{"id":20904,"date":"2026-09-24T09:07:00","date_gmt":"2026-09-24T09:07:00","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=20904"},"modified":"2026-09-24T09:07:00","modified_gmt":"2026-09-24T09:07:00","slug":"cisco-ccie-security-350-701-practice-test-questions-and-exam-dumps-part6-q101-120","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-ccie-security-350-701-practice-test-questions-and-exam-dumps-part6-q101-120\/","title":{"rendered":"Cisco CCIE Security 350-701 Practice Test Questions and Exam Dumps Part6 Q101-120"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/350-701-exam-dumps\"><b>Cisco 350-701 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 101<\/b><\/h3>\n<p><b>Which Cisco security feature can restrict traffic entering a switch port based on the source IP address and associated DHCP binding information?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IP Source Guard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SPAN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">EtherChannel<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HSRP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">IP Source Guard helps prevent source IP address spoofing on Layer 2 access networks. It can use trusted binding information, commonly learned through DHCP snooping, to determine which source IP address is valid for a particular switch port. Traffic using an unauthorized source address can then be filtered. This provides an additional protection layer against hosts attempting to impersonate another address. SPAN copies traffic for monitoring, EtherChannel combines links, and HSRP provides gateway redundancy. Therefore, IP Source Guard is the appropriate feature for this scenario.<\/span><\/p>\n<h3><b>Question 102<\/b><\/h3>\n<p><b>An administrator needs to inspect traffic exchanged between two network devices without changing the forwarding behavior of the original traffic. Which monitoring method should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SPAN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VRF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP relay<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Switched Port Analyzer, or SPAN, copies selected traffic from one or more source interfaces or VLANs to a designated destination interface where a monitoring or security-analysis device can receive it. The copied traffic allows administrators to inspect packets without directly placing the monitoring device in the production forwarding path. SPAN is commonly used for troubleshooting, intrusion analysis, and packet inspection. NAT translates addresses, VRF provides separate routing tables, and DHCP relay forwards DHCP requests. Therefore, SPAN is the appropriate monitoring method.<\/span><\/p>\n<h3><b>Question 103<\/b><\/h3>\n<p><b>Which security mechanism helps ensure that a routing protocol neighbor is an authenticated and trusted peer?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route summarization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Routing protocol authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT overload<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Routing protocol authentication allows routers to verify that routing updates are received from trusted peers rather than unauthorized devices. Depending on the routing protocol and configuration, authentication can use cryptographic mechanisms to protect routing exchanges and prevent attackers from injecting unauthorized routing information. This is important because manipulated routing updates can redirect traffic, create outages, or enable interception. Route summarization reduces routing-table size, load balancing distributes traffic, and NAT overload translates multiple private addresses. Therefore, routing protocol authentication provides the required security function.<\/span><\/p>\n<h3><b>Question 104<\/b><\/h3>\n<p><b>Which security control can detect repeated failed login attempts and generate an alert when an account appears to be under attack?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Login event monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN trunking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Packet fragmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route redistribution<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Login event monitoring collects and analyzes authentication events to identify suspicious patterns such as repeated failed attempts, unusual login locations, impossible travel patterns, or abnormal authentication times. Security teams can use these events to detect password attacks and investigate potentially compromised accounts. Monitoring becomes more effective when authentication logs are centralized and correlated with other security telemetry. VLAN trunking transports multiple VLANs, packet fragmentation divides packets, and route redistribution exchanges routes between routing protocols. Therefore, login event monitoring is the appropriate control for detecting repeated authentication failures.<\/span><\/p>\n<h3><b>Question 105<\/b><\/h3>\n<p><b>Which Cisco Secure Firewall capability can inspect files transferred through supported network traffic and apply malware-related security policies?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File and malware inspection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HSRP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VRRP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LLDP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">File and malware inspection capabilities allow security controls to examine supported files moving through network traffic and apply security policies based on detected threats. This can help identify malicious content before it reaches internal users or systems. Depending on the deployment, file policies can be associated with access-control policies to determine which files should be monitored, blocked, or further analyzed. HSRP and VRRP provide gateway redundancy, while LLDP exchanges information about directly connected network devices. Therefore, file and malware inspection provides the described security capability.<\/span><\/p>\n<h3><b>Question 106<\/b><\/h3>\n<p><b>Which security technique separates routing information into independent logical tables on the same physical router?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VRF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MACsec<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TLS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CoPP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Virtual Routing and Forwarding, or VRF, allows multiple independent routing tables to exist on the same physical device. Each VRF can maintain separate routes and forwarding decisions, which helps isolate traffic between different organizations, departments, tenants, or security zones. VRF is particularly useful in service-provider and enterprise segmentation designs. MACsec protects Layer 2 traffic, TLS protects application communications, and CoPP protects the control plane. Therefore, VRF is the technology that provides independent logical routing tables on the same device.<\/span><\/p>\n<h3><b>Question 107<\/b><\/h3>\n<p><b>Which security concept requires an organization to identify systems, applications, and devices before determining how they should be protected?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Asset inventory<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic shaping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Packet switching<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route filtering<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An asset inventory identifies the systems, applications, devices, services, and other resources that exist within an organization&#8217;s environment. Knowing what assets are present is fundamental to security because organizations cannot effectively protect resources that they do not know about. Inventory information can support vulnerability management, patching, risk assessment, access control, and incident response. Traffic shaping manages bandwidth, packet switching forwards network traffic, and route filtering controls routing information. Therefore, asset inventory is the appropriate security practice for identifying resources before protection decisions are made.<\/span><\/p>\n<h3><b>Question 108<\/b><\/h3>\n<p><b>Which attack uses a malicious wireless access point designed to imitate a legitimate network so that users connect to it?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Evil twin attack<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CAM overflow<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL injection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS amplification<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An evil twin attack uses a rogue wireless access point that imitates a legitimate Wi-Fi network. Unsuspecting users may connect to the malicious access point because its network name or other characteristics appear familiar. Once connected, attackers may attempt to capture credentials, inspect traffic, redirect users, or perform additional attacks. Wireless security controls, certificate validation, user awareness, and proper authentication can reduce this risk. CAM overflow targets switch forwarding tables, SQL injection targets applications, and DNS amplification is a denial-of-service technique. Therefore, an evil twin attack matches the scenario.<\/span><\/p>\n<h3><b>Question 109<\/b><\/h3>\n<p><b>Which security control can help prevent unauthorized devices from communicating through an unused physical switch port?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable unused switch ports<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Enable unrestricted trunking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permit all VLANs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Disabling unused switch ports is a basic network-device hardening practice that reduces opportunities for unauthorized physical connections. An unused port that remains active may allow an attacker who gains physical access to connect a device to the network. Administrators can disable unused interfaces and document their status so that they can be enabled only when legitimately required. Unrestricted trunking can increase exposure to VLAN-related attacks, disabling authentication weakens access control, and permitting all VLANs can unnecessarily expand connectivity. Therefore, disabling unused switch ports is the appropriate control.<\/span><\/p>\n<h3><b>Question 110<\/b><\/h3>\n<p><b>Which security capability allows an organization to automatically respond to detected threats by executing predefined actions?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security automation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Manual auditing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Address translation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security automation enables predefined or dynamically triggered actions to occur when specific security conditions are detected. Automated responses may include blocking an indicator, isolating an endpoint, creating an incident ticket, changing an access policy, or notifying security personnel. Automation can reduce response time and help security teams handle repetitive tasks consistently, although actions should be carefully designed to avoid disrupting legitimate activity. Manual auditing requires human intervention, static routing controls packet paths, and address translation changes addressing information. Therefore, security automation provides the described capability.<\/span><\/p>\n<h3><b>Question 111<\/b><\/h3>\n<p><b>Which protocol is commonly used to securely exchange configuration and operational data with network devices through a structured XML-based model?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NETCONF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Telnet<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TFTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RARP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">NETCONF is a network-management protocol designed for securely installing, manipulating, and retrieving configuration information from network devices. It commonly uses XML-based data structures and can operate over secure transport such as SSH. NETCONF supports structured configuration management and is useful in automation environments where administrators need consistent and programmatic control over infrastructure. Telnet provides insecure remote access, TFTP provides basic file transfer, and RARP is an older address-resolution mechanism. Therefore, NETCONF is the protocol that matches the described configuration-management requirement.<\/span><\/p>\n<h3><b>Question 112<\/b><\/h3>\n<p><b>Which technology allows applications to communicate with network infrastructure programmatically using HTTP-based requests and structured data?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">REST API<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">STP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ARP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LACP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A REST API allows applications and automation tools to interact programmatically with network or security platforms using HTTP-based requests. Resources can typically be accessed or modified through methods such as GET, POST, PUT, PATCH, and DELETE, depending on the API implementation. Structured formats such as JSON are commonly used to exchange data. This approach supports automation, integration, orchestration, and custom security workflows. STP prevents switching loops, ARP resolves local addresses, and LACP negotiates link aggregation. Therefore, REST API technology provides the described programmatic interface.<\/span><\/p>\n<h3><b>Question 113<\/b><\/h3>\n<p><b>Which security control can help ensure that a network device accepts management connections only through encrypted protocols?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Management-plane hardening<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route redistribution<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS caching<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Packet fragmentation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Management-plane hardening protects administrative access to network infrastructure by restricting available management protocols and enforcing secure alternatives. For example, administrators can disable insecure protocols such as Telnet and use SSH instead, restrict management access to trusted networks, apply authentication and authorization controls, and log administrative activity. This reduces the risk of credential interception and unauthorized device configuration. Route redistribution manages routing information, DNS caching stores name-resolution data, and packet fragmentation changes packet structure. Therefore, management-plane hardening addresses secure management access.<\/span><\/p>\n<h3><b>Question 114<\/b><\/h3>\n<p><b>Which technology can identify malicious network behavior by analyzing packet contents and traffic patterns and then actively block matching traffic?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IDS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Syslog<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NetFlow collector<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An Intrusion Prevention System, or IPS, analyzes network traffic for known attack signatures, suspicious patterns, protocol anomalies, and other indicators of malicious behavior. Unlike a passive intrusion detection system, an IPS can take preventive action when a threat is identified, such as dropping or blocking the offending traffic. Syslog collects event messages, while a NetFlow collector analyzes flow records rather than directly blocking packets. IDS traditionally focuses on detection and alerting. Therefore, IPS is the technology that combines traffic inspection with active prevention.<\/span><\/p>\n<h3><b>Question 115<\/b><\/h3>\n<p><b>Which security technology can protect sensitive information by replacing the original data value with a non-sensitive substitute that has no exploitable meaning by itself?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tokenization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Packet filtering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route poisoning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic mirroring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Tokenization replaces sensitive data with a token that can be used in systems without exposing the original value. The token itself generally has no meaningful value outside the controlled tokenization system, while the sensitive data is stored separately under appropriate protection. Tokenization can be used for payment information and other sensitive data where reducing exposure is important. Packet filtering controls network traffic, route poisoning is a routing-related technique, and traffic mirroring copies packets for analysis. Therefore, tokenization is the data-protection technology described.<\/span><\/p>\n<h3><b>Question 116<\/b><\/h3>\n<p><b>Which security mechanism can help detect whether a packet has been replayed by an attacker after it was previously captured from a legitimate session?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anti-replay protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS caching<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP relay<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Anti-replay protection helps prevent attackers from capturing legitimate protected packets and transmitting them again later. IPsec can use sequence numbers and replay-detection mechanisms to identify packets that fall outside an acceptable sequence window or have already been processed. This helps prevent previously valid traffic from being reused to produce unauthorized effects. DNS caching stores name-resolution results, load balancing distributes application traffic, and DHCP relay forwards configuration requests. Therefore, anti-replay protection provides the security function required to detect and reject replayed packets.<\/span><\/p>\n<h3><b>Question 117<\/b><\/h3>\n<p><b>Which security architecture extends security controls closer to users, devices, applications, and cloud services rather than relying exclusively on a centralized corporate perimeter?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SASE<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">STP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN trunking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static NAT<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Secure Access Service Edge, or SASE, combines networking and security capabilities through a cloud-delivered architecture that can apply security controls closer to users, devices, applications, and services. This model supports distributed organizations where users and applications may operate outside traditional corporate network boundaries. SASE commonly brings together capabilities associated with secure access and cloud-based security enforcement. STP prevents switching loops, VLAN trunking transports multiple VLANs, and static NAT performs address translation. Therefore, SASE is the architecture described.<\/span><\/p>\n<h3><b>Question 118<\/b><\/h3>\n<p><b>Which security control is designed to prevent a device from connecting to a wireless network unless it successfully authenticates through the organization&#8217;s approved access-control system?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">802.1X<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port mirroring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">GRE<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VRF<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">802.1X provides port-based network access control and can be used with wired or wireless environments to require authentication before granting normal network access. In enterprise wireless deployments, the wireless client can authenticate through an access point and centralized authentication infrastructure before receiving authorized connectivity. This allows organizations to apply identity-based policies and restrict unauthorized devices. Port mirroring copies traffic, GRE provides tunneling, and VRF separates routing tables. Therefore, 802.1X is the access-control mechanism described.<\/span><\/p>\n<h3><b>Question 119<\/b><\/h3>\n<p><b>Which cloud security practice continuously evaluates cloud resources for insecure configurations such as publicly exposed storage or overly permissive access policies?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CSPM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">STP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MACsec<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud Security Posture Management, or CSPM, helps organizations identify and remediate security risks caused by misconfigured cloud resources. CSPM tools can evaluate cloud environments for issues such as publicly exposed storage, excessive permissions, insecure network settings, missing controls, and policy violations. Continuous posture assessment is important because cloud configurations can change rapidly through both administrators and automation. STP addresses Layer 2 loops, MACsec protects Ethernet traffic, and NAT translates network addresses. Therefore, CSPM is the cloud-security practice described.<\/span><\/p>\n<h3><b>Question 120<\/b><\/h3>\n<p><b>Which security control can restrict communication between workloads even when those workloads are hosted within the same broader cloud or data-center environment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsegmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS recursion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Link aggregation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route summarization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsegmentation applies granular security policies between workloads, applications, users, or devices, even when they operate within the same data center or cloud environment. Instead of treating an internal network as one trusted zone, microsegmentation can restrict which workloads are allowed to communicate and on which ports or protocols. This helps reduce lateral movement after a compromise. DNS recursion handles name resolution, link aggregation combines physical links, and route summarization reduces routing information. Therefore, microsegmentation provides the granular workload-to-workload isolation described.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco 350-701 Exam Dumps and Practice Test Dumps. &nbsp; Question 101 Which Cisco security feature can restrict traffic entering a switch port based on the source IP address and associated DHCP binding information? IP Source Guard SPAN EtherChannel HSRP Correct Answer: 1 Explanation IP Source Guard helps prevent source IP address spoofing on [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20904"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=20904"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20904\/revisions"}],"predecessor-version":[{"id":20905,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20904\/revisions\/20905"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=20904"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=20904"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=20904"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}