Act now and download your Cisco 300 206 dumps test today! Do not waste time for the worthless Cisco ccnp security senss 300 206 official cert guide tutorials. Download Down to date Cisco Implementing Cisco Edge Network Security Solutions exam with real questions and answers and begin to learn Cisco ccnp security senss 300 206 official cert guide with a classic professional.

Q46. Which command enables the HTTP server daemon for Cisco ASDM access? 

A. http server enable 

B. http server enable 443 

C. crypto key generate rsa modulus 1024 

D. no http server enable 

Answer:


Q47. Which statement describes the correct steps to enable Botnet Traffic Filtering on a Cisco ASA version 9.0 transparent-mode firewall with an active Botnet Traffic Filtering license? 

A. Enable DNS snooping, traffic classification, and actions. 

B. Botnet Traffic Filtering is not supported in transparent mode. 

C. Enable the use of the dynamic database, enable DNS snooping, traffic classification, and actions. 

D. Enable the use of dynamic database, enable traffic classification and actions. 

Answer:


Q48. What is the result of the default ip ssh server authenticate user command? 

A. It enables the public key, keyboard, and password authentication methods. B. It enables the public key authentication method only. 

C. It enables the keyboard authentication method only. 

D. It enables the password authentication method only. 

Answer:


Q49. What is a required attribute to configure NTP authentication on a Cisco ASA? 

A. Key ID 

B. IPsec 

C. AAA 

D. IKEv2 

Answer:


Q50. Which command sets the source IP address of the NetFlow exports of a device? 

A. ip source flow-export 

B. ip source netflow-export 

C. ip flow-export source 

D. ip netflow-export source 

Answer:


Q51. Which option describes the enhancements that SNMPv3 adds over 1 and 2 versions? 

A. Predefined events that generate message from the SNMP agent to the NMS 

B. Addition of authentication and privacy options 

C. Cleartext transmission of data between SNMP server and SNMP agent 

D. Addition of the ability to predefine events using traps 

E. Pooling of devices using GET-NEXT requests 

F. Use of the object identifier 

Answer:

Explanation: 

http://www.cisco.com/c/en/us/td/docs/ios/12_2/configfun/configuration/guide/ffun_c/fcf014.html 


Q52. Which option is a different type of secondary VLAN? 

A. Transparent 

B. Promiscuous 

C. Virtual 

D. Community 

Answer:


Q53. When you configure a Cisco firewall in multiple context mode, where do you allocate interfaces? 

A. in the system execution space 

B. in the admin context 

C. in a user-defined context 

D. in the global configuration 

Answer:


Q54. Refer to the exhibit. 

Which two statements about this firewall output are true? (Choose two.) 

A. The output is from a packet tracer debug. 

B. All packets are allowed to 192.168.1.0 255.255.0.0. 

C. All packets are allowed to 192.168.1.0 255.255.255.0. 

D. All packets are denied. 

E. The output is from a debug all command. 

Answer: A,C 


Q55. Which option is a valid action for a port security violation? 

A. Reset 

B. Reject 

C. Restrict 

D. Disable 

Answer:


Q56. Which statement is true of the logging configuration on the Cisco ASA? 

A. The contents of the internal buffer will be saved to an FTP server before the buffer is overwritten. 

B. The contents of the internal buffer will be saved to flash memory before the buffer is overwritten. 

C. System log messages with a severity level of six and higher will be logged to the internal buffer. 

D. System log messages with a severity level of six and lower will be logged to the internal buffer. 

Answer:

Explanation: 

\\psf\Home\.Trash\Screen Shot 2015-06-17 at 5.26.32 PM.png 


Q57. Which two features block traffic that is sourced from non-topological IPv6 addresses? (Choose two.) 

A. DHCPv6 Guard 

B. IPv6 Prefix Guard 

C. IPv6 RA Guard 

D. IPv6 Source Guard 

Answer: B,D 


Q58. On an ASA running version 9.0, which command is used to nest objects in a pre-existing group? 

A. object-group 

B. network group-object 

C. object-group network 

D. group-object 

Answer:


Q59. What are three ways to add devices in Cisco Prime Infrastruture? ( Choose three ) 

A. Use Cisco Security manager 

B. Use Radius 

C. Import devices from a CSV file 

D. Add devices manually 

E. Use an automated process 

F. Use the Access Control Server 

Answer: C,D,E 


Q60. Which Cisco Security Manager form factor is recommended for deployments with fewer than 25 devices? 

A. only Cisco Security Manager Standard 

B. only Cisco Security Manager Professional 

C. only Cisco Security Manager UCS Server Bundle 

D. both Cisco Security Manager Standard and Cisco Security Manager Professional 

Answer: