300-730 Practice Questions
225 real 300-730 exam questions with expert-verified answers and explanations. Page 1 of 5.
- Question #1Secure Communications
Which VPN solution uses TBAR?
GETVPNTBARanti-replaygroup encryption - Question #2Troubleshooting VPNs
Which two commands help determine why the NHRP registration process is not being completed even after the IPsec tunnel is up? (Choose two.)
DMVPNNHRP registrationtroubleshooting commandsIPsec tunnel - Question #3Remote Access VPN
Refer to the exhibit. An internal clients behind the ASA are port address translated to the public outside interface that has an IP address of 3.3.3.3. Client 1 and client 2 have e...
SSL VPNsplit tunnelingPATgroup policy - Question #4Remote Access VPN
Cisco AnyConnect clients need to transfer large files over the VPN sessions. Which protocol provides the best throughput?
AnyConnectDTLSthroughputSSL/TLS - Question #5Remote Access VPN
Which VPN does VPN load balancing on the ASA support?
ASAVPN load balancingVTIhigh availability - Question #6Site-to-site VPNs on Routers and Firewalls
Which parameter must match on all routers in a DMVPN Phase 3 cloud?
DMVPN Phase 3GRE tunnel keymultipoint GREconfiguration - Question #7Secure Communications
Which parameter is initially used to elect the primary key server from a group of key servers?
GETVPNkey server electionprioritygroup member - Question #8Remote Access VPN
A Cisco ASA is configured in active/standby mode. What is needed to ensure that Cisco AnyConnect users can connect after a failover event?
ASA failoverAnyConnectactive/standbyhigh availability - Question #9Site-to-site VPNs on Routers and Firewalls
Which benefit of FlexVPN is a limitation of DMVPN using IKEv1?
FlexVPNDMVPNIKEv2 route installationIKEv1 limitation - Question #10Remote Access VPN
What is a requirement for smart tunnels to function properly?
smart tunnelsSSL VPNJavaActiveX - Question #11Remote Access VPN
Where is split tunneling defined for IKEv2 remote access clients on a Cisco router?
IKEv2split tunnelingauthorization policyFlexVPN remote access - Question #12Site-to-site VPNs on Routers and Firewalls
Which technology is used to send multicast traffic over a site-to-site VPN?
GRE over IPsecmulticastsite-to-site VPNIOS router - Question #13Secure Communications
Which feature of GETVPN is a limitation of DMVPN and FlexVPN?
GETVPNoverlay routingDMVPN comparisonFlexVPN comparison - Question #14Remote Access VPN
Refer to the exhibit. ip access-list extended CCNP permit 192.168.0.10 permit 192.168.0.11 webvpn gateway SSL_Gateway ip address 172.16.0.25 port 443 ssl trustpoint AnyConnect_Cert...
AnyConnectsplit tunnelingsvc split includeIOS router - Question #15Site-to-site VPNs on Routers and Firewalls
Drag and Drop Question Drag and drop the correct commands from the right onto the blanks in the code on the left to implement a design that allow for dynamic spoke-to-spoke communi...
DMVPNspoke-to-spokeNHRP shortcutPhase 3 - Question #16Secure Communications
Which two are characteristics of GETVPN? (Choose two.)
GETVPNIP header preservationtraffic encryption keygroup member - Question #17Site-to-site VPNs on Routers and Firewalls
In FlexVPN, what is the role of a NHRP resolution request?
FlexVPNNHRP resolutionspoke-to-spokedynamic tunnels - Question #18Secure Communications
A second set of traffic selectors is negotiated between two peers using IKEv2. Which IKEv2 packet will contain details of the exchange?
IKEv2CREATE_CHILD_SAtraffic selectorschild SA negotiation - Question #19Troubleshooting VPNs
Refer to the exhibit: HUB#show ip nhrp 0.0.0.2/32 via 10.0.0.2 Tunnel0 created 00:02:09, expire 00:00:01 Type: dynamic, Flags: unique registered used nhop NBMA address: 2.2.2.1 0.0...
DMVPNNHRP holdtimeregistration timeouttunnel stability - Question #20Site-to-site VPNs on Routers and Firewalls
On a FlexVPN hub-and-spoke topology where spoke-to-spoke tunnels are not allowed, which command is needed for the hub to be able to terminate FlexVPN tunnels?
FlexVPNvirtual-templatehub-and-spokespoke-to-spoke restriction - Question #21Site-to-site VPNs on Routers and Firewalls
Which statement about GETVPN is true?
GETVPNkey serverTEK rekeyCOOP - Question #22Site-to-site VPNs on Routers and Firewalls
Refer to the exhibit: Interface: Tunnel1 Crypto map tag: Tunnel-head-0, local addr 192.168.0.1 protected vrf: (none) local ident (addr/mask/prot/port): (0.0.0.0/0.0.0.0/0) remote i...
DMVPNcrypto maptunnel identificationNHRP - Question #23Site-to-site VPNs on Routers and Firewalls
Which two changes must be made in order to migrate from DMVPN Phase 2 to Phase 3 when EIGRP is configured? (Choose two.)
DMVPN Phase 3NHRP redirectsEIGRP next-hop-selfDMVPN migration - Question #24Troubleshooting VPNs
Refer to the exhibit: ASA-4-751015 Local:0.0.0.0:0 Remote:0.0.0.0:0 Username:Unknown SA request rejected by CAC. Reason: IN-NEGOTIATION SA LIMIT REACHED A customer cannot establish...
IKEv2SA limitCACsyslog troubleshooting - Question #25Troubleshooting VPNs
Refer to the exhibit: %LINK-3-UPDOWN: Interface Tunnel0, changed state to up %NHRP-5-REGISTRATION: Tunnel0: Spoke 10.1.1.25, NBMA 1.1.1.25 registered. %NHRP-5-REGISTRATION_COMPLETE...
NHRP registrationDMVPN spokedebug outputtunnel interface - Question #26Secure Communications
Which is used by GETVPN, FlexVPN and DMVPN?
ESPGETVPNFlexVPNDMVPN - Question #27Site-to-site VPNs on Routers and Firewalls
Which IKEv2 feature minimizes the configuration of a FlexVPN on Cisco IOS devices?
IKEv2 Smart DefaultsFlexVPNIOS configurationIKEv2 - Question #28Remote Access VPN
Which two parameters help to map a VPN session to a tunnel group using the tunnel-group-list? (Choose two.)
tunnel-group-listcertificate mapgroup-urlVPN session mapping - Question #29Site-to-site VPNs on Routers and Firewalls
Which method dynamically installs the network routes for remote tunnel endpoints?
reverse route injectiondynamic routingtunnel endpointsRRI - Question #30Remote Access VPN
Which command identifies a Cisco AnyConnect profile that was uploaded to the flash of an IOS router?
AnyConnect profileIOS routerSSL VPNprofile import - Question #31Remote Access VPN
Refer to the exhibit. Which value must be configured in the User Group field when the Cisco AnyConnect profile is created to connect to an ASA headend with IPsec as the primary pro...
AnyConnect profiletunnel-groupIPsec primary protocolASA headend - Question #32Site-to-site VPNs on Routers and Firewalls
Refer to the exhibit. What is configured as a result of this command set?
FlexVPN serverIPv6 dVTIdynamic VTIIKEv2 profile - Question #33Remote Access VPN
Which two types of web resources or protocols are enabled by default on the Cisco ASA Clientless SSL VPN portal? (Choose two.)
clientless SSL VPNdefault protocolsHTTPCIFS - Question #34Site-to-site VPNs on Routers and Firewalls
Which configuration construct must be used in a FlexVPN tunnel?
FlexVPNIKEv2 profiletunnel configurationrequired construct - Question #35Remote Access VPN
A Cisco AnyConnect client establishes a SSL VPN connection with an ASA at the corporate office. An engineer must ensure that the client computer meets the enterprise security polic...
Advanced Endpoint AssessmentAnyConnectendpoint compliancehost scan - Question #36Troubleshooting VPNs
Refer to the exhibit. The customer can establish an AnyConnect connection on the corporate office only. Subsequent attempts fail. What might be the issue?
AnyConnectUserGroupconnection profiletunnel-group mapping - Question #37Remote Access VPN
Regarding licensing, which option will allow IKEv2 connections on the adaptive security appliance?
ASA licensingAnyConnect EssentialsIKEv2license requirements - Question #38Remote Access VPN
Which two features provide headend resiliency for Cisco AnyConnect clients? (Choose two.)
AnyConnect resiliencybackup serversASA failoverheadend redundancy - Question #39Troubleshooting VPNs
Cisco AnyConnect Secure Mobility Client has been configured to use IKEv2 for one group of users and SSL for another group. When the administrator configures a new AnyConnect releas...
AnyConnect IKEv2client software updateclient servicesauto-download - Question #40Remote Access VPN
Under which section must a bookmark or URL list be configured on a Cisco ASA to be available for clientless SSLVPN users?
clientless SSL VPNbookmark listURL listgroup-policy webvpn - Question #41Troubleshooting Using ASDM and CLI
Refer to the exhibit. Based on the exhibit, why are users unable to access CCNP Webserver bookmark?
clientless SSL VPNDNS resolutionWebVPN bookmarksASA - Question #42Remote Access VPN
Which two statements about the Cisco ASA Clientless SSL VPN solution are true? (Choose two.)
clientless SSL VPNWebVPNDNS resolutionAnyConnect - Question #43Remote Access VPN
Which feature allows the ASA to handle nonstandard applications and web resources so that they display correctly over a clientless SSL VPN connection?
Smart Tunnelclientless SSL VPNnonstandard applicationsWebVPN - Question #44Remote Access VPN
Which command automatically initiates a smart tunnel when a user logs in to the WebVPN portal page?
Smart Tunnelauto-startWebVPN portalclientless SSL VPN - Question #45Remote Access VPN
Refer to the exhibit. The customer must launch Cisco AnyConnect in the RDP machine. Which IOS configuration accomplishes this task?
AnyConnectIOS FlexVPNVPN profileRDP - Question #46Remote Access VPN
Refer to the exhibit. Which two commands under the tunnel-group webvpn-attributes result in a Cisco AnyConnect user receiving the AnyConnect prompt in the exhibit? (Choose two.)
tunnel-groupwebvpn-attributesgroup-aliasAAA authentication - Question #47Remote Access VPN
Which two statements are true when designing a SSL VPN solution using Cisco AnyConnect? (Choose two.)
AnyConnectSSL VPN designDTLSIP address pool - Question #48Secure Communications
An engineer is configuring IPsec VPN and wants to choose an authentication protocol that is reliable and supports ACK and sequence. Which protocol accomplishes this goal?
ESPIPsecauthentication protocolACK and sequence - Question #49Troubleshooting Using ASDM and CLI
Refer to the exhibit. What is the problem with the IKEv2 site-to-site VPN tunnel?
IKEv2site-to-site VPNcrypto ACL mismatchtroubleshooting - Question #50Remote Access VPN
Which requirement is needed to use local authentication for Cisco AnyConnect Secure Mobility Clients that connect to a FlexVPN server?
FlexVPNAnyConnectlocal authenticationEAP