300-730 Sample Questions

300-730 Sample Questions & Answers

Remote-access VPN types such as AnyConnect IKEv2, SSL and clientless make up the biggest chunk, alongside site-to-site designs built with GETVPN, DMVPN and FlexVPN, ASDM and CLI-based IPsec troubleshooting, and overall VPN architecture decisions.

Launch the full 300-730 simulator →

Free 300-730 Sample Questions with Answers

Real questions from the Implementing Secure Solutions with Virtual Private Networks (SVPN) practice test — answers and explanations included. Showing 8 of 17 free samples.

  1. Question 1IntermediateSelect 2

    Which two changes must be made in order to migrate from DMVPN Phase 2 to Phase 3 when EIGRP is configured? (Choose two.)

    Show answer & explanation

    Correct answers: C, E

  2. Question 2Intermediate

    Refer to the exhibit. A customer cannot establish an IKEv2 site-to-site VPN tunnel between two Cisco ASA devices. Based on the syslog message, which action brings up the VPN tunnel? A.Reduce the maximum SA limit on the local Cisco ASA.B.Increase the maximum in-negotiation SA limit on the local Cisco ASA.C.Remove the maximum SA limit on the remote Cisco ASA.D.Correct the crypto access list on both Cisco ASA devices.

    300-730 sample question 2
    Show answer & explanation

    Correct answer:

  3. Question 3IntermediateSelect 2

    Which two parameters help to map a VPN session to a tunnel group without using the tunnel-group list? (Choose two.)

    Show answer & explanation

    Correct answers: B, D

  4. Question 4Intermediate

    Which method dynamically installs the network routes for remote tunnel endpoints? A.policy-based routingB.CEFC.reverse route injectionD.route filtering

    Show answer & explanation

    Correct answer: C

  5. Question 5Advanced

    Site-to-site Virtual Private Networks on Routers and Firewalls · Implement FlexVPN

    A network architect is designing a high-availability VPN solution for a financial institution. The design requires a FlexVPN hub-and-spoke topology where the spokes must authenticate the hub using a digital certificate, but the hub must authenticate spokes using EAP-TLS to integrate with an existing RADIUS infrastructure. Which specific IKEv2 configuration construct allows for asymmetric authentication methods between the peers?

    Show answer & explanation

    Correct answer: B

    IKEv2 supports asymmetric authentication, meaning the two peers do not need to use the same method to authenticate each other. In this scenario, the hub configures authentication local rsa-sig to present a certificate to the spoke, and authentication remote eap to demand EAP authentication from the spoke.

  6. Question 6Intermediate

    Troubleshooting using ASDM and CLI · Troubleshoot DMVPN

    A senior engineer is troubleshooting a DMVPN Phase 3 network where spoke-to-spoke tunnels are failing to establish. The hub router is correctly rewriting the next-hop, but the spokes are not installing the shortcut routes. Which command should be verified on the spoke routers' tunnel interfaces?

    Show answer & explanation

    Correct answer: B

    In DMVPN Phase 3, the ip nhrp shortcut command is required on the spoke routers. This command enables the spoke to accept NHRP redirect messages from the hub and to resolve the NBMA address of the target spoke to install a CEF shortcut (specific route) for direct communication.

  7. Question 7Intermediate

    Remote access VPNs · Implement Clientless SSL VPN

    While configuring a Cisco ASA for clientless SSL VPN, an administrator needs to ensure that users can access an internal file server using the CIFS protocol without requiring a Java plug-in. Which feature should be configured to meet this requirement?

    Show answer & explanation

    Correct answer: C

    The ASA Clientless SSL VPN portal includes a native file browser that supports CIFS (Common Internet File System). This allows users to browse file shares directly through the web portal interface using HTML rendering, without requiring Java or ActiveX plug-ins.

  8. Question 8IntermediateSelect 2

    Troubleshooting using ASDM and CLI · Troubleshoot FlexVPN

    A network engineer observes that IKEv2 negotiation between a FlexVPN hub and spoke is failing. The debug output shows the error IKEv2-ERROR: Policy not found. Which two actions should be taken to resolve this issue? (Select TWO)

    Show answer & explanation

    Correct answers: A, B

    The 'Policy not found' error in IKEv2 typically indicates that the receiver could not find an IKEv2 profile that matches the incoming request. This matching is primarily done via the match identity commands.

    While 'Policy not found' points to profile selection, if no valid IKEv2 proposal exists (or the default smart defaults don't match), the negotiation cannot proceed to a point where a policy is fully established. However, profile matching is the most direct cause of this specific error text.

Ready for the real thing?

The full 300-730 simulator has every exam-style question, timed mode, and instant scoring.