Q18Remote access VPNsMultiple answers
Refer to the exhibit. Which two commands in `tunnel-group webvpn-attributes` cause a Cisco AnyConnect user to receive the AnyConnect prompt shown? (Choose two.)
Select 2 answers.
← → navigate · a answer
Community votes
Discussion · 18
3
correct answers are C and E
3
the correct answers are C & E , the question asks about commands under tunnel-group attribute, authentication and group-alias are under the tunnel-group
B, E 3
Selected Answer: BE
From another lab:
group-policy SALES internal
group-policy SALES attributes
webvpn
url-entry enable
!
tunnel-group STUNNEL type remote-access
tunnel-group STUNNEL general-attributes
default-group-policy SALES
tunnel-group STUNNEL webvpn-attributes
group-alias SALES enable
C, E 3
Selected Answer: CE
https://www.cisco.com/c/en/us/td/docs/security/asa/asa72/configuration/guide/conf_gd/vpngrp.html
C, E 3
Selected Answer: CE
E to enable the alias is definitely needed
both B and C are required too but it's always assumed they have already been done.
B group policy is not required since Default can be used
C if AAA is not configured then authentication will not work.
2
B and E are correct
B enables the group-policy to check login-attempts against the internal (local) users storage
E creates the Alias for the Tunnel-Group
C, E 2
Selected Answer: CE
C & E
tunnel-group attribute
C, E 2
Selected Answer: CE
C and E seem correct https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/98580-enable-group-dropdown.html
C, E 2
Selected Answer: CE
authentication aaa
group-alias asdf enable
are the commands under tunnel-group
C, E 2
Selected Answer: CE
C and E seem correct, because AAA authentication is done under tunnel group config, and it will prompt for username and password.
And the group-list under tunnel group as well, it will ask you to select from the drop-down menu.
2
"C and E" looks like the correct answers here:
2
A&E
For each group URL or address, enter a group-URL command. You can also explicitly enable (the default) or disable each URL or alias:
hostname(config-tunnel-webvpn)# group-url url [enable | disable]
hostname(config-tunnel-webvpn)# group-alias "Cisco Remote Access" enable
hostname(config-tunnel-webvpn)# group-url http://www.cisco.com enable
2
The answers are A & E.
https://www.cisco.com/c/en/us/td/docs/security/asa/asa72/configuration/guide/conf_gd/vpngrp.html
Step 5 - To specify incoming URLs or IP addresses for the group, use the group-url command. Setting a group URL or IP address removes the need for the user to select a group at login. When a user logs in, the security appliance checks the user's incoming URL or address in the tunnel-group-policy table. If it finds the URL or address and if group-url is enabled in the tunnel group, then the security appliance automatically picks the associated tunnel group and shows the user only the username and password fields in the login window.
The questions asks which two commands under the tunnel-group webvpn-attributes result in a Cisco AnyConnect user receiving the AnyConnect prompt. It does not ask whether authentication attempts are successful. Here, the keyword is 'AnyConnect prompt'.
A, E 1
Selected Answer: AE
The only 2 commands under tunnel-group webvpn attributes are
group-alias and group-url.
All the others are elsewhere in the configuration, not under tunnel-group webvpn attributes.
1
C and E are correct.
All commands are present under tunnel-group webvpn-attributes, only "group-policy XXX internal" is a hidden command.
authentication aaa is set by default, so only answer E would be enough.
1
BE seems to be the most appropriate answer
1
What about this reason for rejecting A?->"The drop-down list does not appear if you connect to the ASA using a group-url, as the purpose of the group-url is to perform the group selection"
https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/98580-enable-group-dropdown.html
C, E 1
Selected Answer: CE
The question is asking:
Which two commands under tunnel-group webvpn-attributes make a Cisco AnyConnect user get the AnyConnect prompt?
Correct answers:
C. authentication aaa
E. group-alias General enable
Explanation:
authentication aaa makes sure the user is prompted for a username and password when connecting.
group-alias General enable sets an alias for the tunnel group, so the client picks the right group automatically without the user choosing from a list.
Other options like group-url or group-policy are either optional or not configured directly under webvpn-attributes. The exam specifically asks for commands under webvpn-attributes that trigger the AnyConnect prompt.