{"id":17719,"date":"2026-09-21T11:05:11","date_gmt":"2026-09-21T11:05:11","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=17719"},"modified":"2026-09-21T11:05:11","modified_gmt":"2026-09-21T11:05:11","slug":"cisco-ccnp-security-300-745-practice-test-questions-and-exam-dumps-part20-q381-400","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-ccnp-security-300-745-practice-test-questions-and-exam-dumps-part20-q381-400\/","title":{"rendered":"Cisco CCNP Security 300-745 Practice Test Questions and Exam Dumps Part20 Q381-400"},"content":{"rendered":"<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/300-745-exam-dumps\"><b>Cisco CCNP Security 300-745 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/p>\n<p><b><br \/>\n<\/b><b>Q381. A security architect wants firewall policy enforcement without changing the existing IP addressing or routing design between two network segments. Which firewall deployment mode best fits this requirement?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Transparent firewall mode<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Routed firewall mode with new subnets<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> GRE tunnel termination<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> DHCP relay mode<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Transparent firewall mode<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> A transparent firewall operates primarily as a Layer 2 security device while still inspecting and enforcing policy on traffic passing through it. This allows an organization to insert firewall protection between existing network segments without redesigning IP addressing or making the firewall the Layer 3 gateway. It can therefore be valuable when network topology changes are difficult. Routed firewall mode normally participates directly in Layer 3 forwarding and may require subnet or gateway changes. GRE and DHCP relay solve unrelated tunneling and address-assignment problems rather than transparent security enforcement.<\/span><\/p>\n<p><b>Q382. An organization wants the standby firewall to take over active sessions with minimal disruption if the primary firewall fails. Which design is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Two independent firewalls with no synchronization<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Manual failover performed after an outage<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> One firewall with multiple administrator accounts<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Stateful high availability with session synchronization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Stateful high availability with session synchronization<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Stateful high availability synchronizes important connection state between active and standby firewalls so the standby device can continue processing many established sessions after a failover. This reduces disruption compared with a design where every connection must be rebuilt. HA architecture should also consider interface redundancy, health monitoring, configuration synchronization, routing convergence, and failure-domain separation. Two unsynchronized firewalls may provide hardware redundancy but can still interrupt sessions significantly. Manual failover also increases recovery time. Stateful synchronization is therefore important when security enforcement must remain available during individual firewall failures.<\/span><\/p>\n<p><b>Q383. A security team wants to limit IPv6 neighbor discovery spoofing on access networks. Which control should be considered?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> BGP maximum-prefix<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> IPv6 Neighbor Discovery inspection or equivalent first-hop security<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> GRE keepalives<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> NAT overload<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. IPv6 Neighbor Discovery inspection or equivalent first-hop security<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> IPv6 relies on Neighbor Discovery for functions similar to ARP and additional local-link operations. Attackers can attempt to spoof Neighbor Discovery messages to redirect or disrupt traffic. IPv6 first-hop security features can validate or constrain these messages and complement protections such as RA Guard. This is especially important on user-facing access networks where untrusted devices share a Layer 2 domain. BGP maximum-prefix controls routing advertisements, GRE keepalives monitor tunnels, and NAT performs address translation. They do not directly protect IPv6 Neighbor Discovery exchanges.<\/span><\/p>\n<p><b>Q384. A network device must accept routing protocol packets only from legitimate neighbors and reject unexpected protocol traffic from user networks. Which design best supports this requirement?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Permit routing protocols from all internal subnets<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable routing authentication<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Restrict routing protocol traffic with infrastructure ACLs and authenticate neighbors<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Replace routing protocols with DHCP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Restrict routing protocol traffic with infrastructure ACLs and authenticate neighbors<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Routing protocols are part of the network control plane and should be exposed only to legitimate peers. Infrastructure ACLs can restrict protocol traffic to expected source addresses, while routing-protocol authentication helps verify authorized neighbors. Additional controls such as CoPP can protect device CPU resources from excessive control-plane traffic. Allowing routing packets from user networks increases attack surface, and disabling authentication weakens peer trust. DHCP is not a replacement for dynamic routing. Strong control-plane architecture combines traffic restriction, authentication, monitoring, and rate protection.<\/span><\/p>\n<p><b>Q385. A security team wants remote browser sessions to isolate potentially malicious web code while still letting users interact with websites normally. Which technology best meets the requirement?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Static ACLs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> DHCP snooping<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> GRE tunneling<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Browser isolation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Browser isolation<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Browser isolation executes web content in a remote or otherwise isolated environment rather than allowing potentially malicious active content to execute directly on the user&#8217;s endpoint. The user receives a rendered representation or controlled interaction with the web session. This can reduce exposure to browser exploits, malicious scripts, and risky downloads. It is often used alongside secure web gateways, DNS security, and endpoint protection. Static ACLs, DHCP snooping, and GRE solve different network problems and cannot isolate active web content. Browser isolation is particularly useful for unknown or high-risk web destinations.<\/span><\/p>\n<p><b>Q386. An API receives user input that is passed to an operating-system shell command. Which secure design most directly prevents command injection?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Avoid shell invocation where possible and use safe parameterized APIs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Base64-encode all user input<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Hide command output from the user<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Run the service as root<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Avoid shell invocation where possible and use safe parameterized APIs<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Command injection occurs when untrusted input is interpreted as part of an operating-system command. The strongest design is to avoid shell execution when a safer library or system API can perform the required function. If external commands are unavoidable, arguments should be strictly validated and passed through safe interfaces that separate parameters from command syntax. Base64 is only encoding and does not make attacker-controlled content safe. Hiding output does not prevent execution, and running as root makes exploitation substantially more damaging. Least privilege should also be applied to the application process.<\/span><\/p>\n<p><b>Q387. A SaaS integration receives OAuth access tokens intended for a different API. Which validation prevents those tokens from being reused against this service?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Check only the username claim<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Validate the token audience<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Ignore the issuer<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable expiration checking<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Validate the token audience<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> The audience claim identifies the service or resource for which a token was issued. An API should verify that it is an intended audience before accepting the token. Without audience validation, a token legitimately issued for another service might be replayed against an unrelated API. Signature, issuer, expiration, scope, and other relevant claims should also be validated. Checking only usernames provides weak assurance, while ignoring issuer or expiration further weakens token security. Audience validation is therefore a key control for preventing cross-service token misuse.<\/span><\/p>\n<p><b>Q388. An application stores sensitive configuration in environment variables. Which risk should the architect specifically consider?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Environment variables automatically encrypt themselves<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> They cannot be read by processes<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Secrets may be exposed through process inspection, crash output, logs, or misconfiguration<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> They eliminate the need for secret rotation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Secrets may be exposed through process inspection, crash output, logs, or misconfiguration<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Environment variables are convenient but are not automatically secure secret stores. Depending on the operating system, runtime, diagnostics, and deployment platform, values can be exposed through process inspection, support bundles, crash dumps, debug output, or accidental logging. Sensitive credentials should ideally be retrieved from a dedicated secrets-management service using workload identity and short-lived access. If environment variables must be used, access should be tightly controlled and logging reviewed carefully. Secret rotation and lifecycle management remain necessary regardless of how credentials are delivered.<\/span><\/p>\n<p><b>Q389. A SOC wants to identify a compromised system that periodically contacts the same external server at fixed intervals despite little user activity. Which behavioral indicator is this?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Beaconing behavior<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Route summarization<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> ARP aging<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> DHCP renewal<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Beaconing behavior<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Beaconing describes periodic, often regular communication between a compromised host and command-and-control infrastructure. Malware may check in at fixed or semi-random intervals for instructions or to report status. Network flow, proxy, DNS, and endpoint telemetry can help identify repeated low-volume connections that differ from ordinary application behavior. Sophisticated malware may add jitter to avoid simple periodicity detection, so behavioral analytics can consider timing distributions and destination reputation. Routing, ARP, and DHCP timing are normal network operations and do not describe malicious command-and-control check-ins.<\/span><\/p>\n<p><b>Q390. A SOC receives multiple alerts from a single host, including credential dumping, unusual PowerShell, and outbound connections to a suspicious domain. Which action best improves analyst efficiency?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Investigate every alert as unrelated<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Correlate the alerts into a single incident timeline<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Delete lower-severity alerts immediately<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable endpoint logging<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Correlate the alerts into a single incident timeline<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Multiple security alerts generated from the same attack should be correlated so analysts can understand the sequence and relationships among events. Credential dumping, suspicious scripting, and unusual outbound communications may represent different stages of one intrusion. Grouping these events helps analysts prioritize the case, understand scope, and choose appropriate containment. Treating every alert independently increases duplicate work and can obscure the larger attack path. Lower-severity events can still provide valuable context, so automatically deleting them can remove important evidence.<\/span><\/p>\n<p><b>Q391. During forensic analysis, an investigator creates a cryptographic hash of a collected disk image immediately after acquisition. What is the primary purpose?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Demonstrate later that the evidence has not changed<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Compress the disk image<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Encrypt every file automatically<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Identify the attacker&#8217;s IP address<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Demonstrate later that the evidence has not changed<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> A cryptographic hash provides a repeatable integrity value for digital evidence. Investigators can calculate the hash at acquisition and compare it with hashes calculated later to show that the disk image has not changed. This supports evidence integrity and chain-of-custody procedures. Hashing does not compress or encrypt the data, nor does it directly identify an attacker. Strong evidence handling also includes controlled access, documented transfers, validated tooling, timestamps, and preservation of the original acquisition. Integrity verification is essential when forensic findings may be subject to legal or regulatory review.<\/span><\/p>\n<p><b>Q392. A company wants to ensure that major security incidents are assigned severity consistently according to business impact, scope, and regulatory implications. What should it define?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> One severity for every incident<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> DHCP reservation policy<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Incident severity classification criteria<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> BGP route preferences<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Incident severity classification criteria<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Incident severity criteria provide a consistent framework for determining how urgently different incidents should be handled. Factors can include number of affected users, critical assets, privileged accounts, data sensitivity, service disruption, regulatory obligations, and attacker activity. Defined severity levels help determine response SLAs, escalation paths, executive involvement, and communication requirements. Without consistent criteria, similar incidents may receive very different treatment depending on the analyst. DHCP and BGP policies are network configuration concepts and do not provide incident governance. Severity classification connects technical events to business impact.<\/span><\/p>\n<p><b>Q393. A new cloud service will process highly sensitive personal data. Which assessment should the organization perform to evaluate privacy risks before implementation?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> VLAN utilization study<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> DNS performance benchmark<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> BGP convergence analysis<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Privacy impact assessment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Privacy impact assessment<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> A privacy impact assessment examines how personal data will be collected, used, stored, shared, retained, and protected and identifies risks to individuals and the organization. It can help determine whether data minimization, consent, residency, retention, access control, encryption, or contractual safeguards are required. The exact terminology and legal requirement may vary by jurisdiction, but the architectural principle is to evaluate privacy risk before deploying a system that processes sensitive information. Network performance measurements do not address privacy obligations or personal-data handling practices.<\/span><\/p>\n<p><b>Q394. A risk committee wants to understand how multiple moderate risks could combine to create significant exposure to one critical business service. Which concept is most relevant?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Risk aggregation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> ARP inspection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Route redistribution<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> DHCP failover<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Risk aggregation<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Risk aggregation considers how separate risks can accumulate or interact to create a larger overall exposure. For example, moderate identity weaknesses, limited segmentation, poor monitoring, and weak recovery capability might individually appear manageable but together create substantial risk to a critical business service. Security architecture should therefore avoid evaluating every risk in isolation. Aggregation can also identify concentration risks where many controls depend on one provider, identity system, cloud region, or shared platform. Network protocol features do not provide this business-level view of combined exposure.<\/span><\/p>\n<p><b>Q395. Which architectural document most clearly communicates reusable approved approaches for common security problems such as privileged access, Internet-facing applications, or cloud logging?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Approved security design patterns or reference architectures<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> A single incident ticket<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> DHCP lease table<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Packet capture file<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Approved security design patterns or reference architectures<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Security design patterns and reference architectures document approved approaches to recurring architecture problems. They can describe required controls, trust boundaries, identity models, logging, segmentation, failure behavior, and example technology placements. Reusing approved patterns improves consistency and reduces the need to redesign common security solutions for every project. They also accelerate reviews because teams can demonstrate alignment with known architectural standards. Incident tickets, packet captures, and DHCP data are operational artifacts and do not provide reusable architectural guidance for future designs.<\/span><\/p>\n<p><b>Q396. A company is migrating a critical service to a third-party cloud provider. Which contract requirement best supports incident response?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> No requirement for breach notification<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Defined security incident notification timelines and cooperation obligations<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The provider can delete all logs immediately<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> No obligation to preserve evidence<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Defined security incident notification timelines and cooperation obligations<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Third-party contracts should define how quickly the provider must notify the customer of security incidents and what cooperation, logging, evidence preservation, and investigation support is required. Delayed notification can prevent the organization from meeting its own legal, regulatory, contractual, or operational response deadlines. Architects and risk teams should also consider access to audit evidence, data location, subcontractors, resilience, and termination procedures. A provider that can silently delete evidence or avoid notification introduces significant incident-response and governance risk.<\/span><\/p>\n<p><b>Q397. A DevSecOps team wants production deployments to use only artifacts that passed security scanning and came from the approved pipeline. Which architecture best enforces this?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Admission policy that verifies signed artifacts and required attestations<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Allow developers to deploy any local build<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable artifact signatures<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Trust filenames to identify approved software<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Admission policy that verifies signed artifacts and required attestations<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> An admission policy can enforce that a production artifact is signed by a trusted build identity and is accompanied by required attestations, such as successful vulnerability scanning or provenance information. This creates a technical enforcement point at deployment time rather than relying only on process documentation. Locally built or unsigned artifacts can be rejected automatically. Filenames provide no trustworthy evidence of provenance. This design connects CI\/CD security results directly to production runtime policy, strengthening software supply-chain integrity and reducing the chance of bypassing approved build controls.<\/span><\/p>\n<p><b>Q398. An automation workflow performs a security change across many devices. Which capability best ensures a failed deployment can be safely reversed?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Remove configuration backups<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Transactional rollback or known-good configuration restoration<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable state validation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Continue deployment after every error<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Transactional rollback or known-good configuration restoration<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Large-scale security automation can magnify errors quickly. A safe workflow should preserve a known-good state and support rollback if validation fails or a device becomes unreachable. Transactional platforms can apply changes atomically, while other systems may rely on configuration checkpoints or explicit restoration procedures. Automation should also use staged deployment, post-change verification, timeouts, and stop conditions. Continuing blindly after errors can spread misconfiguration throughout the environment. Rollback capability is therefore a critical part of reliable and resilient security automation design.<\/span><\/p>\n<p><b>Q399. An organization purchases an AI model from a third-party provider. Which supply-chain control is most important before deploying the model into a sensitive security workflow?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Evaluate model provenance, integrity, vendor security, and permitted use<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Assume all externally supplied models are trustworthy<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable access controls around the model repository<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Skip testing because the model is pretrained<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Evaluate model provenance, integrity, vendor security, and permitted use<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Third-party models introduce supply-chain risks similar to software dependencies. Organizations should understand where the model came from, how it was trained, how it is licensed, whether its files are authentic, and what security practices the provider follows. The model should also be tested for expected behavior, abuse cases, privacy risks, and compatibility with the intended security workflow. Repository access and integrity should be protected. Pretraining does not guarantee safety or suitability. AI assets should therefore be governed as sensitive software and data supply-chain components.<\/span><\/p>\n<p><b>Q400. A generative AI agent can call security tools. What design most directly prevents a malicious prompt from causing the agent to delete production resources?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Give the model root access but add a warning prompt<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable audit logging<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Enforce least-privilege tool permissions and approval for destructive actions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Trust all retrieved content as instructions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Enforce least-privilege tool permissions and approval for destructive actions<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Prompt instructions alone cannot reliably prevent an AI agent from taking dangerous actions if its connected tool identity already has destructive privileges. The underlying APIs should enforce least privilege so the agent can access only the operations required for its task. Destructive production actions can require human approval, additional policy validation, or separate privileged workflows. Retrieved content and user prompts should be treated as untrusted data. Comprehensive logging should remain enabled. Security boundaries should therefore exist outside the model and remain effective even when the AI is manipulated or makes an incorrect decision.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco CCNP Security 300-745 Exam Dumps and Practice Test Dumps. Q381. A security architect wants firewall policy enforcement without changing the existing IP addressing or routing design between two network segments. Which firewall deployment mode best fits this requirement? Transparent firewall mode 2. Routed firewall mode with new subnets 3. GRE tunnel termination [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17719"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=17719"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17719\/revisions"}],"predecessor-version":[{"id":17720,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17719\/revisions\/17720"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=17719"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=17719"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=17719"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}