Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Service Provider

Domain 1Objective 6

1.6 Describe Management Plane Security 350-501 Practice Questions (Page 4)

Part of the Architecture domain, which accounts for 15% of the 350-501 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–2 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)

33questions here
7free pages
4concepts
15%of the exam

Questions 16–20

  1. 16application · medium

    A network operator is deploying a REST API on a service provider router to allow customers to programmatically configure their own VPN services. The API must authenticate each request, ensure that a customer can only modify their own VPN, and prevent a single customer from overwhelming the API with requests. Which set of mechanisms should the engineer implement?

    Select an answer first
  2. 17application · medium

    A service provider network engineer is troubleshooting a series of failed SSH login attempts to the core router's management interface. The source IP addresses appear to be spoofed, and the engineer needs to determine the actual ingress interface of the attack traffic. The router is configured with AAA using TACACS+ for management access. Which combination of actions will provide the most direct evidence of the true attack source?

    Select an answer first
  3. 18application · medium

    A network operator exposes a REST API on its routers for programmatic configuration changes. The security team requires that only authenticated NOC applications can modify configurations, that all API traffic is encrypted in transit, and that a single misbehaving client cannot overwhelm the API endpoint. Which set of mechanisms should the operator implement?

    Select an answer first
  4. 19expert · hard

    A service provider's management API is being targeted by a DDoS attack that uses a large number of legitimate-looking requests from distributed sources. The API is protected by rate limiting, but the attack is still causing performance degradation. The provider wants to identify the attack sources and also wants to ensure that the API remains available for legitimate users. Which approach should be taken?

    Select an answer first
  5. 20foundation · easy

    Which technique is commonly used to mitigate a DDoS attack targeting the management plane of a router?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-501” is a trademark of its owner, used for identification only.