TechNuggets Academy

Network Security

Free Implementing and Operating Cisco Security Core Technologies practice — 6 questions on Network Security, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Domain 2: Network Security
An engineer is inserting a Cisco Secure Firewall Threat Defense (FTD) appliance physically inline between two switches to evaluate a newly created intrusion policy before it goes into full production enforcement. The requirement is that the appliance must not be able to drop or delay any production traffic, even if the policy is misconfigured or generates false positives, while still receiving live traffic in real time for analysis. Which FTD interface mode meets this requirement?
Inline pair with tap mode physically inserts the FTD in the traffic path but only sends a copy of each packet to the Snort engine for inspection; the original packet is forwarded immediately regardless of the verdict, so the appliance can never drop or delay production traffic — ideal for tuning a policy before cutover to full inline enforcement.
Question 2 of 6 · Domain 2: Network Security
A network team is building a large hub-and-spoke IPsec VPN and wants spokes to be able to dynamically learn each other's public (NBMA) IP addresses at connection time and establish direct spoke-to-spoke tunnels on demand, instead of always routing spoke-to-spoke traffic through the hub. Which protocol provides this dynamic address-mapping and tunnel-discovery capability in a DMVPN deployment?
NHRP (Next Hop Resolution Protocol) maintains a dynamic mapping database of tunnel IP addresses to real NBMA IP addresses. Spokes query the hub's NHRP server to resolve another spoke's public IP address and then build a direct spoke-to-spoke GRE/IPsec tunnel.
Question 3 of 6 · Domain 2: Network Security
Which Cisco IOS/IOS XE NetFlow capability allows an administrator to build a custom flow record by choosing which key fields and non-key fields are exported, rather than being restricted to the fixed field set of traditional NetFlow?
Flexible NetFlow (FNF) lets administrators build custom flow records by selecting from a large library of key and non-key fields (for example MPLS labels, NBAR application, or IPv6 fields), unlike the fixed 5-tuple format of traditional NetFlow.
Question 4 of 6 · Domain 2: Network Security
During a volumetric attack, an ISR router's CPU utilization spikes to 100% because of a flood of crafted packets destined to the router's own IP addresses (spoofed OSPF hellos and repeated SSH connection attempts), while transit traffic passing through the router is unaffected. Which feature should be configured to classify and rate-limit this traffic destined to the route processor using a single aggregate control-plane policy?
CoPP applies a policy-map directly to the control-plane interface, classifying and rate-limiting or dropping traffic destined to the route processor (management and routing-protocol traffic) as a single aggregate policy, protecting the CPU without affecting transit forwarding.
Question 5 of 6 · Domain 2: Network Security
An administrator configures Cisco Secure Client (AnyConnect) so that DNS lookups for specific corporate domains (for example internal.company.com) are resolved using the internal DNS servers pushed down through the VPN tunnel, while all other DNS lookups are resolved locally using the user's own ISP DNS servers. Which feature accomplishes this domain-based DNS resolution split?
Split DNS lets the administrator specify a list of domains that must be resolved using the DNS servers pushed through the VPN tunnel, while all other DNS queries continue to use the client's local (non-tunnel) DNS servers.
Question 6 of 6 · Domain 2: Network Security
A security engineer needs to enable TLS decryption on a Cisco Secure Firewall (FTD) for inbound traffic to an internally hosted HTTPS application. The organization holds the private key and the original certificate for that internal server. Which SSL/TLS decryption policy action should be applied to this traffic so the FTD can decrypt and inspect it without generating any certificate warnings for connecting clients?
Decrypt - Known Key is used when the FTD has the actual private key and certificate of the internal server being protected (inbound traffic). It presents the real server certificate to clients, so no certificate warnings appear, while the firewall decrypts and inspects the session.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →