exam questions

Exam 300-730 All Questions

View all questions & answers for the 300-730 exam

Exam 300-730 topic 1 question 221 discussion

Actual exam question from Cisco's 300-730
Question #: 221
Topic #: 1
[All 300-730 Questions]

An engineer must force a new IKEv2 security association to be built when using FlexVPN. Which two commands must the engineer apply to meet the requirement? (Choose two.)

  • A. clear flexvpn sessions
  • B. clear ipsec sa
  • C. clear isakmp crypto sa
  • D. shut the tunnel interface
  • E. no shut the tunnel interface
Show Suggested Answer Hide Answer
Suggested Answer: BC 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
fukumoto0925
1 month ago
Selected Answer: DE
This is a tricky one but if the cmd are as displayed, first none of them exist (both are clear CRYPTO ....)and 2nd-> https://www.cisco.com/c/en/us/support/docs/security/flexvpn/115782-flexvpn-site-to-site-00.html ->"Use the shut and no shut commands on the tunnel interface in order to force a new IKEv2 SA to be built."
upvoted 1 times
...
4b4ddf8
2 months ago
Selected Answer: DE
A) This command does not exist B) This is for Ipsec Phase 2 SA not IKEv2 SA C) This is for IKEv1 not for IKEv2 Shutting the tunnel interface and no shutting the tunnel interface forces new IKEv2 SA's to be built. See this reference: https://www.cisco.com/c/en/us/support/docs/security/flexvpn/115782-flexvpn-site-to-site-00.html
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago