Courseiva

SDSI · domain

AI Automation And Devsecops

Practise Cisco Designing Cisco Security Infrastructure (SDSI, 300-745, CCNP Security, design-focused) (SDSI) AI Automation And Devsecops practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

41 questions9 easy16 medium16 hard

Focused practice

Practice AI Automation And Devsecops questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about AI Automation And Devsecops

AI Automation And Devsecops questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common AI Automation And Devsecops exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All AI Automation And Devsecops questions (41)

Click any question to see the full explanation, or start a practice session above.

1

Which aspect of AI-driven security automation helps in 'Reducing Mean Time to Respond (MTTR)'?

Easy
2

You are designing an automated pipeline for Cisco Secure Firewall. If a deployment fails, which mechanism ensures the configuration is reverted to the last known good state?

Hard
3

You are implementing automated policy enforcement for Cisco Secure Access by Duo. Which API allows you to programmatically manage users and authentication settings?

Medium
4

What is the primary role of a 'Security Policy Engine' (e.g., Cisco Secure Firewall) within an automated data center architecture?

Easy
5

When automating security with Cisco XDR, which component allows for the execution of arbitrary scripts on third-party security tools?

Hard
6

When designing an automated remediation workflow for Cisco Secure Firewall, what is the specific function of the 'Cisco Secure Firewall REST API' in the context of threat intelligence feeds?

Hard
7

Which THREE of the following are key AI/ML design considerations when selecting a security automation platform?

Hard
8

What is the primary benefit of 'Shift Left' security in a DevSecOps pipeline?

Easy
9

In an AI-enhanced security design, what is 'Supervised Learning' primarily used for?

Medium
10

In an AI-based security architecture, which data source provides the most value for training an ML model to detect unauthorized data exfiltration?

Medium
11

You are automating Cisco Secure Firewall policies. Why is 'Version Control' (e.g., Git) considered a security control?

Medium
12

Which THREE of the following represent common challenges when implementing automated security in a legacy environment?

Medium
13

Which TWO of the following are common benefits of using API-based security automation?

Easy
14

For a DevSecOps pipeline involving Cisco Secure Firewall, what is the 'CI' (Continuous Integration) component responsible for?

Hard
15

In a DevSecOps environment, you need to implement Cisco Secure Firewall Management Center (FMC) rule updates via Ansible. Which approach ensures the highest level of security and idempotency?

Hard
16

When designing automated security for Cisco Secure Workload, what does 'Micro-segmentation' provide in the context of DevSecOps?

Medium
17

Which TWO of the following are benefits of using 'Infrastructure as Code' (IaC) with Cisco Secure Firewall?

Hard
18

When utilizing Cisco DevNet tools for security, which Python library is the standard for interacting with the Cisco FMC API efficiently?

Hard
19

Which TWO of the following are common components of an AI-driven security operations center (SOC)?

Easy
20

Which THREE of the following technologies should be combined to create a 'Security-as-Code' pipeline for Cisco infrastructure?

Medium
21

You are automating the lifecycle of Cisco Secure Firewall policies. Which tool should be selected to integrate security policy as code (SaC) into a GitHub Actions pipeline?

Hard
22

Which component of Cisco XDR (formerly Cisco SecureX) is critical for normalizing data from different Cisco security products to enable automated orchestration?

Hard
23

In DevSecOps, what is the role of an 'Artifact Repository' such as Artifactory in relation to security?

Easy
24

Which THREE of the following are best practices for securing a CI/CD pipeline itself?

Hard
25

What is the primary function of an 'API Gateway' in a secure automated environment?

Easy
26

In the context of AI-driven security, what does 'False Positive Reduction' primarily achieve?

Easy
27

Which TWO of the following identify risks associated with using AI for security automation?

Hard
28

In a DevSecOps pipeline, what is the benefit of 'Static Application Security Testing' (SAST)?

Medium
29

Which THREE of the following are essential components of a robust DevSecOps security architecture for Cisco infrastructure?

Medium
30

Which TWO of the following capabilities does Cisco Secure Firewall (FMC) provide to support automated security workflows?

Medium
31

Which Cisco technology should be included in an automated design to ensure 'Zero Trust' access for remote developers accessing internal development servers?

Medium
32

Which of the following is a key requirement for implementing successful DevSecOps in a large organization?

Easy
33

You are integrating Cisco Umbrella into a CI/CD pipeline. Which API is most appropriate for programmatically blocking domains discovered by your automated security scan?

Medium
34

Which Cisco security solution utilizes AI-based 'Cognitive Intelligence' to detect threats in encrypted traffic without decrypting the payload?

Medium
35

Which THREE of the following are key features of Cisco XDR (formerly SecureX) in an automated pipeline?

Medium
36

Which TWO of the following are true about 'Policy as Code' in Cisco security infrastructure?

Medium
37

When designing a multi-cloud CI/CD security architecture, how should secrets (API keys for Cisco FMC) be managed to ensure compliance?

Hard
38

Which TWO of the following steps are required to integrate a security tool (like Cisco Secure Firewall) into a CI/CD pipeline?

Hard
39

Which Cisco feature is specifically designed to prevent 'Credential Stuffing' in an automated application environment?

Hard
40

When designing an automated security policy deployment for Cisco Secure Workload (formerly Tetration), which mechanism allows you to test policies in a simulation environment before applying them to production?

Medium
41

Which THREE of the following are considered 'Threat Response' automation actions in a Cisco XDR environment?

Hard

Frequently asked questions

What does the AI Automation And Devsecops domain cover on the SDSI exam?
AI Automation And Devsecops questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 41 AI Automation And Devsecops questions in the SDSI question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only AI Automation And Devsecops questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
Cisco Designing Cisco Security Infrastructure (SDSI, 300-745, CCNP Security, design-focused) (SDSI) AI Automation And Devsecops Practice Questions