Which of the following helps the security of the network design to align with industry best practices?
A. Reference architectures
B. Licensing agreement
C. Service-level agreement
D. Memorandum of understanding
Show Answer
Correct Answer: A
Explanation: Reference architectures provide established design patterns and security guidance that help ensure a network design aligns with industry best practices.
Question 22
A developer reports errors when trying to access a web application. The developer uses Postman to troubleshoot and receives the following error:
Which of the following is the cause of the issue?
A. Requested element not found
B. Lack of user authentication
C. Too restrictive NGFW rule
D. Incorrect HTTP redirection
Show Answer
Correct Answer: B
Explanation: A 403 Forbidden response means the server understood the request but denied access, commonly because the user lacks valid authentication or authorization. A missing resource would typically return 404, while a redirection issue would produce a redirect response.
Question 23
A network architect is choosing design options for a new SD-WAN installation that has the following requirements:
All network traffic from the cloud must pass through inspection devices in a dedicated data center.
Ensure redundancy.
Centralize egress traffic.
Which of the following network topologies best meets these requirements?
A. Point-to-point
B. Hub-and-spoke
C. Star
D. Partial mesh
Show Answer
Correct Answer: B
Explanation: A hub-and-spoke topology routes site and cloud traffic through a central hub, where it can be inspected and centrally egressed. Redundant hub connections or multiple hubs can provide resilience.
Question 24
Server A (10.2.3.9) needs to access Server B (10.2.2.7) within the cloud environment since they are segmented into different network sections. All external inbound traffic must be blocked to those servers. Which of the following need to be configured to appropriately secure the cloud network? (Choose two.)
A. Network security group rule: allow 10.2.3.9 to 10.2.2.7
B. Network security group rule: allow 10.2.0.0/16 to 0.0.0.0/0
C. Network security group rule: deny 0.0.0.0/0 to 10.2.0.0/16
D. Firewall rule: deny 10.2.0.0/16 to 0.0.0.0/0
E. Firewall rule: allow 10.2.0.0/16 to 0.0.0.0/0
F. Network security group rule: deny 10.2.0.0/16 to 0.0.0.0/0
Show Answer
Correct Answer: A, C
Explanation: Allow traffic from Server A (10.2.3.9) to Server B (10.2.2.7), and deny other inbound traffic to the internal network. Configure the allow rule with higher priority than the deny rule so the specific Server A exception works.
Question 25
A network architect needs to build a new data center for a large company that has business units that process retail financial transactions. Which of the following information should the architect request from the company?
A. Regulatory requirements
B. Statement of work
C. Business case study
D. Internal reference architecture
Show Answer
Correct Answer: A
Explanation: Because the data center will support retail financial transactions, the architect should request the applicable regulatory and compliance requirements first. These requirements—such as PCI DSS—can constrain the facility’s security, network, and operational design.
Question 26
After a company migrated all services to the cloud, the security auditor discovers many users have administrator roles on different services. The company needs a solution that:
Protects the services on the cloud.
Limits access to administrative roles.
Creates a policy to approve requests for administrative roles on critical services within a limited time.
Forces password rotation for administrative roles.
Audits usage of administrative roles.
Which of the following is the best way to meet the company's requirements?
A. Privileged access management
B. Session-based token
C. Conditional access
D. Access control list
Show Answer
Correct Answer: A
Explanation: Privileged access management (PAM) protects cloud services by restricting and governing privileged accounts. It can require approval for time-limited administrative access, enforce password rotation, and audit privileged activity.
Question 27
A cloud engineer is planning to build VMs in a public cloud environment for a cloud migration. A cloud security policy restricts access to the console for new VM builds. The engineer wants to replicate the settings for each of the VMs to ensure the network settings are preconfigured. Which of the following is the best deployment method?
A. IaC template
B. Custom SDK
C. API script
D. CLI command
Show Answer
Correct Answer: A
Explanation: An IaC template declaratively defines VM and network settings, allowing consistent, repeatable deployments without using the console.
Question 28
A company has a 40Gbps network that uses a network tap to inspect the traffic using an IDS. The IDS usually performs normally except when the servers are downloading patches from their local update repository 10.10.10.139 using HTTPS. During the patch windows, the IDS cannot handle the extra load and drops a significant number of packets. Which of the following would allow a network engineer to prevent this issue without compromising the network visibility?
A. Configuring the IDS to ignore traffic from 10.10.10.139
B. Using PF_RING offload to filter out "host 10.10.10.139 and port 443"
C. Adding a "dst host 10.10.10.139" BPF on the tap
D. Scheduling a cron job to stop the IDS service during the patch window
Show Answer
Correct Answer: B
Explanation: PF_RING offload filters the known high-volume HTTPS patch traffic before it reaches the IDS inspection engine, reducing its processing load while leaving the IDS available to inspect other network traffic. The other options either filter at the wrong point, narrow visibility more broadly, or disable the IDS.
Question 29
A network engineer is working on securing the environment in the screened subnet. Before penetration testing, the engineer would like to run a scan on the servers to identify the OS, application versions, and open ports. Which of the following commands should the engineer use to obtain the information?
A. tcpdump -ni eth0 src net 10.10.10.0/28
B. nmap -A 10.10.10.0/28
C. nc -v -n 10.10.10.x 1-1000
D. hping3 -1 10.10.10.x -rand-dest -I eth0
Show Answer
Correct Answer: B
Explanation: `nmap -A` enables OS detection, service/version detection, script scanning, and traceroute. Nmap also reports discovered open ports, making it the best choice for gathering the requested server information.
Question 30
A user reports an issue connecting to a database server. The front-end application for this database is hosted on the company's web server. The network engineer has changed the network subnet that the company servers are located on along with the IP addresses of the servers. These are the new configurations:
New subnet for the servers is 10.10.10.64/27
Web server IP address is 10.10.10.101
Database server IP is 10.10.10.93
Which of the following is most likely causing the user's issue?
A. The web application server is not forwarding the requests.
B. The database server firewall is blocking the port to the database.
C. The DNS server is not resolving properly.
D. The web server does not have the correct network configuration.
Show Answer
Correct Answer: D
Explanation: A /27 subnet mask (255.255.255.224) gives the 10.10.10.64/27 subnet a usable host range of 10.10.10.65–10.10.10.94. The database server at .93 is within that range, but the web server at .101 is not, so the web server has an incorrect network configuration.
$19
Get all 81 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.