{"id":17689,"date":"2026-09-21T10:59:08","date_gmt":"2026-09-21T10:59:08","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=17689"},"modified":"2026-09-21T10:59:08","modified_gmt":"2026-09-21T10:59:08","slug":"cisco-ccnp-security-300-745-practice-test-questions-and-exam-dumps-part5-q81-100","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-ccnp-security-300-745-practice-test-questions-and-exam-dumps-part5-q81-100\/","title":{"rendered":"Cisco CCNP Security 300-745 Practice Test Questions and Exam Dumps Part5 Q81-100"},"content":{"rendered":"<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/300-745-exam-dumps\"><b>Cisco CCNP Security 300-745 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/p>\n<p><b><br \/>\n<\/b><b>Q81. A company must connect branch offices through a service-provider WAN and wants traffic separation between customers, but encryption is not an explicit requirement. Which technology best fits the design?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> MPLS VPN<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> GRE over the public Internet<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Host-based firewall<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> TLS decryption<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. MPLS VPN<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> MPLS VPN services can provide logically separated customer routing environments across a service-provider backbone. They are commonly selected when an organization needs scalable private WAN connectivity between many locations without building individual Internet VPN tunnels. MPLS provides traffic separation and predictable provider-managed routing, but architects should remember that MPLS does not inherently encrypt customer traffic. If confidentiality is required, an additional encryption layer such as IPsec may be appropriate. GRE provides tunneling but no encryption or provider-managed separation by itself. Host firewalls and TLS decryption serve entirely different security functions and do not provide branch-to-branch WAN connectivity.<\/span><\/p>\n<p><b>Q82. An enterprise permits employees to use personal mobile devices for email but wants corporate data separated from personal applications. Which design is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Give every personal application access to corporate files<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable all device authentication<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Place corporate data in the user&#8217;s personal photo storage<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Use mobile application management with containerized corporate data controls<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Use mobile application management with containerized corporate data controls<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Mobile application management can protect corporate applications and data without requiring the organization to take full ownership of the employee&#8217;s personal device. Policies can restrict copying corporate data into unmanaged applications, require application-level authentication, control data sharing, and remotely remove corporate information while preserving personal content. This supports bring-your-own-device programs where privacy and security must coexist. Allowing unrestricted application access creates data leakage risk, while disabling authentication would weaken identity assurance. Storing enterprise data in personal consumer applications also reduces governance. Containerized application controls therefore provide a practical separation between corporate and personal environments.<\/span><\/p>\n<p><b>Q83. A company wants users to authenticate with a password plus a hardware token before accessing sensitive administrative systems. Which security concept is being applied?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Single-factor authentication<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Multi-factor authentication<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Anonymous authentication<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Network address translation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Multi-factor authentication<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Multi-factor authentication requires evidence from more than one independent authentication factor. A password is something the user knows, while a hardware token represents something the user possesses. Combining the two makes account compromise more difficult because stealing only the password is insufficient. MFA is especially important for administrators, remote access, sensitive applications, and privileged operations. The factors should be genuinely independent; two passwords would still represent one factor type. Anonymous access removes identity assurance, while NAT is a networking function unrelated to authentication. Strong MFA should also be combined with appropriate session controls and monitoring.<\/span><\/p>\n<p><b>Q84. Which architecture best prevents an attacker who compromises an ordinary user account from immediately receiving permanent administrator privileges?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Assign every employee to the administrator group<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Share one root credential across departments<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Use privileged access management with just-in-time elevation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable administrator auditing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Use privileged access management with just-in-time elevation<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Privileged access management reduces the number and duration of standing administrative privileges. With just-in-time elevation, a user receives privileged access only when it is required, typically after additional authentication, approval, or policy checks. The privilege can expire automatically after a defined period. This reduces the usefulness of a compromised everyday account and creates stronger auditability for administrative actions. Assigning everyone permanent administrator rights greatly increases risk, while shared root credentials destroy individual accountability. Disabling auditing makes privileged misuse harder to detect. Just-in-time privilege therefore limits standing access and supports least-privilege security architecture.<\/span><\/p>\n<p><b>Q85. An organization wants to protect email users from attackers who spoof the organization&#8217;s own domain in phishing messages. Which technologies are specifically designed to improve email-domain authentication?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> GRE and IPsec<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> SPF, DKIM, and DMARC<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> SNMP and Syslog<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> DHCP and ARP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. SPF, DKIM, and DMARC<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> SPF, DKIM, and DMARC work together to strengthen email-domain authentication. SPF identifies systems authorized to send mail for a domain. DKIM digitally signs messages so receivers can verify domain-associated message integrity. DMARC builds on these technologies by defining alignment requirements and a domain owner&#8217;s policy for handling authentication failures while also providing reporting. These controls help reduce straightforward domain spoofing, although they do not eliminate every phishing or business email compromise technique. GRE, IPsec, SNMP, Syslog, DHCP, and ARP serve networking or monitoring functions and do not provide sender-domain authentication for Internet email.<\/span><\/p>\n<p><b>Q86. A remote worker connects to an internal application from a company-managed laptop. The organization wants access to be revoked if endpoint protection becomes disabled during the session. Which concept best supports this requirement?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Continuous trust evaluation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Static password authentication only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Permanent network trust after login<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Unrestricted split tunneling<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Continuous trust evaluation<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Continuous trust evaluation extends security decisions beyond the initial login. Identity, device posture, risk indicators, location, and other context can be reevaluated while the session remains active. If a managed laptop loses required endpoint protection or becomes noncompliant, policy can reduce access, trigger reauthentication, or terminate the session. This aligns with zero-trust principles because trust is not granted permanently after one successful authentication event. Password-only authentication cannot detect a later device security change. Permanent trust after login leaves the organization exposed if the endpoint&#8217;s state deteriorates during the session.<\/span><\/p>\n<p><b>Q87. An organization has several applications in AWS, Azure, and an on-premises data center. Which security design provides the most consistent segmentation model across these environments?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use no internal segmentation because the environments are separate<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Rely exclusively on public IP addresses<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Create one large flat routed network across all environments<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Use identity- and policy-based segmentation enforced across workload environments<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Use identity- and policy-based segmentation enforced across workload environments<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Hybrid and multi-cloud environments benefit from segmentation policies based on workload identity, application role, tags, or other consistent context instead of relying only on physical network location. This approach can maintain similar communication rules even when applications move between an on-premises data center and different cloud providers. A flat network expands lateral-movement opportunities, while relying on public addressing does not provide segmentation. Separate environments also do not automatically prevent unauthorized communication when interconnections exist. Consistent identity- and policy-based segmentation supports least privilege and reduces security drift across heterogeneous infrastructure platforms.<\/span><\/p>\n<p><b>Q88. A security architect must allow an Internet-facing application to receive traffic while keeping its database inaccessible directly from the Internet. Which design is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Put both the web server and database directly on the Internet<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Give the database a public address and no firewall<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Use separate application tiers and permit database access only from authorized application servers<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable all database authentication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Use separate application tiers and permit database access only from authorized application servers<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Tiered application architecture separates externally reachable components from sensitive back-end systems. The Internet-facing tier can receive approved client traffic, while firewall or microsegmentation policies allow database connections only from authorized application servers on required ports. Direct Internet access to the database should be denied. This limits the database attack surface and reduces the impact of external scanning and direct exploitation attempts. Authentication and encryption should still be applied between application and database tiers. Publishing the database openly or disabling database authentication would create severe risk and violate least-privilege design principles.<\/span><\/p>\n<p><b>Q89. A security team must choose between IDS and IPS for an application environment where blocking an incorrect packet could cause major financial loss. Which initial deployment is safest?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Deploy IDS passively, tune detections, and evaluate alerts before moving to prevention<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Immediately block every anomalous packet<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable all threat monitoring<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Put the IPS in front of the application with default deny-all signatures<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Deploy IDS passively, tune detections, and evaluate alerts before moving to prevention<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Passive IDS is appropriate when the organization first needs to understand traffic patterns and tune detection logic without risking disruption from false positives. Security teams can observe alerts, validate signatures, establish baselines, and identify application-specific exceptions before considering inline prevention. Once confidence improves, selected high-fidelity detections can be moved to blocking mode. Immediately enabling aggressive prevention can interrupt legitimate business traffic, especially in sensitive financial systems. Disabling monitoring provides no protection. A phased detect-then-prevent deployment balances security improvement with availability requirements and operational risk.<\/span><\/p>\n<p><b>Q90. Which firewall architecture is most appropriate when security policy must be enforced directly between virtual workloads even when traffic never leaves the hypervisor environment?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Internet-edge firewall only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Distributed firewall<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Email gateway<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> DNS server<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Distributed firewall<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> A distributed firewall places enforcement close to virtual workloads and can inspect or control east-west communication even when packets remain within the virtualized environment. This is particularly useful for microsegmentation because policy can be applied to individual workloads or groups based on identity, tags, or application role. A perimeter firewall may never see traffic between two virtual machines on the same internal infrastructure. Email gateways and DNS servers provide different security services. Distributed firewalling therefore closes visibility and enforcement gaps created when application traffic does not traverse traditional physical network boundaries.<\/span><\/p>\n<p><b>Q91. An application team wants to ensure that uploaded files cannot execute malicious code on the production server. Which design provides the strongest defense?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Store uploaded content in the operating system&#8217;s executable directory<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Give uploaded files administrator privileges<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable file-type checking<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Isolate uploads, validate content, scan files, and prevent execution permissions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Isolate uploads, validate content, scan files, and prevent execution permissions<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> File-upload security requires multiple controls because attackers can disguise malicious content or exploit weak server handling. Uploaded files should be stored outside executable application directories, renamed or normalized safely, checked against permitted types, scanned for malware where appropriate, and served with permissions that prevent execution. Application logic should not trust user-supplied filenames or MIME information alone. Giving uploaded content privileged execution rights would create a direct compromise path. Layered validation, isolation, and non-executable storage significantly reduce the risk that an uploaded file becomes a server-side attack mechanism.<\/span><\/p>\n<p><b>Q92. Which control best reduces the risk of an attacker sending millions of API requests to exhaust an application service?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable application authentication<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> API rate limiting and quotas<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Give every client unlimited connections<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Turn off logging<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. API rate limiting and quotas<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Rate limiting controls how many requests a client, token, user, application, or source can submit within a specified period. Quotas can further define longer-term consumption limits. These controls reduce the ability of one actor to exhaust application resources and can limit abuse such as brute-force attempts, scraping, or denial-of-service behavior. Rate limiting should be combined with appropriate authentication, caching, scalable infrastructure, and DDoS protections. Removing authentication or allowing unlimited requests would increase abuse risk. Logging should remain enabled so rate-limit events and suspicious traffic patterns can be investigated.<\/span><\/p>\n<p><b>Q93. A security architect is evaluating a new cloud service. Which requirement best supports later forensic investigation if the service is compromised?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Centralized, time-synchronized, tamper-resistant audit logging<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable logs to save storage<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Permit users to erase audit trails<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Use local logs with inconsistent timestamps only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Centralized, time-synchronized, tamper-resistant audit logging<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Effective forensic analysis depends on reliable records showing what happened, when it happened, and which identity or system performed each action. Centralized logging reduces the risk that attackers erase evidence from the compromised system. Consistent time synchronization allows investigators to correlate events across identity, network, application, and cloud platforms. Retention and access controls should protect logs from unauthorized modification. Disabling logging or allowing users to delete evidence undermines incident response. Inconsistent timestamps also make event reconstruction difficult. Logging architecture should therefore be designed as part of the security system rather than treated as an afterthought.<\/span><\/p>\n<p><b>Q94. A SOC wants to automatically enrich a suspicious IP address with reputation data, identify affected endpoints, and open a ticket. Which technology is most suitable?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Static routing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> VLAN trunking<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> SOAR playbook<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> GRE<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. SOAR playbook<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> SOAR playbooks orchestrate repeatable workflows across security products and business systems. For a suspicious IP indicator, a playbook could query threat-intelligence services, search SIEM and endpoint telemetry, determine which hosts communicated with the address, calculate severity, and create or update a ticket. Higher-risk response steps can require analyst approval. This automation reduces repetitive analyst work and improves response consistency. Static routing, VLAN trunking, and GRE are networking technologies and do not perform multi-system incident enrichment or case-management automation. SOAR is specifically intended to coordinate security investigation and response workflows.<\/span><\/p>\n<p><b>Q95. A security architect reviews an incident caused by excessive permissions granted to a service account. Which architectural change best addresses the root cause?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Give all service accounts the same administrator permissions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Apply least privilege and periodically review service-account permissions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable authentication for services<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Share one permanent credential across applications<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Apply least privilege and periodically review service-account permissions<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Service accounts should have only the privileges required to perform their defined application functions. Permissions should be reviewed periodically because applications change and historical privileges can accumulate over time. Where possible, short-lived workload identities and automated credential rotation can further reduce exposure. Broad administrator rights create unnecessary blast radius if credentials or applications are compromised. Disabling authentication would make services less secure, while shared credentials weaken accountability and rotation. Incident-driven architecture reviews should identify the underlying privilege design failure and modify identity policy rather than only responding to the individual compromised account.<\/span><\/p>\n<p><b>Q96. Which risk response is being used when an organization stops offering a vulnerable legacy Internet service entirely because the business benefit no longer justifies the exposure?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Risk transfer<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Risk acceptance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Risk mitigation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Risk avoidance<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Risk avoidance<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Risk avoidance removes the activity that creates the risk. If a vulnerable legacy Internet service is no longer necessary and the organization permanently eliminates it, the related exposure is avoided rather than merely reduced. Risk mitigation would retain the service while adding controls to lower probability or impact. Risk transfer might move some financial consequences to another party, such as an insurer. Risk acceptance means management knowingly tolerates the remaining exposure. Architects should understand the business objective because sometimes the most effective security design is to remove an unnecessary risky capability rather than add more controls around it.<\/span><\/p>\n<p><b>Q97. An organization must demonstrate that security controls continue operating effectively after a system is authorized for production. Which RMF activity addresses this need?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Continuous monitoring<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Initial categorization only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Procurement only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Asset disposal only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Continuous monitoring<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Continuous monitoring evaluates security controls and risk after a system is placed into operation. Environments change constantly through new vulnerabilities, software updates, configuration changes, user behavior, and evolving threats. A one-time authorization decision cannot guarantee continued security. Monitoring can include vulnerability scans, control assessments, configuration checks, incident metrics, audit-log review, and risk reporting. Findings can trigger remediation or updates to the system&#8217;s risk posture. Initial categorization remains important, but it does not provide ongoing assurance. Continuous monitoring keeps risk decisions current throughout the operational lifecycle.<\/span><\/p>\n<p><b>Q98. A DevSecOps pipeline must prevent developers from accidentally committing passwords and API tokens to a repository. Which automated control is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable version control<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Secret scanning in commits and CI pipelines<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Allow all credentials in source code<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Store production passwords in documentation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Secret scanning in commits and CI pipelines<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Secret-scanning tools identify patterns associated with passwords, access tokens, private keys, API credentials, and other sensitive values before or shortly after they enter source control. Scanning can run in developer hooks, pull requests, and CI pipelines to prevent accidental credential exposure. If a real secret is committed, simply deleting it from the latest file is insufficient because repository history may retain it; the credential should be revoked and rotated. Disabling version control would harm development practices, while deliberately storing credentials in source or documentation creates long-lived exposure. Automated secret scanning is therefore a key DevSecOps safeguard.<\/span><\/p>\n<p><b>Q99. A machine-learning system used for malware detection performs well during testing but slowly becomes less accurate as attacker behavior changes. Which issue does this illustrate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DHCP exhaustion<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> VLAN hopping<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Model drift<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> MAC flooding<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Model drift<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Model drift occurs when the statistical patterns encountered in production change from those represented in the data used to train or validate a machine-learning model. Security models are especially vulnerable because attackers actively change tools and techniques to evade detection. Monitoring model performance, false positives, false negatives, and data distributions helps teams identify drift. Models may require retraining or other updates, but retraining pipelines must themselves be protected against poisoning. DHCP exhaustion, VLAN hopping, and MAC flooding are network-layer attacks and do not describe declining machine-learning accuracy caused by changing data patterns.<\/span><\/p>\n<p><b>Q100. A generative AI assistant is allowed to query internal security documentation but must not retrieve HR or payroll records. Which architectural control best enforces this requirement?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Give the AI access to every corporate database<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Rely solely on the model to refuse sensitive requests<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable authentication on data sources<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Enforce authorization at the retrieval and data-access layer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Enforce authorization at the retrieval and data-access layer<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> AI models should not be treated as the primary security boundary for sensitive information. Access controls should be enforced by the systems that store and retrieve data. The AI service identity should have permission only to approved security documentation repositories, while HR and payroll systems should deny access regardless of what a prompt requests. This prevents prompt injection or model error from bypassing organizational authorization. Additional controls can include data classification, logging, filtering, and human oversight. Relying only on the model&#8217;s behavior is insufficient because models can misinterpret instructions or be manipulated by adversarial input.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco CCNP Security 300-745 Exam Dumps and Practice Test Dumps. Q81. A company must connect branch offices through a service-provider WAN and wants traffic separation between customers, but encryption is not an explicit requirement. Which technology best fits the design? MPLS VPN 2. GRE over the public Internet 3. Host-based firewall 4. TLS [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17689"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=17689"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17689\/revisions"}],"predecessor-version":[{"id":17690,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17689\/revisions\/17690"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=17689"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=17689"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=17689"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}