Courseiva

CCNA Security Questions

75 of 161 questions · Page 1/3 · Security · Answers revealed

1
MCQhard

A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router to protect against excessive ARP traffic. The engineer applies the following policy: policy-map COPP-POLICY class ARP-CLASS police 8000 conform-action transmit exceed-action drop After applying the service-policy to the control-plane, the engineer notices that legitimate ARP requests are being dropped during peak hours. Which action should the engineer take to resolve this issue while maintaining protection?

A.Add a class-map that matches ARP replies and apply a separate police rate to that class.
B.Increase the police rate to a higher value that accommodates peak ARP traffic while still limiting excessive bursts.
C.Remove the service-policy from the control-plane and apply it to the data plane instead.
D.Change the exceed-action to transmit so that all ARP packets are allowed through.
AnswerB

The police rate of 8000 bps is too low for peak ARP traffic, causing legitimate ARP requests to be dropped. Increasing the rate to a value that matches normal peak traffic while still providing an upper bound protects the control plane without dropping legitimate traffic. This is the correct tuning approach for CoPP.

Why this answer

CoPP police rates must be tuned to allow legitimate control-plane traffic while blocking excess. A rate of 8000 bps is insufficient for ARP during peak hours, so increasing the rate to a realistic peak value resolves drops while preserving protection. Changing exceed-action to transmit removes protection, moving the policy to the data plane is ineffective, and splitting classes without raising the rate does not fix the underlying issue.

Exam trap

The trap here is thinking that any drop means the policy is too strict and should be disabled, rather than tuning the rate to match legitimate traffic patterns.

2
MCQmedium

An engineer is configuring an IPsec site-to-site VPN between two Cisco IOS XE routers. Phase 1 completes successfully, but Phase 2 fails and no interesting traffic is encrypted. The engineer confirms that the ACLs on both peers mirror each other correctly. Which configuration element should be verified next to resolve the Phase 2 failure?

A.Verify that the Diffie-Hellman group in the ISAKMP policy matches the group used in the transform set.
B.Verify that the crypto map sequence number is higher on the responding peer than on the initiating peer.
C.Verify that the ISAKMP policy on both peers uses the same pre-shared key for Phase 1 authentication.
D.Verify that the transform set on both peers specifies matching encryption and integrity algorithms for Phase 2.
AnswerD

Phase 2 negotiation uses the transform set to define encryption and integrity algorithms for the IPsec SA. If the transform sets differ between peers, the quick mode negotiation fails even though Phase 1 succeeded. Matching transform sets on both routers is essential to complete Phase 2 and establish the data-protection tunnel.

Why this answer

IPsec Phase 2 negotiation, also called quick mode, relies on matching transform sets that define the encryption and integrity algorithms for the data SA. When Phase 1 succeeds but Phase 2 fails, mismatched transform sets are a common cause. Verifying that both peers use identical transform set definitions resolves the negotiation failure.

Exam trap

The trap here is revisiting Phase 1 parameters such as the pre-shared key after Phase 1 has already succeeded, instead of focusing on Phase 2 elements like the transform set.

3
MCQhard

A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS XE router to protect the route processor. The engineer wants to rate-limit ICMP echo requests destined to the router itself while ensuring that transit traffic passing through the router is not affected. Which classification approach should the engineer use in the CoPP policy?

A.Apply a policy map with police rate to the management VRF interface only.
B.Match ICMP in a class map applied to the ingress interface with the service-policy command.
C.Configure an ingress ACL on all interfaces that denies ICMP echo requests to the router.
D.Use a class map with match access-group referencing an ACL that permits ICMP echo to the router's interface addresses, then attach the policy map to the control-plane interface.
AnswerD

CoPP operates by attaching a service policy to the control-plane interface (control-plane global configuration), which only sees traffic punted to the route processor. Matching ICMP echo requests destined to the router's own addresses in a class map, then applying the policy to control-plane, rate-limits only router-bound ICMP while transit traffic is untouched. This is the standard CoPP design pattern for protecting the route processor.

Why this answer

CoPP works by attaching a service policy to the control-plane interface, which only processes traffic destined to the route processor. Classifying ICMP echo requests to the router's own addresses and policing them there protects the CPU without affecting transit traffic. Interface-level policies or ACLs either affect transit traffic or block rather than rate-limit, so the control-plane attachment with an ACL-based class map is correct.

Exam trap

The trap here is confusing interface-level policing with control-plane policing, when only the control-plane attachment isolates router-bound traffic from transit traffic.

4
MCQhard

A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS XE router that runs BGP, SSH, and SNMP. The engineer wants to ensure that BGP keepalives are not dropped during a control plane overload, while still rate-limiting SSH and SNMP. The engineer creates a class-map matching BGP, SSH, and SNMP traffic, then applies a policy-map with a single policer of 1000 pps to that class. After applying the service-policy to the control plane, BGP sessions flap during high CPU utilization. What is the most likely cause?

A.CoPP cannot be applied to BGP traffic; it only supports management protocols like SSH and SNMP.
B.The service-policy must be applied to the data plane instead of the control plane for BGP to be protected.
C.The policer rate is too low for BGP keepalives, and all matched traffic is treated equally.
D.The policer should be configured with 'police cir' instead of 'police pps' to properly rate-limit BGP.
AnswerC

A single policer applied to a class that matches BGP, SSH, and SNMP treats all three protocols identically. During high CPU, BGP keepalives may exceed the 1000 pps rate along with other traffic, causing drops. BGP requires a separate class with a higher rate or priority to ensure keepalives are not dropped. The design flaw is the lack of granularity.

Why this answer

CoPP requires granular classification to protect critical protocols. When BGP, SSH, and SNMP are matched in the same class and policed together, BGP keepalives compete with other traffic and may be dropped during high CPU. BGP should be placed in its own class with a higher rate or priority to prevent flapping.

The single policer approach lacks the necessary differentiation.

Exam trap

The trap here is assuming that a single policer can adequately protect all control plane protocols, when in fact BGP requires separate treatment to avoid keepalive drops during congestion.

5
MCQhard

Refer to the exhibit. A switch has IP Source Guard (IPSG) and port-security enabled on interface GigabitEthernet0/1. A host with IP 10.1.1.1 and MAC 00:1A:2B:3C:4D:5E is connected and tries to access a web server at 192.168.1.100. What will happen?

A.The traffic is blocked because the host is not using DHCP, so IPSG drops all non-DHCP traffic.
B.The traffic is permitted only if the destination is also in the 10.0.0.0/8 range.
C.The traffic is blocked because IP Source Guard requires a static binding for the host.
D.The traffic is permitted because the host's IP is within the allowed subnet and the MAC is valid according to port-security.
AnswerC

Correct. Without DHCP or a static IP-source binding, IPSG blocks the traffic.

Why this answer

IP Source Guard (IPSG) validates the source IP address of traffic using DHCP snooping bindings or static IP-source bindings. In this scenario, no DHCP snooping binding exists (host is not using DHCP) and no static binding has been configured, so IPSG will drop the traffic from the host. Port-security ensures the source MAC is valid, but does not provide the IP-MAC binding required by IPSG.

Therefore, the traffic is blocked.

Exam trap

The trap is that many candidates assume port-security alone satisfies IPSG requirements, but IPSG needs a separate IP-MAC binding from DHCP snooping or static configuration.

How to eliminate wrong answers

Option A is wrong because IPSG does not drop all non-DHCP traffic; it filters based on IP-to-MAC bindings from DHCP snooping or static entries, not the source of the IP assignment. Option B is wrong because IPSG does not restrict traffic based on the destination IP address; it only validates the source IP and MAC of the host. Option C is wrong because IPSG does not require a static binding for the host; it can use dynamic DHCP snooping bindings, and in this case, port-security provides an alternative validation mechanism.

6
MCQeasy

A network engineer needs to secure management access to a Cisco IOS XE router. The requirement is to encrypt all management traffic, including SNMP, and to authenticate administrators against a centralized server. Which combination of features should be implemented?

A.HTTPS for CLI access, SNMPv3 with noAuthNoPriv, and TACACS+ for authentication.
B.SSH for CLI access, SNMPv3 with authPriv, and TACACS+ for authentication.
C.SSH for CLI access, SNMPv2c with an ACL, and local authentication.
D.Telnet for CLI access, SNMPv2c with a community string, and RADIUS for authentication.
AnswerB

SSH encrypts CLI sessions, SNMPv3 with authPriv provides both authentication and encryption for SNMP, and TACACS+ centralizes administrator authentication with per-command authorization. This combination meets the requirement to encrypt all management traffic and authenticate against a central server. It is the standard secure management baseline for Cisco IOS XE devices.

Why this answer

SSH, SNMPv3 authPriv, and TACACS+ together provide encrypted CLI access, authenticated and encrypted SNMP, and centralized administrator authentication. The other options either use clear-text protocols like Telnet or SNMPv2c, or rely on local authentication, failing the encryption and centralization requirements.

Exam trap

The trap here is assuming SNMPv2c with an ACL is secure, when only SNMPv3 authPriv encrypts SNMP traffic.

7
MCQhard

A network engineer is configuring IPsec VPN on a Cisco IOS XE router. The requirement is to protect traffic between two sites using ESP with AES-256 encryption and SHA-256 authentication, and to ensure that the tunnel is rekeyed every 3600 seconds. Which configuration element directly controls the rekey interval?

A.crypto ipsec transform-set <name> esp-aes 256 esp-sha256-hmac
B.crypto map <name> 10 ipsec-isakmp
C.crypto ipsec security-association lifetime seconds 3600
D.crypto isakmp key <key> address <peer>
AnswerC

The 'crypto ipsec security-association lifetime seconds 3600' command sets the IPsec SA lifetime to 3600 seconds, after which the SA is rekeyed. This is the correct command to control the rekey interval for the IPsec (data) tunnel. The IKE SA lifetime is controlled separately with 'crypto isakmp policy' or 'crypto ikev2 policy' settings, but the IPsec SA lifetime is what governs data tunnel rekeying.

Why this answer

The IPsec SA lifetime, configured with 'crypto ipsec security-association lifetime seconds 3600', determines when the data tunnel is rekeyed. This is distinct from the IKE SA lifetime, which governs the control plane. The transform-set defines the algorithms (AES-256, SHA-256), the crypto map ties the policy together, and the pre-shared key authenticates the peers, but only the security-association lifetime command controls the rekey interval.

Exam trap

The trap here is confusing the IKE SA lifetime with the IPsec SA lifetime, and assuming that the transform-set or crypto map controls rekeying.

8
MCQmedium

A network administrator is configuring 802.1X on a Cisco Catalyst switch. The switch is connected to a Cisco IP phone with a PC attached to the phone's data port. The requirement is to authenticate both the phone and the PC separately, with the phone in the voice VLAN and the PC in the data VLAN. Which 802.1X feature should be enabled?

A.Multi-Authentication (Multi-Auth)
B.MAC Authentication Bypass (MAB)
C.Multi-Domain Authentication (MDA)
D.Web Authentication (WebAuth)
AnswerC

MDA allows both a voice device (phone) and a data device (PC) to authenticate independently on the same switch port. Each device is authenticated in its respective VLAN (voice and data), and the switch applies separate policies. This meets the requirement of authenticating both devices separately.

Why this answer

Multi-Domain Authentication (MDA) is designed for scenarios where a voice device and a data device share a switch port. It allows both to authenticate independently and assigns them to their respective VLANs, meeting the requirement for separate authentication and VLAN segmentation.

Exam trap

The trap here is confusing Multi-Auth with MDA; Multi-Auth allows multiple devices but places them in the same VLAN, while MDA separates voice and data domains.

9
MCQhard

A security architect is evaluating MACsec on a Cisco Catalyst switch uplink between two buildings. The requirement is to encrypt all Layer 2 traffic on the link with minimal configuration and use a standards-based key agreement. Which statement correctly describes how MACsec should be deployed on this link?

A.MACsec must be configured with a pre-shared CAK/CKN pair on both switches, and MKA uses this pair to derive session keys.
B.MACsec can be enabled only on routed ports and is incompatible with switch-to-switch trunk links carrying multiple VLANs.
C.MACsec encrypts only the payload of IP packets, leaving the Ethernet header visible for switching.
D.MACsec requires 802.1X EAP-TLS authentication of both switches before any frame encryption can occur.
AnswerA

MACsec uses the MACsec Key Agreement (MKA) protocol, which relies on a Connectivity Association Key (CAK) and its name (CKN). When configured with a static pre-shared CAK/CKN, MKA derives the Secure Association Key (SAK) used to encrypt traffic. This is the standard, low-configuration deployment for a point-to-point uplink and meets the requirement for standards-based key agreement.

Why this answer

MACsec secures point-to-point Ethernet links using MKA to negotiate encryption keys. A static CAK and CKN configured on both ends lets MKA derive the SAK that encrypts each frame, requiring no external authentication server. This is the standard, minimal-configuration approach for a switch uplink, and MACsec encrypts the full Ethernet frame, not just IP payloads.

Exam trap

The trap here is believing MACsec always requires 802.1X, when a static pre-shared CAK/CKN with MKA is a valid and common deployment for switch-to-switch links.

10
MCQmedium

A network engineer applies the above CoPP policy on a router. The router has BGP peers, SSH management, and SNMP monitoring. After applying this policy, which traffic will be affected?

A.BGP sessions may flap due to dropped keepalives.
B.Data plane traffic will be dropped.
C.Only SSH sessions will be rate-limited.
D.SNMP and SSH will be unaffected because they are explicitly permitted.
AnswerA

BGP keepalives are sent periodically (typically every 60 seconds) and matched by the CoPP BGP class because they are control-plane TCP traffic to/from port 179. If the policer's committed rate is exceeded—even briefly—the excess keepalives are dropped. After a few missed keepalives, the BGP hold timer (default 180 seconds) expires, causing the peer session to flap. The same policer can also drop BGP route updates, which may cause instability beyond just keepalives.

Why this answer

The CoPP policy applies to control plane traffic, not data plane traffic. BGP keepalives are control plane packets; if the policy drops or rate-limits them, BGP sessions may time out and flap. The correct answer is A because BGP keepalives are essential for maintaining neighbor adjacency, and dropping them directly causes session instability.

Exam trap

Cisco often tests the misconception that CoPP affects data plane traffic or that only management protocols like SSH are impacted, when in fact control plane policing targets all control plane packets, including routing protocol keepalives.

How to eliminate wrong answers

Option B is wrong because CoPP operates on the control plane, not the data plane; data plane traffic is forwarded in hardware and unaffected by control plane policing. Option C is wrong because the policy affects all control plane traffic matching the class maps, not just SSH; BGP and SNMP are also subject to rate-limiting or dropping. Option D is wrong because SNMP and SSH are not 'unaffected' — they are explicitly permitted only if they match a permit ACE in the class map; if the class map drops or rate-limits them, they will be affected.

11
MCQhard

A network engineer is configuring IPsec site-to-site VPNs on a Cisco IOS XE router. The design requires that the router authenticate peers using certificates issued by an internal PKI rather than pre-shared keys, and that IKEv2 be used for the key exchange. Which configuration element is required to support certificate-based authentication for IKEv2 on this router?

A.A pre-shared key configured under the IKEv2 keyring with the peer's address.
B.An ISAKMP policy with authentication pre-share under the crypto isakmp configuration.
C.A crypto pki trustpoint configuration with enrollment and an RSA key pair, referenced in the IKEv2 profile.
D.A crypto map with the set peer command specifying the remote peer's hostname.
AnswerC

Certificate-based IKEv2 authentication requires a trustpoint that defines the CA, an enrolled identity certificate, and an RSA key pair on the router. The IKEv2 profile then references authentication local rsa-sig and the trustpoint so the router can present its certificate and validate the peer's certificate chain. Without a properly enrolled trustpoint, the router cannot perform RSA signature authentication, so this element is mandatory for the design.

Why this answer

IKEv2 certificate authentication requires an enrolled PKI trustpoint, an RSA key pair, and an IKEv2 profile that references RSA signature authentication with that trustpoint. Pre-shared keys and ISAKMP policies belong to the alternative authentication method or the older IKEv1 framework, and a crypto map only defines IPsec policy and peer identity. The trustpoint is the essential element enabling certificate-based peer authentication.

Exam trap

The trap here is mixing IKEv1 ISAKMP policy syntax with IKEv2 profile configuration, when IKEv2 certificate authentication depends on a trustpoint referenced in the IKEv2 profile.

12
MCQhard

A Cisco Catalyst 9500 switch in a data center is configured with IP Source Guard on an access port where a server is connected. The server has a static IP address of 10.10.10.50 and MAC address 00:11:22:33:44:55. The network administrator has configured a static IP source binding using the command 'ip source binding 0011.2233.4455 vlan 10 10.10.10.50 interface GigabitEthernet1/0/1'. However, the server cannot communicate through the switch. What is the most likely cause?

A.IP Source Guard only works on trunk ports, not access ports.
B.IP Source Guard requires DHCP snooping to be enabled on the VLAN even when static bindings are used.
C.The static IP source binding must be configured with the MAC address in the format xx:xx:xx:xx:xx:xx.
D.The server must use DHCP to obtain its IP address for IP Source Guard to permit traffic.
AnswerB

IP Source Guard relies on the DHCP snooping binding table to validate IP-to-MAC bindings. Even with static entries, DHCP snooping must be enabled on the VLAN to maintain the binding table and allow IP Source Guard to function. Without it, the switch cannot validate traffic and may drop packets, causing the server to lose connectivity.

Why this answer

IP Source Guard uses the DHCP snooping binding table to validate source IP and MAC addresses on a port. Static bindings can be added manually, but DHCP snooping must still be enabled on the VLAN to activate the binding table and allow IP Source Guard to filter traffic. Without DHCP snooping, the static binding is not effective, and the switch may drop legitimate traffic.

Exam trap

The trap here is assuming that static IP source bindings eliminate the need for DHCP snooping, when in fact DHCP snooping must be enabled on the VLAN for IP Source Guard to function.

13
Multi-Selecthard

A network engineer is deploying MACsec on a Cisco Catalyst switch to secure point-to-point links between the access and distribution layers. The design must ensure data confidentiality and integrity on the wire, and must use a key agreement mechanism that supports dynamic key exchange. Which TWO of the following are required to meet these requirements? (Choose two.)

Select 2 answers
A.Configure MACsec (802.1AE) on the point-to-point interfaces to provide data confidentiality and integrity.
B.Configure a private VLAN between the access and distribution switches to isolate traffic.
C.Configure MKA (MACsec Key Agreement) on the participating interfaces to negotiate and rotate keys.
D.Configure 802.1X with EAP-TLS on the inter-switch links to establish the encryption keys.
E.Configure IPsec transport mode between the switches to encrypt all Layer 2 traffic.
AnswersA, C

MACsec, defined in IEEE 802.1AE, provides hop-by-hop encryption and integrity checking at Layer 2 using GCM-AES. Enabling MACsec on the interfaces is what actually secures the wire between access and distribution. MKA alone negotiates keys but does not encrypt frames, so MACsec must be configured to satisfy the confidentiality and integrity requirement.

Why this answer

MACsec (802.1AE) supplies Layer 2 encryption and integrity, while MKA provides the dynamic key agreement, peer discovery, and key rotation. Both must be configured on the point-to-point links to meet the confidentiality, integrity, and dynamic key exchange requirements. IPsec, 802.1X, and private VLANs do not deliver Layer 2 link encryption with MKA.

Exam trap

The trap here is treating 802.1X as the key agreement for MACsec, when MKA is the protocol that negotiates and rotates MACsec keys.

14
MCQeasy

A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router to protect the route processor from excessive SSH traffic. The engineer wants to classify SSH traffic destined to the router itself and apply a policer to it. Which mechanism is used by CoPP to classify traffic before the policer is applied?

A.Class maps that match on the control-plane interface and access control lists
B.Policy maps that match on the ingress data-plane interface
C.Route maps that match on the management VRF and next-hop address
D.ACLs applied directly to the VTY lines with the access-class command
AnswerA

CoPP uses a modular QoS CLI structure in which class maps match traffic destined to the control plane. Matching combines the control-plane keyword with ACLs, protocol keywords, or NBAR to identify specific flows such as SSH. The matched traffic is then referenced by a policy map that applies a policer, which is attached to the control plane with the service-policy command.

Why this answer

CoPP is built on the modular QoS CLI, where class maps identify control-plane traffic using the control-plane keyword combined with ACLs or protocol matches. A policy map then applies a policer to those classes, and the policy is attached to the control plane with service-policy. This layered approach lets administrators rate-limit SSH and other punted traffic without affecting transit forwarding.

Exam trap

The trap here is confusing VTY access-class filtering with CoPP policing; access-class restricts who can connect, while CoPP actually rate-limits traffic destined to the route processor.

15
MCQmedium

A network administrator is configuring IPsec VPN on a Cisco IOS router. The administrator wants to ensure that only traffic from the 10.1.1.0/24 subnet to the 10.2.2.0/24 subnet is encrypted, while all other traffic is sent unencrypted. Which configuration element is required to define this traffic?

A.A crypto ACL that permits IP traffic from 10.1.1.0/24 to 10.2.2.0/24.
B.An ACL applied to the outside interface with 'ip access-group' to permit the traffic and enable encryption.
C.A prefix list that permits the source and destination subnets, applied to the crypto map.
D.A route map that matches the source and destination subnets and sets the next-hop to the VPN peer.
AnswerA

A crypto ACL (also called an encryption ACL) defines the interesting traffic that should be protected by IPsec. It is referenced in the crypto map. Permitting traffic from 10.1.1.0/24 to 10.2.2.0/24 ensures that only this traffic is encrypted. Other traffic falls through the implicit deny and is sent unencrypted, as desired. This is the standard method to specify VPN traffic.

Why this answer

IPsec uses a crypto ACL to define which traffic is protected. This ACL is referenced in a crypto map, which is applied to the interface. Traffic matching the ACL is encrypted; other traffic is not.

The crypto ACL must permit the specific source and destination subnets. Other options do not correctly identify interesting traffic for IPsec.

Exam trap

The trap here is confusing interface ACLs with crypto ACLs; only the crypto ACL referenced in the crypto map defines interesting traffic for encryption.

16
MCQeasy

A network administrator is configuring a Cisco Wireless LAN Controller (WLC) to use 802.1X authentication for wireless clients. The administrator wants to ensure that the WLC communicates with the RADIUS server securely. Which protocol should be used to encrypt the RADIUS communication between the WLC and the RADIUS server?

A.RADIUS with IPsec
B.RADIUS over TLS (RadSec)
C.RADIUS with MS-CHAPv2
D.RADIUS with EAP-TLS
AnswerB

RadSec (RADIUS over TLS) encrypts RADIUS packets using TLS, providing secure communication between the WLC and the RADIUS server. This protects credentials and attributes from eavesdropping. It is the recommended method for securing RADIUS traffic in modern deployments.

Why this answer

RadSec (RADIUS over TLS) is the correct protocol to encrypt RADIUS communication between a WLC and a RADIUS server. It uses TLS to secure the entire RADIUS packet, ensuring confidentiality and integrity. Other options either refer to authentication methods or do not provide native encryption for RADIUS.

Exam trap

The trap here is confusing authentication protocols like EAP-TLS or MS-CHAPv2 with transport encryption mechanisms, leading to the selection of an option that secures client authentication but not the RADIUS transport.

17
MCQeasy

A network administrator is configuring a site-to-site VPN between two Cisco routers using IPsec. The administrator wants to ensure that the data transmitted between the sites is encrypted and authenticated. Which IPsec protocol should be used to provide both confidentiality and integrity for the data payload?

A.Generic Routing Encapsulation (GRE)
B.Internet Key Exchange (IKE)
C.Authentication Header (AH)
D.Encapsulating Security Payload (ESP)
AnswerD

ESP provides confidentiality through encryption and can also provide authentication and integrity for the payload. It is the standard choice for VPNs requiring encryption. ESP can operate in transport or tunnel mode; in tunnel mode, it encrypts the entire original IP packet. This meets the requirement for both confidentiality and integrity of the data payload.

Why this answer

ESP is the IPsec protocol that provides both confidentiality (encryption) and integrity/authentication for the data payload. AH only provides integrity and authentication, while IKE is for key exchange and GRE is a tunneling protocol without built-in security. Therefore, ESP is the correct choice for encrypting and authenticating VPN traffic.

Exam trap

The trap here is selecting AH because it sounds like it provides authentication, but it lacks encryption; ESP is needed for confidentiality.

18
Multi-Selecthard

A network security engineer is deploying Cisco TrustSec in a campus network. The engineer wants to implement Security Group Tags (SGTs) and enforce policies using a Cisco Catalyst switch as an enforcement point. Which two statements are true regarding SGT propagation and enforcement in this scenario? (Choose two.)

Select 2 answers
A.SGTs are always carried in the IP header as a DSCP value to ensure end-to-end propagation.
B.SGTs can be propagated through a Layer 2 trunk using Cisco Metadata (CMD) or inline tagging.
C.Enforcement devices must be configured with the 'cts manual' command on trunk interfaces to enable SGT propagation.
D.The Security Group Access Control List (SGACL) is downloaded from Cisco ISE to the enforcement device to define permitted traffic between SGTs.
E.SGT enforcement requires that all switches in the path support Cisco TrustSec and have SGT propagation enabled.
AnswersB, D

Cisco TrustSec supports SGT propagation through Layer 2 trunks using either Cisco Metadata (CMD) or inline tagging (also known as SGT Exchange Protocol or SXP for Layer 3). Inline tagging embeds the SGT in the Ethernet frame, allowing switches to enforce policies based on the tag without needing to look up the source identity.

Why this answer

SGTs can be propagated through Layer 2 trunks using Cisco Metadata (CMD) or inline tagging, and SGACLs are downloaded from Cisco ISE to enforcement devices to define permitted traffic between SGTs. These two statements are true. Not all switches need to support TrustSec for enforcement, SGTs are not carried in the IP header as DSCP, and 'cts manual' is not the primary command for trunk propagation.

Exam trap

The trap here is assuming that SGTs are carried in the IP header or that all switches must support TrustSec, when in fact they can be propagated via inline tagging or SXP and enforcement can be centralized.

19
MCQeasy

A network administrator is configuring a zone-based firewall on a Cisco IOS XE router. The requirement is to allow HTTP traffic from the INSIDE zone to the OUTSIDE zone while blocking all other traffic initiated from INSIDE. Which action must be taken to define the traffic that is permitted?

A.Configure a route-map that matches HTTP and apply it to the zone pair.
B.Create a class-map that matches HTTP, then reference it in a policy-map and apply the policy-map to the zone pair.
C.Apply an ACL directly to the INSIDE zone interface with the ip access-group command.
D.Enable NAT with an overload statement matching HTTP on the OUTSIDE interface.
AnswerB

Zone-based firewall uses class-maps to identify traffic and policy-maps to define actions. The policy-map is applied to a zone pair (INSIDE to OUTSIDE) with the service-policy command, so only HTTP is permitted while other traffic is dropped by default.

Why this answer

Zone-based firewall policy is built with class-maps for traffic identification and policy-maps for action. The policy-map is attached to a zone pair, and traffic not explicitly permitted is dropped by default, which matches the requirement to allow only HTTP from INSIDE to OUTSIDE.

Exam trap

The trap here is assuming interface ACLs or route-maps control inter-zone traffic, when zone-based firewall requires class-maps and policy-maps on a zone pair.

20
MCQhard

A campus switch connects to an IP phone that has a PC daisy-chained behind it. The engineer wants the phone to reside in VLAN 100 and the PC in VLAN 200, with the phone tagging its own voice traffic. Which interface configuration accomplishes this?

A.switchport mode access, switchport access vlan 100, switchport voice vlan 200
B.switchport mode access, switchport access vlan 200, switchport trunk encapsulation dot1q
C.switchport mode trunk, switchport trunk native vlan 200, switchport trunk allowed vlan 100,200
D.switchport mode access, switchport access vlan 200, switchport voice vlan 100
AnswerD

An access port with a voice VLAN configured uses Cisco's multi-VLAN access behavior: untagged frames from the attached PC are placed in the access VLAN, while 802.1Q-tagged frames from the phone are placed in the voice VLAN. Setting the access VLAN to 200 and the voice VLAN to 100 satisfies the requirement that the PC sit in VLAN 200 and the phone in VLAN 100.

Why this answer

Cisco's voice VLAN feature allows a single access port to serve two devices in different VLANs. The PC, which sends untagged frames, is placed in the access VLAN, while the IP phone, which tags its traffic with 802.1Q, is placed in the voice VLAN. Setting the access VLAN to 200 for the PC and the voice VLAN to 100 for the phone matches the requirement exactly.

Exam trap

The trap here is believing that a trunk must be configured to support an IP phone, when an access port with a voice VLAN already handles tagged phone traffic and untagged PC traffic.

21
Multi-Selectmedium

A network administrator is configuring a Cisco IOS zone-based firewall (ZBFW) on a router that connects a LAN zone to an Internet zone. The administrator wants to allow outbound HTTP and HTTPS from the LAN to the Internet while blocking all other outbound traffic, and to allow return traffic for established sessions. Which two configuration elements are required to accomplish this? (Choose two.)

Select 2 answers
A.A NAT configuration that translates LAN addresses to the Internet-facing interface address.
B.A parameter map that defines inspection parameters for HTTP and HTTPS.
C.A class map that matches HTTP and HTTPS traffic and a policy map that applies an inspect action.
D.Zone pairs that define the LAN-to-Internet direction and apply the policy map with the service-policy command.
E.An extended ACL applied inbound on the LAN interface to permit HTTP and HTTPS.
AnswersC, D

Zone-based firewall uses class maps to identify traffic and policy maps to apply actions such as inspect. To allow HTTP and HTTPS from LAN to Internet, a class map matching those protocols is required, and the policy map must apply the inspect action so that return traffic is permitted for established sessions.

Why this answer

Zone-based firewall on Cisco IOS requires class maps to identify traffic and policy maps to apply actions like inspect. The policy map must be applied to a zone pair that defines the direction of traffic, in this case LAN to Internet. The inspect action allows return traffic for established sessions, and any traffic not explicitly permitted is implicitly denied by the zone pair policy.

Exam trap

The trap here is assuming that an interface ACL or NAT is part of the zone-based firewall configuration, when ZBFW specifically uses class maps, policy maps, and zone pairs with service-policy.

22
MCQmedium

A network engineer is deploying Control Plane Policing on a Cisco IOS XE router that runs BGP, SSH management, and SNMP monitoring. The engineer must ensure that BGP keepalives are never dropped even during a control-plane flood, while SSH and SNMP traffic should be rate-limited. Which CoPP configuration element accomplishes this requirement?

A.Create a class-map matching BGP traffic with a 'police' action and assign it to the control-plane policy-map.
B.Create a class-map matching BGP traffic and apply a 'police' action with a conform-action of 'transmit' and an exceed-action of 'transmit'.
C.Create a class-map matching BGP traffic and apply a 'police' action with a very high committed information rate (CIR).
D.Create a class-map matching BGP traffic and reference it in the control-plane policy-map without applying any police action.
AnswerD

Classes in a control-plane policy-map that have no police action applied are not rate-limited, so matching BGP traffic and simply referencing it in the policy-map exempts BGP from CoPP policing. The engineer can then apply 'police' actions to SSH and SNMP classes. This satisfies the requirement that BGP keepalives are never dropped while still rate-limiting other control-plane traffic.

Why this answer

CoPP works by classifying control-plane traffic and applying actions, most commonly 'police'. Any class that has no police action is effectively passed without rate limiting, which is exactly what is needed for BGP keepalives that must never be dropped. SSH and SNMP classes can then receive 'police' actions with appropriate conform/exceed handling.

This design isolates critical routing protocol traffic from the effects of a control-plane flood.

Exam trap

The trap here is assuming that every class in a CoPP policy-map must have a police action, when in fact a class without a police action passes traffic unconditionally.

23
MCQeasy

Refer to the exhibit. A network administrator notices that some DHCP packets are being dropped due to 'MAC Address Mismatch'. What is the most likely cause of this drop?

A.The DHCP server is sending packets with an incorrect server identifier option.
B.The DHCP client is using a different MAC address in the DHCP packet than the source MAC in the Ethernet frame.
C.The DHCP client is sending a request with an incorrect transaction ID.
D.The DHCP offer packet is arriving on an untrusted port.
AnswerB

This is the correct cause. DHCP snooping compares the source MAC address in the Ethernet frame header with the 'chaddr' field inside the DHCP packet itself. When the DHCP client inserts a different MAC address in the chaddr field than the actual source MAC of the frame, the switch flags this as a potential spoofing attempt and drops the packet, incrementing the 'MAC address mismatch' counter. This check prevents a client from impersonating another device's MAC address in DHCP requests.

Why this answer

The DHCP snooping feature on a switch compares the source MAC address in the Ethernet frame with the chaddr (client hardware address) field inside the DHCP packet. When a DHCP client sends a packet with a different MAC in the frame than in the chaddr field, the switch considers it a 'MAC Address Mismatch' and drops the packet. This security mechanism prevents a rogue client from spoofing another device's MAC address to obtain a lease.

Exam trap

Cisco often tests the distinction between Layer 2 MAC checks (frame vs. chaddr) and Layer 3 or application-layer checks (server identifier, transaction ID), leading candidates to confuse DHCP snooping drops with client-side validation failures.

How to eliminate wrong answers

Option A is wrong because the DHCP server identifier option (option 54) is used by clients to identify which server to respond to, and an incorrect server identifier would cause a client to ignore the offer, not a switch to drop the packet due to MAC mismatch. Option B is correct as described. Option C is wrong because an incorrect transaction ID (XID) would cause the DHCP client to ignore the server's reply, but the switch does not check the XID for MAC mismatch drops; the XID mismatch is a client-side validation issue.

Option D is wrong because an untrusted port is a DHCP snooping concept where the switch drops DHCP server messages (OFFER, ACK, etc.) received on that port, not client messages, and the 'MAC Address Mismatch' check applies to client messages on untrusted ports as well, but the specific cause described is the mismatch between frame MAC and chaddr.

24
MCQeasy

A network administrator needs to secure management access to a Cisco IOS XE switch. The requirement is that only SSH version 2 with a 2048-bit RSA key be accepted, that Telnet be disabled, and that only the 'netadmin' user with privilege level 15 be allowed to log in via VTY lines 0 through 4. Which configuration accomplishes this?

A.crypto key generate rsa modulus 2048; ip ssh version 2; line vty 0 4; transport input ssh; login local; username netadmin privilege 15 secret <password>
B.crypto key generate rsa modulus 2048; ip ssh version 1; line vty 0 4; transport input ssh; login local; username netadmin privilege 15 secret <password>
C.crypto key generate rsa modulus 2048; ip ssh version 2; line vty 0 4; transport input ssh; login local; username netadmin privilege 1 secret <password>
D.crypto key generate rsa modulus 1024; ip ssh version 2; line vty 0 4; transport input telnet ssh; login local; username netadmin privilege 15 secret <password>
AnswerA

This sequence generates a 2048-bit RSA key, restricts SSH to version 2, disables Telnet by allowing only SSH transport on the VTY lines, and enforces local authentication with a privilege 15 user. All three requirements—SSHv2, no Telnet, and netadmin-only access—are satisfied by this configuration.

Why this answer

The correct configuration generates a 2048-bit RSA key, forces SSH version 2, restricts VTY transport to SSH only (disabling Telnet), and uses local authentication with the netadmin user at privilege 15. Alternatives fail because they use a weak key size, allow Telnet, force SSHv1, or assign the wrong privilege level, each violating at least one stated requirement.

Exam trap

The trap here is overlooking one of the three simultaneous conditions—key size, SSH version, or privilege level—and selecting a configuration that only partially satisfies the policy.

25
Drag & Dropmedium

Drag and drop the steps to configure port security on a Cisco switch in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Port security limits unauthorized MAC addresses; violation mode defines action on violation.

26
MCQeasy

A network engineer needs to provide secure remote-access VPN connectivity for employees using Cisco AnyConnect. The requirement is to use digital certificates issued by the corporate PKI for both server and client authentication. Which component must be configured on the Cisco ASA to validate client certificates presented during the VPN session?

A.A trustpoint containing the CA certificate that signed the client certificates.
B.A local user account with the privilege level 15 assigned.
C.An IKEv2 pre-shared key configured under the tunnel group.
D.An LDAP attribute map for group policy assignment.
AnswerA

To validate client certificates, the ASA must trust the issuing CA. A trustpoint holds the CA certificate and enables the ASA to verify the certificate chain presented by AnyConnect clients. Without this trustpoint, the ASA cannot confirm the client certificate is genuine, so it is the required configuration for certificate-based client authentication.

Why this answer

Certificate-based client authentication requires the ASA to trust the CA that issued the client certificates. Configuring a trustpoint with the CA certificate allows the ASA to validate the chain presented by AnyConnect. Pre-shared keys, local user accounts, and LDAP attribute maps do not perform certificate validation and therefore cannot fulfill the PKI-based authentication requirement.

Exam trap

The trap here is assuming any authentication configuration, such as a local user or LDAP map, will validate certificates, when only a trustpoint containing the issuing CA certificate enables certificate chain validation.

27
MCQhard

A security team wants to deploy MACsec on a Cisco Catalyst switch uplink between two buildings to protect Layer 2 traffic. The switches are Cisco Catalyst 9300 series running IOS XE, and the link must encrypt all frames between them. Which statement accurately describes a requirement for this deployment?

A.MACsec can only be enabled on routed ports, so the uplink must be converted from a switchport to a no switchport interface.
B.MACsec requires that both switches support the MACsec feature and that a connectivity association key be configured or negotiated before encrypted traffic can flow.
C.MACsec encrypts only control plane traffic, so data frames between the switches would remain in clear text.
D.MACsec requires that 802.1X authentication be completed on the link before any encryption keys can be generated.
AnswerB

MACsec uses a secure connectivity association defined by a connectivity association key (CAK) and connectivity association key name (CKN), either pre-shared or negotiated via MKA. Both endpoints must support MACsec and agree on keys before encrypted frames can be exchanged. This matches the requirement to protect all Layer 2 traffic on the uplink between the two Catalyst switches.

Why this answer

MACsec secures Layer 2 links by encrypting frames using keys derived from a connectivity association. Both endpoints must support MACsec and share matching key material, either pre-shared or via MKA. This allows the uplink between the Catalyst switches to carry encrypted traffic, meeting the requirement to protect all frames on that link.

Exam trap

The trap here is believing MACsec requires 802.1X or routed ports, when in fact it needs matching key material and MACsec-capable endpoints on the Layer 2 link.

28
Multi-Selectmedium

Which TWO of the following are valid methods to mitigate VLAN hopping attacks?

Select 2 answers
A.Configure switchport mode dynamic auto on all ports.
B.Disable Dynamic Trunking Protocol (DTP) on all access ports.
C.Set the native VLAN to VLAN 1 on all trunk ports.
D.Set the native VLAN to an unused VLAN ID on all trunk ports.
E.Use 802.1Q trunking instead of ISL.
AnswersB, D

Prevents trunk negotiation.

Why this answer

Disabling Dynamic Trunking Protocol (DTP) on all access ports prevents a switch port from automatically negotiating a trunk, which is the primary vector for VLAN hopping attacks. An attacker can spoof DTP messages to force a port into trunking mode, gaining access to multiple VLANs; disabling DTP eliminates this risk.

Exam trap

Cisco often tests the misconception that simply using 802.1Q trunking (Option E) or setting the native VLAN to VLAN 1 (Option C) provides security, when in fact the key mitigations are disabling DTP on access ports and using an unused native VLAN on trunk ports.

29
Multi-Selecthard

A network engineer is hardening a Cisco IOS XE router that terminates IPsec site-to-site tunnels with remote branches. The security policy requires that the router only accept IKEv2 negotiations using cryptographically strong parameters and that it validate peer identity via certificates issued by the corporate PKI. Which two configuration elements must the engineer apply to meet these requirements? (Choose two.)

Select 2 answers
A.Configure 'crypto ikev2 limit max-in-negotiation-sa 10' on the router to throttle aggressive IKEv2 negotiations.
B.Configure an IKEv2 proposal that includes aes-cbc-256 for encryption, sha512 for integrity, and group 19 for the DH key exchange.
C.Configure 'crypto ikev2 dpd 10 3 periodic' to detect dead peers and tear down stale SAs quickly.
D.Configure an IKEv2 keyring with pre-shared keys per peer and bind the keyring to the IKEv2 profile.
E.Configure an IKEv2 profile with 'authentication local rsa-sig' and 'authentication remote rsa-sig', and reference a PKI trustpoint that validates the corporate CA chain.
AnswersB, E

An IKEv2 proposal with aes-cbc-256, sha512, and DH group 19 (256-bit ECP) enforces cryptographically strong negotiation parameters. Only peers offering these algorithms can complete IKEv2 SA establishment, satisfying the strong-parameters half of the policy without weakening backward compatibility beyond the stated requirement.

Why this answer

Meeting the policy requires two things: an IKEv2 proposal that enforces strong encryption, integrity, and DH groups, and an IKEv2 profile that authenticates both local and remote peers with RSA signatures validated against the corporate PKI trustpoint. PSK keyrings, DPD timers, and SA throttling controls address other concerns and do not satisfy the cryptographic-strength or certificate-validation requirements.

Exam trap

The trap here is treating any IKEv2 hardening knob, such as DPD or SA limits, as equivalent to enforcing strong algorithms and certificate-based authentication.

30
MCQmedium

A network administrator is deploying Cisco TrustSec in a campus network. The security team wants to enforce role-based access control between endpoints without relying on IP addresses or VLANs, and they need to ensure that access policies are consistently applied even when endpoints move between switches. The administrator has already configured Cisco ISE for authentication and authorization. Which technology should be used to propagate the security group tag (SGT) information to network devices that do not support SGT tagging natively?

A.MACsec (802.1AE)
B.IPsec VPN tunnels
C.SXP (SGT Exchange Protocol)
D.802.1X with EAP-TLS
AnswerC

SXP is a Cisco TrustSec protocol that propagates SGT-to-IP mappings to network devices that cannot natively tag packets with SGTs. It allows enforcement of security group ACLs (SGACLs) on devices that lack hardware SGT support by exchanging IP-to-SGT bindings with peer devices. This enables consistent policy enforcement across mixed hardware, which matches the scenario's requirement for propagation to non-SGT-capable devices.

Why this answer

SXP is designed to share SGT-to-IP bindings with devices that cannot natively tag packets with SGTs, enabling consistent role-based access control across mixed hardware. The other options either provide encryption, authentication, or tunneling but do not propagate SGT information. In a Cisco TrustSec deployment where some switches lack hardware SGT support, SXP bridges the gap so that SGACLs can still be enforced based on the endpoint's security group.

Exam trap

The trap here is confusing SGT propagation with SGT enforcement or authentication, assuming that any security feature can carry SGT information when only SXP is designed for that purpose.

31
MCQmedium

A network engineer must protect the OSPF adjacency between two Cisco routers from spoofed hello packets injected by a rogue device on the same broadcast segment. The engineer wants to use a cryptographic authentication method that is natively supported by OSPFv2 and does not rely on plain-text key exchange. Which configuration should be applied to the interfaces?

A.ip ospf authentication-key <key>
B.ip ospf authentication key-chain <name>
C.ip ospf authentication message-digest and ip ospf message-digest-key 1 md5 <key>
D.ip ospf authentication null
AnswerC

OSPFv2 message-digest authentication uses MD5 to hash the key and packet contents, so the key is never sent in cleartext. Configuring ip ospf authentication message-digest enables cryptographic authentication on the interface, and ip ospf message-digest-key 1 md5 supplies the key material. Neighbors must share the same key ID and key string for the adjacency to form, which satisfies the requirement to protect against spoofed hellos.

Why this answer

OSPFv2 supports two authentication types: simple password and message-digest (MD5). Only message-digest provides cryptographic protection, because it hashes the packet with a shared key rather than transmitting the key. Enabling ip ospf authentication message-digest on the interface plus defining ip ospf message-digest-key with an MD5 key ensures hellos are authenticated and spoofed packets from a rogue host are rejected before the adjacency can be affected.

Exam trap

The trap here is assuming that any OSPF authentication command provides cryptographic protection, when simple password authentication transmits the key in cleartext and offers no real defense.

32
MCQmedium

A network administrator is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router that peers BGP with two ISPs and is managed over SSH. The administrator needs to protect the route processor from excessive BGP and SSH traffic without breaking the existing sessions. Which action should be taken when applying the CoPP policy?

A.Apply the policy-map to the control-plane interface using the service-policy input command.
B.Apply the policy-map to the management VRF interface using service-policy input.
C.Apply the policy-map globally with the service-policy command in global configuration mode.
D.Apply the policy-map to each ISP-facing physical interface with service-policy output.
AnswerA

CoPP policies are applied to the control plane by attaching the policy-map to the control-plane interface with service-policy input. This filters traffic destined to the route processor while allowing transit traffic to pass untouched, which preserves the BGP and SSH sessions.

Why this answer

CoPP is designed to classify and police traffic destined to the route processor. The policy-map must be attached to the control-plane interface with service-policy input so that only CPU-bound traffic is policed while transit traffic remains unaffected, preserving BGP peering and SSH management access.

Exam trap

The trap here is assuming CoPP is applied to physical interfaces like a normal QoS policy, when it must be attached to the control-plane interface.

33
MCQmedium

A network administrator is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router that runs BGP, SSH, and SNMP. The administrator needs to verify which traffic classes are being matched and how many packets are being dropped by the policy. Which command should be used to display the CoPP policy statistics and class-map information?

A.show policy-map interface
B.show class-map
C.show policy-map control-plane
D.show control-plane host open-ports
AnswerC

This command displays the Control Plane policy-map configuration and the per-class packet statistics, including matched and dropped packets. It directly shows which traffic classes are being matched and how many packets are being dropped, which is exactly what the administrator needs to verify CoPP operation.

Why this answer

The show policy-map control-plane command is specifically designed to display the CoPP policy configuration and per-class statistics, including matched and dropped packets. It allows the administrator to verify which traffic classes are being matched and how many packets are being dropped by the policy. The other commands either show only class-map definitions or interface-level policy statistics, which are not relevant to the control plane.

Exam trap

The trap here is confusing interface-level policy statistics with control plane policy statistics, or assuming that show class-map displays counters when it only shows match criteria.

34
Multi-Selectmedium

A network engineer is implementing IPsec VPN on a Cisco IOS XE router to connect a branch office to headquarters. The engineer must ensure that the IKEv2 negotiation uses strong authentication and that the data plane is protected with integrity and encryption. Which two configuration elements are required to achieve this? (Choose two.)

Select 2 answers
A.Configure an IKEv2 keyring or PKI trustpoint to authenticate the peers.
B.Configure 'crypto isakmp policy' with pre-shared key authentication for IKEv1.
C.Configure an IPsec transform set specifying ESP encryption and authentication algorithms.
D.Configure 'crypto ipsec profile' with 'set security-association lifetime seconds 3600' only.
E.Configure a crypto ACL with 'permit ip any any' to match all traffic.
AnswersA, C

IKEv2 requires peer authentication before establishing the IPsec SA. A keyring with pre-shared keys or a PKI trustpoint with certificates provides that authentication. Without it, IKEv2 negotiation fails. This element is mandatory for strong authentication and directly supports the requirement. It is separate from the IPsec transform set, which protects the data plane, so both are needed in the overall configuration.

Why this answer

IKEv2 requires peer authentication, provided by a keyring with pre-shared keys or a PKI trustpoint. The data plane is protected by an IPsec transform set that specifies ESP encryption and authentication algorithms. Both elements must be configured and referenced correctly in the IPsec profile or crypto map.

The other options either apply to IKEv1 or do not provide the required security functions.

Exam trap

The trap here is confusing IKEv1 and IKEv2 configuration syntax, and assuming a crypto ACL or lifetime setting alone can provide authentication and encryption.

35
MCQhard

A network administrator is configuring IPsec VPN on a Cisco IOS router. The requirement is that the tunnel must support multicast traffic for OSPF neighbor adjacency across the VPN. Which IPsec configuration element is required to meet this requirement?

A.Use a dynamic VTI with IKEv1.
B.Use transport mode instead of tunnel mode.
C.Configure GRE over IPsec.
D.Enable IKEv2 with MOBIKE.
AnswerC

GRE tunnels can carry multicast traffic, and when combined with IPsec, the GRE packets are encrypted. This allows OSPF to form neighbor adjacencies over the tunnel because OSPF uses multicast (224.0.0.5/224.0.0.6). Native IPsec cannot carry multicast, so GRE over IPsec is the standard solution for dynamic routing protocols requiring multicast over a VPN.

Why this answer

IPsec security associations are inherently unicast and cannot carry multicast or broadcast traffic. To support OSPF, which relies on multicast hellos, the design must encapsulate multicast inside a GRE tunnel and then protect that GRE tunnel with IPsec. This is commonly called GRE over IPsec or IPsec profile applied to a GRE tunnel interface.

Exam trap

The trap here is believing that IPsec itself can carry multicast, when in fact IPsec SAs are point-to-point unicast and require GRE encapsulation for multicast support.

36
Multi-Selectmedium

A network engineer is hardening a Cisco IOS XE router against control plane attacks. The router runs OSPF, BGP, and SSH management. The engineer wants to apply Control Plane Policing (CoPP) to rate-limit nonessential traffic while ensuring routing protocols are not disrupted. Which two actions should the engineer take? (Choose two.)

Select 2 answers
A.Configure a single class map that matches all IP traffic and police it to a low rate to simplify the policy.
B.Use a route map to classify traffic and attach it to the control plane with the service-policy command.
C.Create class maps that match routing protocol traffic, such as OSPF and BGP, and assign them a higher policing rate than nonessential traffic.
D.Apply the CoPP policy map under control-plane configuration mode using the service-policy command.
E.Apply the CoPP policy map inbound on all WAN interfaces to filter traffic before it reaches the route processor.
AnswersC, D

Routing protocols are essential for network stability, so they should be matched in dedicated class maps and given sufficient policing rates to avoid dropping legitimate updates. This allows CoPP to protect the CPU while preventing disruption to OSPF and BGP adjacencies, which is a key requirement in the scenario.

Why this answer

Effective CoPP requires class maps that separate essential traffic, such as OSPF and BGP, from nonessential traffic, with appropriate policing rates for each. The policy map is then applied under control-plane configuration mode. This structure protects the route processor without disrupting routing protocols or management access.

Exam trap

The trap here is applying CoPP to data interfaces or using a single blanket policer, which would either miss CPU-bound traffic or throttle essential routing and management protocols.

37
MCQmedium

A network engineer is deploying Control Plane Policing on a Cisco IOS XE router that carries eBGP, OSPF, SSH management, and SNMP traffic. The engineer wants to ensure that BGP and OSPF routing updates are never dropped while still rate-limiting SSH and SNMP. Which CoPP configuration approach best meets this requirement?

A.Apply a single class-map matching all control-plane traffic and set a single police rate that is high enough for routing protocols.
B.Create separate class-maps for BGP, OSPF, SSH, and SNMP, then apply a policy-map where routing classes use police with a high conform rate and management classes use a lower police rate.
C.Use MQC with a single class-default and configure a priority queue for BGP and OSPF packets.
D.Configure an ACL that denies SSH and SNMP to the control plane and apply it inbound on all interfaces.
AnswerB

Separate class-maps allow granular classification, and the policy-map can apply different police actions per class. Routing classes can be policed generously (or with conform-action transmit and exceed-action transmit for critical control traffic), while SSH and SNMP are rate-limited. This is the standard CoPP design pattern for differentiated control-plane protection.

Why this answer

CoPP is designed to classify control-plane traffic into distinct classes and apply independent policers. Separating routing protocols from management protocols allows the engineer to protect BGP and OSPF adjacencies while still enforcing limits on SSH and SNMP. A single class-map or class-default cannot provide this granularity, and an ACL would block rather than rate-limit management traffic.

Exam trap

The trap here is assuming that a single high-rate policer can protect all control-plane traffic without distinguishing routing protocols from management protocols.

38
MCQmedium

A network engineer configures a Cisco IOS router to authenticate administrative SSH logins against a Cisco ISE server using TACACS+. After applying the configuration, a valid ISE user can log in but receives no privilege level and cannot enter privileged EXEC mode. The relevant configuration is: aaa new-model aaa authentication login default group tacacs+ local aaa authorization exec default group tacacs+ local tacacs server ISE address ipv4 10.10.10.50 key Cisco123 Which action most directly resolves the problem?

A.Enable AAA accounting with the aaa accounting exec default start-stop group tacacs+ command so ISE records the session.
B.Configure the ISE TACACS+ device to return the cisco-av-pair shell:priv-lvl=15 attribute for authorized users.
C.Add the aaa authorization commands 15 default group tacacs+ local command to the router.
D.Change the aaa authentication login method list to use the local database before the tacacs+ group.
AnswerB

TACACS+ authorization for EXEC sessions relies on AV pairs returned by the server. The cisco-av-pair shell:priv-lvl attribute tells the router which privilege level the user receives after authentication. Without it, the AAA client defaults to privilege level 1, so the user cannot enter privileged EXEC mode. Supplying the AV pair in the ISE authorization policy resolves the symptom directly.

Why this answer

Successful TACACS+ authentication only proves the user's identity; the privilege level comes from authorization AV pairs. Because the router shows the user authenticated but stuck at unprivileged EXEC, the ISE authorization policy must be returning no shell:priv-lvl value. Adding the cisco-av-pair shell:priv-lvl=15 attribute to the matching authorization rule gives the router the privilege level to apply after login.

Exam trap

The trap here is assuming that successful TACACS+ authentication automatically carries a privilege level, when privilege assignment actually depends on authorization AV pairs returned by the server.

39
MCQeasy

A network administrator needs to secure management access to a Cisco IOS XE switch. The requirement is to ensure that only SSH version 2 is used for remote CLI access, and that Telnet is disabled. Which configuration achieves this?

A.Configure 'transport input telnet ssh' on the VTY lines and set 'ip ssh version 2' globally.
B.Configure 'transport output ssh' on the VTY lines and set 'ip ssh version 1' globally.
C.Configure 'transport input ssh' on the VTY lines and set 'ip ssh version 2' globally.
D.Configure 'line vty 0 4' with 'login local' and 'password cisco', then set 'ip ssh version 2' globally.
AnswerC

The 'transport input ssh' command on the VTY lines restricts remote CLI access to SSH only, effectively disabling Telnet. Setting 'ip ssh version 2' globally forces the device to use only SSH version 2. Together, these commands meet the requirement to allow only SSHv2 and block Telnet, which is the standard hardening practice for management access.

Why this answer

Restricting VTY access to SSH with 'transport input ssh' and forcing SSH version 2 with 'ip ssh version 2' ensures that only secure SSHv2 sessions are accepted. This combination disables Telnet and prevents fallback to the weaker SSH version 1, satisfying the management access hardening requirement.

Exam trap

The trap here is assuming that setting 'ip ssh version 2' alone disables Telnet, when the VTY transport input must also be restricted to SSH.

40
MCQmedium

A network administrator is deploying a Cisco Wireless LAN Controller (WLC) running AireOS in a branch office. The security policy requires that guest wireless clients be isolated from internal corporate clients and that guest traffic be tunneled back to a DMZ interface on the WLC. Which WLAN configuration element should the administrator use to meet these requirements?

A.Configure the guest WLAN with AP group VLAN tagging and enable FlexConnect local switching.
B.Configure the guest WLAN to use the management interface with a separate SSID.
C.Configure the guest WLAN to use the virtual interface and enable Web Auth.
D.Configure a dynamic interface mapped to the guest VLAN and assign it to the guest WLAN.
AnswerD

A dynamic interface on the AireOS WLC is a user-defined VLAN interface that maps a WLAN to a specific VLAN and is commonly placed on a DMZ segment for guest traffic. Assigning the guest WLAN to a dynamic interface isolates guest clients from corporate clients on the management interface and allows traffic to be tunneled to a firewall in the DMZ.

Why this answer

Guest wireless traffic on an AireOS WLC is isolated and tunneled by mapping the guest WLAN to a dynamic interface whose VLAN resides in a DMZ. The dynamic interface defines the VLAN and IP subnet for that WLAN, and the WLC forwards guest client traffic through that interface rather than the management interface. This design keeps guest clients off corporate VLANs and allows a firewall to enforce policy in the DMZ.

Exam trap

The trap here is assuming that creating a separate SSID or enabling Web Auth automatically isolates guest traffic, when the actual isolation comes from mapping the WLAN to a dedicated dynamic interface on a DMZ VLAN.

41
MCQhard

A network engineer is deploying 802.1X on a Cisco switch with Cisco ISE as the RADIUS server. The engineer wants to allow devices that do not support 802.1X supplicant to connect to a guest VLAN. Which feature should be configured on the switch port to accomplish this?

A.Enable MAB (MAC Authentication Bypass) on the port.
B.Configure the port as a trunk port with native VLAN set to the guest VLAN.
C.Set the port to force-authorized mode.
D.Configure the port as a multi-auth port with an authentication open mode.
AnswerA

MAB allows devices that do not support 802.1X to authenticate using their MAC address. When MAB is enabled, the switch sends the device's MAC address to the RADIUS server (ISE) as username and password. If the MAC address is known, the device can be authorized and assigned to a VLAN, such as a guest VLAN. This is the standard method to support non-supplicant devices.

Why this answer

MAC Authentication Bypass (MAB) enables non-802.1X devices to authenticate using their MAC address. The switch sends the MAC to ISE, which can authorize the device and assign it to a guest VLAN via RADIUS attributes. This allows devices like printers or legacy IP phones to gain network access without supplicant software, while still enforcing policy.

Exam trap

The trap here is thinking that multi-auth or open mode automatically handles non-supplicant devices; MAB is specifically designed for MAC-based authentication of such devices.

42
Multi-Selecthard

A security team is hardening a Cisco IOS router that terminates IPsec site-to-site tunnels to several branch offices. The team wants to protect the control plane by rate-limiting and filtering traffic destined to the router's own CPU. Which two mechanisms are designed specifically for control plane protection on Cisco IOS? (Choose two.)

Select 2 answers
A.Control Plane Policing (CoPP)
B.MACsec on the WAN interface
C.Zone-Based Policy Firewall (ZBFW)
D.Control Plane Protection (CPPr)
E.IPsec DMVPN with IKEv2
AnswersA, D

CoPP uses a modular QoS CLI policy attached to the control-plane interface to rate-limit and classify traffic destined to the route processor. It allows the engineer to define class maps for protocols such as IKE, SSH, and SNMP, then apply policing actions so that a flood of tunnel negotiation packets cannot exhaust CPU resources. This directly addresses the hardening goal for the IPsec headend by protecting the control plane from abusive traffic.

Why this answer

Control plane protection on Cisco IOS is provided by CoPP, which uses MQC policies on the control-plane interface, and CPPr, which adds subinterface granularity for host, transit, and CEF-exception traffic. Both are purpose-built to classify and rate-limit traffic destined to the route processor. Data plane mechanisms such as MACsec and ZBFW, and tunneling architectures such as DMVPN, do not protect the CPU from control plane floods.

Exam trap

The trap here is confusing data plane security features like MACsec and ZBFW with control plane protection mechanisms, even though only CoPP and CPPr police traffic destined to the route processor.

43
MCQmedium

A network administrator is configuring a site-to-site IPsec VPN between two Cisco IOS routers. The requirement is that the VPN must support dynamic routing protocol updates across the tunnel and allow multicast traffic between the sites. Which IPsec configuration mode should be used?

A.IPsec tunnel mode with a crypto map applied to the physical interface
B.GRE over IPsec using a tunnel interface protected by IPsec
C.IPsec transport mode with an access list matching only protocol 47
D.DMVPN phase 1 with only mGRE and no IPsec protection
AnswerB

A GRE tunnel interface can carry unicast, multicast, and broadcast traffic, which allows dynamic routing protocols such as OSPF or EIGRP to form adjacencies and exchange updates. Wrapping the GRE tunnel in IPsec protects the traffic. This combination meets both the routing and multicast requirements that plain IPsec tunnel mode cannot satisfy.

Why this answer

GRE over IPsec creates a virtual tunnel interface that supports multicast and broadcast, enabling dynamic routing protocols to run across the VPN. IPsec then protects the GRE-encapsulated packets. This design satisfies both the routing update and multicast requirements that standard IPsec tunnel mode with a crypto map cannot deliver.

Exam trap

The trap here is assuming plain IPsec tunnel mode carries multicast and routing protocols, which it does not without GRE or another encapsulation.

44
MCQhard

A network security engineer is configuring an IPsec site-to-site VPN between two Cisco IOS routers. The engineer wants to ensure that the VPN tunnel uses perfect forward secrecy (PFS) and that the encryption is AES-256. Which combination of commands achieves this?

A.crypto ipsec transform-set TS esp-aes 256 esp-sha256-hmac, then crypto map CM 10 ipsec-isakmp without set pfs
B.crypto ipsec transform-set TS esp-aes 256 esp-sha256-hmac, then crypto map CM 10 ipsec-isakmp with set pfs group5
C.crypto ipsec transform-set TS esp-aes 256 esp-sha256-hmac, then crypto map CM 10 ipsec-isakmp with set pfs group14
D.crypto ipsec transform-set TS esp-3des esp-md5-hmac, then crypto map CM 10 ipsec-isakmp with set pfs group2
AnswerC

The transform-set with esp-aes 256 and esp-sha256-hmac specifies AES-256 encryption and SHA-256 HMAC for integrity. The set pfs group14 command in the crypto map enables perfect forward secrecy using Diffie-Hellman group 14 (2048-bit). This combination meets both requirements: AES-256 encryption and PFS. The transform-set and crypto map together define the IPsec policy for the tunnel.

Why this answer

To achieve AES-256 encryption and perfect forward secrecy, the transform-set must specify esp-aes 256 and esp-sha256-hmac, and the crypto map must include set pfs with a strong Diffie-Hellman group such as group14. This ensures that each new IPsec SA uses a unique key derived from a fresh Diffie-Hellman exchange, providing forward secrecy. The combination of these commands meets the security requirements.

Exam trap

The trap here is either forgetting to enable PFS or selecting a weak Diffie-Hellman group, which would not satisfy the requirement for perfect forward secrecy with strong encryption.

45
Multi-Selecthard

A network administrator is configuring MACsec on a Cisco Catalyst switch to secure Layer 2 traffic between two switches. Which two statements about MACsec are true? (Choose two.)

Select 2 answers
A.MACsec requires IPsec to establish the secure channel.
B.MACsec encrypts the entire Ethernet frame including the source and destination MAC addresses.
C.MACsec provides end-to-end encryption between any two hosts in a campus network.
D.MACsec provides encryption and integrity for Ethernet frames at Layer 2.
E.MACsec can be deployed with Cisco TrustSec to provide encryption on switch-to-switch links.
AnswersD, E

MACsec (802.1AE) provides hop-by-hop encryption and integrity check for Ethernet frames. It encrypts the payload and adds an integrity check value (ICV) to detect tampering. This is correct: it operates at Layer 2 and secures the data link between two directly connected devices.

Why this answer

MACsec (802.1AE) provides Layer 2 encryption and integrity for Ethernet frames, and it is commonly deployed with Cisco TrustSec for switch-to-switch links. It uses MKA for key agreement, not IPsec. It does not encrypt MAC addresses, and it is hop-by-hop rather than end-to-end.

Exam trap

The trap here is assuming MACsec provides end-to-end encryption or that it relies on IPsec, when it is actually a hop-by-hop Layer 2 technology using MKA.

46
Multi-Selecthard

A network security team is implementing Cisco TrustSec in a campus network. They need to deploy Security Group Tags (SGTs) and enforce policies using Security Group ACLs (SGACLs). Which two statements are true regarding SGT propagation and enforcement in this environment? (Choose two.)

Select 2 answers
A.SGT Exchange Protocol (SXP) is used to propagate SGTs to devices that do not support hardware-based tagging.
B.SXP requires the use of IPsec for secure communication between peers.
C.SGTs can be propagated inline within the Ethernet frame using Cisco Metadata (CMD) on supported hardware.
D.SGACLs are enforced only on the ingress interface where the SGT is assigned.
E.SGTs are always carried in the IP header using the DSCP field.
AnswersA, C

SXP is a control-plane protocol that maps IP addresses to SGTs and is used to propagate SGT information to devices that cannot perform inline tagging, such as older switches or routers. It allows these devices to enforce SGACLs based on the SGT mapping. This is a key component of TrustSec for mixed environments.

Why this answer

SGTs can be propagated inline using Cisco Metadata on supported hardware, and SXP is used for devices that cannot do inline tagging. These two methods allow flexible deployment in mixed environments. SGACLs can be enforced at various points, not just ingress, and SGTs are not carried in DSCP.

SXP does not mandate IPsec.

Exam trap

The trap here is assuming SGTs are carried in the IP header or that enforcement is limited to ingress, while the actual mechanisms are inline tagging and SXP with enforcement at multiple points.

47
MCQhard

A security architect is designing a Cisco TrustSec deployment for a campus network. The architect needs to ensure that security group tags (SGTs) are propagated across a Layer 2 trunk between two Catalyst switches that do not support SGACL enforcement. Which technology should be used to carry SGT information inline within the Ethernet frame?

A.MACsec
B.SXP
C.802.1Q tunneling (QinQ)
D.Cisco Meta Data (CMD)
AnswerD

Cisco Meta Data (CMD) is the inline tagging method that embeds the SGT directly into the Ethernet frame using a special EtherType. It allows SGT propagation across Layer 2 trunks without requiring SGACL enforcement on every switch. This is the correct technology for carrying SGT information inline in the frame, enabling TrustSec propagation across the campus.

Why this answer

Cisco Meta Data (CMD) is the inline tagging mechanism in Cisco TrustSec that inserts the SGT into the Ethernet frame. It enables SGT propagation across switches that may not enforce SGACLs, allowing downstream devices to apply policies. This satisfies the requirement for inline SGT carriage over a Layer 2 trunk.

Exam trap

The trap here is confusing SXP with inline tagging; SXP exchanges SGT bindings out-of-band, while CMD embeds the tag directly in the frame.

48
MCQeasy

A network administrator must secure management access to a Cisco IOS XE router so that only SSH version 2 is accepted and Telnet is disabled on all VTY lines. Which configuration accomplishes this requirement?

A.Configure line vty 0 4 with the exec-timeout command and set the SSH version to 2.
B.Configure transport input ssh on the VTY lines and set the SSH version to 2 globally.
C.Configure transport input telnet ssh on the VTY lines and set the SSH version to 2.
D.Configure transport output ssh on the VTY lines and set the SSH version to 2.
AnswerB

The transport input ssh command on the VTY lines restricts inbound management sessions to SSH, effectively disabling Telnet. Setting the SSH version to 2 with ip ssh version 2 ensures only the stronger protocol version is negotiated. Together these commands satisfy the requirement to allow only SSHv2 and block Telnet.

Why this answer

Restricting management to SSH requires the transport input ssh command applied to the VTY lines, which removes Telnet as an accepted transport. Enforcing SSH version 2 with ip ssh version 2 ensures the stronger protocol is used. Together they block Telnet and guarantee only SSHv2 sessions are accepted on the router.

Exam trap

The trap here is confusing transport input with transport output; only transport input controls which protocols may connect inbound to the VTY lines.

49
Multi-Selecthard

A network engineer is implementing Control Plane Policing (CoPP) on a Cisco ASR 1000 router to protect the route processor from excessive traffic. The router runs OSPF, BGP, SSH management, and NTP. The engineer wants to ensure that OSPF hello packets are always prioritized and that SSH traffic from the management subnet is rate-limited. Which two statements about the CoPP configuration are true? (Choose two.)

Select 2 answers
A.CoPP is applied to individual data plane interfaces using the 'service-policy input' command on each physical interface.
B.CoPP uses a modular QoS CLI policy map applied globally with the 'service-policy' command under control-plane configuration mode.
C.The default CoPP policy that ships with Cisco IOS XE already rate-limits SSH and OSPF traffic without any custom configuration.
D.CoPP policies can differentiate OSPF and SSH traffic by using ACLs referenced in class maps to match specific protocols and source addresses.
E.CoPP can only police traffic; it cannot mark or prioritize specific control plane protocols such as OSPF.
AnswersB, D

CoPP is implemented using MQC constructs where a class map matches control plane traffic and a policy map defines policing actions. The policy map is then applied under the control-plane configuration mode using the service-policy command, which directs the policy to the route processor's traffic rather than to data plane interfaces.

Why this answer

CoPP uses MQC class maps and policy maps applied under control-plane configuration mode. Class maps reference ACLs to distinguish protocols like OSPF and SSH, allowing differentiated policing and prioritization actions. Applying the policy to physical interfaces or assuming default policies meet custom requirements are common misconceptions.

Exam trap

The trap here is confusing CoPP with interface-level QoS by assuming the service-policy is applied to data plane interfaces rather than the control plane.

50
MCQmedium

A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router. The router has management SSH access, SNMP monitoring, and BGP peering. After applying the CoPP policy shown in the exhibit, the engineer notices that SNMP polling from the management station fails, while SSH and BGP remain operational. Which action should be taken to restore SNMP polling while maintaining control plane protection?

A.Increase the policer rate for the default class to allow all unmatched traffic, including SNMP.
B.Remove the CoPP policy from the control plane and reapply it after verifying SNMP connectivity.
C.Configure an ACL to permit SNMP traffic and apply it to the management interface instead of the control plane.
D.Add a class-map that matches SNMP traffic (UDP port 161) and include it in the CoPP policy with an appropriate policer rate.
AnswerD

The CoPP policy likely does not have a class-map for SNMP, so SNMP packets fall into the default class and may be dropped by the default policer. Adding a specific class-map for SNMP (UDP 161) with a suitable policer ensures SNMP traffic is permitted at the required rate while still protecting the control plane from excessive SNMP traffic.

Why this answer

CoPP policies must explicitly classify and police all desired control plane traffic. If SNMP is not classified, it falls into the default class, which typically has a low rate and may drop legitimate SNMP. Adding a dedicated class-map for SNMP with an appropriate policer restores connectivity while preserving protection.

Exam trap

The trap here is assuming that increasing the default policer rate or removing CoPP is acceptable, rather than adding the missing classification for SNMP.

51
MCQhard

A network security engineer is configuring 802.1X on a Cisco Catalyst switch with Cisco ISE as the RADIUS server. The switch is configured with 'dot1x system-auth-control' and the interface is set to 'authentication port-control auto'. The engineer wants to allow a printer that does not support 802.1X to connect to the network by using MAC Authentication Bypass (MAB). Which additional configuration is required on the switch interface to enable MAB?

A.Configure 'authentication host-mode multi-auth' under the interface configuration mode.
B.Configure 'mab' under the interface configuration mode.
C.Configure 'dot1x pae authenticator' under the interface configuration mode.
D.Configure 'authentication order dot1x mab' under the interface configuration mode.
AnswerB

MAB is enabled on an interface with the 'mab' command in interface configuration mode. This allows the switch to use the device's MAC address as the username and password for RADIUS authentication when 802.1X times out. It is the standard method to support non-802.1X devices like printers. The other commands do not enable MAB.

Why this answer

MAC Authentication Bypass (MAB) is enabled on a switch interface with the 'mab' command. This allows the switch to use the connecting device's MAC address as credentials for RADIUS authentication when 802.1X is not supported. The other commands either control host mode, set the authenticator role, or define authentication order, but none enable MAB.

Exam trap

The trap here is confusing commands that define authentication order or host mode with the command that actually enables MAB functionality.

52
MCQmedium

An engineer must secure the management plane of a Cisco IOS XE router so that only SSH version 2 is accepted for remote administration, while Telnet and SSHv1 are rejected. Which set of commands accomplishes this?

A.ip ssh server algorithm encryption aes128-ctr aes256-ctr line vty 0 4 transport input all
B.line vty 0 4 transport input telnet ssh ip ssh version 2
C.line vty 0 4 transport input ssh ip ssh version 2
D.line vty 0 4 transport input ssh no ip ssh version 1
AnswerC

The transport input ssh command restricts VTY lines to SSH only, blocking Telnet, while ip ssh version 2 forces the router to negotiate only SSHv2 sessions. Together they satisfy both requirements. This is the canonical method on Cisco IOS XE for enforcing SSHv2-only management access.

Why this answer

Restricting VTY lines with 'transport input ssh' eliminates Telnet access, and 'ip ssh version 2' forces the SSH server to negotiate only version 2. Used together under the correct configuration modes, they enforce SSHv2-only remote management. Other combinations either leave Telnet enabled, use invalid syntax, or fail to restrict the transport protocol.

Exam trap

The trap here is believing that disabling SSHv1 requires a 'no' form command, when the correct approach is to explicitly set 'ip ssh version 2'.

53
Multi-Selectmedium

A network security team is deploying MACsec on a Cisco Catalyst 9000 switch series to secure Layer 2 traffic between two switches. Which two statements about MACsec operation are true? (Choose two.)

Select 2 answers
A.MACsec encrypts the entire Ethernet frame including the source and destination MAC addresses.
B.MACsec uses MKA (MACsec Key Agreement) to negotiate session keys between peers.
C.MACsec provides hop-by-hop encryption using the GCM-AES-128 cipher suite.
D.MACsec requires the use of IKEv2 to establish the secure channel between switches.
E.MACsec can only be deployed on routed interfaces, not on switchports.
AnswersB, C

MKA is a protocol defined in IEEE 802.1X-2010 that handles key agreement for MACsec. It elects a key server, distributes secure association keys (SAKs), and manages key rotation. On Cisco switches, MKA must be enabled with a pre-shared key or 802.1X-derived CAK. This statement correctly describes how MACsec establishes and maintains cryptographic keys between peers.

Why this answer

MACsec is an IEEE 802.1AE standard that provides hop-by-hop encryption and integrity on Ethernet links. It uses GCM-AES-128 for encryption and MKA for key agreement. It does not encrypt MAC addresses, and it does not use IKEv2.

It is deployed on switchports, not routed interfaces. Therefore, the two true statements are that it provides hop-by-hop encryption with GCM-AES-128 and that it uses MKA to negotiate session keys.

Exam trap

The trap here is confusing MACsec with IPsec by assuming it uses IKEv2 or encrypts the entire frame including MAC addresses, when it actually uses MKA and leaves MAC addresses in clear text.

54
MCQhard

A network engineer is deploying Control Plane Policing (CoPP) on a Cisco IOS XE router. The router runs BGP, OSPF, SSH management, and SNMP. After applying a CoPP policy that rate-limits all control-plane traffic to 1000 pps, BGP sessions flap and OSPF adjacencies reset during peak traffic. Which action should the engineer take to resolve the problem while maintaining control-plane protection?

A.Create separate class-maps for BGP, OSPF, SSH, and SNMP, and apply protocol-specific rate limits within the policy-map.
B.Enable Control Plane Protection (CPPr) with the aggregate option to automatically prioritize routing protocols.
C.Increase the global CoPP rate limit to 5000 pps to accommodate all control-plane protocols.
D.Remove the CoPP policy from the control plane and rely on QoS policies on data interfaces instead.
AnswerA

CoPP works by classifying traffic into distinct classes and applying individual policers. Creating separate class-maps for each protocol allows the engineer to set appropriate rates for BGP and OSPF while still policing SSH and SNMP. This targeted approach protects the control plane without starving routing protocols, resolving the flapping while maintaining security.

Why this answer

CoPP uses a modular QoS CLI (MQC) structure with class-maps to identify traffic types and a policy-map to apply policers per class. A single policer for all control-plane traffic causes legitimate routing protocol updates to compete with management and monitoring traffic, leading to drops and session resets. The correct solution is to define separate class-maps for BGP, OSPF, SSH, and SNMP, then assign differentiated rate limits in the policy-map.

This preserves control-plane protection while ensuring routing protocols receive adequate bandwidth.

Exam trap

The trap here is treating CoPP as a single-rate mechanism and either removing it or inflating the global limit instead of using granular per-protocol classification, which is the intended design.

55
Multi-Selecteasy

Which TWO features are part of Cisco TrustSec for providing role-based access control?

Select 2 answers
A.Security Group Access Control Lists (SGACLs)
B.Change of Authorization (CoA)
C.802.1X authentication
D.Security Group Tags (SGTs)
E.MACsec encryption
AnswersA, D

SGACLs enforce policies based on SGTs.

Why this answer

Security Group Access Control Lists (SGACLs) are a core component of Cisco TrustSec, enforcing role-based access control by applying policies based on Security Group Tags (SGTs). SGACLs replace traditional IP-based ACLs, allowing dynamic, identity-aware traffic filtering that scales across the network.

Exam trap

Cisco often tests the distinction between the authentication mechanism (802.1X) and the authorization/enforcement components (SGTs and SGACLs), leading candidates to mistakenly select 802.1X as a TrustSec RBAC feature.

56
Multi-Selectmedium

A network administrator is deploying 802.1X on Cisco Catalyst access switches with Cisco ISE as the RADIUS server. The design requires that devices failing authentication be placed into a restricted VLAN, and that IP phones be authenticated before the attached PC. Which two features must be configured to meet these requirements? (Choose two.)

Select 2 answers
A.Configure an authentication failure VLAN using the authentication event fail action authorize vlan command.
B.Enable 802.1X multi-domain authentication on the port so the phone and PC authenticate independently.
C.Enable port security with sticky MAC addresses on the access port.
D.Configure a guest VLAN on the switch port for hosts that do not support 802.1X.
E.Configure MAC Authentication Bypass (MAB) as the primary authentication method instead of 802.1X.
AnswersA, B

The authentication event fail action authorize vlan command on the switch port directs hosts that fail 802.1X authentication into a specified restricted VLAN. This exactly matches the requirement to isolate failed devices. It is the correct IOS configuration to define failure handling behavior for the port and is essential for the design described.

Why this answer

Placing failed authentications into a restricted VLAN is accomplished with the authentication event fail action authorize vlan command, which defines failure handling. Supporting an IP phone and a PC on one port with independent authentication requires multi-domain authentication, which creates separate voice and data sessions. Together these two features meet both design requirements.

Exam trap

The trap here is confusing a guest VLAN, which serves non-supplicant devices, with a restricted failure VLAN, which isolates devices that actively fail authentication.

57
MCQhard

A network engineer is deploying MACsec on a Cisco Catalyst 9300 switch to secure a point-to-point link between two access switches. The engineer configures the switchport with the macsec command and a pre-shared key. After applying the configuration, the link comes up but MACsec is not encrypting traffic. Which action should the engineer take to resolve the issue?

A.Apply the macsec command under the VLAN interface instead of the physical interface.
B.Change the switchport mode to trunk to allow MACsec frames to pass.
C.Enable MACsec globally using the macsec command in global configuration mode.
D.Configure the key server protocol (MKA) with a matching connectivity association key (CAK) on both switches and ensure the key server priority is set.
AnswerD

MACsec requires MKA to negotiate session keys between peers. If the CAK or key server priority does not match on both ends, MKA will not establish a secure association, and MACsec will not encrypt traffic even though the link is up. Configuring a matching CAK and designating a key server on both switches allows MKA to complete negotiation, after which MACsec encryption begins.

Why this answer

MACsec relies on MKA to establish a secure channel between two directly connected devices. For MKA to succeed, both peers must share the same connectivity association key and agree on the key server. If these parameters are missing or mismatched, the link remains up but MACsec encryption does not activate.

Verifying and matching the MKA configuration on both switches is the correct troubleshooting step.

Exam trap

The trap here is assuming that enabling MACsec on the interface is sufficient, without ensuring MKA parameters match on both ends of the link.

58
MCQmedium

A network administrator is deploying 802.1X on Cisco Catalyst switches with Cisco ISE as the RADIUS server. The administrator wants to allow devices that do not support 802.1X, such as printers, to connect to the network. Which feature should be configured on the switch ports to support these devices while maintaining security?

A.Configure the switch ports as 802.1X supplicants so they can authenticate on behalf of connected devices.
B.Enable MAC Authentication Bypass (MAB) on the switch ports so that the MAC address of non-802.1X devices is sent to ISE for authentication.
C.Implement 802.1X with EAP-TLS and install certificates on the printers.
D.Disable 802.1X on the ports and rely on port security to restrict access based on MAC addresses.
AnswerB

MAB allows non-802.1X-capable devices like printers to be authenticated by their MAC address. The switch learns the MAC address and sends it to ISE as the username and password. ISE can then apply an authorization policy, such as placing the device in a specific VLAN or applying an ACL. This maintains centralized control while supporting legacy devices.

Why this answer

MAC Authentication Bypass allows devices that lack 802.1X supplicant software to be authenticated by their MAC address against Cisco ISE. The switch sends the MAC address as both username and password, and ISE applies the appropriate authorization policy. This enables printers and similar devices to connect while still enforcing centralized access control.

Exam trap

The trap here is confusing the roles of supplicant, authenticator, and authentication server, and assuming the switch can authenticate on behalf of endpoints without MAB.

59
Multi-Selectmedium

A network security team is hardening a Cisco IOS XE router that terminates IPsec tunnels to remote branch offices. The team wants to use zone-based firewall (ZBFW) to inspect traffic between the inside, outside, and VPN zones. Which two statements correctly describe zone-based firewall behavior on this platform? (Choose two.)

Select 2 answers
A.Applying an inspect action to a zone pair automatically creates a reverse zone pair for return traffic.
B.Traffic between two interfaces assigned to the same zone is implicitly permitted and not inspected by the zone policy.
C.Interfaces not assigned to any zone are treated as members of the self zone and inspected.
D.Traffic between two zones with no configured zone pair is implicitly denied by default.
E.A zone pair must be configured bidirectionally; a single zone pair covers traffic in both directions automatically.
AnswersB, D

ZBFW treats all interfaces in the same zone as a single trust domain, so intra-zone traffic is not inspected and is permitted by default. This design simplifies policy by letting administrators define inspection only for inter-zone flows. In this scenario, if two branch-facing interfaces were both in the VPN zone, traffic between them would bypass inspection, which is a key behavior to understand when designing zone membership.

Why this answer

ZBFW permits intra-zone traffic without inspection and denies inter-zone traffic by default unless a zone pair with a policy exists. Zone pairs are unidirectional, inspection handles return traffic for established sessions, and unassigned interfaces use classic ACL behavior rather than joining the self zone. These behaviors drive how the branch router's inside, outside, and VPN zones must be paired and inspected.

Exam trap

The trap here is assuming a single zone pair inspects traffic in both directions, when zone pairs are unidirectional and return traffic is handled by the stateful inspect action.

60
Multi-Selectmedium

A network security team is evaluating Cisco TrustSec (CTS) for deployment in a campus network. The team wants to understand which components are essential for enforcing security group tags (SGTs) and providing role-based access control. Which two of the following are required to implement CTS with SGT enforcement? (Choose two.)

Select 2 answers
A.Cisco AnyConnect Network Access Manager for endpoint posture
B.Dynamic Host Configuration Protocol (DHCP) snooping
C.Cisco Identity Services Engine (ISE) for policy and SGT assignment
D.Spanning Tree Protocol (STP) for loop prevention
E.Inline tagging or SGT Exchange Protocol (SXP) for tag propagation
AnswersC, E

Cisco ISE is the policy engine that assigns SGTs to users and devices during authentication. It also defines security group ACLs (SGACLs) that determine what traffic is permitted between groups. Without ISE, dynamic SGT assignment and centralized policy management are not possible, making it a fundamental component of CTS.

Why this answer

Implementing Cisco TrustSec requires a policy engine to assign SGTs and a method to propagate those tags. Cisco ISE provides the centralized policy and SGT assignment, while inline tagging or SXP ensures that SGTs are carried across network devices. Together, they enable enforcement of SGACLs.

STP, DHCP snooping, and AnyConnect NAM are not essential for SGT-based access control, though they may be used in a broader security architecture.

Exam trap

The trap here is confusing general security features like DHCP snooping or AnyConnect with the core components required for CTS SGT enforcement.

61
MCQmedium

A network administrator is deploying Cisco TrustSec in a campus network. The security team wants to enforce access policy based on a device's role rather than its IP address, so that the enforced policy remains consistent even when endpoints move between VLANs or subnets. Which Cisco TrustSec component is responsible for assigning and carrying this role-based identity through the network?

A.IPsec tunnel established between the access switch and the Cisco DNA Center appliance.
B.Security Group Tag (SGT) applied at ingress and propagated via inline tagging or SXP.
C.MACsec encryption applied on the uplink between access and distribution switches.
D.Cisco Identity Services Engine (ISE) profiling the endpoint after DHCP and HTTP probes.
AnswerB

The SGT is a 16-bit value inserted into the frame or packet at the ingress device, which then enforces policy at egress based on the tag instead of IP. Propagation via inline tagging or the SGT Exchange Protocol (SXP) keeps role identity intact across VLAN and subnet boundaries, which is exactly what the security team requires.

Why this answer

Role-based enforcement in TrustSec depends on Security Group Tags that travel with the traffic. The ingress device classifies the packet and inserts the SGT; downstream devices enforce the Security Group ACL based on that tag. Because the tag, not the IP address, drives policy, endpoints keep the same access rights after moving between VLANs and subnets, satisfying the stated requirement.

Exam trap

The trap here is assuming that endpoint profiling or encryption alone delivers role-based enforcement, when only the Security Group Tag actually carries role identity in the data plane.

62
MCQhard

A network security team deploys Cisco ISE for 802.1X wired authentication. The switches are configured with MAB as a fallback. A printer that does not support 802.1X is connected, but ISE rejects it even though the printer's MAC address is in the correct identity group. The switch port shows the authentication method as MAB and the status as unauthorized. Which configuration issue is the most likely cause?

A.The MAC address format in the ISE endpoint identity group does not match the format sent by the switch in the MAB request.
B.The switch port is configured with authentication host-mode multi-domain instead of multi-auth.
C.The RADIUS shared secret on the switch does not match the one configured for the switch in Cisco ISE.
D.The switch is configured with dot1x pae authenticator on the port instead of pae supplicant.
AnswerA

ISE matches MAB requests against endpoint MAC addresses in its database using a specific format. If the endpoint was added with a different delimiter or case than what the switch sends in the Calling-Station-Id, ISE will not match the identity group and will reject the request, causing the unauthorized state.

Why this answer

MAB authentication depends on ISE matching the MAC address sent in the RADIUS request to an endpoint record. If the stored MAC format differs from the format in the Calling-Station-Id attribute, the endpoint is not matched to its identity group and authorization fails. Ensuring consistent MAC formatting resolves the rejection.

Exam trap

The trap here is focusing on switch-side 802.1X host modes or RADIUS secrets while overlooking that MAB success hinges on exact MAC address formatting in the ISE endpoint database.

63
MCQmedium

A network administrator is configuring a site-to-site IPsec VPN between two Cisco IOS routers. The design requires that only traffic from specific subnets be encrypted and that the routers use a preshared key for authentication. Which combination of configuration elements must the administrator define to match the interesting traffic and establish the tunnel?

A.An ISAKMP policy, a preshared key, and a crypto map applied to the WAN interface without an ACL for interesting traffic.
B.A route map defining interesting traffic, a crypto map, and a transform set applied to the LAN interface.
C.An ACL defining interesting traffic, an ISAKMP policy, a preshared key, and a crypto map applied to the WAN interface.
D.An ACL defining interesting traffic, a transform set, and a crypto map applied to the LAN interface without an ISAKMP policy.
AnswerC

A classic site-to-site IPsec VPN on Cisco IOS requires an extended ACL to identify interesting traffic, an ISAKMP (IKE) policy to define Phase 1 parameters, a preshared key for peer authentication, and a crypto map that references the ACL and transform set and is applied to the WAN interface. Together these elements establish and encrypt the tunnel.

Why this answer

A Cisco IOS site-to-site IPsec VPN requires an extended ACL to identify interesting traffic, an ISAKMP policy to define Phase 1 parameters, a preshared key for peer authentication, and a crypto map that ties the ACL and transform set together and is applied to the WAN interface. All of these elements work together to negotiate and encrypt traffic between the peers.

Exam trap

The trap here is assuming that a route map or an interface other than the WAN can define or carry the IPsec policy, when interesting traffic must be defined by an ACL and the crypto map must be applied to the WAN interface.

64
MCQmedium

A network engineer is deploying Control Plane Policing on a Cisco IOS-XE router that runs OSPF, BGP, and SSH management. The engineer wants to rate-limit routing protocol traffic while ensuring that SSH management traffic is never dropped, even during a routing protocol flood. The router uses a single physical interface for all control plane traffic. Which CoPP design approach best meets these requirements?

A.Create separate class-maps for OSPF, BGP, and SSH, then apply individual policers to each class in the policy-map, with SSH assigned a higher rate or set to conform-action transmit.
B.Use a single class-map for OSPF and BGP, and rely on SSH being exempt because it is TCP-based and not subject to CoPP.
C.Configure CoPP only on the management interface and leave the data interfaces unprotected.
D.Apply a single class-map matching all control plane traffic and set a single policer with a high rate limit.
AnswerA

Creating separate class-maps allows the engineer to apply distinct policers to each traffic type. By giving SSH a higher rate limit or configuring it to always transmit, management access is protected. OSPF and BGP can be rate-limited independently to prevent control plane overload. This granular approach is the recommended CoPP design for protecting critical management traffic.

Why this answer

Separate class-maps for OSPF, BGP, and SSH allow individual policing actions. Assigning SSH a higher rate or conform-action transmit ensures management access is preserved during routing protocol floods. This granular CoPP design protects both routing stability and administrative access, which is the core goal of control plane policing.

Exam trap

The trap here is assuming that SSH management traffic is automatically exempt from CoPP because it is TCP-based, when in fact all control plane traffic is subject to the policy-map.

65
MCQeasy

An organization wants to implement 802.1X authentication on its wired network using Cisco ISE as the authentication server. The switches are configured with the necessary RADIUS settings. Which additional configuration is required on the switch interfaces to enable 802.1X?

A.dot1x pae authenticator
B.authentication port-control auto
C.authentication port-control force-authorized
D.authentication port-control force-unauthorized
AnswerB

This command sets the port's authentication mode to auto, meaning the port will be unauthorized until the client successfully authenticates via 802.1X. It triggers the authentication process and is the required command to enable 802.1X on an interface. This is the correct answer because it directly controls the port's state based on authentication.

Why this answer

'authentication port-control auto' is the required interface command to enable 802.1X authentication on a switch port. This command sets the port to initiate the authentication process, placing it in the unauthorized state until the client successfully authenticates via the RADIUS server (Cisco ISE). Without this command, the port will not enforce 802.1X.

Exam trap

Cisco often tests the distinction between the 'dot1x pae authenticator' command and the 'authentication port-control auto' command, leading candidates to mistakenly think the PAE command alone enables 802.1X, when in fact both are required for full functionality.

How to eliminate wrong answers

Option A is wrong because 'dot1x pae authenticator' is a subcommand that enables the Port Access Entity (PAE) role as authenticator, but it is not sufficient alone; the port must also be configured with 'authentication port-control auto' to actually enforce 802.1X. Option C is wrong because 'authentication port-control force-authorized' places the port in an always-authorized state, effectively disabling 802.1X authentication and allowing all traffic without verification. Option D is wrong because 'authentication port-control force-unauthorized' places the port in a permanently unauthorized state, blocking all traffic regardless of authentication attempts, which is not the goal for enabling 802.1X.

66
MCQmedium

A network administrator is deploying a new Cisco Catalyst 9200 switch at a branch office. The security policy requires that when a device connected to a port is shut down or moved, the switch must immediately send a SNMP trap and place the port into an error-disabled state while also incrementing a violation counter. The administrator configures port security with the violation mode that meets these requirements. Which command must be applied to the interface to achieve this?

A.switchport port-security violation disable
B.switchport port-security violation restrict
C.switchport port-security violation protect
D.switchport port-security violation shutdown
AnswerD

Shutdown mode causes the port to go into an error-disabled state immediately upon a violation, sends an SNMP trap, and increments the violation counter. This exactly matches the stated security policy. The port must be manually re-enabled with a shutdown/no shutdown sequence after the violation is resolved.

Why this answer

The security policy requires the switch to send an SNMP trap and place the port into an error-disabled state when a violation occurs. The shutdown violation mode does exactly that: it error-disables the port, generates a syslog/SNMP notification, and increments the violation counter. The restrict mode only increments counters and sends notifications without disabling the port, while protect mode silently drops frames.

Disable is not a valid keyword.

Exam trap

The trap here is assuming that restrict mode also error-disables the port, when in fact it only drops frames and logs the violation without shutting down the interface.

67
MCQeasy

A network administrator is configuring a Cisco IOS router to act as a VPN headend for remote access. The requirement is to use IKEv2 with certificate-based authentication. The administrator has installed a valid identity certificate on the router and configured the IKEv2 profile. However, remote clients are unable to establish the VPN tunnel, and the router logs show 'IKEv2 certificate authentication failed'. What is the most likely cause?

A.The pre-shared key is not configured on the IKEv2 profile.
B.The remote clients are using IKEv1 instead of IKEv2.
C.The router's certificate has expired.
D.The IKEv2 profile is not referencing the correct trustpoint for certificate authentication.
AnswerD

In IKEv2, the profile must specify the trustpoint that contains the router's identity certificate and the CA certificate for verifying peer certificates. If the trustpoint is not referenced or is incorrect, the router cannot validate client certificates, leading to authentication failure. This is a common misconfiguration when setting up certificate-based IKEv2. The logs indicating certificate authentication failed point to a trustpoint or PKI issue.

Why this answer

For IKEv2 certificate-based authentication, the IKEv2 profile must reference a trustpoint that contains the router's identity certificate and the CA certificate to validate peer certificates. If the trustpoint is missing or incorrect, the router cannot authenticate the client's certificate, resulting in failure. Ensuring the correct trustpoint is referenced and that the CA chain is complete resolves the issue.

Exam trap

The trap here is assuming that installing a valid certificate is sufficient, while overlooking that the IKEv2 profile must explicitly point to the trustpoint for authentication to succeed.

68
MCQhard

A company uses Cisco TrustSec in its campus network. Security policy requires that a user authenticated by 802.1X be assigned a Security Group Tag (SGT) based on the user's Active Directory group, and that the SGT be carried to downstream switches for enforcement. The access switch is configured for 802.1X with Cisco ISE. Which combination of features must be enabled to meet the requirement?

A.SGT assignment via ISE and enabling MACsec on all inter-switch links
B.SGT assignment via ISE and enabling 802.1X on all downstream switch ports
C.SGT assignment via ISE and configuring dynamic ARP inspection on all switches
D.SGT assignment via ISE authorization policy and inline tagging or SXP propagation on the switch uplinks
AnswerD

ISE can return an SGT in the authorization result based on Active Directory group membership, and the access switch applies it to the session. To carry the tag to downstream devices, either inline tagging on the link or SXP propagation must be configured, enabling enforcement of group-based policy across the network.

Why this answer

Cisco TrustSec assigns SGTs through ISE authorization rules that can reference Active Directory group membership. For the tag to reach downstream switches, the network must propagate it using inline tagging on capable links or SXP where inline tagging is not supported. This enables consistent group-based enforcement across the campus.

Exam trap

The trap here is assuming that enabling 802.1X on additional ports or adding Layer 2 security features like DAI or MACsec will propagate the SGT, when propagation actually requires inline tagging or SXP.

69
MCQhard

A network security engineer is deploying MACsec on a Cisco Catalyst 9000 switch. The switch is connected to a Cisco IP phone that does not support MACsec, and a PC is connected to the phone. The engineer wants to encrypt traffic between the switch and the phone, but the phone does not support MACsec. What should the engineer do to secure the link?

A.Replace the phone with a MACsec-capable model or use a different encryption method such as IPsec for the traffic.
B.Use a MACsec-capable switch port and enable `macsec` with `fallback` to allow unencrypted traffic if the phone does not support it.
C.Configure the switch port to use MACsec for the PC traffic and leave the phone traffic unencrypted.
D.Enable MACsec on the switch port with `macsec` and configure the phone to use 802.1X with MAB.
AnswerA

Since the phone does not support MACsec, link-layer encryption cannot be established. The engineer must either upgrade to a MACsec-capable phone or use a higher-layer encryption method like IPsec, which can encrypt traffic end-to-end regardless of link-layer capabilities. This is the only viable way to secure the traffic.

Why this answer

MACsec is a link-layer encryption protocol that requires both endpoints to support it. If the IP phone does not support MACsec, the switch cannot encrypt traffic to the phone at Layer 2. The engineer must either replace the phone with a MACsec-capable model or use a higher-layer encryption method such as IPsec to secure the traffic.

Exam trap

The trap here is assuming that MACsec can be selectively applied or that it can fall back to clear text, when in reality it requires both endpoints to support it.

70
MCQeasy

A network administrator at a small company wants to prevent users from plugging unauthorized switches into wall jacks and creating loops or bypassing security controls. The administrator decides to implement BPDU Guard on all access ports on a Cisco Catalyst switch. Which statement accurately describes the behavior of BPDU Guard when configured on an access port?

A.It filters BPDUs from being forwarded out of the port while allowing the port to remain active.
B.It converts the access port into a trunk port when BPDUs are detected to allow proper spanning tree convergence.
C.It places the port into err-disabled state if a BPDU is received on the port.
D.It sends a syslog message and drops only the offending BPDU while keeping the port operational.
AnswerC

BPDU Guard is designed to protect access ports from receiving BPDUs. When a BPDU is detected on a port with BPDU Guard enabled, the switch immediately places that port into err-disabled state, preventing the unauthorized device from participating in spanning tree and potentially causing loops or topology changes.

Why this answer

BPDU Guard protects access ports by err-disabling them when any BPDU is received. This prevents unauthorized switches from being connected and potentially disrupting the spanning tree topology. It is commonly deployed alongside PortFast on access ports to ensure that end-user devices cannot participate in STP.

Exam trap

The trap here is confusing BPDU Guard with BPDU Filter, where BPDU Filter suppresses BPDUs while BPDU Guard disables the port upon receiving one.

71
MCQhard

A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router to protect against DoS attacks. The router has a management plane that includes SSH and SNMP, and a control plane that includes routing protocols like OSPF and BGP. The engineer wants to rate-limit traffic destined to the route processor while ensuring that management traffic is not dropped during high CPU load. Which CoPP configuration approach is most appropriate?

A.Configure separate classes for management traffic (SSH, SNMP) and control plane traffic (OSPF, BGP), and assign higher rate limits to management traffic.
B.Use a single class that matches all IP traffic and set a high rate limit to avoid dropping any packets.
C.Apply a single CoPP policy that classifies all traffic to the route processor and sets a low rate limit for all classes.
D.Configure CoPP only for routing protocols and rely on QoS for management traffic.
AnswerA

This is the best practice. By creating separate classes, the engineer can apply different rate limits. Management traffic should have a higher rate limit to ensure administrators can always access the device, while control plane protocols can have lower limits to protect the route processor. This granularity ensures that critical management access is not starved during an attack, and routing protocols are still protected but not at the expense of management access.

Why this answer

CoPP allows granular control over traffic destined to the route processor. By separating management and control plane traffic into different classes, the engineer can assign higher rate limits to management traffic to ensure administrative access is maintained, while still protecting the route processor from excessive control plane traffic. This approach balances security and availability, preventing both DoS attacks and administrator lockout.

Exam trap

The trap here is assuming that a single CoPP policy with a uniform rate limit is sufficient, overlooking the need to prioritize management traffic to prevent lockout during an attack.

72
MCQmedium

A network administrator is deploying Cisco Identity Services Engine (ISE) for wired 802.1X authentication on a Cisco Catalyst 9200 switch. The RADIUS server is reachable at 10.10.10.50 with shared secret 'C1sco123'. The administrator wants the switch to authenticate users before granting access to the data VLAN, and to place unauthenticated devices into a restricted VLAN. Which command sequence correctly enables 802.1X on a switch port?

A.aaa new-model; radius server ISE; address ipv4 10.10.10.50 auth-port 1812 acct-port 1813; key C1sco123; interface GigabitEthernet1/0/1; authentication port-control force-authorized; dot1x pae authenticator
B.aaa new-model; tacacs server ISE; address ipv4 10.10.10.50; key C1sco123; interface GigabitEthernet1/0/1; authentication port-control auto; dot1x pae supplicant
C.aaa new-model; radius server ISE; address ipv4 10.10.10.50 auth-port 1645 acct-port 1646; key C1sco123; interface GigabitEthernet1/0/1; authentication port-control auto; dot1x pae authenticator
D.aaa new-model; radius server ISE; address ipv4 10.10.10.50 auth-port 1812 acct-port 1813; key C1sco123; interface GigabitEthernet1/0/1; authentication port-control auto; dot1x pae authenticator
AnswerD

This sequence enables AAA with 'aaa new-model', configures the ISE RADIUS server with the correct ports and key, then on the interface enables 802.1X port-based authentication with 'authentication port-control auto' and designates the switch port as an authenticator with 'dot1x pae authenticator'. This is the correct method to authenticate before granting access and to use an auth-fail VLAN if configured.

Why this answer

802.1X on a Cisco switch requires enabling AAA, defining the RADIUS server with the correct ports and key, and configuring the interface as an authenticator with 'authentication port-control auto'. The switch acts as the authenticator, ISE as the authentication server, and the endpoint as the supplicant. Using 'force-authorized' bypasses authentication, TACACS+ is not used for 802.1X, and legacy ports 1645/1646 are incorrect.

Exam trap

The trap here is confusing the authenticator role with the supplicant role, or selecting force-authorized instead of auto, which would bypass authentication.

73
MCQhard

A network security architect is designing a Zero Trust architecture for a campus network using Cisco Identity Services Engine (ISE) and Cisco TrustSec. The requirement is to enforce segmentation based on user identity and device posture, and to apply policy dynamically as users move between wired and wireless access points. Which Cisco TrustSec component is responsible for tagging packets with a Security Group Tag (SGT) at the access layer?

A.The Policy Administration Node (PAN) in Cisco ISE.
B.The access layer switch or wireless controller that supports Cisco TrustSec.
C.The Policy Enforcement Node (PEN) in Cisco ISE.
D.The Cisco DNA Center appliance.
AnswerB

In Cisco TrustSec, the access layer device, such as a Catalyst switch or wireless controller, is responsible for classifying and tagging packets with an SGT after the endpoint is authenticated. This tagging enables enforcement throughout the network based on the Security Group Tag, allowing dynamic segmentation as users move between wired and wireless access points.

Why this answer

In Cisco TrustSec, the access layer device performs classification and tagging by inserting the SGT into the packet after authentication and authorization. ISE nodes define and evaluate policy, but they do not tag packets. This design allows dynamic segmentation to follow users as they move between wired and wireless access points.

Exam trap

The trap here is confusing the policy decision point with the enforcement point, when SGT tagging actually occurs on the access device.

74
MCQmedium

A medium-sized enterprise is migrating to a Cisco DNA Center-managed network. The security policy requires that all administrative access to network devices be authenticated via TACACS+ and that authorization for commands be enforced per user role. The network team has configured ISE as the AAA server and integrated it with DNA Center. After configuration, engineers report that they can log in to devices via SSH but are not prompted for a password when entering 'enable' mode; instead, they are granted full privileges immediately. Additionally, while in configuration mode, some engineers can issue 'debug' commands that they should not have access to. The configuration on the devices includes 'aaa new-model', 'aaa authentication login default group tacacs+ local', 'aaa authorization exec default group tacacs+ local', and 'aaa authorization commands 15 default group tacacs+ local'. What is the most likely cause of the privilege escalation and missing authorization?

A.The TACACS+ server is not reachable, so the device is using local authentication, but the local database has all users at privilege level 15.
B.The 'aaa authentication enable default' command is missing, so the device is not requiring authentication to enter enable mode, and command authorization is not being enforced because the user is already at privilege 15.
C.Command authorization is only configured for privilege level 15, but users are logging in at level 1; they need 'aaa authorization commands 1 default' as well.
D.The 'privilege level' command is set to 15 on the VTY lines, bypassing AAA authorization.
AnswerB

The absence of 'aaa authentication enable default' leaves the default behavior of no authentication for enable mode, allowing any user to switch to privileged EXEC without a password. Once in enable mode, the user is at privilege level 15, and if command authorization is configured for level 15, the device may not trigger an authorization check because the user already holds full privilege, or the check may occur but without prior authentication it is ineffective. This configuration flaw directly explains why no credentials are prompted and why authorization seems bypassed.

Why this answer

The missing 'aaa authentication enable default group tacacs+ local' command means the device does not require TACACS+ authentication to enter enable mode. Since the user is already at privilege level 15 after login (due to the 'aaa authorization exec' command or local user configuration), they are not prompted for a password and are granted full privileges immediately. Additionally, command authorization is only configured for privilege level 15 ('aaa authorization commands 15'), so once the user is at level 15, no further authorization checks are performed for commands like 'debug', bypassing the intended per-role enforcement.

Exam trap

Cisco often tests the distinction between authentication (who you are) and authorization (what you can do), and the trap here is that candidates assume 'aaa authorization commands 15' alone enforces command restrictions, but they overlook that without 'aaa authentication enable', users may already be at privilege 15, making command authorization ineffective.

How to eliminate wrong answers

Option A is wrong because if the TACACS+ server were unreachable, the 'aaa authentication login default group tacacs+ local' command would fall back to local authentication, but the issue is about enable mode and command authorization, not login; also, local users would not automatically be at privilege 15 unless explicitly configured. Option C is wrong because command authorization for privilege level 1 is irrelevant; the problem is that users are already at privilege 15, so commands at level 15 are authorized without further checks, and adding 'aaa authorization commands 1' would not fix the enable mode or the privilege escalation. Option D is wrong because the 'privilege level' command on VTY lines would set the initial privilege level for all users, but the configuration shown does not include this command, and the described behavior (no password prompt for enable, debug commands allowed) is consistent with missing enable authentication and command authorization at the current privilege level, not with a VTY line setting.

75
MCQmedium

A network security administrator is configuring a Cisco IOS Zone-Based Firewall on a branch router. The inside zone and outside zone are defined, and the administrator wants to allow inside hosts to initiate sessions to outside servers while preventing outside hosts from initiating sessions to inside hosts. Which configuration accomplishes this?

A.A zone pair from inside to outside with a policy that inspects the relevant traffic, and no zone pair from outside to inside.
B.A zone pair from outside to inside with an inspect action and no zone pair from inside to outside.
C.A single zone pair from inside to outside with a drop action, and a class-map matching return traffic.
D.A zone pair from outside to inside with a policy that inspects traffic, plus a zone pair from inside to outside with a pass action.
AnswerA

Zone-Based Firewall uses zone pairs to define directional policy. Creating a zone pair from inside to outside with an inspect action permits inside-initiated sessions and automatically allows return traffic. Because there is no zone pair from outside to inside, traffic initiated from the outside zone to the inside zone is denied by default, which matches the requirement exactly.

Why this answer

Zone-Based Firewall policy is directional and defined by zone pairs. An inside-to-outside zone pair with an inspect action permits inside-initiated sessions and statefully allows return traffic, while the absence of an outside-to-inside zone pair causes traffic initiated from the outside to be dropped by the default inter-zone policy, achieving the required asymmetry.

Exam trap

The trap here is assuming that configuring an inspect action on one zone pair automatically permits sessions in both directions rather than only the direction defined by the zone pair.

Page 1 of 3 · 161 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Security questions.