350-018 Exam Details

  • Exam Code
    :350-018
  • Exam Name
    :CCIE Security written
  • Certification
    :Cisco Certifications
  • Vendor
    :Cisco
  • Total Questions
    :872 Q&As
  • Last Updated
    :Dec 11, 2021

Cisco 350-018 Online Questions & Answers

  • Question 681:

    CCMP(CCM mode Protocol) is based on which algorithm?

    A. AES
    B. RCS
    C. 3DES
    D. IDEA
    E. Blowfish

  • Question 682:

    Which series of steps illustrates the correct flow for incident management?

    A. Identify, log, categorize, prioritize, initial diagnosis, escalate, investigate and diagnose, resolve and recover, close
    B. Categorize, log, identify, prioritize, initial diagnosis, escalate, investigate and diagnose, resolve and recover, close
    C. Identify, log, categorize, prioritize, initial diagnosis, investigate and diagnose, escalate, resolve and recover, close
    D. Identify, categorize, prioritize, log, initial diagnosis, escalate, investigate and diagnose, resolve and recover, close

  • Question 683:

    Which statement about layer-2 VLAN is true?

    A. VLAN cannot be routed.
    B. VLANs 1006 through 4094 are not propagated by VTP version 3.
    C. VLAN1 is a Cisco default VLAN that can be deleted.
    D. The extended-range VLANs cannot be configured in global configuration mode.

  • Question 684:

    Refer to the exhibit.

    The client is protected by a firewall. An IPv6 SMTP connection from the client to the server on TCP port 25 will be subject to which action?

    A. pass action by the HTTP_CMAP
    B. inspection action by the TCP_CMAP
    C. inspection action by the SMTP_CMAP
    D. drop action by the default class
    E. pass action by the HTTP_CMAP

  • Question 685:

    Which two OSPF network types support the concept of a designated router? (Choose two.)

    A. broadcast
    B. NBMA
    C. point-to-multipoint
    D. point-to-multipoint nonbroadcast
    E. loopback

  • Question 686:

    Refer to the exhibit . Wich effect of this configuration is true ?

    A. The MSS of TCP SYN packets is set to 1452 bytes and the IP MTU of the interface is set to 1942 bytes
    B. The maximum size of TCP SYN+ACK packets passing the transient host is set to 1452 bytes and the IP MTU of the interface is set to 1492 bytes
    C. The PMTUD values sets itself to 1452 bytes when the interface MTU is set to 1492 bytes
    D. SYN packets carries 1452 bytes in the payload when the Ethernet MTU of the interface is to 1492 bytes
    E. The maximum size of TCP SYN+ACK packets passing the router is set to 452 bytes and the IP MTU of the interface is set to 1492 bytes

  • Question 687:

    Which ICMP message type code indicates fragmentation needed but DF bit set?

    A. Type 3, Code 0
    B. Type 4, Code 2
    C. Type 3, Code 4
    D. Type 8, Code 0

  • Question 688:

    What technology can you implement on your network to allow Independent applications to work with IPv6-capable applications?

    A. DS-Lite
    B. NAT-PT
    C. ISATAP
    D. NAT 6to4
    E. NAT64

  • Question 689:

    Which type of VPN is based on the concept of trusted group members using the GDOI key management protocol?

    A. DMVPN
    B. SSLVPN
    C. GETVPN
    D. EzVPN
    E. MPLS VPN
    F. FlexVPN

  • Question 690:

    Which three statements about OCSP are correct? (Choose three.)

    A. OCSP is defined in RFC2560.
    B. OCSP uses only http as a transport.
    C. OCSP responders can use RSA and DSA signatures to validate that responses are from trusted entities.
    D. A response indicator may be good, revoked, or unknown.
    E. OCSP is an updated version SCEP.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cisco exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 350-018 exam preparations and Cisco certification application, do not hesitate to visit our Vcedump.com to find your solutions here.