Courseiva

CCNA Secure Infrastructure Design Questions

75 of 86 questions · Page 1/2 · Secure Infrastructure Design · Answers revealed

1
MCQmedium

What is the primary function of the 'AnyConnect' (Secure Client) profile?

A.To manage connection and security settings for the endpoint.
B.To act as an identity provider.
C.To store user credentials.
D.To monitor CPU usage on the host.
AnswerA

Profiles control the behavior and configuration of the client.

Why this answer

The profile defines the connection settings, server lists, and security policies for the client software.

2
Multi-Selecthard

Which TWO methods are used to provide secure remote access for a mobile workforce? (Select 2)

Select 2 answers
A.FTP
B.Duo Access Gateway
C.Cleartext HTTP
D.AnyConnect VPN
E.Telnet
AnswersB, D

Provides secure, identity-aware access to applications.

Why this answer

Remote access is best handled by encrypted VPN tunnels (AnyConnect) or identity-centric access proxies (Duo Access Gateway).

3
Multi-Selecthard

Which TWO design principles should be followed when selecting a firewall architecture for a multi-cloud environment? (Select 2)

Select 2 answers
A.Physical firewalls for all cloud segments
B.Centralized management of policies
C.Using cloud-native firewalls only
D.Consistent feature set across physical and virtual
E.Deploying firewalls in a single region
AnswersB, D

Consistency is achieved by managing all firewalls via a single interface (FMC).

Why this answer

Multi-cloud designs require consistent policies and centralized management to ensure a uniform security posture.

4
MCQeasy

Which Cisco solution provides host-based visibility and protection against fileless malware?

A.Cisco Secure Endpoint.
B.Cisco ISE.
C.Cisco Secure Firewall.
D.Cisco Prime Infrastructure.
AnswerA

Secure Endpoint provides host-based protection and visibility.

Why this answer

Cisco Secure Endpoint (formerly AMP for Endpoints) uses behavioral analysis to detect fileless malware.

5
MCQhard

In a hybrid work design, what is the advantage of using Cisco Umbrella's roaming client?

A.It replaces the need for a local firewall.
B.It provides consistent security coverage off-network.
C.It only works on internal corporate Wi-Fi.
D.It forces all traffic through a local DC.
AnswerB

The roaming client extends policy protection to the endpoint everywhere.

Why this answer

The roaming client ensures that security policies follow the device wherever it goes, regardless of the network connection.

6
MCQeasy

Which Cisco technology is used to ensure that only authorized users can connect to the network via guest portals?

A.Cisco Umbrella
B.Cisco ISE Guest Services
C.Cisco Firepower
D.Cisco Secure Endpoint
AnswerB

Guest services handle authentication and portal management.

Why this answer

Cisco ISE Guest Services provides captive portal functionality for self-service guest access.

7
MCQhard

A company is migrating to a SASE architecture using Cisco+ Secure Connect. Which component is responsible for the unified identity-based access control for remote users?

A.AnyConnect standalone VPN gateway.
B.Firepower Management Center cloud connector.
C.On-premises ISE cluster.
D.Cisco Duo integration within the Secure Connect platform.
AnswerD

Duo provides the necessary identity assurance and MFA within the SASE framework.

Why this answer

Cisco+ Secure Connect integrates Duo for identity verification and Cisco Umbrella for secure web gateway functions.

8
Multi-Selecthard

Which THREE technologies enable network segmentation in a modern Cisco campus design?

Select 3 answers
A.Standard routing protocols without filters.
B.VRF-Lite.
C.Cisco TrustSec (SGTs).
D.Port forwarding.
E.VLANs.
AnswersB, C, E

VRFs provide L3 segmentation.

Why this answer

Segmentation is achieved through identity-based tags, virtualization, and VLAN isolation.

9
MCQhard

For a high-availability firewall architecture, which design element is critical when utilizing a routed-mode configuration in a data center?

A.Configuring HSRP between firewall interfaces.
B.Implementing OSPF equal-cost multi-path (ECMP) for load balancing.
C.Using a virtual MAC address per interface.
D.Utilizing a dedicated stateful failover link between firewalls.
AnswerD

The failover link is required to sync connection tables and configurations.

Why this answer

Stateful failover ensures that session information is synchronized, preventing connection drops during a device swap.

10
Multi-Selecthard

Which THREE Cisco solutions support the 'Secure Work from Anywhere' concept?

Select 3 answers
A.Cisco Secure Client (AnyConnect).
B.Cisco Duo.
C.Physical desk phone only.
D.Manual VPN configuration files.
E.Cisco Umbrella.
AnswersA, B, E

Provides secure connectivity.

Why this answer

Remote work requires secure connectivity, identity management, and endpoint protection.

11
MCQmedium

A design team is integrating Cisco Secure Firewall with an existing SIEM. Which telemetry export format is best for comprehensive security analysis?

A.NetFlow
B.SNMP
C.eStreamer
D.ICMP
AnswerC

eStreamer is the preferred method for exporting rich security event data from FMC.

Why this answer

Cisco Secure Firewall supports eStreamer and Syslog, but eStreamer is the specialized protocol for granular security event data.

12
Multi-Selectmedium

Which TWO features assist in protecting the network control plane against DoS attacks?

Select 2 answers
A.Configuring static routing only.
B.Increasing interface speed.
C.Disabling all physical interfaces.
D.Control Plane Policing (CoPP).
E.Control Plane Protection (CPPr).
AnswersD, E

CoPP rate-limits traffic to the CPU.

Why this answer

Control plane security requires limiting CPU-bound traffic and filtering malicious sources.

13
MCQhard

In a Cisco Secure Firewall architecture, what is the purpose of the 'Intrusion Policy'?

A.To optimize routing paths.
B.To handle VPN authentication.
C.To identify and block malicious traffic based on pattern matching.
D.To manage firewall NAT rules.
AnswerC

Intrusion policies use Snort to identify threats.

Why this answer

The Intrusion Policy inspects traffic for exploits, vulnerabilities, and malware patterns based on Snort rules.

14
MCQeasy

A security architect is designing a Cisco Secure Firewall deployment for a multi-cloud environment. Which design approach provides the most consistent security policy enforcement across AWS and Azure?

A.Deploy individual local managers for each cloud provider.
B.Rely on native cloud-native security groups only.
C.Implement separate FTD instances with unique local access control lists.
D.Utilize Cisco Defense Orchestrator for centralized policy management.
AnswerD

CDO is designed for centralized visibility and policy consistency.

Why this answer

Cisco Defense Orchestrator (CDO) provides a unified management plane to maintain consistent policies across different cloud infrastructures.

15
Multi-Selectmedium

Which THREE components are part of the Cisco Secure Firewall architecture? (Select 3)

Select 3 answers
A.Firepower Appliance
B.Cisco ISE
C.Firepower Management Center (FMC)
D.Firepower Threat Defense (FTD)
E.Cisco Stealthwatch
AnswersA, C, D

The hardware appliances execute the FTD software.

Why this answer

The architecture comprises the FMC (management), FTD (data plane), and the Firepower 4100/9300 or virtual appliances.

16
MCQhard

In a multi-cloud design, which protocol is preferred for secure inter-site communication to support micro-segmentation?

A.VXLAN with SGTs.
B.Standard GRE.
C.VLAN tagging.
D.802.1Q.
AnswerA

VXLAN carries group-based policy information across the network.

Why this answer

VXLAN with SGT (Group-Based Policy) allows for consistent policy enforcement across multi-cloud and data center environments.

17
MCQhard

In a multi-cloud design, which component is used to connect remote offices directly to the cloud provider while maintaining Cisco-level security?

A.Local NAT translation.
B.Cisco Secure Access Control Server (ACS).
C.Standard site-to-site IPsec tunnel.
D.Cisco SD-WAN Cloud OnRamp.
AnswerD

Cloud OnRamp automates the secure connectivity to cloud-hosted VPCs/VNets.

Why this answer

Cisco SD-WAN (Viptela) provides secure, optimized connectivity to cloud environments via Cloud OnRamp.

18
MCQmedium

When designing a network segmentation strategy using Cisco TrustSec, what is an SGT tag used for?

A.To map IP addresses to MAC addresses
B.To identify the VLAN ID
C.To configure port security
D.To enforce security policy based on identity
AnswerD

SGTs allow for group-based policy enforcement across the network.

Why this answer

SGTs are used as the source of truth in security group ACLs (SGACLs) to permit or deny traffic based on the tag value.

19
MCQeasy

When designing a remote access VPN solution using Cisco AnyConnect, which protocol is preferred to optimize performance for latency-sensitive applications like VoIP?

A.DTLS
B.TLS
C.IPsec IKEv2
D.SSTP
AnswerA

DTLS provides a low-latency connection suitable for real-time traffic.

Why this answer

DTLS (Datagram Transport Layer Security) is preferred for performance as it uses UDP, reducing the overhead and latency associated with TCP-based TLS.

20
MCQmedium

A security architect is designing a remote-work solution. What is the benefit of using Split Tunneling in Cisco Secure Client?

A.It provides dual authentication layers for the user.
B.It encrypts only the authentication phase of the VPN connection.
C.It allows internal traffic to be routed over the VPN while local traffic bypasses it.
D.It enforces all traffic through the corporate firewall.
AnswerC

Split tunneling optimizes performance by offloading non-corporate traffic.

Why this answer

Split tunneling allows trusted internet traffic to bypass the VPN, reducing latency and bandwidth load on the headend gateway.

21
MCQhard

For a zero-trust architecture, what is the primary function of Cisco ISE?

A.Managing user passwords.
B.Packet filtering at the edge.
C.Acting as a Policy Decision Point (PDP) for access control.
D.Automating WAN path selection.
AnswerC

ISE evaluates the policy and provides the access decision.

Why this answer

ISE acts as the Policy Decision Point (PDP) in a zero-trust architecture, validating identity and context before granting access.

22
Multi-Selectmedium

Which THREE factors should be considered when designing a security approach for a hybrid work model? (Select 3)

Select 3 answers
A.Physical security of the home office
B.Multi-factor authentication (MFA)
C.VLAN mapping for home routers
D.Direct internet access security
E.Endpoint posture assessment
AnswersB, D, E

MFA is essential for verifying remote user identity.

Why this answer

Hybrid work requires protecting the identity, the endpoint, and the remote access method simultaneously.

23
Multi-Selectmedium

Which TWO strategies are recommended for securing a cloud-native SaaS environment?

Select 2 answers
A.Duo MFA integration.
B.CASB implementation.
C.Opening all firewall ports.
D.Storing passwords in clear text.
E.Disabling all logging.
AnswersA, B

Identity is the perimeter for SaaS.

Why this answer

SaaS security focuses on identity and data protection.

24
MCQmedium

When designing a firewall architecture for a high-security zone, which inspection mode is required to identify malware within encrypted payloads?

A.Passive logging mode.
B.SSL/TLS Decryption and Inspection.
C.Bypass inspection mode.
D.Layer 3 routing mode.
AnswerB

Decryption is mandatory for inspecting encrypted payloads.

Why this answer

SSL/TLS decryption and inspection (formerly called inspection) are required to see inside encrypted traffic for malware signatures.

25
Multi-Selecthard

Which THREE design principles are key for a multi-cloud security strategy?

Select 3 answers
A.Using different security tools for each cloud.
B.Consistent security policies across environments.
C.Allowing all cross-cloud traffic.
D.Unified threat visibility.
E.Centralized management plane (FMC).
AnswersB, D, E

Policies must be uniform to prevent gaps.

Why this answer

Multi-cloud security relies on centralized management, consistent policy, and visibility.

26
MCQhard

When designing a secure remote access solution, what is the 'Always-On' VPN feature in AnyConnect primarily used for?

A.To reduce authentication time
B.To improve performance
C.To enable seamless roaming
D.To enforce security policy for off-network users
AnswerD

It ensures the user is always protected by corporate security policies.

Why this answer

Always-On VPN ensures that the VPN tunnel is established immediately when a client detects a network connection, enforcing security policy even off-premise.

27
MCQeasy

When designing a site-to-site VPN, which IKEv2 feature allows the tunnel to be established without requiring a static IP address on one side?

A.IKEv2 Virtual Tunnel Interfaces
B.AnyConnect Mobility
C.IKEv2 ID-based authentication
D.Dead Peer Detection
AnswerC

Using IDs (like FQDNs) allows tunnels to form when IPs are dynamic.

Why this answer

IKEv2 allows for identity-based authentication using certificates or pre-shared keys that do not depend on the peer's IP address.

28
MCQeasy

What is the benefit of integrating Cisco Secure Email with Cisco Threat Intelligence (Talos)?

A.It increases email storage capacity.
B.It creates automated email backups.
C.It allows for remote administration of the email server.
D.It provides real-time threat intelligence for filtering.
AnswerD

Talos feeds are essential for proactive threat detection.

Why this answer

Talos provides real-time updates on malicious domains and file signatures, blocking threats before they reach the inbox.

29
Multi-Selecthard

Which THREE components are part of a robust Cisco Zero Trust for the Workplace architecture?

Select 3 answers
A.Cisco Secure Endpoint for device posture.
B.Cisco Duo for user authentication.
C.DHCP for network address assignment.
D.Standard static IP filtering.
E.Cisco ISE for policy enforcement.
AnswersA, B, E

Secure Endpoint confirms device health.

Why this answer

Zero Trust relies on identity, device posture, and network access control for a unified security posture.

30
MCQhard

In an SD-WAN architecture, how does the design ensure the security of traffic between branches?

A.Configuring static VPN keys.
B.Using clear-text GRE tunnels.
C.Relying on MPLS provider security.
D.Enabling automated IPsec tunnels with IKEv2.
AnswerD

SD-WAN orchestrates secure tunnels between endpoints automatically.

Why this answer

SD-WAN uses IPsec tunnels with automated key management and secure overlay routing to protect branch-to-branch communication.

31
MCQhard

Which Cisco technology allows an organization to enforce security policies based on the user's location and device posture, even when the user is off-network?

A.Cisco AnyConnect
B.Cisco Duo
C.Cisco ASA
D.Cisco ISE
AnswerB

Duo enforces access policies based on posture and user identity.

Why this answer

Cisco Duo with its 'Trusted Endpoints' and 'Adaptive Authentication' policies evaluates device posture and location regardless of network connection.

32
MCQhard

You are designing the control plane security for a Cisco switch. Which feature limits the amount of traffic sent to the CPU, protecting it from DoS attacks?

A.Control Plane Policing (CoPP)
B.Port Security
C.Storm Control
D.DHCP Snooping
AnswerA

CoPP manages and filters traffic destined for the CPU.

Why this answer

Control Plane Policing (CoPP) is the feature used to rate-limit traffic destined for the device CPU.

33
MCQhard

A design architect is deploying a Cisco Secure Firewall in a High Availability (HA) pair. Which configuration is required to ensure stateful failover across firewalls?

A.Stateful failover link
B.HSRP on the interfaces
C.Control plane sync via FMC
D.VSS for Firewall
AnswerA

The failover link transmits stateful information for session persistence.

Why this answer

A dedicated state link (failover link) is required to synchronize connection tables and state information between the active and standby units.

34
MCQeasy

When configuring a Cisco ASA/Firepower firewall, what is the 'inside' interface typically used for?

A.To connect to the trusted internal network.
B.To connect to the untrusted internet.
C.To connect to the DMZ.
D.To connect to the management network.
AnswerA

The inside interface holds the internal trusted hosts.

Why this answer

The 'inside' interface is the trusted gateway for the internal network, typically having the highest security level (100).

35
MCQhard

In a Cisco SD-WAN environment, you need to ensure that branch office traffic destined for SaaS applications is optimized and secured. Which design approach is most appropriate?

A.Implementing Cisco Umbrella SIG integration on the SD-WAN edge devices for DIA.
B.Using static routing to bypass all security policies for trusted SaaS domains.
C.Deploying a dedicated physical firewall at every branch office.
D.Hair-pinning all SaaS traffic back to the corporate headend for inspection.
AnswerA

Umbrella SIG provides security at the edge, optimizing SaaS performance.

Why this answer

Direct Internet Access (DIA) with Cisco Umbrella integration ensures traffic is secured at the edge without hair-pinning to a DC.

36
MCQmedium

You are designing an IoT network segment. Which technology allows you to verify device identity at the hardware level?

A.MAC Authentication Bypass (MAB).
B.SNMPv3.
C.Static IP filtering.
D.802.1X with EAP-TLS.
AnswerD

EAP-TLS ensures secure hardware-level identification.

Why this answer

802.1X (EAP-TLS) utilizing digital certificates stored in a TPM or secure element allows for hardware-based identity verification.

37
MCQeasy

Which protocol is recommended for secure network time synchronization across security devices?

A.SNMP
B.HTTP
C.NTP with Authentication
D.DHCP
AnswerC

Authenticated NTP prevents time-spoofing attacks.

Why this answer

NTP with authentication is the industry standard for secure time synchronization.

38
MCQmedium

A network security designer is evaluating email security solutions. Which feature in Cisco Secure Email (ESA) is most effective against sophisticated Business Email Compromise (BEC) attacks?

A.Advanced Phishing Protection
B.URL Filtering
C.Spam Quarantine
D.DKIM Signing
AnswerA

APP analyzes email behavior and sender identity to prevent BEC.

Why this answer

Cisco Secure Email uses Advanced Phishing Protection (APP), which includes AI/ML-driven analysis of communication patterns to detect BEC.

39
MCQmedium

In a SaaS security design, what is the role of a Cloud Access Security Broker (CASB)?

A.To provide visibility and control over SaaS usage
B.To manage identity for the cloud
C.To act as a firewall for SaaS traffic
D.To encrypt end-to-end traffic
AnswerA

CASB bridges the gap between the enterprise security policy and cloud apps.

Why this answer

A CASB provides visibility, compliance, and threat protection for data stored in cloud applications.

40
MCQmedium

You are designing the security for a SaaS application access scenario. What is the role of the Cloud Access Security Broker (CASB)?

A.To manage local network switches.
B.To gain visibility into SaaS application usage and prevent data exfiltration.
C.To encrypt all internet-bound traffic at the gateway.
D.To provide physical security for data centers.
AnswerB

CASB is designed specifically for SaaS/Cloud security.

Why this answer

CASB provides visibility and control over data and users interacting with SaaS applications.

41
MCQeasy

Which component of the Cisco Secure architecture is used to provide centralized visibility and threat analysis across the entire network based on NetFlow data?

A.Cisco ISE
B.Cisco Secure Endpoint
C.Cisco Secure Network Analytics
D.Cisco Firepower Management Center
AnswerC

Stealthwatch analyzes NetFlow for anomaly detection.

Why this answer

Cisco Secure Network Analytics (formerly Stealthwatch) uses NetFlow to provide network-wide visibility and behavioral threat detection.

42
MCQmedium

Which Cisco feature is used to prevent the unauthorized use of dynamic IP addresses on a network?

A.Port Security.
B.Dynamic ARP Inspection (DAI).
C.DHCP Snooping.
D.IP Source Guard.
AnswerD

IPSG enforces the binding database created by DHCP snooping.

Why this answer

IP Source Guard (IPSG) restricts IP traffic on non-routed ports to only those IP addresses that were assigned via DHCP.

43
MCQmedium

You are designing a security architecture for a hybrid cloud environment using Cisco Secure Firewall. Which design pattern effectively mitigates the risk of lateral movement between VPCs in AWS while maintaining centralized policy enforcement?

A.Relying solely on AWS Security Groups for inter-VPC traffic.
B.Implementing an Overlay Network using Cisco ACI Remote Leaf.
C.Utilizing a Transit Gateway with a centralized inspection VPC and VPC attachments.
D.Deploying individual firewall appliances in each VPC.
AnswerC

Centralized inspection via Transit Gateway allows for consistent security policy application.

Why this answer

Using a Transit Gateway with a centralized inspection VPC forces traffic through a firewall cluster, enabling consistent policy enforcement.

44
Multi-Selectmedium

Which TWO factors are critical for selecting a firewall architecture?

Select 2 answers
A.Using only legacy IPsec gateways.
B.Availability of local coffee in the DC.
C.Integration with current management ecosystem (e.g., FMC).
D.The color of the firewall chassis.
E.Required throughput and inspection depth.
AnswersC, E

Operational consistency is vital.

Why this answer

Architecture selection is driven by throughput requirements and the need for advanced security features.

45
MCQmedium

When designing a firewall for a data center, what is the best practice for handling high-bandwidth traffic inspection?

A.Use software-based inspection only.
B.Disable deep packet inspection.
C.Route all traffic through the management interface.
D.Use hardware-accelerated inspection.
AnswerD

Offloading prevents performance degradation.

Why this answer

Using Hardware Acceleration (FPGA/ASIC) offloads inspection from the main CPU, maintaining performance during high throughput.

46
MCQmedium

You are designing an email security gateway deployment. What is the benefit of using Cisco Secure Email's 'Outbreak Filters'?

A.It blocks spam based on reputation
B.It archives email for compliance
C.It provides predictive protection for zero-day threats
D.It encrypts outgoing email
AnswerC

Outbreak filters act proactively before signatures are available.

Why this answer

Outbreak Filters protect users during the window between a new threat release and the availability of signatures by analyzing email traffic patterns.

47
Multi-Selectmedium

Which THREE features of Cisco Secure Email help in mitigating email-based threats? (Select 3)

Select 3 answers
A.DHCP snooping
B.VLAN isolation
C.Cisco Threat Grid sandboxing
D.Outbreak filters
E.SenderBase reputation service
AnswersC, D, E

Sandboxing analyzes attachments for hidden malware.

Why this answer

Cisco Secure Email uses reputation, spam filtering, and sandboxing (Threat Grid) to stop threats.

48
Multi-Selectmedium

Which TWO methods provide identification for IoT devices in an enterprise network?

Select 2 answers
A.802.1X (EAP-TLS).
B.Ignoring the device type.
C.Using public Wi-Fi access.
D.Device profiling (ISE).
E.MAC address spoofing.
AnswersA, D

Certificates provide the strongest identity.

Why this answer

IoT devices require various methods to be identified, ranging from profiling to certificate-based methods.

49
MCQmedium

When designing a VPN solution for a hybrid workforce, which protocol provides the most robust support for DTLS to minimize latency for real-time traffic?

A.Cisco Secure Client with DTLS enabled.
B.SSL VPN Clientless portal.
C.L2TP/IPsec.
D.IPsec IKEv1.
AnswerA

Cisco Secure Client (formerly AnyConnect) uses DTLS to handle real-time traffic efficiency.

Why this answer

AnyConnect (Cisco Secure Client) utilizes DTLS to prioritize latency-sensitive traffic over the standard TLS tunnel.

50
Multi-Selecthard

Which THREE technologies are used in Cisco's architecture for micro-segmentation?

Select 3 answers
A.Cisco ISE as the policy engine.
B.Scalable Group Tags (SGT).
C.Policy Enforcement Points (e.g., switches/firewalls).
D.Standard unmanaged switches.
E.Static IP ACLs on every port.
AnswersA, B, C

ISE defines the policy.

Why this answer

Micro-segmentation requires tagging and distributed enforcement.

51
MCQmedium

Which design principle is essential when configuring Cisco Secure Firewall for SaaS application visibility?

A.Disable SSL decryption for all SaaS traffic to improve performance.
B.Enable Application Filtering policies using the cloud-delivered feed.
C.Install local agents on every endpoint.
D.Configure static IP-based rules for every SaaS provider.
AnswerB

Cisco's application database updates via cloud feeds to ensure SaaS visibility.

Why this answer

Cloud-native application visibility is enabled by the Cisco Secure Firewall's integration with the Cisco Talos Intelligence service for application classification.

52
MCQmedium

When designing an endpoint security strategy, which Cisco tool provides visibility into fileless malware by monitoring system process behavior?

A.Cisco Umbrella
B.Cisco Stealthwatch
C.Cisco Secure Endpoint
D.Cisco Duo
AnswerC

Secure Endpoint monitors process behavior to identify fileless attacks.

Why this answer

Cisco Secure Endpoint (formerly AMP for Endpoints) uses behavioral analytics to detect fileless malware executing in memory.

53
MCQeasy

Which Cisco platform provides a centralized view of security threats across the entire enterprise?

A.Cisco SecureX.
B.Cisco Catalyst Center.
C.Cisco Webex Control Hub.
D.Cisco DNA Center.
AnswerA

SecureX provides a unified security dashboard.

Why this answer

Cisco SecureX (now evolving into XDR) is the platform for unifying security visibility and orchestration.

54
MCQeasy

Which Cisco feature is used to prevent unauthorized devices from connecting to the wired network by enforcing identity-based access control at the access switch port?

A.MAC Authentication Bypass
B.Port Security
C.DHCP Snooping
D.802.1X
AnswerD

802.1X provides authentication via RADIUS/ISE before granting access.

Why this answer

IEEE 802.1X is the standard for port-based network access control.

55
MCQmedium

Which design component is necessary for implementing Cisco TrustSec across a multi-switch campus?

A.VLAN Trunking Protocol (VTP).
B.LLDP.
C.SXP (SGT Exchange Protocol).
D.802.1Q.
AnswerC

SXP propagates SGTs between devices.

Why this answer

SXP (SGT Exchange Protocol) is required to propagate SGT (Scalable Group Tag) information to switches that do not natively support hardware-based tagging.

56
MCQeasy

When designing a secure remote access solution for a hybrid workforce, which Cisco AnyConnect feature should be prioritized to reduce the attack surface by verifying the posture of the device before granting access?

A.IKEv2 protocol support.
B.AnyConnect Posture Module.
C.Split-tunneling.
D.Dynamic Access Policies (DAP).
AnswerB

Posture checks verify the device security state before connection.

Why this answer

HostScan or the AnyConnect Posture module allows for pre-connection assessment.

57
MCQhard

When designing a VPN for a multi-tenant cloud environment, which technology allows for the separation of routing tables to ensure traffic isolation between tenants?

A.VLAN tagging
B.VRF-Lite
C.Access Control Lists
D.IPsec Tunnels
AnswerB

VRF-Lite isolates routing traffic per tenant at the layer 3 level.

Why this answer

VRF-Lite (Virtual Routing and Forwarding) allows multiple instances of a routing table to coexist on the same router, providing tenant isolation.

58
Multi-Selectmedium

Which TWO features are essential for securing the management plane of a Cisco network device?

Select 2 answers
A.Using public IP addresses for management interfaces.
B.Access Control Lists (ACLs) applied to VTY lines.
C.Disabling all physical console ports.
D.Enabling Telnet for remote management.
E.Implementing SSH for encrypted remote access.
AnswersB, E

Restricting VTY access is a fundamental security practice.

Why this answer

Management plane security relies on limiting administrative access to specific networks and securing the communication channel.

59
MCQmedium

A company requires a control plane security design for their campus network. Which feature prevents unauthorized devices from claiming to be the default gateway?

A.Dynamic ARP Inspection (DAI).
B.Port Security.
C.IP Source Guard.
D.Control Plane Policing (CoPP).
AnswerA

DAI prevents unauthorized devices from intercepting traffic by spoofing ARP replies.

Why this answer

DHCP Snooping and Dynamic ARP Inspection (DAI) are primary defenses against man-in-the-middle attacks that target the control plane.

60
MCQmedium

Which Cisco feature is designed to protect the control plane of a router from being overwhelmed by traffic?

A.Access Control Lists (ACLs).
B.Traffic Shaping.
C.Control Plane Policing (CoPP).
D.NetFlow.
AnswerC

CoPP limits traffic to the control plane.

Why this answer

Control Plane Policing (CoPP) rate-limits traffic destined for the router's processor.

61
Multi-Selectmedium

Which THREE services does Cisco Umbrella provide to secure remote workers? (Select 3)

Select 3 answers
A.Host-based Antivirus
B.Local network DHCP service
C.Cloud Access Security Broker (CASB)
D.Secure Web Gateway (SWG)
E.DNS-layer security
AnswersC, D, E

Umbrella inspects SaaS application usage.

Why this answer

Umbrella provides DNS-layer security, SWG (web proxy), and CASB functionality.

62
MCQhard

You are designing a management plane security strategy for Cisco networking devices. Which protocol is recommended to replace Telnet to ensure encrypted administrative sessions?

A.Netconf
B.SSH
C.SNMPv2c
D.HTTPS
AnswerB

SSH provides strong encryption for CLI access.

Why this answer

SSH (Secure Shell) provides encrypted management sessions, replacing insecure protocols like Telnet.

63
Multi-Selectmedium

Which TWO factors are vital for an effective firewall policy design?

Select 2 answers
A.Logical organization and rule documentation.
B.Disabling all logging.
C.Least privilege principle.
D.Using only IP addresses.
E.Permit all traffic by default.
AnswersA, C

Essential for maintainability.

Why this answer

Policy design must prioritize explicit rules and maintainable structure.

64
MCQhard

You are designing a secure infrastructure for a SaaS-heavy office. What strategy best minimizes the impact on user experience while maintaining security?

A.Backhauling all traffic to the data center.
B.Implementing DIA with localized SASE security.
C.Using a client-based proxy for everything.
D.Bypassing all security for trusted SaaS apps.
AnswerB

DIA optimizes latency, and SASE provides distributed security.

Why this answer

Direct Internet Access (DIA) via SD-WAN coupled with a SASE-based security stack provides fast SaaS access while maintaining inspection.

65
MCQmedium

You are designing an IoT security strategy for a manufacturing site. Which approach best isolates unmanaged IoT devices from the enterprise network?

A.Deploy a transparent firewall in bridge mode at the distribution layer.
B.Implement Cisco ISE with SGT-based micro-segmentation.
C.Enable PortFast on all IoT switch ports.
D.Assign static VLANs to all IoT ports on access switches.
AnswerB

SGTs provide scalable, identity-aware segmentation regardless of physical location.

Why this answer

Using Cisco ISE to enforce dynamic segmentation via TrustSec (SGTs) allows for granular isolation of IoT devices.

66
Multi-Selectmedium

Which TWO design considerations are critical for a secure SD-WAN edge deployment?

Select 2 answers
A.Using local breakout for all internet traffic without inspection.
B.Deploying devices with default passwords.
C.Centralized security policy enforcement via vManage.
D.Automated IPsec tunnel encryption.
E.Disabling the control plane firewall.
AnswersC, D

vManage provides the control plane for secure policies.

Why this answer

Secure SD-WAN edge deployments require both physical protection and robust logical encryption policies.

67
MCQmedium

Which feature enables Cisco switches to limit the amount of broadcast traffic received on a port?

A.Port Security.
B.Rate Limiting (QoS).
C.Storm Control.
D.Broadcast suppression.
AnswerC

Storm Control is the standard feature for broadcast management.

Why this answer

Storm Control prevents single ports from overwhelming the switch CPU or the network with excessive broadcast/multicast traffic.

68
Multi-Selectmedium

Which THREE design components are required for a successful implementation of Cisco TrustSec? (Select 3)

Select 3 answers
A.Cisco ISE
B.Scalable Group Tags (SGTs)
C.DHCP Snooping
D.Cisco Umbrella
E.Network Access Devices (NADs)
AnswersA, B, E

ISE is the policy engine that assigns the tags.

Why this answer

TrustSec requires the identity source (ISE), the enforcement points (switches/APs/firewalls), and the tags themselves.

69
MCQeasy

Which Cisco solution provides DNS-layer security to prevent users from connecting to malicious domains?

A.Cisco Stealthwatch.
B.Cisco Umbrella.
C.Cisco ASA Firewall.
D.Cisco Secure Endpoint.
AnswerB

Umbrella provides the DNS-layer security.

Why this answer

Cisco Umbrella uses DNS filtering to block requests to known malicious domains at the resolution layer.

70
MCQeasy

A security designer is choosing a firewall architecture for a high-throughput data center core. Which Cisco Firewall platform is purpose-built for this requirement?

A.Cisco Firepower 4100/9300 Series
B.Cisco Meraki MX
C.Cisco Firepower 1010
D.Cisco ASA 5506-X
AnswerA

These units are modular and optimized for data center throughput.

Why this answer

The Cisco Firepower 9300 or 4100 series is designed for data center environments requiring high throughput and low latency.

71
Multi-Selecthard

Which TWO design considerations are critical for a secure management plane for Cisco networking devices? (Select 2)

Select 2 answers
A.Enabling HTTP for the Web GUI
B.Implementing ACLs on VTY lines
C.Disabling the console port
D.Using SNMPv1
E.Using SSH instead of Telnet
AnswersB, E

This restricts management access to known IP addresses.

Why this answer

Management plane security requires limiting access to the device and ensuring the protocols used are encrypted.

72
Multi-Selecthard

Which TWO identity-based design considerations are critical for secure endpoint access? (Select 2)

Select 2 answers
A.Device posture validation
B.Port security configuration
C.Disabling DHCP
D.Physical cabling security
E.Multi-factor authentication
AnswersA, E

Posture check ensures the device meets security requirements.

Why this answer

Endpoints must be verified via posture (is it safe?) and identity (is the user allowed?) to grant access.

73
Multi-Selectmedium

Which TWO factors must be considered when designing a Secure Remote Access VPN architecture for a hybrid workforce using Cisco AnyConnect?

Select 2 answers
A.Integration with Duo Security for multi-factor authentication.
B.Physical port density on the headend device.
C.The use of DTLS for latency-sensitive traffic.
D.Configuring internal DNS servers for split-tunneling.
E.Maximum supported concurrent user sessions on the ASA or FTD.
AnswersA, E

MFA is a mandatory security design component.

Why this answer

The number of concurrent sessions and the integration with MFA are critical for scaling and security.

74
Multi-Selectmedium

Which TWO design considerations are essential when implementing a Zero Trust architecture for IoT devices in a campus environment using Cisco ISE and TrustSec?

Select 2 answers
A.Using static IP addresses for every IoT device to ensure consistency.
B.Utilizing Cisco ISE to profile and categorize IoT endpoints.
C.Applying Scalable Group Tags (SGTs) to enforce micro-segmentation.
D.Ensuring all IoT devices are placed in the same VLAN for easier management.
E.Disabling 802.1X for all non-PC devices.
AnswersB, C

Profiling is essential to identify the device type for policy application.

Why this answer

Profiling and segmentation are the core components of IoT Zero Trust.

75
MCQeasy

When selecting a security approach for email threats, which Cisco technology provides automated sandboxing to protect against zero-day phishing?

A.Cisco Duo MFA.
B.Cisco Secure Malware Analytics.
C.Cisco Umbrella DNS layer security.
D.Cisco Secure Endpoint protection.
AnswerB

Secure Malware Analytics provides the sandboxing capability for email attachments.

Why this answer

Cisco Secure Email (formerly ESA) integrates with Secure Malware Analytics (formerly Threat Grid) for sandboxing.

Page 1 of 2 · 86 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Secure Infrastructure Design questions.