Cisco® 300-209 Exam Practice Questions (P. 5)
- Full Access (314 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #41
Which two statements are true when designing a SSL VPN solution using Cisco AnyConnect? (Choose two.)
- AThe VPN server must have a self-signed certificate.
- BA SSL group pre-shared key must be configured on the server.
- CServer side certificate is optional if using AAA for client authentication.
- DThe VPN IP address pool can overlap with the rest of the LAN networks.
- EDTLS can be enabled for better performance.
Correct Answer:
DE
DE
send
light_mode
delete
Question #42
Which two features are required when configuring a DMVPN network? (Choose two.)
- ADynamic routing protocol
- BGRE tunnel interface
- CNext Hop Resolution Protocol
- DDynamic crypto map
- EIPsec encryption
Correct Answer:
BC
BC
send
light_mode
delete
Question #43
What are two benefits of DMVPN Phase 3? (Choose two.)
- AAdministrators can use summarization of routing protocol updates from hub to spokes.
- BIt introduces hierarchical DMVPN deployments.
- CIt introduces non-hierarchical DMVPN deployments.
- DIt supports L2TP over IPSec as one of the VPN protocols.
Correct Answer:
AB
AB
send
light_mode
delete
Question #44
Which are two main use cases for Clientless SSL VPN? (Choose two.)
- AIn kiosks that are part of a shared environment
- BWhen the users do not have admin rights to install a new VPN client
- CWhen full tunneling is needed to support applications that use TCP, UDP, and ICMP
- DTo create VPN site-to-site tunnels in combination with remote access
Correct Answer:
AB
AB
send
light_mode
delete
Question #45
Which technology can rate-limit the number of tunnels on a DMVPN hub when system utilization is above a specified percentage?
- ANHRP Event Publisher
- Binterface state control
- CCAC
- DNHRP Authentication
- Eip nhrp connect
Correct Answer:
C
C
send
light_mode
delete
Question #46
Which technology supports tunnel interfaces while remaining compatible with legacy VPN implementations?
send
light_mode
delete
Question #47
Which IKEv2 feature minimizes the configuration of a FlexVPN on Cisco IOS devices?
send
light_mode
delete
Question #48
When an IPsec SVTI is configured, which technology processes traffic forwarding for encryption?
send
light_mode
delete
Question #49
An IOS SSL VPN is configured to forward TCP ports. A remote user cannot access the corporate FTP site with a Web browser. What is a possible reason for the failure?
- AThe user's FTP application is not supported.
- BThe user is connecting to an IOS VPN gateway configured in Thin Client Mode.
- CThe user is connecting to an IOS VPN gateway configured in Tunnel Mode.
- DThe user's operating system is not supported.
Correct Answer:
B
Reference:
http://www.cisco.com/c/en/us/support/docs/security/ssl-vpn-client/70664-IOSthinclient.html
Thin-Client SSL VPN (Port Forwarding)
A remote client must download a small, Java-based applet for secure access of TCP applications that use static port numbers. UDP is not supported. Examples include access to POP3, SMTP, IMAP, SSH, and Telnet. The user needs local administrative privileges because changes are made to files on the local machine.
This method of SSL VPN does not work with applications that use dynamic port assignments, for example, several FTP applications.
B
Reference:
http://www.cisco.com/c/en/us/support/docs/security/ssl-vpn-client/70664-IOSthinclient.html
Thin-Client SSL VPN (Port Forwarding)
A remote client must download a small, Java-based applet for secure access of TCP applications that use static port numbers. UDP is not supported. Examples include access to POP3, SMTP, IMAP, SSH, and Telnet. The user needs local administrative privileges because changes are made to files on the local machine.
This method of SSL VPN does not work with applications that use dynamic port assignments, for example, several FTP applications.
send
light_mode
delete
Question #50
A Cisco IOS SSL VPN gateway is configured to operate in clientless mode so that users can access file shares on a Microsoft Windows 2003 server. Which protocol is used between the Cisco IOS router and the Windows server?
send
light_mode
delete
All Pages