Ensurepass.com : Ensure you pass the IT Exams
2018 Aug Cisco Official New Released 350-018
100% Free Download! 100% Pass Guaranteed!
CCIE Security Exam (v4.1)
Question No: 271 – (Topic 4)
Which two statements about the OSPF authentication configuration are true? (Choose two.)
-
OSPF authentication is required in area 0.
-
There are three types of OSPF authentication options available.
-
In MD5 authentication, the password is encrypted when it is sent.
-
Null authentication includes the password in clear-text.
-
Type-3 authentication is a clear-text password authentication.
-
In MD5 authentication, the password never goes across the network.
Answer: B,F
Question No: 272 – (Topic 4)
Which two security measures are provided when you configure 802.1X on switchports that connect to corporate-controlled wireless access points? (Choose two.)
-
It prevents rogue APs from being wired into the network.
-
It provides encryption capability of data traffic between APs and controllers.
-
It prevents rogue clients from accessing the wired network.
-
It ensures that 802.1x requirements for wired PCs can no longer be bypassed by disconnecting the AP and connecting a PC in its place.
Answer: A,D
Question No: 273 – (Topic 4)
Which ICMP message type code indicates fragment reassembly time exceeded?
-
Type 4, Code 0
-
Type 11, Code 0
-
Type 11, Code 1
-
Type 12, Code 2
Answer: C
Question No: 274 – (Topic 4)
Which transport method is used by the IEEE 802.1X protocol?
-
EAPOL frames
-
802.3 frames
-
UDP RADIUS datagrams
-
PPPoE frames
Answer: A
Question No: 275 – (Topic 4)
Which statement is true about EAP-FAST?
-
It supports Windows single sign-on.
-
It is a proprietary protocol.
-
It requires a certificate only on the server side.
-
It does not support an LDAP database.
Answer: A
Question No: 276 – (Topic 4)
Which two statements about dynamic ARP inspection are true? (Choose two.)
-
Dynamic ARP inspection checks ARP packets on both trusted and untrusted ports.
-
Dynamic ARP inspection is only supported on access and trunk ports.
-
Dynamic ARP inspection checks invalid ARP packets against the trusted database.
-
The trusted database to check for an invalid ARP packet is manually configured.
-
Dynamic ARP inspection does not perform ingress security checking.
-
DHCP snooping must be enabled.
Answer: C,F
Question No: 277 – (Topic 4)
Which three statements about Dynamic ARP Inspection on Cisco Switches are true? (Choose three.)
-
Dynamic ARP inspection checks ARP packets on both trusted and untrusted ports.
-
Dynamic ARP inspection is only supported on access ports.
-
Dynamic ARP inspection checks ARP packets against the trusted database.
-
The trusted database can be manually configured using the CLI.
-
Dynamic ARP inspection does not perform ingress security checking.
-
DHCP snooping is used to dynamically build the trusted database.
Answer: C,D,F
Question No: 278 – (Topic 4)
Which record statement is part of the NetFlow monitor configuration that is used to collect MPLS traffic with an IPv6 payload?
-
record mpls IPv6-fields labels 3
-
record mpls IPv4-fields labels 3
-
record mpls labels 3
-
record mpls ipv6-fields labels
Answer: A
Question No: 279 – (Topic 4)
Which C3PL configuration component is used to tune the inspection timers such as setting the tcp idle-time and tcp synwait-time on the Cisco ZBFW?
-
class-map type inspect
-
parameter-map type inspect
-
service-policy type inspect
-
policy-map type inspect tcp
-
inspect-map type tcp
Answer: B
Question No: 280 – (Topic 4)
Which three configuration tasks are required for VPN clustering of AnyConnect clients that are connecting to an FQDN on the Cisco ASA?? (Choose three.)
-
The redirect-fqdn command must be entered under the vpn load-balancing sub- configuration.
-
Each ASA in the VPN cluster must be able to resolve the IP of all DNS hostnames that are used in the cluster?.
-
The identification and CA certificates for the master FQDN hostname must be imported into each VPN cluster-member device?.
-
The remote-access IP pools must be configured the same on each VPN cluster-member interface.
Answer: A,B,C
100% Ensurepass Free Download!
–350-018 PDF
100% Ensurepass Free Guaranteed!
–350-018 Dumps
EnsurePass | ExamCollection | Testking | |
---|---|---|---|
Lowest Price Guarantee | Yes | No | No |
Up-to-Dated | Yes | No | No |
Real Questions | Yes | No | No |
Explanation | Yes | No | No |
PDF VCE | Yes | No | No |
Free VCE Simulator | Yes | No | No |
Instant Download | Yes | No | No |