
CiscoCertified Network Professional Security
Domain 2Objective 3
2.3 Configure Network Infrastructure Security Methods (network Segmentation Using VLANs or SGTs; Layer 2 and Port Security; DHCP Snooping; Dynamic ARP Inspection; Storm Control; and Defenses Against MAC, ARP, VLAN Hopping, STP, and DHCP Rogue Attacks) 350-701 Practice Questions (Page 7)
Part of the Network Security domain, which accounts for 25% of the 350-701 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–2 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)
34questions here
7free pages
12concepts
25%of the exam
Questions 31–34
- 31
Which port security feature can be used to prevent MAC spoofing by ensuring a specific MAC address is only allowed on a specific port?
Select an answer first - 32
Which security feature is specifically designed to prevent ARP spoofing by validating ARP packets against the DHCP snooping binding table?
Select an answer first - 33
What is the primary security purpose of segmenting a network using VLANs?
Select an answer first - 34
An admin is configuring a switch to prevent ARP poisoning. The network uses static IP addresses for all servers and workstations. The admin wants to validate ARP packets without relying on DHCP. Which configuration should be used?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to 350-701
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-701” is a trademark of its owner, used for identification only.