exam questions

Exam 300-730 All Questions

View all questions & answers for the 300-730 exam

Exam 300-730 topic 1 question 107 discussion

Actual exam question from Cisco's 300-730
Question #: 107
Topic #: 1
[All 300-730 Questions]

A company needs to ensure only corporate issued laptops and devices are allowed to connect with the Cisco AnyConnect client. The solution should be applicable to multiple operating systems, including Windows, MacOS, and Linux, and should allow for remote remediation if a corporate issued device is stolen. Which solution should be used to accomplish these goals?

  • A. Use a DAP registry check on the system to determine the relationship with the corporate domain.
  • B. Use a DAP file check on the system to determine the relationship with the corporate domain.
  • C. Install and authenticate user certificates on the corporate devices.
  • D. Install and authenticate machine certificates on the corporate devices
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
kylesam2017
11 months ago
To accomplish the goals of ensuring only corporate issued laptops and devices connect with the Cisco AnyConnect client, as well as providing remote remediation for stolen devices, it is recommended to use machine certificates for authentication. By installing and authenticating machine certificates on the devices, you can establish a secure connection between the client and the Cisco AnyConnect VPN gateway. This ensures that only devices with valid machine certificates issued by the corporate domain can connect to the VPN. Additionally, machine certificates provide a higher level of security and are applicable to multiple operating systems, including Windows, MacOS, and Linux. This allows for a consistent and unified approach across different platforms. By using machine certificates, if a corporate issued device is stolen or compromised, the certificate can be revoked or disabled remotely. This prevents unauthorized access to the VPN, enhancing security and mitigating potential risks.
upvoted 1 times
...
mjuarez20
1 year ago
Selected Answer: D
Certificate on the machine is the best option here.
upvoted 1 times
...
gondohwe
1 year ago
if rght answer is D then why admin of this site letting wrong answers show???
upvoted 2 times
...
spambox730
1 year, 4 months ago
Selected Answer: D
Machine certificates is the right solution. (D) DAP registry check (A) is wrong, there is no registry in Mac or Linux
upvoted 1 times
...
Anonymous983475
1 year, 5 months ago
Selected Answer: D
Customers usually do double authentication using RADIUS or LDAP plus Machine Certificate, to make sure the certificate is signed and belongs to the domain.
upvoted 2 times
...
mpls_link
1 year, 6 months ago
Selected Answer: A
A is answr
upvoted 1 times
...
netizen937
1 year, 7 months ago
Selected Answer: D
DAP will not revoke access to a stolen or lost PC. It only verifies that the system meets specific security requirements such as antivirus being installed. A machine certificate, however, can be revoked on the CA server that the VPN head end will validate against.
upvoted 4 times
...
mazinhoo
1 year, 10 months ago
Selected Answer: A
https://www.cisco.com/c/en/us/td/docs/security/asa/asa98/asdm78/vpn/asdm-78-vpn-config/vpn-asdm-dap.html#ID-2184-00000017
upvoted 1 times
jimmyjose
7 months, 3 weeks ago
Answer is definitely not A. This is because only Windows OS has a registry. Non-Windows operating systems do not have a registry. Moreover, the link you provided mentions the following. Scanning for registry endpoint attributes applies to Windows operating systems only. The correct answer is D as machine certificates are the most secure and it also applies to all operating systems.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...