Practice with 300-730 Dumps for CCNP Security Certified Exam Questions & Answer
REAL 300-730 Exam Questions With 100% Refund Guarantee
Cisco 300-730 exam is a crucial step for professionals who want to specialize in implementing secure solutions with VPNs. By passing 300-730 exam, candidates demonstrate their knowledge and skills in implementing secure VPN solutions, which are essential for organizations that require secure remote access and site-to-site communications.
NEW QUESTION # 94
Which redundancy protocol must be implemented for IPsec stateless failover to work?
- A. GLBP
- B. VRRP
- C. HSRP
- D. SSO
Answer: C
Explanation:
Reference:
https://www.cisco.com/c/en/us/support/docs/security-vpn/ipsec-negotiation-ike-protocols/17826- ipsec-feat.html
NEW QUESTION # 95
Which two changes must be made in order to migrate from DMVPN Phase 2 to Phase 3 when EIGRP is configured? (Choose two.)
- A. Add NHRP redirects on the spoke.
- B. Add NHRP shortcuts on the hub.
- C. Disable EIGRP next-hop-self on the hub.
- D. Enable EIGRP next-hop-self on the hub.
- E. Add NHRP redirects on the hub.
Answer: C,E
NEW QUESTION # 96
Which feature allows the ASA to handle nonstandard applications and web resources so that they display correctly over a clientless SSL VPN connection?
- A. Smart Tunnel
- B. WebType ACL
- C. plug-ins
- D. single sign-on
Answer: A
NEW QUESTION # 97
Refer to the exhibit.
The VPN tunnel between the FlexVPN spoke and FlexVPN hub 192.168.0.12 is failing. What should be done to correct this issue?
- A. Add the address 192.168.0.12 255.255.255.255 command to the keyring configuration.
- B. Add the aaa authorization group psk list Flex_AAA Flex_Auth command to the IKEv2 profile configuration.
- C. Add the tunnel mode gre ip command to the tunnel configuration.
- D. Add the match fvrf any command to the IKEv2 policy.
Answer: B
NEW QUESTION # 98
Refer to the exhibit.
A network engineer is configuring a remote access SSLVPN and is unable to complete the connection using local credentials. What must be done to remediate this problem?
- A. Enable the client protocol in the Cisco AnyConnect profile.
- B. Configure a AAA server group to authenticate the client.
- C. Change the authentication method to local.
- D. Configure the group policy to force local authentication.
Answer: A
NEW QUESTION # 99
Which VPN technology must be used to ensure that routers are able to dynamically form connections with each other rather than sending traffic through a hub and be able to advertise routes without the use of a dynamic routing protocol?
- A. DMVPN Phase 2
- B. FlexVPN
- C. DMVPN Phase 3
- D. GETVPN
Answer: C
NEW QUESTION # 100
An engineer is using DMVPN to provide secure connectivity between a data center and remote sites. Which two routing protocols should be used between the routers? (Choose two.)
- A. EIGRP
- B. OSPF
- C. BGP
- D. IS-IS
- E. RIPv2
Answer: A,C
NEW QUESTION # 101
Under which section must a bookmark or URL list be configured on a Cisco ASA to be available for clientless SSLVPN users?
- A. tunnel-group (webvpn-attributes)
- B. tunnel-group (general-attributes)
- C. webvpn (global configuration)
- D. webvpn (group-policy)
Answer: C
NEW QUESTION # 102
A DMVPN spoke router tunnel is up and passing traffic, but it cannot establish an EIGRP neighbor relationship with the hub router. Which solution resolves this issue?
- A. Enable EIGRP Split Horizon on the hub tunnel interface.
- B. Enable the EIGRP next hop self feature on the hub tunnel interface.
- C. Remove the EIGRP stub configuration on the spoke tunnel interface.
- D. Configure the dynamic NHRP multicast map on the hub tunnel interface.
Answer: D
Explanation:
DMVPN is an NBMA network, which doesn't support multicast at all. The only reason we can get it working to the hub is because of the nhrp multicast command we add to the tunnel interface.
NEW QUESTION # 103
Refer to the exhibit.
Which type of VPN implementation is displayed?
- A. IKEv2 load balancer
- B. IKEv2 reconnect
- C. IKEv2 backup gateway
- D. IKEv1 cluster
Answer: A
NEW QUESTION # 104
Refer to the exhibit.
An SSL client is connecting to an ASA headend. The session fails with the message "Connection attempt has timed out. Please verify Internet connectivity." Based on how the packet is processed, which phase is causing the failure?
- A. phase 3: UN-NAT
- B. phase 9: rpf-check
- C. phase 4: ACCESS-LIST
- D. phase 5: NAT
Answer: A
NEW QUESTION # 105
Refer to the exhibit.
A network engineer is reconfiguring clientless SSLVPN during a maintenance window, and after testing the new configuration, is unable to establish the connection. What must be done to remediate this problem?
- A. Enable clientless protocol under the group policy.
- B. Enable DTLS under the group policy.
- C. Enable client services on the outside interface.
- D. Enable auto sign-on for the user's IP address.
Answer: A
NEW QUESTION # 106
Where is split tunneling defined for IKEv2 remote access clients on a Cisco router?
- A. IKEv2 authorization policy
- B. virtual template
- C. webvpn context
- D. Group Policy
Answer: A
Explanation:
https://www.cisco.com/c/en/us/support/docs/routers/3600-series-multiservice-platforms/91193-rtr-ipsec-internet-connect.html
NEW QUESTION # 107
An engineer must configure remote desktop connectivity for offsite admins via clientless SSL VPN, configured on a Cisco ASA to Windows Vista workstations. Which two configurations provide the requested access? (Choose two.)
- A. Telnet bookmark via the Telnet plugin
- B. Citrix bookmark via the ICA plugin
- C. SSH bookmark via the SSH plugin
- D. RDP2 bookmark via the RDP2 plugin
- E. VNC bookmark via the VNC plugin
Answer: D,E
NEW QUESTION # 108
An administrator is designing a VPN with a partner's non-Cisco VPN solution. The partner's VPN device will negotiate an IKEv2 tunnel that will only encrypt subnets 192.168.0.0/24 going to 10.0.0.0/24. Which technology must be used to meet these requirements?
- A. VTI
- B. DMVPN
- C. crypto map
- D. GETVPN
Answer: C
NEW QUESTION # 109
Refer to the exhibit.
A Cisco ASA is configured as a client to a router running as a FlexVPN server. The router is configured with a virtual template to terminate FlexVPN clients. Traffic between networks 192.168.0.0/24 and 172.16.20.0/24 does not work as expected. Based on the show crypto ikev2 sa output collected from the Cisco ASA in the exhibit, what is the solution to this issue?
- A. Modify the crypto ACL on the router to permit network 172.16.20.0/24 to network 192.168.0.0/24.
- B. Modify the crypto ACL on the ASA to permit network 192.168.0.0/24 to network 172.16.20.0/24.
- C. Modify the crypto ACL on the ASA to permit network 172.16.20.0/24 to network 192.168.0.0/24.
- D. Modify the crypto ACL on the router to permit network 192.168.0.0/24 to network 172.16.20.0/24.
Answer: B
Explanation:
the show crypto ukev2 sa output from the ASA, the local selector is 192.168.0.0/24 the remote selector is 172.16.2.0/24 ( which is wrong , should be .20.0/24) . so , the ACL in the ASA should be to permit 192.168.0.0/24 to 172.16.20.0/24
NEW QUESTION # 110
......
PDF Download Cisco Test To Gain Brilliante Result!: https://itcertspass.prepawayexam.com/Cisco/braindumps.300-730.ete.file.html