350-018 Exam Details

  • Exam Code
    :350-018
  • Exam Name
    :CCIE Security written
  • Certification
    :Cisco Certifications
  • Vendor
    :Cisco
  • Total Questions
    :872 Q&As
  • Last Updated
    :Dec 11, 2021

Cisco 350-018 Online Questions & Answers

  • Question 621:

    Which option shows the correct sequence of the DHCP packets that are involved in IP address assignment between the DHCP client and the server?

    A. REQUEST, OFFER, ACK
    B. DISCOVER, OFFER, REQUEST, ACK
    C. REQUEST, ASSIGN, ACK
    D. DISCOVER, ASSIGN, ACK
    E. REQUEST, DISCOVER, OFFER, ACK

  • Question 622:

    Which two options are differences between automation and orchestration? (choose two)

    A. Orchestration is focused on an end to-end process or workflow
    B. Automation is a f workflow composed of tasks. And orchestration is a technical task
    C. Automation is focused on automating a single or multiple tasks
    D. Automation is to be used to replace human intervention
    E. Orchestration is focused on multiple technologies to be integrated together

  • Question 623:

    Which two items are required for LDAP authenticated bind operations? (Choose two.)

    A. Root DN
    B. Password
    C. Username
    D. SSO
    E. UID

  • Question 624:

    Which two identifiers are used by a Cisco Easy VPN Server to reference the correct group policy information for connecting a Cisco Easy VPN Client? (Choose two.)

    A. IKE ID_KEY_ID
    B. OU field in a certificate that is presented by a client
    C. XAUTH username
    D. hash of the OTP that is sent during XAUTH challenge/response
    E. IKE ID_IPV4_ADDR

  • Question 625:

    Which of the following statements are true regarding hashing?

    A. Changing 1 bit of the input SHA-1 changes 1 bit of the output.
    B. SHA-1 is stronger than MD5 because t can be used with a key to prevent modification.
    C. MD5 produces a 160-bit result.
    D. MD5 takes more CPU cycles to compute than SHA-1.
    E. SHA-256 is an extension to SHA-1 with a longer output.

  • Question 626:

    What is the purpose of aaa server radius dynamic-author command?

    A. Enables the device to dynamically receive updates from a policy server
    B. Enables the switch to automatically authorize the connecting device if all the configured RADIUS servers are unavailable
    C. Impairs the ability to configure RADIUS local AAA
    D. This command disables dynamic authorization local server configuration mode.

  • Question 627:

    Refer to the exhibit.

    Which statement best describes the problem?

    A. Context vpn1 is not inservice.
    B. There is no gateway that is configured under context vpn1.
    C. The config has not been properly updated for context vpn1.
    D. The gateway that is configured under context vpn1 is not inservice.

  • Question 628:

    Comparing and contrasting IKEv1 and IKEv2, which three statements are true? (Choose three.)

    A. IKEv2 adds EAP as a method of authentication for clients; IKEv1 does not use EAP.
    B. IKEv1 and IKEv2 endpoints indicate support for NAT-T via the vendor_ID payload.
    C. IKEv2 and IKEv1 always ensure protection of the identities of the peers during the negotiation process.
    D. IKEv2 provides user authentication via the IKE_AUTH exchange; IKEv1 uses the XAUTH exchange.
    E. IKEv1 and IKEv2 both use INITIAL_CONTACT to synchronize SAs.
    F. IKEv1 supports config mode via the SET/ACK and REQUEST/RESPONSE methods; IKEv2 supports only REQUEST/RESPONSE.

  • Question 629:

    Which statement is true about SYN cookies?

    A. The state is kept on the server machine TCP stack.
    B. A system has to check every incoming ACK against state tables.
    C. SYN cookies do not help to protect against SYM flood attacks.
    D. No state is kept on the server machine state but is embedded in the initial sequence number.

  • Question 630:

    Which of the following describes the DHCP "starvation" attack?

    A. Exhaust the address space available on the DHCP servers so that an attacker can inject their own DHCP server for malicious reasons.
    B. Saturate the network with DHCP requests to prevent other network services from working.
    C. Inject a DHCP server on the network for the purpose of overflowing DNS servers with bogus learned host names.
    D. Send DHCP response packets for the purpose of overloading CAM tables.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cisco exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 350-018 exam preparations and Cisco certification application, do not hesitate to visit our Vcedump.com to find your solutions here.