Courseiva
Security →mediumMultiple Choice

350-401 Security Practice Question

A company runs a Cisco IOS router as the WAN edge. The security team wants to detect and log traffic that matches a set of known malicious signatures without blocking legitimate traffic, while still dropping clearly malformed packets. Which technology should be deployed on the router?

⚠ Common exam trap

The trap here is assuming any stateful or encrypted feature provides signature-based detection, when only IPS matches known attack patterns.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cisco IOS Intrusion Prevention System with signature categories set to alert

Cisco IOS IPS inspects packets against a signature database and can be tuned to alert on matching traffic instead of dropping it, which meets the detection-and-logging requirement while preserving legitimate flows. Malformed packets can be handled by specific drop signatures, giving the security team both visibility and selective enforcement on the WAN edge router.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Zone-Based Policy Firewall with inspect actions

    Why it's wrong here

    Zone-Based Policy Firewall provides stateful inspection and can drop or pass traffic between zones, but it does not match known malicious signatures. It is useful for enforcing zone-to-zone policy, yet the requirement here is signature-based detection and logging rather than stateful zone filtering, so it does not fulfill the described goal.

  • ✗

    IPsec VPN with AES-256 encryption between peers

    Why it's wrong here

    IPsec provides confidentiality, integrity, and authentication for traffic between peers, but it does not inspect payloads for malicious signatures. Encrypting a session does not identify an attack pattern inside it, and IPsec cannot generate the signature-based alerts the security team requires. This technology addresses transport security, not intrusion detection.

  • ✓

    Cisco IOS Intrusion Prevention System with signature categories set to alert

    Why this is correct

    Cisco IOS IPS uses signatures to inspect traffic for known attack patterns and can be configured per signature or category to produce alerts rather than drops. This supports detection and logging of malicious traffic without blocking legitimate sessions, while malformed packets can still be dropped by specific signatures or by the IPS engine itself.

  • ✗

    Control Plane Policing with a rate limit on management traffic

    Why it's wrong here

    Control Plane Policing protects the route processor by rate-limiting traffic destined to the control plane, which helps against floods and CPU exhaustion. It does not analyze packet payloads against malicious signatures, so it cannot detect or log the attack patterns described. CoPP is a resilience mechanism, not an intrusion detection feature.

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.