Designing Cisco Security Infrastructure (SDSI) Free Sample Questions

Create a free account to browse all 12 sample questions. The full practice test includes 150 questions. Use the simulator for timed and flashcard mode.

Try Simulator

300-745 Sample Questions

  1. Question 1

    Q1

    An organization is transitioning from a traditional VPN architecture to a Zero Trust Network Access (ZTNA) model. Which approach best demonstrates the principle of continuous trust when securing remote endpoints?

    Show answer & explanation

    Correct answer: B

    Continuous trust (or continuous adaptive risk and trust assessment - CARTA) moves away from point-in-time authentication. Instead of verifying a user or device only at the initial login, the system continuously evaluates the device's security posture, location, and user behavior throughout the session. If the risk level changes (e.g., malware is detected or the user moves to a high-risk location), access can be dynamically revoked or restricted.

  2. Question 2

    Q2

    A multinational financial institution is redesigning its email security architecture to combat a surge in Business Email Compromise (BEC) and ransomware delivered via malicious attachments. The current environment relies solely on the default protections provided by their cloud email provider.

    The security architect must select a comprehensive design that addresses both spoofing of executive domains and zero-day malware dropping payloads.

    Which combination of technologies provides the optimal architectural defense against these specific threats?

    Show answer & explanation

    Correct answer: B

    To combat BEC (which relies heavily on domain spoofing), DMARC with a 'p=reject' policy is the industry standard, as it ensures that emails claiming to be from the organization actually align with SPF and DKIM validations. To combat ransomware via zero-day attachments, Cisco Secure Email Threat Defense (which integrates via API to cloud providers like Microsoft 365) provides advanced malware analysis, sandboxing, and retrospective security to catch payloads that bypass native cloud email filters.

  3. Question 3

    Q3

    True or False: Passwordless authentication completely eliminates the use of cryptographic keys, relying entirely on biometric data (such as fingerprints or facial recognition) transmitted to the central authentication server.

    Show answer & explanation

    Correct answer: B

    False. Passwordless authentication (such as FIDO2/WebAuthn) heavily relies on asymmetric cryptographic keys. The biometric data is used locally on the device to unlock a private key stored in a hardware enclave (like a TPM). The biometric data itself is never transmitted to the central authentication server; instead, the device signs a cryptographic challenge to prove the user's identity.

  4. Question 4

    Q4

    A security architect is designing a solution to gain visibility into unsanctioned application usage (Shadow IT) across a globally distributed workforce. Users frequently bypass the corporate VPN when working from home. Which technology should the architect select to enforce data security policies on these unmanaged SaaS applications?

    Show answer & explanation

    Correct answer: B

    A Cloud Access Security Broker (CASB) is specifically designed to discover Shadow IT, monitor SaaS usage, and enforce data security policies (like DLP) on cloud applications. Because the users are remote and bypassing the VPN, integrating the CASB with an endpoint-based Secure Web Gateway (SWG) roaming client (such as Cisco Umbrella) ensures that the traffic is inspected and policies are enforced regardless of the user's physical location.

  5. Question 5

    Q5

    A manufacturing plant relies on legacy Programmable Logic Controllers (PLCs) that cannot run endpoint security agents and cannot be patched. The architect must design a solution to prevent lateral movement of malware if an IT workstation is compromised. Which design provides the best protection for these unmanaged OT devices?

    Show answer & explanation

    Correct answer: B

    Legacy OT devices (like PLCs) cannot run agents, making host-based solutions impossible. Cisco Cyber Vision uses passive network monitoring to discover industrial assets and their communication flows without disrupting them. By integrating this visibility with Cisco Identity Services Engine (ISE), the architect can enforce TrustSec (SGT-based) microsegmentation, restricting the PLCs to communicate only with authorized engineering workstations, effectively preventing lateral movement from a general IT compromise.

  6. Question 6

    Q6

    An enterprise is migrating monolithic applications from its on-premises data center to AWS and Azure. The security team mandates that identical workload protection and microsegmentation policies must be enforced regardless of where the application resides. Which approach best satisfies this multi-cloud requirement?

    Show answer & explanation

    Correct answer: B

    Cisco Secure Workload provides consistent, zero-trust microsegmentation across on-premises data centers and public clouds (AWS, Azure, GCP). By utilizing software agents on the workloads themselves (or integrating with cloud APIs), it enforces identity-driven policies consistently at the workload level, agnostic of the underlying network infrastructure. Managing disparate native cloud security groups manually would violate the requirement for a unified, consistent policy approach.

Register free to unlock 6 more sample questions

Create a free account to continue with the rest of the 300-745 sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 150 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon