CCNP Security 300-745 SDSI Practice Test 9

CCNP Security 300-745 SDSI Practice Test 9 (Hard) - Selecting Firewall Features and Architecture - Traditional, NGFW, WAF, IPS/IDS, Distributed, eBPF, and Host-Based

CISCO CCNP Security Exam Logo

1 / 10

Which firewall capability distinguishes a next-generation firewall (NGFW) from a traditional stateful firewall in terms of policy enforcement?

2 / 10

Which firewall/security function is specifically designed to protect a web application from threats targeting the application layer, such as SQL injection or cross-site scripting?

3 / 10

Which design scenario would most directly justify deploying a distributed firewall architecture (enforcing policy at each workload) rather than relying solely on a centralized perimeter firewall?

4 / 10

Which technology enables lightweight, kernel-level traffic filtering and observability directly within a Linux host's networking stack, increasingly used for host-based and cloud-native security enforcement?

5 / 10

Which firewall/detection technology distinction is most important when a design team must choose between IPS (intrusion prevention system) and IDS (intrusion detection system) deployment for a given network segment?

6 / 10

Which factor would most influence whether a design team selects a host-based firewall (agent-resident) versus a network-based firewall for protecting a specific workload?

7 / 10

Which risk would most likely result from a design that deploys a WAF to protect a web application but relies on it as the sole security control with no underlying network or host-level firewall protection?

8 / 10

Which combination of firewall and inspection technologies would provide layered, comprehensive protection for a modern enterprise running a mix of traditional data center workloads, cloud-native applications, and public-facing web applications?

9 / 10

Which troubleshooting step would be appropriate if a newly deployed distributed firewall policy begins blocking legitimate east-west traffic between two workloads that previously communicated without issue under the prior centralized perimeter-only model?

10 / 10

Which statement accurately describes why a layered combination of NGFW, WAF, distributed/host-based firewalls, and IPS is generally preferred over relying on any single firewall type for a complex enterprise environment?

Your score is

The average score is 0%

0%