350-018 CCIE Security Written Exam (Exam 2)

created by Fisher BRink (@fisher) at Feb. 8, 2016
  • What is the main reason for using the "ip ips deny-action ips-interface" IOS command?

  • How can Netflow be used to help identify a day-zero scanning worm?

  • Which type of attacks can be monitored and mitigated by CS-MARS using NetFlow data?

  • Which Cisco security software product mitigates Day Zero attacks on desktops and s...

  • Referring to the network diagram and the R1 router configurations shown in the exh...

  • Refer to the exhibit. In the sample configuration file what does the ip verify uni...

  • The following is an example of an IPSec error message:IPSEC(validat_proposal): inv...

  • Which RFCs are used to establish internet connectivity from a private office with ...

  • Since HTTP is one of the most common protocols used in the internet, what should b...

  • Referring to the ASDM screen shot shown in the exhibit, which of the following tra...

  • Which statement is true about SYN cookies?

  • Refer to the Exhibit. Which of the following R1 router configurations will correct...

  • Asymmetric and symmetric ciphers differ in which of the following way(s)?

  • When enrolling a Cisco IOS router to a CA server using the SCEP protocol, which on...

  • RFC 2827 ingress filtering is used to help prevent which type of attacks?

  • The following ip protocols and ports are commonly used in IPSec protocols.

  • Refer to the Exhibit. Router R1 is stuck in 2-WAY state with neighbors R2 and R3. ...

  • Referring to the network diagram and the partial router's configuration shown, whi...

  • What is the function of the switch(config-if)# switchport port-security mac-addres...

  • Which statement below is true about the command "nat control" on the ASA?

