Cisco® 300-209 Exam Practice Questions (P. 3)
- Full Access (314 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #21
When Cisco ASA applies VPN permissions, what is the first set of attributes that it applies?
- Adynamic access policy attributes
- Bgroup policy attributes
- Cconnection profile attributes
- Duser attributes
Correct Answer:
A
A
send
light_mode
delete
Question #22
What are two variables for configuring clientless SSL VPN single sign-on? (Choose two.)
- ACSCO_WEBVPN_OTP_PASSWORD
- BCSCO_WEBVPN_INTERNAL_PASSWORD
- CCSCO_WEBVPN_USERNAME
- DCSCO_WEBVPN_RADIUS_USER
Correct Answer:
BC
BC
send
light_mode
delete
Question #23
To change the title panel on the logon page of the Cisco IOS WebVPN portal, which file must you configure?
- ACisco IOS WebVPN customization template
- BCisco IOS WebVPN customization general
- Cweb-access-hlp.inc
- Dapp-access-hlp.inc
Correct Answer:
A
A
send
light_mode
delete
Question #24
Which three plugins are available for clientless SSL VPN? (Choose three.)
send
light_mode
delete
Question #25
Which command simplifies the task of converting an SSL VPN to an IKEv2 VPN on a Cisco ASA appliance that has an invalid IKEv2 configuration?
- Amigrate remote-access ssl overwrite
- Bmigrate remote-access ikev2
- Cmigrate l2l
- Dmigrate remote-access ssl
Correct Answer:
A
Below is a reference for this question:
http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/113597-ptn-113597.html
If your IKEv1, or even SSL, configuration already exists, the ASA makes the migration process simple. On the command line, enter the migrate command: migrate {l2l | remote-access {ikev2 | ssl} | overwrite}
Things of note:
Keyword definitions:
l2l - This converts current IKEv1 l2l tunnels to IKEv2.
remote access - This converts the remote access configuration. You can convert either the IKEv1 or the SSL tunnel groups to IKEv2. overwrite - If you have a IKEv2 configuration that you wish to overwrite, then this keyword converts the current IKEv1 configuration and removes the superfluous
IKEv2 configuration.
A
Below is a reference for this question:
http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/113597-ptn-113597.html
If your IKEv1, or even SSL, configuration already exists, the ASA makes the migration process simple. On the command line, enter the migrate command: migrate {l2l | remote-access {ikev2 | ssl} | overwrite}
Things of note:
Keyword definitions:
l2l - This converts current IKEv1 l2l tunnels to IKEv2.
remote access - This converts the remote access configuration. You can convert either the IKEv1 or the SSL tunnel groups to IKEv2. overwrite - If you have a IKEv2 configuration that you wish to overwrite, then this keyword converts the current IKEv1 configuration and removes the superfluous
IKEv2 configuration.
send
light_mode
delete
Question #26
Which statement describes a prerequisite for single-sign-on Netegrity Cookie Support in an IOC SSL VPN?
- AThe Cisco AnyConnect Secure Mobility Client must be installed in flash.
- BA SiteMinder plug-in must be installed on the Cisco SSL VPN gateway.
- CA Cisco plug-in must be installed on a SiteMinder server.
- DThe Cisco Secure Desktop software package must be installed in flash.
Correct Answer:
C
C
send
light_mode
delete
Question #27
Which two statements describe effects of the DoNothing option within the untrusted network policy on a Cisco AnyConnect profile? (Choose two.)
- AThe client initiates a VPN connection upon detection of an untrusted network.
- BThe client initiates a VPN connection upon detection of a trusted network.
- CThe always-on feature is enabled.
- DThe always-on feature is disabled.
- EThe client does not automatically initiate any VPN connection.
Correct Answer:
DE
Reference: https://www.cisco.com/c/en/us/td/docs/security/vpn_client/anyconnect/anyconnect40/administration/guide/b_AnyConnect_Administrator_Guide_4-0/ configure-vpn.html
DE
Reference: https://www.cisco.com/c/en/us/td/docs/security/vpn_client/anyconnect/anyconnect40/administration/guide/b_AnyConnect_Administrator_Guide_4-0/ configure-vpn.html
send
light_mode
delete
Question #28
Which command enables IOS SSL VPN Smart Tunnel support for PuTTY?
- Aappl ssh putty.exe win
- Bappl ssh putty.exe windows
- Cappl ssh putty
- Dappl ssh putty.exe
Correct Answer:
B
B
send
light_mode
delete
Question #29
Which three remote access VPN methods in an ASA appliance provide support for Cisco Secure Desktop? (Choose three.)
send
light_mode
delete
Question #30
A user is unable to establish an AnyConnect VPN connection to an ASA. When using the Real-Time Log viewer within ASDM to troubleshoot the issue, which two filter options would the administrator choose to show only syslog messages relevant to the VPN connection? (Choose two.)
- AClient's public IP address
- BClient's operating system
- CClient's default gateway IP address
- DClient's username
- EASA's public IP address
Correct Answer:
AD
AD
send
light_mode
delete
All Pages