5.0 Security Fundamentals 200-301 Practice Quiz
120 exam-style questions covering 15% of the 200-301 exam. Instant feedback on every answer, progress tracking, no signup required.
This domain is part of the Cisco CCNA practice test. Each question is tagged by exam objective and difficulty so you can drill exactly the areas you need.
Sample Questions
Which description best matches Threats in CCNA Objective 5.0 Security Fundamentals?
- A. Threats are potential events or actors that can exploit weaknesses and harm systems, data, or operations.
- B. Vulnerabilities are weaknesses in systems, configurations, software, processes, or controls that can be exploited.
- C. Exploits are methods or code that take advantage of vulnerabilities to cause unauthorized behavior.
- D. Mitigation techniques reduce the likelihood or impact of threats exploiting vulnerabilities.
Threats are potential events or actors that can exploit weaknesses and harm systems, data, or operations. This is the correct answer.
Which option correctly defines Vulnerabilities?
- A. Enable secret protects privileged EXEC access using a hashed password on Cisco IOS devices.
- B. Vulnerabilities are weaknesses in systems, configurations, software, processes, or controls that can be exploited.
- C. A console password protects direct local access through the console line.
- D. A VTY password protects remote terminal access lines such as Telnet or SSH sessions.
Vulnerabilities are weaknesses in systems, configurations, software, processes, or controls that can be exploited. This is the correct answer.
A security review references Threats. Which answer best describes the security concept?
- A. Password complexity is the best match when the security scenario requires this behavior: Password complexity requires passwords to meet rules such as length, character variety, and resistance to guessing.
- B. Threats is the best match when the security scenario requires this behavior: Threats are potential events or actors that can exploit weaknesses and harm systems, data, or operations.
- C. Multifactor authentication is the best match when the security scenario requires this behavior: Multifactor authentication requires more than one authentication factor before granting access.
- D. Certificates is the best match when the security scenario requires this behavior: Certificates use public key infrastructure to support identity validation, encryption, and trust.
Threats are potential events or actors that can exploit weaknesses and harm systems, data, or operations. This matches the security scenario without confusing security concepts, device access control, VPNs, ACLs, Layer 2 security, AAA, or wireless protection. This is the correct answer.
A security review references Vulnerabilities. Which answer best describes the security concept?
- A. Standard IPv4 ACL is the best match when the security scenario requires this behavior: A standard IPv4 ACL filters traffic based on source IPv4 address.
- B. Extended IPv4 ACL is the best match when the security scenario requires this behavior: An extended IPv4 ACL filters traffic using source, destination, protocol, and port information.
- C. Vulnerabilities is the best match when the security scenario requires this behavior: Vulnerabilities are weaknesses in systems, configurations, software, processes, or controls that can be exploited.
- D. ACL implicit deny is the best match when the security scenario requires this behavior: The ACL implicit deny drops traffic that does not match any explicit permit statement.
Vulnerabilities are weaknesses in systems, configurations, software, processes, or controls that can be exploited. This matches the security scenario without confusing security concepts, device access control, VPNs, ACLs, Layer 2 security, AAA, or wireless protection. This is the correct answer.
A security review references Exploits. Which answer best describes the security concept?
- A. Authentication is the best match when the security scenario requires this behavior: Authentication verifies the identity of a user, device, or process.
- B. Authorization is the best match when the security scenario requires this behavior: Authorization determines what an authenticated user, device, or process is allowed to do.
- C. Accounting is the best match when the security scenario requires this behavior: Accounting records what users or devices did, when they did it, and sometimes what resources they used.
- D. Exploits is the best match when the security scenario requires this behavior: Exploits are methods or code that take advantage of vulnerabilities to cause unauthorized behavior.
Exploits are methods or code that take advantage of vulnerabilities to cause unauthorized behavior. This matches the security scenario without confusing security concepts, device access control, VPNs, ACLs, Layer 2 security, AAA, or wireless protection. This is the correct answer.
A Cisco security configuration or policy must be interpreted from the described behavior. Which scenario best matches Threats?
- A. A scenario points to DHCP snooping when the security evidence depends on this distinction: DHCP snooping filters DHCP messages and builds a binding table to protect against rogue DHCP servers.
- B. A scenario points to Dynamic ARP inspection when the security evidence depends on this distinction: Dynamic ARP inspection validates ARP messages to help prevent ARP spoofing attacks.
- C. A scenario points to Threats when the security evidence depends on this distinction: Threats are potential events or actors that can exploit weaknesses and harm systems, data, or operations.
- D. A scenario points to Port security when the security evidence depends on this distinction: Port security limits which MAC addresses can use a switchport and can take action when violations occur.
Threats are potential events or actors that can exploit weaknesses and harm systems, data, or operations. This distinction matters because the wrong concept would lead to the wrong control, access method, ACL behavior, Layer 2 protection, or authentication conclusion. This is the correct answer.
A Cisco security configuration or policy must be interpreted from the described behavior. Which scenario best matches Vulnerabilities?
- A. A scenario points to Threats when the security evidence depends on this distinction: Threats are potential events or actors that can exploit weaknesses and harm systems, data, or operations.
- B. A scenario points to Exploits when the security evidence depends on this distinction: Exploits are methods or code that take advantage of vulnerabilities to cause unauthorized behavior.
- C. A scenario points to Mitigation techniques when the security evidence depends on this distinction: Mitigation techniques reduce the likelihood or impact of threats exploiting vulnerabilities.
- D. A scenario points to Vulnerabilities when the security evidence depends on this distinction: Vulnerabilities are weaknesses in systems, configurations, software, processes, or controls that can be exploited.
Vulnerabilities are weaknesses in systems, configurations, software, processes, or controls that can be exploited. This distinction matters because the wrong concept would lead to the wrong control, access method, ACL behavior, Layer 2 protection, or authentication conclusion. This is the correct answer.
A Cisco security scenario requires choosing the correct fundamental protection or policy concept. Which answer applies Threats most accurately?
- A. Security training is the correct operational interpretation when the security, access-control, VPN, ACL, Layer 2, AAA, or WLAN decision depends on this exact meaning: Security training teaches users and administrators the behaviors, procedures, and skills needed to reduce risk.
- B. Physical access control is the correct operational interpretation when the security, access-control, VPN, ACL, Layer 2, AAA, or WLAN decision depends on this exact meaning: Physical access control restricts who can physically reach network devices, cabling, rooms, and infrastructure.
- C. Local passwords is the correct operational interpretation when the security, access-control, VPN, ACL, Layer 2, AAA, or WLAN decision depends on this exact meaning: Local passwords protect access to device modes, lines, or accounts configured directly on the network device.
- D. Threats is the correct operational interpretation when the security, access-control, VPN, ACL, Layer 2, AAA, or WLAN decision depends on this exact meaning: Threats are potential events or actors that can exploit weaknesses and harm systems, data, or operations.
Threats are potential events or actors that can exploit weaknesses and harm systems, data, or operations. This applies the concept at the point where a Cisco administrator must predict how a security control affects real access, traffic, or device management behavior. This is the correct answer.
Link to this quiz
Studying with a group or teaching a class? Send this address or paste the link into your notes, wiki, or course page:
https://quizbuffet.com/cisco-ccna/security-fundamentals/
<a href="https://quizbuffet.com/cisco-ccna/security-fundamentals/">Cisco CCNA Security Fundamentals practice quiz on QuizBuffet</a>
Other 200-301 Domains
- 1.0 Network Fundamentals
- 2.0 Network Access
- 3.0 IP Connectivity
- 4.0 IP Services
- 6.0 Automation and Programmability
← Back to 200-301 practice test overview
Questions are written against the published 200-301 objectives and checked for accuracy and balance before they go live. How QuizBuffet writes and reviews its questions.