
CiscoCertified Network Professional Enterprise
Domain 5Objective 4
5.4 Describe the Components of Network Security Design 350-401 Practice Questions (Page 5)
Part of the 5.0 Security domain, which accounts for 20% of the 350-401 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 3–4 from this objective — we provide 56 practice questions to prepare you well beyond it. (estimate)
56questions here
12free pages
13concepts
20%of the exam
Questions 21–25
- 21
Which component of a threat defense architecture is responsible for taking action to block or mitigate a detected threat?
Select an answer first - 22
A company is deploying NGFWs in a high-availability pair at the internet edge. The NGFWs must perform SSL/TLS inspection on all outbound traffic. The security team is concerned about performance degradation and certificate management. Which design decision best addresses these concerns?
Select an answer first - 23
A university has deployed an endpoint detection and response (EDR) agent on all faculty laptops. The network team wants to automatically quarantine a laptop from the network if the EDR agent detects a high-severity threat. The quarantine must be enforced at the network access layer, not just on the endpoint. Which integration approach should be used?
Select an answer first - 24
What is a common deployment scenario for MACsec?
Select an answer first - 25
What is the purpose of SSL/TLS inspection on an NGFW?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-401” is a trademark of its owner, used for identification only.