显示标签为“351-018”的博文。显示所有博文
显示标签为“351-018”的博文。显示所有博文

2013年12月1日星期日

Le plus récent matériel de formation examen Cisco 351-018 de certification

Dans cette société de plus en plus intense, nous vous proposons à choisir une façon de se former plus efficace : moins de temps et d'argent dépensé. Pass4Test peut vous offrir une bonne solution avec une plus grande space à développer.

Beaucoup de travailleurs dans l'Industrie IT peut obenir un meilleur travail et améliorer son niveau de vie à travers le Certificat Cisco 351-018. Mais la majorité des candidats dépensent beaucoup de temps et d'argent pour préparer le test, ça ne coûte pas dans cette société que le temps est tellement précieux. Pass4Test peut vous aider à économiser le temps et l'effort pendant le cours de la préparation du test Cisco 351-018. Choisir le produit de Pass4Test particulier pour le test Certification Cisco 351-018 vous permet à réussir 100% le test. Votre argent sera tout rendu si malheureusement vous ne passez pas le test.

Pass4Test est un fournisseur important de résume du test Certification IT dans tous les fournissurs. Les experts de Pass4Test travaillent sans arrêt juste pour augmenter la qualité de l'outil formation et vous aider à économiser le temps et l'argent. D'ailleur, le servie en ligne après vendre est toujours disponible pour vous.

Code d'Examen: 351-018
Nom d'Examen: Cisco (CCIE Security written)
Questions et réponses: 560 Q&As

Si vous travaillez quand même très dur et dépensez beaucoup de temps pour préparer le test Cisco 351-018, mais ne se savez pas du tout c'est où le raccourci pour passer le test certification, Pass4Test peut vous donner une solution efficace. Vous vous sentirez magiquement jouer un effet multiplicateur.

351-018 Démo gratuit à télécharger: http://www.pass4test.fr/351-018.html

NO.1 Which one of the following is not a valid RADIUS packet type.?
A. access-reject
B. access-response
C. access-challenge
D. access-reply
E. access-accept
Answer: B

Cisco examen   351-018 examen   351-018 examen   351-018   351-018

NO.2 Which two of these commands are required to implement a Cisco Catalyst 6500 Series Firewall
Services Module (FWSM) in a Catalyst 6500 running Cisco IOS? (Choose two.)
A. firewall multiple-vlan-interfaces
B. firewall module vlan-group
C. module secure-traffic
D. firewall vlan-group <vlan-x>
E. firewall module secure-traffic
Answer: BD

Cisco   certification 351-018   351-018   351-018   351-018

NO.3 Which two of these are valid TACACS+ Accounting packets? (Choose two.)
A. REQUEST
B. REPLY
C. RESPONSE
D. CONTINUE
E. START
Answer: AC

Cisco examen   certification 351-018   351-018 examen

NO.4 Which of these statements best describes the advantage of using Cisco Secure Desktop, which is part
of the Cisco ASA VPN solution?
A. Cisco Secure Desktop creates a separate computing environment that is deleted when you finish,
ensuring that no confidential data is left on the shared or public computer.
B. Cisco Secure Desktop is used to protect access to your registry and system files when browsing to
SSL VPN protected pages.
C. Cisco Secure Desktop ensures that an SSL protected password cannot be exploited by a man-
in-the-middle attack using a spoofed certificate
D. Cisco Secure Desktop hardens the operating system of the machines you are using at the time it is
launched.
Answer: A

Cisco examen   351-018 examen   351-018   351-018

NO.5 For a router to obtain a certificate from a CA, what is the first step of the certificate enrollment process?
A. The router generates a certificate request and forwards it to the CA.
B. The router generates an RSA key pair.
C. The router sends its public key to the CA.
D. The CA sends its public key to the router.
E. The CA verifies the identity of the router.
F. The CA generates a certificate request and forwards it to the router.
Answer: B

Cisco   351-018   certification 351-018   351-018   351-018

NO.6 How do TCP SYN attacks take advantage of TCP to prevent new connections from being established
to a host under attack?
A. sending multiple FIN segments, forcing TCP connection release
B. filling up a host listen queue by failing to ACK partially opened TCP connections
C. taking advantage of the host transmit backoff algorithm by sending jam signals to the host
D. incrementing the ISN of each segment by a random number, causing constant TCP retransmissions
E. sending TCP RST segments in response to connection SYN+ACK segments, forcing SYN
retransmissions
Answer: B

Cisco examen   351-018 examen   351-018 examen   351-018 examen   351-018   351-018

NO.7 When a failover takes place on an adaptive security appliance configured for failover, all active
connections are dropped and clients must reestablish their connections, unless the adaptive security
appliance is configured in which two of the following ways? (Choose two.)
A. active/stand by failover
B. active/active failover
C. active/active failover and a state failover link has been configured
D. active/standby failover and a state failover link has been configured
E. to use a serial cable as the failover link
F. LAN-based failover
Answer: CD

certification Cisco   351-018 examen   certification 351-018   certification 351-018   351-018 examen

NO.8 How does using DHCP Option 82 on a Cisco Wireless LAN Controller make a network more secure?
A. by preventing rogue DHCP servers from returning unauthorized addresses
B. by ensuring that DHCP addresses are parity-checked before being issued
C. by ensuring that clients receive proper routing information as part of their DHCP responses
D. by preventing DHCP address requests from untrusted relay agents
E. by adding fully qualified domain information that the client can use for SSL authentication
Answer: D

Cisco   351-018   351-018   351-018 examen   351-018

NO.9 In the example shown, Host A has attempted a DCOM attack using Metasploit from Host A to Host
Which three statements best describe how event logs and IPS alerts can be used in conjunction with each
other to determine if the attack was successful? (Choose three.)
A. Cisco Security MARS will collect the syslog and the IPS alerts based on time.
B. The IPS event will suggest that an attack may have occurred because a signature was triggered.
C. IPS and Cisco ASA adaptive security appliance will use the Unified Threat Management protocol to
determine that both devices saw the attack
D. Cisco ASA adaptive security appliance will see the attack in both directions and will be able to
determine if an attack was successful.
E. The syslog event will indicate that an attack is likely because a TCP SYN and an ACK followed the
attempted attack.
Answer: ABE

Cisco   certification 351-018   351-018 examen

NO.10 When using Cisco Easy VPN Remote (hardware client deployment) in the client-mode setup, all of the
following statements are correct except which one?
A. Perform split tunneling on the Cisco Easy VPN Remote device.
B. Initiate a connection from a network behind the Cisco Easy VPN Server to the network behind the
Cisco Easy VPN Remote client.
C. Set the Cisco Easy VPN Remote to allow an administrator or user to manually initiate a connection.
D. Set the Cisco Easy VPN Remote to automatically connect to the Cisco Easy VPN Server.
Answer: B

Cisco examen   351-018   351-018 examen

NO.11 Refer to the exhibit.
Which of these statements is correct for the Fidelity Rating and Base RR values?
A. Both the Fidelity Rating and Base RR values are computed from the Severity Factor value.
B. The Fidelity Rating value is computed from the Base RR value.
C. The Severity Factor value is computed from the Fidelity Rating and Base RR values.
D. The Fidelity Rating value is computed from the Base RR and Severity Factor values.
E. The Base RR value is computed from the Fidelity Rating and Severity Factor values.
Answer: E

Cisco examen   certification 351-018   certification 351-018

NO.12 Refer to the exhibit.
Which three of the following statements are correct? (Choose three.)
A. The exhibit shows an example of a NAC Framework network.
B. The exhibit shows an example of a NAC Appliance network.
C. The network utilizes in-band admission control.
D. The network utilizes out-of-band admission control.
E. Cisco NAC Appliance Agent is used to verify end-user PC compliance with the security policy
F. Cisco Trust Agent is used to verify end-user PC compliance with the security policy.
Answer: BDE

certification Cisco   351-018   certification 351-018   certification 351-018   351-018 examen

NO.13 A DNS Client sends DNS messages to obtain information about the requested domain name space.
The information is known as which of these?
A. Resource Record
B. Resolver
C. Branch
D. Authoritative Client
E. Recursive Client
Answer: A

certification Cisco   certification 351-018   351-018   certification 351-018

NO.14 Referring to the partial debug output shown in the exhibit, which of these values is contained inside the
brackets [4] in line 1?
A. RADIUS identifier field value
B. RADIUS attribute type value
C. RADIUS VSA number
D. RADIUS VSA length
E. vendor ID
Answer: B

Cisco   351-018 examen   certification 351-018   351-018 examen   351-018 examen

NO.15 To provide a separation of duties within Cisco Security Manager, which mode would the Cisco Security
Manager administrator use?
A. Activity mode
B. Change Control mode
C. Workflow mode
D. Task-Based mode
E. Task Isolation mode
Answer: C

Cisco examen   certification 351-018   351-018 examen   351-018

NO.16 After the client opens the command channel (port 21) to the FTP server and requests passive mode,
what will be the next step?
A. The FTP server sends back an ACK to the client.
B. The FTP server allocates a port to use for the data channel and transmits that port number to the client.
C. The FTP server opens the data channel to the client using the port number indicated by the client.
D. The FTP client opens the data channel to the FTP server on port 20.
E. The FTP client opens the data channel to the FTP server on port 21.
Answer: B

Cisco examen   351-018   certification 351-018   certification 351-018

NO.17 ASDM on the Cisco ASA adaptive security appliance platform is executed as which of the following?
A. an ActiveX application or a JavaScript application
B. a JavaScript application and a PHP application
C. a fully compiled .Net Framework application
D. a fully operational Visual Basic application
E. a Java applet or a standalone application using the Java Runtime Environment
Answer: E

certification Cisco   351-018 examen   351-018

NO.18 What is the net effect of using ICMP type 4 messages to attack RFC 1122-compliant hosts?
A. Hosts will perform a soft TCP reset and restart the connection.
B. Hosts will perform a hard TCP reset and tear down the connection.
C. Hosts will reduce the rate at which they inject traffic into the network.
D. Hosts will redirect packets to the IP address indicated in the ICMP type 4 message.
E. Hosts will retransmit the last frame sent prior to receiving the ICMP type 4 message.
Answer: C

Cisco   351-018 examen   351-018   certification 351-018

NO.19 In ISO 27001 ISMS, which three of these certification process phases are required to collect
information for ISO 27001? (Choose three.)
A. discover
B. certification audit
C. post-audit
D. observation
E. pre-audit
F. major compliance
Answer: BCE

Cisco   certification 351-018   351-018   certification 351-018   351-018

NO.20 Which two of these statements regarding Authentication Header (AH) are true? (Choose two.)
A. AH requires the use of Encapsulating Security Payload (ESP) to work correctly.
B. AH provides authentication for most of the "outer" IP header, as well as the upper layer protocols.
C. AH can be deployed in tunnel mode only.
D. AH is not commonly used, because it can only encrypt the original packet using a DES encryption
algorithm.
E. AH will work through a NAT (one-to-one) device, but not through a PAT (one-to-many) device.
F. AH uses an IP protocol number of 51.
Answer: BF

Cisco   351-018   351-018   certification 351-018

NO.21 Which two of these Cisco Catalyst security features offer the best ways to prevent ARP cache poisoning?
(Choose two.)
A. Dynamic ARP Inspection
B. port security
C. MAC address notification
D. DHCP snooping
E. PortFast
F. 802.1x authentication
Answer: AD

Cisco   351-018   351-018 examen   351-018

NO.22 The ARP functionality in IPv4 is accomplished using which type of messages, as defined in ICMPv6?
A. router solicitation and advertisement
B. neighbor solicitation and advertisement
C. redirect
D. neighbor solicitation and router advertisement
E. router solicitation and neighbor advertisement
Answer: B

Cisco examen   351-018   351-018 examen

NO.23 Cisco ASA 5500 Series Adaptive Security Appliance application layer protocol inspection is
implemented using which of these?
A. Protocol Header Definition File (PHDF)
B. Cisco Modular Policy Framework
C. Reverse Path Forwarding (RPF)
D. NetFlow version 9
E. Traffic Classification Definition File (TCDF)
Answer: B

Cisco examen   351-018 examen   351-018   certification 351-018

NO.24 Refer to the exhibit.
Switch SW2 has just been added to Fa0/23 on SW1. After a few seconds, interface Fa0/23 on SW1 is
placed in the error-disabled state. SW2 is removed from port 0/23 and inserted into SW1 port Fa0/22 with
the same result. What is the most likely cause of this problem?
A. The spanning-tree PortFast feature has been configured on SW1.
B. BPDU filtering has been enabled either globally or on the interfaces of SW1.
C. The BPDU guard feature has been enabled on the Fast Ethernet interfaces of SW1.
D. The Fast Ethernet interfaces of SW1 are unable to autonegotiate speed and duplex with SW2.
E. PAgP is unable to correctly negotiate VLAN trunk characteristics on the link between SWI and SW2.
Answer: C

Cisco   certification 351-018   351-018 examen   351-018

NO.25 Which two of these are true about TFTP? (Choose two.)
A. TFTP includes a basic username/password authentication mechanism.
B. While "putting" files via TFTP is possible, it is good practice to disallow it, because TFTP lacks access
control mechanisms.
C. TFTP uses a very basic "stop and wait" mechanism for flow control, for which each packet needs to be
acknowledged before the next one is sent.
D. TFTP root directories need to be world-readable and -writable due to the lack of security controls in the
protocol.
E. TFTP can list remote directory contents, but only if advanced options (as defined in RFC 2347) are
negotiated between client and server at initial connection time.
Answer: BC

Cisco   351-018 examen   351-018   certification 351-018

NO.26 Which two of these statements about SMTP and ESMTP are the most correct? (Choose two.)
A. Open mail relays are often used for spamming.
B. ESMTP does not provide more security features than SMTP.
C. SMTP provides authenticated e-mail sending.
D. Worms often spread via SMTP.
Answer: AD

certification Cisco   351-018   351-018   certification 351-018   351-018   351-018

NO.27 Which method is used by Cisco Security Agent to get user state information from the operating
system?
A. secure SSL using HTTPS session
B. application (Layer 7)-based (Cisco proprietary) encryption
C. NetBIOS socket on TCP port 137-139 and UDP port 137-139
D. Win32 application binary interface (ABI)
E. Win32 application programming interface (API)
Answer: E

Cisco   351-018 examen   351-018 examen   351-018   351-018

NO.28 A DNS open resolver is vulnerable to which three of these malicious activities? (Choose three.)
A. cache poisoning attack
B. amplification attack
C. Ping of Death attack
D. Resource Utilization attack
E. Blue Screen of Death
F. Nachi worm attack
Answer: ABD

Cisco   351-018   351-018   351-018   351-018 examen

NO.29 Which three of these protocols are supported when using TACACS+? (Choose three.)
A. AppleTalk
B. CHAP
C. NASI
D. NetBIOS
E. Kerberos
Answer: ACD

certification Cisco   351-018   351-018   351-018   351-018

NO.30 Which of these best represents a typical attack that takes advantage of RFC 792, ICMP type 3
messages?
A. blind connection-reset
B. large packet echo request
C. packet fragmentation offset
D. broadcast-based echo request
E. excessive bandwidth consumption
Answer: A

certification Cisco   351-018   351-018   certification 351-018   certification 351-018

Choisir le Pass4Test vous permet non seulement à réussir le test Cisco 351-018, mais encore à enjouir le service en ligne 24h et la mise à jour gratuite pendant un an. Nous allons lancer au premier temps la Q&A Cisco 351-018 plus nouvelle. Si vous ne passez pas le test, votre argent sera tout rendu.

2013年11月11日星期一

Dernières Cisco 351-018 de la pratique de l'examen questions et réponses téléchargement gratuit

Vous Cisco 351-018 pouvez télécharger le démo Cisco 351-018 gratuit dans le site Pass4Test pour essayer notre qualité. Une fois vous achetez le produit de Pass4Test, nous allons faire tous effort à vous aider à réussir le test à la première fois et vous laisser savoir qu'il ne faut pas beaucoup de travaux pour réussir ce que vous voulez.

Le suucès n'est pas loin de vous une fois que vous choisissez le produit de Q&A Cisco 351-018 de Pass4Test.

Pass4Test est un seul site de provider le guide d'étude Cisco 351-018 de qualité. Peut-être que vous voyiez aussi les Q&A Cisco 351-018 dans autres sites, mais vous allez découvrir laquelle est plus complète. En fait, Pass4Test est aussi une resource de Q&A pour les autres site web.

Code d'Examen: 351-018
Nom d'Examen: Cisco (CCIE Security written)
Questions et réponses: 560 Q&As

L'équipe de Pass4Test rehcerche la Q&A de test certification Cisco 351-018 en visant le test Cisco 351-018. Cet outil de formation peut vous aider à se préparer bien dans une courte terme. Vous vous renforcerez les connaissances de base et même prendrez tous essences de test Certification. Pass4Test vous assure à réussir le test Cisco 351-018 sans aucune doute.

Pass4Test peut vous fournir un raccourci à passer le test Cisco 351-018: moins de temps et efforts dépensés. Vous trouverez les bonnes documentations de se former dans le site Pass4Test qui peut vous aider efficacement à réussir le test Cisco 351-018. Si vous voyez les documentations dans les autres sites, c'est pas difficile à trouver qu''elles sont venues de Pass4Test, parce que lesquelles dans Pass4Test sont le plus complété et la mise à jour plus vite.

Le test simulation Cisco 351-018 sorti par les experts de Pass4Test est bien proche du test réel. Nous sommes confiant sur notre produit qui vous permet à réussir le test Cisco 351-018 à la première fois. Si vous ne passe pas le test, votre argent sera tout rendu.

Pass4Test est aussi un site d'offrir la ressource des connaissances pour le test Certification IT. Selon les Feedbacks venus de gens qui ont untilié les produits de Pass4Test, Pass4Test est un site fiable comme l'outil de se former. Les Q&As offertes par Pass4Test sont bien précises. Les experts de Pass4Test mettent à jour nos documentations de formation de temps de temps.

351-018 Démo gratuit à télécharger: http://www.pass4test.fr/351-018.html

NO.1 Which method is used by Cisco Security Agent to get user state information from the operating
system?
A. secure SSL using HTTPS session
B. application (Layer 7)-based (Cisco proprietary) encryption
C. NetBIOS socket on TCP port 137-139 and UDP port 137-139
D. Win32 application binary interface (ABI)
E. Win32 application programming interface (API)
Answer: E

Cisco   certification 351-018   351-018 examen

NO.2 In the example shown, Host A has attempted a DCOM attack using Metasploit from Host A to Host
Which three statements best describe how event logs and IPS alerts can be used in conjunction with each
other to determine if the attack was successful? (Choose three.)
A. Cisco Security MARS will collect the syslog and the IPS alerts based on time.
B. The IPS event will suggest that an attack may have occurred because a signature was triggered.
C. IPS and Cisco ASA adaptive security appliance will use the Unified Threat Management protocol to
determine that both devices saw the attack
D. Cisco ASA adaptive security appliance will see the attack in both directions and will be able to
determine if an attack was successful.
E. The syslog event will indicate that an attack is likely because a TCP SYN and an ACK followed the
attempted attack.
Answer: ABE

Cisco   351-018 examen   certification 351-018   351-018 examen   351-018   351-018 examen

NO.3 Which one of the following is not a valid RADIUS packet type.?
A. access-reject
B. access-response
C. access-challenge
D. access-reply
E. access-accept
Answer: B

certification Cisco   351-018 examen   351-018   certification 351-018

NO.4 Cisco ASA 5500 Series Adaptive Security Appliance application layer protocol inspection is
implemented using which of these?
A. Protocol Header Definition File (PHDF)
B. Cisco Modular Policy Framework
C. Reverse Path Forwarding (RPF)
D. NetFlow version 9
E. Traffic Classification Definition File (TCDF)
Answer: B

certification Cisco   certification 351-018   351-018

NO.5 Refer to the exhibit.
Switch SW2 has just been added to Fa0/23 on SW1. After a few seconds, interface Fa0/23 on SW1 is
placed in the error-disabled state. SW2 is removed from port 0/23 and inserted into SW1 port Fa0/22 with
the same result. What is the most likely cause of this problem?
A. The spanning-tree PortFast feature has been configured on SW1.
B. BPDU filtering has been enabled either globally or on the interfaces of SW1.
C. The BPDU guard feature has been enabled on the Fast Ethernet interfaces of SW1.
D. The Fast Ethernet interfaces of SW1 are unable to autonegotiate speed and duplex with SW2.
E. PAgP is unable to correctly negotiate VLAN trunk characteristics on the link between SWI and SW2.
Answer: C

Cisco   351-018   certification 351-018   certification 351-018   certification 351-018

NO.6 Which three of these protocols are supported when using TACACS+? (Choose three.)
A. AppleTalk
B. CHAP
C. NASI
D. NetBIOS
E. Kerberos
Answer: ACD

Cisco examen   certification 351-018   351-018   certification 351-018

NO.7 Which two of these Cisco Catalyst security features offer the best ways to prevent ARP cache poisoning?
(Choose two.)
A. Dynamic ARP Inspection
B. port security
C. MAC address notification
D. DHCP snooping
E. PortFast
F. 802.1x authentication
Answer: AD

Cisco   certification 351-018   351-018 examen   351-018 examen

NO.8 Which two of these are valid TACACS+ Accounting packets? (Choose two.)
A. REQUEST
B. REPLY
C. RESPONSE
D. CONTINUE
E. START
Answer: AC

Cisco examen   351-018   certification 351-018   351-018   351-018

NO.9 In ISO 27001 ISMS, which three of these certification process phases are required to collect
information for ISO 27001? (Choose three.)
A. discover
B. certification audit
C. post-audit
D. observation
E. pre-audit
F. major compliance
Answer: BCE

Cisco   certification 351-018   351-018

NO.10 Which two of these statements about SMTP and ESMTP are the most correct? (Choose two.)
A. Open mail relays are often used for spamming.
B. ESMTP does not provide more security features than SMTP.
C. SMTP provides authenticated e-mail sending.
D. Worms often spread via SMTP.
Answer: AD

Cisco   351-018   351-018 examen

NO.11 Which two of these commands are required to implement a Cisco Catalyst 6500 Series Firewall
Services Module (FWSM) in a Catalyst 6500 running Cisco IOS? (Choose two.)
A. firewall multiple-vlan-interfaces
B. firewall module vlan-group
C. module secure-traffic
D. firewall vlan-group <vlan-x>
E. firewall module secure-traffic
Answer: BD

certification Cisco   351-018 examen   certification 351-018

NO.12 Which two of these statements regarding Authentication Header (AH) are true? (Choose two.)
A. AH requires the use of Encapsulating Security Payload (ESP) to work correctly.
B. AH provides authentication for most of the "outer" IP header, as well as the upper layer protocols.
C. AH can be deployed in tunnel mode only.
D. AH is not commonly used, because it can only encrypt the original packet using a DES encryption
algorithm.
E. AH will work through a NAT (one-to-one) device, but not through a PAT (one-to-many) device.
F. AH uses an IP protocol number of 51.
Answer: BF

Cisco examen   351-018   351-018   351-018 examen

NO.13 ASDM on the Cisco ASA adaptive security appliance platform is executed as which of the following?
A. an ActiveX application or a JavaScript application
B. a JavaScript application and a PHP application
C. a fully compiled .Net Framework application
D. a fully operational Visual Basic application
E. a Java applet or a standalone application using the Java Runtime Environment
Answer: E

certification Cisco   351-018 examen   351-018   351-018   certification 351-018   351-018

NO.14 After the client opens the command channel (port 21) to the FTP server and requests passive mode,
what will be the next step?
A. The FTP server sends back an ACK to the client.
B. The FTP server allocates a port to use for the data channel and transmits that port number to the client.
C. The FTP server opens the data channel to the client using the port number indicated by the client.
D. The FTP client opens the data channel to the FTP server on port 20.
E. The FTP client opens the data channel to the FTP server on port 21.
Answer: B

certification Cisco   351-018   certification 351-018

NO.15 How do TCP SYN attacks take advantage of TCP to prevent new connections from being established
to a host under attack?
A. sending multiple FIN segments, forcing TCP connection release
B. filling up a host listen queue by failing to ACK partially opened TCP connections
C. taking advantage of the host transmit backoff algorithm by sending jam signals to the host
D. incrementing the ISN of each segment by a random number, causing constant TCP retransmissions
E. sending TCP RST segments in response to connection SYN+ACK segments, forcing SYN
retransmissions
Answer: B

Cisco   351-018 examen   certification 351-018   351-018   351-018

NO.16 Refer to the exhibit.
Which three of the following statements are correct? (Choose three.)
A. The exhibit shows an example of a NAC Framework network.
B. The exhibit shows an example of a NAC Appliance network.
C. The network utilizes in-band admission control.
D. The network utilizes out-of-band admission control.
E. Cisco NAC Appliance Agent is used to verify end-user PC compliance with the security policy
F. Cisco Trust Agent is used to verify end-user PC compliance with the security policy.
Answer: BDE

certification Cisco   351-018   351-018 examen   351-018   351-018 examen

NO.17 A DNS open resolver is vulnerable to which three of these malicious activities? (Choose three.)
A. cache poisoning attack
B. amplification attack
C. Ping of Death attack
D. Resource Utilization attack
E. Blue Screen of Death
F. Nachi worm attack
Answer: ABD

Cisco   351-018   351-018 examen   351-018   351-018   certification 351-018

NO.18 Refer to the exhibit.
Which of these statements is correct for the Fidelity Rating and Base RR values?
A. Both the Fidelity Rating and Base RR values are computed from the Severity Factor value.
B. The Fidelity Rating value is computed from the Base RR value.
C. The Severity Factor value is computed from the Fidelity Rating and Base RR values.
D. The Fidelity Rating value is computed from the Base RR and Severity Factor values.
E. The Base RR value is computed from the Fidelity Rating and Severity Factor values.
Answer: E

Cisco examen   certification 351-018   certification 351-018

NO.19 To provide a separation of duties within Cisco Security Manager, which mode would the Cisco Security
Manager administrator use?
A. Activity mode
B. Change Control mode
C. Workflow mode
D. Task-Based mode
E. Task Isolation mode
Answer: C

certification Cisco   certification 351-018   351-018

NO.20 When using Cisco Easy VPN Remote (hardware client deployment) in the client-mode setup, all of the
following statements are correct except which one?
A. Perform split tunneling on the Cisco Easy VPN Remote device.
B. Initiate a connection from a network behind the Cisco Easy VPN Server to the network behind the
Cisco Easy VPN Remote client.
C. Set the Cisco Easy VPN Remote to allow an administrator or user to manually initiate a connection.
D. Set the Cisco Easy VPN Remote to automatically connect to the Cisco Easy VPN Server.
Answer: B

Cisco   351-018   certification 351-018   351-018 examen   351-018

NO.21 What is the net effect of using ICMP type 4 messages to attack RFC 1122-compliant hosts?
A. Hosts will perform a soft TCP reset and restart the connection.
B. Hosts will perform a hard TCP reset and tear down the connection.
C. Hosts will reduce the rate at which they inject traffic into the network.
D. Hosts will redirect packets to the IP address indicated in the ICMP type 4 message.
E. Hosts will retransmit the last frame sent prior to receiving the ICMP type 4 message.
Answer: C

Cisco examen   351-018 examen   351-018 examen   351-018

NO.22 Which two of these are true about TFTP? (Choose two.)
A. TFTP includes a basic username/password authentication mechanism.
B. While "putting" files via TFTP is possible, it is good practice to disallow it, because TFTP lacks access
control mechanisms.
C. TFTP uses a very basic "stop and wait" mechanism for flow control, for which each packet needs to be
acknowledged before the next one is sent.
D. TFTP root directories need to be world-readable and -writable due to the lack of security controls in the
protocol.
E. TFTP can list remote directory contents, but only if advanced options (as defined in RFC 2347) are
negotiated between client and server at initial connection time.
Answer: BC

Cisco   certification 351-018   351-018

NO.23 Referring to the partial debug output shown in the exhibit, which of these values is contained inside the
brackets [4] in line 1?
A. RADIUS identifier field value
B. RADIUS attribute type value
C. RADIUS VSA number
D. RADIUS VSA length
E. vendor ID
Answer: B

Cisco   certification 351-018   certification 351-018

NO.24 Which of these statements best describes the advantage of using Cisco Secure Desktop, which is part
of the Cisco ASA VPN solution?
A. Cisco Secure Desktop creates a separate computing environment that is deleted when you finish,
ensuring that no confidential data is left on the shared or public computer.
B. Cisco Secure Desktop is used to protect access to your registry and system files when browsing to
SSL VPN protected pages.
C. Cisco Secure Desktop ensures that an SSL protected password cannot be exploited by a man-
in-the-middle attack using a spoofed certificate
D. Cisco Secure Desktop hardens the operating system of the machines you are using at the time it is
launched.
Answer: A

certification Cisco   351-018 examen   351-018

NO.25 A DNS Client sends DNS messages to obtain information about the requested domain name space.
The information is known as which of these?
A. Resource Record
B. Resolver
C. Branch
D. Authoritative Client
E. Recursive Client
Answer: A

certification Cisco   351-018 examen   certification 351-018   351-018

NO.26 When a failover takes place on an adaptive security appliance configured for failover, all active
connections are dropped and clients must reestablish their connections, unless the adaptive security
appliance is configured in which two of the following ways? (Choose two.)
A. active/stand by failover
B. active/active failover
C. active/active failover and a state failover link has been configured
D. active/standby failover and a state failover link has been configured
E. to use a serial cable as the failover link
F. LAN-based failover
Answer: CD

Cisco   351-018   351-018   351-018

NO.27 Which of these best represents a typical attack that takes advantage of RFC 792, ICMP type 3
messages?
A. blind connection-reset
B. large packet echo request
C. packet fragmentation offset
D. broadcast-based echo request
E. excessive bandwidth consumption
Answer: A

Cisco   351-018   351-018 examen   351-018 examen   351-018

NO.28 How does using DHCP Option 82 on a Cisco Wireless LAN Controller make a network more secure?
A. by preventing rogue DHCP servers from returning unauthorized addresses
B. by ensuring that DHCP addresses are parity-checked before being issued
C. by ensuring that clients receive proper routing information as part of their DHCP responses
D. by preventing DHCP address requests from untrusted relay agents
E. by adding fully qualified domain information that the client can use for SSL authentication
Answer: D

Cisco   351-018   351-018   351-018

NO.29 For a router to obtain a certificate from a CA, what is the first step of the certificate enrollment process?
A. The router generates a certificate request and forwards it to the CA.
B. The router generates an RSA key pair.
C. The router sends its public key to the CA.
D. The CA sends its public key to the router.
E. The CA verifies the identity of the router.
F. The CA generates a certificate request and forwards it to the router.
Answer: B

Cisco examen   351-018 examen   351-018

NO.30 The ARP functionality in IPv4 is accomplished using which type of messages, as defined in ICMPv6?
A. router solicitation and advertisement
B. neighbor solicitation and advertisement
C. redirect
D. neighbor solicitation and router advertisement
E. router solicitation and neighbor advertisement
Answer: B

Cisco examen   351-018   351-018 examen

Il faut une bonne préparation et aussi une série de connaissances professionnelles complètes pour réussir le test Cisco 351-018. La ressourece providée par Pass4Test peut juste s'accorder votre demande.

2013年7月24日星期三

Cisco meilleur examen 351-018 642-481 350-029 350-040 350-030 350-021, questions et réponses

Choisissez le Pass4Test, choisissez le succès. Le produit offert par Pass4Test vous permet à réussir le test Cisco 351-018 642-481 350-029 350-040 350-030 350-021. C'est necessaire de prendre un test simulation avant participer le test réel. C'est une façon bien effective. Choisir Pass4Test vous permet à réussir 100% le test.


L'équipe de Pass4Test autorisée offre sans arrêt les bonnes resources aux candidats de test Certification Cisco 351-018 642-481 350-029 350-040 350-030 350-021. Les documentations particulièrement visée au test Cisco 351-018 642-481 350-029 350-040 350-030 350-021 aide beaucoup de candidats. La Q&A de la version plus nouvelle est lancée maintenant. Vous pouvez télécharger le démo gratuit en Internet. Généralement, vous pouvez réussir le test 100% avec l'aide de Pass4Test, c'est un fait preuvé par les professionnels réputés IT. Ajoutez le produit au panier, vous êtes l'ensuite à réussir le test Cisco 351-018 642-481 350-029 350-040 350-030 350-021.


Est-que vous s'inquiétez encore à passer le test Certification 351-018 642-481 350-029 350-040 350-030 350-021 qui demande beaucoup d'efforts? Est-que vous travaillez nuit et jour juste pour préparer le test de Cisco 351-018 642-481 350-029 350-040 350-030 350-021? Si vous voulez réussir le test Cisco 351-018 642-481 350-029 350-040 350-030 350-021 plus facilement? N'hésitez plus à nous choisir. Pass4Test vous aidera à réaliser votre rêve.


Le test simulation Cisco 351-018 642-481 350-029 350-040 350-030 350-021 sorti par les experts de Pass4Test est bien proche du test réel. Nous sommes confiant sur notre produit qui vous permet à réussir le test Cisco 351-018 642-481 350-029 350-040 350-030 350-021 à la première fois. Si vous ne passe pas le test, votre argent sera tout rendu.


Code d'Examen: 351-018

Nom d'Examen: Cisco (CCIE Security written)

Questions et réponses: 560 Q&As

Code d'Examen: 642-481

Nom d'Examen: Cisco (Cisco Rich Media Communications(CRMC))

Questions et réponses: 114 Q&As

Code d'Examen: 350-029

Nom d'Examen: Cisco (CCIE SP Written Exam)

Questions et réponses: 358 Q&As

Code d'Examen: 350-040

Nom d'Examen: Cisco (CCIE Storage Networking)

Questions et réponses: 313 Q&As

Code d'Examen: 350-030

Nom d'Examen: Cisco (CCIE Voice Written)

Questions et réponses: 196 Q&As

Code d'Examen: 350-021

Nom d'Examen: Cisco (CCIE SP Cable Qualification Exam)

Questions et réponses: 399 Q&As

Pass4Test, où vous pouvez trouver les conseils et les documentations de test Certification Cisco 351-018 642-481 350-029 350-040 350-030 350-021, est un siteweb remarquable offrant les données à préparer le test IT. Les documentations partiels et les mis en nouveau sont offerts gratuitement dans le site de Pass4Test. D'ailleurs, nos experts profitent de leurs expériences et leurs efforts à lancer sans arrêts les Q&A plus proches au test réel. Vous allez passer votre examen plus facile.


350-030 Démo gratuit à télécharger: http://www.pass4test.fr/350-030.html


NO.1 Refer to the exhibit.
You are debugging a problem on a SIP network and have run the debug ccsip messages command. One
of the messages returned is shown in the exhibit. What information will the server return to the caller?
A.the acceptable media type
B.a list of acceptable media types
C.a list of acceptable formats
D.a correct directory number
E.an acceptable language code
Answer: C

Cisco   350-030 examen   certification 350-030   350-030

NO.2 Which three options are valid SCCP call states sent to an IP phone?
A.Ring Off
B.On Hook
C.Call Transmit
D.Connected
E.Disconnected
F.In Use Remotely
Answer: BDF

Cisco examen   350-030   350-030

NO.3 Company Alpha has a central office and a branch office that utilize a central call processing toplogy.
Calls between the two sites are using the G.729 codec; calls within each site are using the G.711 codec.
To conference an existing call between two phones at the central site with a phone at the remote office,
which two of the following are possible solutions? (Choose two.)
A.a software conference bridge that is configured in Cisco Unified Communications Manager
B.a software conference bridge that is configured in Cisco Unified Communications Manager and a HW
transcoder
C.a hardware conference bridge
D.a hardware transcoder and a hardware conference bridge
E.No extra configurations required--phones automatically negotiate using the lowest common
denominator codec (G.729)
Answer: BC

Cisco examen   350-030   certification 350-030   350-030 examen

NO.4 Which two of the following are functions of DHCP snooping? (Choose two.)
A.relies on already discovered trusted and untrusted ports
B.dynamic ARP inspection
C.defines trusted and untrusted ports
D.uses existing binding tables
E.builds a binding table
F.automatically builds ACLs
Answer: CE

Cisco examen   350-030   350-030 examen

NO.5 What are two advantages of multicast technologies? (Choose two.)
A.Denial of service attacks in the network are prevented.
B.They eliminate multipoint applications.
C.They reduce traffic by delivering a separate stream of information to each corporate recipient or home
environment, which reduces bandwidth.
D.They control network traffic and reduce server and CPU load.
E.They eliminate traffic redundancy.
Answer: DE

Cisco   350-030 examen   certification 350-030   350-030 examen

NO.6 Refer to the exhibit.
How many simultaneous G.729 calls can be established between sites SJ and RTP?
A.4
B.5
C.6
D.8
E.12
Answer: C

Cisco   350-030 examen   350-030   certification 350-030

NO.7 When implementing a Cisco Unified Communications Manager solution over an MPLS WAN, which
two rules must be observed to prevent overrunning the priority queue? (Choose two.)
A.RSVP will transparently pass application IDs from the customer network across the MPLS WAN.
B.The media streams must be the same size in both directions.
C.Only the connection to the MPLS WAN where the Cisco Unified Communications Manager resides
must be enabled as a CE device.
D.The media has to be symmetrically routed.
E.If the CE is under corporate control, it may support either topology-aware or measurement- based CAC.
Answer: BD

Cisco   350-030 examen   350-030   certification 350-030

NO.8 Which type of SIP responses would indicate that a server encountered an error in attempting to
complete a SIP request?
A.1xx
B.3xx
C.4xx
D.5xx
E.6xx
Answer: D

Cisco   350-030   350-030 examen   350-030   350-030 examen

NO.9 How is fax pass-through traffic treated over IP WAN connections that use the G.729 codec?
A.The fax traffic is demodulated and sent with VAD and echo chancellor disabled.
B.When the TGW detects the CED tone from the fax machine that has been contacted, the TGW changes
to the G.711 codec with echo chancellor and VAD disabled.
C.When the OGW detects the CED tone from the fax machine that is making the call, the OGW is
informed by the contacted device of the Cisco NSF features and switches to the G.711 codec with VAD
disabled.
D.The contacting fax machine sends a TCF message to the contacted fax machine and waits for a CFR
message. When the CFR message is received, the fax tones sent by the contacting fax machine cause
the OGW to send an NSF message to the TGW, instructing it to switch to the
E.711 codec with echo chancellor and VAD disabled.
Answer: B

Cisco   350-030 examen   350-030 examen   certification 350-030   350-030

NO.10 Which three statements are true about multicast IGMP snooping? (Choose three.)
A.When a host in a multicast group sends an IGMP leave message, only that port is deleted from the
multicast group.
B.An IP multicast stream to the IP host can be stopped only by an IGMP leave message.
C.IGMP snooping does not examine or snoop Layer 3 information in packets that are sent between the
hosts and the router.
D.When the switch hears the IGMP host report from a host for a particular multicast group, the switch
adds the host's port number to the associated multicast table entry.
E.IGMP control messages are transmitted as IGMP multicast packets so that they can be distinguished
from normal multicast data at Layer 2.
F.A switch that is running IGMP snooping examines every multicast data packet to verify whether it
contains any pertinent IGMP "must control" information.
Answer: ADF

Cisco   certification 350-030   350-030   350-030 examen   350-030

NO.11 Which of the following three messages could be sent by the UAC in response to the 180 Ringing?
(Choose three.)
A.PRACK
B.ACK
C.BYE
D.CANCEL
E.INVITE
Answer: ABD

Cisco examen   350-030   350-030   350-030

NO.12 Refer to the exhibit.
You have been asked to edit the sample auto attendant script so that callers are prompted to press 1 for
sales, 2 for service, or 3 for the directory. If callers select 3, they should hear the existing menu choices to
dial by extension, dial by name, or transfer to the operator. What steps can you take to create this nested
menu?
A.Drag a new Menu step from the palette and drop it on the Start step. Drag the existing Menu step and
drop it on Output 3 of the new Menu.
B.Drag a new Menu step from the palette and drop it on the existing Menu step. This will make the
existing Menu subordinate to the new Menu.
C.Drag a new Menu step from the palette and drop it on the existing Menu step. Drag the existing Menu
step and drop it on Output 3 of the new Menu.
D.Delete the existing Menu. Drag a new Menu step from the palette and drop it on the Set
prefixPrompt=P[] step. Recreate the existing directory menu as the third option of the new Menu step.
Answer: C

certification Cisco   350-030   certification 350-030   certification 350-030   350-030 examen

NO.13 Which two of these are possible reasons why a JTAPI subsystem might have the status
PARTIAL_SERVICE? (Choose two.)
A.Cisco Unified Contact Center is not able to resolve the host name of Cisco Unified Communications
Manager.
B.A referenced CTI Route Point is not associated with the JTAPI user.
C.The JTAPI user password is not correct.
D.There is an error in one of the scripts being loaded.
E.The CTI Manager service is not running on Cisco Unified Communications Manager.
Answer: BD

certification Cisco   350-030 examen   350-030 examen   350-030

NO.14 Which three statements are true about Cisco Discovery Protocol? (Choose three.)
A.It is an excellent tool for displaying the interface status on switches.
B.It works on top of the network layer and data link level.
C.It uses a multicast packet with a destination MAC address of 01-00-CC-CC-CC.
D.The platform TLV (TLV type 0x0006) contains an ASCII character string that describes the hardware
platform of the device.
E.You can use the CDP timer feature to change update times. The default is 60 seconds.
F.It uses a broadcast packet with a destination MAC address of 01-00-CC-CC-CC.
Answer: ADE

Cisco   350-030   350-030   350-030 examen

NO.15 Which two statements apply to the partitions function in Cisco Unified Communications Manager?
(Choose two.)
A.When a directory number or route pattern is placed into a certain partition, this creates a rule for who
can call that device or route list.
B.A partition is a logical grouping of directory numbers and route patterns that have similar reachability
characteristics.
C.Calling Search Spaces are assigned to partitions.
D.A directory number may appear in only one partition.
E.Within the partition, each CSS has a directory number.
Answer: AB

Cisco   350-030 examen   350-030   350-030

NO.16 Refer to the exhibit.
Which gatekeeper mechanism prevents the gatekeeper from using all the resources on either gateway 1
or gateway 2 when sending calls to zones SE and NW?
A.bandwidth remote
B.resource availability indicator
C.bandwidth total
D.bandwidth zone
E.lrq immediate advance
F.ras timeout brq
Answer: B

Cisco   350-030   350-030   350-030 examen   certification 350-030

NO.17 Which three of these are mandatory sub-commands of the call-manager-fallback command and will
help an IP phone register to an IOS router in SRST mode? (Choose three.)
A.access-code
B.dialplan-pattern
C.ip source-address
D.keepalive
E.max-dn
F.max-ephones
Answer: CEF

certification Cisco   350-030   certification 350-030   350-030 examen   certification 350-030   350-030

NO.18 Refer to the exhibit.
Traffic flows from the IP phone that is connected to SW1 to the IP phone on SW2. If the trust boundary
has been extended to the IP phone on SW1, in what two places will traffic be marked and classified so
that the proper QoS settings may be carried through the network? (Choose two.)
A.IP phone attached to SW1
B.SW1 ingress port
C.R1 ingress port
D.SW1 egress port
E.R1 egress port
Answer: BC

certification Cisco   350-030   350-030 examen   certification 350-030   350-030 examen

NO.19 Which two descriptions apply to the Calling Search Space function in Cisco Unified Communications
Manager? (Choose two.)
A.It defines which numbers are available for a device to call.
B.It provides a group of dial patterns to look through when making a call.
C.Within a partition, each CSS has a directory number.
D.It defines route patterns and directory numbers from which calls can be received.
E.It defines the search for directory numbers in assigned partitions according to dial patterns.
Answer: AE

Cisco   certification 350-030   350-030 examen   350-030   350-030

NO.20 To hide its identity when initiating calls, SIP Phone B requests that Server B place its calls for it.
What kind of device is Server B?
A.proxy
B.redirect
C.registrar
D.user agent client
E.user agent server
Answer: A

Cisco   350-030   350-030   350-030 examen