351-018 Exam Details

  • Exam Code
    :351-018
  • Exam Name
    :CCIE Security written
  • Certification
    :Cisco Certifications
  • Vendor
    :Cisco
  • Total Questions
    :420 Q&As
  • Last Updated
    :Dec 09, 2021

Cisco 351-018 Online Questions & Answers

  • Question 191:

    DHCPv6 is used in which IPv6 address autoconfiguration method?

    A. stateful autoconfiguration
    B. stateless autoconfiguration
    C. EUI-64 address generation
    D. cryptographically generated addresses

  • Question 192:

    Which IPv6 tunnel type is a standard that is defined in RFC 4214?

    A. ISATAP
    B. 6to4
    C. GREv6
    D. manually configured

  • Question 193:

    Why do firewalls need to specially treat an active mode FTP session?

    A. The data channel is originating from a server side.
    B. The FTP client opens too many concurrent data connections.
    C. The FTP server sends chunks of data that are too big.
    D. The data channel is using a 7-bit transfer mode.

  • Question 194:

    Refer to the exhibit.

    What is the reason for the failure of the DMVPN session between R1 and R2?

    A. tunnel mode mismatch
    B. IPsec phase-1 configuration is missing peer address on R2
    C. IPsec phase-1 policy mismatch
    D. IPsec phase-2 policy mismatch
    E. incorrect tunnel source interface on R1

  • Question 195:

    DRAG DROP

    Select and Place:

  • Question 196:

    What term describes an access point which is detected by your wireless network, but is not a

    A. rogue
    B. unclassified
    C. interferer
    D. malicious

  • Question 197:

    Refer to the exhibit.

    What will be the default action?

    A. HTTP traffic to the Facebook, Youtube, and Twitter websites will be dropped.
    B. HTTP traffic to the Facebook and Youtube websites will be dropped.
    C. HTTP traffic to the Youtube and Twitter websites will be dropped.
    D. HTTP traffic to the Facebook and Twitter websites will be dropped.

  • Question 198:

    What is the size of a point-to-point GRE header, and what is the protocol number at the IP layer?

    A. 8 bytes, and protocol number 74
    B. 4 bytes, and protocol number 47
    C. 2 bytes, and protocol number 71
    D. 24 bytes, and protocol number 1
    E. 8 bytes, and protocol number 47

  • Question 199:

    Which three statements are true regarding RFC 5176 (Change of Authorization)? (Choose three.)

    A. It defines a mechanism to allow a RADIUS server to initiate a communication inbound to a NAD.
    B. It defines a wide variety of authorization actions, including "reauthenticate."
    C. It defines the format for a Change of Authorization packet.
    D. It defines a DM.
    E. It specifies that TCP port 3799 be used for transport of Change of Authorization packets.

  • Question 200:

    Which two options correctly describe Remote Triggered Black Hole Filtering (RFC 5635)? (Choose two.)

    A. RTBH destination based filtering can drop traffic destined to a host based on triggered entries in the FIB.
    B. RTBH source based filtering will drop traffic from a source destined to a host based on triggered entries in the RIB
    C. Loose uRPF must be used in conjunction with RTBH destination based filtering
    D. Strict uRPF must be used in conjunction with RTBH source based filtering
    E. RTBH uses a discard route on the edge devices of the network and a route server to send triggered route updates
    F. When setting the BGP community attribute in a route-map for RTBH use the no-export community unless BGP confederations are used then use local-as to advertise to sub-as confederations

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cisco exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 351-018 exam preparations and Cisco certification application, do not hesitate to visit our Vcedump.com to find your solutions here.