{"id":14605,"date":"2026-09-17T06:09:42","date_gmt":"2026-09-17T06:09:42","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=14605"},"modified":"2026-09-17T06:09:42","modified_gmt":"2026-09-17T06:09:42","slug":"cisco-ccnp-cybersecurity-350-201-practice-test-questions-and-exam-dumps-part3-q41-60","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-ccnp-cybersecurity-350-201-practice-test-questions-and-exam-dumps-part3-q41-60\/","title":{"rendered":"Cisco CCNP Cybersecurity 350-201 Practice Test Questions and Exam Dumps Part3 Q41-60"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/350-201-exam-dumps\"><b>Cisco CCNP Cybersecurity 350-201 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 41<\/b><\/h3>\n<p><b>Which protocol secures web traffic utilizing cryptographic certificates?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unencrypted Telnet remote administration protocol<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File Transfer Protocol utility<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hypertext Transfer Protocol Secure service<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Trivial File Transfer Protocol daemon<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Hypertext Transfer Protocol Secure (HTTPS) is the secure extension of standard HTTP, designed to protect web communications between client browsers and enterprise web servers against eavesdropping, tampering, and man-in-the-middle attacks. HTTPS wraps standard HTTP data payloads inside Transport Layer Security (TLS) or Secure Sockets Layer (SSL) cryptographic encryption wrappers backed by digital certificates issued by trusted certificate authorities. Network administrators configure HTTPS to operate over TCP port 443, ensuring robust data confidentiality, integrity, and authentication for modern web applications and cloud services. This cryptographic wrapping protects sensitive user data during transit across untrusted public networks.<\/span><\/p>\n<h3><b>Question 42<\/b><\/h3>\n<p><b>What security architecture assumes zero implicit network trust?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traditional perimeter defense model<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Zero Trust network architecture<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Demilitarized zone network design<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static VLAN segmentation model<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Zero Trust Architecture (ZTA) is a modern cybersecurity paradigm based on the core philosophy of &#8220;never trust, always verify.&#8221; Traditional enterprise security models relied heavily on perimeter defenses, assuming that everything inside the corporate network was inherently trustworthy. Zero Trust eliminates this assumption, mandating continuous, strict identity verification, device health validation, and least-access authorization for every user and device attempting to access resources, regardless of whether they originate from inside or outside the traditional network perimeter. By micro-segmenting resources and inspecting all traffic flows, organizations significantly reduce lateral movement and improve overall resilience.<\/span><\/p>\n<h3><b>Question 43<\/b><\/h3>\n<p><b>Which cryptographic algorithm provides secure asymmetric public key encryption?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Advanced Encryption Standard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Message Digest 5 algorithm<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secure Hash Algorithm 256<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Rivest-Shamir-Adleman cryptographic system<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Rivest-Shamir-Adleman (RSA) cryptosystem is one of the foundational public-key cryptography algorithms widely used for secure data transmission and digital signatures. Unlike symmetric encryption that utilizes a single shared key, asymmetric cryptography utilizes a mathematically linked key pair: a public key used for encrypting data or verifying signatures, and a private key kept secret for decryption and signing. RSA relies on the mathematical difficulty of factoring the product of two large prime numbers. It plays a critical role in establishing secure TLS sessions, exchanging symmetric session keys safely, and issuing digital certificates across enterprise security architectures.<\/span><\/p>\n<h3><b>Question 44<\/b><\/h3>\n<p><b>What security device inspects deep application layer payloads?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Next-Generation Firewall appliance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Layer 2 Ethernet switch<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Basic network repeater hub<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Passive copper signal regenerator<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Next-Generation Firewall (NGFW) is an advanced security appliance that goes far beyond traditional packet-filtering firewalls by performing deep packet inspection up to Layer 7 of the OSI model. While legacy firewalls evaluated only IP addresses and port numbers, NGFWs inspect application-layer traffic payloads to identify specific applications, detect sophisticated malware signatures, prevent intrusion attempts, and enforce granular security policies. They integrate traditional firewall capabilities with intrusion prevention systems, URL filtering, and advanced threat intelligence feeds, providing comprehensive security visibility and enforcement across modern corporate networks and data centers.<\/span><\/p>\n<h3><b>Question 45<\/b><\/h3>\n<p><b>Which protocol translates internal private addresses to public?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Address Resolution Protocol stack<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic Host Configuration Protocol<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network Address Translation protocol<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Internet Control Message Protocol<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network Address Translation (NAT) is a core networking mechanism used to map internal private IP addresses to external public IP addresses, thereby conserving scarce IPv4 address space. NAT operates on border routers or enterprise firewalls, modifying source or destination IP headers as packets transition between internal local networks and the public internet. This process ensures that internal host infrastructure remains hidden from direct external inspection while retaining full outbound internet connectivity. Variants like Port Address Translation allow thousands of internal client devices to share a single routable public IP address using unique port identifiers.<\/span><\/p>\n<h3><b>Question 46<\/b><\/h3>\n<p><b>What attack floods target servers to exhaust resources?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Structured Query Language injection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Denial of Service attack<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cross-site scripting attack vector<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Address Resolution Protocol spoofing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Denial of Service (DoS) attack is a malicious cyber threat designed to render a target system, network, or application unavailable to its intended users. Attackers achieve this by flooding the victim resource with an overwhelming volume of illegitimate traffic or exploiting software vulnerabilities to exhaust critical system resources, such as processing power, memory, bandwidth, or connection tables. Distributed Denial of Service (DDoS) attacks scale this concept by utilizing coordinated networks of compromised machines, known as botnets, to launch synchronized floods from multiple geographic sources. Mitigating these attacks requires robust traffic monitoring, rate-limiting, and cloud-based scrubbing centers.<\/span><\/p>\n<h3><b>Question 47<\/b><\/h3>\n<p><b>Which security tool captures and analyzes network traffic packets?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Layer 2 Ethernet switch<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Basic network repeater hub<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unshielded twisted-pair patch cable<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Packet sniffer network analyzer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A packet analyzer\u2014commonly referred to as a packet sniffer or network protocol analyzer\u2014is a specialized software or hardware tool designed to intercept, log, and analyze network traffic traversing a wired or wireless medium. When packets pass through a network interface card configured in promiscuous mode, the analyzer captures raw binary frames, decodes encapsulation layers, and displays detailed protocol metrics, payloads, and header fields. Security analysts and network engineers rely heavily on packet sniffers like Wireshark during troubleshooting and forensic investigations to examine network communications, detect anomalies, identify malicious payloads, and audit security policies.<\/span><\/p>\n<h3><b>Question 48<\/b><\/h3>\n<p><b>What vulnerability allows malicious input into database queries?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Structured Query Language injection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Buffer overflow execution flaw<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cross-site scripting vulnerability<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Man-in-the-middle interception vector<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">SQL injection (SQLi) is a dangerous code injection vulnerability that occurs when malicious user input is improperly sanitized and concatenated directly into database query statements. If an application fails to validate input properly, an attacker can input specially crafted SQL commands into web forms or uniform resource locators, tricking the underlying database management system into executing unauthorized commands. This can lead to severe security breaches, including unauthorized access to sensitive user data, table modification, credential theft, and complete database server compromise. Preventing SQLi requires parameterized queries, input validation, and stored procedures.<\/span><\/p>\n<h3><b>Question 49<\/b><\/h3>\n<p><b>Which protocol manages network device configurations securely via SSH?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Telnet remote administration protocol<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hypertext Transfer Protocol service<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network Configuration Protocol daemon<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Trivial File Transfer Protocol<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network Configuration Protocol (NETCONF) is a network management protocol developed by the Internet Engineering Task Force to address the limitations of legacy management interfaces like SNMP and CLI scripting. NETCONF provides mechanisms to install, manipulate, and delete the configurations of network devices programmatically. It operates over secure transport protocols like Secure Shell (SSH), ensuring that management sessions and configuration data payloads are fully encrypted and authenticated. By utilizing XML-based data encodings and supporting structured data models like YANG, NETCONF enables automated network orchestration and software-defined networking workflows across enterprise infrastructures.<\/span><\/p>\n<h3><b>Question 50<\/b><\/h3>\n<p><b>What security device monitors and blocks unauthorized network traffic?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Passive repeater hub device<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Enterprise network firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Structured cabling patch panel<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Layer 2 Ethernet bridge<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A network firewall is a dedicated security system designed to monitor, filter, and control incoming and outgoing network traffic based on a pre-configured set of organizational security rules. Operating at various layers of the OSI model depending on architecture, firewalls establish a trusted boundary between internal corporate networks and untrusted external environments like the internet. Modern next-generation firewalls integrate deep packet inspection, intrusion prevention, and application awareness to block malicious traffic, prevent unauthorized access, and protect enterprise assets against sophisticated cyber threats while permitting legitimate business communications.<\/span><\/p>\n<h3><b>Question 51<\/b><\/h3>\n<p><b>Which malware encrypts user files demanding financial ransom payment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Adware marketing program module<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Spyware tracking software agent<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network propagation worm utility<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ransomware malware software<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Ransomware is a particularly destructive form of malicious software designed to deny access to a computer system or encrypt critical files until a financial ransom is paid to the cybercriminals. Once deployed on a victim machine, ransomware utilizes robust asymmetric and symmetric encryption algorithms to lock local files and connected network shares. Attackers typically leave digital drop notes demanding cryptocurrency payments in exchange for the decryption keys. Mitigating ransomware requires comprehensive multi-layered security strategies, including regular offline backups, advanced endpoint protection, employee security awareness training, and robust network segmentation.<\/span><\/p>\n<h3><b>Question 52<\/b><\/h3>\n<p><b>What protocol provides secure file transfers over SSH transport?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secure File Transfer Protocol<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Legacy File Transfer Protocol<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Trivial File Transfer Protocol<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hypertext Transfer Protocol service<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Secure File Transfer Protocol (SFTP) is a secure network protocol designed to provide file access, file transfer, and file management functionalities over any reliable data stream. Unlike legacy File Transfer Protocol (FTP) which transmits credentials and data payloads in clear text across separate control and data channels, SFTP operates entirely over a secure Secure Shell (SSH) session utilizing TCP port 22. This integration ensures that all transmitted passwords, file metadata, and data streams are fully encrypted from end to end, protecting sensitive enterprise data against eavesdropping and tampering during transit across public networks.<\/span><\/p>\n<h3><b>Question 53<\/b><\/h3>\n<p><b>Which cloud service model provides fully managed application platforms?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Infrastructure as a Service model<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Software as a Service product<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Platform as a Service solution<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Desktop as a Service offering<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Platform as a Service (PaaS) is a cloud computing service model that supplies an on-demand environment for developing, testing, delivering, and managing software applications. PaaS provides developers with a complete hardware and software platform\u2014including operating systems, databases, web servers, and development frameworks\u2014hosted on remote cloud infrastructure, freeing them from managing underlying physical servers or storage arrays. This allows development teams to focus entirely on writing code and building applications, accelerating time-to-market while maintaining scalability and administrative efficiency across cloud environments.<\/span><\/p>\n<h3><b>Question 54<\/b><\/h3>\n<p><b>What security device detects malicious network intrusions via signatures?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ethernet Layer 2 switch<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Intrusion Detection System appliance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network signal repeater device<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Structured cabling patch panel<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An Intrusion Detection System (IDS) is a specialized security appliance or software solution designed to monitor network traffic for suspicious activity, policy violations, and known attack signatures. Operating primarily in passive monitoring modes by tapping into SPAN ports or optical splitters, an IDS analyzes packet streams and compares them against signature databases or behavioral anomaly baselines. When a potential security threat or intrusion attempt is identified, the IDS generates real-time security alerts for administrative review, allowing security operations teams to investigate and respond to cyber threats without interrupting live network traffic flows.<\/span><\/p>\n<h3><b>Question 55<\/b><\/h3>\n<p><b>Which protocol provides secure directory service authentication over networks?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Lightweight Directory Access Protocol<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unencrypted Telnet protocol daemon<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hypertext Transfer Protocol service<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Lightweight Directory Access Protocol Secure<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Lightweight Directory Access Protocol Secure (LDAPS) is the secure implementation of the standard Lightweight Directory Access Protocol, designed to provide directory service querying and user authentication across IP networks. While standard LDAP transmits directory queries, user accounts, and credentials in clear text, LDAPS wraps the communication session inside Transport Layer Security (TLS) or Secure Sockets Layer (SSL) encryption wrappers, typically operating over TCP port 636. This encryption ensures that sensitive user credentials and enterprise directory schemas are protected against packet sniffing and credential harvesting attacks.<\/span><\/p>\n<h3><b>Question 56<\/b><\/h3>\n<p><b>What security principle restricts user account permissions to minimum?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Principle of least privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defense in depth strategy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Zero Trust network architecture<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Separation of duties policy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The principle of least privilege is a fundamental information security concept that dictates that a user, process, or system component must be given only the minimum levels of access permissions\u2014or privileges\u2014necessary to perform its specific, authorized job functions. By restricting privileges strictly to operational requirements, organizations significantly limit the potential blast radius of credential compromise, insider threats, and malware propagation. For example, standard network users should never possess administrative privileges, and software applications should execute under restricted service accounts rather than root-level permissions.<\/span><\/p>\n<h3><b>Question 57<\/b><\/h3>\n<p><b>Which malware type replicates automatically across networks without user?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Computer virus infection file<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Trojan horse program file<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Computer worm malware utility<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Adware spyware tracking program<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A computer worm is a standalone malicious software program that replicates itself in order to spread to other computers across network connections. Unlike traditional computer viruses that require user intervention\u2014such as opening an infected document or running an executable file\u2014worms operate autonomously, exploiting operating system vulnerabilities or misconfigurations to scan and propagate across local networks and the internet. Once a worm infects a system, it consumes valuable bandwidth, exhausts CPU resources, and frequently installs secondary payloads like backdoors or ransomware, posing a severe threat to network availability.<\/span><\/p>\n<h3><b>Question 58<\/b><\/h3>\n<p><b>What protocol secures domain name resolution records using cryptography?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic Host Configuration Protocol<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Domain Name System Security Extensions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Simple Network Management Protocol<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network Time Protocol daemon<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Domain Name System Security Extensions (DNSSEC) is a suite of cryptographic specifications developed by the Internet Engineering Task Force to secure information provided by the Domain Name System. Traditional DNS implementations lacked built-in security, making them highly vulnerable to cache poisoning and spoofing attacks where malicious actors redirected traffic to fraudulent servers. DNSSEC addresses this by signing DNS records cryptographically using digital signatures based on public key cryptography. This allows client resolvers to verify the authenticity and integrity of DNS responses, ensuring users connect to legitimate destinations.<\/span><\/p>\n<h3><b>Question 59<\/b><\/h3>\n<p><b>Which wireless security standard mandates CCMP and AES encryption?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Wired Equivalent Privacy protocol<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Wi-Fi Protected Access protocol<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open unencrypted wireless network<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Wi-Fi Protected Access 2<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Wi-Fi Protected Access 2 (WPA2) was introduced by the Wi-Fi Alliance to provide robust enterprise-grade security for wireless local area networks, addressing critical cryptographic vulnerabilities found in original WEP and transitional WPA-TKIP protocols. WPA2 mandates the use of the Advanced Encryption Standard (AES) algorithm combined with Counter Mode with Cipher Block Chaining Message Authentication Code Protocol (CCMP) to ensure strict data confidentiality, integrity, and authentication over the air. By utilizing strong cryptographic keys and secure cipher wrappers, WPA2 effectively protects enterprise wireless communications against unauthorized eavesdropping and cracking attacks.<\/span><\/p>\n<h3><b>Question 60<\/b><\/h3>\n<p><b>What cryptographic hash function produces a 256-bit digest?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secure Hash Algorithm 256<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Message Digest 5 algorithm<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secure Hash Algorithm 1<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data Encryption Standard cipher<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Secure Hash Algorithm 256 (SHA-256) is a member of the SHA-2 cryptographic hash function family designed by the National Security Agency. SHA-256 takes an input of arbitrary length and produces a fixed 256-bit (32-byte) hash value, typically represented as a 64-character hexadecimal string. Because of its cryptographic strength and collision resistance, SHA-256 is widely utilized across modern security protocols, including digital certificates, blockchain transactions, secure firmware updates, and TLS encryption handshakes. It ensures data integrity by making it computationally infeasible for attackers to alter data without changing the resulting hash digest.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco CCNP Cybersecurity 350-201 Exam Dumps and Practice Test Dumps. &nbsp; Question 41 Which protocol secures web traffic utilizing cryptographic certificates? Unencrypted Telnet remote administration protocol File Transfer Protocol utility Hypertext Transfer Protocol Secure service Trivial File Transfer Protocol daemon Correct Answer: 3 Explanation: Hypertext Transfer Protocol Secure (HTTPS) is the secure extension [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14605"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=14605"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14605\/revisions"}],"predecessor-version":[{"id":14685,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14605\/revisions\/14685"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=14605"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=14605"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=14605"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}