This page was exported from New Braindump2go Exam Dumps
[
https://www.eccouncildumps.com
]
Export date: Fri Mar 29 7:35:05 2024 / +0000 GMT
2018 April Latest Cisco 300-209 Exam Dumps with PDF and VCE Just Updated Today! Following are some new 300-209 Real Exam Questions: 1.|2018 Latest 300-209 Exam Dumps (PDF & VCE) 319Q&As Download: https://www.braindump2go.com/300-209.html 2.|2018 Latest 300-209 Exam Questions & Answers Download: https://drive.google.com/drive/folders/0B75b5xYLjSSNRkY3M21SbTdTNDg?usp=sharing QUESTION 198 A. SAML Answer: BCD QUESTION 199 A. Smart tunnels are enabled on the secure gateway (Cisco ASA) for specific applications that run on the end client and work irrespective of which transport protocol the application uses. Answer: CD QUESTION 200 A. IPsec DVTI Answer: E QUESTION 201 A. transform set Answer: ABG QUESTION 202 A. MD5 produces a 64-bit message digest. Answer: B QUESTION 203 A. PSK Answer: A QUESTION 204 A. Enable EIGRP next-hop-self on the hub. Answer: BDE QUESTION 205 A. SHA-96 Answer: E QUESTION 206 A. Only the IKE configuration that is set up on the active device must be duplicated on the standby device; the IPsec configuration is copied automatically. Answer: CEG QUESTION 207 A. ECC can have the same security as RSA but with a shorter key size. Answer: AE QUESTION 208 A. one IPsec SA for all encrypted traffic Answer: AB 1.|2018 Latest 300-209 Exam Dumps (PDF & VCE) 319Q&As Download: 2.|2018 Latest 300-209 Study Guide Video:
Which three types of SSO functionality are available on the Cisco ASA without any external SSO servers? (Choose three.)
B. HTTP POST
C. HTTP Basic
D. NTLM
E. Kerberos
F. OAuth 2.0
Which two statements about the Cisco ASA Clientless SSL VPN smart tunnels feature are true? (Choose two.)
B. Smart tunnels require Administrative privileges to run on the client machine.
C. A smart tunnel is a DLL that is pushed from the headend to the client machine after SSL VPN portal authentication and that is attached to smart-tunneled processes to route traffic through the SSL VPN session with the gateway.
D. Smart tunnels offer better performance than the client-server plugins.
E. Smart tunnels are supported on Windows, Mac, and Linux.
As network security architect, you must implement secure VPN connectivity among company branches over a private IP cloud with any-to-any scalable connectivity.
Which technology should you use?
B. FlexVPN
C. DMVPN
D. IPsec SVTI
E. GET VPN
Which three configurations are required for both IPsec VTI and crypto map-based VPNs? (Choose three.)
B. ISAKMP policy
C. ACL that defines traffic to encrypt
D. dynamic routing protocol
E. tunnel interface
F. IPsec profile
G. PSK or PKI trustpoint with certificate
Which statement regarding hashing is correct?
B. SHA-1 produces a 160-bit message digest.
C. MD5 takes more CPU cycles to compute than SHA-1.
D. Changing 1 bit of the input to SHA-1 can change up to 5 bits in the output.
Refer to the exhibit. Which type of mismatch is causing the problem with the IPsec VPN tunnel?
B. Phase 1 policy
C. transform set
D. crypto access list
Which three changes must be made to migrate from DMVPN Phase 2 to Phase 3 when EIGRP is configured? (Choose three.)
B. Disable EIGRP next-hop-self on the hub.
C. Enable EIGRP split-horizon on the hub.
D. Add NHRP redirects on the hub.
E. Add NHRP shortcuts on the spoke.
F. Add NHRP shortcuts on the hub.
Which algorithm provides both encryption and authentication for data plane communication?
B. SHA-384
C. 3DES
D. AES-256
E. AES-GCM
F. RC4
Which three configurations are prerequisites for stateful failover for IPsec? (Choose three.)
B. Only crypto map configuration that is set up on the active device must be duplicated on the standby device.
C. The IPsec configuration that is set up on the active device must be duplicated on the standby device.
D. The active and standby devices can run different versions of the Cisco IOS software but need to be the same type of device.
E. The active and standby devices must run the same version of the Cisco IOS software and should be the same type of device.
F. Only the IPsec configuration that is set up on the active device must be duplicated on the standby device; the IKE configuration is copied automatically.
G. The IKE configuration that is set up on the active device must be duplicated on the standby device.
Which two statements comparing ECC and RSA are true? (Choose two.)
B. ECC lags in performance when compared with RSA.
C. Key generation in ECC is slower and less CPU intensive than RSA..
D. ECC cannot have the same security as RSA, even with an increased key size.
E. Key generation in ECC is faster and less CPU intensive.
Which two are features of GETVPN but not DMVPN and FlexVPN? (Choose two.)
B. no requirement for an overlay routing protocol
C. design for use over public or private WAN
D. sequence numbers that enable scalable replay checking
E. enabled use of ESP or AH
F. preservation of IP protocol in outer header
!!!RECOMMEND!!
Post date: 2018-04-25 06:37:18
Post date GMT: 2018-04-25 06:37:18
Post modified date: 2018-04-25 06:37:18
Post modified date GMT: 2018-04-25 06:37:18
Powered by [ Universal Post Manager ] plugin. MS Word saving format developed by gVectors Team www.gVectors.com