
Secure Communications & IKEv1/IKEv2 · Site-to-Site VPN (DMVPN, GET VPN, FlexVPN) · Remote Access VPN (AnyConnect, Clientless SSL) · Troubleshooting
60 questions · 90 min · 70% Techclick practice target
⚠️ Exam Rules
| Questions in this Techclick bank | 60 |
|---|---|
| Timer | 90 min |
| Techclick practice target | 70% |
| Official exam code | 300-730 |
An engineer is comparing IKEv2 with IKEv1 for a new deployment and must justify the change to management. Which IKEv2 characteristic represents a genuine improvement?
Correct: D. IKEv2 negotiates in four messages rather than the six or nine of IKEv1 main and aggressive modes, and NAT traversal plus dead peer detection are integral rather than extensions. It still requires authentication credentials, still creates child security associations for data protection, and still needs traffic selectors defining what is protected.
An engineer must protect site-to-site traffic that traverses a NAT device in the path. Which IPsec protocol choice is required and why?
Correct: C. AH includes immutable IP header fields in its integrity check, so translating the address invalidates it, whereas ESP protects only the payload and works with NAT traversal encapsulation. The protocols are not interchangeable in this respect, and IPsec does work through NAT when ESP with UDP encapsulation is used.
An engineer is configuring an IKEv2 proposal and policy. Select the TWO parameters that must be negotiated successfully for the security association to establish. (Choose TWO)
Correct: C and D. IKE negotiation must reach agreement on the cryptographic transforms and the key exchange group before any security association can form. Routing protocol choice, device hostnames and interface MTU affect operation after the tunnel exists rather than whether the negotiation itself succeeds.
A security policy requires that compromise of a long-term key must not expose previously captured traffic. Which IPsec feature satisfies this?
Correct: A. Perfect forward secrecy derives each session key from an independent exchange, so recovering one key does not unlock previously recorded sessions. Longer lifetimes increase the exposure of a single key, stronger hashing protects integrity rather than confidentiality, and aggressive mode weakens rather than strengthens the negotiation.
An engineer must decide between tunnel mode and transport mode for a GRE over IPsec design. Which choice is appropriate and why?
Correct: D. When GRE supplies the encapsulating header, transport mode avoids adding a second redundant IP header and saves overhead. GRE and IPsec combine routinely, transport mode protects the payload rather than encrypting the original header, and transport mode is fully supported.
Last updated:
Yes. You can start, finish and score it for free, and download the Techclick practice certificate.
This bank has 60 original scenario-based questions with a 90-minute timer and a 70% Techclick practice target.
The official exam code is 300-730 (Cisco).
No. They are original practice questions written by Techclick. This is not the vendor's official exam and not leaked dumps.
Score 70% or higher to get a Techclick practice certificate and LinkedIn badge. It is not an official Cisco certification.
Related practice tests: CCIE Security Written 350-701, CCNA 200-301, Cisco 300-410, CCNP ENCOR 350-401, Cisco 100-160, Cisco 200-201 (linked below).

You earned it — let the world know!
