
CiscoCertified Network Professional Security
Domain 2Objective 3
2.3 Configure Network Infrastructure Security Methods (network Segmentation Using VLANs or SGTs; Layer 2 and Port Security; DHCP Snooping; Dynamic ARP Inspection; Storm Control; and Defenses Against MAC, ARP, VLAN Hopping, STP, and DHCP Rogue Attacks) 350-701 Practice Questions (Page 1)
Part of the Network Security domain, which accounts for 25% of the 350-701 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–2 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)
34questions here
7free pages
12concepts
25%of the exam
Questions 1–5
- 1
What is the primary purpose of DHCP snooping?
Select an answer first - 2
A company has a flat Layer 2 network with a single DHCP server connected to a distribution switch. Users report intermittent IP address conflicts and some machines receiving addresses from an unknown scope. The admin suspects a rogue DHCP server on an access port. The admin enables DHCP snooping globally and on the VLANs. Which additional configuration is required to make DHCP snooping effective?
Select an answer first - 3
What is the primary purpose of storm control on a Cisco switch?
Select an answer first - 4
In a DHCP snooping configuration, what happens to a DHCP OFFER message received on an untrusted port?
Select an answer first - 5
Which configuration practice helps prevent VLAN hopping attacks on a switch access port?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-701” is a trademark of its owner, used for identification only.