Question 1
Q1A network administrator is troubleshooting a Cisco AnyConnect SSL VPN where users are unable to access internal web servers via FQDN but can access them via IP address. The split-tunneling policy is correctly configured to include the internal DNS server's subnet. The ASA configuration includes the command split-dns DefaultDNS. What is the most likely cause of this issue?
Show answer & explanation
Correct answer: B
The split-dns command requires a list of domain names. When a client needs to resolve a name matching a domain in this list, the query is sent through the tunnel to the corporate DNS server. The command split-dns DefaultDNS is not a valid configuration; it should be followed by a domain name, for example, split-dns value internal.company.com. Without the specific domain list, the AnyConnect client will continue to use its local DNS server, failing to resolve internal FQDNs.