• Home
  • Microsoft Exam Dumps
  • Why Choose Lead2pass?
  • Sitemap

Lead2pass New Updated IT Exam Questions

Exam collection of Micfosoft, Cisco,IBM,CompTIA and other IT exam

Menu
  • Home
  • Microsoft Exam Dumps
  • Why Choose Lead2pass?
  • Sitemap
 › 400-251 Dumps › 400-251 Exam Questions › 400-251 New Questions › 400-251 PDF › 400-251 VCE › Cisco › [2017 New] Free Lead2pass 400-251 PDF Guarantee 100% Get 400-251 Certification (251-275)

[2017 New] Free Lead2pass 400-251 PDF Guarantee 100% Get 400-251 Certification (251-275)

admin August 10, 2017     Comment Closed    

2017 August Cisco Official New Released 400-251 Dumps in Lead2pass.com!

100% Free Download! 100% Pass Guaranteed!

This dump is valid to pass Cisco 400-251 exam and don’t just memorize the answer, you need to get through understanding of it because the question changed a little in the real exam. The material is to supplement your studies.

Following questions and answers are all new published by Cisco Official Exam Center: https://www.lead2pass.com/400-251.html

QUESTION 251
Which three Cisco attributes for LDAP authorization are supported on the ASA? (Choose three)

A.    L2TP-Encryption
B.    Web-VPN-ACL-Filters
C.    IPsec-Client-Firewall-Filter-Name
D.    Authenticated-User-Idle-Timeout
E.    IPsec-Default-Domain
F.    Authorization-Type

Answer: BDE
Explanation:
Something wrong with the question. All 6 options given are all supported by Cisco ASA. Check out this document for all attributes supported, they are all in the table 1-2
http://www.cisco.com/c/en/us/td/docs/security/asa/asa90/configuration/guide/asa_90_cli_config/ref_extserver.pdf

QUESTION 252
Which two options are system requirements for single sign-on on Cisco Unified Communications Manager? (Choose two)

A.    OpenAM must be deployed in a different domain Microsoft Active Directory.
B.    All participating entities must have their clocks synchronized.
C.    The local user profile on Cisco Unified Communications must be disabled.
D.    IWA and Kerberos authentication must be configured in the Windows domain.
E.    Microsoft Active Directory must be deployed in a domain-based configuration.

Answer: BE

QUESTION 253
Which of the following statement is true about the ARP attack?

A.    Attackers sends the ARP request with the MAC address and IP address of a legitimate resource in the network.
B.    Attackers sends the ARP request with the MAC address and IP address of its own.
C.    ARP spoofing does not facilitate man-in-the middle attack of the attackers.
D.    Attackers sends the ARP request with its own MAC address and IP address of a legitimate resource in the network.

Answer: D

QUESTION 254
During a DoS attacks all of the data is lost from a user’s laptop and the user must now rebuild the system.
Which tool can the user use to extract the outlook PST file from the Microsoft server database?

A.    Eseutil. exe
B.    NTabackup.cex
C.    Exmerge.exe
D.    Ost2st.exe

Answer: C

QUESTION 255
A Cisco Easy VPN software client is unable to access its local LAN devices once the VPN tunnel is established.
What is the best way to solve this issue?

A.    The IP address that is assigned by the Cisco Easy VPN Server to the client must be on the same network as the local LAN of the client.
B.    The Cisco Easy VPN Server should apply split-tunnel-policy excludespecified with a split-tunnel-list containing the local LAN addresses that are relevant to the client.
C.    The Cisco Easy VPN Server must push down an interface ACL that permits the traffic to the local LAN from the client.
D.    The Cisco Easy VPN Server should apply a split-tunnel-policy tunnelall policy to the client.
E.    The Cisco Easy VPN client machine needs to have multiple NICs to support this.

Answer: B

QUESTION 256
Which two statements about IKEv2 are true? (Choose two)

A.    It uses EAP authentication
B.    It uses X.509 certificates for authentication
C.    The profile is a collection of transforms used to negotiate IKE SAs
D.    It supports DPD and Nat-T by default
E.    The profile contains a repository of symmetric and asymmetric preshared keys
F.    At minimum, a complete proposal requires one encryption algorithm and one integrity algorithm

Answer: AD

QUESTION 257
Which two OSPF network types support the concept of a designated router? (Choose two.)

A.    broadcast
B.    NBMA
C.    point-to-multipoint
D.    point-to-multipoint nonbroadcast
E.    loopback

Answer: AB

QUESTION 258
Given the IPv4 address 10.10.100.16, which two address are valid IPv4-compatible IPv6 addresses? (Choose twoChoose two)

A.    0:0:0:0:0:10:10:100:16
B.    0:0:10:10:10:16:0:0:0
C.    0:0:10:10:100:16:0:0:0
D.    ::10:10:100:16
E.    :::A:A:64:10

Answer: AD

QUESTION 259
What technology can you implement on your network to allow IPv4-dependent applications to work with IPv6- capable application?

A.    NAT 6to4
B.    DS-lite
C.    NAT-PT
D.    ISATAP
E.    NAT64

Answer: E

QUESTION 260
Which three fields are part of the AH header? (Choose three)

A.    Destination address
B.    Protocol ID
C.    Packet ICV
D.    SPI identifying SA
E.    Next header
F.    Application port
G.    Source address

Answer: CDE

QUESTION 261
What ASA feature can do use to restrict a user to a specific VPN group?

A.    A webtypeACL
B.    MPF
C.    A VPN filter
D.    Group-lock

Answer: D

QUESTION 262
Which two statements about SGT Exchange Protocol are true? (Choose two)

A.    It propagates the IP-to-SGT binding table across network devices that do not have the ability to perform SGT tagging at Layer 2 to devices that support it
B.    SXP runs on UDP port 64999
C.    A connection is established between a “listener” and a “speaker”
D.    SXP is only supported across two hops
E.    SXPv2 introduces connection security via TLS

Answer: AC

QUESTION 263
Which three statements are true regarding RFC 5176 (Change of Authorization)? (Choose three.)

A.    It defines a mechanism to allow a RADIUS server to initiate a communication inbound to a NAD.
B.    It defines a wide variety of authorization actions, including “reauthenticate.”
C.    It defines the format for a Change of Authorization packet.
D.    It defines a DM.
E.    It specifies that TCP port 3799 be used for transport of Change of Authorization packets.

Answer: ACD

QUESTION 264
How does a wireless association flood attack create a DoS?

A.    It sends a high-power RF pulse that can damage the internals of the AP
B.    It spoofs disassociation frames from the access point.
C.    It uses a brute force attack to crack the encryption.
D.    It exhausts the access client association table.

Answer: D
Explanation:
This question is very confusing because it doesn’t state if it is DoS against access point or the client. If DoS is run against the AP then the right answer is D. Check the section “Denial of Service attacks against access points”
http://www.cisco.com/c/en/us/td/docs/wireless/mse/3350/7-2/wIPS_Configuration/Guide/wIPS_72/msecg_appA_wIPS.html
If the attack targets wireless clients then the correct answer is B. Check the section “Denial of service attacks against client station” in the same document

QUESTION 265
Refer to the exhibit, you have configured two route-map instances on R1 which passes traffic from switch 1 on both VLAN 1 and VLAN 2.
You wish to ensure that the first route-map instance matches packets from VLAN 1 and sets next hop to 3232::2/128.
The second route-map instance matches packets from VLAN 2 and sets the next hop to 3232::3/128.
What feature can you implement on R1 to make this configuration possible?

 

A.    PBR
B.    BGP local-preference
C.    BGP next-hop
D.    VSSP
E.    GLBP

Answer: A
Explanation:
http://www.cisco.com/c/en/us/td/docs/ios-xml/ios/iproute_pi/configuration/xe-3s/iri-xe-3s-book/ip6-pbr-xe.html

QUESTION 266
What are two feature that can be used to drop incoming traffic with spoofed bogon address? (Choose two)

A.    Unicast RPF
B.    ingress ACLs
C.    flexible ACLs
D.    egress ACLs
E.    reflexive ACLs
F.    Source Specific Multicast

Answer: AB

QUESTION 267
Refer to the exhibit, what is the effect of the given command sequence?

 

A.    The router telnet to the on port 2002
B.    The AP console port is shut down.
C.    A session is opened between the router console and the AP.
D.    The router telnet to the router on port 2002.

Answer: C

QUESTION 268
Which two statements about IPsec in a NAT-enabled environment are true? (Choose two)

A.    The hashes of each peer’s IP address and port number are compared to determine whether NAT-T is required
B.    NAT-T is not supported when IPsec Phase 1 is set to Aggressive Mode
C.    The first two messages of IPsec Phase 2 are used to determine whether the remote host supports NAT-T
D.    NAT-T is not supported when IPsec Phase 1 is set to Main Mode
E.    IPsec packets are encapsulated in UDP 500 or UDP 10000 packets
F.    To prevent translations from expiring, NAT keepalive messages that include a payload are sent between the peers

Answer: AF
Explanation:
http://www.cisco.com/en/US/docs/ios-xml/ios/sec_conn_dplane/configuration/15-1mt/sec-ipsec-nat-transp.html#GUID-54C3D921-581F-48B8-9641-5942C19DEA1F

QUESTION 269
Which statement about the Cisco Secure ACS Solution Engine TACACS+ AV pair is true?

A.    AV pairs are only required to be enabled on Cisco Secure ACS for successful implementation.
B.    The Cisco Secure ACS Solution Engine does not support accounting AV pairs.
C.    AV pairs are only string values.
D.    AV pairs are of two types: string and integer.

Answer: C

QUESTION 270
Which statement about Sarbanes-Oxley (SOX) is true?

A.    SOX is an IEFT compliance procedure for computer systems security.
B.    SOX is a US law.
C.    SOX is an IEEE compliance procedure for IT management to produce audit reports.
D.    SOX is a private organization that provides best practices for financial institution computer systems.
E.    Section 404 of SOX is only related to IT compliance.

Answer: BE

QUESTION 271
Which Cisco ASA firewall mode supports ASDM one-time-password authentication using RSA SecurID?

A.    Network translation mode
B.    Single-context routed mode
C.    Multiple-context mode
D.    Transparent mode

Answer: B

QUESTION 272
What protocol is responsible for issuing certificates?

A.    SCEP
B.    DTLS
C.    ESP
D.    AH
E.    GET

Answer: A

QUESTION 273
Which category to protocol mapping for NBAR is correct?

A.    Category: internet
Protocol: FTP, HTTP, TFTP
B.    Category: Network management
Protocol: ICMP, SNMP, SSH, telent
C.    Category: network mail services
Protocol: mapi, pop3, smtp
D.    Category: Enterprise applications
Protocal: citrixICA, PCAnywhere, SAP, IMAP

Answer: A

QUESTION 274
You have discovered unwanted device with MAC address 001c.0f12.badd on port FastEthernet1/1 on VLAN 4.
What command or command sequence can you enter on the switch to prevent the MAC address from passing traffic on VLAN 4?

A.    
B.    
C.    
D.    
E.    

Answer: E
Explanation:
In order for VLAN access-map to drop a specific MAC address it has to use access-list with permit entry.
http://www.cisco.com/c/en/us/support/docs/switches/catalyst-3550-series-switches/64844-mac-acl-block-arp.html

QUESTION 275
Which two options are benefits the Cisco ASA Identity Firewall?(Choose two)

A.    It supports an AD server module to verify identity data.
B.    It can operate completely independently of other servers.
C.    It decouples security policies from the network topology.
D.    It can apply security policies on an individual user or user-group basis
E.    It can identify threats quickly based on their URLs.

Answer: CD

About 90% questions are from this 400-251 dump. One thing you need to pay attention is the questions are rephrased in the real 400-251 exam. And btw selections are jumbled so you must remember the answer itself not the letter of choice.

400-251 new questions on Google Drive: https://drive.google.com/open?id=0B3Syig5i8gpDMERESjlYcVlZNWs

2017 Cisco 400-251 exam dumps (All 470 Q&As) from Lead2pass:

https://www.lead2pass.com/400-251.html [100% Exam Pass Guaranteed]

400-251 Dumps 400-251 Exam Questions 400-251 New Questions 400-251 PDF 400-251 VCE Cisco
400-251 braindumps400-251 exam dumps400-251 exam question400-251 pdf dumps400-251 practice test400-251 study guide400-251 vce dumpsLead2pass 400-251

 Previous Post

[2017 New] Free Lead2pass 400-251 PDF Guarantee 100% Get 400-251 Certification (226-250)

― August 10, 2017

Next Post 

[2017 New] Free Lead2pass Amazon AWS Certified Solutions Architect – Associate PDF Dumps With New Update Exam Questions (351-375)

― August 10, 2017

Author: admin

Related Articles

admin ― May 29, 2018 | Comment Closed

[May 2018] Easily Pass 400-251 Exam With Lead2pass New 400-251 VCE And PDF Dumps 359q

Easily Pass 400-251 Exam With Lead2pass New Cisco 400-251 Brain Dumps: https://www.lead2pass.com/400-251.html QUESTION 31Refer to the exhibit. What is the

admin ― April 12, 2018 | Comment Closed

[April 2018] New Lead2pass Cisco 400-251 New Questions Free Download 359q

admin ― February 27, 2018 | Comment Closed

[February 2018] Latest Lead2pass 400-251 Exam Free 400-251 Dumps Download 727q

admin ― January 17, 2018 | Comment Closed

[January 2018] Best Lead2pass Cisco 400-251 PDF Dumps With New Update Exam Questions 727q

admin ― October 25, 2017 | Comment Closed

[Lead2pass New] 400-251 Exam Questions Free Download From Lead2pass (426-450)

admin ― October 25, 2017 | Comment Closed

[Lead2pass New] 400-251 Exam Questions Free Download From Lead2pass (376-400)

admin ― October 25, 2017 | Comment Closed

[Lead2pass New] 400-251 Exam Questions Free Download From Lead2pass (351-375)

admin ― October 25, 2017 | Comment Closed

[Lead2pass New] 400-251 Exam Questions Free Download From Lead2pass (326-350)

Categories

Premium VCE Test Engine

VCE Exam Simulator for Mobile

Take exams on your mobile device the same way you do on your desktop. iPhone, iPad and Android devices are supported.

Hottest Microsoft Exam Dumps

HOTMicrosoft 70-243 Dumps ➤ PDF & VCE
HOTMicrosoft 70-246 Dumps ➤ PDF & VCE
HOTMicrosoft 70-247 Dumps ➤ PDF & VCE
HOTMicrosoft 70-331 Dumps ➤ PDF & VCE
HOTMicrosoft 70-332 Dumps ➤ PDF & VCE
HOTMicrosoft 70-333 Dumps ➤ PDF & VCE
HOTMicrosoft 70-341 Dumps ➤ PDF & VCE
HOTMicrosoft 70-342 Dumps ➤ PDF & VCE
HOTMicrosoft 70-346 Dumps ➤ PDF & VCE
HOTMicrosoft 70-347 Dumps ➤ PDF & VCE
HOTMicrosoft 70-410 Dumps ➤ PDF & VCE
HOTMicrosoft 70-411 Dumps ➤ PDF & VCE
HOTMicrosoft 70-412 Dumps ➤ PDF & VCE
HOTMicrosoft 70-413 Dumps ➤ PDF & VCE
HOTMicrosoft 70-414 Dumps ➤ PDF & VCE
HOTMicrosoft 70-417 Dumps ➤ PDF & VCE
HOTMicrosoft 70-457 Dumps ➤ PDF & VCE
HOTMicrosoft 70-458 Dumps ➤ PDF & VCE
HOTMicrosoft 70-461 Dumps ➤ PDF & VCE
HOTMicrosoft 70-462 Dumps ➤ PDF & VCE
HOTMicrosoft 70-463 Dumps ➤ PDF & VCE
HOTMicrosoft 70-464 Dumps ➤ PDF & VCE
HOTMicrosoft 70-465 Dumps ➤ PDF & VCE
HOTMicrosoft 70-466 Dumps ➤ PDF & VCE
HOTMicrosoft 70-467 Dumps ➤ PDF & VCE
HOTMicrosoft 70-469 Dumps ➤ PDF & VCE
HOTMicrosoft 70-480 Dumps ➤ PDF & VCE
HOTMicrosoft 70-481 Dumps ➤ PDF & VCE
HOTMicrosoft 70-482 Dumps ➤ PDF & VCE
HOTMicrosoft 70-483 Dumps ➤ PDF & VCE
HOTMicrosoft 70-486 Dumps ➤ PDF & VCE
HOTMicrosoft 70-487 Dumps ➤ PDF & VCE
HOTMicrosoft 70-488 Dumps ➤ PDF & VCE
HOTMicrosoft 70-489 Dumps ➤ PDF & VCE
HOTMicrosoft 70-511 Dumps ➤ PDF & VCE
HOTMicrosoft 70-513 Dumps ➤ PDF & VCE
HOTMicrosoft 70-515 Dumps ➤ PDF & VCE
HOTMicrosoft 70-532 Dumps ➤ PDF & VCE
HOTMicrosoft 70-533 Dumps ➤ PDF & VCE
HOTMicrosoft 70-534 Dumps ➤ PDF & VCE
HOTMicrosoft 70-640 Dumps ➤ PDF & VCE
HOTMicrosoft 70-642 Dumps ➤ PDF & VCE
HOTMicrosoft 70-646 Dumps ➤ PDF & VCE
HOTMicrosoft 70-687 Dumps ➤ PDF & VCE
HOTMicrosoft 70-688 Dumps ➤ PDF & VCE
HOTMicrosoft 70-689 Dumps ➤ PDF & VCE
HOTMicrosoft 70-692 Dumps ➤ PDF & VCE
HOTMicrosoft 70-695 Dumps ➤ PDF & VCE
HOTMicrosoft 70-696 Dumps ➤ PDF & VCE
HOTMicrosoft 70-697 Dumps ➤ PDF & VCE
HOTMicrosoft 74-335 Dumps ➤ PDF & VCE
HOTMicrosoft 74-338 Dumps ➤ PDF & VCE
HOTMicrosoft 74-343 Dumps ➤ PDF & VCE
HOTMicrosoft 74-344 Dumps ➤ PDF & VCE
HOTMicrosoft 74-409 Dumps ➤ PDF & VCE
HOTMicrosoft 98-361 Dumps ➤ PDF & VCE
HOTMicrosoft 98-367 Dumps ➤ PDF & VCE
HOTMB2-700 Dumps ➤ PDF & VCE
HOTMB2-701 Dumps ➤ PDF & VCE
HOTMB2-702 Dumps ➤ PDF & VCE
HOTMB2-703 Dumps ➤ PDF & VCE
GetAll List Of Microsoft Dumps NOW

Hottest Cisco Exam Dumps

HOTCisco 200-120 Dumps ➤ PDF & VCE
HOTCisco 100-101 Dumps ➤ PDF & VCE
HOTCisco 200-101 Dumps ➤ PDF & VCE
HOTCisco 200-310 Dumps ➤ PDF & VCE
HOTCisco 200-355 Dumps ➤ PDF & VCE
HOTCisco 200-401 Dumps ➤ PDF & VCE
HOTCisco 210-260 Dumps ➤ PDF & VCE
HOTCisco 210-060 Dumps ➤ PDF & VCE
HOTCisco 210-065 Dumps ➤ PDF & VCE
HOTCisco 300-101 Dumps ➤ PDF & VCE
HOTCisco 300-115 Dumps ➤ PDF & VCE
HOTCisco 300-135 Dumps ➤ PDF & VCE
HOTCisco 300-206 Dumps ➤ PDF & VCE
HOTCisco 300-207 Dumps ➤ PDF & VCE
HOTCisco 300-208 Dumps ➤ PDF & VCE
HOTCisco 300-209 Dumps ➤ PDF & VCE
HOTCisco 300-070 Dumps ➤ PDF & VCE
HOTCisco 300-075 Dumps ➤ PDF & VCE
HOTCisco 300-080 Dumps ➤ PDF & VCE
HOTCisco 300-085 Dumps ➤ PDF & VCE
HOTCisco 400-101 Dumps ➤ PDF & VCE
HOTCisco 400-201 Dumps ➤ PDF & VCE
HOTCisco 400-051 Dumps ➤ PDF & VCE
HOTCisco 350-018 Dumps ➤ PDF & VCE
HOTCisco 642-035 Dumps ➤ PDF & VCE

Hottest CompTIA Exam Dumps

HOTSY0-401 Dumps ➤ PDF & VCE
HOTN10-006 Dumps ➤ PDF & VCE
HOT220-901 Dumps ➤ PDF & VCE
HOT220-902 Dumps ➤ PDF & VCE
HOTSG0-001 Dumps ➤ PDF & VCE
HOTCAS-002 Dumps ➤ PDF & VCE
HOTSK0-004 Dumps ➤ PDF & VCE

Other Hottest Exam Dumps

HOTVMware VCP550 Dumps ➤ PDF & VCE
HOTVMware VCP550D Dumps ➤ PDF & VCE
HOTVMware 1V0-601 Dumps ➤ PDF & VCE
HOTVMware 2V0-620 Dumps ➤ PDF & VCE
HOTVCP5-DCV Dumps ➤ PDF & VCE
HOTISC CISSP Dumps ➤ PDF & VCE
HOTPMI PMP Dumps ➤ PDF & VCE
HOTOracle 1Z0-051 Dumps ➤ PDF & VCE
HOTOracle 1Z0-052 Dumps ➤ PDF & VCE
HOTOracle 1Z0-060 Dumps ➤ PDF & VCE
HOTOracle 1Z0-061 Dumps ➤ PDF & VCE
HOTCitrix 1Y0-201 Dumps ➤ PDF & VCE
HOTCitrix 1Y0-301 Dumps ➤ PDF & VCE
HOTCitrix 1Y0-401 Dumps ➤ PDF & VCE
HOT312-50v9 Dumps ➤ PDF & VCE
HOTRHCSA EX200 Dumps ➤ PDF & VCE
HOTRHCE EX300 Dumps ➤ PDF & VCE

Archives

Tags

100-105 exam dumps 200-125 braindumps 200-125 exam dumps 200-125 exam question 200-125 pdf dumps 200-125 practice test 200-125 study guide 200-125 vce dumps 200-355 braindumps 200-355 exam dumps 200-355 exam question 200-355 pdf dumps 200-355 practice test 200-355 study guide 200-355 vce dumps 220-901 braindumps 220-901 exam dumps 220-901 exam question 220-901 pdf dumps 220-901 practice test 220-901 study guide 220-901 vce dumps 300-101 braindumps 300-101 exam dumps 300-101 exam question 300-101 pdf dumps 300-101 practice test 300-101 study guide 300-101 vce dumps 400-101 braindumps 400-101 exam dumps 400-101 exam question 400-101 pdf dumps 400-101 practice test 400-101 study guide 400-101 vce dumps 400-251 braindumps 400-251 exam dumps 400-251 exam question 400-251 pdf dumps 400-251 practice test 400-251 study guide 400-251 vce dumps Lead2pass 220-901 Lead2pass 400-101