{"id":20910,"date":"2026-09-24T09:08:07","date_gmt":"2026-09-24T09:08:07","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=20910"},"modified":"2026-09-24T09:08:07","modified_gmt":"2026-09-24T09:08:07","slug":"cisco-ccie-security-350-701-practice-test-questions-and-exam-dumps-part9-q161-180","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-ccie-security-350-701-practice-test-questions-and-exam-dumps-part9-q161-180\/","title":{"rendered":"Cisco CCIE Security 350-701 Practice Test Questions and Exam Dumps Part9 Q161-180"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/350-701-exam-dumps\"><b>Cisco 350-701 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 161<\/b><\/h3>\n<p><b>Which security mechanism can prevent unauthorized users from accessing a network device through repeated password-guessing attempts?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Login blocking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route redistribution<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN tagging<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS forwarding<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Login blocking can temporarily restrict authentication attempts after a defined number of failed login attempts. This helps reduce the effectiveness of automated password-guessing and brute-force attacks against network-device management interfaces. Administrators can combine login protections with strong passwords, multifactor authentication, centralized AAA, and secure management protocols. Route redistribution exchanges routing information, VLAN tagging identifies Layer 2 membership, and DNS forwarding handles name-resolution requests. Therefore, login blocking is the security mechanism designed to limit repeated unauthorized authentication attempts.<\/span><\/p>\n<h3><b>Question 162<\/b><\/h3>\n<p><b>Which security technology can use endpoint telemetry to investigate how a malicious process entered a system and what actions it performed afterward?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network Address Translation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Endpoint Detection and Response<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP snooping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN trunking<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Endpoint Detection and Response, or EDR, collects detailed endpoint telemetry that can help analysts investigate suspicious processes, files, network connections, and user activity. Security teams can use this information to reconstruct attack activity and understand how a threat entered a device, what processes were executed, and what additional systems may have been contacted. NAT translates addresses, DHCP snooping protects against rogue DHCP servers, and VLAN trunking transports multiple VLANs. Therefore, EDR provides the endpoint investigation capability described.<\/span><\/p>\n<h3><b>Question 163<\/b><\/h3>\n<p><b>Which security control can help protect a network device from excessive traffic directed at its management and control-plane functions?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNSSEC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CoPP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DLP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Control Plane Policing, or CoPP, controls traffic destined for the control plane of a network device. Security policies can classify traffic and apply rate limits or other actions to prevent excessive packets from overwhelming CPU resources. This is particularly useful for protecting routing protocols, management services, and other control-plane functions from abuse or denial-of-service conditions. DNSSEC protects DNS integrity, port security controls switch-port access, and DLP protects sensitive information. Therefore, CoPP provides the required protection for control-plane resources.<\/span><\/p>\n<h3><b>Question 164<\/b><\/h3>\n<p><b>Which authentication protocol commonly separates authentication, authorization, and accounting functions for network-device administrators?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TACACS+<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HTTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SNMP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">TACACS+ is designed to provide centralized authentication, authorization, and accounting for administrative access to network devices. Its separation of these functions allows organizations to apply granular authorization policies and maintain records of administrator activity. This can be particularly useful when different administrators require different command privileges. HTTP is an application protocol, SNMP provides network-management functions, and DHCP provides host configuration. Therefore, TACACS+ is the protocol that best matches centralized administrative AAA requirements.<\/span><\/p>\n<h3><b>Question 165<\/b><\/h3>\n<p><b>Which security capability can identify malicious behavior by analyzing files in an isolated environment before allowing them to reach users?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Sandbox analysis<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route filtering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT traversal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN pruning<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Sandbox analysis executes or examines suspicious files in an isolated environment to observe their behavior without exposing production systems to the same risk. Security solutions can analyze actions such as process creation, file modification, network communication, and other behaviors to determine whether a file is malicious. This approach can help identify threats that may evade simple signature-based detection. Route filtering controls routing information, NAT traversal supports communication through address translation, and VLAN pruning limits VLAN propagation. Therefore, sandbox analysis provides the described security capability.<\/span><\/p>\n<h3><b>Question 166<\/b><\/h3>\n<p><b>Which security technology can verify the identity of a server during a TLS connection by validating its digital certificate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Digital certificate validation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MAC address learning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP relay<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic shaping<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">During a TLS connection, certificate validation allows a client to verify whether a server certificate is trusted and whether it corresponds to the intended identity. Validation can include checking the certificate chain, validity period, trusted certificate authority, and hostname or other identity attributes. This helps reduce the risk of connecting to an unauthorized server through a man-in-the-middle attack. MAC learning supports Ethernet switching, DHCP relay forwards configuration requests, and traffic shaping controls bandwidth. Therefore, certificate validation provides the described server-authentication mechanism.<\/span><\/p>\n<h3><b>Question 167<\/b><\/h3>\n<p><b>Which security control is most directly concerned with preventing sensitive information from leaving an organization through unauthorized channels?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DLP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">STP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">OSPF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VRRP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data Loss Prevention, or DLP, is designed to identify and protect sensitive information as it is stored, processed, or transmitted. DLP policies can inspect content and detect information such as confidential documents, financial data, personally identifiable information, or other organizationally defined sensitive content. Depending on the implementation, DLP can alert, block, quarantine, or otherwise control unauthorized transfers. STP prevents Layer 2 loops, OSPF exchanges routing information, and VRRP provides gateway redundancy. Therefore, DLP directly addresses unauthorized data movement.<\/span><\/p>\n<h3><b>Question 168<\/b><\/h3>\n<p><b>Which cloud security capability identifies publicly exposed cloud resources and configuration settings that violate organizational security policies?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CSPM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SFTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MACsec<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">GRE<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud Security Posture Management, or CSPM, continuously evaluates cloud environments for configuration weaknesses and policy violations. It can identify issues such as publicly exposed storage, overly permissive security rules, missing encryption controls, weak identity permissions, and other insecure settings. CSPM helps security teams maintain a consistent security posture across dynamic cloud environments where resources can be created or modified rapidly. SFTP provides secure file transfer, MACsec protects Ethernet traffic, and GRE provides tunneling. Therefore, CSPM is the appropriate cloud-security capability.<\/span><\/p>\n<h3><b>Question 169<\/b><\/h3>\n<p><b>Which network security technology can create an encrypted tunnel between two sites while allowing their internal hosts to communicate across an untrusted Internet connection?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Site-to-site VPN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS caching<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SPAN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port security<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A site-to-site VPN establishes a secure tunnel between network gateways so that hosts in separate locations can communicate across an untrusted network. IPsec is commonly used to provide encryption, integrity, authentication, and anti-replay protection for this type of connection. The gateways handle VPN processing so that individual internal hosts generally do not need separate VPN software. DNS caching stores name-resolution results, SPAN copies traffic for monitoring, and port security restricts switch-port access. Therefore, site-to-site VPN provides the described connectivity.<\/span><\/p>\n<h3><b>Question 170<\/b><\/h3>\n<p><b>Which security principle requires that a user should receive access only to the applications and resources necessary for their assigned duties?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defense in depth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Availability<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Nonrepudiation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Least privilege limits a user&#8217;s, application&#8217;s, or system&#8217;s permissions to only what is necessary for authorized responsibilities. Restricting access in this way reduces the potential damage caused by compromised credentials, malicious insiders, application vulnerabilities, or accidental misuse. Access should be reviewed periodically because job responsibilities and organizational requirements can change. Defense in depth uses multiple security layers, availability focuses on access to resources, and nonrepudiation provides evidence associated with actions. Therefore, least privilege directly describes the required access-control principle.<\/span><\/p>\n<h3><b>Question 171<\/b><\/h3>\n<p><b>Which security technology provides visibility into encrypted application traffic by inspecting TLS sessions at a security enforcement point?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TLS inspection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP snooping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HSRP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LACP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">TLS inspection allows a security enforcement point to decrypt, inspect, and re-encrypt protected traffic so that security policies can evaluate content that would otherwise remain encrypted. This can support malware detection, application identification, URL filtering, and other inspection functions. Organizations must carefully manage certificates and privacy requirements because inspection involves access to decrypted traffic. DHCP snooping protects against rogue DHCP servers, HSRP provides gateway redundancy, and LACP manages link aggregation. Therefore, TLS inspection provides visibility into encrypted application traffic.<\/span><\/p>\n<h3><b>Question 172<\/b><\/h3>\n<p><b>Which security technology can automatically quarantine an endpoint after it is determined to be infected with malware?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Endpoint isolation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route summarization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS recursion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT overload<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Endpoint isolation restricts a compromised device&#8217;s network communication to contain the threat and reduce opportunities for lateral movement. Modern endpoint-security platforms can isolate a device while preserving controlled communication with security-management infrastructure so that analysts can investigate and remediate the incident. Route summarization reduces routing information, DNS recursion processes name-resolution queries, and NAT overload translates multiple private addresses through a shared public address. Therefore, endpoint isolation is the capability used to quarantine a potentially infected endpoint.<\/span><\/p>\n<h3><b>Question 173<\/b><\/h3>\n<p><b>Which security service provides centralized protection for users accessing websites from locations outside the traditional corporate network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secure Web Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">STP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VRRP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">OSPF<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Secure Web Gateway, or SWG, provides security inspection and policy enforcement for web traffic. Cloud-delivered SWG services can protect users regardless of whether they are working from a corporate office, home, or another remote location. Depending on the implementation, SWG capabilities can include URL filtering, malware inspection, content controls, and data-protection policies. STP prevents switching loops, VRRP provides gateway redundancy, and OSPF exchanges routing information. Therefore, Secure Web Gateway is the service designed to secure web access from distributed locations.<\/span><\/p>\n<h3><b>Question 174<\/b><\/h3>\n<p><b>Which security control can detect and block unauthorized ARP messages by comparing them with trusted IP-to-MAC address bindings?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic ARP Inspection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNSSEC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TLS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPsec<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Dynamic ARP Inspection, or DAI, validates ARP messages against trusted IP-to-MAC address information. In many deployments, the required bindings are obtained from DHCP snooping. ARP messages that do not match expected bindings can be dropped, reducing the risk of ARP spoofing and man-in-the-middle attacks within a local network. DNSSEC protects DNS data, TLS protects application communications, and IPsec protects IP traffic. Therefore, Dynamic ARP Inspection provides the Layer 2 protection described.<\/span><\/p>\n<h3><b>Question 175<\/b><\/h3>\n<p><b>Which security technology provides cryptographic protection for Ethernet frames between directly connected network devices?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MACsec<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">GRE<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SNMP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">MACsec, based on IEEE 802.1AE, provides Layer 2 security for Ethernet frames. It can protect traffic against unauthorized observation and tampering as frames travel across a secured Ethernet link. MACsec is useful when organizations require protection for traffic within campus, data-center, or other switched environments. FTP provides file transfer, GRE provides tunneling without inherent encryption, and SNMP provides network-management capabilities. Therefore, MACsec is the technology that provides cryptographic protection directly at the Ethernet layer.<\/span><\/p>\n<h3><b>Question 176<\/b><\/h3>\n<p><b>Which security mechanism can prevent a user from accessing a network until the user&#8217;s identity has been authenticated?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">802.1X<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SPAN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">GRE<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">EtherChannel<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">802.1X provides port-based network access control and requires authentication before normal network access is granted. It can be used in both wired and wireless environments and commonly integrates with centralized authentication systems. This allows organizations to associate access decisions with user or device identity and apply appropriate authorization policies after successful authentication. SPAN copies traffic for monitoring, GRE creates tunnels, and EtherChannel combines multiple physical links. Therefore, 802.1X provides the authentication-based network-access control described.<\/span><\/p>\n<h3><b>Question 177<\/b><\/h3>\n<p><b>Which security capability helps an organization detect suspicious activity by correlating authentication events, firewall alerts, endpoint events, and other security logs?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SIEM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">STP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Security Information and Event Management, or SIEM, platform aggregates security events from multiple systems and correlates them to identify patterns that may indicate an attack. Authentication failures, firewall blocks, endpoint alerts, and other events can be analyzed together to provide broader context than any individual log source. SIEM systems can support alerting, investigation, compliance reporting, and incident response. DHCP provides network configuration, NAT translates addresses, and STP prevents switching loops. Therefore, SIEM provides the centralized event-correlation capability described.<\/span><\/p>\n<h3><b>Question 178<\/b><\/h3>\n<p><b>Which attack involves sending a large number of authentication requests using many different usernames but a small number of commonly used passwords?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Credential stuffing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password spraying<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL injection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Buffer overflow<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Password spraying attempts to avoid account lockout controls by trying a small number of commonly used passwords against many different accounts. Instead of repeatedly attacking one username, the attacker distributes attempts across a broad set of accounts. This technique can exploit weak passwords while generating fewer attempts against each individual account. Credential stuffing uses previously compromised username-and-password combinations, SQL injection targets vulnerable database queries, and buffer overflow exploits memory-handling weaknesses. Therefore, password spraying matches the described authentication attack.<\/span><\/p>\n<h3><b>Question 179<\/b><\/h3>\n<p><b>Which security technology can provide secure access to private applications without requiring a traditional full-network VPN connection?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ZTNA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ARP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LACP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Zero Trust Network Access, or ZTNA, provides controlled access to specific private applications based on identity, device context, policy, and other security signals. Instead of automatically placing a remote user on a broad internal network, ZTNA can provide access only to applications that the user is authorized to use. This supports least-privilege access and reduces unnecessary network exposure. FTP provides file transfer, ARP performs address resolution, and LACP manages link aggregation. Therefore, ZTNA provides the described application-specific secure-access model.<\/span><\/p>\n<h3><b>Question 180<\/b><\/h3>\n<p><b>Which security technology can identify whether a cloud application is being used by employees and provide policy controls over that application&#8217;s use?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CASB<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HSRP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">OSPF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LACP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Cloud Access Security Broker, or CASB, provides visibility and policy enforcement for cloud-service usage. It can help organizations identify cloud applications, monitor how they are being used, and apply controls related to access, data protection, compliance, and security. CASB capabilities can be especially useful when employees use cloud services outside traditional corporate infrastructure. HSRP provides gateway redundancy, OSPF is a routing protocol, and LACP manages link aggregation. Therefore, CASB provides the cloud-application visibility and control described.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco 350-701 Exam Dumps and Practice Test Dumps. &nbsp; Question 161 Which security mechanism can prevent unauthorized users from accessing a network device through repeated password-guessing attempts? Login blocking Route redistribution VLAN tagging DNS forwarding Correct Answer: 1 Explanation Login blocking can temporarily restrict authentication attempts after a defined number of failed login [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20910"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=20910"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20910\/revisions"}],"predecessor-version":[{"id":20911,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20910\/revisions\/20911"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=20910"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=20910"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=20910"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}