Courseiva

CCNA Application Security Design Questions

8 of 83 questions · Page 2/2 · Application Security Design topic · Answers revealed

76
MCQhard

When designing an API security architecture, what is the primary purpose of 'API Discovery' in the context of Cisco API Security?

A.To replace the need for API gateways
B.To inventory all API endpoints and identify shadow or undocumented APIs
C.To increase the API's performance
D.To automatically generate API documentation for developers
AnswerB

Inventory and shadow API detection are the primary goals of discovery.

Why this answer

API Discovery identifies all API endpoints in an environment to ensure that security policies can be applied to undocumented or shadow APIs.

77
MCQeasy

Which Cisco product provides visibility into traffic within the cloud, helping to identify potential microsegmentation policies?

B.Cisco Secure Workload
C.Cisco Meraki
D.Cisco Umbrella
AnswerB

Secure Workload is the visibility and segmentation tool.

Why this answer

Cisco Secure Workload captures flow telemetry across the cloud to provide the necessary visibility to build security policies.

78
Multi-Selectmedium

When designing a secure API environment, which THREE tasks should the API Gateway handle? (Choose THREE)

Select 3 answers
A.Application data storage
B.Authentication and authorization verification
C.Routing to appropriate backend microservices
D.Request rate limiting
E.Hard-coding all business logic
AnswersB, C, D

The gateway enforces access control.

Why this answer

The API gateway is responsible for securing the edge of the API architecture, including auth, rate limiting, and traffic routing.

79
MCQmedium

What is the purpose of 'Microsegmentation' in a cloud-native architecture?

A.To reduce the attack surface by isolating workloads
B.To automatically scale services based on demand
C.To provide high availability for the service
D.To optimize container scheduling
AnswerA

Isolating workloads via fine-grained rules is the core purpose.

Why this answer

Microsegmentation provides granular security by isolating workloads so that traffic is only allowed if explicitly required, reducing the attack surface.

80
MCQeasy

Which Cisco solution is primarily designed to provide visibility and protection for SaaS applications like Office 365, Salesforce, and Slack?

A.Cisco Secure Workload
B.Cisco Cloudlock
C.Cisco Secure Firewall
D.Cisco Umbrella
AnswerB

Cloudlock is the designated CASB solution.

Why this answer

Cisco Cloudlock is a cloud-native CASB designed to secure SaaS environments.

81
Multi-Selectmedium

Which TWO factors must be considered when designing SaaS security using Cisco Cloudlock to ensure compliance with data protection regulations? (Choose TWO)

Select 2 answers
A.Configuring BGP peering with the SaaS provider
B.Establishing remediation workflows for policy violations
C.Defining appropriate data classification and DLP policies
D.Enabling hardware-based encryption for the SaaS vendor
E.Installing agents on all end-user laptops
AnswersB, C

Automated remediation ensures that policy violations are addressed in a compliant timeframe.

Why this answer

Compliance requires identifying sensitive data types and defining automated remediation actions to protect that data.

82
MCQmedium

Your organization uses a hybrid cloud model. You are tasked with designing a security posture for workloads in AWS and Azure using Cisco Secure Workload. What is the benefit of the 'Anywhere' agent approach?

A.It provides consistent security policy enforcement across heterogenous environments
B.It automatically patches the underlying operating system
C.It replaces the need for a central management platform
D.It eliminates the need for any firewall rules in the cloud
AnswerA

This is the primary advantage of the workload-level agent.

Why this answer

The 'Anywhere' agent allows for consistent policy enforcement across diverse infrastructure, including on-premises and multiple cloud providers.

83
MCQmedium

You are designing microsegmentation for a Kubernetes cluster using Cisco Tetration (Secure Workload). You need to ensure that only authorized pods can communicate with a specific backend database service. Which architectural component should be enforced to achieve zero-trust segmentation at the application layer?

A.Deploy a service-level policy based on process and label identity via the Secure Workload agent.
B.Configure static IP-based ACLs on the physical leaf switches.
C.Implement VRF-lite on the nodes to isolate the database traffic.
D.null
E.Enable port-security on the virtual switch ports connecting the worker nodes.
AnswerA

Secure Workload uses identity-based policies derived from application labels to control traffic flow.

Why this answer

Cisco Secure Workload (Tetration) uses software agents on hosts to enforce policies. For Kubernetes, the agent leverages service-level labels to create microsegmentation policies that are independent of IP addresses, ensuring that security follows the workload.

← PreviousPage 2 of 2 · 83 questions total

Ready to test yourself?

Try a timed practice session using only Application Security Design questions.