Security questions on this certification test your ability to deploy and manage security concepts in scenario-based situations.
Start practicing
Security — choose a session length
Free · No account required
Domain overview
Use this page to practise Security questions for this certification. Focus on how the exam tests security in scenario format — understanding the why behind each answer builds more durable knowledge than memorising options.
Exam objectives
Core Security concepts and how they apply in real-world cloud scenarios.
How to deploy security correctly and verify the outcome.
Troubleshooting security issues by interpreting error output and system state.
Cloud best practices and Security design trade-offs tested by this certification.
Selecting the most expensive service when a simpler managed option meets the requirement.
Forgetting that cloud resources must be explicitly secured — defaults are rarely secure.
Choosing a global service fix when the issue is region-specific.
Overlooking cost implications of cross-region data transfer in architecture questions.
Click any question to see the full explanation and answer options, or start a focused practice session above.
Which TWO of the following are valid methods to mitigate VLAN hopping attacks?
2Which THREE of the following are characteristics of Cisco TrustSec (CTS) security architecture?
3Which TWO features are part of Cisco TrustSec for providing role-based access control?
4Your company has deployed a Cisco Catalyst 9300 switch stack as the distribution layer for a campus network. The network uses VLANs 10 (data), 20 (voice), and 30 (management). The switch stack is configured with DHCP snooping, Dynamic ARP Inspection (DAI), and IP Source Guard (IPSG) on access ports. Recently, users in VLAN 10 report intermittent connectivity issues. You notice that some users receive duplicate IP addresses from the DHCP server. The DHCP server is connected to a trunk port on the switch stack. After reviewing logs, you see that DHCPACK messages are being dropped on the trunk port. The DHCP snooping binding table shows entries for legitimate clients, but also some entries with MAC addresses from a different vendor. Which action should you take to resolve the issue?
5Drag and drop the steps to configure port security on a Cisco switch in the correct order.
6Match each Spanning Tree Protocol (STP) variant to its key characteristic.
Deep-dive questions
The most-searched questions in this domain — detailed explanations, worked examples, full answer breakdowns.
Security questions on this certification test your ability to deploy and manage security concepts in scenario-based situations.
The Courseiva 350-401 question bank contains 6 questions in the Security domain, covering the 20% of the exam attributed to this domain in the official Cisco blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Security domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included