nerdexam
Cisco

350-701 · Question #730

An engineer must modify an existing remote access VPN using a Cisco AnyConnect Secure Mobility client solution and a Cisco Secure Firewall. Currently, all the traffic generated by the user is sent…

The correct answer is D. group policy. To exclude specific server traffic from a Cisco AnyConnect VPN tunnel and allow direct access, the group policy on the Cisco Secure Firewall must be modified to implement split tunneling.

Submitted by tom_us· Mar 30, 2026

Question

An engineer must modify an existing remote access VPN using a Cisco AnyConnect Secure Mobility client solution and a Cisco Secure Firewall. Currently, all the traffic generated by the user is sent to the VPN tunnel and the engineer must now exclude some servers and access them directly instead. Which element must be modified to achieve this goal?

Options

  • ANAT exemption
  • Bencryption domain
  • Crouting table
  • Dgroup policy

How the community answered

(24 responses)
  • A
    13% (3)
  • B
    8% (2)
  • C
    4% (1)
  • D
    75% (18)

Why each option

To exclude specific server traffic from a Cisco AnyConnect VPN tunnel and allow direct access, the group policy on the Cisco Secure Firewall must be modified to implement split tunneling.

ANAT exemption

NAT exemption prevents NAT from occurring for traffic within the VPN, but it does not control whether traffic is initially directed into or out of the VPN tunnel.

Bencryption domain

The encryption domain defines which traffic is encrypted by the VPN, but for AnyConnect, the more granular control over what client-initiated traffic enters the tunnel is managed through split tunneling within the group policy.

Crouting table

While the client's routing table is updated by the VPN connection, the administrative control to modify these client-side routing directives for specific traffic exclusions resides within the firewall's group policy configuration.

Dgroup policyCorrect

In a Cisco AnyConnect VPN deployment, split tunneling behavior, which dictates what traffic goes through the VPN tunnel versus what traffic accesses the local network directly, is configured within the group policy on the Cisco Secure Firewall. Modifying the group policy's split tunneling network list will achieve the goal of excluding specific servers.

Concept tested: Cisco AnyConnect split tunneling configuration

Source: https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/118314-configure-asa-anyconnect-00.html

Topics

#Cisco AnyConnect#Remote Access VPN#Split Tunneling#Group Policy

Community Discussion

No community discussion yet for this question.

Full 350-701 Practice