Act now and download your Cisco 400-251 test today! Do not waste time for the worthless Cisco 400-251 tutorials. Download Up to the minute Cisco CCIE Security Written Exam exam with real questions and answers and begin to learn Cisco 400-251 with a classic professional.


2026 New 400-251 Exam Dumps with PDF and VCE Free: https://www.2passeasy.com/dumps/400-251/

Q1. Which Statement about remote procedure calls is true?

A. They support synchronous and asynchronous requests.

B. They can emulate different hardware specifications on a single platform.

C. They support optimized data replication among multiple machines.

D. They use a special assembly instruction set to process remote code without conflicting with other remote processes.

E. They can be invoked by the client and the server.

Answer: D

Q2. According to RFC 4890, which three message must be dropped at the transit firewall/router?(Choose three.)

A. Router Renumbering(Type 138)

B. Node Information Query(Type 139)

C. Router Solicitation(Type 133)

D. Node information Response(Type

E. Router Advertisement(Type 134)

F. Neighbor Solicitaion(Type 135)

Answer: A,B,D

Q3. When configuration Cisco IOS firewall CBAC operation on Cisco routers, the “inspection rule” can be applied at which two location?(Choose two)

A. at the trusted and untrusted interfaces in the inbound direction.

B. at the trusted interface in the inbound direction.

C. at the trusted and untrusted interfaces in the outbound direction.

D. at the untrusted interface in the inbound direction.

E. at the trusted interface in the outbound direction.

F. at the trusted interface in the outbound direction.

Answer: B,F

Q4. The computer at 10.10.10.4 on your network has been infected by a botnet that directs traffic to a malware site at 168.65.201.120. Assuming that filtering will be performed on a Cisco ASA, What command can you use to block all current and future connections from the infected host?

A. ip access-list extended BLOCK_BOT_OUT deny ip any host 10.10.10.4

B. shun 10.10.10.4 168.65.201.120 6000 80

C. ip access-list extended BLOCK_BOT_OUT deny ip host 10.10.10.4 host 168.65.201.120

D. ip access-list extended BLOCK_BOT_OUT deny ip host 168.65.201.120 host 10.10.10.4

E. shun 168.65.201.120 10.10.10.4 6000 80

Answer: C

Q5. In ISO 27002, access control code of practice for information Security Management servers which of the following objective?

A. Implement protocol control of user, network and application access

B. Optimize the audit process

C. Prevent the physical damage of the resources

D. Educating employees on security requirements and issues

Answer: A

Q6. Which two statements about the MD5 Hash are true? (Choose two.)

A. Length of the hash value varies with the length of the message that is being hashed.

B. Every unique message has a unique hash value.

C. Its mathematically possible to find a pair of message that yield the same hash value.

D. MD5 always yields a different value for the same message if repeatedly hashed.

E. The hash value cannot be used to discover the message.

Answer: B,E

Q7. According to OWASP guidelines, what is the recommended method to prevent cross-site request forgery?

A. Allow only POST requests.

B. Mark all cookies as HTTP only.

C. Use per-session challenge tokens in links within your web application.

D. Always use the "secure" attribute for cookies.

E. Require strong passwords.

Answer: C

Q8. Which Cisco ASA firewall mode supports ASDM one-time-password authentication using RSA SecurID?

A. Network translation mode

B. Single-context routed mode

C. Multiple-context mode

D. Transparent mode

Answer: B

Q9. Which Two statement about the PCoIP protocol are true? (Choose two)

A. It support both loss and lossless compression

B. It is a client-rendered, multicast-codec protocol.

C. It is available in both software and hardware.

D. It is a TCP-based protocol.

E. It uses a variety of codec to support different operating system.

Answer: A,C

Q10. You have discovered unwanted device with MAC address 001c.0f12.badd on port FastEthernet1/1 on

VLAN 4.what command or command sequence can you enter on the switch to prevent the

MAC address from passing traffic on VLAN 4? 

A)

B)

C)

D)

E)

A. Option A

B. Option B

C. Option C

D. Option D

Answer: D