Cisco CCNP Cybersecurity 350-201 Practice Test Questions and Exam Dumps Part18 Q341-360

View Full Cisco CCNP Cybersecurity 350-201 Exam Dumps and Practice Test Dumps.

 

Question 341

What protocol secures BGP routing sessions using TCP MD5?

  1. Resource Public Key Infrastructure authorization framework
  2. TCP MD5 Signature Option specified in RFC 2385
  3. Unicast Reverse Path Forwarding route verification check
  4. Dynamic ARP Inspection port filtering security mechanism

Correct Answer: 2

Explanation:

The TCP MD5 Signature Option—defined in RFC 2385—allows routers to authenticate BGP peering sessions by embedding a cryptographic hash (Message Authentication Code) inside the TCP header of every BGP segment exchanged between peers. Both routers are pre-configured with a shared secret key, and any routing packet lacking the correct MD5 signature hash is automatically dropped by the receiving router. This prevents malicious actors from injecting forged BGP routing updates, hijacking network prefixes, or conducting TCP reset attacks against critical core routing infrastructure across internet exchanges. Implementing TCP MD5 significantly strengthens routing protocol resilience and ensures that autonomous systems maintain trustworthy communications over vulnerable wide-area networks.

Question 342

Which mechanism prevents MAC address flooding attacks on switches?

  1. Port security dynamic MAC address limiting filter
  2. Dynamic Host Configuration Protocol snooping daemon utility
  3. Unicast Reverse Path Forwarding traffic verification check
  4. Address Resolution Protocol dynamic inspection filter mechanism

Correct Answer: 1

Explanation:

Port security is a foundational Layer 2 hardening feature implemented on enterprise network switches to restrict input to an interface by limiting and identifying the maximum number of source MAC addresses allowed on a specific port. By restricting access to authorized physical endpoints, port security prevents CAM table exhaustion attacks—where malicious actors flood switches with thousands of randomized MAC addresses to force hub-like broadcast behavior. When an unauthorized device attempts to connect or when the configured MAC limit is exceeded, port security can trigger automated defensive mitigations such as shutting down the port or dropping offending frames, safeguarding enterprise network integrity against unauthorized physical access.

Question 343

What cloud security tool continuously monitors multi-cloud compliance?

  1. Cloud Access Security Broker proxy inspection tool
  2. Firewall Management Center policy administration appliance
  3. Cloud Security Posture Management (CSPM) solution
  4. Dynamic Host Configuration server lease daemon

Correct Answer: 3

Explanation:

Cloud Security Posture Management (CSPM) tools are specialized security solutions designed to automate the continuous monitoring of multi-cloud environments—such as Amazon Web Services, Microsoft Azure, and Google Cloud Platform—to detect configuration flaws, security risks, compliance violations, and identity management gaps. CSPM platforms provide automated remediation guidance and deep visibility into complex cloud asset inventories, helping security teams maintain a strong, compliant security posture across distributed cloud infrastructure without manual audits or operational delays. By evaluating environments against regulatory standards like CIS benchmarks and NIST frameworks, CSPM tools ensure that cloud misconfigurations are identified and remediated before adversaries can exploit them.

Question 344

Which component in Cisco ISE handles policy distribution?

  1. Basic unmanaged Layer 2 switch hardware device
  2. Passive network traffic signal analyzer monitoring tool
  3. Policy Service Node (PSN) within Cisco ISE
  4. Unshielded twisted-pair network patch cable link

Correct Answer: 3

Explanation:

Within a distributed Cisco Identity Services Engine deployment, the Policy Service Node (PSN) is responsible for handling network access requests, authentication processing, authorization evaluations, and policy enforcement across enterprise network endpoints. While the Policy Administration Node manages central configuration and system setup, the PSNs are deployed across various physical sites and data centers to ensure low-latency authentication responses and local survivability. PSNs communicate directly with network access devices—such as switches and wireless controllers—evaluating user credentials against centralized security profiles, executing posture assessments, and enforcing granular access control rules dynamically at the network edge.

Question 345

What security device inspects web application HTTP traffic?

  1. Unmanaged Layer 2 Ethernet bridge switch device
  2. Web Application Firewall (WAF) appliance or service
  3. Passive network packet sniffing capture probe
  4. Unshielded twisted-pair patch cable network link

Correct Answer: 2

Explanation:

A Web Application Firewall (WAF) is a specialized security appliance or cloud service designed to protect web applications by filtering, monitoring, and blocking HTTP/HTTPS traffic traveling between web applications and client browsers. Unlike traditional network firewalls that operate at lower OSI layers, a WAF inspects Layer 7 application traffic specifically to detect and prevent common web exploits—such as SQL injection, cross-site scripting, local file inclusion, and cookie tampering—before malicious requests reach application backend databases. By utilizing signature matching, behavioral analysis, and negative/positive security models, a WAF ensures that web services remain resilient against sophisticated application-layer cyber attacks.

Question 346

Which protocol provides secure time synchronization with cryptographic protection?

  1. Simple Network Management Protocol version 1 daemon
  2. Dynamic Host Configuration Protocol address leasing utility
  3. Network Time Security (NTS) cryptographic protocol
  4. Trivial File Transfer Protocol utility server

Correct Answer: 3

Explanation:

Network Time Security (NTS) is a cryptographic extension of the Network Time Protocol designed to provide secure, authenticated time synchronization across computer networks. Traditional time synchronization protocols were highly vulnerable to spoofing, tampering, and man-in-the-middle attacks, allowing malicious actors to manipulate system clocks and disrupt time-sensitive security logs, authentication tokens, or Kerberos tickets. NTS addresses this by utilizing Transport Layer Security and authenticated encryption to secure time packets between clients and time servers, guaranteeing absolute temporal integrity. This cryptographic verification ensures that system logs remain reliable and chronologically accurate for forensic investigations and incident response workflows.

Question 347

What framework standardizes cyber threat intelligence data exchange?

  1. Structured Threat Information Expression (STIX) schema
  2. Common Vulnerability Scoring System metric framework
  3. Syslog event logging stream transmission standard
  4. Simple Network Management Protocol trap configuration

Correct Answer: 1

Explanation:

Structured Threat Information Expression (STIX) is a standardized, structured XML/JSON language and serialization format developed to describe cyber threat information so it can be shared, stored, and analyzed consistently across security platforms. STIX covers a comprehensive range of threat data, including threat actor profiles, campaign details, malware signatures, indicators of compromise, and recommended mitigation actions. When paired with trusted automated exchange protocols like TAXII, STIX enables organizations to share real-time threat intelligence seamlessly and automate defensive security postures across heterogeneous enterprise environments, reducing the time required to detect and mitigate emerging cyber threats globally.

Question 348

Which metric group captures intrinsic vulnerability characteristics over time?

  1. Temporal vulnerability metrics measurement group
  2. Environmental vulnerability metrics evaluation group
  3. Base vulnerability metrics characterization group
  4. Exploitability operational index metrics collection

Correct Answer: 3

Explanation:

The Common Vulnerability Scoring System is divided into three core metric groups: Base, Temporal, and Environmental. The Base metrics group captures the intrinsic characteristics of a vulnerability that remain constant over time and are invariant across user environments, such as Attack Vector, Privileges Required, and Confidentiality Impact. Temporal metrics measure characteristics that evolve over time, such as exploit code maturity and remediation availability, while Environmental metrics customize scores to specific organizational deployments. Understanding the Base metric group allows security teams to evaluate the fundamental severity of a software flaw objectively regardless of where it is deployed across enterprise networks.

Question 349

What service provides Single Sign-On across cloud applications?

  1. Active Directory Federation Services and Single Sign-On
  2. Passive network traffic packet sniffing tool
  3. Unshielded twisted-pair patch cable network link
  4. Layer 2 unmanaged Ethernet bridge switch

Correct Answer: 1

Explanation:

Active Directory Federation Services and Single Sign-On services provide centralized identity management and authentication validation across multiple disparate security domains, cloud platforms, and enterprise applications. Instead of requiring users to maintain separate credentials for every service, federation utilizes standardized protocols like Security Assertion Markup Language and OpenID Connect to securely pass authenticated identity tokens between trusted identity providers and service providers. This centralized approach reduces password fatigue, minimizes credential theft risks, and allows security administrators to enforce strict multi-factor authentication policies across all enterprise cloud workloads efficiently.

Question 350

Which protocol encrypts the entire TACACS+ packet payload?

  1. Terminal Access Controller Access-Control System Plus
  2. Remote Authentication Dial-In User Service protocol
  3. Lightweight Directory Access Protocol Secure utility
  4. Unencrypted Telnet remote administration console

Correct Answer: 1

Explanation:

Terminal Access Controller Access-Control System Plus (TACACS+) is a Cisco-developed AAA protocol that operates over TCP port 49, providing robust, centralized authentication, authorization, and accounting management for administrative access to network devices. Unlike traditional RADIUS—which combines authentication and authorization into a single process and encrypts only the password field within access-request packets—TACACS+ separates all three AAA functions completely. Furthermore, TACACS+ encrypts the entire packet payload of every communication between the network device and the TACACS+ server, ensuring that sensitive command inputs, administrative usernames, and operational data remain entirely secure from network eavesdroppers and packet-sniffing adversaries.

Question 351

What attack floods switch memory tables with MAC addresses?

  1. Address Resolution Protocol cache poisoning attack
  2. CAM table flooding (MAC address exhaustion attack)
  3. Dynamic Host Configuration server exhaustion loop
  4. Spanning Tree Root bridge hijacking exploit

Correct Answer: 2

Explanation:

A CAM table flooding attack—commonly referred to as a MAC flooding attack—is a Layer 2 network exploit where a malicious actor overwhelms an enterprise switch by transmitting a high volume of Ethernet frames with randomized source MAC addresses. Because switches maintain limited physical memory capacity within their Content Addressable Memory tables to track port-to-MAC mappings, exhausting this table forces the switch into an insecure broadcast mode (fail-open behavior). In this state, unicast traffic is flooded to all ports, allowing the attacker to capture sensitive enterprise traffic using passive packet sniffers. Mitigating this risk requires configuring port security limits on access switch ports.

Question 352

Which cryptographic mode provides simultaneous data confidentiality and integrity?

  1. Electronic Codebook cipher mode implementation
  2. Cipher Block Chaining standard mechanism
  3. Galois/Counter Mode (GCM) authenticated encryption
  4. Plaintext session key sharing method

Correct Answer: 3

Explanation:

Galois/Counter Mode (GCM) is an authenticated encryption mode of operation designed to provide both data confidentiality and data integrity simultaneously within symmetric block ciphers like AES. Traditional encryption modes required separate mechanisms to verify integrity, leaving systems vulnerable to tampering if message authentication codes were omitted or misconfigured. GCM combines counter mode encryption with universal hashing over a Galois field, ensuring that any unauthorized modification to ciphertext or associated authentication data is detected instantly. Because of its high performance and robust security guarantees, GCM is heavily utilized in modern protocols such as TLS 1.3 to protect data in transit.

Question 353

What tool monitors endpoint behavior for threat detection?

  1. Basic static signature-based antivirus software
  2. Endpoint Detection and Response (EDR) platform
  3. Unmanaged Layer 2 Ethernet bridge switch
  4. Passive network signal tap hub device

Correct Answer: 2

Explanation:

Endpoint Detection and Response (EDR) is a sophisticated cybersecurity technology that continuously monitors end-user devices, servers, and hosts to collect deep behavioral telemetry, detect suspicious activities, and provide automated containment capabilities. Unlike traditional signature-based antivirus software that relied on static file matching to block known malware, EDR tools record process executions, file modifications, registry changes, and network connections in real time. This granular behavioral visibility enables security operations teams and threat hunters to identify zero-day exploits, fileless malware attacks, and advanced persistent threats that successfully evade traditional perimeter defenses, enabling rapid isolation and remediation.

Question 354

Which security assessment simulates real-world targeted cyber attacks?

  1. Static application source code review analysis
  2. Automated vulnerability port scanning utility scan
  3. Penetration testing assessment engagement
  4. Passive network traffic log sniffing capture

Correct Answer: 3

Explanation:

Penetration testing is an authorized, simulated cyber attack launched against a computer system, network, or web application to evaluate security posture and identify exploitable vulnerabilities. Performed by ethical hackers, penetration testing mimics the tactics, techniques, and procedures utilized by real-world threat actors to bypass defenses. The assessment uncovers weak configurations, unpatched software flaws, and architectural security gaps before malicious attackers can exploit them. Organizations utilize penetration testing findings to prioritize remediation efforts, validate security controls, and ensure compliance with various regulatory frameworks and industry standards.

Question 355

What IEEE standard defines port-based network access control?

  1. IEEE 802.1Q VLAN trunking specification
  2. IEEE 802.1X port-based access control standard
  3. IEEE 802.11ac wireless local area network
  4. IEEE 802.1w Rapid Spanning Tree protocol

Correct Answer: 2

Explanation:

The IEEE 802.1X standard defines port-based network access control, providing an authentication mechanism for devices wishing to attach to a wired LAN or wireless WLAN. 802.1X uses the Extensible Authentication Protocol to pass authentication messages between the supplicant client, the network access device acting as an authenticator, and a centralized authentication server such as RADIUS or Cisco ISE. Until the client successfully authenticates, the switch port blocks all non-EAP traffic, preventing unauthorized or rogue endpoints from accessing enterprise network resources. This enforces strict device compliance before granting access to internal corporate network segments.

Question 356

Which DNS extension utilizes cryptographic signatures for validation?

  1. Domain Name System Security Extensions (DNSSEC)
  2. Dynamic Host Configuration Protocol option string
  3. Dynamic DNS record update mechanism protocol
  4. Network Time Protocol synchronization utility

Correct Answer: 1

Explanation:

Domain Name System Security Extensions (DNSSEC) is a suite of cryptographic specifications developed by the IETF to secure information provided by the Domain Name System. Traditional DNS implementations lacked built-in authentication, leaving them vulnerable to cache poisoning, spoofing, and man-in-the-middle attacks where users are redirected to malicious websites. DNSSEC addresses this by cryptographically signing DNS records using public key cryptography. This allows client resolvers to verify the authenticity and integrity of responses, ensuring users connect to legitimate destination servers without malicious interception or data tampering across the internet.

Question 357

What device actively blocks malicious network intrusion attempts?

  1. Layer 2 unmanaged Ethernet bridge switch
  2. Passive network signal sniffing tap hub
  3. Intrusion Prevention System (IPS) appliance
  4. Unshielded twisted-pair patch cable link

Correct Answer: 3

Explanation:

An Intrusion Prevention System (IPS) is an advanced inline security appliance designed to monitor network traffic for malicious activities, policy violations, and known attack signatures with the capability to actively block or drop identified threats in real time. Unlike passive Intrusion Detection Systems that merely generate alerts, an IPS sits directly in the data path of network traffic flows to terminate malicious connection sessions instantly. By executing signature matching, protocol anomaly detection, and heuristic analysis inline, an IPS provides critical frontline defense against network exploits, preventing malicious payloads from reaching vulnerable host systems.

Question 358

Which routing security framework uses Route Origin Authorizations?

  1. Resource Public Key Infrastructure (RPKI) framework
  2. Simple Network Management Protocol version 3 daemon
  3. Dynamic ARP Inspection port filter mechanism
  4. Port-based 802.1X network access control standard

Correct Answer: 1

Explanation:

Resource Public Key Infrastructure (RPKI) is a specialized cryptographic framework designed to secure the routing infrastructure of the internet by validating the ownership of Internet Number Resources. BGP routing table exchanges historically lacked built-in authentication, leaving global routing vulnerable to malicious prefix hijacking and accidental route leaks. RPKI utilizes cryptographic Route Origin Authorizations to bind specific IP address prefixes to authorized autonomous system numbers, allowing routers to validate digital signatures before accepting routing updates. This prevents unauthorized networks from falsely announcing IP blocks they do not own.

Question 359

What hardening practice rate-limits router control plane traffic?

  1. Flat unsegmented network bridging topology
  2. Unencrypted Telnet console remote management
  3. Control Plane Policing (CoPP) security feature
  4. Passive optical network signal tapping hub

Correct Answer: 3

Explanation:

Control Plane Policing (CoPP) is a security and Quality of Service feature implemented on Cisco network hardware that utilizes QoS mechanisms to manage and rate-limit control plane traffic destined for the device’s CPU. By prioritizing legitimate routing protocols—like BGP and OSPF—and throttling excessive or malicious traffic streams—such as ARP floods or Denial of Service attacks—CoPP prevents CPU resource exhaustion and ensures network device stability. Protecting the control plane prevents malicious actors from crashing core routers and switches, maintaining continuous network availability across enterprise architecture.

Question 360

Which switch feature filters traffic using DHCP bindings?

  1. Port security MAC address limiting filter
  2. IP Source Guard traffic filtering feature
  3. Dynamic ARP Inspection port verification
  4. Unicast Reverse Path Forwarding check

Correct Answer: 2

Explanation:

IP Source Guard is a Layer 2 security technology implemented on Cisco switches that filters out malicious or spoofed IP traffic by leveraging the binding database created by DHCP snooping and static IP source entries. When enabled on untrusted ports, IP Source Guard compares incoming IP packets against authorized IP-MAC-port bindings. Any packet arriving with a source IP address that does not match the binding database is immediately dropped, preventing malicious IP spoofing attacks at the access layer. This ensures that endpoints cannot spoof IP addresses to bypass security policies or launch network attacks.