CCNP SECURITY & TRAINING EXAM 200+
Practice Questions with Verified Answers & Detailed
Rationales Complete Study Guide 2025/2026
Standards
=== START OF EXAM ===
CCNP SECURITY & TRAINING EXAM
200+ Questions with Verified Answers & Detailed Rationales
Core Exam SCOR 350-701 | Concentration Exams | 2026 Updated Standards
SECTION 1: SECURITY FUNDAMENTALS & THREAT LANDSCAPE
(Questions 1-30)
Question 1
What is the primary purpose of a Security Information and Event Management
(SIEM) system?
A) To block malicious traffic
B) To collect, analyze, and correlate security events from multiple sources
C) To encrypt data at rest
D) To manage user identities
1
,Answer: B
Rationale: SIEM systems aggregate and analyze log data from various sources
(firewalls, servers, applications) to identify security threats and provide centralized
visibility.
Question 2
Which type of attack involves overwhelming a target with traffic to make it
unavailable?
A) Phishing
B) Man-in-the-middle
C) Denial of Service (DoS) / Distributed Denial of Service (DDoS)
D) SQL injection
Answer: C
Rationale: DoS/DDoS attacks flood a target with excessive traffic, consuming
resources and preventing legitimate users from accessing services.
Question 3
What is the primary defense against ransomware?
A) Firewalls only
2
,B) Regular backups and user education
C) Intrusion prevention systems
D) Antivirus software
Answer: B
Rationale: Ransomware encrypts files and demands payment. Regular offline
backups allow restoration without paying, and user education prevents initial
infection via phishing.
Question 4
What is the difference between a vulnerability and an exploit?
A) They are the same thing
B) A vulnerability is a weakness; an exploit is the code or technique that takes
advantage of it
C) A vulnerability is a type of malware
D) An exploit is a weakness
Answer: B
Rationale: A vulnerability is a flaw or weakness in a system. An exploit is the
specific code, technique, or method used to leverage that vulnerability to
compromise a system.
3
, Question 5
Zero-day vulnerability refers to:
A) A vulnerability that has been patched
B) A vulnerability that is unknown to the vendor and has no patch available
C) A vulnerability that only affects zero-day devices
D) A vulnerability that is no longer a threat
Answer: B
Rationale: A zero-day vulnerability is a flaw that is unknown to the software
vendor or security community. There is no patch available, making it highly
dangerous.
Question 6
What is the purpose of threat intelligence?
A) To block all incoming traffic
B) To provide information about current and emerging threats to inform defense
strategies
C) To replace firewalls
D) To encrypt all data
Answer: B
4
Practice Questions with Verified Answers & Detailed
Rationales Complete Study Guide 2025/2026
Standards
=== START OF EXAM ===
CCNP SECURITY & TRAINING EXAM
200+ Questions with Verified Answers & Detailed Rationales
Core Exam SCOR 350-701 | Concentration Exams | 2026 Updated Standards
SECTION 1: SECURITY FUNDAMENTALS & THREAT LANDSCAPE
(Questions 1-30)
Question 1
What is the primary purpose of a Security Information and Event Management
(SIEM) system?
A) To block malicious traffic
B) To collect, analyze, and correlate security events from multiple sources
C) To encrypt data at rest
D) To manage user identities
1
,Answer: B
Rationale: SIEM systems aggregate and analyze log data from various sources
(firewalls, servers, applications) to identify security threats and provide centralized
visibility.
Question 2
Which type of attack involves overwhelming a target with traffic to make it
unavailable?
A) Phishing
B) Man-in-the-middle
C) Denial of Service (DoS) / Distributed Denial of Service (DDoS)
D) SQL injection
Answer: C
Rationale: DoS/DDoS attacks flood a target with excessive traffic, consuming
resources and preventing legitimate users from accessing services.
Question 3
What is the primary defense against ransomware?
A) Firewalls only
2
,B) Regular backups and user education
C) Intrusion prevention systems
D) Antivirus software
Answer: B
Rationale: Ransomware encrypts files and demands payment. Regular offline
backups allow restoration without paying, and user education prevents initial
infection via phishing.
Question 4
What is the difference between a vulnerability and an exploit?
A) They are the same thing
B) A vulnerability is a weakness; an exploit is the code or technique that takes
advantage of it
C) A vulnerability is a type of malware
D) An exploit is a weakness
Answer: B
Rationale: A vulnerability is a flaw or weakness in a system. An exploit is the
specific code, technique, or method used to leverage that vulnerability to
compromise a system.
3
, Question 5
Zero-day vulnerability refers to:
A) A vulnerability that has been patched
B) A vulnerability that is unknown to the vendor and has no patch available
C) A vulnerability that only affects zero-day devices
D) A vulnerability that is no longer a threat
Answer: B
Rationale: A zero-day vulnerability is a flaw that is unknown to the software
vendor or security community. There is no patch available, making it highly
dangerous.
Question 6
What is the purpose of threat intelligence?
A) To block all incoming traffic
B) To provide information about current and emerging threats to inform defense
strategies
C) To replace firewalls
D) To encrypt all data
Answer: B
4