web analytics

300-209 New Questions

  • [May 2018] New Lead2pass Cisco 300-209 New Questions Free Download 319q

    New Released Exam 300-209 PDF Free From the Lead2pass:

    https://www.lead2pass.com/300-209.html

    QUESTION 31
    A Cisco IOS SSL VPN gateway is configured to operate in clientless mode so that users can access file shares on a Microsoft Windows 2003 server. Which protocol is used between the Cisco IOS router and the Windows server?

    A.    HTTPS
    B.    NetBIOS
    C.    CIFS
    D.    HTTP

    Answer: C

    QUESTION 32
    You are configuring a Cisco IOS SSL VPN gateway to operate with DVTI support. Which command must you configure on the virtual template?

    A.    tunnel protection ipsec
    B.    ip virtual-reassembly
    C.    tunnel mode ipsec
    D.    ip unnumbered

    Answer: D

    QUESTION 33
    Which protocol supports high availability in a Cisco IOS SSL VPN environment?

    A.    HSRP
    B.    VRRP
    C.    GLBP
    D.    IRDP

    Answer: A

    QUESTION 34
    When you configure IPsec VPN High Availability Enhancements, which technology does Cisco recommend that you enable to make reconvergence faster?

    A.    EOT
    B.    IP SLAs
    C.    periodic IKE keepalives
    D.    VPN fast detection

    Answer: C

    QUESTION 35
    Which hash algorithm is required to protect classified information?

    A.    MD5
    B.    SHA-1
    C.    SHA-256
    D.    SHA-384

    Answer: D

    QUESTION 36
    Which cryptographic algorithms are approved to protect Top Secret information?

    A.    HIPPA DES
    B.    AES-128
    C.    RC4-128
    D.    AES-256

    Answer: D

    QUESTION 37
    Which Cisco firewall platform supports Cisco NGE?

    A.    FWSM
    B.    Cisco ASA 5505
    C.    Cisco ASA 5580
    D.    Cisco ASA 5525-X

    Answer: D

    QUESTION 38
    Which algorithm is replaced by elliptic curve cryptography in Cisco NGE?

    A.    3DES
    B.    AES
    C.    DES
    D.    RSA

    Answer: D

    QUESTION 39
    Which encryption and authentication algorithms does Cisco recommend when deploying a Cisco NGE supported VPN solution?

    A.    AES-GCM and SHA-2
    B.    3DES and DH
    C.    AES-CBC and SHA-1
    D.    3DES and SHA-1

    Answer: A

    QUESTION 40
    An administrator wishes to limit the networks reachable over the Anyconnect VPN tunnels. Which configuration on the ASA will correctly limit the networks reachable to 209.165.201.0/27 and 209.165.202.128/27?

    A.    access-list splitlist standard permit 209.165.201.0 255.255.255.224
    access-list splitlist standard permit 209.165.202.128 255.255.255.224 !
    group-policy GroupPolicy1 internal
    group-policy GroupPolicy1 attributes
    split-tunnel-policy tunnelspecified
    split-tunnel-network-list value splitlist
    B.    access-list splitlist standard permit 209.165.201.0 255.255.255.224
    access-list splitlist standard permit 209.165.202.128 255.255.255.224 !
    group-policy GroupPolicy1 internal
    group-policy GroupPolicy1 attributes
    split-tunnel-policy tunnelall
    split-tunnel-network-list value splitlist
    C.    group-policy GroupPolicy1 internal
    group-policy GroupPolicy1 attributes
    split-tunnel-policy tunnelspecified
    split-tunnel-network-list ipv4 1 209.165.201.0 255.255.255.224
    split-tunnel-network-list ipv4 2 209.165.202.128 255.255.255.224
    D.    access-list splitlist standard permit 209.165.201.0 255.255.255.224
    access-list splitlist standard permit 209.165.202.128 255.255.255.224 !
    crypto anyconnect vpn-tunnel-policy tunnelspecified
    crypto anyconnect vpn-tunnel-network-list splitlist
    E.    crypto anyconnect vpn-tunnel-policy tunnelspecified
    crypto anyconnect split-tunnel-network-list ipv4 1 209.165.201.0 255.255.255.224
    crypto anyconnect split-tunnel-network-list ipv4 2 209.165.202.128 255.255.255.224

    Answer: A

    300-209 dumps full version (PDF&VCE): https://www.lead2pass.com/300-209.html

    Large amount of free 300-209 exam questions on Google Drive: https://drive.google.com/open?id=0B3Syig5i8gpDYnF5Vk16OS1tc1E

    You may also need:

    300-206 exam dumps: https://drive.google.com/open?id=0B3Syig5i8gpDQ0xqNGttYzZGYk0

    300-208 exam dumps: https://drive.google.com/open?id=0B3Syig5i8gpDMXlWOHdFVkZmREU

    300-210 exam dumps: https://drive.google.com/open?id=0B3Syig5i8gpDRF9kSExjc1FqREU