350-018 Exam
CCIE Pre-Qualification Test for Security
- Exam Number/Code : 350-018
- Exam Name : CCIE Pre-Qualification Test for Security
- Questions and Answers : 199 Q&As
- Update Time: 2010-08-26
- Price:
$ 102.00$ 60.00
Free 350-018 Demo Download
Hiexam offers free demo for CCIE 350-018 exam (CCIE Pre-Qualification Test for Security). You can check out the interface, question quality and usability of our practice exams before you decide to buy it. We are the only one site can offer demo for almost all products.
Download 350-018 Exam Testing Engine
Exam Description
Why choose Hiexam 350-018 braindumps
Quality and Value for the 350-018 Exam
100% Guarantee to Pass Your 350-018 Exam
Downloadable, Interactive 350-018 Testing engines
Verified Answers Researched by Industry Experts
Drag and Drop questions as experienced in the Actual Exams
Practice Test Questions accompanied by exhibits
Our Practice Test Questions are backed by our 100% MONEY BACK GUARANTEE.
Hiexam 350-018 Exam Features
- Covers the entire recommended syllabus
- Comprehensive questions and answers about 350-018 exam
- Verified Answers Researched by Industry Experts and almost 100% correct
- 350-018 exam questions updated on regular basis
- Same type as the certification exams, 350-018 exam preparation is in multiple-choice questions (MCQs)
- Tested by multiple times before publishing
- Try free 350-018 exam demo before you decide to buy it in Hiexam
- Technical support through Live Chat or Email
Exam : Cisco 350-018
Title : CCIE Security Qualification Exam
1. When initiating a new SSL/TLS session, the client receives the server SSL certificate and validates it. What does the client use the certificate for after validating it?
A. The client and server use the key in the certificate to encrypt all data in the following SSL session.
B. The server creates a separate session key and sends it to the client. The client has to decrypt the session key using the server public key from the certificate.
C. The client creates a separate session key and encrypts it with the server public key from the certificate before sending it to the server.
D. Nothing, the client and server switch to symmetric encryption using IKE to exchange keys.
E. The client generates a random string, encrypts it with the server public key from the certificate, and sends it to the server. Both the client and server derive the session key from the random data sent by the client.
Answer: E
2. A firewall administrator received this syslog message from his adaptive security appliance. What can the firewall administrator infer from the message?
A. The server at 209.165.201.10 is under a smurf attack.
B. The server at 10.1.1.20 is under a SYN attack.
C. The client at 209.165.201.10 has been infected with a virus.
D. The server at 10.1.1.20 is under a smurf attack.
Answer: B
3. In regards to private address space, which three of the following statements are true? (Choose three.)
A. Private address space is defined in RFC 1918.
B. These IP addresses are considered private:
10.0.0.0
172.15.0.0
192.168.0.0
C. Private address space is not supposed to be routed over the Internet.
D. 127.0.0.1 is also considered part of private address space, according to the RFC.
E. Using only private address space and NAT to the Internet is not considered as secure as having a stateful firewall.
Answer: ACE
4. Which three of these statements describe how DNSSEC prevents DNS cache poisoning attacks from succeeding? (Choose three.)
A. DNSSEC encrypts all records with domain-specific keys.
B. DNSSEC eliminates caching and forces all answers to be authoritative.
C. DNSSEC introduces KEY records that hold domain-specific public keys.
D. DNSSEC deprecates CNAME records and replaces them with DS records.
E. DNSSEC utilizes DS records to establish a trusted hierarchy of zones.
F. DNSSEC signs all records with domain-specific keys.
Answer: CEF
5. When using Cisco SDM to manage a Cisco IOS device, what configuration statements are necessary to be able to use Cisco SDM?
A. ip http server
B. ip http secure-server
C. ip http server
sdm location X.X.X.X
D. ip http secure-server
sdm location X.X.X.X
E. ip http server
ip http secure-server
Answer: A
6. Which two of the following statements describe why TACACS+ is more desirable from a security standpoint than RADIUS? (Choose two.)
A. It uses UDP as its transport.
B. It uses TCP as its transport.
C. It encrypts the password field with a unique key between server and requester.
D. Encrypting the whole data payload is optional.
E. Authentication and authorization are combined into a single query for robustness.
Answer: BD
http://www.Hiexam.com The safer.easier way to get CCIE Certification.


Feedbacks
Hiexam 350-018 exam information is accurate, it covers most of the content of 350-018 exam. My first hope is go to Hiexam, I believe it. With the help of Hiexam, I have no difficulty in the next 350-018 exam.
Augustine - 2010-06-09 17:18:59I have heard that Hiexam is one of the best sites which provides exam dumps, so I come to see it. After having a look, I think I could get some 350-018 information. Thank you.
George - 2010-09-03 16:26:30