Cisco Implementing Secure Solutions with Virtual Private Networks 300-730 SVPN Exam Questions

Page: 1 / 14
Total 175 questions
Question 1

A network engineer has set up a FlexVPN server to terminate multiple FlexVPN clients. The VPN tunnels are established without issue. However, when a Change of Authorization is issued by the RADIUS server, the FlexVPN server does not update the authorization of connected FlexVPN clients. Which action resolves this issue?



Answer : C

https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_ike2vpn/configuration/xe-16-10/sec-flex-vpn-xe-16-10-book/sec-ikev2-flex-coa.html


Question 2

A network engineer has almost finished setting up a clientless VPN that allows remote users to access internal HTTP servers. Users must enter their username and password twice: once on the clientless VPN web portal and again to log in to internal HTTP servers. The Cisco ASA and the HTTP servers use the same Active Directory server to authenticate users. Which next step must be taken to allow users to enter their password only once?



Answer : B

https://www.cisco.com/c/en/us/support/docs/security-vpn/webvpn-ssl-vpn/119417-config-asa-00.html#anc17


Question 3

Which two changes must be made in order to migrate from DMVPN Phase 2 to Phase 3 when EIGRP is configured? (Choose two.)



Answer : D, E

DMVPN disables the EIRGP next-hop-self with 'no ip next-hop-self eigrp xxx' in DMVPN phase 2, and to go from Phase 2 to 3 you need use the NHRP protocol, and again enable EIRGP next-hop-self with 'ip next-hop-self eigrp 134' under the tunnel interface https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_dmvpn/configuration/15-mt/sec-conn-dmvpn-15-mt-book/sec-conn-dmvpn-dmvpn.html#GUID-BF561439-BCC0-4AAF-80D9-1F7876CB7B81


Question 4

A DMVPN spoke router tunnel is up and passing traffic, but it cannot establish an EIGRP neighbor relationship with the hub router. Which solution resolves this issue?



Answer : D

DMVPN is an NBMA network, which doesn't support multicast at all. The only reason we can get it working to the hub is because of the nhrp multicast command we add to the tunnel interface.


Question 5

When a FlexVPN is configured, which two components must be configured for IKEv2? (Choose two.)



Answer : B, C

https://www.cisco.com/c/en/us/support/security/flexvpn/products-configuration-examples-list.html


Question 6

An administrator must guarantee that remote access users are able to reach printers on their local LAN after a VPN session is established to the headquarters. All other traffic should be sent over the tunnel. Which split-tunnel policy reduces the configuration on the ASA headend?



Answer : B

You could in theory 'tunnel specified' and list every subnet aside from the local one in the split tunnel list, but that is cumbersome and clearly not the best answer from the 'reduce the configuration' requirement. Exclude only the local subnet and continue with your day.


Question 7

A network engineer is configuring a server. The router will terminate encrypted VPN connections on g0/0, which is in the VRF "Internet". The clear-text traffic that must be encrypted before being sent out traverses g0/1, which is in the VRF "Internal". Which two VRF-specific configurations allow VPN traffic to traverse the VRF-aware interfaces? (Choose two.)



Answer : D, E

https://www.cisco.com/c/en/us/support/docs/security/flexvpn/116000-flexvpn-config-00.html

crypto ikev2 profile CProfile

match fvrf internet // ('out vrf')

...

virtual-template 1

...

interface virtual-template 1 type tunnel

vrf forwarding internal // (internal vrf)

...

tunnel vrf internet // (out vrf)


Page:    1 / 14   
Total 175 questions