Courseiva

350-401 · domain

Security

Security is 20% of ENCOR 350-401 and covers device hardening, access control, and traffic protection on Cisco IOS-XE and Catalyst platforms. Expect scenario questions on AAA with ISE or TACACS+, ACL and CoPP behaviour, 802.1X/MAB, port security, DHCP snooping, Dynamic ARP Inspection, IPsec, and MACsec, plus CLI output interpretation and configuration verification.

161 questions29 easy69 medium63 hard

Focused practice

Practice Security questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Security

Configure device hardening and access control using AAA (TACACS+/ISE), ACLs, CoPP, 802.1X/MAB, port security, DHCP snooping, and Dynamic ARP Inspection. The most important thing: verify ACL and CoPP order/interface direction, since mistakes silently drop or permit traffic.

Configuring AAA with TACACS+ or RADIUS, including authentication, authorization, and accounting method lists

Implementing Layer 2 protections: port security, DHCP snooping, Dynamic ARP Inspection, and 802.1X with MAB

Building and ordering standard, extended, and named ACLs, plus Control Plane Policing for management traffic

Configuring IPsec site-to-site VPNs and MACsec link encryption, including verifying SA and key status

Watch out for

Common Security exam traps

  • ▸Forgetting that ACL entries are processed top-down with an implicit deny, so a permit placed after a broader deny never matches
  • ▸Mixing up DHCP snooping trust on uplinks versus access ports, which breaks client addressing or leaves snooping ineffective
  • ▸Assuming 802.1X alone handles non-supplicant devices, instead of enabling MAB as a fallback on the same port

Question index

All Security questions (161)

Click any question to see the full explanation, or start a practice session above.

1

A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router to protect against excessive ARP traffic. The engineer applies the following policy: policy-map COPP-POLICY class ARP-CLASS police 8000 conform-action transmit exceed-action drop After applying the service-policy to the control-plane, the engineer notices that legitimate ARP requests are being dropped during peak hours. Which action should the engineer take to resolve this issue while maintaining protection?

Hard
2

An engineer is configuring an IPsec site-to-site VPN between two Cisco IOS XE routers. Phase 1 completes successfully, but Phase 2 fails and no interesting traffic is encrypted. The engineer confirms that the ACLs on both peers mirror each other correctly. Which configuration element should be verified next to resolve the Phase 2 failure?

Medium
3

A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS XE router to protect the route processor. The engineer wants to rate-limit ICMP echo requests destined to the router itself while ensuring that transit traffic passing through the router is not affected. Which classification approach should the engineer use in the CoPP policy?

Hard
4

A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS XE router that runs BGP, SSH, and SNMP. The engineer wants to ensure that BGP keepalives are not dropped during a control plane overload, while still rate-limiting SSH and SNMP. The engineer creates a class-map matching BGP, SSH, and SNMP traffic, then applies a policy-map with a single policer of 1000 pps to that class. After applying the service-policy to the control plane, BGP sessions flap during high CPU utilization. What is the most likely cause?

Hard
5

Refer to the exhibit. A switch has IP Source Guard (IPSG) and port-security enabled on interface GigabitEthernet0/1. A host with IP 10.1.1.1 and MAC 00:1A:2B:3C:4D:5E is connected and tries to access a web server at 192.168.1.100. What will happen?

Hard
6

A network engineer needs to secure management access to a Cisco IOS XE router. The requirement is to encrypt all management traffic, including SNMP, and to authenticate administrators against a centralized server. Which combination of features should be implemented?

Easy
7

A network engineer is configuring IPsec VPN on a Cisco IOS XE router. The requirement is to protect traffic between two sites using ESP with AES-256 encryption and SHA-256 authentication, and to ensure that the tunnel is rekeyed every 3600 seconds. Which configuration element directly controls the rekey interval?

Hard
8

A network administrator is configuring 802.1X on a Cisco Catalyst switch. The switch is connected to a Cisco IP phone with a PC attached to the phone's data port. The requirement is to authenticate both the phone and the PC separately, with the phone in the voice VLAN and the PC in the data VLAN. Which 802.1X feature should be enabled?

Medium
9

A security architect is evaluating MACsec on a Cisco Catalyst switch uplink between two buildings. The requirement is to encrypt all Layer 2 traffic on the link with minimal configuration and use a standards-based key agreement. Which statement correctly describes how MACsec should be deployed on this link?

Hard
10

A network engineer applies the above CoPP policy on a router. The router has BGP peers, SSH management, and SNMP monitoring. After applying this policy, which traffic will be affected?

Medium
11

A network engineer is configuring IPsec site-to-site VPNs on a Cisco IOS XE router. The design requires that the router authenticate peers using certificates issued by an internal PKI rather than pre-shared keys, and that IKEv2 be used for the key exchange. Which configuration element is required to support certificate-based authentication for IKEv2 on this router?

Hard
12

A Cisco Catalyst 9500 switch in a data center is configured with IP Source Guard on an access port where a server is connected. The server has a static IP address of 10.10.10.50 and MAC address 00:11:22:33:44:55. The network administrator has configured a static IP source binding using the command 'ip source binding 0011.2233.4455 vlan 10 10.10.10.50 interface GigabitEthernet1/0/1'. However, the server cannot communicate through the switch. What is the most likely cause?

Hard
13

A network engineer is deploying MACsec on a Cisco Catalyst switch to secure point-to-point links between the access and distribution layers. The design must ensure data confidentiality and integrity on the wire, and must use a key agreement mechanism that supports dynamic key exchange. Which TWO of the following are required to meet these requirements? (Choose two.)

Hard
14

A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router to protect the route processor from excessive SSH traffic. The engineer wants to classify SSH traffic destined to the router itself and apply a policer to it. Which mechanism is used by CoPP to classify traffic before the policer is applied?

Easy
15

A network administrator is configuring IPsec VPN on a Cisco IOS router. The administrator wants to ensure that only traffic from the 10.1.1.0/24 subnet to the 10.2.2.0/24 subnet is encrypted, while all other traffic is sent unencrypted. Which configuration element is required to define this traffic?

Medium
16

A network administrator is configuring a Cisco Wireless LAN Controller (WLC) to use 802.1X authentication for wireless clients. The administrator wants to ensure that the WLC communicates with the RADIUS server securely. Which protocol should be used to encrypt the RADIUS communication between the WLC and the RADIUS server?

Easy
17

A network administrator is configuring a site-to-site VPN between two Cisco routers using IPsec. The administrator wants to ensure that the data transmitted between the sites is encrypted and authenticated. Which IPsec protocol should be used to provide both confidentiality and integrity for the data payload?

Easy
18

A network security engineer is deploying Cisco TrustSec in a campus network. The engineer wants to implement Security Group Tags (SGTs) and enforce policies using a Cisco Catalyst switch as an enforcement point. Which two statements are true regarding SGT propagation and enforcement in this scenario? (Choose two.)

Hard
19

A network administrator is configuring a zone-based firewall on a Cisco IOS XE router. The requirement is to allow HTTP traffic from the INSIDE zone to the OUTSIDE zone while blocking all other traffic initiated from INSIDE. Which action must be taken to define the traffic that is permitted?

Easy
20

A campus switch connects to an IP phone that has a PC daisy-chained behind it. The engineer wants the phone to reside in VLAN 100 and the PC in VLAN 200, with the phone tagging its own voice traffic. Which interface configuration accomplishes this?

Hard
21

A network administrator is configuring a Cisco IOS zone-based firewall (ZBFW) on a router that connects a LAN zone to an Internet zone. The administrator wants to allow outbound HTTP and HTTPS from the LAN to the Internet while blocking all other outbound traffic, and to allow return traffic for established sessions. Which two configuration elements are required to accomplish this? (Choose two.)

Medium
22

A network engineer is deploying Control Plane Policing on a Cisco IOS XE router that runs BGP, SSH management, and SNMP monitoring. The engineer must ensure that BGP keepalives are never dropped even during a control-plane flood, while SSH and SNMP traffic should be rate-limited. Which CoPP configuration element accomplishes this requirement?

Medium
23

Refer to the exhibit. A network administrator notices that some DHCP packets are being dropped due to 'MAC Address Mismatch'. What is the most likely cause of this drop?

Easy
24

A network administrator needs to secure management access to a Cisco IOS XE switch. The requirement is that only SSH version 2 with a 2048-bit RSA key be accepted, that Telnet be disabled, and that only the 'netadmin' user with privilege level 15 be allowed to log in via VTY lines 0 through 4. Which configuration accomplishes this?

Easy
25

Drag and drop the steps to configure port security on a Cisco switch in the correct order.

Medium
26

A network engineer needs to provide secure remote-access VPN connectivity for employees using Cisco AnyConnect. The requirement is to use digital certificates issued by the corporate PKI for both server and client authentication. Which component must be configured on the Cisco ASA to validate client certificates presented during the VPN session?

Easy
27

A security team wants to deploy MACsec on a Cisco Catalyst switch uplink between two buildings to protect Layer 2 traffic. The switches are Cisco Catalyst 9300 series running IOS XE, and the link must encrypt all frames between them. Which statement accurately describes a requirement for this deployment?

Hard
28

Which TWO of the following are valid methods to mitigate VLAN hopping attacks?

Medium
29

A network engineer is hardening a Cisco IOS XE router that terminates IPsec site-to-site tunnels with remote branches. The security policy requires that the router only accept IKEv2 negotiations using cryptographically strong parameters and that it validate peer identity via certificates issued by the corporate PKI. Which two configuration elements must the engineer apply to meet these requirements? (Choose two.)

Hard
30

A network administrator is deploying Cisco TrustSec in a campus network. The security team wants to enforce role-based access control between endpoints without relying on IP addresses or VLANs, and they need to ensure that access policies are consistently applied even when endpoints move between switches. The administrator has already configured Cisco ISE for authentication and authorization. Which technology should be used to propagate the security group tag (SGT) information to network devices that do not support SGT tagging natively?

Medium
31

A network engineer must protect the OSPF adjacency between two Cisco routers from spoofed hello packets injected by a rogue device on the same broadcast segment. The engineer wants to use a cryptographic authentication method that is natively supported by OSPFv2 and does not rely on plain-text key exchange. Which configuration should be applied to the interfaces?

Medium
32

A network administrator is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router that peers BGP with two ISPs and is managed over SSH. The administrator needs to protect the route processor from excessive BGP and SSH traffic without breaking the existing sessions. Which action should be taken when applying the CoPP policy?

Medium
33

A network administrator is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router that runs BGP, SSH, and SNMP. The administrator needs to verify which traffic classes are being matched and how many packets are being dropped by the policy. Which command should be used to display the CoPP policy statistics and class-map information?

Medium
34

A network engineer is implementing IPsec VPN on a Cisco IOS XE router to connect a branch office to headquarters. The engineer must ensure that the IKEv2 negotiation uses strong authentication and that the data plane is protected with integrity and encryption. Which two configuration elements are required to achieve this? (Choose two.)

Medium
35

A network administrator is configuring IPsec VPN on a Cisco IOS router. The requirement is that the tunnel must support multicast traffic for OSPF neighbor adjacency across the VPN. Which IPsec configuration element is required to meet this requirement?

Hard
36

A network engineer is hardening a Cisco IOS XE router against control plane attacks. The router runs OSPF, BGP, and SSH management. The engineer wants to apply Control Plane Policing (CoPP) to rate-limit nonessential traffic while ensuring routing protocols are not disrupted. Which two actions should the engineer take? (Choose two.)

Medium
37

A network engineer is deploying Control Plane Policing on a Cisco IOS XE router that carries eBGP, OSPF, SSH management, and SNMP traffic. The engineer wants to ensure that BGP and OSPF routing updates are never dropped while still rate-limiting SSH and SNMP. Which CoPP configuration approach best meets this requirement?

Medium
38

A network engineer configures a Cisco IOS router to authenticate administrative SSH logins against a Cisco ISE server using TACACS+. After applying the configuration, a valid ISE user can log in but receives no privilege level and cannot enter privileged EXEC mode. The relevant configuration is: aaa new-model aaa authentication login default group tacacs+ local aaa authorization exec default group tacacs+ local tacacs server ISE address ipv4 10.10.10.50 key Cisco123 Which action most directly resolves the problem?

Medium
39

A network administrator needs to secure management access to a Cisco IOS XE switch. The requirement is to ensure that only SSH version 2 is used for remote CLI access, and that Telnet is disabled. Which configuration achieves this?

Easy
40

A network administrator is deploying a Cisco Wireless LAN Controller (WLC) running AireOS in a branch office. The security policy requires that guest wireless clients be isolated from internal corporate clients and that guest traffic be tunneled back to a DMZ interface on the WLC. Which WLAN configuration element should the administrator use to meet these requirements?

Medium
41

A network engineer is deploying 802.1X on a Cisco switch with Cisco ISE as the RADIUS server. The engineer wants to allow devices that do not support 802.1X supplicant to connect to a guest VLAN. Which feature should be configured on the switch port to accomplish this?

Hard
42

A security team is hardening a Cisco IOS router that terminates IPsec site-to-site tunnels to several branch offices. The team wants to protect the control plane by rate-limiting and filtering traffic destined to the router's own CPU. Which two mechanisms are designed specifically for control plane protection on Cisco IOS? (Choose two.)

Hard
43

A network administrator is configuring a site-to-site IPsec VPN between two Cisco IOS routers. The requirement is that the VPN must support dynamic routing protocol updates across the tunnel and allow multicast traffic between the sites. Which IPsec configuration mode should be used?

Medium
44

A network security engineer is configuring an IPsec site-to-site VPN between two Cisco IOS routers. The engineer wants to ensure that the VPN tunnel uses perfect forward secrecy (PFS) and that the encryption is AES-256. Which combination of commands achieves this?

Hard
45

A network administrator is configuring MACsec on a Cisco Catalyst switch to secure Layer 2 traffic between two switches. Which two statements about MACsec are true? (Choose two.)

Hard
46

A network security team is implementing Cisco TrustSec in a campus network. They need to deploy Security Group Tags (SGTs) and enforce policies using Security Group ACLs (SGACLs). Which two statements are true regarding SGT propagation and enforcement in this environment? (Choose two.)

Hard
47

A security architect is designing a Cisco TrustSec deployment for a campus network. The architect needs to ensure that security group tags (SGTs) are propagated across a Layer 2 trunk between two Catalyst switches that do not support SGACL enforcement. Which technology should be used to carry SGT information inline within the Ethernet frame?

Hard
48

A network administrator must secure management access to a Cisco IOS XE router so that only SSH version 2 is accepted and Telnet is disabled on all VTY lines. Which configuration accomplishes this requirement?

Easy
49

A network engineer is implementing Control Plane Policing (CoPP) on a Cisco ASR 1000 router to protect the route processor from excessive traffic. The router runs OSPF, BGP, SSH management, and NTP. The engineer wants to ensure that OSPF hello packets are always prioritized and that SSH traffic from the management subnet is rate-limited. Which two statements about the CoPP configuration are true? (Choose two.)

Hard
50

A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router. The router has management SSH access, SNMP monitoring, and BGP peering. After applying the CoPP policy shown in the exhibit, the engineer notices that SNMP polling from the management station fails, while SSH and BGP remain operational. Which action should be taken to restore SNMP polling while maintaining control plane protection?

Medium
51

A network security engineer is configuring 802.1X on a Cisco Catalyst switch with Cisco ISE as the RADIUS server. The switch is configured with 'dot1x system-auth-control' and the interface is set to 'authentication port-control auto'. The engineer wants to allow a printer that does not support 802.1X to connect to the network by using MAC Authentication Bypass (MAB). Which additional configuration is required on the switch interface to enable MAB?

Hard
52

An engineer must secure the management plane of a Cisco IOS XE router so that only SSH version 2 is accepted for remote administration, while Telnet and SSHv1 are rejected. Which set of commands accomplishes this?

Medium
53

A network security team is deploying MACsec on a Cisco Catalyst 9000 switch series to secure Layer 2 traffic between two switches. Which two statements about MACsec operation are true? (Choose two.)

Medium
54

A network engineer is deploying Control Plane Policing (CoPP) on a Cisco IOS XE router. The router runs BGP, OSPF, SSH management, and SNMP. After applying a CoPP policy that rate-limits all control-plane traffic to 1000 pps, BGP sessions flap and OSPF adjacencies reset during peak traffic. Which action should the engineer take to resolve the problem while maintaining control-plane protection?

Hard
55

Which TWO features are part of Cisco TrustSec for providing role-based access control?

Easy
56

A network administrator is deploying 802.1X on Cisco Catalyst access switches with Cisco ISE as the RADIUS server. The design requires that devices failing authentication be placed into a restricted VLAN, and that IP phones be authenticated before the attached PC. Which two features must be configured to meet these requirements? (Choose two.)

Medium
57

A network engineer is deploying MACsec on a Cisco Catalyst 9300 switch to secure a point-to-point link between two access switches. The engineer configures the switchport with the macsec command and a pre-shared key. After applying the configuration, the link comes up but MACsec is not encrypting traffic. Which action should the engineer take to resolve the issue?

Hard
58

A network administrator is deploying 802.1X on Cisco Catalyst switches with Cisco ISE as the RADIUS server. The administrator wants to allow devices that do not support 802.1X, such as printers, to connect to the network. Which feature should be configured on the switch ports to support these devices while maintaining security?

Medium
59

A network security team is hardening a Cisco IOS XE router that terminates IPsec tunnels to remote branch offices. The team wants to use zone-based firewall (ZBFW) to inspect traffic between the inside, outside, and VPN zones. Which two statements correctly describe zone-based firewall behavior on this platform? (Choose two.)

Medium
60

A network security team is evaluating Cisco TrustSec (CTS) for deployment in a campus network. The team wants to understand which components are essential for enforcing security group tags (SGTs) and providing role-based access control. Which two of the following are required to implement CTS with SGT enforcement? (Choose two.)

Medium
61

A network administrator is deploying Cisco TrustSec in a campus network. The security team wants to enforce access policy based on a device's role rather than its IP address, so that the enforced policy remains consistent even when endpoints move between VLANs or subnets. Which Cisco TrustSec component is responsible for assigning and carrying this role-based identity through the network?

Medium
62

A network security team deploys Cisco ISE for 802.1X wired authentication. The switches are configured with MAB as a fallback. A printer that does not support 802.1X is connected, but ISE rejects it even though the printer's MAC address is in the correct identity group. The switch port shows the authentication method as MAB and the status as unauthorized. Which configuration issue is the most likely cause?

Hard
63

A network administrator is configuring a site-to-site IPsec VPN between two Cisco IOS routers. The design requires that only traffic from specific subnets be encrypted and that the routers use a preshared key for authentication. Which combination of configuration elements must the administrator define to match the interesting traffic and establish the tunnel?

Medium
64

A network engineer is deploying Control Plane Policing on a Cisco IOS-XE router that runs OSPF, BGP, and SSH management. The engineer wants to rate-limit routing protocol traffic while ensuring that SSH management traffic is never dropped, even during a routing protocol flood. The router uses a single physical interface for all control plane traffic. Which CoPP design approach best meets these requirements?

Medium
65

An organization wants to implement 802.1X authentication on its wired network using Cisco ISE as the authentication server. The switches are configured with the necessary RADIUS settings. Which additional configuration is required on the switch interfaces to enable 802.1X?

Easy
66

A network administrator is deploying a new Cisco Catalyst 9200 switch at a branch office. The security policy requires that when a device connected to a port is shut down or moved, the switch must immediately send a SNMP trap and place the port into an error-disabled state while also incrementing a violation counter. The administrator configures port security with the violation mode that meets these requirements. Which command must be applied to the interface to achieve this?

Medium
67

A network administrator is configuring a Cisco IOS router to act as a VPN headend for remote access. The requirement is to use IKEv2 with certificate-based authentication. The administrator has installed a valid identity certificate on the router and configured the IKEv2 profile. However, remote clients are unable to establish the VPN tunnel, and the router logs show 'IKEv2 certificate authentication failed'. What is the most likely cause?

Easy
68

A company uses Cisco TrustSec in its campus network. Security policy requires that a user authenticated by 802.1X be assigned a Security Group Tag (SGT) based on the user's Active Directory group, and that the SGT be carried to downstream switches for enforcement. The access switch is configured for 802.1X with Cisco ISE. Which combination of features must be enabled to meet the requirement?

Hard
69

A network security engineer is deploying MACsec on a Cisco Catalyst 9000 switch. The switch is connected to a Cisco IP phone that does not support MACsec, and a PC is connected to the phone. The engineer wants to encrypt traffic between the switch and the phone, but the phone does not support MACsec. What should the engineer do to secure the link?

Hard
70

A network administrator at a small company wants to prevent users from plugging unauthorized switches into wall jacks and creating loops or bypassing security controls. The administrator decides to implement BPDU Guard on all access ports on a Cisco Catalyst switch. Which statement accurately describes the behavior of BPDU Guard when configured on an access port?

Easy
71

A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router to protect against DoS attacks. The router has a management plane that includes SSH and SNMP, and a control plane that includes routing protocols like OSPF and BGP. The engineer wants to rate-limit traffic destined to the route processor while ensuring that management traffic is not dropped during high CPU load. Which CoPP configuration approach is most appropriate?

Hard
72

A network administrator is deploying Cisco Identity Services Engine (ISE) for wired 802.1X authentication on a Cisco Catalyst 9200 switch. The RADIUS server is reachable at 10.10.10.50 with shared secret 'C1sco123'. The administrator wants the switch to authenticate users before granting access to the data VLAN, and to place unauthenticated devices into a restricted VLAN. Which command sequence correctly enables 802.1X on a switch port?

Medium
73

A network security architect is designing a Zero Trust architecture for a campus network using Cisco Identity Services Engine (ISE) and Cisco TrustSec. The requirement is to enforce segmentation based on user identity and device posture, and to apply policy dynamically as users move between wired and wireless access points. Which Cisco TrustSec component is responsible for tagging packets with a Security Group Tag (SGT) at the access layer?

Hard
74

A medium-sized enterprise is migrating to a Cisco DNA Center-managed network. The security policy requires that all administrative access to network devices be authenticated via TACACS+ and that authorization for commands be enforced per user role. The network team has configured ISE as the AAA server and integrated it with DNA Center. After configuration, engineers report that they can log in to devices via SSH but are not prompted for a password when entering 'enable' mode; instead, they are granted full privileges immediately. Additionally, while in configuration mode, some engineers can issue 'debug' commands that they should not have access to. The configuration on the devices includes 'aaa new-model', 'aaa authentication login default group tacacs+ local', 'aaa authorization exec default group tacacs+ local', and 'aaa authorization commands 15 default group tacacs+ local'. What is the most likely cause of the privilege escalation and missing authorization?

Medium
75

A network security administrator is configuring a Cisco IOS Zone-Based Firewall on a branch router. The inside zone and outside zone are defined, and the administrator wants to allow inside hosts to initiate sessions to outside servers while preventing outside hosts from initiating sessions to inside hosts. Which configuration accomplishes this?

Medium
76

A network administrator is implementing Control Plane Policing (CoPP) on a Cisco ASR 1000 router to protect against DoS attacks. The router has a management plane that must remain accessible via SSH and SNMP, and a control plane that must process BGP and OSPF routing updates. The administrator applies a CoPP policy that rate-limits all traffic destined to the control plane to 1000 pps, except for traffic from trusted management subnets. After applying the policy, BGP sessions flap intermittently. What is the most likely cause?

Hard
77

A network administrator is deploying Control Plane Policing (CoPP) on a Cisco IOS XE router to protect the route processor from excessive traffic. The router has a single physical interface Gi0/0/0 that carries both management SSH traffic and transit data traffic. The administrator wants the CoPP policy to apply only to traffic destined to the router's control plane, not to transit traffic. Which CoPP configuration element must be applied to achieve this?

Medium
78

A network engineer is deploying 802.1X on Catalyst access switches with Cisco ISE as the RADIUS server. Some endpoints, such as printers and badge readers, do not support 802.1X supplicants. The design must allow these devices onto a restricted VLAN while still requiring authentication for laptops. Which TWO mechanisms should the engineer configure to achieve this? (Choose two.)

Medium
79

A network administrator needs to securely manage a Cisco Catalyst switch remotely. The requirement is to encrypt all management traffic, including username and password, between the administrator's workstation and the switch. Which management protocol should be enabled on the switch to meet this requirement?

Easy
80

A security team is deploying Control Plane Policing (CoPP) on a Cisco ASR 1000 router to protect the route processor from excessive traffic. They notice that after applying a CoPP policy, OSPF adjacency with a directly connected neighbor flaps intermittently. Which action should the engineer take to resolve the issue while maintaining control plane protection?

Hard
81

A company runs a Cisco IOS router as the WAN edge. The security team wants to detect and log traffic that matches a set of known malicious signatures without blocking legitimate traffic, while still dropping clearly malformed packets. Which technology should be deployed on the router?

Medium
82

An engineer is configuring 802.1X on a Cisco Catalyst switch port where a PC is connected. The requirement is that if the authentication server becomes unreachable, the port should still allow the PC to send traffic in a restricted VLAN rather than being shut down. Which configuration meets this requirement?

Hard
83

A network security team is hardening a Cisco IOS-XE router that terminates IPsec VPN tunnels. They want to protect the control plane from CPU-intensive IKE and management traffic without dropping legitimate tunnel establishment packets. They decide to apply a Control Plane Policing (CoPP) policy. Which statement best describes how CoPP interacts with the forwarding plane and the control plane on this router?

Hard
84

A network administrator is configuring a Cisco IOS XE router to protect against spoofed source addresses on an internal interface facing user subnets. The requirement is to drop packets whose source address does not match the routing table entry for the incoming interface. Which feature should be enabled?

Easy
85

A security engineer is configuring CoPP (Control Plane Policing) on a Cisco router to protect the control plane from DoS attacks. The policy must rate-limit SSH traffic to 1 Mbps with a burst of 2000 bytes, and drop all other traffic destined to the control plane that exceeds a default rate. Which class-map and policy-map configuration is correct?

Hard
86

A security team wants to protect a web application hosted behind a Cisco IOS router from cross-site scripting and SQL injection attacks without modifying the application itself. Which Cisco IOS feature is designed for this purpose?

Easy
87

A network administrator is deploying Control Plane Policing (CoPP) on a Cisco IOS XE router that runs BGP, SSH, and NTP. The requirement is to protect the route processor from excessive BGP keepalive traffic while still allowing all legitimate BGP peering. Which CoPP module should the administrator use to classify and police this traffic before the policy is applied to the control plane?

Medium
88

An engineer is configuring a Cisco IOS XE switch to secure the management plane. The requirement is to allow SSH only from the management subnet 10.10.10.0/24 and block all other management protocols such as Telnet and HTTP. Which configuration approach best meets this requirement?

Medium
89

A network administrator is configuring a Cisco IOS router to terminate a site-to-site IPsec VPN with a remote peer that uses dynamic public IP addressing. The administrator wants the router to accept IKE negotiations from any peer that presents a valid pre-shared key and matches a specific protected subnet. Which configuration element is required to support this?

Medium
90

A network security engineer is deploying Cisco TrustSec in a campus network. The engineer wants to implement Security Group Tagging (SGT) and enforce policies based on SGTs. Which two mechanisms can be used to propagate SGTs between network devices? (Choose two.)

Hard
91

A network administrator is configuring a Cisco IOS router to act as a VPN headend for remote access using SSL VPN. The requirement is to allow users to connect via a web browser and access internal web applications without installing a client. Which feature should the administrator configure?

Easy
92

A network engineer is implementing MACsec on a Cisco Catalyst switch to secure Layer 2 traffic between two campus distribution switches. Which two statements accurately describe MACsec operation on Cisco platforms? (Choose two.)

Medium
93

A network security team is deploying Cisco TrustSec in a data center environment. They want to assign Security Group Tags (SGTs) to traffic based on user identity and device type without relying on IP addresses or VLANs. The team plans to use inline tagging on Cisco Nexus switches that support hardware-based SGACL enforcement. Which statement correctly describes how inline tagging propagates SGT information?

Hard
94

A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS router to protect the route processor from excessive CPU utilization due to malicious traffic. The engineer wants to ensure that BGP, SSH, and SNMP traffic are rate-limited appropriately. After applying the CoPP policy, the engineer notices that BGP sessions are flapping. Which action should the engineer take to resolve the issue while maintaining protection?

Hard
95

A network engineer is configuring a Cisco Catalyst switch to mitigate VLAN hopping attacks. The switch has multiple access ports assigned to VLAN 10 and trunk ports connecting to other switches. The engineer wants to ensure that an attacker cannot send double-tagged frames to hop into another VLAN. Which action should the engineer take on all access ports?

Easy
96

A network engineer is deploying Cisco TrustSec in a campus network. The security team requires that the Security Group Tag (SGT) be carried inside the Ethernet frame so that switches in the path can enforce group-based policy without inline tagging. Which Cisco-proprietary protocol should be enabled on the uplinks between the access and distribution switches to achieve this?

Medium
97

A network engineer is configuring a Zone-Based Firewall on a Cisco IOS XE router. The design requires that traffic from the inside zone to the outside zone be inspected, that return traffic be permitted, and that traffic from the outside zone to the inside zone be dropped unless it matches an existing session. Which configuration element is required to achieve this behavior?

Hard
98

A network administrator is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router. The router runs OSPF, BGP, SSH management, and SNMP polling. After applying a CoPP policy, the administrator notices that OSPF adjacencies flap intermittently while BGP and SSH remain stable. Which action should the administrator take to resolve the flapping while maintaining control plane protection?

Hard
99

A network administrator must protect the control plane of a Cisco IOS XE router that peers BGP with an ISP. The requirement is to rate-limit specifically ARP and IPv4 TTL-expired packets destined to the route processor while allowing all other transit traffic to be forwarded normally. Which CoPP implementation step is required to achieve this?

Hard
100

A network engineer is configuring a Cisco ASA firewall with a site-to-site VPN to a remote peer. The engineer wants to ensure that only specific subnets are encrypted and that traffic from other subnets is not sent through the tunnel. Which configuration element defines the traffic that will be protected by the VPN?

Hard
101

A security team wants to protect a campus network from MAC flooding attacks that could overflow the CAM table on access switches. The requirement is to limit the number of source MAC addresses learned per switch port and to automatically err-disable a port when the limit is exceeded, while still allowing a VoIP phone and a PC on the same port. Which configuration approach meets these requirements?

Hard
102

A network engineer is implementing a Zone-Based Firewall (ZBFW) on a Cisco IOS XE router. The router has three interfaces: inside (GigabitEthernet0/0), outside (GigabitEthernet0/1), and DMZ (GigabitEthernet0/2). The security policy requires that traffic from the inside zone to the outside zone be inspected, traffic from the outside zone to the DMZ be allowed only for HTTP and HTTPS, and all other traffic between zones be denied by default. Which configuration step is essential to achieve this policy?

Medium
103

A security architect is designing a network where endpoint identity and group membership must follow users and devices across both wired and wireless networks, and policy enforcement must be consistent regardless of VLAN or IP subnet. Which Cisco solution provides this identity-based, group-based access control?

Hard
104

A company has deployed a Cisco ASA firewall in transparent mode. The internal network uses VLAN 10 and the external network uses VLAN 20. The ASA is configured with two bridge groups: BVI 10 for inside and BVI 20 for outside. The security policy must allow HTTPS traffic from inside to outside. Which access-list entry is correct?

Medium
105

A network engineer is configuring control plane policing (CoPP) on a Cisco IOS XE router that peers BGP with two service providers and is managed over SSH from a jump host. After applying a new policy-map, the engineer notices that BGP sessions remain up but SSH logins intermittently time out during traffic spikes. Which action should the engineer take to resolve the SSH timeouts while preserving the CoPP protection model?

Hard
106

A network administrator is deploying Control Plane Policing (CoPP) on a Cisco IOS XE router that runs BGP, OSPF, and SSH management. The administrator wants to protect the route processor from excessive control-plane traffic while still allowing legitimate routing protocol and management traffic. The administrator creates a class map that matches BGP, OSPF, and SSH traffic and applies a police action with a committed information rate. Which additional configuration element is required to complete the CoPP implementation?

Medium
107

A network architect is designing a Cisco SD-Access fabric. The security team requires that endpoint traffic be segmented into separate virtual networks and that group-based policy be enforced without using traditional VLANs or ACLs between fabric edge nodes. Which two Cisco SD-Access fabric components or features support these requirements? (Choose two.)

Medium
108

A network administrator is configuring a Cisco IOS XE router to act as a VPN headend with IKEv2. The security policy requires that the router authenticate to peers using a certificate from a corporate PKI, and that peers authenticate using EAP-MSCHAPv2. Which IKEv2 authentication configuration on the headend meets these requirements?

Hard
109

A network administrator is configuring a Cisco Catalyst switch to prevent unauthorized devices from connecting to an access port. The administrator wants to ensure that only one MAC address is allowed on the port, and if a violation occurs, the port should be shut down and an SNMP trap sent. Which port security violation mode should be configured?

Easy
110

A network engineer is configuring MACsec on a point-to-point link between two Cisco Catalyst switches to provide Layer 2 encryption. The engineer wants to use a pre-shared key for authentication and ensure that the key is rotated periodically. Which MACsec component must be configured to specify the pre-shared key and the key rotation timer?

Hard
111

A network administrator is implementing IP Source Guard (IPSG) on a Cisco Catalyst 3850 switch to prevent IP spoofing. The administrator enables DHCP snooping and IPSG on VLAN 10. A user connects a laptop with a statically assigned IP address 10.10.10.50/24 and gateway 10.10.10.1. The laptop cannot reach any network resources. What is the most likely reason?

Medium
112

A network administrator is configuring a Cisco Wireless LAN Controller (WLC) to secure wireless client traffic. The requirement is to encrypt all wireless traffic between the client and the access point using a pre-shared key, without requiring a separate authentication server. Which security policy should the administrator configure on the WLC?

Easy
113

A Cisco Catalyst 9500 switch is configured for 802.1X with MAC Authentication Bypass (MAB) fallback on a port connected to an IP phone that has a PC daisy-chained behind it. The phone authenticates successfully using 802.1X, but the PC behind the phone fails authentication and is placed in the guest VLAN. The requirement is that the PC be authenticated individually and placed in the data VLAN, while the phone remains in the voice VLAN. Which feature should be configured on the switch port to meet this requirement?

Hard
114

A network engineer is implementing Cisco TrustSec in a campus network. The engineer needs to configure the enforcement of security group tags (SGTs) on Cisco Catalyst switches. Which two statements are true regarding SGT enforcement and propagation? (Choose two.)

Medium
115

A network administrator is implementing Dynamic ARP Inspection (DAI) on a Cisco Catalyst switch. The network uses DHCP for most endpoints, but a few servers have static IP addresses. Which two actions are required to ensure DAI allows legitimate traffic while blocking ARP spoofing? (Choose two.)

Medium
116

A network engineer is configuring port security on a Cisco switch to prevent unauthorized devices from connecting. The requirement is to allow only the first two MAC addresses learned on an interface, and to disable the interface if a violation occurs. Which configuration achieves this?

Medium
117

A network security team is hardening a Cisco IOS-XE router that terminates a site-to-site VPN to the internet. They want to ensure that the router itself cannot be managed from untrusted networks and that its management protocols are protected. Which two configuration actions achieve these goals? (Choose two.)

Hard
118

A network administrator is deploying Control Plane Policing (CoPP) on a Cisco IOS XE router that peers BGP with two ISPs. After applying a policer to the control plane, the BGP sessions tear down repeatedly while OSPF adjacencies stay stable. The administrator confirms CPU utilization is low. Which action should be taken to resolve the issue?

Medium
119

A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS-XE router that also runs OSPF, BGP, and SSH management. The engineer needs to protect the control plane while ensuring that routing protocol traffic and management sessions are not disrupted. Which CoPP design approach best meets these requirements?

Medium
120

A network administrator is hardening a Cisco IOS switch that connects to user workstations. The security policy requires that when an unauthorized MAC address appears on an access port, the port must drop only the offending frames, generate a syslog message, and increment a counter, without shutting down the port or requiring administrative intervention. Which port security violation mode meets these requirements?

Easy
121

A network engineer is implementing 802.1X authentication on a Cisco switch. The engineer wants to ensure that the switch dynamically assigns a VLAN to the port based on the user's identity, and that the VLAN assignment is enforced by the authentication server. Which two components are required to achieve this? (Choose two.)

Medium
122

A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router that runs BGP, SSH management, and SNMP. After applying a CoPP policy, BGP peering drops intermittently during route churn, but SSH and SNMP remain reachable. Which action should be taken to correct the issue while preserving control plane protection?

Hard
123

A network administrator is implementing Control Plane Policing on a Cisco IOS-XE router to protect the route processor from excessive BGP, SSH, and SNMP traffic. After applying the policy, legitimate BGP keepalives are being dropped, causing peer resets. Which action should the administrator take to resolve this while still protecting the control plane?

Medium
124

A network security team is deploying MACsec on a Cisco Catalyst 9300 switch connecting to a partner's Catalyst 9200 over a metro Ethernet link. The team wants to encrypt all traffic on the link and ensure that the switches mutually authenticate before any frames are forwarded. Which IEEE standard defines the key agreement and encryption used by MACsec, and which component performs the key exchange?

Hard
125

A network engineer is implementing IPsec VPN on a Cisco IOS XE router. The design requires that traffic from the 10.1.1.0/24 subnet to the 10.2.2.0/24 subnet be encrypted, while all other traffic should be sent unencrypted. The engineer creates a crypto ACL. Which action must be taken to ensure the crypto ACL correctly identifies the traffic to protect?

Medium
126

A network administrator is deploying a Cisco Catalyst switch with DHCP snooping. The switch is configured with DHCP snooping globally and on VLAN 10. A DHCP server is connected to GigabitEthernet1/0/5, and client devices are connected to GigabitEthernet1/0/6 through 1/0/20. The administrator notices that DHCP offers from the server are being dropped. What is the most likely cause?

Medium
127

A network administrator is configuring 802.1X authentication on a Cisco switch port. The port is connected to a VoIP phone that then connects to a PC. The administrator wants to authenticate both the phone and the PC separately, with the phone using MAB and the PC using 802.1X. Which feature should be configured on the switch port to support this?

Medium
128

A network administrator is configuring a Cisco IOS router to act as a VPN headend for remote users. The requirement is to use a protocol that supports both IKEv2 and native IPv6 transport, and that can provide per-user policy enforcement. Which technology should the administrator implement?

Easy
129

A network engineer is configuring an IPsec site-to-site VPN between two Cisco IOS-XE routers. The design requires that the data payload be encrypted and that the two peers authenticate each other using pre-shared keys without any certificate infrastructure. Which combination of IKEv2 parameters must be configured on both peers to establish the tunnel?

Easy
130

A network engineer is configuring a site-to-site VPN between two Cisco IOS routers. The engineer wants to ensure that only traffic from the 10.1.1.0/24 subnet to the 10.2.2.0/24 subnet is encrypted, while all other traffic is sent unencrypted. Which IPsec configuration component defines this traffic?

Easy
131

A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS XE router to protect the route processor from excessive control-plane traffic. The engineer wants to rate-limit ARP and DHCP snooping-related traffic destined to the control plane while allowing routing protocol traffic without restriction. Which CoPP component must the engineer configure to classify and match this traffic before applying the policy?

Hard
132

A network administrator is configuring a site-to-site VPN between two Cisco IOS routers using IPsec. The security policy requires that the VPN use IKEv2 with certificate-based authentication. Which command must be configured on both routers to specify the trustpoint that will be used for IKEv2 authentication?

Easy
133

A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router that runs BGP, SSH management, and SNMP monitoring. After applying a new CoPP policy, BGP sessions flap intermittently while SSH and SNMP continue to work. The engineer wants to confirm which traffic class is being dropped. Which action should the engineer take?

Medium
134

A network security team deploys Cisco TrustSec on a Catalyst 9500 fabric. The team wants to enforce a policy where a user authenticated into the 'Contractor' security group tag (SGT) is denied access to servers tagged with the 'Finance' SGT, while remaining able to reach the 'Printers' SGT. Which enforcement mechanism applies the SGACL to traffic between the tagging devices?

Medium
135

A network engineer is deploying Control Plane Policing (CoPP) on a Cisco IOS XE router that runs BGP, OSPF, and SSH management. The engineer applies a CoPP policy-map to the control plane with a class that matches BGP traffic and sets police rate 8000 conform-action transmit exceed-action drop. After applying the policy, BGP sessions intermittently flap during route convergence. Which action should the engineer take to resolve the issue while maintaining control plane protection?

Medium
136

A network administrator is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router that peers BGP with two ISPs and runs SSH for management. The administrator wants to ensure that a sudden flood of BGP updates from a misbehaving peer does not starve the SSH management plane, while still allowing legitimate BGP traffic. Which CoPP configuration approach best meets this requirement?

Medium
137

A network engineer is deploying MACsec on a Catalyst switch uplink between two buildings to protect Layer 2 traffic. Which two statements about MACsec operation on Cisco Catalyst switches are true? (Choose two.)

Hard
138

A network administrator is configuring a Cisco IOS router to support IPsec VPN for remote workers. The security policy requires that the router authenticate users via digital certificates issued by a corporate PKI. The administrator has already configured the CA trustpoint and obtained a certificate. Which command must be used in the ISAKMP policy to specify that RSA signatures (digital certificates) should be used for authentication?

Medium
139

A network administrator must secure management access to a Cisco Catalyst 9300 switch so that only encrypted sessions are accepted and any Telnet attempt is refused. The administrator wants to enforce this with the fewest configuration lines on the VTY lines. Which configuration accomplishes this?

Easy
140

A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router that runs BGP, SSH management, and SNMP polling. A class-map named CLASS-MGMT matches SNMP and SSH traffic, and a policy-map named COPP-POLICY applies a police rate of 8000 bps with a conform-action transmit and exceed-action drop for that class. After the policy is attached to the control plane, SNMP polling intermittently fails while BGP remains stable. Which action should the engineer take to resolve the SNMP failures while still protecting the route processor?

Medium
141

A security architect is designing a campus network where all access-layer switch ports must authenticate endpoints before granting any Layer 2 connectivity. The design requires the switch to communicate with Cisco ISE using EAP over RADIUS, and the endpoint must be validated before any VLAN assignment occurs. Which 802.1X component role must the access-layer switch perform in this design?

Medium
142

A security architect is designing a Zero Trust access solution for a campus using Cisco Identity Services Engine. The requirement is to enforce dynamic, identity-based segmentation without relying solely on static VLANs, and to support both wired and wireless endpoints. Which two capabilities should be leveraged? (Choose two.)

Hard
143

A network engineer is configuring port security on a Cisco switch to prevent unauthorized devices from connecting. The requirement is to allow only the first two MAC addresses learned on the port and to automatically shut down the port if a violation occurs. Which command set should be used?

Easy
144

A network engineer configures Control Plane Policing on a Cisco IOS XE router acting as the BGP speaker for an ISP edge. The policy must protect the route processor from CPU exhaustion while still allowing BGP keepalives, SSH management, and SNMP polling from the NOC. Which CoPP design element is required to ensure BGP, SSH, and SNMP traffic is matched and rate-limited separately from transit traffic?

Medium
145

A network administrator is deploying a new branch office with a Cisco Catalyst 9200 switch. The security policy requires that any endpoint connecting to access ports must be authenticated before being granted network access, and unauthenticated devices must be placed into a restricted VLAN. The administrator wants to minimize configuration on the switch and rely on the authentication server to assign the VLAN dynamically. Which 802.1X feature should be configured on the switch to meet these requirements?

Medium
146

A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router to protect the route processor from excessive traffic. The router has management SSH access, BGP peering, and SNMP monitoring. After applying a CoPP policy, the engineer notices that BGP sessions flap intermittently, but SSH and SNMP remain stable. Which action should the engineer take to resolve the BGP flapping while maintaining control plane protection?

Hard
147

A network engineer must protect the Cisco IOS control plane from an excessive volume of ARP traffic generated by a compromised host in VLAN 20. The engineer wants to limit ARP packets that are punted to the CPU, while allowing normal data forwarding to continue unaffected. Which feature should be configured to accomplish this goal?

Medium
148

A network administrator is deploying a Cisco Catalyst 9300 switch stack at the access layer. The security policy requires that when an endpoint device is connected to a port and later replaced by a different device, the port must automatically learn the new MAC address without administrative intervention, but a violation must generate a syslog message and increment a counter. The administrator configures the interface with the command 'switchport port-security violation restrict'. Which additional command is required to meet the requirement that the new device is learned automatically?

Medium
149

A network engineer is configuring IPsec VPN on a Cisco IOS router. The engineer wants to ensure that traffic from a specific subnet is encrypted and sent to a remote peer, while all other traffic is sent unencrypted. The engineer has configured an extended ACL for the crypto map. Which additional configuration is required to ensure that the crypto map is applied to the correct interface and that the VPN tunnel is established?

Hard
150

A network security team is implementing Cisco TrustSec in a campus network. The team wants to enforce access based on a tag carried in the packet rather than by IP address, and wants the tag to be propagated across the network without per-hop reclassification. Which Cisco TrustSec component assigns and inserts the Security Group Tag (SGT) at the ingress point?

Hard
151

A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS XE router to protect against control plane overload. The router has management traffic (SSH, SNMP) and routing protocol traffic (OSPF, BGP). After applying the CoPP policy, the engineer notices that OSPF adjacencies are flapping. Which action should the engineer take to resolve this issue while maintaining control plane protection?

Hard
152

A network administrator is configuring a Cisco IOS router to protect the control plane from excessive CPU utilization caused by malicious traffic. The administrator wants to rate-limit specific types of traffic destined to the route processor while allowing all other traffic to pass without restriction. Which feature should be configured?

Easy
153

A network security team is deploying MACsec on a Cisco Catalyst 9000 switch uplink between two buildings to protect Layer 2 traffic. The team wants to ensure that the link encrypts traffic and that the peer is authenticated before secure communication begins. Which configuration approach meets these requirements?

Hard
154

A network engineer is configuring IPsec VPN on a Cisco IOS router. The requirement is to encrypt traffic between two sites using IKEv2. The engineer wants to ensure that the IKEv2 proposal uses AES-256 for encryption, SHA-256 for integrity, and Diffie-Hellman group 14. Which command correctly defines the IKEv2 proposal with these parameters?

Hard
155

Which THREE of the following are characteristics of Cisco TrustSec (CTS) security architecture?

Hard
156

A security architect is designing segmentation for a data center using Cisco TrustSec. The requirement is that classification of traffic into Security Group Tags (SGTs) occur at the access layer based on the identity of the user or device, and that enforcement occur at the data center core where the SGT-to-SGACL matrix is applied. Which statement describes the correct deployment approach?

Hard
157

A network security team is deploying MACsec on Cisco Catalyst switches to protect Layer 2 traffic between two distribution switches. They want to ensure that the link is encrypted and that only authorized devices can participate in the secured session. Which two statements about MACsec operation on Cisco platforms are correct? (Choose two.)

Hard
158

A network security engineer is configuring Control Plane Policing (CoPP) on a Cisco ASR 1000 router to protect the route processor from excessive traffic. The engineer wants to rate-limit SSH traffic to 100 kbps with a burst of 8000 bytes, and ensure that any traffic exceeding the rate is dropped. The engineer applies the following policy: policy-map COPP-POLICY class SSH-CLASS police 100000 8000 exceed-action drop After applying the service-policy to the control plane, the engineer notices that SSH sessions intermittently disconnect during large file transfers over SCP. What is the most likely cause?

Hard
159

A network administrator is configuring IPsec VPN on a Cisco IOS router. The administrator needs to ensure that the VPN traffic is encrypted and authenticated. Which two protocols are used in IPsec to provide encryption and authentication? (Choose two.)

Medium
160

A network administrator is deploying a Cisco Catalyst 9300 switch stack at the access layer. The security policy requires that when an unauthorized device connects to an access port, the port must immediately stop forwarding traffic, generate a syslog message, and increment the violation counter, while allowing the administrator to manually re-enable the port after investigation. Which port security violation mode should be configured?

Medium
161

A network administrator is deploying a Cisco IOS-XE router as the WAN edge. The security policy requires that the router itself be protected against brute-force SSH attacks originating from the untrusted internet, without affecting transit traffic forwarded through the router. The administrator wants to use a feature that automatically blocks the offending source IP after repeated failed login attempts. Which Cisco IOS-XE feature should be configured?

Medium

Frequently asked questions

What does the Security domain cover on the 350-401 exam?
Configure device hardening and access control using AAA (TACACS+/ISE), ACLs, CoPP, 802.1X/MAB, port security, DHCP snooping, and Dynamic ARP Inspection. The most important thing: verify ACL and CoPP order/interface direction, since mistakes silently drop or permit traffic.
How many questions are in this domain?
This page lists all 161 Security questions in the 350-401 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Security questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
encor ENCOR security Practice Questions