Advanced Threat Protection and Content Security for CCIE Security Written v5.0 (400-251)
This page covers the Advanced Threat Protection and Content Security domain of the CCIE Security Written v5.0 (400-251) certification. Master Cybersecurity offers 10 practice questions in this domain, drawn from the same content we use across our timed exam simulations. Below are five sample questions with full answer explanations.
Sample Practice Questions
Question 1
Which two statements are true when comparing ESMTP and SMTP? (Choose two.)- A. Only SMTP inspection is provided on the Cisco ASA firewall.
- B. A mail sender identifies itself as only able to support SMTP by issuing an EHLO command to the mail server.
- C. ESMTP mail servers will respond to an EHLO with a list of the additional extensions they support.
- D. SMTP commands must be in upper case, whereas ESMTP can be either lower or upper case.
- E. ESMTP servers can identify the maximum email size they can receive by using the SIZE command.
Explanation
The correct answers are: C. ESMTP mail servers will respond to an EHLO with a list of the additional extensions they support., E. ESMTP servers can identify the maximum email size they can receive by using the SIZE command..
Extended SMTP is a negotiated superset of the original protocol, and the negotiation is what the true statements describe. A client that supports extensions greets with EHLO instead of HELO, and an ESMTP-capable server answers with a multiline 250 reply whose lines enumerate the extension keywords it offers, such as PIPELINING, STARTTLS, 8BITMIME, DSN and AUTH, so the reply to EHLO is literally the capability list. One of those keywords is SIZE, defined in RFC 1870, which is advertised as SIZE followed by a byte count to tell the client the largest message the server will accept, allowing the client to abandon an oversized message before wasting a full DATA transfer. The claim that a sender signals SMTP-only support with EHLO is backwards, because a plain SMTP client uses HELO and falls back to it if EHLO draws a 500-series error. Command verbs are case-insensitive in both the original RFC 821 grammar and the extended one, so the upper-case rule is invented. The ASA also offers a dedicated esmtp inspection engine rather than only a legacy SMTP engine, and that engine understands the extension keywords and can mask the ones you do not want advertised.
Question 2
In the context of a botnet, what is true regarding a command and control server?- A. It can launch an attack using IRC or Twitter.
- B. It is another name for a zombie.
- C. It is used to generate a worm.
- D. It sends the command to the botnets via adware.
Explanation
The correct answer is: A. It can launch an attack using IRC or Twitter..
A command and control server is the controller side of a botnet, the point from which the attacker issues instructions to the population of infected machines and collects their results. Early botnets used Internet Relay Chat because it gave one-to-many messaging for free: every bot joined a named channel and the topic or a privileged nick issued the commands, which is why blocking TCP 6667 was once a useful containment measure. Later families moved the channel onto HTTP and HTTPS and even onto public social platforms such as Twitter, where bots poll an account and decode instructions from the posted text, because that traffic blends into normal browsing and survives egress filtering. So the statement that the controller can launch an attack using IRC or Twitter correctly describes the range of channels used. A zombie is the infected endpoint taking orders, not the controller giving them, so equating the two confuses the two roles. Worms are written and released by the attacker and spread by self-replication rather than being generated by a controller. Adware is unwanted advertising software and is a nuisance payload category, not a signalling mechanism for commands.
Question 3
What will be the default action?- A. HTTP traffic to the Facebook, Youtube, and Twitter websites will be dropped.
- B. HTTP traffic to the Facebook and Youtube websites will be dropped.
- C. HTTP traffic to the Youtube and Twitter websites will be dropped.
- D. HTTP traffic to the Facebook and Twitter websites will be dropped.
Explanation
The correct answer is: D. HTTP traffic to the Facebook and Twitter websites will be dropped..
In this configuration the regular expression class that is actually referenced by the HTTP inspection policy matches the first and third domain lists, which cover Facebook and Twitter, so those are the sessions the default action tears down while requests to YouTube pass. The lesson underneath is the layering of the ASA Modular Policy Framework for application inspection. A regex statement only defines a pattern. A class-map type regex match-any groups several patterns under one name. Those regex classes then have to be referenced from a class-map type inspect http, typically with match request header host regex class, before a policy-map type inspect http can attach an action such as drop-connection log or reset to the class. Finally the inspect policy has to be invoked from a global or interface service policy through a policy-map type inspect reference. Any regex or regex class-map that is defined but never referenced from the inspection class-map has no effect on traffic at all, which is exactly why a domain list can appear in the running configuration and still not be filtered. Reading such a configuration therefore means following the reference chain rather than simply listing the patterns present.
Question 4
Which statement best describes the concepts of rootkits and privilege escalation?- A. Rootkits propagate themselves.
- B. Privilege escalation is the result of a rootkit.
- C. Rootkits are a result of a privilege escalation.
- D. Both of these require a TCP port to gain access.
Explanation
The correct answer is: B. Privilege escalation is the result of a rootkit..
A rootkit is a toolkit an attacker installs after gaining a foothold, whose purpose is to obtain and then retain the highest privilege level on the system while hiding its own presence. Kernel-mode rootkits load as a driver or loadable kernel module and hook system call tables so that directory listings, process lists and network socket tables no longer report the attacker files, processes and listeners. Because the whole point of the kit is to move the attacker from a limited account or a single exploited service into root or SYSTEM context and keep it, privilege escalation is properly described as the outcome or result of the rootkit, which is why that statement is the accurate one. Self-propagation is the defining behaviour of a worm, not a rootkit, so the claim that rootkits spread themselves belongs to a different malware class. Reversing the causality and saying the rootkit is produced by escalation inverts the relationship, since the kit is the tool and the elevated privilege is the effect. Neither concept depends on a listening TCP port, because escalation is frequently achieved locally through a kernel or setuid flaw with no network socket involved at all.
Question 5
According to OWASP guidelines, what is the recommended method to prevent cross-site request forgery?- A. Allow only POST requests.
- B. Mark all cookies as HTTP only.
- C. Use per-session challenge tokens in links within your web application.
- D. Always use the "secure" attribute for cookies.
- E. Require strong passwords.
Explanation
The correct answer is: C. Use per-session challenge tokens in links within your web application..
Cross-site request forgery works because a browser attaches the victim session cookie automatically to any request aimed at the target site, no matter which page caused the request, so the server cannot tell an intentional action from one triggered by a hostile page. The defence recommended in the OWASP guidance is the synchroniser token pattern: the application generates an unpredictable token bound to the session, embeds it in every state-changing form and link, and rejects any request whose submitted token does not match the stored one. A third-party site cannot read that value because the same-origin policy prevents it from reading the response body of the victim page, so it cannot forge a valid request. Restricting the application to POST helps very little, since a hidden form on the attacker page can be submitted by script without user interaction. Marking cookies HttpOnly stops script from reading them, which mitigates session theft through cross-site scripting rather than forgery. The secure attribute merely keeps the cookie off cleartext HTTP, and strong passwords address credential guessing, which is irrelevant once the user is already authenticated. Modern deployments add the SameSite cookie attribute as well.
Other CCIE Security Written v5.0 (400-251) domains
- Identity Management, Information Exchange, and Access Control (33 questions)
- Infrastructure Security, Virtualization, and Automation (145 questions)
- Perimeter Security and Intrusion Prevention (54 questions)
- Secure Connectivity and Segmentation (87 questions)