Cisco® 300-209 Exam Practice Questions (P. 1)
- Full Access (314 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #1
Which two are characteristics of GETVPN? (Choose two.)
- AThe IP header of the encrypted packet is preserved
- BA key server is elected among all configured Group Members
- CUnique encryption keys are computed for each Group Member
- DThe same key encryption and traffic encryption keys are distributed to all Group Members
Correct Answer:
AD
AD
send
light_mode
delete
Question #2
A company has decided to migrate an existing IKEv1 VPN tunnel to IKEv2. Which two are valid configuration constructs on a Cisco IOS router? (Choose two.)
- Acrypto ikev2 keyring keyring-name peer peer1 address 209.165.201.1 255.255.255.255 pre-shared-key local key1 pre-shared-key remote key2
- Bcrypto ikev2 transform-set transform-set-name esp-3des esp-md5-hmac esp-aes esp-sha-hmac
- Ccrypto ikev2 map crypto-map-name set crypto ikev2 tunnel-group tunnel-group-name set crypto ikev2 transform-set transform-set-name
- Dcrypto ikev2 tunnel-group tunnel-group-name match identity remote address 209.165.201.1 authentication local pre-share authentication remote pre-share
- Ecrypto ikev2 profile profile-name match identity remote address 209.165.201.1 authentication local pre-share authentication remote pre-share
Correct Answer:
AE
AE
send
light_mode
delete
Question #3
Which four activities does the Key Server perform in a GETVPN deployment? (Choose four.)
- Aauthenticates group members
- Bmanages security policy
- Ccreates group keys
- Ddistributes policy/keys
- Eencrypts endpoint traffic
- Freceives policy/keys
- Gdefines group members
Correct Answer:
ABCD
ABCD
send
light_mode
delete
Question #4
Where is split-tunneling defined for remote access clients on an ASA?
- AGroup-policy
- BTunnel-group
- CCrypto-map
- DWeb-VPN Portal
- EISAKMP client
Correct Answer:
A
A
send
light_mode
delete
Question #5
Which of the following could be used to configure remote access VPN Host-scan and pre-login policies?
- AASDM
- BConnection-profile CLI command
- CHost-scan CLI command under the VPN group policy
- DPre-login-check CLI command
Correct Answer:
A
A
send
light_mode
delete
Question #6
In FlexVPN, what command can an administrator use to create a virtual template interface that can be configured and applied dynamically to create virtual access interfaces?
- Ainterface virtual-template number type template
- Binterface virtual-template number type tunnel
- Cinterface template number type virtual
- Dinterface tunnel-template number
Correct Answer:
B
Here is a reference an explanation that can be included with this test. http://www.cisco.com/en/US/docs/ios-xml/ios/sec_conn_ike2vpn/configuration/15-2mt/sec-flex-spoke.html#GUID-4A10927D-4C6A-4202-B01C-DA7E462F5D8A
Configuring the Virtual Tunnel Interface on FlexVPN Spoke
SUMMARY STEPS -
1. enable
2. configure terminal
3. interface virtual-template number type tunnel
4. ip unnumbered tunnel number
5. ip nhrp network-id number
6. ip nhrp shortcut virtual-template-number
7. ip nhrp redirect [timeout seconds]
8. exit
B
Here is a reference an explanation that can be included with this test. http://www.cisco.com/en/US/docs/ios-xml/ios/sec_conn_ike2vpn/configuration/15-2mt/sec-flex-spoke.html#GUID-4A10927D-4C6A-4202-B01C-DA7E462F5D8A
Configuring the Virtual Tunnel Interface on FlexVPN Spoke
SUMMARY STEPS -
1. enable
2. configure terminal
3. interface virtual-template number type tunnel
4. ip unnumbered tunnel number
5. ip nhrp network-id number
6. ip nhrp shortcut virtual-template-number
7. ip nhrp redirect [timeout seconds]
8. exit
send
light_mode
delete
Question #7
In FlexVPN, what is the role of a NHRP resolution request?
- AIt allows these entities to directly communicate without requiring traffic to use an intermediate hop
- BIt dynamically assigns VPN users to a group
- CIt blocks these entities from to directly communicating with each other
- DIt makes sure that each VPN spoke directly communicates with the hub
Correct Answer:
A
A
send
light_mode
delete
Question #8
What are three benefits of deploying a GET VPN? (Choose three.)
- AIt provides highly scalable point-to-point topologies.
- BIt allows replication of packets after encryption.
- CIt is suited for enterprises running over a DMVPN network.
- DIt preserves original source and destination IP address information.
- EIt simplifies encryption management through use of group keying.
- FIt supports non-IP protocols.
Correct Answer:
BDE
BDE
send
light_mode
delete
Question #9
What is the default topology type for a GET VPN?
send
light_mode
delete
Question #10
Which two GDOI encryption keys are used within a GET VPN network? (Choose two.)
- Akey encryption key
- Bgroup encryption key
- Cuser encryption key
- Dtraffic encryption key
Correct Answer:
AD
AD
send
light_mode
delete
All Pages