300-208 Exam Details

  • Exam Code
    :300-208
  • Exam Name
    :Implementing Cisco Secure Access Solutions
  • Certification
    :Cisco Certifications
  • Vendor
    :Cisco
  • Total Questions
    :478 Q&As
  • Last Updated
    :Dec 11, 2021

Cisco 300-208 Online Questions & Answers

  • Question 331:

    Cisco 802.1X phasing enables flexible deployments through the use of open, low-impact, and closed modes. What is a unique characteristic of the most secure mode?

    A. Granular ACLs applied prior to authentication
    B. Per user dACLs applied after successful authentication
    C. Only EAPoL traffic allowed prior to authentication
    D. Adjustable 802.1X timers to enable successful authentication

  • Question 332:

    Which three algorithms should be avoided due to security concerns? (Choose three.)

    A. DES for encryption
    B. SHA-1 for hashing
    C. 1024-bit RSA
    D. AES GCM mode for encryption
    E. HMAC-SHA-1
    F. 256-bit Elliptic Curve Diffie-Hellman
    G. 2048-bit Diffie-Hellman

  • Question 333:

    Which statement about system time and NTP server configuration with Cisco ISE is true?

    A. The system time and NTP server settings can be configured centrally on the Cisco ISE.
    B. The system time can be configured centrally on the Cisco ISE, but NTP server settings must be configured individually on each ISE node.
    C. NTP server settings can be configured centrally on the Cisco ISE, but the system time must be configured individually on each ISE node.
    D. The system time and NTP server settings must be configured individually on each ISE node.

  • Question 334:

    After you connected unmanaged switch to the port dot1x failed,what is the problem?

    A. missing command "mab"
    B. there is no Bpdu in the port
    C. eapol packet not erceived in the port
    D. missing command "authentication host-mode multi-host"
    E. missing command "authentication host-mode multi-auth

  • Question 335:

    Which profiling probe collects the user-agent string?

    A. NetFlow
    B. DHCP
    C. Network Scan
    D. HTTP

  • Question 336:

    Which certificate authority is used for identity source real time certificate validation?

    A. OCSP

  • Question 337:

    What are two actions that can occur when an 802.1X-enabled port enters violation mode? (Choose two.)

    A. The port is error disabled.
    B. The port drops packets from any new device that sends traffic to the port.
    C. The port generates a port resistance error.
    D. The port attempts to repair the violation.
    E. The port is placed in quarantine state.
    F. The port is prevented from authenticating indefinitely.

  • Question 338:

    Which command used to enable SGACL globally?

    A. cts role-based-enforcement

  • Question 339:

    Which command configures console port authorization under line con 0?

    A. authorization default|WORD
    B. authorization exec line con 0|WORD
    C. authorization line con 0|WORD
    D. authorization exec default|WORD

  • Question 340:

    With which two appliance-based products can Cisco Prime Infrastructure integrate to perform centralized management? (Choose two.)

    A. Cisco Managed Services Engine
    B. Cisco Email Security Appliance
    C. Cisco Wireless Location Appliance
    D. Cisco Content Security Appliance
    E. Cisco ISE

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cisco exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 300-208 exam preparations and Cisco certification application, do not hesitate to visit our Vcedump.com to find your solutions here.