Which two changes must be made in order to migrate from DMVPN Phase 2 to Phase 3 when EIGRP is configured? (Choose two.)
Which two changes must be made in order to migrate from DMVPN Phase 2 to Phase 3 when EIGRP is configured? (Choose two.)A . Add NHRP shortcuts on the hub.B . Add NHRP redirects on the spoke.C . Disable EIGRP next-hop-self on the hub.D . Enable EIGRP next-hop-self on the...
Which two statements about the Cisco ASA Clientless SSL VPN solution are true? (Choose two.)
Which two statements about the Cisco ASA Clientless SSL VPN solution are true? (Choose two.)A . When a client connects to the Cisco ASA WebVPN portal and tries to access HTTP resources through the URL bar, the client uses the local DNS to perform FQDN resolution.B . The rewriter enable...
Which IOS configuration accomplishes this task?
Refer to the exhibit. The customer must launch Cisco AnyConnect in the RDP machine. Which IOS configuration accomplishes this task? A) B) C) D) A . Option AB . Option BC . Option CD . Option DView AnswerAnswer: C Explanation: Reference: https://community.cisco.com/t5/vpn/starting-anyconnect-vpn-through-rdp-session-on-cisco-891/td-p/2128284
Which requirement is needed to use local authentication for Cisco AnyConnect Secure Mobility Clients that connect to a FlexVPN server?
Which requirement is needed to use local authentication for Cisco AnyConnect Secure Mobility Clients that connect to a FlexVPN server?A . use of certificates instead of username and passwordB . EAP-AnyConnectC . EAP query-identityD . AnyConnect profileView AnswerAnswer: D Explanation: Reference: https://www.cisco.com/c/en/us/support/docs/security/flexvpn/200555-FlexVPN-AnyConnect-IKEv2-Remote-Access.html
Which IKEv2 packet will contain details of the exchange?
A second set of traffic selectors is negotiated between two peers using IKEv2. Which IKEv2 packet will contain details of the exchange?A . IKEv2 IKE_SA_INITB . IKEv2 INFORMATIONALC . IKEv2 CREATE_CHILD_SAD . IKEv2 IKE_AUTHView AnswerAnswer: B
Which IKE identity does an IOS/IOS-XE headend expect to receive if an IPsec Cisco AnyConnect client uses default settings?
Which IKE identity does an IOS/IOS-XE headend expect to receive if an IPsec Cisco AnyConnect client uses default settings?A . *$SecureMobilityClient$*B . *$AnyConnectClient$*C . *$RemoteAccessVpnClient$*D . *$DfltlkeldentityS*View AnswerAnswer: B Explanation: Reference: https://www.cisco.com/c/en/us/support/docs/security/flexvpn/200555-FlexVPN-AnyConnect-IKEv2-Remote-Access.html
Which two features provide headend resiliency for Cisco AnyConnect clients? (Choose two.)
Which two features provide headend resiliency for Cisco AnyConnect clients? (Choose two.)A . AnyConnect Auto ReconnectB . AnyConnect Network Access ManagerC . AnyConnect Backup ServersD . ASA failoverE . AnyConnect Always OnView AnswerAnswer: C,D
Which VPN technology is allowed for users connecting to the Employee tunnel group?
Refer to the exhibit. Which VPN technology is allowed for users connecting to the Employee tunnel group?A . SSL AnyConnectB . IKEv2 AnyConnectC . crypto mapD . clientlessView AnswerAnswer: B
What might be the problem?
Cisco AnyConnect Secure Mobility Client has been configured to use IKEv2 for one group of users and SSL for another group. When the administrator configures a new AnyConnect release on the Cisco ASA, the IKEv2 users cannot download it automatically when they connect. What might be the problem?A . The...
Which command automatically initiates a smart tunnel when a user logs in to the WebVPN portal page?
Which command automatically initiates a smart tunnel when a user logs in to the WebVPN portal page?A . auto-upgradeB . auto-connectC . auto-startD . auto-runView AnswerAnswer: C Explanation: Reference: https://www.cisco.com/c/en/us/td/docs/security/asa/asa91/configuration/vpn/asa_91_vpn_config/webvpn-configure-policy-group.html