Courseiva

SDSI · domain

Secure Infrastructure Design

Practise Cisco Designing Cisco Security Infrastructure (SDSI, 300-745, CCNP Security, design-focused) (SDSI) Secure Infrastructure Design practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

86 questions16 easy43 medium27 hard

Focused practice

Practice Secure Infrastructure Design questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Secure Infrastructure Design

Secure Infrastructure Design questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Secure Infrastructure Design exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Secure Infrastructure Design questions (86)

Click any question to see the full explanation, or start a practice session above.

1

What is the primary function of the 'AnyConnect' (Secure Client) profile?

Medium
2

Which TWO methods are used to provide secure remote access for a mobile workforce? (Select 2)

Hard
3

Which TWO design principles should be followed when selecting a firewall architecture for a multi-cloud environment? (Select 2)

Hard
4

Which Cisco solution provides host-based visibility and protection against fileless malware?

Easy
5

In a hybrid work design, what is the advantage of using Cisco Umbrella's roaming client?

Hard
6

Which Cisco technology is used to ensure that only authorized users can connect to the network via guest portals?

Easy
7

A company is migrating to a SASE architecture using Cisco+ Secure Connect. Which component is responsible for the unified identity-based access control for remote users?

Hard
8

Which THREE technologies enable network segmentation in a modern Cisco campus design?

Hard
9

For a high-availability firewall architecture, which design element is critical when utilizing a routed-mode configuration in a data center?

Hard
10

Which THREE Cisco solutions support the 'Secure Work from Anywhere' concept?

Hard
11

A design team is integrating Cisco Secure Firewall with an existing SIEM. Which telemetry export format is best for comprehensive security analysis?

Medium
12

Which TWO features assist in protecting the network control plane against DoS attacks?

Medium
13

In a Cisco Secure Firewall architecture, what is the purpose of the 'Intrusion Policy'?

Hard
14

A security architect is designing a Cisco Secure Firewall deployment for a multi-cloud environment. Which design approach provides the most consistent security policy enforcement across AWS and Azure?

Easy
15

Which THREE components are part of the Cisco Secure Firewall architecture? (Select 3)

Medium
16

In a multi-cloud design, which protocol is preferred for secure inter-site communication to support micro-segmentation?

Hard
17

In a multi-cloud design, which component is used to connect remote offices directly to the cloud provider while maintaining Cisco-level security?

Hard
18

When designing a network segmentation strategy using Cisco TrustSec, what is an SGT tag used for?

Medium
19

When designing a remote access VPN solution using Cisco AnyConnect, which protocol is preferred to optimize performance for latency-sensitive applications like VoIP?

Easy
20

A security architect is designing a remote-work solution. What is the benefit of using Split Tunneling in Cisco Secure Client?

Medium
21

For a zero-trust architecture, what is the primary function of Cisco ISE?

Hard
22

Which THREE factors should be considered when designing a security approach for a hybrid work model? (Select 3)

Medium
23

Which TWO strategies are recommended for securing a cloud-native SaaS environment?

Medium
24

When designing a firewall architecture for a high-security zone, which inspection mode is required to identify malware within encrypted payloads?

Medium
25

Which THREE design principles are key for a multi-cloud security strategy?

Hard
26

When designing a secure remote access solution, what is the 'Always-On' VPN feature in AnyConnect primarily used for?

Hard
27

When designing a site-to-site VPN, which IKEv2 feature allows the tunnel to be established without requiring a static IP address on one side?

Easy
28

What is the benefit of integrating Cisco Secure Email with Cisco Threat Intelligence (Talos)?

Easy
29

Which THREE components are part of a robust Cisco Zero Trust for the Workplace architecture?

Hard
30

In an SD-WAN architecture, how does the design ensure the security of traffic between branches?

Hard
31

Which Cisco technology allows an organization to enforce security policies based on the user's location and device posture, even when the user is off-network?

Hard
32

You are designing the control plane security for a Cisco switch. Which feature limits the amount of traffic sent to the CPU, protecting it from DoS attacks?

Hard
33

A design architect is deploying a Cisco Secure Firewall in a High Availability (HA) pair. Which configuration is required to ensure stateful failover across firewalls?

Hard
34

When configuring a Cisco ASA/Firepower firewall, what is the 'inside' interface typically used for?

Easy
35

In a Cisco SD-WAN environment, you need to ensure that branch office traffic destined for SaaS applications is optimized and secured. Which design approach is most appropriate?

Hard
36

You are designing an IoT network segment. Which technology allows you to verify device identity at the hardware level?

Medium
37

Which protocol is recommended for secure network time synchronization across security devices?

Easy
38

A network security designer is evaluating email security solutions. Which feature in Cisco Secure Email (ESA) is most effective against sophisticated Business Email Compromise (BEC) attacks?

Medium
39

In a SaaS security design, what is the role of a Cloud Access Security Broker (CASB)?

Medium
40

You are designing the security for a SaaS application access scenario. What is the role of the Cloud Access Security Broker (CASB)?

Medium
41

Which component of the Cisco Secure architecture is used to provide centralized visibility and threat analysis across the entire network based on NetFlow data?

Easy
42

Which Cisco feature is used to prevent the unauthorized use of dynamic IP addresses on a network?

Medium
43

You are designing a security architecture for a hybrid cloud environment using Cisco Secure Firewall. Which design pattern effectively mitigates the risk of lateral movement between VPCs in AWS while maintaining centralized policy enforcement?

Medium
44

Which TWO factors are critical for selecting a firewall architecture?

Medium
45

When designing a firewall for a data center, what is the best practice for handling high-bandwidth traffic inspection?

Medium
46

You are designing an email security gateway deployment. What is the benefit of using Cisco Secure Email's 'Outbreak Filters'?

Medium
47

Which THREE features of Cisco Secure Email help in mitigating email-based threats? (Select 3)

Medium
48

Which TWO methods provide identification for IoT devices in an enterprise network?

Medium
49

When designing a VPN solution for a hybrid workforce, which protocol provides the most robust support for DTLS to minimize latency for real-time traffic?

Medium
50

Which THREE technologies are used in Cisco's architecture for micro-segmentation?

Hard
51

Which design principle is essential when configuring Cisco Secure Firewall for SaaS application visibility?

Medium
52

When designing an endpoint security strategy, which Cisco tool provides visibility into fileless malware by monitoring system process behavior?

Medium
53

Which Cisco platform provides a centralized view of security threats across the entire enterprise?

Easy
54

Which Cisco feature is used to prevent unauthorized devices from connecting to the wired network by enforcing identity-based access control at the access switch port?

Easy
55

Which design component is necessary for implementing Cisco TrustSec across a multi-switch campus?

Medium
56

When designing a secure remote access solution for a hybrid workforce, which Cisco AnyConnect feature should be prioritized to reduce the attack surface by verifying the posture of the device before granting access?

Easy
57

When designing a VPN for a multi-tenant cloud environment, which technology allows for the separation of routing tables to ensure traffic isolation between tenants?

Hard
58

Which TWO features are essential for securing the management plane of a Cisco network device?

Medium
59

A company requires a control plane security design for their campus network. Which feature prevents unauthorized devices from claiming to be the default gateway?

Medium
60

Which Cisco feature is designed to protect the control plane of a router from being overwhelmed by traffic?

Medium
61

Which THREE services does Cisco Umbrella provide to secure remote workers? (Select 3)

Medium
62

You are designing a management plane security strategy for Cisco networking devices. Which protocol is recommended to replace Telnet to ensure encrypted administrative sessions?

Hard
63

Which TWO factors are vital for an effective firewall policy design?

Medium
64

You are designing a secure infrastructure for a SaaS-heavy office. What strategy best minimizes the impact on user experience while maintaining security?

Hard
65

You are designing an IoT security strategy for a manufacturing site. Which approach best isolates unmanaged IoT devices from the enterprise network?

Medium
66

Which TWO design considerations are critical for a secure SD-WAN edge deployment?

Medium
67

Which feature enables Cisco switches to limit the amount of broadcast traffic received on a port?

Medium
68

Which THREE design components are required for a successful implementation of Cisco TrustSec? (Select 3)

Medium
69

Which Cisco solution provides DNS-layer security to prevent users from connecting to malicious domains?

Easy
70

A security designer is choosing a firewall architecture for a high-throughput data center core. Which Cisco Firewall platform is purpose-built for this requirement?

Easy
71

Which TWO design considerations are critical for a secure management plane for Cisco networking devices? (Select 2)

Hard
72

Which TWO identity-based design considerations are critical for secure endpoint access? (Select 2)

Hard
73

Which TWO factors must be considered when designing a Secure Remote Access VPN architecture for a hybrid workforce using Cisco AnyConnect?

Medium
74

Which TWO design considerations are essential when implementing a Zero Trust architecture for IoT devices in a campus environment using Cisco ISE and TrustSec?

Medium
75

When selecting a security approach for email threats, which Cisco technology provides automated sandboxing to protect against zero-day phishing?

Easy
76

A design team is implementing Cisco ISE for a hybrid work environment. Which Cisco ISE architectural component is responsible for processing RADIUS and TACACS+ requests while offloading policy decision logic from the Administration node?

Medium
77

A network designer needs to implement a VPN that supports both remote access and site-to-site connectivity. Which protocol is recommended for modern Cisco hardware?

Medium
78

In a design for a Zero Trust architecture, what is the primary function of the Policy Decision Point (PDP)?

Medium
79

When designing a secure management plane, why is it critical to use a dedicated Out-of-Band (OOB) network?

Medium
80

Which Cisco tool is best suited for designing and documenting network security architectures?

Easy
81

To protect a SaaS application accessed by remote users, which Cisco solution provides a unified cloud-native security stack including DNS-layer security and SWG?

Medium
82

A manufacturing firm wants to secure IoT devices using Cisco TrustSec. Which mechanism ensures that traffic from IoT sensors is isolated from corporate traffic without relying on complex VLAN/ACL management?

Hard
83

You are designing security for a multi-cloud environment. Which feature in Cisco Secure Firewall allows for automated policy deployment based on cloud tags?

Hard
84

Which protocol is used for the control plane communication between Cisco SD-WAN controllers?

Medium
85

Which TWO methods are effective for securing email infrastructure against phishing?

Medium
86

A security architect is designing a Cisco Secure Firewall deployment for a multi-cloud environment. Which design strategy ensures consistent security policy enforcement across AWS and Azure instances?

Medium

Frequently asked questions

What does the Secure Infrastructure Design domain cover on the SDSI exam?
Secure Infrastructure Design questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 86 Secure Infrastructure Design questions in the SDSI question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Secure Infrastructure Design questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
Cisco Designing Cisco Security Infrastructure (SDSI, 300-745, CCNP Security, design-focused) (SDSI) Secure Infrastructure Design Practice Questions