Pass the Cisco CCNP Security 300-730 Questions and answers with CertsForce

Viewing page 2 out of 5 pages
Viewing questions 11-20 out of questions
Questions # 11:

Which redundancy protocol must be implemented for IPsec stateless failover to work?

Options:

A.

SSO


B.

GLBP


C.

HSRP


D.

VRRP


Expert Solution
Questions # 12:

An engineer is configuring clientless SSL VPN. The finance department has a database server that only they should access, but the sales department can currently access it. The finance and the sales departments are configured as separate group-policies. What must be added to the configuration to make sure the users in the sales department cannot access the finance department server?

Options:

A.

tunnel group lock


B.

smart tunnel


C.

port forwarding


D.

webtype ACL


Expert Solution
Questions # 13:

A network administrator wants the Cisco ASA to automatically start downloading the Cisco AnyConnect client without prompting the user to select between WebVPN or AnyConnect. Which command accomplishes this task?

Options:

A.

anyconnect ssl df-bit-ignore enable


B.

anyconnect ask none default anyconnect


C.

anyconnect ask enable default anyconnect


D.

anyconnect modules value default


Expert Solution
Questions # 14:

Why must a network engineer avoid usage of the default X.509 certificate when implementing clientless SSLVPN on an ASA?

Options:

A.

The certificate must be managed by the local CA.


B.

The certificate is regenerated at each reboot.


C.

The default X.509 certificate is not supported for SSLVPN.


D.

The certificate is too weak to provide adequate security.


Expert Solution
Questions # 15:

Question # 15

Given the output of the show ip route command, which remote access VPN technology is in use?

Options:

A.

Reverse Route Injection


B.

FlexVPN


C.

Dynamic Crypto Map


D.

DMVPN


Expert Solution
Questions # 16:

Refer to the exhibit.

Question # 16

A network administrator is setting up a phone VPN on a Cisco ASA. The phone cannot connect and the error is presented in a debug on the Cisco ASA. Which action fixes this issue?

Options:

A.

Enable web-deploy of the posture module so that the module can be downloaded from the Cisco ASA to an IP phone.


B.

Configure the Cisco ASA to present an RSA certificate to the phone for authentication.


C.

Disable Cisco Secure Desktop under the connection profile VPNPhone.


D.

Install the posture module on the Cisco ASA.


Expert Solution
Questions # 17:

An engineer has integrated a new DMVPN to link remote offices across the internet using Cisco IOS routers. When connecting to remote sites, pings and voice data appear to flow properly, and all tunnel stats show that they are up. However, when trying to connect to a remote server using RDP, the connection fails. Which action resolves this issue?

Options:

A.

Adjust the MTU size within the routers.


B.

Add RDP port to the extended ACL.


C.

Replace certificate on the RDP server.


D.

Change DMVPN timeout values.


Expert Solution
Questions # 18:

A network engineer must expand a company's Cisco AnyConnect solution. Currently, a Cisco ASA is set up in North America and another will be installed in Europe with a different IP address. Users should connect to the ASA that has the lowest Round Trip Time from their network location as measured by the AnyConnect client. Which solution must be implemented to meet this requirement?

Options:

A.

VPN Load Balancing


B.

IP SLA


C.

DNS Load Balancing


D.

Optimal Gateway Selection


Expert Solution
Questions # 19:

An engineer is building an IKEv1 tunnel to a peer Cisco ASA, but the tunnel is failing. Based on the configuration in the exhibit, which action must be taken to allow the VPN tunnel to come up?

Question # 19

Options:

A.

Add a route for the 10.7.7.0/24 network to egress the outside interface.


B.

Enable IKEv1 on the outside interface.


C.

Change the IKEv1 policy number to be at least 256.


D.

Change the transform set mode to transport.


Expert Solution
Questions # 20:

An engineer is requesting an SSL certificate for a VPN load-balancing cluster in which two Cisco ASAs provide clientless SSLVPN access. The FQDN that users will enter to access the clientless VPN is asa.example.com, and users will be redirected to either asa1.example.com or asa2.example.com. The cluster FQDN and individual Cisco ASAs FQDNs resolve to IP addresses 192.168.0.1, 192.168.0.2, and 192.168.0.3 respectively. The issued certificate must be able to be used to validate the identity of either ASA in the cluster without returning any certificate validation errors. Which fields must be included in the certificate to meet these requirements?

Options:

A.

CN=*.example.com, SAN=asa.example.com


B.

CN=192.168.0.1, SAN=asa1.example.com, asa2.example.com


C.

CN=asa.example.com, SAN=asa.example.com, asa1.example.com, asa2.example.com


D.

CN=192.168.0.1, SAN=192.168.0.1, 192.168.0.2, 192.168.0.3


Expert Solution
Viewing page 2 out of 5 pages
Viewing questions 11-20 out of questions