Pass4sure offers free demo for ccna security 210 260 pdf exam. "IINS Implementing Cisco Network Security", also known as ccna security 210 260 lab exam, is a Cisco Certification. This set of posts, Passing the Cisco cisco 210 260 dump exam, will help you answer those questions. The ccna security 210 260 dumps pdf Questions & Answers covers all the knowledge points of the real exam. 100% real Cisco ccna security 210 260 official cert guide pdf download exams and revised by experts!

P.S. Actual 210-260 preparation exams are available on Google Drive, GET MORE: https://drive.google.com/open?id=15Wj8GqxvfYTz0nGHdJkfV_zMadDrezid


New Cisco 210-260 Exam Dumps Collection (Question 2 - Question 11)

Question No: 2

Which statement about extended access lists is true?

A. Extended access lists perform filtering that is based on source and destination and are

most effective when applied to the destination

B. Extended access lists perform filtering that is based on source and destination and are most effective when applied to the source

C. Extended access lists perform filtering that is based on destination and are most effective when applied to the source

D. Extended access lists perform filtering that is based on source and are most effective when applied to the destination

Answer: B


Question No: 3

Which type of attack is directed against the network directly:

A. Denial of Service

B. phishing

C. trojan horse

Answer: A


Question No: 4

When a switch has multiple links connected to a downstream switch, what is the first step that STP takes to prevent loops?

A. STP elects the root bridge

B. STP selects the root port

C. STP selects the designated port

D. STP blocks one of the ports

Answer: A


Question No: 5

Which IOS command do you enter to test authentication against a AAA server?

A. dialer aaa suffix <suffix> password <password>

B. ppp authentication chap pap test

C. aaa authentication enable default test group tacacs+

D. test aaa-server authentication dialergroup username <user> password.

Answer: D


Question No: 6

Which two statements about stateless firewalls are true? (Choose two.)

A. They compare the 5-tuple of each incoming packet against configurable rules.

B. They cannot track connections.

C. They are designed to work most efficiently with stateless protocols such as HTTP or HTTPS.

D. Cisco IOS cannot implement them because the platform is stateful by nature.

E. The Cisco ASA is implicitly stateless because it blocks all traffic by default.

Answer: A,B


Question No: 7

Which command is needed to enable SSH support on a Cisco Router?

A. crypto key lock rsa

B. crypto key generate rsa

C. crypto key zeroize rsa

D. crypto key unlock rsa

Answer: B


Question No: 8

Which two features do CoPP and CPPr use to protect the control plane? (Choose two.)

A. QoS

B. traffic classification

C. access lists

D. policy maps

E. class maps

F. Cisco Express Forwarding

Answer: A,B


Question No: 9

Which Firepower Management Center feature detects and blocks exploits and hack attempts?

A. intrusion prevention

B. advanced malware protection

C. content blocker

D. file control

Answer: D


Question No: 10

With which technology do apply integrity, confidentially and authenticate the source

A. IPSec

B. IKE

C. Certificate authority

D. Data encryption standards

Answer: A


Question No: 11

A Cisco ASA appliance has three interfaces configured. The first interface is the inside interface with a security level of 100. The second interface is the DMZ interface with a security level of 50. The third interface is the outside interface with a security level of 0.

By default, without any access list configured, which five types of traffic are permitted? (Choose five.)

A. outbound traffic initiated from the inside to the DMZ

B. outbound traffic initiated from the DMZ to the outside

C. outbound traffic initiated from the inside to the outside

D. inbound traffic initiated from the outside to the DMZ

E. inbound traffic initiated from the outside to the inside

F. inbound traffic initiated from the DMZ to the inside

G. HTTP return traffic originating from the inside network and returning via the outside interface

H. HTTP return traffic originating from the inside network and returning via the DMZ interface

I. HTTP return traffic originating from the DMZ network and returning via the inside interface

J. HTTP return traffic originating from the outside network and returning via the inside interface

Answer: A,B,C,G,H

Explanation:

http://www.cisco.com/en/US/docs/security/asa/asa70/configuration/guide/intparam.html Security Level

Overview

Each interface must have a security level from 0 (lowest) to 100 (highest). For example, you should assign your most secure network, such as the inside host network, to level 100. While the outside network connected to the Internet can be level 0. Other networks, such as DMZs can be in between. You can assign interfaces to the same security level. See the "Allowing Communication Between Interfaces on the Same Security Level" section for more information.

The level controls the following behavior:

u2022Network access u2014 By default, there is an implicit permit from a higher security interface to a lower security interface (outbound). Hosts on the higher security interface can access any host on a lower security interface. You can limit access by applying an access list to the interface. If you enable communication for same security interfaces (see the "Allowing Communication Between Interfaces on the Same Security Level" section), there is an implicit permit for interfaces to access other interfaces on the same security level or lower.

u2022Inspection engines u2014 Some inspection engines are dependent on the security level. For same security interfaces, inspection engines apply to traffic in either direction.

u2013NetBIOS inspection engineu2014Applied only for outbound connections.

u2013OraServ inspection engine u2014 If a control connection for the OraServ port exists between a pair of hosts, then only an inbound data connection is permitted through the security appliance.

u2022Filteringu2014HTTP(S) and FTP filtering applies only for outbound connections (from a higher level to a lower level).

For same security interfaces, you can filter traffic in either direction.

u2022NAT control u2014 When you enable NAT control, you must configure NAT for hosts on a higher security interface (inside) when they access hosts on a lower security interface (outside).

Without NAT control, or for same security interfaces, you can choose to use NAT between

any interface, or you can choose not to use NAT. Keep in mind that configuring NAT for an outside interface might require a special keyword.

u2022established command u2014 This command allows return connections from a lower security host to a higher security host if there is already an established connection from the higher level host to the lower level host.

For same security interfaces, you can configure established commands for both directions.


Recommend!! Get the Actual 210-260 dumps in VCE and PDF From Certifytools, Welcome to download: https://www.certifytools.com/210-260-exam.html (New 310 Q&As Version)