Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Security

Domain 3Objective 6

3.6 Describe Application and Workload Security Concepts Including eBPF 350-701 Practice Questions (Page 3)

Part of the Cloud Security domain, which accounts for 15% of the 350-701 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–2 from this objective — we provide 26 practice questions to prepare you well beyond it. (estimate)

26questions here
6free pages
4concepts
15%of the exam

Questions 11–15

  1. 11application · medium

    A security team wants to gain visibility into network traffic between workloads in a cloud environment without deploying additional agents on each workload. They want to use a technology that can inspect traffic at the kernel level. Which technology should they consider?

    Select an answer first
  2. 12expert · hard

    A company is deploying a new application that consists of multiple microservices. The security team wants to ensure that each microservice can only communicate with the services it needs, and that any compromise of one service does not expose the others. They also want to enforce this policy without relying on IP addresses, which can change. Which solution is most appropriate?

    Select an answer first
  3. 13application · medium

    A security analyst needs to detect if a process is making DNS queries to known malicious domains. The solution should be able to see the DNS requests at the kernel level and alert in real time. Which technology is most appropriate?

    Select an answer first
  4. 14application · medium

    A company is deploying a containerized application in a cloud environment. The security team wants to ensure that containers are isolated from each other and that any malicious activity inside a container is detected. Which two controls should they implement?

    Select an answer first
  5. 15expert · hard

    A security team is evaluating tools for runtime protection on Linux servers. They need to detect and block zero-day exploits that attempt to use previously unknown attack vectors. The tool must have a minimal performance impact and be able to enforce policies dynamically. Which technology is best suited?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-701” is a trademark of its owner, used for identification only.