View Full Cisco CCNP Security 300-730 Exam Dumps and Practice Test Dumps.
Question 341
Which Cisco technology provides centralized management and policy administration for supported Secure Firewall devices?
- Cisco ISE
- Cisco Secure Client
- Cisco Secure Firewall Management Center
- Cisco Umbrella
Correct Answer: 3
Explanation
Cisco Secure Firewall Management Center provides centralized management, configuration, monitoring, and policy administration for supported Cisco Secure Firewall deployments. It allows administrators to manage security policies and review events from a centralized management platform instead of configuring every firewall independently. Cisco ISE focuses primarily on identity-based network access control, Secure Client provides endpoint connectivity and security capabilities, and Cisco Umbrella provides cloud-delivered security services. Centralized firewall management is especially useful in larger environments where consistent policies, centralized visibility, and coordinated administration are required across multiple security appliances.
Question 342
Which firewall policy component can identify and control traffic according to the application generating it?
- Application Control
- DHCP Snooping
- NHRP
- Certificate Chain
Correct Answer: 1
Explanation
Application Control allows a firewall to identify applications and use application identity as part of security policy decisions. This provides more granular control than relying only on IP addresses and transport ports. Modern applications can use dynamic ports or common ports such as TCP 443, making application-aware identification valuable for security enforcement. DHCP Snooping protects against rogue DHCP servers, NHRP supports DMVPN address resolution, and certificate chains establish PKI trust. Application Control therefore helps administrators define policies based on what application is communicating rather than simply which port or address is being used.
Question 343
Which Cisco security capability can use reputation data to block connections to known malicious destinations?
- Security Intelligence
- MACsec
- Port Security
- SCEP
Correct Answer: 1
Explanation
Security Intelligence can use threat intelligence and reputation information to identify known malicious indicators such as IP addresses and domains. Security policies can use these indicators to block or otherwise control connections before they reach protected resources. This provides a preventive security layer that complements deeper inspection and intrusion prevention. MACsec protects Ethernet frames, Port Security controls MAC addresses on switch ports, and SCEP supports certificate enrollment. Security Intelligence is therefore specifically associated with using reputation-based information and threat indicators to enforce security policies against known malicious infrastructure.
Question 344
Which firewall capability is designed to control access to websites according to URL categories?
- Application Control
- URL Filtering
- Security Intelligence
- IKEv2
Correct Answer: 2
Explanation
URL Filtering controls web access based on URLs, domains, or categories. Organizations can use URL categories to define policies that permit or restrict access to particular types of websites. This can help enforce acceptable-use policies and reduce exposure to unwanted or potentially risky web content. Application Control identifies applications, Security Intelligence focuses on threat indicators and reputation, and IKEv2 handles VPN negotiation. URL Filtering therefore provides a web-destination-focused policy mechanism that can operate alongside application inspection, malware protection, and other firewall security controls.
Question 345
Which firewall technology is primarily responsible for detecting and blocking malicious traffic based on security inspection policies?
- IPS
- RADIUS
- NHRP
- SCEP
Correct Answer: 1
Explanation
An Intrusion Prevention System, or IPS, examines traffic for malicious patterns or behaviors and can actively block detected threats. IPS inspection can use signatures and other detection techniques depending on the security platform and configuration. Unlike a traditional IDS, which primarily detects and alerts, an IPS is designed to operate as an active prevention mechanism. RADIUS provides AAA services, NHRP supports DMVPN address resolution, and SCEP handles certificate enrollment. IPS therefore provides an important inspection and enforcement layer within a broader firewall security architecture.
Question 346
Which feature can identify users and devices so that security policies can be based on identity rather than only IP addresses?
- User identity services
- NAT exemption
- NHRP Redirect
- Transform Set
Correct Answer: 1
Explanation
User identity services provide security platforms with information that associates network activity with specific users or identities. This information can then be used to create policies based on who is accessing a resource rather than relying exclusively on IP addresses. Identity-based policy can be particularly useful in environments where users move between devices or networks and IP addresses change frequently. NAT exemption controls address translation, NHRP Redirect supports DMVPN optimization, and a transform set defines traditional IPsec protection parameters. User identity services therefore enhance security policy with contextual identity information.
Question 347
Which Cisco platform is commonly used to provide identity-based authentication and authorization for wired and wireless network access?
- Cisco ISE
- Cisco FMC
- Cisco Umbrella
- Cisco Secure Client
Correct Answer: 1
Explanation
Cisco Identity Services Engine, or ISE, provides centralized authentication and authorization for network access. It commonly integrates with wired and wireless 802.1X deployments using RADIUS and can support device profiling, guest access, posture-related functionality, and TrustSec-based segmentation. Cisco Secure Firewall Management Center focuses on firewall management, Umbrella provides cloud security services, and Secure Client provides endpoint connectivity and security capabilities. ISE is therefore the Cisco platform most directly associated with centralized identity-based network access control and policy enforcement.
Question 348
Which protocol is commonly used between an authenticator and Cisco ISE for centralized 802.1X authentication?
- TACACS+
- RADIUS
- NHRP
- ESP
Correct Answer: 2
Explanation
RADIUS is commonly used between a network access device acting as an 802.1X authenticator and Cisco ISE. The endpoint communicates with the authenticator using the appropriate EAP mechanism, while the authenticator communicates with ISE through RADIUS for centralized authentication and authorization. TACACS+ is commonly associated with administrative device access and command authorization. NHRP supports DMVPN, while ESP protects IPsec traffic. RADIUS therefore provides the AAA communication mechanism commonly used to connect network access infrastructure with Cisco ISE in 802.1X environments.
Question 349
Which EAP method uses client and server certificates for strong mutual authentication?
- EAP-TLS
- PAP
- CHAP
- NHRP
Correct Answer: 1
Explanation
EAP-TLS uses digital certificates to authenticate the endpoint and authentication server. In a properly configured deployment, the client certificate provides strong endpoint identity while the server certificate allows the endpoint to validate the authentication server. EAP-TLS is commonly used in enterprise 802.1X environments where certificate-based authentication is preferred. PAP and CHAP use different credential mechanisms and do not provide the same certificate-based authentication model. NHRP is unrelated to EAP authentication. EAP-TLS therefore provides a strong certificate-based authentication mechanism for wired and wireless network access.
Question 350
Which 802.1X role is responsible for requesting authentication information from the endpoint and communicating with the AAA server?
- Supplicant
- Authenticator
- Certificate Authority
- Key Server
Correct Answer: 2
Explanation
The authenticator is typically the network access switch or wireless access point controlling access to the network. It communicates with the endpoint, which acts as the supplicant, and forwards authentication information to the centralized AAA server, commonly through RADIUS. The authenticator controls whether the endpoint receives authorized network access based on the result of the authentication and authorization process. The Certificate Authority manages certificates, while a Key Server has a different role in GETVPN. Therefore, the authenticator serves as the intermediary between the supplicant and the centralized authentication infrastructure.
Question 351
Which 802.1X role represents the endpoint requesting access to the network?
- Supplicant
- Authenticator
- RADIUS server
- Certificate Authority
Correct Answer: 1
Explanation
The supplicant is the endpoint that requests network access through an 802.1X-controlled connection. It can be a laptop, desktop, phone, or another supported device running appropriate authentication software. The supplicant provides authentication information to the authenticator, which communicates with the centralized AAA server. The authenticator is usually a switch or wireless access point, while the RADIUS server performs centralized authentication and authorization. A Certificate Authority may support certificate-based authentication but does not represent the endpoint role. The supplicant is therefore the client-side component of the 802.1X architecture.
Question 352
Which Cisco TrustSec feature associates traffic with an identity-based security group?
- SGT
- DHCP Binding
- Crypto ACL
- Transform Set
Correct Answer: 1
Explanation
A Security Group Tag, or SGT, associates traffic with an identity-based security group in Cisco TrustSec. Rather than relying exclusively on IP addresses, TrustSec can use SGTs to classify users, devices, or traffic into logical security groups. Policies can then control communication between groups according to organizational requirements. DHCP bindings associate IP addresses with MAC addresses, crypto ACLs identify interesting traffic for traditional IPsec, and transform sets define IPsec protection algorithms. SGTs therefore provide the identity-oriented classification mechanism that enables TrustSec-based segmentation and policy enforcement.
Question 353
Which technology provides cryptographic security directly for Ethernet frames?
- IPsec
- MACsec
- RADIUS
- IKEv2
Correct Answer: 2
Explanation
MACsec provides cryptographic protection directly at the Ethernet Layer 2 level. It can protect Ethernet frames against unauthorized modification and disclosure on supported links. IPsec operates at the IP layer and is commonly used for routed VPNs, while IKEv2 negotiates IPsec security relationships. RADIUS provides AAA services. MACsec is particularly useful when organizations want to secure traffic between network devices while preserving normal Layer 2 communication. Its Layer 2 operation distinguishes it from IPsec, which generally protects IP packets rather than Ethernet frames directly.
Question 354
Which feature creates a database of IP-to-MAC bindings learned from legitimate DHCP exchanges?
- DHCP Snooping
- Dynamic ARP Inspection
- IP Source Guard
- Port Security
Correct Answer: 1
Explanation
DHCP Snooping builds a binding database containing information learned from DHCP exchanges, such as the assigned IP address, client MAC address, VLAN, and switch interface. This database can then be used by other security mechanisms. Dynamic ARP Inspection can use these bindings to validate ARP packets, while IP Source Guard can use them to validate source IP information. Port Security operates primarily by controlling MAC addresses on switch ports. DHCP Snooping therefore provides the foundational binding information used by multiple Layer 2 security features.
Question 355
Which security feature can use DHCP Snooping bindings to validate ARP packets?
- Port Security
- Dynamic ARP Inspection
- URL Filtering
- Application Control
Correct Answer: 2
Explanation
Dynamic ARP Inspection uses trusted binding information, commonly obtained through DHCP Snooping, to validate ARP packets. It can compare the claimed IP and MAC information in ARP messages against the expected binding information. This helps prevent ARP spoofing and related man-in-the-middle attacks on switched networks. Port Security controls MAC addresses, URL Filtering controls web destinations, and Application Control identifies applications. DAI therefore complements DHCP Snooping by using the binding database to verify ARP traffic and reject packets that do not meet the configured validation criteria.
Question 356
Which security feature can prevent unauthorized devices from using forged source IP addresses on an access port?
- IP Source Guard
- URL Filtering
- SCEP
- IKEv2
Correct Answer: 1
Explanation
IP Source Guard can help prevent source IP spoofing by validating source addresses against trusted binding information on switch ports. In common deployments, the required IP-to-MAC information is learned through DHCP Snooping. When traffic arrives with a source address that does not match the expected binding, the switch can enforce the configured security behavior. URL Filtering controls web destinations, SCEP manages certificate enrollment, and IKEv2 negotiates VPN security associations. IP Source Guard therefore provides a Layer 2 access-network defense against unauthorized source-address use.
Question 357
Which security mechanism limits the number of MAC addresses allowed on a switch access port?
- DHCP Snooping
- Port Security
- IP Source Guard
- Security Intelligence
Correct Answer: 2
Explanation
Port Security allows administrators to limit and control MAC addresses associated with a switch port. This can help prevent unauthorized devices from connecting through an access interface and can reduce certain forms of MAC-based abuse. Depending on the platform and configuration, administrators can define maximum MAC addresses and specify how violations should be handled. DHCP Snooping focuses on DHCP protection, IP Source Guard validates source addressing, and Security Intelligence uses threat reputation information. Port Security is therefore the feature specifically designed to enforce MAC-address-based restrictions on switch ports.
Question 358
Which certificate service allows a device to query the current status of a certificate online?
- SCEP
- CRL
- OCSP
- DHCP
Correct Answer: 3
Explanation
OCSP, or Online Certificate Status Protocol, allows a device to query an OCSP responder for the current status of a certificate. The responder can indicate whether the certificate is valid, revoked, or otherwise unable to be validated. SCEP is primarily used for certificate enrollment, while a CRL provides a periodically published list of revoked certificates. DHCP provides network configuration rather than certificate validation. OCSP can be useful when timely revocation information is important and when devices need to check certificate status without downloading and processing an entire revocation list.
Question 359
Which certificate-management mechanism is designed primarily for automated certificate enrollment?
- OCSP
- SCEP
- CRL
- ESP
Correct Answer: 2
Explanation
SCEP, or Simple Certificate Enrollment Protocol, is designed to support automated certificate enrollment for compatible devices. It can simplify the process of obtaining certificates from a PKI environment, especially when many network devices require certificates for authentication or secure communication. OCSP is used to check certificate status, while a CRL provides a published list of revoked certificates. ESP is an IPsec security protocol used to protect data traffic. SCEP therefore addresses the certificate provisioning stage of PKI rather than certificate-status checking or IPsec data protection.
Question 360
Which statement best describes the relationship between IKE and IPsec?
- IKE provides DNS filtering for IPsec
- IKE negotiates security parameters, while IPsec protects user traffic
- IPsec authenticates administrators through TACACS+
- IKE replaces all routing protocols
Correct Answer: 2
Explanation
IKE and IPsec perform complementary roles in a VPN architecture. IKE negotiates security parameters, authenticates the peers, and establishes the security associations and keying material required for protected communication. IPsec then provides the actual protection of user traffic using mechanisms such as ESP. This separation between control-plane negotiation and data-plane protection is fundamental to understanding IPsec VPN operation. IKE does not provide DNS filtering or replace routing protocols, and IPsec does not perform TACACS+ administrator authentication. Therefore, IKE negotiates the security relationship while IPsec protects the data being transmitted.