QUESTION 151
Which four IPv6 messages should be allowed to transit a transparent firewall? (Choose four.)
A. router solicitation with hop limit = 1
B. router advertisement with hop limit = 1
C. neighbor solicitation with hop limit = 255
D. neighbor advertisement with hop limit = 255
E. listener query with link-local source address
F. listener report with link-local source address
Answer: CDEF
QUESTION 152
Which Cisco IPS appliance feature can automatically adjust the risk rating of IPS events based on the reputation of the attacker?
A. botnet traffic filter
B. event action rules
C. anomaly detection
D. reputation filtering
E. global correlation inspection
Answer: E
QUESTION 153
If an administrator is unable to connect to a Cisco ASA adaptive security appliance via Cisco ASDM, all of these would be useful for the administrator to check except which one?
A. The HTTP server is enabled.
B. The administrator IP is permitted in the interface ACL.
C. The administrator IP is permitted in the HTTP statement.
D. The ASDM file resides on flash memory.
E. The asdm image command exists in the configuration.
Answer: B
QUESTION 154
A Cisc
o ASA adaptive security appliance configured in multiple context mode supports which three of these features? (Choose three.)
A. VPN
B. NAT
C. IPv6 traffic filtering
D. multicast
E. failover
Answer: BCE
QUESTION 155
Low and slow reconnaissance scans used to gain information about a system to see if it is vulnerable to an attack can be stopped with which of the following Cisco products?
A. ASA syn protection
B. ASA ICMP application inspection
C. CSA quarantine lists
D. IPS syn attack signatures
E. Cisco Guard
Answer: C
QUESTION 156
Which three statements regarding Cisco ASA multicast routing support are correct? (Choose three.)
A. The ASA supports both PIM-SM and bi-directional PIM.
B. When configured for stub multicast routing, the ASA can act as the Rendezvous Point (RP)
C. The ASA can be configured for IGMP snooping to constrain the flooding of multicast traffic by
dynamically configuring the multicast traffic to be forwarded only those interfaces associated with
hosts requesting the multicast group.
D. Enabling multicast routing globally on the ASA automatically enables PIM and IGMP on all interfaces.
E. ASA supports both stub multicast routing and PIM multicast routing. However, you cannot configure
both concurrently on a single security appliance.
F. If the ASA detects IGMP version 1 routers, the ASA will automatically switch to IGMP version 1 operations.
Answer: ADE
QUESTION 157
Whenever a failover takes place on the ASA running in failover mode, all active connections are dropped and clients must re-establish their connections unless
A. the ASA is configured for Active-Active failover
B. the ASA is configured for LAN-Based failover
C. the ASA is configured to use a serial cable as the failover link
D. the ASA is configured for Active-Standby failover and a state failover link has been configured
E. the ASA is configured for Active-Active failover and a state failover link has been configured
F. the ASA is configured for Active-Standby failover
Answer: DE
QUESTION 158
You run the show ipv6 port-map telnet command and you see that the port 23 (system-defined) message and the port 223 (user-defined) message are displayed. Which command is in the router configuration?
A. ipv6 port-map port telnet 223
B. ipv6 port-map port 23 port 23223
C. ipv6 port-map telnet port 23 233
D. ipv6 port-map telnet port 223
Answer: D
QUESTION 159
Which statement in reference to IPv6 multicast is true?
A. PIM dense mode is not part of IPv6 multicast.
B. The first 12 bits of an IPv6 multicast address are always FF.
C. IPv6 multicast uses Multicast Listener Discovery (MLD).
D. IPv6 multicast requires Multicast Source Discovery Protocol (MSDP).
Answer: C
QUESTION 160
What does qos pre-classify provides in regard to implementing QoS over GRE/IPSec VPN tunnels?
A. enables IOS to make a copy of the inner (original) IP header and to run a QoS classification before
encryption, based on fields in the inner IP header.
B. enables IOS to classify packets based on the ToS field in the inner (original) IP header.
C. enables IOS to classify packets based on the ToS field in the outer tunnel IP header.
D. enables IOS to copy the ToS field from the inner (original) IP header to the outer tunel IP header.
E. enables the IOS classification engine to only see a single encrypted and tunneled flow to reduce
classification complexity.
Answer: A
If you want to pass the Cisco 350-018 Exam sucessfully, recommend to read latest Cisco 350-018 Dumpfull version.