{"id":20922,"date":"2026-09-24T09:10:38","date_gmt":"2026-09-24T09:10:38","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=20922"},"modified":"2026-09-24T09:10:38","modified_gmt":"2026-09-24T09:10:38","slug":"cisco-ccie-security-350-701-practice-test-questions-and-exam-dumps-part15-q281-300","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-ccie-security-350-701-practice-test-questions-and-exam-dumps-part15-q281-300\/","title":{"rendered":"Cisco CCIE Security 350-701 Practice Test Questions and Exam Dumps Part15 Q281-300"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/350-701-exam-dumps\"><b>Cisco 350-701 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 281<\/b><\/h3>\n<p><b>Which security technology can inspect email messages and attachments for malware, spam, phishing attempts, and other threats before delivery to users?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco Secure Email Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco HSRP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco IP SLA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cisco SPAN<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cisco Secure Email Gateway provides security inspection for email traffic and can help identify threats such as spam, malware, phishing attempts, and potentially dangerous attachments. Email security controls can use reputation information, content inspection, malware analysis, and policy enforcement to reduce the risk of malicious messages reaching users. HSRP provides gateway redundancy, IP SLA monitors network performance, and SPAN copies network traffic for analysis. Therefore, Cisco Secure Email Gateway is designed to protect organizational email communications.<\/span><\/p>\n<h3><b>Question 282<\/b><\/h3>\n<p><b>Which security control can prevent a user from accessing a sensitive application unless the endpoint satisfies predefined security requirements?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS forwarding<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device posture assessment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN trunking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic shaping<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Device posture assessment evaluates the security state of an endpoint before access is granted. Depending on organizational policy, posture checks can examine factors such as operating-system versions, security software, encryption status, device management, or other required controls. Access can then be allowed, restricted, or denied based on the result. DNS forwarding handles name resolution, VLAN trunking transports multiple VLANs, and traffic shaping manages bandwidth. Therefore, device posture assessment provides the endpoint-condition check required for policy-based access.<\/span><\/p>\n<h3><b>Question 283<\/b><\/h3>\n<p><b>Which security mechanism can protect sensitive information by replacing the original value with a non-sensitive substitute that can be mapped back when authorized?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hashing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tokenization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Compression<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Tokenization replaces sensitive information with a surrogate value called a token. The original data is stored separately in a protected system, and authorized applications can use the token without directly handling the sensitive value. This approach is commonly used for protecting payment information and other sensitive data. Hashing is generally one-way, encryption transforms data using cryptographic keys, and compression reduces data size. Therefore, tokenization provides the substitution mechanism described while allowing controlled recovery of the original value.<\/span><\/p>\n<h3><b>Question 284<\/b><\/h3>\n<p><b>Which network security mechanism can prevent an attacker from sending unauthorized packets to a router&#8217;s infrastructure services by filtering traffic destined for the device itself?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Infrastructure ACL<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNSSEC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SFTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MACsec<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An infrastructure ACL can restrict traffic destined for network infrastructure services such as routing protocols, management interfaces, and other device-local functions. By allowing only expected sources and required protocols, administrators can reduce exposure to unauthorized access and certain control-plane attacks. DNSSEC protects DNS integrity, SFTP provides secure file transfer, and MACsec protects Ethernet frames. Therefore, an infrastructure ACL provides the traffic filtering required to protect infrastructure services from unauthorized sources.<\/span><\/p>\n<h3><b>Question 285<\/b><\/h3>\n<p><b>Which security technology provides encrypted communication between a user&#8217;s endpoint and a remote VPN gateway across an untrusted network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">GRE<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remote-access IPsec VPN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TFTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SNMP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A remote-access IPsec VPN establishes a protected connection between an individual endpoint and a VPN gateway across an untrusted network such as the Internet. IPsec can provide confidentiality, integrity, authentication, and anti-replay protection for the communication. This allows authorized remote users to securely access organizational resources according to configured policies. GRE provides tunneling without inherent encryption, TFTP transfers files without strong security, and SNMP supports management. Therefore, a remote-access IPsec VPN provides the required encrypted connectivity.<\/span><\/p>\n<h3><b>Question 286<\/b><\/h3>\n<p><b>Which security mechanism can detect when a certificate has passed its validity period and should no longer be accepted?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate expiration validation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP snooping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SPAN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BGP filtering<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Certificate validation includes checking the certificate&#8217;s validity period to determine whether it is currently valid. Certificates contain defined start and expiration dates, and applications should reject certificates that are outside their permitted validity period unless an appropriate policy provides another trusted mechanism. This check helps prevent the use of outdated credentials for authentication or encrypted communications. DHCP snooping protects DHCP operations, SPAN copies traffic, and BGP filtering controls routing information. Therefore, certificate expiration validation provides the required security check.<\/span><\/p>\n<h3><b>Question 287<\/b><\/h3>\n<p><b>Which security control can restrict network access based on the security group or policy tag associated with an authenticated device?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security Group Tag policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS caching<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT overload<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security Group Tags, or SGTs, can associate users, devices, or traffic with logical security classifications. Policy enforcement points can then use these classifications to determine whether communication between different security groups should be permitted or denied. This allows organizations to apply identity-aware policies without depending exclusively on IP addresses. DNS caching stores name-resolution information, NTP synchronizes system clocks, and NAT overload translates multiple private addresses. Therefore, SGT-based policy provides the identity-aware access control described.<\/span><\/p>\n<h3><b>Question 288<\/b><\/h3>\n<p><b>Which security capability can identify vulnerabilities in containers before images are deployed into a production environment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Container image security scanning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HSRP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VRRP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP relay<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Container image security scanning examines container images for known vulnerabilities, insecure packages, configuration problems, embedded secrets, and other risks before deployment. Integrating these checks into development and CI\/CD pipelines allows organizations to identify issues earlier in the application lifecycle. This supports DevSecOps and helps prevent vulnerable components from reaching production environments. HSRP and VRRP provide gateway redundancy, while DHCP relay forwards DHCP requests between network segments. Therefore, container image security scanning provides the required pre-deployment security assessment.<\/span><\/p>\n<h3><b>Question 289<\/b><\/h3>\n<p><b>Which security feature can prevent unauthorized users from gaining administrative access even when they know another administrator&#8217;s password?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password complexity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Multifactor authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route filtering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port mirroring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Multifactor authentication requires an additional authentication factor beyond the password. If an attacker obtains another administrator&#8217;s password, the attacker may still be unable to authenticate without the additional factor, such as an approved authentication application, hardware token, or biometric factor. Password complexity makes passwords harder to guess but does not protect against a password that has already been stolen. Route filtering controls routing information, while port mirroring copies traffic. Therefore, multifactor authentication provides the additional protection described.<\/span><\/p>\n<h3><b>Question 290<\/b><\/h3>\n<p><b>Which security mechanism helps ensure that only authenticated and authorized devices can participate in a wired enterprise network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">802.1X<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNSSEC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">GRE<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Syslog<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">802.1X provides port-based network access control by requiring an endpoint to authenticate before receiving normal network access. It can work with a centralized authentication service and can use identity or device information to determine authorization. This makes it useful for enterprise wired networks where unauthorized devices should not automatically receive connectivity simply because they can physically connect to a switch port. DNSSEC protects DNS records, GRE provides tunneling, and Syslog transports event messages. Therefore, 802.1X provides the required access-control mechanism.<\/span><\/p>\n<h3><b>Question 291<\/b><\/h3>\n<p><b>Which security technology can inspect cloud service usage and identify unsanctioned applications being accessed by employees?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CASB<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MACsec<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CoPP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IP Source Guard<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Cloud Access Security Broker, or CASB, provides visibility into cloud-service usage and can help organizations identify sanctioned and unsanctioned applications. Security teams can use CASB capabilities to monitor cloud activity, enforce access policies, protect sensitive information, and apply compliance controls. MACsec protects Ethernet traffic, CoPP protects the network-device control plane, and IP Source Guard validates source-address information. Therefore, CASB provides the cloud-application discovery and policy-enforcement capability described.<\/span><\/p>\n<h3><b>Question 292<\/b><\/h3>\n<p><b>Which security control can detect an attacker attempting to exploit a vulnerable database application through specially crafted input parameters?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secure Web Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web Application Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RADIUS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Web Application Firewall can inspect HTTP and HTTPS requests for malicious patterns associated with attacks against web applications. It can detect techniques such as SQL injection by analyzing request parameters and other application-layer information. Depending on the configured policy, malicious requests can be blocked or logged for investigation. Secure Web Gateway focuses primarily on securing user web access, NTP synchronizes clocks, and RADIUS provides centralized authentication. Therefore, WAF is the most appropriate control for the described database-application attack.<\/span><\/p>\n<h3><b>Question 293<\/b><\/h3>\n<p><b>Which security technology provides encrypted protection for Ethernet traffic between supported network interfaces at Layer 2?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPsec<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TLS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MACsec<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SSH<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">MACsec provides cryptographic protection for Ethernet frames at Layer 2. It can provide confidentiality and integrity for traffic traveling across a supported Ethernet link and is useful in campus, data-center, and other switched environments. IPsec protects traffic at the IP layer, TLS protects application-layer sessions, and SSH provides secure remote administration and related secure communications. Therefore, MACsec is the technology specifically designed to protect Ethernet traffic at Layer 2.<\/span><\/p>\n<h3><b>Question 294<\/b><\/h3>\n<p><b>Which security practice helps determine which assets are affected by a newly discovered vulnerability before remediation priorities are assigned?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Asset inventory and vulnerability correlation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic shaping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN tagging<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS forwarding<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Asset inventory and vulnerability correlation combine information about organizational assets with vulnerability findings. By determining which systems, applications, devices, and workloads are affected, security teams can understand the scope of a vulnerability and identify systems that require remediation. This information can then be combined with severity, exposure, exploit availability, and business importance to establish appropriate remediation priorities. Traffic shaping manages bandwidth, VLAN tagging identifies VLAN membership, and DNS forwarding handles name resolution. Therefore, asset-vulnerability correlation provides the required visibility.<\/span><\/p>\n<h3><b>Question 295<\/b><\/h3>\n<p><b>Which security mechanism can detect unauthorized access attempts by comparing incoming authentication activity against known user behavior and access patterns?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">UEBA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LACP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">GRE<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">STP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">User and Entity Behavior Analytics can compare current activity with established behavioral patterns for users and entities. Significant deviations, such as unexpected login locations, unusual access times, abnormal resource usage, or unfamiliar devices, can generate security alerts. This can help identify compromised credentials or suspicious account activity even when valid authentication credentials are being used. LACP manages link aggregation, GRE provides tunneling, and STP prevents Layer 2 loops. Therefore, UEBA provides the behavioral-analysis capability described.<\/span><\/p>\n<h3><b>Question 296<\/b><\/h3>\n<p><b>Which security control can help ensure that a network device accepts management connections only through encrypted protocols?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service minimization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secure management policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route summarization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN pruning<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A secure management policy can require administrators to use encrypted protocols such as SSH or HTTPS while disabling insecure management services such as Telnet and plain HTTP. Combining secure protocols with AAA, management-plane ACLs, and dedicated management networks provides stronger protection for administrative access. Service minimization reduces unnecessary services, but it does not by itself define which management protocols must be encrypted. Route summarization reduces routing information, while VLAN pruning controls VLAN propagation. Therefore, a secure management policy provides the described control.<\/span><\/p>\n<h3><b>Question 297<\/b><\/h3>\n<p><b>Which security technology can identify malicious domains using reputation information and block users from connecting to known harmful destinations?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS security filtering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LACP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VRRP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SPAN<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">DNS security filtering can use domain reputation and threat-intelligence information to identify domains associated with malware, phishing, command-and-control infrastructure, or other threats. Requests for known malicious destinations can be blocked, redirected, or logged according to organizational policy. This provides protection before a user&#8217;s application establishes a connection to the destination. LACP manages link aggregation, VRRP provides gateway redundancy, and SPAN copies traffic for monitoring. Therefore, DNS security filtering provides the described domain-based protection.<\/span><\/p>\n<h3><b>Question 298<\/b><\/h3>\n<p><b>Which security control provides evidence that a specific administrator performed a particular action on a network device?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network Address Translation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Command accounting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP relay<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN trunking<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Command accounting records administrative commands and associates those actions with authenticated users. When combined with accurate time synchronization and centralized AAA, it can provide a useful audit trail showing who performed a particular administrative action and when it occurred. This supports accountability, troubleshooting, compliance, and incident investigation. NAT translates addresses, DHCP relay forwards DHCP messages, and VLAN trunking transports traffic from multiple VLANs. Therefore, command accounting provides the required evidence of administrator activity.<\/span><\/p>\n<h3><b>Question 299<\/b><\/h3>\n<p><b>Which security capability can automatically isolate a compromised endpoint from most network communication while still allowing security administrators to investigate it?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Endpoint isolation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route redistribution<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS caching<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic shaping<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Endpoint isolation restricts a compromised device&#8217;s network communications to contain an active threat and prevent lateral movement. Modern endpoint-security platforms can isolate an endpoint while maintaining limited communication with security-management infrastructure so that administrators can investigate, collect evidence, and remediate the device. Route redistribution exchanges routing information, DNS caching stores name-resolution results, and traffic shaping controls bandwidth. Therefore, endpoint isolation provides the containment capability required for a compromised endpoint.<\/span><\/p>\n<h3><b>Question 300<\/b><\/h3>\n<p><b>Which security principle requires organizations to protect systems using several complementary controls rather than relying on a single defensive mechanism?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Nonrepudiation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defense in depth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Separation of duties<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Defense in depth uses multiple layers of security controls so that the failure or bypass of one control does not automatically expose the protected resource. An organization may combine identity verification, endpoint protection, firewalls, segmentation, encryption, monitoring, and incident-response procedures. Each layer addresses different attack paths or stages of an intrusion. Least privilege limits permissions, nonrepudiation provides evidence associated with actions, and separation of duties distributes sensitive responsibilities. Therefore, defense in depth describes the use of multiple complementary security protections.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco 350-701 Exam Dumps and Practice Test Dumps. &nbsp; Question 281 Which security technology can inspect email messages and attachments for malware, spam, phishing attempts, and other threats before delivery to users? Cisco Secure Email Gateway Cisco HSRP Cisco IP SLA Cisco SPAN Correct Answer: 1 Explanation Cisco Secure Email Gateway provides security [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20922"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=20922"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20922\/revisions"}],"predecessor-version":[{"id":20923,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20922\/revisions\/20923"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=20922"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=20922"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=20922"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}