
CiscoCertified Network Professional Enterprise
Domain 5Objective 4
5.4 Describe the Components of Network Security Design 350-401 Practice Questions (Page 6)
Part of the 5.0 Security domain, which accounts for 20% of the 350-401 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 3–4 from this objective — we provide 56 practice questions to prepare you well beyond it. (estimate)
56questions here
12free pages
13concepts
20%of the exam
Questions 26–30
- 26
A large enterprise is implementing Cisco TrustSec to enforce micro-segmentation between application tiers. The network team wants to ensure that SGTs are propagated across the network so that enforcement devices can apply policy. Which protocol is used to propagate SGT information between switches?
Select an answer first - 27
A campus network uses MACsec to encrypt links between access switches and distribution switches. The security team wants to automate key management and support dynamic key rotation without manual configuration on each switch. Which key management method should be used?
Select an answer first - 28
What is the primary purpose of MACsec?
Select an answer first - 29
A company wants to prevent employees from running unauthorized software on their Windows laptops, while still allowing approved business applications. The endpoint security solution must enforce this policy regardless of user privileges. Which endpoint security technology should be used?
Select an answer first - 30
What is a common method to ensure high availability for NGFWs in a network design?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-401” is a trademark of its owner, used for identification only.