[Free] 2017(Apr) Ensurepass Passguide Cisco 400-251 Latest Dumps 81-90

Ensurepass
2017 April Cisco Official New Released 400-251 Q&As
100% Free Download! 100% Pass Guaranteed!
http://www.ensurepass.com/400-251.html

CCIE Security Written Exam v5.1

QUESTION 81

Which two statements about the 3DES encryption protocol are true? (Choose two)

 

A.

It can operate in the Electronic Code Book and Asymmetric Block Chaining modes.

B.

Its effective key length is 168 bits.

C.

It encrypts and decrypts data in three 64-bit blocks with an overall key length of 192 bits.

D.

The algorithm is most efficient when it is implemented in software instead of hardware.

E.

It encrypts and decrypts data in three 56-bit blocks with an overall key length of 168 bits.

F.

Its effective key length is 112 bits.

 

Correct Answer: EF

 

 

QUESTION 82

You want to enable users in your company’s branch offices to deploy their own access points using WAN link from the central office, but you are unable to a deploy a controller in the branch offices. What lightweight access point wireless mode should you choose?

 

A.

TLS mode

B.

H-REAP mode

C.

Monitor mode

D.

REAP mode

E.

Local mode

 

Correct Answer: B

 

 

QUESTION 83

Refer to the exhibit. Which two effect of this configuration are true? (Choose two)

 

clip_image002

 

A.

The Cisco ASA first check the user credentials against the AD tree of the security.cisco.com.

B.

The Cisco ASA use the cisco directory as the starting point for the user search.

C.

The AAA server SERVERGROUP is configured on host 10.10.10.1 with the timeout of 20 seconds.

D.

The Cisco ASA uses the security account to log in to the AD directory and search for the user cisco.

E.

The Cisco ASA authentication directly with the AD server configured on host 10.10.10.1 with the timeout of 20 second.

F.

The admin user is authenticated against the members of the security.cisco.com group.

 

Correct Answer: CF

 

 

QUESTION 84

Which object table contains information about the clients know to the server in Cisco NHRP MIB implementation?

 

A.

NHRP Cache Table

B.

NHRP Client Statistics Table

C.

NHRP Purge Request Table

D.

NHRP Server NHC Table

 

Correct Answer: D

 

 

QUESTION 85

What is the default communication port used by RSA SDI and ASA?

 

A.

UDP 500

B.

UDP 848

C.

UDP 4500

D.

UDP 5500

 

Correct Answer: D

 

 

QUESTION 86

When a client tries to connect to a WLAN using the MAC filter (RADIUS server), if the client fails the authentication, what is the web policy used tofallback authentication to web authentication?

 

A.

Authentication

B.

Passthrough

C.

Conditional Web Redirect

D.

Splash Page Web Redirect

E.

On MAC Filter Failure

 

Correct Answer: E

 

 

QUESTION 87

Refer the exhibit. Which of the following is the correct output of the above executed command?

 

clip_image003

 

A.

clip_image005

B.

clip_image007

C.

clip_image009

D.

clip_image011

 

Correct Answer: C

 

 

QUESTION 88

Which two statement about IPv6 path MTU discovery are true? (Choose two)

 

A.

The discover packets are dropped if there is congestion on the link

B.

The initial path MTU is the same as the MTU of the original node’s link layer interface

C.

It can allow fragmentation when the minimum MTU is blow a configured value

D.

During the discover process the DF bit is set to 1

E.

If the source host receiver an ICMPv6 packet too BIG message from a router it reduces its path MTU

F.

IF the destination host receives and ICMPv6 packet too Big message from a router it reduces its path MTU

 

Correct Answer: BE

 

 

QUESTION 89

Which two effects of configuring the tunnel path-mtu-discovery command on a GRE tunnel interface are true? (Choose two)

 

A.

The maximum path MTU across the GRE tunnel is set to 65534 bytes.

B.

If a lower MTU link between the IPsec peers is detected , the GRE tunnel MTU are changed.

C.

The router adjusts the MTU value it sends to the GRE tunnel interface in the TCP SYN packet.

D.

It disables PMTUD discovery for tunnel interfaces.

E.

The DF bit are copied to the GRE IP header.

F.

The minimum path MTU across the GRE tunnel is set to 1476 bytes.

 

Correct Answer: BE

QUESTION 90

Which option describes the purpose of the RADIUS VAP-ID attribute?

 

A.

It specifies the ACL ID to be matched against the client

B.

It specifies the WLAN ID of the wireless LAN to which the client belongs

C.

It sets the minimum bandwidth for the connection

D.

It sets the maximum bandwidth for the connection

E.

It specifies the priority of the client

F.

It identifies the VLAN interface to which the client will be associated

 

Correct Answer: B

100% Free Download!
—Download Free Demo:400-251 Demo PDF
100% Pass Guaranteed!
Download 2017 Ensurepass 400-251 Full Exam PDF and VCE Q&As:315
—Get 10% off your purchase! Copy it:8GTC-8UIE-M1SC [2017.04.01-2017.04.30]

Ensurepass ExamCollection Testking
Lowest Price Guarantee Yes No No
Up-to-Dated Yes No No
Real Questions Yes No No
Explanation Yes No No
PDF + VCE Yes No No
Free VCE Simulator Yes No No
Instant Download Yes No No

2017 Ensurepass IT Certification PDF and VCE

HOT EXAM!
Proudly powered by WordPress   Premium Style Theme by www.gopiplus.com