Matching questions give you two columns — concepts, commands, or protocols on the left, and their definitions or use-cases on the right. You drag each left item to its correct match. These appear on most certification exams and punish superficial memorisation.
Start Scenario PracticeMatch each security technology to its primary function.
Explanation: Firewall filters traffic based on rules; IDS/IPS monitors for threats; VPN provides secure tunnels; NAC enforces compliance. Common mistakes include confusing IDS/IPS with firewall and NAC with VPN.
Match each Cisco security solution to its primary use case.
Explanation: Cisco ASA is a firewall/VPN solution, Firepower is NGFW/IPS, and ISE handles network access control. Common confusions involve mixing ASA with ISE or Firepower with Umbrella.
Match each Cisco ASA feature to its description.
Explanation: The correct matches are: Cut-Through Proxy (user authentication), Failover (high availability), ASDM (web GUI), and Packet Tracer (traffic simulation). Common confusions include mistaking Cut-Through Proxy for application inspection and Failover for multiple contexts.
Match each encryption algorithm to its type.
Explanation: AES and DES are symmetric encryption algorithms, RSA is asymmetric, and SHA-256 is a hashing algorithm. Common confusions include misclassifying AES as asymmetric or RSA as symmetric, and confusing hash functions with encryption.
Match each 802.1X component to its role.
Explanation: In 802.1X, the supplicant is the client requesting access, the authenticator is the network device (switch/AP) that enforces access control, and the authentication server (RADIUS) validates credentials. Common confusions involve swapping the roles of supplicant and authenticator.
+5 more scenario questions available
Practice all Drag and Drop Matching QuestionsMatching questions give you two columns — concepts, commands, or protocols on the left, and their definitions or use-cases on the right. You drag each left item to its correct match. These appear on most certification exams and punish superficial memorisation. These appear throughout the 350-701 and require you to apply your knowledge, not just recall facts.
Cisco doesn't publish an exact breakdown, but scenario-based questions (especially exhibit and command-output formats) make up a significant portion of the 350-701. Practicing each scenario type ensures you're ready for any format.
Yes. Courseiva provides free 350-701 scenario practice across all official exam domains. The platform includes scenario-based questions, command-output interpretation, topic-based practice, mock exams, and readiness tracking — no account required.
Launch a full Drag and Drop Matching Questions session with instant scoring and detailed explanations.
Start Scenario Practice →