350-701 Exam Questions
916 real 350-701 exam questions with expert-verified answers and explanations. Page 10 of 19.
- Question #452Secure Network Access, Visibility, and Enforcement
What is a feature of NetFlow Secure Event Logging?
NetFlow Secure Event LoggingNetwork visibilityFlow monitoringEvent-driven logging - Question #453
A hacker initiated a social engineering attack and stole username and passwords of some users within a company. Which product should be used as a solution to this problem?
Multi-factor authenticationCisco DuoIdentity managementSocial engineering defense - Question #454
Which technology provides the benefit of Layer 3 through Layer 7 innovative deep packet inspection, enabling the platform to identify and output various applications within the net...
Cisco NBAR2Deep Packet InspectionApplication Recognition - Question #455
Which RADIUS feature provides a mechanism to change the AAA attributes of a session after it is authenticated?
RADIUS CoAAAASession attributes - Question #456
Which type of data exfiltration technique encodes data in outbound DNS requests to specific servers and can be stopped by Cisco Umbrella?
DNS tunnelingdata exfiltrationCisco Umbrella - Question #457Cloud Security
A large organization wants to deploy a security appliance in the public cloud to form a site-to-site VPN and link the public cloud environment to the private cloud in the headquart...
Cisco ASAvSite-to-site VPNCloud VPN gatewayHybrid cloud connectivity - Question #458Content Security
Which CLI command is used to enable URL filtering support for shortened URLs on the Cisco Secure Email Gateway?
Cisco Secure Email GatewayURL filteringCLI commandsShortened URL protection - Question #459
Which standard is used to automate exchanging cyber threat information?
TAXIIThreat IntelligenceInformation Exchange - Question #460
What is a function of the Layer 4 Traffic Monitor on a Cisco WSA?
Cisco WSALayer 4 Traffic MonitorTraffic monitoring - Question #461
A network engineer entered the snmp-server user asmith myv7 auth sha cisco priv aes 256 cisc0xxxxxxxxx command and needs to send SNMP information to a host at 10.255.255.1. Which c...
Cisco SNMPSNMPv3 configurationsnmp-server host commandNetwork device management - Question #462
Refer to the exhibit. What are two indications of the Cisco Firepower Services Module configuration? (Choose two.)
Cisco FirepowerIDS/IPS modesFail-open configuration - Question #463Endpoint Security and Visibility
Why is it important for the organization to have an endpoint patching strategy?
Endpoint patchingVulnerability managementSecurity updates - Question #464
An email administrator is setting up a new Cisco Secure Email Gateway. The administrator wants to enable the blocking of greymail for the end user. Which feature must the administr...
Cisco Secure Email GatewayGreymail filteringEmail security featuresIntelligent Multi-Scan - Question #465
What limits communication between applications or containers on the same node?
MicrosegmentationContainer securityApplication isolation - Question #466
Which open source tool does Cisco use to create graphical visualizations of network telemetry on Cisco IOS XE devices?
Network TelemetryCisco IOS XEData Visualization - Question #467
How does the Cisco WSA enforce bandwidth restrictions for web applications?
Cisco WSABandwidth ManagementTraffic ShapingWeb Security Proxy - Question #468
Which two components do southbound APIs use to communicate with downstream devices? (Choose two.)
SDNSouthbound APIsOpenFlowOpFlex - Question #469Secure Network Access, Visibility, and Enforcement
What is the term for when an endpoint is associated to a provisioning WLAN that is shared with guest access, and the same guest portal is used as the BYOD portal?
BYODWLAN provisioningGuest access portalsSSID configuration - Question #470Secure Network Access, Visibility, and Enforcement
Which feature within Cisco ISE verifies the compliance of an endpoint before providing access to the network?
Cisco ISEEndpoint ComplianceNetwork Access Control - Question #471
Which MDM configuration provides scalability?
MDM scalabilityBYOD managementMobile Device Management - Question #472
Which Cisco ISE service checks the compliance of endpoints before allowing the endpoints to connect to the network?
Cisco ISEPosture serviceEndpoint complianceNAC - Question #473Endpoint Protection and Detection
Which endpoint protection and detection feature performs correlation of telemetry, files, and intrusion events that are flagged as possible active breaches?
indication of compromisetelemetry correlationbreach detectionEDR - Question #474
Which feature enables a Cisco ISR to use the default bypass list automatically for web filtering?
Cisco ISRWeb FilteringBypass ListConnector - Question #475Network Security
A network engineer has configured a NTP server on a Cisco ASA. The Cisco ASA has IP reachability to the NTP server and is not filtering any traffic. The show ntp association detail...
Cisco ASANTP protocolNTP troubleshootingNTP Stratum - Question #476Endpoint Security
When a next-generation endpoint security solution is selected for a company, what are two key deliverables that help justify the implementation? (Choose two.)
Next-gen endpoint securityThreat intelligence feedsContinuous endpoint monitoringSecurity solution justification - Question #477
What is the process of performing automated static and dynamic analysis of files in an isolated environment against preloaded behavioral indicators for threat analysis?
SandboxingMalware analysisBehavioral analysis - Question #478
Which solution is made from a collection of secure development practices and guidelines that developers must follow to build secure applications?
OWASPSecure development practicesApplication securitySecurity guidelines - Question #479
What do tools like Jenkins, Octopus Deploy, and Azure DevOps provide in terms of application and infrastructure automation?
CI/CDDevOps toolsApplication automationInfrastructure automation - Question #480Network Security
Which direction do attackers encode data in DNS requests during exfiltration using DNS tunneling?
DNS tunnelingdata exfiltration - Question #481
Which Cisco DNA Center RESTful PNP API adds and claims a device into a workflow?
Cisco DNA CenterPNP APIRESTful API - Question #482
What is a feature of container orchestration?
Container OrchestrationKubernetesDeployment capabilities - Question #483
What are two security benefits of an MDM deployment? (Choose two.)
Mobile Device ManagementEndpoint SecuritySecurity Policy EnforcementContent Management - Question #484
An organization is implementing AAA for their users. They need to ensure that authorization is verified for every command that is being entered by the network administrator. Which...
AAATACACS+Per-command authorization - Question #485Secure Network Access, Visibility, and Enforcement
What is the recommendation in a zero-trust model before granting access to corporate applications and resources?
Zero TrustMultifactor authenticationAccess Control - Question #486
Which Cisco AMP feature allows an engineer to look back to trace past activities, such as file and process activity on an endpoint?
Cisco AMPretrospective securityendpoint security - Question #487None
Which solution stops unauthorized access to the system if a user's password is compromised?
MFAAuthenticationAccess Control - Question #488
What is a benefit of using Cisco Tetration?
Cisco TetrationNetwork telemetryFlow analysisSoftware sensors - Question #489
How does Cisco Umbrella protect clients when they operate outside of the corporate network?
Cisco Umbrellaroaming clientDNS security - Question #490
Which API method and required attribute are used to add a device into Cisco DNA Center with the native API?
Cisco DNA Center APIDevice provisioning APIAPI methodsAPI attributes - Question #491
What are two facts about WSA HTTP proxy configuration with a PAC file? (Choose two.)
WSAHTTP proxyPAC fileExplicit proxy - Question #492Secure Network Access, Visibility, and Enforcement
Which solution should be leveraged for secure access of a CI/CD pipeline?
Duo Network GatewaySecure AccessCI/CD Security - Question #493Security Monitoring
Which function is included when Cisco AMP is added to web security?
Cisco AMPWeb SecurityMalware Analysis - Question #494
A small organization needs to reduce the VPN bandwidth load on their headend Cisco ASA in order to ensure that bandwidth is available for VPN users needing access to corporate reso...
Cisco ASASplit TunnelingVPN OptimizationRemote Access VPN - Question #495
Which solution detects threats across a private network, public clouds, and encrypted traffic?
Cisco StealthwatchNetwork threat detectionEncrypted traffic analysisCloud security monitoring - Question #496
Which Cisco security solution integrates with cloud applications like Dropbox and Office 365 while protecting data from being exfiltrated?
Cisco CloudlockCASBSaaS SecurityData Loss Prevention - Question #497CompTIA Security+ Domain 1: Threats, Attacks and Vulnerabilities - specifically identifying types of application/software attacks including injection attacks, buffer overflows, client-side attacks, and directory traversal vulnerabilities.
Drag and Drop Question Drag and drop the exploits from the left onto the type of security vulnerability on the right. Answer:
Web Application SecurityCommon Vulnerabilities and ExploitsAttack TypesSecurity Threats - Question #499
When network telemetry is implemented, what is important to be enabled across all network infrastructure devices to correlate different sources?
NTPNetwork TelemetryTime Synchronization - Question #500Cisco Web Security and Cloud-Based Security Deployment - understanding the various redirection methods for Cisco Cloud Web Security (CWS) including endpoint, router, firewall, and virtual appliance connectors, typically aligned with CCNA Security, CCNP Security (300-206 SENSS or SESA), or Cisco Web Security exam objectives.
Drag and Drop Question Drag and drop the Cisco CWS redirection options from the left onto the capabilities on the right. Answer:
Cisco Cloud Web SecurityCWS RedirectionWeb Security ArchitectureCisco Security Solutions - Question #501
What is the concept of continuous integration/continuous delivery pipelining?
CI/CDDevOpsAutomation - Question #502Security Concepts and Network Security - Understanding Cisco Next-Generation Firewall features and capabilities, typically aligned with CCNA Security, CCNP Security, or Cisco FirePOWER certification objectives covering integrated threat defense solutions.
Drag and Drop Question Drag and drop the features of Cisco ASA with Firepower from the left onto the benefits on the right. Answer:
Cisco ASA with FirepowerNGFWNetwork SecurityThreat Defense