210-260 Exam - IINS Implementing Cisco Network Security

certleader.com

P.S. Best Quality 210-260 bible are available on Google Drive, GET MORE: https://drive.google.com/open?id=15Wj8GqxvfYTz0nGHdJkfV_zMadDrezid


New Cisco 210-260 Exam Dumps Collection (Question 6 - Question 15)

Question No: 6

How does a device on a network using ISE receive its digital certificate during the new- device registration process?

A. ISE acts as a SCEP proxy to enable the device to receive a certificate from a central CA server.

B. ISE issues a certificate from its internal CA server.

C. ISE issues a pre-defined certificate from a local database.

D. The device requests a new certificate directly from a central CA.

Answer: A


Question No: 7

What is the purpose of a honeypot IPS?

A. To create customized policies

B. To detect unknown attacks

C. To normalize streams

D. To collect information about attacks

Answer: D


Question No: 8

How does a zone paid handle traffic if the policy definition of the zone pair is missing?

A. It permits all traffic without logging.

B. it drops all traffic

C. it permits and logs all traffic

D. it inspects all traffic

Answer: B


Question No: 9

Which two features do CoPP and CPPr use to protect the control plane? (Choose two.)

A. QoS

B. traffic classification

C. access lists

D. policy maps

E. class maps

F. Cisco Express Forwarding

Answer: A,B


Question No: 10

Which option is the default value for the Diffieu2013Hellman group when configuring a site-to- site VPN on an ASA device?

A. Group 1

B. Group 2

C. Group 5

D. Group 7

Answer: B


Question No: 11

Refer to the exhibit.

While troubleshooting site-to-site VPN, you issued the show crypto isakmp sa command. What does the given output show?

A. IKE Phase 1 main mode was created on 10.1.1.5, but it failed to negotiate with 10.10.10.2.

B. IKE Phase 1 main mode has successfully negotiated between 10.1.1.5 and 10.10.10.2.

C. IKE Phase 1 aggressive mode was created on 10.1.1.5, but it failed to negotiate with 10.10.10.2.

D. IKE Phase 1 aggressive mode has successfully negotiated between 10.1.1.5 and 10.10.10.2.

Answer: A


Question No: 12

Which type of firewall can serve as the intermediary between a client and a server?

A. Application firewall

B. stateless firewall

C. Personal firewall

D. Proxy firewall

Answer: D

Explanation: http://searchsecurity.techtarget.com/definition/proxy-firewall


Question No: 13

When a switch has multiple links connected to a downstream switch, what is the first step that STP takes to prevent loops?

A. STP elects the root bridge

B. STP selects the root port

C. STP selects the designated port

D. STP blocks one of the ports

Answer: A


Question No: 14

When is the best time to perform an anti-virus signature update?

A. Every time a new update is available.

B. When the local scanner has detected a new virus.

C. When a new virus is discovered in the wild.

D. When the system detects a browser hook.

Answer: A


Question No: 15

Which type of address translation should be used when a Cisco ASA is in transparent mode?

A. Static NAT

B. Dynamic NAT

C. Overload

D. Dynamic PAT

Answer: A


Recommend!! Get the Best Quality 210-260 dumps in VCE and PDF From Dumpscollection, Welcome to download: http://www.dumpscollection.net/dumps/210-260/ (New 310 Q&As Version)