{"id":17695,"date":"2026-09-21T11:00:33","date_gmt":"2026-09-21T11:00:33","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=17695"},"modified":"2026-09-21T11:00:33","modified_gmt":"2026-09-21T11:00:33","slug":"cisco-ccnp-security-300-745-practice-test-questions-and-exam-dumps-part8-q141-160","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-ccnp-security-300-745-practice-test-questions-and-exam-dumps-part8-q141-160\/","title":{"rendered":"Cisco CCNP Security 300-745 Practice Test Questions and Exam Dumps Part8 Q141-160"},"content":{"rendered":"<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/300-745-exam-dumps\"><b>Cisco CCNP Security 300-745 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/p>\n<p><b><br \/>\n<\/b><b>Q141. A company wants to protect IPv6 access networks from hosts advertising themselves as unauthorized routers. Which control is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DHCP snooping<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> IPv6 Router Advertisement Guard<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> GRE authentication<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> BGP route reflectors<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. IPv6 Router Advertisement Guard<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> IPv6 Router Advertisement Guard, commonly called RA Guard, helps prevent unauthorized devices on access networks from sending malicious IPv6 router advertisements. An attacker could otherwise advertise itself as a default router and redirect user traffic through a malicious system. RA Guard allows switches to distinguish trusted router-facing interfaces from ordinary endpoint ports and block inappropriate advertisements. DHCP snooping addresses rogue DHCP activity rather than IPv6 router advertisements. GRE and BGP route reflection solve unrelated tunneling and routing problems. RA Guard is therefore an important Layer 2 security control when designing protected IPv6 access networks.<\/span><\/p>\n<p><b>Q142. A security architect needs a VPN solution for mobile employees whose public IP addresses frequently change as they move between networks. Which design is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A permanent static GRE tunnel from each laptop<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> MPLS Layer 3 VPN directly to each laptop<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> MACsec between the laptop and corporate switch<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Remote-access VPN using authenticated client sessions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Remote-access VPN using authenticated client sessions<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Remote-access VPNs are designed for individual users who connect from variable locations and networks. The client authenticates the user and often the device before establishing an encrypted tunnel to the organization&#8217;s VPN gateway. Because the user&#8217;s Internet address can change, the architecture does not require a permanent static peer configuration for every endpoint. Static GRE is unsuitable for roaming clients and does not provide encryption by itself. MPLS is generally a provider WAN service rather than an endpoint remote-access solution. MACsec protects specific Ethernet links and does not provide Internet-based mobile VPN access.<\/span><\/p>\n<p><b>Q143. Which security feature best prevents an attacker from successfully using a manually configured IP address to impersonate another host on a switched access network when DHCP snooping data is available?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> IP Source Guard<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> DNSSEC<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> GRE<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> NAT overload<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. IP Source Guard<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> IP Source Guard can use information learned through DHCP snooping to restrict which source IP addresses are permitted on a switch access port. If an endpoint attempts to transmit traffic using an unauthorized source address, the switch can block the traffic. This reduces the effectiveness of simple IP spoofing within the access network. DHCP snooping builds trusted IP-to-MAC-to-port bindings, while IP Source Guard uses that information for enforcement. DNSSEC protects DNS integrity, GRE provides tunneling, and NAT overload translates addresses. IP Source Guard is therefore directly suited to controlling source-address spoofing on access ports.<\/span><\/p>\n<p><b>Q144. An organization wants to protect against an attacker sending forged ARP messages to intercept local subnet traffic. Which switch feature should be used with DHCP snooping?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> PortFast<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Route summarization<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Dynamic ARP Inspection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> GRE keepalives<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Dynamic ARP Inspection<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Dynamic ARP Inspection, or DAI, validates ARP messages against trusted bindings, commonly those created by DHCP snooping. It can block forged ARP replies that attempt to associate an attacker&#8217;s MAC address with another host&#8217;s IP address. This helps defend against ARP poisoning and local man-in-the-middle attacks. Trusted interfaces can be defined for legitimate infrastructure devices where necessary. PortFast affects spanning-tree behavior, route summarization affects routing tables, and GRE keepalives monitor tunnels. DAI specifically addresses malicious or invalid ARP information and is an important Layer 2 access-network protection.<\/span><\/p>\n<p><b>Q145. A company operates critical industrial controllers that cannot be patched without shutting down production. Which architecture most effectively reduces their exposure?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Isolate the controllers in restricted network zones with tightly controlled communications<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Give every corporate endpoint direct access to the controllers<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Expose management interfaces directly to the Internet<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable monitoring around the controllers<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Isolate the controllers in restricted network zones with tightly controlled communications<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Legacy or operational-technology systems that cannot be patched require strong compensating controls. Network segmentation can restrict communication to only the systems, protocols, and management stations required for production. Firewalls, industrial security monitoring, jump hosts, application allowlisting, and strict administrative access can further reduce exposure. The goal is to reduce the likelihood that an attacker can reach or exploit the unpatched controller while maintaining required operations. Broad corporate or Internet access dramatically increases risk. Disabling monitoring also removes visibility. Isolation and explicit allow policies are therefore central design controls for difficult-to-patch industrial assets.<\/span><\/p>\n<p><b>Q146. A security architect wants SaaS administrators to receive elevated privileges only after approval and only for a limited period. Which architecture best meets this requirement?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Permanent global administrator assignments<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Shared privileged accounts<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Password-only authentication<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Privileged access management with just-in-time elevation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Privileged access management with just-in-time elevation<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Just-in-time privileged access grants elevated permissions only when they are needed and can automatically remove those permissions after a defined period. A privileged access management workflow may require approval, stronger authentication, ticket references, session recording, or justification before elevation. This reduces standing privilege and therefore limits the value of a compromised normal user account. Permanent global administrator rights create unnecessary exposure, while shared accounts reduce accountability. Password-only access is also insufficient for high-impact privileges. Temporary, approved elevation provides a stronger balance between operational needs and least-privilege security.<\/span><\/p>\n<p><b>Q147. An application team wants to protect sensitive data stored in a database so that stolen storage media does not expose readable records. Which control directly addresses this requirement?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Network address translation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> GRE encapsulation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Encryption at rest<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> DHCP snooping<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Encryption at rest<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Encryption at rest protects stored information by ensuring that database files, disks, backups, or storage objects cannot be read without the appropriate cryptographic keys. If an attacker steals media or obtains unauthorized access to raw storage, encrypted data remains protected as long as the keys are secured separately and managed correctly. Encryption at rest should complement application authorization, database access controls, backup security, and encryption in transit. NAT, GRE, and DHCP snooping provide networking functions and do not protect stored database contents. Key management is a critical part of the overall encryption-at-rest architecture.<\/span><\/p>\n<p><b>Q148. A microservices application uses a message broker. The architect wants to prevent one compromised service from reading messages intended for unrelated services. Which control is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Give every service access to every queue<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Apply per-service identities and least-privilege queue authorization<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable broker authentication<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Share one administrative broker credential among all services<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Apply per-service identities and least-privilege queue authorization<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Each microservice should authenticate using its own workload identity and receive access only to the queues, topics, or message operations required by its role. If one service is compromised, least-privilege authorization limits which messages the attacker can read, publish, or modify. Shared administrative credentials create a large blast radius and make activity difficult to attribute. Disabling authentication would permit unauthorized access entirely. Message brokers are critical trust boundaries in event-driven architectures, so workload identity, encrypted transport, access policy, and audit logging should be designed as carefully as API authorization.<\/span><\/p>\n<p><b>Q149. A web application must prevent users from modifying object identifiers in API requests to access another customer&#8217;s records. Which security control is most important?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Server-side object-level authorization checks<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Client-side JavaScript validation only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Hiding object IDs in the user interface<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Increasing DNS TTL values<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Server-side object-level authorization checks<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Applications must enforce authorization on the server for every requested object. An attacker can modify API requests regardless of what the user interface displays, so hiding identifiers or validating requests only with client-side JavaScript does not provide a reliable security boundary. The server should verify that the authenticated identity is authorized to read, modify, or delete the specific requested record. This protects against broken object-level authorization and insecure direct-object-reference scenarios. DNS behavior is unrelated. Strong server-side authorization should be combined with secure session handling, logging, and careful API design.<\/span><\/p>\n<p><b>Q150. Which technique is most appropriate for protecting passwords stored in an application&#8217;s authentication database?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Reversible plaintext encryption with a shared key in source code<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Plaintext storage<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> A slow, salted password-hashing algorithm<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Base64 encoding<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. A slow, salted password-hashing algorithm<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Password databases should store password verifiers produced by purpose-built, slow password-hashing algorithms with unique salts. Examples include modern adaptive password hashing functions designed to make offline guessing expensive. The salt prevents identical passwords from producing identical stored values and defeats precomputed rainbow tables. Passwords usually do not need to be decrypted, so reversible encryption is generally inappropriate for ordinary authentication storage. Base64 is merely encoding and provides no cryptographic protection. If attackers obtain the password database, strong salted hashes increase the computational cost of recovering users&#8217; original passwords.<\/span><\/p>\n<p><b>Q151. A SOC wants network telemetry that summarizes conversations using source and destination addresses, ports, protocols, byte counts, and timing without storing every packet. Which data source best fits this requirement?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Full packet capture only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Endpoint screenshots<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Source-code repositories<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Network flow records<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Network flow records<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Network flow telemetry summarizes communication between systems without requiring the storage volume of full packet capture. Flow records can include source and destination addresses, ports, protocol, bytes, packets, timestamps, and interface information. This makes them useful for identifying unusual connections, lateral movement, data-transfer patterns, and network baselines across large environments. Full packet capture provides deeper content visibility but requires substantially more storage and privacy considerations. Endpoint screenshots and source-code repositories do not provide equivalent network-communication metadata. Flow telemetry is therefore an efficient data source for network-oriented SOC analytics.<\/span><\/p>\n<p><b>Q152. An analyst needs the complete payload of a suspicious TCP session to determine whether malware was transferred. Which telemetry provides the greatest detail?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DHCP lease logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> DNS cache entries only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Full packet capture<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> A routing table<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Full packet capture<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Full packet capture records actual network packets, including payload data when it is visible and not protected by encryption. This gives analysts the greatest network-level detail for reconstructing sessions, inspecting transferred files, analyzing protocol behavior, and validating detections. It requires considerably more storage than flow telemetry and can contain sensitive information, so retention and access policies are important. DHCP and DNS data provide valuable context but not complete session payloads. Routing tables describe forwarding decisions rather than user traffic. Packet capture is therefore most appropriate when deep forensic examination of network content is required.<\/span><\/p>\n<p><b>Q153. During incident response, malware persistence has been removed and compromised credentials have been reset. Which response phase has primarily been performed?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Eradication<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Identification<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Preparation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Risk transfer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Eradication<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Eradication focuses on removing the threat and its persistence mechanisms from the environment. Activities may include deleting malware, removing unauthorized accounts, eliminating scheduled tasks or persistence mechanisms, patching exploited vulnerabilities, and resetting compromised credentials. Containment generally comes earlier and limits the attacker&#8217;s ability to cause additional damage. Recovery follows eradication and returns systems to normal operation while monitoring for recurrence. Identification determines what happened, while preparation happens before incidents occur. Removing the attacker&#8217;s foothold and correcting the root technical mechanisms are key eradication activities.<\/span><\/p>\n<p><b>Q154. Which threat-modeling approach uses diagrams of system components, data stores, external entities, trust boundaries, and information movement to identify security threats?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DHCP scope analysis<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Data-flow diagram based threat modeling<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Ethernet speed testing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> DNS round robin<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Data-flow diagram based threat modeling<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Data-flow diagrams help architects visualize how information moves through a system, where it is stored, which processes handle it, which external entities interact with it, and where trust boundaries exist. Threat-modeling techniques such as STRIDE can then be applied to the diagram&#8217;s elements to identify possible spoofing, tampering, information disclosure, denial of service, and privilege-escalation threats. This process is particularly useful during application and architecture design because security weaknesses can be addressed before implementation. DHCP, Ethernet testing, and DNS balancing do not provide a structured representation of application trust and data movement.<\/span><\/p>\n<p><b>Q155. A business decides that a critical system must remain operational even if any single application server fails. Which architectural principle best meets this requirement?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> High availability through redundancy<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> One large standalone server<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable health monitoring<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Store all backups on the same server<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. High availability through redundancy<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Redundancy removes single points of failure by providing multiple application instances, load balancers, clustered services, or other failover capabilities. Health monitoring detects failed instances and directs traffic toward healthy resources. The exact design depends on the application&#8217;s state, storage model, session behavior, and RTO requirements. One large server remains a single point of failure regardless of its capacity. Disabling monitoring makes failure detection slower, while placing backups on the failed system provides little resilience. High availability uses redundant components and automated failover to maintain service when individual infrastructure elements fail.<\/span><\/p>\n<p><b>Q156. A security architect wants to define a standard, reusable solution for providing secure administrator access through hardened jump hosts. What architectural artifact is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Incident ticket<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Packet capture<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Security design pattern<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> DHCP reservation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Security design pattern<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> A security design pattern documents a reusable architectural solution to a recurring security problem. A privileged-access pattern could describe hardened jump hosts, administrative network isolation, MFA, session recording, access approval, logging, and permitted management protocols. Teams can reuse the pattern across projects instead of redesigning the same control each time. Patterns also improve architectural consistency and make reviews easier because approved security principles are captured in a repeatable model. Incident tickets and packet captures document operational events, while DHCP reservations provide network configuration. They are not reusable architectural solutions.<\/span><\/p>\n<p><b>Q157. A CI\/CD pipeline needs to test an application for SQL injection and authentication weaknesses after deploying it into a temporary test environment. Which control should be integrated?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Dynamic Application Security Testing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Route summarization<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> DHCP snooping<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> MACsec<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Dynamic Application Security Testing<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> DAST evaluates a running application from an external perspective, making it appropriate after the application is deployed to a temporary test environment. The scanner can send malicious or unexpected requests to identify issues such as injection flaws, insecure authentication behavior, and server configuration weaknesses. This complements SAST, which analyzes code without executing the application, and SCA, which focuses on third-party dependencies. Integrating DAST into the pipeline provides repeatable pre-production security testing. Routing, DHCP snooping, and MACsec address infrastructure security rather than application vulnerability testing.<\/span><\/p>\n<p><b>Q158. Which API authentication design is preferred for an automated security service that calls another internal service without a human user?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Reuse an employee&#8217;s personal password<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable API authentication<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Use a dedicated machine identity with scoped credentials<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Share the root API key with all automation systems<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Use a dedicated machine identity with scoped credentials<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Machine-to-machine integrations should use dedicated workload or service identities rather than personal user credentials. Permissions should be scoped to the exact API operations and resources the automation requires. Where possible, short-lived tokens, certificate-based authentication, or workload identity federation should replace long-lived static secrets. This improves attribution, rotation, and incident response. Disabling authentication allows unauthorized access, while one shared root key creates excessive privilege and makes it difficult to identify which service performed an action. Dedicated machine identities therefore provide a stronger foundation for secure automation workflows.<\/span><\/p>\n<p><b>Q159. An AI-based security tool provides a confidence score for whether an event is malicious. What should the architecture do with low-confidence predictions involving high-impact containment actions?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Automatically shut down the entire environment<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Ignore all predictions permanently<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Delete the underlying telemetry<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Route the decision for additional validation or human review<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Route the decision for additional validation or human review<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> High-impact actions such as disabling critical accounts, isolating production servers, or blocking major network ranges should not rely blindly on uncertain AI predictions. When confidence is low, the architecture should introduce additional deterministic checks, correlated evidence, or human review before containment occurs. This balances automation speed against the risk of damaging false positives. Telemetry should be retained for investigation, and predictions should not simply be ignored. Confidence-aware response policies are part of responsible AI security design and help ensure that machine-learning recommendations are proportional to both certainty and operational impact.<\/span><\/p>\n<p><b>Q160. Which emerging cryptographic approach is specifically intended to remain secure against attacks from sufficiently capable quantum computers?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Post-quantum cryptography<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Base64 encoding<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Plaintext authentication<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> CRC checksums<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Post-quantum cryptography<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Post-quantum cryptography refers to cryptographic algorithms designed to resist attacks from both classical and sufficiently capable quantum computers. Organizations should track standardization, build cryptographic inventories, and improve crypto-agility so vulnerable public-key algorithms can be replaced as required. Migration will take time because certificates, protocols, applications, hardware, vendors, and interoperability all depend on cryptographic choices. Base64 provides encoding rather than security, plaintext authentication exposes credentials, and ordinary checksums do not provide quantum-resistant confidentiality or authentication. PQC is therefore a major architectural consideration for long-lived security systems and sensitive data.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco CCNP Security 300-745 Exam Dumps and Practice Test Dumps. Q141. A company wants to protect IPv6 access networks from hosts advertising themselves as unauthorized routers. Which control is most appropriate? DHCP snooping 2. IPv6 Router Advertisement Guard 3. GRE authentication 4. BGP route reflectors Correct Answer: 2. IPv6 Router Advertisement Guard Explanation: [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17695"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=17695"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17695\/revisions"}],"predecessor-version":[{"id":17696,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17695\/revisions\/17696"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=17695"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=17695"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=17695"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}