
CiscoCertified Network Professional Enterprise
Domain 5Objective 3
5.3 Describe REST API Security 350-401 Practice Questions (Page 1)
Part of the 5.0 Security domain, which accounts for 20% of the 350-401 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 3–4 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
8concepts
20%of the exam
Questions 1–5
- 1
A REST API endpoint accepts a username parameter that is directly concatenated into a SQL query. This design is vulnerable to which type of attack?
Select an answer first - 2
In the OAuth 2.0 authorization framework, what is the primary purpose of the access token?
Select an answer first - 3
A network engineer is writing a script to interact with a REST API on a Cisco device. The script fails with an SSL certificate verification error. The engineer knows the device uses a self-signed certificate. What should the engineer do to securely handle this situation?
Select an answer first - 4
A security analyst is reviewing logs from a REST API for network automation. The logs show a high number of failed authentication attempts from a single IP address, followed by a successful login and unusual API calls. What should the analyst do?
Select an answer first - 5
Which security threat is specifically associated with a REST API that accepts JSON payloads without verifying the structure or content?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-401” is a trademark of its owner, used for identification only.