Cisco CCNP Enterprise 350-401 ENCOR Threat Endpoint and Segmentation Security Design Practice Test
Topic 18 covers threat, endpoint and segmentation security design for the Cisco Certified Specialist – Enterprise Core certification. These original practice questions apply the verified 350-401 objectives to practical decisions and troubleshooting. Select one answer unless a fixed number is requested. For broader preparation, visit the Cisco 350-401 ENCOR Exam Dumps page. Each option includes an explanation of the relevant behavior and scenario constraints.
Question 1
An internet-facing application is allowed through a perimeter firewall. The security requirement is to inspect permitted application traffic for exploit signatures and actively stop matching malicious payloads before they reach the server. Which control best addresses the requirement?
Correct Answer: B
Correct Answer
Answer B is correct because IPS inspection can analyze allowed traffic for malicious patterns and take a blocking action.
Incorrect Answers
Answer A is incorrect because flow metadata improves visibility but does not inspect payloads or block exploit signatures.
Answer C is incorrect because identity tagging supports segmentation decisions but does not itself inspect exploit content.
Answer D is incorrect because capacity does not provide threat inspection. It does not satisfy the stem’s governing point: Use prevention inspection on the relevant traffic path when the requirement is to detect and stop malicious application content.
Answer E is incorrect because link encryption protects that Ethernet hop but does not identify exploit payloads.
Question 2
A SOC receives high-fidelity alerts from a passive sensor when exploit traffic crosses a tap, but management now requires the control to stop the exploit automatically in-line. What has to change?
Correct Answer: D
Correct Answer
Answer D is correct because automatic blocking requires an enforcement point in the path, not detection-only visibility.
Incorrect Answers
Answer A is incorrect because protecting the monitoring link does not create enforcement.
Answer B is incorrect because logging changes do not turn a passive observation point into an enforcement path.
Answer C is incorrect because classification without an enforcement policy does not stop traffic.
Answer E is incorrect because retention supports investigation, not prevention. It does not satisfy the stem’s governing point: Detection visibility and prevention enforcement are different outcomes; blocking requires an enforcement-capable control on the path.
Question 3
A company deploys an IPS at the internet edge. An internal user laterally attacks a database across an east-west path that never traverses the edge. The IPS reports nothing. Which design correction addresses the stated gap?
Correct Answer: A
Correct Answer
Answer A is correct because the control must see the traffic it is expected to inspect.
Incorrect Answers
Answer B is incorrect because removing a layer weakens defense and does not fix path visibility.
Answer C is incorrect because changing addressing does not establish the intended internal inspection architecture.
Answer D is incorrect because a better signature set still cannot inspect traffic that never crosses the sensor.
Answer E is incorrect because time synchronization does not provide threat inspection. It does not satisfy the stem’s governing point: A network inspection control only sees traffic that traverses it; placement must match the threat path.
Question 4
A ransomware campaign may arrive through email, execute on a laptop, and then scan internal servers. Which TWO controls most directly create layered coverage across the host-execution and network-propagation stages? Choose TWO.
Correct Answers: C, F
Correct Answers
Answer C is correct because host control can observe and contain execution even when the device is away from a network inspection point.
Answer F is correct because network inspection adds a separate control over propagation paths.
Incorrect Answers
Answer A is incorrect because removing evidence weakens detection and response. It does not satisfy the stem’s governing point: Layered defense uses controls at different failure stages, such as endpoint execution and network propagation.
Answer B is incorrect because address capacity is not a threat-defense layer. It does not satisfy the stem’s governing point: Layered defense uses controls at different failure stages, such as endpoint execution and network propagation.
Answer D is incorrect because link encryption does not identify ransomware execution or malicious lateral behavior.
Answer E is incorrect because DNS caching does not provide the required security controls.
Question 5
A firewall with IPS inspects all north-south traffic, but a backup VLAN has direct Layer 3 reachability to production and is intentionally excluded from the firewall path. Which statement is the most accurate security assessment?
Correct Answer: D
Correct Answer
Answer D is correct because traffic outside the enforcement path is not inspected by that firewall.
Incorrect Answers
Answer A is incorrect because encryption protects links but does not replace threat inspection.
Answer B is incorrect because SGT propagation is classification context, not payload inspection.
Answer C is incorrect because routing reachability alone does not prove the path crosses the firewall.
Answer E is incorrect because sharing infrastructure does not make bypass traffic traverse inspection.
Question 6
Sales laptops regularly work from home and public networks, outside the corporate firewall. The company needs malware telemetry and the ability to contain a compromised laptop wherever the endpoint agent can reach its cloud service. Which control is most directly aligned?
Correct Answer: A
Correct Answer
Answer A is correct because host-based telemetry and isolation remain available even when traffic is not behind the enterprise gateway.
Incorrect Answers
Answer B is incorrect because off-network devices can bypass that inspection point. It does not satisfy the stem’s governing point: Endpoint protection follows the device and can provide host telemetry/containment outside enterprise network inspection points.
Answer C is incorrect because a campus link control does not provide host telemetry off-network.
Answer D is incorrect because campus group policy cannot protect an endpoint while it is off that network.
Answer E is incorrect because bandwidth is not endpoint protection. It does not satisfy the stem’s governing point: Endpoint protection follows the device and can provide host telemetry/containment outside enterprise network inspection points.
Question 7
A SOC investigates suspicious PowerShell activity. NetFlow shows the laptop contacted an external IP over TCP/443, but analysts need the process command line and host execution context. Which evidence source is more appropriate?
Correct Answer: E
Correct Answer
Answer E is correct because endpoint security can expose process and command-line behavior that network flow metadata cannot.
Incorrect Answers
Answer A is incorrect because identity classification does not provide execution details. It does not satisfy the stem’s governing point: Network flow evidence describes communications; endpoint telemetry can expose process-level execution context.
Answer B is incorrect because utilization has no process context. It does not satisfy the stem’s governing point: Network flow evidence describes communications; endpoint telemetry can expose process-level execution context.
Answer C is incorrect because link-security counters do not identify the host process.
Answer D is incorrect because Layer 2 forwarding state does not show host process command lines.
Question 8
A workstation is confirmed compromised and actively contacting command-and-control infrastructure. Analysts still need controlled access from approved recovery systems. What is the most appropriate immediate host-boundary response?
Correct Answer: C
Correct Answer
Answer C is correct because isolation limits malicious communications while preserving approved remediation access.
Incorrect Answers
Answer A is incorrect because cosmetic changes do not contain the host. It does not satisfy the stem’s governing point: Contain a confirmed compromised endpoint at the host boundary while preserving only trusted remediation access when supported.
Answer B is incorrect because caching does not contain a compromised host. It does not satisfy the stem’s governing point: Contain a confirmed compromised endpoint at the host boundary while preserving only trusted remediation access when supported.
Answer D is incorrect because that weakens enforcement during an active compromise. It does not satisfy the stem’s governing point: Contain a confirmed compromised endpoint at the host boundary while preserving only trusted remediation access when supported.
Answer E is incorrect because removing visibility impairs response. It does not satisfy the stem’s governing point: Contain a confirmed compromised endpoint at the host boundary while preserving only trusted remediation access when supported.
Question 9
A contractor connects an unmanaged personal laptop to a guest segment. The organization has no endpoint agent, management profile, or host telemetry on that device. Which limitation should the architect document?
Correct Answer: A
Correct Answer
Answer A is correct because unmanaged endpoints can be governed at network boundaries without providing managed host visibility.
Incorrect Answers
Answer B is incorrect because endpoint management status does not inherently prevent addressing.
Answer C is incorrect because network evidence does not provide complete host execution telemetry.
Answer D is incorrect because identity segmentation and endpoint software are separate mechanisms.
Answer E is incorrect because link encryption does not instrument host processes. It does not satisfy the stem’s governing point: Unmanaged endpoints may still be subject to network policy, but they lack the host-level telemetry and control of a managed endpoint agent.
Question 10
A branch firewall blocks known malicious destinations, but a laptop executes malware from a USB drive while disconnected from the branch network. Which statement best explains why endpoint protection is still needed?
Correct Answer: A
Correct Answer
Answer A is correct because local execution can occur without crossing a network enforcement point.
Incorrect Answers
Answer B is incorrect because network firewalls do not inspect local removable-media execution that does not traverse them.
Answer C is incorrect because SGTs classify identity and do not remove malware.
Answer D is incorrect because link protection does not inspect endpoint files/processes. It does not satisfy the stem’s governing point: Use endpoint security for host-local threats and gateway/network controls for traffic-path threats; neither boundary fully replaces the other.
Answer E is incorrect because connectivity does not eliminate host-local threats. It does not satisfy the stem’s governing point: Use endpoint security for host-local threats and gateway/network controls for traffic-path threats; neither boundary fully replaces the other.
Question 11
A policy must block a specific file-sharing application even when the application can use TCP/443, while permitting other approved HTTPS applications. Why is application-aware firewalling preferable to a port-only rule?
Correct Answer: E
Correct Answer
Answer E is correct because port 443 can carry many applications, so application identity provides finer policy context.
Incorrect Answers
Answer A is incorrect because modern applications may share or shift ports; that is why application identification matters.
Answer B is incorrect because encrypted traffic can restrict inspection and may require decryption or other visibility methods.
Answer C is incorrect because application awareness does not remove the need for transport encryption.
Answer D is incorrect because firewall application control and endpoint software are separate.
Question 12
A security policy says members of the Finance identity group may reach a reporting application, regardless of which managed workstation they use. Which additional context is decisive beyond destination IP/port?
Correct Answer: B
Correct Answer
Answer B is correct because user-based policy needs a reliable identity-to-session mapping rather than only network coordinates.
Incorrect Answers
Answer A is incorrect because physical appearance does not establish user authorization. It does not satisfy the stem’s governing point: Identity-aware firewall rules require trustworthy identity context associated with the traffic/session.
Answer C is incorrect because time quality can support logs/authentication but does not identify the user group by itself.
Answer D is incorrect because link speed is unrelated to user-based authorization. It does not satisfy the stem’s governing point: Identity-aware firewall rules require trustworthy identity context associated with the traffic/session.
Answer E is incorrect because TTL does not identify the authenticated user. It does not satisfy the stem’s governing point: Identity-aware firewall rules require trustworthy identity context associated with the traffic/session.
Question 13
An NGFW allows outbound TLS. Administrators want full inspection of file contents inside HTTPS, but certificate pinning prevents decryption for one application. Which assessment is most accurate?
Correct Answer: E
Correct Answer
Answer E is correct because Cisco documents visibility methods that reduce blind spots while acknowledging payload inspection limitations.
Incorrect Answers
Answer A is incorrect because port changes do not bypass cryptography. It does not satisfy the stem’s governing point: Encrypted traffic can preserve application/process metadata visibility, but full payload inspection generally depends on decryption and its operational constraints.
Answer B is incorrect because SGTs carry identity context, not TLS keys. It does not satisfy the stem’s governing point: Encrypted traffic can preserve application/process metadata visibility, but full payload inspection generally depends on decryption and its operational constraints.
Answer C is incorrect because transport ports do not defeat TLS encryption. It does not satisfy the stem’s governing point: Encrypted traffic can preserve application/process metadata visibility, but full payload inspection generally depends on decryption and its operational constraints.
Answer D is incorrect because MACsec protects a local Ethernet hop and does not terminate application TLS.
Question 14
Two internal security zones are permitted to communicate, but policy requires session-aware enforcement so return traffic is associated with approved connections and application controls can be applied. Which boundary is most appropriate?
Correct Answer: E
Correct Answer
Answer E is correct because stateful inspection is designed to track permitted sessions and enforce policy at the segmentation boundary.
Incorrect Answers
Answer A is incorrect because passive monitoring does not enforce connection state. It does not satisfy the stem’s governing point: Use a stateful firewall boundary when permitted segments still require session-aware application/security enforcement.
Answer B is incorrect because link encryption does not make inter-zone authorization stateful.
Answer C is incorrect because routing scale does not provide stateful inspection. It does not satisfy the stem’s governing point: Use a stateful firewall boundary when permitted segments still require session-aware application/security enforcement.
Answer D is incorrect because host malware prevention does not enforce network session policy between zones.
Question 15
A compromised endpoint is isolated by the EDR platform, but the network firewall continues allowing the user identity to other applications after the endpoint is restored. Which statement best separates the responsibilities?
Correct Answer: A
Correct Answer
Answer A is correct because host recovery and network authorization are distinct controls that must both be correct.
Incorrect Answers
Answer B is incorrect because endpoint recovery does not inherently define firewall authorization.
Answer C is incorrect because link encryption neither remediates endpoints nor defines application authorization.
Answer D is incorrect because their enforcement boundaries and evidence differ. It does not satisfy the stem’s governing point: Endpoint remediation and network firewall authorization are complementary but distinct security responsibilities.
Answer E is incorrect because network policy does not remediate host files/processes. It does not satisfy the stem’s governing point: Endpoint remediation and network firewall authorization are complementary but distinct security responsibilities.
Question 16
A user moves from one campus access switch to another and receives a different IP address. Policy should still treat the user as the same security role. Which TrustSec concept supports this design?
Correct Answer: A
Correct Answer
Answer A is correct because SGT policy context can remain tied to security-group membership as location/address changes.
Incorrect Answers
Answer B is incorrect because physical ports change when users move. It does not satisfy the stem’s governing point: TrustSec can express policy using security-group identity independent of a specific source IP location.
Answer C is incorrect because that defeats the mobility requirement and is unnecessary for group-based policy.
Answer D is incorrect because link-encryption keys are not the same as TrustSec security-group identity.
Answer E is incorrect because TTL has no role identity semantics. It does not satisfy the stem’s governing point: TrustSec can express policy using security-group identity independent of a specific source IP location.
Question 17
An access edge authenticates a device and assigns it an SGT. No SGACL or other policy consumes that tag anywhere downstream. Which statement is correct?
Correct Answer: D
Correct Answer
Answer D is correct because SGT assignment provides identity context; enforcement requires a policy decision using that context.
Incorrect Answers
Answer A is incorrect because SGT propagation can be clear text and is not MACsec.
Answer B is incorrect because classification is not endpoint remediation. It does not satisfy the stem’s governing point: Separate identity classification (assigning an SGT) from policy enforcement (for example, applying an SGACL matrix decision).
Answer C is incorrect because TrustSec does not remove firewall state behavior. It does not satisfy the stem’s governing point: Separate identity classification (assigning an SGT) from policy enforcement (for example, applying an SGACL matrix decision).
Answer E is incorrect because the effect depends on configured enforcement policy. It does not satisfy the stem’s governing point: Separate identity classification (assigning an SGT) from policy enforcement (for example, applying an SGACL matrix decision).
Question 18
A TrustSec policy matrix specifies that source group Contractors may use HTTPS to destination group Payroll-Servers but must not use SSH. A contractor packet is tagged correctly and reaches an enforcing device. Which information drives the group policy decision?
Correct Answer: E
Correct Answer
Answer E is correct because TrustSec enforcement uses source/destination group context to select policy.
Incorrect Answers
Answer A is incorrect because the permitted service is evaluated within a source/destination group relationship.
Answer B is incorrect because link cryptography does not define the SGACL relationship.
Answer C is incorrect because the design explicitly uses security-group identity rather than subnet-only policy.
Answer D is incorrect because host protection state is not the stated TrustSec matrix key.
Question 19
A nurse moves between wired and wireless access locations during a shift. The hospital wants the same role-based segmentation outcome without rewriting IP ACLs for each subnet. Which design best fits?
Correct Answer: B
Correct Answer
Answer B is correct because identity-based segmentation avoids tying the role solely to changing network location.
Incorrect Answers
Answer A is incorrect because this does not scale and still ties policy to addressing.
Answer C is incorrect because link confidentiality does not define role permissions. It does not satisfy the stem’s governing point: Identity-based segmentation can preserve policy across mobility when classification and enforcement remain consistent.
Answer D is incorrect because per-user VLAN proliferation is not the stated identity-policy model.
Answer E is incorrect because that violates the requirement. It does not satisfy the stem’s governing point: Identity-based segmentation can preserve policy across mobility when classification and enforcement remain consistent.
Question 20
Two switches propagate SGTs using inline tagging. A security review assumes this also encrypts the Ethernet payload between the switches. What correction is required?
Correct Answer: B
Correct Answer
Answer B is correct because Cisco documents SGT-over-Ethernet as clear-text propagation; it is not a confidentiality service.
Incorrect Answers
Answer A is incorrect because group policy and application TLS are unrelated mechanisms.
Answer C is incorrect because the label value does not turn tagging into MACsec.
Answer D is incorrect because SGT tagging does not provide payload encryption for either protocol.
Answer E is incorrect because an SGT is a group identifier, not a payload-encryption key.
Question 21
A company owns a dark-fiber Ethernet link between two buildings. The principal risk is passive tapping of that physical link, and the requirement is confidentiality/integrity on the Ethernet hop without changing application protocols. Which control most directly fits?
Correct Answer: A
Correct Answer
Answer A is correct because MACsec protects Ethernet frames on the secured link and is designed for link-layer confidentiality/integrity.
Incorrect Answers
Answer B is incorrect because detection does not encrypt the wire. It does not satisfy the stem’s governing point: MACsec addresses confidentiality/integrity exposure on an Ethernet link; it does not require changing every application.
Answer C is incorrect because flow telemetry does not encrypt the link. It does not satisfy the stem’s governing point: MACsec addresses confidentiality/integrity exposure on an Ethernet link; it does not require changing every application.
Answer D is incorrect because a group tag provides identity context and can be carried in clear text.
Answer E is incorrect because routing timers do not protect frame confidentiality. It does not satisfy the stem’s governing point: MACsec addresses confidentiality/integrity exposure on an Ethernet link; it does not require changing every application.
Question 22
Traffic crosses three routed provider hops between sites. MACsec is enabled only on the customer Ethernet handoff from each site router to its local provider device. The requirement is end-to-end confidentiality across the entire provider path. Which assessment is correct?
Correct Answer: C
Correct Answer
Answer C is correct because MACsec is link/hop scoped rather than an end-to-end routed tunnel by itself.
Incorrect Answers
Answer A is incorrect because identity tags do not extend encryption scope. It does not satisfy the stem’s governing point: Distinguish link-layer MACsec protection from end-to-end routed encryption such as IPsec.
Answer B is incorrect because intermediate hops are separate links unless they also participate in protection.
Answer D is incorrect because routing preference does not alter encryption scope. It does not satisfy the stem’s governing point: Distinguish link-layer MACsec protection from end-to-end routed encryption such as IPsec.
Answer E is incorrect because stateful inspection is not a path encryption mechanism.
Question 23
Two switches are configured for MACsec, but they do not share a valid keying/trust relationship for MKA. What prerequisite is missing?
Correct Answer: E
Correct Answer
Answer E is correct because the peers need a valid security association/key agreement basis before protected traffic can be established.
Incorrect Answers
Answer A is incorrect because DNS publication is not required for the local MKA relationship described.
Answer B is incorrect because TrustSec identity groups are not the MACsec keying prerequisite.
Answer C is incorrect because IPS signatures do not establish MACsec keys. It does not satisfy the stem’s governing point: MACsec requires participating peers to establish compatible security associations through an approved keying/trust method.
Answer D is incorrect because frame overhead may affect design, but it does not supply trust/keying material.
Question 24
A path is Host—Switch A—Switch B—Switch C—Server. MACsec protects A–B and B–C, but Host–A and C–Server are unprotected Ethernet links. Which TWO statements are true? Choose TWO.
Correct Answers: C, F
Correct Answers
Answer C is correct because those are the links with MACsec enabled. This directly matches the stem’s governing point: Evaluate MACsec coverage link by link; intermediate protection does not automatically secure adjacent unprotected Ethernet segments.
Answer F is correct because link-layer protection does not magically extend to unconfigured adjacent links.
Incorrect Answers
Answer A is incorrect because the endpoints and edge links are outside the stated protection.
Answer B is incorrect because forwarding does not extend link cryptography. It does not satisfy the stem’s governing point: Evaluate MACsec coverage link by link; intermediate protection does not automatically secure adjacent unprotected Ethernet segments.
Answer D is incorrect because identity tagging and link encryption can be separate mechanisms.
Answer E is incorrect because decryption requires participation in the relevant protection context.
Question 25
A MACsec-protected switch interconnect carries traffic from many applications. Which risk remains outside the direct purpose of MACsec on that link?
Correct Answer: E
Correct Answer
Answer E is correct because link confidentiality/integrity does not determine whether the protected payload itself is benign.
Incorrect Answers
Answer A is incorrect because preventing that exposure is a direct MACsec purpose when correctly configured.
Answer B is incorrect because confidentiality protection addresses this risk. It does not satisfy the stem’s governing point: Link encryption protects frames in transit, but it does not determine whether an authorized endpoint is sending malicious application content.
Answer C is incorrect because that is part of establishing link security, not an application-content control.
Answer D is incorrect because integrity protection addresses in-transit tampering on the secured link.
Question 26
EDR confirms a laptop is compromised and isolates it. The user identity is also known to the network. Which TWO actions best combine host containment with network enforcement while the incident is investigated? Choose TWO.
Correct Answers: C, D
Correct Answers
Answer C is correct because this limits host communications at the endpoint boundary.
Answer D is correct because network enforcement supplies an independent containment boundary. This directly matches the stem’s governing point: A serious incident can use complementary endpoint containment and identity/network enforcement rather than relying on one boundary.
Incorrect Answers
Answer A is incorrect because capacity does not contain the incident. It does not satisfy the stem’s governing point: A serious incident can use complementary endpoint containment and identity/network enforcement rather than relying on one boundary.
Answer B is incorrect because losing identity weakens policy and investigation. It does not satisfy the stem’s governing point: A serious incident can use complementary endpoint containment and identity/network enforcement rather than relying on one boundary.
Answer E is incorrect because that removes evidence. It does not satisfy the stem’s governing point: A serious incident can use complementary endpoint containment and identity/network enforcement rather than relying on one boundary.
Answer F is incorrect because layered controls should not be removed during compromise.
Question 27
A university wants students to keep the same access permissions as they roam among campus buildings and subnets. The decisive requirement is role-based segmentation independent of IP address, not link encryption. Which technology is the better architectural fit?
Correct Answer: B
Correct Answer
Answer B is correct because SGT-based policy is intended to decouple role identity from changing network location/address.
Incorrect Answers
Answer A is incorrect because address translation does not express role permissions. It does not satisfy the stem’s governing point: Choose TrustSec when the decisive problem is identity-based segmentation that should persist across changing addresses/locations.
Answer C is incorrect because threat signatures are not an identity-segmentation model. It does not satisfy the stem’s governing point: Choose TrustSec when the decisive problem is identity-based segmentation that should persist across changing addresses/locations.
Answer D is incorrect because MACsec protects links but does not define student-versus-staff authorization policy.
Answer E is incorrect because that conflicts with mobility and address independence. It does not satisfy the stem’s governing point: Choose TrustSec when the decisive problem is identity-based segmentation that should persist across changing addresses/locations.
Question 28
Two switches connect through a physically exposed Ethernet run in a shared utility space. Existing role-based segmentation is correct, but the security requirement newly calls for confidentiality against tapping on that one link. Which control addresses the new requirement?
Correct Answer: D
Correct Answer
Answer D is correct because the decisive gap is local link confidentiality/integrity, which MACsec addresses.
Incorrect Answers
Answer A is incorrect because removing inspection does not protect the wire. It does not satisfy the stem’s governing point: Choose MACsec when the decisive security gap is exposure of a specific Ethernet link, while keeping authorization controls separate.
Answer B is incorrect because VLAN changes do not provide cryptographic confidentiality. It does not satisfy the stem’s governing point: Choose MACsec when the decisive security gap is exposure of a specific Ethernet link, while keeping authorization controls separate.
Answer C is incorrect because logging can show events but does not encrypt traffic.
Answer E is incorrect because additional role labels do not encrypt the physical link.
Question 29
Two application tiers are allowed to communicate. TrustSec permits the source group to the destination group, but policy still requires malware/exploit inspection of the permitted sessions. What should the design retain?
Correct Answer: E
Correct Answer
Answer E is correct because segmentation decides who may communicate; inspection evaluates the allowed traffic for threats.
Incorrect Answers
Answer A is incorrect because reachability is not threat inspection. It does not satisfy the stem’s governing point: Authorization/segmentation and threat inspection solve different problems; permitted flows may still need stateful/IPS inspection.
Answer B is incorrect because names do not enforce or inspect traffic. It does not satisfy the stem’s governing point: Authorization/segmentation and threat inspection solve different problems; permitted flows may still need stateful/IPS inspection.
Answer C is incorrect because authorization does not guarantee benign content. It does not satisfy the stem’s governing point: Authorization/segmentation and threat inspection solve different problems; permitted flows may still need stateful/IPS inspection.
Answer D is incorrect because link encryption does not classify malicious application payloads.
Question 30
A branch encrypts every WAN packet end-to-end with IPsec and uses MACsec on the local uplinks. A compromised administrator account is still able to authenticate to an internal application and exfiltrate permitted data. Which security gap remains?
Correct Answer: C
Correct Answer
Answer C is correct because confidentiality of transport does not establish that the communicating principal is trustworthy or acting legitimately.
Incorrect Answers
Answer A is incorrect because bandwidth does not correct identity misuse. It does not satisfy the stem’s governing point: Encrypted transport can coexist with compromised identities or malicious endpoints; confidentiality is only one security property.
Answer B is incorrect because removing evidence worsens detection and accountability. It does not satisfy the stem’s governing point: Encrypted transport can coexist with compromised identities or malicious endpoints; confidentiality is only one security property.
Answer D is incorrect because more transport encryption does not remediate stolen credentials or excessive authorization.
Answer E is incorrect because identity tagging is unrelated to tunnel decryption. It does not satisfy the stem’s governing point: Encrypted transport can coexist with compromised identities or malicious endpoints; confidentiality is only one security property.
Popular posts
Recent Posts
