and 10.1.10.0/24 subnets.

C.

Modify the transform set to use transport mode.

D.

Adjust the network objects to match the appropriate subnets.

Buy Now
Questions 13

A network engineer is installing Cisco AnyConnect on company laptops so that users can access corporate resources remotely. The VPN concentrator is a Cisco router running IOS-XE 16.9.1 code and configured as a FlexVPN server that uses local authentication and *$Cisc431089017$* as the key-id for the IKEv2 profile. Which two steps must be taken on the computer to allow a successful AnyConnect connection to the router? (Choose two.)

Options:

A.

In the Cisco AnyConnect XML profile, set the IPsec Authentication method to EAP-AnyConnect.

B.

In the Cisco AnyConnect XML profile, add the hostname and host address to the server list.

C.

In the Cisco AnyConnect XML profile, set the user group field to DefaultAnyConnectClientGroup.

D.

In the Cisco AnyConnect Local Policy, set the BypassDownloader option in the local to true.

E.

In the Cisco AnyConnect Local Policy, add the router IP address to the Update Policy.

Buy Now
Questions 14

300-730 Question 14

VPN tunnels between a spoke and two DMVPN hubs are not coming up. The network administrator has verified that the encryption, hashing, and DH group proposals for Phase 1 and Phase 2 match on both ends. What is the solution to this issue?

Options:

A.

Ensure bidirectional UDP 500/4500 traffic.

B.

Increase the isakmp phase 1 lifetime.

C.

Add NAT statements for VPN traffic.

D.

Enable shared tunnel protection.

Buy Now
Questions 15

Which two types of web resources or protocols are enabled by default on the Cisco ASA Clientless SSL VPN portal? (Choose two.)

Options:

A.

HTTP

B.

ICA (Citrix)

C.

VNC

D.

RDP

E.

CIFS

Buy Now
Questions 16

A Cisco AnyConnect client establishes a SSL VPN connection with an ASA at the corporate office. An engineer must ensure that the client computer meets the enterprise security policy. Which feature can update the client to meet an enterprise security policy?

Options:

A.

Endpoint Assessment

B.

Cisco Secure Desktop

C.

Basic Host Scan

D.

Advanced Endpoint Assessment

Buy Now
Questions 17

Which feature allows the ASA to handle nonstandard applications and web resources so that they display correctly over a clientless SSL VPN connection?

Options:

A.

single sign-on

B.

Smart Tunnel

C.

WebType ACL

D.

plug-ins

Buy Now
Questions 18

Which requirement is needed to use local authentication for Cisco AnyConnect Secure Mobility Clients that connect to a FlexVPN server?

Options:

A.

use of certificates instead of username and password

B.

EAP-AnyConnect

C.

EAP query-identity

D.

AnyConnect profile

Buy Now
Questions 19

Which two features provide headend resiliency for Cisco AnyConnect clients? (Choose two.)

Options:

A.

AnyConnect Auto Reconnect

B.

AnyConnect Network Access Manager

C.

AnyConnect Backup Servers

D.

ASA failover

E.

AnyConnect Always On

Buy Now
Questions 20

Refer to the exhibit.

300-730 Question 20

Which VPN technology is allowed for users connecting to the Employee tunnel group?

Options:

A.

SSL AnyConnect

B.

IKEv2 AnyConnect

C.

crypto map

D.

clientless

Buy Now
Questions 21

Refer to the exhibit.

300-730 Question 21

Which value must be configured in the User Group field when the Cisco AnyConnect Profile is created to connect to an ASA headend with IPsec as the primary protocol?

Options:

A.

address-pool

B.

group-alias

C.

group-policy

D.

tunnel-group

Buy Now
Questions 22

Cisco AnyConnect Secure Mobility Client has been configured to use IKEv2 for one group of users and SSL for another group. When the administrator configures a new AnyConnect release on the Cisco ASA, the IKEv2 users cannot download it automatically when they connect. What might be the problem?

Options:

A.

The XML profile is not configured correctly for the affected users.

B.

The new client image does not use the same major release as the current one.

C.

Client services are not enabled.

D.

Client software updates are not supported with IKEv2.

Buy Now
Questions 23

Which command identifies a Cisco AnyConnect profile that was uploaded to the flash of an IOS router?

Options:

A.

svc import profile SSL_profile flash:simos-profile.xml

B.

anyconnect profile SSL_profile flash:simos-profile.xml

C.

crypto vpn anyconnect profile SSL_profile flash:simos-profile.xml

D.

webvpn import profile SSL_profile flash:simos-profile.xml

Buy Now
Questions 24

Which two statements about the Cisco ASA Clientless SSL VPN solution are true? (Choose two.)

Options:

A.

When a client connects to the Cisco ASA WebVPN portal and tries to access HTTP resources through the URL bar, the client uses the local DNS to perform FQDN resolution.

B.

The rewriter enable command under the global webvpn configuration enables the rewriter functionality because that feature is disabled by default.

C.

A Cisco ASA can simultaneously allow Clientless SSL VPN sessions and AnyConnect client sessions.

D.

When a client connects to the Cisco ASA WebVPN portal and tries to access HTTP resources through the URL bar, the ASA uses its configured DNS servers to perform FQDN resolution.

E.

Clientless SSLVPN provides Layer 3 connectivity into the secured network.

Buy Now
Questions 25

Which parameter is initially used to elect the primary key server from a group of key servers?

Options:

A.

code version

B.

highest IP address

C.

highest-priority value

D.

lowest IP address

Buy Now
Questions 26

Which parameter must match on all routers in a DMVPN Phase 3 cloud?

Options:

A.

GRE tunnel key

B.

NHRP network ID

C.

tunnel VRF

D.

EIGRP split-horizon setting

Buy Now
Questions 27

What uses an Elliptic Curve key exchange algorithm?

Options:

A.

ECDSA

B.

ECDHE

C.

AES-GCM

D.

SHA

Buy Now
Questions 28

Which technology works with IPsec stateful failover?

Options:

A.

GLBR

B.

HSRP

C.

GRE

D.

VRRP

Buy Now
Questions 29

Which VPN does VPN load balancing on the ASA support?

Options:

A.

VTI

B.

IPsec site-to-site tunnels

C.

L2TP over IPsec

D.

Cisco AnyConnect

Buy Now
Questions 30

A Cisco ASA is configured in active/standby mode. What is needed to ensure that Cisco AnyConnect users can connect after a failover event?

Options:

A.

AnyConnect images must be uploaded to both failover ASA devices.

B.

The vpnsession-db must be cleared manually.

C.

Configure a backup server in the XML profile.

D.

AnyConnect client must point to the standby IP address.

Buy Now
Questions 31

What is a requirement for smart tunnels to function properly?

Options:

A.

Java or ActiveX must be enabled on the client machine.

B.

Applications must be UDP.

C.

Stateful failover must not be configured.

D.

The user on the client machine must have admin access.

Buy Now
Questions 32

Which VPN solution uses TBAR?

Options:

A.

GETVPN

B.

VTI

C.

DMVPN

D.

Cisco AnyConnect

Buy Now
Questions 33

Cisco AnyConnect clients need to transfer large files over the VPN sessions. Which protocol provides the best throughput?

Options:

A.

SSL/TLS

B.

L2TP

C.

DTLS

D.

IPsec IKEv1

Buy Now
Questions 34

On a FlexVPN hub-and-spoke topology where spoke-to-spoke tunnels are not allowed, which command is needed for the hub to be able to terminate FlexVPN tunnels?

Options:

A.

interface virtual-access

B.

ip nhrp redirect

C.

interface tunnel

D.

interface virtual-template

Buy Now
Questions 35

Which statement about GETVPN is true?

Options:

A.

The configuration that defines which traffic to encrypt originates from the key server.

B.

TEK rekeys can be load-balanced between two key servers operating in COOP.

C.

The pseudotime that is used for replay checking is synchronized via NTP.

D.

Group members must acknowledge all KEK and TEK rekeys, regardless of configuration.

Buy Now
Questions 36

Refer to the exhibit.

300-730 Question 36

The DMVPN tunnel is dropping randomly and no tunnel protection is configured. Which spoke configuration mitigates tunnel drops?

300-730 Question 36

300-730 Question 36

300-730 Question 36

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 37

Drag and drop the correct commands from the night onto the blanks within the code on the left to implement a design that allow for dynamic spoke-to-spoke communication. Not all comments are used.

300-730 Question 37

Options:

Buy Now
Questions 38

Refer to the exhibit.

300-730 Question 38

A customer cannot establish an IKEv2 site-to-site VPN tunnel between two Cisco ASA devices. Based on the syslog message, which action brings up the VPN tunnel?

Options:

A.

Reduce the maximum SA limit on the local Cisco ASA.

B.

Increase the maximum in-negotiation SA limit on the local Cisco ASA.

C.

Remove the maximum SA limit on the remote Cisco ASA.

D.

Correct the crypto access list on both Cisco ASA devices.

Buy Now
Questions 39

Which method dynamically installs the network routes for remote tunnel endpoints?

Options:

A.

policy-based routing

B.

CEF

C.

reverse route injection

D.

route filtering

Buy Now
Questions 40

A second set of traffic selectors is negotiated between two peers using IKEv2. Which IKEv2 packet will contain details of the exchange?

Options:

A.

IKEv2 IKE_SA_INIT

B.

IKEv2 INFORMATIONAL

C.

IKEv2 CREATE_CHILD_SA

D.

IKEv2 IKE_AUTH

Buy Now
Questions 41

Refer to the exhibit.

300-730 Question 41

Which two tunnel types produce the show crypto ipsec sa output seen in the exhibit? (Choose two.)

Options:

A.

crypto map

B.

DMVPN

C.

GRE

D.

FlexVPN

E.

VTI

Buy Now
Questions 42

Which two changes must be made in order to migrate from DMVPN Phase 2 to Phase 3 when EIGRP is configured? (Choose two.)

Options:

A.

Add NHRP shortcuts on the hub.

B.

Add NHRP redirects on the spoke.

C.

Disable EIGRP next-hop-self on the hub.

D.

Enable EIGRP next-hop-self on the hub.

E.

Add NHRP redirects on the hub.

Buy Now
Questions 43

Which two parameters help to map a VPN session to a tunnel group without using the tunnel-group list? (Choose two.)

Options:

A.

group-alias

B.

certificate map

C.

optimal gateway selection

D.

group-url

E.

AnyConnect client version

Buy Now
Questions 44

Refer to the exhibit.

300-730 Question 44

An SSL client is connecting to an ASA headend. The session fails with the message “Connection attempt has timed out. Please verify Internet connectivity.” Based on how the packet is processed, which phase is causing the failure?

Options:

A.

phase 9: rpf-check

B.

phase 5: NAT

C.

phase 4: ACCESS-LIST

D.

phase 3: UN-NAT

Buy Now
Exam Code: 300-730
Exam Name: Implementing Secure Solutions with Virtual Private Networks (SVPN)
Last Update: Apr 23, 2024
Questions: 175

PDF + Testing Engine

$59.5  $169.99

Testing Engine

$45.5  $129.99
buy now 300-730 testing engine

PDF (Q&A)

$38.5  $109.99
buy now 300-730 pdf
dumpsmate guaranteed to pass
24/7 Customer Support

DumpsMate's team of experts is always available to respond your queries on exam preparation. Get professional answers on any topic of the certification syllabus. Our experts will thoroughly satisfy you.

Site Secure

mcafee secure

TESTED 25 Apr 2024