We provide real 400-251 exam questions and answers braindumps in two formats. Download PDF & Practice Tests. Pass Cisco 400-251 Exam quickly & easily. The 400-251 PDF type is available for reading and printing. You can print more and practice many times. With the help of our Cisco 400-251 dumps pdf and vce product and material, you can easily pass the 400-251 exam.

Online 400-251 free questions and answers of New Version:

NEW QUESTION 1

Which statement about encryption headers on the Cisco ESA is true?

  • A. The optional Cisco Iron Port Encryption appliance provides extended encryption headers
  • B. They can be applied to outgoing messages only to force more secure message handling than is provided by the current encryption settings on the ESA
  • C. Content filters can be applied to add encryption headers to outgoing messages only
  • D. They can be configured to enable return receipt, expire messages and prevent the recipient form forwarding the message

Answer: D

NEW QUESTION 2

Which of the following correctly describes NVGRE functionality?

  • A. In NVGRE network the endpoints are not responsible for the NVGRE encapsulation removal
  • B. It allows to create physical layer-2 topologies on physical layer-3 network
  • C. It tunnels PPP frames inside an IP packet over a physical network
  • D. In NVGRE network VSID does not need to be unique
  • E. It tunnels Ethernet frames inside an IP packet over a virtual network
  • F. It allows to create physical layer-2 topologies on virtual layer-3 network
  • G. In NVGRE network VSID is used to identify tenant’s address space

Answer: G

NEW QUESTION 3

Which effect of the crypto key encrypt write rsa command on a router is true?

  • A. The device locks the encrypted key the saves it to the NVRAM
  • B. The device saves the unlocked encrypted key to the NVRAM
  • C. The device locks the encrypted key but the key is lost when the routers is reloaded
  • D. The device encrypts and locks key before authenticating it with an external CA server

Answer: B

NEW QUESTION 4

Which command is required for bonnet filter on Cisco ASA to function properly?

  • A. dynamic-filter inspect tcp /80
  • B. dynamic-filter whitelist
  • C. inspect botnet
  • D. inspect dns dynamic-filter-snoop

Answer: D

NEW QUESTION 5

Which host attributes can be assigned in compliance white list?

  • A. Verified unverified and complaint
  • B. Verified and unverified
  • C. Verified, unverified and evaluated
  • D. Complaint, noncompliant and not evaluated
  • E. Complaint and noncompliant

Answer: E

NEW QUESTION 6

Refer to the exhibit.
400-251 dumps exhibit
Which meaning of this error message on a Cisco ASA is true?

  • A. The route map redistribution is configured incorrectly.
  • B. The default route is undefined.
  • C. packed was denied and dropped by an ACL.
  • D. The host is connected directly to the firewall.

Answer: B

NEW QUESTION 7

All your remote users use AnyConnect VPN to connect into your corporate network, with an ASA providing the VPN service. Authentication is through ISE using RADIUS as the protocol. ISE uses Active Directory as
the Identity Source. You want to be able to assign different policies to users depending on their group membership in Active Directory. Which is one possible way of doing that?

  • A. Configure an authorization policy in ISE to send back a RADIUS class-25 attribute with the name of the ASA Tunnel Group (Connection Profile)
  • B. This is only possible when LDAP authorization is configured directly to Active Directory
  • C. Configure an authentication policy in ISE to send back a RADIUS class-25 attribute with the name of theASA Group Policy
  • D. Configure an authentication policy in ISE to send back a RADIUS class-25 attribute with the name of the ASA Tunel Group (Connection Profile)
  • E. Configure an authorization policy in ISE to send back a RADIUS class-25 attribute with the name of the ASA Group Policy

Answer: E

NEW QUESTION 8

Which statement correctly represents the ACI security principle of Object Model?

  • A. It is logical representation of an application and its interdependencies in the network fabric
  • B. It is policy placed at the intersection of a source and destination EPGs.
  • C. It is defined by the policy applied between EPGs for communication.
  • D. lt consists of one or more tenants having multiple contexts.
  • E. These are rules and policies used by an EPG to communicate with other EPGs.
  • F. It is collection of endpoints representing an application with in a context.

Answer: D

NEW QUESTION 9

Your environment has a large number of network devices that are configured to use AAA for authentication. Additionally, your security policy requires use of Two-Factor Authentication or Multi-Factor Authentication
for all device administrators, which you have integrated with ACS. To simplify device management, your organization has purchased Prime Infrastructure. What is the best way to get Prime Infrastructure to authenticate to at your network of devices?

  • A. Create a user on ISE with a complex password for Prime Infrastructure, along with an authorization policy that uses the ISE local identity store for that user.
  • B. Create a user on ISE with a complex password for Prime Infrastructure, along with an authentication policy that uses the ISE local identity store for that user.
  • C. Configure a local user on each of the network device along with priority to user the local username andpassword for Prime Infrastructure
  • D. Enable the AAA API on the network devices, generate an API token, and configure Prime Infrastructure to use that toke when authenticating to the network device
  • E. Enable Multi-Factor authentication on Prime Infrastructure

Answer: B

NEW QUESTION 10

Which statement is true about VRF-lite implementation in a service provider network?

  • A. It requires multiple links between CE and PE for each VPN connection to enable privacy
  • B. It uses source address to differentiate routes for different VPNs on the CE device
  • C. It can only support one VRF instance per CE device
  • D. It can have multiple VRF instances associated with a single interface on a CE device
  • E. It supports multiple VPNs at a CE device but their address spaces should not overlap
  • F. It enables the sharing of one CE device among multiple customers

Answer: F

NEW QUESTION 11

Which Cisco Firepower intrusion Event Impact level indicates the vulnerable to the attack, and requires the most immediate urgent.

  • A. Impact Level 3
  • B. Impact Level 4
  • C. Impact Level 2
  • D. Impact Level 0
  • E. Impact Level 1

Answer: E

NEW QUESTION 12

Which two options are benefits of the Cisco ASA Identity Firewall? (Choose two.)

  • A. It can identify threats quickly based on their URLs.
  • B. It can operate completely independently of their services.
  • C. It can apply security policies on an individual user or user-group basis.
  • D. It decouples security policies from the network topology.
  • E. It supports an AD server module to verify identity data.

Answer: CD

NEW QUESTION 13

Which statements is true regarding Dynamic ARP inspection (DAI)?

  • A. It requires that DHCP snooping be enabled to build valid binding database.
  • B. It drops invalid ARP responses and requests on the switch trusted ports
  • C. It forwards invalid ARP responses and requests on switch untrusted ports
  • D. It validates ARP requests and responses on trusted ports using IP-to-MAC address binding
  • E. It is only supported in DHCP environments to detect invalid ARP requests and responses
  • F. It requires to enable DHCP snooping to build untrusted database for dropping invalid ARP requests and responses

Answer: A

NEW QUESTION 14

Which three ESMTP extensions are supported by the Cisco ASA?Choose three

  • A. NOOP
  • B. PIPELINING
  • C. SAML
  • D. 8BITMIME
  • E. STARTTLS
  • F. ATRN

Answer: ACE

NEW QUESTION 15

Which statement is correct regarding password encryption and integrity on a Cisco IOS device?

  • A. With “enable secret” missing in the configuration the console session cannot get privilege access using console password due to missing encryption
  • B. The “enable password” is preferred over “enable secret” as it uses a stronger encryption algorithm
  • C. The “service password-encryption” global command encrypts all the passwords except the CHAP secret
  • D. The “username <name> secret <password>” command encrypts the password with SHA-256 hashing
  • E. The “enable secret” uses MD5 for the password hashing
  • F. The “service password-encryption” global command performs both encryption and hashing of all the passwords

Answer: E

NEW QUESTION 16

What are two characteristics of RPL, used in IoT environments?(Choose two)

  • A. It is an Exterior Gateway Protocol
  • B. It is a Interior Gateway Protocol
  • C. It is a hybrid protocol
  • D. It is link-state protocol
  • E. It is a distance-vector protocol

Answer: BE

NEW QUESTION 17

An sneaky employee using an Android phone on your network has disabled DHCP, enabled it's firewall, modified it's HTTP User-Agent header, to fool ISE into
profiling it as a Windows 10 machine connected to the wireless network. This user can now get authorization for unrestricted network access using his Active
Directory credentials, because your policy states that a Windows device using AD credentials should be able to get full network access. However, an Android
device should only get access to the Web Proxy. Which two steps can you take to avoid this sort of rogue behavior? (Choose two.)

  • A. Add an authorization policy before the Windows authorization policy that redirects a user with a static IP to a web portal for authentication
  • B. Perform CoA to push a restricted access when the machine is acquiring address using DHCP.
  • C. Chain an authorization policy to the Windows authorization policy that performs additional NMAP scans to verify the machine type before access is allowed
  • D. Create an authentication rule that allows only a session with a specific HTTP User-Agent header
  • E. Allow only certificate based authentication from Windows endpoints such as EAP-TLS or PEAP-TLS.If the endpoint uses MSCHAPv2 (EAP or PEAP), the useris given only restricted access
  • F. Modify the authorization policy to allow only Windows machines that have passed Machine Authentication to get full network access

Answer: EF

NEW QUESTION 18

Refer to the exhibit.
400-251 dumps exhibit
Which two effects of this configuration are true? (Choose two)

  • A. When a user logs in to privileged EXEC mode, the router will track all user activity
  • B. It configures the router’s local database as the backup authentication method for all TTY, console, and aux logins
  • C. If a user attempts to log in as a level 15 user, the local database will be used for authentication and TACACS+ will be used for authorization
  • D. Configuration commands on the router are authorized without checking the TACACS+ server
  • E. When a user attempts to authenticate on the device, the TACACS+ server will prompt the user to enterthe username stored in the router’s database
  • F. Requests to establish a reverse AUX connection to the router will be authorized against the TACACS+ server

Answer: BF

NEW QUESTION 19

Which statement is true regarding x.509 certificate?

  • A. The version number in the certificate is the OS version of CA
  • B. The Subject Distinguished Name in the certificate is of the entity who issued the certificate
  • C. The algorithm in the certificate is used by the issuer to sign the certificate
  • D. The serial number in the certificate is common across the certificates issued by the same CA
  • E. The algorithm in the certificate is used by the subject to encrypt the traffic
  • F. The Issuer Distinguished Name in the certificate is of the entity to which the certificate is issued

Answer: C

NEW QUESTION 20

Which option is a benefit of VRF Selection Using Policy-Based Routing for routing for packets to different VPNs?

  • A. It suppprts more than one VPN per interface
  • B. It allows bidirectional traffic flow between the service provider and the CEs
  • C. It automatically enables fast switching on all directly connected interfaces
  • D. It can use global routing tables to forward packets if the destination address matches the VRF configure on the interface
  • E. Every PE router in the service provider MPLS cloud can reach every customer network
  • F. It inreases the router performance when longer subnet masks are in use

Answer: D

NEW QUESTION 21

400-251 dumps exhibit
Refer to the exhibit. Which statement about router R1 is true?

  • A. Its NVRAM contains public and private crypto keys
  • B. RMON is configured
  • C. Its private-config is corrupt
  • D. Its startup configuration is missing
  • E. It running configuration is missing

Answer: A

Explanation:
https://www.cisco.com/c/en/us/support/docs/security-vpn/ipsec-negotiation-ike-protocols/50282-ios-caios. html

NEW QUESTION 22

Which two options are open-source SDN controllers? (choose two)

  • A. Opendaylight
  • B. Big Cloud Fabric
  • C. Application Policy Infrastructure Controller
  • D. OpenContrail
  • E. Virtual Application Networks SDN Controller

Answer: AD

NEW QUESTION 23

How would you best describe Jenkins?

  • A. An orchestration tool
  • B. Continuous integration and delivery application
  • C. Operations in a client/server model
  • D. Web-based repository hosting service
  • E. A REST client

Answer: B

NEW QUESTION 24

Which WEP configuration can be exploited by a weak IV attack ?

  • A. When the static WEP password has been stored without encryption.
  • B. When a per-packet WEP key is in use.
  • C. When a 64-bit key is in use.
  • D. When the static WEP password has been given away.
  • E. When a 40-bit key is in use.
  • F. When the same WEP key is used to create every packet.

Answer: E

NEW QUESTION 25

Which statement correctly describes AES encryption algorithm?

  • A. It works on substitution and permutation principle
  • B. It uses three encryption keys of length 168, 112 and 56 bits
  • C. Reapplying same encryption key three times makes it less vulnerable then 3DES
  • D. It only provides data integrity
  • E. Theoretically 3DES is more secure then AES

Answer: A

NEW QUESTION 26

Which protocol does ISE use to secure connection through the Cisco IronPort Tunnel infrastructure?

  • A. SSH
  • B. IKEv1
  • C. IKEv2
  • D. SNMP
  • E. TLS

Answer: A

NEW QUESTION 27

Refer to the exhibit.
R9
crypto ikev2 keyring ccier10 peer r10
address 20.1.4.11
pre-shared-key local ccier10 pre-shared-key remote ccier10
!c
rypto ikev2 profile ccier10
match identity remote address 20.1.4.10 255.255.255.255 authentication local pre-share
authentication remote pre-share keyring local ccier10
!c
rypto ipsec profile ccier10 set ikev2-profile ccier10
!i
nterface Loopback1
ip address 192.168.9.9 255.255.255.0
!i
nterface Tunnel34
ip address 172.16.2.9 255.255.255.0
tunnel source GigabitEthernet1 tunnel destination 20.1.4.10
tunnel protection ipsec profile ccier10
!i
nterface GigabitEthernet1
ip address 20.1.3.9 255.255.255.0 negotiation auto
!r
outer eigrp 34
network 172.16.2.0 0.0.0.255
network 192.168.9.0
!r
outer bgp 3
bgp log-neighbor-changes
network 20.1.3.0 mask 255.255.255.0
neighbour 20.1.3.12 remote-as 345 netighbor 20.1.3.12 password cisco
R9 is running FLEXVPN with peer R10 at 20.1.4.10 using a pre-shared key "ccier10".
The IPSec tunnel is sourced from 172.16.2.0/24 network and is included in EIGRP routing process.
BGP nexthop is AS345 with address 20.1.3.12. It has been reported that FLEXVPN is down. What could be the issue?

  • A. Incorrect IPSec profile configuration
  • B. Incorrect tunnel network address in EIGRP routing process
  • C. Incorrect tunnel source for the tunnel interface
  • D. Incorrect keyring configuration
  • E. Incorrect IKEv2 profile configuration
  • F. Incorrect local network address in BGP routing process

Answer: D

NEW QUESTION 28
......

100% Valid and Newest Version 400-251 Questions & Answers shared by Certifytools, Get Full Dumps HERE: https://www.certifytools.com/400-251-exam.html (New 448 Q&As)