Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Enterprise

Domain 5Objective 2

5.2 Configure and Verify Infrastructure Security Features 350-401 Practice Questions (Page 4)

Part of the 5.0 Security domain, which accounts for 20% of the 350-401 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 3–4 from this objective — we provide 20 practice questions to prepare you well beyond it. (estimate)

20questions here
4free pages
7concepts
20%of the exam

Questions 16–20

  1. 16application · medium

    A network administrator is troubleshooting why a newly applied extended ACL is blocking all traffic to a web server, even though the ACL contains a permit statement for HTTP traffic. The ACL is applied inbound on the interface facing the clients. The ACL entries are: 10 permit tcp any host 192.168.2.10 eq 80 20 deny ip any any Which additional configuration is most likely required to allow the web server to respond to clients?

    Select an answer first
  2. 17foundation · easy

    What does an increasing drop counter for a specific class in the CoPP policy indicate?

    Select an answer first
  3. 18application · easy

    A network administrator is concerned about a potential DDoS attack targeting the control plane of a core router. The administrator wants to implement a solution that rate-limits traffic destined to the router's CPU while allowing legitimate management and routing traffic. Which feature should the administrator configure?

    Select an answer first
  4. 19application · medium

    A network administrator notices that the CPU utilization on a core router spikes to 95% during a distributed denial-of-service (DDoS) attack. The attack traffic is targeting the router's own IP address with ICMP and TCP SYN packets. The administrator wants to protect the router's control plane without affecting transit traffic. Which solution should be implemented?

    Select an answer first
  5. 20application · medium

    A network administrator is implementing CoPP to protect the router's control plane from a potential DDoS attack. They want to allow normal routing protocol traffic (OSPF, BGP) but rate-limit other traffic to the control plane. Which configuration approach is correct?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to 350-401

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-401” is a trademark of its owner, used for identification only.