{"id":14604,"date":"2026-09-17T06:09:54","date_gmt":"2026-09-17T06:09:54","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=14604"},"modified":"2026-09-17T06:09:54","modified_gmt":"2026-09-17T06:09:54","slug":"cisco-ccnp-cybersecurity-350-201-practice-test-questions-and-exam-dumps-part2-q21-40","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-ccnp-cybersecurity-350-201-practice-test-questions-and-exam-dumps-part2-q21-40\/","title":{"rendered":"Cisco CCNP Cybersecurity 350-201 Practice Test Questions and Exam Dumps Part2 Q21-40"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/350-201-exam-dumps\"><b>Cisco CCNP Cybersecurity 350-201 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 21<\/b><\/h3>\n<p><b>What protocol secures email transmission using cryptographic public keys?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Pretty Good Privacy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Telnet remote administration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File Transfer Protocol<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Trivial File Transfer Protocol<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Pretty Good Privacy (PGP) is a widely used cryptographic software system that provides cryptographic privacy and authentication for data communication. PGP is frequently utilized for signing, encrypting, and decrypting texts, emails, files, directories, and whole disk partitions to increase the security of email communications. It combines symmetric encryption algorithms and public-key cryptography to ensure robust confidentiality and integrity. By utilizing a web of trust model, PGP allows users to verify digital signatures and establish trust in public keys without relying exclusively on centralized certificate authorities, making it a powerful tool for secure peer-to-peer messaging.<\/span><\/p>\n<h3><b>Question 22<\/b><\/h3>\n<p><b>Which wireless security standard mandates CCMP and AES encryption?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Wired Equivalent Privacy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Wi-Fi Protected Access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Wi-Fi Protected Access 2<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open unencrypted wireless<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Wi-Fi Protected Access 2 (WPA2) was introduced by the Wi-Fi Alliance to provide robust enterprise-grade security for wireless local area networks, addressing critical cryptographic vulnerabilities found in original WEP and transitional WPA-TKIP protocols. WPA2 mandates the use of the Advanced Encryption Standard (AES) algorithm combined with Counter Mode with Cipher Block Chaining Message Authentication Code Protocol (CCMP) to ensure strict data confidentiality, integrity, and authentication over the air. By utilizing strong cryptographic keys and secure cipher wrappers, WPA2 effectively protects enterprise wireless communications against unauthorized eavesdropping, packet injection, and cryptographic cracking attacks.<\/span><\/p>\n<h3><b>Question 23<\/b><\/h3>\n<p><b>What attack floods target servers to disrupt operational availability?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Structured Query Language injection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Denial of Service attack<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cross-site scripting attack<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Address Resolution Protocol spoofing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Denial of Service (DoS) attack is a malicious cyber threat designed to render a target system, network, or application unavailable to its intended users. Attackers achieve this by flooding the victim resource with an overwhelming volume of illegitimate traffic or exploiting software vulnerabilities to exhaust critical system resources, such as processing power, memory, bandwidth, or connection tables. Distributed Denial of Service (DDoS) attacks scale this concept by utilizing coordinated networks of compromised machines, known as botnets, to launch synchronized floods from multiple geographic sources. Mitigating these attacks requires robust traffic monitoring, rate-limiting, and cloud-based scrubbing centers.<\/span><\/p>\n<h3><b>Question 24<\/b><\/h3>\n<p><b>Which security tool captures and analyzes network traffic packets?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Packet sniffer network analyzer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Layer 2 Ethernet switch<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Basic network repeater hub<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unshielded twisted-pair patch cable<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A packet analyzer\u2014commonly referred to as a packet sniffer or network protocol analyzer\u2014is a specialized software or hardware tool designed to intercept, log, and analyze network traffic traversing a wired or wireless medium. When packets pass through a network interface card configured in promiscuous mode, the analyzer captures raw binary frames, decodes encapsulation layers, and displays detailed protocol metrics, payloads, and header fields. Security analysts and network engineers rely heavily on packet sniffers like Wireshark during troubleshooting and forensic investigations to examine network communications, detect anomalies, identify malicious payloads, and audit security policies.<\/span><\/p>\n<h3><b>Question 25<\/b><\/h3>\n<p><b>What vulnerability allows malicious input into database queries?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cross-site scripting vulnerability<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Buffer overflow flaw<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Structured Query Language injection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Man-in-the-middle interception<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">SQL injection (SQLi) is a dangerous code injection vulnerability that occurs when malicious user input is improperly sanitized and concatenated directly into database query statements. If an application fails to validate input properly, an attacker can input specially crafted SQL commands into web forms or uniform resource locators, tricking the underlying database management system into executing unauthorized commands. This can lead to severe security breaches, including unauthorized access to sensitive user data, table modification, credential theft, and complete database server compromise. Preventing SQLi requires parameterized queries, input validation, and stored procedures.<\/span><\/p>\n<h3><b>Question 26<\/b><\/h3>\n<p><b>Which cryptographic hash function produces a 256-bit digest?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Message Digest 5<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secure Hash Algorithm 256<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secure Hash Algorithm 1<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data Encryption Standard<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Secure Hash Algorithm 256 (SHA-256) is a member of the SHA-2 cryptographic hash function family designed by the National Security Agency. SHA-256 takes an input of arbitrary length and produces a fixed 256-bit (32-byte) hash value, typically represented as a 64-character hexadecimal string. Because of its cryptographic strength and collision resistance, SHA-256 is widely utilized across modern security protocols, including digital certificates, blockchain transactions, secure firmware updates, and TLS encryption handshakes. It ensures data integrity by making it computationally infeasible for attackers to alter data without changing the resulting hash digest.<\/span><\/p>\n<h3><b>Question 27<\/b><\/h3>\n<p><b>What protocol manages network device configurations securely via SSH?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Telnet protocol<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hypertext Transfer Protocol<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Trivial File Transfer Protocol<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network Configuration Protocol<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network Configuration Protocol (NETCONF) is a network management protocol developed by the Internet Engineering Task Force to address the limitations of legacy management interfaces like SNMP and CLI scripting. NETCONF provides mechanisms to install, manipulate, and delete the configurations of network devices programmatically. It operates over secure transport protocols like Secure Shell (SSH), ensuring that management sessions and configuration data payloads are fully encrypted and authenticated. By utilizing XML-based data encodings and supporting structured data models like YANG, NETCONF enables automated network orchestration and software-defined networking workflows.<\/span><\/p>\n<h3><b>Question 28<\/b><\/h3>\n<p><b>Which security device monitors and blocks unauthorized network traffic?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Enterprise network firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Passive repeater hub<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Structured cabling patch panel<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Layer 2 Ethernet bridge<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A network firewall is a dedicated security system designed to monitor, filter, and control incoming and outgoing network traffic based on a pre-configured set of organizational security rules. Operating at various layers of the OSI model depending on architecture, firewalls establish a trusted boundary between internal corporate networks and untrusted external environments like the internet. Modern next-generation firewalls integrate deep packet inspection, intrusion prevention, and application awareness to block malicious traffic, prevent unauthorized access, and protect enterprise assets against sophisticated cyber threats while permitting legitimate business communications.<\/span><\/p>\n<h3><b>Question 29<\/b><\/h3>\n<p><b>What mechanism prevents unauthorized access via wireless network pre-shared keys?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Wired Equivalent Privacy encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open unencrypted network authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">WPA3-Personal Simultaneous Authentication of Equals<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Passive hub signal repeating<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Wi-Fi Protected Access 3 Personal introduced advanced cryptographic enhancements to secure wireless networks against offline dictionary attacks. Traditional WPA2-Personal networks relied on static pre-shared keys, allowing attackers to capture handshake packets over the air and execute brute-force decryption offline if the passphrase was weak. WPA3-Personal replaces this exchange with Simultaneous Authentication of Equals (SAE), a secure key establishment protocol based on elliptic-curve cryptography. SAE ensures that even if users choose weak passwords, attackers cannot recover the password through offline dictionary attacks, while also providing robust forward secrecy for wireless sessions.<\/span><\/p>\n<h3><b>Question 30<\/b><\/h3>\n<p><b>Which attack intercepts communications between two unsuspecting network endpoints?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Denial of service attack<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Man-in-the-middle attack<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Structured Query Language injection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Buffer overflow execution<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A man-in-the-middle (MitM) attack occurs when a malicious actor secretly intercepts and relays communications between two parties who believe they are communicating directly with each other. The attacker positions themselves along the communication path, enabling them to eavesdrop on sensitive conversations, harvest credentials, or modify data payloads in transit without the victims&#8217; knowledge. MitM attacks frequently occur on unsecured public Wi-Fi networks or through ARP spoofing and DNS poisoning techniques. Implementing robust cryptographic protocols such as HTTPS, TLS encryption, and digital certificate validation effectively neutralizes eavesdropping threats.<\/span><\/p>\n<h3><b>Question 31<\/b><\/h3>\n<p><b>What malware encrypts user files demanding financial ransom payment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Adware marketing program<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Spyware tracking software<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ransomware malware software<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Bootkit loader module<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Ransomware is a particularly destructive form of malicious software designed to deny access to a computer system or encrypt critical files until a financial ransom is paid to the cybercriminals. Once deployed on a victim machine, ransomware utilizes robust asymmetric and symmetric encryption algorithms to lock local files and connected network shares. Attackers typically leave digital drop notes demanding cryptocurrency payments in exchange for the decryption keys. Mitigating ransomware requires comprehensive multi-layered security strategies, including regular offline backups, advanced endpoint protection, employee security awareness training, and robust network segmentation.<\/span><\/p>\n<h3><b>Question 32<\/b><\/h3>\n<p><b>Which protocol provides secure file transfers over SSH transport?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File Transfer Protocol<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secure File Transfer Protocol<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Trivial File Transfer Protocol<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hypertext Transfer Protocol<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Secure File Transfer Protocol (SFTP) is a secure network protocol designed to provide file access, file transfer, and file management functionalities over any reliable data stream. Unlike legacy File Transfer Protocol (FTP) which transmits credentials and data payloads in clear text across separate control and data channels, SFTP operates entirely over a secure Secure Shell (SSH) session utilizing TCP port 22. This integration ensures that all transmitted passwords, file metadata, and data streams are fully encrypted from end to end, protecting sensitive enterprise data against eavesdropping and tampering during transit across public networks.<\/span><\/p>\n<h3><b>Question 33<\/b><\/h3>\n<p><b>What security testing method involves examining application source code?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic application analysis<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Black-box penetration testing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static code security analysis<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Active port scanning<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Static code analysis\u2014often referred to as static application security testing (SAST)\u2014is a software debugging and security methodology that analyzes source code or compiled binaries for security vulnerabilities without executing the program. Performed during early phases of the software development lifecycle, static analysis tools inspect code syntax, control flows, and architectural logic against known vulnerability patterns and secure coding standards. By identifying security flaws early in development, organizations can remediate coding defects before applications are deployed into production environments, significantly reducing software risk and remediation costs.<\/span><\/p>\n<h3><b>Question 34<\/b><\/h3>\n<p><b>Which cloud service model provides fully managed application platforms?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Platform as a Service<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Infrastructure as a Service<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Software as a Service<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Desktop as a Service<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Platform as a Service (PaaS) is a cloud computing service model that supplies an on-demand environment for developing, testing, delivering, and managing software applications. PaaS provides developers with a complete hardware and software platform\u2014including operating systems, databases, web servers, and development frameworks\u2014hosted on remote cloud infrastructure, freeing them from managing underlying physical servers or storage arrays. This allows development teams to focus entirely on writing code and building applications, accelerating time-to-market while maintaining scalability and administrative efficiency across cloud environments.<\/span><\/p>\n<h3><b>Question 35<\/b><\/h3>\n<p><b>What security device detects malicious network intrusions via signatures?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ethernet Layer 2 switch<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network signal repeater<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Intrusion Detection System<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Structured cabling patch panel<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An Intrusion Detection System (IDS) is a specialized security appliance or software solution designed to monitor network traffic for suspicious activity, policy violations, and known attack signatures. Operating primarily in passive monitoring modes by tapping into SPAN ports or optical splitters, an IDS analyzes packet streams and compares them against signature databases or behavioral anomaly baselines. When a potential security threat or intrusion attempt is identified, the IDS generates real-time security alerts for administrative review, allowing security operations teams to investigate and respond to cyber threats without interrupting live network traffic flows.<\/span><\/p>\n<h3><b>Question 36<\/b><\/h3>\n<p><b>Which protocol provides secure directory service authentication over networks?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Lightweight Directory Access Protocol<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Lightweight Directory Access Protocol Secure<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unencrypted Telnet protocol<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hypertext Transfer Protocol<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Lightweight Directory Access Protocol Secure (LDAPS) is the secure implementation of the standard Lightweight Directory Access Protocol, designed to provide directory service querying and user authentication across IP networks. While standard LDAP transmits directory queries, user accounts, and credentials in clear text, LDAPS wraps the communication session inside Transport Layer Security (TLS) or Secure Sockets Layer (SSL) encryption wrappers, typically operating over TCP port 636. This encryption ensures that sensitive user credentials and enterprise directory schemas are protected against packet sniffing and credential harvesting attacks.<\/span><\/p>\n<h3><b>Question 37<\/b><\/h3>\n<p><b>What security principle restricts user account permissions to minimum necessary?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defense in depth strategy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Principle of least privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Zero Trust network architecture<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Separation of duties policy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The principle of least privilege is a fundamental information security concept that dictates that a user, process, or system component must be given only the minimum levels of access permissions\u2014or privileges\u2014necessary to perform its specific, authorized job functions. By restricting privileges strictly to operational requirements, organizations significantly limit the potential blast radius of credential compromise, insider threats, and malware propagation. For example, standard network users should never possess administrative privileges, and software applications should execute under restricted service accounts rather than root-level permissions.<\/span><\/p>\n<h3><b>Question 38<\/b><\/h3>\n<p><b>Which malware type replicates automatically across networks without user action?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Computer virus infection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Trojan horse program<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Computer worm malware<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Adware spyware program<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A computer worm is a standalone malicious software program that replicates itself in order to spread to other computers across network connections. Unlike traditional computer viruses that require user intervention\u2014such as opening an infected document or running an executable file\u2014worms operate autonomously, exploiting operating system vulnerabilities or misconfigurations to scan and propagate across local networks and the internet. Once a worm infects a system, it consumes valuable bandwidth, exhausts CPU resources, and frequently installs secondary payloads like backdoors or ransomware, posing a severe threat to network availability.<\/span><\/p>\n<h3><b>Question 39<\/b><\/h3>\n<p><b>What security framework implements continuous verification of all identities?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traditional perimeter defense<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Demilitarized zone architecture<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static VLAN segmentation model<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Zero Trust Architecture<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Zero Trust Architecture (ZTA) is a modern cybersecurity paradigm based on the core philosophy of &#8220;never trust, always verify.&#8221; Traditional enterprise security models relied heavily on perimeter defenses, assuming that everything inside the corporate network was inherently trustworthy. Zero Trust eliminates this assumption, mandating continuous, strict identity verification, device health validation, and least-access authorization for every user and device attempting to access resources, regardless of whether they originate from inside or outside the traditional network perimeter.<\/span><\/p>\n<h3><b>Question 40<\/b><\/h3>\n<p><b>Which protocol secures domain name resolution records using cryptography?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Domain Name System Security Extensions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic Host Configuration Protocol<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Simple Network Management Protocol<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network Time Protocol<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Domain Name System Security Extensions (DNSSEC) is a suite of cryptographic specifications developed by the Internet Engineering Task Force to secure information provided by the Domain Name System. Traditional DNS implementations lacked built-in security, making them highly vulnerable to cache poisoning and spoofing attacks where malicious actors redirected traffic to fraudulent servers. DNSSEC addresses this by signing DNS records cryptographically using digital signatures based on public key cryptography. This allows client resolvers to verify the authenticity and integrity of DNS responses, ensuring users connect to legitimate destinations.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco CCNP Cybersecurity 350-201 Exam Dumps and Practice Test Dumps. &nbsp; Question 21 What protocol secures email transmission using cryptographic public keys? Pretty Good Privacy Telnet remote administration File Transfer Protocol Trivial File Transfer Protocol Correct Answer: 1 Explanation: Pretty Good Privacy (PGP) is a widely used cryptographic software system that provides cryptographic [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14604"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=14604"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14604\/revisions"}],"predecessor-version":[{"id":14686,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14604\/revisions\/14686"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=14604"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=14604"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=14604"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}