Pre-Winter Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 65pass65

Free Implementing and Operating Cisco Security Core Technologies (SCOR 350-701 v2.0) Practice Questions

Exams4sure Dumps

Exam style questions across every 350-701 domain

Last Update 4 hours ago
Total Questions : 801

Start with our free 350-701 practice questions, carefully crafted to mirror the domains, phrasing, and difficulty of the real CCNP Security exam. Each 350-701 exam question comes with a detailed rationale that explains not just which answer is correct but why the others fall short. That's how concepts stick. Use the free set to benchmark yourself: identify your Cisco weak domains, see where you're losing marks, and build a focused study plan in minutes.

350-701 PDF

350-701 PDF (Printable)
$54.25
$154.99

350-701 Testing Engine

350-701 PDF (Printable)
$59.5
$169.99

350-701 PDF + Testing Engine

350-701 PDF (Printable)
$74.55
$212.99
Question # 16

What is the function of the Context Directory Agent?

Options:

A.  

maintains users’ group memberships

B.  

relays user authentication requests from Web Security Appliance to Active Directory

C.  

reads the Active Directory logs to map IP addresses to usernames

D.  

accepts user authentication requests on behalf of Web Security Appliance for user identification

Discussion 0
Question # 17

Which attack type attempts to shut down a machine or network so that users are not able to access it?

Options:

A.  

smurf

B.  

bluesnarfing

C.  

MAC spoofing

D.  

IP spoofing

Discussion 0
Question # 18

Which two Cisco Umbrella security categories are used to prevent command-and-control callbacks on port 53 and protect users from being tricked into providing confidential information? (Choose two.)

Options:

A.  

DNS Tunneling VPN

B.  

Dynamic DNS

C.  

Newly Seen Domains

D.  

Potentially Harmful Domains

E.  

Phishing Attacks

Discussion 0
Question # 19

Which technology must be used to implement secure VPN connectivity among company branches over a

private IP cloud with any-to-any scalable connectivity?

Options:

A.  

DMVPN

B.  

FlexVPN

C.  

IPsec DVTI

D.  

GET VPN

Discussion 0
Question # 20

Which solution for remote workers enables protection, detection, and response on the endpoint against known and unknown threats?

Options:

A.  

Cisco AMP for Endpoints

B.  

Cisco AnyConnect

C.  

Cisco Umbrella

D.  

Cisco Duo

Discussion 0
Question # 21

A security engineer is deploying an IPsec site-to-site VPN between headquarters and a remote plant, protected by Cisco Secure Firewall Threat Defense managed by Cisco Secure Firewall Management Center. The following configurations have already been completed:

    Matching IKEv2 proposals, preshared keys, and IPsec transform sets

    Access control rules permitting the traffic

    Crypto maps applied to the outside interfaces

    VPN traffic exempted from inspection

During a packet capture on the firewall, the engineer observes that the traffic is translated to the public IP address, preventing tunnel establishment. Which configuration action must be performed next?

Options:

A.  

Configure NAT exemption for traffic between the interesting subnet pairs.

B.  

Create a tunnel group with preshared-key authentication under connection profiles.

C.  

Enable IKEv2 fragmentation on both peers to reduce packet size.

D.  

Attach the new VPN policy to the global prefilter default action.

Discussion 0
Question # 22

An organization is receiving SPAM emails from a known malicious domain. What must be configured in order to

prevent the session during the initial TCP communication?

Options:

A.  

Configure the Cisco ESA to drop the malicious emails

B.  

Configure policies to quarantine malicious emails

C.  

Configure policies to stop and reject communication

D.  

Configure the Cisco ESA to reset the TCP connection

Discussion 0
Question # 23

Which service allows a user to export application usage and performance statistics with Cisco Application Visibility and Control?

Options:

A.  

SNMP

B.  

802.1X

C.  

NetFlow

D.  

SNORT

Discussion 0
Question # 24

Which endpoint protection and detection feature performs correlation of telemetry, files, and intrusion

events that are flagged as possible active breaches?

Options:

A.  

retrospective detection

B.  

indication of compromise

C.  

file trajectory

D.  

elastic search

Discussion 0
Question # 25

What is a feature of the open platform capabilities of Cisco DNA Center?

Options:

A.  

intent-based APIs

B.  

automation adapters

C.  

domain integration

D.  

application adapters

Discussion 0
Question # 26

Refer to the exhibit.

Question # 26

What does the number 15 represent in this configuration?

Options:

A.  

privilege level for an authorized user to this router

B.  

access list that identifies the SNMP devices that can access the router

C.  

interval in seconds between SNMPv3 authentication attempts

D.  

number of possible failed attempts until the SNMPv3 user is locked out

Discussion 0
Question # 27

Which statement about IOS zone-based firewalls is true?

Options:

A.  

An unassigned interface can communicate with assigned interfaces

B.  

Only one interface can be assigned to a zone.

C.  

An interface can be assigned to multiple zones.

D.  

An interface can be assigned only to one zone.

Discussion 0
Question # 28

Which two features of Cisco DNA Center are used in a Software Defined Network solution? (Choose two)

Options:

A.  

accounting

B.  

assurance

C.  

automation

D.  

authentication

E.  

encryption

Discussion 0
Question # 29

What are the components of endpoint protection against social engineering attacks?

Options:

A.  

IPsec

B.  

IDS

C.  

Firewall

D.  

Cisco Secure Email Gateway

Discussion 0
Question # 30

Which two types of policies are used by ZTNA to provide access to an application? (Choose two.)

Options:

A.  

Context

B.  

Access

C.  

Site-to-site

D.  

Identity

E.  

Remote access

Discussion 0

Free Exams Sample Questions