Dumps4cert.com : Latest Dumps with PDF and VCE Files
2018 July VMware Official New Released 2V0-651
100% Free Download! 100% Pass Guaranteed!
CCIE Security Exam (v4.1)
Question No: 51 – (Topic 1)
Which three statements about Dynamic ARP inspection on Cisco seithes are true? (Choose three)
-
The trusted database can be manually configured using the CLI
-
Dynamic ARP inspection is supported only on access ports
-
Dynamic ARP inspection does no perform ingress security checking
-
DHCP snooping is used to dynamically build the trusted database
-
Dynamic ARP inspection checks ARP packets against the trusted database
-
Dynamic ARP inspection checks ARP packets on trusted and untrusted ports
Answer: A,D,E
Question No: 52 – (Topic 1)
Refer to the exhibit.
What feature must be implemented on the network to produce the given output?
-
CAR
-
NBAR
-
WFQ
-
PQ
-
CQ
Answer: B
Question No: 53 – (Topic 1)
Refer to the exhibit.
What is the meaning of the given error message?
-
The PFS groups are mismatched
-
IKES disabled on the remote peer
-
The pre-shared keys are mismatched
-
The mirrored crypto ACLs are mismatched
Answer: C
Question No: 54 – (Topic 1)
If a cisco ASA firewall that is configured in multiple-context mode of operation receives a packet whose destination MAC address is a multicast address,how is the packet routed?
-
The Packets dropped
-
The packet is duplicated and forwarded to every context
-
The packet is forwarded to the admin context only
-
The packet duplicated and forwarded to every context except admin
Answer: B
Question No: 55 – (Topic 1)
Which option describes the purpose of Fog architecture in loT?
-
To provide intersensor traffic routing
-
To provide highly available environmentally hardened network access
-
To provide centralized compute resources
-
To provide compute services at the network edge
Answer: D
Question No: 56 – (Topic 1)
Which two statements about DTLS are true?(Choose two)
-
When DPD IS disabled, DTLS connections can automatically fall back to TLS.
-
It can reduce packet delays and improve application performance.
-
It is more secure than TLS
-
It supports SSL VPNS without requiring an SSL tunnel.
-
Unlike TLS DTLS supports VPN connections with ASA
-
It overcome the latency and bandwidth problems that can occur with SSL
Answer: B,F
Question No: 57 – (Topic 1)
What is an example of a WEP cracking attack?
-
Cafe Latte attack
-
Reflected XSS attack
-
Directory traversal attack
-
SQL injection attack
Answer: A
Question No: 58 – (Topic 1)
In a Cisco ASA multiple-context mode of operation configuration ,what three session types are resource-limited by default when their context is a member of the default class?(Choose three)
-
ASDM sessions
-
Telnet sessions
-
IPSec sessions
-
SSL VPN sessions
-
TCP sessions
-
SSH sessions
Answer: A,B,F
Question No: 59 – (Topic 1)
Which three statements about SCEP are true? (choose three)
-
The certificate request format uses PKCS#10
-
Cryptographically signed and encrypted message are conveyed using PKCS#7
-
It supports multiple cryptographic algorithms including RSA
-
CRL retrieval is supported though CDP (certificate distribute point) queries
-
It support synchronous granting
-
It supports online certification revocation
Answer: A,B,D
Question No: 60 – (Topic 1)
Which two statements about IKEv2 are true?(Choose two)
-
it uses EAP authentication
-
At minimum. A complete proposal requires one encryption algorithm and one integrity algorithm.
-
The profile contains a repository of symmetric and asymmetric and asymmetric preshared keys.
-
It uses X.509 certificates for authentication
-
The profile is a collection of transforms used to negotiate IKE SAS
-
It supports DPD and NAT-T by default.
Answer: A,F
100% Dumps4cert Free Download!
–Download Free Demo:2V0-651 Demo PDF
100% Dumps4cert Pass Guaranteed!
–2V0-651 Dumps
Dumps4cert | ExamCollection | Testking | |
---|---|---|---|
Lowest Price Guarantee | Yes | No | No |
Up-to-Dated | Yes | No | No |
Real Questions | Yes | No | No |
Explanation | Yes | No | No |
PDF VCE | Yes | No | No |
Free VCE Simulator | Yes | No | No |
Instant Download | Yes | No | No |