The ciphers available are TLS 1.2, DTLS 1.2 and IKEv2. A,B and C are not available on the system. If A was DTLSv1.2 then I think A would be the best choice.
A. DTLSv1 (Datagram Transport Layer Security version 1) provides the strongest throughput performance when using Cisco AnyConnect VPN.
According to the Cisco document, DTLS (Datagram Transport Layer Security) is the default protocol used by the Cisco AnyConnect VPN Client for SSL connections, it can provide a better throughput performance compared to TLS (Transport Layer Security). DTLS uses UDP as the transport protocol, and it is designed for use in situations where the underlying transport protocol is unreliable, this allows DTLS to be more efficient than TCP-based TLS, especially in situations where network conditions are less than ideal.
DTLS is a variation of the TLS protocol that is optimized for use over unreliable networks and is implemented on top of the User Datagram Protocol (UDP) to provide a more efficient and faster data transfer. It provides similar security to TLS and it is used by Cisco AnyConnect VPN client to secure communications between the VPN client and the VPN server.
A is correct
By default, group policies on ASAs are configured to attempt establishing a DTLS tunnel. If UDP 443 traffic is blocked between the VPN headend and the AnyConnect client, it will automatically fallback to TLS. It is recommended to use DTLS or IKEv2 to increase maximum VPN throughput performance. DTLS offers better performance than TLS due to less protocol overhead. IKEv2 also offers better throughput than TLS. Additionally, using AES-GCM ciphers may slightly improve performance. These ciphers are available in TLS 1.2, DTLS 1.2 and IKEv2.
upvoted 3 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Husein2024
1 month, 2 weeks agoMarshpillowz
3 months, 2 weeks agoch1be2les3
7 months agosull3y
1 year, 6 months agomecacig953
2 years, 4 months ago