Dumps4cert.com : Latest Dumps with PDF and VCE Files
2018 July VMware Official New Released 2V0-651
100% Free Download! 100% Pass Guaranteed!
CCIE Security Exam (v4.1)
Question No: 331 – (Topic 4)
If an incoming packet from the outside interface does not match an existing connection in the connection table, which action will the Cisco ASA appliance perform next?
-
drop the packet
-
check the outside interface inbound ACL to determine if the packet is permitted or denied
-
perform NAT operations on the packet if required
-
check the MPF policy to determine if the packet should be passed to the SSM
-
perform stateful packet inspection based on the MPF policy
Answer: B
Question No: 332 – (Topic 4)
In HTTPS session establishment, what does the server hello message inform the client?
-
that the server will accept only HTTPS traffic
-
which versions of SSL/TLS the server will accept
-
which ciphersuites the client may choose from
-
which ciphersuite the server has chosen to use
-
the PreMaster secret to use in generating keys
Answer: D
Question No: 333 – (Topic 4)
What are two advantages of using NLA with Windows Terminal Services? (Choose two.)
-
uses SPNEGO and TLS to provide optional double encryption of user credentials
-
forces the use of Kerberos to pass credentials from client to server
-
protects against man-in-the-middle attacks
-
requires clients to present an SSL certificate to verify their authenticity
-
protects servers against DoS attacks by requiring lesser resources for authentication
Answer: A,C
Question No: 334 – (Topic 4)
Refer to the exhibit.
Which message could contain an authenticated initial_contact notify during IKE main mode negotiation?
-
message 3
-
message 5
-
message 1
-
none, initial_contact is sent only during quick mode
-
none, notify messages are sent only as independent message types
Answer: B
Question No: 335 – (Topic 4)
Which statement about the Cisco NAC CAS is true?
-
The Cisco NAC CAS acts as a gateway between untrusted networks.
-
The Cisco NAC CAS can only operate as an in-band real IP gateway.
-
The Cisco NAC CAS can operate as an out-of-band virtual gateway.
-
The Cisco NAC CAS is an administration and monitoring server.
Answer: C
Question No: 336 – (Topic 4)
Refer to the exhibit.
Which three statements about the Cisco ASDM screen seen in the exhibit are true? (Choose three.)
-
This access rule is applied to all the ASA interfaces in the inbound direction.
-
The ASA administrator needs to expand the More Options tag to configure the inbound or outbound direction of the access rule.
-
The ASA administrator needs to expand the More Options tag to apply the access rule to an interface.
-
The resulting ASA CLI command from this ASDM configuration is access-list global_access line 1 extended permit ip host 1.1.1.1 host 2.2.2.1.
-
This access rule is valid only on the ASA appliance that is running software release 8.3 or later.
-
This is an outbound access rule.
Answer: A,D,E
Question No: 337 – (Topic 4)
During the establishment of an Easy VPN tunnel, when is XAUTH performed?
-
at the end of IKEv1 Phase 2
-
at the beginning of IKEv1 Phase 1
-
at the end of Phase 1 and before Phase 2 starts in IKEv1 and IKEv2
-
at the end of Phase 1 and before Phase 2 starts in IKEv1
Answer: D
Question No: 338 – (Topic 4)
Which protocol can be used to encrypt traffic sent over a GRE tunnel?
-
SSL
-
SSH
-
IPsec
-
DH
-
TLS
Answer: C
Question No: 339 – (Topic 4)
What are two reasons for a certificate to appear in a CRL? (Choose two.)
-
CA key compromise
-
cessation of operation
-
validity expiration
-
key length incompatibility
-
certification path invalidity
Answer: A,B
Question No: 340 – (Topic 4)
Which IPsec protocol provides data integrity but no data encryption?
-
AH
-
ESP
-
SPI
-
DH
Answer: A
100% Dumps4cert Free Download!
–Download Free Demo:2V0-651 Demo PDF
100% Dumps4cert Pass Guaranteed!
–2V0-651 Dumps
Dumps4cert | ExamCollection | Testking | |
---|---|---|---|
Lowest Price Guarantee | Yes | No | No |
Up-to-Dated | Yes | No | No |
Real Questions | Yes | No | No |
Explanation | Yes | No | No |
PDF VCE | Yes | No | No |
Free VCE Simulator | Yes | No | No |
Instant Download | Yes | No | No |