Pass the Cisco CCNP Security 300-730 Questions and answers with CertsForce

Viewing page 5 out of 5 pages
Viewing questions 41-50 out of questions
Questions # 41:

Refer to the exhibit.

Question # 41

Client 1 cannot communicate with client 2. Both clients are using Cisco AnyConnect and have established a successful SSL VPN connection to the hub ASA. Which command on the ASA is missing?

Options:

A.

dns-server value 10.1.1.2


B.

same-security-traffic permit intra-interface


C.

same-security-traffic permit inter-interface


D.

dns-server value 10.1.1.3


Expert Solution
Questions # 42:

Refer to the exhibit.

Question # 42

Which type of mismatch is causing the problem with the IPsec VPN tunnel?

Options:

A.

crypto access list


B.

Phase 1 policy


C.

transform set


D.

preshared key


Expert Solution
Questions # 43:

In a FlexVPN deployment, the spokes successfully connect to the hub, but spoke-to-spoke tunnels do not form. Which troubleshooting step solves the issue?

Options:

A.

Verify the spoke configuration to check if the NHRP redirect is enabled.


B.

Verify that the spoke receives redirect messages and sends resolution requests.


C.

Verify the hub configuration to check if the NHRP shortcut is enabled.


D.

Verify that the tunnel interface is contained within a VRF.


Expert Solution
Questions # 44:

An engineer is troubleshooting a new DMVPN setup on a Cisco IOS router. After the show crypto isakmp sa command is issued, a response is returned of "MM_NO_STATE." Why does this failure occur?

Options:

A.

The ISAKMP policy priority values are invalid.


B.

ESP traffic is being dropped.


C.

The Phase 1 policy does not match on both devices.


D.

Tunnel protection is not applied to the DMVPN tunnel.


Expert Solution
Viewing page 5 out of 5 pages
Viewing questions 41-50 out of questions