Latest Cisco CCIE 350-018 Real Exam Download 221-230

EnsurepassQUESTION 221 Refer to the exhibit, which shows a partial configuration for the EzVPN server. Which three missing ISAKMP profile options are required to support EzVPN using DVTI? (Choose three.)     A.      match identity group B.      trustpoint C.      virtual-interface D.      keyring E.       enable udp-encapsulation F.       isakmp authorization list G.      virtual-template   Correct Answer: AFG     QUESTION 222 Which Read more [...]

Latest Cisco CCIE 350-018 Real Exam Download 210-220

EnsurepassQUESTION 211 Refer to the exhibit. Choose the correct description of the implementation that produced this output on the Cisco ASA appliance.     A.      stateful failover using active-active for multi-context B.      stateful failover using active-standby for multi-context C.      stateful failover using active-standby for single-context D.      stateless failover using interface-level failover for multi-context   Correct Answer: A     QUESTION Read more [...]

Latest Cisco CCIE 350-018 Real Exam Download 201-210

EnsurepassQUESTION 201 Which two options represent definitions that are found in the syslog protocol (RFC 5426)? (Choose two.)   A.      Syslog message transport is reliable. B.      Each syslog datagram must contain only one message. C.      IPv6 syslog receivers must be able to receive datagrams of up to 1180 bytes. D.      Syslog messages must be prioritized with an IP precedence of 7. E.       Syslog servers must use NTP for the accurate time stamping of message Read more [...]

Latest Cisco CCIE 350-018 Real Exam Download 191-200

EnsurepassQUESTION 191 Which three statements about triple DES are true? (Choose three.)   A.      For 3DES, ANSI X9.52 describes three options for the selection of the keys in a bundle, where all keys are independent. B.      A 3DES key bundle is 192 bits long. C.      A 3DES keyspace is168 bits. D.      CBC, 64-bit CFB, OFB, and CTR are modes of 3DES. E.       3DES involves encrypting a 64-bit block of plaintext with the 3 keys of the key bundle.   Correct Answer: Read more [...]

Latest Cisco CCIE 350-018 Real Exam Download 181-190

EnsurepassQUESTION 181 Which three statements are true about Cryptographically Generated Addresses for IPv6? (Choose three.)   A.      They prevent spoofing and stealing of existing IPv6 addresses. B.      They are derived by generating a random 128-bit IPv6 address based on the public key of the node. C.      They are used for securing neighbor discovery using SeND. D.      SHA or MD5 is Read more [...]

Latest Cisco CCIE 350-018 Real Exam Download 171-180

EnsurepassQUESTION 171 Which four protocols are supported by Cisco IOS Management Plane Protection? (Choose four.)   A.      Blocks Extensible Exchange Protocol (BEEP) B.      Hypertext Transfer Protocol Secure (HTTPS) C.      Secure Copy Protocol (SCP) D.      Secure File Transfer Protocol (SFTP) E.       Secure Shell (SSH) F.       Read more [...]

Latest Cisco CCIE 350-018 Real Exam Download 161-170

EnsurepassQUESTION 161 Which three statements are true about the Cisco NAC Appliance solution? (Choose three.)   A.      In a Layer 3 OOB ACL deployment of the Cisco NAC Appliance, the discovery host must be configured as the untrusted IP address of the Cisco NAC Appliance Server. B.      In a Cisco NAC Appliance deployment, the discovery host must be configured on a Cisco router using the "NAC discovery-host" global configuration Read more [...]

Latest Cisco CCIE 350-018 Real Exam Download 151-160

EnsurepassQUESTION 151 Refer to the exhibit of an ISAKMP debug. Which message of the exchange is failing?   A.      main mode 1 B.      main mode 3 C.      aggressive mode 1 D.      main mode 5 E.       aggressive mode 2   Correct Answer: B     QUESTION 152 Which Cisco IPS appliance feature can automatically adjust the Read more [...]

Latest Cisco CCIE 350-018 Real Exam Download 141-150

EnsurepassQUESTION 141 Which three statements about LDAP are true? (Choose three.)   A.      LDAP uses UDP port 389 by default. B.      LDAP is defined in terms of ASN.1 and transmitted using BER. C.      LDAP is used for accessing X.500 directory services. D.      An LDAP directory entry is uniquely identified by its DN. E.       A secure connection via TLS Read more [...]

Latest Cisco CCIE 350-018 Real Exam Download 131-140

EnsurepassQUESTION 131 Which multicast routing mechanism is optimal to support many-to-many multicast applications?   A.      PIM-SM B.      MOSPF C.      DVMRP D.      BIDIR-PIM E.       MSDP   Correct Answer: D     QUESTION 132 Which three statements regarding VLANs are true? (Choose three.)   A.      Read more [...]

Latest Cisco CCIE 350-018 Real Exam Download 121-130

EnsurepassQUESTION 121 Which two options best describe the authorization process as it relates to network access? (Choose two.)   A.      the process of identifying the validity of a certificate, and validating specific fields in the certificate against an identity store B.      the process of providing network access to the end user C.      applying enforcement controls, such as downloadable ACLs and VLAN assignment, Read more [...]

Latest Cisco CCIE 350-018 Real Exam Download 111-120

EnsurepassQUESTION 111 What type of attack consists of injecting traffic that is marked with the DSCP value of EF into the network?   A.      brute-force attack B.      QoS marking attack C.      DHCP starvation attack D.      SYN flood attack   Correct Answer: B     QUESTION 112 Which statement is true regarding Cisco ASA operations using software versions Read more [...]

Latest Cisco CCIE 350-018 Real Exam Download 101-110

EnsurepassQUESTION 101 Which three nonproprietary EAP methods do not require the use of a client-side certificate for mutual authentication? (Choose three.)   A.      LEAP B.      EAP-TLS C.      PEAP D.      EAP-TTLS E.       EAP-FAST   Correct Answer: CDE         QUESTION 102 When you compare WEP to WPA (not WPA2), which three protections are gained? (Choose three.)   A.      a message integrity check B.      AES-based encryption C.      avoidance Read more [...]

Latest Cisco CCIE 350-018 Real Exam Download 91-100

EnsurepassQUESTION 91 Which three statements are true about PIM-SM operations? (Choose three.)   A.      PIM-SM supports RP configuration using static RP, Auto-RP, or BSR. B.      PIM-SM uses a shared tree that is rooted at the multicast source. C.      Different RPs can be configured for different multicast groups to increase RP scalability. D.      Candidate RPs and RP mapping agents are configured to enable Auto-RP. E.       PIM-SM uses the implicit join model. Correct Read more [...]

Latest Cisco CCIE 350-018 Real Exam Download 81-90

EnsurepassQUESTION 81 Which of the following provides the features of route summarization, assignment of contiguous blocks of addresses, and combining routes for multiple classful networks into a single route?   A.      classless interdomain routing B.      route summarization C.      supernetting D.      private IP addressing   Correct Answer: A     QUESTION Read more [...]

Latest Cisco CCIE 350-018 Real Exam Download 71-80

EnsurepassQUESTION 71 With the Cisco FlexVPN solution, which four VPN deployments are supported? (Choose four.)   A.      site-to-site IPsec tunnels? B.      dynamic spoke-to-spoke IPSec tunnels? (partial mesh) C.      remote access from software or hardware IPsec clients? D.      distributed full mesh IPsec tunnels? E.       IPsec group encryption using GDOI? Read more [...]

Latest Cisco CCIE 350-018 Real Exam Download 61-70

EnsurepassQUESTION 61 Refer to the exhibit. Which statement best describes the problem? A.      Context vpn1 is not inservice. B.      There is no gateway that is configured under context vpn1. C.      The config has not been properly updated for context vpn1. D.      The gateway that is configured under context vpn1 is not inservice.   Correct Answer: A     Read more [...]

Latest Cisco CCIE 350-018 Real Exam Download 51-60

EnsurepassQUESTION 51 Troubleshooting the web authentication fallback feature on a Cisco Catalyst switch shows that clients with the 802.1X supplicant are able to authenticate, but clients without the supplicant are not able to use web authentication. Which configuration option will correct this issue?   A.      switch(config)# aaa accounting auth-proxy default start-stop group radius B.      switch(config-if)# authentication host-mode multi-auth Read more [...]