300-206 Sample Questions & Answers
CLI, GUI and secure device management ties with Layer 2 and firewall threat defense for the top weight, while smaller sections cover designing firewall solutions, AAA configuration plus device hardening, NetFlow-based monitoring, and general VPN awareness.
Launch the full 300-206 simulator →Showing 8 of 17 free samples.
- Question 1Intermediate
Threat Defense · Implement Firewall (ASA or IOS)
A financial institution is deploying a Cisco ASA 5500-X series firewall at the internet edge. The security policy requires that all internal hosts in the 10.10.10.0/24 subnet be hidden behind a single public IP address (203.0.113.10) when accessing the internet. Additionally, a specific internal web server (10.10.10.50) must be accessible from the internet on port 80 using the IP 203.0.113.11. The administrator observes that the web server is reachable, but internal hosts cannot access the internet. A review of the configuration shows the following:
object network OBJ_INSIDE
subnet 10.10.10.0 255.255.255.0
object network OBJ_WEBSERVER
host 10.10.10.50
!
nat (inside,outside) source static OBJ_WEBSERVER interface service tcp 80 80Which configuration change resolves the issue while maintaining the required access?
Show answer & explanation
Correct answer: C
The current configuration has a static NAT for the web server but lacks a rule for the rest of the subnet. On Cisco ASA, NAT rules are processed in order. Adding a dynamic NAT (or PAT) rule for the 10.10.10.0/24 subnet to use the interface IP or a specific public IP is necessary for outbound connectivity. Since the web server needs a specific static mapping, that rule (Auto NAT or Manual NAT) typically takes precedence if specific, but a separate dynamic rule is required for the remaining hosts.
- Question 2IntermediateSelect 3
Threat Defense · Implement Layer 2 Security
A network architect is designing a Layer 2 security strategy for a campus network. The design must prevent a user from connecting a rogue DHCP server to a wall jack and assigning incorrect IP addresses to other users in the same VLAN. The switch is a Cisco Catalyst 9300. Which three steps are required to implement the solution? (Select THREE)
Show answer & explanation
Correct answers: A, D, E
After global enablement, the feature must be activated for the specific VLANs requiring protection.
By default, all ports are untrusted when DHCP snooping is enabled. The uplink to the valid DHCP server must be explicitly trusted to allow DHCP Offer and Ack packets to pass.
DHCP snooping must be enabled globally before it can be active on specific VLANs.
- Question 3Advanced
Management Services on Cisco Devices · Configure AAA
A security engineer is configuring the Cisco ASA to integrate with a Cisco ISE server for administrative access control. The requirement is that network administrators must have full access (privilege level 15) while helpdesk staff should only have read-only access (privilege level 2). The ISE server is configured to return the Cisco-AV-Pair attribute 'shell:priv-lvl=15' for admins. Which command on the ASA ensures this attribute is honored during the authorization process?
Show answer & explanation
Correct answer: C
The command 'aaa authorization exec authentication-server' configures the ASA to use the authorization attributes (like privilege level) retrieved during the authentication phase from the RADIUS/TACACS+ server. Without this command (or specifying 'auto'), the ASA might default to local authorization or not apply the privilege level sent by ISE.
- Question 4Beginner
Threat Defense · Describe threat detection features
While investigating a reported network slowdown, an administrator discovers a large volume of TCP SYN packets targeting the web server farm. The traffic appears to be spoofed. To mitigate this on the Cisco ASA, the administrator enables TCP Intercept. Which Threat Defense feature is being utilized?
Show answer & explanation
Correct answer: C
TCP Intercept on the ASA is typically implemented by setting embryonic connection limits within the Modular Policy Framework (MPF) policy map. When the limit is reached, the ASA proxies the connection (intercepts the SYN) to verify the source is legitimate before forwarding to the server, preventing SYN flood attacks.
- Question 5Intermediate
Threat Defense Architectures · Design Firewall Solutions
A Cisco ASA is configured for Active/Standby failover. The administrator notices that the standby unit is not synchronizing the configuration and remains in a 'pseudo-standby' state. The failover link is directly connected between the two units using GigabitEthernet0/3. Which of the following is the most likely cause?
Show answer & explanation
Correct answer: C
For failover to function correctly and for configuration synchronization to occur, both units must be running the exact same software version (major and minor). A version mismatch often results in the secondary unit failing to sync and entering a pseudo-standby or disabled state.
- Question 6Advanced
Threat Defense · Implement Firewall (ASA or IOS)
Case Study: TechSecure Inc.
TechSecure Inc. is updating its edge security to support a new partner integration. The partner uses an overlapping IP address space (192.168.1.0/24) identical to TechSecure's internal R&D VLAN.
To resolve this, the network architect proposes a Twice NAT solution on the Cisco ASA. The requirements are:
- TechSecure Host A (192.168.1.50) must reach Partner Host B (192.168.1.100).
- TechSecure Host A should initiate traffic to a 'dummy' IP 10.0.0.100, which the ASA translates to the Partner's real IP 192.168.1.100.
- The Partner firewall sees the traffic coming from TechSecure's public IP 203.0.113.50.
Which object configuration correctly defines the destination mapping objects for this Twice NAT rule?
Show answer & explanation
Correct answer: B
In a Twice NAT configuration on the ASA for outbound traffic, the 'destination static' clause maps the 'Mapped Destination' (the dummy IP the internal host speaks to) to the 'Real Destination' (the actual IP of the remote host). Therefore, we need objects for the dummy IP (10.0.0.100) and the real partner IP (192.168.1.100). The NAT rule would look like: nat (inside,outside) source static OBJ_HOST_A OBJ_PUBLIC_A destination static OBJ_DUMMY_DEST OBJ_REAL_DEST.
- Question 7Beginner
Cisco Security Devices GUIs and Secured CLI Management · Implement SSHv2, HTTPS, and SNMPv3
When configuring SNMPv3 on a Cisco IOS router to ensure the highest level of security, which security level should be selected to ensure that both the packet contents are encrypted and the identity of the user is verified?
Show answer & explanation
Correct answer: C
SNMPv3 offers three security levels: noAuthNoPriv (no authentication, no encryption), authNoPriv (authentication, no encryption), and authPriv (authentication and encryption). 'authPriv' provides the highest security by verifying the user's identity (HMAC-MD5 or HMAC-SHA) and encrypting the payload (DES, 3DES, or AES).
- Question 8Beginner
Management Services on Cisco Devices · Implement Logging
A network administrator needs to back up the configuration of a Cisco ASA to a TFTP server. The connection must be initiated from the ASA CLI. Which command should be used?
Show answer & explanation
Correct answer: A
The standard command to copy the current configuration to a TFTP server is 'copy running-config tftp:'. The system will then prompt for the remote host IP and destination filename.
Ready for the real thing?
The full 300-206 simulator has every exam-style question, timed mode, and instant scoring.