web analytics

Valid 300-207 Dumps with VCE and PDF for Free (Question 41 – Question 55)

New 300-207 exam questions from PassLeader 300-207 dumps! Welcome to download the newest PassLeader 300-207 VCE and PDF dumps: http://www.passleader.com/300-207.html (251 Q&As)

P.S. Free 300-207 dumps are available on Google Drive shared by PassLeader: https://drive.google.com/open?id=0B-ob6L_QjGLpfkU1Q3dsMlRzZVdzdjBOMTJYaWw4NzYxSk1sdm8yNTNsUzl3RGx2dllxOTg

QUESTION 41
Which version of AsyncOS for web is required to deploy the Web Security Appliance as a CWS connector?

A.    AsyncOS version 7.7.x
B.    AsyncOS version 7.5.x
C.    AsyncOS version 7.5.7
D.    AsyncOS version 7.5.0

Answer: C

QUESTION 42
What are three benefits of the Cisco AnyConnect Secure Mobility Solution? (Choose three.)

A.    It can protect against command-injection and directory-traversal attacks.
B.    It provides Internet transport while maintaining corporate security policies.
C.    It provides secure remote access to managed computers.
D.    It provides clientless remote access to multiple network-based systems.
E.    It enforces security policies, regardless of the user location.
F.    It uses ACLs to determine best-route connections for clients in a secure environment.

Answer: BCE

QUESTION 43
Which Cisco technology secures the network through malware filtering, category-based control, and reputation-based control?

A.    Cisco ASA 5500 Series appliances
B.    Cisco remote-access VPNs
C.    Cisco IronPort WSA
D.    Cisco IPS

Answer: C

QUESTION 44
Which antispam technology assumes that email from server A, which has a history of distributing spam, is more likely to be spam than email from server B, which does not have a history of distributing spam?

A.    Reputation-based filtering
B.    Context-based filtering
C.    Cisco ESA multilayer approach
D.    Policy-based filtering

Answer: A

QUESTION 45
Which Cisco technology is a modular security service that combines a stateful inspection firewall with next-generation application awareness, providing near real-time threat protection?

A.    Cisco ASA 5500 series appliances
B.    Cisco ASA CX Context-Aware Security
C.    WSA
D.    Internet Edge Firewall / IPS

Answer: B

QUESTION 46
Which three statements about Cisco ASA CX are true? (Choose three.)

A.    It groups multiple ASAs as a single logical device.
B.    It can perform context-aware inspection.
C.    It provides high-density security services with high availability.
D.    It uses policy-based interface controls to inspect and forward TCP- and UDP-based packets.
E.    It can make context-aware decisions.
F.    It uses four cooperative architectural constructs to build the firewall.

Answer: BEF

QUESTION 47
During initial configuration, the Cisco ASA can be configured to drop all traffic if the ASA CX SSP fails by using which command in a policy-map?

A.    cxsc fail
B.    cxsc fail-close
C.    cxsc fail-open
D.    cxssp fail-close

Answer: B

QUESTION 48
Cisco AVC allows control of which three of the following? (Choose three.)

A.    Facebook
B.    LWAPP
C.    IPv6
D.    MySpace
E.    Twitter
F.    WCCP

Answer: ADE

QUESTION 49
The Web Security Appliance has identities defined for faculty and staff, students, and default access. The faculty and staff identity identifies users based on the source network and authenticated credentials. The identity for students identifies users based on the source network along with successful authentication credentials. The global identity is for guest users not authenticated against the domain. Recently, a change was made to the organization’s security policy to allow faculty and staff access to a social network website, and the security group changed the access policy for faculty and staff to allow the social networking category. Which are the two most likely reasons that the category is still being blocked for a faculty and staff user? (Choose two.)

A.    The user is being matched against the student policy because the user did not enter credentials.
B.    The user is using an unsupported browser so the credentials are not working.
C.    The social networking URL was entered into a custom URL category that is blocked in the access policy.
D.    The user is connected to the wrong network and is being blocked by the student policy.
E.    The social networking category is being allowed but the AVC policy is still blocking the website.

Answer: CE

QUESTION 50
Which five system management protocols are supported by the Intrusion Prevention System? (Choose five.)

A.    SNMPv2c
B.    SNMPv1
C.    SNMPv2
D.    SNMPv3
E.    syslog
F.    SDEE
G.    SMTP

Answer: ABCFG

QUESTION 51
Which IPS signature regular expression CLI command matches a host issuing a domain lookup for www.theblock.com?

A.    regex-string (\x03[Tt][Hh][Ee]\x05[Bb][Ll][Oo][Cc][Kk])
B.    regex-string (\x0b[theblock.com])
C.    regex-string (\x03[the]\x05[block]0x3[com])
D.    regex-string (\x03[T][H][E]\x05[B][L][O][C][K]\x03[.][C][O][M]

Answer: A

QUESTION 52
Which three user roles are partially defined by default in Prime Security Manager? (Choose three.)

A.    networkoperator
B.    admin
C.    helpdesk
D.    securityoperator
E.    monitoringadmin
F.    systemadmin

Answer: BCF

QUESTION 53
Which three options are IPS signature classifications? (Choose three.)

A.    tuned signatures
B.    response signatures
C.    default signatures
D.    custom signatures
E.    preloaded signatures
F.    designated signatures

Answer: ACD

QUESTION 54
At which value do custom signatures begin?

A.    1024
B.    10000
C.    1
D.    60000

Answer: D

QUESTION 55
Which two commands are valid URL filtering commands? (Choose two.)

A.    url-server (DMZ) vendor smartfilter host 10.0.1.1
B.    url-server (DMZ) vendor url-filter host 10.0.1.1
C.    url-server (DMZ) vendor n2h2 host 10.0.1.1
D.    url-server (DMZ) vendor CISCO host 10.0.1.1
E.    url-server (DMZ) vendor web host 10.0.1.1

Answer: AC


New 300-207 exam questions from PassLeader 300-207 dumps! Welcome to download the newest PassLeader 300-207 VCE and PDF dumps: http://www.passleader.com/300-207.html (251 Q&As)

P.S. Free 300-207 dumps are available on Google Drive shared by PassLeader: https://drive.google.com/open?id=0B-ob6L_QjGLpfkU1Q3dsMlRzZVdzdjBOMTJYaWw4NzYxSk1sdm8yNTNsUzl3RGx2dllxOTg