Pre-Winter Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 65pass65

Free Implementing and Operating Cisco Security Core Technologies (SCOR 350-701 v2.0) Practice Questions

Exams4sure Dumps

Exam style questions across every 350-701 domain

Last Update 4 hours ago
Total Questions : 801

Start with our free 350-701 practice questions, carefully crafted to mirror the domains, phrasing, and difficulty of the real CCNP Security exam. Each 350-701 exam question comes with a detailed rationale that explains not just which answer is correct but why the others fall short. That's how concepts stick. Use the free set to benchmark yourself: identify your Cisco weak domains, see where you're losing marks, and build a focused study plan in minutes.

350-701 PDF

350-701 PDF (Printable)
$54.25
$154.99

350-701 Testing Engine

350-701 PDF (Printable)
$59.5
$169.99

350-701 PDF + Testing Engine

350-701 PDF (Printable)
$74.55
$212.99
Question # 46

Drag and drop the cloud security assessment components from the left onto the definitions on the right.

Question # 46

Options:

Discussion 0
Question # 47

An administrator is configuring a DHCP server to better secure their environment. They need to be able to ratelimit the traffic and ensure that legitimate requests are not dropped. How would this be accomplished?

Options:

A.  

Set a trusted interface for the DHCP server

B.  

Set the DHCP snooping bit to 1

C.  

Add entries in the DHCP snooping database

D.  

Enable ARP inspection for the required VLAN

Discussion 0
Question # 48

Refer to the exhibit. When creating an access rule for URL filtering, a network engineer adds certain categories and individual URLs to block. What is the result of the configuration?

Options:

A.  

Only URLs for botnets with reputation scores of 1-3 will be blocked.

B.  

Only URLs for botnets with a reputation score of 3 will be blocked.

C.  

Only URLs for botnets with reputation scores of 3-5 will be blocked.

D.  

Only URLs for botnets with a reputation score of 3 will be allowed while the rest will be blocked.

Discussion 0
Question # 49

An administrator has been tasked with configuring the Cisco Secure Email Gateway to ensure there are no viruses before quarantined emails are delivered. In addition, delivery of mail from known bad mail servers must be prevented. Which two actions must be taken in order to meet these requirements? (Choose two.)

Options:

A.  

Deploy the Secure Email Gateway in the DMZ.

B.  

Use outbreak filters from Cisco Talos.

C.  

Configure a recipient access table.

D.  

Enable a message tracking service.

E.  

Scan quarantined emails using AntiVirus signatures.

Discussion 0
Question # 50

Which technology should be used to help prevent an attacker from stealing usernames and passwords of users within an organization?

Options:

A.  

RADIUS-based REAP

B.  

fingerprinting

C.  

Dynamic ARP Inspection

D.  

multifactor authentication

Discussion 0
Question # 51

Which Secure Email Gateway implementation method segregates inbound and outbound email?

Options:

A.  

Pair of logical listeners on a single physical interface with two unique logical IPv4 addresses and one IPv6 address

B.  

One listener on one logical IPv4 address on a single logical interface

C.  

Pair of logical IPv4 listeners and a pair of IPv6 listeners on two physically separate interfaces

D.  

One listener on a single physical interface

Discussion 0
Question # 52

An organization is trying to improve their Defense in Depth by blocking malicious destinations prior to a

connection being established. The solution must be able to block certain applications from being used within the network. Which product should be used to accomplish this goal?

Options:

A.  

Cisco Firepower

B.  

Cisco Umbrella

C.  

ISE

D.  

AMP

Discussion 0
Question # 53

Which feature must be configured before implementing NetFlow on a router?

Options:

A.  

SNMPv3

B.  

syslog

C.  

VRF

D.  

IP routing

Discussion 0
Question # 54

A web hosting company must upgrade its older, unsupported on-premises servers. The company wants a cloud solution in which the cloud provider is responsible for:

Server patching

Application maintenance

Data center security

Disaster recovery

Which type of cloud meets the requirements?

Options:

A.  

Hybrid

B.  

IaaS

C.  

SaaS

D.  

PaaS

Discussion 0
Question # 55

An engineer is trying to securely connect to a router and wants to prevent insecure algorithms from being used.

However, the connection is failing. Which action should be taken to accomplish this goal?

Options:

A.  

Disable telnet using the no ip telnet command.

B.  

Enable the SSH server using the ip ssh server command.

C.  

Configure the port using the ip ssh port 22 command.

D.  

Generate the RSA key using the crypto key generate rsa command.

Discussion 0
Question # 56

What is a capability of a Trojan horse on a computer system?

Options:

A.  

It replicates itself into other programs.

B.  

It disguises itself as a legitimate program.

C.  

It inserts its own code when legitimate programs are executed.

D.  

It enables access to restricted areas without being detected.

Discussion 0
Question # 57

Drag and drop the capabilities from the left onto the correct technologies on the right.

Question # 57

Options:

Discussion 0
Question # 58

Which RADIUS feature provides a mechanism to change the AAA attributes of a session after it is

authenticated?

Options:

A.  

Authorization

B.  

Accounting

C.  

Authentication

D.  

CoA

Discussion 0
Question # 59

A hacker initiated a social engineering attack and stole username and passwords of some users within a company. Which product should be used as a solution to this problem?

Options:

A.  

Cisco NGFW

B.  

Cisco AnyConnect

C.  

Cisco AMP for Endpoints

D.  

Cisco Duo

Discussion 0
Question # 60

Which type of data exfiltration technique encodes data in outbound DNS requests to specific servers

and can be stopped by Cisco Umbrella?

Options:

A.  

DNS tunneling

B.  

DNS flood attack

C.  

cache poisoning

D.  

DNS hijacking

Discussion 0

Free Exams Sample Questions