Configure device hardening and access control using AAA (TACACS+/ISE), ACLs, CoPP, 802.1X/MAB, port security, DHCP snooping, and Dynamic ARP Inspection. The most important thing: verify ACL and CoPP order/interface direction, since mistakes silently drop or permit traffic.
Start practicing
Security — choose a session length
Free · No account required
Domain overview
Security is 20% of ENCOR 350-401 and covers device hardening, access control, and traffic protection on Cisco IOS-XE and Catalyst platforms. Expect scenario questions on AAA with ISE or TACACS+, ACL and CoPP behaviour, 802. 1X/MAB, port security, DHCP snooping, Dynamic ARP Inspection, IPsec, and MACsec, plus CLI output interpretation and configuration verification.
Exam objectives
Configuring AAA with TACACS+ or RADIUS, including authentication, authorization, and accounting method lists
Implementing Layer 2 protections: port security, DHCP snooping, Dynamic ARP Inspection, and 802.1X with MAB
Building and ordering standard, extended, and named ACLs, plus Control Plane Policing for management traffic
Configuring IPsec site-to-site VPNs and MACsec link encryption, including verifying SA and key status
Forgetting that ACL entries are processed top-down with an implicit deny, so a permit placed after a broader deny never matches
Mixing up DHCP snooping trust on uplinks versus access ports, which breaks client addressing or leaves snooping ineffective
Assuming 802.1X alone handles non-supplicant devices, instead of enabling MAB as a fallback on the same port
Click any question to see the full explanation and answer options, or start a focused practice session above.
A network engineer is configuring port security on a Cisco switch to prevent unauthorized devices from connecting. The requirement is to allow only the first two MAC addresses learned on an interface, and to disable the interface if a violation occurs. Which configuration achieves this?
2An organization wants to implement 802.1X authentication on its wired network using Cisco ISE as the authentication server. The switches are configured with the necessary RADIUS settings. Which additional configuration is required on the switch interfaces to enable 802.1X?
3A security engineer is configuring CoPP (Control Plane Policing) on a Cisco router to protect the control plane from DoS attacks. The policy must rate-limit SSH traffic to 1 Mbps with a burst of 2000 bytes, and drop all other traffic destined to the control plane that exceeds a default rate. Which class-map and policy-map configuration is correct?
4A company has deployed a Cisco ASA firewall in transparent mode. The internal network uses VLAN 10 and the external network uses VLAN 20. The ASA is configured with two bridge groups: BVI 10 for inside and BVI 20 for outside. The security policy must allow HTTPS traffic from inside to outside. Which access-list entry is correct?
5Which TWO of the following are valid methods to mitigate VLAN hopping attacks?
6Which THREE of the following are characteristics of Cisco TrustSec (CTS) security architecture?
7Refer to the exhibit. A network administrator notices that some DHCP packets are being dropped due to 'MAC Address Mismatch'. What is the most likely cause of this drop?
8Refer to the exhibit. A switch has IP Source Guard (IPSG) and port-security enabled on interface GigabitEthernet0/1. A host with IP 10.1.1.1 and MAC 00:1A:2B:3C:4D:5E is connected and tries to access a web server at 192.168.1.100. What will happen?
9A medium-sized enterprise is migrating to a Cisco DNA Center-managed network. The security policy requires that all administrative access to network devices be authenticated via TACACS+ and that authorization for commands be enforced per user role. The network team has configured ISE as the AAA server and integrated it with DNA Center. After configuration, engineers report that they can log in to devices via SSH but are not prompted for a password when entering 'enable' mode; instead, they are granted full privileges immediately. Additionally, while in configuration mode, some engineers can issue 'debug' commands that they should not have access to. The configuration on the devices includes 'aaa new-model', 'aaa authentication login default group tacacs+ local', 'aaa authorization exec default group tacacs+ local', and 'aaa authorization commands 15 default group tacacs+ local'. What is the most likely cause of the privilege escalation and missing authorization?
10Which TWO features are part of Cisco TrustSec for providing role-based access control?
11A network engineer applies the above CoPP policy on a router. The router has BGP peers, SSH management, and SNMP monitoring. After applying this policy, which traffic will be affected?
12Drag and drop the steps to configure port security on a Cisco switch in the correct order.
13A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router that runs BGP, SSH management, and SNMP polling. A class-map named CLASS-MGMT matches SNMP and SSH traffic, and a policy-map named COPP-POLICY applies a police rate of 8000 bps with a conform-action transmit and exceed-action drop for that class. After the policy is attached to the control plane, SNMP polling intermittently fails while BGP remains stable. Which action should the engineer take to resolve the SNMP failures while still protecting the route processor?
14A Cisco Catalyst 9500 switch is configured for 802.1X with MAC Authentication Bypass (MAB) fallback on a port connected to an IP phone that has a PC daisy-chained behind it. The phone authenticates successfully using 802.1X, but the PC behind the phone fails authentication and is placed in the guest VLAN. The requirement is that the PC be authenticated individually and placed in the data VLAN, while the phone remains in the voice VLAN. Which feature should be configured on the switch port to meet this requirement?
15A network architect is designing a Cisco SD-Access fabric. The security team requires that endpoint traffic be segmented into separate virtual networks and that group-based policy be enforced without using traditional VLANs or ACLs between fabric edge nodes. Which two Cisco SD-Access fabric components or features support these requirements? (Choose two.)
16A network engineer is deploying Control Plane Policing on a Cisco IOS XE router that carries eBGP, OSPF, SSH management, and SNMP traffic. The engineer wants to ensure that BGP and OSPF routing updates are never dropped while still rate-limiting SSH and SNMP. Which CoPP configuration approach best meets this requirement?
17A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router that runs BGP, SSH management, and SNMP monitoring. After applying a new CoPP policy, BGP sessions flap intermittently while SSH and SNMP continue to work. The engineer wants to confirm which traffic class is being dropped. Which action should the engineer take?
18A network administrator is configuring IPsec VPN on a Cisco IOS router. The requirement is that the tunnel must support multicast traffic for OSPF neighbor adjacency across the VPN. Which IPsec configuration element is required to meet this requirement?
19A network engineer is implementing Control Plane Policing (CoPP) on a Cisco ASR 1000 router to protect the route processor from excessive traffic. The router runs OSPF, BGP, SSH management, and NTP. The engineer wants to ensure that OSPF hello packets are always prioritized and that SSH traffic from the management subnet is rate-limited. Which two statements about the CoPP configuration are true? (Choose two.)
20A network security team deploys Cisco ISE for 802.1X wired authentication. The switches are configured with MAB as a fallback. A printer that does not support 802.1X is connected, but ISE rejects it even though the printer's MAC address is in the correct identity group. The switch port shows the authentication method as MAB and the status as unauthorized. Which configuration issue is the most likely cause?
21A network administrator is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router. The router runs OSPF, BGP, SSH management, and SNMP polling. After applying a CoPP policy, the administrator notices that OSPF adjacencies flap intermittently while BGP and SSH remain stable. Which action should the administrator take to resolve the flapping while maintaining control plane protection?
22A network administrator is deploying Cisco TrustSec in a campus network. The security team wants to enforce access policy based on a device's role rather than its IP address, so that the enforced policy remains consistent even when endpoints move between VLANs or subnets. Which Cisco TrustSec component is responsible for assigning and carrying this role-based identity through the network?
23A network administrator is deploying Control Plane Policing (CoPP) on a Cisco IOS XE router that peers BGP with two ISPs. After applying a policer to the control plane, the BGP sessions tear down repeatedly while OSPF adjacencies stay stable. The administrator confirms CPU utilization is low. Which action should be taken to resolve the issue?
24A network administrator at a small company wants to prevent users from plugging unauthorized switches into wall jacks and creating loops or bypassing security controls. The administrator decides to implement BPDU Guard on all access ports on a Cisco Catalyst switch. Which statement accurately describes the behavior of BPDU Guard when configured on an access port?
25A network engineer is deploying Cisco TrustSec in a campus network. The security team requires that the Security Group Tag (SGT) be carried inside the Ethernet frame so that switches in the path can enforce group-based policy without inline tagging. Which Cisco-proprietary protocol should be enabled on the uplinks between the access and distribution switches to achieve this?
26A security team wants to protect a campus network from MAC flooding attacks that could overflow the CAM table on access switches. The requirement is to limit the number of source MAC addresses learned per switch port and to automatically err-disable a port when the limit is exceeded, while still allowing a VoIP phone and a PC on the same port. Which configuration approach meets these requirements?
27A network engineer is configuring control plane policing (CoPP) on a Cisco IOS XE router that peers BGP with two service providers and is managed over SSH from a jump host. After applying a new policy-map, the engineer notices that BGP sessions remain up but SSH logins intermittently time out during traffic spikes. Which action should the engineer take to resolve the SSH timeouts while preserving the CoPP protection model?
28A network security team is deploying Cisco TrustSec in a data center environment. They want to assign Security Group Tags (SGTs) to traffic based on user identity and device type without relying on IP addresses or VLANs. The team plans to use inline tagging on Cisco Nexus switches that support hardware-based SGACL enforcement. Which statement correctly describes how inline tagging propagates SGT information?
29A network administrator is configuring IPsec VPN on a Cisco IOS router. The administrator wants to ensure that only traffic from the 10.1.1.0/24 subnet to the 10.2.2.0/24 subnet is encrypted, while all other traffic is sent unencrypted. Which configuration element is required to define this traffic?
30A network engineer is configuring a site-to-site VPN between two Cisco IOS routers. The engineer wants to ensure that only traffic from the 10.1.1.0/24 subnet to the 10.2.2.0/24 subnet is encrypted, while all other traffic is sent unencrypted. Which IPsec configuration component defines this traffic?
31A network engineer is implementing MACsec on a Cisco Catalyst switch to secure Layer 2 traffic between two campus distribution switches. Which two statements accurately describe MACsec operation on Cisco platforms? (Choose two.)
32A network administrator is hardening a Cisco IOS switch that connects to user workstations. The security policy requires that when an unauthorized MAC address appears on an access port, the port must drop only the offending frames, generate a syslog message, and increment a counter, without shutting down the port or requiring administrative intervention. Which port security violation mode meets these requirements?
33A security architect is designing a campus network where all access-layer switch ports must authenticate endpoints before granting any Layer 2 connectivity. The design requires the switch to communicate with Cisco ISE using EAP over RADIUS, and the endpoint must be validated before any VLAN assignment occurs. Which 802.1X component role must the access-layer switch perform in this design?
34A network engineer is deploying 802.1X on a Cisco switch with Cisco ISE as the RADIUS server. The engineer wants to allow devices that do not support 802.1X supplicant to connect to a guest VLAN. Which feature should be configured on the switch port to accomplish this?
35A network administrator is configuring a Cisco IOS router to act as a VPN headend for remote users. The requirement is to use a protocol that supports both IKEv2 and native IPv6 transport, and that can provide per-user policy enforcement. Which technology should the administrator implement?
36A network administrator must secure management access to a Cisco IOS XE router so that only SSH version 2 is accepted and Telnet is disabled on all VTY lines. Which configuration accomplishes this requirement?
37A network administrator is configuring MACsec on a Cisco Catalyst switch to secure Layer 2 traffic between two switches. Which two statements about MACsec are true? (Choose two.)
38A network administrator is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router that peers BGP with two ISPs and runs SSH for management. The administrator wants to ensure that a sudden flood of BGP updates from a misbehaving peer does not starve the SSH management plane, while still allowing legitimate BGP traffic. Which CoPP configuration approach best meets this requirement?
39A network administrator is deploying Control Plane Policing (CoPP) on a Cisco IOS XE router that runs BGP, OSPF, and SSH management. The administrator wants to protect the route processor from excessive control-plane traffic while still allowing legitimate routing protocol and management traffic. The administrator creates a class map that matches BGP, OSPF, and SSH traffic and applies a police action with a committed information rate. Which additional configuration element is required to complete the CoPP implementation?
40A network engineer is deploying 802.1X on Catalyst access switches with Cisco ISE as the RADIUS server. Some endpoints, such as printers and badge readers, do not support 802.1X supplicants. The design must allow these devices onto a restricted VLAN while still requiring authentication for laptops. Which TWO mechanisms should the engineer configure to achieve this? (Choose two.)
41A company uses Cisco TrustSec in its campus network. Security policy requires that a user authenticated by 802.1X be assigned a Security Group Tag (SGT) based on the user's Active Directory group, and that the SGT be carried to downstream switches for enforcement. The access switch is configured for 802.1X with Cisco ISE. Which combination of features must be enabled to meet the requirement?
42A network administrator must protect the control plane of a Cisco IOS XE router that peers BGP with an ISP. The requirement is to rate-limit specifically ARP and IPv4 TTL-expired packets destined to the route processor while allowing all other transit traffic to be forwarded normally. Which CoPP implementation step is required to achieve this?
43A network security team deploys Cisco TrustSec on a Catalyst 9500 fabric. The team wants to enforce a policy where a user authenticated into the 'Contractor' security group tag (SGT) is denied access to servers tagged with the 'Finance' SGT, while remaining able to reach the 'Printers' SGT. Which enforcement mechanism applies the SGACL to traffic between the tagging devices?
44An engineer is configuring an IPsec site-to-site VPN between two Cisco IOS XE routers. Phase 1 completes successfully, but Phase 2 fails and no interesting traffic is encrypted. The engineer confirms that the ACLs on both peers mirror each other correctly. Which configuration element should be verified next to resolve the Phase 2 failure?
45A network security engineer is deploying MACsec on a Cisco Catalyst 9000 switch. The switch is connected to a Cisco IP phone that does not support MACsec, and a PC is connected to the phone. The engineer wants to encrypt traffic between the switch and the phone, but the phone does not support MACsec. What should the engineer do to secure the link?
46A network engineer is deploying MACsec on a Cisco Catalyst 9300 switch to secure a point-to-point link between two access switches. The engineer configures the switchport with the macsec command and a pre-shared key. After applying the configuration, the link comes up but MACsec is not encrypting traffic. Which action should the engineer take to resolve the issue?
47An engineer is configuring a Cisco IOS XE switch to secure the management plane. The requirement is to allow SSH only from the management subnet 10.10.10.0/24 and block all other management protocols such as Telnet and HTTP. Which configuration approach best meets this requirement?
48A network engineer is hardening a Cisco IOS XE router that terminates IPsec site-to-site tunnels with remote branches. The security policy requires that the router only accept IKEv2 negotiations using cryptographically strong parameters and that it validate peer identity via certificates issued by the corporate PKI. Which two configuration elements must the engineer apply to meet these requirements? (Choose two.)
49A network administrator is deploying Cisco TrustSec in a campus network. The security team wants to enforce role-based access control between endpoints without relying on IP addresses or VLANs, and they need to ensure that access policies are consistently applied even when endpoints move between switches. The administrator has already configured Cisco ISE for authentication and authorization. Which technology should be used to propagate the security group tag (SGT) information to network devices that do not support SGT tagging natively?
50A network administrator is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router that peers BGP with two ISPs and is managed over SSH. The administrator needs to protect the route processor from excessive BGP and SSH traffic without breaking the existing sessions. Which action should be taken when applying the CoPP policy?
51A network engineer configures Control Plane Policing on a Cisco IOS XE router acting as the BGP speaker for an ISP edge. The policy must protect the route processor from CPU exhaustion while still allowing BGP keepalives, SSH management, and SNMP polling from the NOC. Which CoPP design element is required to ensure BGP, SSH, and SNMP traffic is matched and rate-limited separately from transit traffic?
52A network administrator is deploying a new Cisco Catalyst 9200 switch at a branch office. The security policy requires that when a device connected to a port is shut down or moved, the switch must immediately send a SNMP trap and place the port into an error-disabled state while also incrementing a violation counter. The administrator configures port security with the violation mode that meets these requirements. Which command must be applied to the interface to achieve this?
53A network engineer is deploying MACsec on a Cisco Catalyst switch to secure point-to-point links between the access and distribution layers. The design must ensure data confidentiality and integrity on the wire, and must use a key agreement mechanism that supports dynamic key exchange. Which TWO of the following are required to meet these requirements? (Choose two.)
54A network administrator needs to secure management access to a Cisco IOS XE switch. The requirement is that only SSH version 2 with a 2048-bit RSA key be accepted, that Telnet be disabled, and that only the 'netadmin' user with privilege level 15 be allowed to log in via VTY lines 0 through 4. Which configuration accomplishes this?
55A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router to protect the route processor from excessive traffic. The router has management SSH access, BGP peering, and SNMP monitoring. After applying a CoPP policy, the engineer notices that BGP sessions flap intermittently, but SSH and SNMP remain stable. Which action should the engineer take to resolve the BGP flapping while maintaining control plane protection?
56A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router. The router has management SSH access, SNMP monitoring, and BGP peering. After applying the CoPP policy shown in the exhibit, the engineer notices that SNMP polling from the management station fails, while SSH and BGP remain operational. Which action should be taken to restore SNMP polling while maintaining control plane protection?
57A network security team is evaluating Cisco TrustSec (CTS) for deployment in a campus network. The team wants to understand which components are essential for enforcing security group tags (SGTs) and providing role-based access control. Which two of the following are required to implement CTS with SGT enforcement? (Choose two.)
58A network administrator is deploying a Cisco IOS-XE router as the WAN edge. The security policy requires that the router itself be protected against brute-force SSH attacks originating from the untrusted internet, without affecting transit traffic forwarded through the router. The administrator wants to use a feature that automatically blocks the offending source IP after repeated failed login attempts. Which Cisco IOS-XE feature should be configured?
59A network administrator is deploying Cisco Identity Services Engine (ISE) for wired 802.1X authentication on a Cisco Catalyst 9200 switch. The RADIUS server is reachable at 10.10.10.50 with shared secret 'C1sco123'. The administrator wants the switch to authenticate users before granting access to the data VLAN, and to place unauthenticated devices into a restricted VLAN. Which command sequence correctly enables 802.1X on a switch port?
60A network security team is deploying MACsec on Cisco Catalyst switches to protect Layer 2 traffic between two distribution switches. They want to ensure that the link is encrypted and that only authorized devices can participate in the secured session. Which two statements about MACsec operation on Cisco platforms are correct? (Choose two.)
61A network engineer is implementing 802.1X authentication on a Cisco switch. The engineer wants to ensure that the switch dynamically assigns a VLAN to the port based on the user's identity, and that the VLAN assignment is enforced by the authentication server. Which two components are required to achieve this? (Choose two.)
62A network administrator is configuring a Cisco IOS XE router to protect against spoofed source addresses on an internal interface facing user subnets. The requirement is to drop packets whose source address does not match the routing table entry for the incoming interface. Which feature should be enabled?
63A network administrator is configuring a Cisco Catalyst switch to prevent unauthorized devices from connecting to an access port. The administrator wants to ensure that only one MAC address is allowed on the port, and if a violation occurs, the port should be shut down and an SNMP trap sent. Which port security violation mode should be configured?
64A network engineer is configuring an IPsec site-to-site VPN between two Cisco IOS-XE routers. The design requires that the data payload be encrypted and that the two peers authenticate each other using pre-shared keys without any certificate infrastructure. Which combination of IKEv2 parameters must be configured on both peers to establish the tunnel?
65A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router to protect against excessive ARP traffic. The engineer applies the following policy: policy-map COPP-POLICY class ARP-CLASS police 8000 conform-action transmit exceed-action drop After applying the service-policy to the control-plane, the engineer notices that legitimate ARP requests are being dropped during peak hours. Which action should the engineer take to resolve this issue while maintaining protection?
66A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS XE router to protect against control plane overload. The router has management traffic (SSH, SNMP) and routing protocol traffic (OSPF, BGP). After applying the CoPP policy, the engineer notices that OSPF adjacencies are flapping. Which action should the engineer take to resolve this issue while maintaining control plane protection?
67A network administrator needs to secure management access to a Cisco IOS XE switch. The requirement is to ensure that only SSH version 2 is used for remote CLI access, and that Telnet is disabled. Which configuration achieves this?
68A network engineer configures a Cisco IOS router to authenticate administrative SSH logins against a Cisco ISE server using TACACS+. After applying the configuration, a valid ISE user can log in but receives no privilege level and cannot enter privileged EXEC mode. The relevant configuration is: aaa new-model aaa authentication login default group tacacs+ local aaa authorization exec default group tacacs+ local tacacs server ISE address ipv4 10.10.10.50 key Cisco123 Which action most directly resolves the problem?
69A network administrator is deploying a new branch office with a Cisco Catalyst 9200 switch. The security policy requires that any endpoint connecting to access ports must be authenticated before being granted network access, and unauthenticated devices must be placed into a restricted VLAN. The administrator wants to minimize configuration on the switch and rely on the authentication server to assign the VLAN dynamically. Which 802.1X feature should be configured on the switch to meet these requirements?
70A network security engineer is configuring an IPsec site-to-site VPN between two Cisco IOS routers. The engineer wants to ensure that the VPN tunnel uses perfect forward secrecy (PFS) and that the encryption is AES-256. Which combination of commands achieves this?
71A security architect is designing segmentation for a data center using Cisco TrustSec. The requirement is that classification of traffic into Security Group Tags (SGTs) occur at the access layer based on the identity of the user or device, and that enforcement occur at the data center core where the SGT-to-SGACL matrix is applied. Which statement describes the correct deployment approach?
72A campus switch connects to an IP phone that has a PC daisy-chained behind it. The engineer wants the phone to reside in VLAN 100 and the PC in VLAN 200, with the phone tagging its own voice traffic. Which interface configuration accomplishes this?
73A network engineer is implementing IPsec VPN on a Cisco IOS XE router. The design requires that traffic from the 10.1.1.0/24 subnet to the 10.2.2.0/24 subnet be encrypted, while all other traffic should be sent unencrypted. The engineer creates a crypto ACL. Which action must be taken to ensure the crypto ACL correctly identifies the traffic to protect?
74A network engineer is configuring port security on a Cisco switch to prevent unauthorized devices from connecting. The requirement is to allow only the first two MAC addresses learned on the port and to automatically shut down the port if a violation occurs. Which command set should be used?
75A network administrator is configuring 802.1X on a Cisco Catalyst switch. The switch is connected to a Cisco IP phone with a PC attached to the phone's data port. The requirement is to authenticate both the phone and the PC separately, with the phone in the voice VLAN and the PC in the data VLAN. Which 802.1X feature should be enabled?
76A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router to protect against DoS attacks. The router has a management plane that includes SSH and SNMP, and a control plane that includes routing protocols like OSPF and BGP. The engineer wants to rate-limit traffic destined to the route processor while ensuring that management traffic is not dropped during high CPU load. Which CoPP configuration approach is most appropriate?
77A network administrator is configuring a zone-based firewall on a Cisco IOS XE router. The requirement is to allow HTTP traffic from the INSIDE zone to the OUTSIDE zone while blocking all other traffic initiated from INSIDE. Which action must be taken to define the traffic that is permitted?
78A network administrator is implementing Control Plane Policing on a Cisco IOS-XE router to protect the route processor from excessive BGP, SSH, and SNMP traffic. After applying the policy, legitimate BGP keepalives are being dropped, causing peer resets. Which action should the administrator take to resolve this while still protecting the control plane?
79A security team wants to protect a web application hosted behind a Cisco IOS router from cross-site scripting and SQL injection attacks without modifying the application itself. Which Cisco IOS feature is designed for this purpose?
80A network administrator must secure management access to a Cisco Catalyst 9300 switch so that only encrypted sessions are accepted and any Telnet attempt is refused. The administrator wants to enforce this with the fewest configuration lines on the VTY lines. Which configuration accomplishes this?
81A network administrator is configuring a site-to-site VPN between two Cisco routers using IPsec. The administrator wants to ensure that the data transmitted between the sites is encrypted and authenticated. Which IPsec protocol should be used to provide both confidentiality and integrity for the data payload?
82A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router that runs BGP, SSH management, and SNMP. After applying a CoPP policy, BGP peering drops intermittently during route churn, but SSH and SNMP remain reachable. Which action should be taken to correct the issue while preserving control plane protection?
83A network administrator is configuring a Cisco IOS XE router to act as a VPN headend with IKEv2. The security policy requires that the router authenticate to peers using a certificate from a corporate PKI, and that peers authenticate using EAP-MSCHAPv2. Which IKEv2 authentication configuration on the headend meets these requirements?
84A network security team is hardening a Cisco IOS-XE router that terminates a site-to-site VPN to the internet. They want to ensure that the router itself cannot be managed from untrusted networks and that its management protocols are protected. Which two configuration actions achieve these goals? (Choose two.)
85A network administrator is deploying Control Plane Policing (CoPP) on a Cisco IOS XE router to protect the route processor from excessive traffic. The router has a single physical interface Gi0/0/0 that carries both management SSH traffic and transit data traffic. The administrator wants the CoPP policy to apply only to traffic destined to the router's control plane, not to transit traffic. Which CoPP configuration element must be applied to achieve this?
86A company runs a Cisco IOS router as the WAN edge. The security team wants to detect and log traffic that matches a set of known malicious signatures without blocking legitimate traffic, while still dropping clearly malformed packets. Which technology should be deployed on the router?
87A network administrator is configuring 802.1X authentication on a Cisco switch port. The port is connected to a VoIP phone that then connects to a PC. The administrator wants to authenticate both the phone and the PC separately, with the phone using MAB and the PC using 802.1X. Which feature should be configured on the switch port to support this?
88A network engineer is implementing a Zone-Based Firewall (ZBFW) on a Cisco IOS XE router. The router has three interfaces: inside (GigabitEthernet0/0), outside (GigabitEthernet0/1), and DMZ (GigabitEthernet0/2). The security policy requires that traffic from the inside zone to the outside zone be inspected, traffic from the outside zone to the DMZ be allowed only for HTTP and HTTPS, and all other traffic between zones be denied by default. Which configuration step is essential to achieve this policy?
89A network administrator is implementing Dynamic ARP Inspection (DAI) on a Cisco Catalyst switch. The network uses DHCP for most endpoints, but a few servers have static IP addresses. Which two actions are required to ensure DAI allows legitimate traffic while blocking ARP spoofing? (Choose two.)
90A network engineer is deploying Control Plane Policing on a Cisco IOS XE router that runs BGP, SSH management, and SNMP monitoring. The engineer must ensure that BGP keepalives are never dropped even during a control-plane flood, while SSH and SNMP traffic should be rate-limited. Which CoPP configuration element accomplishes this requirement?
91A network engineer is deploying MACsec on a Catalyst switch uplink between two buildings to protect Layer 2 traffic. Which two statements about MACsec operation on Cisco Catalyst switches are true? (Choose two.)
92A network engineer is implementing IPsec VPN on a Cisco IOS XE router to connect a branch office to headquarters. The engineer must ensure that the IKEv2 negotiation uses strong authentication and that the data plane is protected with integrity and encryption. Which two configuration elements are required to achieve this? (Choose two.)
93A network engineer is configuring IPsec VPN on a Cisco IOS router. The requirement is to encrypt traffic between two sites using IKEv2. The engineer wants to ensure that the IKEv2 proposal uses AES-256 for encryption, SHA-256 for integrity, and Diffie-Hellman group 14. Which command correctly defines the IKEv2 proposal with these parameters?
94A network engineer must protect the Cisco IOS control plane from an excessive volume of ARP traffic generated by a compromised host in VLAN 20. The engineer wants to limit ARP packets that are punted to the CPU, while allowing normal data forwarding to continue unaffected. Which feature should be configured to accomplish this goal?
95A network engineer needs to secure management access to a Cisco IOS XE router. The requirement is to encrypt all management traffic, including SNMP, and to authenticate administrators against a centralized server. Which combination of features should be implemented?
96A network administrator is configuring a site-to-site IPsec VPN between two Cisco IOS routers. The requirement is that the VPN must support dynamic routing protocol updates across the tunnel and allow multicast traffic between the sites. Which IPsec configuration mode should be used?
97A network administrator is configuring a Cisco IOS router to act as a VPN headend for remote access using SSL VPN. The requirement is to allow users to connect via a web browser and access internal web applications without installing a client. Which feature should the administrator configure?
98An engineer is configuring 802.1X on a Cisco Catalyst switch port where a PC is connected. The requirement is that if the authentication server becomes unreachable, the port should still allow the PC to send traffic in a restricted VLAN rather than being shut down. Which configuration meets this requirement?
99A security architect is designing a network where endpoint identity and group membership must follow users and devices across both wired and wireless networks, and policy enforcement must be consistent regardless of VLAN or IP subnet. Which Cisco solution provides this identity-based, group-based access control?
100A network security architect is designing a Zero Trust architecture for a campus network using Cisco Identity Services Engine (ISE) and Cisco TrustSec. The requirement is to enforce segmentation based on user identity and device posture, and to apply policy dynamically as users move between wired and wireless access points. Which Cisco TrustSec component is responsible for tagging packets with a Security Group Tag (SGT) at the access layer?
101A security architect is evaluating MACsec on a Cisco Catalyst switch uplink between two buildings. The requirement is to encrypt all Layer 2 traffic on the link with minimal configuration and use a standards-based key agreement. Which statement correctly describes how MACsec should be deployed on this link?
102A network security engineer is configuring 802.1X on a Cisco Catalyst switch with Cisco ISE as the RADIUS server. The switch is configured with 'dot1x system-auth-control' and the interface is set to 'authentication port-control auto'. The engineer wants to allow a printer that does not support 802.1X to connect to the network by using MAC Authentication Bypass (MAB). Which additional configuration is required on the switch interface to enable MAB?
103A network administrator is configuring a Cisco IOS router to support IPsec VPN for remote workers. The security policy requires that the router authenticate users via digital certificates issued by a corporate PKI. The administrator has already configured the CA trustpoint and obtained a certificate. Which command must be used in the ISAKMP policy to specify that RSA signatures (digital certificates) should be used for authentication?
104A network administrator is deploying 802.1X on Cisco Catalyst access switches with Cisco ISE as the RADIUS server. The design requires that devices failing authentication be placed into a restricted VLAN, and that IP phones be authenticated before the attached PC. Which two features must be configured to meet these requirements? (Choose two.)
105A network administrator is configuring a Cisco IOS router to act as a VPN headend for remote access. The requirement is to use IKEv2 with certificate-based authentication. The administrator has installed a valid identity certificate on the router and configured the IKEv2 profile. However, remote clients are unable to establish the VPN tunnel, and the router logs show 'IKEv2 certificate authentication failed'. What is the most likely cause?
106A network engineer is configuring IPsec VPN on a Cisco IOS XE router. The requirement is to protect traffic between two sites using ESP with AES-256 encryption and SHA-256 authentication, and to ensure that the tunnel is rekeyed every 3600 seconds. Which configuration element directly controls the rekey interval?
107A network engineer is configuring a Cisco Catalyst switch to mitigate VLAN hopping attacks. The switch has multiple access ports assigned to VLAN 10 and trunk ports connecting to other switches. The engineer wants to ensure that an attacker cannot send double-tagged frames to hop into another VLAN. Which action should the engineer take on all access ports?
108A network engineer needs to provide secure remote-access VPN connectivity for employees using Cisco AnyConnect. The requirement is to use digital certificates issued by the corporate PKI for both server and client authentication. Which component must be configured on the Cisco ASA to validate client certificates presented during the VPN session?
109A network administrator is deploying a Cisco Catalyst switch with DHCP snooping. The switch is configured with DHCP snooping globally and on VLAN 10. A DHCP server is connected to GigabitEthernet1/0/5, and client devices are connected to GigabitEthernet1/0/6 through 1/0/20. The administrator notices that DHCP offers from the server are being dropped. What is the most likely cause?
110A network engineer is deploying Control Plane Policing (CoPP) on a Cisco IOS XE router that runs BGP, OSPF, and SSH management. The engineer applies a CoPP policy-map to the control plane with a class that matches BGP traffic and sets police rate 8000 conform-action transmit exceed-action drop. After applying the policy, BGP sessions intermittently flap during route convergence. Which action should the engineer take to resolve the issue while maintaining control plane protection?
111A network security team is implementing Cisco TrustSec in a campus network. The team wants to enforce access based on a tag carried in the packet rather than by IP address, and wants the tag to be propagated across the network without per-hop reclassification. Which Cisco TrustSec component assigns and inserts the Security Group Tag (SGT) at the ingress point?
112A network security team is deploying MACsec on a Cisco Catalyst 9000 switch uplink between two buildings to protect Layer 2 traffic. The team wants to ensure that the link encrypts traffic and that the peer is authenticated before secure communication begins. Which configuration approach meets these requirements?
113A security team is deploying Control Plane Policing (CoPP) on a Cisco ASR 1000 router to protect the route processor from excessive traffic. They notice that after applying a CoPP policy, OSPF adjacency with a directly connected neighbor flaps intermittently. Which action should the engineer take to resolve the issue while maintaining control plane protection?
114A network administrator is configuring a Cisco IOS router to terminate a site-to-site IPsec VPN with a remote peer that uses dynamic public IP addressing. The administrator wants the router to accept IKE negotiations from any peer that presents a valid pre-shared key and matches a specific protected subnet. Which configuration element is required to support this?
115A network security team is implementing Cisco TrustSec in a campus network. They need to deploy Security Group Tags (SGTs) and enforce policies using Security Group ACLs (SGACLs). Which two statements are true regarding SGT propagation and enforcement in this environment? (Choose two.)
116A network administrator is implementing Control Plane Policing (CoPP) on a Cisco ASR 1000 router to protect against DoS attacks. The router has a management plane that must remain accessible via SSH and SNMP, and a control plane that must process BGP and OSPF routing updates. The administrator applies a CoPP policy that rate-limits all traffic destined to the control plane to 1000 pps, except for traffic from trusted management subnets. After applying the policy, BGP sessions flap intermittently. What is the most likely cause?
117A network administrator is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router that runs BGP, SSH, and SNMP. The administrator needs to verify which traffic classes are being matched and how many packets are being dropped by the policy. Which command should be used to display the CoPP policy statistics and class-map information?
118A Cisco Catalyst 9500 switch in a data center is configured with IP Source Guard on an access port where a server is connected. The server has a static IP address of 10.10.10.50 and MAC address 00:11:22:33:44:55. The network administrator has configured a static IP source binding using the command 'ip source binding 0011.2233.4455 vlan 10 10.10.10.50 interface GigabitEthernet1/0/1'. However, the server cannot communicate through the switch. What is the most likely cause?
119A network security administrator is configuring a Cisco IOS Zone-Based Firewall on a branch router. The inside zone and outside zone are defined, and the administrator wants to allow inside hosts to initiate sessions to outside servers while preventing outside hosts from initiating sessions to inside hosts. Which configuration accomplishes this?
120A network security engineer is deploying Cisco TrustSec in a campus network. The engineer wants to implement Security Group Tagging (SGT) and enforce policies based on SGTs. Which two mechanisms can be used to propagate SGTs between network devices? (Choose two.)
121A network administrator is deploying a Cisco Wireless LAN Controller (WLC) running AireOS in a branch office. The security policy requires that guest wireless clients be isolated from internal corporate clients and that guest traffic be tunneled back to a DMZ interface on the WLC. Which WLAN configuration element should the administrator use to meet these requirements?
122A network administrator is configuring a Cisco Wireless LAN Controller (WLC) to secure wireless client traffic. The requirement is to encrypt all wireless traffic between the client and the access point using a pre-shared key, without requiring a separate authentication server. Which security policy should the administrator configure on the WLC?
123A network engineer is deploying Control Plane Policing on a Cisco IOS-XE router that runs OSPF, BGP, and SSH management. The engineer wants to rate-limit routing protocol traffic while ensuring that SSH management traffic is never dropped, even during a routing protocol flood. The router uses a single physical interface for all control plane traffic. Which CoPP design approach best meets these requirements?
124A network administrator is deploying a Cisco Catalyst 9300 switch stack at the access layer. The security policy requires that when an unauthorized device connects to an access port, the port must immediately stop forwarding traffic, generate a syslog message, and increment the violation counter, while allowing the administrator to manually re-enable the port after investigation. Which port security violation mode should be configured?
125A network administrator is deploying a Cisco Catalyst 9300 switch stack at the access layer. The security policy requires that when an endpoint device is connected to a port and later replaced by a different device, the port must automatically learn the new MAC address without administrative intervention, but a violation must generate a syslog message and increment a counter. The administrator configures the interface with the command 'switchport port-security violation restrict'. Which additional command is required to meet the requirement that the new device is learned automatically?
126A network engineer is deploying Control Plane Policing (CoPP) on a Cisco IOS XE router. The router runs BGP, OSPF, SSH management, and SNMP. After applying a CoPP policy that rate-limits all control-plane traffic to 1000 pps, BGP sessions flap and OSPF adjacencies reset during peak traffic. Which action should the engineer take to resolve the problem while maintaining control-plane protection?
127A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS XE router to protect the route processor from excessive control-plane traffic. The engineer wants to rate-limit ARP and DHCP snooping-related traffic destined to the control plane while allowing routing protocol traffic without restriction. Which CoPP component must the engineer configure to classify and match this traffic before applying the policy?
128A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router to protect the route processor from excessive SSH traffic. The engineer wants to classify SSH traffic destined to the router itself and apply a policer to it. Which mechanism is used by CoPP to classify traffic before the policer is applied?
129A network administrator is configuring IPsec VPN on a Cisco IOS router. The administrator needs to ensure that the VPN traffic is encrypted and authenticated. Which two protocols are used in IPsec to provide encryption and authentication? (Choose two.)
130A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS XE router to protect the route processor. The engineer wants to rate-limit ICMP echo requests destined to the router itself while ensuring that transit traffic passing through the router is not affected. Which classification approach should the engineer use in the CoPP policy?
131A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS XE router that runs BGP, SSH, and SNMP. The engineer wants to ensure that BGP keepalives are not dropped during a control plane overload, while still rate-limiting SSH and SNMP. The engineer creates a class-map matching BGP, SSH, and SNMP traffic, then applies a policy-map with a single policer of 1000 pps to that class. After applying the service-policy to the control plane, BGP sessions flap during high CPU utilization. What is the most likely cause?
132A security architect is designing a Cisco TrustSec deployment for a campus network. The architect needs to ensure that security group tags (SGTs) are propagated across a Layer 2 trunk between two Catalyst switches that do not support SGACL enforcement. Which technology should be used to carry SGT information inline within the Ethernet frame?
133A network administrator is configuring a site-to-site VPN between two Cisco IOS routers using IPsec. The security policy requires that the VPN use IKEv2 with certificate-based authentication. Which command must be configured on both routers to specify the trustpoint that will be used for IKEv2 authentication?
134A network administrator is configuring a site-to-site IPsec VPN between two Cisco IOS routers. The design requires that only traffic from specific subnets be encrypted and that the routers use a preshared key for authentication. Which combination of configuration elements must the administrator define to match the interesting traffic and establish the tunnel?
135A network security team is deploying MACsec on a Cisco Catalyst 9300 switch connecting to a partner's Catalyst 9200 over a metro Ethernet link. The team wants to encrypt all traffic on the link and ensure that the switches mutually authenticate before any frames are forwarded. Which IEEE standard defines the key agreement and encryption used by MACsec, and which component performs the key exchange?
136A network security team is hardening a Cisco IOS XE router that terminates IPsec tunnels to remote branch offices. The team wants to use zone-based firewall (ZBFW) to inspect traffic between the inside, outside, and VPN zones. Which two statements correctly describe zone-based firewall behavior on this platform? (Choose two.)
137A network security team is deploying MACsec on a Cisco Catalyst 9000 switch series to secure Layer 2 traffic between two switches. Which two statements about MACsec operation are true? (Choose two.)
138A network engineer is configuring MACsec on a point-to-point link between two Cisco Catalyst switches to provide Layer 2 encryption. The engineer wants to use a pre-shared key for authentication and ensure that the key is rotated periodically. Which MACsec component must be configured to specify the pre-shared key and the key rotation timer?
139A network engineer is configuring a Zone-Based Firewall on a Cisco IOS XE router. The design requires that traffic from the inside zone to the outside zone be inspected, that return traffic be permitted, and that traffic from the outside zone to the inside zone be dropped unless it matches an existing session. Which configuration element is required to achieve this behavior?
140A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS-XE router that also runs OSPF, BGP, and SSH management. The engineer needs to protect the control plane while ensuring that routing protocol traffic and management sessions are not disrupted. Which CoPP design approach best meets these requirements?
141A network administrator needs to securely manage a Cisco Catalyst switch remotely. The requirement is to encrypt all management traffic, including username and password, between the administrator's workstation and the switch. Which management protocol should be enabled on the switch to meet this requirement?
142An engineer must secure the management plane of a Cisco IOS XE router so that only SSH version 2 is accepted for remote administration, while Telnet and SSHv1 are rejected. Which set of commands accomplishes this?
143A network security engineer is configuring Control Plane Policing (CoPP) on a Cisco ASR 1000 router to protect the route processor from excessive traffic. The engineer wants to rate-limit SSH traffic to 100 kbps with a burst of 8000 bytes, and ensure that any traffic exceeding the rate is dropped. The engineer applies the following policy: policy-map COPP-POLICY class SSH-CLASS police 100000 8000 exceed-action drop After applying the service-policy to the control plane, the engineer notices that SSH sessions intermittently disconnect during large file transfers over SCP. What is the most likely cause?
144A network administrator is deploying Control Plane Policing (CoPP) on a Cisco IOS XE router that runs BGP, SSH, and NTP. The requirement is to protect the route processor from excessive BGP keepalive traffic while still allowing all legitimate BGP peering. Which CoPP module should the administrator use to classify and police this traffic before the policy is applied to the control plane?
145A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS router to protect the route processor from excessive CPU utilization due to malicious traffic. The engineer wants to ensure that BGP, SSH, and SNMP traffic are rate-limited appropriately. After applying the CoPP policy, the engineer notices that BGP sessions are flapping. Which action should the engineer take to resolve the issue while maintaining protection?
146A network administrator is configuring a Cisco IOS zone-based firewall (ZBFW) on a router that connects a LAN zone to an Internet zone. The administrator wants to allow outbound HTTP and HTTPS from the LAN to the Internet while blocking all other outbound traffic, and to allow return traffic for established sessions. Which two configuration elements are required to accomplish this? (Choose two.)
147A network engineer is configuring a Cisco ASA firewall with a site-to-site VPN to a remote peer. The engineer wants to ensure that only specific subnets are encrypted and that traffic from other subnets is not sent through the tunnel. Which configuration element defines the traffic that will be protected by the VPN?
148A network administrator is deploying 802.1X on Cisco Catalyst switches with Cisco ISE as the RADIUS server. The administrator wants to allow devices that do not support 802.1X, such as printers, to connect to the network. Which feature should be configured on the switch ports to support these devices while maintaining security?
149A network security team is hardening a Cisco IOS-XE router that terminates IPsec VPN tunnels. They want to protect the control plane from CPU-intensive IKE and management traffic without dropping legitimate tunnel establishment packets. They decide to apply a Control Plane Policing (CoPP) policy. Which statement best describes how CoPP interacts with the forwarding plane and the control plane on this router?
150A security team wants to deploy MACsec on a Cisco Catalyst switch uplink between two buildings to protect Layer 2 traffic. The switches are Cisco Catalyst 9300 series running IOS XE, and the link must encrypt all frames between them. Which statement accurately describes a requirement for this deployment?
151A network administrator is implementing IP Source Guard (IPSG) on a Cisco Catalyst 3850 switch to prevent IP spoofing. The administrator enables DHCP snooping and IPSG on VLAN 10. A user connects a laptop with a statically assigned IP address 10.10.10.50/24 and gateway 10.10.10.1. The laptop cannot reach any network resources. What is the most likely reason?
152A network engineer is configuring IPsec site-to-site VPNs on a Cisco IOS XE router. The design requires that the router authenticate peers using certificates issued by an internal PKI rather than pre-shared keys, and that IKEv2 be used for the key exchange. Which configuration element is required to support certificate-based authentication for IKEv2 on this router?
153A network administrator is configuring a Cisco Wireless LAN Controller (WLC) to use 802.1X authentication for wireless clients. The administrator wants to ensure that the WLC communicates with the RADIUS server securely. Which protocol should be used to encrypt the RADIUS communication between the WLC and the RADIUS server?
154A network engineer is configuring IPsec VPN on a Cisco IOS router. The engineer wants to ensure that traffic from a specific subnet is encrypted and sent to a remote peer, while all other traffic is sent unencrypted. The engineer has configured an extended ACL for the crypto map. Which additional configuration is required to ensure that the crypto map is applied to the correct interface and that the VPN tunnel is established?
155A network engineer must protect the OSPF adjacency between two Cisco routers from spoofed hello packets injected by a rogue device on the same broadcast segment. The engineer wants to use a cryptographic authentication method that is natively supported by OSPFv2 and does not rely on plain-text key exchange. Which configuration should be applied to the interfaces?
156A security team is hardening a Cisco IOS router that terminates IPsec site-to-site tunnels to several branch offices. The team wants to protect the control plane by rate-limiting and filtering traffic destined to the router's own CPU. Which two mechanisms are designed specifically for control plane protection on Cisco IOS? (Choose two.)
157A network security engineer is deploying Cisco TrustSec in a campus network. The engineer wants to implement Security Group Tags (SGTs) and enforce policies using a Cisco Catalyst switch as an enforcement point. Which two statements are true regarding SGT propagation and enforcement in this scenario? (Choose two.)
158A network administrator is configuring a Cisco IOS router to protect the control plane from excessive CPU utilization caused by malicious traffic. The administrator wants to rate-limit specific types of traffic destined to the route processor while allowing all other traffic to pass without restriction. Which feature should be configured?
159A network engineer is hardening a Cisco IOS XE router against control plane attacks. The router runs OSPF, BGP, and SSH management. The engineer wants to apply Control Plane Policing (CoPP) to rate-limit nonessential traffic while ensuring routing protocols are not disrupted. Which two actions should the engineer take? (Choose two.)
160A network engineer is implementing Cisco TrustSec in a campus network. The engineer needs to configure the enforcement of security group tags (SGTs) on Cisco Catalyst switches. Which two statements are true regarding SGT enforcement and propagation? (Choose two.)
161A security architect is designing a Zero Trust access solution for a campus using Cisco Identity Services Engine. The requirement is to enforce dynamic, identity-based segmentation without relying solely on static VLANs, and to support both wired and wireless endpoints. Which two capabilities should be leveraged? (Choose two.)
Configure device hardening and access control using AAA (TACACS+/ISE), ACLs, CoPP, 802.1X/MAB, port security, DHCP snooping, and Dynamic ARP Inspection. The most important thing: verify ACL and CoPP order/interface direction, since mistakes silently drop or permit traffic.
The Courseiva 350-401 question bank contains 161 questions in the Security domain, covering the 20% of the exam attributed to this domain in the official Cisco blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Security domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included