300-745 Sample Questions

300-745 Sample Questions & Answers

Choosing security approaches and VPN tunneling solutions ties for the heaviest weight with how the SOC handles incidents and mitigates risk, alongside firewall and DLP design for cloud-native applications, and AI-driven automation across DevSecOps pipelines.

Launch the full 300-745 simulator →

Showing 6 of 12 free samples.

  1. Question 1Intermediate

    Secure Infrastructure · SaaS

    A security architect is designing a solution to gain visibility into unsanctioned application usage (Shadow IT) across a globally distributed workforce. Users frequently bypass the corporate VPN when working from home. Which technology should the architect select to enforce data security policies on these unmanaged SaaS applications?

    Show answer & explanation

    Correct answer: C

    A Cloud Access Security Broker (CASB) is specifically designed to discover Shadow IT, monitor SaaS usage, and enforce data security policies (like DLP) on cloud applications. Because the users are remote and bypassing the VPN, integrating the CASB with an endpoint-based Secure Web Gateway (SWG) roaming client (such as Cisco Umbrella) ensures that the traffic is inspected and policies are enforced regardless of the user's physical location.

  2. Question 2Intermediate

    Secure Infrastructure · IoT

    A manufacturing plant relies on legacy Programmable Logic Controllers (PLCs) that cannot run endpoint security agents and cannot be patched. The architect must design a solution to prevent lateral movement of malware if an IT workstation is compromised. Which design provides the best protection for these unmanaged OT devices?

    Show answer & explanation

    Correct answer: C

    Legacy OT devices (like PLCs) cannot run agents, making host-based solutions impossible. Cisco Cyber Vision uses passive network monitoring to discover industrial assets and their communication flows without disrupting them. By integrating this visibility with Cisco Identity Services Engine (ISE), the architect can enforce TrustSec (SGT-based) microsegmentation, restricting the PLCs to communicate only with authorized engineering workstations, effectively preventing lateral movement from a general IT compromise.

  3. Question 3Intermediate

    Secure Infrastructure · Applications across data center and multi-cloud

    An enterprise is migrating monolithic applications from its on-premises data center to AWS and Azure. The security team mandates that identical workload protection and microsegmentation policies must be enforced regardless of where the application resides. Which approach best satisfies this multi-cloud requirement?

    Show answer & explanation

    Correct answer: B

    Cisco Secure Workload provides consistent, zero-trust microsegmentation across on-premises data centers and public clouds (AWS, Azure, GCP). By utilizing software agents on the workloads themselves (or integrating with cloud APIs), it enforces identity-driven policies consistently at the workload level, agnostic of the underlying network infrastructure. Managing disparate native cloud security groups manually would violate the requirement for a unified, consistent policy approach.

  4. Question 4Intermediate

    Secure Infrastructure · Select a VPN and tunneling solution such as SD-WAN, IPsec, MPLS, GRE, DMVPN, and public cloud tunnel options based on business and technical requirements

    A retail organization has 500 branch locations using legacy routers. They require a VPN solution that provides dynamic spoke-to-spoke communication to reduce latency for point-of-sale transactions between branches. They do not have the budget to upgrade to SD-WAN edge devices immediately. Which tunneling solution should the architect select?

    Show answer & explanation

    Correct answer: A

    DMVPN Phase 3 is ideal for organizations with legacy routing infrastructure that require scalable, dynamic spoke-to-spoke connectivity. It utilizes Multipoint GRE (mGRE) and Next Hop Resolution Protocol (NHRP) to allow branch sites (spokes) to dynamically establish secure IPsec tunnels directly with one another without requiring traffic to hairpin through a central hub, reducing latency. Static GRE would require an unmanageable full-mesh configuration (N*(N-1)/2 tunnels).

  5. Question 5Advanced

    Secure Infrastructure · Select a VPN and tunneling solution such as SD-WAN, IPsec, MPLS, GRE, DMVPN, and public cloud tunnel options based on business and technical requirements

    A healthcare provider is deploying a new wide area network. They have strict compliance requirements that all patient data must be encrypted in transit. Additionally, they use a cloud-hosted VoIP solution that is highly sensitive to jitter and packet loss. They have dual WAN links (MPLS and Direct Internet Access) at each site.

    Which architecture provides the optimal balance of compliance and application performance?

    Show answer & explanation

    Correct answer: D

    Cisco Catalyst SD-WAN can build IPsec tunnels over any transport (MPLS, Internet, LTE), satisfying the strict compliance requirement that all data (including VoIP) be encrypted in transit. To solve the performance issue, SD-WAN utilizes Application-Aware Routing (AAR), which continuously measures packet loss, latency, and jitter across all available WAN links and dynamically routes sensitive traffic (like VoIP) over the optimal path in real-time.

    graph TD Branch[Branch Edge Router] MPLS((MPLS Transport)) DIA((Internet Transport)) Cloud[Cloud VoIP Provider] DataCenter[Healthcare DC] Branch -->|IPsec Tunnel 1| MPLS Branch -->|IPsec Tunnel 2| DIA MPLS --> DataCenter DIA --> Cloud classDef secure fill:#d4edda,stroke:#28a745,stroke-width:2px; class Branch,DataCenter secure;
  6. Question 6Beginner

    Secure Infrastructure · Select the approach to secure the infrastructure management and control planes

    What is the primary security objective of implementing Control Plane Policing (CoPP) on a core routing device?

    Show answer & explanation

    Correct answer: A

    Control Plane Policing (CoPP) is a security feature designed to protect the control plane (the CPU and memory) of a network device. By applying QoS rate-limiting and filtering rules specifically to traffic destined to the router (such as routing protocol updates, ICMP, or management traffic), CoPP prevents DoS attacks or network anomalies from exhausting the device's CPU, ensuring it can continue routing data plane traffic efficiently.

Ready for the real thing?

The full 300-745 simulator has every exam-style question, timed mode, and instant scoring.