Cisco Implementing Secure Solutions with Virtual Private Networks - 300-730 Exam Practice Test

Question 1
Refer to the exhibit. A network security administrator receives this error message after configuring a site-to-site IPsec VPN between two sites What is the solution to this problem?

Correct Answer: A
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).
Question 2
An engineer notices that while an employee is connected remotely, all traffic is being routed to the corporate network. Which split-tunnel policy allows a remote client to use their local provider for Internet access when working from home?

Correct Answer: D
Question 3
Refer to the exhibit. The DMVPN tunnel is dropping randomly and no tunnel protection is configured.

Which spoke configuration mitigates tunnel drops?

Correct Answer: A
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).
Question 4
Which two statements are true when designing a SSL VPN solution using Cisco AnyConnect?
(Choose two.)

Correct Answer: B,C
Question 5
Which parameter in IPsec VPN tunnel configurations is optional?

Correct Answer: D
Question 6
An administrator is setting up Cisco AnyConnect on a Cisco ASA with the requirement that AnyConnect automatically establishes a VPN when a company-owned laptop is connected to the internet outside of the corporate network. Which configuration meets these requirements?

Correct Answer: D
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).
Question 7
Refer to the exhibit. A company has been using SAML to authenticate their clientless SSLVPN users. After about a year of uptime in production, users begin to experience issues authenticating. Based on the collected debugs, which action resolves the issue?

Correct Answer: D
Question 8
A network administrator is troubleshooting a FlexVPN tunnel. The hub router is unable to ping the spoke router's tunnel interface IP address of 192.168.1.2, even though the tunnel is showing up.
The output of the debug ip packet CLI command on the hub router shows the following entry.
IP: tableid=0123456789 s=192.168.1.1 (local), d=192.168.1.2 (loopback2), routed via FIB.
What must be configured to fix this issue?

Correct Answer: D
Question 9
An administrator is designing a VPN with a partner's non-Cisco VPN solution. The partner's VPN device will negotiate an IKEv2 tunnel that will only encrypt subnets 192.168.0.0/24 going to
10.0.0.0/24. Which technology must be used to meet these requirements?

Correct Answer: D
Question 10
Cisco AnyConnect Secure Mobility Client has been configured to use IKEv2 for one group of users and SSL for another group. When the administrator configures a new AnyConnect release on the Cisco ASA, the IKEv2 users cannot download it automatically when they connect. What might be the problem?

Correct Answer: A
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).
Question 11
Which technology works with IPsec stateful failover?

Correct Answer: A
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).
Question 12
Which is used by GETVPN, FlexVPN and DMVPN?

Correct Answer: B
Question 13
Refer to the exhibit. A new IPsec VPN tunnel has been configured and the security associations do not establish. After the show crypto isakmp command is run, the output is displayed. What must be reconfigured to resolve the issue?

Correct Answer: C
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).