Cisco CCNP Security Core (SCOR) 350-701 practice questions

211 free questions with answers and explanations.

Practice test
  1. 1.A financial institution is implementing a new customer data platform. To comply with various industry regulations (e.g., PCI DSS, GDPR) and internal security standards, the development team is required to follow strict guidelines for data handling, access control, and encryption. These guidelines are formally documented and communicated across all relevant departments. Which security concept do these guidelines primarily represent?Security Concepts
  2. 2.A security architect is evaluating different cloud deployment models for a new application that will process highly sensitive intellectual property. The primary concern is maintaining maximum control over the underlying infrastructure and ensuring complete data isolation, while still benefiting from some aspects of cloud elasticity. Which cloud deployment model would best meet these requirements?Cloud Security
  3. 3.A security analyst is conducting a post-incident review after a successful ransomware attack. The review reveals that several critical servers were not included in the regular patching schedule, and their operating systems were severely outdated. Furthermore, there was no comprehensive inventory of all IT assets, making it difficult to quickly identify affected systems and their owners during the incident. Which security best practice, if properly implemented, could have significantly mitigated the impact of this incident?Security Concepts
  4. 4.A global enterprise is migrating its sensitive customer data to a public cloud provider. Due to regulatory compliance requirements (e.g., GDPR), the company must ensure that encryption keys for this data are generated and managed in a hardware-secured environment and remain under the company's sole control. Which cloud security service best addresses this specific requirement?Cloud Security
  5. 5.A global organization is implementing a cloud security strategy that prioritizes the ability to automatically enforce security policies and respond to threats across its multi-cloud environment without human intervention. This includes automated patching, configuration drift detection, and incident response workflows. Which security automation and orchestration concept is being applied here?Cloud Security
  6. 6.A security auditor is reviewing an organization's endpoint security posture. The auditor identifies that while traditional antivirus is deployed, there is no mechanism to detect advanced persistent threats (APTs) that bypass signature-based detection or to provide visibility into endpoint activities post-compromise. The organization needs a solution that can identify stealthy attacks, provide deep forensic capabilities, and enable rapid containment. Which endpoint security technology should the auditor recommend?Endpoint Security and Secure Network Access
  7. 7.A global technology company is expanding its operations into new countries, each with unique data residency and privacy laws. The company's security team must ensure that their data handling practices comply with all applicable regulations worldwide. Which aspect of security governance is most critical in this scenario?Security Concepts
  8. 8.A global enterprise is deploying a new application across multiple cloud regions to improve latency and resilience. Due to strict data residency regulations, certain types of sensitive customer data must remain within specific geographic boundaries. Which cloud security architecture principle is most relevant for ensuring compliance in this scenario?Cloud Security
  9. 9.A security engineer is tasked with securing a serverless application deployed on AWS Lambda. The application processes user requests and interacts with an Amazon S3 bucket. Which security control is paramount to limit the S3 bucket's exposure only to the specific Lambda function and prevent unauthorized access?Cloud Security
  10. 10.A security engineer is designing a secure network access solution for a campus network. The design requires that all endpoints, including corporate laptops, personal mobile devices, and IoT sensors, are authenticated and authorized before gaining access to network resources. Which network access control (NAC) component is primarily responsible for evaluating the endpoint's compliance with security policies and assigning appropriate network access privileges?Endpoint Security and Secure Network Access
  11. 11.A security analyst is investigating a potential breach where an unauthorized device gained access to the internal network. The network uses 802.1X authentication. Upon initial investigation, it was discovered that the attacker bypassed 802.1X by connecting their malicious device to an already authenticated IP phone, leveraging the phone's authenticated port. What 802.1X feature should have been enabled on the switch port to prevent this specific attack vector?Endpoint Security and Secure Network Access
  12. 12.A security architect is designing an endpoint security architecture that must protect against fileless malware and ransomware, provide deep visibility into endpoint processes, and offer rapid response capabilities across a hybrid environment. The solution must integrate seamlessly with existing security operations tools. Which modern endpoint security solution best meets these requirements?Endpoint Security and Secure Network Access
  13. 13.A security engineer is implementing a new wireless network that must support a mix of corporate devices (laptops, phones) and guest devices. Corporate devices must use strong, certificate-based authentication, while guest devices require a simple, web-based authentication method. Both types of devices need to be placed in separate, isolated network segments with different access policies. Which combination of 802.1X and network access control features would best achieve these requirements?Endpoint Security and Secure Network Access
  14. 14.A security analyst is investigating a recent breach where an unauthorized external party gained access to the company's internal network. The attacker exploited a known vulnerability in an unpatched web server and exfiltrated sensitive customer data. Which security principle was primarily compromised in this scenario?Security Concepts
  15. 15.A security auditor is reviewing an organization's endpoint security posture. The auditor discovers that several critical servers are running outdated operating systems and lack current security patches, making them vulnerable to known exploits. However, these servers cannot be immediately upgraded due to application compatibility issues. Which endpoint security design principle should be prioritized to mitigate the risk posed by these vulnerable servers without directly upgrading them?Endpoint Security and Secure Network Access
  16. 16.An organization is deploying a new containerized application using Kubernetes in a public cloud. The security team needs to ensure that containers are scanned for vulnerabilities before deployment and that only approved images from a trusted registry are used. Which cloud security tool or practice is most effective for achieving this goal?Cloud Security
  17. 17.During an incident response, a security analyst discovers that a threat actor has modified critical system files to maintain persistence and hide their activities. The analyst needs to restore the system to a known good state. Which core security principle has been directly compromised by the file modifications?Security Concepts
  18. 18.A cloud architect is designing a highly available and resilient multi-region application in a public cloud. The application's database tier needs to ensure data consistency across regions while remaining accessible even if an entire region becomes unavailable. Which database deployment strategy is most suitable for meeting both high availability and strong consistency requirements in a multi-region cloud environment?Cloud Security
  19. 19.A security architect is integrating an on-premises Active Directory with a cloud-based Software as a Service (SaaS) application to provide single sign-on (SSO) capabilities. The goal is to allow users to authenticate once using their existing corporate credentials and access the SaaS application without re-entering them. Which protocol is commonly used to facilitate this federated identity management in cloud environments?Cloud Security
  20. 20.A security operations center (SOC) team is struggling to keep up with the volume of security alerts generated by their cloud environment. They need a solution that can automatically collect security data from various cloud services, correlate events, and execute predefined incident response playbooks without human intervention for common, low-risk incidents. Which cloud security technology would best integrate these capabilities?Cloud Security
  21. 21.A security auditor is reviewing an organization's endpoint security posture. The auditor notes that while traditional antivirus is deployed, there's a lack of visibility into post-compromise activity, such as lateral movement, privilege escalation, and data exfiltration attempts. The organization needs a solution that can retrospectively analyze endpoint data to identify hidden threats and provide detailed forensic information for incident response. Which technology is specifically designed to address these gaps?Endpoint Security and Secure Network Access
  22. 22.A company is integrating its Cisco Secure Web Appliance (WSA) with its existing identity management system (Cisco ISE) to implement user-based web access policies. The goal is to ensure that different user groups (e.g., 'Developers', 'Marketing') have varying levels of internet access and content filtering, and that these policies follow users regardless of which device they use or where they connect from within the corporate network. Which integration method is most effective for achieving this user-aware content security?Content Security
  23. 23.A network security administrator is configuring 802.1X authentication on a Cisco Catalyst switch. The goal is to allow endpoints to connect only after successful authentication against a RADIUS server. Which command sequence would correctly enable 802.1X port-based authentication on a specific interface and specify the authentication method list?Endpoint Security and Secure Network Access
  24. 24.A network security architect is designing a content security solution for a large enterprise. The design must ensure that all HTTP/HTTPS traffic is inspected for malware and sensitive data, even if the traffic is encrypted. The solution needs to integrate with existing Active Directory for user-based policies and provide granular reporting on web usage. Where should SSL decryption be performed in the content inspection flow to maximize effectiveness and minimize performance impact?Content Security
  25. 25.An organization is deploying a Cisco Firepower Threat Defense (FTD) appliance and needs to define custom application signatures to accurately identify and control a proprietary internal application that uses a unique protocol header. Which configuration element within Firepower Management Center (FMC) allows for the creation of these custom application identities?Content Security
  26. 26.A large enterprise is designing a highly available and secure multi-cloud architecture. They need to ensure that their applications can failover seamlessly between different cloud providers in the event of a regional outage or security incident, while maintaining consistent security posture. Which architectural pattern is most suitable for this stringent requirement?Cloud Security
  27. 27.A security architect is designing an endpoint security solution for a critical industrial control system (ICS) network. The ICS endpoints are legacy systems that cannot run modern security agents or be frequently patched. The primary goal is to prevent unauthorized network access and lateral movement, treating every connection attempt as suspicious. Which secure network access design principle should be prioritized to segment and protect these vulnerable ICS endpoints?Endpoint Security and Secure Network Access
  28. 28.A security engineer is troubleshooting an issue where legitimate software updates from a vendor's content delivery network (CDN) are being blocked by a Cisco Firepower Threat Defense (FTD) device. The FTD is configured with a strict file policy that blocks all executable files from untrusted sources. The vendor's CDN uses multiple, frequently changing IP addresses. Which FTD content security feature should the engineer adjust or configure to specifically allow these legitimate software updates while maintaining the strict file policy for other traffic?Content Security
  29. 29.A newly appointed Chief Information Security Officer (CISO) is tasked with establishing a unified, organization-wide approach to managing cybersecurity risks. The CISO wants to adopt a set of guidelines and best practices that provide a common language and systematic methodology for identifying, assessing, and responding to cyber threats. Which foundational security concept should the CISO prioritize implementing?Security Concepts
  30. 30.A financial services organization is adopting a multi-cloud strategy. They need a solution to ensure consistent security policies, identity management, and compliance enforcement across different cloud providers (e.g., AWS, Azure, GCP). The solution should provide a unified view of their security posture and automate policy enforcement without requiring separate configurations for each cloud. Which approach would be most effective?Cloud Security
  31. 31.A company is implementing a zero-trust security model. As part of this, every network access attempt, whether from internal or external users, must be continuously verified and authorized based on real-time context. Which principle of zero trust emphasizes that access decisions are not static but are re-evaluated throughout the user's session?Endpoint Security and Secure Network Access
  32. 32.A security engineer is tasked with optimizing the performance of a Cisco Secure Web Appliance (WSA) while maintaining robust security. The goal is to reduce latency for frequently accessed legitimate websites by storing copies of web content locally. Which WSA feature is primarily responsible for this performance enhancement?Content Security
  33. 33.An organization is deploying a new application to a public cloud provider and needs to ensure that all network traffic between different virtual machines (VMs) within the same virtual private cloud (VPC) is inspected for malicious activity. Which cloud security technology is best suited to perform deep packet inspection and intrusion prevention for this East-West traffic?Cloud Security
  34. 34.A company is adopting a 'zero-trust' security model for its cloud environment. They are implementing strict access controls for all internal and external communication. Which core tenet of zero-trust architecture directly addresses the need to continuously verify the legitimacy of every access attempt, regardless of its origin?Cloud Security
  35. 35.A security team is implementing a network segmentation strategy using Cisco TrustSec. The goal is to classify users and devices into logical groups and apply security policies based on these groups, regardless of their IP address or network location. Which core element of Cisco TrustSec is responsible for assigning these logical labels to network traffic, enabling policy enforcement?Endpoint Security and Secure Network Access
  36. 36.A security architect is designing a cloud security solution for a global organization that uses multiple Software-as-a-Service (SaaS) applications, including Salesforce, Microsoft 365, and Dropbox. The organization needs to enforce consistent security policies, monitor user activity, detect anomalous behavior, and prevent data leakage across all these disparate SaaS applications. Which cloud security technology is purpose-built to address these challenges?Cloud Security
  37. 37.A security architect is designing a secure network access solution for a large enterprise with diverse user roles and device types. The solution must provide granular access control based on user identity, device posture, and application being accessed. Which component is primarily responsible for evaluating the authorization policies and making access decisions in such a system?Endpoint Security and Secure Network Access
  38. 38.A company is experiencing an increase in phishing attacks where users are tricked into downloading malicious documents (e.g., weaponized PDFs or Microsoft Office files) from legitimate-looking websites. The existing content security solutions include a Secure Web Gateway (SWG) and an Email Security Gateway (ESG). To specifically address this threat, which additional content security technology would provide the most effective layer of defense against these types of attacks delivered via web downloads?Content Security
  39. 39.A security engineer is configuring a Cisco Secure Web Appliance (WSA) to provide granular control over web traffic. The organization requires that users are allowed to access most social media sites but must be blocked from uploading any files to these sites. Which WSA feature should the engineer use to achieve this specific requirement?Content Security
  40. 40.A manufacturing company is integrating IoT devices into its production network. These devices have limited computational resources, do not support complex authentication protocols like 802.1X, and need to communicate only with specific industrial control systems (ICS). The security team needs to implement a secure network access solution that segments these IoT devices, restricts their communication, and provides a robust alternative to traditional authentication. Which secure network access protocol or method is best suited for securing these resource-constrained IoT devices?Endpoint Security and Secure Network Access
  41. 41.An organization is deploying Cisco Secure Client (formerly AnyConnect) for remote access VPN. The security policy dictates that all remote users must use multi-factor authentication (MFA) and their devices must pass a posture assessment before establishing a VPN tunnel. Which two Cisco ISE components are crucial for enforcing these requirements during the VPN connection process?Endpoint Security and Secure Network Access
  42. 42.A security auditor is reviewing the access control implementation for a cloud-based data lake containing sensitive customer information. The auditor notes that access policies are defined based on the user's role (e.g., 'data analyst', 'developer', 'auditor') and their specific job functions, granting only the necessary permissions to perform their tasks. Which access control model is being utilized?Cloud Security
  43. 43.A global company is expanding its operations and requires a secure and scalable solution for managing access to network resources across various branch offices and cloud environments. The solution must centralize authentication, authorization, and accounting (AAA) services, provide granular access control based on user and device attributes, and integrate with existing identity stores. Which Cisco secure network access architecture is designed to meet these comprehensive requirements, offering a unified policy enforcement framework?Endpoint Security and Secure Network Access
  44. 44.A security architect is designing a secure network architecture for a cloud-native application. The application consists of several microservices, and each microservice needs to communicate securely with specific other microservices and a backend database. Overly broad network access rules are a concern. Which security principle should be applied to restrict communication between these components to only what is absolutely necessary?Cloud Security
  45. 45.A financial institution is required to undergo an annual external audit of its information systems to ensure compliance with industry regulations and standards. This audit specifically aims to verify the effectiveness of implemented security controls and identify any significant deficiencies. Which type of security assessment is being performed?Security Concepts
  46. 46.A financial institution is migrating its legacy applications to a multi-cloud environment. They require a robust solution to enforce consistent security policies, detect shadow IT, and prevent data leakage across all cloud services, including SaaS, PaaS, and IaaS. Which cloud security technology is specifically designed to address these comprehensive requirements?Cloud Security
  47. 47.A financial institution is deploying a new application to a public cloud provider. Due to stringent regulatory requirements (e.g., PCI DSS), network traffic between different security zones within the cloud environment (e.g., web tier, application tier, database tier) must be strictly isolated and inspected. Which cloud network security component provides granular, stateful inspection and filtering of traffic between these zones?Cloud Security
  48. 48.A global technology company is expanding its operations into new countries, each with unique data protection laws (e.g., GDPR in Europe, CCPA in California, LGPD in Brazil). The legal and compliance team is tasked with ensuring that the company's data handling practices, consent mechanisms, and cross-border data transfers adhere to all applicable regulations in every region it operates. Which security concept is this team primarily addressing?Security Concepts
  49. 49.A security engineer is configuring a Cisco Secure Web Appliance (WSA) to enforce strict acceptable use policies and block access to specific categories of websites (e.g., gambling, adult content). The organization also needs to ensure that users cannot bypass these policies by using anonymizing proxies. Which two WSA features, when used together, are most effective for these requirements?Content Security
  50. 50.A managed security service provider (MSSP) is offering a new service to protect client endpoints from fileless malware and ransomware. The service must include advanced behavioral analysis, machine learning for threat detection, and the ability to roll back malicious changes. Traditional signature-based antivirus solutions are not sufficient. Which Cisco endpoint security technology is best suited to fulfill these requirements?Endpoint Security and Secure Network Access