Classify common attacks from log and traffic descriptions, and map each to the correct Cisco control. The single most important thing: know Zero Trust means no implicit trust, with access based on identity, context, and device posture.
Start practicing
Security Concepts — choose a session length
Free · No account required
Domain overview
Security Concepts covers the foundational threat landscape and control models tested throughout 350-701. Expect questions on Zero Trust and least privilege, attack classification (phishing, MITM, DDoS, spoofing), cryptography and PKI fundamentals, and Cisco security architecture including SecureX, Umbrella, and TrustSec. Questions are scenario-based: identify the attack, name the model, or select the correct mitigating control.
Exam objectives
Zero Trust principles: verify explicitly, least privilege, assume breach, and microsegmentation with Cisco TrustSec/ISE
Attack identification: reconnaissance, phishing, ARP spoofing, MITM, SSL stripping, and volumetric SYN flood DDoS
Cryptography and PKI: symmetric vs asymmetric encryption, hashing, certificates, and TLS inspection with Cisco Umbrella
Cisco security architecture: SecureX, Umbrella DNS security, Firepower NGFW, and endpoint protection with AMP/EDR
Confusing brute force with credential stuffing or password spraying; the giveaway is many failures from one source followed by success
Calling ARP spoofing MITM the final attack; the question asks what the attacker does next, such as SSL stripping to downgrade HTTPS
Mixing up Zero Trust with traditional perimeter defense; Zero Trust never trusts by default and evaluates identity, context, and device posture
Click any question to see the full explanation and answer options, or start a focused practice session above.
Which security model requires that all subjects and devices are untrusted by default, and access is granted only after verification, regardless of the network location?
2An organization wants to ensure that digital certificates issued by its internal CA are validated for revocation in real-time. Which protocol should be implemented to allow clients to check certificate status without downloading a full CRL?
3During a penetration test, an attacker sends a malicious payload to a web application that causes the server to execute arbitrary SQL commands on the backend database. Which type of attack is being performed?
4A security administrator is configuring a Cisco Firepower NGFW to detect and block application-layer DDoS attacks. Which type of DDoS attack is characterized by overwhelming a server with incomplete HTTP requests, causing resource exhaustion?
5Which cryptographic algorithm is considered deprecated and should be avoided due to known vulnerabilities, especially when used in digital signatures and certificate signing?
6An attacker uses ARP spoofing to intercept traffic between two devices on the same subnet. After successfully becoming a man-in-the-middle, the attacker can then perform which further attack to downgrade HTTPS connections to HTTP?
7In a PKI hierarchy, which component is responsible for issuing and revoking certificates for end entities, and is directly subordinate to the root CA?
8A security engineer is evaluating authentication methods. Which authentication factor category does a fingerprint scanner fall under?
9Which Cisco security product is primarily designed to provide DNS-layer security by blocking requests to malicious domains?
10An attacker performs a DNS cache poisoning attack on a recursive DNS server. What is the primary impact of this attack?
11A security analyst is investigating a potential insider threat. Which TWO indicators are most commonly associated with malicious insider activity? (Choose two.)
12A company is implementing a Zero Trust architecture. Which THREE principles are core to the Zero Trust model? (Choose three.)
13A network engineer is tasked with securing email communications. Which TWO Cisco products are specifically designed for email security? (Choose two.)
14A security analyst is reviewing logs and sees multiple failed login attempts from a single IP address, followed by a successful login. Which type of attack does this represent?
15An organization wants to implement a security model where no user or device is trusted by default, regardless of whether they are inside or outside the network perimeter. Which concept does this describe?
16A security engineer is configuring a Cisco Firepower NGFW to detect and block a new malware variant that communicates with a command-and-control server using encrypted DNS queries. Which Cisco security product is best suited to provide visibility into this malicious DNS traffic?
17Which of the following is an example of a passive reconnaissance technique?
18A company deploys a solution that uses a root certificate authority (CA) and intermediate CAs to issue certificates. What is the term for the hierarchical structure of certificates from the root CA to the end entity?
19Which Cisco security product provides identity-based access control and policy enforcement for wired and wireless networks?
20An attacker intercepts traffic between a client and a server and modifies the communication without either party knowing. Which type of attack is being performed?
21Which encryption algorithm is classified as symmetric?
22A security team implements a policy where users must provide a password and a one-time code from a mobile app. Which authentication factors are being used?
23A Cisco ESA administrator notices that a large number of emails with malicious attachments are being delivered to users. Which feature should be configured to inspect attachments in a sandbox environment before delivery?
24What is the primary purpose of a digital signature?
25Which type of malware is characterized by encrypting files on a victim's system and demanding payment for the decryption key?
26Which three components are part of the CIA triad?
27A company is planning to deploy a Zero Trust architecture. Which two principles are fundamental to Zero Trust?
28Which component of the CIA triad ensures that data is not altered by unauthorized entities during transmission?
29An attacker uses a tool to scan a target network for open ports and running services. Which type of reconnaissance does this represent?
30A security administrator is evaluating symmetric encryption algorithms for a new VPN deployment. Which algorithm uses a 128-bit block size and supports key sizes of 128, 192, and 256 bits?
31Which of the following is a characteristic of a zero trust security model?
32A security engineer is configuring a Cisco Firepower NGFW to detect a buffer overflow attack. Which attack vector is this?
33What is the primary function of a Certificate Revocation List (CRL) in a PKI?
34Which Cisco security product provides DNS-layer security to block malicious domains and cloud-based threats?
35An organization implements multi-factor authentication requiring a password and a fingerprint scan. Which two authentication factors are being used?
36An attacker intercepts traffic between a client and server using ARP spoofing. Which type of attack is this?
37Which Cisco security product is primarily used for endpoint threat detection and retrospective security?
38An organization is implementing a zero trust architecture. Which two principles are foundational to this model? (Choose two.)
39A security analyst detects a DDoS attack targeting the company's web server. Which three attack types are classified as application layer attacks? (Choose three.)
40Which three cryptographic algorithms are considered secure for use in modern systems? (Choose three.)
41A security analyst notices traffic from an internal host to an external IP address on port 4444, and the host's CPU is high. The host has been running unknown processes. Which type of malware is most likely involved?
42An organization implements a policy where every access request must be authenticated and authorized, even if it originates from within the internal network. Network segments are isolated, and lateral movement is restricted through microsegmentation. Which security model does this align with?
43Which Cisco product provides DNS-layer security to block malicious domains and prevent connections to malware command-and-control servers?
44An attacker intercepts communication between a client and server by spoofing ARP messages to associate the attacker's MAC address with the server's IP. This is an example of which type of attack?
45A web application accepts user input and directly includes it in SQL queries without sanitization. An attacker submits a single quote (') to cause a syntax error. What is this attack called?
46A security engineer needs to choose a hashing algorithm for storing passwords. Which of the following should be avoided due to known collision vulnerabilities?
47Which authentication factor does a fingerprint scanner represent?
48When a certificate is revoked, which protocol allows a client to check the revocation status in real-time without downloading a full CRL?
49Which Cisco product provides advanced malware protection for endpoints, including file analysis and retrospective security?
50An attacker sends a flood of SYN packets with spoofed IP addresses to a server, causing it to allocate resources for half-open connections until it can no longer accept legitimate traffic. This is which type of DDoS attack?
51Which symmetric encryption algorithm is considered the current standard and is often used in VPNs and SSL/TLS?
52A company wants to implement a Zero Trust architecture. Which THREE principles should be included? (Choose three.)
53A security analyst is reviewing logs and identifies numerous ICMP echo requests from an external IP address to multiple internal hosts. Which type of reconnaissance activity is this?
54An attacker injects a malicious SQL query into a web application's login form, bypassing authentication. Which type of exploitation is this?
55A company's server is infected with malware that encrypts files and demands payment for decryption. Which type of malware is this?
56Which cryptographic algorithm is a symmetric block cipher commonly used in modern VPNs and is considered secure?
57A PKI administrator needs to check the revocation status of a certificate without causing a heavy load on the CA. Which protocol should be used?
58Which security model mandates that access decisions should be based on context, device posture, and user identity, and never trust any entity by default?
59An attacker intercepts ARP packets on a local network and associates their MAC address with the IP address of a legitimate host. This is an example of which attack?
60A security engineer is evaluating Cisco solutions to detect and respond to network anomalies, including potential insider threats, by analyzing NetFlow data and behavioral patterns. Which Cisco product is best suited?
61Which authentication factor relies on something the user is, such as a fingerprint or retina scan?
62A company wants to protect against DNS-based attacks by filtering malicious domains and providing secure DNS resolution. Which Cisco product should be deployed?
63During an incident response, a forensic analyst finds that an attacker used a script to modify ARP tables, enabling them to intercept and modify traffic between two hosts. Which attack technique was used?
64Which Cisco product provides next-generation firewall (NGFW) capabilities, including application visibility and intrusion prevention?
65A security administrator is implementing a zero-trust architecture. Which two principles are core to the zero-trust model? (Choose two.)
66An organization is experiencing a DDoS attack that floods the network with large volumes of traffic, overwhelming bandwidth. Which three types of DDoS attacks are primarily volumetric? (Choose three.)
67A security team is investigating a breach where the attacker gained access to a server using stolen credentials. Later, the attacker moved laterally and exfiltrated data. Which three security controls would best help detect and prevent lateral movement? (Choose three.)
68A security engineer is implementing a zero trust architecture. Which TWO principles are foundational to zero trust? (Choose two.)
69An organization is experiencing repeated SQL injection attacks. A security analyst is tasked with recommending mitigations. Which THREE actions are most effective in preventing SQL injection? (Choose three.)
70A network administrator is configuring PKI for secure communications. Which TWO components are essential for a public key infrastructure? (Choose two.)
71A security analyst is investigating a malware outbreak. Analysis reveals a remote access trojan (RAT) that communicates with a command-and-control (C2) server. Which TWO behaviors are typical of a RAT? (Choose two.)
72An organization is adopting Cisco's security portfolio. Which THREE products are correctly paired with their primary function? (Choose three.)
73A Cisco Firepower NGFW administrator notices that a specific internal host is repeatedly establishing outbound TCP connections to a known command-and-control server across multiple ports. The administrator wants to quickly identify the malicious domain and IP addresses associated with this activity for further investigation. Which Firepower feature should be used to correlate this threat intelligence?
74A security analyst at a financial services firm notices a sudden spike in outbound DNS queries from a single internal host, each query targeting a different random subdomain of the same external domain (e.g., a1b2c3.badzone.example). The queries are small and the responses are also small, but the total volume is high. The analyst suspects data exfiltration. Which technique is MOST likely being used?
75A security engineer is configuring a Cisco Identity Services Engine (ISE) to authenticate employees connecting to the corporate wireless network. The engineer wants to ensure that only devices that have the latest antivirus definitions and OS patches are allowed access. Which ISE feature should be used to evaluate the device's posture?
76A security analyst at a financial institution is investigating suspicious outbound traffic from a workstation. The analyst observes that the traffic is encapsulated in DNS TXT record queries to a domain that resolves to an IP address in a known malicious range. The volume of queries is high but each query contains a small, encoded payload. Which type of attack is most likely occurring?
77A security engineer at a financial institution is designing a new threat detection system. The organization wants to identify ongoing attacks by observing real-time network traffic and comparing it against known malicious patterns, but they do not want to block any traffic yet. Which type of security control should the engineer implement?
78A network security analyst is reviewing logs and notices that an attacker is attempting to guess user passwords by trying common words and variations rapidly. Which type of attack is this?
79A network security administrator is deploying 802.1X authentication on Cisco switches. The administrator wants to ensure that if the RADIUS server becomes unreachable, authenticated supplicants remain connected while new supplicants are denied access. Which command should be configured on the switch ports to achieve this behavior?
80A network security engineer is configuring a Cisco Identity Services Engine (ISE) to enforce endpoint compliance. The engineer wants to ensure that only devices with up-to-date antivirus definitions and operating system patches are allowed on the corporate network. Which ISE feature should be used to achieve this?
81A security analyst is investigating a potential data breach. The analyst needs to determine which internal host communicated with a known malicious IP address over the past week. Which Cisco Stealthwatch feature should be used to query historical flow data and identify the host?
82A security engineer is implementing a VPN solution for remote workers. The organization requires that the VPN uses strong encryption, supports perfect forward secrecy, and is widely supported on various client platforms without requiring third-party software. Which VPN technology should the engineer choose?
83A security administrator is configuring a Cisco Firepower Next-Generation Firewall (NGFW) to inspect traffic for malicious patterns. The administrator wants to detect and block exploits that target known vulnerabilities in web servers. Which Firepower feature should be enabled to achieve this?
84A security architect is designing a network segmentation strategy to protect a cardholder data environment (CDE). The architect wants to ensure that systems in the CDE can only communicate with necessary services and that any lateral movement is contained. Which technology should be implemented to achieve microsegmentation within the data center?
85A Cisco administrator is configuring AnyConnect for a remote-access VPN and wants to ensure that unmanaged endpoints are denied access if they lack the required antivirus software. Which Cisco solution should be integrated with the ASA to enforce this endpoint posture requirement?
86A security engineer is implementing a VPN solution for remote workers. The engineer wants to ensure that the VPN uses a protocol that provides strong encryption and supports both IPv4 and IPv6. Which VPN technology should be chosen?
87A security team deploys Cisco Umbrella to protect roaming users who connect their laptops to public Wi-Fi at airports and coffee shops. Users report that web filtering policies still apply even when they are not connected to the corporate VPN. Which Cisco Umbrella capability makes this enforcement possible?
88A Cisco engineer is designing a secure remote-access VPN that must support clientless connections to internal web applications, full tunnel access for managed laptops, and integration with Cisco Identity Services Engine for posture assessment. Which Cisco solution should be deployed to meet all these requirements in a single platform?
89A network security engineer is designing a defense-in-depth strategy for a new data center. The engineer needs to select a control that will detect and alert on malicious activity after it has already bypassed perimeter defenses, without actively blocking the traffic. Which type of security control should be implemented?
90A hospital must protect a medical imaging server that stores patient records from both external attackers and malicious insiders. The security team wants a control that segments east-west traffic between the imaging VLAN and the clinical workstation VLAN, and that can enforce policy based on user identity and device posture. Which Cisco solution best meets these requirements?
91A security operations team wants to detect malicious command-and-control traffic that uses domain fronting and encrypted TLS sessions to well-known cloud services. They need a solution that inspects TLS metadata without full decryption and correlates with threat intelligence. Which Cisco technology best fits this requirement?
92A Cisco Secure Network Analytics (Stealthwatch) administrator notices that a host is generating a high volume of DNS queries for randomly generated domain names, and the host has begun communicating with newly registered domains. The administrator needs to identify the specific threat behavior and the best mitigation. Which conclusion and action are most appropriate?
93A security administrator is configuring a Cisco Identity Services Engine (ISE) to enforce endpoint compliance. The administrator wants to ensure that only endpoints with up-to-date antivirus signatures and operating system patches are allowed full network access. Which ISE feature should be used to assess the endpoint's posture before granting access?
94A security operations center (SOC) analyst is investigating a potential security incident. The analyst observes that an attacker has gained initial access to a workstation and is now attempting to move laterally to other systems by exploiting a vulnerability in the Server Message Block (SMB) protocol. The analyst wants to correlate this activity with known adversary tactics and techniques. Which framework should the analyst use to map the observed behavior to a specific technique ID?
95A security operations center observes an attacker who has compromised a workstation and is now moving laterally to enumerate domain controllers using valid but stolen credentials. The attacker has not triggered any signature-based alerts. Which Cisco security capability is specifically designed to detect this kind of credential-based lateral movement by analyzing network telemetry and correlating it with identity information?
96An organization is deploying a new PKI for internal services and needs a certificate that will be used to sign other certificates, including subordinate CA certificates. Which type of certificate should be issued for this purpose?
97A security engineer is configuring Cisco Identity Services Engine (ISE) to enforce posture assessment for employees connecting to the corporate network. The requirement is that endpoints must have the latest antivirus definitions and an active firewall before being granted full access. Which ISE feature should be used to meet this requirement?
98A network administrator is configuring a Cisco Identity Services Engine (ISE) to authenticate users via 802.1X. The administrator wants to ensure that only domain-joined Windows computers with up-to-date antivirus definitions are allowed on the corporate network. Which ISE feature should be used to evaluate the endpoint's compliance with these requirements before granting access?
99A financial services firm is designing a new remote access solution. The security policy requires that administrators connecting to the data center must be authenticated with a hardware token, and that the resulting session must be tied to a specific user and device identity so that authorization decisions can be made per session. Which Cisco solution provides this combination of strong authentication and per-session identity context?
100A company is deploying Cisco Umbrella and wants to block access to malicious domains for users on the corporate network without installing software on endpoints. Which deployment method should be used?
101A security administrator is configuring 802.1X on Cisco switches and wants to ensure that both the identity of the endpoint and the user are validated before network access is granted. Which two Cisco ISE features or capabilities support this requirement? (Choose two.)
102A security engineer is analyzing a packet capture and notices that an attacker is sending a large number of TCP SYN packets to a web server from various spoofed source IP addresses. The server's SYN backlog is filling up, causing legitimate connection attempts to be dropped. Which type of attack is this?
103A company deploys a Cisco Umbrella virtual appliance on-premises so that internal endpoints are identified individually in reporting. After deployment, all internal client DNS requests still show only the public egress IP address in Umbrella Investigate and reporting. Which configuration step was most likely missed?
104A network administrator is deploying Cisco Umbrella to protect users from malicious domains. The administrator wants to block requests to known malicious domains and see which internal hosts are making those requests. Which Umbrella feature provides this visibility and enforcement?
105A security architect is designing a data loss prevention strategy for a company that uses Cisco Secure Email Gateway and Cisco Secure Web Appliance. The architect must select controls that prevent sensitive data from leaving the organization through both email and web channels. Which two Cisco capabilities should be included in the design? (Choose two.)
106A network engineer is configuring a Cisco Firepower NGFW to inspect traffic between two internal departments. The requirement is to ensure that only traffic matching a specific application is allowed, while all other traffic is blocked, and to log the allowed connections. Which configuration approach should be used?
107A security architect is designing segmentation for an industrial environment where legacy programmable logic controllers cannot run endpoint agents and must remain reachable only from a small set of engineering workstations. Which two Cisco technologies are appropriate to enforce this requirement? (Choose two.)
108A security engineer is configuring a Cisco ASA firewall to secure VPN access for remote users. The engineer wants to ensure that the VPN traffic is encrypted using a protocol that provides both confidentiality and integrity, and that supports perfect forward secrecy (PFS). Which protocol should be used for the IPsec VPN to meet these requirements?
109A security operations center (SOC) analyst is investigating an alert from Cisco SecureX about a suspicious file executed on an endpoint. The analyst needs to determine the file's reputation and gather threat intelligence from multiple sources. Which action should the analyst take within SecureX?
110A user receives an email that appears to come from the CEO and asks for an urgent wire transfer. The message uses a lookalike domain with a single character changed. Which social engineering technique is being used?
111An administrator must allow a remote user to access the corporate network over a VPN so that the user receives an internal address and traffic is tunneled to the headend while split tunneling is disabled. Which technology matches this requirement?
112A security architect is designing segmentation for a multi-tenant data center. The requirement is to provide isolated Layer 2 forwarding domains per tenant across a shared physical leaf-spine fabric, while maintaining a single IP subnet per tenant that can span multiple racks. Which technology should the architect select to meet these requirements?
113A network security engineer is configuring a Cisco ASA with VPN load balancing to distribute remote-access VPN connections across multiple ASA devices. Which technology should be used to achieve this?
114A security operations team is deploying Cisco Secure Network Analytics (Stealthwatch) with Cisco Identity Services Engine to detect compromised endpoints on the campus network. Which two data sources must be integrated to associate network flows with user identities? (Choose two.)
115A Cisco Stealthwatch Enterprise deployment is being reviewed after a security analyst reports that the appliance is not detecting long-lived, low-volume data exfiltration flows from a compromised internal host to an external IP. The flow collector is receiving NetFlow v9 records and the management console shows all sensors as healthy. Which telemetry gap is the most likely cause of the missed detection?
116A security engineer is asked to protect a public web application from application-layer attacks while also ensuring that legitimate user sessions are not blocked during a burst of legitimate traffic. The application team requires granular, signature-based protection for HTTP. Which Cisco solution should be deployed in front of the web servers?
117A security administrator is deploying Cisco Umbrella for a branch office and wants DNS-layer protection that blocks requests to malware domains before any connection is made, while still logging all DNS activity for retrospective investigation. The branch uses a Cisco ISR router as its internet gateway. Which deployment method best meets these requirements with minimal configuration on individual endpoints?
118A financial institution must ensure that data stored in a database is unreadable to anyone who gains access to the storage media, while still allowing authorized applications to query the data. The compliance team also requires that encryption keys be rotated and stored separately from the data. Which control best meets these requirements?
119An organization wants to enforce that only company-managed laptops can connect to the corporate wireless network, and that those laptops must have current antivirus and operating system patches before being granted access. Which Cisco solution should be deployed to evaluate endpoint posture and make the authorization decision?
120A security team is evaluating Cisco Stealthwatch (Secure Network Analytics) to detect threats using network flow data. Which two capabilities are provided by this solution? (Choose two.)
121A security administrator is configuring a Cisco Secure Firewall to inspect traffic between two internal departments that reside in different security zones on the same appliance. The requirement is to log all connection events and to reset any session that matches a specific intrusion rule, while still allowing the rest of the traffic. Which configuration element must be applied to the access control policy to achieve this?
122A security engineer is evaluating Cisco Identity Services Engine (ISE) to enforce endpoint compliance before granting network access. The organization wants to verify that endpoints have current antivirus definitions and required OS patches before allowing them onto the production VLAN. Which two ISE capabilities are required to accomplish this? (Choose two.)
123A security architect is designing segmentation for a data center using Cisco TrustSec. The requirement is that traffic between the web tier and the database tier must be restricted so that only specific TCP ports are allowed, and the policy must follow the workload even if it is migrated to a different rack and subnet. Which TrustSec component provides this enforcement?
Classify common attacks from log and traffic descriptions, and map each to the correct Cisco control. The single most important thing: know Zero Trust means no implicit trust, with access based on identity, context, and device posture.
The Courseiva 350-701 question bank contains 123 questions in the Security Concepts domain, covering the 25% of the exam attributed to this domain in the official Cisco blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Security Concepts domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included