It is more faster and easier to pass the Cisco 350-018 exam by using Vivid Cisco CCIE Pre-Qualification Test for Security questuins and answers. Immediate access to the Most up-to-date 350-018 Exam and find the same core area 350-018 questions with professionally verified answers, then PASS your exam with a high score now.

2021 Dec 350-018 vce:

Q121. Which statement about a botnet attack is true? 

A. The botnet attack is an attack on a firewall to disable it's filtering ability. 

B. The botnet attack is a network sweeping attack to find hosts that are alive alive behind the filtering device. 

C. The botnet attack is a collection of infected computers that launch automated attacks. 

D. The owner of the infected computer willingly participates in automated attacks. 

E. The botnet attack enhances the efficiency of the computer for effective automated attacks. 

Answer:


Q122. Which two options describe how the traffic for the shared interface is classified in ASA multi context mode? (Choose two.) 

A. Traffic is classified at the source address in the packet. 

B. Traffic is classified at the destination address in the packet. 

C. Traffic is classified at the destination address in the context. 

D. Traffic is classified by copying and sending the packet to all the contexts. 

E. Traffic is classified by sending the MAC address for the shared interface. 

Answer: CE 


Q123. Refer to the exhibit, which shows a partial output of the show command. 

Which statement best describes the problem? 

A. Context vpn1 is not inservice. 

B. There is no gateway that is configured under context vpn1. 

C. The config has not been properly updated for context vpn1. 

D. The gateway that is configured under context vpn1 is not inservice. 

Answer:


Q124. Which two statements about dynamic ARP inspection are true? (Choose two.) 

A. Dynamic ARP inspection checks ARP packets on both trusted and untrusted ports. 

B. Dynamic ARP inspection is only supported on access and trunk ports. 

C. Dynamic ARP inspection checks invalid ARP packets against the trusted database. 

D. The trusted database to check for an invalid ARP packet is manually configured. 

E. Dynamic ARP inspection does not perform ingress security checking. 

F. DHCP snooping must be enabled. 

Answer: CF 


Q125. Which two statements about SNMP are true? (Choose two) 

A. SNMP operates at Layer-6 of the OSI model. 

B. NMS sends a request to the agent at TCP port 161. 

C. NMS sends request to the agent from any source port. 

D. NMS receives notifications from the agent on UDP 162. 

E. MIB is a hierarchical representation of management data on NMS. 

Answer: CD 


Up to the immediate present ccie security written 350-018:

Q126. Which statement is true regarding Cisco ASA operations using software versions 8.3 and later? 

A. The global access list is matched first before the interface access lists. 

B. Both the interface and global access lists can be applied in the input or output direction. 

C. When creating an access list entry using the Cisco ASDM Add Access Rule window, choosing "global" as the interface will apply the access list entry globally. 

D. NAT control is enabled by default. 

E. The static CLI command is used to configure static NAT translation rules. 

Answer:


Q127. Refer to the exhibit. 

Which route will be advertised by the Cisco ASA to its OSPF neighbors? 

A. 10.39.23.0/24 

B. 10.40.29.0/24 

C. 10.66.42.215/32 

D. 10.40.29.0/24 

Answer:


Q128. Which three statements regarding ISO 27002 and COBIT are correct? (Choose three.) 

A. COBIT and ISO 27002 both define a best practices framework for IT controls. 

B. COBIT focuses on information system processes, whereas ISO 27002 focuses on the security of the information systems. 

C. ISO 27002 addresses control objectives, whereas COBIT addresses information security management process requirements. 

D. Compared to COBIT, ISO 27002 covers a broader area in planning, operations, delivery, support, maintenance, and IT governance. 

E. Unlike COBIT, ISO 27002 is used mainly by the IT audit community to demonstrate risk mitigation and avoidance mechanisms. 

Answer: ABC 


Q129. Which two pieces of information are communicated by the ASA failover link? (Choose two.) 

A. unit state 

B. connections State 

C. routing tables 

D. power status 

E. MAC address exchange 

Answer: AE 


Q130. Which two statements about VTP passwords are true? (Choose two) 

A. The VTP password can only be configured when the switch is in Server mode. 

B. The VTP password is sent in the summary advertisements.. 

C. The VTP password is encrypted for confidentiality using 3DES. 

D. VTP is not required to be configured on all switches in the domain. 

E. The VTP password is hashed to preserve authenticity using the MD5 algorithm. 

F. The VTP password can only be configured when the switch is in Client mode. 

Answer: BE