
CiscoCertified Network Professional Security
Domain 2Objective 3
2.3 Configure Network Infrastructure Security Methods (network Segmentation Using VLANs or SGTs; Layer 2 and Port Security; DHCP Snooping; Dynamic ARP Inspection; Storm Control; and Defenses Against MAC, ARP, VLAN Hopping, STP, and DHCP Rogue Attacks) 350-701 Practice Questions (Page 4)
Part of the Network Security domain, which accounts for 25% of the 350-701 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–2 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)
34questions here
7free pages
12concepts
25%of the exam
Questions 16–20
- 16
An admin is troubleshooting ARP spoofing on a switch. The switch has DHCP snooping enabled on the VLAN. The admin wants to validate ARP packets without manually configuring static IP-to-MAC bindings for every host. Which configuration should the admin apply?
Select an answer first - 17
Which Layer 2 security feature is specifically designed to prevent a rogue switch from becoming the root bridge and altering the forwarding topology?
Select an answer first - 18
Which mechanism is required to allow communication between hosts in different VLANs while still maintaining the security boundary?
Select an answer first - 19
Which protocol, when left enabled on access ports, can be exploited to perform a VLAN hopping attack?
Select an answer first - 20
A company wants to isolate guest Wi-Fi traffic from the corporate network at Layer 2. The guest and corporate users are on the same access switches. The admin wants to prevent guests from reaching corporate resources while allowing both to use the internet. Which approach meets this requirement?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-701” is a trademark of its owner, used for identification only.