Which three statements about Cisco AnyConnect SSL VPN with the ASA are true? (Choose three.)
A. DTLS can fall back to TLS without enabling dead peer detection.
B. By default, the VPN connection connects with DTLS.
C. Real-time application performance improves if DTLS is implemented.
D. Cisco AnyConnect connections use IKEv2 by default when it is configured as the primary protocol on the client
E. By default, the ASA uses the Cisco AnyConnect Essentials license.
F. The ASA will verify the remote HTTPS certificate
BCE
https://www.cisco.com/c/en/us/td/docs/security/asa/asa84/configuration/guide/asa_84_cli_config/vpn_anyconnect.html#pgfId-1090425
By default, DTLS is enabled when SSL VPN access is enabled on an interface. If you disable DTLS, SSL VPN connections connect with an SSL VPN tunnel only.