{"id":20906,"date":"2026-09-24T09:07:20","date_gmt":"2026-09-24T09:07:20","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=20906"},"modified":"2026-09-24T09:18:41","modified_gmt":"2026-09-24T09:18:41","slug":"cisco-ccie-security-350-701-practice-test-questions-and-exam-dumps-part6-q101-120-2","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-ccie-security-350-701-practice-test-questions-and-exam-dumps-part6-q101-120-2\/","title":{"rendered":"Cisco CCIE Security 350-701 Practice Test Questions and Exam Dumps Part7 Q121-140"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/350-701-exam-dumps\"><b>Cisco 350-701 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 121<\/b><\/h3>\n<p><b>Which IPsec protocol is responsible for negotiating authentication, encryption, and integrity parameters before protected traffic is exchanged?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ESP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IKE<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ARP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">GRE<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Internet Key Exchange, or IKE, negotiates the security parameters required for an IPsec connection. During the negotiation process, peers authenticate each other and agree on cryptographic algorithms, keying material, and other parameters used to establish security associations. IKEv2 is commonly deployed for modern IPsec VPN implementations. ESP subsequently protects the actual user traffic, while ARP performs local address resolution and GRE provides tunneling without inherently providing encryption. Therefore, IKE is responsible for negotiating the security parameters before protected IPsec traffic is transmitted.<\/span><\/p>\n<h3><b>Question 122<\/b><\/h3>\n<p><b>A security engineer wants to prevent unauthorized IPv4 DHCP servers from responding to clients on an access-layer switch. Which feature should be configured?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP snooping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNSSEC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CoPP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MACsec<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">DHCP snooping helps protect an IPv4 network from rogue DHCP servers by distinguishing trusted and untrusted switch interfaces. DHCP server responses received on untrusted interfaces can be blocked, preventing unauthorized devices from assigning misleading network configuration to clients. DHCP snooping can also build binding information that other security features can use for additional protection. DNSSEC protects DNS data, CoPP protects the control plane, and MACsec provides Layer 2 encryption. Therefore, DHCP snooping is the appropriate feature for preventing rogue DHCP server responses.<\/span><\/p>\n<h3><b>Question 123<\/b><\/h3>\n<p><b>Which security function analyzes network traffic against predefined signatures and generates alerts without directly blocking the detected traffic?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DLP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IDS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAC<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An Intrusion Detection System, or IDS, monitors network traffic and analyzes it for indicators of malicious activity, including known attack signatures and suspicious patterns. When an event matches a detection rule, the IDS generates an alert so security personnel or another security system can investigate it. Unlike an IPS, an IDS is primarily designed for detection and notification rather than direct traffic blocking. DLP focuses on sensitive-data protection, while NAC controls network access. Therefore, IDS is the technology described in this scenario.<\/span><\/p>\n<h3><b>Question 124<\/b><\/h3>\n<p><b>Which security control helps ensure that only authorized applications can execute on a managed endpoint?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application allowlisting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network Address Translation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route filtering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS caching<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application allowlisting restricts software execution to applications that have been explicitly approved by an organization. This can prevent unauthorized or malicious executables from running even when they reach an endpoint through phishing, downloads, removable media, or other channels. Depending on the implementation, policies can identify trusted applications using hashes, signatures, paths, publishers, or other attributes. NAT translates addresses, route filtering controls routing information, and DNS caching stores previously resolved names. Therefore, application allowlisting provides the required endpoint execution control.<\/span><\/p>\n<h3><b>Question 125<\/b><\/h3>\n<p><b>Which security mechanism allows a firewall to inspect encrypted HTTPS traffic by decrypting and then re-encrypting the session?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS tunneling<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SSL\/TLS inspection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP relay<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">SSL\/TLS inspection allows a security device to decrypt protected application traffic, inspect its contents, and then establish or continue an encrypted session toward the destination. This provides security controls with visibility into threats that could otherwise remain hidden inside encrypted HTTPS connections. Proper certificate handling and privacy policies are important because the security device temporarily has access to decrypted content. DNS tunneling abuses DNS for communication, port security restricts Layer 2 access, and DHCP relay forwards DHCP requests. Therefore, SSL\/TLS inspection provides the described capability.<\/span><\/p>\n<h3><b>Question 126<\/b><\/h3>\n<p><b>Which cloud security model requires the cloud provider to protect the underlying physical infrastructure while the customer remains responsible for configured resources and data according to the service model?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared responsibility model<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Zero Trust model<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Bell-LaPadula model<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Clark-Wilson model<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The shared responsibility model divides security responsibilities between the cloud provider and the customer. The provider is generally responsible for security of the underlying cloud infrastructure, while customers remain responsible for aspects such as their data, identities, configurations, and workloads depending on the specific cloud service. The exact division changes between IaaS, PaaS, and SaaS. Zero Trust concerns access decisions, while Bell-LaPadula and Clark-Wilson are information-security models. Therefore, the shared responsibility model describes the division of cloud security obligations.<\/span><\/p>\n<h3><b>Question 127<\/b><\/h3>\n<p><b>Which cryptographic mechanism uses a private key to create a signature that can be verified with the corresponding public key?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Symmetric encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Digital signature<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hash collision<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tokenization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A digital signature uses asymmetric cryptography to provide evidence that data was signed by the holder of a particular private key. The corresponding public key can be used to verify the signature. Digital signatures can provide integrity and authentication and may support nonrepudiation depending on the surrounding process and legal context. Symmetric encryption uses a shared secret key, a hash collision concerns two inputs producing the same digest, and tokenization substitutes sensitive data with tokens. Therefore, a digital signature provides the cryptographic mechanism described.<\/span><\/p>\n<h3><b>Question 128<\/b><\/h3>\n<p><b>Which Cisco firewall policy capability can identify traffic according to the application generating it rather than only using traditional port numbers?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ARP inspection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP snooping<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application control allows a security policy to identify and enforce rules based on applications rather than relying solely on IP addresses and transport-layer ports. This provides greater visibility because modern applications may use dynamic ports, shared protocols, or encrypted connections. Application-aware policies can therefore provide more granular control over permitted or denied activity. Static routing determines forwarding paths, ARP inspection protects address-resolution behavior, and DHCP snooping protects against rogue DHCP servers. Therefore, application control is the capability that identifies traffic by application.<\/span><\/p>\n<h3><b>Question 129<\/b><\/h3>\n<p><b>Which security technique makes it more difficult for attackers to determine whether a username exists by returning similar authentication responses for valid and invalid accounts?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Account enumeration prevention<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Packet filtering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN pruning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route redistribution<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Account enumeration prevention reduces the amount of information exposed during authentication attempts. If a system clearly distinguishes between an invalid username and an incorrect password, attackers can use those responses to identify valid accounts before attempting password attacks. Applications can reduce this risk by providing similar responses and carefully controlling error messages, while logging and rate-limiting suspicious authentication activity. Packet filtering controls traffic, VLAN pruning restricts VLAN propagation, and route redistribution exchanges routing information. Therefore, account enumeration prevention is the appropriate security technique.<\/span><\/p>\n<h3><b>Question 130<\/b><\/h3>\n<p><b>Which protocol provides secure remote administration of a network device by encrypting the management session?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Telnet<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SSH<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TFTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">SSH provides encrypted remote command-line administration for network devices and servers. It protects credentials and interactive management traffic from being transmitted as clear text across the network. Administrators can use SSH to configure routers, switches, firewalls, and other infrastructure securely. Telnet provides remote access without equivalent built-in encryption, while FTP and TFTP are primarily file-transfer protocols. Secure management access should also be restricted to authorized source networks and protected with strong authentication and appropriate logging. Therefore, SSH is the correct protocol for encrypted remote administration.<\/span><\/p>\n<h3><b>Question 131<\/b><\/h3>\n<p><b>Which security technology can identify whether sensitive information is being transmitted through an organization&#8217;s approved or unapproved cloud applications?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CASB<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HSRP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">OSPF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LACP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Cloud Access Security Broker, or CASB, provides visibility and policy enforcement between users and cloud services. Depending on the implementation, CASB capabilities can help identify cloud applications, apply access policies, monitor data movement, and enforce controls such as DLP. This is useful when employees use numerous cloud applications that may not all be officially approved. HSRP provides gateway redundancy, OSPF is a routing protocol, and LACP negotiates link aggregation. Therefore, CASB is the security technology associated with cloud-application visibility and policy enforcement.<\/span><\/p>\n<h3><b>Question 132<\/b><\/h3>\n<p><b>Which type of attack attempts to cause a system to execute unauthorized commands by inserting unexpected input into an operating-system command?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Command injection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MAC flooding<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP starvation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Credential stuffing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Command injection occurs when an application improperly handles user-controlled input and allows an attacker to influence commands executed by the underlying operating system. Successful exploitation can allow unauthorized actions with the privileges of the vulnerable application or process. Secure development practices such as input validation, safe APIs, parameterization where appropriate, and least-privilege execution can reduce the risk. MAC flooding targets switch forwarding tables, DHCP starvation consumes address leases, and credential stuffing uses previously compromised credentials. Therefore, command injection matches the described attack.<\/span><\/p>\n<h3><b>Question 133<\/b><\/h3>\n<p><b>Which security technology can provide centralized authentication, authorization, and accounting for administrators accessing network devices?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RADIUS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TACACS+<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">TACACS+ is commonly used for centralized administrative access control to network devices. It separates authentication, authorization, and accounting functions and can provide detailed authorization of administrative commands. This makes it particularly useful for controlling and auditing administrator access to routers, switches, and security appliances. RADIUS is also widely used for centralized authentication, particularly for network access, but TACACS+ is commonly associated with granular device-administration authorization. DNS resolves names and NTP synchronizes time. Therefore, TACACS+ best matches the described administrative access-control requirement.<\/span><\/p>\n<h3><b>Question 134<\/b><\/h3>\n<p><b>Which security capability can automatically place a suspicious endpoint into a restricted network segment after detecting a policy violation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic network access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS forwarding<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT overload<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Dynamic network access control can change an endpoint&#8217;s authorization or network placement in response to security conditions. For example, an endpoint that fails posture checks or is identified as suspicious can be moved into a restricted VLAN or assigned a limited access policy. This allows organizations to contain potentially compromised devices while preserving controlled connectivity for remediation. Static routing determines packet paths, DNS forwarding handles name-resolution requests, and NAT overload translates multiple addresses through one public address. Therefore, dynamic network access control provides the described response capability.<\/span><\/p>\n<h3><b>Question 135<\/b><\/h3>\n<p><b>Which security feature helps prevent attackers from using forged ARP messages to associate their MAC address with another device&#8217;s IP address?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic ARP Inspection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNSSEC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CoPP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port mirroring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Dynamic ARP Inspection, or DAI, validates ARP messages on supported switches to reduce the risk of ARP spoofing and poisoning. It can compare ARP information against trusted IP-to-MAC bindings, commonly obtained through DHCP snooping. Invalid ARP packets can then be discarded. DNSSEC protects DNS information, CoPP protects the control plane, and port mirroring copies traffic for analysis. ARP spoofing can allow an attacker to intercept or redirect local traffic, making DAI an important Layer 2 protection. Therefore, DAI provides the described defense.<\/span><\/p>\n<h3><b>Question 136<\/b><\/h3>\n<p><b>Which security control helps identify unauthorized changes to critical operating-system files by continuously comparing their state with a trusted baseline?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File integrity monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic shaping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route summarization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">File integrity monitoring compares important files against known trusted states and alerts security personnel when unexpected changes occur. It can be used to monitor operating-system files, configuration files, application components, and other critical resources. Unexpected modifications may indicate malware activity, unauthorized administrative actions, or system compromise. File integrity monitoring is particularly useful when combined with centralized logging and incident-response processes. Traffic shaping manages bandwidth, load balancing distributes application requests, and route summarization reduces routing information. Therefore, file integrity monitoring provides the described protection.<\/span><\/p>\n<h3><b>Question 137<\/b><\/h3>\n<p><b>Which security mechanism can use a cryptographic hash to verify that downloaded software has not been modified after publication?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hash verification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN tagging<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP relay<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT traversal<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Hash verification allows a recipient to calculate a cryptographic digest of downloaded software and compare it with a trusted published value. If the calculated digest matches the expected value, the recipient gains evidence that the file contents have not changed since the trusted value was generated. Hashes do not by themselves prove who published the software, so digital signatures may provide stronger authenticity assurance when available. VLAN tagging identifies VLAN membership, DHCP relay forwards requests, and NAT traversal supports certain communications through address translation. Therefore, hash verification provides integrity checking.<\/span><\/p>\n<h3><b>Question 138<\/b><\/h3>\n<p><b>Which security service is primarily designed to filter malicious or inappropriate web requests and enforce acceptable-use policies for Internet browsing?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secure Web Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Routing Information Base<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network Time Protocol<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Secure Web Gateway, or SWG, provides security controls for web traffic between users and Internet destinations. Depending on the implementation, it can enforce URL policies, inspect web content, identify malware, apply data-protection controls, and block prohibited or risky websites. SWGs are commonly used as part of secure access service architectures and can protect users regardless of where they connect from. DHCP provides IP configuration, the routing information base stores routes, and NTP synchronizes clocks. Therefore, Secure Web Gateway is the appropriate web-security service.<\/span><\/p>\n<h3><b>Question 139<\/b><\/h3>\n<p><b>Which security control can reduce the risk of unauthorized users gaining access through a stolen password by requiring an additional authentication factor?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password expiration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Multifactor authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Account naming convention<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static authorization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Multifactor authentication adds one or more independent authentication factors beyond a password. For example, an organization may require a password plus a hardware token, authenticator application approval, or biometric factor. If an attacker obtains the password alone, the additional factor can prevent or significantly complicate unauthorized access. Password expiration may reduce exposure in some circumstances but does not provide an independent authentication factor. Account naming conventions and static authorization do not provide equivalent authentication protection. Therefore, multifactor authentication is the appropriate control.<\/span><\/p>\n<h3><b>Question 140<\/b><\/h3>\n<p><b>Which security technology can identify abnormal network communication by establishing a baseline of expected behavior and detecting significant deviations?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Behavioral analysis<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN trunking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP relay<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Behavioral analysis identifies suspicious activity by comparing observed behavior with an established or dynamically learned baseline of normal activity. Significant deviations, such as unusual communication patterns, unexpected destinations, abnormal data volumes, or atypical user behavior, can generate security alerts for investigation. This approach can help detect previously unknown or modified threats that may not match traditional signatures. Static NAT maps addresses, VLAN trunking transports multiple VLANs, and DHCP relay forwards configuration requests. Therefore, behavioral analysis provides the anomaly-detection capability described.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco 350-701 Exam Dumps and Practice Test Dumps. &nbsp; Question 121 Which IPsec protocol is responsible for negotiating authentication, encryption, and integrity parameters before protected traffic is exchanged? ESP IKE ARP GRE Correct Answer: 2 Explanation Internet Key Exchange, or IKE, negotiates the security parameters required for an IPsec connection. During the negotiation [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20906"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=20906"}],"version-history":[{"count":2,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20906\/revisions"}],"predecessor-version":[{"id":20934,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20906\/revisions\/20934"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=20906"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=20906"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=20906"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}