Pre-Winter Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: cramtick70

350-701 Implementing and Operating Cisco Security Core Technologies (SCOR 350-701 v2.0) Questions and Answers

Questions 4

A network administrator configures Dynamic ARP Inspection on a switch. After Dynamic ARP Inspection is applied, all users on that switch are unable to communicate with any destination. The network administrator checks the interface status of all interfaces, and there is no err-disabled interface. What is causing this problem?

Options:

A.

DHCP snooping has not been enabled on all VLANs.

B.

The ip arp inspection limit command is applied on all interfaces and is blocking the traffic of all users.

C.

Dynamic ARP Inspection has not been enabled on all VLANs

D.

The no ip arp inspection trust command is applied on all user host interfaces

Buy Now
Questions 5

What is a benefit of flexible NetFlow records?

Options:

A.

They are used for security

B.

They are used for accounting

C.

They monitor a packet from Layer 2 to Layer 5

D.

They have customized traffic identification

Buy Now
Questions 6

Which configuration method provides the options to prevent physical and virtual endpoint devices that are in the same base EPG or uSeg from being able to communicate with each other with Vmware VDS or Microsoft vSwitch?

Options:

A.

inter-EPG isolation

B.

inter-VLAN security

C.

intra-EPG isolation

D.

placement in separate EPGs

Buy Now
Questions 7

Which solution stops unauthorized access to the system if a user ' s password is compromised?

Options:

A.

VPN

B.

MFA

C.

AMP

D.

SSL

Buy Now
Questions 8

Which two mechanisms are used to control phishing attacks? (Choose two)

Options:

A.

Enable browser alerts for fraudulent websites.

B.

Define security group memberships.

C.

Revoke expired CRL of the websites.

D.

Use antispyware software.

E.

Implement email filtering techniques.

Buy Now
Questions 9

What is the recommendation in a zero-trust model before granting access to corporate applications and resources?

Options:

A.

To use a wired network, not wireless

B.

To use strong passwords

C.

To use multifactor authentication

D.

To disconnect from the network when inactive

Buy Now
Questions 10

A Cisco ESA network administrator has been tasked to use a newly installed service to help create policy based on the reputation verdict. During testing, it is discovered that the Cisco ESA is not dropping files that have an undetermined verdict. What is causing this issue?

Options:

A.

The policy was created to send a message to quarantine instead of drop

B.

The file has a reputation score that is above the threshold

C.

The file has a reputation score that is below the threshold

D.

The policy was created to disable file analysis

Buy Now
Questions 11

A security administrator must implement a network intrusion policy in Cisco Secure Firewall to block new potential threats without sacrificing network performance. The administrator plans to create a base policy with a broad rule set optimized to protect the environment without significantly affecting throughput. Which type of policy should the administrator create?

Options:

A.

Maximum Detection

B.

Balanced Security and Connectivity

C.

Connectivity Over Security

D.

Security Over Connectivity

Buy Now
Questions 12

What are two benefits of using Cisco Duo as an MFA solution? (Choose two.)

Options:

A.

grants administrators a way to remotely wipe a lost or stolen device

B.

provides simple and streamlined login experience for multiple applications and users

C.

native integration that helps secure applications across multiple cloud platforms or on-premises environments

D.

encrypts data that is stored on endpoints

E.

allows for centralized management of endpoint device applications and configurations

Buy Now
Questions 13

What is the purpose of the Decrypt for Application Detection feature within the WSA Decryption options?

Options:

A.

It decrypts HTTPS application traffic for unauthenticated users.

B.

It alerts users when the WSA decrypts their traffic.

C.

It decrypts HTTPS application traffic for authenticated users.

D.

It provides enhanced HTTPS application detection for AsyncOS.

Buy Now
Questions 14

What is a function of Cisco AMP for Endpoints?

Options:

A.

It detects DNS attacks

B.

It protects against web-based attacks

C.

It blocks email-based attacks

D.

It automates threat responses of an infected host

Buy Now
Questions 15

Which command is used to log all events to a destination colector 209.165.201.107?

Options:

A.

CiscoASA(config-pmap-c)#flow-export event-type flow-update destination 209.165.201.10

B.

CiscoASA(config-cmap)# flow-export event-type all destination 209.165.201.

C.

CiscoASA(config-pmap-c)#flow-export event-type all destination 209.165.201.10

D.

CiscoASA(config-cmap)#flow-export event-type flow-update destination 209.165.201.10

Buy Now
Questions 16

Which method must be used to connect Cisco Secure Workload to external orchestrators at a client site when the client does not allow incoming connections?

Options:

A.

source NAT

B.

reverse tunnel

C.

GRE tunnel

D.

destination NAT

Buy Now
Questions 17

Which feature requires a network discovery policy on the Cisco Firepower Next Generation Intrusion Prevention

System?

Options:

A.

Security Intelligence

B.

Impact Flags

C.

Health Monitoring

D.

URL Filtering

Buy Now
Questions 18

What is the difference between deceptive phishing and spear phishing?

Options:

A.

Deceptive phishing is an attack aimed at a specific user in the organization who holds a C-level role.

B.

A spear phishing campaign is aimed at a specific person versus a group of people.

C.

Spear phishing is when the attack is aimed at the C-level executives of an organization.

D.

Deceptive phishing hijacks and manipulates the DNS server of the victim and redirects the user to a false webpage.

Buy Now
Questions 19

Which two Cisco Umbrella security categories are used to prevent command-and-control callbacks on port 53 and protect users from being tricked into providing confidential information? (Choose two.)

Options:

A.

DNS Tunneling VPN

B.

Dynamic DNS

C.

Newly Seen Domains

D.

Potentially Harmful Domains

E.

Phishing Attacks

Buy Now
Questions 20

A customer has various external HTTP resources available including Intranet. Extranet, and Internet, with a proxy configuration running in explicit mode Which method allows the client desktop browsers to be configured to select when to connect direct or when to use the proxy?

Options:

A.

Transparent mode

B.

Forward file

C.

PAC file

D.

Bridge mode

Buy Now
Questions 21

Drag and drop the cloud security assessment components from the left onto the definitions on the right.

Options:

Buy Now
Questions 22

Which action configures the IEEE 802.1X Flexible Authentication feature lo support Layer 3 authentication mechanisms?

Options:

A.

Identity the devices using this feature and create a policy that allows them to pass Layer 2 authentication.

B.

Configure WebAuth so the hosts are redirected to a web page for authentication.

C.

Modify the Dot1x configuration on the VPN server lo send Layer 3 authentications to an external authentication database

D.

Add MAB into the switch to allow redirection to a Layer 3 device for authentication.

Buy Now
Questions 23

An organization wants to reduce their attach surface for cloud applications. They want to understand application communications, detect abnormal application Behavior, and detect vulnerabilities within the applications. Which action accomplishes this task?

Options:

A.

Configure Cisco Secure Workload to detect anomalies and vulnerabilities.

B.

Use Cisco ISE to provide application visibility and restrict access to them.

C.

Implement Cisco Umbrella lo control the access each application is granted.

D.

Modify the Cisco Duo configuration to restrict access between applications.

Buy Now
Questions 24

Which RADIUS attribute can you use to filter MAB requests in an 802.1 x deployment?

Options:

A.

1

B.

2

C.

6

D.

31

Buy Now
Questions 25

When a Cisco Secure Web Appliance checks a web request, what occurs if it is unable to match a user-defined policy?

Options:

A.

It applies the next identification profile policy.

B.

It applies the advanced policy.

C.

It applies the global policy.

D.

It blocks the request.

Buy Now
Questions 26

Which Cisco cloud security software centrally manages policies on multiple platforms such as Cisco ASA, Cisco Firepower, Cisco Meraki, and AWS?

Options:

A.

Cisco Defense Orchestrator

B.

Cisco Configuration Professional

C.

Cisco Secureworks

D.

Cisco DNAC

Buy Now
Questions 27

An engineer needs to configure a Cisco Secure Email Gateway (SEG) to prompt users to enter multiple forms of identification before gaining access to the SEG. The SEG must also join a cluster using the preshared key of cisc421555367. What steps must be taken to support this?

Options:

A.

Enable two-factor authentication through a RADIUS server, and then join the cluster via the SEG GUI.

B.

Enable two-factor authentication through a TACACS+ server, and then join the cluster via the SEG CLI.

C.

Enable two-factor authentication through a RADIUS server, and then join the cluster via the SEG CLI

D.

Enable two-factor authentication through a TACACS+ server, and then join the cluster via the SEG GUI.

Buy Now
Questions 28

A company identified a phishing vulnerability during a pentest. What are two ways the company can protect employees from the attack? (Choose two.)

Options:

A.

using Cisco Umbrella

B.

using Cisco FTD

C.

using Cisco ISE

D.

using Cisco Secure Email Gateway

E.

using an inline IPS/IDS in the network

Buy Now
Questions 29

What is a benefit of using Cisco FMC over Cisco ASDM?

Options:

A.

Cisco FMC uses Java while Cisco ASDM uses HTML5.

B.

Cisco FMC provides centralized management while Cisco ASDM does not.

C.

Cisco FMC supports pushing configurations to devices while Cisco ASDM does not.

D.

Cisco FMC supports all firewall products whereas Cisco ASDM only supports Cisco ASA devices

Buy Now
Questions 30

What is a benefit of an endpoint patch management strategy?

Options:

A.

Patches are deployed without a testing phase.

B.

Fewer staff is needed to manage the endpoints.

C.

Endpoints are resistant to vulnerabilities.

D.

Ensures adherence to regulatory and compliance standards.

Buy Now
Questions 31

A security engineer must configure a Splunk Universal Forwarder to send network traffic logs from Cisco Catalyst switches to a Splunk indexer cluster. Strict compliance requirements require all network traffic logs to be ingested into Splunk as an audit trail. The environment includes thousands of forwarders, and the data must be distributed across all indexers. Which two configuration actions must be performed? (Choose two.)

Options:

A.

Configure outputs.conf with the DNS names and indexing ports of all indexers within the cluster.

B.

Implement a large output queue in outputs.conf and disable automatic load balancing.

C.

Configure the forwarder to write logs to a local file share and schedule a batch job to copy the data into the indexers.

D.

Use a deployment server to push an application containing outputs.conf to all Universal Forwarders.

E.

Configure a single primary indexer in outputs.conf and enable a forced connection.

Buy Now
Questions 32

A network engineer must enable SSH and SCP on a Cisco IOS router. The engineer has already generated the encryption keys and enabled SCP services on the router. Which configuration action must be performed next?

Options:

A.

Enable SSHv2 in the configuration.

B.

Restrict access to specific SSH commands.

C.

Enable SCP strict host-key checking.

D.

Add an ACL to deny access from the LAN.

Buy Now
Questions 33

Which technology is used to improve web traffic performance by proxy caching?

Options:

A.

WSA

B.

Firepower

C.

FireSIGHT

D.

ASA

Buy Now
Questions 34

Drag and drop the security responsibilities from the left onto the corresponding cloud service models on the right.

Options:

Buy Now
Questions 35

Refer to the exhibit.

A network administrator configured a site-to-site VPN tunnel between two Cisco IOS routers, and hosts are unable to communicate between two sites of VPN. The network administrator runs the debug crypto isakmp sa command to track VPN status. What is the problem according to this command output?

Options:

A.

hashing algorithm mismatch

B.

encryption algorithm mismatch

C.

authentication key mismatch

D.

interesting traffic was not applied

Buy Now
Questions 36

Why is it important to have a patching strategy for endpoints?

Options:

A.

to take advantage of new features released with patches

B.

so that functionality is increased on a faster scale when it is used

C.

so that known vulnerabilities are targeted and having a regular patch cycle reduces risks

D.

so that patching strategies can assist with disabling nonsecure protocols in applications

Buy Now
Questions 37

Which solution should be leveraged for secure access of a CI/CD pipeline?

Options:

A.

Duo Network Gateway

B.

remote access client

C.

SSL WebVPN

D.

Cisco FTD network gateway

Buy Now
Questions 38

A large enterprise is currently managing a hybrid environment consisting of a private data center and multiple public cloud providers. The security engineering team is concerned about “Shadow IT” and the lack of visibility into unauthorized cloud services being used by various departments. The architect must select a solution that provides comprehensive discovery of cloud application usage and assesses the risk of each service based on industry certifications. Which technical solution must be used to provide cross-environment visibility?

Options:

A.

EDR

B.

CASB

C.

Secure Firewall

D.

CWPP

Buy Now
Questions 39

An organization must add new firewalls to its infrastructure and wants to use Cisco ASA or Cisco FTD.

The chosen firewalls must provide methods of blocking traffic that include offering the user the option to bypass the block for certain sites after displaying a warning page and to reset the connection. Which solution should the organization choose?

Options:

A.

Cisco FTD because it supports system rate level traffic blocking, whereas Cisco ASA does not

B.

Cisco ASA because it allows for interactive blocking and blocking with reset to be configured via the GUI, whereas Cisco FTD does not.

C.

Cisco FTD because it enables interactive blocking and blocking with reset natively, whereas Cisco ASA does not

D.

Cisco ASA because it has an additional module that can be installed to provide multiple blocking capabilities, whereas Cisco FTD does not.

Buy Now
Questions 40

Which type of API is being used when a controller within a software-defined network architecture dynamically

makes configuration changes on switches within the network?

Options:

A.

westbound AP

B.

southbound API

C.

northbound API

D.

eastbound API

Buy Now
Questions 41

Which Splunk SOAR component automates multi-step security actions into a repeatable workflow?

Options:

A.

Alert

B.

Action

C.

Data model

D.

Playbook

Buy Now
Questions 42

Refer to the exhibit. When creating an access rule for URL filtering, a network engineer adds certain categories and individual URLs to block. What is the result of the configuration?

Options:

A.

Only URLs for botnets with reputation scores of 1-3 will be blocked.

B.

Only URLs for botnets with a reputation score of 3 will be blocked.

C.

Only URLs for botnets with reputation scores of 3-5 will be blocked.

D.

Only URLs for botnets with a reputation score of 3 will be allowed while the rest will be blocked.

Buy Now
Questions 43

Which statement about IOS zone-based firewalls is true?

Options:

A.

An unassigned interface can communicate with assigned interfaces

B.

Only one interface can be assigned to a zone.

C.

An interface can be assigned to multiple zones.

D.

An interface can be assigned only to one zone.

Buy Now
Questions 44

Which attack type attempts to shut down a machine or network so that users are not able to access it?

Options:

A.

smurf

B.

bluesnarfing

C.

MAC spoofing

D.

IP spoofing

Buy Now
Questions 45

How does Cisco Umbrella protect clients when they operate outside of the corporate network?

Options:

A.

by modifying the registry for DNS lookups

B.

by using Active Directory group policies to enforce Cisco Umbrella DNS servers

C.

by using the Cisco Umbrella roaming client

D.

by forcing DNS queries to the corporate name servers

Buy Now
Questions 46

Which option is the main function of Cisco Firepower impact flags?

Options:

A.

They alert administrators when critical events occur.

B.

They highlight known and suspected malicious IP addresses in reports.

C.

They correlate data about intrusions and vulnerability.

D.

They identify data that the ASA sends to the Firepower module.

Buy Now
Questions 47

Which feature enables a Cisco ISR to use the default bypass list automatically for web filtering?

Options:

A.

filters

B.

group key

C.

company key

D.

connector

Buy Now
Questions 48

A network engineer is deciding whether to use stateful or stateless failover when configuring two ASAs for high availability. What is the connection status in both cases?

Options:

A.

need to be reestablished with stateful failover and preserved with stateless failover

B.

preserved with stateful failover and need to be reestablished with stateless failover

C.

preserved with both stateful and stateless failover

D.

need to be reestablished with both stateful and stateless failover

Buy Now
Questions 49

Which two request methods of REST API are valid on the Cisco ASA Platform? (Choose two.)

Options:

A.

GET

B.

CONNECT

C.

PUSH

D.

OPTIONS

E.

PUT

Buy Now
Questions 50

Which Cisco Advanced Malware protection for Endpoints deployment architecture is designed to keep data

within a network perimeter?

Options:

A.

cloud web services

B.

network AMP

C.

private cloud

D.

public cloud

Buy Now
Questions 51

II

An engineer musí set up 200 new laptops on a network and wants to prevent the users from moving their laptops around to simplify administration Which switch port MAC address security setting must be used?

Options:

A.

sticky

B.

static

C.

aging

D.

maximum

Buy Now
Questions 52

Which product allows Cisco FMC to push security intelligence observable to its sensors from other products?

Options:

A.

Encrypted Traffic Analytics

B.

Threat Intelligence Director

C.

Cognitive Threat Analytics

D.

Cisco Talos Intelligence

Buy Now
Questions 53

What is the difference between a site-to-site VPN and a remote-access VPN?

Options:

A.

A site-to-site VPN connects a private network using software endpoints, and a remote-access VPN connects devices to user resources in the network.

B.

A site-to-site VPN uses a Cisco GET VPN configuration, and a remote-access VPN uses a virtual tunnel interface configuration.

C.

A site-to-site VPN uses a GRE over IPsec configuration, and a remote-access VPN uses a Cisco GET Transport VPN configuration.

D.

A site-to-site VPN connects two private networks behind VPN termination devices, and a remote-access VPN connects a user to a private network.

Buy Now
Questions 54

An engineer enabled SSL decryption for Cisco Umbrella intelligent proxy and needs to ensure that traffic is inspected without alerting end-users. Which action accomplishes this goal?

Options:

A.

Restrict access to only websites with trusted third-party signed certificates.

B.

Modify the user’s browser settings to suppress errors from Cisco Umbrella.

C.

Upload the organization root CA to Cisco Umbrella.

D.

Install the Cisco Umbrella root CA onto the user’s device.

Buy Now
Questions 55

Which policy is used to capture host information on the Cisco Firepower Next Generation Intrusion Prevention

System?

Options:

A.

Correlation

B.

Intrusion

C.

Access Control

D.

Network Discovery

Buy Now
Questions 56

Which CLI command is used to enable URL filtering support for shortened URLs on the Cisco Secure Email Gateway?

Options:

A.

outbreakconfig

B.

websecurityconfig

C.

webadvancedconfig

D.

websecurityadvancedconfig

Buy Now
Questions 57

What is the role of Cisco Umbrella Roaming when it is installed on an endpoint?

Options:

A.

To protect the endpoint against malicious file transfers

B.

To ensure that assets are secure from malicious links on and off the corporate network

C.

To establish secure VPN connectivity to the corporate network

D.

To enforce posture compliance and mandatory software

Buy Now
Questions 58

Which component of Cisco umbrella architecture increases reliability of the service?

Options:

A.

Anycast IP

B.

AMP Threat grid

C.

Cisco Talos

D.

BGP route reflector

Buy Now
Questions 59

An engineer must implement a file transfer solution between a company ' s data center and branches. The company has numerous servers hosted in a hybrid cloud implementation. The file transfer protocol must support authentication, protect the data against unauthorized access, and ensure that users cannot list directories or remove files remotely. Which protocol must be used?

Options:

A.

SCP

B.

SSH

C.

FTPS

D.

SFTP

Buy Now
Questions 60

An engineer has been tasked with configuring a Cisco FTD to analyze protocol fields and detect anomalies in the traffic from industrial systems. What must be done to meet these requirements?

Options:

A.

Implement pre-filter policies for the CIP preprocessor

B.

Enable traffic analysis in the Cisco FTD

C.

Configure intrusion rules for the DNP3 preprocessor

D.

Modify the access control policy to trust the industrial traffic

Buy Now
Questions 61

Which IPS analysis technique matches traffic against a database of known attack patterns?

Options:

A.

Signature-based detection

B.

Behavioral analytics

C.

Heuristic detection

D.

Anomaly-based detection

Buy Now
Questions 62

Which two deployment modes does the Cisco ASA FirePower module support? (Choose two)

Options:

A.

transparent mode

B.

routed mode

C.

inline mode

D.

active mode

E.

passive monitor-only mode

Buy Now
Questions 63

What is managed by Cisco Security Manager?

Options:

A.

access point

B.

WSA

C.

ASA

D.

ESA

Buy Now
Questions 64

A networking team must harden an organization ' s network from VLAN hopping attacks. The team disables Dynamic Trunking Protocol and puts any unused ports in an unused VLAN. A trunk port is used as a trunk link. What must the team configure next to harden the network against VLAN hopping attacks?

Options:

A.

disable STP on the network devices

B.

dedicated VLAN ID for all trunk ports

C.

DHCP snooping on all the switches

D.

enable port-based network access control

Buy Now
Questions 65

Which two probes are configured to gather attributes of connected endpoints using Cisco Identity Services

Engine? (Choose two)

Options:

A.

RADIUS

B.

TACACS+

C.

DHCP

D.

sFlow

E.

SMTP

Buy Now
Questions 66

In which two ways does Easy Connect help control network access when used with Cisco TrustSec? (Choose two)

Options:

A.

It allows multiple security products to share information and work together to enhance security posture in the network.

B.

It creates a dashboard in Cisco ISE that provides full visibility of all connected endpoints.

C.

It allows for the assignment of Security Group Tags and does not require 802.1x to be configured on the switch or the endpoint.

D.

It integrates with third-party products to provide better visibility throughout the network.

E.

It allows for managed endpoints that authenticate to AD to be mapped to Security Groups (PassiveID).

Buy Now
Questions 67

How does Cisco Advanced Phishing Protection protect users?

Options:

A.

It validates the sender by using DKIM.

B.

It determines which identities are perceived by the sender

C.

It utilizes sensors that send messages securely.

D.

It uses machine learning and real-time behavior analytics.

Buy Now
Questions 68

Refer to the exhibit.

An organization is using DHCP Snooping within their network. A user on VLAN 41 on a new switch is

complaining that an IP address is not being obtained. Which command should be configured on the switch

interface in order to provide the user with network connectivity?

Options:

A.

ip dhcp snooping verify mac-address

B.

ip dhcp snooping limit 41

C.

ip dhcp snooping vlan 41

D.

ip dhcp snooping trust

Buy Now
Questions 69

What is the purpose of the My Devices Portal in a Cisco ISE environment?

Options:

A.

to register new laptops and mobile devices

B.

to request a newly provisioned mobile device

C.

to provision userless and agentless systems

D.

to manage and deploy antivirus definitions and patches on systems owned by the end user

Buy Now
Questions 70

Which solution for remote workers enables protection, detection, and response on the endpoint against known and unknown threats?

Options:

A.

Cisco AMP for Endpoints

B.

Cisco AnyConnect

C.

Cisco Umbrella

D.

Cisco Duo

Buy Now
Questions 71

A financial services firm is concerned about employees inadvertently pasting sensitive customer account information into public generative AI websites. The security team needs to implement a solution that inspects outbound traffic and prevents the transmission of sensitive data to AI platforms. Which two configuration actions must the administrator perform on Cisco Secure Access to achieve the requirement? (Choose two.)

Options:

A.

Apply an AI Guardrail rule to block uploads to unauthorized AI domains.

B.

Implement a strict firewall rule to block all outbound traffic on port 443 for the entire organization.

C.

Disable all web-browser access for employees to prevent them from navigating to any external websites.

D.

Configure a DLP policy to inspect outbound traffic for sensitive data patterns.

E.

Enable the local endpoint firewall to block all traffic to known AI-service IP addresses.

Buy Now
Questions 72

Which solution offers automated blocking of known threats and visibility into zero-day attack behavior, with the ability to respond directly from the console?

Options:

A.

EPP solution with an HIDS integration

B.

Cloud-native antivirus with offline update support

C.

EDR with behavioral analytics and remote containment

D.

Secure Email Gateway with phishing sandboxing

Buy Now
Questions 73

How does the Cisco WSA enforce bandwidth restrictions for web applications?

Options:

A.

It implements a policy route to redirect application traffic to a lower-bandwidth link.

B.

It dynamically creates a scavenger class QoS policy and applies it to each client that connects through the WSA.

C.

It sends commands to the uplink router to apply traffic policing to the application traffic.

D.

It simulates a slower link by introducing latency into application traffic.

Buy Now
Questions 74

What are the components of endpoint protection against social engineering attacks?

Options:

A.

IPsec

B.

IDS

C.

Firewall

D.

Cisco Secure Email Gateway

Buy Now
Questions 75

Which capability is exclusive to a Cisco AMP public cloud instance as compared to a private cloud instance?

Options:

A.

RBAC

B.

ETHOS detection engine

C.

SPERO detection engine

D.

TETRA detection engine

Buy Now
Questions 76

An engineer must modify a policy to block specific addresses using Cisco Umbrella. The policy is created already and is actively u: of the default policy elements. What else must be done to accomplish this task?

Options:

A.

Add the specified addresses to the identities list and create a block action.

B.

Create a destination list for addresses to be allowed or blocked.

C.

Use content categories to block or allow specific addresses.

D.

Modify the application settings to allow only applications to connect to required addresses.

Buy Now
Questions 77

Where are individual sites specified to be block listed in Cisco Umbrella?

Options:

A.

Application settings

B.

Security settings

C.

Destination lists

D.

Content categories

Buy Now
Questions 78

Which two types of policies are used by ZTNA to provide access to an application? (Choose two.)

Options:

A.

Context

B.

Access

C.

Site-to-site

D.

Identity

E.

Remote access

Buy Now
Questions 79

A network engineer has entered the snmp-server user andy myv3 auth sha cisco priv aes 256

cisc0380739941 command and needs to send SNMP information to a host at 10.255.254.1. Which command achieves this goal?

Options:

A.

snmp-server host inside 10.255.254.1 version 3 andy

B.

snmp-server host inside 10.255.254.1 version 3 myv3

C.

snmp-server host inside 10.255.254.1 snmpv3 andy

D.

snmp-server host inside 10.255.254.1 snmpv3 myv3

Buy Now
Questions 80

The security architect has concluded that the optimal mail flow positions the existing Cisco Secure Email Gateways as the first termination point for inbound messages, while Cisco Secure Email Threat Defense is positioned between the Secure Email Gateways and the cloud mail platform. The security engineer has been asked to configure the incoming-traffic domain setting in Cisco Secure Email Threat Defense so that it reflects the Secure Email Gateway handling inbound messages ahead of the service. Which domain configuration for incoming traffic must be selected to meet the requirement?

Options:

A.

Secondary Gateway

B.

Secondary with Additional Gateway

C.

Primary Gateway

D.

Primary with Additional Gateway

Buy Now
Questions 81

What is the function of the crypto is a kmp key cisc406397954 address 0.0.0.0 0.0.0.0 command when establishing an IPsec VPN tunnel?

Options:

A.

It defines what data is going to be encrypted via the VPN

B.

lt configures the pre-shared authentication key

C.

It prevents all IP addresses from connecting to the VPN server.

D.

It configures the local address for the VPN server.

Buy Now
Questions 82

An organization is trying to improve their Defense in Depth by blocking malicious destinations prior to a

connection being established. The solution must be able to block certain applications from being used within the network. Which product should be used to accomplish this goal?

Options:

A.

Cisco Firepower

B.

Cisco Umbrella

C.

ISE

D.

AMP

Buy Now
Questions 83

Which two tasks allow NetFlow on a Cisco ASA 5500 Series firewall? (Choose two)

Options:

A.

Enable NetFlow Version 9.

B.

Create an ACL to allow UDP traffic on port 9996.

C.

Apply NetFlow Exporter to the outside interface in the inbound direction.

D.

Create a class map to match interesting traffic.

E.

Define a NetFlow collector by using the flow-export command

Buy Now
Questions 84

A large retail enterprise is deploying Cisco Secure Private Access to enable remote employees to reach internal applications without manual intervention. The IT department requires a seamless, zero-touch enrollment process in which users are registered and authenticated transparently without requiring end-user action. The architecture must support robust high availability for back-end connectivity to ensure continuous access to private resources. Which configuration approach must the administrator implement to meet the requirement?

Options:

A.

Implement ZTA with Certificate Enrollment and multiple Connector Groups associated with the private resource.

B.

Configure ZTA with SAML Enrollment and multiple Connector Groups associated with the private resource.

C.

Define a VPN Machine Tunnel with Certificate Enrollment and Connector Groups associated with the private resource.

D.

Apply ZTA with SAML Enrollment, including passwordless enrollment, and a single Connector associated with the private resource.

Buy Now
Questions 85

What are two functionalities of northbound and southbound APIs within Cisco SDN architecture? (Choose two.)

Options:

A.

Southbound APIs are used to define how SDN controllers integrate with applications.

B.

Southbound interfaces utilize device configurations such as VLANs and IP addresses.

C.

Northbound APIs utilize RESTful API methods such as GET, POST, and DELETE.

D.

Southbound APIs utilize CLI, SNMP, and RESTCONF.

E.

Northbound interfaces utilize OpenFlow and OpFlex to integrate with network devices.

Buy Now
Questions 86

What is a difference between GETVPN and IPsec?

Options:

A.

GETVPN reduces latency and provides encryption over MPLS without the use of a central hub

B.

GETVPN provides key management and security association management

C.

GETVPN is based on IKEv2 and does not support IKEv1

D.

GETVPN is used to build a VPN network with multiple sites without having to statically configure all devices

Buy Now
Questions 87

An organization has two systems in their DMZ that have an unencrypted link between them for communication.

The organization does not have a defined password policy and uses several default accounts on the systems.

The application used on those systems also have not gone through stringent code reviews. Which vulnerability

would help an attacker brute force their way into the systems?

Options:

A.

weak passwords

B.

lack of input validation

C.

missing encryption

D.

lack of file permission

Buy Now
Questions 88

Which attack is commonly associated with C and C++ programming languages?

Options:

A.

cross-site scripting

B.

water holing

C.

DDoS

D.

buffer overflow

Buy Now
Questions 89

What is a functional difference between a Cisco ASA and a Cisco IOS router with Zone-based policy firewall?

Options:

A.

The Cisco ASA denies all traffic by default whereas the Cisco IOS router with Zone-Based Policy Firewall starts out by allowing all traffic, even on untrusted interfaces

B.

The Cisco IOS router with Zone-Based Policy Firewall can be configured for high availability, whereas the Cisco ASA cannot

C.

The Cisco IOS router with Zone-Based Policy Firewall denies all traffic by default, whereas the Cisco ASA starts out by allowing all traffic until rules are added

D.

The Cisco ASA can be configured for high availability whereas the Cisco IOS router with Zone-Based Policy Firewall cannot

Buy Now
Questions 90

An engineer is configuring a Cisco ESA and wants to control whether to accept or reject email messages to a

recipient address. Which list contains the allowed recipient addresses?

Options:

A.

SAT

B.

BAT

C.

HAT

D.

RAT

Buy Now
Questions 91

How does Cisco AMP for Endpoints provide next-generation protection?

Options:

A.

It encrypts data on user endpoints to protect against ransomware.

B.

It leverages an endpoint protection platform and endpoint detection and response.

C.

It utilizes Cisco pxGrid, which allows Cisco AMP to pull threat feeds from threat intelligence centers.

D.

It integrates with Cisco FTD devices.

Buy Now
Questions 92

Based on the NIST 800-145 guide, which cloud architecture is provisioned for exclusive use by a specific group of consumers from different organizations and may be owned, managed, and operated by one or more of those organizations?

Options:

A.

hybrid cloud

B.

private cloud

C.

community cloud

D.

public cloud

Buy Now
Questions 93

Which API is used for Content Security?

Options:

A.

NX-OS API

B.

IOS XR API

C.

OpenVuln API

D.

AsyncOS API

Buy Now
Questions 94

Which security solution is used for posture assessment of the endpoints in a BYOD solution?

Options:

A.

Cisco FTD

B.

Cisco ASA

C.

Cisco Umbrella

D.

Cisco ISE

Buy Now
Questions 95

Which two activities are performed using Cisco Catalyst Center? (Choose two.)

Options:

A.

DHCP

B.

Design

C.

Provision

D.

DNS

E.

Accounting

Buy Now
Questions 96

Using Cisco Cognitive Threat Analytics, which platform automatically blocks risky sites, and test unknown sites for hidden advanced threats before allowing users to click them?

Options:

A.

Cisco Identity Services Engine (ISE)

B.

Cisco Enterprise Security Appliance (ESA)

C.

Cisco Web Security Appliance (WSA)

D.

Cisco Advanced Stealthwatch Appliance (ASA)

Buy Now
Questions 97

Which two deployment model configurations are supported for Cisco FTDv in AWS? (Choose two)

Options:

A.

Cisco FTDv configured in routed mode and managed by an FMCv installed in AWS

B.

Cisco FTDv with one management interface and two traffic interfaces configured

C.

Cisco FTDv configured in routed mode and managed by a physical FMC appliance on premises

D.

Cisco FTDv with two management interfaces and one traffic interface configured

E.

Cisco FTDv configured in routed mode and IPv6 configured

Buy Now
Questions 98

An engineer has been tasked with implementing a solution that can be leveraged for securing the cloud users,

data, and applications. There is a requirement to use the Cisco cloud native CASB and cloud cybersecurity

platform. What should be used to meet these requirements?

Options:

A.

Cisco Umbrella

B.

Cisco Cloud Email Security

C.

Cisco NGFW

D.

Cisco Cloudlock

Buy Now
Questions 99

Which cloud model is a collaborative effort where infrastructure is shared and jointly accessed by several organizations from a specific group?

Options:

A.

Hybrid

B.

Community

C.

Private

D.

Public

Buy Now
Questions 100

Which algorithm provides encryption and authentication for data plane communication?

Options:

A.

AES-GCM

B.

SHA-96

C.

AES-256

D.

SHA-384

Buy Now
Questions 101

A network engineer is trying to figure out whether FlexVPN or DMVPN would fit better in their environment.

They have a requirement for more stringent security multiple security associations for the connections, more efficient VPN establishment as well consuming less bandwidth. Which solution would be best for this and why?

Options:

A.

DMVPN because it supports IKEv2 and FlexVPN does not

B.

FlexVPN because it supports IKEv2 and DMVPN does not

C.

FlexVPN because it uses multiple SAs and DMVPN does not

D.

DMVPN because it uses multiple SAs and FlexVPN does not

Buy Now
Questions 102

Refer to the exhibit.

What is a result of the configuration?

Options:

A.

Traffic from the DMZ network is redirected

B.

Traffic from the inside network is redirected

C.

All TCP traffic is redirected

D.

Traffic from the inside and DMZ networks is redirected

Buy Now
Questions 103

What is the concept of Cl/CD pipelining?

Options:

A.

The project is split into several phases where one phase cannot start before the previous phase finishes successfully.

B.

The project code is centrally maintained and each code change should trigger an automated build and test sequence

C.

The project is split into time-limited cycles and focuses on pair programming for continuous code review

D.

Each project phase is independent from other phases to maintain adaptiveness and continual improvement

Buy Now
Questions 104

An engineer is configuring IPsec VPN and needs an authentication protocol that is reliable and supports ACK

and sequence. Which protocol accomplishes this goal?

Options:

A.

AES-192

B.

IKEv1

C.

AES-256

D.

ESP

Buy Now
Questions 105

A security test performed on one of the applications shows that user input is not validated. Which security vulnerability is the application more susceptible to because of this lack of validation?

Options:

A.

denial -of-service

B.

cross-site request forgery

C.

man-in-the-middle

D.

SQL injection

Buy Now
Questions 106

Which two services are provided by the Cisco Talos Incident Response group? (Choose two.)

Options:

A.

Security policy authorization

B.

Bug identification

C.

Automatic vulnerability remediation

D.

Threat hunting

E.

Cyber range training

Buy Now
Questions 107

Which two methods must be used to add switches into the fabric so that administrators can control how switches are added into DCNM for private cloud management? (Choose two.)

Options:

A.

Cisco Cloud Director

B.

Cisco Prime Infrastructure

C.

PowerOn Auto Provisioning

D.

Seed IP

E.

CDP AutoDiscovery

Buy Now
Questions 108

Which action configures the IEEE 802.1X Flexible Authentication feature to support Layer 3 authentication mechanisms?

Options:

A.

Add MAB into the switch to allow redirection to a Layer 3 device for authentication.

B.

Identify the devices using this feature and create a policy that allows them to pass Layer 2 authentication.

C.

Modify the Dot1x configuration on the VPN server to send Layer 3 authentications to an external authentication database.

D.

Configure WebAuth so the hosts are redirected to a web page for authentication.

Buy Now
Questions 109

An engineer is configuring Cisco Secure Endpoint to enhance network security by specifying a large set of external IP addresses that must be monitored for potential threats. The engineer is configuring an IP List and must add the IP addresses to the list. Which configuration action must the engineer take next to meet the requirement?

Options:

A.

Add the IP addresses using the global bulk configuration wizard.

B.

Automate a threat-feed subscription using an API.

C.

Use the data-upload function and import a file formatted as JSON.

D.

Use the Add Multiple Rows feature and paste all addresses into the input field.

Buy Now
Questions 110

Which component of a Cisco IOS NetFlow solution enables the aggregation of data packets into flows?

Options:

A.

Analyzer

B.

Sampler

C.

Collector

D.

Exporter

Buy Now
Questions 111

An administrator is implementing management plane protection and must configure an interface on a Cisco router to only terminate management packets that are destined for the router. Which set of IOS commands must be used to complete the implementation?

Options:

A.

B.

C.

D.

Buy Now
Questions 112

For which type of attack is multifactor authentication an effective deterrent?

Options:

A.

Ping of death

B.

Teardrop

C.

SYN flood

D.

Phishing

Buy Now
Questions 113

Which Cisco security solution secures public, private, hybrid, and community clouds?

Options:

A.

Cisco ISE

B.

Cisco ASAv

C.

Cisco Cloudlock

D.

Cisco pxGrid

Buy Now
Questions 114

An engineer is configuring cloud logging using a company-managed Amazon S3 bucket for Cisco Umbrella logs. What benefit does this configuration provide for accessing log data?

Options:

A.

It is included m the license cost for the multi-org console of Cisco Umbrella

B.

It can grant third-party SIEM integrations write access to the S3 bucket

C.

No other applications except Cisco Umbrella can write to the S3 bucket

D.

Data can be stored offline for 30 days.

Buy Now
Questions 115

Which interface mode does a Cisco Secure IPS device use to block suspicious traffic?

Options:

A.

Passive

B.

Inline

C.

Promiscuous

D.

Active

Buy Now
Questions 116

Which Linux system call loads an eBPF program and manages eBPF maps within the kernel?

Options:

A.

perf_event_open()

B.

ioctl()

C.

prctl()

D.

bpf()

Buy Now
Questions 117

Which direction do attackers encode data in DNS requests during exfiltration using DNS tunneling?

Options:

A.

inbound

B.

north-south

C.

east-west

D.

outbound

Buy Now
Questions 118

Which cloud service offering allows customers to access a web application that is being hosted, managed, and maintained by a cloud service provider?

Options:

A.

IaC

B.

SaaS

C.

IaaS

D.

PaaS

Buy Now
Questions 119

Refer to the exhibit. When configuring this access control rule in Cisco FMC, what happens with the traffic destined to the DMZ_inside zone once the configuration is deployed?

Options:

A.

All traffic from any zone will be allowed to the DMZ_inside zone only after inspection.

B.

No traffic will be allowed through to the DMZ_inside zone regardless of if it ' s trusted or not.

C.

No traffic will be allowed through to the DMZ_inside zone unless it ' s already trusted.

D.

All traffic from any zone to the DMZ_inside zone will be permitted with no further inspection.

Buy Now
Questions 120

Which two features of Cisco DNA Center are used in a Software Defined Network solution? (Choose two)

Options:

A.

accounting

B.

assurance

C.

automation

D.

authentication

E.

encryption

Buy Now
Questions 121

An engineer is implementing NTP authentication within their network and has configured both the client and server devices with the command ntp authentication-key 1 md5 Cisc392368270. The server at 1.1.1.1 is attempting to authenticate to the client at 1.1.1.2, however it is unable to do so. Which command is required to enable the client to accept the server’s authentication key?

Options:

A.

ntp peer 1.1.1.1 key 1

B.

ntp server 1.1.1.1 key 1

C.

ntp server 1.1.1.2 key 1

D.

ntp peer 1.1.1.2 key 1

Buy Now
Questions 122

An engineer is configuring Cisco WSA and needs to deploy it in transparent mode. Which configuration component must be used to accomplish this goal?

Options:

A.

MDA on the router

B.

PBR on Cisco WSA

C.

WCCP on switch

D.

DNS resolution on Cisco WSA

Buy Now
Questions 123

A Cisco ISE engineer configures Central Web Authentication (CWA) for wireless guest access and must have the guest endpoints redirect to the guest portal for authentication and authorization. While testing the policy, the engineer notices that the device is not redirected and instead gets full guest access. What must be done for the redirect to work?

Options:

A.

Tag the guest portal in the CWA part of the Common Tasks section of the authorization profile for the authorization policy line that the unauthenticated devices hit.

B.

Use the track movement option within the authorization profile for the authorization policy line that the unauthenticated devices hit.

C.

Create an advanced attribute setting of Cisco:cisco-gateway-id=guest within the authorization profile for the authorization policy line that the unauthenticated devices hit.

D.

Add the DACL name for the Airespace ACL configured on the WLC in the Common Tasks section of the authorization profile for the authorization policy line that the unauthenticated devices hit.

Buy Now
Questions 124

In which two ways does a system administrator send web traffic transparently to the Web Security Appliance?

(Choose two)

Options:

A.

configure Active Directory Group Policies to push proxy settings

B.

configure policy-based routing on the network infrastructure

C.

reference a Proxy Auto Config file

D.

configure the proxy IP address in the web-browser settings

E.

use Web Cache Communication Protocol

Buy Now
Questions 125

How does Cisco Workload Optimization portion of the network do EPP solutions solely performance issues?

Options:

A.

It deploys an AWS Lambda system

B.

It automates resource resizing

C.

It optimizes a flow path

D.

It sets up a workload forensic score

Buy Now
Questions 126

Which two capabilities of Cisco Secure Workload facilitate the detection of lateral movement within data-center and cloud environments? (Choose two.)

Options:

A.

Dynamic updates to firewall rules based on user access

B.

Integration with threat intelligence for identifying malicious IP addresses

C.

Automatic blocking of all inbound and outbound traffic

D.

Real-time visibility into communication patterns between workloads

E.

Recommendations for implementing VLANs for network segmentation

Buy Now
Questions 127

Which two aspects of the cloud PaaS model are managed by the customer but not the provider? (Choose two)

Options:

A.

virtualization

B.

middleware

C.

operating systems

D.

applications

E.

data

Buy Now
Questions 128

What is the target in a phishing attack?

Options:

A.

perimeter firewall

B.

IPS

C.

web server

D.

endpoint

Buy Now
Questions 129

A Cisco Secure Email Gateway network administrator has been tasked to use a newly installed service to help create policy based on the reputation verdict. During testing, it is discovered that the Secure Email Gateway is not dropping files that have an undetermined verdict. What is causing this issue?

Options:

A.

The file has a reputation score that is below the threshold.

B.

The file has a reputation score that is above the threshold.

C.

The policy was created to disable file analysis.

D.

The policy was created to send a message to quarantine instead of drop.

Buy Now
Questions 130

Which two prevention techniques are used to mitigate SQL injection attacks? (Choose two)

Options:

A.

Check integer, float, or Boolean string parameters to ensure accurate values.

B.

Use prepared statements and parameterized queries.

C.

Secure the connection between the web and the app tier.

D.

Write SQL code instead of using object-relational mapping libraries.

E.

Block SQL code execution in the web application database login.

Buy Now
Questions 131

Which ESA implementation method segregates inbound and outbound email?

Options:

A.

one listener on a single physical Interface

B.

pair of logical listeners on a single physical interface with two unique logical IPv4 addresses and one IPv6 address

C.

pair of logical IPv4 listeners and a pair Of IPv6 listeners on two physically separate interfaces

D.

one listener on one logical IPv4 address on a single logical interface

Buy Now
Questions 132

How does a cloud access security broker function?

Options:

A.

It is an authentication broker to enable single sign-on and multi-factor authentication for a cloud solution

B.

lt integrates with other cloud solutions via APIs and monitors and creates incidents based on events from the cloud solution

C.

It acts as a security information and event management solution and receives syslog from other cloud solutions.

D.

It scans other cloud solutions being used within the network and identifies vulnerabilities

Buy Now
Questions 133

Which two devices support WCCP for traffic redirection? (Choose two.)

Options:

A.

Cisco Secure Web Appliance

B.

Cisco IOS

C.

proxy server

D.

Cisco ASA

E.

Cisco IPS

Buy Now
Questions 134

An organization has two machines hosting web applications. Machine 1 is vulnerable to SQL injection while machine 2 is vulnerable to buffer overflows. What action would allow the attacker to gain access to machine 1 but not machine 2?

Options:

A.

sniffing the packets between the two hosts

B.

sending continuous pings

C.

overflowing the buffer’s memory

D.

inserting malicious commands into the database

Buy Now
Questions 135

A Cisco Firepower administrator needs to configure a rule to allow a new application that has never been seen

on the network. Which two actions should be selected to allow the traffic to pass without inspection? (Choose

two)

Options:

A.

permit

B.

trust

C.

reset

D.

allow

E.

monitor

Buy Now
Questions 136

An engineer wants to automatically assign endpoints that have a specific OUI into a new endpoint group. Which

probe must be enabled for this type of profiling to work?

Options:

A.

NetFlow

B.

NMAP

C.

SNMP

D.

DHCP

Buy Now
Questions 137

A facilities team is onboarding a fleet of badge readers and IP cameras through MAB authentication on Cisco Catalyst access switches integrated with Cisco ISE. After Cisco ISE profiles each endpoint, an authorization policy must dynamically move the device into a dedicated IoT VLAN that differs from the access VLAN statically defined on the port. The endpoints lack a supplicant and cannot automatically renew their DHCP addresses. The network engineer requires Cisco ISE to issue a Change of Authorization that forces each endpoint to re-establish connectivity and request a fresh DHCP lease under the new authorization policy. Which configuration action must be performed on Cisco ISE to meet the requirement?

Options:

A.

Configure the authorization profile to send a CoA-Reauth to the access switch.

B.

Configure the authentication policy to send a CoA-Terminate to reconnect the endpoint.

C.

Configure the authorization profile to send a Port-Bounce CoA to the switch.

D.

Configure the authorization policy to send a CoA-Reconnect and rely on the idle timeout.

Buy Now
Questions 138

Which role is a default guest type in Cisco ISE?

Options:

A.

Monthly

B.

Yearly

C.

Contractor

D.

Full-Time

Buy Now
Questions 139

Refer to the exhibit. An engineer must configure an incoming mail policy so that each email sent from usera1@example.com to a domain of @cisco.com is scanned for antispam and advanced malware protection. All other settings will use the default behavior. What must be configured in the incoming mail policy to meet the requirements?

Options:

A.

Policy Name: Default Policy  Sender: usera1@example.com  Recipient: @cisco.com

B.

Policy Name: usera1 policy  Sender: usera1@example.com  Recipient: @cisco.com

C.

Policy Name: Anti-Malware policy  Sender: usera1@example.com  Recipient: @cisco.com

D.

Policy Name: cisco.com policy  Sender: usera1@example.com  Recipient: @cisco.com

Buy Now
Questions 140

An engineer configures new features within the Cisco Umbrella dashboard and wants to identify and proxy traffic that is categorized as risky domains and may contain safe and malicious content. Which action accomplishes these objectives?

Options:

A.

Configure URL filtering within Cisco Umbrella to track the URLs and proxy the requests for those categories and below.

B.

Configure intelligent proxy within Cisco Umbrella to intercept and proxy the requests for only those categories.

C.

Upload the threat intelligence database to Cisco Umbrella for the most current information on reputations and to have the destination lists block them.

D.

Create a new site within Cisco Umbrella to block requests from those categories so they can be sent to the proxy device.

Buy Now
Questions 141

Which Cisco platform processes behavior baselines, monitors for deviations, and reviews for malicious processes in data center traffic and servers while performing software vulnerability detection?

Options:

A.

Cisco Tetration

B.

Cisco ISE

C.

Cisco AMP for Network

D.

Cisco AnyConnect

Buy Now
Questions 142

A network engineer must configure a Cisco Secure Email Gateway to prompt users to enter two forms of information before gaining access. The Secure Email Gateway must also join a cluster machine using preshared keys. What must be configured to meet these requirements?

Options:

A.

Enable two-factor authentication through a RADIUS server and then join the cluster by using the Secure Email Gateway CLI.

B.

Enable two-factor authentication through a TACACS+ server and then join the cluster by using the Secure Email Gateway CLI.

C.

Enable two-factor authentication through a RADIUS server and then join the cluster by using the Secure Email Gateway GUI.

D.

Enable two-factor authentication through a TACACS+ server and then join the cluster by using the Secure Email Gateway GUI.

Buy Now
Questions 143

An administrator configures a new destination list in Cisco Umbrella so that the organization can block specific domains for its devices. What should be done to ensure that all subdomains of domain.com are blocked?

Options:

A.

Configure the *.com address in the block list.

B.

Configure the *.domain.com address in the block list

C.

Configure the *.domain.com address in the block list

D.

Configure the domain.com address in the block list

Buy Now
Questions 144

A network administrator is configuring a switch to use Cisco ISE for 802.1X. An endpoint is failing

authentication and is unable to access the network. Where should the administrator begin troubleshooting to verify the authentication details?

Options:

A.

Adaptive Network Control Policy List

B.

Context Visibility

C.

Accounting Reports

D.

RADIUS Live Logs

Buy Now
Questions 145

Which DevSecOps practice helps reduce vulnerabilities introduced through external open-source components?

Options:

A.

Performing static routing configuration checks

B.

Conducting software composition analysis during builds

C.

Using dynamic routing between Kubernetes clusters

D.

Setting up round-robin DNS resolution for service discovery

Buy Now
Questions 146

An engineer is configuring guest WLAN access using Cisco ISE and the Cisco WLC. Which action temporarily gives guest endpoints access dynamically while maintaining visibility into who or what is connecting?

Options:

A.

Modify the WLC configuration to require local WLC logins for the authentication prompts.

B.

Configure ISE and the WLC for guest redirection and services using a self-registered portal.

C.

Configure ISE and the WLC for guest redirection and services using a hotspot portal.

D.

Modify the WLC configuration to allow any endpoint to access an internet-only VLAN.

Buy Now
Questions 147

Which type of data exfiltration technique encodes data in outbound DNS requests to specific servers

and can be stopped by Cisco Umbrella?

Options:

A.

DNS tunneling

B.

DNS flood attack

C.

cache poisoning

D.

DNS hijacking

Buy Now
Questions 148

Which threat intelligence standard contains malware hashes?

Options:

A.

structured threat information expression

B.

advanced persistent threat

C.

trusted automated exchange or indicator information

D.

open command and control

Buy Now
Questions 149

Which cryptographic process provides origin confidentiality, integrity, and origin authentication for packets?

Options:

A.

IKEv1

B.

AH

C.

ESP

D.

IKEv2

Buy Now
Questions 150

Refer to the exhibit.

Traffic is not passing through IPsec site-to-site VPN on the Firepower Threat Defense appliance. What is causing this issue?

Options:

A.

No split-tunnel policy is defined on the Firepower Threat Defense appliance.

B.

The access control policy is not allowing VPN traffic in.

C.

Site-to-site VPN peers are using different encryption algorithms.

D.

Site-to-site VPN preshared keys are mismatched.

Buy Now
Questions 151

Under which two circumstances is a CoA issued? (Choose two)

Options:

A.

A new authentication rule was added to the policy on the Policy Service node.

B.

An endpoint is deleted on the Identity Service Engine server.

C.

A new Identity Source Sequence is created and referenced in the authentication policy.

D.

An endpoint is profiled for the first time.

E.

A new Identity Service Engine server is added to the deployment with the Administration persona

Buy Now
Questions 152

For a given policy in Cisco Umbrella, how should a customer block websites based on a custom list?

Options:

A.

By adding the websites to a blocked type destination list

B.

By specifying blocked domains in the policy settings

C.

By adding the website IP addresses to the Cisco Umbrella blocklist

D.

By specifying the websites in a custom blocked category

Buy Now
Questions 153

Which two risks is a company vulnerable to if it does not have a well-established patching solution for

endpoints? (Choose two)

Options:

A.

exploits

B.

ARP spoofing

C.

denial-of-service attacks

D.

malware

E.

eavesdropping

Buy Now
Questions 154

Which solution allows an administrator to provision, monitor, and secure mobile devices on Windows and Mac computers from a centralized dashboard?

Options:

A.

Cisco Umbrella

B.

Cisco AMP for Endpoints

C.

Cisco ISE

D.

Cisco Stealthwatch

Buy Now
Questions 155

An organization is receiving SPAM emails from a known malicious domain. What must be configured in order to

prevent the session during the initial TCP communication?

Options:

A.

Configure the Cisco ESA to drop the malicious emails

B.

Configure policies to quarantine malicious emails

C.

Configure policies to stop and reject communication

D.

Configure the Cisco ESA to reset the TCP connection

Buy Now
Questions 156

Refer to the exhibit.

An engineer configured wired 802.1x on the network and is unable to get a laptop to authenticate. Which port configuration is missing?

Options:

A.

authentication open

B.

dotlx reauthentication

C.

cisp enable

D.

dot1x pae authenticator

Buy Now
Questions 157

Which Cisco Umbrella package supports selective proxy for Inspection of traffic from risky domains?

Options:

A.

SIG Advantage

B.

DNS Security Essentials

C.

SIG Essentials

D.

DNS Security Advantage

Buy Now
Questions 158

An organization is implementing URL blocking using Cisco Umbrella. The users are able to go to some sites but other sites are not accessible due to an error. Why is the error occurring?

Options:

A.

Client computers do not have the Cisco Umbrella Root CA certificate installed.

B.

IP-Layer Enforcement is not configured.

C.

Intelligent proxy and SSL decryption is disabled in the policy.

D.

Client computers do not have an SSL certificate deployed from an internal CA server.

Buy Now
Questions 159

For Cisco IOS PKI, which two types of Servers are used as a distribution point for CRLs? (Choose two)

Options:

A.

SDP

B.

LDAP

C.

subordinate CA

D.

SCP

E.

HTTP

Buy Now
Questions 160

What is a difference between Cisco AMP for Endpoints and Cisco Umbrella?

Options:

A.

Cisco AMP for Endpoints is a cloud-based service, and Cisco Umbrella is not.

B.

Cisco AMP for Endpoints prevents connections to malicious destinations, and C malware.

C.

Cisco AMP for Endpoints automatically researches indicators of compromise ..

D.

Cisco AMP for Endpoints prevents, detects, and responds to attacks before and against Internet threats.

Buy Now
Questions 161

Refer to the exhibit. Which task is the Python script performing by using the Cisco Umbrella API?

Options:

A.

Creating a list of the latest security events

B.

Copying a list of the latest security activity

C.

Retrieving a list of the latest security events

D.

Sending a list of the latest security activity

Buy Now
Questions 162

An organization is implementing AAA for their users. They need to ensure that authorization is verified for every command that is being entered by the network administrator. Which protocol must be configured in order to provide this capability?

Options:

A.

EAPOL

B.

SSH

C.

RADIUS

D.

TACACS+

Buy Now
Questions 163

Which endpoint protection and detection feature performs correlation of telemetry, files, and intrusion

events that are flagged as possible active breaches?

Options:

A.

retrospective detection

B.

indication of compromise

C.

file trajectory

D.

elastic search

Buy Now
Questions 164

A company recently discovered an attack propagating throughout their Windows network via a file named abc428565580xyz exe The malicious file was uploaded to a Simple Custom Detection list in the AMP for Endpoints Portal and the currently applied policy for the Windows clients was updated to reference the detection list Verification testing scans on known infected systems shows that AMP for Endpoints is not detecting the presence of this file as an indicator of compromise What must be performed to ensure detection of the malicious file?

Options:

A.

Upload the malicious file to the Blocked Application Control List

B.

Use an Advanced Custom Detection List instead of a Simple Custom Detection List

C.

Check the box in the policy configuration to send the file to Cisco Threat Grid for dynamic analysis

D.

Upload the SHA-256 hash for the file to the Simple Custom Detection List

Buy Now
Questions 165

Which PKI enrollment method allows the user to separate authentication and enrollment actions and also

provides an option to specify HTTP/TFTP commands to perform file retrieval from the server?

Options:

A.

url

B.

terminal

C.

profile

D.

selfsigned

Buy Now
Questions 166

Which type of attack is MFA an effective deterrent for?

Options:

A.

ping of death

B.

phishing

C.

teardrop

D.

syn flood

Buy Now
Questions 167

Which term describes when the Cisco Firepower downloads threat intelligence updates from Cisco Talos?

Options:

A.

consumption

B.

sharing

C.

analysis

D.

authoring

Buy Now
Questions 168

Which feature requires that network telemetry be enabled?

Options:

A.

per-interface stats

B.

SNMP trap notification

C.

Layer 2 device discovery

D.

central syslog system

Buy Now
Questions 169

What is the purpose of a NetFlow version 9 template record?

Options:

A.

It specifies the data format of NetFlow processes.

B.

It provides a standardized set of information about an IP flow.

C.

lt defines the format of data records.

D.

It serves as a unique identification number to distinguish individual data records

Buy Now
Questions 170

A pharmaceutical research facility has implemented a “Clean Room” network segment to protect sensitive research data and automated manufacturing equipment. Strict compliance requirements mandate that all network traffic logs from the Cisco Secure Firewall serving the segment be forwarded to Splunk for auditing. A Splunk Universal Forwarder is deployed locally on the log-collection servers to monitor syslog files. The engineer must configure the Universal Forwarder to monitor the local syslog files and assign a specific source type for proper ingestion into Splunk. Which stanza configuration must be used to meet the requirements?

Options:

A.

inputs.conf using [monitor:///var/log/syslog]

B.

server.conf using [monitor:///syslog]

C.

props.conf using [syslog]

D.

outputs.conf using [tcpout]

Buy Now
Questions 171

What are two rootkit types? (Choose two)

Options:

A.

registry

B.

virtual

C.

bootloader

D.

user mode

E.

buffer mode

Buy Now
Questions 172

When using Cisco AMP for Networks which feature copies a file to the Cisco AMP cloud for analysis?

Options:

A.

Spero analysis

B.

dynamic analysis

C.

sandbox analysis

D.

malware analysis

Buy Now
Questions 173

Which Dos attack uses fragmented packets to crash a target machine?

Options:

A.

smurf

B.

MITM

C.

teardrop

D.

LAND

Buy Now
Questions 174

A web hosting company must upgrade its older, unsupported on-premises servers. The company wants a cloud solution in which the cloud provider is responsible for:

Server patching

Application maintenance

Data center security

Disaster recovery

Which type of cloud meets the requirements?

Options:

A.

Hybrid

B.

IaaS

C.

SaaS

D.

PaaS

Buy Now
Questions 175

Which mitigation strategy should be used to protect against session hijacking attacks in a cloud environment?

Options:

A.

Implement input validation.

B.

Use secure cookies.

C.

Apply the principle of least privilege.

D.

Use anti-cross-site request forgery tokens.

Buy Now
Questions 176

What are two reasons for implementing a multifactor authentication solution such as Duo Security provide to an

organization? (Choose two)

Options:

A.

flexibility of different methods of 2FA such as phone callbacks, SMS passcodes, and push notifications

B.

single sign-on access to on-premises and cloud applications

C.

integration with 802.1x security using native Microsoft Windows supplicant

D.

secure access to on-premises and cloud applications

E.

identification and correction of application vulnerabilities before allowing access to resources

Buy Now
Questions 177

Which type of attack is social engineering?

Options:

A.

trojan

B.

phishing

C.

malware

D.

MITM

Buy Now
Questions 178

What Cisco command shows you the status of an 802.1X connection on interface gi0/1?

Options:

A.

show authorization status

B.

show authen sess int gi0/1

C.

show connection status gi0/1

D.

show ver gi0/1

Buy Now
Questions 179

What is the benefit of installing Cisco AMP for Endpoints on a network?

Options:

A.

It provides operating system patches on the endpoints for security.

B.

It provides flow-based visibility for the endpoints network connections.

C.

It enables behavioral analysis to be used for the endpoints.

D.

It protects endpoint systems through application control and real-time scanning

Buy Now
Questions 180

How does Cisco Secure Endpoint provide next-generation protection?

Options:

A.

It integrates with Cisco FTD devices.

B.

It encrypts data on user endpoints to protect against ransomware.

C.

It leverages an endpoint protection platform and endpoint detection and response.

D.

It utilizes Cisco pxGrid, which allows Secure Endpoint to pull threat feeds from threat intelligence centers.

Buy Now
Questions 181

A healthcare organization is deploying Cisco Secure Access to prevent protected health information from being shared with generative AI services. The security team requires real-time DLP inspection only for traffic destined for AI applications, with minimal false positives during general web browsing. The policy must permit tuning based on the proximity and match counts of PHI identifiers. Which configuration action must the engineer perform?

Options:

A.

Configure a real-time DLP rule referencing a built-in PHI data classification with default thresholds, scoped to a web profile that includes all Internet traffic.

B.

Implement an API-based DLP rule referencing a custom PHI data classification with tuned proximity and match-count thresholds, scoped to the generative AI application category.

C.

Deploy a real-time DLP rule referencing a built-in PHI data classification with tuned match-count thresholds, scoped to a web profile filtered by destination lists for known AI vendors.

D.

Apply a real-time DLP rule referencing a custom PHI data classification with tuned proximity and match-count thresholds, scoped to a web profile filtered by the generative AI application category.

Buy Now
Questions 182

Which threat intelligence standard contains malware hashes?

Options:

A.

advanced persistent threat

B.

open command and control

C.

structured threat information expression

D.

trusted automated exchange of indicator information

Buy Now
Questions 183

Drag and drop the steps from the left into the correct order on the right to enable AppDynamics to monitor an EC2 instance in Amazon Web Services.

Options:

Buy Now
Questions 184

What is a benefit of a Cisco Secure Email Gateway Virtual as compared to a physical Secure Email Gateway?

Options:

A.

simplifies the distribution of software updates

B.

provides faster performance

C.

provides an automated setup process

D.

enables the allocation of additional resources

Buy Now
Questions 185

An engineer must configure AsyncOS for Cisco Secure Web Appliance to push log files to a syslog server using the SCP retrieval method. Drag and drop the steps from the left into the sequence on the right to complete the configuration.

Options:

Buy Now
Questions 186

An engineer must modify a policy to block specific addresses using Cisco Umbrella. The policy is created already and is actively used by devices, using many of the default policy elements.

What else must be done to accomplish this task?

Options:

A.

Modify the application settings to allow only applications to connect to required addresses.

B.

Create a destination list for addresses to be allowed or blocked.

C.

Add the specified addresses to the identities list and create a block action.

D.

Use content categories to block or allow specific addresses.

Buy Now
Questions 187

Which feature of Cisco ASA allows VPN users to be postured against Cisco ISE without requiring an inline

posture node?

Options:

A.

RADIUS Change of Authorization

B.

device tracking

C.

DHCP snooping

D.

VLAN hopping

Buy Now
Questions 188

An engineer needs to add protection for data in transit and have headers in the email message Which configuration is needed to accomplish this goal?

Options:

A.

Provision the email appliance

B.

Deploy an encryption appliance.

C.

Map sender !P addresses to a host interface.

D.

Enable flagged message handling

Buy Now
Questions 189

An engineer is deploying a Cisco Secure Email Gateway and must configure a sender group that decides which mail policy will process the mail. The configuration must accept incoming mails and relay the outgoing mails from the internal server. Which component must be configured to accept the connection to the listener and meet these requirements on a Cisco Secure Email Gateway?

Options:

A.

RAT

B.

HAT

C.

Sender list

D.

Access list

Buy Now
Questions 190

Refer to the exhibit.

When configuring a remote access VPN solution terminating on the Cisco ASA, an administrator would like to utilize an external token authentication mechanism in conjunction with AAA authentication using machine

certificates. Which configuration item must be modified to allow this?

Options:

A.

Group Policy

B.

Method

C.

SAML Server

D.

DHCP Servers

Buy Now
Questions 191

With which components does a southbound API within a software-defined network architecture communicate?

Options:

A.

controllers within the network

B.

applications

C.

appliances

D.

devices such as routers and switches

Buy Now
Questions 192

Which solution combines Cisco IOS and IOS XE components to enable administrators to recognize

applications, collect and send network metrics to Cisco Prime and other third-party management tools, and prioritize application traffic?

Options:

A.

Cisco Security Intelligence

B.

Cisco Application Visibility and Control

C.

Cisco Model Driven Telemetry

D.

Cisco DNA Center

Buy Now
Questions 193

An administrator configures new authorization policies within Cisco ISE and has difficulty profiling the devices. Attributes for the new Cisco IP phones that are profiled based on the RADIUS authentication are seen however the attributes for CDP or DHCP are not. What should the administrator do to address this issue?

Options:

A.

Configure the ip dhcp snooping trust command on the DHCP interfaces to get the information to Cisco ISE

B.

Configure the authentication port-control auto feature within Cisco ISE to identify the devices that are trying to connect

C.

Configure a service template within the switch to standardize the port configurations so that the correct information is sent to Cisco ISE

D.

Configure the device sensor feature within the switch to send the appropriate protocol information

Buy Now
Questions 194

What is the result of the ACME-Router(config)#login block-for 100 attempts 4 within 60 command on a Cisco IOS router?

Options:

A.

lf four log in attempts fail in 100 seconds, wait for 60 seconds to next log in prompt.

B.

After four unsuccessful log in attempts, the line is blocked for 100 seconds and only permit IP addresses are permitted in ACL

C.

After four unsuccessful log in attempts, the line is blocked for 60 seconds and only permit IP addresses are permitted in ACL1

D.

If four failures occur in 60 seconds, the router goes to quiet mode for 100 seconds.

Buy Now
Questions 195

Which firewall mode does a Cisco Adaptive Security Appliance use to inspect Layer 2 traffic?

Options:

A.

Routed

B.

Passive

C.

Inline

D.

Transparent

Buy Now
Questions 196

What are two workload security models? (Choose two.)

Options:

A.

SaaS

B.

PaaS

C.

off-premises

D.

on-premises

E.

IaaS

Buy Now
Questions 197

A security engineer must protect endpoints when a file appears harmless during initial inspection but later shows malicious behavior. The solution must continuously observe process and file activity after execution and respond when a threat emerges. The infrastructure includes Cisco Secure Endpoint. Which feature must the engineer configure to meet the requirements?

Options:

A.

File Reputation

B.

Continuous Behavioral Monitoring

C.

Forensic Analysis

D.

System Process Protection

Buy Now
Questions 198

An engineer is configuring Cisco Secure Endpoint to enhance security by preventing the execution of certain files by users. The engineer needs to ensure that the specific executable file name Cisco_Software_0505446151.exe is blocked from running while never being quarantined. What must the engineer configure to meet the requirement?

Options:

A.

Create advanced custom detection list.

B.

Configure application control blocked applications list.

C.

Implement simple custom detection list.

D.

Enable scheduled scans to detect and block the executable files.

Buy Now
Questions 199

A network engineer must create an access control list on a Cisco Adaptive Security Appliance firewall. The access control list must permit HTTP traffic to the internet from the organization ' s inside network 192.168.1.0/24. Which IOS command must oe used to create the access control list?

Options:

A.

B.

C.

D.

Buy Now
Questions 200

Which Cisco product provides proactive endpoint protection and allows administrators to centrally manage the

deployment?

Options:

A.

NGFW

B.

AMP

C.

WSA

D.

ESA

Buy Now
Questions 201

Based on the NIST 800-145 guide, which cloud architecture may be owned, managed, and operated by one or more of the organizations in the community, a third party, or some combination of them, and it may exist on or off premises?

Options:

A.

hybrid cloud

B.

private cloud

C.

public cloud

D.

community cloud

Buy Now
Questions 202

An engineer must force an endpoint to re-authenticate an already authenticated session without disrupting the

endpoint to apply a new or updated policy from ISE. Which CoA type achieves this goal?

Options:

A.

Port Bounce

B.

CoA Terminate

C.

CoA Reauth

D.

CoA Session Query

Buy Now
Questions 203

Which two protocols must be configured to authenticate end users to the Web Security Appliance? (Choose two.)

Options:

A.

NTLMSSP

B.

Kerberos

C.

CHAP

D.

TACACS+

E.

RADIUS

Buy Now
Questions 204

How does a Cisco Secure Firewall help to lower the risk of exfiltration techniques that steal customer data?

Options:

A.

Blocking UDP port 53

B.

Blocking TCP port 53

C.

Encrypting the DNS communication

D.

Inspecting the DNS traffic

Buy Now
Questions 205

Which exfiltration method does an attacker use to hide and encode data inside DNS requests and queries?

Options:

A.

DNS tunneling

B.

DNSCrypt

C.

DNS security

D.

DNSSEC

Buy Now
Questions 206

What is a functional difference between Cisco AMP for Endpoints and Cisco Umbrella Roaming Client?

Options:

A.

The Umbrella Roaming client stops and tracks malicious activity on hosts, and AMP for Endpoints tracks only URL-based threats.

B.

The Umbrella Roaming Client authenticates users and provides segmentation, and AMP for Endpoints allows only for VPN connectivity

C.

AMP for Endpoints authenticates users and provides segmentation, and the Umbrella Roaming Client allows only for VPN connectivity.

D.

AMP for Endpoints stops and tracks malicious activity on hosts, and the Umbrella Roaming Client tracks only URL-based threats.

Buy Now
Questions 207

Which information is required when adding a device to Firepower Management Center?

Options:

A.

username and password

B.

encryption method

C.

device serial number

D.

registration key

Buy Now
Questions 208

What causes alert fatigue in Cisco XDR?

Options:

A.

Alerts lacking sufficient context to be accurate

B.

Reauthentication of an active endpoint during a vulnerability incident

C.

Notifications from too few devices in a data-breach event

D.

Automatic policy enforcement during a suspicious event

Buy Now
Questions 209

What is an advantage of the Cisco Umbrella roaming client?

Options:

A.

the ability to see all traffic without requiring TLS decryption

B.

visibility into IP-based threats by tunneling suspicious IP connections

C.

the ability to dynamically categorize traffic to previously uncategorized sites

D.

visibility into traffic that is destined to sites within the office environment

Buy Now
Questions 210

Drag and drop the deployment models from the left onto the explanations on the right.

Options:

Buy Now
Questions 211

Refer to the exhibit.

What is the result of this Python script of the Cisco DNA Center API?

Options:

A.

adds authentication to a switch

B.

adds a switch to Cisco DNA Center

C.

receives information about a switch

D.

deletes a switch from Cisco DNA Center

Buy Now
Questions 212

Drag and drop the suspicious patterns for the Cisco Tetration platform from the left onto the correct definitions on the right.

Options:

Buy Now
Questions 213

Refer to the exhibit. What is the result of using this authentication protocol in the configuration?

Options:

A.

The authentication request contains only a username.

B.

The authentication request contains only a password.

C.

There are separate authentication and authorization request packets.

D.

The authentication and authorization requests are grouped in a single packet.

Buy Now
Questions 214

Which statement about the configuration of Cisco ASA NetFlow v9 Secure Event Logging is true?

Options:

A.

To view bandwidth usage for NetFlow records, the QoS feature must be enabled.

B.

A sysopt command can be used to enable NSEL on a specific interface.

C.

NSEL can be used without a collector configured.

D.

A flow-export event type must be defined under a policy

Buy Now
Questions 215

Which flaw does an attacker leverage when exploiting SQL injection vulnerabilities?

Options:

A.

user input validation in a web page or web application

B.

Linux and Windows operating systems

C.

database

D.

web page images

Buy Now
Questions 216

Which functionality does Incident Manager provide in Cisco XDR?

Options:

A.

It calculates the time usually required for incident identification.

B.

It determines the time required to resolve an issue.

C.

It enables backup activities when a threat has been misidentified.

D.

It prioritizes the steps required to recover from an incident.

Buy Now
Questions 217

When Cisco and other industry organizations publish and inform users of known security findings and

vulnerabilities, which name is used?

Options:

A.

Common Security Exploits

B.

Common Vulnerabilities and Exposures

C.

Common Exploits and Vulnerabilities

D.

Common Vulnerabilities, Exploits and Threats

Buy Now
Questions 218

Which threat involves software being used to gain unauthorized access to a computer system?

Options:

A.

virus

B.

NTP amplification

C.

ping of death

D.

HTTP flood

Buy Now
Questions 219

The main function of northbound APIs in the SDN architecture is to enable communication between which two areas of a network?

Options:

A.

SDN controller and the cloud

B.

management console and the SDN controller

C.

management console and the cloud

D.

SDN controller and the management solution

Buy Now
Questions 220

What are two advantages of using Cisco Any connect over DMVPN? (Choose two)

Options:

A.

It provides spoke-to-spoke communications without traversing the hub

B.

It allows different routing protocols to work over the tunnel

C.

It allows customization of access policies based on user identity

D.

It allows multiple sites to connect to the data center

E.

It enables VPN access for individual users from their machines

Buy Now
Questions 221

Which Cisco platform onboards the endpoint and can issue a CA signed certificate while also automatically configuring endpoint network settings to use the signed endpoint certificate, allowing the endpoint to gain network access?

Options:

A.

Cisco ISE

B.

Cisco NAC

C.

Cisco TACACS+

D.

Cisco WSA

Buy Now
Questions 222

What is the purpose of CA in a PKI?

Options:

A.

To issue and revoke digital certificates

B.

To validate the authenticity of a digital certificate

C.

To create the private key for a digital certificate

D.

To certify the ownership of a public key by the named subject

Buy Now
Questions 223

How is ICMP used an exfiltration technique?

Options:

A.

by flooding the destination host with unreachable packets

B.

by sending large numbers of ICMP packets with a targeted hosts source IP address using an IP broadcast address

C.

by encrypting the payload in an ICMP packet to carry out command and control tasks on a compromised host

D.

by overwhelming a targeted host with ICMP echo-request packets

Buy Now
Questions 224

Which endpoint solution protects a user from a phishing attack?

Options:

A.

Cisco Identity Services Engine

B.

Cisco AnyConnect with ISE Posture module

C.

Cisco AnyConnect with Network Access Manager module

D.

Cisco AnyConnect with Umbrella Roaming Security module

Buy Now
Questions 225

A recent change left network engineers unable to SSH into a branch Cisco Catalyst switch. The engineer confirms that the TACACS server group TACACS-GROUP is defined but unreachable. There is no fallback to the local database when TACACS+ is unavailable. Security policy requires TACACS+ as the primary authentication method with automatic fallback to local accounts. Which configuration command must be added to resolve the issue?

Options:

A.

aaa authentication login ssh LOCAL TACACS-GROUP

B.

aaa authentication login group TACACS-GROUP local

C.

aaa authentication login default group TACACS-GROUP local

D.

aaa authentication serial console TACACS-GROUP LOCAL

Buy Now
Questions 226

Which open standard underpins OpenID Connect, enabling Cisco Duo to authorize application access?

Options:

A.

OAuth 2.0

B.

SCEP

C.

RSTP

D.

Kerberos

Buy Now
Questions 227

An engineer is deploying Cisco Advanced Malware Protection (AMP) for Endpoints and wants to create a policy that prevents users from executing file named abc424952615.exe without quarantining that file What type of Outbreak Control list must the SHA.-256 hash value for the file be added to in order to accomplish this?

Options:

A.

Advanced Custom Detection

B.

Blocked Application

C.

Isolation

D.

Simple Custom Detection

Buy Now
Questions 228

An engineer must deploy Cisco Secure Email with Cloud URL Analysis and must meet these requirements:

To protect the network from large-scale virus outbreaks

To protect the network from non-viral attacks such as phishing scams and malware distribution

To provide active analysis of the structure of the URL and information about the domain and page contents

Which two prerequisites must the engineer ensure are configured? (Choose two.)

Options:

A.

Scanning enabled for each Verdict, Prepend Subject and Deliver.

B.

Outbreak Filters must be enabled globally.

C.

Enable TLS by setting to Preferred to the Default Domain.

D.

Service Logs must be enabled.

E.

Enable Rejected Connection Logging.

Buy Now
Questions 229

Refer to the exhibit.

Consider that any feature of DNS requests, such as the length off the domain name

and the number of subdomains, can be used to construct models of expected behavior to which

observed values can be compared. Which type of malicious attack are these values associated with?

Options:

A.

Spectre Worm

B.

Eternal Blue Windows

C.

Heartbleed SSL Bug

D.

W32/AutoRun worm

Buy Now
Questions 230

How does DNS Tunneling exfiltrate data?

Options:

A.

An attacker registers a domain that a client connects to based on DNS records and sends malware throughthat connection.

B.

An attacker opens a reverse DNS shell to get into the client’s system and install malware on it.

C.

An attacker uses a non-standard DNS port to gain access to the organization’s DNS servers in order topoison the resolutions.

D.

An attacker sends an email to the target with hidden DNS resolvers in it to redirect them to a maliciousdomain.

Buy Now
Questions 231

Which Cisco security solution determines if an endpoint has the latest OS updates and patches installed on the system?

Options:

A.

Cisco Endpoint Security Analytics

B.

Cisco AMP for Endpoints

C.

Endpoint Compliance Scanner

D.

Security Posture Assessment Service

Buy Now
Questions 232

How many interfaces per bridge group does an ASA bridge group deployment support?

Options:

A.

up to 2

B.

up to 4

C.

up to 8

D.

up to 16

Buy Now
Questions 233

A university policy must allow open access to resources on the Internet for research, but internal workstations are exposed to malware. Which Cisco AMP feature allows the engineering team to determine whether a file is installed on a selected few workstations?

Options:

A.

file prevalence

B.

file discovery

C.

file conviction

D.

file manager

Buy Now
Questions 234

How is a cross-site scripting attack executed?

Options:

A.

Force a currently authenticated end user to execute unwanted actions on a web app

B.

Execute malicious client-side scripts injected to a client via a web app

C.

Inject a database query via the input data from the client to a web app

D.

Intercept communications between a client and a web server

Buy Now
Questions 235

What are two ways a network administrator transparently identifies users using Active Directory on the Cisco WSA? (Choose two.)

Options:

A.

Create an LDAP authentication realm and disable transparent user identification.

B.

Create NTLM or Kerberos authentication realm and enable transparent user identification.

C.

Deploy a separate Active Directory agent such as Cisco Context Directory Agent.

D.

The eDirectory client must be installed on each client workstation.

E.

Deploy a separate eDirectory server; the dent IP address is recorded in this server.

Buy Now
Questions 236

How does Cisco Umbrella archive logs to an enterprise owned storage?

Options:

A.

by using the Application Programming Interface to fetch the logs

B.

by sending logs via syslog to an on-premises or cloud-based syslog server

C.

by the system administrator downloading the logs from the Cisco Umbrella web portal

D.

by being configured to send logs to a self-managed AWS S3 bucket

Buy Now
Questions 237

Which type of API is being used when a security application notifies a controller within a software-defined network architecture about a specific security threat?

Options:

A.

westbound AP

B.

southbound API

C.

northbound API

D.

eastbound API

Buy Now
Questions 238

An engineer needs behavioral analysis to detect malicious activity on the hosts, and is configuring the

organization’s public cloud to send telemetry using the cloud provider’s mechanisms to a security device. Which

mechanism should the engineer configure to accomplish this goal?

Options:

A.

mirror port

B.

Flow

C.

NetFlow

D.

VPC flow logs

Buy Now
Questions 239

An organization has a requirement to collect full metadata information about the traffic going through their AWS cloud services They want to use this information for behavior analytics and statistics Which two actions must be taken to implement this requirement? (Choose two.)

Options:

A.

Configure Cisco ACI to ingest AWS information.

B.

Configure Cisco Thousand Eyes to ingest AWS information.

C.

Send syslog from AWS to Cisco Stealthwatch Cloud.

D.

Send VPC Flow Logs to Cisco Stealthwatch Cloud.

E.

Configure Cisco Stealthwatch Cloud to ingest AWS information

Buy Now
Questions 240

Which VPN provides scalability for organizations with many remote sites?

Options:

A.

DMVPN

B.

site-to-site iPsec

C.

SSL VPN

D.

GRE over IPsec

Buy Now
Exam Code: 350-701
Exam Name: Implementing and Operating Cisco Security Core Technologies (SCOR 350-701 v2.0)
Last Update: Oct 5, 2026
Questions: 801
350-701 pdf

350-701 PDF

$28.5  $94.99
350-701 Engine

350-701 Testing Engine

$33  $109.99
350-701 PDF + Engine

350-701 PDF + Testing Engine

$43.5  $144.99