Weekend Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: Board70

300-730 Exam Dumps - Cisco CCNP Security Questions and Answers

Question # 4

A DMVPN spoke is configured with IKEv1 to secure the tunnel. Despite having a configuration similar to other working spokes, the tunnel is not coming up. Packet captures on the spoke show packets leaving the spoke router, but not making it to the hub router. Which solution resolves this issue?

Options:

A.

Configure the spoke and hub to use the same IKE version.

B.

Ensure that devices between the hub and spoke are not blocking ESP traffic.

C.

Ensure that devices between the hub and spoke are not blocking GRE traffic.

D.

Enable the tunnel interface with the no shutdown command.

Buy Now
Question # 5

Refer to the exhibit.

The IKEv2 site-to-site VPN tunnel between two routers is down. Based on the debug output, which type of mismatch is the problem?

Options:

A.

preshared key

B.

peer identity

C.

transform set

D.

ikev2 proposal

Buy Now
Question # 6

An engineer is using DMVPN to provide secure connectivity between a data center and remote sites. Which two routing protocols should be used between the routers? (Choose two.)

Options:

A.

IS-IS

B.

BGP

C.

RIPv2

D.

OSPF

E.

EIGRP

Buy Now
Question # 7

An engineer is building an IKEv1 tunnel to a peer Cisco ASA, but the tunnel is failing. Based on the configuration in the exhibit, which action must be taken to allow the VPN tunnel to come up?

Options:

A.

Add a route for the 10.7.7.0/24 network to egress the outside interface.

B.

Enable IKEv1 on the outside interface.

C.

Change the IKEv1 policy number to be at least 256.

D.

Change the transform set mode to transport.

Buy Now
Question # 8

A network engineer is setting up a clientless SSLVPN on a Cisco ASA. Remote users must be able to access an internal webserver via the URL example.com. Which two steps accomplish this task? (Choose two.)

Options:

A.

Configure a bookmark for the webserver.

B.

Configure routing so that the user's computer can reach the webserver.

C.

Configure a DNS server that can resolve the webserver URL.

D.

Configure a browser plugin on the Cisco ASA.

E.

Configure routing so that the Cisco ASA can reach the webserver.

Buy Now
Question # 9

When troubleshooting FlexVPN spoke-to-spoke tunnels, what should be verified first?

Options:

A.

NHRP redirect is enabled on the hub.

B.

The spokes have sent a resolution request.

C.

NHRP cache entries exist on the spoke.

D.

NHO routes exist on the spokes.

Buy Now
Question # 10

A network engineer must design a clientless VPN solution for a company. VPN users must be able to access several internal web servers. When reachability to those web servers was tested, it was found that one website is not being rewritten correctly by the ASA. What is a potential solution for this issue while still allowing it to be a clientless VPN setup?

Options:

A.

Set up a smart tunnel with the IP address of the web server.

B.

Set up a NAT rule that translates the ASA public address to the web server private address on port 80.

C.

Set up Cisco AnyConnect with a split tunnel that has the IP address of the web server.

D.

Set up a WebACL to permit the IP address of the web server.

Buy Now
Question # 11

Drag and drop the GETVPN components from the left onto the descriptions on the right.

Options:

Buy Now
Question # 12

Users are getting untrusted server warnings when they connect to the URL https://asa.lab from their browsers. This URL resolves to 192.168.10.10, which is the IP address for a Cisco ASA configured for a clientless VPN. The VPN was recently set up and issued a certificate from an internal CA server. Users can connect to the VPN by ignoring the message, however, when users access other webservers that use certificates issued by the same internal CA server, they do not experience this issue. Which action resolves this issue?

Options:

A.

Import the CA that signed the certificate into the machine trusted root CA store.

B.

Reissue the certificate with asa.lab in the subject alternative name field.

C.

Import the CA that signed the certificate into the user trusted root CA store.

D.

Reissue the certificate with 192.168.10.10 in the subject common name field.

Buy Now
Question # 13

Refer to the exhibit.

An SSL client is connecting to an ASA headend. The session fails with the message “Connection attempt has timed out. Please verify Internet connectivity.” Based on how the packet is processed, which phase is causing the failure?

Options:

A.

phase 9: rpf-check

B.

phase 5: NAT

C.

phase 4: ACCESS-LIST

D.

phase 3: UN-NAT

Buy Now
Exam Code: 300-730
Exam Name: Implementing Secure Solutions with Virtual Private Networks (SVPN)
Last Update: Feb 22, 2025
Questions: 175
300-730 pdf

300-730 PDF

$28.5  $94.99
300-730 Engine

300-730 Testing Engine

$33  $109.99
300-730 PDF + Engine

300-730 PDF + Testing Engine

$43.5  $144.99