351-018 CCIE Security Written Certified Practice Exam (Beta)

via Udemy

Go to Course: https://www.udemy.com/course/351-018-ccie-security-written-certified-practice-exam-beta/

Overview

Sample Questions:Based on RFC 4890, what is the ICMP type and code that should never be dropped by the firewall to allow PMTUD?ICMPv6 Type 1 Code 0 no route to hostICMPv6 Type 1 Code 1 communication with destination administratively prohibitedICMPv6 Type 2 Code 0 packet too bigICMPv6 Type 3 Code 1 fragment reassembly time exceededICMPv6 Type 128 Code 0 echo requestICMPv6 Type 129 Code 0 echo replyWhen a Cisco IOS Router receives a TCP packet with a TTL value less than or equal to 1, what will it do?Route the packet normallyDrop the packet and reply with an ICMP Type 3, Code 1 (Destination Unreachable, Host Unreachable)Drop the packet and reply with an ICMP Type 11, Code 0 (Time Exceeded, Hop Count Exceeded)Drop the packet and reply with an ICMP Type 14, Code 0 (Timestamp Reply)Which three statements are correct when comparing Mobile IPv6 and Mobile IPv4 support? (Choose three.)Mobile IPv6 does not require a foreign agent, but Mobile IPv4 does.Mobile IPv6 supports route optimization as a fundamental part of the protocol; IPv4 requires extensions.Mobile IPv6 and Mobile IPv4 use a directed broadcast approach for home agent address discovery.Mobile IPv6 makes use of its own routing header; Mobile IPv4 uses only IP encapsulation.Mobile IPv6 and Mobile IPv4 use ARP for neighbor discovery.Mobile IPv4 has adopted the use of IPv6 ND.Which two statements are correct regarding the AES encryption algorithm? (Choose two.)It is a FIPS-approved symmetric block cipher.It supports a block size of 128, 192, or 256 bits.It supports a variable length block size from 16 to 448 bits.It supports a cipher key size of 128, 192, or 256 bits.The AES encryption algorithm is based on the presumed difficulty of factoring large integers.What are two benefits of using IKEv2 instead of IKEv1 when deploying remote-access IPsec VPNs? (Choose two.)IKEv2 supports EAP authentication methods as part of the protocol.IKEv2 inherently supports NAT traversal.IKEv2 messages use random message IDs.The IKEv2 SA plus the IPsec SA can be established in six messages instead of nine messages.All IKEv2 messages are encryption-protected.Which three statements are true about MAC sec? (Choose three.)It supports GCM modes of AES and 3DES.It is defined under IEEE 802.1AE.It provides hop-by-hop encryption at Layer 2.MAC sec expects a strict order of frames to prevent anti-replay.MKA is used for session and encryption key management.It uses EAP PACs to distribute encryption keys.Which three statements are true about the SSH protocol? (Choose three.)SSH protocol runs over TCP port 23.SSH protocol provides for secure remote login and other secure network services over an insecure network.Telnet is more secure than SSH for remote terminal access.SSH protocol runs over UDP port 22.SSH transport protocol provides for authentication, key exchange, confidentiality, and integrity.SSH authentication protocol supports public key, password, host based, or none as authentication methods.

Skills

Reviews