web analytics

Cisco CCNP Security 300-209 Dumps With VCE and PDF Download (Question 116 – Question 125)

New 300-209 exam questions from PassLeader 300-209 dumps! Welcome to download the newest PassLeader 300-209 VCE and PDF dumps: http://www.passleader.com/300-209.html (237 Q&As)

P.S. Free 300-209 dumps are available on Google Drive shared by PassLeader: https://drive.google.com/open?id=0B-ob6L_QjGLpVTNFVTRPdC0zTnM

QUESTION 116
Refer to the exhibit. An administrator had the above configuration working with SSL protocol, but as soon as the administrator specified IPsec as the primary protocol, the Cisco AnyConnect client was not able to connect. What is the problem?
passleader-300-209-dumps-1161

A.    IPsec will not work in conjunction with a group URL.
B.    The Cisco AnyConnect implementation does not allow the two group URLs to be the same. SSL does allow this.
C.    If you specify the primary protocol as IPsec, the User Group must be the exact name of the connection profile (tunnel group).
D.    A new XML profile should be created instead of modifying the existing profile, so that the clients force the update.

Answer: C

QUESTION 117
The Cisco AnyConnect client fails to connect via IKEv2 but works with SSL. The following error message is displayed:
“Login Denied, unauthorized connection mechanism, contact your administrator”
What is the most possible cause of this problem?

A.    DAP is terminating the connection because IKEv2 is the protocol that is being used.
B.    The client endpoint does not have the correct user profile to initiate an IKEv2 connection.
C.    The AAA server that is being used does not authorize IKEv2 as the connection mechanism.
D.    The administrator is restricting access to this specific user.
E.    The IKEv2 protocol is not enabled in the group policy of the VPN headend.

Answer: E

QUESTION 118
The Cisco AnyConnect client is unable to download an updated user profile from the ASA headend using IKEv2. What is the most likely cause of this problem?

A.    User profile updates are not allowed with IKEv2.
B.    IKEv2 is not enabled on the group policy.
C.    A new profile must be created so that the adaptive security appliance can push it to the client on the next connection attempt.
D.    Client Services is not enabled on the adaptive security appliance.

Answer: D

QUESTION 119
Refer to the exhibit. The network administrator is adding a new spoke, but the tunnel is not passing traffic. What could cause this issue?
passleader-300-209-dumps-1191

A.    DMVPN is a point-to-point tunnel, so there can be only one spoke.
B.    There is no EIGRP configuration, and therefore the second tunnel is not working.
C.    The NHRP authentication is failing.
D.    The transform set must be in transport mode, which is a requirement for DMVPN.
E.    The NHRP network ID is incorrect.

Answer: C

QUESTION 120
Which two troubleshooting steps should be taken when Cisco AnyConnect cannot establish an IKEv2 connection, while SSL works fine? (Choose two.)

A.    Verify that the primary protocol on the client machine is set to IPsec.
B.    Verify that AnyConnect is enabled on the correct interface.
C.    Verify that the IKEv2 protocol is enabled on the group policy.
D.    Verify that ASDM and AnyConnect are not using the same port.
E.    Verify that SSL and IKEv2 certificates are not referencing the same trustpoint.

Answer: AC

QUESTION 121
Regarding licensing, which option will allow IKEv2 connections on the adaptive security appliance?

A.    AnyConnect Essentials can be used for Cisco AnyConnect IKEv2 connections.
B.    IKEv2 sessions are not licensed.
C.    The Advanced Endpoint Assessment license must be installed to allow Cisco AnyConnect IKEv2 sessions.
D.    Cisco AnyConnect Mobile must be installed to allow AnyConnect IKEv2 sessions.

Answer: A

QUESTION 122
What action does the hub take when it receives a NHRP resolution request from a spoke for a network that exists behind another spoke?

A.    The hub sends back a resolution reply to the requesting spoke.
B.    The hub updates its own NHRP mapping.
C.    The hub forwards the request to the destination spoke.
D.    The hub waits for the second spoke to send a request so that it can respond to both spokes.

Answer: C

QUESTION 123
A spoke has two Internet connections for failover. How can you achieve optimum failover without affecting any other router in the DMVPN cloud?

A.    Create another DMVPN cloud by configuring another tunnel interface that is sourced from the second ISP link.
B.    Use another router at the spoke site, because two ISP connections on the same router for the same hub is not allowed.
C.    Configure SLA tracking, and when the primary interface goes down, manually change the tunnel source of the tunnel interface.
D.    Create another tunnel interface with same configuration except the tunnel source, and configure the if-state nhrp and backup interface commands on the primary tunnel interface.

Answer: D

QUESTION 124
In DMVPN phase 2, which two EIGRP features need to be disabled on the hub to allow spoke-to-spoke communication? (Choose two.)

A.    autosummary
B.    split horizon
C.    metric calculation using bandwidth
D.    EIGRP address family
E.    next-hop-self
F.    default administrative distance

Answer: BE

QUESTION 125
What does NHRP stand for?

A.    Next Hop Resolution Protocol
B.    Next Hop Registration Protocol
C.    Next Hub Routing Protocol
D.    Next Hop Routing Protocol

Answer: A


New 300-209 exam questions from PassLeader 300-209 dumps! Welcome to download the newest PassLeader 300-209 VCE and PDF dumps: http://www.passleader.com/300-209.html (237 Q&As)

P.S. Free 300-209 dumps are available on Google Drive shared by PassLeader: https://drive.google.com/open?id=0B-ob6L_QjGLpVTNFVTRPdC0zTnM