{"id":14798,"date":"2026-09-17T07:16:59","date_gmt":"2026-09-17T07:16:59","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=14798"},"modified":"2026-09-17T07:16:59","modified_gmt":"2026-09-17T07:16:59","slug":"cisco-ccnp-security-300-730-practice-test-questions-and-exam-dumps-part5-q81-100","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-ccnp-security-300-730-practice-test-questions-and-exam-dumps-part5-q81-100\/","title":{"rendered":"Cisco CCNP Security 300-730 Practice Test Questions and Exam Dumps Part5 Q81-100"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/300-730-exam-dumps\"><b>Cisco CCNP Security 300-730 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 81<\/b><\/h3>\n<p><b>Which Cisco technology provides centralized identity-based access control for wired and wireless networks?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco Umbrella<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco Secure Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco ISE<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco Secure Client<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Cisco Identity Services Engine, commonly known as Cisco ISE, provides centralized identity-based access control for enterprise networks. It can authenticate users and devices and then apply authorization policies based on identity, device type, location, security posture, and other contextual information. ISE commonly integrates with 802.1X to control access to wired and wireless infrastructure. It can also support guest access, profiling, and posture-related functions. Cisco Umbrella focuses primarily on cloud-delivered security, Secure Firewall provides network security enforcement, and Secure Client operates on endpoints. ISE is therefore well suited for organizations requiring centralized identity-aware network access policies.<\/span><\/p>\n<h3><b>Question 82<\/b><\/h3>\n<p><b>Which protocol is commonly used by Cisco ISE to authenticate network users through 802.1X?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RADIUS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SNMP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TFTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">RADIUS is commonly used between Cisco ISE and network access devices when implementing 802.1X authentication. The switch or wireless controller acts as the authenticator and communicates with ISE as the RADIUS server. ISE validates the user&#8217;s or device&#8217;s credentials and returns authorization information to the network access device. FTP and TFTP are file-transfer protocols, while SNMP is primarily used for network monitoring and management. RADIUS is widely used for network access authentication because it supports centralized authentication and authorization and integrates well with enterprise identity systems and 802.1X deployments.<\/span><\/p>\n<h3><b>Question 83<\/b><\/h3>\n<p><b>Which IPsec mode encrypts the original IP header along with the payload?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Transport mode<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tunnel mode<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Authentication mode<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Proxy mode<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">IPsec tunnel mode encapsulates the original IP packet inside a new IP packet. The original IP header and payload are protected, while a new outer IP header is added for routing between VPN peers. Tunnel mode is commonly used for site-to-site VPNs where security gateways connect separate networks across an untrusted network. Transport mode protects the payload while retaining the original IP header and is commonly associated with host-to-host communication. Authentication mode and proxy mode are not IPsec operating modes. Tunnel mode therefore provides the encapsulation required for typical gateway-to-gateway VPN deployments.<\/span><\/p>\n<h3><b>Question 84<\/b><\/h3>\n<p><b>Which security mechanism helps prevent rogue DHCP servers from providing unauthorized IP configuration?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic ARP Inspection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IP Source Guard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP Snooping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port Security<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">DHCP Snooping helps protect a switched network from unauthorized or rogue DHCP servers. The switch can classify interfaces as trusted or untrusted. DHCP responses from untrusted interfaces can be blocked, while legitimate DHCP server traffic is allowed through trusted interfaces. DHCP Snooping can also build a binding database containing information such as client MAC addresses, assigned IP addresses, VLANs, and interfaces. Other Layer 2 security features can use this information. Dynamic ARP Inspection validates ARP traffic, IP Source Guard controls source addresses, and Port Security limits MAC addresses. DHCP Snooping is specifically designed to control DHCP behavior.<\/span><\/p>\n<h3><b>Question 85<\/b><\/h3>\n<p><b>Which Cisco Secure Firewall feature allows administrators to control access based on URL categories?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">URL Filtering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP Snooping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MACsec<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IP Source Guard<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">URL Filtering allows Cisco Secure Firewall deployments to control web access based on URL categories and reputation information. Administrators can create policies that permit or block websites according to organizational requirements. For example, categories associated with malicious or inappropriate content can be restricted while business-related categories remain accessible. DHCP Snooping and IP Source Guard are Layer 2 security features, while MACsec protects Ethernet traffic using encryption and integrity mechanisms. URL filtering provides an additional level of web security because policies can consider the destination website or category rather than relying only on IP addresses and ports.<\/span><\/p>\n<h3><b>Question 86<\/b><\/h3>\n<p><b>Which protocol is designed to provide secure remote command-line access to network devices?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Telnet<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SSH<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HTTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">SSH, or Secure Shell, provides encrypted remote command-line access to network devices. It protects administrator credentials and session data from being transmitted in clear text. SSH is commonly used for securely managing routers, switches, firewalls, and other infrastructure. Telnet also provides remote CLI access but does not encrypt the session, making it unsuitable for secure administrative access over untrusted networks. FTP is primarily used for file transfers, while HTTP is used for web-based communication. Organizations generally prefer SSH for remote CLI management because it provides confidentiality and authentication for administrative sessions.<\/span><\/p>\n<h3><b>Question 87<\/b><\/h3>\n<p><b>Which security technology uses digital certificates to establish trusted identities?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">PKI<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ARP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Public Key Infrastructure, or PKI, provides the framework for managing digital certificates and public-key cryptography. A certificate authority issues certificates that bind an identity to a public key. Devices and users can then use these certificates for authentication, encryption, and establishing trust. PKI is commonly used with technologies such as TLS, IPsec VPNs, and secure email. NAT translates network addresses, DHCP provides IP configuration, and ARP resolves IPv4 addresses to MAC addresses. PKI is particularly useful in large environments because certificate-based authentication can scale more effectively than manually managing shared secrets between many systems.<\/span><\/p>\n<h3><b>Question 88<\/b><\/h3>\n<p><b>Which Cisco security feature can identify and control applications regardless of the TCP or UDP port they use?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application Control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port Security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP Snooping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MACsec<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Application Control allows Cisco security platforms to identify applications and enforce policies based on application identity rather than relying only on TCP or UDP port numbers. Modern applications may use dynamic ports, common protocols, or encrypted connections, making simple port-based filtering less effective. Application-aware policies can allow, block, or further inspect identified applications according to organizational requirements. Port Security controls MAC addresses on switch interfaces, DHCP Snooping protects DHCP operations, and MACsec secures Layer 2 traffic. Application Control therefore provides more granular visibility and policy enforcement for modern enterprise network traffic.<\/span><\/p>\n<h3><b>Question 89<\/b><\/h3>\n<p><b>Which component of a PKI environment is responsible for issuing and signing digital certificates?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Registration Authority<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate Authority<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Authentication Server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS Server<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">The Certificate Authority, or CA, is responsible for issuing and digitally signing certificates in a PKI environment. The CA verifies identity according to the organization&#8217;s certificate policies and then creates certificates containing information such as the subject identity and public key. A Registration Authority may assist with identity verification and certificate requests, but the CA performs the certificate issuance and signing function. DNS servers provide name resolution, while authentication servers handle other forms of identity verification. A trusted CA hierarchy allows devices and applications to validate certificates and establish cryptographic trust with other systems.<\/span><\/p>\n<h3><b>Question 90<\/b><\/h3>\n<p><b>Which security control is primarily responsible for determining what an authenticated user is allowed to do?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Accounting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Authorization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encryption<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Authorization determines what actions or resources an authenticated user is permitted to access. Authentication first verifies the identity of a user or device, while authorization applies permissions after that identity has been established. Accounting records activity such as login events and administrative actions. Encryption protects information from unauthorized disclosure during transmission or storage. In an AAA framework, authentication answers who the user is, authorization determines what the user can do, and accounting records what the user did. Understanding these distinctions is important when designing centralized access-control policies for enterprise security systems.<\/span><\/p>\n<h3><b>Question 91<\/b><\/h3>\n<p><b>Which Cisco solution provides DNS-based security enforcement using cloud-delivered threat intelligence?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco ISE<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco Secure Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco Umbrella<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco Secure Client<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Cisco Umbrella provides cloud-delivered security services that can enforce policies at the DNS layer. When a user attempts to access a domain, Umbrella can evaluate the DNS request against security intelligence and configured policies. Requests associated with malicious, phishing, or otherwise blocked destinations can be prevented before the connection is established. Cisco ISE is focused on identity and network access control, Secure Firewall provides network security enforcement, and Secure Client provides endpoint-based capabilities. DNS-layer security is useful because it can protect users even when they are outside the traditional corporate network perimeter.<\/span><\/p>\n<h3><b>Question 92<\/b><\/h3>\n<p><b>Which IPsec protocol provides confidentiality by encrypting network traffic?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AH<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ESP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IKE<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ARP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Encapsulating Security Payload, or ESP, is the primary IPsec protocol used to provide confidentiality through encryption. ESP can also provide integrity, authentication, and anti-replay protection depending on the configured algorithms and security association. AH can provide integrity and authentication but does not encrypt the payload. IKE is responsible for negotiating security associations and cryptographic parameters rather than directly protecting user traffic. ARP is a local network protocol used for IPv4 address-to-MAC resolution. ESP is therefore the protocol most commonly associated with encrypted IPsec VPN traffic.<\/span><\/p>\n<h3><b>Question 93<\/b><\/h3>\n<p><b>Which Layer 2 security feature validates ARP packets against trusted IP-to-MAC bindings?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic ARP Inspection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port Security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IP Source Guard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP Relay<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Dynamic ARP Inspection, or DAI, validates ARP packets to help prevent ARP spoofing attacks. On many Cisco switch deployments, DAI uses the DHCP Snooping binding database as a source of trusted IP-to-MAC information. When an ARP packet arrives, the switch can compare the claimed IP and MAC information with the trusted binding. Invalid packets can then be dropped. Port Security controls MAC addresses on interfaces, IP Source Guard validates source addressing, and DHCP Relay forwards DHCP messages between network segments. DAI is especially effective when deployed together with DHCP Snooping in access-layer security designs.<\/span><\/p>\n<h3><b>Question 94<\/b><\/h3>\n<p><b>Which Cisco security management platform is used to centrally configure and monitor Secure Firewall policies?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco ISE<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco Umbrella<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco Secure Client<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco Secure Firewall Management Center<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Cisco Secure Firewall Management Center, or FMC, provides centralized management and monitoring for supported Cisco Secure Firewall deployments. Administrators can configure access-control policies, network objects, NAT, VPN settings, intrusion policies, and other security functions through the management platform. FMC also provides visibility into security events and traffic activity from managed devices. Cisco ISE focuses on identity-based network access, Umbrella provides cloud security services, and Secure Client provides endpoint capabilities. Centralized management is particularly useful when organizations operate multiple firewalls and need consistent security policies and centralized operational visibility.<\/span><\/p>\n<h3><b>Question 95<\/b><\/h3>\n<p><b>Which VPN type connects two or more complete networks through an encrypted tunnel?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remote-access VPN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Site-to-site VPN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Clientless VPN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Host-only VPN<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">A site-to-site VPN creates an encrypted connection between networks, commonly using security gateways at each location. Users inside the connected networks can communicate through the VPN without individually establishing a VPN session on every endpoint. IPsec is frequently used to provide encryption and authentication for site-to-site VPNs. A remote-access VPN is designed for individual users connecting from external locations. Clientless VPNs typically provide browser-based access to selected resources rather than connecting entire networks. Site-to-site VPNs are therefore commonly used to securely connect branch offices, data centers, headquarters, and other organizational locations.<\/span><\/p>\n<h3><b>Question 96<\/b><\/h3>\n<p><b>Which security technology provides encryption and integrity protection for Ethernet frames at Layer 2?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MACsec<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RADIUS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IKE<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TACACS+<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">MACsec, defined by IEEE 802.1AE, provides Layer 2 security for Ethernet frames. It can provide confidentiality, integrity, data-origin authentication, and protection against certain replay attacks depending on the implementation and configuration. MACsec is useful when organizations need to protect traffic on Ethernet links, including connections between switches or supported endpoint devices. RADIUS and TACACS+ are AAA protocols, while IKE is used for negotiating IPsec security associations. MACsec operates at a different layer from IPsec and is particularly useful when Layer 2 traffic itself needs cryptographic protection across a trusted or semi-trusted network infrastructure.<\/span><\/p>\n<h3><b>Question 97<\/b><\/h3>\n<p><b>Which security function records user or administrator activities for later review?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Authorization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Accounting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encryption<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Accounting records activities performed by authenticated users or administrators. In AAA systems, accounting information can include login times, session durations, commands executed, or other activity depending on the protocol and device configuration. This information can be useful for auditing, troubleshooting, compliance, and security investigations. Authentication verifies identity, authorization determines permitted actions, and encryption protects data from unauthorized disclosure. Accounting therefore completes the AAA model by providing visibility into what authenticated users actually did. Centralized accounting can also help security teams correlate administrative activity across multiple network devices and identify unusual or unauthorized behavior.<\/span><\/p>\n<h3><b>Question 98<\/b><\/h3>\n<p><b>Which technology can restrict a switch port to a specific number of authorized MAC addresses?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPsec<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port Security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco Umbrella<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">URL Filtering<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Port Security allows a Cisco switch interface to be configured with a maximum number of secure MAC addresses. This limits the number of devices that can successfully use the port and can help prevent unauthorized endpoint connections. Secure MAC addresses can be configured manually or learned dynamically depending on the deployment. If the configured limit is exceeded or an unauthorized MAC address is detected, the switch can apply a configured violation action. IPsec protects IP traffic, Cisco Umbrella provides cloud-delivered security, and URL Filtering controls web destinations. Port Security is therefore a direct Layer 2 access-control mechanism.<\/span><\/p>\n<h3><b>Question 99<\/b><\/h3>\n<p><b>Which protocol is responsible for negotiating IPsec security parameters between VPN peers?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ESP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AH<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IKE<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MACsec<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Internet Key Exchange, or IKE, negotiates security parameters between IPsec VPN peers. During the negotiation process, the peers establish trust, agree on cryptographic algorithms, authenticate each other, and establish the information needed to create IPsec security associations. IKEv2 is the modern version commonly used in current VPN deployments. ESP protects the actual user traffic, while AH can provide integrity and authentication without encryption. MACsec protects Ethernet frames at Layer 2 and does not perform IPsec VPN negotiation. IKE is therefore a critical control-plane protocol for establishing secure IPsec communications between VPN endpoints.<\/span><\/p>\n<h3><b>Question 100<\/b><\/h3>\n<p><b>Which security principle uses multiple independent security controls to reduce the impact of a single control failure?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defense in depth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network Address Translation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single sign-on<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<h3><b>Explanation<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Defense in depth is a security principle that uses multiple layers of protection so that the failure or bypass of one security control does not automatically expose the entire environment. Organizations may combine firewalls, intrusion prevention, endpoint protection, identity controls, network segmentation, encryption, monitoring, and security policies to create several defensive layers. Least privilege focuses on limiting permissions to only what users or systems require. NAT translates network addresses, while single sign-on allows users to authenticate once and access multiple authorized applications. Defense in depth improves resilience because different controls can address different attack paths and security weaknesses.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco CCNP Security 300-730 Exam Dumps and Practice Test Dumps. &nbsp; Question 81 Which Cisco technology provides centralized identity-based access control for wired and wireless networks? Cisco Umbrella Cisco Secure Firewall Cisco ISE Cisco Secure Client Correct Answer: 3 Explanation Cisco Identity Services Engine, commonly known as Cisco ISE, provides centralized identity-based access [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14798"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=14798"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14798\/revisions"}],"predecessor-version":[{"id":14825,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14798\/revisions\/14825"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=14798"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=14798"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=14798"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}