Exam style questions across every 350-701 domain
Last Update 4 hours ago
Total Questions : 801
Start with our free 350-701 practice questions, carefully crafted to mirror the domains, phrasing, and difficulty of the real CCNP Security exam. Each 350-701 exam question comes with a detailed rationale that explains not just which answer is correct but why the others fall short. That's how concepts stick. Use the free set to benchmark yourself: identify your Cisco weak domains, see where you're losing marks, and build a focused study plan in minutes.
A network administrator configures Dynamic ARP Inspection on a switch. After Dynamic ARP Inspection is applied, all users on that switch are unable to communicate with any destination. The network administrator checks the interface status of all interfaces, and there is no err-disabled interface. What is causing this problem?
For which two conditions can an endpoint be checked using ISE posture assessment? (Choose two)
What are two ways a network administrator transparently identifies users using Active Directory on the Cisco WSA? (Choose two.)
Which Talos reputation center allows you to track the reputation of IP addresses for email and web traffic?
Refer to the exhibit.
What are two indications of the Cisco Firepower Services Module configuration?
(Choose two.)
Which two actions does the Cisco identity Services Engine posture module provide that ensures endpoint security?(Choose two.)
A network engineer is configuring a Cisco Catalyst switch. The network engineer must prevent traffic on the network from being interrupted by broadcast packets flooding the network using a predefined threshold. What must be configured on the switch?
Refer to the exhibit.
aaa new-model
aaa authentication dot1x default group ISE-SERVERS
aaa authorization network default group ISE-SERVERS
aaa accounting dot1x default start-stop group ISE-SERVERS
!
radius server RADIUS_SRV
address ipv4 172.16.10.12 auth-port 1812 acct-port 1813
key shared-secret C1sc0123
!
aaa group server radius ISE-SERVERS
server name RADIUS_SRV
radius-server vsa send authentication
radius-server vsa send accounting
radius-server attribute 6 on-for-login-auth
radius-server attribute 8 include-in-access-req
radius-server attribute 25 access-request include
ip device tracking
!
interface range GigabitEthernet1/0/1 - 48
switchport
switchport host
authentication priority dot1x mab
authentication order dot1x mab
A security engineer is integrating a new Cisco Catalyst access switch with Cisco ISE to enforce port-based network access control using 802.1X. The AAA RADIUS server group and access interfaces are configured on the Cisco Catalyst switch. Cisco ISE has authentication and authorization policies, the workstation supplicants are configured as expected, and connectivity between the switch and ISE is working. During testing, the workstations fail to trigger authentication sessions, and no RADIUS requests appear in the ISE logs or on the switch interfaces. Which two configuration commands must be added to the Cisco Catalyst switch? (Choose two.)
Which Cisco Advanced Malware protection for Endpoints deployment architecture is designed to keep data
within a network perimeter?
Refer to the exhibit.
A Cisco Secure Endpoint malware event shows that a file was convicted as malicious and that its remediation status is Quarantine Failed. Before escalating the incident, the analyst must determine what can be concluded from the available event data. What is occurring based on the logs?
A mall provides security services to customers with a shared appliance. The mall wants separation of
management on the shared appliance. Which ASA deployment mode meets these needs?
Which protocol provides the strongest throughput performance when using Cisco AnyConnect VPN?
Where are individual sites specified to be blacklisted in Cisco Umbrella?
