Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Enterprise

Domain 5Objective 3

5.3 Describe REST API Security 350-401 Practice Questions (Page 2)

Part of the 5.0 Security domain, which accounts for 20% of the 350-401 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 3–4 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)

43questions here
9free pages
8concepts
20%of the exam

Questions 6–10

  1. 6foundation · easy

    A REST API is being overwhelmed by a flood of requests from a single client, causing service degradation for other users. Which security control is specifically designed to limit the number of requests a client can make in a given time period?

    Select an answer first
  2. 7application · medium

    A network automation platform exposes a REST API. The security team wants to detect a brute-force attack on the API's authentication endpoint. Which logging and monitoring practice should the team implement?

    Select an answer first
  3. 8expert · hard

    A large enterprise exposes a REST API for network automation. The API is critical and must remain available. Recently, a distributed denial-of-service (DDoS) attack used a botnet to overwhelm the API. The team implemented rate limiting per IP, but the attack continues because the botnet rotates IPs. The team also needs to maintain visibility for incident response. Which combination of measures should the team implement?

    Select an answer first
  4. 9application · medium

    A REST API accepts a JSON payload to configure network devices. A security scan found that the API is vulnerable to cross-site scripting (XSS) because it reflects user input in error messages. Which mitigation should be applied?

    Select an answer first
  5. 10expert · hard

    A company is deploying a REST API for network configuration. The API uses OAuth 2.0 with scopes. The security team wants to enforce that a user with the 'network-admin' role can modify configurations, while a user with the 'network-viewer' role can only read them. The API receives an access token with the scope 'network:read'. Which action should the API take?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-401” is a trademark of its owner, used for identification only.