exam questions

Exam 300-730 All Questions

View all questions & answers for the 300-730 exam

Exam 300-730 topic 1 question 136 discussion

Actual exam question from Cisco's 300-730
Question #: 136
Topic #: 1
[All 300-730 Questions]

Which remote access VPN technology requires the use of the IPsec-proposal configuration option?

  • A. clientless SSLVPN
  • B. SSLVPN Full Tunnel
  • C. IKEv2-based VPN
  • D. IKEv1-based VPN
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
kylesam2017
10 months, 2 weeks ago
The IPsec-proposal configuration option is typically associated with IKEv1-based VPNs. In IKEv1 (Internet Key Exchange version 1) VPNs, the IPsec proposal defines the combination of encryption, integrity, and authentication algorithms that will be used to protect the data traffic. In the context of IKEv2 (Internet Key Exchange version 2), the concept of proposals still exists, but it is often more flexible and simplified compared to IKEv1. IKEv2 introduces the concept of a "transform set" that includes multiple proposals, allowing for a more dynamic negotiation of cryptographic algorithms during the IKEv2 exchange. So, if you are dealing with a VPN technology that specifically requires the use of the IPsec-proposal configuration option, it is more likely associated with IKEv1-based VPNs.
upvoted 1 times
shadow2020
9 months, 4 weeks ago
you are correct when seen from proposals. But have a look at how Cisco place it. Step 1 Configure an IKEv1 transform set that specifies the IPsec IKEv1 encryption and hash algorithms to be used to ensure data integrity. crypto ipsec ikev1 transform-set transform-set-name encryption-method [authentication] Use one of the following values for encryption: ======Ikev2========================= Configure an IKEv2 proposal set that specifies the IPsec IKEv2 protocol, encryption, and integrity algorithms to be used. esp specifies the Encapsulating Security Payload (ESP) IPsec protocol (currently the only supported protocol for IPsec). crypto ipsec ikev2 ipsec-proposal proposal_name so its IKEv2 ( ipsec-proposal proposal_name).
upvoted 1 times
...
...
gondohwe
11 months, 4 weeks ago
correct answer is C
upvoted 1 times
...
Toni_Su91
1 year, 4 months ago
Selected Answer: C
Configure an IKEv2 proposal set that specifies the IPsec IKEv2 protocol, encryption, and integrity algorithms to be used. esp specifies the Encapsulating Security Payload (ESP) IPsec protocol (currently the only supported protocol for IPsec). crypto ipsec ikev2 ipsec-proposal
upvoted 1 times
...
Net4dd
1 year, 8 months ago
Selected Answer: C
C is correct. The IPsec-proposal configuration option is used to specify the encryption, integrity, and authentication algorithms that will be used in the IPsec protocol. In the case of IKEv2-based VPN, this option is used to configure the IPsec security associations (SA) that will be established between the VPN client and the VPN gateway during IKEv2 negotiation. IKEv2 uses IPsec as its underlying encryption and authentication protocol, so the IPsec-proposal configuration is essential to establishing a secure VPN tunnel using IKEv2
upvoted 1 times
...
Tiptonlad
1 year, 9 months ago
Selected Answer: C
C in the answer
upvoted 1 times
...
mazinhoo
1 year, 9 months ago
Selected Answer: C
https://www.cisco.com/c/en/us/td/docs/security/asa/asa96/configuration/vpn/asa-96-vpn-config/vpn-remote-access.html
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago