350-018 Exam Details

  • Exam Code
    :350-018
  • Exam Name
    :CCIE Security written
  • Certification
    :Cisco Certifications
  • Vendor
    :Cisco
  • Total Questions
    :872 Q&As
  • Last Updated
    :Dec 11, 2021

Cisco 350-018 Online Questions & Answers

  • Question 111:

    All of these are available from Cisco IPS Device Manager (Cisco IDM) except which one?

    A. B.Sensor Information
    B. C.Interface Status
    C. Global Correlation Reports
    D. CPU. Memory. and Load

  • Question 112:

    Refer to the exhibit.

    To configure the Cisco ASA, what should you enter in the Name field, under the Group Authentication option for the IPSec VPN client?

    A. group policy name
    B. crypto map name
    C. isakmp policy name
    D. crypto ipsec transform-set name
    E. tunnel group name

  • Question 113:

    Which three statements about triple DES are true? (Choose three.)

    A. For 3DES, ANSI X9.52 describes three options for the selection of the keys in a bundle, where all keys are independent.
    B. A 3DES key bundle is 192 bits long.
    C. A 3DES keyspace is168 bits.
    D. CBC, 64-bit CFB, OFB, and CTR are modes of 3DES.
    E. 3DES involves encrypting a 64-bit block of plaintext with the 3 keys of the key bundle.

  • Question 114:

    A firewall rule that filters on the protocol field of an IP packet is acting on which layer of the OSI reference model?

    A. network layer
    B. application layer
    C. transport layer
    D. session layer

  • Question 115:

    Which three RADIUS protocol statements are true? (Choose three.)

    A. RADIUS protocol runs over TCP 1645 and 1646.
    B. Network Access Server operates as a server for RADIUS.
    C. RADIUS packet types for authentication include Access-Request, Access-Challenge, Access-Accept, and Access-Reject.
    D. RADIUS protocol runs over UDP 1812 and 1813.
    E. RADIUS packet types for authentication include Access-Request, Access-Challenge, Access-Permit, and Access-Denied.
    F. RADIUS supports PPP, PAP, and CHAP as authentication methods.

  • Question 116:

    Which two statements about the DH group are true? (Choose two.)

    A. The DH group is used to provide data authentication.
    B. The DH group is negotiated in IPsec phase-1.
    C. The DH group is used to provide data confidentiality.
    D. The DH group is used to establish a shared key over an unsecured medium.
    E. The DH group is negotiated in IPsec phase-2.

  • Question 117:

    Which three LSA types are used by OSPFv3? (Choose three.)

    A. Link LSA
    B. Intra-Area Prefix LSA
    C. Interarea-prefix LSA for ASBRs
    D. Autonomous system external LSA
    E. Internetwork LSA

  • Question 118:

    Which record statement is part of the NetFlow monitor configuration that is used to collect MPLS traffic with an IPv6 payload?

    A. record mpls IPv6-fields labels 3
    B. record mpls IPv4-fields labels 3
    C. record mpls labels 3
    D. record mpls ipv6-fields labels

  • Question 119:

    When a host initiates a TCP session,what is the numerical range into which the initial sequence number must fall ?

    A. 1 to 4,294,967,295
    B. 0 to 4,294,967,295
    C. 1 to 65535
    D. 0 to 65535
    E. 0 to 1024
    F. 1 to 1024

  • Question 120:

    Select and Place:

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cisco exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 350-018 exam preparations and Cisco certification application, do not hesitate to visit our Vcedump.com to find your solutions here.