What Does 400-251 exam question Mean?

Exam Code: 400-251 (Practice Exam Latest Test Questions VCE PDF)
Exam Name: CCIE Security Written Exam
Certification Provider: Cisco
Free Today! Guaranteed Training- Pass 400-251 Exam.


♥♥ 2021 NEW RECOMMEND ♥♥

Free VCE & PDF File for Cisco 400-251 Real Exam (Full Version!)

★ Pass on Your First TRY ★ 100% Money Back Guarantee ★ Realistic Practice Exam Questions

Free Instant Download NEW 400-251 Exam Dumps (PDF & VCE):
Available on: http://www.surepassexam.com/400-251-exam-dumps.html

Q111. Which Cisco ASA firewall mode supports ASDM one-time-password authentication using RSA SecurID?

A. Network translation mode

B. Single-context routed mode

C. Multiple-context mode

D. Transparent mode

Answer: B


Q112. Which three statements about the Cisco IPS sensor are true? (Choose three.)

A. You cannot pair a VLAN with itself.

B. For a given sensing interface, an interface used in a VLAN pair can be a member of another inline interface pair.

C. For a given sensing interface, a VLAN can be a member of only one inline VLAN pair, however, a given VLAN can

be a member of an inline VLAN pair on more than one sensing interface.

D. The order in which you specify the VLANs in a inline pair is significant.

E. A sensing interface in inline VLAN pair mode can have from 1 to 255 inline VLAN pairs.

Answer: A,C,E

Explanation:

Inline VLAN Interface Pairs

You cannot pair a VLAN with itself.

For a given sensing interface, a VLAN can be a member of only one inline VLAN pair. However, a given VLAN can be a member of an inline VLAN pair on more than one sensing interface.

The order in which you specify the VLANs in an inline VLAN pair is not significant.

A sensing interface in inline VLAN pair mode can have from 1 to 255 inline VLAN pairs.


Q113. Which three statements about Unicast RPF in strict mode and loose mode are true? (choose three)

A. Inadvertent packet loss can occur when loose mode is used with asymmetrical routing.

B. Strict mode requires a default route to be associated with the uplink network interface.

C. Both loose and strict modes are configured globally on the router.

D. Loose mode requires the source address to be present in the routing table.

E. Strict mode is recommended on interfaces that will receive packets only form the same subnet to which the interface is assigned.

F. Interfaces in strict mode drop traffic with return routes that point to the NULL 0 interface.

Answer: D,E,F


Q114. Which Two statement about the PCoIP protocol are true? (Choose two)

A. It support both loss and lossless compression

B. It is a client-rendered, multicast-codec protocol.

C. It is available in both software and hardware.

D. It is a TCP-based protocol.

E. It uses a variety of codec to support different operating system.

Answer: A,C


Q115. Which command sequence can you enter to enable IP multicast for WCCPv2?

A. Router(config)#ip wccp web-cache service-list Router(config)#interface FastEthernet0/0

Router(config)#ip wccp web-cache group-listen

B. Router(config)#ip wccp web-cache group-list Router(config)#interface FastEthernet0/0 Router(config)#ip wccp web-cache group-listen

C. Router(config)#ip wccp web-cache group-address 224.1.1.100 Router(config)#interface FastEthernet0/0

Router(config)#ip wccp web-cache redirect in

D. Router(config)#ip wccp web-cache group-address 224.1.1.100 Router(config)#interface FastEthernet0/0

Router(config)#ip wccp web-cache group-listen

E. Router(config)#ip wccp web-cache group-address 224.1.1.100 Router(config)#interface FastEthernet0/0

Router(config)#ip wccp web-cache redirect out

Answer: D


Q116. Which three statements about SCEP are true?(Choose three)

A. It Supports online certification revocation.

B. Cryptographically signed and encrypted message are conveyed using PKCS#7.

C. The certificate request format uses PKCS#10.

D. It supports multiple cryptographic algorithms, including RSA.

E. CRL retrieval is support through CDP (Certificate Distribution Point) queries.

F. It supports Synchronous granting.

Answer: B,C,E


Q117. Refer to the exhibit. 

What are three effect of the given firewall configuration? (Choose three.)

A. The firewall allows Echo Request packets from any source to pass server.

B. The firewall allows time Exceeded error messages from any source to pass to the server.

C. PCs outside the firewall are unable to communicate with the server over HTTP

D. The firewall allows Echo Reply packets from any source to pass to the server.

E. The firewall allows Destination Unreachable error messages from any source to pass to the server.

F. The firewall allows Packet too big error messages from any source to pass to the server.

Answer: A,D,F


Q118. What are the two IPSec modes? (Choose two)

A. Aggressive

B. ISAKMP

C. Transport

D. IKE

E. Main

F. Tunnel

Answer: C,F


Q119. DRAG DROP

Drag each OSPF security feature on the left to its description on the right.

Answer:

Explanation:

TTL security check:protects ospf neighbor sessions against CPU prefix length: protects the routers in an ospf neighbor session

Type0:Establishes OSPF sessions without authenthication Type1:Uses Clear-text authenthication to protect

Type2:Uses MD5 authenthication to protect


Q120. What protocol is responsible for issuing certificates?

A. SCEP

B. DTLS

C. ESP

D. AH

E. GET

Answer: A