Cause all that matters here is passing the Cisco 400-251 exam. Cause all that you need is a high score of 400-251 CCIE Security Written Exam exam. The only one thing you need to do is downloading Pass4sure 400-251 exam study guides now. We will not let you down with our money-back guarantee.


♥♥ 2021 NEW RECOMMEND ♥♥

Free VCE & PDF File for Cisco 400-251 Real Exam (Full Version!)

★ Pass on Your First TRY ★ 100% Money Back Guarantee ★ Realistic Practice Exam Questions

Free Instant Download NEW 400-251 Exam Dumps (PDF & VCE):
Available on: http://www.surepassexam.com/400-251-exam-dumps.html

Q11. NWhich two statements about the ISO are true? (Choose two.

A. The ISO is a government-based organization.

B. The ISO has three membership categories: Member, Correspondent, and Subscribers.

C. Subscriber members are individual organizations.

D. Only member bodies have voting rights.

E. Correspondent bodies are small countries with their own standards organization.

Answer: B,D

Explanation: Member bodies are national bodies considered the most representative standards body in each country. These are the only members of ISO that have voting rights.


Q12. Refer to the exhibit. 

After you configured routes R1 and R2 for IPv6 OSPFv3 authentication as shown, the OSPFv3 neighbor adjacency failed to establish. What is a possible reason for the problem?

A. R2 received a packet with an incorrect area form the loopback1 interface

B. OSPFv3 area authentication is missing

C. R1 received a packet with an incorrect area from the FastEthernet0/0 interface

D. The SPI and the authentication key are unencrypted

E. The SPI value and the key are the same on both R1 and R2

Answer: C


Q13. Which three statement about VRF-Aware Cisco Firewall are true? (Choose three)

A. It can run as more than one instance.

B. It supports both global and per-VRF commands and DoS parameters.

C. It can support VPN networks with overlapping address ranges without NAT.

D. It enables service providers to implement firewalls on PE devices.

E. It can generate syslog massages that are visible only to individual VPNs.

F. It enables service providers to deploy firewalls on customer devices.

Answer: A,D,E


Q14. Which two options are benefits of shortcut Switching Enhancements for NHRP on DMVPN networks? (choose two)

A. Its enables the NHRP FIB lookup process to perform route summarization on the hub.

B. It allows data packets to be fast switched while spoke-to-spoke tunnels are being established.

C. It is most beneficial with partial full-mesh DVMPN setup.

D. It supports layered network topologies with the central hubs and direct spoke-to –spoke tunnels between

spokes on different hubs.

E. It enables spokes to use a summary route to build spoke-to-spoke tunnels.

Answer: B,E


Q15. Which two statement about Infrastructure ACLs on Cisco IOS software are true? (Choose two.)

A. Infrastructure ACLs are used to block-permit the traffic in the router forwarding path.

B. Infrastructure ACLs are used to block-permit the traffic handled by the route processor.

C. Infrastructure ACLs are used to block-permit the transit traffic.

D. Infrastructure ACLs only protect device physical management interface.

Answer: B,D


Q16. Which three IP resources is IANA responsible for? (Choose three.)

A. IP address allocation

B. detection of spoofed address

C. criminal prosecution of hackers

D. autonomous system number allocation

E. root zone management in DNS

F. BGP protocol vulnerabilities

Answer: A,D,E


Q17. Which two statements about the MD5 Hash are true? (Choose two.)

A. Length of the hash value varies with the length of the message that is being hashed.

B. Every unique message has a unique hash value.

C. Its mathematically possible to find a pair of message that yield the same hash value.

D. MD5 always yields a different value for the same message if repeatedly hashed.

E. The hash value cannot be used to discover the message.

Answer: B,E


Q18. DRAG DROP

Drag each EAP variant in the 802.1x framework to the matching statement on the right?

Answer:

Explanation: EAP-FAST: An encapsulated EAP variant that can travel through TLS tunnel EAP-MD5: When used, EAP servers provide authentication to EAP peers only EAP-OTP: Authenticates using a single-use token

EAP-PEAP: Performs secure tunnel authentication

EAP-SIM: Enables GSM users to access both voice and data services with unified authentication. EAP-TLS: Provides EAP message fragmentation.

EAP-TTLS: An early EAP variant that uses certificates based authentication of both client and server

LEAP: A simplified EAP variant that uses password as shared service.


Q19. On which two protocols is VNC based?(Choose two)

A. Rdesktop

B. UDP

C. RFB

D. Terminal Services Client

E. CoRD

F. TCP

Answer: C,F


Q20. Which two statements about CoPP are true? (Choose two)

A. When a deny rule in an access list is used for MQC is matched, classification continues on the next class

B. It allows all traffic to be rate limited and discarded

C. Access lists that are used with MQC policies for CoPP should omit the log and log-input keywords

D. The mls qos command disables hardware acceleration so that CoPP handles all QoS

E. Access lists that use the log keyword can provide information about the device’s CPU

usage

F. The policy-map command defines the traffic class

Answer: A,C