Latest [Dec 01, 2021] Real Cisco 350-701 Exam Dumps Questions [Q139-Q164]

Share

Latest [Dec 01, 2021]  Real Cisco 350-701 Exam Dumps Questions

350-701 Dumps To Pass CCNP Security Exam in One Day (Updated 358 Questions)

NEW QUESTION 139
Drag and drop the solutions from the left onto the solution's benefits on the right.

Answer:

Explanation:

 

NEW QUESTION 140
Which type of protection encrypts RSA keys when they are exported and imported?

  • A. NGE
  • B. nonexportable
  • C. file
  • D. passphrase

Answer: D

 

NEW QUESTION 141
An organization wants to secure data in a cloud environment. Its security model requires that all users be authenticated and authorized. Security configuration and posture must be continuously validated before access is granted or maintained to applications and dat a. There is also a need to allow certain application traffic and deny all other traffic by default. Which technology must be used to implement these requirements?

  • A. Virtual routing and forwarding
  • B. Microsegmentation
  • C. Virtual LAN
  • D. Access control policy

Answer: B

Explanation:
Zero Trust is a security framework requiring all users, whether in or outside the organization's network, to be authenticated, authorized, and continuously validated for security configuration and posture before being granted or keeping access to applications and data. Zero Trust assumes that there is no traditional network edge; networks can be local, in the cloud, or a combination or hybrid with resources anywhere as well as workers in any location.
The Zero Trust model uses microsegmentation - a security technique that involves dividing perimeters into small zones to maintain separate access to every part of the network - to contain attacks.

 

NEW QUESTION 142
An organization is trying to improve their Defense in Depth by blocking malicious destinations prior to a connection being established. The solution must be able to block certain applications from being used within the network Which product should be used to accomplish this goal?

  • A. AMP
  • B. ISE
  • C. Cisco Umbrella
  • D. Cisco Firepower

Answer: C

Explanation:

 

NEW QUESTION 143
Drag and drop the capabilities of Cisco Firepower versus Cisco AMP from the left into the appropriate category on the right.

Answer:

Explanation:

https://www.cisco.com/c/en/us/products/collateral/security/ngips/datasheet-c78-742472.html
https://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide-v60/Reference_a_wrapper_Chapter_topic_here.html
https://www.cisco.com/c/en/us/solutions/collateral/enterprise-networks/advanced-malware-protection/solution-overview-c22-734228.html

 

NEW QUESTION 144
What is a characteristic of traffic storm control behavior?

  • A. Traffic storm control uses the Individual/Group bit in the packet source address to determine if the packet is unicast or broadcast.
  • B. Traffic storm control drops all broadcast and multicast traffic if the combined traffic exceeds the level within the interval.
  • C. Traffic storm control monitors incoming traffic levels over a 10-second traffic storm control interval.
  • D. Traffic storm control cannot determine if the packet is unicast or broadcast.

Answer: B

Explanation:
Explanation/Reference: https://www.cisco.com/c/en/us/td/docs/routers/7600/ios/12-1E/configuration/guide/storm.html

 

NEW QUESTION 145
In which two ways does a system administrator send web traffic transparently to the Web Security Appliance? (Choose two.)

  • A. snmp-server host inside 10.255.254.1 version 3 myv3
  • B. reference a Proxy Auto Config file
  • C. configure policy-based routing on the network infrastructure
  • D. configure Active Directory Group Policies to push proxy settings
  • E. configure the proxy IP address in the web-browser settings

Answer: A,B

 

NEW QUESTION 146
Drag and drop the solutions from the left onto the solution's benefits on the right.

Answer:

Explanation:

Explanation:
Cisco Stealthwatch - rapidly collects and analyzes netflow and telementy data to deliver in-depth visibility and understanding of network traffic Cisco ISE - obtains contextual identity and profiles for all users and device Cisco TrustSec - software defined segmentation that uses SGTs Cisco Umbrella - secure internet gateway ion the cloud that provides a security solution

 

NEW QUESTION 147
What must be configured in Cisco ISE to enforce reauthentication of an endpoint session when an endpoint is deleted from an identity group?

  • A. SNMP probe
  • B. CoA
  • C. external identity source
  • D. posture assessment

Answer: A

 

NEW QUESTION 148
What can be integrated with Cisco Threat Intelligence Director to provide information about security threats, which allows the SOC to proactively automate responses to those threats?

  • A. Cisco Threat Grid
  • B. External Threat Feeds
  • C. Cisco Stealthwatch
  • D. Cisco Umbrella

Answer: A

Explanation:
Cisco Threat Intelligence Director (CTID) can be integrated with existing Threat Intelligence Platforms deployed by your organization to ingest threat intelligence automatically.
Cisco Threat Intelligence Director (CTID) can be integrated with existing Threat Intelligence Platforms deployed by your organization to ingest threat intelligence automatically.
Reference:
Cisco Threat Intelligence Director (CTID) can be integrated with existing Threat Intelligence Platforms deployed by your organization to ingest threat intelligence automatically.

 

NEW QUESTION 149
What is a difference between an XSS attack and an SQL injection attack?

  • A. SQL injection is a hacking method used to attack SQL databases, whereas XSS attacks can exist in many different types of applications
  • B. SQL injection attacks are used to steal information from databases whereas XSS attacks are used to redirect users to websites where attackers can steal data from them
  • C. XSS is a hacking method used to attack SQL databases, whereas SQL injection attacks can exist in many different types of applications
  • D. XSS attacks are used to steal information from databases whereas SQL injection attacks are used to redirect users to websites where attackers can steal data from them

Answer: B

 

NEW QUESTION 150
What are two differences between a Cisco WSA that is running in transparent mode and one running in explicit mode? (Choose two.)

  • A. The Cisco WSA is configured in a web browser only if it is running in transparent mode.
  • B. The Cisco WSA uses a Layer 3 device to redirect traffic only if it is running in transparent mode.
  • C. The Cisco WSA responds with its own IP address only if it is running in explicit mode.
  • D. When the Cisco WSA is running in transparent mode, it uses the WSA's own IP address as the HTTP request destination.
  • E. The Cisco WSA responds with its own IP address only if it is running in transparent mode.

Answer: B,C

 

NEW QUESTION 151
An engineer has been tasked with implementing a solution that can be leveraged for securing the cloud users, data, and applications. There is a requirement to use the Cisco cloud native CASB and cloud cybersecurity platform. What should be used to meet these requirements?

  • A. Cisco Cloudlock
  • B. Cisco Cloud Email Security
  • C. Cisco NGFW
  • D. Cisco Umbrella

Answer: A

Explanation:
Explanation
Cisco Cloudlock: Secure your cloud users, data, and applications with the cloud-native Cloud Access Security Broker (CASB) and cloud cybersecurity platform.
Reference:
738565.pdf

 

NEW QUESTION 152
Which posture assessment requirement provides options to the client for remediation and requires the remediation within a certain timeframe?

  • A. Optional
  • B. Mandatory
  • C. Visibility
  • D. Audio

Answer: D

 

NEW QUESTION 153
Which attack is preventable by Cisco ESA but not by the Cisco WSA?

  • A. phishing
  • B. SQL injection
  • C. buffer overflow
  • D. DoS

Answer: A

 

NEW QUESTION 154
What is the function of Cisco Cloudlock for data security?

  • A. detects anomalies
  • B. controls malicious cloud apps
  • C. data loss prevention
  • D. user and entity behavior analytics

Answer: C

 

NEW QUESTION 155
An organization has noticed an increase in malicious content downloads and wants to use Cisco Umbrella to prevent this activity for suspicious domains while allowing normal web traffic. Which action will accomplish this task?

  • A. Set content settings to High
  • B. Configure application block lists.
  • C. Configure the intelligent proxy.
  • D. Use destination block lists.

Answer: C

Explanation:
Explanation Explanation Obviously, if you allow all traffic to these risky domains, users might access malicious content, resulting in an infection or data leak. But if you block traffic, you can expect false positives, an increase in support inquiries, and thus, more headaches. By only proxying risky domains, the intelligent proxy delivers more granular visibility and control. The intelligent proxy bridges the gap by allowing access to most known good sites without being proxied and only proxying those that pose a potential risk. The proxy then filters and blocks against specific URLs hosting malware while allowing access to everything else. Reference: https://docs.umbrella.com/deployment-umbrella/docs/what-is-the-intelligent-proxy Explanation Obviously, if you allow all traffic to these risky domains, users might access malicious content, resulting in an infection or data leak. But if you block traffic, you can expect false positives, an increase in support inquiries, and thus, more headaches. By only proxying risky domains, the intelligent proxy delivers more granular visibility and control.
The intelligent proxy bridges the gap by allowing access to most known good sites without being proxied and only proxying those that pose a potential risk. The proxy then filters and blocks against specific URLs hosting malware while allowing access to everything else.
Explanation Explanation Obviously, if you allow all traffic to these risky domains, users might access malicious content, resulting in an infection or data leak. But if you block traffic, you can expect false positives, an increase in support inquiries, and thus, more headaches. By only proxying risky domains, the intelligent proxy delivers more granular visibility and control. The intelligent proxy bridges the gap by allowing access to most known good sites without being proxied and only proxying those that pose a potential risk. The proxy then filters and blocks against specific URLs hosting malware while allowing access to everything else. Reference: https://docs.umbrella.com/deployment-umbrella/docs/what-is-the-intelligent-proxy

 

NEW QUESTION 156
Which DevSecOps implementation process gives a weekly or daily update instead of monthly or quarterly in the applications?

  • A. container
  • B. orchestration
  • C. security
  • D. CI/CD pipeline

Answer: D

 

NEW QUESTION 157
Drag and drop the steps from the left into the correct order on the right to enable AppDynamics to monitor an EC2 instance in Amazon Web Services.

Answer:

Explanation:

Explanation

 

NEW QUESTION 158
A network administrator is configuring a switch to use Cisco ISE for 802.1X. An endpoint is failing authentication and is unable to access the network. Where should the administrator begin troubleshooting to verify the authentication details?

  • A. Adaptive Network Control Policy List
  • B. Accounting Reports
  • C. RADIUS Live Logs
  • D. Context Visibility

Answer: C

Explanation:
Explanation
Explanation
How To Troubleshoot ISE Failed Authentications & Authorizations
Check the ISE Live Logs
Login to the primary ISE Policy Administration Node (PAN).
Go to Operations > RADIUS > Live Logs
(Optional) If the event is not present in the RADIUS Live Logs, go to Operations > Reports > Reports > Endpoints and Users > RADIUS Authentications Check for Any Failed Authentication Attempts in the Log

 

NEW QUESTION 159
Refer to the exhibit.

When configuring a remote access VPN solution terminating on the Cisco ASA, an administrator would like to utilize an external token authentication mechanism in conjunction with AAA authentication using machine certificates. Which configuration item must be modified to allow this?

  • A. DHCP Servers
  • B. SAML Server
  • C. Group Policy
  • D. Method

Answer: D

Explanation:
In order to use AAA along with an external token authentication mechanism, set the "Method" as "Both" in the Authentication.

 

NEW QUESTION 160
Refer to the exhibit.

What does the number 15 represent in this configuration?

  • A. interval in seconds between SNMPv3 authentication attempts
  • B. number of possible failed attempts until the SNMPv3 user is locked out
  • C. access list that identifies the SNMP devices that can access the router
  • D. privilege level for an authorized user to this router

Answer: C

Explanation:
The syntax of this command is shown below:
snmp-server group [group-name {v1 | v2c | v3 [auth | noauth | priv]}] [read read-view] [write write-view] [notify notify-view] [access access-list] The command above restricts which IP source addresses are allowed to access SNMP functions on the router. You could restrict SNMP access by simply applying an interface ACL to block incoming SNMP packets that don't come from trusted servers. However, this would not be as effective as using the global SNMP commands shown in this recipe. Because you can apply this method once for the whole router, it is much simpler than applying ACLs to block SNMP on all interfaces separately. Also, using interface ACLs would block not only SNMP packets intended for this router, but also may stop SNMP packets that just happened to be passing through on their way to some other destination device.

 

NEW QUESTION 161
What is the difference between a vulnerability and an exploit?

  • A. An exploit is a hypothetical event that causes a vulnerability in the network
  • B. An exploit is a weakness that can cause a vulnerability in the network
  • C. A vulnerability is a weakness that can be exploited by an attacker
  • D. A vulnerability is a hypothetical event for an attacker to exploit

Answer: C

 

NEW QUESTION 162
An organization deploys multiple Cisco FTD appliances and wants to manage them using one centralized solution. The organization does not have a local VM but does have existing Cisco ASAs that must migrate over to Cisco FTDs. Which solution meets the needs of the organization?

  • A. CDO
  • B. Cisco FDM
  • C. Cisco FMC
  • D. CSM

Answer: C

 

NEW QUESTION 163
A network engineer has entered the snmp-server user andy myv3 auth sha cisco priv aes 256 cisc0380739941 command and needs to send SNMP information to a host at 10.255.254.1. Which command achieves this goal?

  • A. snmp-server host inside 10.255.254.1 snmpv3 andy
  • B. snmp-server host inside 10.255.254.1 version 3 andy
  • C. snmp-server host inside 10.255.254.1 version 3 myv3
  • D. snmp-server host inside 10.255.254.1 snmpv3 myv3

Answer: B

 

NEW QUESTION 164
......


Available Certification Paths

The Cisco SCOR 350-701 exam brings one the Cisco Certified Specialist – Security Core certificate. Also, it will take candidates closer to obtaining the CCNP Security and the CCIE Security certifications. To earn the first one, applicant should obtain the passing score in any of the six offered concentration tests. The second one requires students to pass the CCIE Security v6.0 lab exam. This certification is for candidates who want to prove they are experts in implementing and operating Cisco security technologies.


Understanding functional and technical aspects of Implementing and Operating Cisco Security Core Technologies (SCOR 350-701) Securing the Cloud

The following will be discussed in CISCO 350-701 dumps:

  • Configure cloud logging and monitoring methodologies
  • Identify security capabilities, deployment models, and policy management to secure the cloud
  • Cloud service models: SaaS, PaaS, IaaS (NIST 800-145)
  • Compare the customer vs. provider security responsibility for the different cloud service models
  • Patch management in the cloud
  • Describe the concept of DevSecOps (CI/CD pipeline, container orchestration, and security
  • Implement application and data security in cloud environments
  • Security assessment in the cloud
  • Identify security solutions for cloud environments
  • Describe application and workload security concepts
  • Cloud-delivered security solutions such as firewall, management, proxy, security intelligence, and CASB
  • Public, private, hybrid, and community clouds

 

350-701 Exam Brain Dumps - Study Notes and Theory: https://www.passcollection.com/350-701_real-exams.html

100% Guaranteed Results 350-701 Unlimited 358 Questions: https://drive.google.com/open?id=19kbQl6SfnSAXUuuG5iU_QL3E2nwOBu8I