Cisco CCNP 350-401 ENCOR Threat Defense, Endpoint Security, NGFW, TrustSec, and MACsec Practice Test 2

 

Topic 18 Practice Test 2 covers Threat Defense, Endpoint Security, NGFW, TrustSec, and MACsec for Cisco 350-401 ENCOR. For broader exam preparation, review the Cisco 350-401 ENCOR Exam Dumps. Every option includes focused technical reasoning explaining both the Cisco enterprise networking concept and its fit to the scenario.

Question 1

A user’s IP connectivity is normal, but TrustSec policy treats the user as the wrong role because the session received an incorrect security-group identity at access. What should the engineer correct first? Choose ONE.

  1. Change the user’s subnet and addressing to mirror the desired security role
  2. Correct the ingress classification so the session receives the proper SGT
  3. Increase the MACsec replay window
  4. Change the destination server’s DNS record

Correct Answer(s)

 

B

Rationale

  1. Moving the user to a different subnet changes addressing but does not correct the mistaken identity classification that is driving role-based policy. The case requires the user’s authorization is wrong because the access edge assigned an incorrect security-group identity even though the user’s IP connectivity is normal, which this option does not provide.
  2. TrustSec authorization depends on the security-group identity assigned to the session, so correcting ingress classification fixes the policy input without tying role to topology. The decisive requirement is the user’s authorization is wrong because the access edge assigned an incorrect security-group identity even though the user’s IP connectivity is normal, so this is the direct fit.
  3. A MACsec replay window affects acceptance of protected frames and has no effect on which SGT the access session is assigned. The case requires the user’s authorization is wrong because the access edge assigned an incorrect security-group identity even though the user’s IP connectivity is normal, which this option does not provide.
  4. Changing DNS modifies name resolution and does not repair the security-group classification attached to the user’s session. The case requires the user’s authorization is wrong because the access edge assigned an incorrect security-group identity even though the user’s IP connectivity is normal, which this option does not provide.

 

Question 2

A TrustSec enforcement point receives traffic carrying a source SGT and must decide whether the source group may reach the destination server group. What additional identity information is required for the SGACL decision? Choose ONE.

  1. The sender’s MACsec key-server priority
  2. The destination’s DNS TTL
  3. A second source SGT inserted by the sender
  4. The destination security group associated with the target

Correct Answer(s)

 

D

Rationale

  1. MACsec key-server priority influences key management on a protected link and is not an input to the SGACL permission matrix. The case requires a packet arrives with a source SGT, but enforcement must decide whether that source group may reach a destination server group, which this option does not provide.
  2. DNS TTL controls caching behavior for name resolution and does not identify the destination’s TrustSec security group. The case requires a packet arrives with a source SGT, but enforcement must decide whether that source group may reach a destination server group, which this option does not provide.
  3. TrustSec does not require the sender to attach a second source tag to represent the destination; destination identity is derived at the enforcement point. The case requires a packet arrives with a source SGT, but enforcement must decide whether that source group may reach a destination server group, which this option does not provide.
  4. SGACL authorization evaluates a source security group against a destination security group, so the enforcement point must know the target’s destination-group identity in addition to the source SGT. The decisive requirement is a packet arrives with a source SGT, but enforcement must decide whether that source group may reach a destination server group, so this is the direct fit.

 

Question 3

A switch shows a local SGACL permission that conflicts with a policy downloaded from Cisco ISE. Which policy should the engineer expect to take precedence on a supported TrustSec deployment? Choose ONE.

  1. The dynamically downloaded ISE/AAA policy
  2. The newest DHCP binding decides the action
  3. The local policy always wins
  4. The MACsec policy decides the SGACL action

Correct Answer(s)

 

A

Rationale

  1. Cisco TrustSec policy downloaded dynamically from ISE or the authentication system can override a conflicting locally defined SGACL policy, so the centralized policy should be treated as authoritative. The decisive requirement is a switch has a locally configured TrustSec permission that conflicts with policy downloaded dynamically from ISE, so this is the direct fit.
  2. A DHCP binding may help identify an endpoint address, but its recency does not determine which SGACL policy source has precedence. The case requires a switch has a locally configured TrustSec permission that conflicts with policy downloaded dynamically from ISE, which this option does not provide.
  3. Assuming the local entry always wins ignores the TrustSec precedence behavior and can lead an engineer to troubleshoot the wrong policy source. The case requires a switch has a locally configured TrustSec permission that conflicts with policy downloaded dynamically from ISE, which this option does not provide.
  4. A MACsec policy defines link-security behavior such as keying or cipher parameters; it does not resolve an SGACL authorization conflict. The case requires a switch has a locally configured TrustSec permission that conflicts with policy downloaded dynamically from ISE, which this option does not provide.

 

Question 4

An application flow is unexpectedly denied after a TrustSec policy change. Which evidence is most directly useful for checking the source-to-destination security-group permission and its enforcement result? Choose ONE.

  1. Only the MAC address table for Layer 2 location
  2. Only the NTP association table
  3. SGACL permissions and role-based enforcement counters
  4. Only a DNS cache

Correct Answer(s)

 

C

Rationale

  1. The MAC address table confirms Layer 2 location but does not show the source-SGT to destination-group permission that allowed or denied the flow. The case requires an expected TrustSec flow is denied and the engineer needs evidence of which source-to-destination group permission is being enforced, which this option does not provide.
  2. NTP associations verify time synchronization and contain no TrustSec authorization decision or SGACL match information. The case requires an expected TrustSec flow is denied and the engineer needs evidence of which source-to-destination group permission is being enforced, which this option does not provide.
  3. SGACL permission output and role-based counters expose the group-pair policy and matching enforcement activity, which directly addresses an unexpected TrustSec authorization result. The decisive requirement is an expected TrustSec flow is denied and the engineer needs evidence of which source-to-destination group permission is being enforced, so this is the direct fit.
  4. A DNS cache maps names to addresses but does not reveal role-based policy selection or enforcement counters. The case requires an expected TrustSec flow is denied and the engineer needs evidence of which source-to-destination group permission is being enforced, which this option does not provide.

 

Question 5

TrustSec enforcement sees a flow whose source security group cannot be determined because neither a usable inline tag nor an IP-to-SGT mapping is available. What should the engineer investigate first? Choose ONE.

  1. The BGP local preference
  2. The firewall URL category
  3. Inspect the MACsec replay window for protected frames
  4. The missing SGT classification or binding path

Correct Answer(s)

 

D

Rationale

  1. BGP local preference influences route selection but cannot supply a security-group identity for SGACL enforcement. The case requires traffic reaches an SGACL enforcement point with an unknown source identity because no usable SGT or IP-to-SGT binding is available, which this option does not provide.
  2. A URL category is an NGFW web-policy input and does not repair missing SGT classification on the TrustSec enforcement path. The case requires traffic reaches an SGACL enforcement point with an unknown source identity because no usable SGT or IP-to-SGT binding is available, which this option does not provide.
  3. The MACsec replay window affects acceptance of protected Ethernet frames and does not create the missing TrustSec source classification. The case requires traffic reaches an SGACL enforcement point with an unknown source identity because no usable SGT or IP-to-SGT binding is available, which this option does not provide.
  4. TrustSec group policy depends on resolving the source identity, so a missing inline tag or IP-to-SGT binding is the first gap to correct before evaluating normal SGACL permissions. The decisive requirement is traffic reaches an SGACL enforcement point with an unknown source identity because no usable SGT or IP-to-SGT binding is available, so this is the direct fit.

 

Question 6

A user receives a new IP address, but a remote TrustSec enforcement point still associates that address with the old security group. Inline tagging is unavailable across the transit. Which area should be checked first? Choose ONE.

  1. Check SXP health and updated IP-to-SGT propagation
  2. Change BGP AS-path selection for the transit
  3. Renegotiate MACsec ciphers on the local link
  4. Reconfigure SPAN monitoring on the enforcement switch

Correct Answer(s)

 

A

Rationale

  1. When TrustSec relies on SXP across a non-inline segment, stale remote identity information points to binding propagation or SXP session state rather than data-plane tagging. The decisive requirement is downstream enforcement is using a stale IP-to-SGT mapping after the user’s address was reassigned, and inline tagging is unavailable across the transit, so this is the direct fit.
  2. BGP AS-path length affects route selection and does not update TrustSec identity mappings at the enforcement point. The case requires downstream enforcement is using a stale IP-to-SGT mapping after the user’s address was reassigned, and inline tagging is unavailable across the transit, which this option does not provide.
  3. MACsec cipher negotiation determines how a supported Ethernet link is encrypted; it does not refresh remote IP-to-SGT mappings. The case requires downstream enforcement is using a stale IP-to-SGT mapping after the user’s address was reassigned, and inline tagging is unavailable across the transit, which this option does not provide.
  4. SPAN configuration controls packet mirroring for monitoring and cannot distribute a corrected security-group binding. The case requires downstream enforcement is using a stale IP-to-SGT mapping after the user’s address was reassigned, and inline tagging is unavailable across the transit, which this option does not provide.

 

Question 7

A remote employee’s laptop is suspected of compromise while connected only to the Internet. Analysts need process telemetry and retrospective investigation from the host without relying on campus packet capture. Which capability is most relevant? Choose ONE.

  1. RSPAN on the campus switch
  2. MACsec on a campus trunk
  3. Cloud-managed endpoint detection and response
  4. A campus-only SGACL counter

Correct Answer(s)

 

C

Rationale

  1. RSPAN mirrors traffic within configured network infrastructure and cannot capture a remote laptop’s local process activity while it is off campus. The case requires a remote laptop is off the corporate LAN but analysts need continuous process telemetry and retrospective investigation, which this option does not provide.
  2. MACsec on a campus trunk protects frames traversing that trunk; the remote laptop is not using that link and still needs host telemetry. The case requires a remote laptop is off the corporate LAN but analysts need continuous process telemetry and retrospective investigation, which this option does not provide.
  3. Cloud-managed EDR follows the endpoint and retains host-level telemetry, so analysts can investigate activity even when the device is away from the campus network. The decisive requirement is a remote laptop is off the corporate LAN but analysts need continuous process telemetry and retrospective investigation, so this is the direct fit.
  4. An SGACL counter can show TrustSec enforcement events on campus but cannot reconstruct off-campus endpoint process behavior. The case requires a remote laptop is off the corporate LAN but analysts need continuous process telemetry and retrospective investigation, which this option does not provide.

 

Question 8

An analyst issues a host-isolation action for a confirmed compromised laptop, but the device remains normally reachable. The endpoint connector is healthy. Which configuration should be verified first? Choose ONE.

  1. Increase the switch’s MACsec key-server priority
  2. Enable host isolation in the endpoint’s applied security policy
  3. Change the firewall’s URL category database
  4. Disable the entire user VLAN containing the compromised endpoint

Correct Answer(s)

 

B

Rationale

  1. MACsec key-server priority influences MKA elections on protected links and does not enable endpoint host-isolation behavior. The case requires the analyst issued a host-isolation action but the endpoint remains reachable because isolation was not enabled in the applied endpoint policy, which this option does not provide.
  2. Host isolation depends on the endpoint security policy permitting that response function, so a healthy connector with an ineffective isolation command makes the applied policy the first place to verify. The decisive requirement is the analyst issued a host-isolation action but the endpoint remains reachable because isolation was not enabled in the applied endpoint policy, so this is the direct fit.
  3. A URL category database affects web filtering and cannot authorize the endpoint connector to enter isolation mode. The case requires the analyst issued a host-isolation action but the endpoint remains reachable because isolation was not enabled in the applied endpoint policy, which this option does not provide.
  4. Disabling the VLAN would cause broad collateral outage and bypasses the actual endpoint-policy problem rather than fixing targeted isolation. The case requires the analyst issued a host-isolation action but the endpoint remains reachable because isolation was not enabled in the applied endpoint policy, which this option does not provide.

 

Question 9

An investigation shows a document reader spawning a scripting engine and creating local persistence entries. No known malicious network signature was observed. Which telemetry source is best positioned to detect this behavior chain? Choose ONE.

  1. Endpoint behavioral telemetry
  2. NAT translation counters
  3. A port-only router ACL
  4. MACsec statistics

Correct Answer(s)

 

A

Rationale

  1. Endpoint behavioral telemetry records process relationships and local system changes, allowing detection of a suspicious execution chain even when there is no matching network signature. The decisive requirement is an alert is based on a process spawning a scripting engine and modifying local persistence keys rather than on a known network signature, so this is the direct fit.
  2. NAT counters show address translations and flow activity but do not reveal which executable spawned another process or changed the host. The case requires an alert is based on a process spawning a scripting engine and modifying local persistence keys rather than on a known network signature, which this option does not provide.
  3. A port-only ACL evaluates packet headers and cannot observe process ancestry or local persistence modifications inside a workstation. The case requires an alert is based on a process spawning a scripting engine and modifying local persistence keys rather than on a known network signature, which this option does not provide.
  4. MACsec statistics describe protected-link operation and integrity, not process creation or registry-style persistence behavior. The case requires an alert is based on a process spawning a scripting engine and modifying local persistence keys rather than on a known network signature, which this option does not provide.

 

Question 10

An approved application can use more than one port and may change transport behavior across releases. The organization wants policy to follow the application rather than a fixed port list. Which NGFW feature addresses this? Choose ONE.

  1. Static port ACLs based on transport numbers only
  2. MACsec secure association
  3. Application identification with application-aware rules
  4. SXP binding exchange

Correct Answer(s)

 

C

Rationale

  1. Static port ACLs couple the policy to port numbers, so they can misclassify traffic when the application legitimately uses different ports. The case requires an application shifts between ports and transport behaviors but the business policy must consistently allow only that application, which this option does not provide.
  2. A MACsec secure association protects a local Ethernet link and does not identify applications for firewall authorization. The case requires an application shifts between ports and transport behaviors but the business policy must consistently allow only that application, which this option does not provide.
  3. Application-aware identification lets the firewall classify the application itself and apply a consistent rule even when simple transport-port assumptions change. The decisive requirement is an application shifts between ports and transport behaviors but the business policy must consistently allow only that application, so this is the direct fit.
  4. SXP exchanges IP-to-SGT bindings for TrustSec and provides no application classifier for NGFW policy. The case requires an application shifts between ports and transport behaviors but the business policy must consistently allow only that application, which this option does not provide.

 

Question 11

Employees and contractors use the same address pool, but only employees should be allowed to use a particular SaaS application. Which NGFW policy capability is most useful? Choose ONE.

  1. Use MACsec to distinguish employee application sessions
  2. Use URL reputation alone
  3. Create a rule based only on the shared source subnet
  4. Combine user or identity context with application-aware policy

Correct Answer(s)

 

D

Rationale

  1. MACsec protects link traffic cryptographically but does not label application sessions as employee or contractor for firewall authorization. The case requires employees and contractors share the same address pool but require different permissions to the same SaaS application, which this option does not provide.
  2. URL reputation assesses destination risk or category and does not express which authenticated workforce identity may use an otherwise legitimate SaaS application. The case requires employees and contractors share the same address pool but require different permissions to the same SaaS application, which this option does not provide.
  3. A rule based only on the shared subnet cannot distinguish employees from contractors because both populations present the same network location. The case requires employees and contractors share the same address pool but require different permissions to the same SaaS application, which this option does not provide.
  4. An NGFW can combine application identification with available user or identity context, allowing two users from the same address pool to receive different application permissions. The decisive requirement is employees and contractors share the same address pool but require different permissions to the same SaaS application, so this is the direct fit.

 

Question 12

A legitimate application is repeatedly blocked by one verified false-positive IPS signature. Other intrusion protections are still required. What is the best response? Choose ONE.

  1. Permit every flow from the application subnet before inspection
  2. Tune the false-positive signature while retaining other IPS protections
  3. Disable the entire intrusion-prevention policy globally
  4. Replace intrusion prevention with MACsec link encryption

Correct Answer(s)

 

B

Rationale

  1. A broad pre-inspection permit would create a bypass for all traffic from the subnet instead of correcting the single problematic signature. The case requires one IPS signature is producing verified false positives for a legitimate application while other intrusion protections must remain active, which this option does not provide.
  2. Targeted signature tuning removes the known false-positive condition while preserving the broader intrusion-prevention coverage that the requirement says must remain active. The decisive requirement is one IPS signature is producing verified false positives for a legitimate application while other intrusion protections must remain active, so this is the direct fit.
  3. Disabling IPS globally removes protection against unrelated exploits and therefore sacrifices far more security than the specific false-positive condition requires. The case requires one IPS signature is producing verified false positives for a legitimate application while other intrusion protections must remain active, which this option does not provide.
  4. MACsec provides link confidentiality and integrity but cannot replace exploit-signature inspection or solve an IPS false-positive. The case requires one IPS signature is producing verified false positives for a legitimate application while other intrusion protections must remain active, which this option does not provide.

 

Question 13

A file was allowed when its reputation was unknown. Several hours later, threat intelligence classifies the same hash as malicious. Which security capability is most valuable for finding earlier exposure? Choose ONE.

  1. MACsec replay protection
  2. Static source NAT
  3. Retrospective file tracking and updated malware disposition
  4. An SGACL that permits the user’s group

Correct Answer(s)

 

C

Rationale

  1. MACsec replay protection detects repeated protected frames and has no historical file reputation or trajectory function. The case requires a file was initially unknown when transferred, but later threat intelligence classifies its hash as malicious and analysts need to identify prior exposure, which this option does not provide.
  2. Static NAT preserves a translation mapping but does not retain malware history or reassess a file when threat intelligence changes. The case requires a file was initially unknown when transferred, but later threat intelligence classifies its hash as malicious and analysts need to identify prior exposure, which this option does not provide.
  3. Retrospective malware capability can revisit previously observed file hashes when intelligence changes, helping analysts identify systems that received a file before its malicious disposition was known. The decisive requirement is a file was initially unknown when transferred, but later threat intelligence classifies its hash as malicious and analysts need to identify prior exposure, so this is the direct fit.
  4. An SGACL controls group-to-group access and cannot retrospectively identify endpoints that received a newly convicted file. The case requires a file was initially unknown when transferred, but later threat intelligence classifies its hash as malicious and analysts need to identify prior exposure, which this option does not provide.

 

Question 14

An enterprise can decrypt some outbound TLS traffic for inspection, but legally protected categories must remain undecrypted. Which NGFW design is most appropriate? Choose ONE.

  1. Use MACsec instead of defining TLS inspection policy
  2. Use selective TLS decryption policy with explicit exemptions for protected traffic
  3. Bypass all security controls for every undecrypted HTTPS session by policy
  4. Decrypt every TLS flow unconditionally

Correct Answer(s)

 

B

Rationale

  1. MACsec protects local Ethernet links and does not decide which end-to-end TLS sessions an NGFW may decrypt for inspection. The case requires the enterprise may decrypt selected business traffic for inspection but must exempt legally protected categories from decryption, which this option does not provide.
  2. Selective decryption lets policy inspect eligible traffic while explicitly exempting categories that must remain private, balancing security visibility with the stated legal boundary. The decisive requirement is the enterprise may decrypt selected business traffic for inspection but must exempt legally protected categories from decryption, so this is the direct fit.
  3. Bypassing all HTTPS traffic discards permitted inspection and other metadata-based controls, going far beyond the required exemptions. The case requires the enterprise may decrypt selected business traffic for inspection but must exempt legally protected categories from decryption, which this option does not provide.
  4. Decrypting every flow violates the explicit requirement to preserve protected categories and therefore fails the governance constraint. The case requires the enterprise may decrypt selected business traffic for inspection but must exempt legally protected categories from decryption, which this option does not provide.

 

Question 15

A flow crosses several routed hops, and MACsec is enabled only on one inter-switch Ethernet segment. What protection should the architect attribute to that MACsec deployment? Choose ONE.

  1. Treat MACsec as protection for the configured Ethernet hop
  2. Assume MACsec performs malware inspection automatically on every routed hop
  3. End-to-end payload encryption for the entire application session
  4. Assume MACsec creates identity authorization on every hop

Correct Answer(s)

 

A

Rationale

  1. MACsec protects Layer 2 frames between participating peers on the secured link; its scope does not automatically extend cryptographic protection across unrelated routed segments. The decisive requirement is traffic crosses three routed hops but only one inter-switch Ethernet segment is protected by MACsec, so this is the direct fit.
  2. Frame encryption and integrity do not provide malware analysis or application inspection. The case requires traffic crosses three routed hops but only one inter-switch Ethernet segment is protected by MACsec, which this option does not provide.
  3. End-to-end application encryption requires a protocol whose security association spans the communicating endpoints or routed path, which a single MACsec hop does not provide. The case requires traffic crosses three routed hops but only one inter-switch Ethernet segment is protected by MACsec, which this option does not provide.
  4. MACsec authenticates and protects a link but does not automatically create identity-based authorization policies on every network hop. The case requires traffic crosses three routed hops but only one inter-switch Ethernet segment is protected by MACsec, which this option does not provide.

 

Question 16

A MACsec-protected link remains physically up, but a received protected frame fails its integrity validation. What does that failure most directly indicate? Choose ONE.

  1. Refresh the destination URL-category policy on the firewall
  2. Reassign the endpoint’s TrustSec security-group classification
  3. Lower the OSPF path cost toward the destination
  4. Reject the frame because MACsec integrity validation failed

Correct Answer(s)

 

D

Rationale

  1. URL category information belongs to web-security policy and has no bearing on MACsec frame integrity verification. The case requires a protected Ethernet frame arrives with a failed integrity check even though the physical link remains up, which this option does not provide.
  2. An SGT classification problem affects TrustSec identity policy, not the cryptographic integrity result of a MACsec-protected frame. The case requires a protected Ethernet frame arrives with a failed integrity check even though the physical link remains up, which this option does not provide.
  3. OSPF cost influences routing path selection and does not cause a MACsec integrity check to fail. The case requires a protected Ethernet frame arrives with a failed integrity check even though the physical link remains up, which this option does not provide.
  4. MACsec includes integrity protection, so a failed integrity check means the protected frame cannot be accepted as authentic and unmodified according to the security association. The decisive requirement is a protected Ethernet frame arrives with a failed integrity check even though the physical link remains up, so this is the direct fit.

 

Question 17

Two switches have physical connectivity, but the expected MACsec secure association never forms. Which control-plane function should be investigated first for peer authentication and key establishment? Choose ONE.

  1. SXP binding table
  2. MKA state and key agreement
  3. NAT translation slots
  4. URL filtering database used for destination reputation policy

Correct Answer(s)

 

B

Rationale

  1. SXP exchanges TrustSec IP-to-SGT mappings; a healthy or unhealthy SXP session does not negotiate MACsec link keys. The case requires the physical link forwards ordinary Ethernet but no MACsec secure association forms between peers, which this option does not provide.
  2. MKA is responsible for MACsec participant key agreement and secure-association establishment, so its state is the relevant first checkpoint when the link works but the secure channel does not form. The decisive requirement is the physical link forwards ordinary Ethernet but no MACsec secure association forms between peers, so this is the direct fit.
  3. NAT translation state affects Layer 3 address conversion and is unrelated to peer key agreement on a local Ethernet link. The case requires the physical link forwards ordinary Ethernet but no MACsec secure association forms between peers, which this option does not provide.
  4. A URL filtering database categorizes web destinations and has no role in creating a MACsec secure association. The case requires the physical link forwards ordinary Ethernet but no MACsec secure association forms between peers, which this option does not provide.

 

Question 18

Two applications must have confidentiality across an arbitrary routed WAN that includes intermediate networks the enterprise does not control. Why is MACsec on a single access link insufficient by itself? Choose ONE.

  1. Add end-to-end or routed-path protection beyond the MACsec hop
  2. Replace endpoint security with MACsec on the access link
  3. Assume MACsec cannot encrypt Ethernet traffic at all
  4. Use MACsec only as a URL-filtering control

Correct Answer(s)

 

A

Rationale

  1. MACsec secures participating Layer 2 links rather than creating an end-to-end application tunnel across every intermediate routed network, so the remaining WAN path needs appropriate protection. The decisive requirement is the requirement is confidential communication between two applications across an arbitrary routed WAN with intermediate routers outside the enterprise, so this is the direct fit.
  2. Link encryption does not replace endpoint protection, and endpoint security is a separate control domain from routed-path confidentiality. The case requires the requirement is confidential communication between two applications across an arbitrary routed WAN with intermediate routers outside the enterprise, which this option does not provide.
  3. Encrypting Ethernet frames is a core MACsec purpose; the limitation here is protection scope, not an inability to encrypt. The case requires the requirement is confidential communication between two applications across an arbitrary routed WAN with intermediate routers outside the enterprise, which this option does not provide.
  4. URL filtering is an NGFW function and has nothing to do with the link-layer scope of MACsec. The case requires the requirement is confidential communication between two applications across an arbitrary routed WAN with intermediate routers outside the enterprise, which this option does not provide.

 

Question 19

A MACsec link already provides confidentiality and integrity. The remaining concern is that an attacker could capture valid protected frames and retransmit them later. Which MACsec-related control addresses this risk? Choose ONE.

  1. Apply SGACL authorization policy between the source and destination security groups
  2. Run endpoint vulnerability scanning on both switches
  3. Enable NGFW URL filtering for the protected link
  4. Use MACsec replay protection with packet numbering and a window

Correct Answer(s)

 

D

Rationale

  1. SGACL authorization decides whether security groups may communicate but does not detect reuse of a previously valid MACsec frame. The case requires an attacker may capture valid protected Ethernet frames and retransmit them later, while confidentiality and integrity are already enabled, which this option does not provide.
  2. Endpoint vulnerability scanning identifies software weaknesses and has no role in link-layer replay detection. The case requires an attacker may capture valid protected Ethernet frames and retransmit them later, while confidentiality and integrity are already enabled, which this option does not provide.
  3. URL filtering evaluates web destinations and cannot determine whether a protected Ethernet frame has been retransmitted. The case requires an attacker may capture valid protected Ethernet frames and retransmit them later, while confidentiality and integrity are already enabled, which this option does not provide.
  4. MACsec replay protection uses protected-frame sequencing and an acceptance window to reject replayed traffic even when the copied frame was originally authentic. The decisive requirement is an attacker may capture valid protected Ethernet frames and retransmit them later, while confidentiality and integrity are already enabled, so this is the direct fit.

 

Question 20

A high-value application faces three risks: exploit traffic at the network boundary, compromised user endpoints, and excessive east-west access. Which design best addresses the full set? Choose ONE.

  1. Use a single permissive inside firewall zone for all users
  2. Rely only on endpoint antivirus
  3. Layered threat prevention, endpoint security, and identity-based segmentation
  4. Deploy MACsec only on the server uplink

Correct Answer(s)

 

C

Rationale

  1. A permissive inside zone leaves lateral access broadly open and does not address the segmentation requirement or endpoint compromise. The case requires a high-value application needs defenses for malicious network traffic, compromised endpoints, and excessive east-west privilege rather than a single control, which this option does not provide.
  2. Endpoint antivirus can reduce host malware risk, but it cannot by itself enforce network-boundary inspection and identity-based east-west policy. The case requires a high-value application needs defenses for malicious network traffic, compromised endpoints, and excessive east-west privilege rather than a single control, which this option does not provide.
  3. Combining network threat prevention, endpoint controls, and identity-based segmentation places defenses at the distinct control points represented by the three risks instead of assuming one technology covers them all. The decisive requirement is a high-value application needs defenses for malicious network traffic, compromised endpoints, and excessive east-west privilege rather than a single control, so this is the direct fit.
  4. MACsec secures the server link but does not detect boundary exploits, investigate compromised endpoints, or define least-privilege east-west authorization. The case requires a high-value application needs defenses for malicious network traffic, compromised endpoints, and excessive east-west privilege rather than a single control, which this option does not provide.

Leave a Reply

How It Works

img
Step 1. Choose Exam
on ExamLabs
Download IT Exams Questions & Answers
img
Step 2. Open Exam with
Avanset Exam Simulator
Press here to download VCE Exam Simulator that simulates real exam environment
img
Step 3. Study
& Pass
IT Exams Anywhere, Anytime!