
CiscoCertified Network Professional Security
Domain 2Objective 10
2.10 Troubleshoot VPN Tunnel Establishment on Cisco Secure Firewall (FTD) 350-701 Practice Questions (Page 2)
Part of the Network Security domain, which accounts for 25% of the 350-701 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–2 from this objective — we provide 21 practice questions to prepare you well beyond it. (estimate)
21questions here
5free pages
7concepts
25%of the exam
Questions 6–10
- 6
A remote-access VPN on FTD uses certificate authentication. Users report they cannot connect. The FTD logs show 'Certificate validation failed: certificate is not trusted'. The client certificates are issued by an internal CA. What is the most likely cause?
Select an answer first - 7
Which FTD CLI command displays active VPN sessions and their status?
Select an answer first - 8
During IPsec tunnel establishment on Cisco FTD, what is the primary purpose of IKEv2's IKE_SA_INIT exchange?
Select an answer first - 9
A site-to-site VPN between two FTDs is failing. The local FTD's `debug crypto ikev2` shows that IKE_SA_INIT is sent, but no response is received. The remote FTD's outside interface is reachable via ping. You check the remote FTD's access rules and see that UDP 500 and UDP 4500 are allowed from the local peer. What should you check next?
Select an answer first - 10
Which configuration error is most likely to cause an IKEv1 Phase 1 failure on a Cisco FTD site-to-site VPN?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-701” is a trademark of its owner, used for identification only.