Cisco CCNA 200-301 Core Security Concepts Practice Test

Topic 32 focuses on Core Security Concepts for the Cisco Certified Network Associate (CCNA) certification and the 200-301 exam, using Cisco networking and Cisco IOS concepts where relevant. For broader exam preparation, review the Cisco CCNA 200-301 Exam Dumps page. Each question includes a concise explanation of the correct answer and the technical reason the other choices are incorrect.

Question 1

What is a potential cause of an unwanted security incident or harm to an information system?

  1. Mitigation
  2. Social engineering
  3. Threat
  4. Phishing

Correct Answer: C

 

Correct Answer

Answer C is correct because the selected answer describes a potential cause of an unwanted security incident or harm to an information system.

Incorrect Answers

Answer A is incorrect because the “Mitigation” option describes a different concept: a control or action intended to reduce the likelihood or impact of a security risk.

Answer B is incorrect because the “Social engineering” option describes a different concept: Manipulating people rather than only technical controls to obtain unauthorized access or information.

Answer D is incorrect because the “Phishing” option describes a different concept: a social-engineering technique that uses deceptive messages to trick users into revealing information or performing unsafe actions.

 

Question 2

Which weakness could be exploited to compromise a system or network?

  1. Mitigation
  2. Vulnerability
  3. Denial of service
  4. Exploit

Correct Answer: B

 

Correct Answer

Answer B is correct because the selected answer describes a weakness that could be exploited to compromise a system or network.

Incorrect Answers

Answer A is incorrect because the “Mitigation” option describes a different concept: a control or action intended to reduce the likelihood or impact of a security risk.

Answer C is incorrect because the “Denial of service” option describes a different concept: an attack intended to reduce or eliminate the availability of a network service or resource.

Answer D is incorrect because the “Exploit” option describes a different concept: a technique or code that takes advantage of a vulnerability.

 

Question 3

Which technique or code takes advantage of a vulnerability?

  1. Attack surface
  2. Exploit
  3. Risk
  4. Threat

Correct Answer: B

 

Correct Answer

Answer B is correct because the selected answer describes a technique or code that takes advantage of a vulnerability.

Incorrect Answers

Answer A is incorrect because the “Attack surface” option describes a different concept: the collection of exposed interfaces, services, users, and other entry points an attacker could target.

Answer C is incorrect because the “Risk” option describes a different concept: the potential for loss or harm based on the likelihood and impact of a security event.

Answer D is incorrect because the “Threat” option describes a different concept: a potential cause of an unwanted security incident or harm to an information system.

 

Question 4

Which potential for loss or harm is based on the likelihood and impact of a security event?

  1. Risk
  2. Denial of service
  3. Mitigation
  4. Phishing

Correct Answer: A

 

Correct Answer

Answer A is correct because the selected answer describes the potential for loss or harm based on the likelihood and impact of a security event.

Incorrect Answers

Answer B is incorrect because the “Denial of service” option describes a different concept: an attack intended to reduce or eliminate the availability of a network service or resource.

Answer C is incorrect because the “Mitigation” option describes a different concept: a control or action intended to reduce the likelihood or impact of a security risk.

Answer D is incorrect because the “Phishing” option describes a different concept: a social-engineering technique that uses deceptive messages to trick users into revealing information or performing unsafe actions.

 

Question 5

What is the collection of exposed interfaces, services, users, and other entry points an attacker could target?

  1. Attack surface
  2. Social engineering
  3. Threat
  4. Phishing

Correct Answer: A

 

Correct Answer

Answer A is correct because the selected answer describes the collection of exposed interfaces, services, users, and other entry points an attacker could target.

Incorrect Answers

Answer B is incorrect because the “Social engineering” option describes a different concept: Manipulating people rather than only technical controls to obtain unauthorized access or information.

Answer C is incorrect because the “Threat” option describes a different concept: a potential cause of an unwanted security incident or harm to an information system.

Answer D is incorrect because the “Phishing” option describes a different concept: a social-engineering technique that uses deceptive messages to trick users into revealing information or performing unsafe actions.

 

Question 6

Which control or action is intended to reduce the likelihood or impact of a security risk?

  1. Vulnerability
  2. Threat
  3. Denial of service
  4. Mitigation

Correct Answer: D

 

Correct Answer

Answer D is correct because the selected answer describes a control or action intended to reduce the likelihood or impact of a security risk.

Incorrect Answers

Answer A is incorrect because the “Vulnerability” option describes a different concept: a weakness that could be exploited to compromise a system or network.

Answer B is incorrect because the “Threat” option describes a different concept: a potential cause of an unwanted security incident or harm to an information system.

Answer C is incorrect because the “Denial of service” option describes a different concept: an attack intended to reduce or eliminate the availability of a network service or resource.

 

Question 7

Which term describes malicious software designed to disrupt, damage, spy on, or gain unauthorized access to systems?

  1. Malware
  2. Mitigation
  3. Social engineering
  4. Risk

Correct Answer: A

 

Correct Answer

Answer A is correct because it describes malicious software designed to disrupt, damage, spy on, or gain unauthorized access to systems.

Incorrect Answers

Answer B is incorrect because the “Mitigation” option describes a different concept: a control or action intended to reduce the likelihood or impact of a security risk.

Answer C is incorrect because the “Social engineering” option describes a different concept: Manipulating people rather than only technical controls to obtain unauthorized access or information.

Answer D is incorrect because the “Risk” option describes a different concept: the potential for loss or harm based on the likelihood and impact of a security event.

 

Question 8

Which social-engineering technique uses deceptive messages to trick users into revealing information or performing unsafe actions?

  1. Denial of service
  2. Threat
  3. Risk
  4. Phishing

Correct Answer: D

 

Correct Answer

Answer D is correct because the selected answer describes a social-engineering technique that uses deceptive messages to trick users into revealing information or performing unsafe actions.

Incorrect Answers

Answer A is incorrect because the “Denial of service” option describes a different concept: an attack intended to reduce or eliminate the availability of a network service or resource.

Answer B is incorrect because the “Threat” option describes a different concept: a potential cause of an unwanted security incident or harm to an information system.

Answer C is incorrect because the “Risk” option describes a different concept: the potential for loss or harm based on the likelihood and impact of a security event.

 

Question 9

Which attack is intended to reduce or eliminate the availability of a network service or resource?

  1. Vulnerability
  2. Phishing
  3. Social engineering
  4. Denial of service

Correct Answer: D

 

Correct Answer

Answer D is correct because the selected answer describes an attack intended to reduce or eliminate the availability of a network service or resource.

Incorrect Answers

Answer A is incorrect because the “Vulnerability” option describes a different concept: a weakness that could be exploited to compromise a system or network.

Answer B is incorrect because the “Phishing” option describes a different concept: a social-engineering technique that uses deceptive messages to trick users into revealing information or performing unsafe actions.

Answer C is incorrect because the “Social engineering” option describes a different concept: Manipulating people rather than only technical controls to obtain unauthorized access or information.

 

Question 10

Which term describes manipulating people rather than only technical controls to obtain unauthorized access or information?

  1. Social engineering
  2. Vulnerability
  3. Malware
  4. Exploit

Correct Answer: A

 

Correct Answer

Answer A is correct because Manipulating people rather than only technical controls to obtain unauthorized access or information.

Incorrect Answers

Answer B is incorrect because the “Vulnerability” option describes a different concept: a weakness that could be exploited to compromise a system or network.

Answer C is incorrect because the “Malware” option describes a different concept: Malicious software designed to disrupt, damage, spy on, or gain unauthorized access to systems.

Answer D is incorrect because the “Exploit” option describes a different concept: a technique or code that takes advantage of a vulnerability.

 

Question 11

For Threat, which statement is accurate?

  1. Malicious software designed to disrupt, damage, spy on, or gain unauthorized access to systems.
  2. The potential for loss or harm based on the likelihood and impact of a security event.
  3. A control or action intended to reduce the likelihood or impact of a security risk.
  4. A potential cause of an unwanted security incident or harm to an information system.

Correct Answer: D

 

Correct Answer

Answer D is correct because the selected answer describes a potential cause of an unwanted security incident or harm to an information system.

Incorrect Answers

Answer A is incorrect because the “Malware” option describes a different concept: Malicious software designed to disrupt, damage, spy on, or gain unauthorized access to systems.

Answer B is incorrect because the “Risk” option describes a different concept: the potential for loss or harm based on the likelihood and impact of a security event.

Answer C is incorrect because the “Mitigation” option describes a different concept: a control or action intended to reduce the likelihood or impact of a security risk.

 

Question 12

For Vulnerability, which statement is accurate?

  1. A weakness that could be exploited to compromise a system or network.
  2. A technique or code that takes advantage of a vulnerability.
  3. An attack intended to reduce or eliminate the availability of a network service or resource.
  4. A control or action intended to reduce the likelihood or impact of a security risk.

Correct Answer: A

 

Correct Answer

Answer A is correct because it accurately defines Vulnerability. The matching definition is: A weakness that could be exploited to compromise a system or network.

Incorrect Answers

Answer B is incorrect because the “Exploit” option describes a different concept: a technique or code that takes advantage of a vulnerability.

Answer C is incorrect because the “Denial of service” option describes a different concept: an attack intended to reduce or eliminate the availability of a network service or resource.

Answer D is incorrect because the “Mitigation” option describes a different concept: a control or action intended to reduce the likelihood or impact of a security risk.

 

Question 13

For Exploit, which statement is accurate?

  1. A weakness that could be exploited to compromise a system or network.
  2. The collection of exposed interfaces, services, users, and other entry points an attacker could target.
  3. A social-engineering technique that uses deceptive messages to trick users into revealing information or performing unsafe actions.
  4. A technique or code that takes advantage of a vulnerability.

Correct Answer: D

 

Correct Answer

Answer D is correct because the choice accurately describes Exploit: A technique or code that takes advantage of a vulnerability.

Incorrect Answers

Answer A is incorrect because the “Vulnerability” option describes a different concept: a weakness that could be exploited to compromise a system or network.

Answer B is incorrect because the “Attack surface” option describes a different concept: the collection of exposed interfaces, services, users, and other entry points an attacker could target.

Answer C is incorrect because the “Phishing” option describes a different concept: a social-engineering technique that uses deceptive messages to trick users into revealing information or performing unsafe actions.

 

Question 14

For Risk, which statement is accurate?

  1. An attack intended to reduce or eliminate the availability of a network service or resource.
  2. The potential for loss or harm based on the likelihood and impact of a security event.
  3. A weakness that could be exploited to compromise a system or network.
  4. Manipulating people rather than only technical controls to obtain unauthorized access or information.

Correct Answer: B

 

Correct Answer

Answer B is correct because the selected answer describes the potential for loss or harm based on the likelihood and impact of a security event.

Incorrect Answers

Answer A is incorrect because the “Denial of service” option describes a different concept: an attack intended to reduce or eliminate the availability of a network service or resource.

Answer C is incorrect because the “Vulnerability” option describes a different concept: a weakness that could be exploited to compromise a system or network.

Answer D is incorrect because the “Social engineering” option describes a different concept: Manipulating people rather than only technical controls to obtain unauthorized access or information.

 

Question 15

For Attack surface, which statement is accurate?

  1. Manipulating people rather than only technical controls to obtain unauthorized access or information.
  2. The collection of exposed interfaces, services, users, and other entry points an attacker could target.
  3. An attack intended to reduce or eliminate the availability of a network service or resource.
  4. A technique or code that takes advantage of a vulnerability.

Correct Answer: B

 

Correct Answer

Answer B is correct because the selected answer describes the collection of exposed interfaces, services, users, and other entry points an attacker could target.

Incorrect Answers

Answer A is incorrect because the “Social engineering” option describes a different concept: Manipulating people rather than only technical controls to obtain unauthorized access or information.

Answer C is incorrect because the “Denial of service” option describes a different concept: an attack intended to reduce or eliminate the availability of a network service or resource.

Answer D is incorrect because the “Exploit” option describes a different concept: a technique or code that takes advantage of a vulnerability.

 

Question 16

For Mitigation, which statement is accurate?

  1. A control or action intended to reduce the likelihood or impact of a security risk.
  2. A potential cause of an unwanted security incident or harm to an information system.
  3. A social-engineering technique that uses deceptive messages to trick users into revealing information or performing unsafe actions.
  4. A technique or code that takes advantage of a vulnerability.

Correct Answer: A

 

Correct Answer

Answer A is correct because it accurately defines Mitigation. The matching definition is: A control or action intended to reduce the likelihood or impact of a security risk.

Incorrect Answers

Answer B is incorrect because the “Threat” option describes a different concept: a potential cause of an unwanted security incident or harm to an information system.

Answer C is incorrect because the “Phishing” option describes a different concept: a social-engineering technique that uses deceptive messages to trick users into revealing information or performing unsafe actions.

Answer D is incorrect because the “Exploit” option describes a different concept: a technique or code that takes advantage of a vulnerability.

 

Question 17

For Malware, which statement is accurate?

  1. A weakness that could be exploited to compromise a system or network.
  2. Manipulating people rather than only technical controls to obtain unauthorized access or information.
  3. Malicious software designed to disrupt, damage, spy on, or gain unauthorized access to systems.
  4. The potential for loss or harm based on the likelihood and impact of a security event.

Correct Answer: C

 

Correct Answer

Answer C is correct because the choice accurately describes Malware: Malicious software designed to disrupt, damage, spy on, or gain unauthorized access to systems.

Incorrect Answers

Answer A is incorrect because the “Vulnerability” option describes a different concept: a weakness that could be exploited to compromise a system or network.

Answer B is incorrect because the “Social engineering” option describes a different concept: Manipulating people rather than only technical controls to obtain unauthorized access or information.

Answer D is incorrect because the “Risk” option describes a different concept: the potential for loss or harm based on the likelihood and impact of a security event.

 

Question 18

For Phishing, which statement is accurate?

  1. A social-engineering technique that uses deceptive messages to trick users into revealing information or performing unsafe actions.
  2. Malicious software designed to disrupt, damage, spy on, or gain unauthorized access to systems.
  3. A weakness that could be exploited to compromise a system or network.
  4. The collection of exposed interfaces, services, users, and other entry points an attacker could target.

Correct Answer: A

 

Correct Answer

Answer A is correct because the selected answer describes a social-engineering technique that uses deceptive messages to trick users into revealing information or performing unsafe actions.

Incorrect Answers

Answer B is incorrect because the “Malware” option describes a different concept: Malicious software designed to disrupt, damage, spy on, or gain unauthorized access to systems.

Answer C is incorrect because the “Vulnerability” option describes a different concept: a weakness that could be exploited to compromise a system or network.

Answer D is incorrect because the “Attack surface” option describes a different concept: the collection of exposed interfaces, services, users, and other entry points an attacker could target.

 

Question 19

For Denial of service, which statement is accurate?

  1. A social-engineering technique that uses deceptive messages to trick users into revealing information or performing unsafe actions.
  2. An attack intended to reduce or eliminate the availability of a network service or resource.
  3. The collection of exposed interfaces, services, users, and other entry points an attacker could target.
  4. A weakness that could be exploited to compromise a system or network.

Correct Answer: B

 

Correct Answer

Answer B is correct because the selected answer describes an attack intended to reduce or eliminate the availability of a network service or resource.

Incorrect Answers

Answer A is incorrect because the “Phishing” option describes a different concept: a social-engineering technique that uses deceptive messages to trick users into revealing information or performing unsafe actions.

Answer C is incorrect because the “Attack surface” option describes a different concept: the collection of exposed interfaces, services, users, and other entry points an attacker could target.

Answer D is incorrect because the “Vulnerability” option describes a different concept: a weakness that could be exploited to compromise a system or network.

 

Question 20

For Social engineering, which statement is accurate?

  1. An attack intended to reduce or eliminate the availability of a network service or resource.
  2. A weakness that could be exploited to compromise a system or network.
  3. The collection of exposed interfaces, services, users, and other entry points an attacker could target.
  4. Manipulating people rather than only technical controls to obtain unauthorized access or information.

Correct Answer: D

 

Correct Answer

Answer D is correct because it accurately defines Social engineering. The matching definition is: Manipulating people rather than only technical controls to obtain unauthorized access or information.

Incorrect Answers

Answer A is incorrect because the “Denial of service” option describes a different concept: an attack intended to reduce or eliminate the availability of a network service or resource.

Answer B is incorrect because the “Vulnerability” option describes a different concept: a weakness that could be exploited to compromise a system or network.

Answer C is incorrect because the “Attack surface” option describes a different concept: the collection of exposed interfaces, services, users, and other entry points an attacker could target.

 

Question 21

In a campus security deployment, the team must identify the technology that provides the following function: A potential cause of an unwanted security incident or harm to an information system. Which option should be selected?

  1. Vulnerability
  2. Denial of service
  3. Phishing
  4. Threat

Correct Answer: D

 

Correct Answer

Answer D is correct because the operational requirement in the stem maps to Threat: A potential cause of an unwanted security incident or harm to an information system.

Incorrect Answers

Answer A is incorrect because the “Vulnerability” option describes a different concept: a weakness that could be exploited to compromise a system or network.

Answer B is incorrect because the “Denial of service” option describes a different concept: an attack intended to reduce or eliminate the availability of a network service or resource.

Answer C is incorrect because the “Phishing” option describes a different concept: a social-engineering technique that uses deceptive messages to trick users into revealing information or performing unsafe actions.

 

Question 22

A security assessment finds a software weakness that an attacker could exploit. Which security concept names the weakness itself?

  1. Exploit
  2. Threat
  3. Vulnerability
  4. Phishing

Correct Answer: C

 

Correct Answer

Answer C is correct because Vulnerability is the most precise fit for the stated requirement. A weakness that could be exploited to compromise a system or network.

Incorrect Answers

Answer A is incorrect because the “Exploit” option describes a different concept: a technique or code that takes advantage of a vulnerability.

Answer B is incorrect because the “Threat” option describes a different concept: a potential cause of an unwanted security incident or harm to an information system.

Answer D is incorrect because the “Phishing” option describes a different concept: a social-engineering technique that uses deceptive messages to trick users into revealing information or performing unsafe actions.

 

Question 23

During a defensive configuration review, the design calls for the following capability: A technique or code that takes advantage of a vulnerability. Which option names that capability most accurately?

  1. Threat
  2. Risk
  3. Exploit
  4. Vulnerability

Correct Answer: C

 

Correct Answer

Answer C is correct because the scenario is describing the role of Exploit. A technique or code that takes advantage of a vulnerability.

Incorrect Answers

Answer A is incorrect because the “Threat” option describes a different concept: a potential cause of an unwanted security incident or harm to an information system.

Answer B is incorrect because the “Risk” option describes a different concept: the potential for loss or harm based on the likelihood and impact of a security event.

Answer D is incorrect because the “Vulnerability” option describes a different concept: a weakness that could be exploited to compromise a system or network.

 

Question 24

A team evaluates both the probability of a damaging event and the loss it would cause. Which security concept combines these considerations?

  1. Attack surface
  2. Phishing
  3. Risk
  4. Denial of service

Correct Answer: C

 

Correct Answer

Answer C is correct because Risk directly provides the function required by the scenario. The potential for loss or harm based on the likelihood and impact of a security event.

Incorrect Answers

Answer A is incorrect because the “Attack surface” option describes a different concept: the collection of exposed interfaces, services, users, and other entry points an attacker could target.

Answer B is incorrect because the “Phishing” option describes a different concept: a social-engineering technique that uses deceptive messages to trick users into revealing information or performing unsafe actions.

Answer D is incorrect because the “Denial of service” option describes a different concept: an attack intended to reduce or eliminate the availability of a network service or resource.

 

Question 25

While working on an access-control investigation, an administrator encounters this requirement: The collection of exposed interfaces, services, users, and other entry points an attacker could target. Which answer is the most precise match?

  1. Denial of service
  2. Attack surface
  3. Threat
  4. Mitigation

Correct Answer: B

 

Correct Answer

Answer B is correct because the operational requirement in the stem maps to Attack surface: The collection of exposed interfaces, services, users, and other entry points an attacker could target.

Incorrect Answers

Answer A is incorrect because the “Denial of service” option describes a different concept: an attack intended to reduce or eliminate the availability of a network service or resource.

Answer C is incorrect because the “Threat” option describes a different concept: a potential cause of an unwanted security incident or harm to an information system.

Answer D is incorrect because the “Mitigation” option describes a different concept: a control or action intended to reduce the likelihood or impact of a security risk.

 

Question 26

In a campus security deployment, the team must identify the technology that provides the following function: A control or action intended to reduce the likelihood or impact of a security risk. Which option should be selected?

  1. Denial of service
  2. Exploit
  3. Mitigation
  4. Risk

Correct Answer: C

 

Correct Answer

Answer C is correct because Mitigation is the most precise fit for the stated requirement. A control or action intended to reduce the likelihood or impact of a security risk.

Incorrect Answers

Answer A is incorrect because the “Denial of service” option describes a different concept: an attack intended to reduce or eliminate the availability of a network service or resource.

Answer B is incorrect because the “Exploit” option describes a different concept: a technique or code that takes advantage of a vulnerability.

Answer D is incorrect because the “Risk” option describes a different concept: the potential for loss or harm based on the likelihood and impact of a security event.

 

Question 27

A host contains software written to steal data and gain unauthorized access. Which broad category describes the software?

  1. Mitigation
  2. Risk
  3. Malware
  4. Social engineering

Correct Answer: C

 

Correct Answer

Answer C is correct because the scenario is describing the role of Malware. Malicious software designed to disrupt, damage, spy on, or gain unauthorized access to systems.

Incorrect Answers

Answer A is incorrect because the “Mitigation” option describes a different concept: a control or action intended to reduce the likelihood or impact of a security risk.

Answer B is incorrect because the “Risk” option describes a different concept: the potential for loss or harm based on the likelihood and impact of a security event.

Answer D is incorrect because the “Social engineering” option describes a different concept: Manipulating people rather than only technical controls to obtain unauthorized access or information.

 

Question 28

During a defensive configuration review, the design calls for the following capability: A social-engineering technique that uses deceptive messages to trick users into revealing information or performing unsafe actions. Which option names that capability most accurately?

  1. Malware
  2. Phishing
  3. Exploit
  4. Denial of service

Correct Answer: B

 

Correct Answer

Answer B is correct because Phishing directly provides the function required by the scenario. A social-engineering technique that uses deceptive messages to trick users into revealing information or performing unsafe actions.

Incorrect Answers

Answer A is incorrect because the “Malware” option describes a different concept: Malicious software designed to disrupt, damage, spy on, or gain unauthorized access to systems.

Answer C is incorrect because the “Exploit” option describes a different concept: a technique or code that takes advantage of a vulnerability.

Answer D is incorrect because the “Denial of service” option describes a different concept: an attack intended to reduce or eliminate the availability of a network service or resource.

 

Question 29

An attacker overwhelms a service so legitimate clients cannot use it. Which attack category describes the availability impact?

  1. Phishing
  2. Denial of service
  3. Malware
  4. Threat

Correct Answer: B

 

Correct Answer

Answer B is correct because the operational requirement in the stem maps to Denial of service: An attack intended to reduce or eliminate the availability of a network service or resource.

Incorrect Answers

Answer A is incorrect because the “Phishing” option describes a different concept: a social-engineering technique that uses deceptive messages to trick users into revealing information or performing unsafe actions.

Answer C is incorrect because the “Malware” option describes a different concept: Malicious software designed to disrupt, damage, spy on, or gain unauthorized access to systems.

Answer D is incorrect because the “Threat” option describes a different concept: a potential cause of an unwanted security incident or harm to an information system.

 

Question 30

While working on an access-control investigation, an administrator encounters this requirement: Manipulating people rather than only technical controls to obtain unauthorized access or information. Which answer is the most precise match?

  1. Social engineering
  2. Phishing
  3. Threat
  4. Denial of service

Correct Answer: A

 

Correct Answer

Answer A is correct because Social engineering is the most precise fit for the stated requirement. Manipulating people rather than only technical controls to obtain unauthorized access or information.

Incorrect Answers

Answer B is incorrect because the “Phishing” option describes a different concept: a social-engineering technique that uses deceptive messages to trick users into revealing information or performing unsafe actions.

Answer C is incorrect because the “Threat” option describes a different concept: a potential cause of an unwanted security incident or harm to an information system.

Answer D is incorrect because the “Denial of service” option describes a different concept: an attack intended to reduce or eliminate the availability of a network service or resource.

img