350-401 exam dumps

350-401 practice question 291 of 631

Implementing Cisco Enterprise Network Core Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-401 Question 291

Select 3

An organization is deploying endpoint security measures to protect its enterprise network. Which of the following actions should the network administrator implement to ensure endpoints are protected from malware and unauthorized access?

  1. A

    Enforce regular software and firmware updates on endpoint devices.

  2. B

    Configure endpoint devices to use only pre-approved applications.

  3. C

    Disable all endpoint device firewalls to minimize network traffic complexity.

  4. D

    Deploy endpoint detection and response (EDR) solutions for real-time monitoring.

  5. E

    Allow end-users to configure their own security settings for flexibility.

Show answer and explanation

Correct answers: A, B, D

Explanation

Endpoint security involves implementing measures to protect devices from malware, unauthorized access, and other threats. Enforcing updates ensures vulnerabilities are patched, using pre-approved applications minimizes risks, and deploying EDR solutions provides real-time threat detection. Disabling firewalls or allowing end-users to configure their own security settings weakens endpoint security and should be avoided.

  • A. Correct.

    Regular software and firmware updates address vulnerabilities and patch security flaws that can be exploited by attackers, making this a critical step in endpoint security.

  • B. Correct.

    Restricting endpoint devices to use only pre-approved applications reduces the attack surface by preventing the execution of malicious or unauthorized software.

  • C. Incorrect.

    Disabling endpoint firewalls makes devices more vulnerable to attacks and is counterproductive to endpoint security principles.

  • D. Correct.

    EDR solutions provide real-time monitoring and threat detection, enabling quick responses to potential security incidents, which is a key aspect of endpoint security.

  • E. Incorrect.

    Allowing end-users to configure their own security settings introduces inconsistencies and increases the risk of misconfigurations, which could lead to vulnerabilities.

Timed practice exam

Take a 350-401 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam