Courseiva

350-701 · domain

Security Concepts

Practise Cisco SCOR / CCNP Security Core 350-701 Security Concepts practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

80 questions20 easy38 medium22 hard

Focused practice

Practice Security Concepts questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Security Concepts

Security Concepts questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Security Concepts exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Security Concepts questions (80)

Click any question to see the full explanation, or start a practice session above.

1

A web application accepts user input and directly includes it in SQL queries without sanitization. An attacker submits a single quote (') to cause a syntax error. What is this attack called?

Medium
2

A security engineer is implementing a zero trust architecture. Which TWO principles are foundational to zero trust? (Choose two.)

Medium
3

An attacker injects a malicious SQL query into a web application's login form, bypassing authentication. Which type of exploitation is this?

Medium
4

An organization is experiencing repeated SQL injection attacks. A security analyst is tasked with recommending mitigations. Which THREE actions are most effective in preventing SQL injection? (Choose three.)

Hard
5

An organization is experiencing a DDoS attack that floods the network with large volumes of traffic, overwhelming bandwidth. Which three types of DDoS attacks are primarily volumetric? (Choose three.)

Medium
6

A security administrator is configuring a Cisco Firepower NGFW to detect and block application-layer DDoS attacks. Which type of DDoS attack is characterized by overwhelming a server with incomplete HTTP requests, causing resource exhaustion?

Medium
7

What is the primary purpose of a digital signature?

Easy
8

Which Cisco security product provides identity-based access control and policy enforcement for wired and wireless networks?

Medium
9

During a penetration test, an attacker sends a malicious payload to a web application that causes the server to execute arbitrary SQL commands on the backend database. Which type of attack is being performed?

Hard
10

Which Cisco security product is primarily used for endpoint threat detection and retrospective security?

Medium
11

Which authentication factor relies on something the user is, such as a fingerprint or retina scan?

Easy
12

An employee receives an email that appears to be from the company's IT department requesting their login credentials. This is an example of which type of attack?

Medium
13

A security team implements a policy where users must provide a password and a one-time code from a mobile app. Which authentication factors are being used?

Medium
14

During an incident response, a forensic analyst finds that an attacker used a script to modify ARP tables, enabling them to intercept and modify traffic between two hosts. Which attack technique was used?

Hard
15

Which component of the CIA triad ensures that data is not altered by unauthorized entities during transmission?

Easy
16

Which type of malware is characterized by encrypting files on a victim's system and demanding payment for the decryption key?

Medium
17

An attacker intercepts traffic between a client and a server and modifies the communication without either party knowing. Which type of attack is being performed?

Hard
18

A security analyst is reviewing logs and identifies numerous ICMP echo requests from an external IP address to multiple internal hosts. Which type of reconnaissance activity is this?

Easy
19

A company wants to protect against DNS-based attacks by filtering malicious domains and providing secure DNS resolution. Which Cisco product should be deployed?

Medium
20

A Cisco ESA administrator notices that a large number of emails with malicious attachments are being delivered to users. Which feature should be configured to inspect attachments in a sandbox environment before delivery?

Hard
21

A company wants to implement a Zero Trust architecture. Which THREE principles should be included? (Choose three.)

Hard
22

A company is implementing a Zero Trust architecture. Which THREE principles are core to the Zero Trust model? (Choose three.)

Hard
23

An organization wants to implement a security model where no user or device is trusted by default, regardless of whether they are inside or outside the network perimeter. Which concept does this describe?

Medium
24

An attacker uses a tool to scan a target network for open ports and running services. Which type of reconnaissance does this represent?

Medium
25

A company is planning to deploy a Zero Trust architecture. Which two principles are fundamental to Zero Trust?

Hard
26

Which Cisco product provides advanced malware protection for endpoints, including file analysis and retrospective security?

Medium
27

What is the primary purpose of a digital signature?

Medium
28

An attacker performs a DNS cache poisoning attack on a recursive DNS server. What is the primary impact of this attack?

Medium
29

A security administrator is evaluating symmetric encryption algorithms for a new VPN deployment. Which algorithm uses a 128-bit block size and supports key sizes of 128, 192, and 256 bits?

Hard
30

Which cryptographic algorithm is a symmetric block cipher commonly used in modern VPNs and is considered secure?

Easy
31

Which of the following is a characteristic of a zero trust security model?

Easy
32

An attacker sends a flood of SYN packets with spoofed IP addresses to a server, causing it to allocate resources for half-open connections until it can no longer accept legitimate traffic. This is which type of DDoS attack?

Hard
33

Which of the following is an example of a passive reconnaissance technique?

Easy
34

A security engineer is evaluating Cisco solutions to detect and respond to network anomalies, including potential insider threats, by analyzing NetFlow data and behavioral patterns. Which Cisco product is best suited?

Hard
35

A security engineer needs to choose a hashing algorithm for storing passwords. Which of the following should be avoided due to known collision vulnerabilities?

Hard
36

An attacker intercepts ARP packets on a local network and associates their MAC address with the IP address of a legitimate host. This is an example of which attack?

Medium
37

A network engineer is tasked with securing email communications. Which TWO Cisco products are specifically designed for email security? (Choose two.)

Medium
38

What is the primary function of a Certificate Revocation List (CRL) in a PKI?

Medium
39

Which three components are part of the CIA triad?

Easy
40

An attacker intercepts communication between a client and server by spoofing ARP messages to associate the attacker's MAC address with the server's IP. This is an example of which type of attack?

Medium
41

A security engineer is configuring a Cisco Firepower NGFW to detect and block a new malware variant that communicates with a command-and-control server using encrypted DNS queries. Which Cisco security product is best suited to provide visibility into this malicious DNS traffic?

Hard
42

Which security model requires that all subjects and devices are untrusted by default, and access is granted only after verification, regardless of the network location?

Easy
43

Which Cisco product provides next-generation firewall (NGFW) capabilities, including application visibility and intrusion prevention?

Easy
44

A network administrator is configuring an ASA to enforce that traffic between two internal zones must be inspected by the firewall. Which security principle is being applied?

Hard
45

An attacker uses Shodan to discover internet-facing ICS devices and then performs banner grabbing. This is an example of which type of attack?

Easy
46

A network administrator wants to deploy security products that provide network-based intrusion prevention and advanced threat detection. Which TWO Cisco products are most suitable? (Choose two.)

Medium
47

A security analyst is investigating a potential insider threat. Which TWO indicators are most commonly associated with malicious insider activity? (Choose two.)

Medium
48

Which security model mandates that access decisions should be based on context, device posture, and user identity, and never trust any entity by default?

Medium
49

A PKI administrator needs to check the revocation status of a certificate without causing a heavy load on the CA. Which protocol should be used?

Hard
50

An attacker intercepts traffic between a client and server using ARP spoofing. Which type of attack is this?

Hard
51

In a PKI hierarchy, which component is responsible for issuing and revoking certificates for end entities, and is directly subordinate to the root CA?

Hard
52

An organization is adopting Cisco's security portfolio. Which THREE products are correctly paired with their primary function? (Choose three.)

Hard
53

A company's server is infected with malware that encrypts files and demands payment for decryption. Which type of malware is this?

Medium
54

Which authentication factor does a fingerprint scanner represent?

Easy
55

An organization implements a policy where every access request must be authenticated and authorized, even if it originates from within the internal network. Network segments are isolated, and lateral movement is restricted through microsegmentation. Which security model does this align with?

Hard
56

An organization wants to ensure that digital certificates issued by its internal CA are validated for revocation in real-time. Which protocol should be implemented to allow clients to check certificate status without downloading a full CRL?

Medium
57

A company deploys a solution that uses a root certificate authority (CA) and intermediate CAs to issue certificates. What is the term for the hierarchical structure of certificates from the root CA to the end entity?

Medium
58

A security engineer is configuring a Cisco Firepower NGFW to detect a buffer overflow attack. Which attack vector is this?

Hard
59

Which Cisco security product provides DNS-layer security to block malicious domains and cloud-based threats?

Easy
60

A security team is investigating a breach where the attacker gained access to a server using stolen credentials. Later, the attacker moved laterally and exfiltrated data. Which three security controls would best help detect and prevent lateral movement? (Choose three.)

Hard
61

A security analyst notices traffic from an internal host to an external IP address on port 4444, and the host's CPU is high. The host has been running unknown processes. Which type of malware is most likely involved?

Medium
62

A security analyst detects a DDoS attack targeting the company's web server. Which three attack types are classified as application layer attacks? (Choose three.)

Hard
63

Which Cisco product provides DNS-layer security to block malicious domains and prevent connections to malware command-and-control servers?

Easy
64

Which encryption algorithm is classified as symmetric?

Easy
65

A security analyst is investigating a potential ARP spoofing attack. Which two symptoms would indicate this type of attack?

Medium
66

Which three cryptographic algorithms are considered secure for use in modern systems? (Choose three.)

Medium
67

A security analyst notices unusual outbound traffic from an internal host to a known malicious IP address on TCP port 4444. The host is also exhibiting high CPU usage and running an unknown process. Which type of malware is most likely present?

Medium
68

A security analyst is reviewing logs and sees multiple failed login attempts from a single IP address, followed by a successful login. Which type of attack does this represent?

Easy
69

A security administrator is implementing a zero-trust architecture. Which two principles are core to the zero-trust model? (Choose two.)

Medium
70

A network administrator is configuring PKI for secure communications. Which TWO components are essential for a public key infrastructure? (Choose two.)

Easy
71

An organization is implementing a zero trust architecture. Which two principles are foundational to this model? (Choose two.)

Medium
72

A security analyst observes a sustained increase in traffic from many different IP addresses to a single web application, causing CPU spikes. The traffic consists of legitimate-looking HTTP GET requests for the same resource. Which TWO types of attack could this be? (Choose two.)

Medium
73

An organization implements multi-factor authentication requiring a password and a fingerprint scan. Which two authentication factors are being used?

Medium
74

Which Cisco security product is primarily designed to provide DNS-layer security by blocking requests to malicious domains?

Easy
75

An attacker uses ARP spoofing to intercept traffic between two devices on the same subnet. After successfully becoming a man-in-the-middle, the attacker can then perform which further attack to downgrade HTTPS connections to HTTP?

Medium
76

A security analyst is investigating a malware outbreak. Analysis reveals a remote access trojan (RAT) that communicates with a command-and-control (C2) server. Which TWO behaviors are typical of a RAT? (Choose two.)

Medium
77

Which cryptographic algorithm is considered deprecated and should be avoided due to known vulnerabilities, especially when used in digital signatures and certificate signing?

Easy
78

When a certificate is revoked, which protocol allows a client to check the revocation status in real-time without downloading a full CRL?

Medium
79

A security engineer is evaluating authentication methods. Which authentication factor category does a fingerprint scanner fall under?

Medium
80

Which symmetric encryption algorithm is considered the current standard and is often used in VPNs and SSL/TLS?

Easy

Frequently asked questions

What does the Security Concepts domain cover on the 350-701 exam?
Security Concepts questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 80 Security Concepts questions in the 350-701 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Security Concepts questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
Cisco SCOR / CCNP Security Core 350-701 Security Concepts Practice Questions