Network Security
Drill 20 practice questions focused entirely on Network Security for the Cisco 350-701 exam. Tap an answer for instant feedback and a full explanation — no sign-up, always free.
A data center team wants to enforce east-west traffic controls between servers regardless of their IP subnet or VLAN, so that policy remains consistent even when workloads move or are re-addressed. They already run Cisco ISE and TrustSec-capable switches. Which approach best meets this requirement?
A network engineer is configuring Flexible NetFlow on a Cisco router to track conversations between hosts so that traffic can be analyzed per source/destination IP pair. The engineer defines a flow record but the collector reports that all traffic from a single source is being aggregated into one flow regardless of destination. Which change to the flow record configuration will correctly separate the flows by conversation?
A company runs a FlexVPN hub-and-spoke topology built on IKEv2 and a dynamic VTI on the hub. Two branch spokes frequently exchange large volumes of VoIP and file-transfer traffic with each other, and network engineers notice all this traffic currently transits the hub, saturating the hub's WAN link and adding latency. Management wants the spokes to build direct tunnels dynamically without a full mesh of static tunnels. Which action should the engineer take to achieve this?
A security engineer notices that the malware protection and intrusion policies on a Cisco FTD sensor are failing to detect threats in outbound HTTPS traffic to unknown websites, even though the same policies successfully catch threats in cleartext HTTP sessions. Application visibility (AVC) also shows most flows as 'SSL/TLS' with no deeper application identification. Which action should the engineer take to allow the deep inspection engines to examine the payload of these encrypted sessions?
A security team is deploying 45 new Cisco Secure Firewall Threat Defense (FTD) appliances across multiple branch sites. They require centralized policy management, shared object reuse, correlation of intrusion events from all devices in a single console, and role-based access with change history. Which management option should the team select?
A security engineer deploys a Cisco FTD sensor inline between the distribution and access layers. An intrusion policy is applied with rules set to 'Generate Events'. After a demonstrated exploit, management demands that matching malicious traffic actually be dropped rather than just logged. The engineer verifies the rule state shows 'Drop and Generate Events'. However, testing shows the traffic is still passing while events are being generated. What is the MOST likely cause?
A network engineer is deploying a Cisco Secure Firewall Threat Defense (FTD) sensor to protect a data center segment. The security team requires that the sensor be able to actively drop malicious traffic in real time before it reaches the protected servers, without deploying the device as a routed or transparent Layer 3/2 firewall. Which interface deployment mode should the engineer configure on the FTD?
A security engineer is deploying a pair of Cisco Secure Firewall Threat Defense (FTD) appliances at a remote branch. The corporate FMC is located in the data center. Company policy requires that all device management traffic remain logically and physically separated from user/data traffic so that a compromise of the production data path cannot expose the management plane. The branch has a dedicated management network with its own switch and uplink back to the data center. Which management approach satisfies this requirement?
A company hosts a web server in the DMZ zone (192.168.50.10) of a Cisco Secure Firewall Threat Defense (FTD) appliance. External users reach it via the public IP 203.0.113.10 using a static NAT rule. Internal users on the inside zone report that when they browse to the server's public FQDN (which resolves to 203.0.113.10), the connection fails, even though external access works fine. What must the administrator configure on the FTD to allow internal users to reach the DMZ server using its public IP?
A network engineer notices that a large, trusted database replication flow between two internal data centers is consuming significant Snort inspection resources on an FTD appliance, causing latency for other traffic. The flow is known-good and does not require deep inspection. Which FTD configuration allows this specific traffic to bypass Snort processing entirely while still being handled by the appliance?
A network administrator is deploying a Cisco Secure Firewall Threat Defense (FTD) firewall to segment three internal departments (Finance, HR, and Engineering) so that no department can initiate connections to another unless explicitly permitted. Each department resides on its own VLAN and connects to a separate FTD data interface. The administrator wants the most scalable and maintainable way to enforce this segmentation in the access control policy. Which approach should the administrator take?
A security engineer configures URL filtering on a Cisco Secure Firewall Threat Defense (FTD) device managed by FMC. Corporate policy requires that any website with an unknown/uncategorized classification, as well as any site whose reputation score indicates it is high-risk (Questionable/Suspicious to High Risk), must be blocked for the internal user zone. All other categorized, reputable business sites should be allowed. Which access control rule configuration meets this requirement?
A security engineer is deploying a next-generation IPS to protect a data center. Management wants the sensor to detect a brand-new exploit that has no published signature yet, by flagging traffic that deviates from a learned baseline of normal protocol behavior and traffic volume. Which IPS detection method meets this requirement?
A network security engineer must secure infrastructure switch-to-switch links against Layer 2 sniffing and tampering within the campus. The requirement is to encrypt and authenticate frames on a hop-by-hop basis between directly connected switches, providing confidentiality and integrity at wire speed. Which technology should the engineer deploy?
A security engineer deploys Cisco Secure Firewall (FTD) with a Malware and File policy enabled. A user downloads a file that AMP initially assigns a 'Clean' disposition, so it is allowed through. Six hours later, the AMP cloud reclassifies that file's SHA-256 hash as malicious based on new threat intelligence. The engineer wants the FMC to alert on the fact that this file, previously allowed, is now known to be malicious. Which AMP capability provides this after-the-fact notification?
A network engineer is automating configuration changes on perimeter routers using NETCONF. The requirement is to push a multi-line configuration change, validate it before it takes effect, and be able to discard all pending changes if validation fails — without any partial configuration ever being applied to the running device. Which NETCONF capability and workflow satisfies this requirement?
A security engineer wants to enable traditional (non-Flexible) NetFlow v5 on a Cisco IOS router to build a baseline of traffic behavior for anomaly detection. During a design review, a colleague asks how the router decides that two packets belong to the same flow. Which set of attributes does traditional NetFlow use to define a unique flow?
A security engineer needs to establish network traffic baselines and detect volumetric anomalies (such as DDoS floods and unusual east-west traffic patterns) across dozens of Layer 3 switches and routers in a large campus. Storage capacity is limited, and the solution must scale without deploying dedicated capture appliances on every segment. Which technology best meets these requirements?
A security engineer is hardening the infrastructure devices in a data center. Accurate, trusted time is required so that syslog and certificate validation are reliable, and the engineer must ensure that routers only synchronize with an authorized internal NTP server and reject rogue time sources. Which configuration approach on the client routers meets this requirement?
A network engineer is hardening access-layer switches after a security audit found that an attacker on the guest VLAN successfully poisoned the ARP cache of other hosts and intercepted their traffic. The engineer needs to prevent this specific Layer 2 attack while relying on binding information already learned from client DHCP transactions. Which infrastructure security feature should be enabled to directly mitigate the ARP spoofing described?
More 350-701 practice
Keep going with the other Cisco CCNP Security SCOR (350-701) domains, or take a full timed mock exam.
← Back to 350-701 overview