350-401 exam dumps

350-401 practice question 283 of 631

Implementing Cisco Enterprise Network Core Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-401 Question 283

Select 3

An organization is designing a new network security solution for its enterprise network. The design must ensure that unauthorized devices cannot connect to the network, that sensitive data is encrypted in transit, and that there is a mechanism to detect and respond to attacks from both internal and external sources. Which combination of network security components should be included to meet these requirements?

  1. A

    802.1X authentication for network access control

  2. B

    SSL/TLS for encrypting sensitive data in transit

  3. C

    Network Address Translation (NAT) for hiding internal IP addresses

  4. D

    Intrusion Detection and Prevention Systems (IDPS) for attack detection and response

  5. E

    Static routing for improved traffic control

Show answer and explanation

Correct answers: A, B, D

Explanation

To meet the security requirements, the network design must include components that address access control (802.1X), encryption of data in transit (SSL/TLS), and attack detection and response capabilities (IDPS). These solutions work together to protect the network from unauthorized devices, secure sensitive data, and monitor for malicious activity. NAT and static routing, while useful in specific scenarios, do not address the specific security needs outlined in this scenario.

  • A. Correct.

    802.1X authentication provides port-based network access control, ensuring that only authorized devices can connect to the network. This directly addresses the requirement to block unauthorized devices.

  • B. Correct.

    SSL/TLS is a critical component for ensuring that sensitive data is encrypted during transit, meeting the requirement for data security.

  • C. Incorrect.

    Network Address Translation (NAT) is primarily used for IP address translation and does not provide encryption, access control, or attack detection. It is not relevant to the requirements in this scenario.

  • D. Correct.

    Intrusion Detection and Prevention Systems (IDPS) are designed to monitor network traffic for malicious activity and respond to attacks. This fulfills the need for attack detection and response.

  • E. Incorrect.

    Static routing is used for controlling traffic flow in the network but does not contribute to access control, encryption, or attack detection. It is not pertinent to the security requirements described.

Timed practice exam

Take a 350-401 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam