TAKE CCNP Security 300-730 PRACTICE QUESTIONS FOR AMAZING RESULTS [Q48-Q66]

Share

TAKE CCNP Security 300-730 PRACTICE QUESTIONS FOR AMAZING RESULTS

 Cisco 300-730 Exam Dumps Are Essential To Get Good Marks

NEW QUESTION # 48
Which feature allows the ASA to handle nonstandard applications and web resources so that they display correctly over a clientless SSL VPN connection?

  • A. single sign-on
  • B. WebType ACL
  • C. plug-ins
  • D. Smart Tunnel

Answer: C

Explanation:
Plug-ins are extensions to the Clientless SSL VPN feature that enable the ASA to handle non-standard applications and Web resources so that they display correctly over a Clientless SSL VPN connection. Plug-ins are software components that the ASA downloads to the remote user's browser. The plug-ins provide support for applications and protocols that are not natively supported by Clientless SSL VPN, such as Java, ActiveX, SSH, Telnet, and RDP. Plug-ins can also provide enhanced functionality and security for Web applications, such as Outlook Web Access and Lotus iNotes.
You can read more about plug-ins and how to configure them in the document [ASDM Book 3: Cisco ASA Series VPN ASDM Configuration Guide, 7.7] 1.


NEW QUESTION # 49
Which two NHRP functions are specific to DMVPN Phase 3 implementation? (Choose two.)

  • A. redirect
  • B. resolution reply
  • C. resolution request
  • D. registration reply
  • E. registration request

Answer: C,E

Explanation:
Registration request is used by spoke routers to send a registration request to the hub router. The registration request includes the IP address of the spoke router and the protocol information. The hub router then sends a registration reply, which includes the IP address of the hub router.
Resolution request is used by spoke routers to send a resolution request to the hub router. The resolution request includes the IP address of the destination router. The hub router then sends a resolution reply, which includes the IP address of the destination router.


NEW QUESTION # 50
An engineer is requesting an SSL certificate for a VPN load-balancing cluster in which two Cisco ASAs provide clientless SSLVPN access. The FQDN that users will enter to access the clientless VPN is asa.example.com, and users will be redirected to either asa1.example.com or asa2.example.com. The cluster FQDN and individual Cisco ASAs FQDNs resolve to IP addresses 192.168.0.1, 192.168.0.2, and 192.168.0.3 respectively. The issued certificate must be able to be used to validate the identity of either ASA in the cluster without returning any certificate validation errors. Which fields must be included in the certificate to meet these requirements?

  • A. CN=asa.example.com, SAN=asa.example.com, asa1.example.com, asa2.example.com
  • B. CN=*.example.com, SAN=asa.example.com
  • C. CN=192.168.0.1, SAN=asa1.example.com, asa2.example.com
  • D. CN=192.168.0.1, SAN=192.168.0.1, 192.168.0.2, 192.168.0.3

Answer: A

Explanation:
https://integratingit.wordpress.com/2020/03/14/asa-vpn-load-balancing/


NEW QUESTION # 51
Refer to the exhibit.

Upon setting up a tunnel between two sites, users are complaining that connections to applications over the VPN are not working consistently. The output of show crypto ipsec sa was collected on one of the VPN devices. Based on this output, what should be done to fix this issue?

  • A. Specify the application networks in the remote identity.
  • B. Enable perfect forward secrecy.
  • C. Make an adjustment to IPSec replay window.
  • D. Lower the tunnel MTU.

Answer: D


NEW QUESTION # 52

Refer to the exhibit. Client 1 cannot communicate with client 2. Both clients are using Cisco AnyConnect and have established a successful SSL VPN connection to the hub ASA. Which command on the ASA is missing?

  • A. same-security-traffic permit intra-interface
  • B. dns-server value 10.1.1.2
  • C. dns-server value 10.1.1.3
  • D. same-security-traffic permit inter-interface

Answer: A

Explanation:
Section: Troubleshooting using ASDM and CLI


NEW QUESTION # 53
An engineer notices that while an employee is connected remotely, all traffic is being routed to the corporate network. Which split-tunnel policy allows a remote client to use their local provider for Internet access when working from home?

  • A. tunnelspecified
  • B. excludespecified
  • C. tunnelall
  • D. excludeall

Answer: A


NEW QUESTION # 54
Which benefit of FlexVPN is a limitation of DMVPN using IKEv1?

  • A. IKE implementation can install routes in routing table.
  • B. GRE encapsulation allows for forwarding of non-IP traffic.
  • C. Dynamic routing protocols can be configured.
  • D. NHRP authentication provides enhanced security.

Answer: A

Explanation:
Section: Secure Communications Architectures


NEW QUESTION # 55
Which two types of web resources or protocols are enabled by default on the Cisco ASA Clientless SSL VPN portal? (Choose two.)

  • A. ICA (Citrix)
  • B. RDP
  • C. HTTP
  • D. VNC
  • E. CIFS

Answer: B,E

Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/asa/asa94/config-guides/cli/vpn/asa-94-vpn-config/ webvpn-configure-gateway.html


NEW QUESTION # 56
Which VPN technology must be used to ensure that routers are able to dynamically form connections with each other rather than sending traffic through a hub and be able to advertise routes without the use of a dynamic routing protocol?

  • A. FlexVPN
  • B. DMVPN Phase 2
  • C. GETVPN
  • D. DMVPN Phase 3

Answer: D


NEW QUESTION # 57
Which redundancy protocol must be implemented for IPsec stateless failover to work?

  • A. VRRP
  • B. SSO
  • C. HSRP
  • D. GLBP

Answer: C


NEW QUESTION # 58
A network engineer must implement an SSLVPN Cisco AnyConnect solution that supports 500 concurrent users, ensures all traffic from the client passes through the ASA, and allows users to access all devices on the inside interface subnet (192.168.0.0/24). Assuming all other configuration is set up appropriately, which configuration implements this solution?

  • A. Option A
  • B. Option D
  • C. Option C
  • D. Option B

Answer: A


NEW QUESTION # 59
Which two components are required in a Cisco IOS GETVPN key server configuration? (Choose two.)

  • A. RSA key
  • B. L2TP protocol
  • C. IKE policy
  • D. SSL cipher
  • E. GRE tunnel

Answer: A,C


NEW QUESTION # 60
Which requirement is needed to use local authentication for Cisco AnyConnect Secure Mobility Clients that connect to a FlexVPN server?

  • A. EAP query-identity
  • B. use of certificates instead of username and password
  • C. EAP-AnyConnect
  • D. AnyConnect profile

Answer: C

Explanation:
https://www.cisco.com/c/en/us/support/docs/security/flexvpn/200555-FlexVPN-AnyConnect-IKEv2-Remote-Access.pdf


NEW QUESTION # 61
Refer to the exhibit.

What is configured as a result of this command set?

  • A. FlexVPN server to authorize groups by using an IPv6 external AAA
  • B. FlexVPN server for an IPv6 dVTI session
  • C. FlexVPN client profile for IPv6
  • D. FlexVPN server to authenticate IPv6 peers by using EAP

Answer: C


NEW QUESTION # 62
A network engineer has set up a FlexVPN server to terminate multiple FlexVPN clients. The VPN tunnels are established without issue. However, when a Change of Authorization is issued by the RADIUS server, the FlexVPN server does not update the authorization of connected FlexVPN clients. Which action resolves this issue?

  • A. Add the aaa server radius dynamic-author command on the FlexVPN server.
  • B. Fix the RADIUS key mismatch between the RADIUS server and FlexVPN clients.
  • C. Add the aaa server radius dynamic-author command on the FlexVPN clients.
  • D. Fix the RADIUS key mismatch between the RADIUS server and FlexVPN server.

Answer: A

Explanation:
https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_ike2vpn/configuration/xe-16-10/sec-flex-vpn-xe-16-10-book/sec-ikev2-flex-coa.html


NEW QUESTION # 63
Refer to the exhibit.

The DMVPN spoke is not establishing a session with the hub. Which two actions resolve this issue? (Choose two.)

  • A. Change the transform set to mode tunnel.
  • B. Change the spoke nhs to 172.16.18.1 and the nbma to 10.0.0.1.
  • C. Change the nhrp authentication key on the spoke to cisco123.
  • D. Change the ISAKMP key address on the spoke to 0.0.0.0.
  • E. Change the ISAKMP policy authentication on the spoke to pre-shared.

Answer: C,D


NEW QUESTION # 64
Refer to the exhibit.

Which type of Cisco VPN is shown for group Cisc012345678?

  • A. Clientless SSLVPN
  • B. Cisco AnyConnect Client VPN
  • C. DMVPN
  • D. GETVPN

Answer: B


NEW QUESTION # 65
Which IKE identity does an IOS/IOS-XE headend expect to receive if an IPsec Cisco AnyConnect client uses default settings?

  • A. *$DfltlkeldentityS*
  • B. *$AnyConnectClient$*
  • C. *$RemoteAccessVpnClient$*
  • D. *$SecureMobilityClient$*

Answer: B


NEW QUESTION # 66
......

Latest Cisco 300-730 Dumps with Test Engine and PDF (New Questions): https://www.vceengine.com/300-730-vce-test-engine.html

Pass Your 300-730 Exam Easily - Real 300-730 Practice Dump Updated: https://drive.google.com/open?id=1bzwvNR5f5w725DbxTJkQLxiWFSdqpZ67