Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Security

Domain 1Objective 2

1.2 Describe Security Vulnerabilities and Exploits Such as Software Bugs, Weak And/or Hardcoded Passwords, OWASP Top Ten, Missing Encryption Ciphers, Buffer Overflow, Path Traversal, Cross-Site Scripting/forgery, SQL Injection, and Identification and Prioritization Using CVEs and CVSS Scores 350-701 Practice Questions (Page 2)

Part of the Security Concepts domain, which accounts for 20% of the 350-701 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)

39questions here
8free pages
10concepts
20%of the exam

Questions 6–10

  1. 6foundation · easy

    What is the primary goal of a path traversal attack?

    Select an answer first
  2. 7expert · medium

    A developer is reviewing code for a network service that processes incoming packets. The code uses a function that copies data into a buffer without checking the size. The developer is considering mitigations. Which combination of mitigations is most effective to prevent exploitation?

    Select an answer first
  3. 8application · medium · select all that apply

    A security analyst is reviewing a web application for OWASP Top Ten risks. The analyst finds that the application is vulnerable to SQL injection and stored XSS. Which of the following are appropriate mitigations? (Select all that apply.)

    Select an answer first
  4. 9expert · medium

    A security team is using CVSS scores to prioritize vulnerabilities. They have a vulnerability with a CVSS v3.1 base score of 9.8 in a public-facing web server, and another with a score of 7.5 in an internal application. The team has limited resources. Which vulnerability should be remediated first?

    Select an answer first
  5. 10expert · medium

    A security team is triaging vulnerabilities in a mixed environment. They have a critical CVSS 9.8 vulnerability in a public-facing web server, a CVSS 7.5 vulnerability in an internal database, and a CVSS 5.3 vulnerability in a legacy application that is not exposed to the internet. The team has limited resources and must decide which to remediate first. Which approach should they take?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-701” is a trademark of its owner, used for identification only.