we provide Download Cisco 400-251 exam answers which are the best for clearing 400-251 test, and to get certified by Cisco CCIE Security Written Exam. The 400-251 Questions & Answers covers all the knowledge points of the real 400-251 exam. Crack your Cisco 400-251 Exam with latest dumps, guaranteed!


2026 New 400-251 Exam Dumps with PDF and VCE Free: https://www.surepassexam.com/400-251-exam-dumps.html

Q1. Which two statements about the 3DES encryption protocol are true?(Choose two)

A. It can operate in the Electronic Code Book and Asymmetric Block Chaining modes.

B. Its effective key length is 168 bits.

C. It encrypts and decrypts data in three 64-bit blocks with an overall key length of 192 bits.

D. The algorithm is most efficient when it is implemented in software instead of hardware.

E. It encrypts and decrypts data in three 56-bit blocks with an overall key length of 168 bits.

F. Its effective key length is 112 bits.

Answer: E,F

Q2. Refer to the exhibit 

which two statement about the given IPV6 ZBF configuration are true? (Choose two)

A. It provides backward compability with legacy IPv6 inspection

B. It inspect TCP, UDP,ICMP and FTP traffic from Z1 to Z2.

C. It inspect TCP, UDP,ICMP and FTP traffic from Z2 to Z1.

D. It inspect TCP,UDP,ICMP and FTP traffic in both direction between z1 and z2.

E. It passes TCP, UDP,ICMP and FTP traffic from z1 to z2.

F. It provide backward compatibility with legacy IPv4 inseption.

Answer: A,B

Q3. Which of the following Cisco IPS signature engine has relatively high memory usage ?

A. The STRING-TCP engine

B. The STRING-UDP engine

C. The NORMALIZER engine

D. The STRING-ICMP engine

Answer: C

Q4. Which Three statement about cisco IPS manager express are true? (Choose three)

A. It provides a customizable view of events statistics.

B. It Can provision policies based on risk rating.

C. It Can provision policies based on signatures.

D. It Can provision policies based on IP addresses and ports.

E. It uses vulnerability-focused signature to protect against zero-day attacks.

F. It supports up to 10 sensors.

Answer: A,B,F

Q5. Which two statements about NAT-PT with IPv6 are true?(choose twp)

A. It can be configured as dynamic, static, or PAT.

B. It provides end-to-end security.

C. It supports IPv6 BVI configurations.

D. It provides support for Cisco Express Forwarding.

E. It provides ALG support for ICMP and DNS.

F. The router can be a single point of failure on the network.

Answer: A,E

Q6. According ISO27001 ISMS, which of the following are mandatory documents? (Choose 4)

A. ISMS Policy

B. Corrective Action Procedure

C. IS Procedures

D. Risk Assessment Reports

E. Complete Inventory of all information assets

Answer: A,B,C,D

Q7. Which statement about ICMPv6 filtering is true? 

A)

B)

C)

D)

E)

F)

A. Option A

B. Option B

C. Option C

D. Option D

Answer: B

Q8. Which two statements about the ISO are true? (Choose two)

A. The ISO is a government-based organization.

B. The ISO has three membership categories: member, correspondent, and subscribers.

C. Only member bodies have voting rights.

D. Correspondent bodies are small countries with their own standards organization.

E. Subscriber members are individual organizations.

Answer: B,C

Q9. Which of the following statement is true about the ARP attack?

A. Attackers sends the ARP request with the MAC address and IP address of a legitimate resource in the network.

B. Attackers sends the ARP request with the MAC address and IP address of its own.

C. ARP spoofing does not facilitate man-in-the middle attack of the attackers.

D. Attackers sends the ARP request with its own MAC address and IP address of a legitimate resource in the network.

Answer: D

Q10. DRAG DROP

Drag each EAP variant in the 802.1x framework to the matching statement on the right?

Answer:

Explanation: EAP-FAST: An encapsulated EAP variant that can travel through TLS tunnel EAP-MD5: When used, EAP servers provide authentication to EAP peers only EAP-OTP: Authenticates using a single-use token

EAP-PEAP: Performs secure tunnel authentication

EAP-SIM: Enables GSM users to access both voice and data services with unified authentication. EAP-TLS: Provides EAP message fragmentation.

EAP-TTLS: An early EAP variant that uses certificates based authentication of both client and server

LEAP: A simplified EAP variant that uses password as shared service.