{"id":14478,"date":"2026-09-17T05:08:00","date_gmt":"2026-09-17T05:08:00","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=14478"},"modified":"2026-09-17T05:08:00","modified_gmt":"2026-09-17T05:08:00","slug":"cisco-200-201-practice-test-questions-and-exam-dumps-part19-q361-380","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-200-201-practice-test-questions-and-exam-dumps-part19-q361-380\/","title":{"rendered":"Cisco 200-201 Practice Test Questions and Exam Dumps Part19 Q361-380"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"http:\/\/examlabs.com\/200-201-exam-dumps\"><b>Cisco 200-201 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 361<\/b><\/h3>\n<p><b>Which security control provides a centralized method for collecting authentication logs and tracking user access activity?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RADIUS accounting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNSSEC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP snooping<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">RADIUS accounting provides a centralized mechanism for recording information about user network-access sessions. It can record details such as when a user connects, when the session ends, and other attributes associated with network access. This information can support auditing, troubleshooting, security investigations, and usage monitoring. Authentication determines whether a user is allowed to access the network, while accounting records information about the resulting activity. DNSSEC protects DNS information, port security controls switch interfaces, and DHCP snooping protects DHCP operations. Therefore, RADIUS accounting is the appropriate technology for centralized tracking of network-access activity.<\/span><\/p>\n<h3><b>Question 362<\/b><\/h3>\n<p><b>Which security technology can enforce access policies based on a user&#8217;s identity and the security posture of the endpoint?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco ISE<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Cisco Identity Services Engine (ISE) provides identity-based access control and can evaluate information about users and endpoints when making network-access decisions. It can work with technologies such as 802.1X, MAB, RADIUS, endpoint profiling, and posture assessment. Policies can consider factors such as user identity, device type, authentication status, and security posture. NAT translates addresses, NTP synchronizes clocks, and FTP transfers files. Cisco ISE therefore provides the centralized identity and policy capabilities described in the question.<\/span><\/p>\n<h3><b>Question 363<\/b><\/h3>\n<p><b>Which attack attempts to exhaust the resources of a server or network service by sending a large number of requests from many compromised systems?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Brute-force attack<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL injection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Distributed denial-of-service attack<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Credential stuffing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">A Distributed Denial-of-Service (DDoS) attack attempts to overwhelm a target using traffic or requests generated from multiple compromised or otherwise distributed systems. The objective is to consume resources such as bandwidth, CPU, memory, or connection capacity so legitimate users cannot access the service normally. A brute-force attack attempts to guess credentials, SQL injection targets vulnerable database queries, and credential stuffing uses previously stolen credentials. Organizations can use traffic filtering, rate limiting, specialized mitigation services, and other controls to reduce DDoS impact. Therefore, DDoS is correct.<\/span><\/p>\n<h3><b>Question 364<\/b><\/h3>\n<p><b>Which security mechanism can provide evidence that a message was signed by a particular private key and has not been modified?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Digital signature<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">A digital signature provides cryptographic evidence that data was signed using a particular private key and can help verify that the signed information has not been modified. The sender uses a private key to create the signature, while the recipient uses the corresponding public key to verify it. Digital signatures support integrity and authentication and can contribute to nonrepudiation depending on the implementation and legal context. NAT translates addresses, VLANs provide network segmentation, and DHCP supplies network configuration. Therefore, a digital signature is the appropriate security mechanism.<\/span><\/p>\n<h3><b>Question 365<\/b><\/h3>\n<p><b>Which security control helps limit communication between different network security zones according to defined policies?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File hashing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">A firewall can control communication between different network security zones according to configured policies. Organizations can use firewalls to separate internal networks, guest networks, server networks, DMZs, management networks, and external networks. Rules can allow required traffic while blocking unauthorized connections. This segmentation can reduce the ability of an attacker to move laterally after compromising one system. File hashing is used to identify data changes, password managers securely store credentials, and NTP synchronizes clocks. Therefore, a firewall is the security control that can enforce communication policies between network zones.<\/span><\/p>\n<h3><b>Question 366<\/b><\/h3>\n<p><b>Which type of malware disguises itself as legitimate software to trick a user into installing or executing it?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Worm<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Rootkit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Trojan horse<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ransomware<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">A Trojan horse is malware that disguises itself as legitimate or useful software to persuade a victim to install or execute it. Once executed, the malicious program may steal information, provide unauthorized access, install additional malware, or perform other harmful activities. Unlike a worm, a Trojan does not primarily depend on self-propagation. Rootkits focus on hiding malicious activity and maintaining access, while ransomware generally attempts to encrypt or otherwise restrict access to data. Therefore, Trojan horse is the correct malware category described in the question.<\/span><\/p>\n<h3><b>Question 367<\/b><\/h3>\n<p><b>Which technology allows administrators to identify the operating system and device type of endpoints connecting to a network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NetFlow<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco ISE profiling<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNSSEC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SNMPv1<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Cisco ISE profiling can identify characteristics of endpoints connected to a network and use those characteristics in access-control policies. Profiling can help distinguish devices such as computers, smartphones, printers, IP phones, cameras, and other endpoint types. Information gathered from network activity and other available attributes can support policy decisions. NetFlow provides information about traffic flows, DNSSEC protects DNS data, and SNMPv1 is an older network-management protocol. Therefore, Cisco ISE profiling is the technology most directly associated with identifying endpoint characteristics for access-control purposes.<\/span><\/p>\n<h3><b>Question 368<\/b><\/h3>\n<p><b>Which security practice helps ensure that security logs from different systems can be accurately correlated by using consistent timestamps?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Time synchronization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port security<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Time synchronization ensures that systems and network devices maintain consistent and accurate clocks. This is important for security monitoring because analysts often need to correlate events occurring across multiple systems. If devices have significantly different timestamps, it can become difficult to establish the correct sequence of events during an investigation. NTP is commonly used to synchronize system clocks with trusted time sources. Network segmentation separates networks, encryption protects information, and port security controls switch interfaces. Therefore, time synchronization is essential for accurate correlation of security logs.<\/span><\/p>\n<h3><b>Question 369<\/b><\/h3>\n<p><b>Which security architecture places public-facing servers in a dedicated network segment isolated from the internal network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DMZ<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Flat network<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Peer-to-peer network<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open LAN<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">A Demilitarized Zone (DMZ) is a dedicated network segment commonly used to host public-facing services such as web, DNS, mail, or other externally accessible servers. Firewalls can control communication between the Internet, DMZ, and internal network. This architecture provides an additional security boundary so that compromise of a public-facing server does not automatically provide unrestricted access to internal systems. A flat network provides little segmentation, while peer-to-peer and open LAN designs do not specifically provide the security architecture described. Therefore, a DMZ is correct.<\/span><\/p>\n<h3><b>Question 370<\/b><\/h3>\n<p><b>Which security technique attempts to determine whether a system contains exploitable vulnerabilities by actively testing the system?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Asset inventory<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Penetration testing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Log collection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Backup verification<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Penetration testing is an authorized security assessment in which testers actively attempt to exploit vulnerabilities in systems, applications, networks, or other resources. The objective is to determine whether identified weaknesses can actually be exploited and to understand their potential impact. Vulnerability scanning can identify potential weaknesses but generally does not attempt exploitation in the same manner as penetration testing. Asset inventory identifies resources, log collection gathers events, and backup verification confirms that backups can be restored. Therefore, penetration testing is the correct answer.<\/span><\/p>\n<h3><b>Question 371<\/b><\/h3>\n<p><b>Which security feature can prevent an edge switch port from participating in Spanning Tree after receiving an unexpected BPDU?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BPDU Guard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Root Guard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP snooping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IP Source Guard<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">BPDU Guard protects edge ports by responding when unexpected Bridge Protocol Data Units are received. If a BPDU arrives on a port where BPDUs are not expected, BPDU Guard can place the interface into an error-disabled state. This helps prevent unauthorized switches from influencing the Spanning Tree topology through ports intended for end devices. Root Guard has a different purpose and prevents a port from accepting superior BPDUs that could change the root bridge. DHCP snooping protects DHCP operations, while IP Source Guard helps prevent IP address spoofing. Therefore, BPDU Guard is correct.<\/span><\/p>\n<h3><b>Question 372<\/b><\/h3>\n<p><b>Which security feature helps prevent an unauthorized switch from becoming the root bridge in a Spanning Tree topology?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">PortFast<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Root Guard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP snooping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File Integrity Monitoring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Root Guard helps protect the intended Spanning Tree topology by preventing a protected interface from accepting superior BPDUs that could cause another switch to become the root bridge. If superior BPDUs are received, the interface can enter a root-inconsistent state until the unexpected information is removed. PortFast accelerates the forwarding transition of edge ports but does not protect the root role. DHCP snooping protects DHCP traffic, while File Integrity Monitoring detects changes to files. Therefore, Root Guard is the appropriate security feature.<\/span><\/p>\n<h3><b>Question 373<\/b><\/h3>\n<p><b>Which security mechanism protects sensitive information by transforming readable data into ciphertext using an encryption algorithm?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hashing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Digital signature<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tokenization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Encryption transforms readable plaintext into ciphertext using a cryptographic algorithm and key. Authorized parties with the appropriate key can decrypt the ciphertext and recover the original information. Encryption is commonly used to protect data at rest and data in transit. Hashing creates a one-way digest rather than reversible ciphertext, while digital signatures provide authentication and integrity capabilities. Tokenization replaces sensitive values with tokens that represent the original data without directly exposing it. Therefore, encryption is the mechanism that transforms readable information into ciphertext for confidentiality.<\/span><\/p>\n<h3><b>Question 374<\/b><\/h3>\n<p><b>Which attack attempts to take control of an already authenticated user&#8217;s active session?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Session hijacking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS poisoning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP starvation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MAC flooding<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Session hijacking occurs when an attacker obtains or otherwise takes control of a valid authenticated session. Instead of needing to authenticate normally, the attacker may attempt to use a stolen session token, cookie, or other session identifier to impersonate the legitimate user. Strong session management, HTTPS, secure cookies, multifactor authentication, and appropriate session expiration policies can help reduce the risk. DNS poisoning manipulates DNS information, DHCP starvation exhausts address pools, and MAC flooding targets switch CAM tables. Therefore, session hijacking is the correct attack.<\/span><\/p>\n<h3><b>Question 375<\/b><\/h3>\n<p><b>Which security protocol provides encryption and authentication for IP traffic and is commonly used to create VPN tunnels?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SMTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPsec<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SNMP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">IPsec is a collection of protocols and standards used to secure IP communications. It can provide confidentiality, integrity, authentication, and anti-replay protection depending on the selected protocols and configuration. IPsec is widely used to establish secure VPN connections, including site-to-site and remote-access VPNs. SMTP is used for email transport, SNMP is used for network management, and DHCP provides automatic network configuration. Therefore, IPsec is the technology commonly used to secure IP traffic and create VPN tunnels.<\/span><\/p>\n<h3><b>Question 376<\/b><\/h3>\n<p><b>Which type of VPN connects two or more entire networks rather than providing access for only one individual remote user?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remote-access VPN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Site-to-site VPN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Host-based firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Proxy server<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">A site-to-site VPN securely connects entire networks through a VPN tunnel, allowing systems at one location to communicate with systems at another location over an untrusted network. This type of VPN is commonly used to connect branch offices, data centers, or organizational sites. A remote-access VPN is generally designed for individual users connecting to an organization&#8217;s network from external locations. A host-based firewall protects an individual system, while a proxy server acts as an intermediary for specific traffic. Therefore, site-to-site VPN is correct.<\/span><\/p>\n<h3><b>Question 377<\/b><\/h3>\n<p><b>Which security method replaces sensitive information such as payment-card data with a non-sensitive substitute value?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tokenization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hashing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Compression<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Tokenization replaces sensitive information with a substitute value called a token. The token can be used by systems that do not need direct access to the original sensitive data, reducing the number of systems that must store or process the actual information. Tokenization is commonly used for payment-card data and other sensitive information. Encryption transforms data into ciphertext using a cryptographic key, hashing creates a fixed-length digest, and compression reduces data size. Therefore, tokenization is the security technique described in the question.<\/span><\/p>\n<h3><b>Question 378<\/b><\/h3>\n<p><b>Which security technology can detect and block access to websites categorized as malicious, phishing, or otherwise prohibited by organizational policy?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web security filtering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RADIUS accounting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP relay<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Web security filtering can inspect web requests and apply organizational policies to determine whether access should be allowed. Security filters may block websites associated with malware, phishing, inappropriate content, or other categories selected by an organization. Depending on the implementation, filtering can occur through DNS security, secure web gateways, proxies, or other security services. NTP synchronizes system clocks, RADIUS accounting records authentication activity, and DHCP relay forwards DHCP messages between network segments. Therefore, web security filtering is the appropriate technology for controlling access to malicious or prohibited websites.<\/span><\/p>\n<h3><b>Question 379<\/b><\/h3>\n<p><b>Which security technology can use a centralized server to authenticate administrators accessing network devices and provide detailed authorization controls?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TACACS+<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TFTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">TACACS+ is a AAA protocol commonly used to centrally manage administrative access to network devices. It supports authentication, authorization, and accounting and can provide detailed authorization policies for administrative commands. This allows organizations to control what individual administrators can do after successfully authenticating. TACACS+ uses TCP and encrypts the body of the authentication packet between the client and server. DHCP provides IP configuration, DNS resolves domain names, and TFTP provides basic file transfer. Therefore, TACACS+ is the appropriate centralized protocol for network-device administrative access.<\/span><\/p>\n<h3><b>Question 380<\/b><\/h3>\n<p><b>Which security principle focuses on ensuring that authorized users can access systems and information when they are needed?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Confidentiality<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Integrity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Availability<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Authentication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Availability ensures that authorized users can access systems, applications, and information when they need them. Security controls that support availability include redundancy, backups, disaster recovery planning, DDoS protection, fault-tolerant infrastructure, and appropriate capacity management. Confidentiality focuses on preventing unauthorized disclosure, while integrity ensures information is not improperly modified. Authentication verifies the identity of users or devices. Availability is especially important for business-critical applications where service interruptions can affect operations. Therefore, availability is the security principle described in the question.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco 200-201 Exam Dumps and Practice Test Dumps. &nbsp; Question 361 Which security control provides a centralized method for collecting authentication logs and tracking user access activity? RADIUS accounting DNSSEC Port security DHCP snooping Correct Answer: 1 Explanation RADIUS accounting provides a centralized mechanism for recording information about user network-access sessions. It can [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14478"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=14478"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14478\/revisions"}],"predecessor-version":[{"id":14484,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14478\/revisions\/14484"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=14478"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=14478"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=14478"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}