Free Implementing and Operating Cisco Security Core Technologies practice — 6 questions on Security Concepts, with explanations. No sign-up.
Full 12-question mixed test →
Question 1 of 6 · Domain 1: Security Concepts
A financial services company deployed a PKI-based VPN client authentication solution on a Cisco ASA headend. Security auditors discover that certificates revoked by the CA are still being accepted by the VPN headend for up to 12 hours, matching the CRL publish interval. Which change provides near real-time revocation checking without dramatically increasing CRL publishing frequency and its associated bandwidth/CPU overhead?
OCSP allows the VPN headend to query the CA (or an OCSP responder) in real time for the status of a specific certificate, eliminating the delay inherent in periodically published CRLs.
Question 2 of 6 · Domain 1: Security Concepts
A network engineer must configure an IKEv2 IPsec VPN between two Cisco ASAs that meets NSA Suite B-aligned cryptographic requirements, using a single algorithm that provides both confidentiality and data-origin authentication/integrity, removing the need to negotiate a separate HMAC integrity algorithm. Which IKEv2 encryption choice satisfies this requirement?
AES-GCM is an AEAD (Authenticated Encryption with Associated Data) cipher that provides confidentiality and integrity/authentication in one algorithm, so a separate HMAC integrity transform is not required and is in fact set to null.
Question 3 of 6 · Domain 1: Security Concepts
While building an IKEv2 policy on a Cisco ASA, an engineer selects AES-GCM as the encryption algorithm. IKEv2 proposals allow independent selection of an integrity algorithm and a separate pseudo-random function (PRF), unlike IKEv1 policies. Which configuration is correct for the integrity and PRF settings when GCM is used?
When using an AEAD cipher like AES-GCM, the integrity algorithm must be set to null because authentication is built into the cipher itself. However, IKEv2 still requires a PRF (e.g., SHA-256) for key derivation material — the PRF is a separate function from data integrity and cannot be null.
Question 4 of 6 · Domain 1: Security Concepts
Which statement accurately differentiates the Zero Trust security model from a traditional defense-in-depth (perimeter-based) architecture?
Zero Trust operates on 'never trust, always verify' — every access request is authenticated, authorized, and continuously validated regardless of whether it originates inside or outside the network. Defense-in-depth uses multiple layered perimeter/network defenses but generally still trusts traffic once it has passed inside those layers.
Question 5 of 6 · Domain 1: Security Concepts
A SOC analyst notices an internal host generating thousands of DNS queries per hour to random-looking subdomains of a domain registered to an unknown third party, with TXT record responses containing long base64-encoded strings. Which attack technique is most likely occurring, and which Cisco solution is best suited to detect and block it?
High volumes of DNS queries to random subdomains carrying encoded data in TXT records is a classic signature of DNS tunneling used for command-and-control or data exfiltration. Cisco Umbrella performs DNS-layer security and can identify and block malicious/tunneling domains using threat intelligence and behavioral analysis.
Question 6 of 6 · Domain 1: Security Concepts
An organization wants to automatically consume threat intelligence feeds in a standardized, machine-readable format and share indicators of compromise (IOCs) with Cisco Secure Network Analytics and other third-party security tools using an industry-standard exchange mechanism. Which combination of standards should be implemented?
STIX (Structured Threat Information eXpression) is the industry-standard format for describing threat intelligence and IOCs, while TAXII (Trusted Automated Exchange of Intelligence Information) is the standard transport protocol used to share STIX content between platforms and organizations, and is supported by Cisco security intelligence integrations.
Ready for the real thing?
The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.