Cisco® 300-206 Exam Practice Questions (P. 3)
- Full Access (368 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #21
When a Cisco ASA is configured in multicontext mode, which command is used to change between contexts?
- Achangeto config context
- Bchangeto context
- Cchangeto/config context change
- Dchangeto/config context 2
Correct Answer:
B
B
send
light_mode
delete
Question #22
Which statement about the Cisco Security Manager 4.4 NAT Rediscovery feature is true?
- AIt provides NAT policies to existing clients that connect from a new switch port.
- BIt can update shared policies even when the NAT server is offline.
- CIt enables NAT policy discovery as it updates shared polices.
- DIt enables NAT policy rediscovery while leaving existing shared polices unchanged.
Correct Answer:
D
D
send
light_mode
delete
Question #23
When you install a Cisco ASA AIP-SSM, which statement about the main Cisco ASDM home page is true?
- AIt is replaced by the Cisco AIP-SSM home page.
- BIt must reconnect to the NAT policies database.
- CThe administrator can manually update the page.
- DIt displays a new Intrusion Prevention panel.
Correct Answer:
D
D
send
light_mode
delete
Question #24
Which Cisco product provides a GUI-based device management tool to configure Cisco access routers?
send
light_mode
delete
Question #25
Which statement about Cisco IPS Manager Express is true?
- AIt provides basic device management for large-scale deployments.
- BIt provides a GUI for configuring IPS sensors and security modules.
- CIt enables communication with Cisco ASA devices that have no administrative access.
- DIt provides greater security than simple ACLs.
Correct Answer:
B
B
send
light_mode
delete
Question #26
Which three options describe how SNMPv3 traps can be securely configured to be sent by IOS? (Choose three.)
- AAn SNMPv3 group is defined to configure the read and write views of the group.
- BAn SNMPv3 user is assigned to SNMPv3 group and defines the encryption and authentication credentials.
- CAn SNMPv3 host is configured to define where the SNMPv3 traps will be sent.
- DAn SNMPv3 host is used to configure the encryption and authentication credentials for SNMPv3 traps.
- EAn SNMPv3 view is defined to configure the address of where the traps will be sent.
- FAn SNMPv3 group is used to configure the OIDs that will be reported.
Correct Answer:
ABC
ABC
send
light_mode
delete
Question #27
A network engineer is asked to configure NetFlow to sample one of every 100 packets on a router's fa0/0 interface. Which configuration enables sampling, assuming that NetFlow is already configured and running on the router's fa0/0 interface?
- Aflow-sampler-map flow1 mode random one-out-of 100 interface fas0/0 flow-sampler flow1
- Bflow monitor flow1 mode random one-out-of 100 interface fas0/0 ip flow monitor flow1
- Cflow-sampler-map flow1 one-out-of 100 interface fas0/0 flow-sampler flow1
- Dip flow-export source fas0/0 one-out-of 100
Correct Answer:
A
A
send
light_mode
delete
Question #28
What is the default log level on the Cisco Web Security Appliance?
send
light_mode
delete
Question #29
Which command sets the source IP address of the NetFlow exports of a device?
- Aip source flow-export
- Bip source netflow-export
- Cip flow-export source
- Dip netflow-export source
Correct Answer:
C
C
send
light_mode
delete
Question #30
Which two SNMPv3 features ensure that SNMP packets have been sent securely?" Choose two.
send
light_mode
delete
All Pages