CISCO EXAM AND PRACTICE EXAM NEWEST 2026
TEST BANK| CISCO CERTIFIED NETWORK
PROFESSIONAL (CCNP) CERTIFICATION EXAM PREP
WITH COMPLETE 400 REAL EXAM QUESTIONS AND
CORRECT VERIFIED ANSWERS/ ALREADY GRADED
A+ (MOST RECENT!!)
What type of information does CVSS provide for a vulnerability?
A. risk transfer procedures
B. severity of the vulnerability
C. suggestions for managing the vulnerability
D. risk mitigation – Correct Answer – B.
Log monitoring and correlation, IPSs, and surveillance cameras are
examples of which type of countermeasure?
A. Deterrent
B. Corrective
C. Recovery
D. Detective– Correct Answer – D.
Which IP attack type is a simultaneous, coordinated attack from multiple
source machines?
A. Rogue DHCP attack
B. DDoS attack
C. MITM attack
pg. 1
,D. MAC address flooding attack – Correct Answer – B.
Which information can an attacker use within the ICMP to determine
which type of operating system the device is running?
A. total length
B. TTL value
C. version
D. checksum – Correct Answer – B.
Which option is used to establish a covert connection between two
remote computers, using ICMP echo requests and reply packets, and
which can be used to bypass firewall rules?
A. Smurf attack
B. Firewalking
C. ICMP tunneling
D. ICMP-based Operating System fingerprinting – Correct Answer – C.
Which TCP flag is used to initiate a graceful termination of a TCP
connection?
A. RST
B. FIN
C. ACK
D. SYN
E. URG – Correct Answer - B
pg. 2
,Which application-layer protocol, that uses UDP to manage and monitor
devices on the network, could be exploited if it is not secured on
devices?
A. TFTP
B. SNMP
C. HTTPS
D. FTP – Correct Answer – B.
Which two options might be considered attack surfaces in the network
environment? (Choose two.)
A. open ports
B. privacy settings
C. use of SSH
D. use of Telnet – Correct Answer – A, D.
Which type of a common security threat can be solved by patching the
operating system or hardware device?
A. phishing
B. SQL injection
C. malware
D. known vulnerabilities
E. weak authentication – Correct Answer – D.
Which three options are methods that are used by an attacker while
gathering network data? (Choose three.)
A. unplug network devices
pg. 3
, B. packet sniffer
C. port sniffer
D. ping sniffer
E. ping sweeps
F. port scans – Correct Answer – B, E, F.
Which option is an attack in which the session established by the client
to the server is taken over by a malicious person or process?
A. Password attack
B. Spoofing/masquerading attack
C. Session hijacking
D. Malware – Correct Answer – C.
What do attackers use to launch an attack on a location without the
attack coming directly from the attacker's location?
A. spear phishing
B. malware that is controlled through CnC
C. direct SYN flood attack
D. ping of death – Correct Answer – B.
Which TCP/IP application protocol can be used in an amplification
attack by exploiting the protocol weakness in recursive lookup?
A. HTTPS
B. LDAP
C. HTTP
pg. 4
TEST BANK| CISCO CERTIFIED NETWORK
PROFESSIONAL (CCNP) CERTIFICATION EXAM PREP
WITH COMPLETE 400 REAL EXAM QUESTIONS AND
CORRECT VERIFIED ANSWERS/ ALREADY GRADED
A+ (MOST RECENT!!)
What type of information does CVSS provide for a vulnerability?
A. risk transfer procedures
B. severity of the vulnerability
C. suggestions for managing the vulnerability
D. risk mitigation – Correct Answer – B.
Log monitoring and correlation, IPSs, and surveillance cameras are
examples of which type of countermeasure?
A. Deterrent
B. Corrective
C. Recovery
D. Detective– Correct Answer – D.
Which IP attack type is a simultaneous, coordinated attack from multiple
source machines?
A. Rogue DHCP attack
B. DDoS attack
C. MITM attack
pg. 1
,D. MAC address flooding attack – Correct Answer – B.
Which information can an attacker use within the ICMP to determine
which type of operating system the device is running?
A. total length
B. TTL value
C. version
D. checksum – Correct Answer – B.
Which option is used to establish a covert connection between two
remote computers, using ICMP echo requests and reply packets, and
which can be used to bypass firewall rules?
A. Smurf attack
B. Firewalking
C. ICMP tunneling
D. ICMP-based Operating System fingerprinting – Correct Answer – C.
Which TCP flag is used to initiate a graceful termination of a TCP
connection?
A. RST
B. FIN
C. ACK
D. SYN
E. URG – Correct Answer - B
pg. 2
,Which application-layer protocol, that uses UDP to manage and monitor
devices on the network, could be exploited if it is not secured on
devices?
A. TFTP
B. SNMP
C. HTTPS
D. FTP – Correct Answer – B.
Which two options might be considered attack surfaces in the network
environment? (Choose two.)
A. open ports
B. privacy settings
C. use of SSH
D. use of Telnet – Correct Answer – A, D.
Which type of a common security threat can be solved by patching the
operating system or hardware device?
A. phishing
B. SQL injection
C. malware
D. known vulnerabilities
E. weak authentication – Correct Answer – D.
Which three options are methods that are used by an attacker while
gathering network data? (Choose three.)
A. unplug network devices
pg. 3
, B. packet sniffer
C. port sniffer
D. ping sniffer
E. ping sweeps
F. port scans – Correct Answer – B, E, F.
Which option is an attack in which the session established by the client
to the server is taken over by a malicious person or process?
A. Password attack
B. Spoofing/masquerading attack
C. Session hijacking
D. Malware – Correct Answer – C.
What do attackers use to launch an attack on a location without the
attack coming directly from the attacker's location?
A. spear phishing
B. malware that is controlled through CnC
C. direct SYN flood attack
D. ping of death – Correct Answer – B.
Which TCP/IP application protocol can be used in an amplification
attack by exploiting the protocol weakness in recursive lookup?
A. HTTPS
B. LDAP
C. HTTP
pg. 4