Topic 16 Practice Test 2 covers Security Concepts, Programs, and Device Passwords for Cisco Certified Network Associate 200-301 CCNA and maps to objectives 5.1–5.4. For broader exam preparation, review the Cisco CCNA 200-301 Exam Dumps. Every option includes focused technical reasoning explaining both the networking concept and its fit to the scenario.
Question 1
A threat-model workshop records a malicious actor and phishing campaign as possible sources of harm, even though no weakness has been successfully used yet. Which option should the engineer use or identify? Choose ONE.
- Mitigation
- Threat
- Vulnerability
- Attack surface reduction
Correct Answer: B
Correct Answer
Answer B is correct because Threat provides the potential source of harm that could act against an exposed system. In a Threat use case, it is appropriate when Use the term when describing a possible source of adverse action rather than the weakness itself. The observed behavior aligns with that role.
Incorrect Answers
Answer A is incorrect because Mitigation concerns this behavior: A mitigation is a control or action. The operations evidence favors Threat; Mitigation operates at another control point. The Threat result depends on another mechanism, not the Mitigation behavior described above.
Answer C is incorrect because Vulnerability concerns this behavior: A vulnerability is a weakness in technology. For Threat, the operations evidence requires another function than Vulnerability. Using Vulnerability here would leave the Threat requirement unresolved during this operations task.
Answer D is incorrect because Attack surface reduction concerns this behavior: The attack surface is the collection of. Using Attack surface reduction would not produce the Threat behavior shown by this operations evidence. The Attack surface reduction function therefore differs materially from the Threat outcome required here.
Question 2
A security scan finds an unpatched service with a flaw that could be abused, but there is no evidence of an attack attempt. Which option should the engineer use or identify? Choose ONE.
- Attack surface reduction
- Exploit
- Vulnerability
- Threat
Correct Answer: C
Correct Answer
Answer C is correct because Vulnerability provides the underlying weakness that makes compromise possible. In a Vulnerability use case, it is appropriate when Use the term for the exploitable weakness, not the attacker or the attack technique. The observed behavior aligns with that role.
Incorrect Answers
Answer A is incorrect because The attack surface is the collection of reachable services, interfaces, accounts, and other opportunities an attacker could target Using Attack surface reduction would not produce the Vulnerability behavior shown by this operations evidence.
Answer B is incorrect because Exploit concerns this behavior: An exploit is a technique or code. Using Exploit would not produce the Vulnerability behavior shown by this operations evidence. The Exploit function therefore differs materially from the Vulnerability outcome required here.
Answer D is incorrect because Threat concerns this behavior: A threat is a circumstance, actor, or. The required Vulnerability outcome differs from the Threat purpose in this operations case. For Vulnerability, choosing Threat would change the control point in this operations case.
Question 3
Incident responders identify the crafted input and technique that actually triggers a known software weakness to obtain unauthorized behavior. Which option should the engineer use or identify? Choose ONE.
- Threat
- Mitigation
- Vulnerability
- Exploit
Correct Answer: D
Correct Answer
Answer D is correct because Exploit provides the method used to take advantage of a known weakness. In a Exploit use case, it is appropriate when the scenario describes the mechanism used to leverage a weakness. The observed behavior aligns with that role.
Incorrect Answers
Answer A is incorrect because A threat is a circumstance, actor, or event with the potential to cause harm by taking advantage of a weakness The required Exploit outcome differs from the Threat purpose in this operations case.
Answer B is incorrect because A mitigation is a control or action that reduces the likelihood or impact of a security risk Mitigation misses the Exploit decision in this operations scenario. For Mitigation, separation from Exploit remains material in this operations scenario.
Answer C is incorrect because A vulnerability is a weakness in technology, configuration, process, or design that could be exploited In the operations case, Exploit differs from Vulnerability behavior. Operationally, Exploit needs another behavior than Vulnerability provides in this operations case.
Question 4
A vulnerable service cannot be replaced this week, so the team adds filtering, hardening, and segmentation to reduce the chance and impact of compromise. Which option should the engineer use or identify? Choose ONE.
- Mitigation
- Vulnerability
- Attack surface reduction
- Exploit
Correct Answer: A
Correct Answer
Answer A is correct because Mitigation provides the defensive action that reduces the risk associated with an identified weakness. In a Mitigation use case, it is appropriate when Use it for patches, filtering, segmentation, hardening, or other measures that reduce exposure. The observed behavior aligns with that role.
Incorrect Answers
Answer B is incorrect because Vulnerability is used when Use the term for the exploitable weakness, not the attacker or the attack technique. In the operations case, Mitigation differs from Vulnerability behavior. Operationally, Mitigation needs another behavior than Vulnerability provides in this operations case.
Answer C is incorrect because Attack surface reduction is used when Reduce it by disabling unnecessary services and limiting exposed management interfaces. The operations evidence favors Mitigation; Attack surface reduction operates at another control point. The Mitigation result depends on another mechanism, not the Attack surface reduction behavior described above.
Answer D is incorrect because An exploit is a technique or code path that takes advantage of a vulnerability to produce unintended behavior The operations evidence favors Mitigation; Exploit operates at another control point. The Mitigation result depends on another mechanism, not the Exploit behavior described above.
Question 5
A router exposes several unused management services. The hardening plan calls for disabling unnecessary listeners so attackers have fewer reachable entry points. Which option should the engineer use or identify? Choose ONE.
- Exploit
- Attack surface reduction
- Threat
- Mitigation
Correct Answer: B
Correct Answer
Answer B is correct because Attack surface reduction provides fewer reachable services and entry points for an attacker. In a Attack surface reduction use case, it is appropriate when Reduce it by disabling unnecessary services and limiting exposed management interfaces. The observed behavior aligns with that role.
Incorrect Answers
Answer A is incorrect because Exploit is used when the scenario describes the mechanism used to leverage a weakness. The operations evidence favors Attack surface reduction; Exploit operates at another control point. The Attack surface reduction result depends on another mechanism, not the Exploit behavior described above.
Answer C is incorrect because Threat is used when Use the term when describing a possible source of adverse action rather than the weakness itself. For Attack surface reduction, the operations evidence requires another function than Threat.
Answer D is incorrect because Mitigation is used when Use it for patches, filtering, segmentation, hardening, or other measures that reduce exposure. Using Mitigation would not produce the Attack surface reduction behavior shown by this operations evidence.
Question 6
All employees, regardless of job role, need recurring instruction on phishing recognition, reporting suspicious messages, and basic safe behavior. Which option should the engineer use or identify? Choose ONE.
- Anti-tailgating physical control
- Badge-controlled physical access
- Security awareness program
- Role-based security training
Correct Answer: C
Correct Answer
Answer C is correct because Security awareness program provides broad employee recognition of everyday security risks and expected behavior. In a Security awareness program use case, it is appropriate when Use awareness campaigns for organization-wide habits such as identifying phishing and reporting suspicious activity. The observed behavior aligns with that role.
Incorrect Answers
Answer A is incorrect because Anti-tailgating physical control is used when Use them where a badge alone is insufficient to prevent piggybacking. In the operations case, Security awareness program differs from Anti-tailgating physical control behavior. Operationally, Security awareness program needs another behavior than Anti-tailgating physical control provides in this operations case.
Answer B is incorrect because Badge-controlled physical access is used when restrict network closets, data centers, and other controlled spaces. Badge-controlled physical access misses the Security awareness program decision in this operations scenario. For Badge-controlled physical access, separation from Security awareness program remains material in this operations scenario.
Answer D is incorrect because Role-based security training is used when Use targeted training when administrators or developers need hands-on competence for their responsibilities. For Security awareness program, the operations evidence requires another function than Role-based security training.
Question 7
Network administrators need hands-on instruction for secure device configuration that goes beyond the general security material provided to all employees. Which option should the engineer use or identify? Choose ONE.
- Security awareness program
- Anti-tailgating physical control
- Badge-controlled physical access
- Role-based security training
Correct Answer: D
Correct Answer
Answer D is correct because Role-based security training provides specialized security skills for employees with technical duties. In a Role-based security training use case, it is appropriate when Use targeted training when administrators or developers need hands-on competence for their responsibilities. The observed behavior aligns with that role.
Incorrect Answers
Answer A is incorrect because Security awareness program is used when Use awareness campaigns for organization-wide habits such as identifying phishing and reporting suspicious activity. Security awareness program misses the Role-based security training decision in this operations scenario.
Answer B is incorrect because The purpose of Anti-tailgating physical control is a control that prevents one authorized entry from admitting an unverified follower. The operations evidence favors Role-based security training; Anti-tailgating physical control operates at another control point.
Answer C is incorrect because The purpose of Badge-controlled physical access is identity-based control over entry to a restricted physical area. The required Role-based security training outcome differs from the Badge-controlled physical access purpose in this operations case.
Question 8
A data-center door should admit only personnel whose individual identity has been authorized for that restricted area. Which option should the engineer use or identify? Choose ONE.
- Badge-controlled physical access
- Role-based security training
- Security awareness program
- Anti-tailgating physical control
Correct Answer: A
Correct Answer
Answer A is correct because Badge-controlled physical access provides identity-based control over entry to a restricted physical area. In a Badge-controlled physical access use case, it is appropriate when restrict network closets, data centers, and other controlled spaces. The observed behavior aligns with that role.
Incorrect Answers
Answer B is incorrect because The purpose of Role-based security training is specialized security skills for employees with technical duties. The operations evidence favors Badge-controlled physical access; Role-based security training operates at another control point. The Badge-controlled physical access result depends on another mechanism, not the Role-based security training behavior described above.
Answer C is incorrect because The purpose of Security awareness program is broad employee recognition of everyday security risks and expected behavior. The required Badge-controlled physical access outcome differs from the Security awareness program purpose in this operations case.
Answer D is incorrect because Anti-tailgating physical control concerns this behavior: Anti-tailgating controls such as mantraps or staffed. In the operations case, Badge-controlled physical access differs from Anti-tailgating physical control behavior. Operationally, Badge-controlled physical access needs another behavior than Anti-tailgating physical control provides in this operations case.
Question 9
An authorized employee badges into a secure room and an unknown person tries to follow through the same open door without presenting credentials. Which option should the engineer use or identify? Choose ONE.
- Badge-controlled physical access
- Anti-tailgating physical control
- Role-based security training
- Security awareness program
Correct Answer: B
Correct Answer
Answer B is correct because Anti-tailgating physical control provides a control that prevents one authorized entry from admitting an unverified follower. In a Anti-tailgating physical control use case, it is appropriate when Use them where a badge alone is insufficient to prevent piggybacking. The observed behavior aligns with that role.
Incorrect Answers
Answer A is incorrect because Badge-controlled physical access concerns this behavior: Electronic badge access limits entry to authorized. Using Badge-controlled physical access would not produce the Anti-tailgating physical control behavior shown by this operations evidence. The Badge-controlled physical access function therefore differs materially from the Anti-tailgating physical control outcome required here.
Answer C is incorrect because Role-based security training concerns this behavior: Security training develops specific skills required for. In the operations case, Anti-tailgating physical control differs from Role-based security training behavior. Operationally, Anti-tailgating physical control needs another behavior than Role-based security training provides in this operations case.
Answer D is incorrect because Security awareness program concerns this behavior: Security awareness builds broad recognition of common. Security awareness program misses the Anti-tailgating physical control decision in this operations scenario. For Security awareness program, separation from Anti-tailgating physical control remains material in this operations scenario.
Question 10
Privileged EXEC mode on a router needs a protected local credential rather than relying on a plainly stored enable password. Which option should the engineer use or identify? Choose ONE.
- service password-encryption limitation
- Account lockout or rate limiting after failed attempts
- enable secret
- Biometric authentication factor
Correct Answer: C
Correct Answer
Answer C is correct because enable secret provides a protected local credential for privileged EXEC access. In a enable secret use case, it is appropriate when require a protected credential before entering privileged EXEC mode. The observed behavior aligns with that role.
Incorrect Answers
Answer A is incorrect because service password-encryption limitation concerns this behavior: service password-encryption obscures certain clear-text passwords in. In the operations case, enable secret differs from service password-encryption limitation behavior. Operationally, enable secret needs another behavior than service password-encryption limitation provides in this operations case.
Answer B is incorrect because Account lockout or concerns this behavior: Lockout or rate limiting limits repeated authentication. Account lockout or misses the enable secret decision in this operations scenario. For Account lockout or, separation from enable secret remains material in this operations scenario.
Answer D is incorrect because Biometric authentication factor concerns this behavior: A biometric factor uses an inherence characteristic. For enable secret, the operations evidence requires another function than Biometric authentication factor. Using Biometric authentication factor here would leave the enable secret requirement unresolved during this operations task.
Question 11
SSH will use local authentication, so the device needs a named administrator account whose credential is stored using the protected secret form. Which option should the engineer use or identify? Choose ONE.
- Long password or passphrase policy
- Multi-factor authentication
- Physical locks and secured racks
- username … secret local account
Correct Answer: D
Correct Answer
Answer D is correct because username … secret local account provides a named local administrator credential stored with a protected secret. In a username … secret use case, it is appropriate when the device should authenticate a named administrator from its local database. The observed behavior aligns with that role.
Incorrect Answers
Answer A is incorrect because Long password or concerns this behavior: Longer passwords or passphrases increase the search. Long password or misses the username … secret decision in this operations scenario. For Long password or, separation from username … secret remains material in this operations scenario.
Answer B is incorrect because Multi-factor authentication concerns this behavior: MFA requires evidence from at least two. For username … secret, the operations evidence requires another function than Multi-factor authentication. Using Multi-factor authentication here would leave the username … secret requirement unresolved during this operations task.
Answer C is incorrect because Physical locks and concerns this behavior: Physical locks on rooms, racks, and consoles. The operations evidence favors username … secret; Physical locks and operates at another control point. The username … secret result depends on another mechanism, not the Physical locks and behavior described above.
Question 12
Local usernames already exist, but the console or VTY line must be told to authenticate sessions against that local account database. Which option should the engineer use or identify? Choose ONE.
- login local
- Password reuse restriction
- Digital certificate for identity validation
- enable secret
Correct Answer: A
Correct Answer
Answer A is correct because login local provides line authentication using the local username database. In a login local use case, it is appropriate when console or VTY lines when named locally configured user accounts should be required. The observed behavior aligns with that role.
Incorrect Answers
Answer B is incorrect because Password reuse restriction concerns this behavior: A password history or reuse rule reduces. For login local, the operations evidence requires another function than Password reuse restriction. Using Password reuse restriction here would leave the login local requirement unresolved during this operations task.
Answer C is incorrect because Digital certificate for concerns this behavior: A digital certificate binds identity information to. The operations evidence favors login local; Digital certificate for operates at another control point. The login local result depends on another mechanism, not the Digital certificate for behavior described above.
Answer D is incorrect because enable secret concerns this behavior: The enable secret command protects access to. The required login local outcome differs from the enable secret purpose in this operations case. For login local, choosing enable secret would change the control point in this operations case.
Question 13
An engineer wants to hide eligible clear-text passwords from casual viewing in the configuration but understands that the feature is reversible obfuscation, not strong password hashing. Which option should the engineer use or identify? Choose ONE.
- Account lockout or rate limiting after failed attempts
- service password-encryption limitation
- Biometric authentication factor
- username … secret local account
Correct Answer: B
Correct Answer
Answer B is correct because service password-encryption limitation provides basic reversible obfuscation of eligible clear-text configuration passwords. In a service password-encryption limitation use case, it is appropriate when avoid obvious plain-text display, not as a substitute for stronger secrets or secure transport. The observed behavior aligns with that role.
Incorrect Answers
Answer A is incorrect because Lockout or rate limiting limits repeated authentication attempts and makes online password guessing more difficult The required service password-encryption limitation outcome differs from the Account lockout or purpose in this operations case.
Answer C is incorrect because A biometric factor uses an inherence characteristic such as a fingerprint or facial pattern to help verify identity Using Biometric authentication factor would not produce the service password-encryption limitation behavior shown by this operations evidence.
Answer D is incorrect because username … secret concerns this behavior: A local username configured with a secret. Using username … secret would not produce the service password-encryption limitation behavior shown by this operations evidence. The username … secret function therefore differs materially from the service password-encryption limitation outcome required here.
Question 14
A password standard is being revised to make brute-force guessing harder by increasing the minimum number of characters users must provide. Which option should the engineer use or identify? Choose ONE.
- Multi-factor authentication
- Physical locks and secured racks
- Long password or passphrase policy
- login local
Correct Answer: C
Correct Answer
Answer C is correct because Long password or passphrase policy provides a policy control that raises password strength by requiring sufficient length. In a Long password or use case, it is appropriate when Use minimum length requirements to improve resistance to guessing and brute-force attacks. The observed behavior aligns with that role.
Incorrect Answers
Answer A is incorrect because MFA requires evidence from at least two different factor categories such as knowledge, possession, and inherence Using Multi-factor authentication would not produce the Long password or behavior shown by this operations evidence.
Answer B is incorrect because Physical locks on rooms, racks, and consoles reduce unauthorized hands-on access to network equipment In the operations case, Long password or differs from Physical locks and behavior. Operationally, Long password or needs another behavior than Physical locks and provides in this operations case.
Answer D is incorrect because login local concerns this behavior: The login local command instructs a line. In the operations case, Long password or differs from login local behavior. Operationally, Long password or needs another behavior than login local provides in this operations case.
Question 15
Users keep rotating between the same two old passwords. The policy must prevent recently used credentials from being selected again. Which option should the engineer use or identify? Choose ONE.
- Digital certificate for identity validation
- enable secret
- service password-encryption limitation
- Password reuse restriction
Correct Answer: D
Correct Answer
Answer D is correct because Password reuse restriction provides a policy that prevents repeated recycling of old credentials. In a Password reuse restriction use case, it is appropriate when policy should prevent immediate reuse of recent passwords. The observed behavior aligns with that role.
Incorrect Answers
Answer A is incorrect because A digital certificate binds identity information to a public key and can support authenticated trust relationships In the operations case, Password reuse restriction differs from Digital certificate for behavior. Operationally, Password reuse restriction needs another behavior than Digital certificate for provides in this operations case.
Answer B is incorrect because The enable secret command protects access to privileged EXEC mode with a one-way protected secret and is preferred over the older enable password enable secret misses the Password reuse restriction decision in this operations scenario.
Answer C is incorrect because service password-encryption obscures certain clear-text passwords in the configuration but is only a minimal protection and is not strong cryptographic storage For Password reuse restriction, the operations evidence requires another function than service password-encryption limitation.
Question 16
An internet-facing login is receiving rapid repeated password guesses. The control should slow or stop further attempts after too many failures. Which option should the engineer use or identify? Choose ONE.
- Account lockout or rate limiting after failed attempts
- Biometric authentication factor
- username … secret local account
- Long password or passphrase policy
Correct Answer: A
Correct Answer
Answer A is correct because Account lockout or rate limiting after failed attempts provides a control that constrains repeated failed sign-in attempts. In a Account lockout or use case, it is appropriate when Use it with care to slow brute-force attempts while considering denial-of-service risk. The observed behavior aligns with that role.
Incorrect Answers
Answer B is incorrect because Biometric authentication factor is used when Use it as something the user is, typically combined with another factor in stronger authentication. For Account lockout or, the operations evidence requires another function than Biometric authentication factor.
Answer C is incorrect because A local username configured with a secret provides a device-resident credential that can be used by login local For Account lockout or, the operations evidence requires another function than username … secret.
Answer D is incorrect because Longer passwords or passphrases increase the search space and are a core element of a strong authentication policy The operations evidence favors Account lockout or; Long password or operates at another control point.
Question 17
Remote administration should require two independent categories of evidence, so theft of a password alone is insufficient. Which option should the engineer use or identify? Choose ONE.
- Physical locks and secured racks
- Multi-factor authentication
- login local
- Password reuse restriction
Correct Answer: B
Correct Answer
Answer B is correct because Multi-factor authentication provides authentication that combines independent factor categories. In a Multi-factor authentication use case, it is appropriate when Use it so a stolen password alone is insufficient to complete authentication. The observed behavior aligns with that role.
Incorrect Answers
Answer A is incorrect because Physical locks and is used when Use them to protect infrastructure that could otherwise be reset, cabled into, or directly manipulated. The operations evidence favors Multi-factor authentication; Physical locks and operates at another control point.
Answer C is incorrect because The login local command instructs a line to authenticate users with the device local username database The operations evidence favors Multi-factor authentication; login local operates at another control point. The Multi-factor authentication result depends on another mechanism, not the login local behavior described above.
Answer D is incorrect because A password history or reuse rule reduces the chance that users repeatedly cycle back to previously compromised credentials The required Multi-factor authentication outcome differs from the Password reuse restriction purpose in this operations case.
Question 18
A device must present public-key identity evidence that can be validated through a trusted issuing chain rather than a shared secret. Which option should the engineer use or identify? Choose ONE.
- enable secret
- service password-encryption limitation
- Digital certificate for identity validation
- Account lockout or rate limiting after failed attempts
Correct Answer: C
Correct Answer
Answer C is correct because Digital certificate for identity validation provides public-key identity evidence validated through certificate trust. In a Digital certificate for use case, it is appropriate when Use certificates where systems or users need cryptographic proof tied to a trusted issuing authority. The observed behavior aligns with that role.
Incorrect Answers
Answer A is incorrect because enable secret is used when require a protected credential before entering privileged EXEC mode. The required Digital certificate for outcome differs from the enable secret purpose in this operations case. For Digital certificate for, choosing enable secret would change the control point in this operations case.
Answer B is incorrect because service password-encryption limitation is used when avoid obvious plain-text display, not as a substitute for stronger secrets or secure transport. Using service password-encryption limitation would not produce the Digital certificate for behavior shown by this operations evidence.
Answer D is incorrect because Account lockout or is used when Use it with care to slow brute-force attempts while considering denial-of-service risk. In the operations case, Digital certificate for differs from Account lockout or behavior.
Question 19
A facility wants authentication based on a user characteristic such as a fingerprint rather than something the user knows or carries. Which option should the engineer use or identify? Choose ONE.
- username … secret local account
- Long password or passphrase policy
- Multi-factor authentication
- Biometric authentication factor
Correct Answer: D
Correct Answer
Answer D is correct because Biometric authentication factor provides an inherence factor based on a physical characteristic. In a Biometric authentication factor use case, it is appropriate when Use it as something the user is, typically combined with another factor in stronger authentication. The observed behavior aligns with that role.
Incorrect Answers
Answer A is incorrect because username … secret is used when the device should authenticate a named administrator from its local database. Using username … secret would not produce the Biometric authentication factor behavior shown by this operations evidence.
Answer B is incorrect because Long password or is used when Use minimum length requirements to improve resistance to guessing and brute-force attacks. In the operations case, Biometric authentication factor differs from Long password or behavior.
Answer C is incorrect because Multi-factor authentication is used when Use it so a stolen password alone is insufficient to complete authentication. Multi-factor authentication misses the Biometric authentication factor decision in this operations scenario. For Multi-factor authentication, separation from Biometric authentication factor remains material in this operations scenario.
Question 20
A switch is correctly configured but is installed where unauthorized people could unplug, reset, or replace it. The security team must protect the hardware itself. Which option should the engineer use or identify? Choose ONE.
- Physical locks and secured racks
- login local
- Password reuse restriction
- Digital certificate for identity validation
Correct Answer: A
Correct Answer
Answer A is correct because Physical locks and secured racks provides direct physical protection of network hardware from unauthorized handling. In a Physical locks and use case, it is appropriate when Use them to protect infrastructure that could otherwise be reset, cabled into, or directly manipulated. The observed behavior aligns with that role.
Incorrect Answers
Answer B is incorrect because login local is used when console or VTY lines when named locally configured user accounts should be required. In the operations case, Physical locks and differs from login local behavior. Operationally, Physical locks and needs another behavior than login local provides in this operations case.
Answer C is incorrect because Password reuse restriction is used when policy should prevent immediate reuse of recent passwords. Password reuse restriction misses the Physical locks and decision in this operations scenario. For Password reuse restriction, separation from Physical locks and remains material in this operations scenario.
Answer D is incorrect because Digital certificate for is used when Use certificates where systems or users need cryptographic proof tied to a trusted issuing authority. For Physical locks and, the operations evidence requires another function than Digital certificate for.