Courseiva

300-410 · topic practice

Infrastructure Security practice questions

Infrastructure Security covers device access control and control-plane protection on Cisco IOS/IOS-XE routers and switches. Expect scenario items on AAA with TACACS+ and RADIUS, fallback and authorization behavior, OSPF and EIGRP neighbor authentication, and Control Plane Policing, plus IPv6 first-hop security and uRPF features.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Infrastructure Security

What the exam tests

What to know about Infrastructure Security

Configure and verify AAA with TACACS+ or RADIUS and local fallback, OSPF/EIGRP neighbor authentication, and CoPP policies on Cisco IOS. The critical skill is reading show command output to confirm which authentication method or policy actually applied to the traffic.

AAA authentication, authorization, and accounting using TACACS+ and RADIUS with local fallback

OSPFv2 and OSPFv3 neighbor authentication using MD5 or SHA key chains

Control Plane Policing and control-plane protection for router CPU-bound traffic

IPv6 first-hop security and uRPF anti-spoofing features on Cisco IOS

Watch out for

Common Infrastructure Security exam traps

  • ▸Assuming 'aaa authentication login default group tacacs+ local' falls back to local when the TACACS+ server is reachable but rejects the user; fallback only occurs on server unavailability.
  • ▸Configuring OSPF MD5 authentication on an interface without matching authentication on the neighbor, or forgetting that authentication must be enabled in the OSPF area or interface.
  • ▸Building CoPP policy-maps with wrong match criteria or applying them to the wrong control-plane interface, so policing never affects the intended traffic.

Practice set

Infrastructure Security questions

20 questions · select your answer, then reveal the explanation

Question 1easymultiple choice
Review the full routing breakdown →

A network engineer wants to secure management access to a Cisco IOS router by allowing only SSH and denying Telnet. The engineer applies the following configuration:

line vty 0 4

transport input ssh

However, after applying this, the engineer is unable to establish an SSH session to the router. Which additional configuration is required to enable SSH?

Question 2mediummultiple choice
Study the full AAA explanation →

A network engineer is configuring a Cisco IOS router to authenticate management users against a TACACS+ server. The engineer wants to ensure that if the TACACS+ server is unreachable, the router will fall back to using the local username database. The engineer also wants to log all authentication attempts to the TACACS+ server. Which configuration accomplishes this?

Question 3hardmultiple choice
Read the full VPN explanation →

A network administrator is configuring IPsec VPN on a Cisco IOS router. The requirement is to encrypt traffic between two sites using IKEv2. The administrator wants to ensure that the pre-shared key is not sent in clear text and that perfect forward secrecy (PFS) is used for the IPsec SA. Which combination of IKEv2 and IPsec parameters should be configured?

Question 4hardmulti select
Review the full routing breakdown →

A network administrator is implementing uRPF on a Cisco IOS router to mitigate spoofed source IP addresses. The router has two interfaces: GigabitEthernet0/0 (connected to the Internet) and GigabitEthernet0/1 (connected to the internal network). The administrator wants to ensure that uRPF does not drop legitimate traffic when asymmetric routing exists. Which two uRPF modes should the administrator consider? (Choose two.)

Question 5hardmultiple choice
Open the full VLAN trunking answer →

A network administrator is deploying 802.1X on a Cisco Catalyst switch. The administrator wants to ensure that if the RADIUS server becomes unavailable, the switch port is placed in a restricted VLAN that allows limited access to remediation resources. Which feature should be configured on the switch port?

Question 6hardmultiple choice
Study the full ACL explanation →

A network administrator is implementing Control Plane Policing (CoPP) on a Cisco IOS router to protect the route processor from excessive traffic. The administrator wants to limit ICMP echo requests destined to the router to 50 packets per second, with a burst of 100 packets, and drop excess traffic. Which configuration accomplishes this?

Question 7easymultiple choice
Read the full VPN explanation →

A network engineer is configuring a site-to-site IPsec VPN on a Cisco IOS router. The engineer wants to ensure that only traffic from the 10.1.1.0/24 subnet to the 10.2.2.0/24 subnet is encrypted. Which configuration element defines this traffic?

Question 8easymultiple choice
Review the full routing breakdown →

A network administrator is configuring SSH access on a Cisco IOS router. The administrator wants to ensure that only SSH version 2 is used and that the RSA key modulus is at least 2048 bits. Which set of commands accomplishes this?

Question 9mediummulti select
Study the full ACL explanation →

A network administrator is configuring Control Plane Policing (CoPP) on a Cisco IOS router to protect the route processor from excessive traffic. The administrator wants to rate-limit ICMP echo requests destined to the router itself. Which two actions must be performed to achieve this? (Choose two.)

Question 10hardmultiple choice
Review the full routing breakdown →

A network security engineer is configuring a Zone-Based Firewall (ZBFW) on a Cisco IOS router. The router has two zones: INSIDE and OUTSIDE. The requirement is to allow HTTP traffic from INSIDE to OUTSIDE, allow return traffic, and block all other traffic from INSIDE to OUTSIDE. Which configuration is necessary to achieve this?

Question 11mediummultiple choice
Study the full AAA explanation →

A network engineer is configuring a Cisco IOS router to authenticate login users against a RADIUS server. The RADIUS server is reachable at 10.1.1.100, and the shared secret is 'Cisco123'. The engineer also wants to ensure that if the RADIUS server is unreachable, the router falls back to local authentication using the local username 'admin' with password 'AdminPass'. Which configuration sequence correctly achieves this?

Question 12mediummultiple choice
Study the full ACL explanation →

A network engineer is configuring a site-to-site IPsec VPN between two Cisco IOS routers. The engineer wants to ensure that only traffic from the 10.1.1.0/24 network to the 10.2.2.0/24 network is encrypted, while all other traffic is sent unencrypted. Which access list configuration should be used in the crypto ACL?

Question 13hardmultiple choice
Study the full ACL explanation →

A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS router to protect the route processor from excessive traffic. The engineer wants to rate-limit ICMP echo requests destined to the router's management IP address to 10 Mbps, while allowing all other traffic to the control plane without restriction. The router uses a modular QoS CLI (MQC) configuration. Which set of commands correctly applies CoPP to achieve this?

A network administrator is configuring a Cisco IOS router to log all denied IP traffic on its outside interface to a syslog server at 192.168.1.50. The administrator wants to ensure that only denied packets are logged, and that the log messages include the source and destination IP addresses and port numbers. Which configuration accomplishes this?

Question 15hardmultiple choice
Study the full ACL explanation →

A network engineer is troubleshooting an IPsec VPN tunnel between two Cisco IOS routers. The tunnel is up, but traffic from the local subnet to the remote subnet is not being encrypted and is instead sent in clear text. The engineer verifies that the crypto map is applied to the correct interface and that the ACL matches the traffic. What is the most likely cause?

Question 16hardmulti select
Study the full AAA explanation →

A network engineer is configuring 802.1X authentication on a Cisco IOS switch. The engineer wants to ensure that if the RADIUS server is unreachable, the switch will fall back to MAC authentication bypass (MAB) for devices that do not support 802.1X. The engineer also wants to enable critical authentication for a phone that must always have access. Which two commands are required to achieve these goals? (Choose two.)

Question 17mediummulti select
Study the full AAA explanation →

A network security engineer is deploying 802.1X authentication on Cisco Catalyst switches. The engineer wants to ensure that if the RADIUS server becomes unavailable, endpoints can still access the network with limited privileges. The engineer plans to implement a fallback policy. Which two configurations are required to achieve this? (Choose two.)

Question 18hardmultiple choice
Open the full VLAN trunking answer →

A network engineer is deploying 802.1X on Cisco Catalyst switches. The requirement is to authenticate users via a RADIUS server and, if the RADIUS server is unreachable, to place the port in a restricted VLAN that allows limited access to remediation resources. Which set of commands on the switch interface correctly implements this fallback behavior?

Question 19hardmultiple choice
Study the full AAA explanation →

A network administrator is deploying 802.1X authentication on a Cisco Catalyst switch. The switch is configured as an authenticator, and the RADIUS server is reachable. However, when a PC attempts to authenticate, the switch port goes into the unauthorized state and the PC cannot access the network. The administrator notices that the switch is sending EAPOL-Start frames to the PC but receiving no response. Which action should the administrator take to resolve this issue?

Question 20hardmultiple choice
Study the full ACL explanation →

A network administrator is implementing Control Plane Policing (CoPP) on a Cisco IOS router. The administrator wants to rate-limit ARP packets destined to the route processor to 1000 packets per second, while allowing all other traffic without policing. Which configuration correctly applies CoPP to achieve this?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Infrastructure Security sessions

Start a Infrastructure Security only practice session

Every question in these sessions is drawn from the Infrastructure Security domain — nothing else.

Related practice questions

Related 300-410 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the 300-410 exam test about Infrastructure Security?
Configure and verify AAA with TACACS+ or RADIUS and local fallback, OSPF/EIGRP neighbor authentication, and CoPP policies on Cisco IOS. The critical skill is reading show command output to confirm which authentication method or policy actually applied to the traffic.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Infrastructure Security questions in a focused session?
Yes — the session launcher on this page draws every question from the Infrastructure Security domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other 300-410 topics?
Use the topic links above to move to related areas, or go back to the 300-410 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the 300-410 exam covers. They are not copied from any real exam or dump site.