300-740 Exam Questions
75 real 300-740 exam questions with expert-verified answers and explanations. Page 1 of 2.
- Question #1Threat Response
According to Cisco Security Reference Architecture, which solution provides threat intelligence and malware analytics?
Threat IntelligenceMalware AnalyticsCisco TalosSecurity Architecture - Question #2Application and Data Security
Which types of algorithm does a web application firewall use for zero-day DDoS protection?
Web Application FirewallZero-day protectionDDoS mitigationAdaptive algorithms - Question #3User and Device Security
An administrator must deploy an endpoint posture policy for all users. The organization wants to have all endpoints checked against antimalware definitions and operating system upd...
Endpoint Posture ComplianceCisco ISE PolicyNAD RedirectionSecure Client Modules - Question #4Cloud Security Architecture
Refer to the exhibit. An engineer must provide HTTPS access from the Google Cloud Platform virtual machine to the on-premises mail server. All other connections from the virtual ma...
Firewall Rules ConfigurationCloud-to-On-Premises ConnectivityNAT ConfigurationHTTPS Access - Question #5Threat Response
Refer to the exhibit. A security engineer deployed Cisco Secure XDR, and during testing, the log entry shows a security incident. Which action must the engineer take first?
Incident ResponseEndpoint IsolationThreat ContainmentCisco Secure XDR - Question #6Network and Cloud Security
Refer to the exhibit. An engineer must create a policy in Cisco Secure Firewall Management Center to prevent restricted users from being able to browse any business or mobile phone...
firewall rule precedenceaccess control policiesrule orderingpolicy enforcement - Question #7Secure Cloud Access Overview
Refer to the exhibit. An engineer must provide RDP access to the AWS virtual machines and HTTPS access to the Google Cloud Platform virtual machines. All other connectivity must be...
firewall rule orderingaccess control listscloud VM accessrule evaluation - Question #8Cisco Umbrella
Refer to the exhibit. An engineer must connect an on-premises network to the public cloud using Cisco Umbrella as a Cloud Access Security Broker. The indicated configuration was ap...
DNS resolutionDHCP configurationUmbrella connectivityOpenDNS - Question #9Application and Data Security
Which mitigation technique does a web application firewall use to protect a web server against DDoS attacks?
WAFDDoS mitigationRate limitingPacket filtering - Question #10Threat Response
Refer to the exhibit. An engineer is investigating an issue by using Cisco Secure Cloud Analytics. The engineer confirms that the connections are unauthorized and informs the incid...
Threat DetectionIncident ContainmentHost IsolationNetwork Segmentation - Question #11User and Device Security
In the zero-trust network access model, which criteria is used for continuous verification to modify trust levels?
zero-trust modelcontinuous verificationuser and device behaviortrust assessment - Question #12Network and Cloud Security
Refer to the exhibit. An engineer must create a segmentation policy in Cisco Secure Workload to block HTTP traffic. The indicated configuration was applied; however, HTTP traffic i...
Cisco Secure WorkloadSegmentation PolicyProtocol FilteringTraffic Configuration - Question #13Visibility and Assurance
Refer to the exhibit. An engineer must analyze the Cisco Secure Cloud Analytics report. What is occurring?
Cisco Secure Cloud AnalyticsGeographically unusual access detectionAnomaly detectionRemote access monitoring - Question #14Network and Cloud Security
Refer to the exhibit. An engineer must configure the Cisco ASA firewall to allow the client with IP indicated configuration was applied to the firewall and public DNS 4.4.4.4 is us...
ASA firewall rulesAccess control listsDNS resolutionRule precedence - Question #15Network and Cloud Security
Refer to the exhibit. An engineer must configure a remote access IPsec/IKEv1 VPN that will use AES256 and SHA256 on a Cisco ASA firewall. The indicated configuration was applied to...
IKEv1 Policy ConfigurationIPsec EncryptionHash/AuthenticationCisco ASA VPN - Question #16Threat Response
Which method is used by a Cisco XDR solution to prioritize actions?
XDRAI/MLThreat ResponsePrioritization - Question #17Cisco Umbrella
Refer to the exhibit. An engineer must configure a global allow list in Cisco Umbrella for the cisco.com domain. All other domains must be blocked. After creating a new policy and...
Cisco UmbrellaAllow-Only ModeDomain FilteringSecurity Policy - Question #18User and Device Security
An administrator received an incident report indicating suspicious activity of a user using a corporate device. The manager requested that the credentials of user [email protected] b...
Account ManagementIncident ResponseCredential ResetActive Directory Integration - Question #19User and Device Security
What helps prevent drive-by compromise?
drive-by compromisead blockersmalware preventionbrowser security - Question #20Cisco Cloudlock
Refer to the exhibit. An engineer must integrate Cisco Cloudlock with Salesforce in an organization. Despite the engineer's successful execution of the Salesforce integration with...
Cloudlock integrationSalesforce permissionsAdministrator visibilityAccess control - Question #21Threat Response
What must be automated to enhance the efficiency of a security team response?
Incident response automationSecurity policy enforcementSystem isolation proceduresThreat response efficiency - Question #22Network and Cloud Security
Refer to the exhibit. An engineer must troubleshoot an issue with excessive SSH traffic leaving the internal network between the hours of 18:00 and 08:00. The engineer applies a po...
ASA FirewallAccess Control ListsSSH PolicyRule Precedence - Question #23Threat Response
What does the MITRE ATT&CK framework catalog?
MITRE ATT&CKAttack TechniquesThreat IntelligenceSecurity Frameworks - Question #24Network and Cloud Security
An organization is distributed across several sites. Each site is connected to the main HQ using site-to-site VPNs implemented using Secure Firewall Threat Defense. Which functiona...
policy-based routingSaaS traffic breakoutsite-to-site VPNtraffic routing policies - Question #25Visibility and Assurance
Refer to the exhibit. An engineer is troubleshooting an incident by using Cisco Secure Cloud Analytics. What is the cause of the issue?
Cloud AnalyticsThreat DetectionDomain Controller SecurityAnomalous Activity - Question #26Network and Cloud Security
Refer to the exhibit. An engineer must configure VPN load balancing across two Cisco ASA. The indicated configuration was applied to each firewall; however, the load-balancing encr...
VPN load balancingASA clusteringIKEv1 encryptioncluster encryption - Question #27Network and Cloud Security
Refer to the exhibit. An engineer must block internal users from accessing Facebook and Facebook Apps. All other access must be allowed. The indicated policy was created in Cisco S...
Firewall Policy ConfigurationZone-Based Access ControlApplication BlockingTraffic Flow Direction - Question #28Threat Response
What is a crucial component in the MITRE ATT&CK framework?
MITRE ATT&CKThreat IntelligenceAttack TechniquesCredential Access - Question #29Network and Cloud Security
Refer to the exhibit. An engineer must create a firewall policy to allow web server communication only. The indicated firewall policy was applied; however, a recent audit requires...
firewall policy optimizationaccess control rulespolicy analysisrule redundancy - Question #30User and Device Security
Refer to the exhibit. An engineer must configure SAML SSO in Cisco ISE to use Microsoft Azure AD as an identity provider. These configurations were performed: - Configure a SAML Id...
SAML SSOISE ConfigurationAzure AD IntegrationIdentity Management - Question #31Visibility and Assurance
Refer to the exhibit. An engineer is analyzing a Cisco Secure Firewall Management Center report. Which activity does the output verify?
DNS response blockingFirewall reportingLog analysisTraffic verification - Question #32Cloud Security Architecture
Which concept is used in the Cisco SAFE key reference model?
Cisco SAFESecure DomainsReference ArchitectureSecurity Framework - Question #33Threat Response
A security analyst detects an employee endpoint making connections to a malicious IP on the internet and downloaded a file named Test0511127691C.pdf. The analyst discovers the mach...
Endpoint IsolationIncident ResponseMalware ContainmentThreat Mitigation - Question #34Secure Cloud Access Overview
Refer to the exhibit. An engineer must configure Duo SSO for Cisco Webex and add the Webex application to the Duo Access Gateway. Which two actions must be taken in Duo? (Choose tw...
Duo SSO configurationSAML metadataApplication integrationDuo Access Gateway - Question #35Application and Data Security
Which common strategy should be used to mitigate directory traversal attacks in a cloud environment?
Directory TraversalFile System PermissionsAccess ControlCloud Security - Question #36User and Device Security
Which attack mitigation must be in place to prevent an attacker from authenticating to a service using a brute force attack?
Brute Force MitigationMultifactor AuthenticationAccount Access ControlAuthentication Security - Question #37Cloud Security Architecture
What is associated with implementing Cisco zero-trust architecture?
zero-trust architecturetrust verificationaccess controlidentity verification - Question #38Cisco AMP for Endpoints and Cloud
An engineer configures trusted endpoints with Active Directory with Device Health to determine if an endpoint complies with the policy posture. After a week, an alert is received b...
Device Health ComplianceCisco Secure Endpoint (AMP)Endpoint Remediation WorkflowTrust Policy Enforcement - Question #39Threat Response
Refer to the exhibit. An engineer must troubleshoot an incident by using Cisco Secure Cloud Analytics. What is the cause of the issue?
SYN Flood AttackThreat DetectionCisco Secure Cloud AnalyticsNetwork Anomaly Analysis - Question #40Threat Response
Refer to the exhibit. An engineer is investigating an unauthorized connection issue using Cisco Secure Cloud Analytics. Which two actions must be taken? (Choose two.)
Incident ResponseUnauthorized Access DetectionCloud AnalyticsFirewall Controls - Question #41Threat Response
Refer to the exhibit. An engineer is investigating the critical alert received in Cisco Secure Network Analytics. The engineer confirms that the incident is valid. Which two action...
Incident ResponseAlert InvestigationThreat ContainmentNetwork Analytics - Question #42User and Device Security
An engineer is configuring multifactor authentication using Duo. The implementation must use Duo Authentication Proxy and the Active Directory as an identity source. The company us...
Duo Authentication ProxyActive Directory IntegrationMulti-factor AuthenticationIdentity Sources - Question #43Network and Cloud Security
Refer to the exhibit. An engineer must configure a remote access IPsec/IKEv2 VPN that will use SHA- 512 on a Cisco ASA firewall. The indicated configuration was applied to the fire...
IPsec ConfigurationIKEv2SHA-512 IntegrityCisco ASA - Question #44Visibility and Assurance
What does the Cisco Telemetry Broker provide for telemetry data?
Telemetry BrokerData brokeringTelemetry collectionNetwork visibility - Question #45User and Device Security
Refer to the exhibit. An engineer must configure Cisco ASA so that the Secure Client deployment is removed when the user laptop disconnects from the VPN. The indicated configuratio...
AnyConnect/Secure ClientVPN DeploymentASA ConfigurationClient Lifecycle Management - Question #46Cloud Security Architecture
Which SAFE component logically arranges the security capabilities into blueprints?
SAFE ComponentsReference ArchitecturesSecurity BlueprintsArchitecture Design - Question #47Cisco Umbrella
A recent InfraGard news release indicates the need to establish a risk ranking for all on-premises and cloud services. The ACME Corporation already performs risk assessments for on...
App DiscoveryCloud Service IdentificationRisk RankingCloud Services - Question #48Cisco Cloudlock
Refer to the exhibit. An engineer must enable access to Salesforce using Cisco Umbrella and Cisco Cloudlock. These actions were performed: From Salesforce, add the Cloudlock IP add...
Cloudlock integrationAPI authorizationCASBSalesforce SaaS access - Question #49Network and Cloud Security
Refer to the exhibit. An engineer must analyze a segmentation policy in Cisco Secure Workload. What is the result of applying the policy?
Segmentation PolicyAccess Control RulesRule PrecedenceWorkload Protection - Question #50User and Device Security
Refer to the exhibit. An engineer must implement a remote access VPN solution that provides user and device verification. The company uses Active Directory for user authentication...
Remote Access VPNDevice Certificate VerificationCisco ASAUser Authentication