Skip to content

300-730 Implementing Secure Solutions with Virtual Private Networks (SVPN) Practice Questions

Prepare for 300-730 with more than an answer.

240 questions in the full set17 sample questionsUpdated Jan 30, 2026

Unlock the full exam and previous versions

  • v1Version 1 240 questions Current
  • 300-209Legacy Security Implementing Cisco Secure Mobility Solutions (SIMOS) 289 questions Locked
Exam fee
$300 USD
Level
Professional
Valid for
3 years
Domains covered on the exam 4
  1. Site-to-Site Virtual Private Networks on Routers and Firewalls20%
  2. Remote Access VPNs35%
  3. Troubleshooting Using ASDM and CLI30%
  4. Secure Communications Architectures15%
  1. 1

    True or False: In a GETVPN environment, the Key Server (KS) participates in the data plane routing and encryption of user traffic.

    Show answer details

    Correct answer: B

    This is False. The Key Server (KS) in GETVPN is responsible for the control plane only—maintaining policies and creating/distributing keys. It does not encrypt traffic or sit in the data path. Group Members (GMs) handle the actual encryption and routing.

  2. 2

    An administrator is configuring the AnyConnect Secure Mobility Client for a Windows fleet. The requirement is to ensure the VPN automatically disconnects when the user connects to the corporate trusted network. Which feature in the XML profile must be configured?

    Show answer details

    Correct answer: D

    Trusted Network Detection (TND) allows the AnyConnect client to detect if it is on a trusted (internal) network based on DNS suffixes and DNS server reachability. If detected, TND can be configured to automatically disconnect the VPN.

  3. 3

    A Cisco ASA is configured for IKEv2 site-to-site VPNs. A new security policy mandates that all IKEv2 negotiations must use Elliptic Curve Digital Signature Algorithm (ECDSA) with SHA-384 for authentication. Which configuration command correctly implements this requirement in the IKEv2 policy?

    Show answer details

    Correct answer: B

    The IKEv2 policy (proposal) defines encryption, integrity, PRF, and DH group. The authentication method (like ECDSA vs RSA) is defined in the tunnel-group under ipsec-attributes using the ikev2 remote-authentication and ikev2 local-authentication commands. The IKEv2 policy does not have an 'authentication' command.

  4. 4

    Case Study: Orbital Logistics VPN Redesign

    Background
    Orbital Logistics is a global supply chain firm migrating their legacy Frame Relay network to a new WAN architecture. They have a primary data center in London and a DR site in Frankfurt. They have 300 branch offices worldwide. The branches connect to the internet via varying bandwidth links (DSL, Fiber, 4G).

    Requirements

    1. Direct Branch-to-Branch: Branches must be able to communicate directly (VoIP traffic) without pinning traffic through the Data Center hub.
    2. Multicast Support: The solution must support multicast routing for a new inventory update application.
    3. Address Conservation: Public IP addresses are scarce; the solution should minimize public IP usage at the branches.
    4. Encryption: All traffic over the WAN must be encrypted with AES-256.

    Current Challenge
    The network team is debating between DMVPN and FlexVPN. They are concerned about the complexity of IKEv2 but need the most robust support for future IPv6 migration.

    Question
    Based on the requirements, which VPN technology and phase design is the optimal choice for Orbital Logistics, and why?

    Show answer details

    Correct answer: A

    DMVPN Phase 3 is the correct choice. It meets the requirement for direct branch-to-branch communication (spoke-to-spoke) via NHRP redirects and shortcuts. It supports multicast (unlike some basic IPsec meshes), handles dynamic public IPs at branches, and supports strong encryption. While FlexVPN is also a candidate, DMVPN is specifically designed for this large-scale hub-and-spoke to mesh transition and is often simpler to deploy for this specific set of requirements.

  5. 5

    When configuring a Cisco ASA to support AnyConnect connections, which command creates a pool of IP addresses named 'VPN_POOL' ranging from 10.10.10.10 to 10.10.10.100?

    Show answer details

    Correct answer: C

    The correct syntax on Cisco ASA to define a local address pool is ip local pool - mask <mask.

  6. 6

    A second set of traffic selectors is negotiated between two peers using IKEv2. Which IKEv2 packet will contain details of the exchange?

    Show answer details

    Correct answer: A

  7. 7

    On a FlexVPN hub-and-spoke topology where spoke-to-spoke tunnels are not allowed, which command is needed for the hub to be able to terminate FlexVPN tunnels?

    Show answer details

    Correct answer: C

  8. 8

    Which statement about GETVPN is true?

    Show answer details

    Correct answer: C

Create an account to continue.