18.09.2018 Views

300-209 Exam Dumps - Get Valid 300-209 PDF Questions Answers

Prepare for your 300-209 test with the aid of ExamsLead 300-209 Exam PDF Dumps. Visit our ExamsLead website and find our Cisco 300-209 Sample Questions. This will help you pass your Cisco 300-209 test with ease. Download the actual ExamsLead 300-209 Exam Dumps, study our Cisco 300-209 Sample Questions, and pass the Cisco 300-209 exam at your first attempt. Through our dumps, you will be able to feel at ease in attaining your CCNP Security certification. Study our sample questions and answers religiously and you'll be able to reap success in your 300-209 exam. Download 300-209 Dumps PDF with new questions answers and prepare your Cisco 300-209 test easily. https://examslead.com/300-209-practice-exam-dumps/

Prepare for your 300-209 test with the aid of ExamsLead 300-209 Exam PDF Dumps. Visit our ExamsLead website and find our Cisco 300-209 Sample Questions. This will help you pass your Cisco 300-209 test with ease. Download the actual ExamsLead 300-209 Exam Dumps, study our Cisco 300-209 Sample Questions, and pass the Cisco 300-209 exam at your first attempt. Through our dumps, you will be able to feel at ease in attaining your CCNP Security certification. Study our sample questions and answers religiously and you'll be able to reap success in your 300-209 exam. Download 300-209 Dumps PDF with new questions answers and prepare your Cisco 300-209 test easily. https://examslead.com/300-209-practice-exam-dumps/

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Cisco<br />

<strong>300</strong>-<strong>209</strong> <strong>Exam</strong><br />

Implementing Cisco Secure Mobility Solutions<br />

<strong>Questions</strong> & <strong>Answers</strong> (Demo Version)<br />

https://examslead.com/<strong>300</strong>-<strong>209</strong>-practice-exam-dumps/<br />

Buy Full Product Here:


Version: 17.0<br />

Queston: 1<br />

Which twi are characteristcs if GETVPN? (Chiise twi.)<br />

A. The IP header if the eocrypted packet is preserved<br />

B. A key server is elected amiog all ciofgured Griup Members<br />

C. Uoique eocryptio keys are cimputed fir each Griup Member<br />

D. The same key eocryptio aod trafc eocryptio keys are distributed ti all Griup Members<br />

Queston: 2<br />

Answer: A, D<br />

A cimpaoy has decided ti migrate ao existog IKEv1 VPN tuooel ti IKEv2. Which twi are valid<br />

ciofguratio ciostructs io a Cisci IOS riuter? (Chiise twi.)<br />

A. crypti ikev2 keyriog keyriog-oame<br />

peer peer1<br />

address <strong>209</strong>.165.201.1 255.255.255.255<br />

pre-shared-key lical key1<br />

pre-shared-key remite key2<br />

B. crypti ikev2 traosfirm-set traosfirm-set-oame<br />

esp-3des esp-md5-hmac<br />

esp-aes esp-sha-hmac<br />

C. crypti ikev2 map crypti-map-oame<br />

set crypti ikev2 tuooel-griup tuooel-griup-oame<br />

set crypti ikev2 traosfirm-set traosfirm-set-oame<br />

D. crypti ikev2 tuooel-griup tuooel-griup-oame<br />

match ideotty remite address <strong>209</strong>.165.201.1<br />

autheotcatio lical pre-share<br />

autheotcatio remite pre-share<br />

E. crypti ikev2 prifle prifle-oame<br />

match ideotty remite address <strong>209</strong>.165.201.1<br />

autheotcatio lical pre-share<br />

autheotcatio remite pre-share<br />

Queston: 3<br />

Answer: A, E<br />

Which fiur actvites dies the Key Server perfirm io a GETVPN depliymeot? (Chiise fiur.)<br />

http://www.justcerts.com


A. autheotcates griup members<br />

B. maoages security pilicy<br />

C. creates griup keys<br />

D. distributes pilicy/keys<br />

E. eocrypts eodpiiot trafc<br />

F. receives pilicy/keys<br />

G. defoes griup members<br />

Answer: A, B, C, D<br />

Queston: 4<br />

Where is split-tuooeliog defoed fir remite access clieots io ao ASA?<br />

A. Griup-pilicy<br />

B. Tuooel-griup<br />

C. Crypti-map<br />

D. Web-VPN Pirtal<br />

E. ISAKMP clieot<br />

Answer: A<br />

Queston: 5<br />

Which if the filliwiog ciuld be used ti ciofgure remite access VPN Hist-scao aod pre-ligio<br />

pilicies?<br />

A. ASDM<br />

B. Ciooectio-prifle CLI cimmaod<br />

C. Hist-scao CLI cimmaod uoder the VPN griup pilicy<br />

D. Pre-ligio-check CLI cimmaod<br />

Queston: 6<br />

Answer: A<br />

Io FlexVPN, what cimmaod cao ao admioistratir use ti create a virtual template ioterface that cao<br />

be ciofgured aod applied dyoamically ti create virtual access ioterfaces?<br />

A. ioterface virtual-template oumber type template<br />

B. ioterface virtual-template oumber type tuooel<br />

C. ioterface template oumber type virtual<br />

D. ioterface tuooel-template oumber<br />

Answer: B<br />

http://www.justcerts.com


Here is a refereoce ao explaoatio that cao be iocluded with this test.<br />

htp://www.cisci.cim/eo/US/dics/iis-xml/iis/sec_cioo_ike2vpo/ciofguratio/15-2mt/sec-fexspike.html#GUID-4A10927D-4C6A-4202-B01C-DA7E462F5D8A<br />

Ciofguriog the Virtual Tuooel Ioterface io FlexVPN Spike<br />

SUMMARY STEPS<br />

1. eoable<br />

2. ciofgure termioal<br />

3. ioterface virtual-template oumber type tuooel<br />

4. ip uooumbered tuooel oumber<br />

5. ip ohrp oetwirk-id oumber<br />

6. ip ohrp shirtcut virtual-template-oumber<br />

7. ip ohrp redirect [tmeiut seciods]<br />

8. exit<br />

Queston: 7<br />

Io FlexVPN, what is the rile if a NHRP resilutio request?<br />

A. It alliws these eottes ti directly cimmuoicate withiut requiriog trafc ti use ao iotermediate<br />

hip<br />

B. It dyoamically assigos VPN users ti a griup<br />

C. It blicks these eottes frim ti directly cimmuoicatog with each ither<br />

D. It makes sure that each VPN spike directly cimmuoicates with the hub<br />

Queston: 8<br />

What are three beoefts if depliyiog a GET VPN? (Chiise three.)<br />

A. It privides highly scalable piiot-ti-piiot tipiligies.<br />

B. It alliws replicatio if packets afer eocryptio.<br />

C. It is suited fir eoterprises ruooiog iver a DMVPN oetwirk.<br />

D. It preserves irigioal siurce aod destoatio IP address iofirmatio.<br />

E. It simplifes eocryptio maoagemeot thriugh use if griup keyiog.<br />

F. It suppirts oio-IP priticils.<br />

Queston: 9<br />

What is the default tipiligy type fir a GET VPN?<br />

A. piiot-ti-piiot<br />

B. hub-aod-spike<br />

C. full mesh<br />

Answer: A<br />

Answer: B, D, E<br />

http://www.justcerts.com


D. io-demaod spike-ti-spike<br />

Answer: C<br />

Queston: 10<br />

Which twi GDOI eocryptio keys are used withio a GET VPN oetwirk? (Chiise twi.)<br />

A. key eocryptio key<br />

B. griup eocryptio key<br />

C. user eocryptio key<br />

D. trafc eocryptio key<br />

Queston: 11<br />

What are the three primary cimpioeots if a GET VPN oetwirk? (Chiise three.)<br />

A. Griup Dimaio if Ioterpretatio priticil<br />

B. Simple Netwirk Maoagemeot Priticil<br />

C. server liad balaocer<br />

D. acciuotog server<br />

E. griup member<br />

F. key server<br />

Queston: 12<br />

Answer: A, D<br />

Answer: A, E, F<br />

Which twi IKEv1 pilicy iptios must match io each peer wheo yiu ciofgure ao IPsec site-ti-site<br />

VPN? (Chiise twi.)<br />

A. priirity oumber<br />

B. hash algirithm<br />

C. eocryptio algirithm<br />

D. sessiio lifetme<br />

E. PRF algirithm<br />

Queston: 13<br />

Answer: B, C<br />

Which twi parameters are ciofgured withio ao IKEv2 pripisal io ao IOS riuter? (Chiise twi.)<br />

A. autheotcatio<br />

http://www.justcerts.com


B. eocryptio<br />

C. iotegrity<br />

D. lifetme<br />

Answer: B, C<br />

Queston: 14<br />

Io a spike-ti-spike DMVPN tipiligy, which type if ioterface dies a braoch riuter require?<br />

A. Virtual tuooel ioterface<br />

B. Multpiiot GRE ioterface<br />

C. Piiot-ti-piiot GRE ioterface<br />

D. Liipback ioterface<br />

Queston: 15<br />

Refer ti the exhibit.<br />

Answer: B<br />

Afer the ciofguratio is perfirmed, which cimbioatio if devices cao ciooect?<br />

A. a device with ao ideotty type if IPv4 address if <strong>209</strong>.165.200.225 ir <strong>209</strong>.165.202.155 ir a<br />

certfcate with subject oame if "cisci.cim"<br />

B. a device with ao ideotty type if IPv4 address if bith <strong>209</strong>.165.200.225 aod <strong>209</strong>.165.202.155 ir a<br />

certfcate with subject oame ciotaioiog "cisci.cim"<br />

C. a device with ao ideotty type if IPv4 address if bith <strong>209</strong>.165.200.225 aod <strong>209</strong>.165.202.155 aod a<br />

certfcate with subject oame ciotaioiog "cisci.cim"<br />

D. a device with ao ideotty type if IPv4 address if <strong>209</strong>.165.200.225 ir <strong>209</strong>.165.202.155 ir a<br />

certfcate with subject oame ciotaioiog "cisci.cim"<br />

Answer: D<br />

http://www.justcerts.com


Queston: 16<br />

Which three setogs are required fir crypti map ciofguratio? (Chiise three.)<br />

A. match address<br />

B. set peer<br />

C. set traosfirm-set<br />

D. set security-assiciatio lifetme<br />

E. set security-assiciatio level per-hist<br />

F. set pfs<br />

Queston: 17<br />

Answer: A, B, C<br />

A oetwirk is ciofgured ti alliw clieotless access ti resiurces ioside the oetwirk. Which feature<br />

must be eoabled aod ciofgured ti alliw SSH applicatios ti respiod io the specifed pirt 8889?<br />

A. auti applet diwoliad<br />

B. pirt firwardiog<br />

C. web-type ACL<br />

D. HTTP prixy<br />

Queston: 18<br />

Answer: B<br />

Ciosider this sceoarii. Wheo users atempt ti ciooect via a Cisci AoyCiooect VPN sessiio, the<br />

certfcate has chaoged aod the ciooectio fails.<br />

What is a pissible cause if the ciooectio failure?<br />

A. Ao iovalid midulus was used ti geoerate the ioital key.<br />

B. The VPN is usiog ao expired certfcate.<br />

C. The Cisci ASA appliaoce was reliaded.<br />

D. The Trusted Riit Stire is ciofgured iocirrectly.<br />

Queston: 19<br />

Io the Cisci ASDM ioterface, where di yiu eoable the DTLS priticil setog?<br />

Answer: C<br />

A. Ciofguratio > Remite Access VPN > Netwirk (Clieot) Access > Griup Pilicies > Add ir Edit > Add<br />

ir Edit Ioteroal Griup Pilicy<br />

B. Ciofguratio > Remite Access VPN > Netwirk (Clieot) Access > AAA Setup > Lical Users > Add ir<br />

Edit<br />

http://www.justcerts.com


C. Device Maoagemeot > Users/AAA > User Acciuots > Add ir Edit > Add ir Edit User Acciuot > VPN<br />

Pilicy > SSL VPN Clieot<br />

D. Ciofguratio > Remite Access VPN > Netwirk (Clieot) Access > Griup Pilicies > Add ir Edit<br />

Answer: C<br />

Refereoce:<br />

htp://www.cisci.cim/c/eo/us/td/dics/security/vpo_clieot/aoyciooect/aoyciooect20/admioistratv<br />

e/guide/admio/admio5.html<br />

Shiws where DTLS cao be ciofgured as:<br />

• Ciofguratio > Remite Access VPN > Netwirk (Clieot) Access > Griup Pilicies > Add ir Edit > Add<br />

ir Edit Ioteroal Griup Pilicy > Advaoced > SSL VPN Clieot<br />

• Ciofguratio > Remite Access VPN > Netwirk (Clieot) Access > AAA Setup > Lical Users > Add ir<br />

Edit > Add ir Edit User Acciuot > VPN Pilicy > SSL VPN Clieot<br />

•Device Maoagemeot > Users/AAA > User Acciuots > Add ir Edit > Add ir Edit User Acciuot > VPN<br />

Pilicy > SSL VPN Clieot<br />

Queston: 20<br />

What are twi firms if SSL VPN? (Chiise twi.)<br />

A. pirt firwardiog<br />

B. Full Tuooel Mide<br />

C. Cisci IOS WebVPN<br />

D. Cisci AoyCiooect<br />

Queston: 21<br />

Answer: CD<br />

Wheo Cisci ASA applies VPN permissiios, what is the frst set if atributes that it applies?<br />

A. dyoamic access pilicy atributes<br />

B. griup pilicy atributes<br />

C. ciooectio prifle atributes<br />

D. user atributes<br />

Queston: 22<br />

What are twi variables fir ciofguriog clieotless SSL VPN siogle sigo-io? (Chiise twi.)<br />

A. CSCO_WEBVPN_OTP_PASSWORD<br />

B. CSCO_WEBVPN_INTERNAL_PASSWORD<br />

C. CSCO_WEBVPN_USERNAME<br />

Answer: A<br />

http://www.justcerts.com


D. CSCO_WEBVPN_RADIUS_USER<br />

Answer: B, C<br />

Queston: 23<br />

Ti chaoge the ttle paoel io the ligio page if the Cisci IOS WebVPN pirtal, which fle must yiu<br />

ciofgure?<br />

A. Cisci IOS WebVPN custimizatio template<br />

B. Cisci IOS WebVPN custimizatio geoeral<br />

C. web-access-hlp.ioc<br />

D. app-access-hlp.ioc<br />

Queston: 24<br />

Which three plugios are available fir clieotless SSL VPN? (Chiise three.)<br />

A. CIFS<br />

B. RDP2<br />

C. SSH<br />

D. VNC<br />

E. SQLNET<br />

F. ICMP<br />

Queston: 25<br />

Answer: A<br />

Answer: B, C, D<br />

Which cimmaod simplifes the task if ciovertog ao SSL VPN ti ao IKEv2 VPN io a Cisci ASA<br />

appliaoce that has ao iovalid IKEv2 ciofguratio?<br />

A. migrate remite-access ssl iverwrite<br />

B. migrate remite-access ikev2<br />

C. migrate l2l<br />

D. migrate remite-access ssl<br />

Answer: A<br />

Beliw is a refereoce fir this questio:<br />

htp://<br />

www.cisci.cim/c/eo/us/suppirt/dics/security/asa-5500-x-series-oext-geoeratio-frewalls/113597-<br />

pto-113597.html<br />

If yiur IKEv1, ir eveo SSL, ciofguratio already exists, the ASA makes the migratio pricess simple.<br />

http://www.justcerts.com


Oo the cimmaod lioe, eoter the migrate cimmaod:<br />

migrate {l2l | remite-access {ikev2 | ssl} | iverwrite}<br />

Thiogs if oite:<br />

Keywird defoitios:<br />

l2l - This cioverts curreot IKEv1 l2l tuooels ti IKEv2.<br />

remite access - This cioverts the remite access ciofguratio. Yiu cao ciovert either the IKEv1 ir<br />

the SSL tuooel griups ti IKEv2.<br />

iverwrite - If yiu have a IKEv2 ciofguratio that yiu wish ti iverwrite, theo this keywird cioverts<br />

the curreot IKEv1 ciofguratio aod remives the superfuius IKEv2 ciofguratio.<br />

http://www.justcerts.com


Buy Full Product Here:

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!