Cisco® 300-730 Exam Practice Questions (P. 2)
- Full Access (224 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #6

Refer to the exhibit. Which two tunnel types produce the show crypto ipsec sa output seen in the exhibit? (Choose two.)
send
light_mode
delete
Question #7
Which two changes must be made in order to migrate from DMVPN Phase 2 to Phase 3 when EIGRP is configured? (Choose two.)
- AAdd NHRP shortcuts on the hub.
- BAdd NHRP redirects on the spoke.
- CDisable EIGRP next-hop-self on the hub.
- DEnable EIGRP next-hop-self on the hub.
- EAdd NHRP redirects on the hub.
Correct Answer:
CE
CE

In DMVPN Phase 3 with EIGRP, the key adjustments involve how routing information is handled by the hub. Specifically, disabling the EIGRP next-hop-self on the hub is crucial. This function, when active, causes the hub to advertise its own IP as the next hop for data heading to spoke routers; disabling it permits direct spoke-to-spoke routing without hub intervention. Another important feature is implementing NHRP redirects on the hub, which facilitates this direct spoke-to-spoke communication by informing spoke routers that a direct path is preferable over routing through the hub.
send
light_mode
delete
Question #8

Refer to the exhibit. A customer cannot establish an IKEv2 site-to-site VPN tunnel between two Cisco ASA devices. Based on the syslog message, which action brings up the VPN tunnel?
- AReduce the maximum SA limit on the local Cisco ASA.
- BIncrease the maximum in-negotiation SA limit on the local Cisco ASA.
- CRemove the maximum SA limit on the remote Cisco ASA.
- DCorrect the crypto access list on both Cisco ASA devices.
Correct Answer:
B
B
send
light_mode
delete
Question #9
Which two parameters help to map a VPN session to a tunnel group without using the tunnel-group list? (Choose two.)
- Agroup-aliasMost Voted
- Bcertificate map
- Coptimal gateway selection
- Dgroup-urlMost Voted
- EAnyConnect client version
Correct Answer:
BD
BD

The correct answers, certificate map and group-url, enable VPN sessions to be linked directly to specific tunnel groups without using a tunnel-group list. Certificate maps utilize data from a user's certificate to direct sessions into the appropriate tunnel group. The group-url function permits a user to access a VPN via a specific URL, automatically associating them with its respective tunnel group. These mechanisms streamline the process, enhancing both security and user experience, by bypassing the need for manual selection from a tunnel-group list.
send
light_mode
delete
Question #10
Which method dynamically installs the network routes for remote tunnel endpoints?
- Apolicy-based routing
- BCEF
- Creverse route injection
- Droute filtering
Correct Answer:
C
Reference:
https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_vpnav/configuration/12-4t/sec-vpn-availability-12-4t-book/sec-rev-rte-inject.html
C
Reference:
https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_vpnav/configuration/12-4t/sec-vpn-availability-12-4t-book/sec-rev-rte-inject.html
send
light_mode
delete
All Pages