210-260 Exam Details

  • Exam Code
    :210-260
  • Exam Name
    :Implementing Cisco Network Security
  • Certification
    :Cisco Certifications
  • Vendor
    :Cisco
  • Total Questions
    :527 Q&As
  • Last Updated
    :Dec 12, 2021

Cisco 210-260 Online Questions & Answers

  • Question 281:

    What action must you take on the ISE to blacklist a wired device?

    A. Revoke the device's certificate so it is unable to authenticate to the network
    B. Issue a CoA request for the device's MAC address to each access switch in the network
    C. Locate the switch through which the device is connected and push an ACL restricting all access by the device
    D. Add the device's MAC address to a list of blacklisted devices

  • Question 282:

    Which option is a characteristic of the RADIUS protocol?

    A. uses TCP
    B. offers multiprotocol support
    C. combines authentication and authorization in one process
    D. supports bi-directional challenge

  • Question 283:

    What are two well-known security terms? (Choose Two)

    A. Phishing.
    B. BPDU guard
    C. LACP
    D. ransomeware
    E. hair-pinning

  • Question 284:

    Which type of layer 2 attack enables the attacker to intercept traffic that is intended for one specific recipient?

    A. BPDU attack
    B. DHCP Starvation
    C. CAM table overflow
    D. MAC address spoofing

  • Question 285:

    Which IPS mode is less secure than other options but allows optimal network throughput?

    A. promiscuous mode
    B. inline mode
    C. inline-bypass mode
    D. transparent mode.

  • Question 286:

    Refer to the exhibit. Which statement about the given configuration is true?

    A. The timeout command causes the device to move to the next server after 20 seconds of TACACS inactivity.
    B. The single-connection command causes the device to process one TACACS request and then move to the next server.
    C. The single-connection command causes the device to establish one connection for all TACACS transactions.
    D. The router communicates with the NAS on the default port, TCP 1645

  • Question 287:

    What can cause the the state table of a stateful firewall to update? (choose two)

    A. when a connection is created
    B. When a connection's timer has expired within state table
    C. when packet is evaluated against the outbound access list and is denied
    D. when outbound packets forwarded to outbound interface
    E. when rate-limiting is applied

  • Question 288:

    How does a device on a network using ISE receive its digital certificate during the new-device registration process?

    A. ISE acts as a SCEP proxy to enable the device to receive a certificate from a central CA server
    B. The device request a new certificate directly from a central CA
    C. ISE issues a pre-defined certificate from a local database
    D. ISE issues a certificate from its internal CA server.

  • Question 289:

    What is a possible reason for the error message? Router(config)#aaa server?% Unrecognized command

    A. The command syntax requires a space after the word "server"
    B. The command is invalid on the target device
    C. The router is already running the latest operating system
    D. The router is a new device on which the aaa new-model command must be applied before continuing

  • Question 290:

    A user on your network inadvertently activates a botnet program that was received as an email attachment Which type of mechanism does Cisco Firepower use to detect and block only the botnet attack?

    A. network-based access control rule
    B. botnet traffic filter
    C. reputation-based
    D. user-based access control rule

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cisco exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 210-260 exam preparations and Cisco certification application, do not hesitate to visit our Vcedump.com to find your solutions here.