exam questions

Exam 350-701 All Questions

View all questions & answers for the 350-701 exam

Exam 350-701 topic 1 question 85 discussion

Actual exam question from Cisco's 350-701
Question #: 85
Topic #: 1
[All 350-701 Questions]

A network engineer is configuring DMVPN and entered the crypto isakmp key cisc0383320506 address 0.0.0.0 command on host A. The tunnel is not being established to host B. What action is needed to authenticate the VPN?

  • A. Change the password on host A to the default password
  • B. Enter the command with a different password on host B
  • C. Enter the same command on host B
  • D. Change isakmp to ikev2 in the command on host A
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Marshpillowz
7 months, 1 week ago
Selected Answer: C
C is correct
upvoted 1 times
...
sull3y
1 year, 9 months ago
C. Enter the same command on host B The crypto isakmp key command is used to set the shared secret key for Internet Security Association and Key Management Protocol (ISAKMP) on a router. In order for the VPN tunnel to be established between host A and host B, the same shared secret key must be configured on both hosts. In this case, the network engineer needs to enter the same crypto isakmp key command, with the same password, on host B as they did on host A. This will ensure that both hosts are using the same shared secret key for authentication and the tunnel will be established. The other options A, B and D are not correct.
upvoted 3 times
...
psuoh
1 year, 9 months ago
The question should say the crypto isakmp key cisc0383320506 address 0.0.0.0 0.0.0.0 Example Add dynamic pre-shared keys for all the remote VPN !--- routers and the hub router. crypto isakmp key cisco123 address 0.0.0.0 0.0.0.0
upvoted 1 times
...
Net4dd
1 year, 10 months ago
C. Is true https://www.cisco.com/c/en/us/support/docs/security-vpn/ipsec-negotiation-ike-protocols/29240-dcmvpn.html
upvoted 2 times
...
dr4gn00t
2 years, 9 months ago
C is correct answer according to DMVPN configuration examples in cert guide
upvoted 2 times
...
Laryoul
2 years, 10 months ago
For me the good answer is C. Enter 0.0.0.0 on a this command line could be done on Hub and Spoke. Hub configuration is done on ip nhrp. https://www.cisco.com/c/en/us/td/docs/ios/12_2/security/command/reference/srfike.html#wp1017897 https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_dmvpn/configuration/15-mt/sec-conn-dmvpn-15-mt-book/sec-conn-dmvpn-dmvpn.html#GUID-BDBD63D7-C9FD-490F-B1AF-EFC38B6B497B
upvoted 2 times
...
loiphin
2 years, 10 months ago
I would say its A, because if you entered the same command on Host B, they would never establish a tunnel. crypto isakmp key xxx 0.0.0.0 is only ever used on hubs. If you use the same command on a spoke they will never connect to each other.
upvoted 1 times
DarkestHour
2 years, 4 months ago
How would spoke to spoke tunnels ever be encrypted then?
upvoted 1 times
...
...
_nomad_
2 years, 11 months ago
0.0.0.0 addres wth! threw me off :P
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago