Courseiva

350-401 · topic practice

Security practice questions

Security is 20% of ENCOR 350-401 and covers device hardening, access control, and traffic protection on Cisco IOS-XE and Catalyst platforms. Expect scenario questions on AAA with ISE or TACACS+, ACL and CoPP behaviour, 802.1X/MAB, port security, DHCP snooping, Dynamic ARP Inspection, IPsec, and MACsec, plus CLI output interpretation and configuration verification.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Security

What the exam tests

What to know about Security

Configure device hardening and access control using AAA (TACACS+/ISE), ACLs, CoPP, 802.1X/MAB, port security, DHCP snooping, and Dynamic ARP Inspection. The most important thing: verify ACL and CoPP order/interface direction, since mistakes silently drop or permit traffic.

Configuring AAA with TACACS+ or RADIUS, including authentication, authorization, and accounting method lists

Implementing Layer 2 protections: port security, DHCP snooping, Dynamic ARP Inspection, and 802.1X with MAB

Building and ordering standard, extended, and named ACLs, plus Control Plane Policing for management traffic

Configuring IPsec site-to-site VPNs and MACsec link encryption, including verifying SA and key status

Watch out for

Common Security exam traps

  • ▸Forgetting that ACL entries are processed top-down with an implicit deny, so a permit placed after a broader deny never matches
  • ▸Mixing up DHCP snooping trust on uplinks versus access ports, which breaks client addressing or leaves snooping ineffective
  • ▸Assuming 802.1X alone handles non-supplicant devices, instead of enabling MAB as a fallback on the same port

Practice set

Security questions

20 questions · select your answer, then reveal the explanation

Question 1hardmultiple choice
Open the full VLAN trunking answer →

A network administrator is troubleshooting a DHCP snooping issue on a Cisco switch. The switch is configured with DHCP snooping globally and on VLAN 10. The trusted interface is GigabitEthernet0/1 connected to the DHCP server. However, clients on VLAN 10 are not receiving IP addresses from the DHCP server. What is the most likely cause?

Question 2hardmultiple choice
Open the full VLAN trunking answer →

Your company has deployed a Cisco Catalyst 9300 switch stack as the distribution layer for a campus network. The network uses VLANs 10 (data), 20 (voice), and 30 (management). The switch stack is configured with DHCP snooping, Dynamic ARP Inspection (DAI), and IP Source Guard (IPSG) on access ports. Recently, users in VLAN 10 report intermittent connectivity issues. You notice that some users receive duplicate IP addresses from the DHCP server. The DHCP server is connected to a trunk port on the switch stack. After reviewing logs, you see that DHCPACK messages are being dropped on the trunk port. The DHCP snooping binding table shows entries for legitimate clients, but also some entries with MAC addresses from a different vendor. Which action should you take to resolve the issue?

Question 3mediummatching
Open the full STP breakdown →

Match each Spanning Tree Protocol (STP) variant to its key characteristic.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Original standard, slow convergence

Fast convergence, backward compatible

Multiple spanning trees per VLAN group

Cisco proprietary, per-VLAN STP

Cisco proprietary, per-VLAN RSTP

A network administrator is deploying a Cisco Catalyst 9300 switch in a campus access layer. The security policy mandates that when an unauthorized device connects to an access port, the port must immediately shut down and generate a syslog message, and the administrator must manually re-enable the port. The administrator configures the interface with the command 'switchport port-security violation shutdown'. However, after an unauthorized device connects, the port goes into the 'err-disabled' state, but no syslog message is generated. What is the most likely reason for the missing syslog message?

Question 5mediummultiple choice
Read the full Security explanation →

A network engineer is deploying 802.1X on a Cisco Catalyst 9200 switch. The authentication server is Cisco ISE. The help desk reports that some corporate Windows laptops fail authentication when they are first connected, but succeed after the user manually opens a browser. The switch port is configured with `authentication host-mode multi-auth` and `authentication open`. Which change should the engineer make to allow the laptops to authenticate without user interaction?

A network administrator is deploying a Cisco Catalyst 9300 switch in a branch office. The security policy requires that when an unauthorized MAC address is detected on interface GigabitEthernet1/0/5, the interface must be placed into the err-disabled state and an SNMP trap must be generated. The administrator has configured 'switchport port-security' on the interface. Which additional command is required to meet the policy?

Question 7mediummultiple choice
Study the full ACL explanation →

A network administrator is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router to protect against CPU overload. The administrator wants to rate-limit ARP packets destined to the control plane to 100 packets per second, while allowing all other traffic to the control plane without rate limiting. Which CoPP configuration accomplishes this?

Question 8hardmultiple choice
Study the full ACL explanation →

A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router to protect against denial-of-service attacks. The router has a management interface and several data interfaces. The engineer wants to rate-limit SSH traffic destined to the router's control plane to 100 kbps, while allowing all other management traffic (SNMP, NTP) without rate limiting. The engineer creates a class map named 'SSH-CLASS' matching TCP port 22, and a policy map named 'COPP-POLICY' with a police action of 100000 bps. The policy is applied to the control plane using 'service-policy input COPP-POLICY'. After applying the policy, the engineer notices that SNMP traffic is also being rate-limited, even though it is not explicitly matched. What is the most likely cause?

Question 9easymultiple choice
Read the full VPN explanation →

A network administrator is configuring a Cisco IOS router for IPsec site-to-site VPN with a peer that uses a dynamic public IP address. The administrator needs the router to accept IKE negotiations from any peer while still using pre-shared keys for authentication. Which configuration element is required on the local router?

Question 10mediummultiple choice
Open the full VLAN trunking answer →

A network security team is implementing 802.1X on Cisco Catalyst switches with Cisco ISE. The requirement is that if the RADIUS server is unreachable, endpoints should be placed into a restricted VLAN that only allows access to remediation servers. Which feature should be configured on the switch ports?

Question 11easymultiple choice
Read the full Security explanation →

A network engineer is deploying MACsec on a Cisco Catalyst 9000 switch to secure Layer 2 traffic between two switches. The engineer wants to ensure that MACsec is enabled on the link and that the switches use MKA for key management. Which command is required to enable MKA on the interface?

Question 12mediummulti select
Read the full Security explanation →

A network engineer is deploying Cisco TrustSec in a campus network. The engineer needs to enable Security Group Tagging (SGT) on a Cisco Catalyst 9000 switch. Which two actions are required to support SGT propagation and enforcement? (Choose two.)

Question 13hardmultiple choice
Open the full BGP breakdown →

A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router that peers BGP with two service providers over the same WAN interface. The engineer notices that during BGP session flaps, the router's CPU spikes and management SSH sessions become unresponsive. Which CoPP configuration change most directly protects the CPU during these events without disrupting legitimate BGP updates?

Question 14hardmultiple choice
Review the full routing breakdown →

A network administrator is configuring a Cisco IOS Zone-Based Policy Firewall (ZPF) on a router. The inside zone contains the LAN interface, and the outside zone contains the WAN interface. The administrator wants to allow inside-to-outside traffic, deny outside-to-inside traffic, and allow the router itself to initiate SSH to the outside for management. Which configuration is required to meet these requirements?

Question 15mediummultiple choice
Read the full DHCP explanation →

A network administrator is hardening a Cisco IOS XE switch against DHCP starvation attacks. The requirement is to limit the number of DHCP requests that can be processed on an untrusted access port to 10 per second and to err-disable the port if the rate is exceeded. Which configuration accomplishes this?

Question 16mediummultiple choice
Open the full VLAN trunking answer →

A network security engineer is implementing 802.1X authentication on a Cisco Catalyst switch. The switch is configured with RADIUS server 10.1.1.10 and a shared secret. The engineer wants to ensure that if the RADIUS server is unreachable, authenticated devices remain connected and unauthenticated devices are placed in a guest VLAN. The engineer configures 'authentication event server dead action authorize vlan 100' on the interface. However, when the RADIUS server goes down, authenticated devices are disconnected. What is the most likely cause?

Question 17hardmultiple choice
Review the full OSPF breakdown →

A network administrator is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router. The router runs OSPF, receives SNMP polling from the NMS, and terminates SSH management sessions. The administrator needs to ensure that OSPF hellos are never dropped by the CoPP policy while still rate-limiting SNMP and SSH. Which CoPP action should be applied to the OSPF class to meet this requirement?

Question 18mediummultiple choice
Read the full wireless explanation →

A network administrator is configuring a Cisco Wireless LAN Controller (WLC) to secure corporate Wi-Fi access. The requirement is to use 802.1X authentication with EAP-TLS, where both the client and the authentication server present certificates. The administrator has configured the WLAN with WPA2 Enterprise and selected 802.1X as the security policy. Which additional configuration is required on the WLC to support EAP-TLS?

Question 19mediummultiple choice
Open the full VLAN trunking answer →

A network administrator is deploying Cisco TrustSec in a campus network. The security policy requires that all traffic from the employee VLAN (VLAN 10) to the server VLAN (VLAN 20) be encrypted and authenticated at Layer 2, without relying on IPsec or any overlay tunneling. Which TrustSec component should be implemented to meet this requirement?

Question 20hardmultiple choice
Open the full BGP breakdown →

A security team is reviewing a Cisco IOS router configuration and finds that an ACL applied inbound on the WAN interface permits TCP port 179 from any source. The team wants to restrict BGP peering to only the two known service provider addresses while keeping the ACL efficient. Which ACL entry should be used to replace the overly permissive statement?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Security sessions

Start a Security only practice session

Every question in these sessions is drawn from the Security domain — nothing else.

Related practice questions

Related 350-401 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the 350-401 exam test about Security?
Configure device hardening and access control using AAA (TACACS+/ISE), ACLs, CoPP, 802.1X/MAB, port security, DHCP snooping, and Dynamic ARP Inspection. The most important thing: verify ACL and CoPP order/interface direction, since mistakes silently drop or permit traffic.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Security questions in a focused session?
Yes — the session launcher on this page draws every question from the Security domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other 350-401 topics?
Use the topic links above to move to related areas, or go back to the 350-401 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the 350-401 exam covers. They are not copied from any real exam or dump site.