Cisco® 400-251 Exam Practice Questions (P. 5)
- Full Access (952 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #41
Troubleshooting the web authentication fallback feature on a Cisco Catalyst switch shows that clients with the 802.1X supplicant are able to authenticate, but clients without the supplicant are not able to use web authentication. Which configuration option will correct this issue?
- Aswitch(config)# aaa accounting auth-proxy default start-stop group radius
- Bswitch(config-if)# authentication host-mode multi-auth
- Cswitch(config-if)# webauth
- Dswitch(config)# ip http server
- Eswitch(config-if)# authentication priority webauth dot1x
Correct Answer:
D
D
send
light_mode
delete
Question #42
Which option on the Cisco ASA appliance must be enabled when implementing botnet traffic filtering?
- AHTTP inspection
- Bstatic entries in the botnet blacklist and whitelist
- Cglobal ACL
- DNetFlow
- EDNS inspection and DNS snooping
Correct Answer:
E
E
send
light_mode
delete
Question #43
Refer to the exhibit.

Which statement about this Cisco Catalyst switch 802.1X configuration is true?

Which statement about this Cisco Catalyst switch 802.1X configuration is true?
- AIf an IP phone behind the switch port has an 802.1X supplicant, MAC address bypass will still be used to authenticate the IP Phone.
- BIf an IP phone behind the switch port has an 802.1X supplicant, 802.1X authentication will be used to authenticate the IP phone.
- CThe authentication host-mode multi-domain command enables the PC connected behind the IP phone to bypass 802.1X authentication.
- DUsing the authentication host-mode multi-domain command will allow up to eight PCs connected behind the IP phone via a hub to be individually authentication
Correct Answer:
B
B
send
light_mode
delete
Question #44
Which signature engine is used to create a custom IPS signature on a Cisco IPS appliance that triggers when a vulnerable web application identified by the "/ runscript.php" URI is run?
send
light_mode
delete
Question #45
The ASA can be configured to drop IPv6 headers with routing-type 0 using the MPF. Choose the correct configuration.
- Apolicy-map type inspect ipv6 IPv6_PMAP match header routing-type eq 0 drop log
- Bpolicy-map type inspect icmpv6 ICMPv6_PMAP match header routing-type eq 0 drop log
- Cpolicy-map type inspect ipv6-header HEADER_PMAP match header routing-type eq 0 drop log
- Dpolicy-map type inspect http HEADER_PMAP match routing-header 0 drop log
- Epolicy-map type inspect ipv6 IPv6_PMAP match header type 0 drop log
- Fpolicy-map type inspect ipv6-header HEADER_PMAP match header type 0
Correct Answer:
A
A
send
light_mode
delete
Question #46

With the client protected by the firewall, an HTTP connection from the client to the server on TCP port 80 will be subject to which action?
- Ainspection action by the HTTP_CMAP
- Binspection action by the TCP_CMAP
- Cdrop action by the default class
- Dinspection action by both the HTTP_CMAP and TCP_CMAP
- Epass action by the HTTP_CMAP
- Fdrop action due to class-map misclassification
Correct Answer:
B
B
send
light_mode
delete
Question #47

Which route will be advertised by the Cisco ASA to its OSPF neighbors?
send
light_mode
delete
Question #48
Which three options can be configured within the definition of a network object, as introduced in Cisco ASA version 8.3(1)? (Choose three.)
- Arange of IP addresses
- Bsubnet of IP addresses
- Cdestination IP NAT translation
- Dsource IP NAT translation
- Esource and destination FQDNs
- Fport and protocol ranges
Correct Answer:
ABD
ABD
send
light_mode
delete
Question #49
Regarding VSAs, which statement is true?
- AVSAs may be implemented on any RADIUS server.
- BVSAs are proprietary, and therefore may only be used on the RADIUS server of that vendor. For example, a Cisco VSA may only be used on a Cisco RADIUS server, such as ACS or ISE.
- CVSAs do not apply to RADIUS; they are a TACACS attribute.
- DEach VSA is defined in an RFC and is considered to be a standard.
Correct Answer:
A
A
send
light_mode
delete
Question #50
Which four items may be checked via a Cisco NAC Agent posture assessment? (Choose four.)
- AMicrosoft Windows registry keys
- Bthe existence of specific processes in memory
- Cthe UUID of an Apple iPad or iPhone
- Dif a service is started on a Windows host
- Ethe HTTP User-Agent string of a device
- Fif an Apple iPad or iPhone has been "jail-broken"
- Gif an antivirus application is installed on an Apple MacBook
Correct Answer:
ABDG
ABDG
send
light_mode
delete
All Pages