
CiscoCertified Network Associate (CCNA)
Domain 5Objective 4
5.4 Describe Security Password Policy Elements, Such as Management, Complexity, and Password Alternatives (multifactor Authentication, Certificates, and Biometrics) 200-301 Practice Questions (Page 3)
Part of the Security Fundamentals domain, which accounts for 15% of the 200-301 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–1 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
5concepts
15%of the exam
Questions 11–15
- 11
An organization is moving from password-based authentication to certificate-based authentication for its internal web applications. The administrator has issued certificates to all users. What is a key advantage of certificate-based authentication over passwords in this scenario?
Select an answer first - 12
A company is planning to replace password-based authentication with certificate-based authentication for its VPN. The IT team has deployed a PKI and issued certificates to all employees. However, the help desk is concerned about supporting users who lose their laptops or need to authenticate from a new device. Which process is essential to maintain security and usability?
Select an answer first - 13
An administrator is configuring a password policy for a new user group. The policy must prevent users from using the same password across multiple systems. Which mechanism should the administrator implement?
Select an answer first - 14
A company is designing a new password policy. They want to balance security with usability. The current policy requires a 10-character password with complexity and a 60-day rotation. A security audit shows that users often choose passwords based on the current month and year (e.g., 'March2024!'). The company also wants to implement MFA for all users. Which combination of policies would be most effective?
Select an answer first - 15
A small business uses a cloud-based application that supports password authentication only. The owner wants to add a second factor without purchasing additional hardware or requiring users to install a separate app. Which option is the most practical way to implement multifactor authentication under these constraints?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-301” is a trademark of its owner, used for identification only.