Exam Code: 400-251 (Practice Exam Latest Test Questions VCE PDF)
Exam Name: CCIE Security Written Exam
Certification Provider: Cisco
Free Today! Guaranteed Training- Pass 400-251 Exam.


2026 New 400-251 Exam Dumps with PDF and VCE Free: https://www.surepassexam.com/400-251-exam-dumps.html

Q1. DRAG DROP

Drag and drop ESP header field on the left to the appropriate field length on the right

Answer:

Q2. Which Cisco ASA firewall mode supports ASDM one-time-password authentication using RSA SecurID?

A. Network translation mode

B. Single-context routed mode

C. Multiple-context mode

D. Transparent mode

Answer: B

Q3. What is an example of a WEP cracking attack ?

A. SQL injection attack

B. Café latte attack

C. directory traversal attack

D. Reflected XSS attack

Answer: B

Q4. DRAG DROP

Drag each step in the SCEP workflow on the left into the correct order of operations on the right?

Answer:

Explanation:

Step 1: Obtain and validate CA cert.

Step 2: Generate a certificate signing request for the CA.

Step 3: Sent a request to SCEP server to confirm that the cert was signed. Step 4: Re- enroll the client and replace the existing certificate.

Step 5: Check Certificate revocation list.

Q5. Which two options are differences between a automation and orchestration?(Choose two)

A. Automation is an IT workflow composed of tasks, and orchestration is a technical task.

B. Orchestration is focused on multiple technologies to be integrated together.

C. Orchestration is focused on an end-to-end process or workflow

D. Automation is to be used to replace human intervention.

E. Automation is focused on automating a single or multiple tasks.

Answer: B,C

Q6. You have been asked to configure a Cisco ASA appliance in multiple mode with these settings:

(A) You need two customer contexts, named contextA and contextB

(B) Allocate interfaces G0/0 and G0/1 to contextA

(C) Allocate interfaces G0/0 and G0/2 to contextB

(D) The physical interface name for G0/1 within contextA should be "inside".

(E) All other context interfaces must be viewable via their physical interface names.

If the admin context is already defined and all interfaces are enabled, which command set will complete this configuration?

A. context contextA

config-url disk0:/contextA.cfg

allocate-interface GigabitEthernet0/0 visible allocate-interface GigabitEthernet0/1 inside context contextB

config-url disk0:/contextB.cfg

allocate-interface GigabitEthernet0/0 visible allocate-interface GigabitEthernet0/2 visible

B. context contexta

config-url disk0:/contextA.cfg

allocate-interface GigabitEthernet0/0 visible allocate-interface GigabitEthernet0/1 inside context contextb

config-url disk0:/contextB.cfg

allocate-interface GigabitEthernet0/0 visible allocate-interface GigabitEthernet0/2 visible

C. context contextA

config-url disk0:/contextA.cfg

allocate-interface GigabitEthernet0/0 invisible allocate-interface GigabitEthernet0/1 inside context contextB

config-url disk0:/contextB.cfg

allocate-interface GigabitEthernet0/0 invisible allocate-interface GigabitEthernet0/2 invisible

D. context contextA

config-url disk0:/contextA.cfg

allocate-interface GigabitEthernet0/0 allocate-interface GigabitEthernet0/1 inside context contextB

config-url disk0:/contextB.cfg

allocate-interface GigabitEthernet0/0 allocate-interface GigabitEthernet0/2

E. context contextA

config-url disk0:/contextA.cfg

allocate-interface GigabitEthernet0/0 visible allocate-interface GigabitEthernet0/1 inside context contextB

config-url disk0:/contextB.cfg

allocate-interface GigabitEthernet0/1 visible allocate-interface GigabitEthernet0/2 visible

Answer: A

Q7. Which two statement about PVLAN port types are true? (Choose two)

A. A community port can send traffic to community port in other communities on its broadcast domain.

B. An isolated port can send and receive traffic only to and from promiscuous ports.

C. An isolated port can receive traffic from promiscuous port in an community on its broadcast domain, but can send traffic only to port in its own community.

D. A promiscuous port can send traffic promiscuous port in other communities on its broadcast domain.

E. A community port can send traffic to promiscuous port in other communities on its broadcast domain.

F. A Promiscuous port can send traffic to all ports within a broadcast domain.

Answer: B,F

Q8. Which three statements about RLDP are true? (Choose three)

A. It can detect rogue Aps that use WPA encryption

B. It detects rogue access points that are connected to the wired network

C. The AP is unable to serve clients while the RLDP process is active

D. It can detect rogue APs operating only on 5 GHz

E. Active Rogue Containment can be initiated manually against rogue devices detected on the wired network

F. It can detect rogue APs that use WEP encryption

Answer: A,B,D

Q9. What is the name of the unique tool/feature in cisco security manager that is used to merge an access list based on the source/destination IP address service or combination of these to provide a manageable view of access policies?

A. merge rule tool

B. policy simplification tool

C. rule grouping tool

D. object group tool

E. combine rule tool

Answer: E

Q10. Which protocol does VNC use for remote access to a GUI?

A. RTPS

B. RARP

C. E6

D. SSH

E. RFB

Answer: D