300-206 Exam Details

  • Exam Code
    :300-206
  • Exam Name
    :Implementing Cisco Edge Network Security Solutions
  • Certification
    :Cisco Certifications
  • Vendor
    :Cisco
  • Total Questions
    :463 Q&As
  • Last Updated
    :Dec 11, 2021

Cisco 300-206 Online Questions & Answers

  • Question 341:

    CSM Rules Inheritance

    Correct Answer. Check the answer below

  • Question 342:

    An engineer is adding devices to Cisco Prime Infrastructure using Discovery and wants to use Web Services Management Agent for configuring devices. Which credential setting must be used?

    A. SNMPv2 Credential
    B. SNMPv3 Credential
    C. Telnet Credential
    D. SSH Credential

  • Question 343:

    A security engineer is troubleshooting traffic across a Cisco ASA firewall using a packet tracer.

    When configuring the packet tracer, which option must be used first?

    A. interface
    B. protocol
    C. source
    D. destination

  • Question 344:

    An enterprise has enforced DHCP snooping on the enterprise switches. In which two cases does the switch drop a DHCP packet? (Choose two.)

    A. A packet is received on an untrusted interface, and the source MAC address and the DHCP client hardware address match.
    B. A DHCP relay agent forwards a DHCP packet that includes a 0.0.0.0 relay-agent IP address.
    C. The switch receives a DHCPRELEASE broadcast message that has a MAC address in the DHCP snooping binding database, and the interface information in the binding database matches the interface on which the message was received.
    D. A packet is received on an untrusted interface, and the source MAC address and the DHCP client hardware address do not match.
    E. A packet from a DHCP server, such as a DHCPOFFER or DHCPLEASEQUERY packet, is received from outside the network or firewall.

  • Question 345:

    To which port does a firewall send secure logging messages?

    A. TCP/1500
    B. UDP/1500
    C. TCP/500
    D. UDP/500

  • Question 346:

    Which statement describes the correct steps to enable Botnet Traffic Filtering on a Cisco ASA version 9.0 transparent-mode firewall with an active Botnet Traffic Filtering license?

    A. Enable DNS snooping, traffic classification, and actions.
    B. Botnet Traffic Filtering is not supported in transparent mode.
    C. Enable the use of the dynamic database, enable DNS snooping, traffic classification, and actions.
    D. Enable the use of dynamic database, enable traffic classification and actions.

  • Question 347:

    Which information does the ASA fail to replicate to the secondary Cisco ASA adaptive security appliance in an active/standby configuration with stateful and failover links?

    A. TCP sessions
    B. routing tables
    C. DHCP lease
    D. NAT translations

  • Question 348:

    An engineer must secure a LAN infrastructure from potential Layer 2 spoofing attacks. Which technology helps mitigate this issue?

    A. BPDU guard
    B. PVLANs
    C. VRFs
    D. ARP inspection

  • Question 349:

    What are three of the RBAC views within Cisco IOS Software? (Choose three.)

    A. Admin
    B. CLI
    C. Root
    D. Super Admin
    E. Guest
    F. Super

  • Question 350:

    Which two main functions for application inspection on ASA are true?

    A. When services use dynamically assigned ports, the application inspection identifies dynamic port and permits data on these ports.
    B. When services embed IP addresses in the packet, the application inspection translates embedded addresses and updates the checksum.
    C. When services are operating on nonstandard ports, the application inspection identifies the nonstandard port and allows the service to run normally.
    D. When services need IP options to function, the application inspection keeps IP options during the packet transition through the appliance.
    E. When services use load balancing, the application inspection ensures that connections are load blanaced across the servers equally.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cisco exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 300-206 exam preparations and Cisco certification application, do not hesitate to visit our Vcedump.com to find your solutions here.