Get Full Version of the Exam
http://www.EnsurePass.com/300-206.html
Question No.51
A Cisco ASA is configured in multiple context mode and has two user-defined contexts Context_A and Context_B. From which context are device logging messages sent?
-
Admin
-
Context_A
-
Context_B
-
System
Correct Answer: A
Question No.52
What are two primary purposes of Layer 2 detection in Cisco IPS networks? (Choose two.)
-
identifying Layer 2 ARP attacks
-
detecting spoofed MAC addresses and tracking 802.1X actions and data communication after a successful client association
-
detecting and preventing MAC address spoofing in switched environments
-
mitigating man-in-the-middle attacks
Correct Answer: AD
Question No.53
At which layer does Dynamic ARP Inspection validate packets?
-
Layer 2
-
Layer 3
-
Layer 4
-
Layer 7
Correct Answer: A
Question No.54
Your company is replacing a high-availability pair of Cisco ASA 5550 firewalls with the newer Cisco ASA 5555-X models. Due to budget constraints, one Cisco ASA 5550 will be replaced at a time. Which statement about the minimum requirements to set up stateful failover between these two firewalls is true?
-
You must install the USB failover cable between the two Cisco ASAs and provide a 1 Gigabit Ethernet interface for state exchange.
-
It is not possible to use failover between different Cisco ASA models.
-
You must have at least 1 Gigabit Ethernet interface between the two Cisco ASAs for state exchange.
-
You must use two dedicated interfaces. One link is dedicated to state exchange and the other link is for heartbeats.
Correct Answer: B
Question No.55
Which two device types can Cisco Prime Security Manager manage in Multiple Device mode? (Choose two.)
-
Cisco ESA
-
Cisco ASA
-
Cisco WSA
-
Cisco ASA CX
Correct Answer: BD
Question No.56
When configured in accordance to Cisco best practices, the ip verify source command can mitigate which two types of Layer 2 attacks? (Choose two.)
-
rogue DHCP servers
-
ARP attacks
-
DHCP starvation
-
MAC spoofing
-
CAM attacks
-
IP spoofing
Correct Answer: DF
Question No.57
Which three options are default settings for NTP parameters on a Cisco ASA? (Choose three.)
-
NTP authentication is enabled.
-
NTP authentication is disabled.
-
NTP logging is enabled.
-
NTP logging is disabled.
-
NTP traffic is not restricted.
-
NTP traffic is restricted.
Correct Answer: BDE
Question No.58
Which two parameters must be configured before you enable SCP on a router? (Choose two.)
-
SSH
-
authorization
-
ACLs
-
NTP
-
TACACS
Correct Answer: AB
Question No.59
Which type of object group will allow configuration for both TCP 80 and TCP 443?
-
service
-
network
-
time range
-
user group
Correct Answer: A
Question No.60
A rogue device has connected to the network and has become the STP root bridge, which has caused a network availability issue. Which two commands can protect against this problem? (Choose two.)
-
switch(config)#spanning-tree portfast bpduguard default
-
switch(config)#spanning-tree portfast bpdufilter default
-
switch(config-if)#spanning-tree portfast
-
switch(config-if)#spanning-tree portfast disable
-
switch(config-if)#switchport port-security violation protect
-
switch(config-if)#spanning-tree port-priority 0
Correct Answer: AC
Get Full Version of the Exam
300-206 Dumps
300-206 VCE and PDF