300-206 Exam Details

  • Exam Code
    :300-206
  • Exam Name
    :Implementing Cisco Edge Network Security Solutions
  • Certification
    :Cisco Certifications
  • Vendor
    :Cisco
  • Total Questions
    :463 Q&As
  • Last Updated
    :Dec 11, 2021

Cisco 300-206 Online Questions & Answers

  • Question 211:

    An engineer must implement secure device management on a Cisco ASA. Which two actions are required? (Choose two)

    A. enable logging
    B. enable Telnet
    C. enable SSH
    D. disable login timeouts
    E. configure SNMPv3

  • Question 212:

    Which of the following that Cisco engineer must secure a current monitoring environment? (Choose Two)

    A. RSA-SIG
    B. MD5
    C. AES
    D. 3DES
    E. DES

  • Question 213:

    CSM (or Prime Infra) Dashboards

    Correct Answer. Check the answer below

  • Question 214:

    CORRECT TEXT

    You are a network security engineer for the Secure-X network. You have been tasked with implementing dynamic network object NAT with PAT on a Cisco ASA. You must configure the Cisco ASA such that the source IP addresses of all

    internal hosts are translated to a single IP address (using different ports) when the internal hosts access the Internet.

    To successfully complete this activity, you must perform the following tasks:

    Use the Cisco ASDM GUI on the Admin PC to configure dynamic network object NAT with PAT using the following parameters:

    Network object name: Internal-Networks

    IP subnet: 10.10.0.0/16

    Translated IP address: 192.0.2.100

    Source interface: inside

    Destination interface: outside

    NOTE: The object (TRANSLATED-INSIDE-HOSTS) for this translated IP address has already been created for your use in this activity.

    NOTE: Not all ASDM screens are active for this exercise.

    NOTE: Login credentials are not needed for this simulation.

    In the Cisco ASDM, display and view the auto-generated NAT rule.

    From the Employee PC, generate traffic to SP-SRV by opening a browser and navigating to http://sp-srv.sp.public.

    From the Guest PC, generate traffic to SP-SRV by opening a browser and navigating to http://sp-srv.sp.public.

    At the CLI of the Cisco ASA, display your NAT configuration. You should see the configured policy and statistics for translated packets.

    At the CLI of the Cisco ASA, display the translation table. You should see dynamic translations for the Employee PC and the Guest PC. Both inside IP addresses translate to the same IP address, but using different ports.

    You have completed this exercise when you have configured and successfully tested dynamic network object NAT with PAT.

    Correct Answer. Check the answer below

  • Question 215:

    Which option is a valid action for a port security violation ?

    A. Restrict
    B. Reject
    C. Disable
    D. Reset

  • Question 216:

    On the Cisco ASA, where are the Layer 5-7 policy maps applied?

    A. inside the Layer 3-4 policy map
    B. inside the Layer 3-4 class map
    C. inside the Layer 5-7 class map
    D. inside the Layer 3-4 service policy
    E. inside the Layer 5-7 service policy

  • Question 217:

    When a traffic storm threshold occurs on a port, into which state can traffic storm control put the port?

    A. Disabled
    B. Err-disabled
    C. Disconnected
    D. Blocked
    E. Connected

  • Question 218:

    What is the default behavior of NAT control on Cisco ASA Software Version 8.3?

    A. NAT control has been deprecated on Cisco ASA Software Version 8.3.
    B. It will prevent traffic from traversing from one enclave to the next without proper access configuration.
    C. It will allow traffic to traverse from one enclave to the next without proper access configuration.
    D. It will deny all traffic.

  • Question 219:

    By default, how does the Cisco ASA authenticate itself to the Cisco ASDM users?

    A. The administrator validates the Cisco ASA by examining the factory built-in identity certificate thumbprint of the Cisco ASA.
    B. The Cisco ASA automatically creates and uses a persistent self-signed X.509 certificate to authenticate itself to the administrator.
    C. The Cisco ASA automatically creates a self-signed X.509 certificate on each reboot to authenticate itself to the administrator.
    D. The Cisco ASA and the administrator use a mutual password to authenticate each other.
    E. The Cisco ASA authenticates itself to the administrator using a one-time password.

  • Question 220:

    When you install a Cisco ASA AIP-SSM, which statement about the main Cisco ASDM home page is true?

    A. It is replaced by the Cisco AIP-SSM home page.
    B. It must reconnect to the NAT policies database.
    C. The administrator can manually update the page.
    D. It displays a new Intrusion Prevention panel.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cisco exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 300-206 exam preparations and Cisco certification application, do not hesitate to visit our Vcedump.com to find your solutions here.