{"id":17705,"date":"2026-09-21T11:03:01","date_gmt":"2026-09-21T11:03:01","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=17705"},"modified":"2026-09-21T11:03:01","modified_gmt":"2026-09-21T11:03:01","slug":"cisco-ccnp-security-300-745-practice-test-questions-and-exam-dumps-part13-q241-260","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-ccnp-security-300-745-practice-test-questions-and-exam-dumps-part13-q241-260\/","title":{"rendered":"Cisco CCNP Security 300-745 Practice Test Questions and Exam Dumps Part13 Q241-260"},"content":{"rendered":"<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/300-745-exam-dumps\"><b>Cisco CCNP Security 300-745 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/p>\n<p><b><br \/>\n<\/b><b>Q241. An organization wants remote administrators to access management interfaces without exposing those interfaces directly to the Internet. Which architecture best meets the requirement?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Publish every management interface with a public IP address<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Require administrators to connect through a hardened bastion or jump host<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Permit Telnet from any remote network<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable administrative authentication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Require administrators to connect through a hardened bastion or jump host<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> A hardened bastion or jump host provides a controlled entry point for privileged administrative access. Instead of exposing routers, firewalls, servers, and other management interfaces directly to the Internet, administrators authenticate to the protected jump system and then reach authorized infrastructure from a restricted management network. The design can enforce MFA, session recording, command logging, endpoint posture, and source restrictions. Directly publishing management interfaces greatly increases attack surface. Telnet lacks suitable encryption, while disabling authentication would be unacceptable. A secured jump-host architecture therefore centralizes privileged access and supports stronger monitoring and least privilege.<\/span><\/p>\n<p><b>Q242. A security architect must protect stored encryption keys while allowing applications to request cryptographic operations through an API. Which architecture provides the strongest key protection?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Store keys in plaintext files beside the application<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Commit keys to the source repository<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Share one key through email<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Use an HSM-backed key management service<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Use an HSM-backed key management service<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> An HSM-backed key management service protects sensitive cryptographic keys inside a hardened hardware boundary and can expose controlled cryptographic operations through authenticated APIs. Applications can encrypt, decrypt, or sign without necessarily receiving the raw private key material. This reduces the chance that keys are exposed through source repositories, application files, debug logs, or compromised hosts. Access policies, audit logs, rotation procedures, and separation of duties further strengthen the design. Plaintext storage, email distribution, and source-code repositories provide far weaker key protection and make rotation and incident response substantially more difficult.<\/span><\/p>\n<p><b>Q243. An enterprise wants switches to permit only approved source MAC addresses on user-facing access ports and shut down or restrict the port after violations. Which feature should be configured?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Port security<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> GRE tunneling<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> BGP communities<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> DNSSEC<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Port security<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Switch port security can restrict the number or identity of MAC addresses permitted on an access port. Depending on configuration, the switch can learn approved addresses dynamically or use statically configured values and can restrict, protect, or shut down a port when violations occur. This helps reduce unauthorized device attachment and some forms of Layer 2 abuse. It should be combined with stronger technologies such as 802.1X where identity assurance is required. GRE, BGP communities, and DNSSEC provide tunneling, routing-policy metadata, and DNS integrity rather than endpoint admission controls on switch access ports.<\/span><\/p>\n<p><b>Q244. A company needs a firewall architecture that identifies traffic by application even when the application uses nonstandard TCP ports. Which capability is required?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Traditional port-only ACLs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Static routing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Application-aware next-generation firewall inspection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> DHCP relay<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Application-aware next-generation firewall inspection<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Application-aware next-generation firewalls inspect traffic beyond basic IP addresses and TCP or UDP ports. They can use protocol behavior, signatures, TLS metadata, and other context to identify applications even when those applications use nonstandard or dynamic ports. This allows policy to be based on the actual application rather than simply permitting all traffic on a port. Traditional ACLs remain useful but cannot reliably distinguish different applications sharing the same transport port. Static routing and DHCP relay provide network connectivity services and do not identify application-layer behavior. Application-aware inspection therefore supports more precise firewall policy.<\/span><\/p>\n<p><b>Q245. A cloud application must call an external payment API, but the security team wants to ensure the application cannot make arbitrary outbound connections to other Internet destinations. Which design is best?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Permit unrestricted outbound Internet access<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable application logging<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Give the application a public administrator account<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Enforce egress filtering that allows only approved destinations and services<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Enforce egress filtering that allows only approved destinations and services<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Egress filtering restricts which external systems and services a workload is permitted to contact. If the application only requires access to a specific payment API, policy can allow that destination while denying unnecessary outbound communication. This reduces opportunities for malware command and control, data exfiltration, and server-side request forgery to arbitrary Internet targets. DNS controls, proxy enforcement, workload identity, and TLS validation can further strengthen the design. Unrestricted outbound access increases the blast radius of application compromise, while disabling logs or adding administrator privileges provides no security benefit.<\/span><\/p>\n<p><b>Q246. A security architect wants to prevent a web browser from sending an authentication cookie over an unencrypted HTTP connection. Which cookie attribute is most relevant?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Domain<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Secure<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Path<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Expires<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Secure<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> The Secure cookie attribute instructs supported browsers to transmit the cookie only over HTTPS rather than ordinary unencrypted HTTP. This helps protect authentication or session cookies from exposure over insecure network connections. Other attributes can provide complementary protections. HttpOnly can reduce access from client-side scripts, and SameSite can help limit certain cross-site request scenarios. The Domain and Path attributes define where the browser sends a cookie, while expiration controls lifetime. Sensitive authentication cookies should generally be protected with appropriate Secure, HttpOnly, SameSite, lifetime, and server-side session-management settings.<\/span><\/p>\n<p><b>Q247. An application needs to reduce the risk that browsers downgrade from HTTPS to HTTP after users have securely visited the site. Which response header is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Access-Control-Allow-Origin<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Content-Disposition<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Strict-Transport-Security<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Server<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Strict-Transport-Security<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> HTTP Strict Transport Security, or HSTS, tells compatible browsers to use HTTPS for a site for a specified period and prevents normal downgrade to insecure HTTP. This can reduce exposure to certain SSL-stripping and protocol-downgrade attacks after the browser has learned the policy. HSTS should be deployed carefully because configuration mistakes can make a site inaccessible until the policy expires. <\/span><span style=\"font-weight: 400;\">Access-Control-Allow-Origin<\/span><span style=\"font-weight: 400;\"> is associated with CORS, while <\/span><span style=\"font-weight: 400;\">Content-Disposition<\/span><span style=\"font-weight: 400;\"> affects content handling. A complete HTTPS design also requires trusted certificates, strong TLS settings, proper redirects, and secure cookie configuration.<\/span><\/p>\n<p><b>Q248. A development team wants to reduce the impact of a compromised software dependency by ensuring the application runs without unnecessary operating-system privileges. Which principle is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Least privilege<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Shared root access<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Anonymous administration<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable process isolation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Least privilege<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Least privilege ensures that applications and services receive only the operating-system, filesystem, network, and cloud permissions necessary for their intended functions. If a software dependency is compromised, an attacker inherits only those limited privileges rather than unrestricted system control. Applications should avoid running as root or administrator unless absolutely necessary. Container capabilities, filesystem permissions, service accounts, and workload identities should all be constrained. Shared root access and disabled isolation increase the potential impact of compromise. Least privilege is therefore a foundational control for containing vulnerabilities within application and cloud-native environments.<\/span><\/p>\n<p><b>Q249. A SOC receives evidence that an attacker has obtained legitimate credentials but is logging in from unusual locations and devices. Which capability best helps detect this behavior?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Static routing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Identity analytics and anomalous-login detection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> DHCP relay<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> GRE keepalives<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Identity analytics and anomalous-login detection<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Identity analytics can compare authentication events against normal user behavior and detect signals such as new devices, impossible travel, unusual locations, abnormal login times, atypical applications, or rapid changes in privilege use. This is particularly valuable when an attacker uses valid credentials because traditional authentication alone may not distinguish the attacker from the legitimate user. Risk-based policies can trigger additional MFA, block access, or generate SOC alerts. Static routing, DHCP relay, and GRE keepalives provide networking functions rather than behavioral identity detection. Identity telemetry is essential in modern credential-theft defense.<\/span><\/p>\n<p><b>Q250. A company wants an automated incident workflow to disable a compromised account, but only after two independent high-confidence detections agree. Which design principle is being used?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Single-source automation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Permanent administrator access<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Corroboration before high-impact response<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Anonymous API access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Corroboration before high-impact response<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Requiring multiple independent signals before executing a disruptive action reduces the chance that a false positive causes unnecessary business impact. For example, an endpoint alert and a high-confidence identity-risk event might both be required before automatically disabling an account. The workflow should define the evidence threshold, logging, rollback procedure, and human escalation path. This approach is especially useful when actions such as account disablement, host isolation, or firewall blocking can interrupt critical operations. Unrestricted automation based on one weak signal can amplify detection errors. Corroboration therefore improves response reliability.<\/span><\/p>\n<p><b>Q251. A security team wants to share indicators of compromise with external partners while automating distribution through a standard transport protocol. Which combination is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> STIX data transported with TAXII<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> FTP files with no schema<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> BGP communities over Telnet<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> ARP tables sent by email<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. STIX data transported with TAXII<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> STIX provides a structured data model for threat intelligence, including indicators, malware, campaigns, threat actors, and relationships. TAXII provides network services for exchanging that structured intelligence between organizations and security platforms. Together, they allow automated and interoperable sharing of cyber threat information. This is more scalable and machine-readable than ad hoc text files or email-based indicator sharing. FTP alone does not provide a standardized threat-intelligence schema. BGP and ARP information serve network infrastructure purposes and are not standards for exchanging contextual cyber threat intelligence.<\/span><\/p>\n<p><b>Q252. A security team confirms that an attacker exploited an Internet-facing server through an unpatched vulnerability. Which architectural change most directly reduces recurrence?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable vulnerability scanning<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Implement timely patching plus compensating controls for systems that cannot be patched immediately<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Remove all server logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Give the server broader network access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Implement timely patching plus compensating controls for systems that cannot be patched immediately<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> The root cause is an exploitable vulnerability that remained exposed. A stronger architecture includes formal vulnerability and patch management with risk-based remediation timelines. When a patch cannot be installed immediately, compensating controls such as segmentation, IPS signatures, WAF rules, virtual patching, restricted access, or increased monitoring can reduce exposure temporarily. Disabling scanning removes visibility, while broader network access increases attack surface. Incident-driven design improvements should address both the specific vulnerable system and the process that allowed a known weakness to remain exploitable.<\/span><\/p>\n<p><b>Q253. An organization maintains a formal list of identified risks, owners, likelihood, impact, treatment decisions, and current status. What is this document called?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Routing table<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Packet capture<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Risk register<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> VLAN database<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Risk register<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> A risk register provides a structured record of identified organizational risks and their management status. Entries commonly include a description, affected assets, likelihood, impact, risk rating, owner, chosen treatment, mitigation activities, due dates, and residual risk. The register helps ensure that risks are tracked rather than discussed once and forgotten. Security architects can use it to connect technical findings with accountable business decisions. Routing tables, packet captures, and VLAN databases document technical network state rather than enterprise risk ownership and treatment. A current risk register supports governance, prioritization, and executive reporting.<\/span><\/p>\n<p><b>Q254. A vulnerability would cost approximately $50,000 each time it causes a successful incident and is expected to occur once every five years. What is the approximate Annualized Loss Expectancy?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> $50,000<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> $10,000<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> $250,000<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> $5,000<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. $10,000<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Annualized Loss Expectancy can be estimated by multiplying Single Loss Expectancy by the Annual Rate of Occurrence. Here, the expected loss per successful event is $50,000. One event every five years corresponds to an annual rate of 0.2. Multiplying $50,000 by 0.2 produces an ALE of approximately $10,000 per year. Quantitative estimates are rarely exact, but they can help compare expected risk against the annual cost of safeguards. Security teams should clearly document assumptions and ranges rather than presenting uncertain estimates as precise predictions.<\/span><\/p>\n<p><b>Q255. Which security-design approach requires systems to remain secure even if a single protective mechanism fails?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Implicit trust<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Single-point enforcement<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Defense in depth<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Security through obscurity only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Defense in depth<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Defense in depth uses multiple complementary security layers so that failure or bypass of one control does not automatically expose the protected asset. For example, an Internet application might use DDoS protection, firewalling, WAF inspection, secure authentication, application authorization, endpoint protection, segmentation, and monitoring. No single control is expected to provide perfect protection. Implicit trust and single-point enforcement create larger failure domains. Obscurity may marginally slow attackers but should never be the primary security mechanism. Defense in depth increases resilience by requiring attackers to overcome multiple independent safeguards.<\/span><\/p>\n<p><b>Q256. An organization wants security design decisions to be derived from business objectives, assets, risk, and required security services rather than starting with specific products. Which architecture philosophy best matches this goal?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Product-first architecture<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Flat network design<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Uncontrolled technology adoption<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Business-driven security architecture<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Business-driven security architecture<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Business-driven security architecture begins by understanding organizational objectives, important assets, stakeholders, risk, legal obligations, and required security properties. Controls and products are then selected to satisfy those requirements. This prevents architectures from becoming collections of disconnected technologies that do not address actual business risk. Frameworks such as SABSA emphasize this type of alignment. Product-first design can lead teams to deploy tools simply because they are available rather than because they solve a defined problem. Security architecture should therefore trace technical decisions back to measurable business and risk requirements.<\/span><\/p>\n<p><b>Q257. A DevSecOps team wants to prevent unreviewed code from being merged into the production branch. Which source-control control is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Protected branches with mandatory pull-request review<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Allow force-pushes from every developer<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable source-control authentication<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Share one repository administrator account<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Protected branches with mandatory pull-request review<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Protected branches can prevent direct or unauthorized updates to critical branches and require pull requests, peer review, automated tests, and security checks before code is merged. This creates a repeatable control point in the development workflow and provides an auditable record of who proposed and approved changes. Force-pushing or using shared administrator credentials weakens traceability and can bypass review. Authentication should remain enabled. Branch protection is especially valuable when production deployments are automatically triggered from the main branch because source-control integrity then becomes part of the production security boundary.<\/span><\/p>\n<p><b>Q258. An infrastructure automation workflow must make changes to hundreds of devices. Which practice best reduces the risk that one incorrect template causes a widespread outage?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Deploy immediately to every device<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable pre-deployment testing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Test in stages and use canary or phased rollout techniques<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Remove rollback capability<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Test in stages and use canary or phased rollout techniques<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Canary and phased deployments limit blast radius by applying a change to a small, representative subset of systems before wider rollout. Monitoring can verify expected behavior before the automation continues. If problems appear, the workflow can stop and roll back rather than affecting the entire infrastructure. This approach is particularly important for large-scale security policy or network configuration automation where a small template mistake can cause major outages. Full immediate rollout removes an important validation opportunity. Pre-deployment testing, change windows, backups, dry runs, and automated rollback further improve automation safety.<\/span><\/p>\n<p><b>Q259. An AI-based security assistant exposes too much confidential information when users ask carefully crafted questions about the training data. Which AI risk is most closely associated with this behavior?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> BGP hijacking<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> ARP poisoning<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Model inversion or training-data leakage<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> DHCP starvation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Model inversion or training-data leakage<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Model inversion and related privacy attacks attempt to recover or infer sensitive information represented in a model&#8217;s training data. If an AI system reveals confidential records, secrets, or other memorized data in response to crafted prompts, the organization faces a significant privacy and data-governance risk. Controls can include data minimization, redaction, privacy-preserving training, access restrictions, output filtering, and rigorous model testing. BGP, ARP, and DHCP attacks affect network infrastructure rather than AI training-data confidentiality. Sensitive organizational data should be carefully evaluated before inclusion in model training or fine-tuning datasets.<\/span><\/p>\n<p><b>Q260. An AI security assistant is integrated with a ticketing system containing untrusted user text. How should the architecture prevent ticket content from overriding the assistant&#8217;s privileged operational instructions?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Treat ticket text as privileged system instructions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Isolate untrusted content from system instructions and constrain tool permissions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Give the model unrestricted shell access<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable all authorization on connected tools<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Isolate untrusted content from system instructions and constrain tool permissions<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> User-submitted ticket content is untrusted data and might include prompt-injection instructions intended to manipulate the AI system. The architecture should clearly separate privileged system instructions from retrieved or user-provided text and prevent untrusted content from automatically becoming executable commands. Connected tools should use least-privilege identities and deterministic authorization controls so the model cannot perform prohibited actions even if manipulated. High-impact actions can also require human approval. Giving the assistant unrestricted tool access would turn a prompt-injection weakness into a potentially severe infrastructure compromise.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco CCNP Security 300-745 Exam Dumps and Practice Test Dumps. Q241. An organization wants remote administrators to access management interfaces without exposing those interfaces directly to the Internet. Which architecture best meets the requirement? Publish every management interface with a public IP address 2. Require administrators to connect through a hardened bastion or [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17705"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=17705"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17705\/revisions"}],"predecessor-version":[{"id":17706,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17705\/revisions\/17706"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=17705"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=17705"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=17705"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}