210-260 Exam - IINS Implementing Cisco Network Security

certleader.com

P.S. Virtual 210-260 forum are available on Google Drive, GET MORE: https://drive.google.com/open?id=1vkyWuCceSS4_Yw83isWjMHMxw-tsQUcW


New Cisco 210-260 Exam Dumps Collection (Question 8 - Question 17)

Question No: 8

How can the administrator enable permanent client installation in a Cisco AnyConnect VPN firewall configuration?

A. Issue the command anyconnect keep-installer under the group policy or username webvpn mode

B. Issue the command anyconnect keep-installer installed in the global configuration

C. Issue the command anyconnect keep-installer installed under the group policy or username webvpn mode

D. Issue the command anyconnect keep-installer installer under the group policy or username webvpn mode

Answer: C


Question No: 9

The Oakley cryptography protocol is compatible with following for managing security?

A. IPSec

B. ISAKMP

Answer: B


Question No: 10

What is the effect of the send-lifetime local 23:59:00 31 December 31 2013 infinite command?

A. It configures the device to begin transmitting the authentication key to other devices at 00:00:00 local time on January 1, 2014 and continue using the key indefinitely.

B. It configures the device to begin transmitting the authentication key to other devices at 23:59:00 local time on December 31, 2013 and continue using the key indefinitely.

C. It configures the device to begin accepting the authentication key from other devices immediately and stop accepting the key at 23:59:00 local time on December 31, 2013.

D. It configures the device to generate a new authentication key and transmit it to other devices at 23:59:00 local time on December 31, 2013.

E. It configures the device to begin accepting the authentication key from other devices at 23:59:00 local time on December 31, 2013 and continue accepting the key indefinitely.

F. It configures the device to begin accepting the authentication key from other devices at 00:00:00 local time on January 1, 2014 and continue accepting the key indefinitely.

Answer: B


Question No: 11

Which line in the following OSPF configuration will not be required for MD5 authentication to work?

interface GigabitEthernet0/1

ip address 192.168.10.1 255.255.255.0

ip ospf authentication message-digest

ip ospf message-digest-key 1 md5 CCNA

!

router ospf 65000

router-id 192.168.10.1

area 20 authentication message-digest network 10.1.1.0 0.0.0.255 area 10

network 192.168.10.0 0.0.0.255 area 0

!

A. ip ospf authentication message-digest

B. network 192.168.10.0 0.0.0.255 area 0

C. area 20 authentication message-digest

D. ip ospf message-digest-key 1 md5 CCNA

Answer: C


Question No: 12

Which option is a characteristic of the RADIUS protocol?

A. uses TCP

B. offers multiprotocol support

C. combines authentication and authorization in one process

D. supports bi-directional challenge

Answer: C

Explanation:

http://www.cisco.com/en/US/tech/tk59/technologies_tech_note09186a0080094e99.shtml Authentication and Authorization

RADIUS combines authentication and authorization. The access-accept packets sent by the RADIUS server to the client contain authorization information. This makes it difficult to decouple authentication and authorization.

TACACS+ uses the AAA architecture, which separates AAA. This allows separate authentication solutions that can still use TACACS+ for authorization and accounting. For example, with TACACS+, it is possible to use Kerberos authentication and TACACS+ authorization and accounting. After a NAS authenticates on a Kerberos server, it requests authorization information from a TACACS+ server without having to re-authenticate. The NAS informs the TACACS+ server that it has successfully authenticated on a Kerberos server, and the server then provides authorization information.

During a session, if additional authorization checking is needed, the access server checks with a TACACS+ server to determine if the user is granted permission to use a particular command. This provides greater control over the commands that can be executed on the access server while decoupling from the authentication mechanism.


Question No: 13

What are two options for running Cisco SDM? (Choose two)

A. Running SDM from a mobile device.

B. Running SDM from a routeru2021s flash.

C. Running SDM from a PC

D. Running SDM from within CiscoWorks

E. Running SDM from the Cisco web portal.

Answer: C,E


Question No: 14

If a router configuration includes the line aaa authentication login default group tacacs+ enable, which events will occur when the TACACS+ server returns an error? (Choose two.)

A. The user will be prompted to authenticate using the enable password

B. Authentication attempts to the router will be denied

C. Authentication will use the router`s local database

D. Authentication attempts will be sent to the TACACS+ server

Answer: A,B


Question No: 15

Which option is the most effective placement of an IPS device within the infrastructure?

A. Inline, behind the internet router and firewall

B. Inline, before the internet router and firewall

C. Promiscuously, after the Internet router and before the firewall

D. Promiscuously, before the Internet router and the firewall

Answer: A


Question No: 16

If a switch port goes directly into a blocked state only when a superior BPDU is received, what mechanism must be in use?

A. STP BPDU guard

B. loop guard

C. STP Root guard

D. EtherChannel guard

Answer: A


Question No: 17

Refer to the exhibit.

You have configured R1 and R2 as shown, but the routers are unable to establish a site-to- site VPN tunnel. What action can you take to correct the problem?

A. Edit the crypto keys on R1 and R2 to match.

B. Edit the ISAKMP policy sequence numbers on R1 and R2 to match.

C. Set a valid value for the crypto key lifetime on each router.

D. Edit the crypto isakmp key command on each router with the address value of its own interface.

Answer: A


100% Far out Cisco 210-260 Questions & Answers shared by Surepassexam, Get HERE: https://www.surepassexam.com/210-260-exam-dumps.html (New 310 Q&As)