{"id":20894,"date":"2026-09-24T09:02:28","date_gmt":"2026-09-24T09:02:28","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=20894"},"modified":"2026-09-24T09:02:28","modified_gmt":"2026-09-24T09:02:28","slug":"cisco-ccie-security-350-701-practice-test-questions-and-exam-dumps-part1-q1-20","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-ccie-security-350-701-practice-test-questions-and-exam-dumps-part1-q1-20\/","title":{"rendered":"Cisco CCIE Security 350-701 Practice Test Questions and Exam Dumps Part1 Q1-20"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/350-701-exam-dumps\"><b>Cisco 350-701 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 1<\/b><\/h3>\n<p><b>Which security architecture assumes that users and devices should not automatically be trusted simply because they are located inside an organization&#8217;s network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defense in depth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Zero trust<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network address translation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Perimeter-only security<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Zero trust is a security architecture based on the principle that trust should not be granted solely because a user or device is inside a corporate network. Access decisions should consider identity, device posture, context, and the requested resource. Authentication and authorization are continuously evaluated rather than assuming that internal traffic is inherently trustworthy. This approach helps reduce the impact of compromised accounts and lateral movement. Traditional perimeter-only security places greater emphasis on protecting the network boundary and may provide less granular control after access is granted.<\/span><\/p>\n<h3><b>Question 2<\/b><\/h3>\n<p><b>An attacker crafts specially designed instructions that cause an AI application to ignore its intended behavior and follow attacker-controlled instructions. Which vulnerability does this represent?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Buffer overflow<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Path traversal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL injection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Prompt injection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Prompt injection occurs when an attacker provides malicious or carefully constructed instructions to an AI or large language model application in an attempt to manipulate its behavior. Depending on the application&#8217;s design, this could cause the model to reveal information, bypass intended restrictions, or perform actions outside its expected purpose. Buffer overflow, path traversal, and SQL injection target different components and mechanisms. Security teams should validate untrusted inputs and apply appropriate authorization controls rather than relying solely on an AI model to enforce security boundaries.<\/span><\/p>\n<h3><b>Question 3<\/b><\/h3>\n<p><b>Which vulnerability scoring system provides a standardized numerical assessment that helps organizations prioritize vulnerabilities according to severity?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CVSS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SAML<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SNMP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Common Vulnerability Scoring System, or CVSS, provides a standardized framework for evaluating the severity of security vulnerabilities. CVSS scores consider characteristics such as exploitability and potential impact, helping organizations compare vulnerabilities and prioritize remediation activities. A higher score generally indicates greater severity, although organizations should also consider environmental factors and business context when determining remediation priorities. CVEs identify individual publicly documented vulnerabilities, while DNS and SNMP serve networking functions. Therefore, CVSS is the scoring system used to assess vulnerability severity.<\/span><\/p>\n<h3><b>Question 4<\/b><\/h3>\n<p><b>Which technology allows IPsec traffic to traverse a device performing IPv4 NAT by encapsulating the encrypted traffic in UDP?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">GRE<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SSL<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT-T<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VXLAN<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">NAT Traversal, commonly called NAT-T, allows IPsec VPN traffic to operate through IPv4 NAT devices. Traditional IPsec can encounter difficulties when address translation modifies packet information, particularly because ESP does not use TCP or UDP port numbers in the same way ordinary transport protocols do. NAT-T encapsulates ESP traffic within UDP, allowing NAT devices to process the traffic more effectively. GRE and VXLAN provide different tunneling functions, while SSL is a cryptographic protocol rather than the specific NAT traversal mechanism described here.<\/span><\/p>\n<h3><b>Question 5<\/b><\/h3>\n<p><b>Which Cisco-related VPN technology is designed to provide a scalable group-encrypted network architecture in which traffic can be encrypted without requiring traditional point-to-point IPsec tunnels between every pair of routers?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SSL VPN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">GETVPN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remote Desktop Protocol<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">L2TP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">GETVPN, or Group Encrypted Transport VPN, is designed for environments where multiple trusted sites require secure communication while preserving the original IP addressing and routing characteristics of the network. Instead of creating a separate point-to-point tunnel for every pair of sites, GETVPN uses group-based encryption and centralized key management. This makes it suitable for certain large enterprise networks with many participating locations. SSL VPN and L2TP serve different remote-access purposes, while RDP provides remote desktop functionality rather than group-based network encryption.<\/span><\/p>\n<h3><b>Question 6<\/b><\/h3>\n<p><b>Which switch security feature helps prevent unauthorized DHCP servers from responding to clients on a network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP snooping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port mirroring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MAC flooding<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">DHCP snooping is a Layer 2 security feature that helps protect networks from rogue DHCP servers. The switch identifies trusted interfaces where legitimate DHCP server responses are expected and can block DHCP server messages arriving through untrusted ports. DHCP snooping can also build a binding database containing information such as client MAC addresses, IP addresses, VLANs, and switch ports. This information can support other security mechanisms, including Dynamic ARP Inspection. Port mirroring is used for monitoring traffic, while NAT performs address translation.<\/span><\/p>\n<h3><b>Question 7<\/b><\/h3>\n<p><b>Which security mechanism helps prevent ARP spoofing by validating ARP packets against trusted IP-to-MAC address bindings?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP relay<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">PortFast<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic ARP Inspection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">EtherChannel<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Dynamic ARP Inspection, or DAI, helps protect Layer 2 networks against ARP spoofing and poisoning attacks. It can validate ARP packets by comparing their IP-to-MAC address information against trusted bindings, commonly those learned through DHCP snooping. Invalid ARP messages can then be discarded, reducing the ability of an attacker to impersonate another device on the local network. DHCP relay forwards DHCP requests between networks, PortFast affects spanning-tree behavior, and EtherChannel combines physical links. Therefore, DAI is the appropriate protection mechanism.<\/span><\/p>\n<h3><b>Question 8<\/b><\/h3>\n<p><b>Which AAA protocol is commonly preferred for centralized administration of network device access because it separates authentication and authorization functions?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RADIUS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LDAP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TACACS+<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Kerberos<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">TACACS+ is a AAA protocol commonly used for centralized authentication, authorization, and accounting of administrative access to network devices. One important characteristic is its separation of authentication and authorization, allowing administrators to receive more granular control over which commands or services they can use. RADIUS is also widely used for centralized authentication and network access, particularly for user connectivity, but it combines authentication and authorization differently. LDAP is primarily a directory protocol, while Kerberos provides ticket-based authentication. Therefore, TACACS+ fits the described requirement.<\/span><\/p>\n<h3><b>Question 9<\/b><\/h3>\n<p><b>Which protocol provides encrypted management and monitoring communications for network devices by using authentication and privacy mechanisms?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SNMPv1<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SNMPv2c<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SNMPv3<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TFTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">SNMPv3 provides security features that are not available in the older community-string-based SNMP versions. It supports authentication to verify the source of management messages and privacy mechanisms to protect sensitive SNMP communication from being read by unauthorized parties. This makes SNMPv3 more appropriate for secure network monitoring and management. SNMPv1 and SNMPv2c rely on community strings and do not provide the same level of built-in security. TFTP is a file-transfer protocol and does not provide secure network-management functionality.<\/span><\/p>\n<h3><b>Question 10<\/b><\/h3>\n<p><b>A Cisco Secure Firewall Threat Defense policy needs to identify and control applications rather than relying only on IP addresses and ports. Which capability should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP snooping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application Visibility and Control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MAC address learning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT-T<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application Visibility and Control, commonly referred to as AVC, enables Cisco Secure Firewall Threat Defense to identify applications and apply security policies based on application characteristics. This provides more granular control than relying exclusively on source and destination addresses or transport-layer ports. Administrators can use application identification as part of access control policies to restrict or permit specific application traffic. DHCP snooping is a Layer 2 security feature, MAC learning is a switching function, and NAT-T supports IPsec traversal through NAT. Therefore, AVC is appropriate.<\/span><\/p>\n<h3><b>Question 11<\/b><\/h3>\n<p><b>In a typical cloud shared responsibility model, which responsibility generally remains with the cloud customer regardless of whether infrastructure is hosted by a provider?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Physical security of the provider&#8217;s data center<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Maintenance of the provider&#8217;s physical servers<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Protection and appropriate handling of the customer&#8217;s data<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replacement of failed provider storage hardware<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">In a cloud shared responsibility model, the cloud provider and customer divide security responsibilities according to the service being consumed. The customer generally remains responsible for protecting its own data, configuring appropriate access controls, and using services securely. The provider normally handles responsibilities associated with the underlying physical infrastructure, such as data-center facilities and provider-managed hardware. The exact division changes between SaaS, PaaS, and IaaS models. Therefore, protecting and appropriately handling customer data remains an important customer responsibility.<\/span><\/p>\n<h3><b>Question 12<\/b><\/h3>\n<p><b>Which cloud security capability acts as an intermediary between cloud users and cloud services to provide visibility and enforce security policies?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CASB<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RAID<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Cloud Access Security Broker, or CASB, provides security controls and visibility between an organization&#8217;s users and cloud service providers. CASB capabilities can include policy enforcement, data protection, access control, threat detection, and visibility into cloud application usage. This can help organizations address security requirements when employees use cloud services outside traditional on-premises infrastructure. DHCP assigns network configuration, NAT translates addresses, and RAID provides storage redundancy. Therefore, CASB is the cloud security capability described in the question.<\/span><\/p>\n<h3><b>Question 13<\/b><\/h3>\n<p><b>Which DevSecOps practice integrates security checks into the software development and CI\/CD process rather than waiting until deployment to perform security testing?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Manual patching only<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Perimeter firewalling<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security integration throughout the pipeline<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Physical server replacement<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">DevSecOps integrates security into the software development lifecycle so that security controls and testing occur throughout development, build, testing, and deployment activities. Security checks can be incorporated into CI\/CD pipelines to identify vulnerabilities earlier and reduce the cost of fixing problems late in the process. Infrastructure as Code can also be reviewed and scanned for security issues before deployment. This approach differs from relying exclusively on perimeter controls or performing security checks only after an application reaches production. Therefore, integrating security throughout the pipeline is correct.<\/span><\/p>\n<h3><b>Question 14<\/b><\/h3>\n<p><b>Which security architecture combines networking capabilities with cloud-delivered security services to provide secure access for users regardless of their location?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SASE<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RAID<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">STP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Secure Access Service Edge, or SASE, combines networking capabilities with cloud-delivered security services to provide secure access to applications and resources. It is designed for environments where users, devices, applications, and workloads may be distributed across offices, data centers, and cloud platforms. Security capabilities can be delivered closer to users instead of requiring all traffic to return to a traditional corporate perimeter. SSE focuses specifically on security services, while SASE combines those security capabilities with networking functionality. Therefore, SASE is the broader architecture described.<\/span><\/p>\n<h3><b>Question 15<\/b><\/h3>\n<p><b>Which endpoint security technology continuously monitors endpoint activity to detect suspicious behavior and support investigation and response?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MDM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">EDR<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CASB<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Endpoint Detection and Response, or EDR, continuously monitors endpoint activity and collects security-related telemetry that can be analyzed for suspicious behavior. EDR platforms can help security teams investigate incidents, identify malicious activity, and support response actions on affected endpoints. Endpoint Protection Platforms generally focus more broadly on preventing malware and other threats, while EDR emphasizes detection, investigation, and response capabilities. MDM focuses on managing mobile devices, DHCP provides network configuration, and CASB addresses cloud-service security. Therefore, EDR is the correct technology.<\/span><\/p>\n<h3><b>Question 16<\/b><\/h3>\n<p><b>Which technology allows an organization to centrally manage mobile devices, enforce configuration policies, and control organizational data on supported endpoints?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MDM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">EDR<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IDS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Mobile Device Management, or MDM, enables organizations to centrally manage supported mobile endpoints. Administrators can use MDM to enforce configuration requirements, distribute applications, apply security policies, manage device settings, and support organizational control over corporate data. MDM can also assist with device inventory and compliance management. EDR focuses on endpoint threat detection and response, IDS monitors for suspicious network activity, and NTP synchronizes system time. Therefore, MDM is the technology designed for centralized management of mobile devices and their configurations.<\/span><\/p>\n<h3><b>Question 17<\/b><\/h3>\n<p><b>Which network access-control method requires a device or user to authenticate before gaining access to a controlled switch port?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">802.1X<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">802.1X provides port-based network access control by requiring authentication before a device is granted access to a protected network connection. It commonly works with an authentication server such as Cisco Identity Services Engine and can use protocols such as EAP to exchange authentication information. This allows organizations to make access decisions based on user or device identity and related policy information. NAT translates addresses, DHCP provides IP configuration, and DNS resolves names. Therefore, 802.1X is the appropriate mechanism for authenticated switch-port access.<\/span><\/p>\n<h3><b>Question 18<\/b><\/h3>\n<p><b>A security administrator needs to change an endpoint&#8217;s authorization state immediately after a security policy decision without requiring the device to reconnect physically. Which capability can be used with Cisco ISE?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNSSEC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CoA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">GRE<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Change of Authorization, or CoA, allows a network access-control system such as Cisco Identity Services Engine to dynamically change the authorization state of an active endpoint. This capability can be useful when a device&#8217;s security posture changes after authentication or when policy enforcement requires an immediate adjustment. For example, an endpoint could be moved to a restricted access state after failing a compliance check. DNSSEC protects DNS information, NAT translates addresses, and GRE provides tunneling. Therefore, CoA provides the required dynamic authorization change.<\/span><\/p>\n<h3><b>Question 19<\/b><\/h3>\n<p><b>An attacker hides command-and-control or data-transfer traffic inside DNS queries and responses to bypass some traditional network controls. Which exfiltration technique is being used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS tunneling<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN hopping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ARP spoofing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MAC flooding<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">DNS tunneling is a technique in which an attacker encodes information or commands within DNS queries and responses. Because DNS traffic is commonly permitted through network security controls, attackers may attempt to use it as a covert channel for command-and-control communication or data exfiltration. Security monitoring can look for unusual DNS patterns, excessive query volumes, abnormal domain structures, and other indicators. VLAN hopping targets Layer 2 segmentation, ARP spoofing manipulates address resolution, and MAC flooding attacks switch forwarding behavior. Therefore, DNS tunneling matches the scenario.<\/span><\/p>\n<h3><b>Question 20<\/b><\/h3>\n<p><b>Which security platform category is primarily designed to collect, correlate, and analyze security events from multiple sources to support centralized detection and response?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MDM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CASB<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SIEM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Security Information and Event Management, or SIEM, platform collects and correlates security events from multiple sources such as network devices, endpoints, applications, and security appliances. Centralized analysis can help security teams identify patterns that may not be obvious when individual events are reviewed separately. SIEM platforms can support alerting, investigation, compliance reporting, and incident response workflows. MDM manages endpoints, CASB focuses on cloud-service security, and DHCP provides network configuration. Therefore, SIEM is the appropriate platform category for centralized security-event analysis.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco 350-701 Exam Dumps and Practice Test Dumps. &nbsp; Question 1 Which security architecture assumes that users and devices should not automatically be trusted simply because they are located inside an organization&#8217;s network? Defense in depth Zero trust Network address translation Perimeter-only security Correct Answer: 2 Explanation Zero trust is a security architecture [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20894"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=20894"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20894\/revisions"}],"predecessor-version":[{"id":20895,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20894\/revisions\/20895"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=20894"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=20894"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=20894"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}