Be able to configure NTP authentication and access control on IOS XR, select correct BGP FlowSpec match components for a given filter, and choose FlowSpec over RTBH or static ACLs for dynamic DDoS mitigation. The key skill is mapping the scenario's requirement to the exact feature and component.
0Start practicing
Security and Services — choose a session length
Free · No account required
Domain overview
This domain covers securing and managing Cisco Service Provider networks: NTP authentication, control-plane and management-plane protection, BGP FlowSpec for DDoS mitigation, and traffic filtering distribution. Questions test IOS XR and IOS XE feature configuration, FlowSpec component selection, and matching the right tool to an operational scenario rather than recalling raw theory.
Exam objectives
NTP authentication and access control on IOS XR to block unauthorized time sources
BGP FlowSpec components: match destination port, DSCP, protocol, and traffic-rate actions
Control-plane policing (CoPP) and management-plane protection to filter router-bound traffic
Distributing dynamic traffic filtering rules to multiple routers during DDoS attacks
Confusing FlowSpec match components with action components, or picking the wrong component for destination port versus DSCP.
Assuming NTP authentication alone restricts servers; access-group or serve/peer ACLs are also needed to prevent synchronization.
Choosing static ACLs or RTBH when the scenario demands dynamic, multi-router rule distribution that FlowSpec provides.
Click any question to see the full explanation and answer options, or start a focused practice session above.
A service provider wants to protect its routers from CPU overload caused by excessive traffic to the control plane. Which mechanism should be configured on IOS XR routers to classify and rate-limit management traffic?
2An engineer is configuring management plane hardening on an IOS XR router. The requirement is to authenticate users against a central server and provide granular command authorization. Which protocol and feature should be used?
3A service provider is deploying uRPF on customer-facing interfaces to prevent IP spoofing. The network has asymmetric routing due to multiple upstream connections. Which uRPF mode should be used?
4An SP wants to filter BGP prefixes received from a customer to prevent hijacking. Which two tools can be used together on the provider edge router to implement inbound prefix filtering?
5A network engineer needs to perform maintenance on a BGP router without causing traffic loss. They plan to use BGP Graceful Shutdown (GSHUT). What does GSHUT do?
6A service provider is deploying a BNG for subscriber management. Which protocol is used to authenticate subscribers and assign IP addresses via the BNG?
7An SP is implementing CGNAT to conserve IPv4 addresses. For legal compliance, they must log all NAT translations with timestamps and source/destination information. Which CGNAT feature should be enabled?
8An SP uses DPI to classify traffic. What is the primary purpose of DPI in a service provider network?
9An engineer is configuring NTP authentication on IOS XR routers to ensure secure time synchronization. What is required for NTP authentication to work?
10An SP wants to secure management access to IOS XR routers. Which two measures should be implemented? (Choose two.)
11A service provider wants to protect its core routers from CPU exhaustion caused by excessive ICMP traffic. Which control plane protection mechanism on IOS XR would be most appropriate to rate-limit ICMP packets destined to the router?
12An SP engineers want to restrict management access to their IOS XR routers. Which combination provides the most secure management plane hardening?
13A service provider deploys uRPF on customer-facing interfaces to prevent IP spoofing. They have a multihomed customer with asymmetric routing. Which uRPF mode should be used to avoid dropping legitimate traffic?
14In an MPLS L3VPN, how can a service provider prevent a CE device from learning the MPLS label stack and potentially spoofing labels?
15An SP implements Carrier-Grade NAT (CGNAT) to conserve IPv4 addresses. For legal compliance, what additional function must be enabled to log subscriber IP-port mappings?
16A service provider uses BGP FlowSpec (RFC 8955) to mitigate DDoS attacks. Which component in the network is responsible for originating the FlowSpec rules and distributing them to routers?
17To secure NTP in a service provider network, which feature should be enabled on IOS XR routers to prevent time synchronization with unauthorized NTP servers?
18A service provider is deploying uRPF on peering edges with multiple upstream providers and asymmetric routing. Which two statements are true about uRPF operation in this scenario? (Choose two.)
19A service provider is implementing BGP security using RPKI. Which three components are required for RPKI-based BGP origin validation? (Choose three.)
20A service provider is implementing control plane protection (CoPP) on an IOS XR router. Which protocol should be classified and rate-limited to prevent excessive control plane load due to routing updates?
21An engineer is hardening the management plane of an IOS XR router. Which combination is the most secure for remote administration?
22A service provider wants to prevent IP spoofing at the customer edge by verifying that the source IP address of incoming packets is reachable via the interface they arrive on. Which uRPF mode should be used?
23A network operator wants to distribute traffic filtering rules to multiple routers dynamically during a DDoS attack. Which technology should be used?
24Which feature is used to validate that a BGP route origin is authorized by the prefix owner?
25A service provider is preparing for maintenance on a BGP-speaking router. To minimize packet loss, they want to signal to neighbors that the session is being shut down gracefully. Which BGP feature should be used?
26Which protocol is used by a BNG to authenticate and authorize subscribers?
27A service provider implements CGNAT to conserve IPv4 addresses. Which feature is required to ensure that application-level protocols such as SIP or FTP function correctly?
28Which IOS XR feature allows an administrator to grant specific commands to a user based on their role, using task groups?
29What is the purpose of NTP authentication in a service provider network?
30A service provider wants to deploy DDoS mitigation using BGP FlowSpec. Which two actions can FlowSpec rules specify? (Choose two.)
31When implementing RPKI for BGP origin validation, which three states can a route be marked as? (Choose three.)
32A service provider is implementing security for BGP peering. Which two methods help prevent BGP route hijacking? (Choose two.)
33An SP engineer is hardening management plane access on IOS XR routers. They want to enforce role-based access control using task groups. Which AAA protocol is required to support attribute-based authorization on IOS XR?
34An engineer is implementing Unicast Reverse Path Forwarding (uRPF) on a provider edge (PE) router to mitigate IP spoofing. The customer-facing interface has a single static default route. Which uRPF mode should be used to provide anti-spoofing without causing false drops?
35An SP is deploying BGP FlowSpec (RFC 8955) to distribute traffic filtering rules. Which component is responsible for disseminating FlowSpec rules to routers in the network?
36A service provider wants to prevent BGP hijacking by validating the origin AS of received routes. They deploy RPKI with Route Origin Authorizations (ROAs). When a router receives a prefix with an origin AS that matches the ROA, what is the BGP Origin Validation state?
37An engineer is configuring BGP Graceful Shutdown (GSHUT) for maintenance on a router. Which BGP attribute is set to trigger the graceful shutdown behavior?
38An MPLS L3VPN service provider wants to prevent label spoofing attacks where a customer could inject MPLS labels to bypass ACLs. Which configuration practice should be implemented on PE-CE links?
39An SP is implementing Carrier-Grade NAT (CGNAT) to conserve IPv4 addresses. Which feature must be enabled to support applications that embed IP addresses in the payload, such as SIP or FTP?
40An engineer is configuring BGP prefix filtering on a provider edge router to prevent BGP hijacking. They want to allow only customer prefixes that are registered in the RIR database. What is the most effective method to automate this filtering?
41An SP is deploying Deep Packet Inspection (DPI) to classify traffic for QoS and security. Which DPI technique is used to identify applications regardless of port numbers?
42An engineer wants to secure NTP on IOS XR routers. Which configuration is required to prevent unauthorized time synchronization?
43A service provider is using Cisco Peakflow for DDoS detection. Peakflow identifies anomalies based on network traffic telemetry. Which data collection method does Peakflow primarily use?
44An SP is implementing BGP FlowSpec to mitigate DDoS. The FlowSpec rule should match traffic with destination port 80 and DSCP value 0. Which FlowSpec component is used to specify the destination port?
45A service provider is hardening management plane access on IOS XR routers. Which TWO measures should be implemented to secure management access? (Choose two)
46Which TWO protocols are supported by a BNG (Broadband Network Gateway) for subscriber session establishment? (Choose two)
47A service provider is implementing RPKI to validate BGP routes. Which THREE components are necessary for a complete RPKI deployment on routers? (Choose three)
48A service provider router running IOS XR is configured with Control Plane Policing (CoPP) to protect the route processor. Which type of traffic is most commonly rate-limited using CoPP in the control plane?
49An SP network engineer is hardening management plane access on IOS XR routers. They require authentication, authorization, and accounting (AAA) with per-command authorization and role-based access control. Which combination should be used?
50A service provider wants to prevent IP spoofing attacks from customer edge devices connected to a PE router. The customer prefixes are known and asymmetric routing is not present. Which uRPF mode should be configured on the PE-CE interface?
51A BNG (Broadband Network Gateway) is used for subscriber management. Which protocol is typically used between the BNG and the subscriber's modem (CPE) for authentication and IP address assignment in a PPPoE environment?
52A network engineer is configuring management plane security on IOS XR. Which TWO of the following are recommended practices? (Choose two.)
53A service provider is implementing BGP security measures to prevent route hijacking. Which TWO mechanisms directly validate the origin AS of BGP prefixes? (Choose two.)
54An SP engineer is configuring NTP authentication on IOS XR routers in the management plane. Which TWO statements about NTP authentication are correct? (Choose two.)
55An engineer is configuring BGP Origin Validation on an IOS XR router using RPKI. The router is peering with a validator via RTR protocol. After configuration, the engineer notices that some routes are marked as 'valid' even though their origin AS is not in the RPKI database. Which action should be taken to ensure that only routes with a valid ROA are accepted?
Be able to configure NTP authentication and access control on IOS XR, select correct BGP FlowSpec match components for a given filter, and choose FlowSpec over RTBH or static ACLs for dynamic DDoS mitigation. The key skill is mapping the scenario's requirement to the exact feature and component.
The Courseiva 350-501 question bank contains 55 questions in the Security and Services domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Security and Services domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included