Courseiva

300-410 · domain

Infrastructure Security

Infrastructure Security covers device access control and control-plane protection on Cisco IOS/IOS-XE routers and switches. Expect scenario items on AAA with TACACS+ and RADIUS, fallback and authorization behavior, OSPF and EIGRP neighbor authentication, and Control Plane Policing, plus IPv6 first-hop security and uRPF features.

77 questions13 easy41 medium23 hard

Focused practice

Practice Infrastructure Security questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Infrastructure Security

Configure and verify AAA with TACACS+ or RADIUS and local fallback, OSPF/EIGRP neighbor authentication, and CoPP policies on Cisco IOS. The critical skill is reading show command output to confirm which authentication method or policy actually applied to the traffic.

AAA authentication, authorization, and accounting using TACACS+ and RADIUS with local fallback

OSPFv2 and OSPFv3 neighbor authentication using MD5 or SHA key chains

Control Plane Policing and control-plane protection for router CPU-bound traffic

IPv6 first-hop security and uRPF anti-spoofing features on Cisco IOS

Watch out for

Common Infrastructure Security exam traps

  • ▸Assuming 'aaa authentication login default group tacacs+ local' falls back to local when the TACACS+ server is reachable but rejects the user; fallback only occurs on server unavailability.
  • ▸Configuring OSPF MD5 authentication on an interface without matching authentication on the neighbor, or forgetting that authentication must be enabled in the OSPF area or interface.
  • ▸Building CoPP policy-maps with wrong match criteria or applying them to the wrong control-plane interface, so policing never affects the intended traffic.

Question index

All Infrastructure Security questions (77)

Click any question to see the full explanation, or start a practice session above.

1

A network engineer is configuring a Cisco IOS router to authenticate OSPFv2 neighbors using MD5. The engineer enters the following commands: interface GigabitEthernet0/0 ip ospf authentication message-digest ip ospf message-digest-key 1 md5 C1sco123 After applying the configuration, the OSPF neighbor relationship fails to form. Which action must the engineer take to resolve the issue?

Medium
2

A network engineer is configuring Unicast Reverse Path Forwarding (uRPF) on a Cisco IOS router to mitigate IP spoofing. The router has two interfaces: GigabitEthernet0/0 connecting to the internet (untrusted) and GigabitEthernet0/1 connecting to the internal network (trusted). The engineer wants to enable strict uRPF on the untrusted interface. Which command should be applied to GigabitEthernet0/0?

Medium
3

A network engineer is implementing Zone-Based Policy Firewall (ZPFW) on a Cisco IOS router. The router has three interfaces: inside, outside, and DMZ. The engineer wants to allow HTTP traffic from the inside zone to the DMZ zone, and block all other traffic from inside to DMZ. Which configuration is required?

Medium
4

A network engineer is troubleshooting a Cisco IOS router that is configured for AAA authorization. The engineer notices that users are not being authorized for certain commands even though the TACACS+ server is reachable and the user is authenticated. The configuration includes 'aaa authorization exec default group tacacs+ local' and 'aaa authorization commands 15 default group tacacs+ local'. Which issue is most likely causing the problem?

Hard
5

A network engineer is configuring Unicast Reverse Path Forwarding (uRPF) on a Cisco IOS router to mitigate spoofed source IP addresses. The engineer wants to allow traffic from a multihomed customer that uses asymmetric routing. Which uRPF mode should the engineer configure?

Easy
6

A network engineer is configuring AAA on a Cisco IOS router. The engineer wants to authenticate administrative users against a TACACS+ server and ensure that if the server is unreachable, a local username and password can be used as a fallback. Which configuration achieves this?

Easy
7

A network administrator is configuring a router to authenticate with a TACACS+ server for administrative access. The administrator enters the command `aaa authentication login default group tacacs+ local` on the router. Which statement describes the authentication behavior when the TACACS+ server is reachable but rejects the user's credentials?

Medium
8

A network engineer is configuring a Cisco IOS router to authenticate login users against an external TACACS+ server. The engineer wants to ensure that if the TACACS+ server becomes unreachable, local authentication is used as a fallback. Which command set correctly configures this behavior on the router?

Medium
9

A network security engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS router to protect against denial-of-service attacks. The engineer wants to ensure that CoPP policies are applied correctly and that the router's control plane is protected. Which two statements about CoPP configuration are true? (Choose two.)

Hard
10

A network engineer is configuring a Cisco IOS XE router to authenticate OSPFv3 neighbors. The engineer applies the following configuration under the OSPFv3 process: `area 0 authentication ipsec spi 256 sha1 0123456789ABCDEF0123456789ABCDEF01234567`. The engineer then verifies the neighbor relationship and sees that it remains in EXSTART state. Which action should the engineer take to resolve the issue?

Medium
11

A network administrator is configuring AAA on a Cisco IOS router. The administrator wants to authenticate administrative users against a TACACS+ server and ensure that if the TACACS+ server is unreachable, the router falls back to local authentication. The administrator has configured the TACACS+ server and local user accounts. Which additional configuration is required to achieve this?

Easy
12

A network administrator is configuring a Cisco IOS router to authenticate SSH users against an external TACACS+ server. The TACACS+ server is reachable at 10.10.10.5, and the shared secret is 'Cisco123'. The administrator wants to ensure that if the TACACS+ server is unreachable, a local user account 'backup' with privilege level 15 is used for authentication. Which configuration sequence correctly achieves this?

Medium
13

A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS XE router to protect against route processor overload. The engineer creates a class map matching OSPF and BGP traffic and a policy map that polices this traffic to 1 Mbps with a burst of 2000 bytes. After applying the policy map to the control plane, the engineer notices that OSPF adjacencies flap intermittently. Which action should the engineer take to resolve the flapping?

Hard
14

A network engineer is configuring a Cisco IOS XE router for Zone-Based Policy Firewall (ZPFW) to control traffic between a LAN zone and a WAN zone. The engineer wants to inspect all TCP and UDP traffic initiated from the LAN zone toward the WAN zone, while denying any traffic initiated from the WAN zone toward the LAN zone. The engineer has already created the zones and assigned interfaces. Which configuration step is required to achieve this?

Medium
15

A network administrator is implementing Control Plane Policing (CoPP) on a Cisco IOS router to protect against DoS attacks. The administrator wants to rate-limit ARP traffic destined to the route processor. Which configuration correctly applies a CoPP policy to ARP traffic?

Medium
16

A network engineer is configuring a Cisco IOS router to authenticate SSH users against a TACACS+ server. The engineer wants to ensure that if the TACACS+ server is unreachable, the router will fall back to using the local username and password configured on the router. Which command set correctly configures this fallback behavior?

Medium
17

A network administrator is configuring a Cisco IOS router to authenticate login users against a TACACS+ server. The administrator wants to ensure that if the TACACS+ server is unreachable, the router falls back to the local username database for authentication. Which configuration should be applied?

Medium
18

A network engineer is configuring Zone-Based Policy Firewall on a Cisco IOS XE router. The company requires that all traffic from the internal LAN zone to the untrusted Internet zone be inspected, but traffic from the Internet to the internal LAN must be blocked unless it is return traffic. The engineer has already defined zone pairs with 'zone-pair security IN-TO-OUT source LAN destination INTERNET' and applied an inspect policy-map. What must the engineer do to complete the configuration?

Medium
19

A network technician is configuring a Cisco IOS router to authenticate administrative users via TACACS+ using a centralized server. The requirement is that if the TACACS+ server is unreachable, the router should use the local username database for authentication. Which command sequence correctly configures this fallback behavior?

Easy
20

A network engineer is configuring IPsec VPN on a Cisco IOS router. The engineer wants to ensure that only traffic from the 192.168.1.0/24 subnet is encrypted and sent through the tunnel, while all other traffic is sent unencrypted. The engineer creates an extended ACL named VPN_TRAFFIC and applies it to the crypto map. However, after testing, the engineer finds that traffic from 192.168.1.0/24 is not being encrypted. Which action should the engineer take to correct the issue?

Hard
21

A network engineer is configuring IPsec VPN on a Cisco IOS router. The engineer wants to ensure that only traffic from the 10.1.1.0/24 subnet to the 10.2.2.0/24 subnet is encrypted, while all other traffic is sent unencrypted. The engineer also wants to use a pre-shared key for authentication. Which configuration element is required to define the interesting traffic?

Hard
22

A network engineer is configuring Unicast Reverse Path Forwarding (uRPF) on a Cisco IOS router to mitigate spoofed source IP addresses. The engineer wants to ensure that packets are dropped if the source IP address is not reachable via the same interface they arrived on. The engineer configures 'ip verify unicast source reachable-via rx' on interface GigabitEthernet0/0. However, some legitimate traffic from a secondary path is being dropped. What is the most likely cause?

Medium
23

A network engineer is troubleshooting an IPsec VPN tunnel between two Cisco IOS routers. The tunnel fails to establish, and the engineer sees the debug output: 'ISAKMP: Unable to find a valid preshared key'. The engineer verifies that the preshared key is identical on both peers. Which additional configuration is most likely causing the issue?

Hard
24

A network engineer is implementing Unicast Reverse Path Forwarding (uRPF) on a Cisco IOS XE router to mitigate spoofed source IP addresses. The router has two interfaces: GigabitEthernet0/0 (WAN, connected to ISP) and GigabitEthernet0/1 (LAN, connected to internal network). The engineer wants to apply strict uRPF on the WAN interface to drop packets with spoofed source addresses, but the internal network uses asymmetric routing, with some return traffic going out a different interface. The engineer applies the following configuration: interface GigabitEthernet0/0 ip address 203.0.113.1 255.255.255.0 ip verify unicast source reachable-via rx After applying this, the engineer notices that some legitimate traffic from the internal network is being dropped. Which action should the engineer take to resolve the issue while maintaining spoofing protection?

Hard
25

A network administrator is configuring AAA on a Cisco IOS router using TACACS+. The requirement is that if the TACACS+ server is unreachable, the router should allow administrative access using the local username and password configured on the router. Which configuration accomplishes this?

Hard
26

A network administrator is troubleshooting an 802.1X deployment on a Cisco switch. Users report that they cannot authenticate and are placed into a guest VLAN. The administrator suspects that the switch is not receiving EAPOL packets from the supplicants. Which two actions should the administrator take to verify that EAPOL packets are being received and processed on the switch? (Choose two.)

Medium
27

A network engineer is configuring object tracking to influence a static default route on a Cisco IOS router. The engineer wants the default route to be removed from the routing table if the tracked object (a reachability test to 192.0.2.1) goes down. The engineer enters the following configuration: track 1 ip route 192.0.2.1 255.255.255.255 reachability ip route 0.0.0.0 0.0.0.0 203.0.113.1 track 1 After the link to 203.0.113.1 fails, the default route remains in the routing table. What is the most likely reason?

Hard
28

A network engineer is implementing 802.1X authentication on a Cisco Catalyst switch. The engineer wants to ensure that if the RADIUS server is unavailable, the switch will place the port in a restricted VLAN for guest access. Which command must be configured on the switch port?

Hard
29

A network administrator is configuring AAA on a Cisco IOS router to authenticate administrative SSH users against a TACACS+ server. The administrator wants to ensure that if the TACACS+ server is unreachable, a locally configured user account can still be used for authentication. Which configuration should the administrator apply?

Easy
30

A network engineer is configuring an IPv6 First Hop Security feature on a Cisco Catalyst switch to prevent rogue devices from sending Router Advertisement messages with a prefix that conflicts with the legitimate prefix. The engineer wants to ensure that only authorized routers can advertise prefixes, while still allowing hosts to perform SLAAC. Which feature should be implemented?

Medium
31

A network engineer is configuring Unicast Reverse Path Forwarding (uRPF) on a Cisco IOS router to mitigate spoofed source IP addresses. The engineer wants to ensure that uRPF is applied in a way that allows asymmetric routing. Which uRPF mode should be configured?

Hard
32

A network administrator is configuring a Cisco IOS router to authenticate login users against an external TACACS+ server. The administrator wants to ensure that if the TACACS+ server becomes unreachable, local authentication is used as a fallback. The TACACS+ server has been configured with the IP address 10.1.1.100 and the shared secret key 'cisco123'. Which set of commands correctly implements this requirement?

Medium
33

A network engineer is deploying a new branch office router (Cisco IOS XE) and wants to protect the control plane from routing protocol floods. The router will run OSPF and EIGRP. The engineer must ensure that control plane packets are rate-limited and that the router logs when the rate is exceeded. Which of the following should be configured?

Medium
34

A network administrator is configuring Unicast Reverse Path Forwarding (uRPF) on a Cisco IOS router to mitigate IP spoofing. The router has two interfaces: GigabitEthernet0/0 connects to the internet, and GigabitEthernet0/1 connects to the internal network. The administrator wants to ensure that packets arriving on GigabitEthernet0/0 are dropped if their source address is not reachable via that interface. However, the administrator also wants to allow asymmetric routing where return traffic may use a different path. Which uRPF mode should be configured on GigabitEthernet0/0?

Medium
35

A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router to protect against a flood of OSPF hello packets. The engineer wants to ensure that OSPF hellos are rate-limited to 1000 packets per second (pps) with a burst of 2000 packets, while allowing all other traffic without policing. The engineer applies the following configuration: class-map match-any OSPF_HELLO match access-group name OSPF_HELLO_ACL ! policy-map COPP_POLICY class OSPF_HELLO police 1000 2000 conform-action transmit exceed-action drop class class-default police 1000000 2000000 conform-action transmit exceed-action drop ! control-plane service-policy input COPP_POLICY After applying the policy, the engineer notices that OSPF adjacencies are flapping. Which action should the engineer take to resolve the issue?

Hard
36

A network security engineer is configuring a Cisco IOS router to support Zone-Based Policy Firewall (ZPF). The engineer has created zones INSIDE and OUTSIDE, assigned interfaces to them, and now needs to allow HTTP traffic from INSIDE to OUTSIDE while inspecting return traffic. Which configuration step is required to achieve this?

Medium
37

A network engineer configures a Cisco IOS router with the following commands: ip access-list extended BLOCK_TELNET deny tcp any any eq 23 permit ip any any ! interface GigabitEthernet0/0 ip access-group BLOCK_TELNET in After applying the configuration, the engineer notices that Telnet traffic from the local router to a remote device is still successful. What is the cause of this issue?

Medium
38

A network administrator is implementing Control Plane Policing (CoPP) on a Cisco IOS router to protect the route processor from excessive traffic. The administrator wants to rate-limit ICMP echo requests destined to the router itself to 64 kbps, while allowing all other traffic to the control plane without restriction. Which configuration snippet correctly achieves this?

Hard
39

A network engineer is implementing Unicast Reverse Path Forwarding (uRPF) on a Cisco IOS router to mitigate IP spoofing. The router has two interfaces: GigabitEthernet0/0 (WAN) and GigabitEthernet0/1 (LAN). The engineer wants to apply strict mode uRPF on the WAN interface and loose mode uRPF on the LAN interface. Which two commands are required to accomplish this? (Choose two.)

Medium
40

A network engineer is configuring a Cisco IOS XE router to send syslog messages to a remote server for security auditing. The engineer wants to ensure that the syslog messages are protected from eavesdropping and tampering. The router already has a CA trustpoint configured. Which command should the engineer use to enable secure syslog?

Medium
41

A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS router to protect the route processor from excessive traffic. The engineer has created a class map named 'CRITICAL' that matches BGP traffic and a policy map named 'COPP-POLICY' that applies a police rate of 1000000 bps with a conform-action transmit and exceed-action drop. After applying the policy map to the control plane, the engineer notices that BGP sessions are flapping. Which action should the engineer take to resolve the issue?

Hard
42

A network engineer is configuring a Cisco IOS router to authenticate administrative SSH logins against an external TACACS+ server. The engineer wants to ensure that if the TACACS+ server becomes unreachable, a locally configured fallback account can still be used. The TACACS+ server IP is 10.1.1.100 and the shared key is 'Cisco123'. Which configuration snippet correctly implements this requirement?

Medium
43

A network engineer is configuring a site-to-site VPN between two Cisco IOS routers using IPsec. The engineer wants to ensure that only traffic from the 10.1.1.0/24 subnet is encrypted and sent over the VPN, while all other traffic is sent unencrypted. Which configuration element defines the traffic to be encrypted?

Medium
44

A network administrator is deploying 802.1X on a Cisco Catalyst switch. The switch is configured as an authenticator, and a RADIUS server is used for authentication. The administrator wants to ensure that if the RADIUS server becomes unreachable, endpoints are placed into a guest VLAN with limited access. Which command must be configured on the switch to enable this behavior?

Hard
45

A network administrator is configuring IPsec VPN on a Cisco IOS router. The administrator wants to ensure that only traffic from the 10.1.1.0/24 subnet to the 10.2.2.0/24 subnet is encrypted, while all other traffic is sent unencrypted. The administrator has configured the crypto ACL as follows: 'access-list 101 permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255'. However, after applying the crypto map, the administrator notices that all traffic, including traffic to other destinations, is being dropped. What is the most likely cause?

Medium
46

A network administrator is deploying Control Plane Policing (CoPP) on a Cisco IOS-XE router to protect the route processor from excessive traffic. The administrator creates a class-map to match all management traffic (SSH, SNMP, TACACS+) and a policy-map to police that traffic to 1 Mbps. After applying the service-policy to the control-plane, the administrator notices that some legitimate SNMP polling is being dropped. Which two actions can the administrator take to resolve this issue while maintaining protection against DoS attacks? (Choose two.)

Hard
47

A network engineer is configuring uRPF on a Cisco IOS router. The router has two interfaces: GigabitEthernet0/0 (WAN) and GigabitEthernet0/1 (LAN). The engineer wants to prevent spoofed packets from entering the WAN interface while allowing asymmetric routing. Which uRPF mode should be configured on GigabitEthernet0/0?

Medium
48

A network engineer is configuring a Cisco IOS router to use IPsec VPN with IKEv2. The engineer wants to ensure that the router prefers a specific transform set that includes AES-256 encryption and SHA-256 hashing for integrity. Which command correctly defines the IKEv2 proposal with these parameters?

Easy
49

A network engineer is configuring a Cisco IOS router to authenticate administrative SSH logins against an external TACACS+ server. The engineer wants to ensure that if the TACACS+ server becomes unreachable, local authentication is used as a fallback. Which configuration accomplishes this?

Medium
50

A network administrator is deploying 802.1X on a Cisco Catalyst switch. The switch is configured as an authenticator, and the RADIUS server is reachable. However, some devices such as printers do not support 802.1X supplicant software. The administrator wants these devices to be automatically placed into a restricted VLAN with limited access. Which feature should be configured on the switch ports to achieve this?

Hard
51

A network administrator is configuring IPsec VPN on a Cisco IOS router using IKEv2. The administrator wants to ensure that the IKEv2 proposal includes encryption and integrity algorithms that are considered secure. Which two algorithms should be included in the IKEv2 proposal? (Choose two.)

Medium
52

A network administrator is configuring a Cisco IOS router to use AAA authorization for administrative commands. The administrator wants to ensure that users are authorized for specific commands based on their user role. The TACACS+ server is configured with command authorization sets. Which AAA authorization method should the administrator configure to enforce command authorization?

Hard
53

A network administrator is configuring a Cisco IOS router to authenticate administrative logins using TACACS+ with a fallback to local authentication. The TACACS+ server is reachable, but the administrator wants to ensure that if the TACACS+ server becomes unreachable, local authentication is used. The router currently has the following configuration: aaa new-model aaa authentication login default group tacacs+ local tacacs server TAC1 address ipv4 10.1.1.1 key cisco What additional configuration is required to ensure that the router falls back to local authentication when the TACACS+ server does not respond?

Medium
54

A network administrator is configuring Unicast Reverse Path Forwarding (uRPF) on a Cisco IOS router to mitigate spoofed source IP addresses. The administrator wants to ensure that uRPF is applied in strict mode on an interface that connects to an ISP. Which command correctly enables strict uRPF on the interface?

Easy
55

A network engineer is implementing Unicast Reverse Path Forwarding (uRPF) on a Cisco IOS router to mitigate spoofed source IP addresses. The router has two interfaces: GigabitEthernet0/0 connected to the Internet, and GigabitEthernet0/1 connected to the internal network. The engineer wants to ensure that packets coming from the Internet are dropped if their source IP address is not reachable via the same interface. However, the internal network uses asymmetric routing, so strict uRPF cannot be used on the internal interface. Which configuration should be applied to GigabitEthernet0/0 to achieve the goal?

Hard
56

A network engineer is configuring IPsec VPN on a Cisco IOS router. The engineer wants to ensure that only traffic from the 192.168.1.0/24 subnet is encrypted and sent through the tunnel, while other traffic is sent unencrypted. Which configuration element is required to define the interesting traffic?

Medium
57

A network engineer is configuring a Cisco IOS XE router to mitigate spoofed source addresses on a WAN-facing interface using Unicast Reverse Path Forwarding. The WAN provider uses asymmetric routing, where return traffic from the provider occasionally arrives on a different interface than the one used for outbound traffic. The engineer wants to avoid dropping legitimate packets while still providing anti-spoofing protection. Which uRPF mode should the engineer configure on the WAN interface?

Medium
58

A network engineer is configuring a Cisco IOS router to authenticate management users via TACACS+ against an ISE server. The engineer wants to ensure that if the TACACS+ server becomes unreachable, the router will fall back to using the local username database for authentication. The TACACS+ server is already configured with the address 10.1.1.100 and a shared secret. Which additional configuration is required on the router to achieve this fallback?

Medium
59

A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS XE router to protect against DoS attacks. The engineer has created a class-map to match malicious traffic and a policy-map to police it. Which two statements are true regarding the application and behavior of CoPP? (Choose two.)

Hard
60

A network administrator is configuring a site-to-site VPN on a Cisco IOS router using IPsec. The administrator wants to ensure that only traffic from the 192.168.1.0/24 subnet is encrypted and sent over the VPN tunnel. Which configuration component is used to define the interesting traffic?

Easy
61

A network engineer is configuring a site-to-site IPsec VPN on a Cisco IOS router. The engineer wants to ensure that only traffic from the 10.1.1.0/24 subnet to the 10.2.2.0/24 subnet is encrypted, while all other traffic is sent unencrypted. Which crypto ACL configuration achieves this?

Medium
62

A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS router to protect against DoS attacks. The engineer wants to rate-limit ARP packets destined to the route processor to 1000 packets per second, with a burst of 2000 packets. Which CoPP policy configuration accomplishes this?

Hard
63

A network administrator is deploying Control Plane Policing (CoPP) on a Cisco IOS XE router to protect the route processor from excessive control-plane traffic. After applying the CoPP policy, the administrator notices that OSPF adjacencies are flapping and that SNMP polling from the management station is failing. The administrator wants to correct the CoPP policy without disabling protection entirely. Which two actions should the administrator take? (Choose two.)

Hard
64

A network security engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS router to protect against denial-of-service attacks. The engineer wants to classify and police traffic destined to the route processor. Which two types of traffic should be considered for policing? (Choose two.)

Medium
65

A network engineer is configuring a Cisco IOS router to authenticate management access using TACACS+. The TACACS+ server is reachable at 10.1.1.100. The engineer wants to ensure that if the TACACS+ server becomes unavailable, the router will fall back to using the local username database for authentication. Which command sequence correctly configures this fallback?

Medium
66

A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS router to protect the route processor from excessive traffic. The engineer wants to limit ICMP echo requests destined to the router to 100 packets per second, while allowing other traffic. Which configuration snippet correctly applies CoPP for this purpose?

Medium
67

A network technician is configuring SSH access on a Cisco IOS router. The technician wants to ensure that only SSH version 2 is allowed and that the RSA key pair is generated with a modulus of 2048 bits. Which commands are required?

Easy
68

A network engineer is configuring a Cisco IOS router to authenticate administrative SSH access using TACACS+ with a backup local user account. The TACACS+ server is reachable, but the engineer wants to ensure that if the TACACS+ server becomes unreachable, the router falls back to local authentication for users who are not defined on the TACACS+ server. Which AAA configuration accomplishes this?

Medium
69

A network administrator is configuring a Cisco IOS router for site-to-site VPN using DMVPN Phase 3. The administrator wants to ensure that spoke-to-spoke traffic flows directly between spokes without traversing the hub, and that the hub is only used for initial registration and route resolution. Which technology must be enabled on the spokes to achieve direct spoke-to-spoke communication?

Medium
70

A network engineer is configuring SSH access on a Cisco IOS router. The engineer wants to restrict SSH access to only the management subnet 192.168.1.0/24 and ensure that only SSH version 2 is used. Which set of commands accomplishes this?

Easy
71

A network engineer is configuring a Cisco IOS router to authenticate management users via TACACS+ using the server at 10.1.1.100 with the shared key 'Cisco123'. The engineer wants to ensure that if the TACACS+ server becomes unreachable, the router will fall back to local authentication using the local username 'admin' with password 'AdminPass'. Which configuration correctly achieves this?

Medium
72

A network engineer is configuring AAA authorization on a Cisco IOS router. The engineer wants to limit which commands a user can execute after logging in via SSH. The user should be allowed to run show commands but not configuration commands. Which AAA authorization method should be used?

Easy
73

A network technician is configuring a Cisco IOS router to use SSH for remote management. The technician generates an RSA key pair with 2048 bits, configures a local username and password, and enables SSH version 2. However, when attempting to connect via SSH, the connection is refused. Which additional configuration is required on the VTY lines to allow SSH access?

Easy
74

A network engineer is configuring a Cisco IOS XE router to authenticate administrative SSH users against a TACACS+ server. The engineer wants to ensure that if the TACACS+ server is unreachable, a locally configured fallback account can still be used to log in. The engineer also wants to ensure that the fallback account is not used when the TACACS+ server is reachable but rejects the credentials. Which AAA configuration should the engineer apply?

Medium
75

A network administrator is configuring AAA on a Cisco IOS router. The administrator wants to use a RADIUS server for authentication and authorization, but wants to use local authentication as a fallback if the RADIUS server is unreachable. Which command should be used to configure the fallback?

Easy
76

A network engineer is configuring Unicast Reverse Path Forwarding (uRPF) on a Cisco IOS router to mitigate spoofed source IP addresses. The engineer wants to ensure that uRPF is applied correctly and does not drop legitimate traffic. Which uRPF mode should the engineer use to allow asymmetric routing while still providing some protection?

Medium
77

A network engineer is configuring Unicast Reverse Path Forwarding (uRPF) on a Cisco IOS router to mitigate spoofed source IP addresses. The router has two interfaces: GigabitEthernet0/0 connecting to an ISP (untrusted) and GigabitEthernet0/1 connecting to the internal network. The engineer wants to ensure that uRPF is applied only to traffic entering from the ISP. Which configuration mode and command should be used?

Hard

Frequently asked questions

What does the Infrastructure Security domain cover on the 300-410 exam?
Configure and verify AAA with TACACS+ or RADIUS and local fallback, OSPF/EIGRP neighbor authentication, and CoPP policies on Cisco IOS. The critical skill is reading show command output to confirm which authentication method or policy actually applied to the traffic.
How many questions are in this domain?
This page lists all 77 Infrastructure Security questions in the 300-410 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Infrastructure Security questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
enarsi ENARSI infrastructure security Practice Questions