Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Security

Domain 1Objective 2

1.2 Describe Security Vulnerabilities and Exploits Such as Software Bugs, Weak And/or Hardcoded Passwords, OWASP Top Ten, Missing Encryption Ciphers, Buffer Overflow, Path Traversal, Cross-Site Scripting/forgery, SQL Injection, and Identification and Prioritization Using CVEs and CVSS Scores 350-701 Practice Questions (Page 4)

Part of the Security Concepts domain, which accounts for 20% of the 350-701 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)

39questions here
8free pages
10concepts
20%of the exam

Questions 16–20

  1. 16application · medium

    A security analyst is reviewing the configuration of a web server that supports TLS 1.0 and uses RC4 for encryption. The analyst is concerned about the security of data in transit. Which vulnerability is present, and what is the recommended action?

    Select an answer first
  2. 17expert · medium

    A web application uses cookies for session management but does not include anti-CSRF tokens in its forms. An attacker crafts a malicious page that, when visited by an authenticated user, submits a form to the application to change the user's email address. The application processes the request without verifying the origin. Which mitigation would be most effective to prevent this attack?

    Select an answer first
  3. 18foundation · easy

    What is the primary risk of using a weak or missing encryption cipher in a web application?

    Select an answer first
  4. 19expert · medium

    A security auditor is reviewing a network device that has a password policy allowing weak passwords. The auditor also finds that the device has a hardcoded backdoor account. The organization wants to improve security without disrupting operations. Which action should be prioritized?

    Select an answer first
  5. 20foundation · easy

    What is the key characteristic of a cross-site request forgery (CSRF) attack?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-701” is a trademark of its owner, used for identification only.