
CiscoCertified Network Professional Service Provider
Domain 1Objective 6
1.6 Describe Management Plane Security 350-501 Practice Questions (Page 5)
Part of the Architecture domain, which accounts for 15% of the 350-501 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–2 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
4concepts
15%of the exam
Questions 21–25
- 21
A service provider is facing a sophisticated DDoS attack that targets the management plane of its edge routers. The attack uses a mix of spoofed SYN floods and legitimate-looking HTTPS requests to the management interface. The NOC must maintain access to the routers for emergency configuration changes. The engineer has the following tools available: control plane policing (CoPP), traceback, TACACS+ with per-command authorization, and a REST API with rate limiting. Which combination of actions provides the most effective defense while preserving NOC access?
Select an answer first - 22
A network administrator is configuring AAA on a service provider router. The security policy requires that all configuration changes be logged with the username, the exact command, and the timestamp. The administrator also needs to ensure that if the AAA server is unreachable, the router can still be accessed via the console for emergency recovery. Which configuration should be implemented?
Select an answer first - 23
A service provider's management network is experiencing a DDoS attack that is saturating the link to the management plane. The attack traffic appears to come from many different source IPs and is targeting the SSH port on the management routers. The operator needs to mitigate the attack while maintaining legitimate administrative access. Which approach is most effective?
Select an answer first - 24
A service provider is integrating a third-party orchestration system with its router management API. The orchestration system needs to retrieve configuration data but must not be able to modify configurations. The security team also wants to ensure that the API traffic is not intercepted. Which approach should be used?
Select an answer first - 25
A service provider is designing a management plane for a new network. The design must support both CLI and REST API access, with centralized authentication and authorization. The provider also wants to ensure that the management plane is resilient to DDoS attacks. The security team is considering using TACACS+ for CLI and OAuth 2.0 for the API. Which additional measure is essential to meet the DDoS resilience requirement?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-501” is a trademark of its owner, used for identification only.