CCNP Security 350-701 SCOR Practice Test 9

CCNP Security 350-701 SCOR Practice Test 9 (Hard) - Cisco ASA Firewall Fundamentals

CISCO CCNP Security Exam Logo

1 / 10

On a Cisco ASA, which concept determines the default rule that traffic can flow from a higher-security-level interface to a lower-security-level interface without an explicit access list, while the reverse requires one?

2 / 10

Which ASA feature allows an administrator to translate multiple internal private IP addresses to a single public IP address using different port numbers, conserving public address space?

3 / 10

Which ASA object type allows an administrator to define a reusable, named group of IP addresses or networks that can be referenced across multiple access control rules for easier management?

4 / 10

Which ASA inspection feature is responsible for tracking the state of active connections (such as TCP sequence numbers and connection state) to permit legitimate return traffic without requiring an explicit inbound rule for every response?

5 / 10

An administrator configures an ASA access control list that explicitly denies traffic from a specific host, placed above a broader permit rule for that host's subnet. Which ASA ACL processing behavior determines the outcome for that host's traffic?

6 / 10

Which ASA high-availability feature allows two ASA appliances to operate as a redundant pair, with one actively passing traffic while the other stands by ready to take over if the active unit fails?

7 / 10

Which ASA feature would be most appropriate for permitting a specific external partner's IP address to reach an internal web server on TCP port 443, while denying all other external access to that server?

8 / 10

Which ASA troubleshooting command output would most directly show whether a specific connection is currently being tracked in the stateful connection table, including its state and translated addresses?

9 / 10

Which ASA concept describes traffic originating from a lower-security interface destined to a higher-security interface being denied by default, requiring an explicit access-list permit to allow it through?

10 / 10

Which ASA design practice would best support both high availability and consistent security policy enforcement for a business-critical internet-facing application, while minimizing administrative overhead for ongoing rule changes?

Your score is

The average score is 0%

0%