Cisco CCNP 350-401 ENCOR Threat Defense, Endpoint Security, NGFW, TrustSec, and MACsec Practice Test 1

 

Topic 18 Practice Test 1 covers Threat Defense, Endpoint Security, NGFW, TrustSec, and MACsec for Cisco 350-401 ENCOR. For broader exam preparation, review the Cisco 350-401 ENCOR Exam Dumps. Every option includes focused technical reasoning explaining both the Cisco enterprise networking concept and its fit to the scenario.

Question 1

A branch security team wants to block known command-and-control destinations before users establish sessions, using continuously updated reputation intelligence. Which security capability most directly meets the requirement? Choose ONE.

  1. Threat-intelligence-based reputation blocking
  2. TrustSec SGACL enforcement
  3. MACsec link encryption
  4. Endpoint host isolation

Correct Answer(s)

 

A

Rationale

  1. Reputation feeds let a security control identify and block destinations already associated with malicious infrastructure, matching the requested prevention point before a session is established. The decisive requirement is the organization wants to stop known command-and-control destinations before users connect while using continuously updated reputation intelligence, so this is the direct fit.
  2. SGACLs apply identity-group policy between security groups; they are not a dynamic reputation service for command-and-control domains or Internet destinations. The case requires the organization wants to stop known command-and-control destinations before users connect while using continuously updated reputation intelligence, which this option does not provide.
  3. MACsec protects Ethernet frames on a link; it does not classify Internet destinations by malicious reputation, so confidentiality does not satisfy the requested threat-intelligence decision. The case requires the organization wants to stop known command-and-control destinations before users connect while using continuously updated reputation intelligence, which this option does not provide.
  4. Host isolation contains an endpoint after a compromise or high-confidence detection; the requirement is to prevent connections to known malicious infrastructure before endpoint containment is needed. The case requires the organization wants to stop known command-and-control destinations before users connect while using continuously updated reputation intelligence, which this option does not provide.

 

Question 2

An enterprise needs a control that can inspect traffic for exploit signatures and stop matching packets inline, not just report them. Which component best fits? Choose ONE.

  1. Passive IDS sensor that generates alerts only
  2. MACsec
  3. Inline intrusion prevention system (IPS)
  4. Endpoint inventory scanner

Correct Answer(s)

 

C

Rationale

  1. A passive IDS can detect suspicious patterns and generate alerts but does not normally sit inline to stop the matching packets requested by the scenario. The case requires the design must block exploit traffic inline rather than merely alert after observing it, which this option does not provide.
  2. MACsec provides Layer 2 confidentiality and integrity on supported Ethernet links; it does not inspect application payloads for exploit signatures. The case requires the design must block exploit traffic inline rather than merely alert after observing it, which this option does not provide.
  3. An inline IPS sits in the forwarding path and can actively block traffic that matches exploit or intrusion logic, which is the prevention behavior stated in the design. The decisive requirement is the design must block exploit traffic inline rather than merely alert after observing it, so this is the direct fit.
  4. An endpoint inventory scanner identifies software or asset state but does not perform inline network inspection and packet blocking. The case requires the design must block exploit traffic inline rather than merely alert after observing it, which this option does not provide.

 

Question 3

Security architects assume a user endpoint may be compromised after entering the campus. They want to reduce the internal blast radius by restricting which protected services that endpoint can reach. Which design principle is most relevant? Choose ONE.

  1. Encrypt every access link with MACsec only
  2. Internal segmentation with least-privilege policy
  3. Use a single broad inside trust zone
  4. Increase Internet edge bandwidth

Correct Answer(s)

 

B

Rationale

  1. MACsec can protect frames on individual links, but link encryption alone does not decide which internal applications or security zones an endpoint may access. The case requires a compromised user device must be prevented from freely reaching sensitive internal services even though perimeter controls remain intact, which this option does not provide.
  2. Internal segmentation limits lateral movement by allowing only required relationships between users and services, so a compromise does not automatically inherit broad internal reachability. The decisive requirement is a compromised user device must be prevented from freely reaching sensitive internal services even though perimeter controls remain intact, so this is the direct fit.
  3. A broad inside trust zone does the opposite of the requirement because it expands implicit reachability and therefore increases the possible blast radius. The case requires a compromised user device must be prevented from freely reaching sensitive internal services even though perimeter controls remain intact, which this option does not provide.
  4. Additional Internet bandwidth improves capacity but does not constrain east-west access from a compromised endpoint to sensitive internal services. The case requires a compromised user device must be prevented from freely reaching sensitive internal services even though perimeter controls remain intact, which this option does not provide.

 

Question 4

A security review requires that failure or evasion of one defensive mechanism should not leave an important service completely exposed. Which approach best addresses that requirement? Choose ONE.

  1. Replace endpoint controls with link encryption
  2. Rely on one high-capacity firewall
  3. Use one universal permit policy plus logging
  4. Defense in depth with independent control layers

Correct Answer(s)

 

D

Rationale

  1. Link encryption protects confidentiality and integrity in transit; replacing endpoint and network controls with it removes rather than adds independent defensive layers. The case requires the security program must remain effective if any single defensive control is bypassed, which this option does not provide.
  2. A single firewall can be valuable, but concentrating protection in one device leaves the design dependent on the very single control the requirement says not to trust alone. The case requires the security program must remain effective if any single defensive control is bypassed, which this option does not provide.
  3. A universal permit policy with logging can improve visibility but deliberately removes independent preventive barriers, so it does not provide layered resistance. The case requires the security program must remain effective if any single defensive control is bypassed, which this option does not provide.
  4. Defense in depth combines complementary preventive, detective, and containment controls so another layer can still reduce risk when one mechanism is bypassed or fails. The decisive requirement is the security program must remain effective if any single defensive control is bypassed, so this is the direct fit.

 

Question 5

A suspicious executable ran on a laptop. Analysts need endpoint process, file, and behavior history to determine what the program did after execution. Which security component is the best fit? Choose ONE.

  1. Endpoint detection and response (EDR)
  2. Network address translation
  3. MACsec
  4. Stateless router ACL for packet-header filtering

Correct Answer(s)

 

A

Rationale

  1. EDR collects endpoint-centric telemetry and supports investigation of processes, files, and behavior over time, directly matching the need to reconstruct post-execution activity on the workstation. The decisive requirement is analysts need process, file, and behavioral telemetry from the affected workstation to investigate activity that occurred after execution, so this is the direct fit.
  2. NAT translates addresses and ports; it provides neither process-level telemetry nor a history of executable behavior on the endpoint. The case requires analysts need process, file, and behavioral telemetry from the affected workstation to investigate activity that occurred after execution, which this option does not provide.
  3. MACsec secures Layer 2 traffic on a supported link but cannot report which local process launched, changed files, or spawned child processes. The case requires analysts need process, file, and behavioral telemetry from the affected workstation to investigate activity that occurred after execution, which this option does not provide.
  4. A stateless ACL can permit or deny traffic by header fields, yet it does not record endpoint process trees or file activity. The case requires analysts need process, file, and behavioral telemetry from the affected workstation to investigate activity that occurred after execution, which this option does not provide.

 

Question 6

A laptop is confirmed compromised and is still communicating with other systems. The response team wants to cut normal network access while keeping the endpoint available for security investigation. Which action is most appropriate? Choose ONE.

  1. Encrypt the access switch uplink with MACsec
  2. Add a URL category to the perimeter firewall
  3. Disable every campus VLAN
  4. Use the endpoint security platform’s host isolation capability

Correct Answer(s)

 

D

Rationale

  1. MACsec protects traffic confidentiality and integrity on a link but does not quarantine the compromised host or stop its authorized Layer 3 communications. The case requires a confirmed infected laptop must be contained quickly while analysts preserve the device for investigation, which this option does not provide.
  2. A URL category can block web destinations, but a compromised endpoint may use other protocols or internal targets, leaving the requested host-level containment incomplete. The case requires a confirmed infected laptop must be contained quickly while analysts preserve the device for investigation, which this option does not provide.
  3. Disabling campus VLANs would disrupt many unrelated users and services, far exceeding the scope required to contain one compromised laptop. The case requires a confirmed infected laptop must be contained quickly while analysts preserve the device for investigation, which this option does not provide.
  4. Endpoint host isolation is designed to contain a specific compromised device by restricting its ordinary communications while retaining controlled management or investigation access. The decisive requirement is a confirmed infected laptop must be contained quickly while analysts preserve the device for investigation, so this is the direct fit.

 

Question 7

Security operations wants a capability that identifies endpoints with vulnerable software so remediation can be prioritized before exploitation. Which endpoint-security function best meets the need? Choose ONE.

  1. MACsec replay protection on protected Ethernet frames
  2. Endpoint vulnerability visibility and prioritization
  3. SGT inline tagging
  4. Stateful NAT

Correct Answer(s)

 

B

Rationale

  1. MACsec replay protection rejects replayed protected frames; it does not identify vulnerable applications installed on an endpoint. The case requires the organization wants to reduce exposure to known exploitable software versions on managed endpoints before an attack occurs, which this option does not provide.
  2. Endpoint vulnerability visibility ties device software state to known weaknesses so teams can prioritize remediation before an exploit is observed, which addresses the preventive requirement. The decisive requirement is the organization wants to reduce exposure to known exploitable software versions on managed endpoints before an attack occurs, so this is the direct fit.
  3. SGT tagging carries identity-group context for policy; it does not inventory software versions or rank endpoint vulnerabilities. The case requires the organization wants to reduce exposure to known exploitable software versions on managed endpoints before an attack occurs, which this option does not provide.
  4. Stateful NAT tracks translated flows but provides no assessment of local software exposure or patch urgency. The case requires the organization wants to reduce exposure to known exploitable software versions on managed endpoints before an attack occurs, which this option does not provide.

 

Question 8

A malicious executable can arrive on a workstation through USB media, so relying only on network inspection is insufficient. Which component most directly addresses the risk at execution time? Choose ONE.

  1. Internet-edge NGFW inspecting network traffic only
  2. TrustSec SGACL
  3. Endpoint anti-malware and behavioral prevention
  4. MACsec

Correct Answer(s)

 

C

Rationale

  1. An Internet edge NGFW can inspect traffic crossing that boundary, but a file introduced through removable media may never traverse the firewall. The case requires the control must stop a malicious executable on the host even if the file arrived through removable media rather than the network, which this option does not provide.
  2. An SGACL controls communication between security groups; it does not determine whether a local executable is malicious when it starts. The case requires the control must stop a malicious executable on the host even if the file arrived through removable media rather than the network, which this option does not provide.
  3. Endpoint anti-malware and behavioral prevention can evaluate and block a malicious file where it executes, regardless of whether the file arrived through USB, email, or another path. The decisive requirement is the control must stop a malicious executable on the host even if the file arrived through removable media rather than the network, so this is the direct fit.
  4. MACsec protects Ethernet traffic between participating peers and cannot inspect or stop a file launched locally from removable media. The case requires the control must stop a malicious executable on the host even if the file arrived through removable media rather than the network, which this option does not provide.

 

Question 9

A firewall rule must allow an approved collaboration application while denying other applications that also use TCP port 443. Which NGFW capability is essential? Choose ONE.

  1. MACsec encryption
  2. Static IP-to-SGT mapping
  3. Application identification and application-aware policy
  4. Port-only extended ACL matching TCP port 443

Correct Answer(s)

 

C

Rationale

  1. MACsec encrypts and authenticates Ethernet frames on a link but does not classify applications for firewall policy decisions. The case requires policy must distinguish a collaboration application from unrelated traffic even when both use TCP 443, which this option does not provide.
  2. An IP-to-SGT mapping supplies identity-group context; by itself it does not identify which application is carried inside an allowed HTTPS flow. The case requires policy must distinguish a collaboration application from unrelated traffic even when both use TCP 443, which this option does not provide.
  3. Application identification classifies traffic beyond the transport port, allowing policy to treat two applications using TCP 443 differently as the requirement demands. The decisive requirement is policy must distinguish a collaboration application from unrelated traffic even when both use TCP 443, so this is the direct fit.
  4. A port-only ACL sees both flows as TCP 443 and therefore lacks the application context needed to separate the approved and disallowed applications. The case requires policy must distinguish a collaboration application from unrelated traffic even when both use TCP 443, which this option does not provide.

 

Question 10

The security team must block browsing to a prohibited category of websites without maintaining a list of every site’s current IP address. Which NGFW function best fits? Choose ONE.

  1. URL filtering by category and reputation
  2. EtherChannel hashing for member-link selection only
  3. MACsec
  4. NAT overload

Correct Answer(s)

 

A

Rationale

  1. URL filtering evaluates requested web destinations using maintained category and reputation data, avoiding a brittle manual list of changing server IP addresses. The decisive requirement is the policy requirement is to block users from browsing sites in a prohibited web category without maintaining every destination IP address, so this is the direct fit.
  2. EtherChannel hashing selects a member link for forwarding and has no role in web categorization or reputation-based security decisions. The case requires the policy requirement is to block users from browsing sites in a prohibited web category without maintaining every destination IP address, which this option does not provide.
  3. MACsec protects link-layer traffic from disclosure or tampering but does not categorize web destinations for acceptable-use policy. The case requires the policy requirement is to block users from browsing sites in a prohibited web category without maintaining every destination IP address, which this option does not provide.
  4. NAT overload conserves public addresses by translating many private sessions; it does not classify or block websites by content category. The case requires the policy requirement is to block users from browsing sites in a prohibited web category without maintaining every destination IP address, which this option does not provide.

 

Question 11

A next-generation firewall already permits an application, but security policy also requires it to detect and block known exploit patterns inside the permitted traffic. Which integrated function is needed? Choose ONE.

  1. Source NAT
  2. SGT assignment
  3. MACsec key agreement for link encryption
  4. Intrusion prevention (IPS/NGIPS)

Correct Answer(s)

 

D

Rationale

  1. Source NAT changes addressing for a flow but performs no exploit-signature inspection within the permitted application traffic. The case requires the firewall must inspect permitted traffic for known exploit patterns and actively stop matching flows, which this option does not provide.
  2. SGT assignment classifies an endpoint or session into an identity group; it does not inspect payloads for known exploit patterns. The case requires the firewall must inspect permitted traffic for known exploit patterns and actively stop matching flows, which this option does not provide.
  3. MACsec key agreement establishes link-protection keys between peers and is unrelated to application-layer exploit detection. The case requires the firewall must inspect permitted traffic for known exploit patterns and actively stop matching flows, which this option does not provide.
  4. Integrated intrusion prevention examines allowed traffic for exploit and intrusion indicators and can block matching packets or sessions rather than treating application permission as sufficient. The decisive requirement is the firewall must inspect permitted traffic for known exploit patterns and actively stop matching flows, so this is the direct fit.

 

Question 12

Users are allowed to transfer documents through an approved service, but the firewall must identify malicious files within those permitted sessions. Which capability addresses this requirement? Choose ONE.

  1. MACsec confidentiality
  2. Integrated malware/file inspection
  3. VRF route separation between independent routing domains
  4. QoS classification

Correct Answer(s)

 

B

Rationale

  1. MACsec confidentiality prevents unauthorized observation of protected Ethernet frames but does not inspect files for malicious behavior or reputation. The case requires files transferred through allowed sessions must be evaluated for malicious content rather than blocked solely by extension, which this option does not provide.
  2. Malware or file inspection analyzes transferred objects for malicious content or reputation while allowing policy to remain focused on the actual file risk, not just the transport. The decisive requirement is files transferred through allowed sessions must be evaluated for malicious content rather than blocked solely by extension, so this is the direct fit.
  3. VRF separation creates independent routing tables, which can isolate paths but cannot determine whether an allowed document itself is malicious. The case requires files transferred through allowed sessions must be evaluated for malicious content rather than blocked solely by extension, which this option does not provide.
  4. QoS classification places traffic into forwarding classes for service treatment; it does not decide whether a transferred document contains malware. The case requires files transferred through allowed sessions must be evaluated for malicious content rather than blocked solely by extension, which this option does not provide.

 

Question 13

Legal restrictions prevent broad TLS decryption. The security team still wants a modern firewall to gain policy-relevant visibility into encrypted sessions where possible. Which design expectation is most appropriate? Choose ONE.

  1. Use MACsec to reveal the application payload to the firewall
  2. Use encrypted-flow metadata and security intelligence
  3. Trust all traffic that uses TCP 443
  4. Disable security inspection for all encrypted traffic

Correct Answer(s)

 

B

Rationale

  1. MACsec adds Layer 2 encryption on participating links; it does not decrypt an unrelated end-to-end TLS payload for the firewall. The case requires operations cannot decrypt all TLS traffic but still needs useful policy signals for encrypted flows, which this option does not provide.
  2. A modern firewall can use connection, certificate, application, reputation, and related intelligence even when policy or technology prevents full payload decryption, preserving useful control without making an impossible visibility assumption. The decisive requirement is operations cannot decrypt all TLS traffic but still needs useful policy signals for encrypted flows, so this is the direct fit.
  3. Treating every TCP 443 session as trusted discards application and destination context and creates an unnecessarily broad bypass for encrypted threats. The case requires operations cannot decrypt all TLS traffic but still needs useful policy signals for encrypted flows, which this option does not provide.
  4. Disabling all inspection is more restrictive than the legal requirement; metadata and non-payload signals can still support useful security decisions. The case requires operations cannot decrypt all TLS traffic but still needs useful policy signals for encrypted flows, which this option does not provide.

 

Question 14

A company wants centrally coordinated policy for application control, intrusion prevention, malware protection, and URL filtering across multiple enterprise firewalls. Which architecture best fits? Choose ONE.

  1. Independent port-based ACLs configured on every router
  2. MACsec-only campus design
  3. A standalone DHCP server
  4. Centralized NGFW management with integrated security services

Correct Answer(s)

 

D

Rationale

  1. Independent router ACLs can filter addresses and ports, but they do not centrally orchestrate the application, IPS, malware, and URL security capabilities listed. The case requires administrators need one policy system to coordinate application control, intrusion prevention, malware protection, and URL filtering across managed firewalls, which this option does not provide.
  2. A MACsec-only design protects links but does not provide centralized application-layer threat policy or the integrated firewall services required. The case requires administrators need one policy system to coordinate application control, intrusion prevention, malware protection, and URL filtering across managed firewalls, which this option does not provide.
  3. A DHCP server assigns network configuration to clients and has no role in managing NGFW security services. The case requires administrators need one policy system to coordinate application control, intrusion prevention, malware protection, and URL filtering across managed firewalls, which this option does not provide.
  4. Centralized NGFW management provides a common policy and operational plane for the integrated security functions named in the requirement, reducing inconsistent per-device rule management. The decisive requirement is administrators need one policy system to coordinate application control, intrusion prevention, malware protection, and URL filtering across managed firewalls, so this is the direct fit.

 

Question 15

A user moves between campus subnets and receives different IP addresses, but access policy should remain tied to the user’s assigned security role. Which TrustSec concept best supports the design? Choose ONE.

  1. Classify the session with a Security Group Tag (SGT)
  2. Use MACsec as the authorization policy
  3. Use NAT to keep a constant public address
  4. Write separate IP ACLs for every possible user address

Correct Answer(s)

 

A

Rationale

  1. An SGT represents security-group identity independently of a particular IP subnet, allowing downstream policy to use the role classification as the user moves. The decisive requirement is access decisions should follow a user’s security role even when the user’s IP address changes between campus locations, so this is the direct fit.
  2. MACsec protects link confidentiality and integrity; it does not express the user’s authorization role for group-based access decisions. The case requires access decisions should follow a user’s security role even when the user’s IP address changes between campus locations, which this option does not provide.
  3. NAT can translate addresses but does not preserve user identity as a policy label across campus access locations. The case requires access decisions should follow a user’s security role even when the user’s IP address changes between campus locations, which this option does not provide.
  4. Per-IP ACLs bind policy to changing addresses and create the operational coupling the design is trying to avoid. The case requires access decisions should follow a user’s security role even when the user’s IP address changes between campus locations, which this option does not provide.

 

Question 16

A security policy must control communications from contractor endpoints to production servers using group identity instead of maintaining large IP address lists. Which TrustSec mechanism expresses the permission? Choose ONE.

  1. DHCP relay
  2. MACsec cipher suite for Ethernet link cryptography
  3. Security Group ACL (SGACL) policy
  4. PBR route map

Correct Answer(s)

 

C

Rationale

  1. DHCP relay forwards address-assignment messages between subnets and has no role in source-to-destination security-group authorization. The case requires the enterprise wants policy between two identity groups to be expressed by source and destination security groups rather than long address lists, which this option does not provide.
  2. A MACsec cipher suite chooses cryptographic protection for an Ethernet link and does not define which security groups may communicate. The case requires the enterprise wants policy between two identity groups to be expressed by source and destination security groups rather than long address lists, which this option does not provide.
  3. An SGACL defines role-based permissions between source and destination security groups, directly matching the desired identity-group policy model without enumerating endpoint addresses. The decisive requirement is the enterprise wants policy between two identity groups to be expressed by source and destination security groups rather than long address lists, so this is the direct fit.
  4. A PBR route map can alter forwarding based on policy matches, but it is not the TrustSec authorization matrix between SGTs. The case requires the enterprise wants policy between two identity groups to be expressed by source and destination security groups rather than long address lists, which this option does not provide.

 

Question 17

Two TrustSec-aware sites are separated by a network segment that cannot propagate inline SGT tags. The sites still need to exchange IP-to-SGT binding information for policy. Which mechanism is designed for this purpose? Choose ONE.

  1. MACsec MKA
  2. OSPF graceful restart for routing adjacency continuity
  3. SPAN
  4. Security Group Tag Exchange Protocol (SXP)

Correct Answer(s)

 

D

Rationale

  1. MKA negotiates and maintains MACsec keying for link protection; it does not exchange IP-to-SGT binding databases between TrustSec domains. The case requires two TrustSec domains need to share IP-to-SGT bindings across an intermediate network that does not carry inline SGT tags, which this option does not provide.
  2. OSPF graceful restart helps routing adjacency continuity during a control-plane restart and carries no security-group bindings. The case requires two TrustSec domains need to share IP-to-SGT bindings across an intermediate network that does not carry inline SGT tags, which this option does not provide.
  3. SPAN copies traffic to a monitoring destination and does not distribute identity mappings for policy enforcement. The case requires two TrustSec domains need to share IP-to-SGT bindings across an intermediate network that does not carry inline SGT tags, which this option does not provide.
  4. SXP propagates IP-to-SGT bindings between peers when inline tagging is unavailable across part of the path, preserving identity context for TrustSec policy. The decisive requirement is two TrustSec domains need to share IP-to-SGT bindings across an intermediate network that does not carry inline SGT tags, so this is the direct fit.

 

Question 18

A campus path supports TrustSec natively end to end. The design should carry the source security-group identity with the traffic instead of reconstructing it from IP mappings downstream. Which approach is preferred? Choose ONE.

  1. MACsec alone
  2. TrustSec inline SGT tagging
  3. Static default route
  4. SXP as the primary data-plane tag

Correct Answer(s)

 

B

Rationale

  1. MACsec secures Ethernet frames but does not by itself classify traffic into a TrustSec security group for authorization policy. The case requires the access-to-distribution path supports TrustSec metadata natively and should preserve the source security-group identity with the frames, which this option does not provide.
  2. Inline tagging carries the source SGT as metadata with supported traffic, letting downstream TrustSec devices consume the identity directly when the path supports it. The decisive requirement is the access-to-distribution path supports TrustSec metadata natively and should preserve the source security-group identity with the frames, so this is the direct fit.
  3. A static route selects a forwarding next hop and carries no user or device security-group metadata. The case requires the access-to-distribution path supports TrustSec metadata natively and should preserve the source security-group identity with the frames, which this option does not provide.
  4. SXP exchanges IP-to-SGT bindings through a control-plane mechanism; it is useful when inline propagation is unavailable, not the preferred substitute on a fully capable path. The case requires the access-to-distribution path supports TrustSec metadata natively and should preserve the source security-group identity with the frames, which this option does not provide.

 

Question 19

Two enterprise switches are connected across an exposed Ethernet handoff. The team must protect frame confidentiality and integrity on that link without modifying applications. Which technology is the best fit? Choose ONE.

  1. NAT overload
  2. SGACL only
  3. MACsec (IEEE 802.1AE)
  4. URL filtering for web destination security policy

Correct Answer(s)

 

C

Rationale

  1. NAT overload translates many private sessions to fewer public addresses and does not protect frame contents from observation or tampering. The case requires an exposed Ethernet link between two supported switches requires confidentiality and integrity at Layer 2 without changing applications, which this option does not provide.
  2. An SGACL controls group-based authorization but does not encrypt the frames crossing the exposed handoff. The case requires an exposed Ethernet link between two supported switches requires confidentiality and integrity at Layer 2 without changing applications, which this option does not provide.
  3. MACsec provides link-layer encryption and integrity protection for Ethernet traffic between participating devices, meeting the requirement without depending on application changes. The decisive requirement is an exposed Ethernet link between two supported switches requires confidentiality and integrity at Layer 2 without changing applications, so this is the direct fit.
  4. URL filtering controls access to web destinations and offers no general Layer 2 confidentiality or integrity for the Ethernet link. The case requires an exposed Ethernet link between two supported switches requires confidentiality and integrity at Layer 2 without changing applications, which this option does not provide.

 

Question 20

A design uses MACsec between supported peers. Which companion function establishes and maintains the keying relationships used by the MACsec secure channel? Choose ONE.

  1. MACsec Key Agreement (MKA)
  2. SXP
  3. SGACL
  4. URL reputation filtering for risky web destinations

Correct Answer(s)

 

A

Rationale

  1. MKA handles MACsec participant authentication and key agreement, maintaining the cryptographic material needed for MACsec secure associations on the protected link. The decisive requirement is MACsec peers need a protocol to authenticate participation and establish the keys used for secure associations, so this is the direct fit.
  2. SXP distributes IP-to-SGT bindings for TrustSec identity propagation and does not negotiate MACsec encryption keys. The case requires MACsec peers need a protocol to authenticate participation and establish the keys used for secure associations, which this option does not provide.
  3. An SGACL defines permissions between security groups; it does not establish cryptographic secure associations. The case requires MACsec peers need a protocol to authenticate participation and establish the keys used for secure associations, which this option does not provide.
  4. URL reputation filtering evaluates web destinations and is unrelated to link-layer key establishment. The case requires MACsec peers need a protocol to authenticate participation and establish the keys used for secure associations, which this option does not provide.

Leave a Reply

How It Works

img
Step 1. Choose Exam
on ExamLabs
Download IT Exams Questions & Answers
img
Step 2. Open Exam with
Avanset Exam Simulator
Press here to download VCE Exam Simulator that simulates real exam environment
img
Step 3. Study
& Pass
IT Exams Anywhere, Anytime!