350-401 · domain
Security
Use this page to practise Security questions for this certification. Focus on how the exam tests security in scenario format — understanding the why behind each answer builds more durable knowledge than memorising options.
Focused practice
Practice Security questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Security
Security questions on this certification test your ability to deploy and manage security concepts in scenario-based situations.
Core Security concepts and how they apply in real-world cloud scenarios.
How to deploy security correctly and verify the outcome.
Troubleshooting security issues by interpreting error output and system state.
Cloud best practices and Security design trade-offs tested by this certification.
Watch out for
Common Security exam traps
- ▸Selecting the most expensive service when a simpler managed option meets the requirement.
- ▸Forgetting that cloud resources must be explicitly secured — defaults are rarely secure.
- ▸Choosing a global service fix when the issue is region-specific.
- ▸Overlooking cost implications of cross-region data transfer in architecture questions.
Question index
All Security questions (6)
Click any question to see the full explanation, or start a practice session above.
Drag and drop the steps to configure port security on a Cisco switch in the correct order.
Medium2Which TWO of the following are valid methods to mitigate VLAN hopping attacks?
Medium3Your company has deployed a Cisco Catalyst 9300 switch stack as the distribution layer for a campus network. The network uses VLANs 10 (data), 20 (voice), and 30 (management). The switch stack is configured with DHCP snooping, Dynamic ARP Inspection (DAI), and IP Source Guard (IPSG) on access ports. Recently, users in VLAN 10 report intermittent connectivity issues. You notice that some users receive duplicate IP addresses from the DHCP server. The DHCP server is connected to a trunk port on the switch stack. After reviewing logs, you see that DHCPACK messages are being dropped on the trunk port. The DHCP snooping binding table shows entries for legitimate clients, but also some entries with MAC addresses from a different vendor. Which action should you take to resolve the issue?
Hard4Which TWO features are part of Cisco TrustSec for providing role-based access control?
Easy5Match each Spanning Tree Protocol (STP) variant to its key characteristic.
Medium6Which THREE of the following are characteristics of Cisco TrustSec (CTS) security architecture?
HardOther domains
All 350-401 exam domains
Frequently asked questions
- What does the Security domain cover on the 350-401 exam?
- Security questions on this certification test your ability to deploy and manage security concepts in scenario-based situations.
- How many questions are in this domain?
- This page lists all 6 Security questions in the 350-401 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Security questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.