Designing Cisco Security Infrastructure — Free Practice Questions
10 free sample questions from a bank of 39, with the correct answers and explanations. No signup required — start practising right now.
1A technology company recently onboarded a new customer in the medical space. The customer needs a solution to provide data integrity across remote sites. Which solution must be used to meet this requirement?
hashing
data masking
preshared key
authentication
Answer: A
The short version
A — Hashing is the integrity mechanism. It produces a fixed digest of data at the source and destination, so any alteration across remote sites is detectable.
Key concepts in this question
Hashing: one-way function producing a fixed-length digest used to verify data is unchanged.
Data integrity: assurance that information was not modified in transit or storage.
Authentication vs integrity: authentication proves identity, while hashing proves content is intact.
Why A is correct
The requirement is data integrity across remote sites, which is exactly what hashing provides: the sender computes a digest and the receiver recomputes it, and a mismatch proves tampering. Standard integrity designs pair hashing with secure transport, and a medical customer moving records between sites relies on this detect-any-change property.
Why the others are wrong
B. Data masking hides sensitive values for privacy, but it does not detect modification in transit.
C. A preshared key is authentication or encryption keying material, not itself the integrity check.
D. Authentication verifies who is communicating, not whether the payload bits were altered.
300-745 exam tip — memory hook
Integrity equals hashing; identity equals authentication; secrecy equals encryption — match the stem's noun to the mechanism.
2Which design policy addresses harmful content creation by generative AI?
quantum resistant encryption
watermarking
retrieval augmented generation
human in the loop
Answer: B
The short version
B — Watermarking marks AI-generated content. Embedded signals let platforms and users identify synthetic media and trace harmful generations.
Key concepts in this question
Watermarking: imperceptible or visible markers embedded in generated text, images, or audio.
Generative AI governance: design policies for provenance, detection, and accountability.
Deterrence vs prevention: watermarking aids detection and attribution rather than blocking generation outright.
Why B is correct
The stem asks for a design policy addressing harmful content creation by generative AI. Watermarking is the recognized provenance control: it labels synthetic output so downstream filters, moderators, and recipients can detect AI origin and act on misuse. That directly answers content-creation accountability.
Why the others are wrong
A. Quantum-resistant encryption protects future confidentiality, not AI content provenance.
C. Retrieval augmented generation improves factual grounding, but does not mark or govern harmful outputs.
D. Human in the loop adds oversight to decisions, yet without provenance it cannot identify synthetic content at scale.
300-745 exam tip — memory hook
Harmful AI content equals watermarking and provenance; improved answers equals retrieval augmentation; oversight equals human in the loop.
3A software development company uses multiple cloud providers to host the applications. The company is designing a scalable firewall solution that must meet the requirements:- Consistent security policies across multiple cloud environments.- Centralized visibility and management.- Scalability to accommodate different cloud platforms.Which type of firewall meets the requirements?
traditional firewall
zone-based firewall
distributed firewall
host-based firewall
Answer: C
The short version
C — Distributed firewall fits multi-cloud scale. Policy is defined centrally and enforced close to each workload across different cloud platforms.
Key concepts in this question
Distributed firewall: central management with enforcement points spread across hosts, VPCs, and clouds.
Consistent policy: one intent model translated to each cloud's native controls.
Centralized visibility: aggregated logs and posture across all environments.
Why C is correct
The company needs consistent policies, centralized visibility, and scalability across multiple cloud providers. A distributed firewall meets all three: a single controller defines policy once, pushes it to enforcement points in each cloud, and collects telemetry centrally while scaling out with new workloads and platforms.
Why the others are wrong
A. A traditional perimeter firewall is a single choke point and cannot follow workloads across clouds.
B. A zone-based firewall segments one device or site into zones, not multiple public clouds centrally.
D. A host-based firewall protects an individual endpoint and lacks central multi-cloud orchestration.
300-745 exam tip — memory hook
Multi-cloud plus central management equals distributed firewall; single box or single host answers fail the scale test.
4Which financial reporting regulatory framework must a publicly traded company doing business in the US comply with?
HIPAA
SOX
SOC
FEDRAMP
Answer: B
The short version
B — SOX governs US public-company financial reporting. It mandates internal controls, executive certification, and audited disclosures.
Key concepts in this question
SOX: Sarbanes-Oxley Act of 2002 for investor protection and reporting accuracy.
Applicability: US publicly traded companies and their financial controls.
Controls and audits: management assessment plus independent auditor attestation.
Why B is correct
A publicly traded company doing business in the US must comply with the Sarbanes-Oxley Act for financial reporting. SOX requires documented internal controls over financial reporting, CEO and CFO certification of reports, and external audits — precisely the financial-reporting regulatory framework the stem describes.
Why the others are wrong
A. HIPAA governs protected health information, not financial statements.
C. SOC reports, such as SOC 2, are auditor attestations about controls, not the governing law itself.
D. FedRAMP authorizes cloud services for federal agencies, not public-company financial reporting.
300-745 exam tip — memory hook
Publicly traded plus financial reporting equals SOX; health data equals HIPAA; federal cloud equals FedRAMP.
5A financial company uses a remote access solution that directs all traffic over a secure tunnel.The company recently received some large ISP bills from the headcounter location. According to traffic analysis during the investigation, most of the network traffic was due to employees spending a lot of time on video conferences provided by a SaaS collaboration company. What must the company modify to reduce the cost without negatively impacting security or employee experience?
Reduce the video resolution size permitted within the SaaS application.
Split-exclude the video SaaS application from the VPN.
Block the video conferencing app when connected on VPN.
Suggest users to disconnect from the VPN when on video calls.
Answer: B
The short version
B — Split-exclude the trusted SaaS video from the tunnel. Hairpinning high-volume collaboration traffic through headquarters inflates ISP and VPN load for no security gain.
Key concepts in this question
Full tunnel: all traffic traverses the VPN concentrator and headquarters egress.
Split tunneling: selected traffic goes direct to the internet while corporate traffic stays protected.
Split-exclude: trusted SaaS destinations bypass the tunnel with policy control.
Why B is correct
Traffic analysis shows the cost driver is SaaS video backhauled over the secure tunnel. Split-excluding that specific collaboration application sends its media directly to the provider's nearby points of presence while corporate traffic remains inspected. Costs fall and employee experience improves because latency drops, with no loss of protection on what still uses the tunnel.
Why the others are wrong
A. Reducing video resolution degrades employee experience, which the stem forbids.
C. Blocking the conferencing app breaks business workflows rather than optimizing transport.
D. Asking users to drop off VPN during calls removes protection from the endpoint and relies on behavior, not design.
300-745 exam tip — memory hook
Expensive SaaS backhaul equals split-exclude the trusted app; keep security on corporate traffic and send bulk SaaS direct.
6A furniture company recently discovered that the endpoint detection and response configuration flagged several malicious files on company-managed laptops. The company must enhance security to prevent known malicious files from being delivered to the network and endpoints. The new solution must enhance the company's ability to inspect and filter incoming traffic effectively.Which security product must be used to accomplish this goal?
next-generation firewall
traditional firewall
host-based firewall
eBPF
Answer: A
The short version
A — A next-generation firewall inspects and filters incoming traffic. Application awareness, IPS, and file and malware analysis block known malicious files before endpoints.
Key concepts in this question
Next-generation firewall: combines stateful inspection with application control, IPS, URL filtering, and malware defense.
Network-delivered malware: malicious files arriving over web, email, or downloads.
Defense in depth: network filtering complements endpoint detection and response.
Why A is correct
The gap is network ingress: known malicious files are reaching endpoints, and EDR only flags them after arrival. A next-generation firewall inspects sessions inline, applies threat intelligence and file reputation, and drops malicious payloads at the boundary, directly enhancing the ability to inspect and filter incoming traffic.
Why the others are wrong
B. A traditional firewall filters ports and addresses but cannot analyze files or application payloads.
C. A host-based firewall guards one machine's stack and adds no network-wide ingress inspection.
D. eBPF is a kernel programmability framework for observability and controls, not a turnkey ingress filtering product.
300-745 exam tip — memory hook
Block files at ingress equals next-generation firewall; detect on the laptop equals endpoint detection and response.
7An oil and gas company recently faced a security breach when an employee's notepad, which contained critical login credentials, was stolen. The incident led to unauthorized access to a user account, which posed a significant risk to sensitive company data and operations. The company wants to adopt a security measure that enhances user account protection. Which action must be taken to prevent breaches like this from happening in the future?
Implement MFA
Implement single sign-on.
Update the RADIUS server.
Configure a password expiration policy.
Answer: A
The short version
A — MFA neutralizes stolen passwords. A second factor keeps the account safe even when written-down credentials are compromised.
Key concepts in this question
MFA: requires two or more factors such as knowledge, possession, or inherence.
Credential theft: stolen passwords alone grant access under single-factor schemes.
Compensating control: MFA limits blast radius of password exposure.
Why A is correct
The breach came from a stolen notepad holding login credentials, a classic single-factor failure. Implementing multi-factor authentication means the attacker still lacks the phone token, smart card, or biometric needed to complete sign-in, so future password theft no longer yields unauthorized account access or data risk.
Why the others are wrong
B. Single sign-on improves convenience and centralizes policy, but a stolen SSO password still signs in everywhere.
C. Updating the RADIUS server hardens network authentication transport, not the stolen-password vector itself.
D. Password expiration rotates secrets but leaves the window open until expiry and does not stop reuse of a fresh password.
300-745 exam tip — memory hook
Stolen or phished password in the stem equals MFA; convenience and central login equals single sign-on.
8An administrator at a large university wants to ensure that the new employees have the right level of access when they are onboarded. The administrator asked the team to configure the cloud environment and ensure that new employees have the appropriate access based on their roles and responsibilities. Which technique must be recommended to ensure the right level of access?
identity access management
security groups
VPN
network access control list
Answer: A
The short version
A — Identity access management grants role-appropriate access. It ties onboarding, roles, and least privilege to cloud resources.
Key concepts in this question
Identity access management: centralized identities, roles, and policies for who can do what.
Role-based access: permissions follow job responsibilities, not individual exceptions.
Least privilege: new employees receive only the access their role requires.
Why A is correct
The administrator needs onboarding where each employee's cloud access matches roles and responsibilities. Identity access management provides exactly that: identity lifecycle, role definitions, and policy enforcement, so the team configures entitlements once by role and every new hire inherits the right level automatically.
Why the others are wrong
B. Security groups are network or resource firewalls; they do not manage identity lifecycle or role entitlement.
C. A VPN supplies remote connectivity, not authorization decisions about who may access what.
D. A network access control list filters subnets by address, which cannot express per-role cloud permissions.
300-745 exam tip — memory hook
Right access by role at onboarding equals identity access management; packet filtering answers are distractors for identity questions.
9How is generative AI used in securing network?
to provide real-time load balancing
to improve resource consumption
to perform real-time audits to ensure regulatory compliance
to detect unusual patterns in network traffic
Answer: D
The short version
D — Generative AI spots unusual traffic patterns. Learned baselines let it flag anomalies faster than static thresholds.
Key concepts in this question
Anomaly detection: comparing live traffic against learned normal behavior.
Network telemetry: flows, DNS, and session features feeding models.
Operational use: triage, hunting, and alert enrichment rather than forwarding or balancing.
Why D is correct
Securing the network with generative AI centers on learning normal traffic and detecting deviations that indicate intrusion, exfiltration, or botnet behavior. Pattern-level reasoning over large telemetry volumes surfaces subtle, novel anomalies that signature or threshold systems miss, which is the stated security use case.
Why the others are wrong
A. Real-time load balancing is a traffic-engineering function, not a generative-AI security role.
B. Improving resource consumption is capacity optimization, unrelated to threat detection.
C. Real-time compliance auditing is governance reporting, not the traffic-anomaly detection the correct choice names.
300-745 exam tip — memory hook
AI plus securing the network equals anomaly and pattern detection; balancing, scaling, and auditing are non-security distractors.
10A video game company identified a potential threat of a SYN flood attack, which could disrupt the online gaming services and impact user experience. The attack can overwhelm network resources by exploiting the TCP handshake process, leading to server unavailability and degraded performance. To safeguard the company's infrastructure and ensure uninterrupted service, it is essential to enhance the security measures in place. The company must implement a solution that manages and mitigates the risk of such network-based attacks. Which security product must be implemented to mitigate similar risks?
Cisco Web Security Appliance
Cisco Umbrella
Cisco Secure Endpoint
Cisco Secure Firewall
Answer: D
The short version
D — Cisco Secure Firewall mitigates SYN floods. Stateful inspection, connection limits, and SYN-cookie style defenses absorb handshake abuse.
Key concepts in this question
SYN flood: half-open TCP handshakes exhaust server backlog and state tables.
Network-based mitigation: rate limiting, embryonic-connection limits, and anomaly detection at the edge.
Product fit: firewall for Layer 3 and Layer 4 floods versus web, DNS, or endpoint tools.
Why D is correct
A SYN flood exploits the TCP handshake to overwhelm network resources, so mitigation belongs at the network enforcement point. Cisco Secure Firewall provides SYN-flood controls, connection-rate limiting, and threat defense that shield gaming servers and preserve availability, matching the required network-based solution.
Why the others are wrong
A. Cisco Web Security Appliance proxies web traffic and cannot absorb Layer 4 SYN floods.
B. Cisco Umbrella enforces DNS-layer security, not TCP handshake state exhaustion.
C. Cisco Secure Endpoint protects hosts after delivery and does not mitigate volumetric network floods upstream.
300-745 exam tip — memory hook
SYN flood and handshake exhaustion equals firewall; web proxy, DNS, and endpoint are the wrong layers.