Cisco 400-251 CCIE Security Written Exam (v5.0) Online Training
Cisco 400-251 Online Training
The questions for 400-251 were last updated at Jul 18,2026.
- Exam Code: 400-251
- Exam Name: CCIE Security Written Exam (v5.0)
- Certification Provider: Cisco
- Latest update: Jul 18,2026
Refer to the exhibit.

Users cannot access web servers 192. 168 101.3/24 and 192. 168 102.3/24 using FireFox web browser when initiated from 172.61.1.0/24 network.
Which possible cause is true?
- A . The access policy "Allow policy" is porting to an incorrect identification profile
- B . The identification profile "Allowed Profile" has a misconfigured user agent
- C . The custom URL category "Allowed Sites" has an incorrect server address listed
- D . The identification profile "Allow Profile" has an incorrect protocol
- E . The access policy "Allow Policy" has an incorrect action set for the custom URL category
- F . The identification profile "allow profile" has an incorrect source network
Which description of the AES encryption algorithm is true?
- A . It provides only data integrity
- B . Theoretically 3DES is more secure than AES
- C . Reapplying the same encryption key three times makes rt less vulnerable than 3DES
- D . It does not use the substitution and permutation principle
- E . It uses three encryption keys of lengths 126.192 and 256
- F . It uses the block of 128 bits
Refer to the exhibit.

The AMP cloud is configured to report AMP Connector scan events from Windows machines that belong to the audit group to the FMC However, the scanned events are not showing up in the FMC which possible cause true?
- A . There is a possible issue with certificate download from the AMP cloud for FMC integration
- B . The AMP cloud is pointing to an incorrect FMC address.
- C . The event must be viewed as a malware event in the FMC
D. The DNS address is misconfigured on the FMC. - D . An incorrect group is selected for the events export in the AMP cloud for FMC.
- E . The FMC is pointing to an incorrect AMP cloud address
Which requirement for the FTD high availability setup is true?
- A . Units must be in different domains in FMC
- B . Units must have DHCP configured for the interfaces
- C . Units must not have the same major, minor, and maintenance software version running on them
- D . Units can have any uncommitted changes on FMC and need not be fully deployed
- E . Units must be synchronized using the same NTP source.
- F . Units must be configured in routed mode
- G . Units must be configured in transparent mode
Which statement about OSPFv2 configuration on ASA is true?
- A . It does not support stub areas and not-so-stubby areas
- B . It only supports MD5 authentication with the peers
- C . Routing decision is based on the hop counts to the destination
- D . It does not support virtual links
- E . It allows multiple routing processes to be configured
- F . ASA can exist as ABR but not as ASBR
Which statement about the traffic Substitution and insertion attack is true?
- A . It substitutes by performing action slower than normal not exceeding threshold
- B . it is used for reconnaissance
- C . It substitutes payload data in a different format but has the same meaning
- D . It is form of a dos attack
- E . It substitutes payload data in the same format but has different meaning
- F . It substitutes by performing action faster than normal not exceeding threshold
- G . It is a form pivoting in the network
Which description of TAP mode deployment in IPS is true?
- A . Access rules configured in TAP mode generate events when trigged and performs defined action on the traffic stream
- B . TAP mode is not available when IPS is deployed inline
- C . Access rules configured in TAP mode generate events
- D . In TAP mode, traffic flow gets distributed for analysis
- E . TAP mode is available when ports are configured as passive interfaces
- F . TAP mode implementation requires span configuration on a switc
Which statement about x 509 certificates is true?
- A . The Subject distinguished name in the certificate is of the entity who issued the certificate
- B . The issuer distinguished name in the certificate is of the entity receiving the certificate
- C . The algorithm in the certificate is used by the receiver to sign the certificate
- D . The version number in the certificate is x 509 version number
- E . The serial number in the certificate is common across the certificates issued by the same CA
- F . The algorithm in the certificate is used by the subject to encrypt the traffic
Refer to the exhibit.

Which statement about this packet capture from Wireshark is true?
- A . The RADIUS connection keep alive using TCP originated from ISE
- B . The SXP message uses TCP port 64999 for connection termination
- C . The TACACS connection keep alive using UDP originated from ASA
- D . The SXP keep alive message using TCP originated from ASA
- E . The ISE keep alive message for NDAC connection using TCP originated from ASA
- F . The SXP message uses MDS for packet encryption
- G . The NTP keep alive message using UDP originate from ISE
Which statement is true regarding the failover link when ASAs are configured in a failover mode?
- A . The information sent over the failover link cannot be in dear text
- B . Failover key is not required for the secure communication over the failover link
- C . Configuration replication sent across the link can be secured using a failover key
- D . The information sent over the failover link cannot be in dear text but it could be secured communication using a failover key
- E . It is not recommended to use secure communication over failover link when ASA terminating the VPN tunnel
- F . The information sent over the failover link can only be sent as a secured communication