Courseiva

300-410 · topic practice

Infrastructure Security practice questions

Practise Cisco CCNP ENARSI 300-410 Infrastructure Security practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: Infrastructure Security

What the exam tests

What to know about Infrastructure Security

Infrastructure Security questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Infrastructure Security exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Practice set

Infrastructure Security questions

20 questions · select your answer, then reveal the explanation

Question 1easymultiple choice
Study the full IPv6 explanation →

Which IPv6 FHS feature uses a 'device tracking' database to maintain reachability information for hosts?

Which TWO statements about EEM environment variables and their scoping are true? (Choose TWO.)

A network engineer runs the following command on Router R1:

R1# show snmp user

User name: monitor Engine ID: 800000090300001122334455 storage-type: nonvolatile Authentication Protocol: MD5 Privacy Protocol: DES Group-name: readonly

User name: admin Engine ID: 800000090300AABBCCDDEEFF storage-type: nonvolatile Authentication Protocol: SHA Privacy Protocol: AES256 Group-name: admin

Based on this output, which statement is correct?

Question 4hardmulti select
Read the full VPN explanation →

Which TWO statements about IPsec site-to-site VPN troubleshooting using 'show crypto session' and 'show crypto ipsec sa' are correct? (Choose TWO.)

snmp-server community public RO\nsnmp-server community private RW\nsnmp-server community secret RW

What is wrong with this configuration?

Question 6mediumdrag order
Study the full IPv6 explanation →

Drag and drop the steps to verify and validate IPv6 First Hop Security operational state into the correct order, from first to last.

Drag steps to the numbered slots on the right, or tap a step then tap a slot.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5
Question 7mediummultiple choice
Study the full IPv6 explanation →

A network engineer is troubleshooting an issue where IPv6 hosts are receiving multiple Router Advertisements from different routers, causing routing instability. The switch is configured with IPv6 First Hop Security features. The engineer wants to ensure that only the primary router's RAs are accepted by hosts. What is the most effective solution?

Question 8mediummultiple choice
Study the full IPv6 explanation →

In IPv6 First Hop Security, which feature is used to prevent duplicate address detection (DAD) attacks by snooping Neighbor Discovery (ND) messages?

Drag and drop the steps to configure SNMPv3 with auth-priv and verify traps into the correct order, from first to last.

Drag steps to the numbered slots on the right, or tap a step then tap a slot.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Drag and drop the steps to troubleshoot SNMP adjacency or connectivity failures into the correct order, from first to last.

Drag steps to the numbered slots on the right, or tap a step then tap a slot.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5
Question 11mediummultiple choice
Open the full VLAN trunking answer →

An engineer is troubleshooting a network where IPv6 hosts on VLAN 20 are unable to communicate with each other. The switch is configured with IPv6 First Hop Security features including Private VLAN (PVLAN) and IPv6 Source Guard. The hosts are in the same VLAN but cannot ping each other. What is the most likely cause?

Question 12mediummultiple choice
Read the full DHCP explanation →

In IPv6 First Hop Security, what is the purpose of the 'device-role' command in a DHCP guard policy?

Question 13easymultiple choice
Read the full VPN explanation →

What is the default IKE (ISAKMP) lifetime value in Cisco IOS for IPsec Site-to-Site VPN?

Which authentication type is the default when BFD authentication is enabled on Cisco IOS-XE?

Question 15mediummultiple choice
Read the full network assurance explanation →

What is the default SNMPv3 security level for a user configured with the "snmp-server user username groupname v3 auth sha password" command?

Question 16mediummultiple choice
Review the full routing breakdown →

A network engineer runs the following command on Router R1:

R1# show crypto isakmp sa

dst src state conn-id slot status

10.1.1.2        10.1.1.1        MM_ACTIVE      1       0     ACTIVE
10.1.1.3        10.1.1.1        MM_ACTIVE      2       0     ACTIVE

Based on this output, which statement is correct?

Question 17mediummultiple choice
Study the full IPv6 explanation →

In IPv6 FHS, what is the default action for 'RA Guard' when a rogue RA is detected on a switch port?

Which TWO commands are used to troubleshoot SNMPv3 authentication or encryption failures? (Choose TWO.)

Question 19mediumdrag order
Study the full AAA explanation →

Drag and drop the steps to configure SSH access with local AAA on a Cisco router into the correct order, from first to last.

Drag steps to the numbered slots on the right, or tap a step then tap a slot.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5
Question 20hardmultiple choice
Study the full IPv6 explanation →

A network engineer is troubleshooting an issue where IPv6 hosts are unable to perform Duplicate Address Detection (DAD) successfully. The switch is configured with IPv6 First Hop Security features including ND Inspection and ND Suppress. The engineer notices that Neighbor Solicitation messages for DAD are being dropped by the switch. What is the most likely cause?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Infrastructure Security sessions

Start a Infrastructure Security only practice session

Every question in these sessions is drawn from the Infrastructure Security domain — nothing else.

Related practice questions

Related 300-410 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the 300-410 exam test about Infrastructure Security?
Infrastructure Security questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Infrastructure Security questions in a focused session?
Yes — the session launcher on this page draws every question from the Infrastructure Security domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other 300-410 topics?
Use the topic links above to move to related areas, or go back to the 300-410 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the 300-410 exam covers. They are not copied from any real exam or dump site.