CCNA SECURITY FINAL EXAM | COMPLETE PRACTICE QUESTIONS, ANSWERS &
STUDY GUIDE 2026/2027
Which security implementation will provide control plane protection for a network device? - ANS
✔✔routing protocol authentication
What is the one major difference between local AAA authentication and using the login local command
when configuring device access authentication? - ANS ✔✔Local AAA authentication provides a way to
configure backup methods of authentication, but login local does not.
Refer to the exhibit. A network administrator configures AAA authentication on R1. The administrator
then tests the configuration by telnetting to R1. The ACS servers are configured and running. What will
happen if the authentication fails? - ANS ✔✔The authentication process stops
What are two tasks that can be accomplished with the Nmap and Zen map network tools? - ANS
✔✔identification of Layer 3 protocol support on hosts
TCP and UDP port scanning
Which Cisco IOS subcommand is used to compile an IPS signature into memory? - ANS ✔✔retired false
Why are DES keys considered weak keys? - ANS ✔✔They produce identical subkeys.
What is a benefit of using a next-generation firewall rather than a stateful firewall? - ANS ✔✔granularity
control within applications
What is a result of securing the Cisco IOS image using the Cisco IOS Resilient Configuration feature? -
ANS ✔✔The Cisco IOS image file is not visible in the output of the show flash command.
The corporate security policy dictates that the traffic from the remote-access VPN clients must be
separated between trusted traffic that is destined for the corporate subnets and untrusted traffic
destined for the public Internet. Which VPN solution should be implemented to ensure compliance with
the corporate policy? - ANS ✔✔split tunneling
Which two conditions must be met in order for a network administrator to be able to remotely manage
multiple ASAs with Cisco ASDM? (Choose two.) - ANS ✔✔The ASAs must all be running the same ASDM
version.
ASDM must be run as a local application.
What is negotiated in the establishment of an IPsec tunnel between two IPsec hosts during IKE Phase 1?
- ANS ✔✔ISAKMP SA policy
What are two benefits of using a ZPF rather than a Classic Firewall? (Choose two.) - ANS ✔✔The ZPF is
not dependent on ACLs.
, ZPF policies are easy to read and troubleshoot.
Which security policy characteristic defines the purpose of standards? - ANS ✔✔required steps to
ensure consistent configuration of all company switches
What algorithm is used to provide data integrity of a message through the use of a calculated hash
value? - ANS ✔✔HMAC
On which port should Dynamic ARP Inspection (DAI) be configured on a switch? - ANS ✔✔an uplink port
to another switch
What is a feature of a Cisco IOS Zone-Based Policy Firewall? - ANS ✔✔A router interface can belong to
only one zone at a time.
Refer to the exhibit. The administrator can ping the S0/0/1 interface of RouterB but is unable to gain
Telnet access to the router by using the password cisco123. What is a possible cause of the problem? -
ANS ✔✔The password cisco123 is wrong.
Refer to the exhibit. The ip verify source command is applied on untrusted interfaces. Which type of
attack is mitigated by using this configuration? - ANS ✔✔MAC and IP address spoofing
Refer to the exhibit. Which conclusion can be made from the show crypto map command output that is
shown on R1? - ANS ✔✔The crypto map has not yet been applied to an interface.
What type of algorithms require sender and receiver to exchange a secret key that is used to ensure the
confidentiality of messages? - ANS ✔✔symmetric algorithms
What is an advantage in using a packet filtering firewall versus a high-end firewall appliance? - ANS
✔✔Packet filters perform almost all the tasks of a high-end firewall at a fraction of the cost.
Refer to the exhibit. In the network that is shown, which AAA command logs the use of EXEC session
commands? - ANS ✔✔aaa accounting exec start-stop group tacacs+
A network administrator enters the single-connection command. What effect does this command have
on AAA operation? - ANS ✔✔allows a Cisco ACS server to minimize delay by establishing persistent TCP
connections
Which two practices are associated with securing the features and performance of router operating
systems? (Choose two.) - ANS ✔✔Keep a secure copy of router operating system images.
Configure the router with the maximum amount of memory possible.
Which statement describes a characteristic of the IKE protocol? - ANS ✔✔It uses UDP port 500 to
exchange IKE information between the security gateways.
Refer to the exhibit. If a network administrator is using ASDM to configure a site-to-site VPN between
the CCNAS-ASA and R3, which IP address would the administrator use for the peer IP address textbox on
the ASA if data traffic is to be encrypted between the two remote LANs? - ANS ✔✔209.165.201.1
STUDY GUIDE 2026/2027
Which security implementation will provide control plane protection for a network device? - ANS
✔✔routing protocol authentication
What is the one major difference between local AAA authentication and using the login local command
when configuring device access authentication? - ANS ✔✔Local AAA authentication provides a way to
configure backup methods of authentication, but login local does not.
Refer to the exhibit. A network administrator configures AAA authentication on R1. The administrator
then tests the configuration by telnetting to R1. The ACS servers are configured and running. What will
happen if the authentication fails? - ANS ✔✔The authentication process stops
What are two tasks that can be accomplished with the Nmap and Zen map network tools? - ANS
✔✔identification of Layer 3 protocol support on hosts
TCP and UDP port scanning
Which Cisco IOS subcommand is used to compile an IPS signature into memory? - ANS ✔✔retired false
Why are DES keys considered weak keys? - ANS ✔✔They produce identical subkeys.
What is a benefit of using a next-generation firewall rather than a stateful firewall? - ANS ✔✔granularity
control within applications
What is a result of securing the Cisco IOS image using the Cisco IOS Resilient Configuration feature? -
ANS ✔✔The Cisco IOS image file is not visible in the output of the show flash command.
The corporate security policy dictates that the traffic from the remote-access VPN clients must be
separated between trusted traffic that is destined for the corporate subnets and untrusted traffic
destined for the public Internet. Which VPN solution should be implemented to ensure compliance with
the corporate policy? - ANS ✔✔split tunneling
Which two conditions must be met in order for a network administrator to be able to remotely manage
multiple ASAs with Cisco ASDM? (Choose two.) - ANS ✔✔The ASAs must all be running the same ASDM
version.
ASDM must be run as a local application.
What is negotiated in the establishment of an IPsec tunnel between two IPsec hosts during IKE Phase 1?
- ANS ✔✔ISAKMP SA policy
What are two benefits of using a ZPF rather than a Classic Firewall? (Choose two.) - ANS ✔✔The ZPF is
not dependent on ACLs.
, ZPF policies are easy to read and troubleshoot.
Which security policy characteristic defines the purpose of standards? - ANS ✔✔required steps to
ensure consistent configuration of all company switches
What algorithm is used to provide data integrity of a message through the use of a calculated hash
value? - ANS ✔✔HMAC
On which port should Dynamic ARP Inspection (DAI) be configured on a switch? - ANS ✔✔an uplink port
to another switch
What is a feature of a Cisco IOS Zone-Based Policy Firewall? - ANS ✔✔A router interface can belong to
only one zone at a time.
Refer to the exhibit. The administrator can ping the S0/0/1 interface of RouterB but is unable to gain
Telnet access to the router by using the password cisco123. What is a possible cause of the problem? -
ANS ✔✔The password cisco123 is wrong.
Refer to the exhibit. The ip verify source command is applied on untrusted interfaces. Which type of
attack is mitigated by using this configuration? - ANS ✔✔MAC and IP address spoofing
Refer to the exhibit. Which conclusion can be made from the show crypto map command output that is
shown on R1? - ANS ✔✔The crypto map has not yet been applied to an interface.
What type of algorithms require sender and receiver to exchange a secret key that is used to ensure the
confidentiality of messages? - ANS ✔✔symmetric algorithms
What is an advantage in using a packet filtering firewall versus a high-end firewall appliance? - ANS
✔✔Packet filters perform almost all the tasks of a high-end firewall at a fraction of the cost.
Refer to the exhibit. In the network that is shown, which AAA command logs the use of EXEC session
commands? - ANS ✔✔aaa accounting exec start-stop group tacacs+
A network administrator enters the single-connection command. What effect does this command have
on AAA operation? - ANS ✔✔allows a Cisco ACS server to minimize delay by establishing persistent TCP
connections
Which two practices are associated with securing the features and performance of router operating
systems? (Choose two.) - ANS ✔✔Keep a secure copy of router operating system images.
Configure the router with the maximum amount of memory possible.
Which statement describes a characteristic of the IKE protocol? - ANS ✔✔It uses UDP port 500 to
exchange IKE information between the security gateways.
Refer to the exhibit. If a network administrator is using ASDM to configure a site-to-site VPN between
the CCNAS-ASA and R3, which IP address would the administrator use for the peer IP address textbox on
the ASA if data traffic is to be encrypted between the two remote LANs? - ANS ✔✔209.165.201.1