Cisco

300-209 practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 38-question bank.

Provider
Cisco
Question bank
38
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for 300-209, a certification listed under Cisco. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Cisco. The certification credential is issued by Cisco, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    Which two are characteristics of GETVPN? (Choose two.)

    Choose all answers that apply.

    • The IP header of the encrypted packet is preserved
    • A key server is elected among all configured Group Members
    • Unique encryption keys are computed for each Group Member
    • The same key encryption and traffic encryption keys are distributed to all Group Members
  2. Question 2 · 1

    Which transform set is contained in the IKEv2 default proposal?

    Choose one answer.

    • aes-cbc-192, sha256, group 14
    • 3des, md5, group 7
    • 3des, sha1, group 1
    • aes-cbc-128, sha, group 5
  3. Question 3 · 1

    The following configuration steps have been completeD. ✑ WebVPN was enabled on the ASA outside interface. ✑ SSL VPN client software was loaded to the ASA. ✑ A DHCP scope was configured and applied to a WebVPN Tunnel Group. What additional step is required if the client software fails to load when connecting to the ASA SSL page?

    Choose one answer.

    • The SSL client must be loaded to the client by an ASA administrator
    • The SSL client must be downloaded to the client via FTP
    • The SSL VPN client must be enabled on the ASA after loading
    • The SSL client must be enabled on the client machine before loading
  4. Question 4 · 1

    Refer to the exhibit. Which statement about the given IKE policy is true?

    Choose one answer.

    Question illustration 1
    • The tunnel will be valid for 2 days, 88 minutes, and 00 seconds.
    • It will use encrypted nonces for authentication.
    • It has a keepalive of 60 minutes, checking every 5 minutes.
    • It uses a 56-bit encryption algorithm.
  5. Question 5 · 1

    In which situation would you enable the Smart Tunnel option with clientless SSL VPN?

    Choose one answer.

    • when a user is using an outdated version of a web browser
    • when an application is failing in the rewrite process
    • when IPsec should be used over SSL VPN
    • when a user has a nonsupported Java version installed
    • when cookies are disabled
  6. Question 6 · 1

    Where do you configure AnyConnect certificate-based authentication in ASDM?

    Choose one answer.

    • group policies
    • AnyConnect Connection Profile
    • AnyConnect Client Profile
    • Advanced Network (Client) Access
  7. Question 7 · 1

    Refer to the exhibit. Which VPN solution does this configuration represent?

    Choose one answer.

    Question illustration 1
    • Cisco AnyConnect
    • IPsec
    • L2TP
    • SSL VPN
  8. Question 8 · 1

    In the Diffie-Hellman protocol, which type of key is the shared secret?

    Choose one answer.

    • a symmetric key
    • an asymmetric key
    • a decryption key
    • an encryption key
  9. Question 9 · 1

    Which interface is managed by the VPN Access Interface field in the Cisco ASDM IPsec Site-to-Site VPN Wizard?

    Choose one answer.

    • the local interface named "VPN_access"
    • the local interface configured with crypto enable
    • the local interface from which traffic originates
    • the remote interface with security level 0
  10. Question 10 · 1

    Which option describes the purpose of the command show derived-config interface virtual-access 1?

    Choose one answer.

    • It verifies that the virtual access interface is cloned correctly with per-user attributes.
    • It verifies that the virtual template created the tunnel interface.
    • It verifies that the virtual access interface is of type Ethernet.
    • It verifies that the virtual access interface is used to create the tunnel interface.
  11. Question 11 · 1

    Which two RADIUS attributes are needed for a VRF-aware FlexVPN hub? (Choose two.)

    Choose all answers that apply.

    • ip:interface-config=ip unnumbered loobackn
    • ip:interface-config=ip vrf forwarding ivrf
    • ip:interface-config=ip src route
    • ip:interface-config=ip next hop
    • ip:interface-config=ip neighbor 0.0.0.0
  12. Question 12 · 1

    Which option is a required element of Secure Device Provisioning communications?

    Choose one answer.

    • the introducer
    • the certificate authority
    • the requestor
    • the registration authority
  13. Question 13 · 1

    Refer to the exhibit. Based on the partial configuration shown, which the GET VPN group member GDOI configuration? ! crypto gdoi group CLASSROOM identity number 12345 ! crypto map GETVPN_MAP 10 gdoi set group CLASSROOM ! interface Serial0/0/0 ip address 192.168.1.2 255.255.255.252 crypto map GETVPN_MAP !

    Choose one answer.

    • key server IP address
    • local priority
    • mapping of the IPsec profile to the IPsec SA
    • mapping of the IPsec transform set to the GDOI group
  14. Question 14 · 1

    When implementing GET VPN, which of these is a characteristic of GDOI IKE?

    Choose one answer.

    • GDOI IKE sessions are established between all peers in the network
    • GDOI IKE uses UDP port 500
    • Security associations do not need to linger between members once a group member has authenticated to the key server and obtained the group policy
    • Each pair of peers has a private set of IPsec security associations that is only shared between the two peers
  15. Question 15 · 1

    Which Cisco ASA configuration is used to configure the TCP intercept feature?

    Choose one answer.

    • a TCP map
    • an access list
    • the established command
    • the set connection command with the embryonic-conn-max option
    • a type inspect policy map

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free