Pre-Winter Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 65pass65

Free Implementing and Operating Cisco Security Core Technologies (SCOR 350-701 v2.0) Practice Questions

Exams4sure Dumps

Exam style questions across every 350-701 domain

Last Update 5 hours ago
Total Questions : 801

Start with our free 350-701 practice questions, carefully crafted to mirror the domains, phrasing, and difficulty of the real CCNP Security exam. Each 350-701 exam question comes with a detailed rationale that explains not just which answer is correct but why the others fall short. That's how concepts stick. Use the free set to benchmark yourself: identify your Cisco weak domains, see where you're losing marks, and build a focused study plan in minutes.

350-701 PDF

350-701 PDF (Printable)
$54.25
$154.99

350-701 Testing Engine

350-701 PDF (Printable)
$59.5
$169.99

350-701 PDF + Testing Engine

350-701 PDF (Printable)
$74.55
$212.99
Question # 166

Question # 166

Refer to the exhibit. An engineer is implementing a certificate-based VPN. What is the result of the existing configuration?

Options:

A.  

The OU of the IKEv2 peer certificate is encrypted when the OU is set to MANGLER.

B.  

The OU of the IKEv2 peer certificate is used as the identity when matching an IKEv2 authorization policy.

C.  

Only an IKEv2 peer that has an OU certificate attribute set to MANGLER establishes an IKEv2 SA successfully.

D.  

The OU of the IKEv2 peer certificate is set to MANGLER.

Discussion 0
Question # 167

An engineer is implementing DHCP security mechanisms and needs the ability to add additional attributes to profiles that are created within Cisco ISE Which action accomplishes this task?

Options:

A.  

Define MAC-to-lP address mappings in the switch to ensure that rogue devices cannot get an IP address

B.  

Use DHCP option 82 to ensure that the request is from a legitimate endpoint and send the information to Cisco ISE

C.  

Modify the DHCP relay and point the IP address to Cisco IS

E.  

D.  

Configure DHCP snooping on the switch VLANs and trust the necessary interfaces

Discussion 0
Question # 168

Which IPS analysis technique matches traffic against a database of known attack patterns?

Options:

A.  

Signature-based detection

B.  

Behavioral analytics

C.  

Heuristic detection

D.  

Anomaly-based detection

Discussion 0
Question # 169

Which two devices support WCCP for traffic redirection? (Choose two.)

Options:

A.  

Cisco Secure Web Appliance

B.  

Cisco IOS

C.  

proxy server

D.  

Cisco ASA

E.  

Cisco IPS

Discussion 0
Question # 170

Which statement describes a serverless application?

Options:

A.  

The application delivery controller in front of the server farm designates on which server the application runs each time.

B.  

The application runs from an ephemeral, event-triggered, and stateless container that is fully managed by a cloud provider.

C.  

The application is installed on network equipment and not on physical servers.

D.  

The application runs from a containerized environment that is managed by Kubernetes or Docker Swarm.

Discussion 0
Question # 171

An engineer is trying to decide whether to use Cisco Umbrella, Cisco CloudLock, Cisco Stealthwatch, or Cisco AppDynamics Cloud Monitoring for visibility into data transfers as well as protection against data exfiltration Which solution best meets these requirements?

Options:

A.  

Cisco CloudLock

B.  

Cisco AppDynamics Cloud Monitoring

C.  

Cisco Umbrella

D.  

Cisco Stealthwatch

Discussion 0
Question # 172

What are two features of NetFlow flow monitoring? (Choose two)

Options:

A.  

Can track ingress and egress information

B.  

Include the flow record and the flow importer

C.  

Copies all ingress flow information to an interface

D.  

Does not required packet sampling on interfaces

E.  

Can be used to track multicast, MPLS, or bridged traffic

Discussion 0
Question # 173

Which technology provides a combination of endpoint protection endpoint detection, and response?

Options:

A.  

Cisco AMP

B.  

Cisco Talos

C.  

Cisco Threat Grid

D.  

Cisco Umbrella

Discussion 0
Question # 174

What is a description of microsegmentation?

Options:

A.  

Environments deploy a container orchestration platform, such as Kubernetes, to manage the application delivery.

B.  

Environments apply a zero-trust model and specify how applications on different servers or containers can communicate.

C.  

Environments deploy centrally managed host-based firewall rules on each server or container.

D.  

Environments implement private VLAN segmentation to group servers with similar applications.

Discussion 0
Question # 175

How is a cross-site scripting attack executed?

Options:

A.  

Force a currently authenticated end user to execute unwanted actions on a web app

B.  

Execute malicious client-side scripts injected to a client via a web app

C.  

Inject a database query via the input data from the client to a web app

D.  

Intercept communications between a client and a web server

Discussion 0
Question # 176

What is a difference between an XSS attack and an SQL injection attack?

Options:

A.  

SQL injection is a hacking method used to attack SQL databases, whereas XSS attacks can exist in many different types of applications

B.  

XSS is a hacking method used to attack SQL databases, whereas SQL injection attacks can exist in many different types of applications

C.  

SQL injection attacks are used to steal information from databases whereas XSS attacks are used toredirect users to websites where attackers can steal data from them

D.  

XSS attacks are used to steal information from databases whereas SQL injection attacks are used toredirect users to websites where attackers can steal data from them

Discussion 0
Question # 177

What is a functional difference between Cisco AMP for Endpoints and Cisco Umbrella Roaming Client?

Options:

A.  

The Umbrella Roaming client stops and tracks malicious activity on hosts, and AMP for Endpoints tracks only URL-based threats.

B.  

The Umbrella Roaming Client authenticates users and provides segmentation, and AMP for Endpoints allows only for VPN connectivity

C.  

AMP for Endpoints authenticates users and provides segmentation, and the Umbrella Roaming Client allows only for VPN connectivity.

D.  

AMP for Endpoints stops and tracks malicious activity on hosts, and the Umbrella Roaming Client tracks only URL-based threats.

Discussion 0
Question # 178

Drag and drop the security responsibilities from the left onto the corresponding cloud service models on the right.

Question # 178

Options:

Discussion 0
Question # 179

A pharmaceutical research facility has implemented a “Clean Room” network segment to protect sensitive research data and automated manufacturing equipment. Strict compliance requirements mandate that all network traffic logs from the Cisco Secure Firewall serving the segment be forwarded to Splunk for auditing. A Splunk Universal Forwarder is deployed locally on the log-collection servers to monitor syslog files. The engineer must configure the Universal Forwarder to monitor the local syslog files and assign a specific source type for proper ingestion into Splunk. Which stanza configuration must be used to meet the requirements?

Options:

A.  

inputs.conf using [monitor:///var/log/syslog]

B.  

server.conf using [monitor:///syslog]

C.  

props.conf using [syslog]

D.  

outputs.conf using [tcpout]

Discussion 0
Question # 180

Which system facilitates deploying microsegmentation and multi-tenancy services with a policy-based container?

Options:

A.  

SDLC

B.  

Docker

C.  

Lambda

D.  

Contiv

Discussion 0

Free Exams Sample Questions