CCNP Data Center 350-601 DCCOR Practice Test 28

CCNP Data Center 350-601 DCCOR Practice Test 28 - Network Security - First-Hop Security, Keychain Authentication, and MACsec

CCNP Data Center Exam Logo

1 / 10

What is the primary purpose of Dynamic ARP Inspection (DAI) as a first-hop security feature?

2 / 10

A host on an access VLAN with DHCP Snooping enabled is unable to obtain an IP address from a legitimate DHCP server. What is a likely cause?

3 / 10

What is a benefit of using keychain authentication for routing protocol neighbor relationships (such as OSPF or BGP) in a data center fabric?

4 / 10

Two OSPF neighbors using keychain authentication fail to maintain their adjacency after a scheduled key rotation. What should be verified first?

5 / 10

A design team must secure point-to-point Ethernet links between data center pods against eavesdropping and tampering, in addition to existing Layer 3 protections. Which technology should be implemented at Layer 2?

6 / 10

How does DHCP Snooping's trusted/untrusted port classification relate to the effectiveness of Dynamic ARP Inspection on the same switch?

7 / 10

When deciding whether to enable MACsec on inter-switch links within a single secure data center versus only on links leaving the data center to less trusted locations, what is a key decision factor?

8 / 10

Which command is commonly used to verify that DHCP Snooping is enabled and to view the current DHCP Snooping binding table on a Cisco switch?

9 / 10

What is the relationship between keychain authentication and the overall security of a routing protocol's control plane in a data center fabric?

10 / 10

A security audit recommends implementing defense-in-depth for a data center's Layer 2 and Layer 3 infrastructure. Which combination of features addresses both layers?

Your score is

The average score is 0%

0%