Courseiva

Cisco Designing Cisco Security Infrastructure (SDSI, 300-745, CCNP Security, design-focused) (SDSI) (SDSI) — Questions 175

298 questions total · 4pages · All types, answers revealed

Page 1 of 4

Page 2
1
MCQmedium

When designing for high availability, what is the role of the 'Heartbeat' mechanism in a Cisco firewall pair?

A.To authenticate users.
B.To sync firewall configurations.
C.To detect the failure of the peer unit.
D.To balance traffic load.
AnswerC

The heartbeat ensures timely detection of peer failure for failover.

Why this answer

The heartbeat signal allows the active unit to monitor the status of the standby unit.

2
MCQhard

A security architect is configuring a design for an enterprise with high-speed (100G) traffic. Which Cisco firewall solution is most appropriate?

A.Cisco Umbrella virtual appliance.
B.Cisco Firepower 1000 series.
C.Cisco AnyConnect.
D.Cisco Firepower 9300 series.
AnswerD

The 9300 is built for large enterprise and carrier-grade throughput.

Why this answer

Cisco Firepower 9300 appliances are designed for high-throughput, high-speed data center environments.

3
MCQhard

A security architect is designing a solution to block malicious URLs across all branch offices. Which Cisco feature provides the most efficient, scalable way to manage this across 500+ locations?

A.Cisco Umbrella cloud-delivered DNS filtering.
B.Cisco Stealthwatch.
C.Cisco Identity Services Engine (ISE).
D.Local URL filtering on each branch firewall.
AnswerA

Umbrella allows for global policy changes managed from a central dashboard.

Why this answer

Cisco Umbrella uses cloud-delivered DNS-based blocking, making it highly scalable compared to managing local firewall URL lists.

4
MCQeasy

A design requirement for a new SOC environment mandates that incident data must be centralized. Which Cisco tool is best suited to act as the single pane of glass for integrating disparate security logs and telemetry?

A.Cisco SecureX
B.Cisco Firepower Management Center (FMC)
C.Cisco Identity Services Engine (ISE)
D.Cisco Defense Orchestrator (CDO)
AnswerA

SecureX is the integration platform for security orchestration and visibility.

Why this answer

Cisco SecureX is designed as an open platform to aggregate data from multiple Cisco and third-party security products.

5
MCQmedium

What is the primary function of the 'AnyConnect' (Secure Client) profile?

A.To manage connection and security settings for the endpoint.
B.To act as an identity provider.
C.To store user credentials.
D.To monitor CPU usage on the host.
AnswerA

Profiles control the behavior and configuration of the client.

Why this answer

The profile defines the connection settings, server lists, and security policies for the client software.

6
MCQmedium

A security architect is designing a SIEM integration for a distributed enterprise. Which tool selection criteria best aligns with the requirement to support real-time correlation across disparate cloud and on-premises environments?

A.Choose tools that utilize a monolithic database structure to ensure data consistency.
B.Focus on tools that strictly utilize hardware-based packet capture for all telemetry.
C.Select tools based solely on the number of pre-built connectors available in the marketplace.
D.Prioritize tools that support native Common Event Format (CEF) ingestion and bidirectional API integrations.
AnswerD

CEF and robust API support ensure compatibility with diverse vendor products.

Why this answer

The ability to normalize logs from heterogeneous sources is critical for effective correlation in hybrid environments.

7
Multi-Selecthard

Which TWO methods are used to provide secure remote access for a mobile workforce? (Select 2)

Select 2 answers
A.FTP
B.Duo Access Gateway
C.Cleartext HTTP
D.AnyConnect VPN
E.Telnet
AnswersB, D

Provides secure, identity-aware access to applications.

Why this answer

Remote access is best handled by encrypted VPN tunnels (AnyConnect) or identity-centric access proxies (Duo Access Gateway).

8
MCQeasy

What is the primary benefit of 'Visibility' in the Cisco API Security architecture?

A.Automatic translation of API code
B.Reduction of API storage costs
C.Increased performance of the API calls
D.Identification of all APIs and shadow endpoints
AnswerD

Visibility's main goal is inventory and shadow API identification.

Why this answer

Visibility allows you to see all your API endpoints, including shadow APIs, which is the necessary first step for any security strategy.

9
Multi-Selecthard

Which TWO design principles should be followed when selecting a firewall architecture for a multi-cloud environment? (Select 2)

Select 2 answers
A.Physical firewalls for all cloud segments
B.Centralized management of policies
C.Using cloud-native firewalls only
D.Consistent feature set across physical and virtual
E.Deploying firewalls in a single region
AnswersB, D

Consistency is achieved by managing all firewalls via a single interface (FMC).

Why this answer

Multi-cloud designs require consistent policies and centralized management to ensure a uniform security posture.

10
MCQeasy

Which aspect of AI-driven security automation helps in 'Reducing Mean Time to Respond (MTTR)'?

A.Updating hardware firmware
B.Automated data correlation
C.Reducing network latency
D.Increasing developer training
AnswerB

Speeds up incident triage.

Why this answer

By automating the collection and correlation of data, AI reduces the manual time analysts spend investigating.

11
MCQhard

You are designing an automated pipeline for Cisco Secure Firewall. If a deployment fails, which mechanism ensures the configuration is reverted to the last known good state?

A.Terraform state rollback
B.Manual CLI restore
C.FMC Factory Reset
D.Automated snapshot deletion
AnswerA

Manages configuration versioning and state.

Why this answer

Using Terraform 'state' management or Ansible 'check mode' allows for rollback or verification before committing changes, preventing broken states.

12
MCQeasy

Which Cisco solution provides host-based visibility and protection against fileless malware?

A.Cisco Secure Endpoint.
B.Cisco ISE.
C.Cisco Secure Firewall.
D.Cisco Prime Infrastructure.
AnswerA

Secure Endpoint provides host-based protection and visibility.

Why this answer

Cisco Secure Endpoint (formerly AMP for Endpoints) uses behavioral analysis to detect fileless malware.

13
MCQmedium

You are implementing automated policy enforcement for Cisco Secure Access by Duo. Which API allows you to programmatically manage users and authentication settings?

A.Duo Web SDK
B.Duo Admin API
C.Duo Auth API
D.Duo Telemetry API
AnswerB

Allows for administrative automation.

Why this answer

The Duo Admin API is the standard for managing users, policies, and authentication programmatically.

14
MCQhard

In a hybrid work design, what is the advantage of using Cisco Umbrella's roaming client?

A.It replaces the need for a local firewall.
B.It provides consistent security coverage off-network.
C.It only works on internal corporate Wi-Fi.
D.It forces all traffic through a local DC.
AnswerB

The roaming client extends policy protection to the endpoint everywhere.

Why this answer

The roaming client ensures that security policies follow the device wherever it goes, regardless of the network connection.

15
MCQhard

Which security design decision is most critical when migrating an application to the cloud, specifically regarding API security?

A.Relying on the cloud provider's firewall
B.Maintaining a VPN tunnel to the on-premise data center
C.Disabling all API endpoints that are not internal
D.Implementing API security and identity-based access at the application layer
AnswerD

This is the core of modern cloud-native security.

Why this answer

When moving to the cloud, the perimeter dissolves. You must transition from perimeter-based security to a model that secures the APIs themselves, regardless of where they are accessed from.

16
MCQeasy

Which Cisco technology is used to ensure that only authorized users can connect to the network via guest portals?

A.Cisco Umbrella
B.Cisco ISE Guest Services
C.Cisco Firepower
D.Cisco Secure Endpoint
AnswerB

Guest services handle authentication and portal management.

Why this answer

Cisco ISE Guest Services provides captive portal functionality for self-service guest access.

17
MCQhard

A company is migrating to a SASE architecture using Cisco+ Secure Connect. Which component is responsible for the unified identity-based access control for remote users?

A.AnyConnect standalone VPN gateway.
B.Firepower Management Center cloud connector.
C.On-premises ISE cluster.
D.Cisco Duo integration within the Secure Connect platform.
AnswerD

Duo provides the necessary identity assurance and MFA within the SASE framework.

Why this answer

Cisco+ Secure Connect integrates Duo for identity verification and Cisco Umbrella for secure web gateway functions.

18
MCQmedium

An organization is modifying their architecture to meet new compliance requirements for logging. The design requires offloading logs from multiple Cisco Firepower sensors. What is the recommended destination for long-term audit storage?

A.Security Information and Event Management (SIEM)
B.Cisco ISE Node
C.Cisco Catalyst Center
D.Local flash memory on the sensor
AnswerA

SIEM systems are the industry standard for long-term audit storage and compliance reporting.

Why this answer

Cisco Secure Event Logs (via Syslog/eStreamer) are typically sent to a SIEM or Cisco Secure Cloud Analytics for long-term storage and compliance auditing.

19
Multi-Selecthard

Which THREE technologies enable network segmentation in a modern Cisco campus design?

Select 3 answers
A.Standard routing protocols without filters.
B.VRF-Lite.
C.Cisco TrustSec (SGTs).
D.Port forwarding.
E.VLANs.
AnswersB, C, E

VRFs provide L3 segmentation.

Why this answer

Segmentation is achieved through identity-based tags, virtualization, and VLAN isolation.

20
MCQmedium

An organization is performing a risk assessment for a new remote access design. They identify that the SOC currently lacks visibility into anomalous VPN session behavior. Which Cisco solution should the design incorporate to provide behavioral analytics for incident response tool selection?

A.Cisco Identity Services Engine
B.Cisco Umbrella
C.Cisco Secure Network Analytics
D.Cisco Secure Firewall Management Center
AnswerC

Secure Network Analytics uses behavioral modeling to detect threats that bypass traditional perimeter defenses.

Why this answer

Cisco Stealthwatch (now Secure Network Analytics) provides behavioral modeling to identify anomalies in encrypted traffic and VPN sessions, making it the correct tool for incident visibility.

21
MCQmedium

You are designing an API security layer for a public-facing web application. Which security control is most effective against 'Broken Function Level Authorization' (BFLA) attacks?

A.Rate limiting
B.Blocking traffic from known malicious IP addresses
C.Strict RBAC/ABAC authorization checks on every function
D.Encrypting all traffic with TLS 1.3
AnswerC

Enforcing access control at the function level is the direct fix for BFLA.

Why this answer

BFLA occurs when a user accesses functions they shouldn't. Proper authorization logic must be enforced at every API endpoint.

22
MCQhard

When designing an API security strategy using Cisco API Security, how should you address APIs that are currently using legacy authentication?

A.Force the legacy backend to support modern OAuth
B.Block all access to legacy APIs immediately
C.Use an API gateway to terminate modern authentication and proxy to the legacy backend
D.Ignore the legacy APIs as they are 'trusted'
AnswerC

This is the standard design for modernizing legacy API access.

Why this answer

You should use an API gateway to 'wrap' the legacy API, enforcing modern authentication (like OIDC/OAuth) at the gateway layer while the backend continues to use legacy auth.

23
MCQmedium

What is the benefit of using 'Identity-Based' microsegmentation in Cisco Secure Workload?

A.It requires less initial configuration
B.It relies on hard-coded firewall rules
C.It provides stable policies that persist through workload moves and scaling
D.It is only compatible with physical servers
AnswerC

Logical identity is stable even when the underlying infrastructure changes.

Why this answer

Identity-based segmentation uses metadata (like application name, service tier) which is permanent and logical, rather than transient attributes like IP addresses.

24
MCQhard

When designing security for a cloud-native architecture, why is it better to use an identity-based model instead of a network-based model for microsegmentation?

A.Because it is easier to implement IP-based rules
B.Because identity is always known to the network hardware
C.Because it doesn't require any policy configuration
D.Because identity is persistent while IP addresses are volatile
AnswerD

Stability is the core requirement for scalable security.

Why this answer

Identity is persistent; IP addresses are volatile in cloud-native environments, making network-based rules impossible to manage at scale.

25
MCQmedium

You are designing security for a multi-tier application. Why is it recommended to use a Service Mesh to manage the identity of microservices?

A.To simplify the management of IP addresses
B.To replace the need for firewalls
C.To increase the network throughput
D.To provide cryptographically verifiable workload identity
AnswerD

This is the basis for secure service-to-service communication.

Why this answer

A service mesh assigns a cryptographically verifiable identity (like an SPIFFE ID) to each service, which is essential for secure, authenticated communication.

26
MCQmedium

A design architect is updating an incident response strategy. What is the role of the 'Post-Incident Architecture Adaptation' phase?

A.To document the costs of the incident.
B.To identify and implement changes to prevent recurrence of the incident.
C.To discipline employees who caused the incident.
D.To update the network documentation for the next audit.
AnswerB

The primary role is to evolve the architecture based on lessons learned.

Why this answer

This phase ensures that identified gaps are closed and the infrastructure is hardened.

27
MCQeasy

What is the primary role of a 'Security Policy Engine' (e.g., Cisco Secure Firewall) within an automated data center architecture?

A.Application load balancing
B.Centralized policy enforcement
C.Server virtualization
D.DNS resolution
AnswerB

Consistency is vital in automation.

Why this answer

To enforce consistent security policies automatically across physical and virtual workloads.

28
MCQhard

For a high-availability firewall architecture, which design element is critical when utilizing a routed-mode configuration in a data center?

A.Configuring HSRP between firewall interfaces.
B.Implementing OSPF equal-cost multi-path (ECMP) for load balancing.
C.Using a virtual MAC address per interface.
D.Utilizing a dedicated stateful failover link between firewalls.
AnswerD

The failover link is required to sync connection tables and configurations.

Why this answer

Stateful failover ensures that session information is synchronized, preventing connection drops during a device swap.

29
MCQeasy

What is the primary purpose of conducting a risk assessment as part of the security design process?

A.To identify and prioritize security controls based on threat and vulnerability data.
B.To automate the patching of all network servers.
C.To ensure compliance with local labor laws.
D.To select the cheapest security hardware.
AnswerA

Risk assessment is the foundation for determining appropriate security measures.

Why this answer

Risk assessments identify vulnerabilities, threats, and asset values, allowing designers to prioritize security controls effectively.

30
MCQhard

You are designing a secure API gateway architecture using Cisco API Connectivity (part of the Cisco AppDynamics/Cisco Networking stack). To protect against OWASP Top 10 threats, which specific feature should be enabled on the API Gateway to validate request payloads?

A.Configure JSON/XML schema validation policies based on the imported OpenAPI specification.
B.Enable Basic Authentication for all API endpoints.
C.Deploy a WAF rule to block all traffic from unknown IP addresses.
D.null
E.Enable rate limiting on the gateway to prevent DoS attacks.
AnswerA

Schema validation is the industry-standard method to prevent malformed payloads and injection attacks.

Why this answer

Cisco API Connectivity solutions (often integrated with AppDynamics) use schema validation features to compare incoming JSON/XML payloads against predefined OpenAPI specifications to prevent injection and malformed request attacks.

31
Multi-Selecthard

Which THREE Cisco solutions support the 'Secure Work from Anywhere' concept?

Select 3 answers
A.Cisco Secure Client (AnyConnect).
B.Cisco Duo.
C.Physical desk phone only.
D.Manual VPN configuration files.
E.Cisco Umbrella.
AnswersA, B, E

Provides secure connectivity.

Why this answer

Remote work requires secure connectivity, identity management, and endpoint protection.

32
MCQeasy

A design requirements gathering phase identifies that users frequently access untrusted SaaS applications. Which Cisco solution should be included to mitigate data exfiltration risks?

A.Cisco Secure Firewall with IPS enabled.
B.Cisco Umbrella with CASB capability enabled.
C.Cisco AnyConnect VPN.
D.Cisco Identity Services Engine (ISE).
AnswerB

Umbrella CASB provides the necessary policy enforcement for SaaS applications.

Why this answer

Cisco Cloud Access Security Broker (CASB) functionality within Cisco Umbrella provides visibility and control over SaaS usage.

33
MCQhard

An organization is deploying an API that returns user financial records. Which security design pattern should be used to ensure that a user can only access their own records?

A.WAF signature-based blocking
B.Implementing an API Key for all users
C.Implement BOLA (Broken Object Level Authorization) checks in the application logic
D.Rate limiting
AnswerC

BOLA prevention is explicitly about validating that the user is authorized to access the specific object ID.

Why this answer

This requires object-level authorization checks, where the system validates that the authenticated user owns the requested record ID.

34
Multi-Selecthard

When designing for cloud-native API security, which TWO components are critical for ensuring visibility into API traffic? (Choose TWO)

Select 2 answers
A.Manual inspection of firewall rules
B.Disabling TLS for easier traffic analysis
C.API Gateway access logs
D.Physical network tap at the data center core
E.Traffic telemetry from the service mesh sidecars
AnswersC, E

Access logs are essential for visibility and forensics.

Why this answer

Visibility into APIs requires capturing traffic at the gateway and analyzing logs to map the flow and identify potential threats.

35
MCQhard

A security architect is designing an incident response workflow. Which action in the Cisco Secure Endpoint console would be most appropriate to perform if a 'Host Isolation' request fails during an active threat containment?

A.Clear the event logs in FMC
B.Reboot the Cisco Secure Endpoint server
C.Quarantine the host via Cisco ISE
D.Deploy a new firewall policy
AnswerC

ISE provides a fallback mechanism by changing the network access policy if the endpoint-level agent isolation fails.

Why this answer

If Host Isolation fails, the architect should utilize the 'Network Access Control' (ISE) integration to quarantine the endpoint via dynamic VLAN assignment or dACL change.

36
MCQmedium

Which Cisco product allows administrators to manage security policies across a multi-vendor firewall environment?

A.Cisco SecureX.
B.Cisco Defense Orchestrator (CDO).
C.Cisco ISE.
D.Cisco Firepower Management Center (FMC).
AnswerB

CDO is designed for policy management across multiple platforms.

Why this answer

Cisco Defense Orchestrator (CDO) supports management of Cisco and select third-party firewalls.

37
MCQmedium

A design team is integrating Cisco Secure Firewall with an existing SIEM. Which telemetry export format is best for comprehensive security analysis?

A.NetFlow
B.SNMP
C.eStreamer
D.ICMP
AnswerC

eStreamer is the preferred method for exporting rich security event data from FMC.

Why this answer

Cisco Secure Firewall supports eStreamer and Syslog, but eStreamer is the specialized protocol for granular security event data.

38
Multi-Selectmedium

Which TWO features assist in protecting the network control plane against DoS attacks?

Select 2 answers
A.Configuring static routing only.
B.Increasing interface speed.
C.Disabling all physical interfaces.
D.Control Plane Policing (CoPP).
E.Control Plane Protection (CPPr).
AnswersD, E

CoPP rate-limits traffic to the CPU.

Why this answer

Control plane security requires limiting CPU-bound traffic and filtering malicious sources.

39
MCQhard

In a Cisco Secure Firewall architecture, what is the purpose of the 'Intrusion Policy'?

A.To optimize routing paths.
B.To handle VPN authentication.
C.To identify and block malicious traffic based on pattern matching.
D.To manage firewall NAT rules.
AnswerC

Intrusion policies use Snort to identify threats.

Why this answer

The Intrusion Policy inspects traffic for exploits, vulnerabilities, and malware patterns based on Snort rules.

40
MCQeasy

When designing a SOC, the team identifies a need for centralized management of threat intelligence feeds. Which Cisco product is the primary repository for this function?

A.Cisco Adaptive Security Appliance
B.Cisco AnyConnect
C.Cisco Secure Firewall Management Center
D.Cisco Defense Orchestrator
AnswerC

FMC centrally manages threat intelligence feeds and applies them to security policies.

Why this answer

Cisco Talos Intelligence is the primary source, but Cisco Secure Firewall (FMC) or SecureX acts as the repository for consuming these feeds in a design.

41
MCQhard

A risk assessment reveals that internal servers are vulnerable to unauthorized access via SMB protocols. Which Cisco feature should be implemented on the internal switching infrastructure to mitigate this risk?

A.ACLs on the core switch.
B.Cisco Secure Endpoint scan.
C.Cisco TrustSec (SGTs).
D.Cisco Umbrella local policy.
AnswerC

SGTs provide tag-based segmentation that effectively blocks unauthorized SMB access between servers.

Why this answer

Cisco TrustSec/SGTs allow for segmentation that blocks lateral movement between servers, regardless of VLAN.

42
MCQeasy

A security architect is designing a Cisco Secure Firewall deployment for a multi-cloud environment. Which design approach provides the most consistent security policy enforcement across AWS and Azure?

A.Deploy individual local managers for each cloud provider.
B.Rely on native cloud-native security groups only.
C.Implement separate FTD instances with unique local access control lists.
D.Utilize Cisco Defense Orchestrator for centralized policy management.
AnswerD

CDO is designed for centralized visibility and policy consistency.

Why this answer

Cisco Defense Orchestrator (CDO) provides a unified management plane to maintain consistent policies across different cloud infrastructures.

43
MCQhard

When automating security with Cisco XDR, which component allows for the execution of arbitrary scripts on third-party security tools?

A.Cisco XDR Workflow Engine
B.Cisco XDR Threat Intel module
C.Cisco XDR Telemetry API
D.Cisco XDR Dashboard
AnswerA

Allows custom script integration.

Why this answer

The 'Cisco XDR Workflow Engine' allows for custom python/javascript scripts to be executed during an orchestration sequence.

44
MCQhard

When designing an automated remediation workflow for Cisco Secure Firewall, what is the specific function of the 'Cisco Secure Firewall REST API' in the context of threat intelligence feeds?

A.Encryption key rotation
B.Automated firmware flashing
C.Traffic scrubbing
D.Dynamic update of Network Objects
AnswerD

Allows automation of IP blacklisting/whitelisting.

Why this answer

The API allows for dynamic injection of IP or Domain lists into 'Network Objects' which are used in policy rules.

45
Multi-Selectmedium

Which THREE components are part of the Cisco Secure Firewall architecture? (Select 3)

Select 3 answers
A.Firepower Appliance
B.Cisco ISE
C.Firepower Management Center (FMC)
D.Firepower Threat Defense (FTD)
E.Cisco Stealthwatch
AnswersA, C, D

The hardware appliances execute the FTD software.

Why this answer

The architecture comprises the FMC (management), FTD (data plane), and the Firepower 4100/9300 or virtual appliances.

46
MCQeasy

Which Cisco product is specifically designed to provide visibility into encrypted traffic without the need for manual decryption?

A.Cisco Encrypted Traffic Analytics (ETA).
B.Cisco Identity Services Engine (ISE).
C.Cisco Stealthwatch.
D.Cisco Firepower IPS.
AnswerA

ETA uses machine learning to identify threats in encrypted traffic by observing metadata.

Why this answer

Cisco Encrypted Traffic Analytics (ETA) provides this capability.

47
Multi-Selecthard

Which THREE of the following are key AI/ML design considerations when selecting a security automation platform?

Select 3 answers
A.Number of employees on the vendor's team
B.Explainability and transparency (XAI)
C.API integration and extensibility
D.Local hardware GPU acceleration
E.Data quality and labeling
AnswersB, C, E

Necessary to understand why an alert was triggered.

Why this answer

Data quality, model transparency, and integration capabilities are critical for effective AI security.

48
MCQeasy

When designing security for SaaS applications, what is the primary benefit of an API-based CASB like Cisco Cloudlock over a proxy-based CASB?

A.Proxy-based is cheaper
B.API-based only works on-premises
C.API-based does not require routing user traffic through the CASB
D.Proxy-based is always faster
AnswerC

This is a major operational advantage for cloud-native setups.

Why this answer

API-based CASBs can monitor data at rest and provide deeper remediation without requiring users to route their traffic through a proxy, which is ideal for cloud-first environments.

49
MCQhard

In a multi-cloud design, which protocol is preferred for secure inter-site communication to support micro-segmentation?

A.VXLAN with SGTs.
B.Standard GRE.
C.VLAN tagging.
D.802.1Q.
AnswerA

VXLAN carries group-based policy information across the network.

Why this answer

VXLAN with SGT (Group-Based Policy) allows for consistent policy enforcement across multi-cloud and data center environments.

50
Multi-Selecthard

When designing microsegmentation policies in Cisco Secure Workload (Tetration) for a multi-tier application, which THREE factors must be considered to ensure traffic flow integrity?

Select 3 answers
A.Application dependency mapping
B.DHCP lease duration
C.Workload inventory classification
D.Infrastructure zone isolation
E.User identity mapping
AnswersA, C, D

Necessary to understand traffic requirements.

Why this answer

Tetration relies on application flow mapping, policy intent, and agent-based enforcement for microsegmentation.

51
Multi-Selecthard

Which THREE actions are recommended when designing a secure API architecture using Cisco API Security to mitigate OWASP API Top 10 threats? (Choose THREE)

Select 3 answers
A.Implement strict schema validation on all incoming API requests
B.Allow all API traffic to bypass authentication for performance
C.Disable all logging of API request headers
D.Monitor API traffic for anomalies that indicate data exfiltration
E.Deploy API Security to detect Broken Object Level Authorization (BOLA)
AnswersA, D, E

Schema validation prevents injections and malformed data.

Why this answer

Mitigation requires visibility, schema validation, and behavioral analysis to stop common attacks like BOLA and excessive data exposure.

52
MCQeasy

In a cloud-native environment, which Cisco solution provides visibility into vulnerabilities within the application code and runtime environment?

A.Cisco Secure Endpoint
B.Cisco Stealthwatch
C.Cisco Secure Malware Analytics
D.Cisco Secure Application for AppDynamics
AnswerD

This integrates security directly into the application runtime.

Why this answer

Cisco Secure Application for AppDynamics provides full-stack security observability including code vulnerabilities and runtime threats.

53
MCQmedium

You are designing security for a microservices environment. You want to ensure that if one service is compromised, it cannot easily move laterally to other services. What is the most effective architectural design choice?

A.Keep all services on the same VLAN
B.Implement microsegmentation between services
C.Disable all internal firewalls for better performance
D.Use a single shared database for all services
AnswerB

Microsegmentation is explicitly designed to stop lateral movement.

Why this answer

Microsegmentation restricts communication to only the necessary paths, preventing attackers from moving across the network.

54
MCQeasy

In the context of microsegmentation, what is the primary benefit of using a 'Whitelist' approach over a 'Blacklist' approach?

A.It improves performance of the underlying network
B.It provides a more secure, 'deny-all' default posture
C.It is easier to configure
D.It removes the need for security policies
AnswerB

Deny-all by default is the most secure posture.

Why this answer

A whitelist only allows known good traffic, providing a 'deny-all' default posture which is the cornerstone of a Zero Trust architecture.

55
MCQhard

In a multi-cloud design, which component is used to connect remote offices directly to the cloud provider while maintaining Cisco-level security?

A.Local NAT translation.
B.Cisco Secure Access Control Server (ACS).
C.Standard site-to-site IPsec tunnel.
D.Cisco SD-WAN Cloud OnRamp.
AnswerD

Cloud OnRamp automates the secure connectivity to cloud-hosted VPCs/VNets.

Why this answer

Cisco SD-WAN (Viptela) provides secure, optimized connectivity to cloud environments via Cloud OnRamp.

56
MCQeasy

What is the primary benefit of 'Shift Left' security in a DevSecOps pipeline?

A.Automated hardware deployment
B.Increased development speed
C.Elimination of security teams
D.Reduced remediation costs
AnswerD

Early detection is cheaper than post-production fixes.

Why this answer

Shifting security to the beginning of the development cycle lowers remediation costs and reduces risk exposure.

57
MCQmedium

When designing a network segmentation strategy using Cisco TrustSec, what is an SGT tag used for?

A.To map IP addresses to MAC addresses
B.To identify the VLAN ID
C.To configure port security
D.To enforce security policy based on identity
AnswerD

SGTs allow for group-based policy enforcement across the network.

Why this answer

SGTs are used as the source of truth in security group ACLs (SGACLs) to permit or deny traffic based on the tag value.

58
MCQeasy

What is the primary function of Cisco pxGrid in a network design?

A.To encrypt traffic.
B.To exchange security context and data between Cisco and third-party products.
C.To filter web traffic.
D.To manage physical hardware.
AnswerB

pxGrid is an open framework for sharing identity and security data.

Why this answer

Cisco pxGrid enables the exchange of context and data between different security platforms.

59
MCQmedium

In an AI-enhanced security design, what is 'Supervised Learning' primarily used for?

A.Classification of malicious vs. benign data
B.Predicting hardware failure
C.Automated documentation generation
D.Unsupervised clustering of anomalies
AnswerA

Requires labeled training data.

Why this answer

Supervised learning models are trained on labeled datasets to classify new, incoming traffic or files as 'malicious' or 'benign'.

60
MCQeasy

When designing a remote access VPN solution using Cisco AnyConnect, which protocol is preferred to optimize performance for latency-sensitive applications like VoIP?

A.DTLS
B.TLS
C.IPsec IKEv2
D.SSTP
AnswerA

DTLS provides a low-latency connection suitable for real-time traffic.

Why this answer

DTLS (Datagram Transport Layer Security) is preferred for performance as it uses UDP, reducing the overhead and latency associated with TCP-based TLS.

61
MCQmedium

A security architect is designing a DR strategy. Which feature of Cisco Secure Firewall ensures that configurations are synchronized between primary and backup units in a high-availability pair?

A.Cisco Secure Firewall Failover Link.
B.Cisco Defense Orchestrator auto-sync.
C.Cisco Identity Services Engine RADIUS sync.
D.Cisco FMC policy deployment.
AnswerA

The failover link is the physical connection used to sync state and config.

Why this answer

Stateful failover ensures configuration and session state synchronization.

62
MCQmedium

A security architect is designing a remote-work solution. What is the benefit of using Split Tunneling in Cisco Secure Client?

A.It provides dual authentication layers for the user.
B.It encrypts only the authentication phase of the VPN connection.
C.It allows internal traffic to be routed over the VPN while local traffic bypasses it.
D.It enforces all traffic through the corporate firewall.
AnswerC

Split tunneling optimizes performance by offloading non-corporate traffic.

Why this answer

Split tunneling allows trusted internet traffic to bypass the VPN, reducing latency and bandwidth load on the headend gateway.

63
Multi-Selectmedium

Which THREE criteria are used during the 'Requirements Gathering' phase of a secure architecture design?

Select 3 answers
A.Existing network topology and traffic flow patterns.
B.Throughput and latency requirements for critical applications.
C.The personal email addresses of the network staff.
D.Business objectives and compliance requirements.
E.The color of the hardware rack units.
AnswersA, B, D

You must understand the current state.

Why this answer

Design must be based on business goals, performance needs, and existing architecture.

64
MCQmedium

In an AI-based security architecture, which data source provides the most value for training an ML model to detect unauthorized data exfiltration?

A.NetFlow/IPFIX logs
B.User password history
C.System process logs
D.DHCP lease logs
AnswerA

Metadata is the key to identifying exfiltration.

Why this answer

Flow logs (NetFlow/IPFIX) provide the metadata (source, destination, volume) required to detect exfiltration patterns.

65
MCQhard

For a zero-trust architecture, what is the primary function of Cisco ISE?

A.Managing user passwords.
B.Packet filtering at the edge.
C.Acting as a Policy Decision Point (PDP) for access control.
D.Automating WAN path selection.
AnswerC

ISE evaluates the policy and provides the access decision.

Why this answer

ISE acts as the Policy Decision Point (PDP) in a zero-trust architecture, validating identity and context before granting access.

66
MCQhard

When designing an API strategy, what is the 'API Contract' and why is it important for security?

A.A password file for the API
B.A technical specification that allows for automated schema validation and security enforcement
C.A legal document for the API usage
D.A file that lists all allowed IP addresses
AnswerB

Schema validation is a key security defense.

Why this answer

The API contract defines how the API behaves and what it accepts. Security uses this contract for schema validation to block malformed requests.

67
Multi-Selectmedium

Which THREE factors should be considered when designing a security approach for a hybrid work model? (Select 3)

Select 3 answers
A.Physical security of the home office
B.Multi-factor authentication (MFA)
C.VLAN mapping for home routers
D.Direct internet access security
E.Endpoint posture assessment
AnswersB, D, E

MFA is essential for verifying remote user identity.

Why this answer

Hybrid work requires protecting the identity, the endpoint, and the remote access method simultaneously.

68
MCQmedium

You are automating Cisco Secure Firewall policies. Why is 'Version Control' (e.g., Git) considered a security control?

A.Automatically encrypts all traffic
B.Increases bandwidth
C.Replaces the need for a firewall
D.Provides audit trails and change history
AnswerD

Accountability is a security requirement.

Why this answer

It provides a source of truth, audit trail, and the ability to revert unauthorized or malicious configuration changes.

69
Multi-Selectmedium

Which TWO strategies are recommended for securing a cloud-native SaaS environment?

Select 2 answers
A.Duo MFA integration.
B.CASB implementation.
C.Opening all firewall ports.
D.Storing passwords in clear text.
E.Disabling all logging.
AnswersA, B

Identity is the perimeter for SaaS.

Why this answer

SaaS security focuses on identity and data protection.

70
Multi-Selectmedium

Which THREE of the following represent common challenges when implementing automated security in a legacy environment?

Select 3 answers
A.Cultural resistance to change
B.Too much documentation
C.Excessive API performance
D.Fragmented or inconsistent log data
E.Lack of native API support in legacy devices
AnswersA, D, E

People are often the biggest barrier.

Why this answer

Lack of APIs, fragmented data, and organizational resistance are common barriers.

71
MCQmedium

When designing security for a microservices architecture, why should you implement a 'Zero Trust' approach at the service level?

A.To rely solely on network perimeter security
B.To ensure that every service-to-service call is authenticated and authorized
C.To increase the latency of inter-service communication
D.To simplify the management of firewall rules
AnswerB

Zero Trust mandates this to prevent unauthorized lateral movement.

Why this answer

Zero Trust assumes the network is compromised, requiring explicit authentication and authorization for every request, regardless of origin.

72
MCQeasy

Which design principle helps minimize the impact of a compromised API key?

A.Hard-coding keys in the source code
B.Rotating keys frequently
C.Using long-lived static API keys
D.Sharing a single key among all users
AnswerB

Frequent rotation is a standard security practice to limit exposure.

Why this answer

By rotating keys frequently and using short-lived tokens, you minimize the window of opportunity for an attacker to use a leaked key.

73
MCQmedium

When designing a firewall architecture for a high-security zone, which inspection mode is required to identify malware within encrypted payloads?

A.Passive logging mode.
B.SSL/TLS Decryption and Inspection.
C.Bypass inspection mode.
D.Layer 3 routing mode.
AnswerB

Decryption is mandatory for inspecting encrypted payloads.

Why this answer

SSL/TLS decryption and inspection (formerly called inspection) are required to see inside encrypted traffic for malware signatures.

74
Multi-Selecteasy

Which TWO of the following are common benefits of using API-based security automation?

Select 2 answers
A.Automatic removal of all vulnerabilities
B.Unlimited system memory
C.Consistent enforcement across infrastructure
D.Elimination of all human security analysts
E.Increased deployment speed
AnswersC, E

Reduces human error and configuration drift.

Why this answer

Increased speed and consistent enforcement are the two primary benefits.

75
Multi-Selecthard

Which THREE design principles are key for a multi-cloud security strategy?

Select 3 answers
A.Using different security tools for each cloud.
B.Consistent security policies across environments.
C.Allowing all cross-cloud traffic.
D.Unified threat visibility.
E.Centralized management plane (FMC).
AnswersB, D, E

Policies must be uniform to prevent gaps.

Why this answer

Multi-cloud security relies on centralized management, consistent policy, and visibility.

Page 1 of 4

Page 2

All pages