Courseiva

CCNA Application And Data Security Questions

46 questions · Application And Data Security · All types, answers revealed

1
Multi-Selecthard

Which TWO factors are critical when configuring an automated remediation workflow in Cisco Cloudlock to prevent data loss?

Select 2 answers
A.Action selection (e.g., Delete, Notify, Quarantine).
B.Manual user approval for every file deletion.
C.Hardware firewall throughput settings.
D.Policy trigger conditions (e.g., severity, file type).
E.Network bandwidth throttling configuration.
AnswersA, D

Correct. You must define the automated step to take.

Why this answer

Effective remediation requires an action (what to do) and a trigger condition (when to do it based on policy severity).

2
Multi-Selectmedium

Which TWO methods can Cisco Cloudlock use to notify an administrator of a policy violation?

Select 2 answers
A.Email notification
B.Physical alarm sound
C.Webhook integration
D.Automated phone call
E.SMS text message
AnswersA, C

Standard notification mechanism.

Why this answer

Cloudlock provides multiple notification channels, including email alerts and integration with webhooks/ticketing systems.

3
MCQeasy

Which feature in Cisco Cloudlock allows administrators to view a dashboard of users who are behaving outside of their normal baseline?

A.App Firewall
B.UBA
C.Policy manager
D.DLP engine
AnswerB

UBA is specifically designed for behavioral anomalies.

Why this answer

Cloudlock's UBA (User Behavior Analytics) module uses machine learning to establish a baseline and flag anomalies.

4
Multi-Selecthard

Which TWO actions can a user take if a file is quarantined by Cisco Cloudlock?

Select 2 answers
A.Move the file to another folder
B.Delete the original file directly
C.Change the file permissions
D.Read the tombstone file
E.Request a review
AnswersD, E

The user is notified via this file.

Why this answer

Quarantine moves the original file to a secure location and replaces it with a placeholder (tombstone) file; the user can typically only access the tombstone.

5
MCQmedium

When creating a policy in Cisco Cloudlock, what is the significance of setting a 'Threshold'?

A.To limit the total number of files scanned.
B.To define the minimum number of occurrences to trigger an alert.
C.To set the maximum file size for scanning.
D.To assign an expiration date to the policy.
AnswerB

Thresholds prevent false-positive alerts on single occurrences.

Why this answer

Thresholds allow you to define how many times a violation must occur (or how many instances of sensitive data are found) before an incident is triggered, reducing noise.

6
MCQeasy

What is the primary role of a Cloud Access Security Broker (CASB)?

A.To develop SaaS applications.
B.To enforce security policies between cloud users and cloud applications.
C.To manage physical server racks.
D.To provide internet connectivity.
AnswerB

Core definition of a CASB.

Why this answer

A CASB acts as a gatekeeper, sitting between users and cloud services to enforce security policies and monitor activity.

7
Multi-Selectmedium

Which TWO settings should be verified if a Cisco Cloudlock API connector to Google Workspace is showing a 'Warning' status?

Select 2 answers
A.Network bandwidth usage
B.Physical server cooling status
C.Service account permissions
D.API Token expiration
E.Local DNS server settings
AnswersC, D

Insufficient scopes will prevent the API from functioning.

Why this answer

Connector warnings usually stem from insufficient API permissions (scopes) or expired credentials/tokens.

8
MCQhard

A user is attempting to upload a file to a SaaS application, but the Cisco Umbrella Intelligent Proxy blocks it. What is the most effective way to troubleshoot the block?

A.Use the Umbrella Activity Search dashboard.
B.Reboot the client device.
C.Disable the browser cache.
D.Check the local host logs.
AnswerA

This dashboard identifies the policy that triggered the block.

Why this answer

The Umbrella Activity Search is the primary tool to see why a specific request (domain/URL) was blocked by policy.

9
MCQhard

You need to ensure that only corporate-managed devices can access Microsoft 365. Which component should be configured to verify the device's security posture before granting access?

A.Cisco Secure Firewall
B.Cisco Duo
C.Cisco Cloudlock
D.Cisco Umbrella
AnswerB

Duo performs posture checks (Trusted Endpoints) at login.

Why this answer

Duo's Device Health and Trusted Endpoint features specifically check for device management status before allowing access to applications.

10
MCQhard

An administrator needs to ensure that only managed devices can access sensitive data in Box. Which Cisco solution feature enables this verification?

A.SAML assertion mapping.
B.Cloudlock custom regex matching.
C.Secure Access device posture check.
D.OAuth token rotation.
AnswerC

Correct. Posture checking verifies device health before granting SaaS access.

Why this answer

Cisco Secure Access with device posture checks ensures that only devices meeting minimum security requirements can access defined SaaS applications.

11
MCQeasy

In Cisco Cloudlock, what is the purpose of an 'Incident'?

A.To record system uptime.
B.To manage app credentials.
C.To notify admins of a policy violation.
D.To backup user data.
AnswerC

Correct definition of an incident.

Why this answer

An incident is an alert generated when a specific policy rule is triggered by a user or data action within a protected SaaS app.

12
Multi-Selectmedium

Which THREE criteria can be used to classify a 'Shadow IT' application in Cisco Umbrella?

Select 3 answers
A.Volume of traffic
B.Category (e.g., File Sharing)
C.User's password hash
D.Device serial number
E.Risk level
AnswersA, B, E

High traffic volume often flags an app for review.

Why this answer

Shadow IT identification is based on traffic volumes, application category, and risk scores assigned by Umbrella.

13
MCQmedium

What is the primary function of the 'CASB' category in Cisco Umbrella's web policy?

A.To scan emails for malware.
B.To govern application usage and control data movement.
C.To filter malicious DNS queries.
D.To provide VPN connectivity to the cloud.
AnswerB

CASB controls enable granular governance of SaaS access.

Why this answer

The CASB category in Umbrella allows admins to enforce policies specifically for cloud applications, such as blocking uploads to unsanctioned tenants.

14
MCQmedium

You are configuring a Cisco Cloudlock policy to detect sensitive PII in a Salesforce instance. Which configuration step ensures that the policy specifically triggers when sensitive data is uploaded to a public-facing object?

A.Configure an API-based firewall rule to block all inbound traffic from Salesforce.
B.Apply a global blocklist for all Salesforce users.
C.Set the policy scan interval to 'Real-time' and enable TLS decryption.
D.Enable the PII inspection engine and set the exposure filter to 'Public'.
AnswerD

Correct. The exposure filter is the mechanism used to restrict policy enforcement to publicly accessible data.

Why this answer

Cisco Cloudlock allows scoping of policies to specific application objects and exposure levels. Selecting the 'Public' exposure flag ensures that only data accessible to unauthorized external users triggers the alert.

15
Multi-Selecthard

When configuring an OAuth policy in Cisco Cloudlock, which TWO actions can be taken against third-party applications granted access to user data?

Select 2 answers
A.Quarantine the application
B.Force an OS update on the app server
C.Revoke authorization
D.Update the app's source code
E.Enable two-factor authentication for the app
AnswersA, C

Quarantining restricts the app's scope until reviewed.

Why this answer

Cloudlock provides the ability to audit third-party app permissions and revoke them if the application is deemed risky.

16
Multi-Selecthard

When setting up a DLP policy for cloud storage, which TWO elements should be defined to ensure accurate classification of sensitive data?

Select 2 answers
A.Hardware acceleration settings.
B.Scope of the policy (e.g., specific folders or users).
C.Data patterns (e.g., regex, predefined templates).
D.SaaS application uptime SLAs.
E.Physical server rack location.
AnswersB, C

Correct. This limits the scan to the relevant data subset.

Why this answer

DLP policies rely on content inspection patterns (regex/keywords) and scope (the folders/apps) to function correctly.

17
Multi-Selectmedium

You are auditing a Cisco Cloudlock deployment for O365. Which TWO methods can be used to remediate a file that violates a Data Loss Prevention policy?

Select 2 answers
A.Delete the file
B.Block the user account in Active Directory
C.Change the file owner
D.Change sharing level to Private
E.Re-encrypt the file with a new key
AnswersA, D

Cloudlock can trigger a delete command via API to remove the sensitive document.

Why this answer

Cloudlock provides automated remediation actions including changing the permission level of the file or deleting the file entirely.

18
MCQeasy

Which feature in Cisco Cloudlock allows you to identify if a SaaS user is logging in from an anonymizer or TOR exit node?

A.SaaS application object mapping.
B.File content scanning.
C.Encryption key management.
D.User Behavior Analytics (UBA) anomaly detection.
AnswerD

Correct. UBA identifies impossible travel and suspicious login sources like TOR nodes.

Why this answer

Cisco Cloudlock's Threat Intelligence engine correlates user login logs with known malicious IP reputation lists.

19
MCQhard

You have configured a DLP policy in Cisco Cloudlock that flags files shared with external users. You notice files shared with 'Anyone with the link' are not being flagged. What is the most likely configuration error?

A.The scope of the policy is set to 'internal' only.
B.SSL inspection is not enabled.
C.The user is an administrator.
D.The API token for the SaaS has expired.
AnswerA

If the policy scope does not include public or link-based sharing, it will ignore those files.

Why this answer

Cloudlock policies require the specific permission level (e.g., 'Public' or 'Anyone with link') to be explicitly selected in the 'Exposure' criteria of the policy engine.

20
MCQmedium

You have detected a compromised account in Google Workspace via Cloudlock. Which automated response action can immediately prevent further data exfiltration from this user account?

A.Change user's DNS settings.
B.Delete the user's primary mailbox.
C.Suspend User account.
D.Clear browser cache for the user.
AnswerC

Correct. Suspending the account immediately revokes access to the SaaS app.

Why this answer

The 'Disable User' or 'Suspend User' action is the standard response to isolate a compromised identity and prevent further access.

21
Multi-Selectmedium

Which THREE actions can be performed by the Cisco Cloudlock UBA engine?

Select 3 answers
A.Monitor mass file download events
B.Perform port scanning
C.Flag logins at unusual times
D.Block outbound DNS requests
E.Detect impossible travel
AnswersA, C, E

Flags potential data exfiltration attempts.

Why this answer

UBA tracks user activity and can flag anomalies like impossible travel, mass file downloads, and unusual access times.

22
MCQmedium

In Cisco Cloudlock, why would you use a 'Custom Regex' pattern in a DLP policy?

A.To detect non-standard sensitive data formats.
B.To increase the storage limit.
C.To scan files faster.
D.To bypass file encryption.
AnswerA

Standard templates don't cover unique internal data.

Why this answer

Custom Regex patterns allow you to define organization-specific sensitive data formats, such as employee ID numbers or unique project code formats, that aren't in standard templates.

23
Multi-Selecthard

When configuring Cisco Duo for SaaS application access, which THREE conditions can be used in a 'Policy' to restrict access to a sensitive application?

Select 3 answers
A.File size limit
B.Operating System version
C.MFA strength
D.Geographic location
E.Application bandwidth usage
AnswersB, C, D

Duo checks if the OS is updated to meet security requirements.

Why this answer

Duo allows for granular access control based on user location, device security posture, and authentication methods.

24
MCQmedium

You are configuring a Cisco Cloudlock policy to detect sensitive data in a Salesforce environment. You need to identify instances where credit card numbers are shared publicly. Which specific policy category should you configure?

A.User Behavior Analytics
B.Data Exposure
C.Application Firewall
D.Threat Intelligence
AnswerB

Data Exposure policies in Cloudlock are designed to monitor and remediate public or external file/record sharing.

Why this answer

The Cisco Cloudlock Data Loss Prevention engine uses specific policy categories to identify PII/PCI data, and 'Data Exposure' is the correct category for monitoring sharing settings.

25
MCQmedium

To ensure compliance, you must ensure that all emails containing credit card numbers sent via O365 are encrypted. How is this achieved within the Cloudlock framework?

A.Configure a DLP policy to trigger an 'Apply Sensitivity Label' action.
B.Reset the user's password.
C.Enable TLS 1.3 for all outgoing mail.
D.Create a firewall rule to block the email.
AnswerA

Correct. This integrates with O365's Information Protection to trigger encryption.

Why this answer

Cloudlock policies can trigger automated actions such as applying sensitivity labels or encryption policies in the underlying SaaS application upon detecting sensitive content.

26
Multi-Selecthard

When configuring a Duo authentication policy for a SaaS app, which THREE device health indicators can be required?

Select 3 answers
A.Security software (AV) active
B.Monitor CPU utilization
C.Hard drive space capacity
D.OS version status
E.Full disk encryption enabled
AnswersA, D, E

Required for endpoint integrity.

Why this answer

Duo's policy engine can require that endpoints have disk encryption enabled, up-to-date operating systems, and activated security software.

27
Multi-Selectmedium

Which THREE factors influence the risk rating of an application in Cisco Umbrella's App Discovery tool?

Select 3 answers
A.Compliance certifications
B.Server location
C.Encryption support
D.Data protection standards
E.Number of employees
AnswersA, C, D

SOC2, ISO, etc., impact the score.

Why this answer

Risk ratings are calculated based on an application's data privacy policies, compliance certifications, and security features.

28
MCQmedium

In Cisco Umbrella, what is the primary purpose of defining a 'Cloud Application' in the 'App Discovery' dashboard?

A.To identify and govern Shadow IT usage across the enterprise.
B.To pre-authenticate users for that SaaS.
C.To increase bandwidth for authorized SaaS apps.
D.To bypass SSL inspection for the application.
AnswerA

The primary intent of App Discovery is to track and control unauthorized SaaS usage.

Why this answer

App Discovery allows administrators to see which shadow IT applications are in use and decide whether to block or monitor them via policy.

29
Multi-Selectmedium

Which THREE of the following are primary functions of a Cloud Access Security Broker (CASB) regarding application and data security?

Select 3 answers
A.Physical access control for data centers.
B.Local area network traffic routing.
C.Automated threat protection for user sessions.
D.Visibility into Shadow IT usage.
E.Enforcement of DLP policies in the cloud.
AnswersC, D, E

Correct. CASB detects and blocks malicious session activity.

Why this answer

CASB provides visibility, compliance, threat protection, and data security for cloud applications.

30
Multi-Selecthard

Which THREE items are included in a Cisco Cloudlock 'Incident' report?

Select 3 answers
A.BIOS version
B.Severity level
C.Policy name
D.User's home Wi-Fi SSID
E.User identity
AnswersB, C, E

Helps prioritize the response.

Why this answer

Cloudlock incidents provide detailed context including the user involved, the severity of the violation, and the specific file or resource affected.

31
MCQeasy

What is the primary benefit of deploying a 'Managed' SaaS application configuration in Cisco Umbrella?

A.Faster internet speed.
B.Granular policy enforcement and visibility.
C.Reduced cloud storage costs.
D.Automatic software updates.
AnswerB

This allows for specific control over SaaS usage.

Why this answer

Managed applications allow for granular visibility and enforcement policies to be applied specifically to those apps, as opposed to generic web traffic.

32
MCQhard

When configuring Cisco Umbrella for SaaS, how does SSL inspection impact the visibility of application traffic?

A.It blocks all encrypted traffic.
B.It decreases application performance.
C.It removes the need for DNS filtering.
D.It enables deep packet inspection of SaaS content.
AnswerD

Decryption is required for content-level inspection.

Why this answer

SSL inspection decrypts traffic, allowing the proxy to inspect the actual payload, which is essential for granular visibility and DLP enforcement within SaaS apps.

33
Multi-Selectmedium

When integrating Cisco Umbrella with a SaaS application, which TWO methods can be used to ensure secure user authentication?

Select 2 answers
A.SNMP monitoring
B.Local LDAP database
C.Duo MFA integration
D.WPA2-Enterprise
E.SAML integration with an IdP
AnswersC, E

Duo adds a second layer of verification for SaaS access.

Why this answer

Umbrella can work with IdPs (like Duo or Azure AD) to enforce SAML-based authentication and ensure consistent security posture.

34
MCQeasy

Which Cisco technology provides visibility and control over SaaS applications using API-based integration to inspect data at rest?

A.Cisco Cloudlock
B.Cisco Secure Firewall
C.Cisco Stealthwatch
D.Cisco Umbrella
AnswerA

Cloudlock uses APIs to scan data stored in cloud apps.

Why this answer

Cisco Cloudlock is an API-based CASB that monitors data at rest in SaaS applications by connecting directly to the cloud provider's APIs.

35
MCQhard

In a Cisco Secure Access environment, you are applying an application-layer policy to restrict access to a specific SaaS application based on the user's geolocation. Which tool is used to define this access control rule?

A.Cloudlock API Gateway.
B.Web Security Appliance (WSA) Filter.
C.Secure Access Policy rules.
D.Identity Services Engine (ISE) Policy Sets.
AnswerC

Correct. Access policies in Cisco Secure Access define the 'Who, Where, What' for application access.

Why this answer

Cisco Secure Access uses Access Policies that integrate with Identity and Context-Aware settings to enforce location-based access to SaaS applications.

36
Multi-Selectmedium

Which THREE types of information are typically displayed in the Cisco Umbrella 'App Discovery' report?

Select 3 answers
A.Risk Score
B.User's home address
C.Application Name
D.Traffic Volume
E.Application's source code
AnswersA, C, D

Helps assess the security posture of the app.

Why this answer

The App Discovery report provides insights into application categories, risk levels, and usage statistics per app.

37
MCQhard

When integrating Cisco Cloudlock with O365, which authentication mechanism is required to allow the CASB to perform administrative actions, such as removing a malicious file share?

A.LDAP over TLS.
B.SAML 2.0 with manual certificate import.
C.Basic Authentication over SSL.
D.OAuth 2.0 delegated permissions.
AnswerD

Correct. Cloudlock uses OAuth 2.0 to obtain tokens necessary for API operations on SaaS resources.

Why this answer

Cisco Cloudlock requires OAuth 2.0 scopes granted via an administrative consent process to perform actions on behalf of the application in the O365 tenant.

38
MCQmedium

You notice an employee is accessing a cloud app that is not approved by IT. Which Umbrella feature allows you to see this activity?

A.App Discovery
B.Activity Search
C.DNS Policy
D.SSL Inspection
AnswerA

Specifically designed to reveal shadow IT.

Why this answer

Shadow IT reporting within the App Discovery feature shows a list of applications accessed by users that have not been sanctioned by the IT department.

39
MCQhard

If you configure an API-based connector for a new SaaS app in Cisco Cloudlock, when does the initial scan typically begin?

A.At midnight, based on the system clock.
B.Only when the first user logs in.
C.After an administrator manually clicks 'Start'.
D.Immediately upon saving the configuration.
AnswerD

The scan initiates as soon as authorization is granted.

Why this answer

After the OAuth handshake and the 'Save' of the connector configuration, Cloudlock triggers an initial scan of the application's environment (e.g., all files in Google Drive).

40
Multi-Selectmedium

Which THREE mechanisms are commonly used by a CASB to enforce access control to SaaS applications?

Select 3 answers
A.Local host firewall rules.
B.Direct switch-to-server connection.
C.API-based integration.
D.Reverse Proxy.
E.Forward Proxy.
AnswersC, D, E

Correct. API allows granular policy enforcement.

Why this answer

CASB enforces access via API integration, forward proxy, and reverse proxy architectures.

41
MCQmedium

Which Cisco Cloudlock policy type should be used to detect when a user logs in from an unusual geographic location?

A.Data Exposure
B.Cross-platform threat
C.Application firewall
D.User Behavior Analytics
AnswerD

UBA monitors login patterns and locations.

Why this answer

User Behavior Analytics (UBA) specifically includes checks for 'Impossible Travel' and unusual login locations.

42
MCQmedium

Which component of Cisco's secure cloud access architecture is responsible for performing URL filtering and malware scanning on traffic destined for SaaS applications?

A.Cisco Secure Endpoint
B.Cisco Umbrella
C.Cisco Cloudlock
D.Cisco Adaptive Security Appliance
AnswerB

Umbrella performs URL filtering and proxying of web traffic.

Why this answer

Cisco Umbrella acts as a secure web gateway (SWG) to inspect traffic flow and perform URL filtering and malware analysis.

43
MCQhard

You are utilizing Cisco Umbrella to block access to unsanctioned SaaS apps. You want to allow access to O365 but restrict users to only your corporate tenant. Which feature should you enable?

A.URL filtering
B.DNS Layer Security
C.SSL Decryption
D.Tenant Restrictions
AnswerD

This is the standard mechanism to pin users to a corporate tenant.

Why this answer

Tenant Restrictions (often via headers) allow you to ensure that users can only log in to your specific organization's tenant for SaaS applications.

44
MCQeasy

Which term describes the unauthorized use of cloud applications by employees within an organization?

A.Zero Trust
B.Cloud-Native
C.Shadow IT
D.BYOD
AnswerC

Correct definition for unauthorized SaaS usage.

Why this answer

Shadow IT refers to applications or software used within an organization without explicit IT department approval.

45
Multi-Selectmedium

Which THREE data types are commonly supported by the Cisco Cloudlock DLP engine for pattern matching?

Select 3 answers
A.Unencrypted binary firmware images
B.Passport Numbers
C.System BIOS versions
D.Credit Card Numbers
E.Social Security Numbers
AnswersB, D, E

Passport numbers are supported under PII templates.

Why this answer

Cloudlock uses a wide variety of predefined regex and pattern matching templates for common sensitive data, including credit cards, social security numbers, and passport numbers.

46
MCQeasy

An administrator notices that sensitive data is being shared via Microsoft Teams. Where in the Cloudlock dashboard should they navigate to identify which specific users are sharing the files?

A.Platform > Users > Provisioning.
B.Platform > Settings > API Configuration.
C.Platform > Threat Intelligence.
D.Platform > Incidents dashboard.
AnswerD

Correct. The Incidents dashboard provides granular details on users and files involved in policy violations.

Why this answer

The 'Security Audit' or 'Incidents' dashboard provides a breakdown of users involved in data exposure incidents in SaaS applications like Teams.

Ready to test yourself?

Try a timed practice session using only Application And Data Security questions.