This page was exported from Offer Free Microsoft and Cisco Exam Dumps [ http://www.hitachidumps.com ] Export date:Thu Oct 2 14:51:11 2025 / +0000 GMT ___________________________________________________ Title: [2017-New]Braindump2go Cisco 400-251 Exam VCE PDF 1106Q&As for 100% Passing 400-251 Exam[Q101-Q115] --------------------------------------------------- 2017 CISCO Official News: 350-018 Exam is Replaced by 400-251 Written Exam Now! 2017 New 400-251: CCIE Security Written Exam v5.1 PDF and VCE Dumps Just Released Today by Braindump2go.com! 1.|2017 NEW 400-251 Written Exam Dumps (PDF & VCE) 1106Q&As  Download:http://www.braindump2go.com/400-251.html 2.|2017 NEW 400-251 Written Exam Questions & Answers:http://www.braindump2go.com/400-251.html   QUESTION 101Refer to the exhibit. Which effect of this configuration is true?  A.    Host_1 learns about R2 and only and prefers R2 as its default routerB.    Host_1 selects R2 as its default router and load balances between R2 and R3C.    Host_1 learns about R2 and R3 only and prefers R3 as its default routerD.    Host_1 learns about R1,R2 and R3 and load balances between themE.    Host_1 learns about R1, R2 and R3 and prefers R2 as its default router Answer: E QUESTION 102Which statement regarding the routing functions of the Cisco ASA is true running software version 9.2? A.    In a failover pair of ASAs, the standby firewall establishes a peer relationship with OSPF neighborsB.    The ASA supports policy-based routing with route mapsC.    Routes to the Null0 interface cannot be configured to black-hole trafficD.    The translations table cannot override the routing table for new connections Answer: C QUESTION 103Which two statement about router Advertisement message are true? (Choose two) A.    Local link prefixes are shared automatically.B.    Each prefix included in the advertisement carries lifetime information f Or that prefix.C.    Massage are sent to the miscast address FF02::1D.    It support a configurable number of retransmission attempts for neighbor solicitation massage.E.    Flag setting are shared in the massage and retransmitted on the link.F.    Router solicitation massage are sent in response to router advertisement massage Answer: AF QUESTION 104Refer to the exhibit. Which effect of this configuration is true?  A.    NUD retransmits 1000 Neighbor solicitation messages every 4 hours and 4 minutes.B.    NUD retransmits Neighbor Solicitation messages after 4, 16, 64 and 256 seconds.C.    NUD retransmits Neighbor Solicitation messages every 4 seconds.D.    NUD retransmits unsolicited Neighbor advertisements messages every 4 hours.E.    NUD retransmits f our Neighbor Solicitation messages every 1000 seconds.F.    NUD retransmits Neighbor Solicitation messages after 1, 4, 16, and 64 seconds. Answer: E QUESTION 105What are two features of cisco IOS that can help mitigate Blaster worm attack on RPC ports? (Choose two) A.    FPMB.    DCARC.    NBARD.    IP source GuardE.    URPFF.    Dynamic ARP inspection Answer: DE QUESTION 106Which two statement about the multicast addresses query message are true?(Choose two) A.    They are solicited when a node initialized the multicast process.B.    They are used to discover the multicast group to which listeners on a link are subscribedC.    They are used to discover whether a specified multicast address has listenersD.    They are send unsolicited when a node initializes the multicast processE.    They are usually sent only by a single router on a linkF.    They are sent when a node discover a multicast group Answer: BC QUESTION 107Refer to the exhibit. What IPSec function does the given debug output demonstrate?  A.    DH exchange initiationB.    setting SPIs to pass trafficC.    PFS parameter negotiationD.    crypto ACL confirmation Answer: B QUESTION 108Drag and Drop QuestionDrag each MACsec term on the left to the right matching statement on the right. Answer:   QUESTION 109IANA is responsible for which three IP resources? (Choose three.) A.    IP address allocationB.    Detection of spoofed addressC.    Criminal prosecution of hackersD.    Autonomous system number allocationE.    Root zone management in DNSF.    BGP protocol vulnerabilities Answer: ADE QUESTION 110When you are configuring QoS on the Cisco ASA appliance.Which four are valid traffic selection criteria? (Choose four) A.    default-inspection-trafficB.    qos-groupC.    DSCPD.    VPN groupE.    tunnel groupF.    IP precedence Answer: ACEF QUESTION 111Which two statements about the anti-replay feature are true? (Choose two) A.    By default, the sender uses a single 1024-packet sliding windowB.    By default, the receiver uses a single 64-packet sliding windowC.    The sender assigns two unique sequence numbers to each clear-text packetD.    The sender assigns two unique sequence numbers to each encrypted packetE.    the receiver performs a hash of each packet in the window to detect replaysF.    The replay error counter is incremented only when a packet is dropped Answer: BD QUESTION 112You have configured a DMVPN hub and spoke a follows (assume the IPsec profile "dmvpnprofile" is configured correctly): With this configuration, you notice that the IKE and IPsec SAs come up between the spoke and the hub, but NHRP registration fails. Registration will continue to fail until you do which of these? A.    Configure the ipnhrp cache non-authoritative command on the hub's tunnel interfaceB.    Modify the NHRP hold times to match on the hub and spokeC.    Modify the NHRP network IDs to match on the hub and spokeD.    Modify the tunnel keys to match on the hub and spoke Answer: D QUESTION 113Which of the following is one of the components of cisco Payment Card Industry Solution? A.    VirtualizationB.    Risk AssessmentC.    MonitoringD.    Disaster Management Answer: B QUESTION 114Which two statements about the DH group are true? (Choose two.) A.    The DH group is used to provide data authentication.B.    The DH group is negotiated in IPsec phase-1.C.    The DH group is used to provide data confidentiality.D.    The DH group is used to establish a shared key over an unsecured medium.E.    The DH group is negotiated in IPsec phase-2. Answer: BD QUESTION 115Your 1Pv6 network uses a CA and trust anchor to implement secure network discover. What extension must your CA certificates support? A.    extKeyUsageB.    nameConstrainstsC.    id-pe-ipAddrBlocksD.    Id-pe-autonomousSysldsE. Ia-ad-calssuersE.    keyUsage Answer: B !!! RECOMMEND!!! 1.|2017 NEW 400-251 Exam Dumps (PDF & VCE) 1106Q&As  Download:http://www.braindump2go.com/400-251.html 2.|2017 NEW 400-251 Study Guide Video: YouTube Video: YouTube.com/watch?v=GSXnXKIh834 --------------------------------------------------- Images: --------------------------------------------------- --------------------------------------------------- Post date: 2017-02-15 06:05:30 Post date GMT: 2017-02-15 06:05:30 Post modified date: 2017-02-15 06:05:30 Post modified date GMT: 2017-02-15 06:05:30 ____________________________________________________________________________________________ Export of Post and Page as text file has been powered by [ Universal Post Manager ] plugin from www.gconverters.com