{"id":14475,"date":"2026-09-17T05:08:29","date_gmt":"2026-09-17T05:08:29","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=14475"},"modified":"2026-09-17T05:08:29","modified_gmt":"2026-09-17T05:08:29","slug":"cisco-200-201-practice-test-questions-and-exam-dumps-part16-q301-320","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-200-201-practice-test-questions-and-exam-dumps-part16-q301-320\/","title":{"rendered":"Cisco 200-201 Practice Test Questions and Exam Dumps Part16 Q301-320"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"http:\/\/examlabs.com\/200-201-exam-dumps\"><b>Cisco 200-201 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 301<\/b><\/h3>\n<p><b>Which protocol provides centralized authentication and authorization for network access while commonly using UDP ports 1812 and 1813?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RADIUS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TACACS+<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LDAP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Kerberos<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">RADIUS is a widely used AAA protocol that provides centralized authentication, authorization, and accounting services. It is commonly used for network access technologies such as wireless authentication, VPN access, and 802.1X. Modern RADIUS implementations commonly use UDP port 1812 for authentication and authorization and UDP port 1813 for accounting. RADIUS is different from TACACS+, which is commonly associated with administrative access to network devices and uses TCP. LDAP is primarily a directory-access protocol, while Kerberos provides ticket-based authentication. Therefore, RADIUS is the protocol described in this question.<\/span><\/p>\n<h3><b>Question 302<\/b><\/h3>\n<p><b>Which feature allows a network administrator to configure a switch port so that only a limited number of MAC addresses can use the port?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic ARP Inspection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP snooping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Root Guard<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Port security allows administrators to control which MAC addresses can use a switch interface. A maximum number of secure MAC addresses can be configured, and addresses can be learned dynamically or assigned statically depending on the implementation. If a violation occurs, the switch can take actions such as dropping unauthorized traffic, generating notifications, or disabling the interface. Dynamic ARP Inspection focuses on validating ARP messages, DHCP snooping protects against unauthorized DHCP activity, and Root Guard protects the Spanning Tree topology. Therefore, port security is the appropriate feature for limiting the number of MAC addresses on a switch port.<\/span><\/p>\n<h3><b>Question 303<\/b><\/h3>\n<p><b>Which security control is specifically designed to detect and block malicious network traffic by actively inspecting packets?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IDS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firewall logging<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Syslog<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">An Intrusion Prevention System (IPS) actively inspects network traffic and can automatically block or prevent traffic identified as malicious according to configured signatures, behavioral rules, or security policies. This distinguishes an IPS from a traditional intrusion detection system, which primarily detects and alerts without directly blocking the traffic. Firewall logging records events, while Syslog provides a mechanism for transmitting and collecting log messages. An IPS can therefore serve as an active security control positioned within or integrated into the network traffic path. The correct answer is IPS.<\/span><\/p>\n<h3><b>Question 304<\/b><\/h3>\n<p><b>Which type of access control uses characteristics such as department, location, device type, and time of day when making an authorization decision?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DAC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RBAC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MAC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ABAC<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Attribute-Based Access Control (ABAC) evaluates attributes associated with users, devices, resources, and environmental conditions when determining whether access should be permitted. Examples include a user&#8217;s department, device security status, geographic location, requested resource, and time of access. This allows organizations to create detailed policies that can adapt to different circumstances. Role-Based Access Control primarily uses predefined roles, while Discretionary Access Control relies on resource owners and Mandatory Access Control uses centrally defined classifications. Therefore, ABAC is the model that can combine multiple attributes in an authorization decision.<\/span><\/p>\n<h3><b>Question 305<\/b><\/h3>\n<p><b>Which security mechanism is designed to prevent unauthorized devices from connecting through a switch port by validating endpoint identity?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">802.1X<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNSSEC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPsec<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SPF<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">IEEE 802.1X provides port-based network access control by requiring an endpoint to authenticate before receiving normal network access. The endpoint acts as the supplicant, the switch or wireless access point acts as the authenticator, and an authentication server such as RADIUS can validate the credentials. This prevents unauthorized endpoints from freely accessing protected network resources through a switch port. DNSSEC protects DNS integrity, IPsec secures IP communications, and SPF is an email-security mechanism. Therefore, 802.1X is the appropriate technology for controlling network access based on endpoint authentication.<\/span><\/p>\n<h3><b>Question 306<\/b><\/h3>\n<p><b>Which attack attempts to manipulate the DNS cache so that users are redirected to an attacker-controlled destination?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ARP spoofing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS cache poisoning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP starvation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MAC flooding<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">DNS cache poisoning occurs when an attacker causes false DNS information to be stored in a resolver&#8217;s cache. When users subsequently request the affected domain, the resolver may provide the malicious IP address instead of the legitimate one. This can redirect users to attacker-controlled websites that may attempt to steal credentials, deliver malware, or collect sensitive information. ARP spoofing targets IP-to-MAC mappings, DHCP starvation exhausts DHCP address pools, and MAC flooding targets switch CAM tables. DNSSEC can help reduce certain DNS manipulation risks by providing cryptographic validation of DNS data.<\/span><\/p>\n<h3><b>Question 307<\/b><\/h3>\n<p><b>Which security protocol is commonly used to protect management traffic between a network-management system and network devices?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SNMPv1<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SNMPv2c<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SNMPv3<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Telnet<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">SNMPv3 provides security features that are not available in the same way in earlier SNMP versions. It can provide authentication, integrity, and privacy for management communications. This makes SNMPv3 more appropriate for securely monitoring and managing network infrastructure across potentially untrusted networks. SNMPv1 and SNMPv2c commonly rely on community strings and do not provide the same level of built-in security. Telnet provides remote terminal access but transmits information without encryption. Therefore, SNMPv3 is the preferred choice among these options for securing network-management traffic.<\/span><\/p>\n<h3><b>Question 308<\/b><\/h3>\n<p><b>Which security feature helps prevent an unauthorized switch from becoming the Spanning Tree root by blocking superior BPDUs on a protected port?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Root Guard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BPDU Guard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP snooping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port security<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Root Guard helps protect the intended Spanning Tree topology by preventing a designated interface from accepting superior Bridge Protocol Data Units that could cause an unauthorized switch to become the root bridge. If superior BPDUs are received on a Root Guard-protected interface, the port can enter a root-inconsistent state until the superior information is removed. BPDU Guard has a different purpose: it protects edge ports from unexpected BPDUs and can place them into an error-disabled state. DHCP snooping protects DHCP operations, while port security controls MAC addresses. Therefore, Root Guard is correct.<\/span><\/p>\n<h3><b>Question 309<\/b><\/h3>\n<p><b>Which security technology can use endpoint information such as operating system, device type, and user identity to apply network-access policies?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco ISE<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Cisco Identity Services Engine (ISE) can provide centralized identity and access-control capabilities for enterprise networks. It can use information about users and endpoints, including identity, device characteristics, authentication status, and posture information, to apply network-access policies. ISE can work with technologies such as 802.1X, MAB, RADIUS, and network-access control policies. NAT translates IP addresses, NTP synchronizes system clocks, and FTP transfers files. Therefore, Cisco ISE is the technology that can use endpoint and identity information to enforce network-access policies.<\/span><\/p>\n<h3><b>Question 310<\/b><\/h3>\n<p><b>Which security control provides multiple independent layers of protection so that failure of one control does not necessarily expose the entire environment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single sign-on<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defense in depth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port forwarding<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data compression<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Defense in depth is a security strategy that uses multiple complementary security controls rather than relying on a single protection mechanism. For example, an organization might combine firewalls, network segmentation, endpoint security, multifactor authentication, intrusion prevention, monitoring, and backups. If one control fails or is bypassed, additional controls can still provide protection or limit the attacker&#8217;s progress. Single sign-on simplifies authentication, port forwarding modifies how connections are directed, and data compression reduces data size. Therefore, defense in depth describes the layered security approach in this question.<\/span><\/p>\n<h3><b>Question 311<\/b><\/h3>\n<p><b>Which technology can inspect encrypted TLS traffic after decrypting it for security analysis and then re-encrypt it before forwarding it?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TLS inspection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP snooping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ARP inspection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">TLS inspection allows a security device to decrypt encrypted traffic so that it can inspect the contents for threats, policy violations, malware, or other suspicious activity. After inspection, the traffic can be re-encrypted and forwarded toward its destination. Without appropriate inspection, encrypted traffic can potentially conceal malicious content from traditional security controls. TLS inspection requires careful certificate management because the security device typically acts as an intermediary for the protected connection. DHCP snooping protects DHCP operations, port security restricts MAC addresses, and ARP inspection validates ARP traffic. Therefore, TLS inspection is correct.<\/span><\/p>\n<h3><b>Question 312<\/b><\/h3>\n<p><b>Which type of malware can independently replicate and spread from one system to another without requiring a user to execute an infected file?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Trojan<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Spyware<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Worm<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ransomware<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">A worm is malware capable of self-propagation, allowing it to spread from one system to another without necessarily requiring a user to manually execute an infected file. Worms may exploit network vulnerabilities, weak credentials, or other weaknesses to reach additional systems. A Trojan typically disguises itself as legitimate software and relies on a user or administrator to execute it. Spyware focuses on secretly collecting information, while ransomware generally encrypts or locks data to demand payment. Therefore, the malware characterized by independent replication and network propagation is a worm.<\/span><\/p>\n<h3><b>Question 313<\/b><\/h3>\n<p><b>Which type of attack attempts to capture a valid authentication exchange and reuse the captured information later?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replay attack<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL injection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DDoS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Watering-hole attack<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">A replay attack occurs when an attacker captures valid authentication information or communication and later retransmits it to attempt unauthorized access. If a protocol does not adequately protect against replay, an attacker may be able to reuse captured messages even without knowing the underlying secret. Security mechanisms such as timestamps, sequence numbers, nonces, and challenge-response authentication can help prevent replay attacks. SQL injection targets vulnerable database queries, DDoS attempts to overwhelm services with traffic, and watering-hole attacks compromise websites commonly visited by a target group. Therefore, replay attack is correct.<\/span><\/p>\n<h3><b>Question 314<\/b><\/h3>\n<p><b>Which vulnerability-management metric provides a standardized numerical assessment of the severity of a vulnerability?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CVE<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CVSS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IOC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SIEM<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">The Common Vulnerability Scoring System (CVSS) provides a standardized framework for assessing the severity of security vulnerabilities. CVSS scores consider factors such as exploitability and potential impact, helping organizations prioritize remediation activities. A CVE identifier is primarily used to identify a specific publicly known vulnerability, while an IOC is an indicator of compromise that can assist detection and investigation. SIEM is a security monitoring and event-correlation technology. Therefore, CVSS is the metric used to provide a standardized severity assessment of vulnerabilities.<\/span><\/p>\n<h3><b>Question 315<\/b><\/h3>\n<p><b>Which document defines acceptable employee behavior when using an organization&#8217;s information systems and network resources?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disaster Recovery Plan<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Incident Response Plan<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Acceptable Use Policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Business Continuity Plan<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">An Acceptable Use Policy (AUP) defines how employees and other authorized users may use an organization&#8217;s information systems, networks, devices, and services. It can address activities such as prohibited software, inappropriate web usage, handling of company information, personal device use, and other security responsibilities. An Incident Response Plan describes how security incidents should be handled. A Disaster Recovery Plan focuses on restoring systems after disruptive events, while a Business Continuity Plan addresses maintaining critical operations. Therefore, the Acceptable Use Policy is the document that defines expected and prohibited user behavior.<\/span><\/p>\n<h3><b>Question 316<\/b><\/h3>\n<p><b>Which security practice ensures that an organization knows what hardware, software, and other technology resources exist in its environment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Asset inventory<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password rotation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">An asset inventory provides an organized record of hardware, software, network devices, applications, cloud resources, and other technology assets belonging to an organization. Maintaining an accurate inventory is important because security teams cannot effectively protect systems they do not know exist. Asset inventories can support vulnerability management, patching, risk assessment, incident response, and compliance activities. Data encryption protects information, network segmentation separates network environments, and password rotation changes authentication credentials. Therefore, maintaining an asset inventory is the security practice that ensures an organization has visibility into its technology resources.<\/span><\/p>\n<h3><b>Question 317<\/b><\/h3>\n<p><b>Which security mechanism can detect unauthorized changes to important files by comparing their current cryptographic hashes with previously recorded values?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File integrity monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP relay<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">File Integrity Monitoring (FIM) detects unauthorized or unexpected changes to files by establishing a known baseline and comparing later file states against it. Cryptographic hashes can be used to identify changes because even a small modification to a file can produce a different hash value. FIM is commonly used to monitor sensitive system files, configuration files, application components, and other important resources. NAT translates addresses, DHCP relay forwards DHCP messages between network segments, and load balancing distributes traffic among systems. Therefore, file integrity monitoring is the appropriate security mechanism.<\/span><\/p>\n<h3><b>Question 318<\/b><\/h3>\n<p><b>Which network security architecture separates public-facing servers from the internal corporate network using firewall-controlled boundaries?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open network<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Flat network<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DMZ architecture<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Peer-to-peer network<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">A DMZ architecture places public-facing services such as web, email, or DNS servers in a separate network segment from the internal corporate network. Firewalls can enforce security policies between the Internet, DMZ, and internal network. This separation limits the potential impact if a publicly accessible server becomes compromised because the attacker does not automatically gain direct access to internal systems. A flat network provides less segmentation, while open and peer-to-peer network models do not specifically provide the layered security boundaries described. Therefore, DMZ architecture is the correct answer.<\/span><\/p>\n<h3><b>Question 319<\/b><\/h3>\n<p><b>Which security principle requires access decisions to be continuously evaluated instead of assuming that previously authenticated users should always remain trusted?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Zero Trust<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network Address Translation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static routing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Zero Trust emphasizes continuous verification rather than granting permanent trust after an initial authentication event. Access decisions can consider identity, device security posture, resource sensitivity, context, and current policy requirements. A user or device that successfully authenticated earlier is not automatically considered trustworthy for every subsequent request. This approach can reduce the impact of stolen credentials and compromised endpoints by limiting access to only what is required. NAT translates addresses, port security controls switch interfaces, and static routing determines network paths. Therefore, Zero Trust is the security principle described.<\/span><\/p>\n<h3><b>Question 320<\/b><\/h3>\n<p><b>Which incident-response activity focuses on limiting the spread of an attack while allowing security teams time to investigate and remediate it?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Recovery<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Eradication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Preparation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Containment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Containment is the incident-response activity focused on limiting the scope and impact of an active security incident. Security teams may isolate compromised endpoints, block malicious network connections, disable compromised accounts, or segment affected systems to prevent further spread. The goal is to control the incident while preserving enough information for investigation and remediation. Eradication focuses on removing the threat and its causes, while recovery focuses on restoring normal operations. Preparation occurs before incidents and establishes procedures, tools, and resources. Therefore, containment is the correct phase for limiting the spread of an attack.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco 200-201 Exam Dumps and Practice Test Dumps. &nbsp; Question 301 Which protocol provides centralized authentication and authorization for network access while commonly using UDP ports 1812 and 1813? RADIUS TACACS+ LDAP Kerberos Correct Answer: 1 Explanation RADIUS is a widely used AAA protocol that provides centralized authentication, authorization, and accounting services. It [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14475"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=14475"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14475\/revisions"}],"predecessor-version":[{"id":14487,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14475\/revisions\/14487"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=14475"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=14475"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=14475"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}