Security
Drill 18 practice questions focused entirely on Security for the Cisco 350-601 exam. Tap an answer for instant feedback and a full explanation — no sign-up, always free.
An ACI administrator has an existing contract between the Web-EPG and App-EPG that permits all TCP traffic. A new security requirement mandates that TCP port 23 (Telnet) be explicitly denied between these two EPGs while all other permitted TCP traffic continues to flow. The administrator wants to apply this exception without rewriting the entire allow contract. Which ACI construct should be applied to enforce this specific deny?
A data center administrator is securing an ACI fabric that hosts a multi-tenant virtualized environment. Several VMs belonging to the same application EPG must be dynamically isolated based on their VM attributes (for example, VM name containing 'DB') without moving them to a different base EPG or requiring VLAN reassignment. The administrator wants endpoints matching the criteria to be classified into a separate policy group so that contracts can control communication between them and the rest of the EPG. Which ACI feature should be implemented to meet this requirement?
A storage administrator has correctly configured single-initiator zoning on a Cisco MDS 9000 fabric so that a specific server HBA can reach a storage array's target port. However, the security team is concerned that the server can still see and potentially access LUNs belonging to other servers presented by that same array target port. Which additional control most directly restricts which specific LUNs behind the target port that particular server is permitted to access?
A storage administrator is enabling Fibre Channel port security on VSAN 20 of a Cisco MDS switch to prevent unauthorized devices from logging into fabric ports. To speed initial configuration, they enable auto-learning, let all current devices perform FLOGI, and then plan to make the learned bindings permanent. Which action must they take so that the learned entries are retained and no NEW devices can be learned automatically afterward?
A storage administrator wants to ensure that only authenticated switches and end devices can join a Cisco MDS Fibre Channel fabric. The requirement is a challenge-response protocol that mutually authenticates devices using a shared secret before allowing fabric access, without relying solely on WWN-based lists. Which security mechanism should be configured?
A network engineer is hardening access-layer Nexus switches in a data center. Users report intermittent connectivity, and investigation reveals a rogue device on an access port replying to DHCP requests with false gateway addresses, plus ARP spoofing attempts. The engineer enables DHCP snooping and Dynamic ARP Inspection (DAI) on the user VLAN. After enablement, legitimate clients on that VLAN can no longer obtain IP addresses, and the uplink toward the aggregation switch drops all DHCP replies. What is the MOST likely cause and correct remediation?
A data center engineer is hardening a Nexus 9000 access layer that supports a dual-stack IPv6 tenant network. Rogue IPv6 router advertisements from a compromised host in the VLAN have caused clients to install a malicious default gateway, redirecting traffic. Which First-Hop Security feature should the engineer deploy on the untrusted access ports to prevent unauthorized devices from sending Router Advertisement messages?
A data center administrator is hardening the management plane of a Nexus 9000 switch after a security audit. The auditors require that administrative CLI access use public-key authentication (no passwords over the wire) and that only the dedicated management subnet 10.20.30.0/24 be permitted to reach the VTY lines. Which combination of configuration actions satisfies BOTH requirements?
A data center administrator secures access ports on a Nexus 9000 switch connecting to a rack of physical servers. The requirement is that each port dynamically learns the connected server's MAC address, retains it across reboots by saving it to the running configuration, and — if an unauthorized MAC appears — the port must drop the offending traffic and increment a violation counter WITHOUT shutting the interface down or affecting the legitimate server. Which port security configuration meets all of these requirements?
A network engineer notices that a Nexus 9000 switch in a production data center is experiencing high CPU utilization due to a burst of ARP and glean traffic from a misbehaving host subnet. Legitimate management (SSH) and routing (BGP) sessions are beginning to flap because control-plane packets are being dropped. The engineer wants to protect the supervisor CPU while ensuring critical protocol traffic is prioritized over the offending traffic. Which action best addresses this problem?
A data center engineer is deploying Cisco TrustSec on a pair of Nexus 9000 switches to segment east-west traffic between application tiers. Endpoints are classified into Security Group Tags (SGTs) at the ingress switch, and the security policy must be enforced so that 'Web' servers (SGT 10) can never initiate connections to 'Database' servers (SGT 30). Where in the TrustSec architecture is this restriction actually enforced, and what construct defines the permit/deny behavior?
A data center engineer must restrict traffic on a Nexus 9000 leaf so that internal hosts in 10.10.0.0/16 can initiate TCP connections to an external web service at 203.0.113.50, but the external service must NOT be able to initiate new connections back into the data center. The engineer configures an ingress IPv4 ACL on the external-facing interface to filter inbound (returning) traffic. Which ACL entry correctly permits only the return traffic for sessions the internal hosts initiated, using the stateless NX-OS ACL capability?
A data center engineer is configuring hop-by-hop link encryption between two Nexus 9000 switches connected by a dark-fiber DCI link. The switches must authenticate each other and derive session keys automatically using a pre-shared key, without relying on 802.1X or an external policy server. Which key agreement protocol should the engineer configure for the MACsec session?
A data center engineer is enabling MACsec (CTS) on a point-to-point link between two Nexus 9000 switches using a manual pre-shared key. During the phased rollout, one switch has the MACsec policy applied but the peer has not yet been configured. The engineer needs the link to remain forwarding unencrypted clear traffic until both sides are ready, then automatically encrypt once the peer negotiates a session. Which MACsec security policy setting on the keychain interface achieves this behavior?
A data center operations team wants a group of junior engineers on a Nexus 9000 switch to be able to view and modify only interface and VLAN configuration, while being denied access to all routing, security, and AAA commands. The security lead insists on following least-privilege principles using native NX-OS capabilities. Which approach correctly meets this requirement?
A data center administrator notices that a Layer 2 access port on a Nexus 9000 switch connected to a poorly behaved server NIC is periodically flooding the segment with broadcast traffic, degrading performance for other hosts in the VLAN. The administrator wants to limit inbound broadcast traffic on that interface to 2% of the available bandwidth without shutting the port down, while leaving unicast traffic unaffected. Which configuration approach meets this requirement?
A security team requires that the Cisco UCS Manager HTTPS interface present a certificate signed by the organization's internal Certificate Authority instead of the default self-signed certificate. After creating a key ring and generating a certificate request, which sequence correctly completes the trusted-certificate deployment on the fabric interconnect?
A security team audits a Cisco Intersight Managed Mode (IMM) UCS domain and finds that a third-party monitoring tool requires out-of-band access to the server's baseboard management controller to read sensors and power state, but the team wants to prohibit any interactive KVM redirection and virtual media mounting on those servers. Which server profile policy change best satisfies both requirements?
More 350-601 practice
Keep going with the other Cisco CCNP Data Center DCCOR (350-601) domains, or take a full timed mock exam.
← Back to 350-601 overview