351-018 Exam Details

  • Exam Code
    :351-018
  • Exam Name
    :CCIE Security written
  • Certification
    :Cisco Certifications
  • Vendor
    :Cisco
  • Total Questions
    :420 Q&As
  • Last Updated
    :Dec 09, 2021

Cisco 351-018 Online Questions & Answers

  • Question 331:

    Which protocol can be used to encrypt traffic sent over a GRE tunnel?

    A. SSL
    B. SSH
    C. IPsec
    D. DH
    E. TLS

  • Question 332:

    Which two security measures are provided when you configure 802.1X on switchports that connect to corporate-controlled wireless access points? (Choose two.)

    A. It prevents rogue APs from being wired into the network.
    B. It provides encryption capability of data traffic between APs and controllers.
    C. It prevents rogue clients from accessing the wired network.
    D. It ensures that 802.1x requirements for wired PCs can no longer be bypassed by disconnecting the AP and connecting a PC in its place.

  • Question 333:

    Refer to the exhibit.

    Which statement correctly describes the configuration?

    A. The configuration is the super view configuration of role-based access control.
    B. The configuration would not work unless the AAA server is configured for authentication and authorization.
    C. The exec commands in the configuration will be excluded from the test view.
    D. The configuration is the CLI configuration of role-based access control.

  • Question 334:

    DRAG DROP

    Select and Place:

  • Question 335:

    Which two EAP methods may be susceptible to offline dictionary attacks? (Choose two.)

    A. EAP-MD5
    B. LEAP
    C. PEAP with MS-CHAPv2
    D. EAP-FAST

  • Question 336:

    Refer to the exhibit.

    Which statement about this Cisco Catalyst switch 802.1X configuration is true?

    A. If an IP phone behind the switch port has an 802.1X supplicant, MAC address bypass will still be used to authenticate the IP Phone.
    B. If an IP phone behind the switch port has an 802.1X supplicant, 802.1X authentication will be used to authenticate the IP phone.
    C. The authentication host-mode multi-domain command enables the PC connected behind the IP phone to bypass 802.1X authentication.
    D. Using the authentication host-mode multi-domain command will allow up to eight PCs connected behind the IP phone via a hub to be individually authentication using 802.1X.

  • Question 337:

    What is the purpose of the OCSP protocol?

    A. checks the revocation status of a digital certificate
    B. submits a certificate signing request
    C. verifies a signature of a digital certificate
    D. protects a digital certificate with its private key

  • Question 338:

    Which VTP mode allows the Cisco Catalyst switch administrator to make changes to the VLAN configuration that only affect the local switch and are not propagated to other switches in the VTP domain?

    A. transparent
    B. server
    C. client
    D. local
    E. pass-through

  • Question 339:

    Which four types of VPN natively provide encryption of user traffic? (Choose four.)

    A. MPLS
    B. IPsec
    C. L2TPv3
    D. SSL
    E. VPLS
    F. AToM
    G. GETVPN
    H. Microsoft PPTP

  • Question 340:

    Which common FTP client command transmits a direct, byte-for-byte copy of a file?

    A. ascii
    B. binary
    C. hash
    D. quote
    E. glob

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cisco exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 351-018 exam preparations and Cisco certification application, do not hesitate to visit our Vcedump.com to find your solutions here.