
CiscoCertified Network Professional Data Center
Domain 5Objective 1
5.1 Apply Network Security 350-601 Practice Questions (Page 7)
Part of the Security domain, which accounts for 15% of the 350-601 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 3–4 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
15concepts
15%of the exam
Questions 31–35
- 31
A data center has a mix of NX-OS switches and ACI fabric. The security team requires centralized authentication for both, but the ACI fabric uses RADIUS for authentication and the NX-OS switches use TACACS+. The team also wants to enforce different authorization levels for network admins and network operators on the NX-OS switches. Which approach best meets these requirements?
Select an answer first - 32
In the AAA model for network device access, which component provides a record of user activity, such as commands executed and sessions started?
Select an answer first - 33
Which of the following is a valid method to configure MACsec on Cisco switches?
Select an answer first - 34
When integrating RBAC with TACACS+ on Cisco NX-OS, what is the purpose of the 'tacacs+ server' configuration?
Select an answer first - 35
An engineer is configuring keychain authentication for EIGRP between two NX-OS switches. The keychain has two keys: key 1 with a send lifetime from 00:00 Jan 1 to 23:59 Dec 31, and key 2 with a send lifetime from 00:00 Jun 1 to 23:59 Dec 31. The engineer notices that the adjacency is flapping on June 1. What is the most likely cause?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-601” is a trademark of its owner, used for identification only.