300-209 Sample Questions

300-209 Sample Questions & Answers

Troubleshooting VPNs through ASDM and the CLI is the single largest section, with the remainder split between remote-access and site-to-site tunnels on routers and firewalls, and architecting them with hashing, encryption and next-gen crypto.

Launch the full 300-209 simulator →

Showing 10 of 20 free samples.

  1. Question 1Intermediate

    Secure Communications · DMVPN Phase 3 and NHRP

    A financial institution is implementing a DMVPN Phase 3 network with EIGRP. Security policy mandates that spoke-to-spoke traffic must be encrypted and must not traverse the hub. However, during testing, it is observed that the first few packets between two spokes are dropped before the direct tunnel is established. Which NHRP message is responsible for triggering the creation of the dynamic spoke-to-spoke tunnel?

    Show answer & explanation

    Correct answer: C

    In DMVPN Phase 3, when a spoke (Spoke A) sends a packet to another spoke (Spoke B) via the hub, the hub processes the packet and forwards it to Spoke B. Simultaneously, the hub sends an 'NHRP Redirect' message back to Spoke A. This message tells Spoke A to find a better path. Spoke A then sends an 'NHRP Resolution Request' for Spoke B's NBMA address, triggering the dynamic spoke-to-spoke tunnel formation. The initial packet loss occurs during this discovery and tunnel setup process.

  2. Question 2Beginner

    Secure Remote Communications · AnyConnect Posture Assessment

    A systems administrator is configuring Cisco AnyConnect Secure Mobility Client with the posture module. The goal is to ensure that any connecting endpoint has an approved antivirus application installed and running before granting network access. Which component is responsible for defining these specific posture requirements?

    Show answer & explanation

    Correct answer: C

    The HostScan module, deployed from the Cisco ASA or integrated with Cisco Identity Services Engine (ISE), is responsible for endpoint posture assessment. Administrators configure posture policies (requirements) within the ASA's HostScan settings or more granularly within ISE. These policies define the specific conditions, such as the presence and state of antivirus software, OS patch levels, or running processes, that must be met for an endpoint to be considered compliant.

  3. Question 3Advanced

    Troubleshoot Secure Communications · IKEv2 Fragmentation

    An administrator observes that IKEv2 negotiations are failing between two sites over a network path that has a lower MTU than expected. Debugs indicate that large IKEv2 packets containing multiple certificates are being dropped. Which IKEv2 feature should be enabled on the Cisco IOS routers to resolve this issue?

    Show answer & explanation

    Correct answer: B

    IKEv2 Fragmentation is a specific feature designed to address issues where large IKE packets, especially those carrying extensive certificate chains, exceed the path MTU. When enabled with the crypto ikev2 fragmentation command, the router will fragment the IKEv2 messages at the IKE layer before encryption, allowing them to be transmitted in smaller IP packets that can traverse links with lower MTU values without being dropped by intermediate devices.

  4. Question 4Advanced

    Secure Communications · IKEv2 EAP Authentication

    An organization uses FlexVPN with an IKEv2 hub router that authenticates remote spokes using EAP passed through to a RADIUS server. To enhance security, which command must be configured within the IKEv2 profile on the hub to ensure that the EAP identity exchange is protected within the IKE security association?

    Show answer & explanation

    Correct answer: B

    The authentication remote eap command within an IKEv2 profile specifies that the remote peer (spoke) will be authenticated using EAP. A corresponding authentication local command defines how the hub authenticates itself to the spoke. Crucially, IKEv2 performs the EAP exchange inside the encrypted IKE_AUTH exchange, protecting user credentials from eavesdropping. This is a significant security improvement over IKEv1's Xauth, which sent the credentials in a separate, potentially vulnerable transaction.

  5. Question 5Intermediate

    Secure Communications · GETVPN Architecture

    A company is deploying a Cisco IOS GETVPN solution. The security architect needs to visualize the relationship between the key components. Which diagram accurately represents the control plane and data plane interactions in a GETVPN environment?

    Diagram A:
    
    [Key Server] [GM 1] [GM 2]
    ^ ^
    |-------------(GDOI)-----------------|
    
    Diagram B:
    
    [Key Server] --(GDOI)--> [GM 1]
    | \ |
    (GDOI) (GDOI) (IPsec)
    | \ |
    v v v
    [GM 2] [GM 3]
    
    Diagram C:
    
    [Key Server]
    | (Control Plane: GDOI)
    /------|------ v v v
    [GM 1] [GM 2] [GM 3]
    ^ ^ ^
    |-------|-------| (Data Plane: Full Mesh IPsec)
    \_______________/
    
    Diagram D:
    
    [GM 1] [Hub] [GM 2]
    ^
    | (Control: NHRP)
    v
    [GM 3]
    
    Show answer & explanation

    Correct answer: C

    Diagram C correctly illustrates the GETVPN architecture. The Key Server (KS) acts as a centralized control plane entity, distributing keys and policies to all Group Members (GMs) using the GDOI protocol. The data plane, however, is a full mesh. Once GMs receive the common security policy and keys, they can encrypt and decrypt traffic directly between each other without involving the KS. This preserves the original IP headers and supports native IP routing and multicast.

  6. Question 6Intermediate

    Secure Remote Communications · ASA VPN Access Control

    A network engineer is configuring a Cisco ASA 5525-X for remote access VPN using AnyConnect. The requirement is to enforce a policy where users from the 'Sales' group can only access the CRM server (10.10.20.5), while users from the 'Engineering' group can access the entire engineering subnet (10.10.30.0/24). Which ASA feature is the most appropriate and efficient way to implement these distinct access policies?

    Show answer & explanation

    Correct answer: C

    The standard and most efficient method to enforce per-group access control for VPN users on a Cisco ASA is to use VPN filters. This involves creating separate ACLs defining the permitted traffic for each group (e.g., Sales_ACL permits access to 10.10.20.5, Engineering_ACL permits access to 10.10.30.0/24). These ACLs are then applied to their respective group-policies using the vpn-filter value command under the group-policy attributes. This ensures that traffic is filtered after decryption based on the user's group membership.

  7. Question 7Intermediate

    Troubleshoot Secure Remote Communications · AnyConnect DTLS Performance

    A remote access user reports that their Cisco AnyConnect VPN connection is extremely slow, and applications frequently time out. A packet capture on the user's machine shows that the VPN is using TLS for the data channel. What is the most likely reason for the poor performance, and what should be done to resolve it?

    Show answer & explanation

    Correct answer: C

    Cisco AnyConnect prefers to use DTLS (Datagram TLS, which runs over UDP 443) for the data channel because it avoids the TCP-over-TCP meltdown problem and offers better performance for latency-sensitive applications. If the client cannot establish a DTLS session, it gracefully falls back to using TLS (over TCP 443) for the data channel. The most common reason for DTLS failure is a firewall or ACL blocking UDP port 443. The symptom of being connected via TLS indicates DTLS has failed, and the poor performance is a direct result. Allowing UDP 443 will enable the preferred DTLS tunnel.

  8. Question 8IntermediateSelect 3

    Secure Communications · IKEv1 vs IKEv2 Comparison

    Which of the following statements correctly describe differences between IKEv1 and IKEv2? (Select THREE)

    Show answer & explanation

    Correct answers: A, C, D

    IKEv2 streamlines the SA negotiation process into a single four-message exchange (IKE_SA_INIT and IKE_AUTH), which is more efficient than IKEv1 Main Mode.

    Liveness checks (DPD) are an integral part of the IKEv2 protocol, whereas in IKEv1, DPD is a vendor-specific extension that must be explicitly negotiated.

    IKEv2 provides a robust and standardized way to perform user authentication using EAP, a significant advantage for remote access scenarios over IKEv1's less secure Xauth.

  9. Question 9Advanced

    Secure Remote Communications · AnyConnect Posture and Remediation

    A hospital is deploying Cisco AnyConnect for doctors to remotely access patient records. Due to compliance requirements, endpoints connecting to the VPN must have disk encryption enabled. If an endpoint connects without disk encryption, it should be placed into a 'quarantine' VLAN with access only to a remediation server. Which technology combination is best suited to implement this policy?

    Show answer & explanation

    Correct answer: D

    This scenario requires advanced posture assessment and dynamic policy enforcement, which is the primary function of Cisco Identity Services Engine (ISE). The AnyConnect client with the posture module sends endpoint attributes (like disk encryption status) to the ASA, which forwards them to ISE. ISE's authorization policies can then check for compliance. If the endpoint is non-compliant, ISE can return an authorization profile to the ASA that assigns a downloadable ACL (dACL) or assigns the user to a specific group policy that restricts access to the quarantine VLAN.

  10. Question 10Beginner

    Secure Communications · DMVPN Phase 2 Operation

    True or False: In a DMVPN Phase 2 configuration, spoke-to-spoke traffic initially traverses the hub router, and the routing table on the spokes points to the hub as the next-hop for all other spoke subnets.

    Show answer & explanation

    Correct answer: A

    True. This statement accurately describes the core operation of DMVPN Phase 2. The routing protocol (e.g., EIGRP, OSPF) is configured in a way that the hub advertises all spoke routes to other spokes, making the hub the next-hop for inter-spoke communication. When a spoke initiates traffic to another spoke, it sends the packet to the hub. The hub forwards it, and this process triggers the NHRP resolution that allows the initiating spoke to build a direct dynamic tunnel to the destination spoke for subsequent packets. The routing table itself, however, continues to point to the hub.

Ready for the real thing?

The full 300-209 simulator has every exam-style question, timed mode, and instant scoring.