SDSI · domain
Secure Infrastructure Design
Practise Cisco Designing Cisco Security Infrastructure (SDSI, 300-745, CCNP Security, design-focused) (SDSI) Secure Infrastructure Design practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Secure Infrastructure Design questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Secure Infrastructure Design
Secure Infrastructure Design questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Secure Infrastructure Design exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Secure Infrastructure Design questions (86)
Click any question to see the full explanation, or start a practice session above.
What is the primary function of the 'AnyConnect' (Secure Client) profile?
Medium2Which TWO methods are used to provide secure remote access for a mobile workforce? (Select 2)
Hard3Which TWO design principles should be followed when selecting a firewall architecture for a multi-cloud environment? (Select 2)
Hard4Which Cisco solution provides host-based visibility and protection against fileless malware?
Easy5In a hybrid work design, what is the advantage of using Cisco Umbrella's roaming client?
Hard6Which Cisco technology is used to ensure that only authorized users can connect to the network via guest portals?
Easy7A company is migrating to a SASE architecture using Cisco+ Secure Connect. Which component is responsible for the unified identity-based access control for remote users?
Hard8Which THREE technologies enable network segmentation in a modern Cisco campus design?
Hard9For a high-availability firewall architecture, which design element is critical when utilizing a routed-mode configuration in a data center?
Hard10Which THREE Cisco solutions support the 'Secure Work from Anywhere' concept?
Hard11A design team is integrating Cisco Secure Firewall with an existing SIEM. Which telemetry export format is best for comprehensive security analysis?
Medium12Which TWO features assist in protecting the network control plane against DoS attacks?
Medium13In a Cisco Secure Firewall architecture, what is the purpose of the 'Intrusion Policy'?
Hard14A security architect is designing a Cisco Secure Firewall deployment for a multi-cloud environment. Which design approach provides the most consistent security policy enforcement across AWS and Azure?
Easy15Which THREE components are part of the Cisco Secure Firewall architecture? (Select 3)
Medium16In a multi-cloud design, which protocol is preferred for secure inter-site communication to support micro-segmentation?
Hard17In a multi-cloud design, which component is used to connect remote offices directly to the cloud provider while maintaining Cisco-level security?
Hard18When designing a network segmentation strategy using Cisco TrustSec, what is an SGT tag used for?
Medium19When designing a remote access VPN solution using Cisco AnyConnect, which protocol is preferred to optimize performance for latency-sensitive applications like VoIP?
Easy20A security architect is designing a remote-work solution. What is the benefit of using Split Tunneling in Cisco Secure Client?
Medium21For a zero-trust architecture, what is the primary function of Cisco ISE?
Hard22Which THREE factors should be considered when designing a security approach for a hybrid work model? (Select 3)
Medium23Which TWO strategies are recommended for securing a cloud-native SaaS environment?
Medium24When designing a firewall architecture for a high-security zone, which inspection mode is required to identify malware within encrypted payloads?
Medium25Which THREE design principles are key for a multi-cloud security strategy?
Hard26When designing a secure remote access solution, what is the 'Always-On' VPN feature in AnyConnect primarily used for?
Hard27When designing a site-to-site VPN, which IKEv2 feature allows the tunnel to be established without requiring a static IP address on one side?
Easy28What is the benefit of integrating Cisco Secure Email with Cisco Threat Intelligence (Talos)?
Easy29Which THREE components are part of a robust Cisco Zero Trust for the Workplace architecture?
Hard30In an SD-WAN architecture, how does the design ensure the security of traffic between branches?
Hard31Which Cisco technology allows an organization to enforce security policies based on the user's location and device posture, even when the user is off-network?
Hard32You are designing the control plane security for a Cisco switch. Which feature limits the amount of traffic sent to the CPU, protecting it from DoS attacks?
Hard33A design architect is deploying a Cisco Secure Firewall in a High Availability (HA) pair. Which configuration is required to ensure stateful failover across firewalls?
Hard34When configuring a Cisco ASA/Firepower firewall, what is the 'inside' interface typically used for?
Easy35In a Cisco SD-WAN environment, you need to ensure that branch office traffic destined for SaaS applications is optimized and secured. Which design approach is most appropriate?
Hard36You are designing an IoT network segment. Which technology allows you to verify device identity at the hardware level?
Medium37Which protocol is recommended for secure network time synchronization across security devices?
Easy38A network security designer is evaluating email security solutions. Which feature in Cisco Secure Email (ESA) is most effective against sophisticated Business Email Compromise (BEC) attacks?
Medium39In a SaaS security design, what is the role of a Cloud Access Security Broker (CASB)?
Medium40You are designing the security for a SaaS application access scenario. What is the role of the Cloud Access Security Broker (CASB)?
Medium41Which component of the Cisco Secure architecture is used to provide centralized visibility and threat analysis across the entire network based on NetFlow data?
Easy42Which Cisco feature is used to prevent the unauthorized use of dynamic IP addresses on a network?
Medium43You are designing a security architecture for a hybrid cloud environment using Cisco Secure Firewall. Which design pattern effectively mitigates the risk of lateral movement between VPCs in AWS while maintaining centralized policy enforcement?
Medium44Which TWO factors are critical for selecting a firewall architecture?
Medium45When designing a firewall for a data center, what is the best practice for handling high-bandwidth traffic inspection?
Medium46You are designing an email security gateway deployment. What is the benefit of using Cisco Secure Email's 'Outbreak Filters'?
Medium47Which THREE features of Cisco Secure Email help in mitigating email-based threats? (Select 3)
Medium48Which TWO methods provide identification for IoT devices in an enterprise network?
Medium49When designing a VPN solution for a hybrid workforce, which protocol provides the most robust support for DTLS to minimize latency for real-time traffic?
Medium50Which THREE technologies are used in Cisco's architecture for micro-segmentation?
Hard51Which design principle is essential when configuring Cisco Secure Firewall for SaaS application visibility?
Medium52When designing an endpoint security strategy, which Cisco tool provides visibility into fileless malware by monitoring system process behavior?
Medium53Which Cisco platform provides a centralized view of security threats across the entire enterprise?
Easy54Which Cisco feature is used to prevent unauthorized devices from connecting to the wired network by enforcing identity-based access control at the access switch port?
Easy55Which design component is necessary for implementing Cisco TrustSec across a multi-switch campus?
Medium56When designing a secure remote access solution for a hybrid workforce, which Cisco AnyConnect feature should be prioritized to reduce the attack surface by verifying the posture of the device before granting access?
Easy57When designing a VPN for a multi-tenant cloud environment, which technology allows for the separation of routing tables to ensure traffic isolation between tenants?
Hard58Which TWO features are essential for securing the management plane of a Cisco network device?
Medium59A company requires a control plane security design for their campus network. Which feature prevents unauthorized devices from claiming to be the default gateway?
Medium60Which Cisco feature is designed to protect the control plane of a router from being overwhelmed by traffic?
Medium61Which THREE services does Cisco Umbrella provide to secure remote workers? (Select 3)
Medium62You are designing a management plane security strategy for Cisco networking devices. Which protocol is recommended to replace Telnet to ensure encrypted administrative sessions?
Hard63Which TWO factors are vital for an effective firewall policy design?
Medium64You are designing a secure infrastructure for a SaaS-heavy office. What strategy best minimizes the impact on user experience while maintaining security?
Hard65You are designing an IoT security strategy for a manufacturing site. Which approach best isolates unmanaged IoT devices from the enterprise network?
Medium66Which TWO design considerations are critical for a secure SD-WAN edge deployment?
Medium67Which feature enables Cisco switches to limit the amount of broadcast traffic received on a port?
Medium68Which THREE design components are required for a successful implementation of Cisco TrustSec? (Select 3)
Medium69Which Cisco solution provides DNS-layer security to prevent users from connecting to malicious domains?
Easy70A security designer is choosing a firewall architecture for a high-throughput data center core. Which Cisco Firewall platform is purpose-built for this requirement?
Easy71Which TWO design considerations are critical for a secure management plane for Cisco networking devices? (Select 2)
Hard72Which TWO identity-based design considerations are critical for secure endpoint access? (Select 2)
Hard73Which TWO factors must be considered when designing a Secure Remote Access VPN architecture for a hybrid workforce using Cisco AnyConnect?
Medium74Which TWO design considerations are essential when implementing a Zero Trust architecture for IoT devices in a campus environment using Cisco ISE and TrustSec?
Medium75When selecting a security approach for email threats, which Cisco technology provides automated sandboxing to protect against zero-day phishing?
Easy76A design team is implementing Cisco ISE for a hybrid work environment. Which Cisco ISE architectural component is responsible for processing RADIUS and TACACS+ requests while offloading policy decision logic from the Administration node?
Medium77A network designer needs to implement a VPN that supports both remote access and site-to-site connectivity. Which protocol is recommended for modern Cisco hardware?
Medium78In a design for a Zero Trust architecture, what is the primary function of the Policy Decision Point (PDP)?
Medium79When designing a secure management plane, why is it critical to use a dedicated Out-of-Band (OOB) network?
Medium80Which Cisco tool is best suited for designing and documenting network security architectures?
Easy81To protect a SaaS application accessed by remote users, which Cisco solution provides a unified cloud-native security stack including DNS-layer security and SWG?
Medium82A manufacturing firm wants to secure IoT devices using Cisco TrustSec. Which mechanism ensures that traffic from IoT sensors is isolated from corporate traffic without relying on complex VLAN/ACL management?
Hard83You are designing security for a multi-cloud environment. Which feature in Cisco Secure Firewall allows for automated policy deployment based on cloud tags?
Hard84Which protocol is used for the control plane communication between Cisco SD-WAN controllers?
Medium85Which TWO methods are effective for securing email infrastructure against phishing?
Medium86A security architect is designing a Cisco Secure Firewall deployment for a multi-cloud environment. Which design strategy ensures consistent security policy enforcement across AWS and Azure instances?
MediumOther domains
All SDSI exam domains
Frequently asked questions
- What does the Secure Infrastructure Design domain cover on the SDSI exam?
- Secure Infrastructure Design questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 86 Secure Infrastructure Design questions in the SDSI question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Secure Infrastructure Design questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.