20+ practice questions focused on Security — one of the most tested topics on the ENCOR 350-401 exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Security PracticeA network administrator is troubleshooting a DHCP snooping issue on a Cisco switch. The switch is configured with DHCP snooping globally and on VLAN 10. The trusted interface is GigabitEthernet0/1 connected to the DHCP server. However, clients on VLAN 10 are not receiving IP addresses from the DHCP server. What is the most likely cause?
Explanation: The scenario states that DHCP snooping is configured globally and on VLAN 10, and that GigabitEthernet0/1 is connected to the DHCP server. However, for DHCP snooping to allow DHCP server messages (OFFER, ACK) to be forwarded, the interface connected to the legitimate DHCP server must be explicitly configured as a trusted port using the 'ip dhcp snooping trust' interface command. Without this, the switch treats all DHCP server responses as untrusted and drops them, preventing clients from receiving IP addresses.
Your company has deployed a Cisco Catalyst 9300 switch stack as the distribution layer for a campus network. The network uses VLANs 10 (data), 20 (voice), and 30 (management). The switch stack is configured with DHCP snooping, Dynamic ARP Inspection (DAI), and IP Source Guard (IPSG) on access ports. Recently, users in VLAN 10 report intermittent connectivity issues. You notice that some users receive duplicate IP addresses from the DHCP server. The DHCP server is connected to a trunk port on the switch stack. After reviewing logs, you see that DHCPACK messages are being dropped on the trunk port. The DHCP snooping binding table shows entries for legitimate clients, but also some entries with MAC addresses from a different vendor. Which action should you take to resolve the issue?
Explanation: The DHCP snooping feature treats all ports as untrusted by default, which means DHCP server messages (DHCPOFFER, DHCPACK, DHCPNAK) are dropped on untrusted ports. Since the DHCP server is connected to a trunk port and DHCPACK messages are being dropped, that trunk port must be explicitly configured as a trusted port for DHCP snooping using the 'ip dhcp snooping trust' interface command. This allows legitimate DHCP server responses to reach clients, resolving the duplicate IP address issue caused by clients not receiving their assigned addresses.
Match each Spanning Tree Protocol (STP) variant to its key characteristic.
Explanation: STP (802.1D) is the original slow-converging standard; RSTP (802.1w) provides rapid convergence; MSTP (802.1s) maps multiple VLANs to fewer spanning tree instances; PVST+ runs per-VLAN STP. Common confusions include equating STP with per-VLAN and RSTP with multiple instances.
A network administrator is deploying a Cisco Catalyst 9300 switch in a campus access layer. The security policy mandates that when an unauthorized device connects to an access port, the port must immediately shut down and generate a syslog message, and the administrator must manually re-enable the port. The administrator configures the interface with the command 'switchport port-security violation shutdown'. However, after an unauthorized device connects, the port goes into the 'err-disabled' state, but no syslog message is generated. What is the most likely reason for the missing syslog message?
Explanation: Port security violations are logged at severity level 2 (critical). If the switch's logging level is configured to a higher severity (e.g., emergencies only), these messages are suppressed. The administrator should verify the logging level and ensure that critical messages are logged. The violation mode itself is correct for the requirement.
A network engineer is deploying 802.1X on a Cisco Catalyst 9200 switch. The authentication server is Cisco ISE. The help desk reports that some corporate Windows laptops fail authentication when they are first connected, but succeed after the user manually opens a browser. The switch port is configured with `authentication host-mode multi-auth` and `authentication open`. Which change should the engineer make to allow the laptops to authenticate without user interaction?
Explanation: The laptops fail initial authentication because the Windows 802.1X supplicant is not enabled or configured to start automatically. Without the supplicant, the switch port does not receive EAPOL-Start frames, so authentication never begins. Enabling the supplicant through Group Policy ensures the laptops initiate authentication as soon as they connect, allowing Cisco ISE to authenticate them without user intervention.
+15 more Security questions available
Practice all Security questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Security. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Security questions on the 350-401 frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Security is tested as part of the ENCOR 350-401 blueprint. Practicing with targeted Security questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free 350-401 practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Security is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Security practice session with instant scoring and detailed explanations.
Start Security Practice →