Cisco 300-209 - Implementing Cisco Secure Mobility Solutions Exam

Question #11 (Topic: )
Which three settings are required for crypto map configuration? (Choose three.)
A. match address B. set peer C. set transform-set D. set security-association lifetime E. set security-association level per-host F. set pfs
Answer: A,B,C
Question #12 (Topic: )
Which Cisco firewall platform supports Cisco NGE?
A. FWSM B. Cisco ASA 5505 C. Cisco ASA 5580 D. Cisco ASA 5525-X
Answer: D
Question #13 (Topic: )
Refer to the exhibit.
[Cisco-300-209-15.1/Cisco-300-209-7_2.png]
The "level_2" digital certificate was installed on a laptop.
What can cause an "invalid not active" status message?
A. On first use, a CA server-supplied passphrase is entered to validate the certificate. B. A "newly installed" digital certificate does not become active until it is validated by the peer device upon its first usage. C. The user has not clicked the Verify button within the Cisco VPN Client. D. The CA server and laptop PC clocks are out of sync.
Answer: D
Question #14 (Topic: )
Which three types of web resources or protocols are enabled by default on the Cisco ASA
Clientless SSL VPN portal? (Choose three.)
A. HTTP B. VNC C. CIFS D. RDP E. HTTPS F. ICA (Citrix)
Answer: A,C,E
Question #15 (Topic: )
[Cisco-300-209-15.1/Cisco-300-209-8_2.png]
[Cisco-300-209-15.1/Cisco-300-209-8_3.png]
[Cisco-300-209-15.1/Cisco-300-209-9_2.png]
[Cisco-300-209-15.1/Cisco-300-209-9_3.png]
An engineer wants to ensure that employees cannot access corporate resources on
untrusted networks, but does not want a new VPN session to be established each time
they leave the trusted network. Which Cisco AnyConnect Trusted Network Policy option
allows this ability?
A. Pause B. Connect C. Do Nothing D. Disconnect
Answer: A
Download Exam
Page: 3 / 6
Total 26 questions