CCNP Security 300-745 SDSI Practice Test 2

CCNP Security 300-745 SDSI Practice Test 2 (Hard) - Identity Threat Protection - MFA, Passwordless, Continuous Trust, and Identity Intelligence

CISCO CCNP Security Exam Logo

1 / 10

Which identity threat protection approach would most directly reduce the risk of an attacker successfully authenticating using a stolen static password alone?

2 / 10

Which authentication approach eliminates the shared-secret password entirely in favor of cryptographic key pairs or biometric-backed credentials bound to a specific device?

3 / 10

Which principle best describes a continuous trust (continuous authentication/evaluation) model for identity, as opposed to a one-time login model?

4 / 10

Which capability does identity intelligence provide that supports proactive identity threat protection design?

5 / 10

Which design scenario would most benefit from deploying phishing-resistant MFA (such as FIDO2 security keys or platform passkeys) rather than SMS-based one-time codes?

6 / 10

Which risk would most likely result from a design that relies solely on SMS-based one-time passcodes as the only MFA factor for privileged accounts?

7 / 10

Which combination of identity threat protection design elements would provide the strongest protection for an organization's privileged and executive accounts?

8 / 10

Which factor would most influence how aggressively a design team applies continuous trust reevaluation (such as frequent step-up authentication challenges) for a given user population?

9 / 10

Which troubleshooting step would be appropriate if legitimate users report being repeatedly challenged with step-up authentication despite no apparent change in their device or location?

10 / 10

Which statement accurately describes why identity intelligence is considered a valuable complement to MFA and continuous trust rather than a redundant capability?

Your score is

The average score is 0%

0%