{"id":20932,"date":"2026-09-24T09:12:04","date_gmt":"2026-09-24T09:12:04","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=20932"},"modified":"2026-09-24T09:12:04","modified_gmt":"2026-09-24T09:12:04","slug":"cisco-ccie-security-350-701-practice-test-questions-and-exam-dumps-part20-q381-400","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-ccie-security-350-701-practice-test-questions-and-exam-dumps-part20-q381-400\/","title":{"rendered":"Cisco CCIE Security 350-701 Practice Test Questions and Exam Dumps Part20 Q381-400"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/350-701-exam-dumps\"><b>Cisco 350-701 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 381<\/b><\/h3>\n<p><b>Which control can prevent unauthorized devices from using a switch port by limiting the MAC addresses permitted on that interface?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP snooping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNSSEC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NetFlow<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Port security can restrict which MAC addresses are permitted to use a switch interface. Administrators can configure limits on the number of learned or statically defined MAC addresses and specify actions when unauthorized addresses appear. This helps reduce risks such as unauthorized device connections and certain MAC-based attacks. DHCP snooping protects DHCP operations, DNSSEC protects DNS integrity, and NetFlow provides traffic telemetry. Therefore, port security provides the Layer 2 access-control mechanism described.<\/span><\/p>\n<h3><b>Question 382<\/b><\/h3>\n<p><b>Which protocol security feature protects BGP sessions by limiting the acceptable IP time-to-live value of incoming packets from a directly connected neighbor?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Prefix filtering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route dampening<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BGP TTL Security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RPKI<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">BGP TTL Security uses the IP TTL field to help protect BGP sessions from spoofed packets originating beyond the expected network distance. A router can require incoming BGP packets to have a sufficiently high TTL, which implies that they originated within a limited hop count. This makes certain remote spoofing attacks against BGP sessions more difficult. Prefix filtering controls advertised routes, route dampening addresses route instability, and RPKI validates route origins. Therefore, BGP TTL Security provides the described protection.<\/span><\/p>\n<h3><b>Question 383<\/b><\/h3>\n<p><b>Which security feature can automatically disable or restrict a switch port when the configured MAC-address violation condition occurs?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port-security violation action<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS filtering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RPKI<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TLS inspection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A port-security violation action defines how a switch should respond when traffic violates configured MAC-address restrictions. Depending on the selected mode, the switch can drop violating traffic, generate notifications, restrict the interface, or place the port into an error-disabled state. This provides a direct response to unauthorized devices attempting to use a protected interface. DNS filtering controls domain access, RPKI validates BGP route origins, and TLS inspection examines encrypted application traffic. Therefore, the port-security violation action provides the required response.<\/span><\/p>\n<h3><b>Question 384<\/b><\/h3>\n<p><b>Which technology can validate whether a DNS response was generated from an authenticated DNS zone and has not been modified in transit?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SPF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DKIM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNSSEC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SFTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">DNS Security Extensions, or DNSSEC, uses digital signatures to provide authenticity and integrity for DNS data. A validating resolver can verify the cryptographic chain of trust and determine whether the received DNS information can be trusted. This helps protect against attacks in which DNS responses are modified or forged. SPF and DKIM are email-security mechanisms, while SFTP provides secure file transfer. Therefore, DNSSEC provides the authentication and integrity protection required for DNS responses.<\/span><\/p>\n<h3><b>Question 385<\/b><\/h3>\n<p><b>Which security mechanism can prevent an attacker from sending forged DHCP server responses from an unauthorized switch port?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP snooping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MACsec<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RADIUS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SNI<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">DHCP snooping distinguishes trusted and untrusted switch interfaces and can block unauthorized DHCP server messages arriving from untrusted ports. This helps prevent rogue DHCP servers from assigning malicious gateway, DNS, or address information to clients. DHCP snooping can also build trusted bindings that other Layer 2 security features can use. MACsec protects Ethernet traffic, RADIUS provides centralized authentication, and SNI identifies a requested hostname during TLS negotiation. Therefore, DHCP snooping provides the described rogue-DHCP protection.<\/span><\/p>\n<h3><b>Question 386<\/b><\/h3>\n<p><b>Which control allows security administrators to identify which users are associated with network traffic instead of relying only on source IP addresses?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">User identity mapping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route summarization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storm control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT overload<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">User identity mapping associates authenticated users with network addresses or traffic flows so that security policies can be based on identity rather than only on IP addresses. This can improve visibility and allow administrators to create policies that follow users even when their network addresses change. Route summarization reduces routing information, storm control limits excessive Layer 2 traffic, and NAT overload translates multiple addresses through a shared public address. Therefore, user identity mapping provides the identity-aware visibility described.<\/span><\/p>\n<h3><b>Question 387<\/b><\/h3>\n<p><b>Which security control can limit excessive broadcast, multicast, or unknown-unicast traffic on a switch interface to reduce the impact of a traffic storm?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storm control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Root Guard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP relay<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SFTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Storm control monitors specific types of Layer 2 traffic and can restrict traffic when configured thresholds are exceeded. This helps protect switching infrastructure from excessive broadcast, multicast, or unknown-unicast traffic that could consume bandwidth and processing resources. Depending on configuration, the switch may drop excess traffic or take another defined protective action. Root Guard protects spanning-tree topology, DHCP relay forwards DHCP messages, and SFTP provides secure file transfer. Therefore, storm control provides the required traffic-storm mitigation.<\/span><\/p>\n<h3><b>Question 388<\/b><\/h3>\n<p><b>Which spanning-tree security feature prevents an unauthorized switch from becoming the root bridge on a protected interface?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BPDU Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Root Guard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">PortFast<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP snooping<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Root Guard protects the intended spanning-tree topology by preventing a protected interface from accepting superior Bridge Protocol Data Units that could cause an unauthorized switch to become the root bridge. If an unexpected superior BPDU is received, the affected interface can enter a restricted state until the condition is resolved. BPDU Filter suppresses or filters BPDUs, PortFast accelerates edge-port transition, and DHCP snooping protects DHCP exchanges. Therefore, Root Guard provides the required protection against unauthorized root-bridge influence.<\/span><\/p>\n<h3><b>Question 389<\/b><\/h3>\n<p><b>Which secure file-transfer protocol provides encrypted authentication and data transfer by operating through SSH?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TFTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SFTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HTTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Secure File Transfer Protocol, or SFTP, provides file-transfer capabilities through the SSH framework. It protects authentication and file data using the cryptographic protections provided by SSH. This makes it appropriate for securely transferring configuration files, logs, and other sensitive information across untrusted networks. Traditional FTP and TFTP do not provide equivalent built-in encryption, while HTTP is primarily designed for web communication. Therefore, SFTP provides the secure file-transfer mechanism described.<\/span><\/p>\n<h3><b>Question 390<\/b><\/h3>\n<p><b>Which authentication protocol commonly uses TCP and provides centralized authentication, authorization, and accounting for network-device administrators?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TACACS+<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RADIUS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SNMPv3<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LDAP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">TACACS+ is commonly used for centralized administrative access to network devices. It uses TCP and separates authentication, authorization, and accounting functions, allowing organizations to control administrator access and record administrative activity. This is particularly useful when different administrators require different command permissions. RADIUS commonly uses UDP and is widely used for network access authentication, SNMPv3 provides secure network management, and LDAP provides directory services. Therefore, TACACS+ provides the described administrative AAA capability.<\/span><\/p>\n<h3><b>Question 391<\/b><\/h3>\n<p><b>Which network-access mechanism can dynamically change a user&#8217;s authorization or network policy after authentication has already occurred?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP snooping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Change of Authorization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNSSEC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MACsec<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Change of Authorization, or CoA, allows an authentication or access-control system to modify an existing session&#8217;s authorization after the initial authentication process. For example, a user&#8217;s access level can be changed when a posture assessment changes, an account is disabled, or a security policy requires immediate restriction. DHCP snooping protects DHCP behavior, DNSSEC protects DNS integrity, and MACsec protects Ethernet frames. Therefore, CoA provides the dynamic authorization mechanism described.<\/span><\/p>\n<h3><b>Question 392<\/b><\/h3>\n<p><b>Which security capability can quarantine a device when its security posture no longer meets the organization&#8217;s access requirements?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network Access Control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS caching<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route redistribution<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT traversal<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network Access Control can evaluate device identity and posture before or during network access and apply appropriate authorization policies. If an endpoint fails required security checks, the NAC system can restrict access, place the device into a remediation network, or otherwise quarantine it according to policy. This helps prevent noncompliant devices from obtaining unrestricted access to sensitive resources. DNS caching stores query results, route redistribution exchanges routing information, and NAT traversal supports IPsec through NAT. Therefore, NAC provides the described access-enforcement capability.<\/span><\/p>\n<h3><b>Question 393<\/b><\/h3>\n<p><b>Which security mechanism can detect an attempt to overwhelm a server with a large number of incomplete TCP connection requests?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SYN flood detection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNSSEC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File integrity monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SFTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A SYN flood attempts to exhaust server resources by sending large numbers of TCP connection requests without completing the connection establishment process. Security devices can identify abnormal SYN behavior and apply controls such as rate limiting, connection thresholds, or other mitigation techniques. DNSSEC protects DNS data, file integrity monitoring detects changes to files, and SFTP provides secure file transfer. Therefore, SYN flood detection provides the capability needed to identify this type of denial-of-service activity.<\/span><\/p>\n<h3><b>Question 394<\/b><\/h3>\n<p><b>Which security technology monitors critical files and alerts administrators when unauthorized modifications occur?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DLP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File Integrity Monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CASB<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SWG<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">File Integrity Monitoring, or FIM, tracks important files and detects changes to their contents, attributes, permissions, or other monitored properties. Unexpected modifications can indicate malware activity, unauthorized administrative actions, configuration tampering, or compromise. FIM can generate alerts that help security teams investigate potentially suspicious changes. DLP focuses on sensitive-data movement, CASB manages cloud-service security, and SWG secures web access. Therefore, FIM provides the required file-change detection capability.<\/span><\/p>\n<h3><b>Question 395<\/b><\/h3>\n<p><b>Which security control can identify unauthorized changes to a software package or configuration file by comparing its current cryptographic digest with a trusted value?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hash verification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN pruning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SPAN<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Hash verification can identify unauthorized changes by calculating a cryptographic digest of a file and comparing it with a previously trusted digest. If the values differ, the file contents have changed, although the comparison alone does not necessarily establish whether the change was malicious or authorized. This technique is useful for software integrity, configuration validation, and forensic analysis. VLAN pruning controls VLAN propagation, NAT translates addresses, and SPAN mirrors traffic. Therefore, hash verification provides the described integrity check.<\/span><\/p>\n<h3><b>Question 396<\/b><\/h3>\n<p><b>Which security capability helps identify whether a user account is being accessed from an unusual geographic location or device compared with its normal behavior?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SIEM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">UEBA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP relay<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port security<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">User and Entity Behavior Analytics can establish normal behavioral patterns for users and entities and identify significant deviations. An unexpected geographic location, unfamiliar device, unusual access time, or abnormal resource usage can indicate compromised credentials or suspicious activity. UEBA can generate risk indicators that security teams can investigate alongside other security events. SIEM aggregates and correlates events, DHCP relay forwards DHCP messages, and port security restricts switch-port access. Therefore, UEBA provides the behavioral-anomaly capability described.<\/span><\/p>\n<h3><b>Question 397<\/b><\/h3>\n<p><b>Which security technology can inspect outbound web requests and block access based on website category, reputation, or organizational policy?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secure Web Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MACsec<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RPKI<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SNMPv3<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Secure Web Gateway provides centralized security controls for users&#8217; web traffic. It can enforce policies based on URL categories, destination reputation, user identity, application characteristics, and other conditions. Depending on configuration, it can also integrate malware inspection and other security functions. MACsec protects Ethernet frames, RPKI validates BGP route origins, and SNMPv3 provides secure network management. Therefore, Secure Web Gateway provides the web-access filtering capability described.<\/span><\/p>\n<h3><b>Question 398<\/b><\/h3>\n<p><b>Which security architecture verifies identity, device context, and authorization policy before granting access to a specific application rather than trusting a user&#8217;s network location?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traditional perimeter security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Zero Trust<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN trunking<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Zero Trust treats access as a policy decision that should be continuously evaluated rather than assuming that a user is trustworthy because the user is located inside a particular network. Identity, device posture, resource sensitivity, and other contextual information can be considered before access is granted. This approach supports least privilege and reduces reliance on broad network-level trust. Traditional perimeter security relies more heavily on network boundaries, while static routing and VLAN trunking provide network functions rather than identity-based access decisions. Therefore, Zero Trust matches the requirement.<\/span><\/p>\n<h3><b>Question 399<\/b><\/h3>\n<p><b>Which security capability can identify and block malicious files by analyzing their behavior in an isolated environment before allowing them to reach an endpoint?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Sandboxing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route filtering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN tagging<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Sandboxing executes suspicious files or objects in an isolated environment so their behavior can be observed without exposing production systems directly. Security systems can analyze activities such as process creation, file modifications, network connections, and other indicators to determine whether a sample behaves maliciously. This approach can detect threats that may not yet have reliable static signatures. Route filtering controls routing information, NTP authentication protects time synchronization, and VLAN tagging identifies VLAN membership. Therefore, sandboxing provides the described behavioral-analysis capability.<\/span><\/p>\n<h3><b>Question 400<\/b><\/h3>\n<p><b>Which security process compares identified vulnerabilities with available threat intelligence and asset information to determine which issues should be addressed first?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vulnerability prioritization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Packet capture<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network address translation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate enrollment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Vulnerability prioritization determines which identified weaknesses require attention first by considering factors beyond technical severity alone. Security teams can combine vulnerability information with asset criticality, exposure, exploit availability, threat intelligence, business impact, and other contextual factors. This helps organizations direct limited remediation resources toward the issues that present the most significant operational risk. Packet capture records network traffic, NAT translates addresses, and certificate enrollment obtains digital certificates. Therefore, vulnerability prioritization provides the required risk-based remediation process.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco 350-701 Exam Dumps and Practice Test Dumps. &nbsp; Question 381 Which control can prevent unauthorized devices from using a switch port by limiting the MAC addresses permitted on that interface? DHCP snooping Port security DNSSEC NetFlow Correct Answer: 2 Explanation Port security can restrict which MAC addresses are permitted to use a [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20932"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=20932"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20932\/revisions"}],"predecessor-version":[{"id":20933,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20932\/revisions\/20933"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=20932"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=20932"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=20932"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}