nerdexam
Cisco

350-701 · Question #150

Which protocol provides the strongest throughput performance when using Cisco AnyConnect VPN?

The correct answer is D. DTLSv1. By default, group policies on ASAs are configured to attempt establishing a DTLS tunnel. If UDP 443 traffic is blocked between the VPN headend and the AnyConnect client, it will automatically fallback to TLS. It is recommended to use DTLS or IKEv2 to increase maximum VPN…

Submitted by satoshi_tk· Mar 30, 2026Secure Network Access, Visibility, and Enforcement

Question

Which protocol provides the strongest throughput performance when using Cisco AnyConnect VPN?

Options

  • ATLSv1.2
  • BTLSv1
  • CTLSv1.1
  • DDTLSv1

How the community answered

(50 responses)
  • A
    6% (3)
  • B
    2% (1)
  • C
    4% (2)
  • D
    88% (44)

Explanation

By default, group policies on ASAs are configured to attempt establishing a DTLS tunnel. If UDP 443 traffic is blocked between the VPN headend and the AnyConnect client, it will automatically fallback to TLS. It is recommended to use DTLS or IKEv2 to increase maximum VPN throughput performance. DTLS offers better performance than TLS due to less protocol overhead. IKEv2 also offers better throughput than TLS. Additionally, using AES-GCM ciphers may slightly improve performance. These ciphers are available in TLS 1.2, DTLS 1.2 and IKEv2.

Topics

#AnyConnect VPN#DTLS#TLS#VPN performance

Community Discussion

No community discussion yet for this question.

Full 350-701 Practice