Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Security

Domain 3Objective 6

3.6 Describe Application and Workload Security Concepts Including eBPF 350-701 Practice Questions (Page 1)

Part of the Cloud Security domain, which accounts for 15% of the 350-701 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–2 from this objective — we provide 26 practice questions to prepare you well beyond it. (estimate)

26questions here
6free pages
4concepts
15%of the exam

Questions 1–5

  1. 1expert · hard

    A cloud provider offers a managed Kubernetes service. The security team wants to implement runtime security monitoring for all pods, but they have a constraint: they cannot modify the node operating system or install kernel modules. Which approach should they take?

    Select an answer first
  2. 2application · medium

    A security operations team needs to monitor system calls and network activity on Linux hosts without modifying the application code or requiring the applications to be restarted. They want a solution that provides deep visibility with low overhead. Which technology should they use?

    Select an answer first
  3. 3expert · hard

    A security architect is designing a zero-trust network for a hybrid cloud environment. They need to enforce access policies based on user identity and device posture, and also gain visibility into all traffic between workloads. Which combination of technologies is most aligned with zero-trust principles?

    Select an answer first
  4. 4application · medium

    A security team wants to implement a solution that can automatically block a process if it attempts to write to a sensitive directory, such as /etc/shadow, on a Linux host. The solution should be policy-driven and operate in real time. Which approach should they use?

    Select an answer first
  5. 5application · medium

    A security team wants to detect and block malicious behavior at runtime, such as a process attempting to execute a file from a temporary directory or making an unauthorized network connection. They need a solution that can enforce policy directly in the kernel with minimal latency. Which approach is most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-701” is a trademark of its owner, used for identification only.