350-018 Exam Details

  • Exam Code
    :350-018
  • Exam Name
    :CCIE Security written
  • Certification
    :Cisco Certifications
  • Vendor
    :Cisco
  • Total Questions
    :872 Q&As
  • Last Updated
    :Dec 11, 2021

Cisco 350-018 Online Questions & Answers

  • Question 601:

    In Cisco IOS firewall the HTTP inspection engine has the ability to protect against which of the following?

    A. Tunneling over port 443.
    B. Tunneling over port 80.
    C. HTTP file transfers authorized by the configured security policy.
    D. Authorized request methods.

  • Question 602:

    DNSSEC was designed to overcome which security limitation of DNS?

    A. DNS man-in-the-middle attacks
    B. DNS flood attacks
    C. DNS fragmentation attacks
    D. DNS hash attacks
    E. DNS replay attacks
    F. DNS violation attacks

  • Question 603:

    Which pair of ICMP messages is used in an inverse mapping attack?

    A. Echo-Echo Request
    B. Route Solicitation- Time Exceeded
    C. Echo-Time Exceeded
    D. Echo Reply-Host Unreachable
    E. Echo-Host Unreachable

  • Question 604:

    Which three options are methods of load-balancing data in an ASA cluster environment? (Choose three.)

    A. ECMP
    B. floating static routes
    C. PBR
    D. HSRP
    E. distance-vector routing
    F. spanned EtherChannel

  • Question 605:

    For which two reasons BVI is required in the Transparent Cisco IOS Firewall? (Choose two)

    A. BVI is required for the inspection of IP traffic.
    B. The firewall can perform routing on bridged interfaces.
    C. BVI is required if routing is disabled on the firewall.
    D. BVI is required if more than two interfaces are in a bridge group.
    E. BVI is required for the inspection of non-IP traffic.
    F. BVI can manage the device without having an interface that is configured for routing.

  • Question 606:

    Refer to the exhibit.

    Which option describes the behavior of this configuration?

    A. Traffic from the 30.30.0.0/16 network to the 10.10.0.0/32 network will be translated.
    B. Traffic from the 30.30.0.0/32 network to the 10.10.0.0/16 network will not be translated.
    C. Traffic from the 10.10.0.0/16 network to the 30.30.30.0/24 network will not be translated.
    D. Traffic from the 10.10.0.0/32 network to the 30.30.30.0/16 network will be translated.

  • Question 607:

    Which two router configurations block packets with the type 0 routing header on the interface?(Choose two) A. Option A

    B. Option B
    C. Option C
    D. Option D
    E. Option E

  • Question 608:

    Refer to the exhibit.What is the effect of the given command sequence?

    A. The server will accept secure HTTP connections from clients with signed security certicates
    B. The client profile will match the authorization profile defined in the AAA server
    C. The HTTP server and client will negotiate the cipher suite encryption parameters
    D. The clients are added to the cipher suite*s profile
    E. The server will accept secure HTTP connections from clients defined in the AAA server

  • Question 609:

    What are the three default account duration settings supported by the Cisco ISE Guest services? (Choose three)

    A. DefaultStartEnd
    B. DefaultEightHours
    C. DefaultFirstLoginEight
    D. DefaultUnlimited
    E. DefaultFirstLogin
    F. DefaultFiveHours

  • Question 610:

    What are the three scanning engines that the cisco IronPort dynamic vectoring and Streaming engine can use to protect against malware? (Choose three)

    A. Sophos
    B. McAfee
    C. Symantec
    D. F-Secure
    E. Webroot
    F. TrendMicro

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cisco exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 350-018 exam preparations and Cisco certification application, do not hesitate to visit our Vcedump.com to find your solutions here.