Courseiva

Cisco Designing Cisco Security Infrastructure (SDSI, 300-745, CCNP Security, design-focused) (SDSI) (SDSI) — Questions 226298

298 questions total · 4pages · All types, answers revealed

Page 3

Page 4 of 4

226
MCQmedium

You are designing a microsegmentation strategy using Cisco Secure Workload (formerly Tetration) for a multi-tier application. Which mechanism allows you to enforce fine-grained security policies between application tiers while maintaining visibility across the hybrid cloud?

A.Applying static ACLs on the core switch
B.Using policy-based agents on endpoints to enforce segmentation
C.Implementing Cisco ASA zone-based firewalling
D.Configuring VRF-Lite on the distribution layer
AnswerB

Secure Workload agents enforce policies directly at the workload level, enabling true microsegmentation.

Why this answer

Cisco Secure Workload uses software agents on endpoints to enforce microsegmentation policies based on workload identity, rather than IP addresses.

227
Multi-Selectmedium

Which THREE items should be included in a 'Security Design Requirements' document?

Select 3 answers
A.The preferred color scheme for the SOC monitors.
B.List of all potential threat actors and their motivations.
C.Latency requirements for critical business applications.
D.The salary information of the security team.
E.Regulatory compliance requirements (e.g., GDPR, HIPAA).
AnswersB, C, E

Understanding the threat profile is a core requirement.

Why this answer

Design requirements must cover performance, threat vectors, and compliance standards.

228
MCQeasy

What is the primary role of Cisco Secure Firewall in a network design?

A.To act as a core network switch.
B.To manage user credentials.
C.To provide internet access for all users.
D.To provide traffic inspection, filtering, and access control.
AnswerD

These are the core security functions of an NGFW.

Why this answer

The firewall acts as the perimeter defense, providing traffic control and inspection.

229
MCQmedium

A security architect is adapting a design post-incident after a credential theft event. Which Cisco ISE feature should be integrated into the architecture to mitigate the risk of compromised static credentials?

A.Deploying Cisco pxGrid to share user identity info with the firewall.
B.Configuring Cisco TrustSec to segment user traffic based on IP address.
C.Implementing Cisco AnyConnect Device Posture assessment.
D.Enabling MFA integration with Cisco Duo via RADIUS.
AnswerD

Duo integration with ISE provides MFA for network access, mitigating static credential risk.

Why this answer

Cisco ISE supports Multi-Factor Authentication (MFA) integration via RADIUS/TACACS+ to mitigate credential theft risk.

230
MCQhard

Which tool provides visibility into encrypted traffic without full decryption in a Cisco network design?

A.Cisco Encrypted Traffic Analytics (ETA).
B.Cisco Firepower IPS.
C.Cisco Identity Services Engine (ISE).
D.Cisco Stealthwatch.
AnswerA

ETA uses metadata to identify threats in encrypted traffic.

Why this answer

Cisco Encrypted Traffic Analytics (ETA) analyzes metadata in encrypted traffic.

231
MCQhard

You are designing a secure API architecture where services are deployed in Kubernetes. You need to enforce authentication and rate limiting at the ingress. Which tool should be used for centralized policy enforcement?

A.An API Gateway integrated into the Ingress Controller
B.Using IP-based ACLs on the Kubernetes node
C.Hard-coding auth logic into every microservice
D.Cisco Secure Firewall running in transparent mode
AnswerA

Modern API architectures use the Ingress/Gateway layer for centralized security policy enforcement like rate limiting and JWT verification.

Why this answer

Cisco API Connectivity Manager (ACM) or an API Gateway integrated with the Ingress Controller handles centralized auth, rate limiting, and observability.

232
MCQeasy

What is the primary goal of implementing microsegmentation in an enterprise data center?

A.To prevent lateral movement of attackers
B.To increase bandwidth capacity
C.To simplify the network topology
D.To reduce the number of servers required
AnswerA

Stopping lateral movement is the fundamental security goal of microsegmentation.

Why this answer

The primary goal is to isolate workloads and prevent lateral movement of attackers in the event of a breach.

233
MCQmedium

A design architect is updating an incident response strategy. What is the role of the 'Post-Incident Architecture Adaptation' phase?

A.To document the costs of the incident.
B.To update the network documentation for the next annual audit.
C.To discipline employees who caused the incident.
D.To identify and implement changes to prevent recurrence of the incident.
AnswerD

The primary role is to evolve the architecture based on lessons learned.

Why this answer

This phase ensures that identified gaps are closed and the infrastructure is hardened to prevent recurrence.

234
MCQhard

You are designing security for a SaaS application integrated via Cisco Cloudlock. Which mechanism allows you to detect anomalous data sharing behavior within Google Workspace?

A.Cisco Umbrella roaming client
B.Cisco ISE Profiling
C.Cloudlock API-based CASB integration
D.Cisco Secure Firewall NAT
AnswerC

Cloudlock connects via API to SaaS platforms to monitor data activity.

Why this answer

Cloudlock uses API-based CASB integration to monitor activity and detect anomalies like abnormal file sharing patterns.

235
MCQhard

Following a major data exfiltration incident, the design team needs to adapt the architecture to prevent lateral movement. Which Cisco Secure Firewall design modification is most effective for mitigating this risk while maintaining operational performance?

A.Enable all IPS signatures in blocking mode
B.Transition to transparent mode
C.Increase firewall inspection timeouts
D.Implement SGT-based micro-segmentation
AnswerD

SGTs provide identity-based segmentation that travels with the traffic, preventing lateral movement regardless of IP subnet.

Why this answer

Implementing micro-segmentation using TrustSec SGTs within the firewall policy allows for granular control based on identity, which is more effective against lateral movement than standard IP-based filtering.

236
MCQmedium

An organization is updating its SOC incident response toolset. Which Cisco technology provides the ability to perform 'retrospective security' by tracking files that have entered the network in the past?

A.Cisco Secure Network Analytics (Stealthwatch).
B.Cisco Firepower IPS.
C.Cisco Secure Endpoint (AMP).
D.Cisco Umbrella.
AnswerC

AMP tracks file disposition changes and alerts on previously 'clean' files that later become malicious.

Why this answer

Cisco Secure Endpoint (formerly AMP for Endpoints) performs retrospective analysis by continuously monitoring file activity over time.

237
Multi-Selectmedium

Which THREE design components are required for a successful implementation of Cisco TrustSec? (Select 3)

Select 3 answers
A.Cisco ISE
B.Scalable Group Tags (SGTs)
C.DHCP Snooping
D.Cisco Umbrella
E.Network Access Devices (NADs)
AnswersA, B, E

ISE is the policy engine that assigns the tags.

Why this answer

TrustSec requires the identity source (ISE), the enforcement points (switches/APs/firewalls), and the tags themselves.

238
MCQmedium

A security design requires that all outbound traffic be inspected for malware. Which Cisco solution feature should be included to achieve this at the DNS layer?

A.Cisco AnyConnect VPN tunnel.
B.Cisco Identity Services Engine.
C.Cisco Secure Firewall IPS.
D.Cisco Umbrella DNS-layer security.
AnswerD

Umbrella performs DNS filtering and malware blocking at the DNS resolution stage.

Why this answer

Cisco Umbrella provides DNS-layer security by preventing connections to known malicious domains.

239
MCQmedium

Following a ransomware incident, an architect must modify the network segmentation strategy. What is the most effective approach to mitigate lateral movement using Cisco TrustSec?

A.Deploy extended ACLs on every core switch port to block peer-to-peer traffic.
B.Configure static port-security across the entire enterprise to prevent unauthorized devices.
C.Implement SGT-based micro-segmentation at the access layer to enforce policies based on identity rather than IP.
D.Transition all physical cabling to private VLANs without leveraging SGTs.
AnswerC

SGTs provide identity-based access control, effectively restricting lateral movement.

Why this answer

TrustSec SGTs (Scalable Group Tags) allow for dynamic policy enforcement regardless of IP address, making it ideal for mitigating lateral movement.

240
Multi-Selectmedium

Which THREE of the following are key features of Cisco XDR (formerly SecureX) in an automated pipeline?

Select 3 answers
A.Workflow orchestration
B.Incident management and response
C.Threat intelligence aggregation
D.Automated server patching
E.Network packet capture hardware
AnswersA, B, C

Core component of the platform.

Why this answer

Orchestration, threat intelligence, and incident management are core XDR features.

241
MCQmedium

Which risk assessment methodology is best suited to guide a design modification for a cloud-native architecture relying on Cisco Secure Cloud Analytics?

A.ISO 27002 implementation guide.
B.OWASP Top 10 for all infrastructure components.
C.PCI-DSS compliance checklist.
D.NIST SP 800-30 for conducting the assessment.
AnswerD

NIST 800-30 provides the structure for identifying, assessing, and mitigating risks in IT systems.

Why this answer

NIST SP 800-30 is a standard for conducting risk assessments that inform architectural security controls.

242
MCQeasy

Which Cisco solution provides DNS-layer security to prevent users from connecting to malicious domains?

A.Cisco Stealthwatch.
B.Cisco Umbrella.
C.Cisco ASA Firewall.
D.Cisco Secure Endpoint.
AnswerB

Umbrella provides the DNS-layer security.

Why this answer

Cisco Umbrella uses DNS filtering to block requests to known malicious domains at the resolution layer.

243
MCQmedium

A security architect is designing a SOC response workflow using Cisco SecureX Orchestration. Which mechanism is most effective for automated remediation of an endpoint identified as compromised via Cisco Secure Endpoint?

A.Triggering a workflow that executes the isolate endpoint action in Cisco Secure Endpoint via API.
B.Deploying an umbrella policy change to redirect the host traffic to a sinkhole.
C.Configuring a local script on the Cisco ASA to block the host IP address.
D.Using Cisco Defense Orchestrator to push a new access control policy to the endpoint.
AnswerA

This is the native capability for programmatic remediation in SecureX.

Why this answer

Cisco SecureX Orchestration uses workflow automation to link threat intelligence from Secure Endpoint to automated containment actions like isolation.

244
MCQmedium

Which design principle should be followed when implementing micro-segmentation in a data center?

A.Segment based only on IP addresses.
B.Disable all firewalls for maximum performance.
C.Implement identity-based segmentation at the workload level.
D.Keep all servers in the same VLAN for simplicity.
AnswerC

This is the most effective approach for micro-segmentation.

Why this answer

Identity-based segmentation provides the most granular control at the workload level.

245
MCQmedium

Why is 'Behavioral Analysis' a critical component of Cisco API Security?

A.To speed up the API processing
B.To reduce API storage requirements
C.To replace the need for API documentation
D.To detect anomalous and signature-less threats
AnswerD

Detecting anomalies is the primary benefit of behavioral analysis.

Why this answer

Behavioral analysis allows the tool to identify attacks that do not match known signatures, such as a user accessing endpoints in a sequence that indicates a BOLA attack.

246
Multi-Selectmedium

Which TWO of the following are true about 'Policy as Code' in Cisco security infrastructure?

Select 2 answers
A.Policies are stored in version control systems
B.Policies are always written in assembly language
C.Policies are automatically applied without review
D.Policies are only for cloud-native apps
E.Policies can be validated with automated tests
AnswersA, E

Essential for tracking changes.

Why this answer

It promotes version control and allows for automated testing of policies.

247
MCQeasy

What is the primary goal of the 'Requirement Gathering' phase in the Cisco security design process?

A.To install the hardware.
B.To define the business and technical requirements for the security system.
C.To document the budget only.
D.To troubleshoot existing issues.
AnswerB

This is the core purpose of requirements gathering.

Why this answer

To define the business and technical objectives that the security design must meet.

248
MCQeasy

A security designer is choosing a firewall architecture for a high-throughput data center core. Which Cisco Firewall platform is purpose-built for this requirement?

A.Cisco Firepower 4100/9300 Series
B.Cisco Meraki MX
C.Cisco Firepower 1010
D.Cisco ASA 5506-X
AnswerA

These units are modular and optimized for data center throughput.

Why this answer

The Cisco Firepower 9300 or 4100 series is designed for data center environments requiring high throughput and low latency.

249
MCQhard

When designing a multi-cloud CI/CD security architecture, how should secrets (API keys for Cisco FMC) be managed to ensure compliance?

A.Embed as environment variables in the build runner
B.Encrypt with base64 and store in Git
C.Use a dedicated Secret Management service
D.Hardcode in the Terraform provider block
AnswerC

Ensures secrets are rotated and encrypted.

Why this answer

Secrets must be stored in a dedicated vault (like HashiCorp Vault or AWS Secrets Manager) and never in code repositories.

250
Multi-Selecthard

Which TWO design considerations are critical for a secure management plane for Cisco networking devices? (Select 2)

Select 2 answers
A.Enabling HTTP for the Web GUI
B.Implementing ACLs on VTY lines
C.Disabling the console port
D.Using SNMPv1
E.Using SSH instead of Telnet
AnswersB, E

This restricts management access to known IP addresses.

Why this answer

Management plane security requires limiting access to the device and ensuring the protocols used are encrypted.

251
Multi-Selecthard

When designing a secure API environment, which THREE threat categories should be prioritized for detection by Cisco API Security? (Choose THREE)

Select 3 answers
A.Broken Object Level Authorization (BOLA)
B.Excessive Data Exposure
C.Broken Authentication
D.Local fiber optic cable breaks
E.Standard server hardware failures
AnswersA, B, C

BOLA is a top-priority API threat.

Why this answer

API security focuses on common threats like BOLA, excessive data exposure, and broken authentication.

252
MCQmedium

You are designing microsegmentation for a Kubernetes cluster using Cisco Tetration (Secure Workload). Which specific architectural component must be deployed within the Kubernetes worker nodes to enforce policy without relying on external firewall hairpining?

A.Cisco ASA Virtual Appliance
B.Secure Workload Software Agent
C.Cisco Nexus Dashboard Orchestrator
D.Cisco Firepower Management Center
AnswerB

The agent performs enforcement at the host level.

Why this answer

The Secure Workload software agent (or sensor) is deployed on host nodes to enforce policy at the vSwitch or kernel level, enabling microsegmentation directly at the workload.

253
MCQhard

A security design architect needs to ensure that all endpoints have the latest malware signatures. Which tool provides continuous, automated updates?

A.Cisco Secure Firewall.
B.Cisco ISE.
C.Cisco Secure Endpoint.
D.Cisco Umbrella.
AnswerC

Secure Endpoint receives automatic updates from the cloud (Talos).

Why this answer

Cisco Secure Endpoint automatically updates its malware definitions from Cisco Talos.

254
MCQmedium

A security architect is developing a requirements document for a SOC. Which Cisco capability allows the SOC to prioritize alerts by correlating threats across network, endpoint, and cloud?

A.Cisco SecureX cross-product correlation.
B.Cisco Stealthwatch alert grouping.
C.Cisco Secure Firewall management center alert correlation.
D.Cisco Identity Services Engine monitoring.
AnswerA

SecureX integrates telemetry across the Cisco security portfolio for unified correlation.

Why this answer

Cisco SecureX provides cross-product correlation to reduce alert fatigue and prioritize incidents.

255
MCQmedium

Which Cisco product is best for enforcing security policy based on the user's AD group membership?

A.Cisco Umbrella.
B.Cisco Secure Firewall.
C.Cisco Identity Services Engine (ISE).
D.Cisco Stealthwatch.
AnswerC

ISE is the central engine for AD-integrated group-based policy.

Why this answer

Cisco ISE integrates with Active Directory to apply policies based on AD group memberships.

256
MCQmedium

What is the primary design benefit of deploying Cisco Secure Workload as a 'software-only' solution in a public cloud environment?

A.It reduces the need for VPC configuration
B.It guarantees 100% protection against all malware
C.It provides consistent security enforcement without relying on physical network appliances
D.It automates the creation of virtual machines
AnswerC

This is the primary benefit of software-based, agent-driven security.

Why this answer

It allows the organization to utilize native cloud features while maintaining consistent security policy across clouds without the latency of hair-pinning traffic to a physical appliance.

257
MCQmedium

Which risk assessment technique involves evaluating the impact of an attack on the confidentiality, integrity, and availability of an asset?

A.CIA Triad Impact Assessment.
B.SWOT Analysis.
C.Network Penetration Testing.
D.Cost-Benefit Analysis.
AnswerA

This technique assesses security impact on Confidentiality, Integrity, and Availability.

Why this answer

CIA Triad assessment is a standard risk evaluation methodology.

258
MCQmedium

You are designing security for a SaaS application integrated with Cisco Cloudlock. A user is persistently attempting to share sensitive documents with external parties. Which Cloudlock feature should be applied to remediate this?

A.Implement MFA for the SaaS login portal
B.Enable Cisco Umbrella DNS-layer protection
C.Create a policy to automatically unshare files containing PII with external collaborators
D.Configure an API Key for the SaaS platform
AnswerC

Cloudlock policies can be configured to detect PII and automatically remove external share links.

Why this answer

Cloudlock allows for automated remediation policies that can revoke sharing permissions based on document sensitivity labels or user behavior.

259
MCQhard

When conducting a risk assessment, what is the best way to determine the value of an asset to the organization?

A.Perform a Business Impact Analysis (BIA).
B.Check the manufacturer's list price.
C.Ask the IT department for their opinion.
D.Check the hardware replacement cost.
AnswerA

BIA identifies the critical impact of losing an asset on business operations.

Why this answer

The business impact analysis (BIA) is the standard method for determining asset value.

260
MCQmedium

What is the primary architectural benefit of deploying an API Gateway in a microservices environment?

A.It centralizes security and policy enforcement for all services
B.It makes all internal services public-facing
C.It eliminates the need for service-to-service security
D.It provides data storage for the microservices
AnswerA

Centralization is the primary benefit.

Why this answer

An API Gateway acts as a single entry point, allowing you to centralize security policies like authentication, rate limiting, and observability.

261
Multi-Selecthard

Which TWO identity-based design considerations are critical for secure endpoint access? (Select 2)

Select 2 answers
A.Device posture validation
B.Port security configuration
C.Disabling DHCP
D.Physical cabling security
E.Multi-factor authentication
AnswersA, E

Posture check ensures the device meets security requirements.

Why this answer

Endpoints must be verified via posture (is it safe?) and identity (is the user allowed?) to grant access.

262
Multi-Selectmedium

Which TWO factors must be considered when designing a Secure Remote Access VPN architecture for a hybrid workforce using Cisco AnyConnect?

Select 2 answers
A.Integration with Duo Security for multi-factor authentication.
B.Physical port density on the headend device.
C.The use of DTLS for latency-sensitive traffic.
D.Configuring internal DNS servers for split-tunneling.
E.Maximum supported concurrent user sessions on the ASA or FTD.
AnswersA, E

MFA is a mandatory security design component.

Why this answer

The number of concurrent sessions and the integration with MFA are critical for scaling and security.

263
MCQeasy

Which Cisco solution is best suited to prevent data exfiltration from a cloud-native Kubernetes cluster?

A.Cisco Secure Workload
B.Cisco DNA Center
C.Cisco Umbrella
D.Cisco Meraki Dashboard
AnswerA

Secure Workload is the primary solution for container security and segmentation.

Why this answer

Cisco Secure Workload provides visibility and microsegmentation, which is the most effective way to prevent exfiltration by limiting what a compromised pod can reach.

264
Multi-Selectmedium

Which TWO design considerations are essential when implementing a Zero Trust architecture for IoT devices in a campus environment using Cisco ISE and TrustSec?

Select 2 answers
A.Using static IP addresses for every IoT device to ensure consistency.
B.Utilizing Cisco ISE to profile and categorize IoT endpoints.
C.Applying Scalable Group Tags (SGTs) to enforce micro-segmentation.
D.Ensuring all IoT devices are placed in the same VLAN for easier management.
E.Disabling 802.1X for all non-PC devices.
AnswersB, C

Profiling is essential to identify the device type for policy application.

Why this answer

Profiling and segmentation are the core components of IoT Zero Trust.

265
Multi-Selecthard

Which TWO of the following steps are required to integrate a security tool (like Cisco Secure Firewall) into a CI/CD pipeline?

Select 2 answers
A.Replace the existing firewall hardware
B.Hardcode credentials in the pipeline build file
C.Configure API authentication credentials
D.Disable all firewall rules for testing
E.Use an infrastructure provisioning tool
AnswersC, E

Necessary for secure automated access.

Why this answer

You need an authentication mechanism (API keys) and a deployment tool (Terraform/Ansible) to manage the infrastructure.

266
Multi-Selecthard

To ensure effective post-incident architecture adaptation, which THREE items must be included in the design documentation for future reference? (Choose three)

Select 3 answers
A.User password policies
B.Modified security policy logic
C.Log correlation and alert rules
D.Hardware rack elevation diagrams
E.Automated response orchestration workflows
AnswersB, C, E

Essential for understanding how security posture changed.

Why this answer

Proper design documentation must include the security policy changes, the automated response workflow, and the specific log correlation rules created during the incident recovery.

267
Multi-Selectmedium

A SOC manager requests a design that simplifies the incident investigation process. Which TWO Cisco tools should the design include for improved correlation of network traffic and endpoint events? (Choose two)

Select 2 answers
A.Cisco DNA Spaces
B.Cisco Secure Network Analytics
C.Cisco Smart Licensing
D.Cisco Nexus Dashboard
E.Cisco Secure Endpoint
AnswersB, E

Provides network telemetry and behavioral correlation.

Why this answer

Secure Network Analytics (NetFlow) and Secure Endpoint (Process/File data) are the core tools for correlating network and host activities.

268
Multi-Selectmedium

Which THREE components in Cisco Secure Workload are essential for building a Zero Trust segmentation policy? (Choose THREE)

Select 3 answers
A.Policy enforcement agents
B.Manual IP address manual entry
C.Flow telemetry analysis
D.Physical cable management
E.Workload discovery and profiling
AnswersA, C, E

Agents are the mechanism for policy enforcement.

Why this answer

Zero Trust requires identifying the assets, understanding the flows, and enforcing the policies through the agents.

269
MCQeasy

When selecting a security approach for email threats, which Cisco technology provides automated sandboxing to protect against zero-day phishing?

A.Cisco Duo MFA.
B.Cisco Secure Malware Analytics.
C.Cisco Umbrella DNS layer security.
D.Cisco Secure Endpoint protection.
AnswerB

Secure Malware Analytics provides the sandboxing capability for email attachments.

Why this answer

Cisco Secure Email (formerly ESA) integrates with Secure Malware Analytics (formerly Threat Grid) for sandboxing.

270
MCQhard

When designing an API security architecture, what is the primary purpose of 'API Discovery' in the context of Cisco API Security?

A.To replace the need for API gateways
B.To inventory all API endpoints and identify shadow or undocumented APIs
C.To increase the API's performance
D.To automatically generate API documentation for developers
AnswerB

Inventory and shadow API detection are the primary goals of discovery.

Why this answer

API Discovery identifies all API endpoints in an environment to ensure that security policies can be applied to undocumented or shadow APIs.

271
MCQeasy

Which Cisco product provides visibility into traffic within the cloud, helping to identify potential microsegmentation policies?

A.Cisco DNA Center
B.Cisco Secure Workload
C.Cisco Meraki
D.Cisco Umbrella
AnswerB

Secure Workload is the visibility and segmentation tool.

Why this answer

Cisco Secure Workload captures flow telemetry across the cloud to provide the necessary visibility to build security policies.

272
MCQmedium

A design team is implementing Cisco ISE for a hybrid work environment. Which Cisco ISE architectural component is responsible for processing RADIUS and TACACS+ requests while offloading policy decision logic from the Administration node?

A.Primary Administration Node (PAN)
B.Policy Service Node (PSN)
C.Monitoring Node (MnT)
D.Policy Information Point (PIP)
AnswerB

PSNs handle the actual authentication and authorization traffic.

Why this answer

The Policy Service Node (PSN) is designed to handle session-based requests and policy processing, ensuring the Administration node remains available for management tasks.

273
MCQhard

Which Cisco feature is specifically designed to prevent 'Credential Stuffing' in an automated application environment?

A.DNS Filtering
B.SSL Inspection
C.Adaptive Authentication
D.Intrusion Prevention System (IPS)
AnswerC

Uses context to identify suspicious logins.

Why this answer

Cisco Secure Access (Duo) Adaptive Authentication uses risk-based policies to detect and block credential stuffing.

274
MCQeasy

A security designer is choosing a tool for DNS-layer security. Which Cisco product is the standard choice?

A.Cisco Secure Endpoint.
B.Cisco Umbrella.
C.Cisco ISE.
D.Cisco Secure Firewall.
AnswerB

Umbrella is built specifically for DNS-layer security and threat blocking.

Why this answer

Cisco Umbrella is the industry leader for DNS-layer security.

275
Multi-Selectmedium

Which THREE steps are required for a successful security design process?

Select 3 answers
A.Ignoring all existing network infrastructure.
B.Developing a detailed architectural plan and implementation roadmap.
C.Requirements gathering from stakeholders.
D.Purchasing the most expensive hardware available.
E.Performing a risk assessment of the current environment.
AnswersB, C, E

A plan is essential for implementation.

Why this answer

Successful designs require assessment, planning, and validation.

276
MCQmedium

A network designer needs to implement a VPN that supports both remote access and site-to-site connectivity. Which protocol is recommended for modern Cisco hardware?

A.IKEv2.
B.SSL VPN.
C.IKEv1.
D.PPTP.
AnswerA

IKEv2 is the industry standard for modern Cisco VPN deployments.

Why this answer

IKEv2 is the standard for modern VPNs, supporting both Remote Access and Site-to-Site with high security and flexibility.

277
MCQeasy

A design requirement for a SOC environment is to have real-time visibility into who is on the network. Which Cisco tool is best for this?

A.Cisco Identity Services Engine (ISE).
B.Cisco Umbrella.
C.Cisco Firepower Management Center.
D.Cisco SecureX.
AnswerA

ISE is the source of truth for identity and device location in Cisco networks.

Why this answer

Cisco ISE provides real-time tracking of all network authentication and access events.

278
MCQmedium

In a design for a Zero Trust architecture, what is the primary function of the Policy Decision Point (PDP)?

A.To audit session traffic
B.To provide identity management
C.To evaluate access requests based on policy
D.To enforce the policy on the endpoint
AnswerC

The PDP assesses the request and makes the determination.

Why this answer

The PDP is responsible for evaluating access requests against defined security policies and making the final 'permit' or 'deny' decision.

279
Multi-Selectmedium

When designing a secure API environment, which THREE tasks should the API Gateway handle? (Choose THREE)

Select 3 answers
A.Application data storage
B.Authentication and authorization verification
C.Routing to appropriate backend microservices
D.Request rate limiting
E.Hard-coding all business logic
AnswersB, C, D

The gateway enforces access control.

Why this answer

The API gateway is responsible for securing the edge of the API architecture, including auth, rate limiting, and traffic routing.

280
MCQmedium

What is the purpose of 'Microsegmentation' in a cloud-native architecture?

A.To reduce the attack surface by isolating workloads
B.To automatically scale services based on demand
C.To provide high availability for the service
D.To optimize container scheduling
AnswerA

Isolating workloads via fine-grained rules is the core purpose.

Why this answer

Microsegmentation provides granular security by isolating workloads so that traffic is only allowed if explicitly required, reducing the attack surface.

281
MCQeasy

Which Cisco solution is primarily designed to provide visibility and protection for SaaS applications like Office 365, Salesforce, and Slack?

A.Cisco Secure Workload
B.Cisco Cloudlock
C.Cisco Secure Firewall
D.Cisco Umbrella
AnswerB

Cloudlock is the designated CASB solution.

Why this answer

Cisco Cloudlock is a cloud-native CASB designed to secure SaaS environments.

282
MCQmedium

When designing a secure management plane, why is it critical to use a dedicated Out-of-Band (OOB) network?

A.To reduce the cost of cabling.
B.To prevent management plane saturation during a data plane DoS attack.
C.To increase the throughput of user traffic.
D.To allow for DHCP-based addressing of management interfaces.
AnswerB

Isolating management traffic ensures administrators can reach devices during congestion.

Why this answer

OOB management isolates management traffic from data plane traffic, preventing potential DDoS attacks on the management interface.

283
Multi-Selectmedium

Which TWO factors must be considered when designing SaaS security using Cisco Cloudlock to ensure compliance with data protection regulations? (Choose TWO)

Select 2 answers
A.Configuring BGP peering with the SaaS provider
B.Establishing remediation workflows for policy violations
C.Defining appropriate data classification and DLP policies
D.Enabling hardware-based encryption for the SaaS vendor
E.Installing agents on all end-user laptops
AnswersB, C

Automated remediation ensures that policy violations are addressed in a compliant timeframe.

Why this answer

Compliance requires identifying sensitive data types and defining automated remediation actions to protect that data.

284
MCQmedium

When designing an automated security policy deployment for Cisco Secure Workload (formerly Tetration), which mechanism allows you to test policies in a simulation environment before applying them to production?

A.Policy Analysis mode
B.Agentless vulnerability scanning
C.Workload isolation testing
D.Inventory change management
E.Live enforcement mode
AnswerA

This mode simulates the impact of policies on existing traffic patterns.

Why this answer

Cisco Secure Workload allows for 'Policy Simulation' or 'Policy Analysis' to validate the impact of rules before enforcement.

285
Multi-Selecthard

Which TWO methods are used by Cisco Stealthwatch to detect anomalies in network traffic?

Select 2 answers
A.Signature-based matching for every packet.
B.Deep packet inspection of every payload byte.
C.Behavioral baseline modeling of host and network patterns.
D.Analysis of NetFlow, IPFIX, and other flow telemetry.
E.Manual input of all known malicious IP addresses.
AnswersC, D

Baseline modeling is the core of Stealthwatch anomaly detection.

Why this answer

Stealthwatch uses behavioral modeling and flow data analysis to detect threats.

286
MCQmedium

A design requirements document specifies a need for 'Network Segmentation' to contain breaches. Which Cisco technology provides the best granular control using Scalable Group Tags (SGTs)?

A.Cisco TrustSec (SGTs).
B.Cisco Secure Firewall interface zones.
C.VLAN-based segmentation.
D.Cisco Umbrella local policy.
AnswerA

TrustSec provides flexible, identity-based segmentation.

Why this answer

Cisco TrustSec uses SGTs to enforce segmentation policies based on identity, independent of IP address.

287
MCQmedium

Your organization uses a hybrid cloud model. You are tasked with designing a security posture for workloads in AWS and Azure using Cisco Secure Workload. What is the benefit of the 'Anywhere' agent approach?

A.It provides consistent security policy enforcement across heterogenous environments
B.It automatically patches the underlying operating system
C.It replaces the need for a central management platform
D.It eliminates the need for any firewall rules in the cloud
AnswerA

This is the primary advantage of the workload-level agent.

Why this answer

The 'Anywhere' agent allows for consistent policy enforcement across diverse infrastructure, including on-premises and multiple cloud providers.

288
MCQeasy

Which Cisco tool is best suited for designing and documenting network security architectures?

A.Cisco Meraki Dashboard.
B.Cisco Webex.
C.Cisco Modeling Labs (CML).
D.Cisco Jabber.
AnswerC

CML is the standard for simulating and designing topologies.

Why this answer

Cisco Modeling Labs (CML) allows for the simulation and design of complex network security topologies.

289
MCQmedium

To protect a SaaS application accessed by remote users, which Cisco solution provides a unified cloud-native security stack including DNS-layer security and SWG?

A.Cisco Duo
B.Cisco Firepower Threat Defense
C.Cisco Secure Endpoint
D.Cisco Umbrella
AnswerD

Umbrella is the cloud-native SASE component that secures SaaS access.

Why this answer

Cisco Umbrella provides the cloud-native security stack including DNS security, SWG, and CASB functions.

290
MCQeasy

What is the primary role of Cisco SecureX in a SOC architecture?

A.To provide local firewall policy management.
B.To provide a centralized platform for visibility and orchestration.
C.To act as a secondary backup firewall.
D.To replace all other security tools.
AnswerB

SecureX is designed to unite security products into a single workflow.

Why this answer

SecureX serves as the unified platform for security visibility and orchestration.

291
MCQmedium

You are designing microsegmentation for a Kubernetes cluster using Cisco Tetration (Secure Workload). You need to ensure that only authorized pods can communicate with a specific backend database service. Which architectural component should be enforced to achieve zero-trust segmentation at the application layer?

A.Deploy a service-level policy based on process and label identity via the Secure Workload agent.
B.Configure static IP-based ACLs on the physical leaf switches.
C.Implement VRF-lite on the nodes to isolate the database traffic.
D.null
E.Enable port-security on the virtual switch ports connecting the worker nodes.
AnswerA

Secure Workload uses identity-based policies derived from application labels to control traffic flow.

Why this answer

Cisco Secure Workload (Tetration) uses software agents on hosts to enforce policies. For Kubernetes, the agent leverages service-level labels to create microsegmentation policies that are independent of IP addresses, ensuring that security follows the workload.

292
MCQmedium

When assessing risk for a remote office branch, the architect decides to use Cisco Umbrella. Which requirement is addressed by implementing the Umbrella roaming client for branch endpoints?

A.Providing deep packet inspection for local branch-to-branch file transfers.
B.Managing local firewall rules on the branch router.
C.Providing local site-to-site VPN encryption for branch traffic.
D.Enforcing security policies on endpoints even when they are off the corporate network.
AnswerD

The roaming client forces DNS requests through Umbrella regardless of location.

Why this answer

Roaming clients ensure security policies are applied regardless of the network location, satisfying mobile user risk requirements.

293
MCQhard

A manufacturing firm wants to secure IoT devices using Cisco TrustSec. Which mechanism ensures that traffic from IoT sensors is isolated from corporate traffic without relying on complex VLAN/ACL management?

A.Dynamic ARP Inspection
B.Scalable Group Tags (SGTs)
C.Private VLANs (PVLANs)
D.VLAN Trunking Protocol
AnswerB

SGTs allow for segmenting traffic based on identity rather than IP addresses.

Why this answer

Scalable Group Tags (SGTs) provide identity-based segmentation, which decouples security policies from network topology.

294
MCQhard

You are designing security for a multi-cloud environment. Which feature in Cisco Secure Firewall allows for automated policy deployment based on cloud tags?

A.Static IP-based Access Control Lists.
B.VLAN tagging.
C.Dynamic Object Groups.
D.Network Interface Virtualization.
AnswerC

Dynamic objects in Secure Firewall can be mapped to cloud tags.

Why this answer

Cisco Secure Firewall uses cloud-based tags to dynamically apply security group policies, ensuring that as instances scale, the policy follows them.

295
Multi-Selecthard

Which THREE of the following are considered 'Threat Response' automation actions in a Cisco XDR environment?

Select 3 answers
A.Sending a company-wide email
B.Blocking a malicious file hash
C.Rebooting the server hardware
D.Blocking a malicious URL
E.Isolating an infected host
AnswersB, D, E

Prevents malware spread.

Why this answer

Isolating an endpoint, blocking a file hash, and blocking a URL are common automated responses.

296
MCQmedium

Which protocol is used for the control plane communication between Cisco SD-WAN controllers?

A.EIGRP.
B.BGP.
C.OSPF.
D.OMP.
AnswerD

OMP is the foundational control plane protocol for Cisco SD-WAN.

Why this answer

OMP (Overlay Management Protocol) is used for routing, policy, and service information exchange between SD-WAN components.

297
Multi-Selectmedium

Which TWO methods are effective for securing email infrastructure against phishing?

Select 2 answers
A.Using only local SMTP relays.
B.DMARC/SPF/DKIM implementation.
C.Disabling all attachments in emails.
D.Cisco Secure Email sandboxing.
E.Allowing all inbound mail traffic.
AnswersB, D

These protocols prevent domain spoofing.

Why this answer

Email security requires both gateway-based protection and user authentication protocols.

298
MCQmedium

A security architect is designing a Cisco Secure Firewall deployment for a multi-cloud environment. Which design strategy ensures consistent security policy enforcement across AWS and Azure instances?

A.Utilize a centralized FMC to manage virtual Secure Firewalls across all cloud environments.
B.Deploy separate FMC instances in each cloud provider for localized management.
C.Use individual Firewall Device Managers (FDM) for every instance.
D.Implement cloud-native security groups exclusively to bypass firewall bottlenecks.
AnswerA

Centralized FMC provides a unified control plane for policy consistency.

Why this answer

Cisco Secure Firewall Management Center (FMC) acts as the central management plane to push uniform policies across heterogeneous cloud environments.

Page 3

Page 4 of 4

All pages