exam questions

Exam 300-730 All Questions

View all questions & answers for the 300-730 exam

Exam 300-730 topic 1 question 82 discussion

Actual exam question from Cisco's 300-730
Question #: 82
Topic #: 1
[All 300-730 Questions]

While troubleshooting, an engineer finds that the show crypto isakmp sa command indicates that the last state of the tunnel is MM_KEY_EXCH. What is the next step that should be taken to resolve this issue?

  • A. Verify that the ISAKMP proposals match.
  • B. Ensure that UDP 500 is not being blocked between the devices.
  • C. Correct the peer's IP address on the crypto map.
  • D. Confirm that the pre-shared keys match on both devices.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ed81044
7 months, 2 weeks ago
Selected Answer: D
show crypto isakmp sa This command shows the ISAKMP SA built between peers. dst src state conn-id slot 10.1.0.2 10.1.0.1 QM_IDLE 1 0 In theshow crypto isakmp sa output, the state must always be QM_IDLE. If the state is MM_KEY_EXCH, it means either the configured pre-shared key is not correct or the peer IP addresses are different. PIX(config)#show crypto isakmp sa Total : 2 Embryonic : 1 dst src state pending created 192.168.254.250 10.177.243.187 MM_KEY_EXCH 0 0 You can rectify this when you configure the correct IP address or pre-shared key.
upvoted 1 times
...
kylesam2017
10 months, 3 weeks ago
"D" is the correct answer.
upvoted 2 times
...
mihaid
1 year, 2 months ago
Selected Answer: D
Why not C ? because the process went up to MM_KEY-EXCH which is the 4th-5th message exchange. In the 1st message the peers IP are checked
upvoted 2 times
...
Khs01
1 year, 3 months ago
Selected Answer: D
MM_KEY_EXCH* – Both peers exchange their DH keys and are generating their secret keys. (This state could also mean there is a mis-matched authentication type or PSK, if it does not proceed to the next step)
upvoted 2 times
...
mpls_link
1 year, 7 months ago
Selected Answer: D
D is the most correct answer
upvoted 1 times
...
Net4dd
1 year, 8 months ago
https://ccie-or-null.net/tag/cisco-vpn-troubleshooting/ https://www.networkworld.com/article/2288666/chapter-4--common-ipsec-vpn-issues.html
upvoted 1 times
...
mazinhoo
2 years, 3 months ago
Selected Answer: C
as Kyle1776 said that MM_Key_Exch message would means either psk or peer wrong, but as the output of the show crypto isakmp sa would show you the local and remote peer IP, so the next step would be checking the peer IP is correct, so the answer is C
upvoted 1 times
...
AF_Nick
2 years, 3 months ago
Selected Answer: D
If it's stuck at MM_Key_Exch and without any additional information, I would chose D.
upvoted 2 times
...
Kyle1776
2 years, 5 months ago
Well according to Cisco its both C and D the pre-shared key is wrong of the peer is wrong would result in the MM_Key_Exch message In the show crypto isakmp sa output, the state should always be QM_IDLE. If the state is MM_KEY_EXCH, it means either the configured pre-shared key is not correct or the peer IP addresses are different. https://www.cisco.com/c/en/us/support/docs/security-vpn/ipsec-negotiation-ike-protocols/5409-ipsec-debug-00.html
upvoted 1 times
...
e_mwas
2 years, 7 months ago
I go with D
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago