CCNP Security 350-701 SCOR Practice Test 13

CCNP Security 350-701 SCOR Practice Test 13 (Hard) - Network Segmentation and Layer 2/3 Security

CISCO CCNP Security Exam Logo

1 / 10

Which switch security feature prevents an unauthorized device from flooding a switch's MAC address table with fake source addresses in order to force traffic to be broadcast to all ports?

2 / 10

Which Layer 2 attack involves an attacker sending crafted BPDUs in an attempt to become the root bridge of a spanning tree topology, potentially redirecting traffic through the attacker's device?

3 / 10

Which mitigation is specifically designed to prevent an unauthorized switch port from participating in spanning tree root bridge elections, protecting the topology from a rogue switch attempting to become root?

4 / 10

Which VLAN hopping technique relies on an attacker's device being connected to a port configured with DTP auto-negotiation, allowing the attacker to negotiate a trunk link and gain access to all VLANs carried on that trunk?

5 / 10

Which best practice reduces the risk of double-tagging VLAN hopping attacks on trunk links?

6 / 10

Which technology validates that DHCP responses on a switch only originate from designated trusted ports, preventing a rogue DHCP server from assigning malicious configuration to clients?

7 / 10

Which technology uses the DHCP snooping binding table to validate that ARP replies come from the legitimate IP-to-MAC mapping, mitigating ARP cache poisoning (man-in-the-middle) attacks on a VLAN?

8 / 10

Which Layer 2 feature restricts communication between hosts in the same VLAN by placing them into isolated or community sub-VLANs beneath a single primary VLAN, commonly used in shared hosting or guest environments?

9 / 10

Which control limits the impact of a broadcast, multicast, or unknown-unicast traffic storm on a switch port by shutting down or rate-limiting the port when traffic exceeds a configured threshold?

10 / 10

Which practice contributes most directly to reducing the overall attack surface of a Layer 3 network segmentation design between security zones of different trust levels?

Your score is

The average score is 0%

0%