
CiscoCertified Network Professional Enterprise
Domain 5Objective 4
5.4 Describe the Components of Network Security Design 350-401 Practice Questions (Page 2)
Part of the 5.0 Security domain, which accounts for 20% of the 350-401 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 3–4 from this objective — we provide 56 practice questions to prepare you well beyond it. (estimate)
56questions here
12free pages
13concepts
20%of the exam
Questions 6–10
- 6
Where is an NGFW typically placed in a network design to provide the most effective security?
Select an answer first - 7
Which endpoint security technology is specifically designed to prevent malicious code from modifying system files or registry keys?
Select an answer first - 8
A security architect is designing threat defense for a high-security research network. The network must prevent data exfiltration and detect advanced persistent threats (APTs). The team is considering deploying a network IPS and an EDR solution. Which design consideration is most important to ensure the IPS and EDR work effectively together?
Select an answer first - 9
A healthcare organization wants to implement micro-segmentation to protect patient records. They have a mix of legacy switches that do not support SGT tagging and newer switches that do. The security team wants to enforce SGT-based policies at the firewall. Which approach best achieves segmentation without upgrading all legacy switches?
Select an answer first - 10
Which feature is a key differentiator of a next-generation firewall (NGFW) compared to a traditional stateful firewall?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-401” is a trademark of its owner, used for identification only.