Cisco 300-209 Certification Exam Sample Questions and Answers

Before you write the Cisco CCNP Security (300-209) certification exam, you may have certain doubts in your mind regarding the pattern of the test, the types of questions asked in it, the difficulty level of the questions and time required to complete the questions. These Cisco Certified Network Professional Security (SIMOS) sample questions and demo exam help you in removing these doubts and prepare you to take the test.

Cisco 300-209 (SIMOS) Sample Questions:

01. Which two of the following provide protect against man-in-the-middle attacks?
(Choose two.)
a) TCP initial sequence number randomization?
b) TCP sliding-window checking
c) Network Address Translation
d) IPsec VPNs
e) Secure Sockets Layer
02. Which of the following VPN technologies uses non-tunneled IPsec as its encapsulation mode?
a) Individual IPsec tunnels
b) Cisco Easy VPN
c) Dynamic Multipoint VPN (DMVPN)
d) Group Encrypted Transport (GET) VPN
03. Which of the following are valid characterizations of key encryption protocols?
(Choose all that apply.)
a) Asymmetric
b) Bidirectional
c) Symmetric
d) One-Way
04. Which encapsulation mode, when deployed in tunnel mode, provides confidentiality, authenticity, integrity, and antireplay by encapsulating and protecting the entire original IP packet?
a) Authentication Headers (AH)
b) Internet Security Association and Key Management Protocol (ISAKMP)
c) Diffie-Hellman key exchange with Perfect Forward Secrecy (PFS)
d) Encapsulating Security Payload (ESP)
05. The encapsulation on a virtual tunnel interface must be which of the following?
a) Frame Relay
b) ATM
c) AH or ESP
06. Where are dynamic point-to-point VTI tunnels deployed?
a) On the hub router
b) On each spoke router
c) On the hub router and on each spoke router
d) On the VPN concentrator
e) None of the above
07. The IP address of a virtual tunnel interface must be configured using which interface command?
a) ip address
b) ip address dhcp
c) ip address pppoe
d) ip unnumbered
08. Which mechanism provides dynamic mutual discovery of spoke devices?
a) GRE
b) IKE
e) Expired Certificate List
09. Which network topology is in use when every network has a direct VPN connection to every other network? This topology provides any-to-any communication and provides the most optimal direct path for network traffic.
a) Fully meshed network
b) Star topology network
c) Partially meshed network
d) Individual point-to-point VPN connection
e) Hub-and-spoke network
10. When deploying an IPsec site-to-site VPN, what is the recommended method of peer authentication from a security perspective?
a) Pre-shared keys
b) Digital certificates
c) Biometrics
d) OTP


Question: 01

Answer: d, e

Question: 02

Answer: d

Question: 03

Answer: a, c

Question: 04

Answer: d

Question: 05

Answer: c

Question: 06

Answer: a

Question: 07

Answer: d

Question: 08

Answer: c

Question: 09

Answer: a

Question: 10

Answer: b

