{"id":14620,"date":"2026-09-17T06:06:02","date_gmt":"2026-09-17T06:06:02","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=14620"},"modified":"2026-09-17T06:06:02","modified_gmt":"2026-09-17T06:06:02","slug":"cisco-ccnp-cybersecurity-350-201-practice-test-questions-and-exam-dumps-part18-q341-360","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-ccnp-cybersecurity-350-201-practice-test-questions-and-exam-dumps-part18-q341-360\/","title":{"rendered":"Cisco CCNP Cybersecurity 350-201 Practice Test Questions and Exam Dumps Part18 Q341-360"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/350-201-exam-dumps\"><b>Cisco CCNP Cybersecurity 350-201 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 341<\/b><\/h3>\n<p><b>What protocol secures BGP routing sessions using TCP MD5?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Resource Public Key Infrastructure authorization framework<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TCP MD5 Signature Option specified in RFC 2385<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unicast Reverse Path Forwarding route verification check<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic ARP Inspection port filtering security mechanism<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The TCP MD5 Signature Option\u2014defined in RFC 2385\u2014allows routers to authenticate BGP peering sessions by embedding a cryptographic hash (Message Authentication Code) inside the TCP header of every BGP segment exchanged between peers. Both routers are pre-configured with a shared secret key, and any routing packet lacking the correct MD5 signature hash is automatically dropped by the receiving router. This prevents malicious actors from injecting forged BGP routing updates, hijacking network prefixes, or conducting TCP reset attacks against critical core routing infrastructure across internet exchanges. Implementing TCP MD5 significantly strengthens routing protocol resilience and ensures that autonomous systems maintain trustworthy communications over vulnerable wide-area networks.<\/span><\/p>\n<h3><b>Question 342<\/b><\/h3>\n<p><b>Which mechanism prevents MAC address flooding attacks on switches?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port security dynamic MAC address limiting filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic Host Configuration Protocol snooping daemon utility<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unicast Reverse Path Forwarding traffic verification check<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Address Resolution Protocol dynamic inspection filter mechanism<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Port security is a foundational Layer 2 hardening feature implemented on enterprise network switches to restrict input to an interface by limiting and identifying the maximum number of source MAC addresses allowed on a specific port. By restricting access to authorized physical endpoints, port security prevents CAM table exhaustion attacks\u2014where malicious actors flood switches with thousands of randomized MAC addresses to force hub-like broadcast behavior. When an unauthorized device attempts to connect or when the configured MAC limit is exceeded, port security can trigger automated defensive mitigations such as shutting down the port or dropping offending frames, safeguarding enterprise network integrity against unauthorized physical access.<\/span><\/p>\n<h3><b>Question 343<\/b><\/h3>\n<p><b>What cloud security tool continuously monitors multi-cloud compliance?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Access Security Broker proxy inspection tool<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firewall Management Center policy administration appliance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Security Posture Management (CSPM) solution<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic Host Configuration server lease daemon<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud Security Posture Management (CSPM) tools are specialized security solutions designed to automate the continuous monitoring of multi-cloud environments\u2014such as Amazon Web Services, Microsoft Azure, and Google Cloud Platform\u2014to detect configuration flaws, security risks, compliance violations, and identity management gaps. CSPM platforms provide automated remediation guidance and deep visibility into complex cloud asset inventories, helping security teams maintain a strong, compliant security posture across distributed cloud infrastructure without manual audits or operational delays. By evaluating environments against regulatory standards like CIS benchmarks and NIST frameworks, CSPM tools ensure that cloud misconfigurations are identified and remediated before adversaries can exploit them.<\/span><\/p>\n<h3><b>Question 344<\/b><\/h3>\n<p><b>Which component in Cisco ISE handles policy distribution?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Basic unmanaged Layer 2 switch hardware device<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Passive network traffic signal analyzer monitoring tool<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Policy Service Node (PSN) within Cisco ISE<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unshielded twisted-pair network patch cable link<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Within a distributed Cisco Identity Services Engine deployment, the Policy Service Node (PSN) is responsible for handling network access requests, authentication processing, authorization evaluations, and policy enforcement across enterprise network endpoints. While the Policy Administration Node manages central configuration and system setup, the PSNs are deployed across various physical sites and data centers to ensure low-latency authentication responses and local survivability. PSNs communicate directly with network access devices\u2014such as switches and wireless controllers\u2014evaluating user credentials against centralized security profiles, executing posture assessments, and enforcing granular access control rules dynamically at the network edge.<\/span><\/p>\n<h3><b>Question 345<\/b><\/h3>\n<p><b>What security device inspects web application HTTP traffic?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unmanaged Layer 2 Ethernet bridge switch device<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web Application Firewall (WAF) appliance or service<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Passive network packet sniffing capture probe<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unshielded twisted-pair patch cable network link<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Web Application Firewall (WAF) is a specialized security appliance or cloud service designed to protect web applications by filtering, monitoring, and blocking HTTP\/HTTPS traffic traveling between web applications and client browsers. Unlike traditional network firewalls that operate at lower OSI layers, a WAF inspects Layer 7 application traffic specifically to detect and prevent common web exploits\u2014such as SQL injection, cross-site scripting, local file inclusion, and cookie tampering\u2014before malicious requests reach application backend databases. By utilizing signature matching, behavioral analysis, and negative\/positive security models, a WAF ensures that web services remain resilient against sophisticated application-layer cyber attacks.<\/span><\/p>\n<h3><b>Question 346<\/b><\/h3>\n<p><b>Which protocol provides secure time synchronization with cryptographic protection?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Simple Network Management Protocol version 1 daemon<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic Host Configuration Protocol address leasing utility<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network Time Security (NTS) cryptographic protocol<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Trivial File Transfer Protocol utility server<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network Time Security (NTS) is a cryptographic extension of the Network Time Protocol designed to provide secure, authenticated time synchronization across computer networks. Traditional time synchronization protocols were highly vulnerable to spoofing, tampering, and man-in-the-middle attacks, allowing malicious actors to manipulate system clocks and disrupt time-sensitive security logs, authentication tokens, or Kerberos tickets. NTS addresses this by utilizing Transport Layer Security and authenticated encryption to secure time packets between clients and time servers, guaranteeing absolute temporal integrity. This cryptographic verification ensures that system logs remain reliable and chronologically accurate for forensic investigations and incident response workflows.<\/span><\/p>\n<h3><b>Question 347<\/b><\/h3>\n<p><b>What framework standardizes cyber threat intelligence data exchange?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Structured Threat Information Expression (STIX) schema<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Common Vulnerability Scoring System metric framework<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Syslog event logging stream transmission standard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Simple Network Management Protocol trap configuration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Structured Threat Information Expression (STIX) is a standardized, structured XML\/JSON language and serialization format developed to describe cyber threat information so it can be shared, stored, and analyzed consistently across security platforms. STIX covers a comprehensive range of threat data, including threat actor profiles, campaign details, malware signatures, indicators of compromise, and recommended mitigation actions. When paired with trusted automated exchange protocols like TAXII, STIX enables organizations to share real-time threat intelligence seamlessly and automate defensive security postures across heterogeneous enterprise environments, reducing the time required to detect and mitigate emerging cyber threats globally.<\/span><\/p>\n<h3><b>Question 348<\/b><\/h3>\n<p><b>Which metric group captures intrinsic vulnerability characteristics over time?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Temporal vulnerability metrics measurement group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Environmental vulnerability metrics evaluation group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Base vulnerability metrics characterization group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exploitability operational index metrics collection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Common Vulnerability Scoring System is divided into three core metric groups: Base, Temporal, and Environmental. The Base metrics group captures the intrinsic characteristics of a vulnerability that remain constant over time and are invariant across user environments, such as Attack Vector, Privileges Required, and Confidentiality Impact. Temporal metrics measure characteristics that evolve over time, such as exploit code maturity and remediation availability, while Environmental metrics customize scores to specific organizational deployments. Understanding the Base metric group allows security teams to evaluate the fundamental severity of a software flaw objectively regardless of where it is deployed across enterprise networks.<\/span><\/p>\n<h3><b>Question 349<\/b><\/h3>\n<p><b>What service provides Single Sign-On across cloud applications?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Active Directory Federation Services and Single Sign-On<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Passive network traffic packet sniffing tool<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unshielded twisted-pair patch cable network link<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Layer 2 unmanaged Ethernet bridge switch<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Active Directory Federation Services and Single Sign-On services provide centralized identity management and authentication validation across multiple disparate security domains, cloud platforms, and enterprise applications. Instead of requiring users to maintain separate credentials for every service, federation utilizes standardized protocols like Security Assertion Markup Language and OpenID Connect to securely pass authenticated identity tokens between trusted identity providers and service providers. This centralized approach reduces password fatigue, minimizes credential theft risks, and allows security administrators to enforce strict multi-factor authentication policies across all enterprise cloud workloads efficiently.<\/span><\/p>\n<h3><b>Question 350<\/b><\/h3>\n<p><b>Which protocol encrypts the entire TACACS+ packet payload?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Terminal Access Controller Access-Control System Plus<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remote Authentication Dial-In User Service protocol<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Lightweight Directory Access Protocol Secure utility<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unencrypted Telnet remote administration console<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Terminal Access Controller Access-Control System Plus (TACACS+) is a Cisco-developed AAA protocol that operates over TCP port 49, providing robust, centralized authentication, authorization, and accounting management for administrative access to network devices. Unlike traditional RADIUS\u2014which combines authentication and authorization into a single process and encrypts only the password field within access-request packets\u2014TACACS+ separates all three AAA functions completely. Furthermore, TACACS+ encrypts the entire packet payload of every communication between the network device and the TACACS+ server, ensuring that sensitive command inputs, administrative usernames, and operational data remain entirely secure from network eavesdroppers and packet-sniffing adversaries.<\/span><\/p>\n<h3><b>Question 351<\/b><\/h3>\n<p><b>What attack floods switch memory tables with MAC addresses?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Address Resolution Protocol cache poisoning attack<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CAM table flooding (MAC address exhaustion attack)<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic Host Configuration server exhaustion loop<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Spanning Tree Root bridge hijacking exploit<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A CAM table flooding attack\u2014commonly referred to as a MAC flooding attack\u2014is a Layer 2 network exploit where a malicious actor overwhelms an enterprise switch by transmitting a high volume of Ethernet frames with randomized source MAC addresses. Because switches maintain limited physical memory capacity within their Content Addressable Memory tables to track port-to-MAC mappings, exhausting this table forces the switch into an insecure broadcast mode (fail-open behavior). In this state, unicast traffic is flooded to all ports, allowing the attacker to capture sensitive enterprise traffic using passive packet sniffers. Mitigating this risk requires configuring port security limits on access switch ports.<\/span><\/p>\n<h3><b>Question 352<\/b><\/h3>\n<p><b>Which cryptographic mode provides simultaneous data confidentiality and integrity?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Electronic Codebook cipher mode implementation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cipher Block Chaining standard mechanism<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Galois\/Counter Mode (GCM) authenticated encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Plaintext session key sharing method<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Galois\/Counter Mode (GCM) is an authenticated encryption mode of operation designed to provide both data confidentiality and data integrity simultaneously within symmetric block ciphers like AES. Traditional encryption modes required separate mechanisms to verify integrity, leaving systems vulnerable to tampering if message authentication codes were omitted or misconfigured. GCM combines counter mode encryption with universal hashing over a Galois field, ensuring that any unauthorized modification to ciphertext or associated authentication data is detected instantly. Because of its high performance and robust security guarantees, GCM is heavily utilized in modern protocols such as TLS 1.3 to protect data in transit.<\/span><\/p>\n<h3><b>Question 353<\/b><\/h3>\n<p><b>What tool monitors endpoint behavior for threat detection?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Basic static signature-based antivirus software<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Endpoint Detection and Response (EDR) platform<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unmanaged Layer 2 Ethernet bridge switch<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Passive network signal tap hub device<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Endpoint Detection and Response (EDR) is a sophisticated cybersecurity technology that continuously monitors end-user devices, servers, and hosts to collect deep behavioral telemetry, detect suspicious activities, and provide automated containment capabilities. Unlike traditional signature-based antivirus software that relied on static file matching to block known malware, EDR tools record process executions, file modifications, registry changes, and network connections in real time. This granular behavioral visibility enables security operations teams and threat hunters to identify zero-day exploits, fileless malware attacks, and advanced persistent threats that successfully evade traditional perimeter defenses, enabling rapid isolation and remediation.<\/span><\/p>\n<h3><b>Question 354<\/b><\/h3>\n<p><b>Which security assessment simulates real-world targeted cyber attacks?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static application source code review analysis<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Automated vulnerability port scanning utility scan<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Penetration testing assessment engagement<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Passive network traffic log sniffing capture<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Penetration testing is an authorized, simulated cyber attack launched against a computer system, network, or web application to evaluate security posture and identify exploitable vulnerabilities. Performed by ethical hackers, penetration testing mimics the tactics, techniques, and procedures utilized by real-world threat actors to bypass defenses. The assessment uncovers weak configurations, unpatched software flaws, and architectural security gaps before malicious attackers can exploit them. Organizations utilize penetration testing findings to prioritize remediation efforts, validate security controls, and ensure compliance with various regulatory frameworks and industry standards.<\/span><\/p>\n<h3><b>Question 355<\/b><\/h3>\n<p><b>What IEEE standard defines port-based network access control?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IEEE 802.1Q VLAN trunking specification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IEEE 802.1X port-based access control standard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IEEE 802.11ac wireless local area network<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IEEE 802.1w Rapid Spanning Tree protocol<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The IEEE 802.1X standard defines port-based network access control, providing an authentication mechanism for devices wishing to attach to a wired LAN or wireless WLAN. 802.1X uses the Extensible Authentication Protocol to pass authentication messages between the supplicant client, the network access device acting as an authenticator, and a centralized authentication server such as RADIUS or Cisco ISE. Until the client successfully authenticates, the switch port blocks all non-EAP traffic, preventing unauthorized or rogue endpoints from accessing enterprise network resources. This enforces strict device compliance before granting access to internal corporate network segments.<\/span><\/p>\n<h3><b>Question 356<\/b><\/h3>\n<p><b>Which DNS extension utilizes cryptographic signatures for validation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Domain Name System Security Extensions (DNSSEC)<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic Host Configuration Protocol option string<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic DNS record update mechanism protocol<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network Time Protocol synchronization utility<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Domain Name System Security Extensions (DNSSEC) is a suite of cryptographic specifications developed by the IETF to secure information provided by the Domain Name System. Traditional DNS implementations lacked built-in authentication, leaving them vulnerable to cache poisoning, spoofing, and man-in-the-middle attacks where users are redirected to malicious websites. DNSSEC addresses this by cryptographically signing DNS records using public key cryptography. This allows client resolvers to verify the authenticity and integrity of responses, ensuring users connect to legitimate destination servers without malicious interception or data tampering across the internet.<\/span><\/p>\n<h3><b>Question 357<\/b><\/h3>\n<p><b>What device actively blocks malicious network intrusion attempts?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Layer 2 unmanaged Ethernet bridge switch<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Passive network signal sniffing tap hub<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Intrusion Prevention System (IPS) appliance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unshielded twisted-pair patch cable link<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An Intrusion Prevention System (IPS) is an advanced inline security appliance designed to monitor network traffic for malicious activities, policy violations, and known attack signatures with the capability to actively block or drop identified threats in real time. Unlike passive Intrusion Detection Systems that merely generate alerts, an IPS sits directly in the data path of network traffic flows to terminate malicious connection sessions instantly. By executing signature matching, protocol anomaly detection, and heuristic analysis inline, an IPS provides critical frontline defense against network exploits, preventing malicious payloads from reaching vulnerable host systems.<\/span><\/p>\n<h3><b>Question 358<\/b><\/h3>\n<p><b>Which routing security framework uses Route Origin Authorizations?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Resource Public Key Infrastructure (RPKI) framework<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Simple Network Management Protocol version 3 daemon<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic ARP Inspection port filter mechanism<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port-based 802.1X network access control standard<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Resource Public Key Infrastructure (RPKI) is a specialized cryptographic framework designed to secure the routing infrastructure of the internet by validating the ownership of Internet Number Resources. BGP routing table exchanges historically lacked built-in authentication, leaving global routing vulnerable to malicious prefix hijacking and accidental route leaks. RPKI utilizes cryptographic Route Origin Authorizations to bind specific IP address prefixes to authorized autonomous system numbers, allowing routers to validate digital signatures before accepting routing updates. This prevents unauthorized networks from falsely announcing IP blocks they do not own.<\/span><\/p>\n<h3><b>Question 359<\/b><\/h3>\n<p><b>What hardening practice rate-limits router control plane traffic?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Flat unsegmented network bridging topology<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unencrypted Telnet console remote management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Control Plane Policing (CoPP) security feature<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Passive optical network signal tapping hub<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Control Plane Policing (CoPP) is a security and Quality of Service feature implemented on Cisco network hardware that utilizes QoS mechanisms to manage and rate-limit control plane traffic destined for the device&#8217;s CPU. By prioritizing legitimate routing protocols\u2014like BGP and OSPF\u2014and throttling excessive or malicious traffic streams\u2014such as ARP floods or Denial of Service attacks\u2014CoPP prevents CPU resource exhaustion and ensures network device stability. Protecting the control plane prevents malicious actors from crashing core routers and switches, maintaining continuous network availability across enterprise architecture.<\/span><\/p>\n<h3><b>Question 360<\/b><\/h3>\n<p><b>Which switch feature filters traffic using DHCP bindings?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port security MAC address limiting filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IP Source Guard traffic filtering feature<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic ARP Inspection port verification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unicast Reverse Path Forwarding check<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">IP Source Guard is a Layer 2 security technology implemented on Cisco switches that filters out malicious or spoofed IP traffic by leveraging the binding database created by DHCP snooping and static IP source entries. When enabled on untrusted ports, IP Source Guard compares incoming IP packets against authorized IP-MAC-port bindings. Any packet arriving with a source IP address that does not match the binding database is immediately dropped, preventing malicious IP spoofing attacks at the access layer. This ensures that endpoints cannot spoof IP addresses to bypass security policies or launch network attacks.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco CCNP Cybersecurity 350-201 Exam Dumps and Practice Test Dumps. &nbsp; Question 341 What protocol secures BGP routing sessions using TCP MD5? Resource Public Key Infrastructure authorization framework TCP MD5 Signature Option specified in RFC 2385 Unicast Reverse Path Forwarding route verification check Dynamic ARP Inspection port filtering security mechanism Correct Answer: 2 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14620"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=14620"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14620\/revisions"}],"predecessor-version":[{"id":14670,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14620\/revisions\/14670"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=14620"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=14620"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=14620"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}