ExamDumpster

Free 300-206 sample questions

Real questions from the Security Implementing Cisco Edge Network Security Solutions (SENSS) practice bank, with the correct answer and an explanation for each one. No junk, no filler.

Try them in the simulator Same questions, with study, timed and flashcard modes.

Showing 8 of 17 free sample questions.

Question 1Choose one

All 30 users on a single floor of a building are complaining about network slowness. After investigating the access switch, the network administrator notices that the MAC address table is full (10,000 entries) and all traffic is being flooded out of every port. Which action can the administrator take to prevent this from occurring? A.Configure port-security to limit the number of mac-addresses allowed on each portB.Upgrade the switch to one that can handle 20,000 entriesC.Configure private-vlans to prevent hosts from communicating with one anotherD.Enable storm-control to limit the traffic rateE.Configure a VACL to block all IP traffic except traffic to and from that subnet

Question 2Choose one

A network printer has a DHCP server service that cannot be disabled. How can a layer 2 switch be configured to prevent the printer from causing network issues? A.Remove the ip helper-addressB.Configure a Port-ACL to block outbound TCP port 68C.Configure DHCP snoopingD.Configure port-security

Question 3Choose one

A switch is being configured at a new location that uses statically assigned IP addresses. Which will ensure that ARP inspection works as expected? A.Configure the 'no-dhcp' keyword at the end of the ip arp inspection commandB.Enable static arp inspection using the command 'ip arp inspection static vlan vlan-numberC.Configure an arp access-list and apply it to the ip arp inspection commandD.Enable port security

Question 4Choose one

Which of the following would need to be created to configure an application-layer inspection of SMTP traffic operating on port 2525? A.A class-map that matches port 2525 and applying an inspect ESMTP policy-map for that class in the global inspection policyB.A policy-map that matches port 2525 and applying an inspect ESMTP class-map for that policyC.An access-list that matches on TCP port 2525 traffic and applying it on an interface with the inspect optionD.A class-map that matches port 2525 and applying it on an access-list using the inspect option

Question 5Choose one

A financial institution is deploying a Cisco ASA 5500-X series firewall at the internet edge. The security policy requires that all internal hosts in the 10.10.10.0/24 subnet be hidden behind a single public IP address (203.0.113.10) when accessing the internet. Additionally, a specific internal web server (10.10.10.50) must be accessible from the internet on port 80 using the IP 203.0.113.11. The administrator observes that the web server is reachable, but internal hosts cannot access the internet. A review of the configuration shows the following: object network OBJ_INSIDE subnet 10.10.10.0 255.255.255.0 object network OBJ_WEBSERVER host 10.10.10.50 ! nat (inside,outside) source static OBJ_WEBSERVER interface service tcp 80 80 Which configuration change resolves the issue while maintaining the required access?

Question 6Choose 3

A network architect is designing a Layer 2 security strategy for a campus network. The design must prevent a user from connecting a rogue DHCP server to a wall jack and assigning incorrect IP addresses to other users in the same VLAN. The switch is a Cisco Catalyst 9300. Which three steps are required to implement the solution? (Select THREE)

Question 7Choose one

A security engineer is configuring the Cisco ASA to integrate with a Cisco ISE server for administrative access control. The requirement is that network administrators must have full access (privilege level 15) while helpdesk staff should only have read-only access (privilege level 2). The ISE server is configured to return the Cisco-AV-Pair attribute 'shell:priv-lvl=15' for admins. Which command on the ASA ensures this attribute is honored during the authorization process?

Question 8Choose one

While investigating a reported network slowdown, an administrator discovers a large volume of TCP SYN packets targeting the web server farm. The traffic appears to be spoofed. To mitigate this on the Cisco ASA, the administrator enables TCP Intercept. Which Threat Defense feature is being utilized?

9 more free samples are waiting

Create a free account to unlock the whole 300-206 sample bank, or get full access to all 270 practice questions in the simulator.

Create account