Dumps4cert.com : Latest Dumps with PDF and VCE Files
2018 July Microsoft Official New Released 77-601
100% Free Download! 100% Pass Guaranteed!
CCIE Security Exam (v4.1)
Question No: 381 – (Topic 4)
Refer to the exhibit.
Choose the correct description of the implementation that produced this output on the Cisco ASA appliance.
-
stateful failover using active-active for multi-context
-
stateful failover using active-standby for multi-context
-
stateful failover using active-standby for single-context
-
stateless failover using interface-level failover for multi-context
Answer: A
Question No: 382 – (Topic 4)
A device is sending a PDU of 5000 B on a link with an MTU of 1500 B. If the PDU includes 20 B of IP header, which statement is true considering the most efficient way to transmit this PDU?
-
The first three packets will have a packet payload size of 1400.
-
The last packet will have a payload size of 560.
-
The first three packets will have a packet payload size of 1480.
-
The last packet will have a payload size of 20.
Answer: C
Question No: 383 – (Topic 4)
Which configuration is the correct way to change a GET VPN Key Encryption Key lifetime to 10800 seconds on the key server?
-
crypto isakmp policy 1 lifetime 10800
-
crypto ipsec security-association lifetime? seconds 10800
-
crypto ipsec profile getvpn-profile
set security-association lifetime seconds 10800
!
crypto gdoi group GET-Group identity number 1234
server local sa ipsec 1
profile getvpn-profile
-
?crypto gdoi group GET-Group identity number 1234
server local
rekey lifetime seconds 10800
-
crypto gdoi group GET-Group identity number 1234
server local
set security-association lifetime seconds 10800
Answer: D
Question No: 384 – (Topic 4)
What is the purpose of the SPI field in an IPsec packet?
-
identifies a transmission channel
-
provides anti-replay protection
-
ensures data integrity
-
contains a shared session key
Answer: A
Question No: 385 – (Topic 4)
What feature on the Cisco ASA is used to check for the presence of an up-to-date antivirus vendor on an AnyConnect client?
-
Dynamic Access Policies with no additional options
-
Dynamic Access Policies with Host Scan enabled
-
advanced endpoint assessment
-
LDAP attribute maps obtained from Antivirus vendor
Answer: B
Question No: 386 – (Topic 4)
Which transport type is used by the DHCP protocol?
-
UDP ports 67 and 69
-
TCP ports 67 and 68
-
UDP and TCP port 67
-
UDP ports 67 and 68
Answer: D
Question No: 387 – (Topic 4)
crypto isakmp profile vpn1 vrf vpn1
keyring vpn1
match identity address 172.16.1.1 255.255.255.255 crypto map crypmap 1 ipsec-isakmp
set peer 172.16.1.1 set transform-set vpn1
set isakmp-profile vpn1 match address 101
!
interface Ethernet1/2 crypto map crypmap
Which statements apply to the above configuration? (Choose two.)
-
This configuration shows the VRF-Aware IPsec feature that is used to map the crypto ISAKMP profile to a specific VRF.
-
VRF and ISAKMP profiles are mutually exclusive, so the configuration is invalid.
-
An IPsec tunnel can be mapped to a VRF instance.
-
Peer command under the crypto map is redundant and not required.
Answer: A,C
Question No: 388 – (Topic 4)
What is the purpose of the BGP TTL security check?
-
The BGP TTL security check is used for iBGP session.
-
The BGP TTL security check protects against CPU utilization-based attacks.
-
The BGP TTL security check checks for a TTL value in packet header of less than or equal to for successful peering.
-
The BGP TTL security check authenticates a peer.
-
The BGP TTL security check protects against routing table corruption.
Answer: B
Question No: 389 – (Topic 4)
Which two statements about SNMP are true? (Choose two)
-
SNMP operates at Layer-6 of the OSI model.
-
NMS sends a request to the agent at TCP port 161.
-
NMS sends request to the agent from any source port.
-
NMS receives notifications from the agent on UDP 162.
-
MIB is a hierarchical representation of management data on NMS.
Answer: C,D
Question No: 390 – (Topic 4)
Which three options are components of Mobile IPv6? (Choose three.)
-
home agent
-
correspondent node
-
mobile node
-
binding node
-
discovery probe
Answer: A,B,C
100% Dumps4cert Free Download!
–Download Free Demo:77-601 Demo PDF
100% Dumps4cert Pass Guaranteed!
–77-601 Dumps
Dumps4cert | ExamCollection | Testking | |
---|---|---|---|
Lowest Price Guarantee | Yes | No | No |
Up-to-Dated | Yes | No | No |
Real Questions | Yes | No | No |
Explanation | Yes | No | No |
PDF VCE | Yes | No | No |
Free VCE Simulator | Yes | No | No |
Instant Download | Yes | No | No |