Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Design Expert (CCDE)

Domain 5Objective 1

5.1 Network Security Design and Integration 400-007 Practice Questions (Page 3)

Part of the 5.0 Security Design domain, which accounts for 15% of the 400-007 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 8–12 from this objective — we provide 26 practice questions to prepare you well beyond it. (estimate)

26questions here
6free pages
8concepts
15%of the exam

Questions 11–15

  1. 11application · medium

    A financial services firm is redesigning its data center network to isolate cardholder data (CDE) from the rest of the corporate network. The design must prevent lateral movement from the corporate zone to the CDE zone while still allowing the CDE application servers to initiate outbound updates to a specific patch repository in the corporate zone. The security team insists on stateful inspection at every trust boundary. Which segmentation approach best meets these requirements?

    Select an answer first
  2. 12foundation · easy

    Which regulatory framework is specifically focused on protecting the privacy of personal data of individuals in the European Union?

    Select an answer first
  3. 13foundation · easy

    What is a key security policy consideration when employees use external AI services that may process proprietary data?

    Select an answer first
  4. 14application · medium

    A security architect has designed a new segmentation policy that uses a next-generation firewall to isolate the finance department from the rest of the network. Before rolling this out to production, the architect needs to validate that the firewall rules are working as intended and that no unintended traffic is being allowed. Which assurance method is most appropriate for this validation?

    Select an answer first
  5. 15expert · hard

    A marketing agency is using an external AI service to generate content for clients. The agency's security team is concerned about the AI service's use of client data, which may contain confidential business information. The agency's current security policy does not address AI services. The team must balance the need to use the AI service for productivity with the need to protect client data. Which approach best balances these competing requirements?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “400-007” is a trademark of its owner, used for identification only.