Cisco CCNP Security Core (SCOR) 350-701 practice questions

211 free questions with answers and explanations.

Practice test
  1. 151.A network security engineer is designing a new firewall policy for a corporate network. The policy needs to permit HTTP and HTTPS traffic from the internal network to the internet, block all other outbound traffic, and allow only SSH access from a specific management subnet to internal servers. Which ordered set of Access Control List (ACL) entries would achieve this, assuming a default implicit deny at the end?Network Security
  2. 152.A network architect is designing a secure network for a new branch office that will connect to the main corporate data center over the public internet. The design requires ensuring data confidentiality, integrity, and authenticity between the branch and the data center. Which technology is best suited to meet these requirements for site-to-site connectivity?Network Security
  3. 153.A network security engineer is deploying a new web application and needs to ensure that only legitimate HTTP/HTTPS traffic reaches the web servers, while blocking common web-based attacks like SQL injection and cross-site scripting (XSS). Which network security device is specifically designed to provide this type of advanced, application-layer protection?Network Security
  4. 154.A security analyst is investigating a suspected malware infection on a host within the corporate network. The analyst needs to isolate the host from the rest of the network while maintaining a management connection for remediation. Which network security technology is best suited for this temporary isolation without reconfiguring physical cabling?Network Security
  5. 155.A company is implementing a Zero Trust architecture for its internal network. The security team needs to ensure that every connection attempt, regardless of its origin (internal or external), is authenticated and authorized before access is granted to any resource. Which core principle of Zero Trust is being emphasized in this implementation?Network Security
  6. 156.A security analyst is investigating a network segment where several critical servers are hosted. The analyst observes a high volume of traffic originating from these servers towards external, unknown IP addresses on various non-standard ports, even during periods of low legitimate activity. There is no business justification for these servers to initiate outbound connections to arbitrary external destinations. Which security principle is most directly being violated in this scenario?Network Security
  7. 157.A company is implementing a security policy that mandates the use of multifactor authentication (MFA) for all remote access to internal resources. The security team also wants to ensure that all user authentication attempts, including successful and failed ones, are centrally logged and available for auditing. Which authentication, authorization, and accounting (AAA) protocol is best suited to support both MFA integration and centralized accounting for remote access VPNs?Network Security
  8. 158.A cyber-physical system used in an industrial control environment requires strong protection against both external network attacks and unauthorized internal access. Due to the critical nature of the system, any security solution must introduce minimal latency and ensure deterministic communication. Which network security architecture is best suited for segmenting such a system while meeting these strict performance and reliability requirements?Network Security
  9. 159.A security operations center (SOC) analyst is investigating a series of sophisticated, stealthy attacks targeting critical intellectual property. These attacks involve custom malware that evades traditional signature-based detection and exhibit highly targeted reconnaissance and data exfiltration techniques over extended periods. The attackers leverage legitimate system tools and processes to blend in with normal network activity. Which type of threat best describes this scenario?Network Security
  10. 160.A security operations center (SOC) analyst is reviewing logs from an Intrusion Prevention System (IPS). The IPS has detected and blocked several attempts of a known exploit targeting a common vulnerability. Which core function of the IPS is being demonstrated in this scenario?Network Security
  11. 161.A company is experiencing slow network performance, and users are reporting frequent connection drops when accessing a specific critical application. A network engineer suspects that some network devices are being overwhelmed due to excessive traffic. The engineer needs to implement a mechanism to prioritize the critical application's traffic over less important traffic to ensure its availability and performance. Which network security technology can be used to achieve this prioritization?Network Security
  12. 162.A security auditor is reviewing the access control policies for critical network infrastructure devices. The current policy allows administrators to log in using local accounts with static passwords configured on each device. The auditor recommends implementing a centralized authentication, authorization, and accounting (AAA) system. Which of the following AAA protocols is commonly used for device administration and offers granular command authorization?Network Security
  13. 163.A network security administrator is tasked with implementing granular access control for network devices, ensuring that only authorized individuals can execute specific commands based on their roles. For example, junior administrators should only be able to view configurations, while senior administrators can modify them. Which protocol or framework is most suitable for achieving this level of command authorization and accounting?Network Security
  14. 164.A security engineer is designing a secure network for a new branch office. The design requires that all traffic between the branch office and the headquarters network traverse a secure, encrypted tunnel over the public internet. The solution must support both site-to-site connectivity and remote user access. Which VPN technology should be implemented to meet these requirements?Network Security
  15. 165.A security architect is designing a solution for a critical industrial control system (ICS) network. The requirement is to ensure that even if a workstation connected to the ICS network is compromised, the impact is limited, and the attacker cannot easily move to other segments of the ICS or the corporate network. Which network security architecture principle is paramount in this design?Network Security
  16. 166.A network administrator is configuring Network Address Translation (NAT) on a Cisco router. The internal network uses private IP addresses (10.0.0.0/8) and needs to access the internet. The router has a single public IP address (203.0.113.10) assigned to its internet-facing interface. Which type of NAT is most appropriate for allowing multiple internal hosts to share this single public IP address for outbound internet access?Network Security
  17. 167.A company is implementing a new security policy that requires all remote access to internal resources to use a secure, encrypted tunnel over the internet. The solution must support various client operating systems and provide strong authentication. Which technology best fits these requirements?Network Security
  18. 168.A security operations center (SOC) analyst observes a significant increase in DNS queries originating from multiple internal hosts to a large number of seemingly random, non-existent domains. This activity occurs in short bursts over several hours. What type of attack is this most indicative of?Network Security
  19. 169.A security operations center (SOC) analyst observes unusual outbound DNS queries from several internal hosts to an external, unclassified domain. The queries are frequent and appear to be encoding small chunks of data within the query names. What type of attack is most likely occurring?Network Security
  20. 170.A large enterprise is migrating its on-premises data center to a hybrid cloud environment. The security team needs to extend their existing network security policies, including firewall rules and intrusion prevention, consistently across both the on-premises infrastructure and the public cloud. They also want to achieve automated policy deployment and orchestration. Which network security concept provides the framework for achieving this unified, automated security management across heterogeneous environments?Network Security
  21. 171.A network security architect is designing a secure industrial control system (ICS) network. The design requires strict isolation between different operational zones and critical assets, ensuring that communication is only permitted between explicitly authorized systems and services. Which security principle is being primarily applied in this design?Network Security
  22. 172.A security engineer is configuring a web application firewall (WAF) to protect an online e-commerce platform. The WAF needs to detect and block SQL injection attempts, cross-site scripting (XSS) attacks, and other common web-based vulnerabilities. Which layer of the OSI model does a WAF primarily operate at to perform these functions?Network Security
  23. 173.A web development team has deployed a new e-commerce application. A security audit reveals that the application is vulnerable to SQL injection attacks due to improper input validation. Which security device or service is specifically designed to protect web applications from such vulnerabilities without requiring changes to the application code?Network Security
  24. 174.A security auditor is reviewing the configuration of a network device that uses SNMP for monitoring. The auditor discovers that the device is configured with SNMPv2c and uses a simple community string for authentication. No encryption is configured. What is the most significant security vulnerability associated with this configuration?Network Security
  25. 175.A network security architect is designing a solution to protect against zero-day exploits and advanced persistent threats (APTs) that bypass traditional signature-based detection. The solution needs to analyze unknown files and URLs in a safe, isolated environment before they reach end-user systems. Which technology is best suited for this purpose?Network Security
  26. 176.A company is implementing a new firewall and needs to ensure that all internal hosts can access external web resources, but external hosts cannot initiate connections into the internal network unless explicitly allowed for specific services. Which firewall policy model best describes this requirement?Network Security
  27. 177.A network security architect is designing a new infrastructure that requires high availability and seamless failover for critical security services, such as firewalls and intrusion prevention systems. These services must be able to share state information and maintain active connections even if one device fails. Which high availability feature is essential for achieving this stateful failover in redundant security devices?Network Security
  28. 178.A network security administrator is configuring a new firewall policy to allow only HTTPS traffic to a web server. Which standard port number should be explicitly permitted?Network Security
  29. 179.A security engineer is designing a secure remote access solution for mobile users. The solution must support various operating systems, provide strong authentication, and ensure that all traffic to the corporate network is encrypted. Which VPN technology, when implemented with certificate-based authentication, provides the most flexible and robust solution for this scenario?Visibility and Enforcement
  30. 180.A network administrator is troubleshooting an issue where users are unable to access internal web applications hosted on a server behind a Cisco ASA firewall. The ASA is configured with NAT and access rules. Upon reviewing the firewall logs, the administrator observes denied connections with the reason 'Deny inbound UDP from 1.1.1.1/32 to 10.0.0.10/32 on interface outside'. Which of the following is the most likely cause of this issue?Visibility and Enforcement
  31. 181.A large enterprise is migrating its data center to a hybrid cloud environment. They need to extend their on-premises network security policies to workloads running in public cloud infrastructure, ensuring consistent enforcement and visibility. The solution must support dynamic scaling and integration with existing security orchestration tools. Which architectural approach best achieves these goals?Visibility and Enforcement
  32. 182.A network security engineer is tasked with implementing network access control (NAC) for a corporate campus. The solution must dynamically assign users to different VLANs and apply specific security policies based on their role, device type, and compliance posture. Which Cisco technology is designed to centralize and automate this type of policy enforcement?Visibility and Enforcement
  33. 183.A company is implementing a new BYOD policy and needs to ensure that personal devices can access corporate resources securely, but only after passing a security posture assessment. Which Cisco solution is best suited to provide this dynamic access control based on endpoint compliance?Visibility and Enforcement
  34. 184.An organization is deploying an IPv6-only network segment for its IoT devices. They need to ensure that these devices can securely communicate with internal IPv4-only servers for data collection, without requiring a full dual-stack implementation on the IoT devices or the servers. Which IPv6 transition mechanism is most appropriate for this specific scenario?Visibility and Enforcement
  35. 185.A network security engineer is configuring a Cisco Firepower Threat Defense (FTD) device to inspect traffic for known vulnerabilities. Which security intelligence feed should be configured to block access to IP addresses and URLs that are associated with active botnet command and control servers?Visibility and Enforcement
  36. 186.A security analyst is investigating a suspected intrusion on the corporate network. They observe unusual outbound connections from several internal hosts to external IP addresses on non-standard ports. The analyst needs to quickly identify the applications generating this traffic and their associated processes. Which security visibility tool is best suited for this task?Visibility and Enforcement
  37. 187.A security architect is designing a network segmentation strategy for an organization with a mix of IT and Operational Technology (OT) assets. The goal is to isolate critical OT systems from the IT network while allowing controlled, monitored access for maintenance and data collection. Which segmentation approach provides the strongest isolation for critical OT assets while still enabling necessary, secure communication paths?Visibility and Enforcement
  38. 188.An organization is deploying a new web application and requires robust protection against common web-based attacks such as SQL injection, cross-site scripting (XSS), and cross-site request forgery (CSRF). They also need to ensure high availability and load balancing for the application servers. Which security device is specifically designed to address these requirements effectively?Visibility and Enforcement
  39. 189.A security auditor is reviewing the access control policies for a critical server farm. The current policy uses standard ACLs to permit specific source IPs to access designated server ports. The auditor recommends moving to a more granular and scalable access control mechanism that can dynamically adapt to changes in network topology and application requirements, without requiring manual ACL updates across many devices. Which access control solution aligns best with this recommendation?Visibility and Enforcement
  40. 190.A network security engineer is implementing a distributed denial-of-service (DDoS) protection solution for an organization's public-facing web services. The solution must be capable of identifying and mitigating volumetric, protocol, and application-layer DDoS attacks without impacting legitimate user traffic. Which deployment model for a DDoS protection system is generally considered most effective for meeting these requirements at scale?Visibility and Enforcement
  41. 191.A security operations center (SOC) analyst is investigating a potential data exfiltration event. Network flow data (NetFlow) shows unusually large outbound traffic from an internal server to an unknown external IP address, but the destination port is frequently changing. Traditional firewall logs only show permitted 'any' rules for this server's outbound traffic. Which Cisco visibility technology would be most effective in identifying the specific application or process generating this anomalous traffic?Visibility and Enforcement
  42. 192.A large enterprise is implementing micro-segmentation within its data center to isolate individual workloads and applications. They require a solution that can apply granular security policies between virtual machines (VMs) and containers, regardless of their physical location, based on attributes like application role, operating system, and security context. Which technology best facilitates this advanced segmentation strategy?Visibility and Enforcement
  43. 193.A security architect is designing a network for a critical infrastructure facility. The design requires absolute segregation of the operational technology (OT) network from the information technology (IT) network, allowing only unidirectional data flow from OT to IT for monitoring purposes. No data should ever be able to flow from IT back to OT. Which technology is paramount for enforcing this strict unidirectional data flow?Visibility and Enforcement
  44. 194.A security engineer is configuring QoS policies on a Cisco router to prioritize voice and video traffic while ensuring that critical business applications receive sufficient bandwidth, even during periods of network congestion. Which QoS mechanism should be applied to classify and mark packets at the network edge to enable downstream devices to apply appropriate prioritization?Visibility and Enforcement
  45. 195.A network security administrator is configuring a Cisco Adaptive Security Appliance (ASA) firewall to allow internal users to access external web servers. The administrator wants to translate the internal private IP addresses to a single public IP address for outbound connections. Which NAT type should the administrator implement?Visibility and Enforcement
  46. 196.A security operations center (SOC) analyst is investigating a potential insider threat. They need to monitor all user activity on critical servers, including file access, command execution, and application usage, to detect anomalous behavior. The solution must provide detailed logs and alerts for forensic analysis. Which visibility and enforcement technology is most appropriate for this requirement?Visibility and Enforcement
  47. 197.A network engineer is configuring an access control list (ACL) on a router to permit HTTP and HTTPS traffic from the subnet 192.168.10.0/24 to a web server at 10.0.0.5. All other traffic from this subnet should be denied. Which two ACL entries, when placed in the correct order, achieve this goal?Visibility and Enforcement
  48. 198.A company is implementing a new security policy that requires all remote users to establish a secure, encrypted tunnel to the corporate network before accessing any internal resources. The solution must support various operating systems and devices, including laptops and mobile phones, without requiring extensive client software installation or hardware tokens. Which VPN technology best meets these requirements?Visibility and Enforcement
  49. 199.A global enterprise is deploying Cisco Secure Client (formerly AnyConnect) for remote access VPN. The security team requires that remote users' devices must meet specific security posture requirements (e.g., up-to-date antivirus, operating system patches) before being granted VPN access. Which Cisco Secure Client module is primarily responsible for performing this endpoint posture assessment?Endpoint Security and Secure Network Access
  50. 200.A network architect is designing a secure guest Wi-Fi solution for a corporate environment. The solution must ensure that guest users can access the internet but are strictly isolated from the internal corporate network and cannot communicate with each other. Which combination of technologies would best achieve these requirements?Visibility and Enforcement