[Full Version] 100% New Updated 400-251 New Questions Lead2pass Helps Pass 400-251 Successfully (121-140)

2017 February Cisco Official New Released 400-251 Dumps in Lead2pass.com!

100% Free Download! 100% Pass Guaranteed!

Lead2pass provides 100% pass 400-251 exam questions and answers for your Cisco 400-251 exam. We provide Cisco 400-251 exam questions from Lead2pass dumps and answers for the training of 400-251 practice test.

Following questions and answers are all new published by Cisco Official Exam Center: http://www.lead2pass.com/400-251.html

The computer at on your network has been infected by a botnet that directs traffic to a malware site at Assuming that filtering will be performed on a Cisco ASA.
What command can you use to block all current and future connections from the infected host?

A.    ip access-list extended BLOCK_BOT_OUT deny ip any host
B.    shun 6000 80
C.    ip access-list extended BLOCK_BOT_OUT deny ip host host
D.    ip access-list extended BLOCK_BOT_OUT deny ip host host
E.    shun 6000 80

Answer: C

IKEv2 provide greater network attack resiliency against a DoS attack than IKEv1 by utilizing which two functionalities?(Choose two)

A.    with cookie challenge IKEv2 does not track the state of the initiator until the initiator respond with cookie.
B.    Ikev2 perform TCP intercept on all secure connections
C.    IKEv2 only allows symmetric keys for peer authentication
D.    IKEv2 interoperates with IKEv1 to increase security in IKEv1
E.    IKEv2 only allows certificates for peer authentication
F.    An IKEv2 responder does not initiate a DH exchange until the initiator responds with a cookie

Answer: AF

Which five of these are criteria for rule-based rogue classification of access points by the cisco Wireless LAN controller? (Choose five)

A.    MAC address range
B.    MAC address range number of clients it has
C.    open authentication
D.    whether it matches a user-configured SSID
E.    whether it operates on an authorized channel
F.    minimum RSSI
G.    time of day the rogue operates
H.    Whether it matches a managed AP SSID

Answer: BCDFH

Which two statement about the DES algorithm are true?(Choose two)

A.    It uses a 64-bit key block size and its effective key length is 65 bits
B.    It uses a 64-bits key block size and its effective key length is 56 bits
C.    It is a stream cripher that can be used with any size input
D.    It is more efficient in software implements than hardware implementations.
E.    It is vulnerable to differential and linear cryptanalysis
F.    It is resistant to square attacks

Answer: BE

Which three types of addresses can the Botnet Traffic Filter feature of the Cisco ASA monitor? (Choose three)



A.    Ambiguous addresses
B.    Known malware addresses
C.    Listed addresses
D.    Dynamic addresses
E.    Internal addresses
F.    Known allowed addresses

Answer: ABF

Which Three statement about cisco IPS manager express are true? (Choose three)

A.    It provides a customizable view of events statistics.
B.    It Can provision policies based on risk rating.
C.    It Can provision policies based on signatures.
D.    It Can provision policies based on IP addresses and ports.
E.    It uses vulnerability-focused signature to protect against zero-day attacks.
F.    It supports up to 10 sensors.

Answer: ABF

In Cisco Wireless LAN Controller (WLC. which web policy enables failed Layer 2 authentication to fall back to WebAuth authentication with a user name and password?

A.    On MAC Filter Failure
B.    Pass through
C.    Splash Page Web Redirect
D.    Conditional Web Redirect
E.    Authentication

Answer: A

Drag and Drop Question
Drag and drop each syslog facility code on the left onto its description on the right.




Refer to the exhibit. What is the effect of the given configuration?


A.    It reset and logs FTP connection to all sites except cisco.com and hp.com.
B.    FTP connections are unaffected.
C.    It resets FTP connection to all sites except cisco.com and hp.com.
D.    It resets and logs FTP connection to cisco.com and hp.com only.
E.    It resets FPT connection to cisco.com and hp.com only

Answer: A

What port has IANA assigned to the GDOI protocol ?

A.    UDP 4500
B.    UDP 1812
C.    UDP 500
D.    UDP 848

Answer: D

Refer to the exhibit, after you implement ingress filter 101 to deny all icmp traffic on your perimeter router user complained of poor web performance and the router and the router display increase CPU load. The debug ipicmp command returned the given output.
Which configuration you make to the router configuration to correct the problem?



Answer: D

Which two statements about implementing GDOI in a DMVPN network are true?(Choose true)

A.    Direct spoke-to-spoke traffic is black-holed.
B.    Rekeying requires an exclusive IGMP join in the mGRE interface
C.    The crypto map is applied to the sub interface of each spoke.
D.    If a group member rekey operation fails, it must wait for the SA lifetime to expire before it can reregister with the key server.
E.    The DMVPN hub can act as the GDOI key server.
F.    DMVPN spokes with tunnel protection allow traffic to be encrypted to the hub

Answer: DE

For which two reasons BVI is required in the Transparent Cisco IOS Firewall? (Choose two)

A.    BVI is required for the inspection of IP traffic.
B.    The firewall can perform routing on bridged interfaces.
C.    BVI is required if routing is disabled on the firewall.
D.    BVI is required if more than two interfaces are in a bridge group.
E.    BVI is required for the inspection of non-IP traffic.
F.    BVI can manage the device without having an interface that is configured for routing.

Answer: DF

Drag and Drop Question
Drag each step in the configuration of a cisco ASA NSEL export to a NETFLOW collector on the left into the correct order of operations on the right.




Which two u.s government entities are authorized to execute and enforce the penalties for violations of the Sarbanes-oxley(SOX) act? (Choose two)

A.    Federal trade commission (FTC.
B.    internal Revenue service (IRS)
C.    Office of Civil Rights (OCR)
D.    federal reserve board
E.    Securities and exchange commission (SEC.
F.    United states Citizenship and immigration services (USCIS)

Answer: DE

MWhich three are RFC 5735 addresses? (Choose three.)


Answer: BCE

Refer to the exhibit . Which Statement about this configuration is true?


A.    The ASA stops LSA type 7 packets from flooding into OSPF area 1.
B.    The ASA injects a static default route into OSPF area 1.
C.    The ASA redistributes routes from one OSPF process to another.
D.    The ASA redistributes routes from one routing protocol to another.
E.    The ASA injects a static default route into OSPF process 1.

Answer: C

Drag and Drop Question
Drag and drop step in the flow of packets on a DMVPN network using GDOI on the left into the correct sequence on the right




When attempting to use basic Http authentication to authenticate a client,which type of HTTP massage should the server use?

A.    HTTP 200 with a WWW-authenticate header.
B.    HTTP 401 with a WWW-authenticate header.
C.    Http 302 with an authenticate header.
D.    HTTP 407.

Answer: B

Drag and Drop Question
Drag and Drop each Cisco Intrusion Prevention System anomaly detection event action on the left onto the matching description on the right.




Lead2pass is the leader in 400-251 certification test questions with training materials for Cisco 400-251 exam dumps. Lead2pass Cisco training tools are constantly being revised and updated. We 100% guarantee Cisco 400-251 exam questions with quality and reliability which will help you pass Cisco 400-251 exam.

400-251 new questions on Google Drive: https://drive.google.com/open?id=0B3Syig5i8gpDbkNSWnpMam9TWWM

2017 Cisco 400-251 exam dumps (All 336 Q&As) from Lead2pass:

http://www.lead2pass.com/400-251.html [100% Exam Pass Guaranteed]


Why Choose Lead2pass?

If you want to pass the exam successfully in first attempt you have to choose the best IT study material provider, in my opinion, Lead2pass is one of the best way to prepare for the exam.

Lead2pass Testking Pass4sure Actualtests Others
$99.99 $124.99 $125.99 $189 $29.99-$49.99
Real Questions
Error Correction
Printable PDF
Premium VCE
VCE Simulator
One Time Purchase
Instant Download
Unlimited Install
100% Pass Guarantee
100% Money Back