{"id":14613,"date":"2026-09-17T06:07:40","date_gmt":"2026-09-17T06:07:40","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=14613"},"modified":"2026-09-17T06:07:40","modified_gmt":"2026-09-17T06:07:40","slug":"cisco-ccnp-cybersecurity-350-201-practice-test-questions-and-exam-dumps-part11-q201-220","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-ccnp-cybersecurity-350-201-practice-test-questions-and-exam-dumps-part11-q201-220\/","title":{"rendered":"Cisco CCNP Cybersecurity 350-201 Practice Test Questions and Exam Dumps Part11 Q201-220"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/350-201-exam-dumps\"><b>Cisco CCNP Cybersecurity 350-201 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 201<\/b><\/h3>\n<p><b>What is the primary function of a Hardware Security Module (HSM) in enterprise security architectures?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unencrypted local log file storage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Passive network packet capture analysis<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secure cryptographic key generation, management, and storage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic IP address leasing and assignment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Hardware Security Module (HSM) is a dedicated physical computing device designed specifically to safeguard and manage digital keys, accelerate cryptographic operations, and provide secure crypto-processing. HSMs are heavily utilized in enterprise environments to protect sensitive keys used by Certificate Authorities, database encryption, and SSL\/TLS termination. Because they are tamper-evident and tamper-resistant, HSMs prevent unauthorized extraction or exposure of master private keys, even if the host operating system is compromised.<\/span><\/p>\n<h3><b>Question 202<\/b><\/h3>\n<p><b>Which protocol is used for automated digital certificate enrollment and management over HTTP, commonly used by Let&#8217;s Encrypt?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Simple Network Management Protocol v3<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Enrollment over Secure Transport (EST)<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Simple Certificate Enrollment Protocol (SCEP)<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Automated Certificate Management Environment (ACME) protocol<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Automated Certificate Management Environment (ACME) protocol is a communications protocol designed for automating interactions between certificate authorities and web servers, enabling the automated deployment of Public Key Infrastructure (PKI) certificates without human intervention. Standardized in RFC 8555 and popularized by Let&#8217;s Encrypt, ACME allows web servers to verify domain ownership and request, renew, or revoke digital certificates securely over HTTPS, drastically reducing administrative overhead and eliminating outages caused by expired certificates.<\/span><\/p>\n<h3><b>Question 203<\/b><\/h3>\n<p><b>What type of distributed cyber attack overwhelms a target server or network with massive volumes of traffic from multiple coordinated sources?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Address Resolution Protocol cache poisoning attack<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Distributed Denial of Service (DDoS) flood attack<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Content Addressable Memory table flooding exploit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic Host Configuration server exhaustion loop<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Distributed Denial of Service (DDoS) attack is a malicious attempt to disrupt the normal traffic of a targeted server, service, or network by overwhelming the target or its surrounding infrastructure with a massive flood of internet traffic. DDoS attacks utilize multiple compromised computer systems\u2014often organized into botnets\u2014as sources of attack traffic. Because the incoming traffic originates from numerous distributed IP locations, mitigating DDoS attacks requires specialized cloud scrubbing centers, rate-limiting rules, and traffic anomaly detection tools.<\/span><\/p>\n<h3><b>Question 204<\/b><\/h3>\n<p><b>Which asymmetric cryptographic algorithm is widely used for secure key exchange, digital signatures, and public-key encryption?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Message Digest 5 hashing algorithm<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Advanced Encryption Standard symmetric cipher<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Rivest-Shamir-Adleman (RSA) cryptosystem<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Galois\/Counter Mode authentication cipher<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Rivest-Shamir-Adleman (RSA) cryptosystem is one of the earliest and most widely utilized public-key cryptographic algorithms. It relies on the mathematical difficulty of factoring the product of two large prime numbers. RSA is foundational to modern cybersecurity, providing robust mechanisms for secure data encryption, digital signatures, and key exchange protocols (such as establishing TLS sessions). While newer elliptic-curve cryptography offers equivalent security with smaller key sizes, RSA remains a cornerstone of enterprise PKI deployments.<\/span><\/p>\n<h3><b>Question 205<\/b><\/h3>\n<p><b>What Cisco switch security feature protects against rogue DHCP servers by validating client messages on trusted ports?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic Host Configuration Protocol (DHCP) snooping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unicast Reverse Path Forwarding (uRPF) inspection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port-based 802.1X network access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic ARP Inspection (DAI) filtering<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">DHCP snooping is a Layer 2 security technology built into Cisco Catalyst and Nexus switches that acts as a firewall between untrusted host devices and trusted DHCP servers. When enabled, DHCP snooping intercepts DHCP traffic, drops malicious DHCP server replies originating from untrusted ports (mitigating rogue DHCP server attacks), and builds a dynamic binding database tracking client IP addresses, MAC addresses, switch ports, and VLANs. This database is subsequently utilized by features like Dynamic ARP Inspection and IP Source Guard.<\/span><\/p>\n<h3><b>Question 206<\/b><\/h3>\n<p><b>Which email security standard adds cryptographic digital signatures to message headers to verify sender authenticity and integrity?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Sender Policy Framework (SPF)<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Domain-based Message Authentication, Reporting, and Conformance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unencrypted Simple Mail Transfer Protocol<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DomainKeys Identified Mail (DKIM)<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">DomainKeys Identified Mail (DKIM) is an email authentication method designed to detect email spoofing by providing a cryptographic mechanism to validate a domain name identity associated with a message through cryptographic signing. The sending mail server signs the email header and body hashes with a private key, and the receiving server validates the signature using the sender&#8217;s public key published in the domain&#8217;s DNS records. DKIM ensures that the email was genuinely sent by the domain owner and that the message payload was not altered in transit.<\/span><\/p>\n<h3><b>Question 207<\/b><\/h3>\n<p><b>What Cisco technology provides network traffic visibility and telemetry collection using NetFlow\/IPFIX data exported from network routers and switches?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco Identity Services Engine (ISE)<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco Secure Network Analytics (Stealthwatch)<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco Firewall Management Center (FMC)<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco Cloud Access Security Broker (CASB)<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cisco Secure Network Analytics\u2014formerly known as Stealthwatch\u2014is an enterprise security platform that uses network telemetry (such as NetFlow, IPFIX, and proxy logs) combined with machine learning and behavioral modeling to detect threats, lateral movement, and anomalous traffic patterns across campus, data center, and cloud environments. By analyzing network flows without requiring inline packet decryption, Stealthwatch provides deep visibility into enterprise communications, helping security operations teams identify compromised endpoints and insider threats rapidly.<\/span><\/p>\n<h3><b>Question 208<\/b><\/h3>\n<p><b>What cloud security architecture ensures that sensitive workloads remain encrypted while being actively processed in memory using hardware isolation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traditional public cloud shared tenancy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Infrastructure as a Service virtualization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Confidential Computing hardware-based enclaves<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Perimeter firewall micro-segmentation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Confidential Computing is a cloud security technology that protects data in use by performing computations in a hardware-based, isolated CPU enclave. While traditional cloud architectures encrypted data at rest (storage) and in transit (network), data in memory was historically vulnerable to hypervisor-level attacks or malicious host administrators. Confidential Computing utilizes secure enclaves\u2014such as Intel SGX or AMD SEV\u2014to isolate sensitive workloads and encryption keys at the hardware level, ensuring that even the cloud provider cannot access data while it is being processed.<\/span><\/p>\n<h3><b>Question 209<\/b><\/h3>\n<p><b>What memory vulnerability occurs when an application writes more data to a buffer than it can hold, allowing execution flow manipulation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Buffer overflow vulnerability exploit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Structured Query Language injection flaw<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cross-site scripting web application bug<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Address Resolution Protocol poisoning attack<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A buffer overflow is a software vulnerability that occurs when a program or application attempts to store more data in a fixed-length memory buffer than the buffer was allocated to hold. Excess data overflows into adjacent memory locations, overwriting stored execution pointers or critical application data. Skilled attackers can craft malicious payloads that exploit buffer overflows to inject and execute arbitrary machine code, granting them system access or causing application crashes. Defending against buffer overflows requires rigorous bounds checking, safe programming practices, and compiler protections.<\/span><\/p>\n<h3><b>Question 210<\/b><\/h3>\n<p><b>Which operational incident response metric measures the average time required to repair, patch, or restore a system following a security breach?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mean Time to Detect (MTTD) metric<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mean Time to Acknowledge (MTTA) alert<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Common Vulnerability Scoring System (CVSS) score<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mean Time to Repair or Remediate (MTTR)<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Mean Time to Repair or Remediate (MTTR) is a key operational performance metric in security and IT operations that calculates the average time required to troubleshoot, fix, patch, or fully recover a compromised system or service following a security incident. Along with Mean Time to Detect, MTTR helps security leaders evaluate the efficiency of their Incident Response team, automated containment workflows, and patching pipelines, driving continuous improvement in enterprise security resilience.<\/span><\/p>\n<h3><b>Question 211<\/b><\/h3>\n<p><b>Which secure protocol is used to query directory services over encrypted Transport Layer Security connections on TCP port 636?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unencrypted Lightweight Directory Access Protocol (LDAP)<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Lightweight Directory Access Protocol Secure (LDAPS)<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Trivial File Transfer Protocol directory utility<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Simple Network Management Protocol daemon<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Lightweight Directory Access Protocol Secure (LDAPS) is the secure implementation of LDAP that encrypts all communications between client applications and directory service servers using Transport Layer Security (TLS) or Secure Sockets Layer (SSL). Standard LDAP transmits directory queries, user attributes, and passwords in clear text over TCP port 389, leaving them vulnerable to packet sniffing and credential harvesting. LDAPS operates by default over TCP port 636, wrapping directory transactions in cryptographic privacy to protect enterprise authentication data.<\/span><\/p>\n<h3><b>Question 212<\/b><\/h3>\n<p><b>What component within the Cisco XDR architecture serves as the automated orchestration engine for executing incident response workflows?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco Secure Firewall Threat Defense<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Basic unmanaged Layer 2 switch hardware<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco Secure Orchestration (formerly Threat Response)<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unshielded twisted-pair patch cable link<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cisco Secure Orchestration\u2014integrated within the Cisco XDR platform\u2014serves as the automated engine that executes security playbooks, orchestrates incident response workflows, and coordinates actions across disparate security products (such as firewalls, email gateways, and endpoint agents). By automating repetitive containment tasks\u2014like isolating compromised hosts, blocking malicious IP addresses, or revoking compromised user sessions\u2014Secure Orchestration significantly reduces incident response times and operational overhead for Security Operations Centers.<\/span><\/p>\n<h3><b>Question 213<\/b><\/h3>\n<p><b>What type of malicious software encrypts files on a host system and demands financial ransom in exchange for the decryption key?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ransomware file encryption payload<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Adware marketing software package<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Spyware tracking telemetry agent<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Rootkit kernel concealment module<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Ransomware is a destructive form of malware that encrypts files, directories, or entire hard disk drives on a victim&#8217;s computer system using robust symmetric and asymmetric encryption algorithms. Once the files are locked, the malicious actors demand a financial ransom payment\u2014typically in cryptocurrency\u2014in exchange for the private decryption key. Modern ransomware operations frequently employ double-extortion tactics, exfiltrating sensitive corporate data prior to encryption and threatening public leaks if demands are unmet. Defense requires rigorous backup strategies, endpoint detection, and email filtering.<\/span><\/p>\n<h3><b>Question 214<\/b><\/h3>\n<p><b>Which IEEE standard defines Rapid Spanning Tree Protocol to eliminate network switching loops and speed convergence?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IEEE 802.1X port-based access control standard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IEEE 802.1Q VLAN trunking encapsulation specification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IEEE 802.11ac wireless local networking protocol<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IEEE 802.1w Rapid Spanning Tree Protocol (RSTP)<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The IEEE 802.1w standard defines Rapid Spanning Tree Protocol (RSTP), an evolution of the original IEEE 802.1D Spanning Tree Protocol designed to prevent switching loops in enterprise LAN topologies. While legacy STP took up to 50 seconds to converge after a topology change, RSTP introduces rapid state transitions and backup port roles, achieving convergence in milliseconds. This ensures high availability and rapid fault recovery across enterprise switched infrastructure without disrupting mission-critical network connectivity.<\/span><\/p>\n<h3><b>Question 215<\/b><\/h3>\n<p><b>What routing security feature checks incoming packets against routing table entries to drop spoofed IP source addresses?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic Host Configuration Protocol snooping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unicast Reverse Path Forwarding (uRPF)<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port security MAC address limiting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Address Resolution Protocol dynamic inspection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Unicast Reverse Path Forwarding (uRPF) is a security and routing feature implemented on Cisco network devices to mitigate problems caused by malicious or accidental IP address spoofing. When uRPF is enabled on an interface, the router examines incoming packets and checks its routing table to determine if the packet arrived on the optimal interface back to the source IP address. If the packet arrives on an unexpected interface or if no valid routing entry exists for that source IP, the router drops the packet. This prevents attackers from launching spoofed DoS attacks or bypassing perimeter access controls.<\/span><\/p>\n<h3><b>Question 216<\/b><\/h3>\n<p><b>Which cryptographic hash function produces a fixed 256-bit hash digest and belongs to the Secure Hash Algorithm 2 family?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Message Digest 5 (MD5) algorithm<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secure Hash Algorithm 1 (SHA-1)<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secure Hash Algorithm 256 (SHA-256)<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secure Hash Algorithm 384 (SHA-384)<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Secure Hash Algorithm 256 (SHA-256) is a widely utilized cryptographic hash function that produces a fixed 256-bit (32-byte) hash digest, typically represented as a 64-character hexadecimal string. Part of the SHA-2 family standardized by NIST, SHA-256 provides strong collision resistance and data integrity verification. It is foundational to modern digital signatures, TLS certificates, blockchain technology, and secure file checksum validation, replacing older broken algorithms like MD5 and SHA-1.<\/span><\/p>\n<h3><b>Question 217<\/b><\/h3>\n<p><b>What cybersecurity framework developed by MITRE provides a comprehensive taxonomy of adversary tactics, techniques, and procedures (TTPs)?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MITRE ATT&amp;CK knowledge base framework<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open Web Application Security Project standard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">National Institute of Standards risk framework<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Information Technology Infrastructure Library guide<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">MITRE ATT&amp;CK (Adversarial Tactics, Techniques, and Common Knowledge) is a globally accessible, curated knowledge base of adversary tactics and techniques based on real-world observation. Security operations teams, threat hunters, and defenders utilize the ATT&amp;CK framework to understand attacker behavior, map enterprise security monitoring coverage, evaluate detection tool effectiveness, and simulate adversary TTPs during threat emulation and penetration testing exercises.<\/span><\/p>\n<h3><b>Question 218<\/b><\/h3>\n<p><b>Which mechanism secures BGP peer authentication by embedding cryptographic hash checks into TCP session headers?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Resource Public Key Infrastructure (RPKI)<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic ARP Inspection (DAI) filtering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unicast Reverse Path Forwarding (uRPF)<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TCP MD5 Signature Option (RFC 2385)<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The TCP MD5 Signature Option\u2014defined in RFC 2385\u2014allows routers to authenticate BGP routing sessions by embedding a cryptographic hash (MAC) inside the TCP header of every BGP segment. Both peering routers are configured with a shared secret key, and any routing packet lacking the correct MD5 signature hash is automatically dropped. This prevents malicious actors from injecting forged BGP routing updates, hijacking prefixes, or conducting TCP reset attacks against critical core routing infrastructure.<\/span><\/p>\n<h3><b>Question 219<\/b><\/h3>\n<p><b>What software tool captures and analyzes raw network frames to assist with troubleshooting and security forensic investigations?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Layer 2 unmanaged Ethernet switch device<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Packet analyzer utility (e.g., Wireshark)<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unshielded twisted-pair patch cable link<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Passive network signal repeater hub<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A packet analyzer\u2014commonly referred to as a packet sniffer or network protocol analyzer\u2014is a specialized software tool designed to intercept, log, and analyze network traffic traversing a wired or wireless medium. When packets pass through a network interface card configured in promiscuous mode, the analyzer captures raw binary frames, decodes encapsulation layers, and displays detailed protocol metrics, payloads, and header fields. Security analysts and network engineers rely heavily on packet sniffers like Wireshark during troubleshooting and forensic investigations to examine network communications and detect anomalies.<\/span><\/p>\n<h3><b>Question 220<\/b><\/h3>\n<p><b>What internal security policy mandates dividing critical operational responsibilities among multiple individuals to prevent fraud and errors?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Principle of least privilege access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defense in depth architectural strategy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Separation of duties governance policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Zero Trust network verification model<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Separation of duties is a foundational internal control and governance principle designed to prevent fraud, errors, and malicious activities by ensuring that no single individual maintains end-to-end control over a critical operational or financial transaction. By dividing sensitive workflows\u2014such as financial authorizations, code deployments, or cryptographic key management\u2014across multiple distinct roles, organizations enforce accountability and require collusion for malicious actions to succeed, significantly enhancing enterprise security posture and compliance alignment.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco CCNP Cybersecurity 350-201 Exam Dumps and Practice Test Dumps. &nbsp; Question 201 What is the primary function of a Hardware Security Module (HSM) in enterprise security architectures? Unencrypted local log file storage Passive network packet capture analysis Secure cryptographic key generation, management, and storage Dynamic IP address leasing and assignment Correct Answer: [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14613"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=14613"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14613\/revisions"}],"predecessor-version":[{"id":14677,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14613\/revisions\/14677"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=14613"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=14613"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=14613"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}