300-206 Practice Questions
Prepare for 300-206 with more than an answer.
Unlock the full exam and previous versions
- v1Version 1 178 questions Locked
- 300-206Legacy Security Implementing Cisco Edge Network Security Solutions (SENSS) 270 questions Current
- Exam fee
- $300 USD
- Level
- Professional
- Valid for
- 3 years
Domains covered on the exam 6
- Threat Defense25%
- Cisco Security Devices GUIs and Secured CLI Management25%
- Threat Defense Architectures16%
- Management Services on Cisco Devices12%
- Troubleshooting, Monitoring and Reporting Tools10%
- Security Components and Considerations12%
- 1
Which of the following statements is TRUE regarding the difference between a Transparent Firewall and a Routed Firewall mode on the Cisco ASA?
Show answer details
Correct answer: A
In Transparent mode, the ASA acts as a Layer 2 bridge and is not a hop in the routing table, making it 'invisible' to Layer 3 traceroutes. It does not support dynamic routing protocols or VPN termination (in older versions, though newer versions have limited support, the primary distinction remains L2 vs L3 operation). Routed mode operates as a Layer 3 router hop.
- 2
An administrator is configuring a Zone-Based Policy Firewall (ZBFW) on a Cisco IOS router. They have defined the zones and zone-pairs. To inspect HTTP traffic from the 'Inside' zone to the 'Outside' zone, what is the correct order of configuration steps?
Show answer details
Correct answer: A
The C3PL (Cisco Common Classification Policy Language) workflow for ZBFW is: 1. Define a Class Map to identify the traffic (match protocol http). 2. Define a Policy Map to specify the action (inspect) for that class. 3. Apply the Policy Map to a Zone Pair using the 'service-policy type inspect' command.
- 3
A network engineer needs to configure a Cisco switch to prevent users from connecting a switch to an access port and potentially causing a Layer 2 loop or spanning-tree instability. The solution should verify that the connected device is not generating BPDUs. Which feature should be enabled on the access ports?
Show answer details
Correct answer: D
BPDU Guard is designed for access ports where end devices (PCs, printers) are connected. If a BPDU is received on a port with BPDU Guard enabled, the port is immediately put into an err-disabled state, effectively preventing unauthorized switches from participating in Spanning Tree.
- 4
You are configuring Control Plane Policing (CoPP) on a Cisco IOS router to protect the CPU from DoS attacks. You have defined an ACL to identify management traffic (SSH, SNMP) and another ACL for routing protocols. What is the next logical step in the configuration process before applying the policy?
Show answer details
Correct answer: D
CoPP uses the Modular Quality of Service (MQC) framework. After defining ACLs to classify traffic, you must create Class Maps to match those ACLs. Then you create a Policy Map to define actions (policing/rate-limiting) for each class, and finally apply it to the control plane using 'control-plane' service-policy.
- 5
Which command on the Cisco ASA allows you to verify the specific NAT rule that a packet is hitting, including the translation result and the interface it is egressing?
Show answer details
Correct answer: D
The 'packet-tracer' command simulates a packet passing through the firewall and reports on every phase of processing, including ACL checks, route lookups, and specifically, NAT rule matching (showing the rule ID) and the final egress interface.
- 6
All 30 users on a single floor of a building are complaining about network slowness. After investigating the access switch, the network administrator notices that the MAC address table is full (10,000 entries) and all traffic is being flooded out of every port. Which action can the administrator take to prevent this from occurring? A.Configure port-security to limit the number of mac-addresses allowed on each portB.Upgrade the switch to one that can handle 20,000 entriesC.Configure private-vlans to prevent hosts from communicating with one anotherD.Enable storm-control to limit the traffic rateE.Configure a VACL to block all IP traffic except traffic to and from that subnet
Show answer details
Correct answer: A
- 7
A network printer has a DHCP server service that cannot be disabled. How can a layer 2 switch be configured to prevent the printer from causing network issues? A.Remove the ip helper-addressB.Configure a Port-ACL to block outbound TCP port 68C.Configure DHCP snoopingD.Configure port-security
Show answer details
Correct answer: C
- 8
A switch is being configured at a new location that uses statically assigned IP addresses. Which will ensure that ARP inspection works as expected? A.Configure the 'no-dhcp' keyword at the end of the ip arp inspection commandB.Enable static arp inspection using the command 'ip arp inspection static vlan vlan-numberC.Configure an arp access-list and apply it to the ip arp inspection commandD.Enable port security
Show answer details
Correct answer: C
