{"id":20902,"date":"2026-09-24T09:06:24","date_gmt":"2026-09-24T09:06:24","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=20902"},"modified":"2026-09-24T09:06:24","modified_gmt":"2026-09-24T09:06:24","slug":"cisco-ccie-security-350-701-practice-test-questions-and-exam-dumps-part5-q81-100","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-ccie-security-350-701-practice-test-questions-and-exam-dumps-part5-q81-100\/","title":{"rendered":"Cisco CCIE Security 350-701 Practice Test Questions and Exam Dumps Part5 Q81-100"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/350-701-exam-dumps\"><b>Cisco 350-701 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 81<\/b><\/h3>\n<p><b>Which IPsec mode encrypts the original IP packet and adds a new IP header for routing across an untrusted network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tunnel mode<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Transport mode<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Broadcast mode<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Access mode<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">IPsec tunnel mode encapsulates the entire original IP packet, including its original IP header, inside a new IPsec packet. A new outer IP header is added so that the protected packet can be routed between VPN endpoints. This mode is commonly used for site-to-site VPNs because the original internal addressing can remain protected while traffic crosses an external network. Transport mode protects the payload of the original IP packet while retaining the original IP header. Therefore, tunnel mode provides the encapsulation described.<\/span><\/p>\n<h3><b>Question 82<\/b><\/h3>\n<p><b>A company wants to ensure that employees cannot authenticate to internal applications unless their endpoint meets defined security requirements. Which capability addresses this requirement?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS filtering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device posture assessment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic shaping<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Device posture assessment evaluates the security state of an endpoint before or during access authorization. Checks can include operating-system status, security software, patch levels, configuration settings, or other organizational requirements. An access-control system can use the resulting posture information to permit, restrict, or deny access. DNS filtering controls name-resolution or web destinations, static NAT maps addresses, and traffic shaping manages bandwidth usage. Therefore, device posture assessment is the capability that determines whether an endpoint satisfies required security conditions before receiving access.<\/span><\/p>\n<h3><b>Question 83<\/b><\/h3>\n<p><b>Which Cisco technology provides application-aware visibility by identifying applications rather than relying only on IP addresses and ports?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco AVC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco HSRP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco VRF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco GLBP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cisco Application Visibility and Control, or AVC, provides deeper visibility into network applications by identifying application traffic and providing information that can be used for policy enforcement and monitoring. Traditional controls based only on IP addresses and ports may not distinguish different applications using the same transport mechanisms. Application-aware visibility can therefore support more granular security and quality-of-service decisions. HSRP and GLBP provide gateway redundancy, while VRF separates routing tables. Therefore, Cisco AVC provides the application-level visibility described.<\/span><\/p>\n<h3><b>Question 84<\/b><\/h3>\n<p><b>Which security mechanism allows an organization to revoke a digital certificate before its scheduled expiration date?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate pinning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate revocation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Key stretching<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tokenization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Certificate revocation allows a certificate authority to invalidate a certificate before its normal expiration date. This may be necessary if a private key is compromised, the certificate was issued incorrectly, or the identity associated with the certificate should no longer be trusted. Certificate revocation information can be distributed through mechanisms such as Certificate Revocation Lists and Online Certificate Status Protocol. Certificate pinning addresses trust relationships, key stretching strengthens password-derived keys, and tokenization replaces sensitive data with tokens. Therefore, certificate revocation provides the required capability.<\/span><\/p>\n<h3><b>Question 85<\/b><\/h3>\n<p><b>Which firewall policy element determines whether traffic is permitted or denied based on defined source, destination, application, and other attributes?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Access control rule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS record<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Routing metric<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP scope<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An access control rule defines how a firewall handles traffic that matches specified conditions. Depending on the firewall platform, these conditions can include source and destination addresses, users, applications, ports, protocols, URLs, security zones, and other attributes. The rule can then permit, deny, or otherwise process matching traffic according to the security policy. DNS records provide name-resolution information, routing metrics influence path selection, and DHCP scopes provide address configuration. Therefore, an access control rule is the policy element responsible for making the described traffic decision.<\/span><\/p>\n<h3><b>Question 86<\/b><\/h3>\n<p><b>Which security technique attempts to deceive users into revealing credentials by presenting a fraudulent message or website that appears legitimate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port scanning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Phishing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MAC flooding<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Packet fragmentation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Phishing is a social-engineering technique in which attackers use deceptive messages, websites, or other communication methods to persuade victims to disclose sensitive information or perform unsafe actions. Attackers may imitate trusted organizations and use urgency or convincing branding to make fraudulent requests appear legitimate. Technical controls such as secure email gateways, URL filtering, multifactor authentication, and user awareness training can reduce the impact of phishing. Port scanning discovers services, MAC flooding targets switch tables, and packet fragmentation concerns packet structure. Therefore, phishing matches the scenario.<\/span><\/p>\n<h3><b>Question 87<\/b><\/h3>\n<p><b>Which security feature helps limit the number of MAC addresses that can be learned on a switch port?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IP SLA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">OSPF authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNSSEC<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Switch port security can limit the number of MAC addresses permitted on an interface and can define how the switch responds when unauthorized addresses are detected. This is useful on access ports where the expected number of connected devices is known. It can help reduce unauthorized physical connections and certain Layer 2 attacks involving unexpected source MAC addresses. IP SLA measures network performance, OSPF authentication protects routing-protocol exchanges, and DNSSEC protects DNS information. Therefore, port security provides the MAC-address restriction described.<\/span><\/p>\n<h3><b>Question 88<\/b><\/h3>\n<p><b>Which technology provides cryptographic protection for DNS responses so that clients can verify that DNS data has not been altered?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNSSEC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">GRE<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LLDP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">DNS Security Extensions, or DNSSEC, add authentication and integrity protection to DNS data through digitally signed records. DNSSEC helps clients validate that received DNS information originated from the appropriate authoritative source and has not been modified during transit. This can reduce the risk of attacks that manipulate DNS responses and redirect users to unauthorized destinations. DNSSEC does not encrypt ordinary DNS queries by itself; its primary purpose is authentication and integrity. FTP provides file transfer, GRE provides tunneling, and LLDP exchanges device information. Therefore, DNSSEC is the correct technology.<\/span><\/p>\n<h3><b>Question 89<\/b><\/h3>\n<p><b>Which security technology can enforce policy based on a user&#8217;s identity and group membership instead of relying only on the user&#8217;s IP address?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identity-based policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route redistribution<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Link aggregation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Packet fragmentation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Identity-based policy uses information about a user or device identity to determine which resources or services should be accessible. This approach can provide more consistent policy enforcement because a user&#8217;s permissions can remain associated with the identity even when the user changes network locations or receives a different IP address. Identity information may be obtained through authentication and integrated with directory services or access-control platforms. Route redistribution manages routing information, link aggregation combines interfaces, and packet fragmentation divides packets. Therefore, identity-based policy is the appropriate approach.<\/span><\/p>\n<h3><b>Question 90<\/b><\/h3>\n<p><b>Which security technology can isolate a compromised endpoint from other network resources while still allowing security personnel to investigate it?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Endpoint isolation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT overload<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS caching<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Link aggregation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Endpoint isolation restricts an affected device&#8217;s network communication to contain a suspected compromise and reduce the opportunity for lateral movement. Modern endpoint security platforms can isolate a host while maintaining a controlled communication path for security-management functions, allowing analysts to investigate processes, files, connections, and other evidence. NAT overload translates multiple private addresses through a shared public address, DNS caching stores name-resolution results, and link aggregation combines physical interfaces. Therefore, endpoint isolation provides the containment capability described.<\/span><\/p>\n<h3><b>Question 91<\/b><\/h3>\n<p><b>Which authentication method requires a user to provide two or more independent types of evidence before access is granted?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Multifactor authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single sign-on<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password synchronization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Account federation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Multifactor authentication, or MFA, requires authentication using multiple independent factor categories, such as something the user knows, something the user has, or something the user is. For example, a password combined with a hardware security key uses two different factor types. MFA can reduce the impact of stolen passwords because possession of the password alone is insufficient for successful authentication. Single sign-on simplifies access across applications, while password synchronization and federation address identity-management relationships. Therefore, multifactor authentication provides the described protection.<\/span><\/p>\n<h3><b>Question 92<\/b><\/h3>\n<p><b>Which network attack attempts to overwhelm a switch&#8217;s CAM table with numerous fabricated MAC addresses?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP starvation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CAM table overflow<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS poisoning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Credential stuffing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A CAM table overflow attack attempts to fill a switch&#8217;s Content Addressable Memory table with large numbers of fabricated source MAC addresses. When the table becomes unable to maintain legitimate mappings, the switch may flood certain frames in ways that can expose traffic to an attacker connected to the same Layer 2 environment. Port security and appropriate switch protections can help reduce this risk. DHCP starvation consumes address pools, DNS poisoning manipulates name resolution, and credential stuffing uses previously compromised credentials. Therefore, CAM table overflow matches the described attack.<\/span><\/p>\n<h3><b>Question 93<\/b><\/h3>\n<p><b>Which security protocol can provide encryption and integrity protection for traffic between IPsec peers after security associations have been established?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ESP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ICMP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ARP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Encapsulating Security Payload, or ESP, protects IP traffic after IPsec security associations have been established. Depending on the configuration, ESP can provide confidentiality through encryption, integrity authentication, and anti-replay protection. IKE is responsible for negotiating the security associations and cryptographic parameters, while ESP carries the protected traffic itself. ICMP supports control and diagnostic messaging, ARP resolves IPv4 addresses to MAC addresses, and DHCP provides host configuration. Therefore, ESP is the protocol that provides the requested protection for IPsec data traffic.<\/span><\/p>\n<h3><b>Question 94<\/b><\/h3>\n<p><b>Which security control can restrict access to a network based on whether a device has current security software and required configuration settings?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device posture policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route summarization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT exemption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS recursion<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A device posture policy evaluates endpoint characteristics against defined security requirements before allowing or continuing network access. Organizations may check whether security software is installed and active, whether operating-system patches are current, or whether specific configuration requirements are satisfied. Devices that fail the required posture can be denied, quarantined, or assigned restricted access depending on the network-access design. Route summarization reduces routing-table information, NAT exemption changes address-translation behavior, and DNS recursion handles name-resolution requests. Therefore, device posture policy provides the described security control.<\/span><\/p>\n<h3><b>Question 95<\/b><\/h3>\n<p><b>Which Cisco security solution provides threat intelligence that can help identify malicious domains, IP addresses, and other indicators associated with known threats?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco Talos<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco HSRP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco StackWise<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco EtherChannel<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cisco Talos is Cisco&#8217;s threat-intelligence organization and provides research and intelligence related to cyber threats, malicious infrastructure, vulnerabilities, and attack techniques. Security products can use threat intelligence to improve detection and blocking decisions involving indicators such as malicious domains, IP addresses, files, and other artifacts. HSRP provides gateway redundancy, StackWise supports switch stacking, and EtherChannel combines multiple physical links. Therefore, Cisco Talos is the threat-intelligence capability described. Threat intelligence is most effective when integrated with appropriate prevention, detection, and response controls.<\/span><\/p>\n<h3><b>Question 96<\/b><\/h3>\n<p><b>Which security practice helps ensure that a firewall or network device is running only the services and protocols required for its intended role?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service minimization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic mirroring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route redistribution<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Packet fragmentation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Service minimization is a hardening practice that removes or disables unnecessary services, protocols, interfaces, and features from a device. Reducing the attack surface makes fewer network-accessible functions available to attackers and can decrease the number of vulnerabilities that require management. Administrators should retain only the capabilities needed for the device&#8217;s intended role and keep necessary services securely configured. Traffic mirroring copies packets for analysis, route redistribution exchanges routes between protocols, and packet fragmentation divides packets. Therefore, service minimization is the appropriate hardening practice.<\/span><\/p>\n<h3><b>Question 97<\/b><\/h3>\n<p><b>Which security mechanism can detect unauthorized changes to a file by comparing its current cryptographic digest with a previously trusted value?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File integrity monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP relay<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT traversal<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">File integrity monitoring can detect unauthorized changes by calculating a cryptographic hash or similar integrity value for a file and comparing it with a known trusted value. If the values differ unexpectedly, the security system can generate an alert for investigation. This approach is useful for monitoring critical system files, configuration files, and other sensitive resources. Load balancing distributes application traffic, DHCP relay forwards configuration requests, and NAT traversal assists certain VPN connections through address translation. Therefore, file integrity monitoring provides the described detection capability.<\/span><\/p>\n<h3><b>Question 98<\/b><\/h3>\n<p><b>Which type of attack attempts to exploit excessive permissions so that a compromised account can gain access to resources beyond its authorized role?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Privilege escalation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Packet sniffing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS tunneling<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port scanning<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Privilege escalation occurs when an attacker gains permissions beyond those originally assigned to a compromised account or process. Vertical privilege escalation may involve obtaining higher-level privileges, while horizontal escalation can involve accessing resources belonging to another user with similar privilege levels. Excessive permissions, vulnerable applications, weak configurations, and stolen administrative credentials can contribute to these attacks. Packet sniffing focuses on capturing traffic, DNS tunneling abuses DNS for communication or data transfer, and port scanning identifies exposed services. Therefore, privilege escalation matches the described activity.<\/span><\/p>\n<h3><b>Question 99<\/b><\/h3>\n<p><b>Which technology can provide secure communication between applications by using encryption and server authentication at the transport layer?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TLS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ARP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ICMP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">STP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Transport Layer Security, or TLS, provides cryptographic protection for application communications. It can encrypt transmitted data, authenticate a server through digital certificates, and provide integrity protection against unauthorized modification. TLS is widely used by protocols and applications such as HTTPS and can also protect other application-layer communications. ARP performs local address resolution, ICMP provides control and diagnostic messages, and STP prevents Layer 2 switching loops. Therefore, TLS provides the secure transport-layer communication capability described.<\/span><\/p>\n<h3><b>Question 100<\/b><\/h3>\n<p><b>Which security architecture assumes that users and devices should not automatically be trusted simply because they are connected to an internal network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Perimeter-only security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Zero Trust<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static segmentation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Zero Trust is a security architecture based on the principle that network location alone should not establish trust. Users, devices, applications, and requests should be evaluated using appropriate identity, security posture, context, and authorization information before access is granted. Access should also be limited to the resources necessary for the user&#8217;s or device&#8217;s role, and trust decisions may be continuously evaluated. This approach differs from traditional perimeter-only models that may implicitly trust traffic originating inside a network. Therefore, Zero Trust matches the described architecture.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco 350-701 Exam Dumps and Practice Test Dumps. &nbsp; Question 81 Which IPsec mode encrypts the original IP packet and adds a new IP header for routing across an untrusted network? Tunnel mode Transport mode Broadcast mode Access mode Correct Answer: 1 Explanation IPsec tunnel mode encapsulates the entire original IP packet, including [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20902"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=20902"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20902\/revisions"}],"predecessor-version":[{"id":20903,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20902\/revisions\/20903"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=20902"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=20902"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=20902"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}