exam questions

Exam 300-730 All Questions

View all questions & answers for the 300-730 exam

Exam 300-730 topic 1 question 178 discussion

Actual exam question from Cisco's 300-730
Question #: 178
Topic #: 1
[All 300-730 Questions]

An administrator is deciding which authentication protocol should be implemented for their upcoming Cisco AnyConnect deployment. A list of the security requirements from upper management are: the ability to force AnyConnect users to use complex passwords such as C1$c0451035084!, warn users a few days before their password expires, and allow users to change their password during a remote access session. Which authentication protocol must be used to meet these requirements?

  • A. LDAPS
  • B. RADIUS
  • C. Kerberos
  • D. TACACS+
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
haydenme97
7 months, 3 weeks ago
A. LDAPS is correct https://community.cisco.com/t5/security-knowledge-base/password-management-with-ldap-vs-radius-for-vpn-users/ta-p/3147278
upvoted 2 times
...
pfrank
9 months ago
Selected Answer: A
https://community.cisco.com/t5/security-knowledge-base/password-management-with-ldap-vs-radius-for-vpn-users/ta-p/3147278
upvoted 1 times
...
kylesam2017
10 months, 3 weeks ago
To meet the security requirements of forcing AnyConnect users to use complex passwords, warning users before their password expires, and allowing users to change their password during a remote access session, the authentication protocol that must be used is RADIUS (Remote Authentication Dial-In User Service). RADIUS is a widely used authentication protocol that provides centralized authentication, authorization, and accounting for remote access. It supports a variety of authentication methods, including the ability to enforce complex password policies and password expiration warnings. Additionally, RADIUS allows users to change their passwords during a remote access session, providing flexibility and convenience. On the other hand, LDAPS (LDAP over SSL/TLS) is a secure version of the LDAP protocol used for directory services. While LDAPS can provide secure authentication, it does not inherently include the ability to enforce complex passwords, password expiration warnings, or support password changes during a remote access session. Therefore, to meet the specified security requirements, the authentication protocol that must be used is RADIUS.
upvoted 1 times
...
Acnaris
1 year, 1 month ago
Selected Answer: A
https://www.cisco.com/c/en/us/td/docs/security/asa/asa97/configuration/vpn/asa-97-vpn-config/vpn-groups.html
upvoted 1 times
...
lyubo01
1 year, 3 months ago
Selected Answer: A
IMO, this one should be A. Also according to Cisco tips: To enforce complex passwords—for example, to require that a password contain upper- and lowercase letters, numbers, and special characters—enter the password-management command in tunnel-group general-attributes configuration mode on the ASA and perform the following steps under Active Directory. https://www.cisco.com/c/en/us/td/docs/security/asa/asa97/configuration/vpn/asa-97-vpn-config/vpn-groups.html
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago