
CiscoCertified Network Professional Enterprise
Domain 5Objective 4
5.4 Describe the Components of Network Security Design 350-401 Practice Questions (Page 9)
Part of the 5.0 Security domain, which accounts for 20% of the 350-401 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 3–4 from this objective — we provide 56 practice questions to prepare you well beyond it. (estimate)
56questions here
12free pages
13concepts
20%of the exam
Questions 41–45
- 41
A regional bank is deploying a new internet edge for its headquarters. The security team requires that all inbound and outbound traffic be inspected for application-layer threats, and that users be identified by their Active Directory credentials rather than just IP address. The bank also wants to enforce different policies for guest and employee traffic without adding separate physical devices. Which deployment approach best meets these requirements?
Select an answer first - 42
How does an NGFW enforce application filtering policies?
Select an answer first - 43
A hospital's IT department wants to protect its Windows-based workstations from ransomware. They have deployed an endpoint detection and response (EDR) solution. What additional capability should they enable to proactively prevent ransomware from executing?
Select an answer first - 44
What key exchange method is commonly used to establish MACsec keys?
Select an answer first - 45
What is the primary role of endpoint security in a network security design?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-401” is a trademark of its owner, used for identification only.