Exit demo 300-209 Implementing Cisco Secure Mobility Solutions PDF format · free preview

Cisco 300-209 - Questions & Answers

Free preview · every answer includes a full explanation

Product page: https://prepkeys.com/300-209.html

Question 1
Multiple choice

Which two statements comparing ECC and RSA are true? (Choose two.)

A.

ECC can have the same security as RSA but with a shorter key size.

B.

ECC lags in performance when compared with RSA.

C.

Key generation in ECC is slower and less CPU intensive.

D.

ECC cannot have the same security as RSA, even with an increased key size.

E.

Key generation in ECC is faster and less CPU intensive.

Question 2
Multiple choice

Which two are features of GETVPN but not DMVPN and FlexVPN? (Choose two.)

A.

one IPsec SA for all encrypted traffic

B.

no requirement for an overlay routing protocol

C.

design for use over public or private WAN

D.

sequence numbers that enable scalable replay checking

E.

enabled use of ESP or AH

F.

preservation of IP protocol in outer header

Question 3
Multiple choice

A customer requires all traffic to go through a VPN. However, access to the local network is also required.

Which two options can enable this configuration? (Choose two.)

A.

split exclude

B.

use of an XML profile

C.

full tunnel by default

D.

split tunnel

E.

split include

Question 4
Single choice

As network consultant, you are asked to suggest a VPN technology that can support a multivendor environment and secure traffic between sites.

Which technology should you recommend?

A.

DMVPN

B.

FlexVPN

C.

GET VPN

D.

SSL VPN

Question 5
Single choice

Which protocol must be enabled on the inside interface to use cluster encryption in SSL VPN load balancing?

A.

TLS

B.

DTLS

C.

IKEv2

D.

ISAKMP

Question 6
Single choice

Refer to the exhibit.

Which type of VPN implementation is displayed?

A.

IKEv2 reconnect

B.

IKEv1 cluster

C.

IKEv2 load balancer

D.

IKEv1 client

E.

IPsec high availability

F.

IKEv2 backup gateway

Question 7
Single choice

Which PKI enrollment method allows the user to separate authentication and enrollment actions and also provides an option to specify HTTP/TFTP commands to perform file retrieval from the server?

A.

enrollment profile

B.

enrollment terminal

C.

enrollment url

D.

enrollment selfsigned

Question 8
Single choice

Refer to the exhibit. A customer cannot establish an IKEv2 site-to-site VPN tunnel between two Cisco ASA devices.
Based on the syslog message, which action can bring up the VPN tunnel?

A.

Increase the maximum SA limit on the local Cisco ASA.

B.

Correct the crypto access list on both Cisco ASA devices.

C.

Remove the maximum SA limit on the remote Cisco ASA.

D.

Reduce the maximum SA limit on the local Cisco ASA.

E.

Correct the IP address in the local and remote crypto maps.

F.

Increase the maximum SA limit on the remote Cisco ASA.

Question 9
Single choice

Refer to the exhibit.

Which type of VPN is being configured, based on the partial configuration snippet?

A.

DMVPN with dual hub

B.

GET VPN with dual group member

C.

FlexVPN backup gateway

D.

GET VPN with COOP key server

E.

FlexVPN load balancer

Question 10
Single choice

Which configuration is used to build a tunnel between a Cisco ASA and ISR?

A.

crypto map

B.

DMVPN

C.

GET VPN

D.

GRE with IPsec

E.

GRE without IPsec

Showing 10 of 450 questions · Unlock the full set