
CiscoCertified Network Professional Security
Domain 2Objective 5
2.5 Describe CIS Benchmarks for Hardening Devices Such as Cisco Secure Firewall (FTD) and Cisco IOS XE 350-701 Practice Questions (Page 5)
Part of the Network Security domain, which accounts for 25% of the 350-701 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–2 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)
29questions here
6free pages
6concepts
25%of the exam
Questions 21–25
- 21
In a CIS Benchmark document, what is the purpose of the 'Level 1' and 'Level 2' profile designations?
Select an answer first - 22
A security team is applying CIS Benchmark recommendations to a Cisco FTD device. The team wants to ensure that only authorized administrators can access the device. Which configuration should be implemented?
Select an answer first - 23
A security analyst is reading the CIS Benchmark for Cisco IOS XE. The analyst notices that some recommendations are marked as 'Level 2' while others are 'Level 1'. The analyst is working in a standard enterprise environment without strict regulatory requirements. Which recommendations should the analyst prioritize for implementation?
Select an answer first - 24
Which command on a Cisco IOS XE device would be used to verify that Telnet is disabled on the VTY lines?
Select an answer first - 25
According to CIS Benchmark guidance for Cisco FTD, which practice is recommended for securing the data plane?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-701” is a trademark of its owner, used for identification only.