Topic 16 Practice Test 1 covers Security Concepts, Programs, and Device Passwords for Cisco Certified Network Associate 200-301 CCNA and maps to objectives 5.1–5.4. For broader exam preparation, review the Cisco CCNA 200-301 Exam Dumps. Every option includes focused technical reasoning explaining both the networking concept and its fit to the scenario.
Question 1
At Contoso, the risk review is labeling a phishing campaign that could target employees but has not yet succeeded. Which option best provides the potential source of harm that could act against an exposed system? Choose ONE.
- Threat
- Exploit
- Attack surface reduction
- Vulnerability
Correct Answer: A
Correct Answer
Answer A is correct because Threat is the right selection because A threat is a circumstance, actor, or event with the potential to cause harm by taking advantage of a weakness. For Threat, the scenario key outcome is the potential source of harm that could act against an exposed system.
Incorrect Answers
Answer B is incorrect because An exploit is a technique or code path that takes advantage of a vulnerability to produce unintended behavior Exploit misses the Threat decision in this configuration scenario. Operationally, Threat needs another behavior than Exploit provides in this configuration case.
Answer C is incorrect because The attack surface is the collection of reachable services, interfaces, accounts, and other opportunities an attacker could target For Threat, the configuration evidence requires another function than Attack surface reduction. For Attack surface reduction, separation from Threat remains material in this configuration scenario.
Answer D is incorrect because A vulnerability is a weakness in technology, configuration, process, or design that could be exploited The configuration evidence favors Threat; Vulnerability operates at another control point. Using Vulnerability here would leave the Threat requirement unresolved during this configuration task.
Question 2
At Fabrikam, a router is running a software release with a known remotely exploitable flaw. Which option best provides the underlying weakness that makes compromise possible? Choose ONE.
- Mitigation
- Vulnerability
- Threat
- Exploit
Correct Answer: B
Correct Answer
Answer B is correct because Vulnerability is the right selection because A vulnerability is a weakness in technology, configuration, process, or design that could be exploited. For Vulnerability, the scenario key outcome is the underlying weakness that makes compromise possible.
Incorrect Answers
Answer A is incorrect because A mitigation is a control or action that reduces the likelihood or impact of a security risk For Vulnerability, the configuration evidence requires another function than Mitigation. For Mitigation, separation from Vulnerability remains material in this configuration scenario.
Answer C is incorrect because A threat is a circumstance, actor, or event with the potential to cause harm by taking advantage of a weakness The configuration evidence favors Vulnerability; Threat operates at another control point.
Answer D is incorrect because Exploit is used when the scenario describes the mechanism used to leverage a weakness. Using Exploit would not produce the Vulnerability behavior shown by this configuration evidence. For Vulnerability, choosing Exploit would change the control point in this configuration case.
Question 3
At Tailspin, an attacker sends a crafted packet specifically designed to trigger a documented software flaw. Which option best provides the method used to take advantage of a known weakness? Choose ONE.
- Attack surface reduction
- Vulnerability
- Exploit
- Mitigation
Correct Answer: C
Correct Answer
Answer C is correct because Exploit is the right selection because An exploit is a technique or code path that takes advantage of a vulnerability to produce unintended behavior. For Exploit, the scenario key outcome is the method used to take advantage of a known weakness.
Incorrect Answers
Answer A is incorrect because Attack surface reduction is used when Reduce it by disabling unnecessary services and limiting exposed management interfaces. The required Exploit outcome differs from the Attack surface reduction purpose in this configuration case.
Answer B is incorrect because Vulnerability is used when Use the term for the exploitable weakness, not the attacker or the attack technique. Using Vulnerability would not produce the Exploit behavior shown by this configuration evidence.
Answer D is incorrect because Mitigation is used when Use it for patches, filtering, segmentation, hardening, or other measures that reduce exposure. In the configuration case, Exploit differs from Mitigation behavior. The Mitigation function therefore differs materially from the Exploit outcome required here.
Question 4
At Woodgrove, the team cannot replace a vulnerable service immediately and deploys a filtering control that blocks the attack path. Which option best provides the defensive action that reduces the risk associated with an identified weakness? Choose ONE.
- Threat
- Exploit
- Attack surface reduction
- Mitigation
Correct Answer: D
Correct Answer
Answer D is correct because Mitigation is the right selection because A mitigation is a control or action that reduces the likelihood or impact of a security risk. For Mitigation, the scenario key outcome is the defensive action that reduces the risk associated with an identified weakness.
Incorrect Answers
Answer A is incorrect because Threat is used when Use the term when describing a possible source of adverse action rather than the weakness itself. Using Threat would not produce the Mitigation behavior shown by this configuration evidence.
Answer B is incorrect because The purpose of Exploit is the method used to take advantage of a known weakness. Exploit misses the Mitigation decision in this configuration scenario. Operationally, Mitigation needs another behavior than Exploit provides in this configuration case.
Answer C is incorrect because The purpose of Attack surface reduction is fewer reachable services and entry points for an attacker. For Mitigation, the configuration evidence requires another function than Attack surface reduction. For Attack surface reduction, separation from Mitigation remains material in this configuration scenario.
Question 5
At Adventure Works, a branch router still listens for several legacy management protocols that the organization does not use. Which option best provides fewer reachable services and entry points for an attacker? Choose ONE.
- Attack surface reduction
- Vulnerability
- Mitigation
- Threat
Correct Answer: A
Correct Answer
Answer A is correct because Attack surface reduction is the right selection because The attack surface is the collection of reachable services, interfaces, accounts, and other opportunities an attacker could target. For Attack surface reduction, the scenario key outcome is fewer reachable services and entry points for an attacker.
Incorrect Answers
Answer B is incorrect because The purpose of Vulnerability is the underlying weakness that makes compromise possible. Vulnerability misses the Attack surface reduction decision in this configuration scenario. Operationally, Attack surface reduction needs another behavior than Vulnerability provides in this configuration case.
Answer C is incorrect because The purpose of Mitigation is the defensive action that reduces the risk associated with an identified weakness. For Attack surface reduction, the configuration evidence requires another function than Mitigation. For Mitigation, separation from Attack surface reduction remains material in this configuration scenario.
Answer D is incorrect because The purpose of Threat is the potential source of harm that could act against an exposed system. The configuration evidence favors Attack surface reduction; Threat operates at another control point. Using Threat here would leave the Attack surface reduction requirement unresolved during this configuration task.
Question 6
At Litware, all employees need recurring reminders on spotting phishing messages and reporting suspicious links. Which option best provides broad employee recognition of everyday security risks and expected behavior? Choose ONE.
- Badge-controlled physical access
- Security awareness program
- Threat
- Vulnerability
Correct Answer: B
Correct Answer
Answer B is correct because Security awareness program is the right selection because Security awareness builds broad recognition of common risks and expected safe behavior across the workforce. For Security awareness program, the scenario key outcome is broad employee recognition of everyday security risks and expected behavior.
Incorrect Answers
Answer A is incorrect because Electronic badge access limits entry to authorized identities and can create an auditable record of physical access In the configuration case, Security awareness program differs from Badge-controlled physical access behavior. The Badge-controlled physical access function therefore differs materially from the Security awareness program outcome required here.
Answer C is incorrect because Threat concerns this behavior: A threat is a circumstance, actor, or. The required Security awareness program outcome differs from the Threat purpose in this configuration case. The Security awareness program result depends on another mechanism, not the Threat behavior described above.
Answer D is incorrect because Vulnerability concerns this behavior: A vulnerability is a weakness in technology. Using Vulnerability would not produce the Security awareness program behavior shown by this configuration evidence. For Security awareness program, choosing Vulnerability would change the control point in this configuration case.
Question 7
At Proseware, network administrators must learn the approved hardening procedure and practice applying it correctly. Which option best provides specialized security skills for employees with technical duties? Choose ONE.
- Anti-tailgating physical control
- Threat
- Role-based security training
- Vulnerability
Correct Answer: C
Correct Answer
Answer C is correct because Role-based security training is the right selection because Security training develops specific skills required for a job role and is deeper than general awareness messaging. For Role-based security training, the scenario key outcome is specialized security skills for employees with technical duties.
Incorrect Answers
Answer A is incorrect because Anti-tailgating controls such as mantraps or staffed entry points reduce the chance that an unauthorized person follows an authorized user inside Anti-tailgating physical control misses the Role-based security training decision in this configuration scenario.
Answer B is incorrect because A threat is a circumstance, actor, or event with the potential to cause harm by taking advantage of a weakness In the configuration case, Role-based security training differs from Threat behavior.
Answer D is incorrect because A vulnerability is a weakness in technology, configuration, process, or design that could be exploited Vulnerability misses the Role-based security training decision in this configuration scenario. Operationally, Role-based security training needs another behavior than Vulnerability provides in this configuration case.
Question 8
At Alpine, the company wants only authorized facilities and network staff to enter the main equipment room. Which option best provides identity-based control over entry to a restricted physical area? Choose ONE.
- Security awareness program
- Threat
- Vulnerability
- Badge-controlled physical access
Correct Answer: D
Correct Answer
Answer D is correct because Badge-controlled physical access is the right selection because Electronic badge access limits entry to authorized identities and can create an auditable record of physical access. For Badge-controlled physical access, the scenario key outcome is identity-based control over entry to a restricted physical area.
Incorrect Answers
Answer A is incorrect because Security awareness builds broad recognition of common risks and expected safe behavior across the workforce For Badge-controlled physical access, the configuration evidence requires another function than Security awareness program. For Security awareness program, separation from Badge-controlled physical access remains material in this configuration scenario.
Answer B is incorrect because Threat is used when Use the term when describing a possible source of adverse action rather than the weakness itself. For Badge-controlled physical access, the configuration evidence requires another function than Threat.
Answer C is incorrect because Vulnerability is used when Use the term for the exploitable weakness, not the attacker or the attack technique. The configuration evidence favors Badge-controlled physical access; Vulnerability operates at another control point.
Question 9
At Blue Yonder, people are holding a secure door open for others after using valid badges. Which option best provides a control that prevents one authorized entry from admitting an unverified follower? Choose ONE.
- Anti-tailgating physical control
- Role-based security training
- Threat
- Vulnerability
Correct Answer: A
Correct Answer
Answer A is correct because Anti-tailgating physical control is the right selection because Anti-tailgating controls such as mantraps or staffed entry points reduce the chance that an unauthorized person follows an authorized user inside. For Anti-tailgating physical control, the scenario key outcome is a control that prevents one authorized entry from admitting an unverified follower.
Incorrect Answers
Answer B is incorrect because Security training develops specific skills required for a job role and is deeper than general awareness messaging The configuration evidence favors Anti-tailgating physical control; Role-based security training operates at another control point.
Answer C is incorrect because The purpose of Threat is the potential source of harm that could act against an exposed system. The required Anti-tailgating physical control outcome differs from the Threat purpose in this configuration case.
Answer D is incorrect because The purpose of Vulnerability is the underlying weakness that makes compromise possible. Using Vulnerability would not produce the Anti-tailgating physical control behavior shown by this configuration evidence. For Anti-tailgating physical control, choosing Vulnerability would change the control point in this configuration case.
Question 10
At Fourth Coffee, the router must require a locally configured secret before administrators can enter enable mode. Which option best provides a protected local credential for privileged EXEC access? Choose ONE.
- login local
- enable secret
- Long password or passphrase policy
- Account lockout or rate limiting after failed attempts
Correct Answer: B
Correct Answer
Answer B is correct because enable secret is the right selection because The enable secret command protects access to privileged EXEC mode with a one-way protected secret and is preferred over the older enable password. For enable secret, the scenario key outcome is a protected local credential for privileged EXEC access.
Incorrect Answers
Answer A is incorrect because The login local command instructs a line to authenticate users with the device local username database The required enable secret outcome differs from the login local purpose in this configuration case.
Answer C is incorrect because Longer passwords or passphrases increase the search space and are a core element of a strong authentication policy Using Long password or would not produce the enable secret behavior shown by this configuration evidence.
Answer D is incorrect because Lockout or rate limiting limits repeated authentication attempts and makes online password guessing more difficult In the configuration case, enable secret differs from Account lockout or behavior. The Account lockout or function therefore differs materially from the enable secret outcome required here.
Question 11
At Wingtip, a small site has no AAA server and requires named local accounts for console and SSH administration. Which option best provides a named local administrator credential stored with a protected secret? Choose ONE.
- service password-encryption limitation
- Password reuse restriction
- username … secret local account
- Multi-factor authentication
Correct Answer: C
Correct Answer
Answer C is correct because username … secret local account is the right selection because A local username configured with a secret provides a device-resident credential that can be used by login local. For username … secret, the scenario key outcome is a named local administrator credential stored with a protected secret.
Incorrect Answers
Answer A is incorrect because service password-encryption obscures certain clear-text passwords in the configuration but is only a minimal protection and is not strong cryptographic storage Using service password-encryption limitation would not produce the username … secret behavior shown by this configuration evidence.
Answer B is incorrect because A password history or reuse rule reduces the chance that users repeatedly cycle back to previously compromised credentials In the configuration case, username … secret differs from Password reuse restriction behavior.
Answer D is incorrect because MFA requires evidence from at least two different factor categories such as knowledge, possession, and inherence Multi-factor authentication misses the username … secret decision in this configuration scenario. Operationally, username … secret needs another behavior than Multi-factor authentication provides in this configuration case.
Question 12
At Northwind, the VTY lines must stop using a shared line password and instead require the configured named accounts. Which option best provides line authentication using the local username database? Choose ONE.
- Long password or passphrase policy
- Account lockout or rate limiting after failed attempts
- Digital certificate for identity validation
- login local
Correct Answer: D
Correct Answer
Answer D is correct because login local is the right selection because The login local command instructs a line to authenticate users with the device local username database. For login local, the scenario key outcome is line authentication using the local username database.
Incorrect Answers
Answer A is incorrect because Long password or is used when Use minimum length requirements to improve resistance to guessing and brute-force attacks. Long password or misses the login local decision in this configuration scenario. Operationally, login local needs another behavior than Long password or provides in this configuration case.
Answer B is incorrect because Account lockout or is used when Use it with care to slow brute-force attempts while considering denial-of-service risk. For login local, the configuration evidence requires another function than Account lockout or.
Answer C is incorrect because A digital certificate binds identity information to a public key and can support authenticated trust relationships For login local, the configuration evidence requires another function than Digital certificate for. For Digital certificate for, separation from login local remains material in this configuration scenario.
Question 13
At Contoso, an auditor wants to prevent casual viewing of a line password but warns that the mechanism is not strong protection. Which option best provides basic reversible obfuscation of eligible clear-text configuration passwords? Choose ONE.
- service password-encryption limitation
- Password reuse restriction
- Multi-factor authentication
- Biometric authentication factor
Correct Answer: A
Correct Answer
Answer A is correct because service password-encryption limitation is the right selection because service password-encryption obscures certain clear-text passwords in the configuration but is only a minimal protection and is not strong cryptographic storage. For service password-encryption limitation, the scenario key outcome is basic reversible obfuscation of eligible clear-text configuration passwords.
Incorrect Answers
Answer B is incorrect because Password reuse restriction is used when policy should prevent immediate reuse of recent passwords. For service password-encryption limitation, the configuration evidence requires another function than Password reuse restriction. For Password reuse restriction, separation from service password-encryption limitation remains material in this configuration scenario.
Answer C is incorrect because Multi-factor authentication is used when Use it so a stolen password alone is insufficient to complete authentication. The configuration evidence favors service password-encryption limitation; Multi-factor authentication operates at another control point.
Answer D is incorrect because A biometric factor uses an inherence characteristic such as a fingerprint or facial pattern to help verify identity The configuration evidence favors service password-encryption limitation; Biometric authentication factor operates at another control point.
Question 14
At Fabrikam, the organization is revising its policy after finding many short administrator passwords. Which option best provides a policy control that raises password strength by requiring sufficient length? Choose ONE.
- Account lockout or rate limiting after failed attempts
- Long password or passphrase policy
- Digital certificate for identity validation
- Physical locks and secured racks
Correct Answer: B
Correct Answer
Answer B is correct because Long password or passphrase policy is the right selection because Longer passwords or passphrases increase the search space and are a core element of a strong authentication policy. For Long password or, the scenario key outcome is a policy control that raises password strength by requiring sufficient length.
Incorrect Answers
Answer A is incorrect because The purpose of Account lockout or is a control that constrains repeated failed sign-in attempts. The required Long password or outcome differs from the Account lockout or purpose in this configuration case.
Answer C is incorrect because Digital certificate for is used when Use certificates where systems or users need cryptographic proof tied to a trusted issuing authority. The required Long password or outcome differs from the Digital certificate for purpose in this configuration case.
Answer D is incorrect because Physical locks on rooms, racks, and consoles reduce unauthorized hands-on access to network equipment The required Long password or outcome differs from the Physical locks and purpose in this configuration case.
Question 15
At Tailspin, users currently alternate between two familiar passwords whenever forced to change them. Which option best provides a policy that prevents repeated recycling of old credentials? Choose ONE.
- Multi-factor authentication
- Biometric authentication factor
- Password reuse restriction
- enable secret
Correct Answer: C
Correct Answer
Answer C is correct because Password reuse restriction is the right selection because A password history or reuse rule reduces the chance that users repeatedly cycle back to previously compromised credentials. For Password reuse restriction, the scenario key outcome is a policy that prevents repeated recycling of old credentials.
Incorrect Answers
Answer A is incorrect because The purpose of Multi-factor authentication is authentication that combines independent factor categories. Using Multi-factor authentication would not produce the Password reuse restriction behavior shown by this configuration evidence. For Password reuse restriction, choosing Multi-factor authentication would change the control point in this configuration case.
Answer B is incorrect because Biometric authentication factor is used when Use it as something the user is, typically combined with another factor in stronger authentication. Using Biometric authentication factor would not produce the Password reuse restriction behavior shown by this configuration evidence.
Answer D is incorrect because The enable secret command protects access to privileged EXEC mode with a one-way protected secret and is preferred over the older enable password Using enable secret would not produce the Password reuse restriction behavior shown by this configuration evidence.
Question 16
At Woodgrove, the authentication policy must slow automated password guessing against administrator accounts. Which option best provides a control that constrains repeated failed sign-in attempts? Choose ONE.
- Digital certificate for identity validation
- Physical locks and secured racks
- username … secret local account
- Account lockout or rate limiting after failed attempts
Correct Answer: D
Correct Answer
Answer D is correct because Account lockout or rate limiting after failed attempts is the right selection because Lockout or rate limiting limits repeated authentication attempts and makes online password guessing more difficult. For Account lockout or, the scenario key outcome is a control that constrains repeated failed sign-in attempts.
Incorrect Answers
Answer A is incorrect because The purpose of Digital certificate for is public-key identity evidence validated through certificate trust. In the configuration case, Account lockout or differs from Digital certificate for behavior. The Digital certificate for function therefore differs materially from the Account lockout or outcome required here.
Answer B is incorrect because Physical locks and is used when Use them to protect infrastructure that could otherwise be reset, cabled into, or directly manipulated. In the configuration case, Account lockout or differs from Physical locks and behavior.
Answer C is incorrect because A local username configured with a secret provides a device-resident credential that can be used by login local In the configuration case, Account lockout or differs from username … secret behavior.
Question 17
At Adventure Works, remote administrators must present a password and approve a hardware-backed possession factor. Which option best provides authentication that combines independent factor categories? Choose ONE.
- Multi-factor authentication
- Biometric authentication factor
- enable secret
- login local
Correct Answer: A
Correct Answer
Answer A is correct because Multi-factor authentication is the right selection because MFA requires evidence from at least two different factor categories such as knowledge, possession, and inherence. For Multi-factor authentication, the scenario key outcome is authentication that combines independent factor categories.
Incorrect Answers
Answer B is incorrect because The purpose of Biometric authentication factor is an inherence factor based on a physical characteristic. Biometric authentication factor misses the Multi-factor authentication decision in this configuration scenario. Operationally, Multi-factor authentication needs another behavior than Biometric authentication factor provides in this configuration case.
Answer C is incorrect because enable secret is used when require a protected credential before entering privileged EXEC mode. enable secret misses the Multi-factor authentication decision in this configuration scenario. Operationally, Multi-factor authentication needs another behavior than enable secret provides in this configuration case.
Answer D is incorrect because login local is used when console or VTY lines when named locally configured user accounts should be required. For Multi-factor authentication, the configuration evidence requires another function than login local. For login local, separation from Multi-factor authentication remains material in this configuration scenario.
Question 18
At Litware, a VPN gateway must prove its identity to peers using a credential signed by the enterprise CA. Which option best provides public-key identity evidence validated through certificate trust? Choose ONE.
- Physical locks and secured racks
- Digital certificate for identity validation
- username … secret local account
- service password-encryption limitation
Correct Answer: B
Correct Answer
Answer B is correct because Digital certificate for identity validation is the right selection because A digital certificate binds identity information to a public key and can support authenticated trust relationships. For Digital certificate for, the scenario key outcome is public-key identity evidence validated through certificate trust.
Incorrect Answers
Answer A is incorrect because The purpose of Physical locks and is direct physical protection of network hardware from unauthorized handling. For Digital certificate for, the configuration evidence requires another function than Physical locks and. For Physical locks and, separation from Digital certificate for remains material in this configuration scenario.
Answer C is incorrect because username … secret is used when the device should authenticate a named administrator from its local database. For Digital certificate for, the configuration evidence requires another function than username … secret.
Answer D is incorrect because service password-encryption limitation is used when avoid obvious plain-text display, not as a substitute for stronger secrets or secure transport. The configuration evidence favors Digital certificate for; service password-encryption limitation operates at another control point.
Question 19
At Proseware, the new administrator login flow requires a fingerprint in addition to another independent factor. Which option best provides an inherence factor based on a physical characteristic? Choose ONE.
- enable secret
- login local
- Biometric authentication factor
- Long password or passphrase policy
Correct Answer: C
Correct Answer
Answer C is correct because Biometric authentication factor is the right selection because A biometric factor uses an inherence characteristic such as a fingerprint or facial pattern to help verify identity. For Biometric authentication factor, the scenario key outcome is an inherence factor based on a physical characteristic.
Incorrect Answers
Answer A is incorrect because The purpose of enable secret is a protected local credential for privileged EXEC access. The configuration evidence favors Biometric authentication factor; enable secret operates at another control point. Using enable secret here would leave the Biometric authentication factor requirement unresolved during this configuration task.
Answer B is incorrect because The purpose of login local is line authentication using the local username database. The required Biometric authentication factor outcome differs from the login local purpose in this configuration case. The Biometric authentication factor result depends on another mechanism, not the login local behavior described above.
Answer D is incorrect because The purpose of Long password or is a policy control that raises password strength by requiring sufficient length. Using Long password or would not produce the Biometric authentication factor behavior shown by this configuration evidence.
Question 20
At Alpine, a branch switch is mounted in a publicly accessible hallway and anyone can reach its console port. Which option best provides direct physical protection of network hardware from unauthorized handling? Choose ONE.
- username … secret local account
- service password-encryption limitation
- Password reuse restriction
- Physical locks and secured racks
Correct Answer: D
Correct Answer
Answer D is correct because Physical locks and secured racks is the right selection because Physical locks on rooms, racks, and consoles reduce unauthorized hands-on access to network equipment. For Physical locks and, the scenario key outcome is direct physical protection of network hardware from unauthorized handling.
Incorrect Answers
Answer A is incorrect because The purpose of username … secret is a named local administrator credential stored with a protected secret. The required Physical locks and outcome differs from the username … secret purpose in this configuration case.
Answer B is incorrect because The purpose of service password-encryption limitation is basic reversible obfuscation of eligible clear-text configuration passwords. Using service password-encryption limitation would not produce the Physical locks and behavior shown by this configuration evidence.
Answer C is incorrect because The purpose of Password reuse restriction is a policy that prevents repeated recycling of old credentials. In the configuration case, Physical locks and differs from Password reuse restriction behavior. The Password reuse restriction function therefore differs materially from the Physical locks and outcome required here.