{"id":14622,"date":"2026-09-17T06:05:33","date_gmt":"2026-09-17T06:05:33","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=14622"},"modified":"2026-09-17T06:05:33","modified_gmt":"2026-09-17T06:05:33","slug":"cisco-ccnp-cybersecurity-350-201-practice-test-questions-and-exam-dumps-part20-q381-400","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-ccnp-cybersecurity-350-201-practice-test-questions-and-exam-dumps-part20-q381-400\/","title":{"rendered":"Cisco CCNP Cybersecurity 350-201 Practice Test Questions and Exam Dumps Part20 Q381-400"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/350-201-exam-dumps\"><b>Cisco CCNP Cybersecurity 350-201 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 381<\/b><\/h3>\n<p><b>What protocol negotiates cryptographic keys for IPsec VPNs securely?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Internet Key Exchange version 2 (IKEv2)<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Simple Network Management Protocol version 3 daemon<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic Host Configuration Protocol lease utility<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Trivial File Transfer Protocol transfer mechanism<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Internet Key Exchange version 2 (IKEv2) is a standardized request\/response protocol designed within the IPsec protocol suite to securely negotiate security associations, establish cryptographic keys, and authenticate peers for Virtual Private Network connections. IKEv2 streamlines the handshake process significantly compared to its predecessor, reducing message exchanges, providing built-in NAT traversal support, and ensuring robust mobility and multihoming capabilities via MOBIKE. By establishing shared secret keys through secure Diffie-Hellman exchanges authenticated with digital certificates or pre-shared keys, IKEv2 lays a dependable cryptographic foundation for encrypted data tunnels traversing untrusted public networks.<\/span><\/p>\n<h3><b>Question 382<\/b><\/h3>\n<p><b>Which security architecture defines scalable group tags for micro-segmentation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Flat unsegmented network bridging topology<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco TrustSec (Scalable Group Tagging) architecture<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unencrypted Telnet remote administrative console<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Passive optical network signal tapping hub<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cisco TrustSec technology implements Software-Defined Segmentation using Scalable Group Tags (SGTs) to enforce access control policies across enterprise networks independently of physical IP subnets. Instead of relying on complex access control lists tied to frequently changing IP addresses, TrustSec classifies users and devices based on their authenticated role or function, tagging traffic at the ingress switch port with a secure hardware-based SGT header. Destination devices or egress enforcement points evaluate this tag against centralized policy matrices managed by Cisco ISE, enabling granular, micro-segmented security enforcement across campus and data center environments.<\/span><\/p>\n<h3><b>Question 383<\/b><\/h3>\n<p><b>What certificate validation mechanism queries real-time revocation status?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Online Certificate Status Protocol (OCSP) responder<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static Certificate Revocation List (CRL) file download<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unencrypted Lightweight Directory Access Protocol query<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic Host Configuration Protocol address lease table<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Online Certificate Status Protocol (OCSP) is an internet protocol used for obtaining the real-time revocation status of digital certificates in Public Key Infrastructure environments. Unlike traditional Certificate Revocation Lists\u2014which require client applications to download large, periodically updated lists containing all revoked serial numbers\u2014OCSP allows applications to send a targeted query to an OCSP responder and receive an immediate, cryptographically signed response indicating whether a specific certificate remains valid, has been revoked, or is unknown. This real-time validation mechanism minimizes security windows and optimizes bandwidth consumption across enterprise networks.<\/span><\/p>\n<h3><b>Question 384<\/b><\/h3>\n<p><b>Which automated security platform orchestrates incident response playbooks?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security Orchestration, Automation, and Response (SOAR)<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unmanaged Layer 2 Ethernet bridge switch device<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Passive network traffic packet sniffing tool<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unshielded twisted-pair patch cable network link<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security Orchestration, Automation, and Response (SOAR) platforms are advanced cybersecurity software solutions designed to streamline Security Operations Center workflows by integrating disparate security tools, automating repetitive investigative tasks, and executing predefined machine-driven incident response playbooks. When a security alert is triggered, SOAR platforms automatically aggregate threat telemetry, enrich event data with intelligence feeds, run containment scripts, and coordinate remediation actions across firewalls, endpoint protection systems, and email gateways without manual intervention, dramatically reducing mean time to respond.<\/span><\/p>\n<h3><b>Question 385<\/b><\/h3>\n<p><b>What security feature prevents ARP cache poisoning attacks on switches?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port security MAC address limiting filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic ARP Inspection (DAI) security feature<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unicast Reverse Path Forwarding route check<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP snooping Layer 2 binding cache<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Dynamic ARP Inspection (DAI) is a Layer 2 security feature built into enterprise switches that prevents Address Resolution Protocol spoofing and cache poisoning attacks. DAI leverages the trusted binding database established by DHCP snooping to intercept, log, and validate all ARP packets traversing untrusted ports. If an incoming ARP packet contains IP-to-MAC address mappings that conflict with the trusted DHCP binding database, DAI drops the packet immediately. This prevents malicious threat actors from intercepting local network traffic, conducting man-in-the-middle exploits, or hijacking default gateway communications.<\/span><\/p>\n<h3><b>Question 386<\/b><\/h3>\n<p><b>Which wireless security protocol mandates enterprise EAP-TLS authentication?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Wired Equivalent Privacy encryption protocol<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Wi-Fi Protected Access 2 pre-shared key<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Wi-Fi Protected Access 3 Enterprise (WPA3-Enterprise)<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unencrypted open guest wireless network<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Wi-Fi Protected Access 3 Enterprise (WPA3-Enterprise) provides enhanced cryptographic protection for corporate wireless networks by requiring robust authentication mechanisms such as the Extensible Authentication Protocol with Transport Layer Security (EAP-TLS). Unlike personal wireless modes that rely on shared passphrases, WPA3-Enterprise authenticates individual users or client devices against a centralized authentication server using unique digital certificates. Furthermore, WPA3-Enterprise enforces a minimum cryptographic strength baseline, mandating protected management frames and optional 192-bit cryptographic suites to secure enterprise wireless communications against eavesdropping and advanced impersonation attacks.<\/span><\/p>\n<h3><b>Question 387<\/b><\/h3>\n<p><b>What security assessment tool evaluates container image vulnerabilities?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Container image vulnerability scanning tool<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Passive network traffic packet sniffing probe<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static application source code review utility<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Active network port scanning utility scanner<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Container image vulnerability scanners are specialized security tools designed to inspect container images\u2014including application binaries, operating system packages, third-party libraries, and configuration files\u2014prior to deployment in production container orchestration environments like Kubernetes. These scanners compare software bill of materials against known vulnerability databases, Common Vulnerabilities and Exposures feeds, and security baselines to identify outdated dependencies or unpatched flaws. Integrating image scanning into CI\/CD pipelines ensures that insecure container workloads are intercepted and remediated before reaching runtime environments.<\/span><\/p>\n<h3><b>Question 388<\/b><\/h3>\n<p><b>Which protocol records user accounting data in centralized AAA?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remote Authentication Dial-In User Service (RADIUS) Accounting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Simple Network Management Protocol trap message<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic Host Configuration Protocol lease record<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Trivial File Transfer Protocol utility file transfer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">RADIUS Accounting is a core component of the Remote Authentication Dial-In User Service protocol responsible for tracking and recording resource consumption, connection durations, data transfer volumes, and session start\/stop events for network users and devices. When a user authenticates and accesses network services, the network access device transmits accounting start packets to the RADIUS server, followed by periodic updates and stop packets upon session termination. Security and administrative teams utilize RADIUS accounting logs for compliance auditing, billing reconciliation, capacity planning, and forensic tracking of user sessions across enterprise networks.<\/span><\/p>\n<h3><b>Question 389<\/b><\/h3>\n<p><b>What cloud proxy mode intercepts inline web traffic actively?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">API-based Cloud Access Security Broker mode<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Inline Forward Proxy Cloud Access Security Broker mode<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Passive network sniffing capture tap probe<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unmanaged Layer 2 Ethernet bridge switch<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An Inline Forward Proxy Cloud Access Security Broker (CASB) deployment mode sits directly in the network traffic path between enterprise user devices and cloud service providers. As users attempt to access web applications or cloud platforms, the forward proxy inspects outgoing HTTP\/HTTPS traffic in real time, enforcing granular Data Loss Prevention policies, blocking unauthorized shadow IT services, decrypting TLS traffic for deep inspection, and applying access controls based on user identity and device posture. This active inline positioning ensures immediate threat mitigation and strict adherence to corporate cloud governance policies.<\/span><\/p>\n<h3><b>Question 390<\/b><\/h3>\n<p><b>Which routing security filter blocks unauthorized prefix advertisements?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BGP Route Filtering using prefix lists and route maps<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unicast Reverse Path Forwarding interface check<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic ARP Inspection port verification filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port security MAC address limiting filter<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Border Gateway Protocol route filtering\u2014implemented using prefix lists, AS-path access lists, and route maps\u2014is an essential routing security practice used by network operators to control which routing update information is accepted or advertised to external peers. Without strict filtering, autonomous systems risk accepting malicious or accidental prefix announcements that could lead to global traffic hijacking or denial of service. By explicitly defining permitted IP address ranges and validating route origins, BGP filtering ensures that routers only propagate legitimate routing paths across the public internet infrastructure.<\/span><\/p>\n<h3><b>Question 391<\/b><\/h3>\n<p><b>What hardware security technology provides secure boot root of trust?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unmanaged Layer 2 Ethernet bridge switch<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Trusted Platform Module (TPM) \/ Hardware Trust Anchor<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Passive network tapping signal hub device<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unshielded twisted-pair patch cable link<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Trusted Platform Module (TPM) or hardware Trust Anchor provides an immutable hardware-based foundation for system security and cryptographic operations. During device startup, Secure Boot utilizes cryptographic public keys stored securely within the hardware trust anchor to verify the digital signature of operating system boot loaders, firmware images, and hypervisor components. If any firmware component has been tampered with or modified maliciously, the device halts the boot process, preventing compromised code execution. This hardware-level validation guarantees that the underlying platform has not been subverted by persistent firmware rootkits.<\/span><\/p>\n<h3><b>Question 392<\/b><\/h3>\n<p><b>Which incident response phase captures post-incident root cause analysis?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Preparation incident management phase<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Detection and analysis response phase<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Containment, eradication, and recovery phase<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Post-Incident Activity (Lessons Learned) phase<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Post-Incident Activity phase\u2014often referred to as the Lessons Learned phase\u2014is the final and critical stage of the National Institute of Standards and Technology incident response lifecycle. Following the successful containment, eradication, and recovery of a security breach, the incident response team conducts a comprehensive post-mortem review. This involves analyzing what went wrong, evaluating the effectiveness of detection tools and response procedures, documenting root causes, and implementing preventative security improvements to ensure that similar attacks cannot succeed in the future.<\/span><\/p>\n<h3><b>Question 393<\/b><\/h3>\n<p><b>What network hardening practice disables unnecessary device discovery protocols?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabling Cisco Discovery Protocol (CDP) and LLDP on untrusted ports<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Flat unsegmented network bridging topology configuration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unencrypted Telnet remote console management service<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Passive optical network signal tapping hub installation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Disabling discovery protocols such as Cisco Discovery Protocol (CDP) and Link Layer Discovery Protocol (LLDP) on untrusted access switch ports connected to end-user devices is a foundational network hardening practice. While discovery protocols are useful for mapping internal network topologies between enterprise switches, leaving them enabled on edge ports allows malicious actors to plug in devices, gather detailed hardware models, operating system versions, and IP addresses, and leverage that intelligence to launch targeted exploits. Restricting discovery protocols to internal infrastructure links minimizes reconnaissance exposure.<\/span><\/p>\n<h3><b>Question 394<\/b><\/h3>\n<p><b>Which vulnerability metric captures exploit code maturity changes?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Base vulnerability metrics characterization group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Environmental vulnerability metrics evaluation group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Temporal vulnerability metrics measurement group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exploitability operational index metrics collection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Common Vulnerability Scoring System Temporal metrics group measures the characteristics of a vulnerability that evolve over time as remediation data and exploit availability change. While Base metrics remain constant, Temporal metrics account for factors such as Exploit Code Maturity (whether functional exploit code is publicly available), Remediation Level (whether an official patch, workaround, or official fix exists), and Report Confidence (the degree of validation concerning the vulnerability&#8217;s existence). These metrics allow security teams to dynamically adjust vulnerability risk scores based on real-world threat landscape evolutions.<\/span><\/p>\n<h3><b>Question 395<\/b><\/h3>\n<p><b>What endpoint technology automatically isolates compromised host connections?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Endpoint Detection and Response (EDR) automated quarantine<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Basic static signature-based antivirus software scanner<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unmanaged Layer 2 Ethernet bridge switch hardware<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Passive network signal tap hub monitoring device<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Endpoint Detection and Response platforms provide automated containment capabilities that can logically or physically isolate a compromised host from the broader corporate network instantly upon detecting malicious activity. While isolation disconnects the infected machine from lateral network access and external command-and-control servers, it maintains a secure, dedicated management tunnel for security analysts to execute forensic data collections, memory dumps, and remote remediation actions. This rapid containment prevents malware from spreading across adjacent endpoints while preserving critical forensic artifacts.<\/span><\/p>\n<h3><b>Question 396<\/b><\/h3>\n<p><b>Which cryptographic property ensures past sessions remain uncompromised?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static RSA public key encryption mechanism<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Forward Secrecy (Perfect Forward Secrecy) property<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Electronic Codebook cipher mode implementation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Plaintext symmetric session key sharing method<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Forward Secrecy\u2014frequently referred to as Perfect Forward Secrecy\u2014is a cryptographic property of specific key agreement protocols that ensures session keys derived from public key cryptography are not compromised even if the long-term private key of the server is compromised at a later date. Ephemeral Diffie-Hellman key exchanges achieve this by generating a unique, temporary session key for every individual communication session and discarding it immediately afterwards. Because the long-term private key is never used directly to encrypt session data, past recorded ciphertexts remain completely secure against retrospective decryption attempts.<\/span><\/p>\n<h3><b>Question 397<\/b><\/h3>\n<p><b>What web security feature blocks inappropriate URL categories dynamically?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">URL filtering and web reputation filtering service<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unmanaged Layer 2 Ethernet bridge switch hardware<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Passive network packet sniffing capture probe tool<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unshielded twisted-pair patch cable network link<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">URL filtering and web reputation filtering is a core security service deployed on Next-Generation Firewalls and Secure Web Gateways that inspects HTTP\/HTTPS traffic to control user access to specific websites based on predefined organizational policies. Cloud-based intelligence engines categorize millions of URLs in real time\u2014spanning categories such as malware distribution sites, phishing portals, adult content, and social media. When a user attempts to access a restricted or low-reputation domain, the security gateway blocks the request instantly and presents a warning page, protecting enterprise employees from web-based threats.<\/span><\/p>\n<h3><b>Question 398<\/b><\/h3>\n<p><b>Which AAA framework component evaluates user authorization policies?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Policy Service Node (PSN) within Cisco ISE<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unmanaged Layer 2 Ethernet bridge switch device<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Passive network traffic signal analyzer monitoring tool<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unshielded twisted-pair network patch cable link<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Within a distributed Cisco Identity Services Engine architecture, the Policy Service Node (PSN) is responsible for handling network access requests, evaluating user credentials, performing endpoint profiling, and executing centralized authorization policy decisions. When a supplicant requests network access, the authenticator passes the credentials to the PSN, which compares the request against configured authorization rules and pushes back access attributes\u2014such as VLAN assignments, downloadable access control lists, or scalable group tags\u2014ensuring dynamic and consistent policy enforcement at the network edge.<\/span><\/p>\n<h3><b>Question 399<\/b><\/h3>\n<p><b>What threat hunting framework categorizes attacker tactics and techniques?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MITRE ATT&amp;CK adversary knowledge base framework<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open Web Application Security Project standard guide<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">National Institute of Standards risk framework model<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Information Technology Infrastructure Library framework<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">MITRE ATT&amp;CK is a globally accessible, curated knowledge base of adversary tactics and techniques based on real-world observation. Security operations teams, threat hunters, and defenders utilize the ATT&amp;CK framework to understand attacker behavior, map enterprise security monitoring coverage, evaluate detection tool effectiveness, and simulate adversary tactics during threat emulation and penetration testing exercises. By categorizing methods from initial compromise to data exfiltration, ATT&amp;CK provides a common taxonomy that empowers security professionals to strengthen defenses against specific threat actor behaviors.<\/span><\/p>\n<h3><b>Question 400<\/b><\/h3>\n<p><b>Which firewall deployment mode operates transparently at Layer 2?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Layer 3 routed firewall gateway deployment mode<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Transparent Firewall mode (Layer 2 bridge mode)<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Inline forward proxy Cloud Access Security Broker mode<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Passive network packet sniffing capture probe mode<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Transparent Firewall\u2014often referred to as a bridged firewall\u2014is a specialized security deployment mode where a firewall operates as a Layer 2 bridge rather than a traditional Layer 3 routed interface. Because the firewall does not alter IP addresses or act as a router hop, it can be inserted seamlessly into an existing network topology with minimal re-addressing or configuration changes. It inspects traffic passing across the bridge, applying stateful filtering, access control lists, and intrusion prevention rules between network segments while remaining completely invisible to surrounding routing protocols.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco CCNP Cybersecurity 350-201 Exam Dumps and Practice Test Dumps. &nbsp; Question 381 What protocol negotiates cryptographic keys for IPsec VPNs securely? Internet Key Exchange version 2 (IKEv2) Simple Network Management Protocol version 3 daemon Dynamic Host Configuration Protocol lease utility Trivial File Transfer Protocol transfer mechanism Correct Answer: 1 Explanation: Internet Key [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14622"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=14622"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14622\/revisions"}],"predecessor-version":[{"id":14668,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14622\/revisions\/14668"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=14622"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=14622"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=14622"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}