[Nov 14, 2023] 350-701 Test Prep Training Practice Exam Questions Practice Tests
Exam Questions Answers Braindumps 350-701 Exam Dumps PDF Questions
Cisco 350-701 certification exam is an ideal choice for IT professionals who want to advance their careers in the field of network security. Implementing and Operating Cisco Security Core Technologies certification is particularly valuable for those who work in security operations centers, network administration, or security consulting. By earning this certification, candidates can demonstrate their ability to design, implement, and manage secure networks and protect them against cyber threats.
Best Revision Book: Introducing Cisco 350-701 Official Certification Guide
The CCNP and CCIE Security Core SCOR 350-701 Official Cert Guide (1st Edition) is one of the most comprehensive study materials you can use to pass 350-701 exam. Why? Because it features a lot of exciting resources that will cover everything about the final test. Written by Omar Santos, this book presents the best combination of tools to help you master all the exam concepts easily. It has quizzes at the beginning of every chapter to help you know what you will cover in every section. Besides, it also has chapter review tasks that will help you achieve much more than just drilling on the vital exam concepts. All in all, the official cert guide for the Cisco 350-701 exam is not only valuable because of the exciting study plans it provides but also for the video instruction from the author, a lot of questions and exercises, and unmatched detail on every test objective to ensure you get everything right at the first attempt.
NEW QUESTION # 259
Drag and drop the posture assessment flow actions from the left into a sequence on the right.
Answer:
Explanation:
NEW QUESTION # 260
Drag and drop the steps from the left into the correct order on the right to enable AppDynamics to monitor an EC2 instance in Amazon Web Services.
Answer:
Explanation:

NEW QUESTION # 261
What is the process of performing automated static and dynamic analysis of files against preloaded behavioral indicators for threat analysis?
- A. deep visibility scan
- B. point-in-time checks
- C. advanced scanning
- D. advanced sandboxing
Answer: D
NEW QUESTION # 262
A network administrator configures Dynamic ARP Inspection on a switch. After Dynamic ARP Inspection is applied, all users on that switch are unable to communicate with any destination. The network administrator checks the interface status of all interfaces, and there is no err-disabled interface. What is causing this problem?
- A. The ip arp inspection limit command is applied on all interfaces and is blocking the traffic of all users.
- B. The no ip arp inspection trust command is applied on all user host interfaces
- C. Dynamic ARP Inspection has not been enabled on all VLANs
- D. DHCP snooping has not been enabled on all VLANs.
Answer: B
Explanation:
Dynamic ARP inspection (DAI) is a security feature that validates ARP packets in a network. It intercepts, logs, and discards ARP packets with invalid IP-to-MAC address bindings. This capability protects the network from certain man-in-the-middle attacks. After enabling DAI, all ports become untrusted ports.
NEW QUESTION # 263
Which license is required for Cisco Security Intelligence to work on the Cisco Next Generation Intrusion Prevention System?
- A. URL filtering
- B. control
- C. protect
- D. matware
Answer: C
NEW QUESTION # 264
Which algorithm is an NGE hash function?
- A. HMAC
- B. SHA-1
- C. MD5
- D. SISHA-2
Answer: D
NEW QUESTION # 265
Which two application layer preprocessors are used by Firepower Next Generation Intrusion Prevention System? (Choose two)
- A. SSL
- B. packet decoder
- C. inline normalization
- D. SIP
- E. modbus
Answer: A,D
Explanation:
Application layer protocols can represent the same data in a variety of ways. The Firepower System provides application layer protocol decoders that normalize specific types of packet data into formats that the intrusion rules engine can analyze. Normalizing application-layer protocol encodings allows the rules engine to effectively apply the same content-related rules to packets whose data is represented differently and obtain meaningful results. Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guidev60/Application_Layer_Preprocessors.html#ID-2244-0000080c FirePower uses many preprocessors, including DNS, FTP/Telnet, SIP, SSL, SMTP, SSH preprocessors.
application layer protocol decoders that normalize specific types of packet data into formats that the intrusion rules engine can analyze. Normalizing application-layer protocol encodings allows the rules engine to effectively apply the same content-related rules to packets whose data is represented differently and obtain meaningful results.
Reference:
Application layer protocols can represent the same data in a variety of ways. The Firepower System provides application layer protocol decoders that normalize specific types of packet data into formats that the intrusion rules engine can analyze. Normalizing application-layer protocol encodings allows the rules engine to effectively apply the same content-related rules to packets whose data is represented differently and obtain meaningful results. Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guidev60/Application_Layer_Preprocessors.html#ID-2244-0000080c FirePower uses many preprocessors, including DNS, FTP/Telnet, SIP, SSL, SMTP, SSH preprocessors.
NEW QUESTION # 266
Drag and drop the solutions from the left onto the solution's benefits on the right.
Answer:
Explanation:
NEW QUESTION # 267
Which exfiltration method does an attacker use to hide and encode data inside DNS requests and queries?
- A. DNS security
- B. DNSCrypt
- C. DNSSEC
- D. DNS tunneling
Answer: D
Explanation:
Explanation
DNS Tunneling is a method of cyber attack that encodes the data of other programs or protocols in DNS queries and responses. DNS tunneling often includes data payloads that can be added to an attacked DNS server and used to control a remote server and applications.
NEW QUESTION # 268
Refer to the exhibit.
Which command was used to display this output?
- A. show dot1x all summary
- B. show dot1x all
- C. show dot1x interface gi1/0/12
- D. show dot1x
Answer: B
NEW QUESTION # 269
What is the purpose of a Netflow version 9 template record?
- A. It serves as a unique identification number to distinguish individual data records
- B. It provides a standardized set of information about an IP flow.
- C. It specifies the data format of NetFlow processes.
- D. It defines the format of data records.
Answer: D
NEW QUESTION # 270
What are the two types of managed Intercloud Fabric deployment models? (Choose two)
- A. Service Provider managed
- B. User managed
- C. Hybrid managed
- D. Public managed
- E. Enterprise managed
Answer: E
Explanation:
Many enterprises prefer to deploy development workloads in the public cloud, primarily for convenience and faster deployment.
This approach can cause concern for IT administrators, who must control the flow of IT traffic and spending and help ensure the security of data and intellectual property.
Without the proper controls, data and intellectual property can escape this oversight.
The Cisco Intercloud Fabric solution helps control this shadow IT, discovering resources deployed in the public cloud outside IT control and placing these resources under Cisco Intercloud Fabric control.
Cisco Intercloud Fabric addresses the cloud deployment requirements appropriate for two hybrid cloud deployment models:
Enterprise Managed (an enterprise manages its own cloud environments) and Service Provider Managed (the service provider administers and controls all cloud resources).
Reference: https://www.cisco.com/c/en/us/td/docs/solutions/Hybrid_Cloud/Intercloud/Intercloud_Fabric.pdf
The Cisco Intercloud Fabric architecture provides two product configurations to address the following two consumption models:
+ Cisco Intercloud Fabric for Business + Cisco Intercloud Fabric for Providers
Reference: https://www.cisco.com/c/en/us/td/docs/solutions/Hybrid_Cloud/Intercloud/Intercloud_Fabric/Intercloud_Fabric_2.html
NEW QUESTION # 271
Drag and drop the capabilities of Cisco Firepower versus Cisco AMP from the left into the appropriate category on the right.
Answer:
Explanation:
NEW QUESTION # 272
A user has a device in the network that is receiving too many connection requests from multiple machines.
Which type of attack is the device undergoing?
- A. phishing
- B. pharming
- C. SYN flood
- D. slowloris
Answer: C
NEW QUESTION # 273
What are two DDoS attack categories? (Choose two.)
- A. protocol
- B. source-based
- C. sequential
- D. database
- E. volume-based
Answer: A,E
NEW QUESTION # 274
An organization is trying to improve their Defense in Depth by blocking malicious destinations prior to a connection being established. The solution must be able to block certain applications from being used within the network. Which product should be used to accomplish this goal?
- A. AMP
- B. Cisco Umbrella
- C. Cisco Firepower
- D. ISE
Answer: B
Explanation:
Cisco Umbrella protects users from accessing malicious domains by proactively analyzing and blocking unsafe destinations - before a connection is ever made. Thus it can protect from phishing attacks by blocking suspicious domains when users click on the given links that an attacker sent.
NEW QUESTION # 275
An engineer used a posture check on a Microsoft Windows endpoint and discovered that the MS17-010 patch was not installed, which left the endpoint vulnerable to WannaCry ransomware. Which two solutions mitigate the risk of this ransomware infection? (Choose two.)
- A. Configure a posture policy in Cisco Identity Services Engine to install the MS17-010 patch before allowing access on the network.
- B. Configure endpoint firewall policies to stop the exploit traffic from being allowed to run and replicate throughout the network.
- C. Set up a profiling policy in Cisco Identity Service Engine to check and endpoint patch level before allowing access on the network.
- D. Set up a well-defined endpoint patching strategy to ensure that endpoints have critical vulnerabilities patched in a timely fashion.
- E. Configure a posture policy in Cisco Identity Services Engine to check that an endpoint patch level is met before allowing access on the network.
Answer: D,E
NEW QUESTION # 276
Which two cryptographic algorithms are used with IPsec? (Choose two)
- A. AES-CBC
- B. AES-ABC
- C. HMAC-SHA1/SHA2
- D. AES-BAC
- E. Triple AMC-CBC
Answer: A,C
Explanation:
Explanation
Explanation
Cryptographic algorithms defined for use with IPsec include:
+ HMAC-SHA1/SHA2 for integrity protection and authenticity.
+ TripleDES-CBC for confidentiality
+ AES-CBC and AES-CTR for confidentiality.
+ AES-GCM and ChaCha20-Poly1305 providing confidentiality and authentication together efficiently.
NEW QUESTION # 277
Which two criteria must a certificate meet before the WSA uses it to decrypt application traffic? (Choose two.)
- A. It must reside in the trusted store of the endpoint.
- B. It must include the current date.
- C. It must have been signed by an internal CA.
- D. it must contain a SAN.
- E. It must reside in the trusted store of the WSA.
Answer: B,E
NEW QUESTION # 278
Drag and drop the features of Cisco ASA with Firepower from the left onto the benefits on the right.
Answer:
Explanation:
NEW QUESTION # 279
I I
An engineer musiet up 200 new laptops on a network and wants to prevent the users from moving their laptops around to simplify administration Which switch port MAC address security setting must be used?
- A. sticky
- B. aging
- C. maximum
- D. static
Answer: A
NEW QUESTION # 280
What two mechanisms are used to redirect users to a web portal to authenticate to ISE for guest services?
(Choose two.)
- A. single sign-on
- B. central web auth
- C. TACACS+
- D. local web auth
- E. multiple factor auth
Answer: B,D
NEW QUESTION # 281
Which benefit is provided by ensuring that an endpoint is compliant with a posture policy configured in Cisco ISE?
- A. It allows CoA to be applied if the endpoint status is compliant.
- B. It allows the endpoint to authenticate with 802.1xor MAB.
- C. It verifies that the endpoint has the latest Microsoft security patches installed.
- D. It adds endpoints to identity groups dynamically.
Answer: C
NEW QUESTION # 282
Drag and drop the capabilities from the left onto the correct technologies on the right.
Answer:
Explanation:
NEW QUESTION # 283
......
Cisco 350-701 exam consists of 90-110 multiple-choice and simulation questions, and it takes 120 minutes to complete. 350-701 exam is available in English and Japanese and can be taken at any Pearson VUE testing center or online. 350-701 exam fee is $400, and candidates must pass the exam to earn the Cisco Certified Specialist – Security Core certification.
Download Free Cisco 350-701 Real Exam Questions: https://pass4sure.testvalid.com/350-701-valid-exam-test.html