Cisco CCNP Enterprise ENCOR (350-401) · Domain 5 · 20% of exam

Security

Drill 14 practice questions focused entirely on Security for the Cisco 350-401 exam. Tap an answer for instant feedback and a full explanation — no sign-up, always free.

Verified answer14 questions
Question 1 of 14

A network engineer configures AAA on a Catalyst switch to authenticate administrative logins against a RADIUS server. During a maintenance window the RADIUS server becomes unreachable, and the engineer is now completely locked out of the console and VTY lines even though a local username exists. The relevant configuration is: 'aaa authentication login default group radius'. Which change ensures the engineer can still log in with the local database when RADIUS is unreachable?

Reviewed for accuracy · Report an issue
Question 2 of 14

A network administrator wants junior technicians to log into a Catalyst switch and be able to run all show commands and clear counters, but NOT enter global configuration mode or reload the device. The administrator prefers a solution local to the device that avoids assigning each command an individual privilege level. Which approach best meets this requirement?

Reviewed for accuracy · Report an issue
Question 3 of 14

A network engineer notices that a Catalyst switch experiences high CPU utilization during a burst of ARP and routing protocol traffic directed at the device itself, causing management sessions to time out. The engineer wants to rate-limit traffic destined to the router's control plane without affecting transit data traffic. Which feature should be implemented to accomplish this?

Reviewed for accuracy · Report an issue
Question 4 of 14

A network engineer is hardening a Catalyst 9300 switch. Corporate policy requires that only the management subnet 10.50.10.0/24 be permitted to reach the device management plane, and that any denied management attempt be recorded for the SOC. The engineer has already configured SSHv2. Which additional configuration correctly restricts and logs remote management access to the VTY lines?

Reviewed for accuracy · Report an issue
Question 5 of 14

During a security audit of a new Catalyst 9300 switch, you are asked to reduce the device's attack surface before it is placed into production. The switch currently has its factory-default configuration for management services. Which action most directly hardens the management plane by removing a plaintext, legacy remote-access protocol that transmits credentials in clear text?

Reviewed for accuracy · Report an issue
Question 6 of 14

A network engineer is hardening a Catalyst switch and wants to protect privileged EXEC mode. The running configuration currently contains both 'enable password Cisco123' and 'enable secret Str0ngP@ss'. When the engineer types 'enable' at the user EXEC prompt, which behavior occurs, and why?

Reviewed for accuracy · Report an issue
Question 7 of 14

A security engineer must encrypt all traffic on the point-to-point uplink between two Catalyst switches inside the data center to prevent an attacker who taps the cable from reading or modifying frames. The solution must operate at Layer 2, provide line-rate encryption in hardware, and authenticate the two switches to each other. Which technology should the engineer deploy on this switch-to-switch link?

Reviewed for accuracy · Report an issue
Question 8 of 14

A network architect is designing the security framework for a new enterprise campus. Management wants to ensure that if a perimeter firewall is compromised, additional controls still protect internal resources. The architect proposes stacking multiple independent security controls at the perimeter, distribution, and access layers so that no single failure exposes critical assets. Which network security design principle does this approach represent?

Reviewed for accuracy · Report an issue
Question 9 of 14

A network automation engineer is writing a Python script that repeatedly polls a Cisco Catalyst Center REST API for device inventory data. During a security review, an auditor flags that the script sends the administrator username and password in a Base64-encoded HTTP header on every single request. The auditor asks the engineer to redesign the authentication so that long-lived credentials are not transmitted on each API call. Which approach best addresses this concern while following Catalyst Center's intended authentication model?

Reviewed for accuracy · Report an issue
Question 10 of 14

A network automation team is integrating a Python script with a Cisco Catalyst Center REST API. During a security review, an auditor notes that API credentials and returned device inventory data must not be readable if the traffic is captured on the wire. Which characteristic of REST API security addresses this specific requirement?

Reviewed for accuracy · Report an issue
Question 11 of 14

A network automation engineer is developing a Python script that will retrieve interface statistics from Cisco Catalyst Center via its REST API. During testing, the initial call to the /dna/system/api/v1/auth/token endpoint using HTTP Basic authentication succeeds, but subsequent calls to data endpoints return HTTP 401 Unauthorized. What is the MOST likely cause and correct resolution?

Reviewed for accuracy · Report an issue
Question 12 of 14

A network automation team exposes a REST API on a Catalyst Center appliance to internal scripts. During a scripting error, one client sent thousands of requests per second, degrading the controller's responsiveness for other clients. The security architect wants a control that protects the API from being overwhelmed by excessive requests from any single client without blocking legitimate access entirely. Which REST API security mechanism directly addresses this concern?

Reviewed for accuracy · Report an issue
Question 13 of 14

A network engineer is hardening a Catalyst 9300 switch for remote management. Corporate policy requires that only SSH (never Telnet) be permitted to the VTY lines, that only management subnet 10.10.50.0/24 be allowed to connect, and that the strongest supported SSH protocol be enforced. Which configuration set correctly meets all three requirements?

Reviewed for accuracy · Report an issue
Question 14 of 14

A network engineer must deploy AAA on a fleet of Catalyst switches with the following requirements: administrators must be authorized on a per-command basis, each command executed must be logged for audit, and the entire packet payload between the switch and the AAA server must be encrypted. Which protocol should be configured to meet ALL of these requirements?

Reviewed for accuracy · Report an issue

More 350-401 practice

Keep going with the other Cisco CCNP Enterprise ENCOR (350-401) domains, or take a full timed mock exam.

← Back to 350-401 overview