CCNP Security 300-740 SSCA Practice Test 11

CCNP Security 300-740 SSCA Practice Test 11 (Hard) - IPS, DLP, and Malware Protection Features

CISCO CCNP Security Exam Logo

1 / 10

Which security control inspects network traffic in real time and can actively block traffic matching known attack signatures or anomalous behavior patterns?

2 / 10

Which capability does Data Loss Prevention (DLP) provide to help protect sensitive information such as credit card numbers or health records from leaving an organization's control?

3 / 10

Which detection approach do modern malware protection features commonly use in addition to traditional signature-based matching, to identify previously unseen (zero-day) malicious files?

4 / 10

Which DLP policy design practice helps reduce false positives when scanning outbound communications for sensitive data patterns such as national identification numbers?

5 / 10

Which IPS deployment mode would actively block malicious traffic in real time, as opposed to only alerting after the fact?

6 / 10

Which combination of controls would help an organization detect and prevent both network-based intrusions and unauthorized exfiltration of sensitive data?

7 / 10

Which risk would most likely result from relying exclusively on signature-based malware detection with no behavioral or sandboxing capability?

8 / 10

Which combination of IPS, DLP, and malware protection practices would provide comprehensive threat coverage for an organization's cloud-connected network traffic?

9 / 10

Which factor would most influence how an organization tunes its IPS to balance threat detection against the risk of blocking legitimate business traffic?

10 / 10

Which statement accurately describes why IPS, DLP, and malware protection are considered complementary rather than redundant security controls?

Your score is

The average score is 0%

0%