Get Full Version of the Exam
http://www.EnsurePass.com/400-251.html
Question No.51
In a Cisco ASA multiple-context mode of operation configuration, what three session types are resourcelimited by default when their context is a member of the default class? (Choose three.)
-
SSL VPN sessions
-
Telnet sessions
-
TCP session
-
IPSec sessions
-
ASDM sessions
-
SSH sessions
Correct Answer: BDF
Question No.52
Refer to the exhibit. What are two effects of the given configuration? (Choose two.)
-
It enables the ASA to download the static botnet filter database.
-
It enables the ASA to download the dynamic botnet filter database.
-
It enables botnet filtering in single context mode.
-
It enables botnet filtering in mutiple context mode.
-
It enables multiple context mode.
-
It enables single context mode.
Correct Answer: BD
Question No.53
Which OpenStack project has orchestration capabilities?
-
Cinder
-
Horizon
-
Sahara
-
Heat
Correct Answer: D
Question No.54
What is the purpose of the BGP TTL security check?
-
to check for a TTL value in packet header of less than or equal to for successful peering
-
to protect against routing table corruption
-
to use for iBGP session
-
to protect against CPU utilization-based attacks
-
to authenticate a peer
Correct Answer: D
Question No.55
Refer to the exhibit. A user authenticates to the NAS , which communicates to the TACACS sever for authentication. The TACACS server then accesses the Active Directory Server through the firewall to validate the user credentials. Which protocol-port pair must be allow access through the ASA Firewall?
-
SMB over TCP 455
-
DNS over UDP 53
-
LDAP over UDP 389
-
global catalog over UDP 3268
-
TACACS over TCP 49
-
DNS over TCP 53
Correct Answer: C
Question No.56
Which three of these are properties of RC4? (Choose three.)
-
It is a block cipher.
-
It is a stream cipher.
-
It is used in AES.
-
It is a symmetric cipher.
-
It is used in SSL.
-
It is an asymmetric cipher.
Correct Answer: BDE
Question No.57
Refer to the exhibit. Which effect of this command is true?
-
The route immediately deletes its current public key from the cache and generates a new one.
-
The public key of the remote peer is deleted from the router cache.
-
The CA revokes the public key certificate of the router.
-
The current public key of the router is deleted from the cache when the router reboots, and the router generates a new one.
-
The router sends a request to the CA to delete the router certificate from its configuration.
Correct Answer: B
Question No.58
Which two statements about the Cisco AnyConnect VPN Client are true? (Choose two.)
-
It can use an SSL tunnel and a DTLS tunnel simultaneously.
-
It enables users to manage their own profiles.
-
It can be configured to download automatically without prompting the user.
-
By default, DTLS connections can fall back to TLS.
-
To improve security, keepalives are disabled by default.
Correct Answer: AC
Question No.59
Which two statements about EVPN are true? (Choose two.)
-
EVPN route exchange enables PEs to discover one another and elect a DF.
-
EVPN routes can advertise backbone MAC reachability.
-
EVLs allow you to map traffic on one or more VLANs or ports to a Bridge Domain.
-
EVPN routes can advertise VLAN membership and verify the reachability of Ethernet segments.
-
It is a next-generation Ethernet L2VPN solution that supports load balancing at the individual flow level and provider advanced access redundancy.
-
It is a next-generation Ethernet L3VPN solution that simplifies control-plane operations and enhances scalability.
Correct Answer: AB
Question No.60
Which three statements about Dynamic ARP inspection on Cisco switches are true? (Choose three)
-
The trusted database can be manually configured using the CLI
-
Dynamic ARP inspection is supported only on access ports
-
Dynamic ARP inspection does no perform ingress security checking
-
DHCP snooping is used to dynamically build the trusted database
-
Dynamic ARP inspection checks ARP packets against the trusted database
-
Dynamic ARP inspection checks ARP packets on trusted and untrusted ports
Correct Answer: ADE
Get Full Version of the Exam
400-251 Dumps
400-251 VCE and PDF