Cisco® 300-206 Exam Practice Questions (P. 1)
- Full Access (368 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #1
All 30 users on a single floor of a building are complaining about network slowness. After investigating the access switch, the network administrator notices that the MAC address table is full (10,000 entries) and all traffic is being flooded out of every port. Which action can the administrator take to prevent this from occurring?
- AConfigure port-security to limit the number of mac-addresses allowed on each port
- BUpgrade the switch to one that can handle 20,000 entries
- CConfigure private-vlans to prevent hosts from communicating with one another
- DEnable storm-control to limit the traffic rate
- EConfigure a VACL to block all IP traffic except traffic to and from that subnet
Correct Answer:
A
A
send
light_mode
delete
Question #2
A network printer has a DHCP server service that cannot be disabled. How can a layer 2 switch be configured to prevent the printer from causing network issues?
- ARemove the ip helper-address
- BConfigure a Port-ACL to block outbound TCP port 68
- CConfigure DHCP snooping
- DConfigure port-security
Correct Answer:
C
C
send
light_mode
delete
Question #3
A switch is being configured at a new location that uses statically assigned IP addresses. Which will ensure that ARP inspection works as expected?
- AConfigure the 'no-dhcp' keyword at the end of the ip arp inspection command
- BEnable static arp inspection using the command 'ip arp inspection static vlan vlan-number
- CConfigure an arp access-list and apply it to the ip arp inspection command
- DEnable port security
Correct Answer:
C
C
send
light_mode
delete
Question #4
Which of the following would need to be created to configure an application-layer inspection of SMTP traffic operating on port 2525?
- AA class-map that matches port 2525 and applying an inspect ESMTP policy-map for that class in the global inspection policy
- BA policy-map that matches port 2525 and applying an inspect ESMTP class-map for that policy
- CAn access-list that matches on TCP port 2525 traffic and applying it on an interface with the inspect option
- DA class-map that matches port 2525 and applying it on an access-list using the inspect option
Correct Answer:
A
A
send
light_mode
delete
Question #5
Which command is used to nest objects in a pre-existing group?
- Aobject-group
- Bnetwork group-object
- Cobject-group network
- Dgroup-object
Correct Answer:
D
D
send
light_mode
delete
Question #6
Which threat-detection feature is used to keep track of suspected attackers who create connections to too many hosts or ports?
- Acomplex threat detection
- Bscanning threat detection
- Cbasic threat detection
- Dadvanced threat detection
Correct Answer:
B
B
send
light_mode
delete
Question #7
What is the default behavior of an access list on the Cisco ASA security appliance?
- AIt will permit or deny traffic based on the access-list criteria.
- BIt will permit or deny all traffic on a specified interface.
- CAn access group must be configured before the access list will take effect for traffic control.
- DIt will allow all traffic.
Correct Answer:
C
C
send
light_mode
delete
Question #8
What is the default behavior of NAT control on Cisco ASA Software Version 8.3?
- ANAT control has been deprecated on Cisco ASA Software Version 8.3.
- BIt will prevent traffic from traversing from one enclave to the next without proper access configuration.
- CIt will allow traffic to traverse from one enclave to the next without proper access configuration.
- DIt will deny all traffic.
Correct Answer:
A
A
send
light_mode
delete
Question #9
Which three options are hardening techniques for Cisco IOS routers? (Choose three.)
- Alimiting access to infrastructure with access control lists
- Benabling service password recovery
- Cusing SSH whenever possible
- Dencrypting the service password
- Eusing Telnet whenever possible
- Fenabling DHCP snooping
Correct Answer:
ACD
ACD
send
light_mode
delete
Question #10
Which three commands can be used to harden a switch? (Choose three.)
- Aswitch(config-if)# spanning-tree bpdufilter enable
- Bswitch(config)# ip dhcp snooping
- Cswitch(config)# errdisable recovery interval 900
- Dswitch(config-if)# spanning-tree guard root
- Eswitch(config-if)# spanning-tree bpduguard disable
- Fswitch(config-if)# no cdp enable
Correct Answer:
BDF
BDF
send
light_mode
delete
All Pages