22 February, 2020
Implementing Cisco Secure Mobility Solutions (SIMOS) 300-209 Rapidshare
Your success in Cisco 300-209 is our sole target and we develop all our 300-209 braindumps in a way that facilitates the attainment of this target. Not only is our 300-209 study material the best you can find, it is also the most detailed and the most updated. 300-209 Practice Exams for Cisco 300-209 are written to the highest standards of technical accuracy.
Free 300-209 Demo Online For Cisco Certifitcation:
Question 1
- (Exam Topic 2)
A user is trying to connect to a Cisco IOS device using clientless SSL VPN and cannot establish the connection. Which three commands can be used for troubleshooting of the AAA subsystem? (Choose three.)
A user is trying to connect to a Cisco IOS device using clientless SSL VPN and cannot establish the connection. Which three commands can be used for troubleshooting of the AAA subsystem? (Choose three.)
Question 2
- (Exam Topic 1)
Which two parameters are specified in the isakmp (IKEv1) policy? (Choose two.)
Which two parameters are specified in the isakmp (IKEv1) policy? (Choose two.)
Question 3
- (Exam Topic 3)
Refer to the exhibit.
A NOC engineer is in the process of entering information into the Create New VPN Connection Entry fields. Which statement correctly describes how to do this?
Refer to the exhibit.
A NOC engineer is in the process of entering information into the Create New VPN Connection Entry fields. Which statement correctly describes how to do this?
Question 4
- (Exam Topic 2)
Refer to the exhibit.
What technology does the given configuration demonstrate?
Refer to the exhibit.
What technology does the given configuration demonstrate?
Question 5
- (Exam Topic 2)
Which algorithm provides both encryption and authentication for data plane communication?
Which algorithm provides both encryption and authentication for data plane communication?
Question 6
- (Exam Topic 1)
When a tunnel is initiated by the headquarter ASA, which one of the following Diffie-Hellman groups is selected by the headquarter ASA during CREATE_CHILD_SA exchange?
When a tunnel is initiated by the headquarter ASA, which one of the following Diffie-Hellman groups is selected by the headquarter ASA during CREATE_CHILD_SA exchange?
Question 7
- (Exam Topic 3)
Refer to the exhibit. Client 1 cannot communication with Client 2. Both clients are using Cisco AnyConnect and have established a successful SSL VPN connection to the hub ASA. Which command on the ASA is missing?
Refer to the exhibit. Client 1 cannot communication with Client 2. Both clients are using Cisco AnyConnect and have established a successful SSL VPN connection to the hub ASA. Which command on the ASA is missing?
Question 8
- (Exam Topic 3)
Refer to the exhibit.
A junior network engineer configured the corporate Cisco ASA appliance to accommodate a new temporary worker. For security reasons, the IT department wants to restrict the internal network access of the new temporary worker to the corporate server, with an IP address of 10.0.4.10. After the junior network engineer finished the configuration, an IT security specialist tested the account of the temporary worker. The tester was able to access the URLs of additional secure servers from the WebVPN user account of the temporary worker.
What did the junior network engineer configure incorrectly?
Refer to the exhibit.
A junior network engineer configured the corporate Cisco ASA appliance to accommodate a new temporary worker. For security reasons, the IT department wants to restrict the internal network access of the new temporary worker to the corporate server, with an IP address of 10.0.4.10. After the junior network engineer finished the configuration, an IT security specialist tested the account of the temporary worker. The tester was able to access the URLs of additional secure servers from the WebVPN user account of the temporary worker.
What did the junior network engineer configure incorrectly?
Question 9
- (Exam Topic 2)
Which technology is FlexVPN based on?
Which technology is FlexVPN based on?
Question 10
- (Exam Topic 3)
Refer to the exhibit.
What is the problem with the IKEv2 site-to-site VPN tunnel?
Refer to the exhibit.
What is the problem with the IKEv2 site-to-site VPN tunnel?
Question 11
- (Exam Topic 1)
What are two benefits of DMVPN Phase 3? (Choose two.)
What are two benefits of DMVPN Phase 3? (Choose two.)
Question 12
- (Exam Topic 1)
A private wan connection is suspected of intermittently corrupting data. Which technology can a network administrator use to detect and drop the altered data traffic?
A private wan connection is suspected of intermittently corrupting data. Which technology can a network administrator use to detect and drop the altered data traffic?
Question 13
- (Exam Topic 2)
Which two statements about the Cisco ASAClientless SSL VPN solution are true? (Choose two.)
Which two statements about the Cisco ASAClientless SSL VPN solution are true? (Choose two.)
Question 14
- (Exam Topic 2)
Which cryptographic algorithms are a part of the Cisco NGE suite?
Which cryptographic algorithms are a part of the Cisco NGE suite?
Question 15
- (Exam Topic 1)
An internet-based VPN solution is being considered to replace an existing private WAN connecting remote offices. A multimedia application is used that relies on multicast for communication. Which two VPN solutions meet the application's network requirement? (Choose two.)
An internet-based VPN solution is being considered to replace an existing private WAN connecting remote offices. A multimedia application is used that relies on multicast for communication. Which two VPN solutions meet the application's network requirement? (Choose two.)
Question 16
- (Exam Topic 1)
Refer to the exhibit.
After the configuration is performed, which combination of devices can connect?
Refer to the exhibit.
After the configuration is performed, which combination of devices can connect?
Question 17
- (Exam Topic 1)
Refer to the exhibit.
An administrator had the above configuration working with SSL protocol, but as soon as the administrator specified IPsec as the primary protocol, the Cisco AnyConnect client was not able to connect. What is the problem?
Refer to the exhibit.
An administrator had the above configuration working with SSL protocol, but as soon as the administrator specified IPsec as the primary protocol, the Cisco AnyConnect client was not able to connect. What is the problem?
Question 18
- (Exam Topic 1)
What are two forms of SSL VPN? (Choose two.)
What are two forms of SSL VPN? (Choose two.)
Question 19
- (Exam Topic 3)
Which PKI enrollment method allows the user to separate authentication and enrollment actions and also provides an option to specify HTTP/TFTP commands to perform file retrieval from the server?
Which PKI enrollment method allows the user to separate authentication and enrollment actions and also provides an option to specify HTTP/TFTP commands to perform file retrieval from the server?
Question 20
- (Exam Topic 1)
An administrator wishes to limit the networks reachable over the Anyconnect VPN tunnels. Which configuration on the ASA will correctly limit the networks reachable to 209.165.201.0/27 and 209.165.202.128/27?
An administrator wishes to limit the networks reachable over the Anyconnect VPN tunnels. Which configuration on the ASA will correctly limit the networks reachable to 209.165.201.0/27 and 209.165.202.128/27?
Question 21
- (Exam Topic 1)
A company needs to provide secure access to its remote workforce. The end users use public kiosk computers and a wide range of devices. They will be accessing only an internal web application. Which VPN solution satisfies these requirements?
A company needs to provide secure access to its remote workforce. The end users use public kiosk computers and a wide range of devices. They will be accessing only an internal web application. Which VPN solution satisfies these requirements?
Question 22
What is the name of the transform set being used on the ISR?
Question 23
- (Exam Topic 2)
An administrator desires that when work laptops are not connected to the corporate network, they should automatically initiate an AnyConnect VPN tunnel back to headquarters. Where does the administrator configure this?
An administrator desires that when work laptops are not connected to the corporate network, they should automatically initiate an AnyConnect VPN tunnel back to headquarters. Where does the administrator configure this?
Question 24
- (Exam Topic 1)
An engineer is troubleshooting DMVPN and wants to check if traffic flows in only one direction
An engineer is troubleshooting DMVPN and wants to check if traffic flows in only one direction
Question 25
- (Exam Topic 3)
An XYZ Corporation systems engineer, while making a sales call on the ABC Corporation headquarters, tried to access the XYZ sales demonstration folder to transfer a demonstration via FTP from an ABC conference room behind the firewall. The engineer could not reach XYZ through the remote-access VPN tunnel. From home the previous day, however, the engineer did connect to the XYZ sales demonstration folder and transferred the demonstration via IPsec over DSL.
To get the connection to work and transfer the demonstration, what should the engineer do?
An XYZ Corporation systems engineer, while making a sales call on the ABC Corporation headquarters, tried to access the XYZ sales demonstration folder to transfer a demonstration via FTP from an ABC conference room behind the firewall. The engineer could not reach XYZ through the remote-access VPN tunnel. From home the previous day, however, the engineer did connect to the XYZ sales demonstration folder and transferred the demonstration via IPsec over DSL.
To get the connection to work and transfer the demonstration, what should the engineer do?
Question 26
- (Exam Topic 1)
A custom desktop application needs to access an internal server. An administrator is tasked with configuring the company's SSL VPN gateway to allow remote users to work. Which two technologies would accommodate the company's requirement? (Choose two).
A custom desktop application needs to access an internal server. An administrator is tasked with configuring the company's SSL VPN gateway to allow remote users to work. Which two technologies would accommodate the company's requirement? (Choose two).
Question 27
- (Exam Topic 1)
Drag and drop the debug messages on the left onto the associated function during trouble shooting on the right.
Solution:
Does this meet the goal?
Drag and drop the debug messages on the left onto the associated function during trouble shooting on the right.
Solution:
Does this meet the goal?
Question 28
- (Exam Topic 2)
Which two are features of GETVPN but not DMVPN and FlexVPN? (Choose two.)
Which two are features of GETVPN but not DMVPN and FlexVPN? (Choose two.)
Question 29
- (Exam Topic 3)
Which DAP endpoint attribute checks for the matching MAC address of a client machine?
Which DAP endpoint attribute checks for the matching MAC address of a client machine?