Cisco

210-260 practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 47-question bank.

Provider
Cisco
Question bank
47
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for 210-260, a certification listed under Cisco. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Cisco. The certification credential is issued by Cisco, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    Refer to the exhibit. What is the effect of the given command?

    Choose one answer.

    Question illustration 1
    • It merges authentication and encryption methods to protect traffic that matches an ACL.
    • It configures the network to use a different transform set between peers.
    • It configures encryption for MD5 HMAC.
    • It configures authentication as AES 256.
    Read explanation

    The crypto ipsec transform-set myset esp-md5-hmac esp-aes-256 command merges authentication and encryption methods to protect traffic that matches an ACL.

  2. Question 2 · 1

    Which two characteristics apply to an Intrusion Prevention System (IPS)? (Choose two.)

    Choose all answers that apply.

    • Does not add delay to the original traffic
    • Cabled directly inline with the flow of the network traffic
    • Can drop traffic based on a set of rules
    • Cannot drop the packet on its own
    • Runs in promiscuous mode
  3. Question 3 · 1

    Which quantifiable item should you consider when your organization adopts new technologies?

    Choose one answer.

    • exploits
    • risk
    • threats
    • vulnerability
  4. Question 4 · 1

    Refer to the exhibit. A network security administrator checks the ASA firewall NAT policy table with the show nat command. Which statement is false?

    Choose one answer.

    Question illustration 1
    • First policy in the Section 1 is dynamic nat entry defined in the object configuration.
    • There are only reverse translation matches for the REAL_SERVER object.
    • NAT policy in Section 2 is a static entry defined in the object configuration.
    • Translation in Section 3 is used when a connection does not match any entries in first two sections.
  5. Question 5 · 1

    Referencing the CIA model, in which scenario is a hash-only function most appropriate?

    Choose one answer.

    • securing data at rest
    • securing wireless transmissions
    • securing data in files
    • securing real-time traffic
  6. Question 6 · 1

    Which command do you enter to enable authentication for OSPF on an interface?

    Choose one answer.

    • router(config-router)#area 0 authentication message-digest
    • router(config-router)#ip ospf authentication-key CISCOPASS
    • router(config-if)#ip ospf message-digest-key 1 md5 CISCOPASS
    • router(config-if)#ip ospf authentication message-digest
  7. Question 7 · 1

    Which two functions can SIEM provide? (Choose two.)

    Choose all answers that apply.

    • dual-factor authentication
    • proactive malware analysis to block malicious traffic
    • centralized firewall management
    • correlation between logs and events from multiple systems
    • event aggregation that allows for reduced log storage requirements
  8. Question 8 · 1

    Refer to the exhibit. If a supplicant supplies incorrect credentials for all authentication methods configured on the switch, how will the switch respond?

    Choose one answer.

    Question illustration 1
    • The supplicant will fail to advance beyond the webauth method.
    • The switch will cycle through the configured authentication methods indefinitely.
    • The authentication attempt will time out and the switch will place the port into the unauthorized state.
    • The authentication attempt will time out and the switch will place the port into VLAN 101.
    Read explanation

    Incorrect credentials supplied will result in failure to advance beyond webauth method. The authentication needs correct credentials as seen in the exhibit.

  9. Question 9 · 1

    Which two features do CoPP and CPPr use to protect the control plane? (Choose two.)

    Choose all answers that apply.

    • QoS
    • traffic classification
    • access lists
    • policy maps
    • class maps
    • Cisco Express Forwarding
  10. Question 10 · 2

    Which technology can you implement to centrally mitigate potential threats when users on your network download files that might be malicious?

    Choose one answer.

    • Verify that the company IPS blocks all known malicious websites.
    • Implement URL filtering on the perimeter firewall.
    • Enable file-reputation services to inspect all files that traverse the company network and block files with low reputation scores.
    • Verify that antivirus software is installed and up to date for all users on your network.
  11. Question 11 · 2

    Which attack can be prevented by OSPF authentication?

    Choose one answer.

    • smurf attack
    • IP spoofing attack
    • Denial of service attack
    • buffer overflow attack
  12. Question 12 · 2

    Information about a managed device. Is resources and activity is defined by a series of objects. What defines the structure of these management objects?

    Choose one answer.

    • MIB
    • FIB
    • LDAP
    • CEF
  13. Question 13 · 2

    Which command enables subnet 192.168.8.4/30 to communicate with subnet 192.168.8.32/27 on IP protocol 50?

    Choose one answer.

    • permit esp 192.168.8.4 255.255.255.252 192.168.8.32 255.255.255.224
    • permit esp 192.168.8.4 0.0.0.31 192.168.8.32 0.0.0.31
    • permit esp 192.168.8.4 255.255.255.224 192.168.8.32 255.255.255.192
    • permit esp 192.168.8.0.0.0.3 192.168.8.32 0.0.0.31
  14. Question 14 · 2

    Which two options are symmetric-key algorithms that are recommended by Cisco? (Choose two).

    Choose all answers that apply.

    • Twofish
    • Advanced Encryption Standard
    • Blowfish
    • Triple Data Encryption Standard
  15. Question 15 · 2

    In a brute-force attack, what percentage of the keyspace must an attacker generally search through until he or she finds the key that decrypts the data?

    Choose one answer.

    • Roughly 50 percent
    • Roughly 66 percent
    • Roughly 75 percent
    • Roughly 10 percent

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free