300-209 Exam Details

  • Exam Code
    :300-209
  • Exam Name
    :Implementing Cisco Secure Mobility Solutions
  • Certification
    :Cisco Certifications
  • Vendor
    :Cisco
  • Total Questions
    :450 Q&As
  • Last Updated
    :Dec 15, 2021

Cisco 300-209 Online Questions & Answers

  • Question 291:

    An Network Engineer is troubleshooting a VPN tunnel configured on an ASA and has found that Phase 1 is not completing. Which configuration parameter must match for IKE Phae 1 tunnel to get successfully negotiated?

    A. SA lifetime
    B. transform-set
    C. DH group
    D. idle timeout

  • Question 292:

    Which IKEv2 feature minimizes the configuration of a FlexVPN on Cisco IOS devices?

    A. IKEv2 Suite-B
    B. IKEv2 proposals
    C. IKEv2 profiles
    D. IKEv2 Smart Defaults

  • Question 293:

    SIMULATION

    Scenario

    You are the network security administrator for your organization. Your company is growing and a remote branch office is being created. You are tasked with configuring your headquarters Cisco ASA to create a site-to-site IPsec VPN

    connection to the branch office Cisco ISR. The branch office ISR has already been deployed and configured and you need to complete the IPsec connectivity configurations on the HQ ASA to bring the new office online.

    Use the following parameters to complete your configuration using ASDM. For this exercise, not all ASDM screens are active.

    Enable IKEv1 on outside I/F for Site-to-site VPN

    Add a Connection Profile with the following parameters:

    -Peer IP: 203.0.113.1

    -Connection name: 203.0.113.1

    -Local protected network: 10.10.9.0/24

    -Remote protected network: 10.11.11.0/24

    -Group Policy Name: use the default policy name supplied

    -Preshared key: cisco

    -Disable IKEv2

    -Encryption Algorithms: use the ASA defaults Disable pre-configured NAT for testing of the IPsec tunnel

    -

    Disable the outside NAT pool rule Establish the IPsec tunnel by sending ICMP pings from the Employee PC to the Branch Server at IP address 10.11.11.20 Verify tunnel establishment in ASDM VPN Statistics> Sessions window pane

    A. Check the explanation You have completed this exercise when you have successfully configured, established, and verified site-to-site IPsec connectivity between the ASA and the Branch ISR. Topology

  • Question 294:

    Refer to the exhibit. What technology does the given configuration demonstrate?

    A. Keyring used to encrypt IPSec traffic
    B. FlexVPN with IPV6
    C. FlexVPN with AnyConnect
    D. Crypto Policy to enable IKEv2

  • Question 295:

    Which two parameters are specified in the isakmp (IKEv1) policy? (Choose two.)

    A. the peer
    B. the hashing algorithm
    C. the session key
    D. the authentication method
    E. the transform-set

  • Question 296:

    Which two examples of transform sets are contained in the IKEv2 default proposal? (Choose two.)

    A. aes-cbc-192, sha256, 14
    B. 3des, md5, 5
    C. 3des, sha1, 1
    D. aes-cbc-128, sha, 5

  • Question 297:

    A network administrator is configuring AES encryption for the ISAKMP policy on an IOS router. Which two configurations are valid? (Choose two.)

    A. crypto isakmp policy 10 encryption aes 254
    B. crypto isakmp policy 10 encryption aes 192
    C. crypto isakmp policy 10 encryption aes 256
    D. crypto isakmp policy 10 encryption aes 196
    E. crypto isakmp policy 10 encryption aes 198
    F. crypto isakmp policy 10 encryption aes 64

  • Question 298:

    An engineer is configuring an IP VPN with IKEv2. Which two components are part of the IKEv2 proposal for this implementation? (Choose two.)

    A. Key ring
    B. Encryption
    C. Tunnel mode
    D. Peer name
    E. integrity

  • Question 299:

    A company's remote locations connect to data centers via MPLS.

    A new request requires that unicast traffic that exist the remote location be encrypted.

    Which no tunneled technology can be used to satisfy this requirement?

    A. SSL
    B. GET VPN
    C. DMVPN
    D. EzVPN

  • Question 300:

    Which Cisco ASDM option configures forwarding syslog messages to email?

    A. Configuration > Device Management > Logging > E-Mail Setup
    B. Configuration > Device Management > E-Mail Setup > Logging Enable
    C. Select the syslogs to email, click Edit, and select the Forward Messages option.
    D. Select the syslogs to email, click Settings, and specify the Destination Email Address option.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cisco exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 300-209 exam preparations and Cisco certification application, do not hesitate to visit our Vcedump.com to find your solutions here.