Security Concepts
Drill 20 practice questions focused entirely on Security Concepts for the Cisco 350-701 exam. Tap an answer for instant feedback and a full explanation — no sign-up, always free.
A penetration tester submits an oversized input string to a legacy C-based network daemon running on a company server. The application crashes, and the tester is subsequently able to execute arbitrary code by overwriting the return address on the stack with a pointer to injected shellcode. Which vulnerability class does this describe?
A security engineer is deploying a remote access VPN and wants to eliminate the risk of shared or reused credentials. The organization already operates an internal PKI. The engineer configures the VPN gateway to require that each connecting client present an X.509 digital certificate issued by the corporate CA, and the gateway validates the certificate chain and checks revocation before granting access. Which cryptography function is being used to authenticate the user in this design?
A security analyst reviews authentication logs for a company's public-facing web portal and notices thousands of failed login attempts across many different user accounts, each account tried only a handful of times before the attacker moves to the next. The source IPs rotate frequently, and a small percentage of logins eventually succeed using valid username/password pairs that were never reset after a breach at an unrelated third-party site. Which type of attack best describes this activity?
A network engineer must deploy a VPN solution connecting one central hub to 200 branch offices. The design must support dynamic spoke-to-spoke tunnels that build on demand, use multipoint GRE with NHRP for address resolution, and minimize hub configuration overhead as new spokes are added. Which VPN deployment type best satisfies these requirements?
A network operations team wants to programmatically pull the health scores of wireless clients and network devices from Cisco Catalyst Center so that a custom dashboard can proactively alert on degraded performance. Which category of Cisco Catalyst Center APIs should the automation engineer target to retrieve this data?
A network automation engineer needs to programmatically push a standardized device configuration template to 200 branch switches and then verify the deployment status across the fabric. They plan to use Cisco Catalyst Center APIs. Which Catalyst Center API category should the engineer call to automate the initial rollout of the standardized configuration to the branch devices?
A network engineer is consolidating VPN infrastructure on Cisco IOS routers. The design must support both site-to-site tunnels and remote access clients using a single, unified IKEv2-based framework that leverages a modular CLI with reusable configuration blocks (profiles, keyrings, and authorization policies). Which VPN technology should the engineer deploy to meet these requirements?
During a security audit, a penetration tester discovers that a batch of deployed IoT cameras all authenticate management access using the same username and password, which are embedded directly in the firmware image and cannot be changed by the customer. Which vulnerability category best describes this finding?
A security engineer downloads a Cisco IOS image from the vendor and wants to confirm the file was not altered or corrupted during transfer. The vendor publishes a SHA-512 value alongside the download link. Which cryptographic function is the engineer using, and what property does it provide in this scenario?
A network engineer is configuring a site-to-site IPsec tunnel between two data centers to carry sensitive financial replication traffic over the public Internet. The security policy mandates that the payload be both encrypted and integrity-protected, and the tunnel must survive traversal through an intermediate NAT device. Which IPsec protocol should the engineer select for the transform set to meet these requirements?
A network engineer is configuring a standards-based site-to-site IPsec VPN between two branch routers. During IKEv2 negotiation, the engineer must ensure both peers can mutually verify each other's identity before establishing the secure channel, but the organization has decided not to deploy a PKI. Which cryptographic component fulfills the peer authentication requirement in this deployment?
During a security audit of a company's customer portal, a penetration tester discovers that the web application transmits session tokens over an unencrypted HTTP connection and stores passwords in the database in plaintext. The tester must categorize this finding accurately for the remediation report. Which vulnerability category best describes this finding?
A remote site's IPsec site-to-site VPN to headquarters fails to establish the IPsec SAs even though IKE phase 1 completes successfully. The remote router sits behind an ISP device that performs PAT (Port Address Translation) for all outbound traffic. Traffic is being dropped as it traverses the PAT device. Which mechanism must be enabled so the encrypted ESP traffic can successfully traverse the NAT device?
A network automation team is building a custom dashboard application that pulls device health and network assurance data from Cisco Catalyst Center. The application communicates with Catalyst Center over a RESTful interface, while Catalyst Center itself uses device-facing protocols to push configuration to the switches and routers it manages. Which statement correctly characterizes the API relationship in this SDN architecture?
A security analyst at a hybrid enterprise notices that internal users connecting to a cloud-hosted HR portal are receiving certificate warnings intermittently. Investigation reveals an attacker on the corporate LAN has poisoned the ARP cache of several hosts, silently relaying and reading traffic between the users and the default gateway before forwarding it to the cloud. Which type of threat does this activity BEST represent?
A security analyst reviews a penetration test report for a company's customer-facing web portal. The finding states: an attacker was able to submit crafted input into a search field that was passed unsanitized into a backend database query, allowing the attacker to retrieve records belonging to other users. Which OWASP Top Ten category best classifies this vulnerability?
A security analyst reviews a penetration test report for a web-based document portal. The tester demonstrated that by submitting a request such as GET /download?file=../../../../etc/passwd, they retrieved the contents of a system file located outside the intended document directory. Which vulnerability class does this finding represent?
A financial services company reports that employees keep clicking links in phishing emails that pass the initial email gateway inspection because the destination pages are weaponized only hours after delivery. The security team needs a control that re-evaluates the reputation and content of a link at the moment the user actually clicks it, rather than only when the message is received. Which control best addresses this requirement?
A financial services company keeps receiving emails that appear to come from its own domain, tricking employees into wire transfers. The security team has already implemented SPF but attackers are still successfully spoofing the exact 'From' header address. Which control should be added to reject messages that fail domain alignment and provide the organization with visibility reporting on spoofing attempts?
A security engineer is deploying certificate-based authentication for a corporate PKI. During validation testing, a client presents a certificate that was administratively invalidated by the CA two hours ago, yet the client is still granted access. The engineer needs to ensure the authenticating device performs a real-time query to confirm a certificate has not been revoked before trusting it. Which PKI component provides this function?
More 350-701 practice
Keep going with the other Cisco CCNP Security SCOR (350-701) domains, or take a full timed mock exam.
← Back to 350-701 overview