200-301 - Security Fundamentals - Section 5.1

Define key security concepts (threats, vulnerabilities, exploits, and mitigation techniques), describe security program elements, and describe IPsec remote access and site-to-site VPNs.

Distinguish a vulnerability (a weakness), a threat (something that could exploit it), an exploit (the actual mechanism), and the mitigation that reduces risk, and place user awareness, training, and physical access control as program elements. Describe how IPsec protects traffic across an untrusted network with confidentiality, integrity, and authentication, and contrast remote-access VPNs for individual users with site-to-site VPNs that join two networks.

Threat vs vulnerability vs exploitMitigation techniquesSecurity program elementsIPsec VPNRemote-access vs site-to-site VPN

Practice question for this objective

Free sampleSecurity Fundamentalsmedium

A new chief information security officer is building a formal security programme and asks which organisational measures, aimed at how people behave and how the premises are protected, should be funded first rather than purely technical controls on the network devices. Which two of the following are recognised elements of a security programme that address those people-and-premises concerns? Select TWO.

  • AA user awareness initiative that teaches staff to recognise phishing emails and report suspicious messages promptly. Correct
  • BAn access control list applied inbound on the router to permit only approved TCP ports toward the server farm.
  • CPhysical access control such as badge readers and locked wiring closets that limit who can reach the equipment. Correct
  • DA floating static route configured with a higher administrative distance to back up the primary learned path.
  • EAn EtherChannel bundle that aggregates two uplinks so traffic keeps flowing if one member link fails.
Recognise that a security programme rests on organisational elements such as user awareness, user training, and physical access control rather than only device controls. A security programme addresses the human and physical layers of an organisation. User awareness and physical access control are explicitly named programme elements: the first lowers the chance that staff fall for social engineering, and the second stops unauthorised people from physically reaching equipment. ACLs, floating static routes, and EtherChannel are technical network features for filtering, routing resilience, and link redundancy, so none of them is a security-programme element even though each contributes to a robust network.

Why A is correct: User awareness is a core security-programme element; it reduces human risk by helping staff spot social-engineering attempts before they cause a breach.

Why B is wrong: An ACL is a tempting pick because it enforces security, but it is a technical packet-filtering control on a device, not an organisational programme element about people or premises.

Why C is correct: Physical access control is a named security-programme element; restricting who can touch devices and cabling protects assets the people-and-premises layer relies on.

Why D is wrong: A floating static route sounds protective through redundancy, but it is a routing resilience mechanism for failover and has nothing to do with a security programme.

Why E is wrong: EtherChannel improves link availability and bandwidth, which can feel like security, but it is a switching redundancy feature, not an element of a security programme.

See more 200-301 practice questions, answers explained.

More in this domain

Back to all Security Fundamentals objectives, or the 200-301 cert hub.

Examworthy is not affiliated with or endorsed by Cisco. Original, blueprint-aligned practice material only.