Refer to the exhibit.
A customer cannot establish an IKEv2 site-to-site VPN tunnel between two Cisco ASA devices. Based on the syslog message, which action brings up the VPN tunnel?
A. Reduce the maximum SA limit on the local Cisco ASA.
B. Increase the maximum in-negotiation SA limit on the local Cisco ASA.
C. Remove the maximum SA limit on the remote Cisco ASA.
D. Correct the crypto access list on both Cisco ASA devices.
Which method dynamically installs the network routes for remote tunnel endpoints?
A. policy-based routing
B. CEF
C. reverse route injection
D. route filtering
Refer to the exhibit.
Which VPN technology is used in the exhibit?
A. DVTI
B. VTI
C. DMVPN
D. GRE
Refer to the exhibit.
Users cannot connect via AnyConnect SSLVPN. Which action resolves this issue?
A. Configure the ASA to act as a DHCP server.
B. Configure the HTTP server to listen on port 443.
C. Add an IPsec preshared key to the group policy.
D. Add ssl-client to the allowed list of VPN protocols.
An organization wants to distribute remote access VPN load across 12 VPN headend locations supporting 25,000 simultaneous users. Which load balancing method meets this requirement?
A. one VPN profile per site
B. DNS-based load balancing
C. AnyConnect native load balancing
D. equal cost, multipath load balancing
Refer to the exhibit.
A network administrator is setting up Cisco AnyConnect on an ASA headend. When users attempt to connect to the VPN, they are presented with this message. The administrator has replaced the ASA's self-signed certificate with a certificate enrolled with the internal CA and has confirmed that the certificate is not revoked. Which two tasks will the administrator need to do to prevent users from seeing this message? (Choose two.)
A. Trust the issuing CA for the ASA identity certificate on the user's PC.
B. Enroll and import an SSL certificate with the CN value example.cisco.com on the ASA.
C. Add the CN example.cisco.com to the AnyConnect XML certificate matching section.
D. Enable certificate authentication under the connection profile.
E. Add example.cisco.com to the server name list within the AnyConnect Local Policy.
Two Cisco ASAs are set up in a VPN load-balancing configuration in an environment where there are thousands of unique Cisco AnyConnect connections per day. Which scalable IP address assignment method must be implemented on both ASAs to achieve minimal overlap when assigning IP addresses from the same subnet to AnyConnect clients?
A. DHCP
B. local
C. RADIUS framed IP address
D. RADIUS address pools
An engineer has integrated a new DMVPN to link remote offices across the internet using Cisco IOS routers. When connecting to remote sites, pings and voice data appear to flow properly, and all tunnel stats show that they are up. However, when trying to connect to a remote server using RDP, the connection fails. Which action resolves this issue?
A. Adjust the MTU size within the routers.
B. Add RDP port to the extended ACL.
C. Replace certificate on the RDP server.
D. Change DMVPN timeout values.
Refer to the exhibit.
Which type of VPN is being configured, based on the partial configuration snippet?
A. GET VPN with COOP key server
B. GET VPN with dual group member
C. FlexVPN load balancer
D. FlexVPN backup gateway
DRAG DROP
Drag and drop the code snippets from the right onto the blanks in the configuration to implement FlexVPN. Not all snippets are used.
Select and Place: