CCNP Security 300-740 SSCA Practice Test 14

CCNP Security 300-740 SSCA Practice Test 14 (Hard) - Web Application Firewalls and DDoS Protection

CISCO CCNP Security Exam Logo

1 / 10

Which security control inspects HTTP/HTTPS traffic destined for a web application and blocks requests matching known attack patterns such as SQL injection or cross-site scripting?

2 / 10

Which type of attack is specifically designed to overwhelm a web application or network resource with excessive traffic or requests, aiming to make the service unavailable to legitimate users?

3 / 10

Which WAF rule design practice would help protect a web application against SQL injection attempts while minimizing the risk of blocking legitimate user input?

4 / 10

Which DDoS mitigation approach helps absorb and filter a volumetric attack before it reaches an organization's origin servers?

5 / 10

Which characteristic distinguishes a volumetric DDoS attack from an application-layer (Layer 7) DDoS attack?

6 / 10

Which WAF and DDoS protection combination would provide comprehensive coverage for a public-facing e-commerce web application?

7 / 10

Which risk would most likely result from an organization deploying a WAF with default, out-of-the-box rules and never tuning them to the specific application's behavior?

8 / 10

Which factor would most influence how much DDoS scrubbing capacity an organization provisions for a given public-facing application?

9 / 10

Which practice would help an organization validate that its WAF and DDoS protection configuration actually performs as expected before relying on it during a real attack?

10 / 10

Which statement accurately describes why WAF and DDoS protection are considered complementary rather than interchangeable controls?

Your score is

The average score is 0%

0%