Black Friday Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: Board70

Free 300-730 Questions Attempt

Page: 4 / 12
Question 16

When troubleshooting FlexVPN spoke-to-spoke tunnels, what should be verified first?

Options:

A.

NHRP redirect is enabled on the hub.

B.

The spokes have sent a resolution request.

C.

NHRP cache entries exist on the spoke.

D.

NHO routes exist on the spokes.

Question 17

An engineer is building an IKEv1 tunnel to a peer Cisco ASA, but the tunnel is failing. Based on the configuration in the exhibit, which action must be taken to allow the VPN tunnel to come up?

Options:

A.

Add a route for the 10.7.7.0/24 network to egress the outside interface.

B.

Enable IKEv1 on the outside interface.

C.

Change the IKEv1 policy number to be at least 256.

D.

Change the transform set mode to transport.

Question 18

A network engineer is setting up Cisco AnyConnect 4.9 on a Cisco ASA running ASA software 9.1. Cisco AnyConnect must connect to the Cisco ASA before the user logs on so that login scripts can work successfully. In addition, the VPN must connect without user intervention. Which two key steps accomplish this task? (Choose two.)

Options:

A.

Create a Network Access Manager profile with a client policy set to connect before user logon.

B.

Create a Cisco AnyConnect VPN profile with Start Before Logon set to true.

C.

Issue an identity certificate to the trusted root CA folder in the machine store.

D.

Create a Cisco AnyConnect VPN profile with Always On set to true.

E.

Create a Cisco Anyconnect VPN Management Tunnel profile.

Question 19

A DMVPN spoke is configured with IKEv1 to secure the tunnel. Despite having a configuration similar to other working spokes, the tunnel is not coming up. Packet captures on the spoke show packets leaving the spoke router, but not making it to the hub router. Which solution resolves this issue?

Options:

A.

Configure the spoke and hub to use the same IKE version.

B.

Ensure that devices between the hub and spoke are not blocking ESP traffic.

C.

Ensure that devices between the hub and spoke are not blocking GRE traffic.

D.

Enable the tunnel interface with the no shutdown command.

Page: 4 / 12
Exam Code: 300-730
Exam Name: Implementing Secure Solutions with Virtual Private Networks (SVPN)
Last Update: Nov 23, 2024
Questions: 175
300-730 pdf

300-730 PDF

$28.5  $94.99
300-730 Engine

300-730 Testing Engine

$33  $109.99
300-730 PDF + Engine

300-730 PDF + Testing Engine

$43.5  $144.99