Cisco

300-730 practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 153-question bank.

Provider
Cisco
Question bank
153
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for 300-730, a certification listed under Cisco. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Cisco. The certification credential is issued by Cisco, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    Refer to the exhibit. A TCP based application that should be accessible over the VPN tunnel is not working. Pings to the appropriate IP address are failing. Based on the output, what is a fix for this issue?

    Choose one answer.

    Question illustration 1
    • Add a route on the remote peer for 209.165.201.0/27.
    • Add a route on the local peer for 10.1.1.0/24.
    • Add a permit for TCP traffic going to 10.1.1.0/24.
    • Add a permit for TCP traffic going to 209.165.201.0/27.
  2. Question 2 · 1

    A network engineer must expand a company's Cisco AnyConnect solution. Currently, a Cisco ASA is set up in North America and another will be installed in Europe with a different IP address. Users should connect to the ASA that has the lowest Round Trip Time from their network location as measured by the AnyConnect client. Which solution must be implemented to meet this requirement?

    Choose one answer.

    • VPN Load Balancing
    • IP SLA
    • DNS Load Balancing
    • Optimal Gateway Selection
  3. Question 3 · 1

    Refer to the exhibit. An engineer is diagnosing an issue that occurred after a router at a branch site was assigned a new address. Based on the debugs, what must be done to resolve this issue?

    Choose one answer.

    Question illustration 1
    • Add the remote peer’s IP address to the server's IKEv2 keyring.
    • Ensure that the correct preshared keys are set on both sides.
    • Ensure that the UDP 500 packets between devices are not dropped.
    • Add the remote peer’s identity to the server’s IKEv2 profile.
  4. Question 4 · 1

    A network engineer is setting up a clientless SSLVPN on a Cisco ASA. Remote users must be able to access an internal webserver via the URL example.com. Which two steps accomplish this task? (Choose two.)

    Choose all answers that apply.

    • Configure a bookmark for the webserver.
    • Configure routing so that the user's computer can reach the webserver.
    • Configure a DNS server that can resolve the webserver URL.
    • Configure a browser plugin on the Cisco ASA.
    • Configure routing so that the Cisco ASA can reach the webserver.
  5. Question 5 · 1

    A network engineer has set up a FlexVPN server to terminate multiple FlexVPN clients. The VPN tunnels are established without issue. However, when a Change of Authorization is issued by the RADIUS server, the FlexVPN server does not update the authorization of connected FlexVPN clients. Which action resolves this issue?

    Choose one answer.

    • Add the aaa server radius dynamic-author command on the FlexVPN clients.
    • Fix the RADIUS key mismatch between the RADIUS server and FlexVPN server.
    • Add the aaa server radius dynamic-author command on the FlexVPN server.
    • Fix the RADIUS key mismatch between the RADIUS server and FlexVPN clients.
  6. Question 6 · 1

    A company needs to ensure only corporate issued laptops and devices are allowed to connect with the Cisco AnyConnect client. The solution should be applicable to multiple operating systems, including Windows, MacOS, and Linux, and should allow for remote remediation if a corporate issued device is stolen. Which solution should be used to accomplish these goals?

    Choose one answer.

    • Use a DAP registry check on the system to determine the relationship with the corporate domain.
    • Use a DAP file check on the system to determine the relationship with the corporate domain.
    • Install and authenticate user certificates on the corporate devices.
    • Install and authenticate machine certificates on the corporate devices
  7. Question 7 · 1

    When a FlexVPN is configured, which two components must be configured for IKEv2? (Choose two.)

    Choose all answers that apply.

    • method
    • profile
    • proposal
    • preference
    • persistence
  8. Question 8 · 1

    A DMVPN spoke router tunnel is up and passing traffic, but it cannot establish an EIGRP neighbor relationship with the hub router. Which solution resolves this issue?

    Choose one answer.

    • Enable EIGRP Split Horizon on the hub tunnel interface.
    • Remove the EIGRP stub configuration on the spoke tunnel interface.
    • Enable the EIGRP next hop self feature on the hub tunnel interface.
    • Configure the dynamic NHRP multicast map on the hub tunnel interface.
  9. Question 9 · 1

    Refer to the exhibit. An IPsec Cisco AnyConnect client is failing to connect and generates these debugs every time a connection to an IOS headend is attempted. Which action resolves this issue?

    Choose one answer.

    Question illustration 1
    • Correct the DH group setting.
    • Correct the PFS setting.
    • Correct the integrity setting.
    • Correct the encryption setting.
  10. Question 10 · 1

    Refer to the exhibit. An engineer must allow Cisco AnyConnect users to access the outside interface using protocol UDP 500/4500. In addition, these clients must be able to establish an SSL connection to update Cisco AnyConnect software over the same connection. Which two actions must be taken to achieve this goal? (Choose two.)

    Choose all answers that apply.

    Question illustration 1
    • IPsec (IKEv2) Allow Access must be checked on the outside interface.
    • SSL Enable DTLS must be checked on the outside interface.
    • Bypass interface access lists for inbound VPN sessions must be unchecked.
    • IPsec (IKEv2) Enable Client Services must be checked on the outside interface.
    • SSL Allow Access must be checked on the outside interface.
  11. Question 11 · 1

    Refer to the exhibit. Based on the configuration output, what is the VPN technology?

    Choose one answer.

    Question illustration 1
    • site-to-site
    • DMVPN
    • L2VPN
    • multicast VPN
  12. Question 12 · 1

    A user at a company HQ is having trouble accessing a network share at a branch site that is connected with a L2L IPsec VPN. While troubleshooting, a network security engineer runs a packet tracer on the Cisco ASA to simulate the user traffic and discovers that the encryption counter is increasing but the decryption counter is not. What must be configured to correct this issue?

    Choose one answer.

    • Adjust the routing on the remote peer device to direct traffic back over the tunnel.
    • Adjust the preshared key on the remote peer to allow traffic to flow over the tunnel.
    • Adjust the transform set to allow bidirectional traffic.
    • Adjust the peer IP address on the remote peer to direct traffic back to the ASA.
  13. Question 13 · 1

    A user is experiencing delays on audio calls over a Cisco AnyConnect VPN. Which implementation step resolves this issue?

    Choose one answer.

    • Change to 3DES Encryption.
    • Shorten the encryption key lifetime.
    • Install the Cisco AnyConnect 2.3 client for the user to download.
    • Enable DTLS.
  14. Question 14 · 1

    Users cannot log in to a Cisco ASA using clientless SSLVPN. Troubleshooting reveals the error message "WebVPN session terminated: Client type not supported". Which step does the administrator take to resolve this issue?

    Choose one answer.

    • Enable the Cisco AnyConnect premium license on the Cisco ASA.
    • Have the user upgrade to a supported browser.
    • Increase the simultaneous logins on the group policy.
    • Enable the clientless VPN protocol on the group policy.
  15. Question 15 · 1

    An administrator is setting up a VPN on an ASA for users who need to access an internal RDP server. Due to security restrictions, the Microsoft RDP client is blocked from running on client workstations via Group Policy. Which VPN feature should be implemented by the administrator to allow these users to have access to the RDP server?

    Choose one answer.

    • clientless proxy
    • smart tunneling
    • clientless plug-in
    • clientless rewriter

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free