Cisco CCNP Security Core (SCOR) 350-701 practice questions
211 free questions with answers and explanations.
- 101.A multinational corporation is developing a new global data privacy policy. They must ensure compliance with GDPR in Europe, CCPA in California, and various other regional regulations. Which aspect of security governance is primarily addressed by this effort?Security Concepts
- 102.A company is utilizing a PaaS offering to host its application. The PaaS provider manages the operating system, runtime, and middleware. The company's security team is responsible for securing the application code and data. According to the shared responsibility model, what is the primary security concern for the company in this scenario?Cloud Security
- 103.An organization relies heavily on a high-availability clustered database system for its critical business applications. A recent analysis revealed that while the database itself is resilient, the underlying network infrastructure has several single points of failure that could lead to a complete outage. To address this, the security team proposes implementing redundant network paths and devices. This initiative directly supports which aspect of the CIA triad?Security Concepts
- 104.A large organization is deploying a new secure network access solution. The security team wants to segment network resources based on user roles and device types, ensuring that a sales laptop has different access privileges than an engineering workstation, even if both are on the same physical network segment. Which Cisco technology should be implemented to achieve this granular level of access control and dynamic policy enforcement?Endpoint Security and Secure Network Access
- 105.A network security team is deploying a new wireless network and needs to ensure secure access for both corporate devices and guests. Corporate devices must use 802.1X with certificates for authentication, while guests should use a web-based portal. Which secure network access technology provides the flexibility to support both authentication methods from a single wireless infrastructure?Endpoint Security and Secure Network Access
- 106.A financial institution is implementing a new customer data platform. To comply with various industry regulations and data protection laws, they need to establish a set of rules and practices that dictate how information security is managed throughout the organization. Which component of security governance best describes this requirement?Security Concepts
- 107.A security engineer is configuring a Cisco Firepower Threat Defense (FTD) device to apply different security policies based on user identity, rather than just IP address. This requires integration with the organization's Active Directory. Which Firepower Management Center (FMC) feature must be configured to achieve this identity-based content security enforcement?Content Security
- 108.A security team is developing a strategy to protect sensitive data from unauthorized access, modification, and destruction. Which core security principle is primarily concerned with ensuring that information is accessible and usable when needed by authorized entities?Security Concepts
- 109.A global company is expanding its operations and requires a secure and scalable solution for managing network access policies across multiple geographically dispersed sites. The solution must provide centralized authentication, authorization, and accounting (AAA) services, integrate with various network devices (switches, WAPs, VPN gateways), and support advanced posture assessment for endpoints. Which Cisco product is best suited to meet these requirements?Endpoint Security and Secure Network Access
- 110.A security analyst is investigating a suspected malware infection on an endpoint that bypassed traditional antivirus. The analyst needs to understand the full scope of the attack, including process spawns, file modifications, and network connections originating from the compromised host, to contain and remediate effectively. Which endpoint security technology is best suited for this detailed forensic analysis and threat hunting?Endpoint Security and Secure Network Access
- 111.A security architect is designing a secure network access solution for a large university campus. The solution must support a diverse range of devices, including student laptops, faculty desktops, IoT devices in labs, and guest mobile phones. The architect wants to ensure that each device type receives appropriate network access policies based on its identity and security posture. Which component of a secure network access solution is primarily responsible for evaluating device identity and health against predefined policies to grant or deny access?Endpoint Security and Secure Network Access
- 112.A security engineer is designing a secure network access solution for a new data center that hosts critical applications. The design must ensure that only authorized servers can communicate with each other, minimizing the attack surface even if a server is compromised. Traditional VLANs are deemed insufficient due to flat access control capabilities within a VLAN. Which approach using Cisco technologies would best achieve this granular segmentation and policy enforcement within the data center?Endpoint Security and Secure Network Access
- 113.A security team is evaluating the effectiveness of its incident response process. They collect data on the Mean Time To Detect (MTTD) and Mean Time To Respond (MTTR) for various types of incidents over the past year. This data is then presented to management to show trends and identify areas for improvement. Which security concept is this activity primarily focused on?Security Concepts
- 114.A security auditor recommends implementing a content security solution that can prevent sensitive data from leaving the network via email, web uploads, and endpoint devices simultaneously. The solution must also provide detailed reporting on data movement and policy violations. Which content security technology offers this comprehensive, multi-channel data protection and visibility?Content Security
- 115.A company is experiencing an increase in phishing attacks targeting its employees. To combat this, they decide to launch a series of simulated phishing campaigns and provide interactive training modules to help employees recognize and report suspicious emails. Which security best practice are they primarily implementing?Security Concepts
- 116.A company is developing a new cloud-native application using serverless functions and containers. The security team wants to embed security checks throughout the CI/CD pipeline, from code commit to deployment, to identify vulnerabilities and misconfigurations as early as possible. This approach aims to reduce the cost and effort of fixing security issues later in the development lifecycle. Which security principle or methodology are they applying?Cloud Security
- 117.A Chief Information Security Officer (CISO) is developing a strategy to align the organization's security initiatives with its overall business objectives and risk appetite. The CISO wants to ensure that security investments are prioritized based on their impact on business goals and regulatory requirements. Which aspect of security concepts is the CISO primarily focusing on?Security Concepts
- 118.A company is developing a new mobile application that will handle sensitive customer data. Before deployment, they engage a third-party firm to conduct a comprehensive review of the application's source code, architecture, and deployment environment to identify design flaws and potential vulnerabilities. This activity is a form of:Security Concepts
- 119.A security administrator is configuring a new Cisco Router to enforce secure network access policies. The administrator needs to ensure that only authenticated users from specific departments can access the internal network segments. Which feature, when configured on the router, allows for dynamic policy assignment based on user identity and group membership, rather than static IP addresses or VLANs?Endpoint Security and Secure Network Access
- 120.A security analyst is investigating a suspected malware infection on an endpoint that bypassed traditional antivirus solutions. The malware exhibits advanced persistent threat (APT) characteristics, including fileless execution and lateral movement attempts. Which endpoint security technology is best suited to detect and respond to such sophisticated threats by continuously monitoring endpoint activity and providing deep visibility for forensic analysis?Endpoint Security and Secure Network Access
- 121.A security team is implementing a cloud security strategy. They are concerned about the risk of a single point of failure and want to ensure business continuity in case of a regional outage from their primary cloud provider. Which strategy addresses this concern by distributing workloads across different cloud providers?Cloud Security
- 122.A company is implementing a bring-your-own-device (BYOD) policy and needs to ensure that personal mobile devices accessing corporate Wi-Fi meet minimum security requirements, such as having a screen lock enabled and a specific antivirus app installed. Which endpoint security technology is best suited to assess and enforce these compliance checks dynamically before granting network access?Endpoint Security and Secure Network Access
- 123.An organization is adopting a serverless architecture for its new application, utilizing AWS Lambda, API Gateway, and DynamoDB. The security team is concerned about potential vulnerabilities introduced through the custom code deployed in Lambda functions, as well as maintaining proper access controls between the serverless components. Which security best practice is crucial for minimizing the attack surface and ensuring secure communication and execution within this serverless environment?Cloud Security
- 124.A security administrator is evaluating content security solutions for an industrial control system (ICS) network. The ICS network has stringent requirements for low latency and deterministic behavior. Internet access from the ICS network is highly restricted, but necessary for critical updates from specific vendor sites. Which content security strategy is most appropriate for this environment, prioritizing security without compromising operational integrity?Content Security
- 125.A security team is deploying a new Cisco Secure Email Gateway (formerly ESA) to protect against advanced email threats. The requirement is to identify and quarantine emails that contain suspicious attachments, such as obfuscated executables or password-protected archives, before they reach user inboxes. The solution should also analyze the behavior of these attachments in a safe environment. Which content security feature directly addresses this requirement?Content Security
- 126.A security engineer is evaluating different cloud deployment models for a new application that will process highly sensitive intellectual property. The primary concern is maintaining complete control over the underlying infrastructure and data, with strict regulatory compliance requirements preventing data from residing on shared hardware. Which cloud deployment model would best meet these requirements?Cloud Security
- 127.A security engineer is configuring a Cisco Secure Endpoint (formerly AMP for Endpoints) deployment. The organization has strict requirements for blocking advanced threats, including polymorphic malware and fileless attacks, while minimizing false positives. Which protection engine within Cisco Secure Endpoint is primarily responsible for detecting these sophisticated threats using behavioral analysis and machine learning?Endpoint Security and Secure Network Access
- 128.A security team needs to implement a solution that provides real-time visibility into application usage, user behavior, and potential threats within SaaS applications like Office 365 and Salesforce. The solution must also enforce data loss prevention policies for data stored and shared within these cloud applications. Which content security technology is designed for this specific purpose?Content Security
- 129.A security architect is evaluating a cloud provider's API security. The provider uses OAuth 2.0 for authorization. The architect notes that client applications are granted access tokens directly after user authentication without an authorization server mediating the process. Which OAuth 2.0 flow is being improperly used or misinterpreted, leading to a potential security vulnerability?Cloud Security
- 130.A security auditor is reviewing the access control implementation for a cloud-based data lake containing highly sensitive customer information. The current setup relies solely on network-based access control lists (ACLs) to restrict access to the storage endpoints. What is the most significant security gap in this approach for protecting sensitive data in the cloud?Cloud Security
- 131.A security team is implementing a network segmentation strategy using Cisco TrustSec. The goal is to classify users and devices into logical groups and apply security policies based on these groups, rather than IP addresses or VLANs. Which key component of Cisco TrustSec is responsible for assigning a Security Group Tag (SGT) to each authenticated user or device?Endpoint Security and Secure Network Access
- 132.A global enterprise is migrating its legacy applications to a multi-cloud environment. The security team identifies a significant challenge in maintaining consistent security policies and visibility across different cloud providers, each with its own native security tools and APIs. They need a solution that can centralize security policy enforcement, threat detection, and incident response across all cloud platforms. Which advanced cloud security solution would best address this need?Cloud Security
- 133.A network security team is designing a secure network access solution for a new research and development (R&D) facility. The design requires that network devices (switches, routers) automatically apply appropriate security policies (e.g., VLAN assignments, ACLs) to connected endpoints based on their role and compliance status, without manual intervention. This dynamic policy assignment must be achieved through integration with a centralized authentication and authorization server. Which protocol is primarily used by the network devices to communicate with the centralized server for this dynamic policy enforcement?Endpoint Security and Secure Network Access
- 134.A security team is implementing a new SIEM solution. They want to ensure that the SIEM can effectively correlate events and detect advanced threats. To achieve this, they need to integrate threat intelligence feeds from various sources, including government agencies and private security vendors. This integration directly enhances which aspect of security operations?Security Concepts
- 135.A security engineer is configuring a Cisco Secure Web Appliance (WSA) to prevent users from uploading sensitive company documents to unauthorized cloud storage services. The solution needs to identify specific types of data, such as credit card numbers and intellectual property, within HTTP/HTTPS uploads. Which feature of the WSA would be most effective for this requirement?Content Security
- 136.A security team is implementing a new endpoint detection and response (EDR) solution. Before full deployment, they conduct a pilot program with a small group of users to identify potential issues and gather feedback. This approach is an example of which security best practice?Security Concepts
- 137.A security engineer is configuring a Cisco Secure Endpoint (formerly AMP for Endpoints) deployment. The organization has identified a new, highly evasive custom malware strain used in targeted attacks. To ensure maximum protection, the engineer wants to deploy a detection engine that can analyze suspicious files in a cloud-based sandbox environment to identify malicious behavior that might bypass static analysis. Which Cisco Secure Endpoint engine should the engineer prioritize for this capability?Endpoint Security and Secure Network Access
- 138.A cloud security engineer needs to implement a solution that automatically identifies and remediates misconfigurations in their AWS environment, such as S3 buckets with public access or security groups allowing unrestricted SSH access (0.0.0.0/0). The solution should continuously monitor the environment and provide compliance reporting. Which specialized cloud security tool is designed for this purpose?Cloud Security
- 139.A large enterprise is migrating its on-premises infrastructure to a public cloud provider. The security team needs to ensure that network security policies, such as microsegmentation and automated threat response, can be consistently applied across both the cloud environment and the remaining on-premises data centers. Which network security architecture concept is most relevant for achieving this consistent and agile security posture?Network Security
- 140.A network security engineer is deploying a new intrusion prevention system (IPS) to protect critical internal servers. After initial deployment, legitimate applications are experiencing intermittent connectivity issues and slow performance. Further investigation reveals that the IPS is dropping packets for these applications. What is the most likely cause of this issue?Network Security
- 141.An organization is migrating its data center to a hybrid cloud environment. They need to ensure consistent security policies and visibility across both on-premises and cloud-based virtualized workloads. Traditional perimeter-based firewalls are proving inadequate for securing East-West traffic within the cloud. Which technology offers a centralized, programmable approach to enforce granular security policies across this hybrid infrastructure?Network Security
- 142.A network administrator is configuring a Cisco ASA firewall to allow internal users to access external web servers. The internal network uses private IP addresses (10.0.0.0/8), and the ASA has a single public IP address for outbound internet access. The administrator wants to configure NAT so that multiple internal hosts can share this single public IP address for their outbound connections. Which type of NAT should the administrator configure?Network Security
- 143.A network security team is designing a defense strategy against Distributed Denial of Service (DDoS) attacks. They need a solution that can identify and mitigate large-scale volumetric attacks, protocol attacks, and application-layer attacks without significantly impacting legitimate traffic. Which security measure is most effective for comprehensive DDoS protection?Network Security
- 144.A network security administrator is configuring a Cisco router to protect against spoofed IP addresses originating from within the internal network. The administrator wants to ensure that only IP addresses assigned to specific interfaces can be used for outbound traffic, preventing an attacker from sending packets with a forged source IP. Which feature should be enabled to achieve this ingress filtering?Network Security
- 145.A managed security service provider (MSSP) is advising a client on securing their cloud infrastructure. The client wants to ensure that virtual machines (VMs) running sensitive applications are isolated from other VMs in the same cloud environment, even if they reside on the same physical host. Which security concept should the MSSP recommend?Network Security
- 146.A security team is implementing a network segmentation strategy to isolate critical servers from the general user network. They have deployed a firewall between these segments. To further enhance security, they want to limit the protocols allowed to communicate with the critical servers to only the absolute necessities. This approach aligns with which security best practice?Network Security
- 147.A security analyst is investigating a compromised internal server that was accessed from an external IP address. The firewall logs show a connection originating from an IP address that is not part of the company's approved vendor list or remote access VPN pool. Which type of attack is most likely indicated by this activity?Network Security
- 148.A large enterprise is adopting a Zero Trust security model. They are implementing a solution that continuously monitors device posture, user behavior, and application access requests, even for internal traffic. Which principle of Zero Trust is primarily being addressed by this continuous monitoring?Network Security
- 149.A security auditor is reviewing the IPv6 deployment in a corporate network. They notice that stateless address autoconfiguration (SLAAC) is being used extensively. What is a significant security concern associated with SLAAC that the auditor should highlight, especially in environments requiring strict control over IP address assignment?Network Security
- 150.A network security administrator needs to implement a security solution that restricts network access based on user identity, device posture (e.g., up-to-date antivirus, OS patch level), and location. This solution should dynamically assign users to appropriate network segments or enforce specific access policies. Which security technology is best suited for these requirements?Network Security