{"id":17713,"date":"2026-09-21T11:04:20","date_gmt":"2026-09-21T11:04:20","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=17713"},"modified":"2026-09-21T11:04:20","modified_gmt":"2026-09-21T11:04:20","slug":"cisco-ccnp-security-300-745-practice-test-questions-and-exam-dumps-part17-q321-340","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-ccnp-security-300-745-practice-test-questions-and-exam-dumps-part17-q321-340\/","title":{"rendered":"Cisco CCNP Security 300-745 Practice Test Questions and Exam Dumps Part17 Q321-340"},"content":{"rendered":"<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/300-745-exam-dumps\"><b>Cisco CCNP Security 300-745 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/p>\n<p><b><br \/>\n<\/b><b>Q321. An enterprise wants network authorization policies to follow users and devices independently of their IP addresses or physical VLANs. Which Cisco-oriented design concept best supports this requirement?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Static extended ACLs based only on subnet<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> One VLAN for every individual employee<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Unrestricted routing between business units<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Security Group Tags used for identity-based segmentation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Security Group Tags used for identity-based segmentation<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Security Group Tags, or SGTs, allow access policy to be based on logical security groups rather than relying entirely on IP addresses and physical network location. Users, devices, or workloads can be classified according to their role, and policy can then determine which security groups may communicate. This supports scalable segmentation when users move between access switches, wireless networks, or other locations. Traditional subnet ACLs can still be useful, but they become difficult to maintain when identity and location frequently change. Identity-based segmentation therefore provides more flexible policy enforcement across dynamic enterprise environments.<\/span><\/p>\n<p><b>Q322. A network architect must encrypt IP traffic between gateways and wants only the original IP payload protected while keeping the original IP header visible. Which IPsec mode should be selected?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Transport mode<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Tunnel mode<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> GRE mode<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> MPLS mode<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Transport mode<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> IPsec transport mode protects the payload of the original IP packet while retaining the original IP header for routing. It is commonly associated with host-to-host protection or scenarios where additional tunneling already provides the outer packet structure. IPsec tunnel mode instead encapsulates and protects the entire original IP packet inside a new outer IP packet and is widely used for site-to-site VPN gateways. GRE and MPLS are not IPsec operating modes. Architects should choose the mode based on topology, endpoint capabilities, routing requirements, and whether the original packet header itself needs to be hidden.<\/span><\/p>\n<p><b>Q323. A company wants a modern key-exchange protocol for an IPsec VPN that provides stronger negotiation efficiency and better support for mobility than older approaches. Which protocol is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Telnet<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> PPTP<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> IKEv2<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> TFTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. IKEv2<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Internet Key Exchange version 2, or IKEv2, negotiates security associations and cryptographic parameters for IPsec. Compared with older IKE designs, it simplifies negotiation and supports capabilities useful for modern VPN deployments, including improved resilience and mobility-related scenarios. Strong cipher suites, certificate or credential authentication, and appropriate lifetime settings should still be selected according to security policy. Telnet and TFTP are insecure management or file-transfer protocols, while PPTP is an obsolete VPN technology with significant security limitations. IKEv2 is therefore the preferred modern choice among the listed options.<\/span><\/p>\n<p><b>Q324. An organization is concerned that employees are using unsanctioned cloud applications that have not undergone security review. Which capability best helps identify this shadow IT usage?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Spanning Tree Protocol<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> CASB or SSE cloud application discovery<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> GRE keepalives<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> BGP local preference<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. CASB or SSE cloud application discovery<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> CASB and broader SSE platforms can analyze user web and cloud activity to identify SaaS applications being accessed across the organization, including unsanctioned services. Security teams can assess discovered applications according to risk, data handling, compliance, and business need before deciding whether to sanction, restrict, or block them. This visibility is particularly important because departments can adopt cloud services without involving security teams. Spanning tree, GRE, and BGP settings provide network infrastructure functionality and do not classify SaaS usage. Cloud application discovery supports governance of shadow IT and associated data-loss risks.<\/span><\/p>\n<p><b>Q325. A company wants to reduce ransomware infections delivered through malicious email attachments. Which email-security architecture provides the strongest layered defense?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Attachment scanning, sandboxing, reputation analysis, and phishing controls<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Permit all attachments because the endpoint has antivirus<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable sender authentication<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Allow executable attachments from unknown senders<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Attachment scanning, sandboxing, reputation analysis, and phishing controls<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Email remains a common ransomware delivery mechanism, so layered controls are preferable to one detection technique. Reputation services can evaluate senders and URLs, attachment scanning can identify known threats, and sandboxing can analyze suspicious files behaviorally. Phishing detection, sender authentication, URL protection, and endpoint controls provide additional defenses when a malicious message bypasses one layer. Relying solely on endpoint antivirus leaves unnecessary exposure. Disabling sender authentication or broadly allowing executable attachments makes email security weaker. Defense in depth provides more opportunities to detect and stop malicious content before execution.<\/span><\/p>\n<p><b>Q326. A web application loads a JavaScript library from a public content delivery network. The architect wants browsers to detect if the downloaded library is unexpectedly modified. Which browser security mechanism is most suitable?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DHCP snooping<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> NAT traversal<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Subresource Integrity<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> BGP authentication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Subresource Integrity<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Subresource Integrity, or SRI, allows a web page to specify a cryptographic hash for an externally loaded resource such as a JavaScript or CSS file. The browser calculates the hash of the downloaded content and refuses to use it if the value does not match the expected hash. This helps reduce risk if a third-party CDN or hosted library is modified unexpectedly. SRI does not replace CSP, dependency management, or trusted software sourcing, but it provides useful client-side integrity verification. DHCP, NAT, and BGP features do not validate web resource contents.<\/span><\/p>\n<p><b>Q327. A Java application accepts serialized objects from an untrusted network source. Which architectural change best reduces insecure deserialization risk?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Accept every object type automatically<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Run the application as root<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable application logging<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Avoid native object deserialization of untrusted input and use constrained data formats with validation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Avoid native object deserialization of untrusted input and use constrained data formats with validation<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Insecure deserialization can allow attacker-controlled objects to trigger unexpected code paths or dangerous object construction. A safer architecture avoids deserializing arbitrary native objects supplied by untrusted clients. Instead, applications can use simple constrained data representations with explicit schemas and validation, then map approved fields into internal objects. Where deserialization is unavoidable, type allowlists, hardened libraries, and least privilege can reduce exposure. Running with elevated privileges makes exploitation more damaging, while disabling logging removes evidence. Treating serialized data as trusted can create serious remote-code-execution risk.<\/span><\/p>\n<p><b>Q328. An API supports financial transfers. Which control best prevents a user who is authorized to view an account from automatically being authorized to transfer money from it?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Hide the transfer button in the client application<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Enforce function-level authorization separately for the transfer operation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Rely on the account identifier being difficult to guess<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Increase the API timeout<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Enforce function-level authorization separately for the transfer operation<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Authorization should be checked for each sensitive operation, not inferred simply because a user has access to a related object. A user might legitimately view an account balance but lack permission to initiate transfers. Server-side function-level authorization should evaluate the authenticated identity, account relationship, role, transaction policy, and potentially additional controls such as step-up authentication. Hiding a client-side button does not prevent direct API calls. Difficult-to-guess identifiers are also not authorization controls. Fine-grained server-side authorization prevents privilege escalation through sensitive API functions.<\/span><\/p>\n<p><b>Q329. A security team wants to detect when a cloud administrator makes an unusual privilege change that deviates significantly from their normal activity. Which analytical capability is most useful?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Static subnetting<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> VLAN pruning<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> User and Entity Behavior Analytics<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> GRE encapsulation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. User and Entity Behavior Analytics<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> User and Entity Behavior Analytics, or UEBA, develops behavioral context around users, service accounts, hosts, and other entities and identifies deviations that may indicate compromise or abuse. An unusual privilege grant by an administrator can be compared with historical activity, normal change windows, device context, peer behavior, and other signals. UEBA is useful when individual actions are technically valid but suspicious in context. Static network configuration does not provide this behavioral interpretation. UEBA should complement deterministic detections and human analysis rather than serve as the sole basis for disruptive response actions.<\/span><\/p>\n<p><b>Q330. A SOC wants an investigation platform to automatically group multiple related alerts from the same attack into one case. What is the principal benefit?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Increase the number of duplicate alerts<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable analyst context<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Eliminate the need for telemetry<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Reduce alert fragmentation and improve incident context<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Reduce alert fragmentation and improve incident context<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> One attack can generate alerts from identity, endpoint, firewall, email, and cloud systems. Correlating related alerts into a single incident helps analysts understand the broader attack sequence rather than investigating every alert independently. This can reduce duplicate work, reveal relationships, and improve prioritization. Correlation should preserve underlying evidence so analysts can still inspect individual detections. It does not eliminate the need for quality telemetry. Effective incident grouping is a key SOC capability because attackers commonly cross multiple security domains during a single intrusion.<\/span><\/p>\n<p><b>Q331. An organization measures how long it takes from incident detection until the affected system is isolated from the network. Which operational metric is most directly being evaluated?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Mean Time to Contain<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Recovery Point Objective<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> CVSS base score<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Annualized Loss Expectancy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Mean Time to Contain<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Mean Time to Contain measures how quickly an organization limits an incident after it has been identified, for example by isolating endpoints, disabling compromised accounts, blocking malicious infrastructure, or segmenting affected systems. Lower containment time can reduce attacker dwell time and limit lateral movement or data loss. MTTD measures detection speed, while recovery metrics focus on restoring service. CVSS evaluates vulnerability severity, and ALE estimates financial risk. Tracking containment speed helps SOC and incident-response teams assess whether alerts translate into timely defensive action.<\/span><\/p>\n<p><b>Q332. A security architecture team uses the NIST Cybersecurity Framework to organize security outcomes. Which function is most closely associated with understanding organizational assets, risks, and vulnerabilities?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Recover<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Identify<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Respond<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Contain<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Identify<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> The Identify function of the NIST Cybersecurity Framework focuses on understanding the organization&#8217;s environment, assets, business context, governance, and cybersecurity risk. Activities such as asset management and risk assessment support informed decisions about how protection, detection, response, and recovery should be designed. The framework organizes security outcomes rather than prescribing a specific product architecture. Recover addresses restoration and improvement after incidents, while Respond focuses on actions taken after detection. Understanding the environment and risk is essential because security controls should be derived from what the organization needs to protect.<\/span><\/p>\n<p><b>Q333. Which framework is commonly used to establish an information security management system based on risk management and continual improvement?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> ARP<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> OSPF<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> DHCP<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> ISO\/IEC 27001<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. ISO\/IEC 27001<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> ISO\/IEC 27001 defines requirements for establishing, implementing, maintaining, and continually improving an information security management system, or ISMS. The standard uses a risk-based approach and helps organizations govern information security systematically rather than treating security as a set of isolated technical controls. Certification can provide external assurance that an organization operates an ISMS conforming to the standard&#8217;s requirements. ARP, OSPF, and DHCP are networking protocols rather than information-security management frameworks. Security architects may need to align technical designs with controls and governance requirements established through an organization&#8217;s ISMS.<\/span><\/p>\n<p><b>Q334. A proposed security control costs $500,000 annually but is expected to reduce only $20,000 of annualized risk. What should the risk decision process do?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Automatically implement it because every security control is beneficial<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Ignore risk analysis entirely<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Evaluate whether a less costly treatment better aligns with business risk and requirements<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable all existing controls<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Evaluate whether a less costly treatment better aligns with business risk and requirements<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Security controls should be evaluated in relation to business risk, mandatory requirements, and the expected reduction in exposure. If a control costs far more than the risk it reduces, decision-makers should consider whether other treatment options provide better value, unless legal, safety, contractual, or strategic requirements mandate the control. Quantitative analysis is not the only factor, but it provides useful context. Security architecture is ultimately a risk-management discipline rather than an objective of maximizing security spending. Alternative mitigation, transfer, acceptance, or avoidance may be more appropriate.<\/span><\/p>\n<p><b>Q335. An organization accepts a temporary exception to a security standard. Which governance practice is most important?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Make the exception permanent automatically<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Document the owner, justification, expiration date, and compensating controls<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Hide the exception from auditors<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Remove all monitoring from the affected system<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Document the owner, justification, expiration date, and compensating controls<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Security exceptions should be formally governed so temporary business needs do not become undocumented permanent weaknesses. The exception should state what requirement is being waived, why it is necessary, who owns the associated risk, what compensating controls reduce exposure, and when the exception expires or must be reviewed. Monitoring should remain in place and may need to be strengthened. An explicit expiration date helps ensure the issue returns for review. Transparent exception management supports accountability, auditability, and informed risk acceptance.<\/span><\/p>\n<p><b>Q336. A company wants its infrastructure templates to be continuously checked against security standards before and after deployment. Which DevSecOps design is best?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Manual annual inspection only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> No configuration validation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Policy as code integrated with CI\/CD and continuous compliance checks<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Administrator memory as the primary enforcement mechanism<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Policy as code integrated with CI\/CD and continuous compliance checks<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Policy as code turns security and compliance requirements into machine-evaluable rules. CI\/CD pipelines can evaluate Infrastructure as Code before deployment, while continuous compliance checks can evaluate the resulting live environment for drift or noncompliance afterward. This provides both preventive and detective controls. Manual annual checks occur too infrequently for fast-changing cloud environments, and relying on administrator memory is inconsistent. Policy as code also creates versioned, reviewable, and testable security rules that can be improved alongside infrastructure automation.<\/span><\/p>\n<p><b>Q337. A CI pipeline executes third-party build tools. Which isolation strategy best limits damage if one build tool is malicious?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use isolated, ephemeral build environments with minimal permissions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Run every build tool on the production database server<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Give build tools domain administrator privileges<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable network controls around build workers<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Use isolated, ephemeral build environments with minimal permissions<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Ephemeral build environments reduce persistence because each build runs in a fresh environment that is destroyed afterward. Isolation limits access to other builds and internal systems, while least-privilege identities restrict what a compromised build process can do. Network egress can also be constrained to required repositories and services. Running third-party tooling on production servers or granting broad privileges creates a direct supply-chain attack path. Build infrastructure should be treated as sensitive security infrastructure because compromise can affect every artifact produced by the pipeline.<\/span><\/p>\n<p><b>Q338. An AI security system is offered as a hosted API. The organization is concerned that an attacker could copy the model&#8217;s functionality by sending large numbers of carefully selected queries. Which AI threat does this describe?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> VLAN hopping<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> DHCP exhaustion<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Model extraction or model stealing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> ARP poisoning<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Model extraction or model stealing<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Model extraction attacks use repeated queries and observed outputs to approximate or reproduce the behavior of a proprietary machine-learning model. This can threaten intellectual property and may also help attackers study the model for later evasion. Defenses can include authentication, rate limits, query monitoring, output minimization, watermarking where appropriate, and behavioral detection of suspicious query patterns. Traditional network attacks such as ARP poisoning or DHCP exhaustion do not describe the theft of model functionality. Hosted AI services should consider model confidentiality alongside ordinary API security.<\/span><\/p>\n<p><b>Q339. A generative AI service processes confidential SOC incidents. Which control is most important for protecting prompts and responses from unnecessary retention by external providers?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Review provider data-retention and training policies and use enterprise privacy controls<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Assume all public AI services discard information automatically<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Submit credentials to improve response quality<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable contractual review<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Review provider data-retention and training policies and use enterprise privacy controls<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Before sensitive incident information is submitted to an external AI provider, the organization should understand how prompts and responses are stored, retained, accessed, processed, and potentially used for service improvement or model training. Enterprise agreements and privacy controls may provide different behavior from public consumer services. Data minimization and redaction can further reduce exposure. Assuming that information is automatically deleted is unsafe. Credentials and secrets should not be provided merely for additional context. Third-party AI services should undergo security, privacy, contractual, and compliance review like other sensitive SaaS providers.<\/span><\/p>\n<p><b>Q340. An organization wants to evaluate whether a generative AI system can be manipulated through prompt injection before allowing production use. Which activity is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable security testing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Assume vendor testing is sufficient for every use case<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Perform AI-focused adversarial testing and red-team exercises<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Give the model production administrator rights first<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Perform AI-focused adversarial testing and red-team exercises<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> AI red teaming deliberately tests how a model and its surrounding application behave under adversarial prompts, indirect prompt injection, data-exfiltration attempts, tool misuse, and other abuse scenarios. Testing should include the complete AI system, not just the base model, because retrieval systems, plugins, tools, and authorization boundaries can create additional attack paths. Findings can guide guardrails, access controls, prompt separation, output validation, and human approval requirements. Vendor evaluation is useful but cannot cover every organization&#8217;s data sources, workflows, and permissions. Production deployment should follow risk-based adversarial validation.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco CCNP Security 300-745 Exam Dumps and Practice Test Dumps. Q321. An enterprise wants network authorization policies to follow users and devices independently of their IP addresses or physical VLANs. Which Cisco-oriented design concept best supports this requirement? Static extended ACLs based only on subnet 2. One VLAN for every individual employee 3. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17713"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=17713"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17713\/revisions"}],"predecessor-version":[{"id":17714,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17713\/revisions\/17714"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=17713"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=17713"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=17713"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}