Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 350-701 Exam - Topic 3 Question 95 Discussion

An engineer must modify an existing remote access VPN using a Cisco AnyConnect Secure Mobility client solution and a Cisco Secure Firewall. Currently, all the traffic generate by the user Is sent to the VPN tunnel and the engineer must now exclude some servers and access them directly instead. Which element must be modified to achieve this goat?
D) group policy
A) NAT exemption
B) encryption domain
C) routing table

Cisco 350-701 Exam - Topic 3 Question 95 Discussion

Actual exam question for Cisco's 350-701 exam
Question #: 95
Topic #: 3
[All 350-701 Questions]

An engineer must modify an existing remote access VPN using a Cisco AnyConnect Secure Mobility client solution and a Cisco Secure Firewall. Currently, all the traffic generate by the user Is sent to the VPN tunnel and the engineer must now exclude some servers and access them directly instead. Which element must be modified to achieve this goat?

Show Suggested Answer Hide Answer
Suggested Answer: D

To achieve the goal of excluding some servers from the VPN tunnel and accessing them directly, the engineer must modify the group policy that is applied to the remote access VPN users. The group policy contains the settings for split tunneling, which is a feature that allows the VPN client to route some traffic through the VPN tunnel and some traffic directly to the internet. Split tunneling can be configured based on the destination IP address, the application, or the domain name of the traffic. By modifying the group policy, the engineer can specify which servers or networks should be excluded from the VPN tunnel and accessed directly by the VPN client. This can improve the performance and efficiency of the VPN connection, as well as reduce the load on the VPN gateway and the corporate network. However, split tunneling also introduces some security risks, such as exposing the VPN client to internet threats, bypassing the corporate firewall and security policies, and leaking sensitive dat

a. Therefore, the engineer must carefully evaluate the trade-offs and best practices of using split tunneling for remote access VPNs.Reference:=

Implementing and Operating Cisco Security Core Technologies (SCOR) v1.0, Module 3: Secure Connectivity, Lesson 3.1: Implementing and Troubleshooting Remote Access VPN, Topic 3.1.4: Configure and Verify Remote Access VPN, Subtopic 3.1.4.2: Configure and Verify Split Tunneling

VPN Split Tunneling: What It Is & Pros and Cons

Cisco ASA - Enable Split Tunnel for Remote VPN Clients


Contribute your Thoughts:

0/2000 characters
Gail
9 months ago
Really? I thought encryption domain was the key here.
upvoted 0 times
...
Vivan
9 months ago
I think group policy could work too, but A seems right.
upvoted 0 times
...
Louis
10 months ago
Wait, are we sure it's not the routing table?
upvoted 0 times
...
Tiera
10 months ago
Definitely A, makes the most sense.
upvoted 0 times
...
Slyvia
10 months ago
Gotta modify the NAT exemption for that!
upvoted 0 times
...
Joaquin
10 months ago
Group policy might be the key here, but I can't recall if it directly affects traffic routing. I need to think this through more.
upvoted 0 times
...
Billye
11 months ago
I feel like this question is similar to one we did in class about routing tables. But I’m not convinced that’s the right answer here.
upvoted 0 times
...
Melita
11 months ago
I'm not entirely sure, but I remember something about NAT exemption being important for excluding certain traffic.
upvoted 0 times
...
Art
11 months ago
I think we need to look at the encryption domain to define which traffic goes through the VPN. That sounds familiar from our last practice exam.
upvoted 0 times
...
Jacquelyne
11 months ago
I'm a little confused on this one. Is it the group policy that controls the VPN traffic? Or is that something else entirely? I'll need to review my notes on Cisco VPN configuration to be sure.
upvoted 0 times
...
Cassi
11 months ago
Okay, I've got it. The element that needs to be modified is the NAT exemption. That will allow us to exclude the specified servers from the VPN tunnel and access them directly. Feels like a good strategy to me.
upvoted 0 times
...
Jacquline
11 months ago
This seems like a straightforward VPN configuration question. I think the key is to identify the element that controls which traffic gets sent through the VPN tunnel versus directly to the servers.
upvoted 0 times
...
Detra
11 months ago
Hmm, I'm a bit unsure on this one. Is it the encryption domain that determines what traffic goes through the VPN? Or could it be the routing table? I'll need to think this through carefully.
upvoted 0 times
...
Lilli
11 months ago
Okay, I think I've got this. The key is understanding that change request types allow you to control the behavior and properties of the change management process. Based on the options, it seems like the correct answer is B - the validation and derivation behavior during runtime.
upvoted 0 times
...
Hortencia
2 years ago
I'm picturing the engineer right now, scratching their head and muttering, 'Routing table, where art thou?' Just another day in the life of a network admin.
upvoted 0 times
Yen
2 years ago
C) routing table
upvoted 0 times
...
Lettie
2 years ago
B) encryption domain
upvoted 0 times
...
Gail
2 years ago
A) NAT exemption
upvoted 0 times
...
...
Sabina
2 years ago
NAT exemption? Sounds like a fancy way to say 'let's just ignore the VPN and go straight to the servers.'
upvoted 0 times
Renay
2 years ago
No problem! Always happy to help.
upvoted 0 times
...
Ona
2 years ago
That makes sense. Thanks for clarifying!
upvoted 0 times
...
Ammie
2 years ago
Yes, NAT exemption is the correct answer. It allows certain traffic to bypass the VPN tunnel and access servers directly.
upvoted 0 times
...
Lenna
2 years ago
D) group policy
upvoted 0 times
...
Fabiola
2 years ago
C) routing table
upvoted 0 times
...
Martha
2 years ago
B) encryption domain
upvoted 0 times
...
Helene
2 years ago
A) NAT exemption
upvoted 0 times
...
...
Joseph
2 years ago
I agree with Cristal, NAT exemption makes the most sense in this scenario.
upvoted 0 times
...
Shasta
2 years ago
I think it could be D) group policy, as that controls user access permissions.
upvoted 0 times
...
Aileen
2 years ago
I disagree, I believe it's C) routing table that needs to be modified.
upvoted 0 times
...
Matthew
2 years ago
Hmm, group policy seems like the way to go. Who doesn't love a good policy to keep things in check?
upvoted 0 times
...
Kimbery
2 years ago
I'd go for the encryption domain. Sounds like the kind of thing that would let us bypass the VPN tunnel.
upvoted 0 times
...
Zana
2 years ago
The routing table is definitely the key element to modify here. Gotta love those dynamic routes!
upvoted 0 times
Gail
2 years ago
D) group policy
upvoted 0 times
...
Almeta
2 years ago
The routing table is definitely the key element to modify here. Gotta love those dynamic routes!
upvoted 0 times
...
Lili
2 years ago
C) routing table
upvoted 0 times
...
Bulah
2 years ago
B) encryption domain
upvoted 0 times
...
Cassandra
2 years ago
A) NAT exemption
upvoted 0 times
...
...
Cristal
2 years ago
I think the correct answer is A) NAT exemption.
upvoted 0 times
...

Save Cancel