Cisco CCIE Security 350-701 Practice Test Questions and Exam Dumps Part4 Q61-80

View Full Cisco 350-701 Exam Dumps and Practice Test Dumps.

 

Question 61

Which IPsec component provides confidentiality by encrypting the payload of an IP packet?

  1. ESP
  2. AH
  3. IKE
  4. ARP

Correct Answer: 1

Explanation

Encapsulating Security Payload, or ESP, provides confidentiality through encryption and can also provide integrity, authentication, and anti-replay protection depending on its configuration. ESP is widely used with IPsec VPNs to protect traffic traveling across untrusted networks. Authentication Header, or AH, provides integrity and authentication but does not encrypt the packet payload. IKE is used to negotiate security associations and cryptographic parameters rather than directly carrying protected application data. ARP performs local address resolution. Therefore, ESP is the IPsec component responsible for payload encryption.

Question 62

A security engineer wants to prevent an attacker from sending unauthorized IPv6 Router Advertisement messages on an access-layer switch. Which control should be implemented?

  1. DHCP snooping
  2. IPv6 RA Guard
  3. Port Address Translation
  4. MACsec

Correct Answer: 2

Explanation

IPv6 Router Advertisement Guard, commonly called RA Guard, helps protect IPv6 networks from unauthorized Router Advertisement messages arriving through untrusted access ports. A malicious device could otherwise advertise itself as a router and influence how hosts configure their IPv6 connectivity. RA Guard allows administrators to distinguish trusted and untrusted ports and block inappropriate Router Advertisement traffic. DHCP snooping addresses DHCP-related attacks, PAT translates addresses, and MACsec protects Layer 2 traffic through encryption. Therefore, IPv6 RA Guard is the appropriate control for this scenario.

Question 63

Which Cisco Secure Firewall feature can use URL categories to control access to websites based on their classification?

  1. Security intelligence
  2. URL filtering
  3. Network Address Translation
  4. High availability

Correct Answer: 2

Explanation

URL filtering allows security policies to control web access according to website categories or specific destinations. In Cisco Secure Firewall environments, URL filtering can be incorporated into access control decisions so that organizations can restrict categories considered inappropriate, risky, or inconsistent with corporate policy. Security intelligence can identify known malicious indicators and block associated traffic, but URL filtering specifically addresses web destinations and categories. NAT translates addresses, while high availability provides resilience. Therefore, URL filtering is the feature designed for category-based website access control.

Question 64

Which cryptographic property ensures that a message has not been modified after it was generated?

  1. Confidentiality
  2. Availability
  3. Integrity
  4. Nonrepudiation

Correct Answer: 3

Explanation

Integrity ensures that information remains accurate and has not been altered without authorization. Cryptographic mechanisms such as hashes, message authentication codes, and digital signatures can help detect unauthorized modification. Confidentiality protects information from unauthorized disclosure, while availability focuses on ensuring that systems and services remain accessible. Nonrepudiation provides evidence that can associate an action or message with a particular entity and help prevent denial of an action. Therefore, integrity is the security property concerned with detecting unauthorized changes to a message.

Question 65

Which IPsec negotiation protocol establishes security associations and negotiates cryptographic parameters between VPN peers?

  1. IKE
  2. FTP
  3. SNMP
  4. LDAP

Correct Answer: 1

Explanation

Internet Key Exchange, or IKE, is used by IPsec peers to negotiate security parameters and establish security associations. IKE can negotiate encryption algorithms, integrity mechanisms, authentication methods, and keying material before protected IPsec traffic is exchanged. IKEv2 is widely used for modern IPsec VPN deployments because it improves negotiation efficiency and provides useful capabilities for mobility and reliability. FTP transfers files, SNMP supports network management, and LDAP provides directory-access services. Therefore, IKE is the protocol responsible for IPsec security-association negotiation.

Question 66

Which Cisco security mechanism can encrypt Layer 2 Ethernet frames to protect traffic from unauthorized observation on a switched network?

  1. GRE
  2. MACsec
  3. HSRP
  4. OSPF

Correct Answer: 2

Explanation

MACsec, defined by IEEE 802.1AE, provides Layer 2 encryption for Ethernet traffic. It can protect frames traveling across links from unauthorized observation or manipulation and is particularly useful where traffic must remain protected within a switched infrastructure. Unlike technologies that operate at higher network layers, MACsec secures Ethernet frames directly. GRE provides tunneling but does not inherently encrypt traffic, HSRP provides gateway redundancy, and OSPF is a routing protocol. Therefore, MACsec is the appropriate technology for protecting Ethernet traffic at Layer 2.

Question 67

Which Cisco Secure Firewall component is primarily responsible for managing firewall policies, configurations, and centralized device administration?

  1. Cisco ISE
  2. Cisco Secure Endpoint
  3. Cisco Secure Firewall Management Center
  4. Cisco Umbrella

Correct Answer: 3

Explanation

Cisco Secure Firewall Management Center, commonly known as FMC, provides centralized management and administration for supported Cisco Secure Firewall deployments. Security teams can use it to configure policies, manage devices, monitor events, and perform administrative tasks from a centralized interface. Cisco ISE focuses on identity and network access control, Secure Endpoint focuses on endpoint protection and response, and Cisco Umbrella provides cloud-delivered security services such as DNS-layer protection. Therefore, Secure Firewall Management Center is the component responsible for centralized firewall management.

Question 68

What is the primary purpose of Control Plane Policing (CoPP) on a Cisco router?

  1. Encrypting user traffic
  2. Protecting the control plane from excessive or malicious traffic
  3. Assigning IP addresses to endpoints
  4. Providing wireless authentication

Correct Answer: 2

Explanation

Control Plane Policing, or CoPP, protects the router’s control plane by controlling traffic that is destined for CPU-managed functions. Attackers may generate excessive packets targeting routing protocols, management services, or other control-plane processes, potentially consuming CPU resources and affecting device stability. CoPP can classify and rate-limit or otherwise control this traffic according to defined policies. It does not encrypt user traffic, assign endpoint addresses, or provide wireless authentication. Therefore, CoPP is primarily used to protect the control plane from harmful or excessive traffic.

Question 69

Which security feature can help prevent a compromised host from using a forged source IP address when sending traffic into a network?

  1. IP Source Guard
  2. NTP authentication
  3. DNSSEC
  4. TLS inspection

Correct Answer: 1

Explanation

IP Source Guard helps prevent IP address spoofing by filtering traffic based on source IP information associated with trusted bindings. It can work with mechanisms such as DHCP snooping to determine which IP address is legitimately associated with a switch port. This makes it harder for a compromised host to send packets using a forged source address. NTP authentication protects time synchronization, DNSSEC protects DNS data integrity and authenticity, and TLS inspection provides visibility into encrypted application traffic. Therefore, IP Source Guard is the appropriate control.

Question 70

Which attack involves sending numerous requests to a service with the goal of exhausting its available resources and preventing legitimate users from accessing it?

  1. Credential stuffing
  2. Data exfiltration
  3. Denial-of-service attack
  4. Privilege escalation

Correct Answer: 3

Explanation

A denial-of-service attack attempts to make a system, service, or network resource unavailable to legitimate users by consuming its resources or exploiting weaknesses that affect availability. Attackers may generate excessive requests, malformed traffic, or other resource-consuming activity. A distributed denial-of-service attack uses multiple sources to increase the volume and complexity of the attack. Credential stuffing focuses on reused credentials, data exfiltration involves unauthorized data removal, and privilege escalation seeks higher access permissions. Therefore, denial-of-service accurately describes the scenario.

Question 71

Which security technology can use digital certificates to authenticate devices participating in an enterprise network?

  1. PKI
  2. NAT
  3. VRRP
  4. GRE

Correct Answer: 1

Explanation

Public Key Infrastructure, or PKI, provides the framework for issuing, managing, validating, and revoking digital certificates. Certificates can be used to establish trust and authenticate users, devices, or services in enterprise environments. A certificate authority can issue certificates to authorized entities, while clients can validate certificate chains against trusted authorities. NAT translates addresses, VRRP provides gateway redundancy, and GRE creates tunnels without inherently providing certificate-based authentication. Therefore, PKI is the technology framework that supports certificate-based device authentication.

Question 72

Which Cisco security capability is designed to identify malicious files and analyze suspicious content using threat intelligence and sandboxing techniques?

  1. Cisco Secure Malware Analytics
  2. Cisco HSRP
  3. Cisco DNA Center
  4. Cisco IP SLA

Correct Answer: 1

Explanation

Cisco Secure Malware Analytics provides capabilities for analyzing suspicious files and identifying potentially malicious behavior. Sandbox-based analysis can execute or examine suspicious content in an isolated environment and produce information about observed behaviors and indicators. This can help security teams investigate malware that may not be identified through simple signature matching. HSRP provides gateway redundancy, DNA Center supports network management and automation, and IP SLA measures network performance characteristics. Therefore, Cisco Secure Malware Analytics is the solution associated with sandbox-oriented malware analysis.

Question 73

Which protocol is commonly used to securely transfer files between a client and server through an SSH-based connection?

  1. TFTP
  2. FTP
  3. SFTP
  4. HTTP

Correct Answer: 3

Explanation

SFTP, or SSH File Transfer Protocol, provides secure file transfer through an SSH connection. It protects authentication information and file-transfer data using the security mechanisms provided by SSH. This makes SFTP suitable for transferring configuration files, reports, backups, and other sensitive information across untrusted networks. Traditional FTP does not inherently encrypt its traffic, while TFTP is a lightweight protocol without built-in authentication and encryption. HTTP can transfer files but does not inherently provide the same secure file-transfer model. Therefore, SFTP is the appropriate protocol.

Question 74

Which security control is intended to detect and block traffic that matches known malicious IP addresses, domains, or other threat indicators?

  1. Security intelligence
  2. EtherChannel
  3. HSRP
  4. LLDP

Correct Answer: 1

Explanation

Security intelligence controls can use known threat indicators such as malicious IP addresses, domains, URLs, or other reputation information to identify and block potentially harmful traffic. This provides a preventive layer by stopping communications associated with known malicious infrastructure before additional inspection or application-level analysis is required. EtherChannel combines physical interfaces, HSRP provides gateway redundancy, and LLDP exchanges device and neighbor information. Therefore, security intelligence is the control most directly associated with blocking traffic based on known threat indicators.

Question 75

Which security principle requires that users receive only the permissions necessary to perform their assigned responsibilities?

  1. Separation of duties
  2. Least privilege
  3. Defense in depth
  4. Nonrepudiation

Correct Answer: 2

Explanation

The principle of least privilege requires users, applications, and systems to receive only the access permissions necessary to perform their authorized tasks. Limiting privileges reduces the potential impact of compromised credentials, malicious insiders, and application vulnerabilities. Separation of duties instead divides sensitive responsibilities among multiple individuals so that one person cannot complete an entire high-risk process alone. Defense in depth uses multiple layers of protection, while nonrepudiation helps provide evidence that an action was performed by a particular entity. Therefore, least privilege directly matches the requirement.

Question 76

Which IPv6 security feature can help protect against unauthorized DHCPv6 servers on an access network?

  1. IPv6 DHCP Guard
  2. Port Address Translation
  3. MACsec
  4. CoPP

Correct Answer: 1

Explanation

IPv6 DHCP Guard is designed to help prevent unauthorized DHCPv6 server messages from reaching clients through untrusted network paths. A rogue DHCPv6 server could provide misleading configuration information and potentially influence how hosts communicate on the network. DHCP Guard allows administrators to identify trusted interfaces and restrict inappropriate DHCPv6 server traffic from untrusted ports. Port Address Translation handles address translation, MACsec protects Ethernet frames, and CoPP protects the control plane. Therefore, IPv6 DHCP Guard is the appropriate protection against rogue DHCPv6 servers.

Question 77

Which security technology provides a secure tunnel between a remote user’s device and an enterprise network over an untrusted Internet connection?

  1. Remote-access VPN
  2. Syslog
  3. SNMP
  4. SPAN

Correct Answer: 1

Explanation

A remote-access VPN establishes a protected communication path between an individual user’s device and an organization’s network through an untrusted network such as the Internet. Authentication and encryption help protect the connection and ensure that only authorized users can access permitted internal resources. Organizations can combine remote-access VPNs with multifactor authentication, endpoint posture checks, and access policies to improve security. Syslog provides event logging, SNMP supports network management, and SPAN copies traffic for monitoring. Therefore, remote-access VPN is the appropriate technology.

Question 78

Which security capability can help an organization identify suspicious relationships between users, devices, applications, and security events by correlating information from multiple sources?

  1. VLAN trunking
  2. SIEM
  3. NAT
  4. STP

Correct Answer: 2

Explanation

A Security Information and Event Management, or SIEM, platform collects and correlates security events from multiple sources such as firewalls, endpoints, authentication systems, servers, and network devices. Correlation rules can identify relationships that may be difficult to recognize when events are viewed individually. SIEM platforms can support alerting, investigation, threat hunting, reporting, and incident-response workflows. VLAN trunking transports multiple VLANs, NAT translates addresses, and STP prevents Layer 2 loops. Therefore, SIEM provides the centralized event-correlation capability described.

Question 79

Which technique can reduce the impact of a compromised device by separating sensitive workloads into isolated network segments?

  1. Network segmentation
  2. DNS caching
  3. Load balancing
  4. Route summarization

Correct Answer: 1

Explanation

Network segmentation divides an environment into separate logical or physical security zones and applies controls between them. Segmentation can limit lateral movement because a compromised endpoint may not have unrestricted connectivity to systems in other security zones. Organizations can implement segmentation through VLANs, firewalls, security groups, VRFs, TrustSec policies, or other mechanisms depending on the architecture. DNS caching improves name-resolution efficiency, load balancing distributes application traffic, and route summarization reduces routing-table size. Therefore, network segmentation is the technique described.

Question 80

Which protocol is commonly used to securely exchange management information with network devices while providing authentication, integrity, and encryption?

  1. SNMPv1
  2. SNMPv2c
  3. SNMPv3
  4. TFTP

Correct Answer: 3

Explanation

SNMPv3 provides security features that are absent or limited in earlier SNMP versions. Depending on the selected security level, SNMPv3 can provide message authentication, integrity protection, and encryption for management traffic. This makes it suitable for securely monitoring and managing network devices across environments where management traffic may traverse untrusted networks. SNMPv1 and SNMPv2c commonly rely on community strings and do not provide equivalent built-in security, while TFTP is a lightweight file-transfer protocol. Therefore, SNMPv3 is the appropriate secure network-management protocol.