Free Cisco® 300-206 Exam Questions (page: 5)

A security engineer is troubleshooting traffic across a Cisco ASA firewall using a packet tracer. When configuring the packet tracer, which option must be used first?

  1. interface
  2. protocol
  3. source
  4. destination

Answer(s): A



Which two statements about the utilization of IPv4 and IPv6 addresses in the Cisco ASA 9.x firewall access list configuration are true? (Choose two.)

  1. Mixed IPv4 and IPv6 addresses cannot be used in the same access list entry
  2. Mixed IPv4 and IPv6 addresses can be used in the same access list entry
  3. Mixed IPv4 and IPv6 addresses can be used in the same access list for network object group
  4. Mixed IPv4 and IPv6 addresses cannot be used in the same access list
  5. Mixed IPv4 and IPv6 addresses cannot be used in the same access list for network object group

Answer(s): B,C


Reference:

https://www.cisco.com/c/en/us/td/docs/security/asa/asa90/configuration/guide/asa_90_cli_config/acl_extended.pdf



A user is having trouble connecting to websites on the Internet. The network engineer proposes configuring a packet capture that captures only the HTTP response traffic on the Cisco Adaptive Security Appliance between the user’s workstation and Internet. If the user’s workstation IP address is 10.0.0.101, which ACE is needed to achieve this capture?

  1. access-list capture permit tcp host 10.0.0.101 eq 80 any
  2. access-list capture permit tcp host 10.0.0.101 any eq 80
  3. access-list capture permit tcp any eq 80 host 10.0.0.101
  4. access-list capture permit tcp any host 10.0.0.101 eq 80

Answer(s): D



Which two mandatory policies are needed to support a regular IPsec VPN in a Cisco Security Manager environment? (Choose two.)

  1. GRE modes
  2. IKE proposal
  3. group encryption
  4. server load balance

Answer(s): B,C



Viewing page 5 of 110



Post your Comments and Discuss Cisco® 300-206 exam prep with other Community members:

300-206 Exam Discussions & Posts