{"id":17691,"date":"2026-09-21T10:59:38","date_gmt":"2026-09-21T10:59:38","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=17691"},"modified":"2026-09-21T10:59:38","modified_gmt":"2026-09-21T10:59:38","slug":"cisco-ccnp-security-300-745-practice-test-questions-and-exam-dumps-part6-q101-120","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-ccnp-security-300-745-practice-test-questions-and-exam-dumps-part6-q101-120\/","title":{"rendered":"Cisco CCNP Security 300-745 Practice Test Questions and Exam Dumps Part6 Q101-120"},"content":{"rendered":"<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/300-745-exam-dumps\"><b>Cisco CCNP Security 300-745 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/p>\n<p><b><br \/>\n<\/b><b>Q101. An organization wants to protect users from phishing websites even when employees work from home and are not connected to the corporate VPN. Which architecture is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Internal-only Layer 2 ACLs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> A firewall deployed only in the headquarters data center<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Cloud-delivered DNS security enforced on managed endpoints<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Static routes to all known phishing servers<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Cloud-delivered DNS security enforced on managed endpoints<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Cloud-delivered DNS security can protect roaming users by enforcing DNS policies directly through an endpoint agent or a secure resolver reachable from any network. When a user attempts to resolve a known malicious or phishing domain, the security service can block the request before the endpoint establishes a connection. A headquarters-only firewall may not see traffic from users who are off-network without a VPN. Static routes cannot scale to continuously changing malicious infrastructure. Endpoint-enforced DNS security therefore extends consistent protection to hybrid workers regardless of whether they are connected to the corporate network.<\/span><\/p>\n<p><b>Q102. A company wants to prevent attackers from using stolen passwords to access sensitive SaaS applications from unmanaged devices. Which design best addresses both identity and endpoint risk?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Password authentication with no device checks<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Conditional access using MFA and device posture evaluation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Allow access based only on source IP address<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Shared department credentials<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Conditional access using MFA and device posture evaluation<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Conditional access combines identity assurance with contextual information such as device management state, operating-system compliance, location, risk level, and application sensitivity. Requiring MFA reduces the usefulness of stolen passwords, while device posture checks can prevent access from unknown or compromised endpoints. Source IP addresses alone are weak trust signals, especially for remote workers and cloud applications. Shared credentials also remove user accountability and increase compromise risk. A policy that evaluates both the user and device before granting SaaS access aligns with zero-trust principles and provides stronger protection against credential theft.<\/span><\/p>\n<p><b>Q103. Which architecture best protects a router&#8217;s administrative SSH interface from access by ordinary user subnets?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Restrict management access through an out-of-band or dedicated management network<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Permit SSH from every VLAN<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Enable Telnet as a backup from the Internet<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Use one shared local administrator password<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Restrict management access through an out-of-band or dedicated management network<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> A dedicated or out-of-band management network isolates administrative traffic from normal user and application traffic. Access to device management interfaces can then be limited to hardened administrative workstations, jump hosts, or approved management services. This reduces exposure to compromised user endpoints and supports stronger monitoring and access control. Allowing SSH from every VLAN unnecessarily expands attack surface, while Telnet exposes credentials and management traffic without encryption. Shared administrator passwords also weaken accountability. Management-plane isolation is therefore a fundamental infrastructure security design principle for routers, switches, and firewalls.<\/span><\/p>\n<p><b>Q104. An organization wants to securely connect a new branch to a public-cloud VPC across the Internet using standards-based encryption. Which solution is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Plain GRE<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Unencrypted public routing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Layer 2 trunk extension across the Internet<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> IPsec VPN to the cloud VPN gateway<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. IPsec VPN to the cloud VPN gateway<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Public cloud providers commonly support standards-based IPsec VPN gateways for encrypted connectivity from branch offices, data centers, or other cloud environments. IPsec provides confidentiality, integrity, peer authentication, and anti-replay protection over the untrusted Internet. GRE can provide tunneling but does not encrypt traffic by itself. Extending Layer 2 networks over the public Internet without appropriate protection would be risky and operationally complex. Unencrypted public routing also exposes application traffic. An IPsec tunnel to the cloud VPN gateway therefore provides a practical secure connectivity solution when dedicated private circuits are not required.<\/span><\/p>\n<p><b>Q105. A data center contains several application tiers that must communicate using only explicitly approved ports. Which security approach best enforces this requirement?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Place every server in one VLAN<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Rely only on Internet-edge filtering<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Apply east-west segmentation between application tiers<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable internal traffic monitoring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Apply east-west segmentation between application tiers<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> East-west segmentation controls traffic between internal workloads rather than focusing only on Internet-facing communication. Policies can permit only required connections, such as web servers reaching application servers on approved ports and application servers reaching databases on specific database ports. This reduces lateral movement if one workload is compromised. A single flat VLAN allows broad reachability, while a perimeter-only firewall might never see traffic between internal systems. Disabling monitoring reduces visibility further. Segmentation can be implemented with distributed firewalls, internal firewalls, microsegmentation, or workload-based policy depending on the environment.<\/span><\/p>\n<p><b>Q106. A company is deploying thousands of IoT devices that communicate only with two application servers and a DNS resolver. Which policy best reduces compromise impact?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allow the IoT devices to communicate only with the required services<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Permit unrestricted access to all corporate subnets<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Place the devices in the administrator network<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable device identification<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Allow the IoT devices to communicate only with the required services<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> IoT security should follow least privilege because many devices have limited built-in protection and may be difficult to patch. If a device only needs access to two application servers and DNS, network policy should restrict it to those exact services. This reduces the potential for compromised IoT devices to scan internal systems, move laterally, or communicate with unauthorized destinations. Broad access to corporate networks increases blast radius. Device identification and inventory should remain enabled so the organization understands what is connected. Segmentation and narrowly scoped communication policy are strong compensating controls for constrained IoT endpoints.<\/span><\/p>\n<p><b>Q107. Which technology is most appropriate for protecting a web application from cross-site scripting and SQL injection while preserving legitimate HTTP traffic?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DHCP snooping<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Web Application Firewall<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> GRE<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> MACsec only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Web Application Firewall<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> A Web Application Firewall inspects HTTP and HTTPS requests with awareness of application-layer behavior. It can detect and block attacks such as SQL injection, cross-site scripting, malicious request patterns, and other web-specific threats while allowing legitimate application traffic. DHCP snooping protects against unauthorized DHCP servers, GRE provides tunneling, and MACsec protects Ethernet frames on supported links. A WAF should not replace secure development, but it provides an additional protective layer in front of web applications and APIs, particularly when rapid virtual patching or centralized application-layer policy enforcement is required.<\/span><\/p>\n<p><b>Q108. A security architect wants to inspect encrypted HTTPS sessions for malware but must preserve user privacy for approved banking and healthcare categories. Which approach is best?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Decrypt every connection without exception<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable TLS inspection completely<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Replace HTTPS with HTTP<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Use policy-based TLS decryption with defined bypass categories<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Use policy-based TLS decryption with defined bypass categories<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Policy-based TLS decryption allows an organization to inspect encrypted traffic where security visibility is necessary while exempting traffic categories that should remain private for regulatory, legal, or organizational reasons. The architecture can use URL categorization, application identification, user context, and destination trust to decide which connections to decrypt. Decrypting everything may create privacy and compliance issues, while decrypting nothing creates large inspection blind spots. Replacing HTTPS with HTTP would severely weaken security. Selective decryption therefore provides a balanced approach when combined with strong controls around certificates, decryption infrastructure, and access to decrypted content.<\/span><\/p>\n<p><b>Q109. Which security design best protects a cloud-native microservice from receiving requests from unauthorized services inside the same cluster?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use service identity with mutual TLS and authorization policies<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Trust every workload because it is internal<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Use one shared credential across the cluster<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable east-west logging<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Use service identity with mutual TLS and authorization policies<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Cloud-native environments should authenticate workloads rather than assuming that network location provides trust. Mutual TLS can provide each service with a cryptographic identity and encrypt service-to-service traffic. Authorization policies can then determine exactly which identities may call a given microservice. This approach limits lateral movement and prevents unauthorized internal workloads from freely accessing sensitive services. Shared credentials make attribution and rotation difficult, while trusting every internal workload creates a broad attack surface. Service identity combined with mTLS and least-privilege authorization provides a scalable zero-trust model for microservices.<\/span><\/p>\n<p><b>Q110. An application uses a managed database and object-storage service in the public cloud. What is the best method to authenticate the application to those services?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Hard-code administrator passwords in source code<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Store root credentials in a container image<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Use cloud workload identity with short-lived credentials<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable authentication between cloud services<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Use cloud workload identity with short-lived credentials<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Cloud workload identities allow applications to authenticate to managed services without embedding long-lived static secrets. The cloud platform can issue temporary credentials based on the workload&#8217;s assigned identity and permissions. This reduces credential leakage risk and simplifies rotation because the application does not need to store reusable passwords or access keys. Permissions should be scoped to the specific database, bucket, or API operations required. Hard-coded secrets and root credentials increase compromise impact and often persist in repositories or images. Workload identity with short-lived credentials therefore supports both least privilege and secure credential lifecycle management.<\/span><\/p>\n<p><b>Q111. A security architect wants to verify that a container image was produced by the organization&#8217;s trusted CI\/CD pipeline and was not modified before deployment. Which control is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable image registries<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Use unsigned images from public repositories<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Store the image on a developer laptop<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Cryptographically sign the image and verify the signature before deployment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Cryptographically sign the image and verify the signature before deployment<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Cryptographic signing provides evidence of artifact provenance and integrity. The trusted CI\/CD pipeline signs the container image after building it, and the deployment platform verifies the signature before allowing the image to run. If the artifact is modified after signing or originates from an unauthorized source, verification fails. This helps reduce software supply-chain risk. Signature keys should be strongly protected, ideally using dedicated key-management infrastructure. Unsigned public images provide weak provenance, while local storage does not provide equivalent cryptographic assurance. Signing and admission-time verification therefore create a strong trusted-artifact control.<\/span><\/p>\n<p><b>Q112. Which risk-analysis method uses a numerical estimate of expected financial loss to help compare security investments?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Qualitative ranking only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Quantitative risk analysis<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> VLAN assignment<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Route summarization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Quantitative risk analysis<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Quantitative risk analysis estimates risk using numerical values, often expressed in financial terms. Concepts such as Single Loss Expectancy, Annual Rate of Occurrence, and Annualized Loss Expectancy can help decision-makers compare potential losses against the cost of security controls. The numbers are estimates and depend on the quality of available data, but they can provide a useful business-oriented basis for prioritization. Qualitative analysis instead uses categories such as low, medium, and high. VLAN assignment and route summarization are networking tasks rather than methods for estimating the financial impact of security risk.<\/span><\/p>\n<p><b>Q113. A business chooses to continue running an application despite a low-impact known vulnerability because remediation costs more than the expected loss. Which risk treatment is being used?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Avoidance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Transfer<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Acceptance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Elimination<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Acceptance<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Risk acceptance occurs when authorized management decides that the remaining risk is tolerable and chooses not to add further controls at the current time. The decision should be informed, documented, and periodically reviewed because business context, exploitability, or vulnerability severity may change. Acceptance does not mean ignoring the issue; it means the organization consciously retains the risk. Avoidance would remove the risky activity, while transfer shifts some consequences to another party. Mitigation would reduce probability or impact through additional controls. In this scenario, management has determined that the residual exposure is acceptable relative to remediation cost.<\/span><\/p>\n<p><b>Q114. A security team wants to understand how an attacker could progress from initial compromise to privilege escalation, lateral movement, and data theft. Which approach is most useful?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DHCP lease analysis only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Attack-path and threat modeling<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Increasing switch port speed<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disabling application logs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Attack-path and threat modeling<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Attack-path and threat modeling help architects understand how an attacker might chain multiple weaknesses and trust relationships to reach a high-value objective. Rather than examining each vulnerability independently, the team considers entry points, identities, privileges, network paths, applications, and security boundaries. This can reveal that several individually moderate weaknesses combine into a serious attack path. The resulting analysis can guide segmentation, identity controls, hardening, detection, and remediation priorities. DHCP lease information can contribute evidence but is not a complete threat-modeling method. Disabling logs would reduce visibility into attacker behavior.<\/span><\/p>\n<p><b>Q115. Which SOC metric measures the average time required to discover that a security incident has occurred?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Mean Time to Detect<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Recovery Point Objective<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Maximum Transmission Unit<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Annualized Loss Expectancy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Mean Time to Detect<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Mean Time to Detect, or MTTD, represents the average amount of time between the beginning of a security incident and its detection by the organization. Lower MTTD generally indicates that monitoring, telemetry, analytics, and SOC processes are identifying threats more quickly. A related metric, Mean Time to Respond or Remediate, measures how quickly the organization acts after detection. Recovery Point Objective concerns acceptable data loss in resilience planning, while Annualized Loss Expectancy is a risk-analysis concept. Tracking detection and response metrics helps security leaders identify operational weaknesses and measure SOC improvement over time.<\/span><\/p>\n<p><b>Q116. A security incident was caused by an overly permissive firewall rule that had been added during emergency maintenance and never removed. Which architectural improvement best prevents recurrence?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable firewall logging<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Give all engineers permanent unrestricted access<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Remove change documentation requirements<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Use time-bound policy changes with automated expiration and review<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Use time-bound policy changes with automated expiration and review<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Temporary security exceptions often become permanent because they are forgotten after an emergency ends. Time-bound policy changes can automatically expire at a defined date unless an authorized reviewer explicitly extends them. Combining this with change tickets, peer review, ownership, and configuration monitoring makes exceptions more visible and prevents long-term configuration drift. Disabling logging or documentation would make emergency changes harder to track, while unrestricted engineer access increases the chance of inappropriate policy changes. Automated expiration is therefore a strong design improvement when temporary firewall exceptions are operationally necessary.<\/span><\/p>\n<p><b>Q117. A DevSecOps team wants to prevent Terraform templates from creating publicly accessible object-storage buckets. Which mechanism best enforces this automatically?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Policy-as-code checks in the CI\/CD pipeline<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Ask developers to remember the rule manually<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable source control<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Permit every cloud resource by default<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Policy-as-code checks in the CI\/CD pipeline<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Policy as code expresses security requirements in machine-evaluable rules that can be automatically applied to Infrastructure as Code before deployment. A CI\/CD pipeline can reject Terraform plans that create public storage, unrestricted firewall rules, unencrypted databases, or other prohibited configurations. This provides consistent enforcement and immediate developer feedback. Manual reminders are easy to forget and do not scale reliably. Disabling source control would remove valuable auditability and review capabilities. Policy-as-code gates make security requirements repeatable, testable, and integrated into the same automated workflow used to provision infrastructure.<\/span><\/p>\n<p><b>Q118. An automation workflow needs permission to isolate endpoints but must not be able to delete users or modify firewalls. Which design principle should be applied to the automation account?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Give it global administrator access<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Grant only the endpoint-isolation permissions required by the workflow<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Use the CEO&#8217;s personal account<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable authentication for the workflow<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Grant only the endpoint-isolation permissions required by the workflow<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Automation accounts should follow least privilege just like human administrators. If a workflow only needs to isolate endpoints, its service identity should receive only the permissions required for that action and related read operations. This limits the impact if the workflow, API token, or orchestration platform is compromised. Global administrator access would unnecessarily expose identity, firewall, and other infrastructure capabilities. Personal accounts should not be used for machine automation, and unauthenticated automation removes accountability. Narrowly scoped service permissions improve security while still allowing the automated response to perform its intended task.<\/span><\/p>\n<p><b>Q119. Which AI governance practice is most important when a security model is retrained using incident data collected from multiple sources?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Track training-data provenance and validate data quality<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Accept every input as trustworthy<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable access controls on training storage<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Allow anonymous modification of datasets<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Track training-data provenance and validate data quality<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Training-data provenance records where data came from, how it was collected, and how it was modified. This is important for security AI because poor-quality or maliciously manipulated training data can produce inaccurate, biased, or intentionally weakened models. Validation processes should detect anomalous samples, labeling problems, and unauthorized changes. Access controls and integrity monitoring should protect training repositories. Treating all inputs as trustworthy increases model-poisoning risk. Provenance, quality validation, and controlled data pipelines therefore improve confidence that retrained models reflect legitimate security telemetry rather than attacker-influenced data.<\/span><\/p>\n<p><b>Q120. A company plans to adopt post-quantum cryptography over several years. Which architectural characteristic will make the transition easier?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Hard-code one algorithm into every application permanently<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Never inventory certificates or cryptographic libraries<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Use the same long-lived key indefinitely<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Crypto-agility that allows algorithms and keys to be replaced with minimal redesign<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Crypto-agility that allows algorithms and keys to be replaced with minimal redesign<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Crypto-agility is the ability to replace cryptographic algorithms, protocols, certificates, and keys without requiring a complete redesign of dependent applications and infrastructure. This is particularly important for post-quantum migration because organizations will need to identify existing cryptography, test new algorithms, support transitional configurations, and replace legacy mechanisms over time. Hard-coded cryptographic choices make migration expensive and risky. Long-lived keys also increase exposure. A crypto-agile architecture separates cryptographic implementation from business logic where practical and supports controlled algorithm updates as standards, products, and interoperability requirements evolve.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco CCNP Security 300-745 Exam Dumps and Practice Test Dumps. Q101. An organization wants to protect users from phishing websites even when employees work from home and are not connected to the corporate VPN. Which architecture is most appropriate? Internal-only Layer 2 ACLs 2. A firewall deployed only in the headquarters data center [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17691"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=17691"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17691\/revisions"}],"predecessor-version":[{"id":17692,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17691\/revisions\/17692"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=17691"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=17691"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=17691"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}