{"id":14616,"date":"2026-09-17T06:07:04","date_gmt":"2026-09-17T06:07:04","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=14616"},"modified":"2026-09-17T06:07:04","modified_gmt":"2026-09-17T06:07:04","slug":"cisco-ccnp-cybersecurity-350-201-practice-test-questions-and-exam-dumps-part14-q261-280","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-ccnp-cybersecurity-350-201-practice-test-questions-and-exam-dumps-part14-q261-280\/","title":{"rendered":"Cisco CCNP Cybersecurity 350-201 Practice Test Questions and Exam Dumps Part14 Q261-280"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/350-201-exam-dumps\"><b>Cisco CCNP Cybersecurity 350-201 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 261<\/b><\/h3>\n<p><b>What feature within the Cisco Identity Services Engine (ISE) collects endpoint attributes passively or actively to classify device types without requiring user authentication?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IEEE 802.1X port access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic ARP Inspection filtering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco ISE endpoint profiling service<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unicast Reverse Path Forwarding check<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Cisco Identity Services Engine (ISE) profiling service dynamically collects attributes from endpoints\u2014using active probes like SNMP and HTTP, and passive listeners like DHCP, NetFlow, and MAC OUI lookups\u2014to identify and classify device types (such as IP phones, printers, medical devices, or personal smartphones). This profiling data enables security administrators to enforce granular, role-based access control policies across the enterprise network automatically.<\/span><\/p>\n<h3><b>Question 262<\/b><\/h3>\n<p><b>Which XML-based open standard protocol is used for exchanging authentication and authorization data between an identity provider and a service provider for Single Sign-On?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security Assertion Markup Language (SAML)<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Simple Network Management Protocol v3<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Lightweight Directory Access Protocol Secure<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic Host Configuration Protocol daemon<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security Assertion Markup Language (SAML) is an open standard designed for exchanging authentication and authorization data securely in XML format, primarily used to enable web-based Single Sign-On (SSO) across disparate administrative domains. SAML allows users to log in once at an Identity Provider (IdP) and gain seamless access to multiple independent Service Providers (SPs) without re-entering credentials, improving user experience and centralizing credential management.<\/span><\/p>\n<h3><b>Question 263<\/b><\/h3>\n<p><b>What component of a Next-Generation Intrusion Prevention System rule defines the action, protocol, source\/destination IP addresses, and port numbers?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Snort rule option metadata block<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application layer payload regex filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cryptographic hash file verification tag<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Snort rule header structure<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Snort intrusion detection\/prevention rule is structured into two main sections: the rule header and the rule options. The rule header defines the core characteristics of the packet filter, including the action (e.g., alert, drop, pass, log), the networking protocol (e.g., TCP, UDP, ICMP), source and destination IP addresses, and port numbers. The rule options section contains specific content matching patterns, thresholds, and message strings used to inspect payloads.<\/span><\/p>\n<h3><b>Question 264<\/b><\/h3>\n<p><b>Which feature on the Cisco Secure Email Gateway uses advanced heuristics and sandboxing to detect zero-day malware hidden within inbound email attachments?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static sender domain blacklist blocking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco Secure Email Outbreak Filters<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unencrypted Simple Mail Transfer relay<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic Host Configuration lease table<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cisco Secure Email Outbreak Filters provide proactive protection against emerging email threats and zero-day malware campaigns before traditional signature updates become available. When a suspicious attachment or URL is detected, the Outbreak Filter quarantines the message and evaluates it in real time against threat intelligence feeds and sandbox threat engines. Once verified or remediated, the email is released to the recipient, effectively stopping advanced phishing and malware payloads.<\/span><\/p>\n<h3><b>Question 265<\/b><\/h3>\n<p><b>Within the IEEE 802.1X framework, what role does the intermediate network switch or wireless access point assume during the authentication exchange?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The Supplicant client endpoint device<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The Authentication server database backend<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The Authenticator gateway interface<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The Certificate Authority validation server<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The IEEE 802.1X framework consists of three core components: the Supplicant (the client device requesting access), the Authenticator (the network access device, such as a switch or wireless access point acting as a gatekeeper), and the Authentication Server (typically a RADIUS server like Cisco ISE). The Authenticator controls physical or logical port access, blocking traffic until the Supplicant successfully passes credentials to the Authentication Server.<\/span><\/p>\n<h3><b>Question 266<\/b><\/h3>\n<p><b>What Kubernetes security feature enforces network isolation by restricting traffic flow between pods based on namespace and label selectors?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Kubernetes Network Policies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Flat unsegmented container bridge<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unshielded twisted-pair patch link<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Passive network packet capture tap<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Kubernetes Network Policies are specifications that dictate how groups of pods are allowed to communicate with each other and with other network endpoints. By default, container communication in Kubernetes is non-namespaced and unisolated. Implementing Network Policies enables micro-segmentation at the container level, ensuring that workloads only accept authorized traffic and restricting lateral movement within containerized microservices architectures.<\/span><\/p>\n<h3><b>Question 267<\/b><\/h3>\n<p><b>Which metric group within the Common Vulnerability Scoring System (CVSS) evaluates characteristics of a vulnerability that remain constant over time and across user environments?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Temporal vulnerability metrics group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Environmental vulnerability metrics group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exploitability operational index metrics<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Base vulnerability metrics group<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Common Vulnerability Scoring System (CVSS) is divided into three metric groups: Base, Temporal, and Environmental. The Base metrics group captures the intrinsic characteristics of a vulnerability that are constant over time and invariant across user environments (such as Attack Vector, Privileges Required, and Confidentiality Impact). Temporal metrics measure characteristics that evolve over time (like exploit code maturity), while Environmental metrics customize scores to specific organizational deployments.<\/span><\/p>\n<h3><b>Question 268<\/b><\/h3>\n<p><b>What authentication and authorization protocol operates over TCP port 49, provides granular command-line authorization, and encrypts the entire packet payload?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remote Authentication Dial-In User Service<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Terminal Access Controller Access-Control System Plus (TACACS+)<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Lightweight Directory Access Protocol Secure<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Simple Network Management Protocol v3<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">TACACS+ (Terminal Access Controller Access-Control System Plus) is a Cisco-developed AAA protocol that operates over TCP port 49. Unlike RADIUS, which combines authentication and authorization and encrypts only the password field, TACACS+ separates AAA functions entirely, encrypts the entire packet payload for enhanced security, and provides granular command-line authorization down to individual device configuration commands.<\/span><\/p>\n<h3><b>Question 269<\/b><\/h3>\n<p><b>What cloud-based malware analysis platform provides automated behavioral sandboxing and threat intelligence integration for Cisco security products?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco Firewall Management Center<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco Identity Services Engine<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco Secure Malware Analytics (Threat Grid)<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco Secure Network Analytics<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cisco Secure Malware Analytics\u2014formerly known as Threat Grid\u2014is a cloud-delivered threat intelligence and malware analysis platform that combines advanced static and dynamic sandbox analysis with comprehensive global threat intelligence feeds. It evaluates suspicious files and artifacts in isolated virtual environments, generating threat scores and indicators of compromise (IoCs) that integrate seamlessly across Cisco&#8217;s security portfolio.<\/span><\/p>\n<h3><b>Question 270<\/b><\/h3>\n<p><b>Which IPsec protocol provides data confidentiality, integrity, and anti-replay protection by encrypting the entire packet payload?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encapsulating Security Payload (ESP) protocol<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Authentication Header (AH) integrity protocol<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Transport Layer Security (TLS) handshake<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secure Shell (SSH) remote protocol session<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Encapsulating Security Payload (ESP) is an IPsec protocol designed to provide comprehensive security services, including data confidentiality (encryption), data integrity, data origin authentication, and anti-replay protection. In contrast, the IPsec Authentication Header (AH) protocol provides integrity and authentication but lacks encryption capabilities, leaving packet payloads transmitted in clear text.<\/span><\/p>\n<h3><b>Question 271<\/b><\/h3>\n<p><b>What hardware-based security technology establishes a secure root of trust by storing cryptographic keys and validating firmware integrity during system boot?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Layer 2 unmanaged switch architecture<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Passive network tapping signal hub<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unshielded twisted-pair patch cable<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hardware Trust Anchor \/ Secure Boot module<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A hardware Trust Anchor\u2014often implemented using a Trusted Platform Module (TPM) or specialized secure crypto-processor\u2014provides an immutable hardware-based foundation for system security. During device startup, Secure Boot utilizes cryptographic keys stored in the hardware trust anchor to verify the digital signature of operating system boot loaders and firmware images. If any component has been tampered with or modified maliciously, the device halts the boot process, preventing compromised firmware execution.<\/span><\/p>\n<h3><b>Question 272<\/b><\/h3>\n<p><b>Within the Cisco Software-Defined Access (SDA) architecture, what centralized management platform orchestrates fabric provisioning, policy enforcement, and automation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco Firewall Management Center<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco Catalyst Center (formerly DNA Center)<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco Secure Client endpoint agent<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco Identity Services Engine node<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cisco Catalyst Center (formerly known as Cisco Digital Network Architecture Center or DNA Center) serves as the core management, automation, and orchestration engine for Cisco Software-Defined Access (SDA) networks. Catalyst Center works in tandem with the Cisco Identity Services Engine (ISE) to translate business intent into network policies, automate provisioning across campus fabrics, and monitor end-to-end network assurance.<\/span><\/p>\n<h3><b>Question 273<\/b><\/h3>\n<p><b>Which protocol acts as a simple identity verification layer built on top of the OAuth 2.0 authorization framework?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Simple Network Management Protocol v3<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unencrypted Lightweight Directory Access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">OpenID Connect (OIDC) protocol<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Trivial File Transfer Protocol utility<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">OpenID Connect (OIDC) is an interoperable authentication protocol built on top of the OAuth 2.0 framework. While OAuth 2.0 is strictly designed for authorization (granting third-party apps limited resource access), OIDC adds a standardized identity layer that allows client applications to verify user identity via secure JSON Web Tokens (JWT) known as ID tokens, enabling secure Single Sign-On.<\/span><\/p>\n<h3><b>Question 274<\/b><\/h3>\n<p><b>What vulnerability management process evaluates reported software flaws based on exploitability, asset criticality, and business impact to schedule patching?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk-based vulnerability prioritization and remediation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Passive network packet capture sniffing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static source code fuzz testing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MAC address port security limiting<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk-based vulnerability prioritization is a structured security methodology that moves beyond simple CVSS scoring by factoring in real-world exploitability intelligence, internal asset criticality, network exposure, and potential business impact. Because organizations cannot patch every discovered vulnerability simultaneously, risk-based prioritization ensures security teams focus remediation efforts on flaws actively being targeted by threat actors on critical assets.<\/span><\/p>\n<h3><b>Question 275<\/b><\/h3>\n<p><b>What network hardening practice isolates control plane traffic on Cisco routers and switches to prevent CPU resource exhaustion attacks?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Flat unsegmented network bridging<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unencrypted Telnet console access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Passive optical signal tapping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Control Plane Policing (CoPP)<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Control Plane Policing (CoPP) is a security and QoS feature implemented on Cisco network hardware that utilizes Quality of Service (QoS) mechanisms to manage and rate-limit control plane traffic destined for the device&#8217;s CPU. By prioritizing legitimate routing protocols (like BGP and OSPF) and throttling excessive or malicious traffic streams (like ARP floods or DoS attacks), CoPP prevents CPU resource exhaustion and ensures network device stability.<\/span><\/p>\n<h3><b>Question 276<\/b><\/h3>\n<p><b>What SIEM data management process extracts specific log fields, converts timestamps, and assigns standardized event categories during ingestion?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Passive network sniffing capture<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Log parsing and normalization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cryptographic file hash verification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic IP address lease tracking<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Log parsing and normalization is the foundational data ingestion pipeline within a SIEM platform where raw, unstructured log messages from diverse vendor systems are dissected. Parsing extracts specific attributes (such as source IP, username, and event ID), while normalization maps these fields into a unified schema, enabling efficient event correlation and multi-vendor threat analysis.<\/span><\/p>\n<h3><b>Question 277<\/b><\/h3>\n<p><b>During the SSL\/TLS 1.3 handshake, which cryptographic mechanism is negotiated to ensure that session keys remain secure even if long-term private keys are compromised later?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static RSA public key encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Plaintext symmetric session sharing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ephemeral Diffie-Hellman Key Exchange (Forward Secrecy)<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Electronic Codebook cipher mode<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">TLS 1.3 mandates the use of ephemeral Diffie-Hellman key exchange algorithms during the handshake process. Because keys are generated dynamically per session and discarded after connection termination, the protocol guarantees Forward Secrecy (Perfect Forward Secrecy). This ensures that an attacker who records encrypted traffic and later compromises the server&#8217;s long-term private key cannot decrypt past recorded sessions.<\/span><\/p>\n<h3><b>Question 278<\/b><\/h3>\n<p><b>What Cloud Access Security Broker (CASB) deployment mode utilizes direct API integrations with cloud service providers to inspect stored data and user configurations?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">API-based CASB deployment mode<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Inline forward proxy deployment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reverse proxy authentication gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Passive network tap sniffing probe<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">API-based Cloud Access Security Broker (CASB) deployments connect directly to cloud service providers (such as Microsoft 365, Salesforce, or AWS) via administrative APIs. This out-of-band architecture allows security teams to scan stored data at rest, detect configuration drift, audit user permissions, and identify shadow IT usage without sitting in the inline traffic path or impacting user network latency.<\/span><\/p>\n<h3><b>Question 279<\/b><\/h3>\n<p><b>What incident response containment strategy involves logically or physically isolating a compromised endpoint from the network while preserving system memory for forensic analysis?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabling all enterprise internet circuits<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Re-imaging the host operating system immediately<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Deleting critical system log repositories<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Endpoint isolation \/ network quarantine<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Endpoint isolation\u2014often executed via automated Endpoint Detection and Response (EDR) platforms\u2014logically or physically quarantines a compromised host from the wider network while maintaining a secure management tunnel for security analysts. This containment strategy stops malware from spreading laterally across enterprise systems while preserving active RAM memory and local artifacts necessary for thorough digital forensics investigations.<\/span><\/p>\n<h3><b>Question 280<\/b><\/h3>\n<p><b>What threat intelligence framework provides standardized, structured JSON serialization formats for exchanging cyber threat indicators and actor profiles?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Common Vulnerability Scoring System (CVSS)<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Structured Threat Information Expression (STIX)<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open Web Application Security Project (OWASP)<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">National Institute of Standards framework (NIST)<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Structured Threat Information Expression (STIX) is a standardized, structured XML\/JSON language and serialization format developed to describe cyber threat information so it can be shared, stored, and analyzed in a consistent manner. STIX covers threat actor profiles, campaign details, malware signatures, indicators of compromise, and recommended mitigation actions, working hand-in-hand with TAXII transport protocols.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco CCNP Cybersecurity 350-201 Exam Dumps and Practice Test Dumps. &nbsp; Question 261 What feature within the Cisco Identity Services Engine (ISE) collects endpoint attributes passively or actively to classify device types without requiring user authentication? IEEE 802.1X port access control Dynamic ARP Inspection filtering Cisco ISE endpoint profiling service Unicast Reverse Path [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14616"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=14616"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14616\/revisions"}],"predecessor-version":[{"id":14674,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14616\/revisions\/14674"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=14616"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=14616"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=14616"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}