Cisco CCNA 200-301 Core Security Concepts Practice Test
Topic 32 focuses on Core Security Concepts for the Cisco Certified Network Associate (CCNA) certification and the 200-301 exam, using Cisco networking and Cisco IOS concepts where relevant. For broader exam preparation, review the Cisco CCNA 200-301 Exam Dumps page. Each question includes a concise explanation of the correct answer and the technical reason the other choices are incorrect.
Question 1
What is a potential cause of an unwanted security incident or harm to an information system?
Correct Answer: C
Correct Answer
Answer C is correct because the selected answer describes a potential cause of an unwanted security incident or harm to an information system.
Incorrect Answers
Answer A is incorrect because the “Mitigation” option describes a different concept: a control or action intended to reduce the likelihood or impact of a security risk.
Answer B is incorrect because the “Social engineering” option describes a different concept: Manipulating people rather than only technical controls to obtain unauthorized access or information.
Answer D is incorrect because the “Phishing” option describes a different concept: a social-engineering technique that uses deceptive messages to trick users into revealing information or performing unsafe actions.
Question 2
Which weakness could be exploited to compromise a system or network?
Correct Answer: B
Correct Answer
Answer B is correct because the selected answer describes a weakness that could be exploited to compromise a system or network.
Incorrect Answers
Answer A is incorrect because the “Mitigation” option describes a different concept: a control or action intended to reduce the likelihood or impact of a security risk.
Answer C is incorrect because the “Denial of service” option describes a different concept: an attack intended to reduce or eliminate the availability of a network service or resource.
Answer D is incorrect because the “Exploit” option describes a different concept: a technique or code that takes advantage of a vulnerability.
Question 3
Which technique or code takes advantage of a vulnerability?
Correct Answer: B
Correct Answer
Answer B is correct because the selected answer describes a technique or code that takes advantage of a vulnerability.
Incorrect Answers
Answer A is incorrect because the “Attack surface” option describes a different concept: the collection of exposed interfaces, services, users, and other entry points an attacker could target.
Answer C is incorrect because the “Risk” option describes a different concept: the potential for loss or harm based on the likelihood and impact of a security event.
Answer D is incorrect because the “Threat” option describes a different concept: a potential cause of an unwanted security incident or harm to an information system.
Question 4
Which potential for loss or harm is based on the likelihood and impact of a security event?
Correct Answer: A
Correct Answer
Answer A is correct because the selected answer describes the potential for loss or harm based on the likelihood and impact of a security event.
Incorrect Answers
Answer B is incorrect because the “Denial of service” option describes a different concept: an attack intended to reduce or eliminate the availability of a network service or resource.
Answer C is incorrect because the “Mitigation” option describes a different concept: a control or action intended to reduce the likelihood or impact of a security risk.
Answer D is incorrect because the “Phishing” option describes a different concept: a social-engineering technique that uses deceptive messages to trick users into revealing information or performing unsafe actions.
Question 5
What is the collection of exposed interfaces, services, users, and other entry points an attacker could target?
Correct Answer: A
Correct Answer
Answer A is correct because the selected answer describes the collection of exposed interfaces, services, users, and other entry points an attacker could target.
Incorrect Answers
Answer B is incorrect because the “Social engineering” option describes a different concept: Manipulating people rather than only technical controls to obtain unauthorized access or information.
Answer C is incorrect because the “Threat” option describes a different concept: a potential cause of an unwanted security incident or harm to an information system.
Answer D is incorrect because the “Phishing” option describes a different concept: a social-engineering technique that uses deceptive messages to trick users into revealing information or performing unsafe actions.
Question 6
Which control or action is intended to reduce the likelihood or impact of a security risk?
Correct Answer: D
Correct Answer
Answer D is correct because the selected answer describes a control or action intended to reduce the likelihood or impact of a security risk.
Incorrect Answers
Answer A is incorrect because the “Vulnerability” option describes a different concept: a weakness that could be exploited to compromise a system or network.
Answer B is incorrect because the “Threat” option describes a different concept: a potential cause of an unwanted security incident or harm to an information system.
Answer C is incorrect because the “Denial of service” option describes a different concept: an attack intended to reduce or eliminate the availability of a network service or resource.
Question 7
Which term describes malicious software designed to disrupt, damage, spy on, or gain unauthorized access to systems?
Correct Answer: A
Correct Answer
Answer A is correct because it describes malicious software designed to disrupt, damage, spy on, or gain unauthorized access to systems.
Incorrect Answers
Answer B is incorrect because the “Mitigation” option describes a different concept: a control or action intended to reduce the likelihood or impact of a security risk.
Answer C is incorrect because the “Social engineering” option describes a different concept: Manipulating people rather than only technical controls to obtain unauthorized access or information.
Answer D is incorrect because the “Risk” option describes a different concept: the potential for loss or harm based on the likelihood and impact of a security event.
Question 8
Which social-engineering technique uses deceptive messages to trick users into revealing information or performing unsafe actions?
Correct Answer: D
Correct Answer
Answer D is correct because the selected answer describes a social-engineering technique that uses deceptive messages to trick users into revealing information or performing unsafe actions.
Incorrect Answers
Answer A is incorrect because the “Denial of service” option describes a different concept: an attack intended to reduce or eliminate the availability of a network service or resource.
Answer B is incorrect because the “Threat” option describes a different concept: a potential cause of an unwanted security incident or harm to an information system.
Answer C is incorrect because the “Risk” option describes a different concept: the potential for loss or harm based on the likelihood and impact of a security event.
Question 9
Which attack is intended to reduce or eliminate the availability of a network service or resource?
Correct Answer: D
Correct Answer
Answer D is correct because the selected answer describes an attack intended to reduce or eliminate the availability of a network service or resource.
Incorrect Answers
Answer A is incorrect because the “Vulnerability” option describes a different concept: a weakness that could be exploited to compromise a system or network.
Answer B is incorrect because the “Phishing” option describes a different concept: a social-engineering technique that uses deceptive messages to trick users into revealing information or performing unsafe actions.
Answer C is incorrect because the “Social engineering” option describes a different concept: Manipulating people rather than only technical controls to obtain unauthorized access or information.
Question 10
Which term describes manipulating people rather than only technical controls to obtain unauthorized access or information?
Correct Answer: A
Correct Answer
Answer A is correct because Manipulating people rather than only technical controls to obtain unauthorized access or information.
Incorrect Answers
Answer B is incorrect because the “Vulnerability” option describes a different concept: a weakness that could be exploited to compromise a system or network.
Answer C is incorrect because the “Malware” option describes a different concept: Malicious software designed to disrupt, damage, spy on, or gain unauthorized access to systems.
Answer D is incorrect because the “Exploit” option describes a different concept: a technique or code that takes advantage of a vulnerability.
Question 11
For Threat, which statement is accurate?
Correct Answer: D
Correct Answer
Answer D is correct because the selected answer describes a potential cause of an unwanted security incident or harm to an information system.
Incorrect Answers
Answer A is incorrect because the “Malware” option describes a different concept: Malicious software designed to disrupt, damage, spy on, or gain unauthorized access to systems.
Answer B is incorrect because the “Risk” option describes a different concept: the potential for loss or harm based on the likelihood and impact of a security event.
Answer C is incorrect because the “Mitigation” option describes a different concept: a control or action intended to reduce the likelihood or impact of a security risk.
Question 12
For Vulnerability, which statement is accurate?
Correct Answer: A
Correct Answer
Answer A is correct because it accurately defines Vulnerability. The matching definition is: A weakness that could be exploited to compromise a system or network.
Incorrect Answers
Answer B is incorrect because the “Exploit” option describes a different concept: a technique or code that takes advantage of a vulnerability.
Answer C is incorrect because the “Denial of service” option describes a different concept: an attack intended to reduce or eliminate the availability of a network service or resource.
Answer D is incorrect because the “Mitigation” option describes a different concept: a control or action intended to reduce the likelihood or impact of a security risk.
Question 13
For Exploit, which statement is accurate?
Correct Answer: D
Correct Answer
Answer D is correct because the choice accurately describes Exploit: A technique or code that takes advantage of a vulnerability.
Incorrect Answers
Answer A is incorrect because the “Vulnerability” option describes a different concept: a weakness that could be exploited to compromise a system or network.
Answer B is incorrect because the “Attack surface” option describes a different concept: the collection of exposed interfaces, services, users, and other entry points an attacker could target.
Answer C is incorrect because the “Phishing” option describes a different concept: a social-engineering technique that uses deceptive messages to trick users into revealing information or performing unsafe actions.
Question 14
For Risk, which statement is accurate?
Correct Answer: B
Correct Answer
Answer B is correct because the selected answer describes the potential for loss or harm based on the likelihood and impact of a security event.
Incorrect Answers
Answer A is incorrect because the “Denial of service” option describes a different concept: an attack intended to reduce or eliminate the availability of a network service or resource.
Answer C is incorrect because the “Vulnerability” option describes a different concept: a weakness that could be exploited to compromise a system or network.
Answer D is incorrect because the “Social engineering” option describes a different concept: Manipulating people rather than only technical controls to obtain unauthorized access or information.
Question 15
For Attack surface, which statement is accurate?
Correct Answer: B
Correct Answer
Answer B is correct because the selected answer describes the collection of exposed interfaces, services, users, and other entry points an attacker could target.
Incorrect Answers
Answer A is incorrect because the “Social engineering” option describes a different concept: Manipulating people rather than only technical controls to obtain unauthorized access or information.
Answer C is incorrect because the “Denial of service” option describes a different concept: an attack intended to reduce or eliminate the availability of a network service or resource.
Answer D is incorrect because the “Exploit” option describes a different concept: a technique or code that takes advantage of a vulnerability.
Question 16
For Mitigation, which statement is accurate?
Correct Answer: A
Correct Answer
Answer A is correct because it accurately defines Mitigation. The matching definition is: A control or action intended to reduce the likelihood or impact of a security risk.
Incorrect Answers
Answer B is incorrect because the “Threat” option describes a different concept: a potential cause of an unwanted security incident or harm to an information system.
Answer C is incorrect because the “Phishing” option describes a different concept: a social-engineering technique that uses deceptive messages to trick users into revealing information or performing unsafe actions.
Answer D is incorrect because the “Exploit” option describes a different concept: a technique or code that takes advantage of a vulnerability.
Question 17
For Malware, which statement is accurate?
Correct Answer: C
Correct Answer
Answer C is correct because the choice accurately describes Malware: Malicious software designed to disrupt, damage, spy on, or gain unauthorized access to systems.
Incorrect Answers
Answer A is incorrect because the “Vulnerability” option describes a different concept: a weakness that could be exploited to compromise a system or network.
Answer B is incorrect because the “Social engineering” option describes a different concept: Manipulating people rather than only technical controls to obtain unauthorized access or information.
Answer D is incorrect because the “Risk” option describes a different concept: the potential for loss or harm based on the likelihood and impact of a security event.
Question 18
For Phishing, which statement is accurate?
Correct Answer: A
Correct Answer
Answer A is correct because the selected answer describes a social-engineering technique that uses deceptive messages to trick users into revealing information or performing unsafe actions.
Incorrect Answers
Answer B is incorrect because the “Malware” option describes a different concept: Malicious software designed to disrupt, damage, spy on, or gain unauthorized access to systems.
Answer C is incorrect because the “Vulnerability” option describes a different concept: a weakness that could be exploited to compromise a system or network.
Answer D is incorrect because the “Attack surface” option describes a different concept: the collection of exposed interfaces, services, users, and other entry points an attacker could target.
Question 19
For Denial of service, which statement is accurate?
Correct Answer: B
Correct Answer
Answer B is correct because the selected answer describes an attack intended to reduce or eliminate the availability of a network service or resource.
Incorrect Answers
Answer A is incorrect because the “Phishing” option describes a different concept: a social-engineering technique that uses deceptive messages to trick users into revealing information or performing unsafe actions.
Answer C is incorrect because the “Attack surface” option describes a different concept: the collection of exposed interfaces, services, users, and other entry points an attacker could target.
Answer D is incorrect because the “Vulnerability” option describes a different concept: a weakness that could be exploited to compromise a system or network.
Question 20
For Social engineering, which statement is accurate?
Correct Answer: D
Correct Answer
Answer D is correct because it accurately defines Social engineering. The matching definition is: Manipulating people rather than only technical controls to obtain unauthorized access or information.
Incorrect Answers
Answer A is incorrect because the “Denial of service” option describes a different concept: an attack intended to reduce or eliminate the availability of a network service or resource.
Answer B is incorrect because the “Vulnerability” option describes a different concept: a weakness that could be exploited to compromise a system or network.
Answer C is incorrect because the “Attack surface” option describes a different concept: the collection of exposed interfaces, services, users, and other entry points an attacker could target.
Question 21
In a campus security deployment, the team must identify the technology that provides the following function: A potential cause of an unwanted security incident or harm to an information system. Which option should be selected?
Correct Answer: D
Correct Answer
Answer D is correct because the operational requirement in the stem maps to Threat: A potential cause of an unwanted security incident or harm to an information system.
Incorrect Answers
Answer A is incorrect because the “Vulnerability” option describes a different concept: a weakness that could be exploited to compromise a system or network.
Answer B is incorrect because the “Denial of service” option describes a different concept: an attack intended to reduce or eliminate the availability of a network service or resource.
Answer C is incorrect because the “Phishing” option describes a different concept: a social-engineering technique that uses deceptive messages to trick users into revealing information or performing unsafe actions.
Question 22
A security assessment finds a software weakness that an attacker could exploit. Which security concept names the weakness itself?
Correct Answer: C
Correct Answer
Answer C is correct because Vulnerability is the most precise fit for the stated requirement. A weakness that could be exploited to compromise a system or network.
Incorrect Answers
Answer A is incorrect because the “Exploit” option describes a different concept: a technique or code that takes advantage of a vulnerability.
Answer B is incorrect because the “Threat” option describes a different concept: a potential cause of an unwanted security incident or harm to an information system.
Answer D is incorrect because the “Phishing” option describes a different concept: a social-engineering technique that uses deceptive messages to trick users into revealing information or performing unsafe actions.
Question 23
During a defensive configuration review, the design calls for the following capability: A technique or code that takes advantage of a vulnerability. Which option names that capability most accurately?
Correct Answer: C
Correct Answer
Answer C is correct because the scenario is describing the role of Exploit. A technique or code that takes advantage of a vulnerability.
Incorrect Answers
Answer A is incorrect because the “Threat” option describes a different concept: a potential cause of an unwanted security incident or harm to an information system.
Answer B is incorrect because the “Risk” option describes a different concept: the potential for loss or harm based on the likelihood and impact of a security event.
Answer D is incorrect because the “Vulnerability” option describes a different concept: a weakness that could be exploited to compromise a system or network.
Question 24
A team evaluates both the probability of a damaging event and the loss it would cause. Which security concept combines these considerations?
Correct Answer: C
Correct Answer
Answer C is correct because Risk directly provides the function required by the scenario. The potential for loss or harm based on the likelihood and impact of a security event.
Incorrect Answers
Answer A is incorrect because the “Attack surface” option describes a different concept: the collection of exposed interfaces, services, users, and other entry points an attacker could target.
Answer B is incorrect because the “Phishing” option describes a different concept: a social-engineering technique that uses deceptive messages to trick users into revealing information or performing unsafe actions.
Answer D is incorrect because the “Denial of service” option describes a different concept: an attack intended to reduce or eliminate the availability of a network service or resource.
Question 25
While working on an access-control investigation, an administrator encounters this requirement: The collection of exposed interfaces, services, users, and other entry points an attacker could target. Which answer is the most precise match?
Correct Answer: B
Correct Answer
Answer B is correct because the operational requirement in the stem maps to Attack surface: The collection of exposed interfaces, services, users, and other entry points an attacker could target.
Incorrect Answers
Answer A is incorrect because the “Denial of service” option describes a different concept: an attack intended to reduce or eliminate the availability of a network service or resource.
Answer C is incorrect because the “Threat” option describes a different concept: a potential cause of an unwanted security incident or harm to an information system.
Answer D is incorrect because the “Mitigation” option describes a different concept: a control or action intended to reduce the likelihood or impact of a security risk.
Question 26
In a campus security deployment, the team must identify the technology that provides the following function: A control or action intended to reduce the likelihood or impact of a security risk. Which option should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because Mitigation is the most precise fit for the stated requirement. A control or action intended to reduce the likelihood or impact of a security risk.
Incorrect Answers
Answer A is incorrect because the “Denial of service” option describes a different concept: an attack intended to reduce or eliminate the availability of a network service or resource.
Answer B is incorrect because the “Exploit” option describes a different concept: a technique or code that takes advantage of a vulnerability.
Answer D is incorrect because the “Risk” option describes a different concept: the potential for loss or harm based on the likelihood and impact of a security event.
Question 27
A host contains software written to steal data and gain unauthorized access. Which broad category describes the software?
Correct Answer: C
Correct Answer
Answer C is correct because the scenario is describing the role of Malware. Malicious software designed to disrupt, damage, spy on, or gain unauthorized access to systems.
Incorrect Answers
Answer A is incorrect because the “Mitigation” option describes a different concept: a control or action intended to reduce the likelihood or impact of a security risk.
Answer B is incorrect because the “Risk” option describes a different concept: the potential for loss or harm based on the likelihood and impact of a security event.
Answer D is incorrect because the “Social engineering” option describes a different concept: Manipulating people rather than only technical controls to obtain unauthorized access or information.
Question 28
During a defensive configuration review, the design calls for the following capability: A social-engineering technique that uses deceptive messages to trick users into revealing information or performing unsafe actions. Which option names that capability most accurately?
Correct Answer: B
Correct Answer
Answer B is correct because Phishing directly provides the function required by the scenario. A social-engineering technique that uses deceptive messages to trick users into revealing information or performing unsafe actions.
Incorrect Answers
Answer A is incorrect because the “Malware” option describes a different concept: Malicious software designed to disrupt, damage, spy on, or gain unauthorized access to systems.
Answer C is incorrect because the “Exploit” option describes a different concept: a technique or code that takes advantage of a vulnerability.
Answer D is incorrect because the “Denial of service” option describes a different concept: an attack intended to reduce or eliminate the availability of a network service or resource.
Question 29
An attacker overwhelms a service so legitimate clients cannot use it. Which attack category describes the availability impact?
Correct Answer: B
Correct Answer
Answer B is correct because the operational requirement in the stem maps to Denial of service: An attack intended to reduce or eliminate the availability of a network service or resource.
Incorrect Answers
Answer A is incorrect because the “Phishing” option describes a different concept: a social-engineering technique that uses deceptive messages to trick users into revealing information or performing unsafe actions.
Answer C is incorrect because the “Malware” option describes a different concept: Malicious software designed to disrupt, damage, spy on, or gain unauthorized access to systems.
Answer D is incorrect because the “Threat” option describes a different concept: a potential cause of an unwanted security incident or harm to an information system.
Question 30
While working on an access-control investigation, an administrator encounters this requirement: Manipulating people rather than only technical controls to obtain unauthorized access or information. Which answer is the most precise match?
Correct Answer: A
Correct Answer
Answer A is correct because Social engineering is the most precise fit for the stated requirement. Manipulating people rather than only technical controls to obtain unauthorized access or information.
Incorrect Answers
Answer B is incorrect because the “Phishing” option describes a different concept: a social-engineering technique that uses deceptive messages to trick users into revealing information or performing unsafe actions.
Answer C is incorrect because the “Threat” option describes a different concept: a potential cause of an unwanted security incident or harm to an information system.
Answer D is incorrect because the “Denial of service” option describes a different concept: an attack intended to reduce or eliminate the availability of a network service or resource.
Popular posts
Recent Posts
