300-745 Exam Questions
71 real 300-745 exam questions with expert-verified answers and explanations. Page 1 of 2.
- Question #1Network Security
A technology company recently onboarded a new customer in the medical space. The customer needs a solution to provide data integrity across remote sites. Which solution must be use...
hashingdata integritycryptographyremote sites - Question #2Cloud, Content, and Managed Security
An administrator at a large university wants to ensure that the new employees have the right level of access when they are onboarded. The administrator asked the team to configure...
identity access managementRBACaccess controlcloud security - Question #3Advanced Threat and Endpoint Security
A manufacturing company implemented IoT devices throughout their smart factory and needs a security solution that meets these requirements: - Protect IoT devices from network-based...
IoT securityIPS/IDSanomaly detectionnetwork-based attacks - Question #4Advanced Threat and Endpoint Security
A financial company is focused on proactively protecting sensitive data stored on the devices. The company recognizes the potential risks associated with lost or stolen devices and...
disk encryptiondata protectionendpoint securitydevice theft - Question #5Network Security
An oil and gas company recently faced a security breach when an employee's notepad, which contained critical login credentials, was stolen. The incident led to unauthorized access...
MFAauthenticationcredential securityaccount protection - Question #6Advanced Threat and Endpoint Security
Employees in a healthcare organization could not access their devices when they returned to work after the weekend. The security team discovered that a threat actor had encrypted t...
EDRransomwareendpoint detectionthreat response - Question #7Network Security
A telecommunications company recently introduced a hybrid working model. Based on the new policy, employees can work remotely for 2 days per week if corporate equipment is used. Th...
Secure Clientremote access VPNendpoint protectionfull-tunnel VPN - Question #8Network Security
A pharmaceutical company needs hub-and-spoke VPN topology. The design must be capable of building either partial or full mesh overlay networks. Which VPN solution must be implement...
DMVPNhub-and-spoke VPNmesh overlayVPN topology - Question #9Network Security
A furniture company recently discovered that the endpoint detection and response configuration flagged several malicious files on company-managed laptops. The company must enhance...
NGFWtraffic inspectionmalware preventioncontent filtering - Question #10Network Security
A bank experienced challenges with compromised endpoints gaining access to the internal network. To enhance security, the bank wants to ensure that all endpoints are scanned for co...
ISE postureNACendpoint compliancenetwork access control - Question #11Network Security
A financial company is in the process of upgrading network access across the entire company. The solution must ensure: - least privilege access - control access across different ne...
RBACleast privilegeaccess controlnetwork segmentation - Question #12Network Security
A global hotel chain is using Cisco ISE and Cisco switches to manage the network. The hotel company wants to enhance network security by segmenting users and endpoints. The company...
TrustSecISEnetwork segmentationVLAN isolation - Question #13Network Security
A financial company uses a remote access solution that directs all traffic over a secure tunnel. The company recently received some large ISP bills from the headcounter location. A...
split tunnelingsplit-excludeVPN optimizationremote access - Question #14Advanced Threat and Endpoint Security
A manufacturing company recently experienced a network-down scenario due to malware spread on the management network. The company wants to implement a solution to detect and mitiga...
EDRmalware detectionmanagement networkendpoint security - Question #15Advanced Threat and Endpoint Security
A technology company has many remote workers who access corporate resources from various locations. The company must ensure that security policies are managed and enforced directly...
host-based firewallendpoint protectionremote workersfirewall architecture - Question #16Network Security
An IT company experienced the spread of malicious content between user endpoints, which impacted business critical resources. The company wants to implement a solution to control c...
TrustSecmicrosegmentationlateral movement preventionendpoint isolation - Question #17Advanced Threat and Endpoint Security
Refer to the exhibit. A retail company recently deployed a file inspection feature using secure endpoint. The file inspection must detect and prevent the execution of malicious fil...
Secure Endpointaudit modefile inspectionpolicy configuration - Question #18Applications
After deploying a new API, the security team must identify the components of the application that are exposed to the internet and whether there are application authentication risks...
API trace analysisAPI securityauthentication monitoringapplication exposure - Question #19Artificial Intelligence, Automation, and DevSecOps
A product manager is focused on maintaining the security integrity of a microservice-based application as new features are developed and integrated. To ensure that known software v...
container scanningSDLC build phasemicroservices securityvulnerability management - Question #20Cloud Security
A logistics company wants to deploy an application in the cloud using cloud native techniques. The company must ensure that the development, testing, and production environments ar...
environment isolationcloud accountscloud-native deploymentproduction security - Question #21Artificial Intelligence, Automation, and DevSecOps
A company has been facing recurring issues with SQL injection vulnerabilities affecting the products, leading to significant disruptions for customers. To address the security conc...
SASTSQL injectionCI/CD pipelinestatic analysis - Question #22Artificial Intelligence, Automation, and DevSecOps
A company published software that had a security vulnerability, and an attacker used the vulnerability to steal critical information from the environment. The issue was reported by...
shift-left securitysource code managementsoftware pipelinepre-deployment testing - Question #23Applications
Refer to the exhibit. A software developer noticed that the application source code had been found on the internet. To avoid such an incident from happening again, the developer ap...
DLP policydata loss preventiongenerative AIpolicy enforcement - Question #24Applications
A developer is building new API functions for a cloud-based application. Before writing the code, the developer wants to ensure that destructive actions, including deleting and upd...
OpenAPI specificationAPI securityaccess controlrisk assessment - Question #25Applications
A retail company is facing a series of cyberattacks targeting the web servers, which results in disruptions to the online services. Upon investigation, the security team identified...
WAFweb application firewallHTTP securityweb attack mitigation - Question #26Endpoint Protection
A developer company recently implemented a testing environment based on Linux operating system. The company needs a technology solution that produces tracing and filtering capabili...
eBPFLinux kerneltracingnetwork filtering - Question #27Secure Connectivity
In preparation for an upcoming security audit, a metal production company decided to enhance the security of container-based services running in a Kubernetes environment. The compa...
service meshmTLSKubernetesencryption at scale - Question #28Applications
An IT company operates an application in a SaaS model. The administrative tasks, such as customer onboarding, within the application must be restricted to users who are on the corp...
RBACrole-based access controlSaaSgranular access control - Question #29Cloud Security
A global energy company moved a monolithic application from the data center to public cloud. Over time, the company added many capabilities to the application, and it is now diffic...
CiliumCNIKubernetescloud-native security - Question #30Artificial Intelligence, Automation, and DevSecOps
An employee of a pharmaceutical company accidentally checked in code that contains AWS secret keys to a public GitHub repository, which exposes production resources to attackers. W...
precommit hooksecret scanningSCMAWS credentials - Question #31Cloud Security
A company hosted multiple applications in the Kubernetes environment, using the naming app01, app02, and so on. An app01 user could access app02 data because no security measures a...
NetworkPolicyKubernetesnamespace isolationmicrosegmentation - Question #32Artificial Intelligence, Automation, and DevSecOps
A software development company relies on GitHub for managing the source code and is committed to maintaining application security. The company must ensure that known software vulne...
Dependabotdependency scanningsemantic versioningGitHub security - Question #33Endpoint Protection
A company recently discovered that a former employee, who left to join a competitor, continued to access and exfiltrate sensitive data over several weeks after leaving. The breach...
DLPdata exfiltrationinsider threataccess control - Question #34Risk, Events, and Requirements
A global marketing firm, based in California with customers on every continent, suffered a data breach that exposed employee and customer PII. Which regulations is the company in d...
GDPRPIIdata breachprivacy regulation - Question #35Risk, Events, and Requirements
An engineering company's Chief Financial Officer recently fall victim to a phishing scam by responding to an urgent email. The mail appeared to be from a trusted business partner,...
phishing awarenesssecurity educationsocial engineeringuser training - Question #36Risk, Events, and Requirements
A healthcare organization in the United States recently discovered that a highly confidential report name Records ______ that includes patient records name Patient_Medical_Records...
HIPAAhealthcare compliancepatient recordsPHI - Question #37Risk, Events, and Requirements
Which financial reporting regulatory framework must a publicly traded company doing business in the US comply with?
SOXfinancial reportingregulatory compliancepublicly traded - Question #38Security Concepts and Design Principles
A security engineer on an application design team must choose a framework of attack patterns to evaluate during threat modeling. Which framework provides the common set of attacks?
threat modelingMITRE CAPECattack patternssecurity frameworks - Question #39Visibility, Detection, and Response
A manufacturing company experienced a security breach that resulted in sales data being compromised. An engineer participating in the investigation must identify who logged into th...
AAAauthenticationaccountingaccess logging - Question #40Risk, Events, and Requirements
The network security team of a private university is conducting a comprehensive audit to evaluate the security posture across the network infrastructure. During the review, the sec...
vulnerability managementCI/CD pipelinerisk assessmentthird-party disclosure - Question #41Visibility, Detection, and Response
How does a SOC leverage flow collectors?
flow collectorsSOCthreat detectionnetwork visibility - Question #42Visibility, Detection, and Response
Which tool is used to collect, analyze, and visualize logs from network devices, endpoints, and other sources in an enterprise?
SIEMSplunklog managementlog analysis - Question #43Visibility, Detection, and Response
Which tool must be used to prioritize incidents by a SOC?
SIEMincident prioritizationSOCsecurity operations - Question #44Risk, Events, and Requirements
Considering recent cybersecurity threats, a company wants to improve the process for identifying, assessing, and managing risks with a comprehensive and holistic approach. Which fr...
risk management frameworkNIST SP 800-37risk assessmentsecurity governance - Question #45Artificial Intelligence, Automation, and DevSecOps
Which benefit does AI provide in network security?
AI securityTLS vulnerabilitiesvulnerability detectionnetwork security - Question #46Artificial Intelligence, Automation, and DevSecOps
Which generative AI impact is addressed by a human-in-the-loop design policy?
generative AIhuman-in-the-loopAI hallucinationsAI governance - Question #47Artificial Intelligence, Automation, and DevSecOps
What is a use for AI in securing network infrastructure?
AI securityzero-day detectionanomaly detectionnetwork security - Question #48Endpoint Protection
Which tool is used by SOC analyst to quarantine an endpoint?
endpoint quarantineCisco XDREDRincident response - Question #49Artificial Intelligence, Automation, and DevSecOps
Which design policy addresses harmful content creation by generative AI?
generative AIwatermarkingharmful contentAI governance - Question #50Artificial Intelligence, Automation, and DevSecOps
What does watermarking AI generated content prevent?
watermarkingdeep fakesAI content integritygenerative AI