Weekend Special Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: scxmas70

300-730 Exam Dumps - Implementing Secure Solutions with Virtual Private Networks (SVPN)

Go to page:
Question # 41

Which technology works with IPsec stateful failover?

A.

GLBR

B.

HSRP

C.

GRE

D.

VRRP

Full Access
Question # 42

Which two remote access VPN solutions support SSL? (Choose two.)

A.

FlexVPN

B.

clientless

C.

EZVPN

D.

L2TP

E.

Cisco AnyConnect

Full Access
Question # 43

Which component must be configured on routers for a GETVPN deployment work properly?

A.

PE3: Key Server – Customer 2 CEs: Group Members

B.

Customer 1 CE1: Key Server – R1 and Customer 1 CE2: Group Members

C.

R1: Key Server – Customer 1 CEs: Group Members

D.

PE3: Key Server – all CEs: Group Members

Full Access
Question # 44

A network engineer is implementing a FlexVPN tunnel between two Cisco IOS routers. The FlexVPN tunnels will terminate on encrypted traffic on an interface configured with an IP MTU of 1500, and the company has a security policy to drop fragmented traffic coming into or leaving the network. The tunnel will be used to transfer TFTP data between users and internal servers. When the TFTP traffic is not traversing a VPN, it can have a maximum IP packet size of 1500. Assuming the encrypted payload will add 90 bytes, which configuration allows TFTP traffic to traverse the FlexVPN tunnel without being dropped?

A.

Set the tunnel IP MTU to 1500.

B.

Set the tunnel tcp adjust-mss to 1460.

C.

Set the tunnel IP MTU to 1400.

D.

Set the tunnel tcp adjust-mss to 1360.

Full Access
Question # 45

Which two types of SSO functionality are available on the Cisco ASA without any external SSO servers? (Choose two.)

A.

SAML

B.

NTLM

C.

Kerberos

D.

OAuth 2.0

E.

HTTP Basic

Full Access
Question # 46

Users are getting untrusted server warnings when they connect to the URL https://asa.lab from their browsers. This URL resolves to 192.168.10.10, which is the IP address for a Cisco ASA configured for a clientless VPN. The VPN was recently set up and issued a certificate from an internal CA server. Users can connect to the VPN by ignoring the message, however, when users access other webservers that use certificates issued by the same internal CA server, they do not experience this issue. Which action resolves this issue?

A.

Import the CA that signed the certificate into the machine trusted root CA store.

B.

Reissue the certificate with asa.lab in the subject alternative name field.

C.

Import the CA that signed the certificate into the user trusted root CA store.

D.

Reissue the certificate with 192.168.10.10 in the subject common name field.

Full Access
Question # 47

A user is trying to log in to a Cisco ASA using the clientless SSLVPN feature and receives the error message "clientless (browser) SSLVPN access is not allowed". Which step should the Cisco ASA administrator take to resolve this issue?

A.

Enable the clientless VPN protocol on the group policy.

B.

Validate that the correct license is in use on the ASA for WebVPN.

C.

Increase the number of simultaneous logins allowed on the group policy.

D.

Verify that a user account exists in the local AAA database for the user.

Full Access
Question # 48

Refer to the exhibit.

The IKEv2 site-to-site VPN tunnel between two routers is down. Based on the debug output, which type of mismatch is the problem?

A.

preshared key

B.

peer identity

C.

transform set

D.

ikev2 proposal

Full Access
Go to page: