
CiscoCertified Network Professional Security
Domain 2Objective 3
2.3 Configure Network Infrastructure Security Methods (network Segmentation Using VLANs or SGTs; Layer 2 and Port Security; DHCP Snooping; Dynamic ARP Inspection; Storm Control; and Defenses Against MAC, ARP, VLAN Hopping, STP, and DHCP Rogue Attacks) 350-701 Practice Questions (Page 6)
Part of the Network Security domain, which accounts for 25% of the 350-701 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–2 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)
34questions here
7free pages
12concepts
25%of the exam
Questions 26–30
- 26
In a Cisco TrustSec deployment, how is the SGT typically carried across the network so that downstream devices can enforce policy?
Select an answer first - 27
What is the purpose of BPDU guard on a Cisco switch port?
Select an answer first - 28
What is the primary purpose of configuring port security on a Cisco switch access port?
Select an answer first - 29
An admin enables DAI on VLAN 10. The network uses a mix of DHCP-assigned and statically configured hosts. After enabling DAI, all ARP traffic is dropped, and hosts cannot communicate. The admin has verified that DHCP snooping is working and the binding table is populated for DHCP hosts. What is the most likely cause of the total ARP failure?
Select an answer first - 30
Which port security violation mode causes the port to immediately disable itself and require manual intervention to re-enable?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-701” is a trademark of its owner, used for identification only.