Courseiva

CCNA Security Questions

11 of 161 questions · Page 3/3 · Security · Answers revealed

151
MCQhard

A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS XE router to protect against control plane overload. The router has management traffic (SSH, SNMP) and routing protocol traffic (OSPF, BGP). After applying the CoPP policy, the engineer notices that OSPF adjacencies are flapping. Which action should the engineer take to resolve this issue while maintaining control plane protection?

A.Increase the rate limit for the OSPF class in the CoPP policy.
B.Configure OSPF to use a different DSCP value so it matches a higher-priority class in the CoPP policy.
C.Remove the CoPP policy from the control plane and reapply it after OSPF stabilizes.
D.Apply the CoPP policy only to the management plane interface instead of the control plane.
AnswerA

OSPF adjacency flapping indicates that OSPF hello packets are being dropped due to the policer rate being too low. Increasing the rate limit for the OSPF class allows legitimate OSPF control traffic to pass while still protecting the control plane from excessive traffic. This is the correct action because it directly addresses the dropped OSPF packets without removing protection entirely.

Why this answer

OSPF adjacency flapping after CoPP deployment indicates that OSPF hello packets are being dropped by the policer. The CoPP policy likely has a rate limit for OSPF that is too low for the network's requirements. Increasing the rate limit for the OSPF class allows OSPF traffic to pass while still enforcing a policer to protect against excess traffic.

This maintains control plane protection and resolves the flapping.

Exam trap

The trap here is assuming that any CoPP issue requires removing the policy, when in fact tuning the rate limits for specific classes is the correct approach to balance protection and protocol operation.

152
MCQeasy

A network administrator is configuring a Cisco IOS router to protect the control plane from excessive CPU utilization caused by malicious traffic. The administrator wants to rate-limit specific types of traffic destined to the route processor while allowing all other traffic to pass without restriction. Which feature should be configured?

A.Policy-Based Routing
B.Management Plane Protection
C.Control Plane Policing
D.Control Plane Protection
AnswerC

Control Plane Policing (CoPP) uses a modular QoS CLI policy applied to the control plane interface to rate-limit or drop traffic destined to the route processor. It allows granular classification of traffic types such as routing protocols, management access, and ICMP, while permitting unmatched traffic to pass, which matches the requirement exactly.

Why this answer

Control Plane Policing applies a QoS policy to the control plane interface, allowing administrators to classify and rate-limit specific traffic types destined to the route processor while permitting other traffic. This directly addresses CPU protection from malicious floods without affecting transit traffic.

Exam trap

The trap here is confusing Control Plane Policing with Control Plane Protection, when CPPr is a granular extension and CoPP is the standard feature for rate-limiting control plane traffic.

153
MCQhard

A network security team is deploying MACsec on a Cisco Catalyst 9000 switch uplink between two buildings to protect Layer 2 traffic. The team wants to ensure that the link encrypts traffic and that the peer is authenticated before secure communication begins. Which configuration approach meets these requirements?

A.Enable IPsec transport mode on the switch uplink with a crypto map and IKEv2 pre-shared key.
B.Enable port security with sticky MAC addresses and storm control on the uplink to secure the connection.
C.Enable MACsec with MKA using a pre-shared key or 802.1X-derived CAK, and set the switchport to macsec desired or must.
D.Enable 802.1AE without MKA and manually configure static secure associations on both ends.
AnswerC

MACsec on Catalyst 9000 uses the MACsec Key Agreement protocol to negotiate secure associations and authenticate peers. Configuring MKA with a connectivity association key either as a pre-shared key or derived from 802.1X, and setting the interface to macsec desired or macsec must, ensures encryption and peer authentication before traffic passes, which matches the stated requirement.

Why this answer

MACsec provides Layer 2 hop-by-hop encryption and integrity using 802.1AE, with the MACsec Key Agreement protocol handling key exchange and peer authentication. On Catalyst 9000, the supported design uses MKA with a connectivity association key from a pre-shared key or 802.1X, plus an interface mode of macsec desired or macsec must to enforce encrypted, authenticated links.

Exam trap

The trap here is confusing Layer 3 IPsec with Layer 2 MACsec and assuming a crypto map can be applied to a switch uplink for hop-by-hop encryption.

154
MCQhard

A network engineer is configuring IPsec VPN on a Cisco IOS router. The requirement is to encrypt traffic between two sites using IKEv2. The engineer wants to ensure that the IKEv2 proposal uses AES-256 for encryption, SHA-256 for integrity, and Diffie-Hellman group 14. Which command correctly defines the IKEv2 proposal with these parameters?

A.crypto ikev2 proposal PROP encryption aes-cbc-256 integrity sha256 group 14
B.crypto ikev2 keyring KEYRING peer SITE address 1.1.1.1 pre-shared-key local secret
C.crypto isakmp policy 10 encryption aes 256 hash sha256 group 14
D.crypto ikev2 policy POLICY proposal PROP encryption aes-256 integrity sha256 group 14
AnswerA

This command sequence under crypto ikev2 proposal correctly specifies AES-CBC-256 encryption, SHA-256 integrity, and Diffie-Hellman group 14. In Cisco IOS, the IKEv2 proposal is configured with the encryption, integrity, and group keywords, and this syntax matches the required parameters for the proposal.

Why this answer

The correct command to define an IKEv2 proposal with specific encryption, integrity, and DH group is under crypto ikev2 proposal, using the encryption, integrity, and group keywords. The policy command only references a proposal, and ISAKMP policy is for IKEv1. The keyring is for authentication, not proposal parameters.

Exam trap

The trap here is mixing IKEv1 ISAKMP policy syntax with IKEv2 proposal syntax, or placing proposal parameters under the policy command.

155
Multi-Selecthard

Which THREE of the following are characteristics of Cisco TrustSec (CTS) security architecture?

Select 3 answers
A.It uses IPsec to encrypt traffic between network devices.
B.It uses VLANs to segment traffic based on security roles.
C.It uses Security Group Tags (SGTs) to classify traffic.
D.It provides data confidentiality using IEEE 802.1AE (MACsec) encryption.
E.It uses Security Group Access Control Lists (SGACLs) to enforce policies.
AnswersC, D, E

SGTs are used for classification.

Why this answer

C is correct because Cisco TrustSec uses Security Group Tags (SGTs) to classify traffic based on user, device, or role, rather than IP addresses. SGTs are 16-bit values (0–65535) assigned dynamically via authentication (e.g., 802.1X) or static mapping, enabling scalable policy enforcement.

Exam trap

Cisco often tests the misconception that TrustSec uses VLANs or IPsec for segmentation and encryption, when in fact it uses SGTs for classification and MACsec for Layer 2 encryption.

156
MCQhard

A security architect is designing segmentation for a data center using Cisco TrustSec. The requirement is that classification of traffic into Security Group Tags (SGTs) occur at the access layer based on the identity of the user or device, and that enforcement occur at the data center core where the SGT-to-SGACL matrix is applied. Which statement describes the correct deployment approach?

A.SGTs are assigned by Cisco ISE to the core switch, and enforcement is performed by the access switch using downloadable ACLs.
B.SGTs are assigned by the access switch using 802.1X or SXP, propagated in the SGT Exchange Protocol or inline tagging, and enforced by SGACLs on the core device.
C.SGTs are assigned at the core based on destination subnet, and enforcement occurs at the access layer using PACLs.
D.SGTs are carried in IPsec ESP headers across the data center, and enforcement is performed by the Cisco ASA using the SGT matrix.
AnswerB

TrustSec separates classification from enforcement. Access-layer devices assign SGTs based on identity (802.1X, MAB) or receive them via SXP from upstream, then propagate the tag in the packet header using inline tagging (CMD) or via SXP to devices that cannot tag. Enforcement devices at the core apply SGACLs from the SGT matrix. This matches the described architecture.

Why this answer

TrustSec's strength is the separation of classification from enforcement. Identity-based classification happens as close to the source as possible at the access layer, using 802.1X, MAB, or SXP to assign SGTs. Tags then travel across the fabric via inline tagging or SXP propagation.

Enforcement devices, typically in the distribution or core, apply SGACLs derived from the SGT matrix, allowing consistent policy regardless of IP addressing or topology changes.

Exam trap

The trap here is reversing classification and enforcement points, or assuming SGACL enforcement happens on the access switch using dACLs rather than on TrustSec-capable devices in the core using the SGT matrix.

157
Multi-Selecthard

A network security team is deploying MACsec on Cisco Catalyst switches to protect Layer 2 traffic between two distribution switches. They want to ensure that the link is encrypted and that only authorized devices can participate in the secured session. Which two statements about MACsec operation on Cisco platforms are correct? (Choose two.)

Select 2 answers
A.MACsec can be configured in switch-to-host mode where the host runs an 802.1X supplicant that supports MACsec key agreement, allowing encryption to the endpoint.
B.MACsec uses the MKA protocol to negotiate and exchange keys between peers, and it can be configured with a pre-shared key or with 802.1X-based key derivation.
C.MACsec is only supported on routed ports and cannot be enabled on switch access ports or EtherChannel member links.
D.MACsec encryption keys are exchanged in clear text during the MKA handshake, so the link is only protected against physical taps after the session is established.
E.MACsec operates at Layer 3 and encrypts IP packets between routers, requiring IPsec configuration on the participating interfaces.
AnswersA, B

Cisco supports MACsec in switch-to-host deployments, where the endpoint runs a supplicant capable of MKA, such as the Cisco AnyConnect Network Access Manager or a compatible NIC driver. This extends encryption to the access edge rather than only between switches. It requires 802.1X authentication and a supplicant that supports MACsec, but it is a valid and commonly deployed mode.

Why this answer

MACsec secures Ethernet frames using MKA to negotiate keys, supporting both pre-shared CAK and 802.1X-based key derivation. It can be deployed switch-to-switch or switch-to-host when the endpoint has a MACsec-capable supplicant. These two facts address the requirement for encryption and authorized participation on the Layer 2 link.

Exam trap

The trap here is assuming MACsec is a Layer 3 IPsec-like technology or that it sends keys in clear text, when it is actually a Layer 2 frame encryption method with secure MKA key exchange.

158
MCQhard

A network security engineer is configuring Control Plane Policing (CoPP) on a Cisco ASR 1000 router to protect the route processor from excessive traffic. The engineer wants to rate-limit SSH traffic to 100 kbps with a burst of 8000 bytes, and ensure that any traffic exceeding the rate is dropped. The engineer applies the following policy: policy-map COPP-POLICY class SSH-CLASS police 100000 8000 exceed-action drop After applying the service-policy to the control plane, the engineer notices that SSH sessions intermittently disconnect during large file transfers over SCP. What is the most likely cause?

A.Control Plane Policing does not support the exceed-action drop keyword; the correct action is transmit.
B.The service-policy must be applied to the control plane with the input keyword, otherwise SSH traffic is not policed.
C.The police rate is configured in kilobits per second, but the burst size is in kilobytes, causing a mismatch that drops all SSH packets.
D.The police rate is configured in bits per second, but the burst size is too small for SCP transfers, causing packets to be dropped.
AnswerD

The police command specifies the rate in bits per second (100000 bps = 100 kbps) and the burst in bytes (8000 bytes). During large SCP transfers, the burst of SSH packets can exceed 8000 bytes, causing the policer to drop packets and disconnect sessions. Increasing the burst size would allow more data before policing, resolving the intermittent drops.

Why this answer

The police command uses bits per second for the rate and bytes for the burst. A 100 kbps rate with an 8000-byte burst is too restrictive for SCP file transfers, which generate bursts of SSH packets larger than 8000 bytes. The policer drops excess packets, causing SSH sessions to disconnect intermittently.

Increasing the burst size or rate would resolve the problem.

Exam trap

The trap here is confusing the units of the police command, assuming the burst is in bits or kilobytes, when it is actually in bytes, leading to an undersized burst for the traffic profile.

159
Multi-Selectmedium

A network administrator is configuring IPsec VPN on a Cisco IOS router. The administrator needs to ensure that the VPN traffic is encrypted and authenticated. Which two protocols are used in IPsec to provide encryption and authentication? (Choose two.)

Select 2 answers
A.L2TP
B.SSL
C.AH
D.GRE
E.ESP
AnswersC, E

Authentication Header (AH) is an IPsec protocol that provides authentication and integrity but does not provide encryption. It ensures that the data is from a legitimate source and has not been altered. In the scenario, AH can be used for authentication, but it does not encrypt the traffic.

Why this answer

ESP and AH are the two core IPsec protocols. ESP provides encryption and optional authentication, while AH provides authentication and integrity but no encryption. Together or separately, they can secure VPN traffic.

The other options are tunneling or security protocols not part of IPsec's native encryption and authentication mechanisms.

Exam trap

The trap here is confusing tunneling protocols like GRE or L2TP with IPsec protocols, or thinking that SSL is part of IPsec when it is a separate security protocol.

160
MCQmedium

A network administrator is deploying a Cisco Catalyst 9300 switch stack at the access layer. The security policy requires that when an unauthorized device connects to an access port, the port must immediately stop forwarding traffic, generate a syslog message, and increment the violation counter, while allowing the administrator to manually re-enable the port after investigation. Which port security violation mode should be configured?

A.err-disable recovery
B.protect
C.restrict
D.shutdown
AnswerD

Shutdown mode places the port into an err-disabled state immediately upon a violation, stops all forwarding, generates a syslog message, and increments the violation counter. Recovery requires manual intervention (or err-disable recovery configuration), matching the scenario's requirement that the administrator re-enable the port after investigation. This is the classic default violation mode on Cisco Catalyst switches and satisfies every stated condition.

Why this answer

Port security shutdown mode is the only violation action that immediately err-disables the interface, halts forwarding, logs a syslog message, increments the violation counter, and requires manual recovery. Protect and restrict leave the port up, and err-disable recovery is a global timer feature rather than a violation mode. The stated need for manual re-enablement after investigation confirms shutdown is correct.

Exam trap

The trap here is assuming that restrict mode shuts down the port because it logs violations, when in fact only shutdown mode err-disables the interface.

161
MCQmedium

A network administrator is deploying a Cisco IOS-XE router as the WAN edge. The security policy requires that the router itself be protected against brute-force SSH attacks originating from the untrusted internet, without affecting transit traffic forwarded through the router. The administrator wants to use a feature that automatically blocks the offending source IP after repeated failed login attempts. Which Cisco IOS-XE feature should be configured?

A.Zone-Based Firewall with a policy dropping TCP port 22 inbound
B.IP Source Guard on the WAN interface
C.Control Plane Policing (CoPP) with a class-map matching TCP port 22
D.Login Enhancements (login block-for) with an ACL triggered after failed attempts
AnswerD

The login block-for feature, often called Login Enhancements, monitors failed login attempts against the router's local authentication and, when the threshold is exceeded within the configured window, places a temporary ACL that blocks all further login attempts from offending sources for the quiet period. It protects the router's control plane without affecting transit traffic, matching the stated requirement exactly.

Why this answer

The login block-for command, part of Cisco IOS Login Enhancements, watches failed authentication attempts against the device itself. When the configured failure threshold is crossed inside the observation window, the router installs a temporary access list that denies further login attempts from offending hosts for the quiet period. Because it only affects traffic destined to the router's management plane, transit forwarding is unaffected, which is precisely what the scenario demands.

Exam trap

The trap here is assuming that CoPP or an ACL can provide dynamic, attempt-triggered blocking of brute-force sources, when only Login Enhancements tracks failed logins and applies the temporary deny automatically.

← PreviousPage 3 of 3 · 161 questions total

Ready to test yourself?

Try a timed practice session using only Security questions.