It is impossible to pass Cisco 400-251 exam without any help in the short term. Come to Exambible soon and find the most advanced, correct and guaranteed Cisco 400-251 practice questions. You will get a surprising result by our Far out CCIE Security Written Exam practice guides.
♥♥ 2021 NEW RECOMMEND ♥♥
Free VCE & PDF File for Cisco 400-251 Real Exam (Full Version!)
★ Pass on Your First TRY ★ 100% Money Back Guarantee ★ Realistic Practice Exam Questions
Free Instant Download NEW 400-251 Exam Dumps (PDF & VCE):
Available on:
http://www.surepassexam.com/400-251-exam-dumps.html
Q61. Which two options are benefits of shortcut Switching Enhancements for NHRP on DMVPN networks? (choose two)
A. Its enables the NHRP FIB lookup process to perform route summarization on the hub.
B. It allows data packets to be fast switched while spoke-to-spoke tunnels are being established.
C. It is most beneficial with partial full-mesh DVMPN setup.
D. It supports layered network topologies with the central hubs and direct spoke-to –spoke tunnels between
spokes on different hubs.
E. It enables spokes to use a summary route to build spoke-to-spoke tunnels.
Answer: B,E
Q62. What functionality does SXP provide to enhance security?
A. It supports secure communication between cisco ironport Cisco and Microsoft Exchange.
B. It supports Cisco’s trustsec solution by transporting information over network that are unable to support
SGT propagation.
C. It support secure communications between cisco ironport and cloud-based email servers.
D. It support cisco’s trustsec implementation on virtual machines.
Answer: B
Q63. DRAG DROP
Drag and drop the desktop-security terms from the left onto their right definitions on the right?
Answer:
Explanation:
governance = directing and controlling information and communications technology penetration testing = using hacking techniques to attempt to bypass existing security phishing = attempting to elict information from users by sending targeted emails
SSO = allowing users to sign in to multiple systems without reentering their credentials two factor authentication = using more than one mechanism to verify a user login
Q64. Which two statements about CoPP are true? (Choose two)
A. When a deny rule in an access list is used for MQC is matched, classification continues on the next class
B. It allows all traffic to be rate limited and discarded
C. Access lists that are used with MQC policies for CoPP should omit the log and log-input keywords
D. The mls qos command disables hardware acceleration so that CoPP handles all QoS
E. Access lists that use the log keyword can provide information about the device’s CPU
usage
F. The policy-map command defines the traffic class
Answer: A,C
Q65. DRAG DROP
Drag each step in the SCEP workflow on the left into the correct order of operations on the right?
Answer:
Explanation:
Step 1: Obtain and validate CA cert.
Step 2: Generate a certificate signing request for the CA.
Step 3: Sent a request to SCEP server to confirm that the cert was signed. Step 4: Re- enroll the client and replace the existing certificate.
Step 5: Check Certificate revocation list.
Q66. On which two protocols is VNC based?(Choose two)
A. Rdesktop
B. UDP
C. RFB
D. Terminal Services Client
E. CoRD
F. TCP
Answer: C,F
Q67. DRAG DROP
Drag each ISE probe on the left to the matching statement on the right.
Answer:
Q68. Which statement about the Cisco Secure ACS Solution Engine TACACS+ AV pair is true?
A. AV pairs are only required to be enabled on Cisco Secure ACS for successful implementation.
B. The Cisco Secure ACS Solution Engine does not support accounting AV pairs.
C. AV pairs are only string values.
D. AV pairs are of two types: string and integer.
Answer: C
Q69. Which two answers describe provisions of the SOX Act and its international counterpart Acts? (Choose two.)
A. confidentiality and integrity of customer records and credit card information
B. accountability in the event of corporate fraud
C. financial information handled by entities such as banks, and mortgage and insurance brokers
D. assurance of the accuracy of financial records
E. US Federal government information
F. security standards that protect healthcare patient data
Answer: B,D
Q70. Which two statements about IPsec in a NAT-enabled environment are true? (Choose two)
A. The hashes of each peer’s IP address and port number are compared to determine whether NAT-T is required
B. NAT-T is not supported when IPsec Phase 1 is set to Aggressive Mode
C. The first two messages of IPsec Phase 2 are used to determine whether the remote host supports
NAT-T
D. NAT-T is not supported when IPsec Phase 1 is set to Main Mode
E. IPsec packets are encapsulated in UDP 500 or UDP 10000 packets
F. To prevent translations from expiring, NAT keepalive messages that include a payload are sent between the peers
Answer: A,D
