300-445 exam dumps

300-445 practice question 143 of 255

Designing and Implementing Enterprise Network Assurance. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-445 Question 143

Select 3

An enterprise organization is deploying a web-based monitoring dashboard for its network assurance platform. The platform must ensure that web traffic between users and the dashboard is encrypted and authenticated. Which of the following configurations should be implemented to achieve this requirement?

  1. A

    Enable HTTPS with a valid SSL/TLS certificate for the dashboard

  2. B

    Implement HTTP Strict Transport Security (HSTS) on the dashboard

  3. C

    Deploy a self-signed SSL/TLS certificate for HTTPS traffic

  4. D

    Configure a Web Application Firewall (WAF) in front of the dashboard

  5. E

    Use Basic HTTP authentication to secure user access

Show answer and explanation

Correct answers: A, B, D

Explanation

To ensure encrypted and authenticated access to the web-based monitoring dashboard, HTTPS with a valid SSL/TLS certificate should be enabled, and HTTP Strict Transport Security (HSTS) should be implemented to enforce HTTPS usage. Additionally, deploying a Web Application Firewall (WAF) provides further protection against web-based threats. Self-signed certificates and Basic HTTP authentication do not meet enterprise-grade security standards.

  • A. Correct.

    Enabling HTTPS with a valid SSL/TLS certificate ensures secure encryption and authentication of web traffic, which is critical for protecting sensitive data and verifying server identity.

  • B. Correct.

    HTTP Strict Transport Security (HSTS) ensures that all communications with the dashboard are performed over HTTPS, preventing downgrade attacks and ensuring consistent encryption.

  • C. Incorrect.

    Using a self-signed certificate does not provide authentication as it is not trusted by clients, thus failing to meet the requirement of secure and authenticated traffic.

  • D. Correct.

    A Web Application Firewall (WAF) provides an additional layer of security by inspecting and filtering web traffic, protecting against common web-based attacks such as SQL injection and XSS.

  • E. Incorrect.

    Basic HTTP authentication is insecure as it transmits credentials in base64 encoding without encryption, which does not meet the requirement for secure and encrypted communication.

Timed practice exam

Take a 300-445 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam