Which two statements describe effects of the DoNothing option within the untrusted network policy on a Cisco AnyConnect profile? (Choose two.)
A.
The client initiates a VPN connection upon detection of an untrusted network.
B.
The client initiates a VPN connection upon detection of a trusted network.
C.
The always-on feature is enabled.
D.
The always-on feature is disabled.
E.
The client does not automatically initiate any VPN connection.
The answers are:
D. The always-on feature is disabled.
E. The client does not automatically initiate any VPN connection.
hxxp://www.cisco.com/c/en/us/td/docs/security/vpn_client/anyconnect/anyconnect40/administration/guide/b_AnyConnect_Administrator_Guide_4-0/configure-vpn.html#ID-1428-00000152
(4/July/2017 Updated) New 300-209 Exam Questions:
NEW QUESTION 295
An engineer is attempting to establish a new site-to-site VPN connection. The tunnel terminates on an ASA 5506-X which is behind an ASA 5515-X. The engineer notices that the tunnel is not establishing. Which option is a potential cause?
A. Certificates were not configured
B. Diffie – Helman Group is not set
C. Access lists were not applied
D. NAT – traversal is not configured
Answer: D
NEW QUESTION 296
Which algorithm does ISAKMP use to securely derive encryption and integrity keys?
A. Diffie – Hellman
B. AES
C. ECDSA
D. RSA
E. 3DES
Answer: D
NEW QUESTION 297
Which purpose of configuring perfect Forward secret is true?
A. For every negotiation of a new phase 1 SA, the two gateways generate a new set of phase 2 keys.
B. For every negotiation of a new phase 2 SA, the two gateways generate a new set of phase 1 keys.
C. For every negotiation of a new phase 1 SA, the two gateways generate a new set of phase 1 keys.
D. For every negotiation of a new phase 2 SA, the two gateways generate a new set of phase 2 keys.
Answer: A
NEW QUESTION 298
An engineer has successfully established a phase 1 tunnel, but notices that no packets are decrypted on the head end side of the tunnel. What is a potential cause for this issue?
A. different phase 2 encryption
B. misconfigured DH group
C. disabled PFS
D. firewall blocking Phase 2 ESP or AH
Answer: A
NEW QUESTION 299
Which option describes traffic that will initiate a VPN connection?
A. trusted
B. external
C. internal
D. interesting
Answer: D
NEW QUESTION 300
……
P.S. These New 300-209 Exam Questions Were Just Updated From The Real 300-209 Exam, You Can Get The Newest 300-209 Dumps In PDF And VCE From — http://www.passleader.com/300-209.html (307q VCE and PDF)
Good Luck!
More, part of the new 307Q 300-209 dumps FYI:
https://drive.google.com/open?id=0B-ob6L_QjGLpVTNFVTRPdC0zTnM
Best Regards!