Security Concepts for Implementing and Operating Cisco Security Core Technologies (SCOR 350-701)

This page covers the Security Concepts domain of the Implementing and Operating Cisco Security Core Technologies (SCOR 350-701) certification. Master Cybersecurity offers 102 practice questions in this domain, drawn from the same content we use across our timed exam simulations. Below are five sample questions with full answer explanations.

Sample Practice Questions

  1. Question 1

    Which functions of an SDN architecture require southbound APIs to enable communication?
    1. A. SDN controller and the network elements
    2. B. management console and the SDN controller
    3. C. management console and the cloud
    4. D. SDN controller and the cloud
    Explanation

    The correct answer is: A. SDN controller and the network elements.

    Southbound APIs run between the SDN controller and the network elements it programs, meaning the routers, switches, firewalls, and access points that actually forward traffic. The controller uses them to push configuration and flow state down into the data plane and to read operational state back, through interfaces such as OpenFlow, NETCONF with YANG models, RESTCONF, or vendor CLI and SNMP shims where a device lacks a modern interface. The complementary direction, from a management console or an orchestration and analytics application into the controller, is the northbound API, which is where business intent is expressed and is not the southbound role. A link between a management console and a cloud service is simply an external integration and sits outside the controller-to-device relationship being described. Likewise, a controller talking to a cloud platform is either a northbound consumer relationship or an east-west peering, again not the interface that programs forwarding hardware. Remembering that south points down toward the devices keeps the two directions straight.

  2. Question 2

    The main function of northbound APIs in the SDN architecture is to enable communication between which two areas of a network?
    1. A. SDN controller and the cloud
    2. B. management console and the SDN controller
    3. C. management console and the cloud
    4. D. SDN controller and the management solution
    Explanation

    The correct answer is: D. SDN controller and the management solution.

    In software-defined networking the controller sits between the devices it programs and the software that tells it what the network should do, and the northbound interface is the upward-facing half of that split: it exposes the controller to the management and orchestration solution, normally as a REST API consumed by automation, analytics, and policy tools. That upward pairing of controller and management solution is precisely what northbound means, and it is deliberately broader than one graphical front end because the same interface serves orchestrators, security applications, and scripts alike. The downward half is the southbound interface, which uses OpenFlow, NETCONF, or OpFlex to push forwarding and policy state into routers and switches. Naming an operator console by itself describes only one possible consumer rather than the management solution the interface exists to serve. Pairing the controller with the cloud, or a console with the cloud, matches no defined interface here, because the controller is always one endpoint of both the northbound and southbound path.

  3. Question 3

    Which form of attack is launched using botnets?
    1. A. TCP flood
    2. B. DDOS
    3. C. DOS
    4. D. virus
    Explanation

    The correct answer is: B. DDOS.

    A botnet is a collection of compromised hosts under a single command and control channel, so when it is turned against a victim the flood arrives from many sources at once, which is by definition a distributed denial of service. That distributed sourcing is what makes the attack hard to stop: the addresses belong to legitimate infected machines spread across many networks and providers, so blocking one address achieves nothing and mitigation relies on upstream scrubbing, rate limiting, and anycast absorption. A plain denial of service comes from a single system or a small handful, as with a slowloris that holds connections open from one host, and it is far easier to trace and filter, so it does not describe botnet-driven traffic. A TCP flood such as a SYN flood names a specific technique for exhausting connection state rather than the overall class of attack, and it can be launched with or without a botnet. A virus is malware that spreads by infecting files and may be what recruited the bots in the first place, but it is not the attack the botnet then performs.

  4. Question 4

    In which form of attack is alternate encoding, such as hexadecimal representation, most often observed?
    1. A. smurf
    2. B. distributed denial of service
    3. C. cross-site scripting
    4. D. rootkit exploit
    Explanation

    The correct answer is: C. cross-site scripting.

    Cross-site scripting is the attack where alternate encodings are the standard evasion technique, because the attacker only needs a browser to interpret the payload as script while the server-side filter fails to recognise it as one. Writing the same characters as hexadecimal escapes, HTML entities, percent-encoding, decimal references, Unicode escapes, or base64 hides keywords such as script and javascript from naive block lists, and layering encodings defeats filters that decode only once. The correct defences are context-appropriate output encoding, allow-list input validation applied after canonicalising the input, and a Content Security Policy, rather than pattern matching on raw strings. A smurf attack floods a victim by sending ICMP echo requests to a broadcast address with a spoofed source, so payload content is irrelevant to it. Distributed denial of service turns on volume and protocol exhaustion, not crafted characters. A rootkit exploit is about hiding privileged code on an already compromised host.

  5. Question 5

    Which flaw does an attacker leverage when exploiting SQL injection vulnerabilities?
    1. A. user input validation in a web page or web application
    2. B. Linux and Windows operating systems
    3. C. database
    4. D. web page images
    Explanation

    The correct answer is: A. user input validation in a web page or web application.

    SQL injection succeeds when a web page or web application takes what a user typed and stitches it directly into a database query without validating or parameterizing it, so the flaw being leveraged is that missing input validation in the application layer. Quotes, semicolons, comment markers, and boolean tricks placed in a form field or URL parameter then change the meaning of the statement, letting the attacker read other people's rows, bypass a login, or in some deployments run administrative commands. The fix lives in the same layer, using prepared statements and parameterized queries that keep data separate from code, plus allow-list validation, least-privilege database accounts, and a web application firewall for depth. The operating system underneath, whether Linux or Windows, is not the weakness, and patching it does not stop the attack. The database is the target and the source of the exposed data, yet it behaves correctly by executing exactly the statement it was handed. Images on the page are static content and play no part in query construction.

Other Implementing and Operating Cisco Security Core Technologies (SCOR 350-701) domains

Practice all 102 Security Concepts questions · Browse Implementing and Operating Cisco Security Core Technologies (SCOR 350-701)