350-701 Exam Questions
916 real 350-701 exam questions with expert-verified answers and explanations. Page 8 of 19.
- Question #352
An organization is selecting a cloud architecture and does not want to be responsible for patch management of the operating systems. Why should the organization select either Platf...
PaaSIaaSShared responsibility modelOS patch management - Question #353Deployment and Architecture
An administrator is adding a new Cisco ISE node to an existing deployment. What must be done to ensure that the addition of the node will be successful when inputting the FQDN?
Cisco ISE deploymentDNS resolutionFQDN - Question #354Secure Network Access, Visibility, and Enforcement
Refer to the exhibit. What will occur when this device tries to connect to the port?
802.1XMAC Authentication BypassNetwork Access Control - Question #355
A network engineer must configure a Cisco Secure Email Gateway to prompt users to enter two forms of information before gaining access. The Secure Email Gateway must also join a cl...
Cisco Secure Email GatewayTwo-factor authenticationRADIUSCluster configuration - Question #356
Which portion of the network do EPP solutions solely focus on and EDR solutions do not?
EPPEDREndpoint securityNetwork perimeter - Question #3573.0 VPN Technologies
Refer to the exhibit. An engineer is implementing a certificate based VPN. What is the result of the existing configuration?
IKEv2VPN certificatesCertificate identity matching - Question #358Content Security
What is a benefit of using Cisco CWS compared to an on-premises Cisco WSA?
Cisco CWSCisco WSATraffic BackhaulingCloud Security Architecture - Question #359
What is the term for having information about threats and threat actors that helps mitigate harmful events that would otherwise compromise networks or systems?
threat intelligencecybersecurity concepts - Question #360Securing the Cloud
An organization has a requirement to collect full metadata information about the traffic going through their AWS cloud services. They want to use this information for behavior anal...
AWS Cloud SecurityVPC Flow LogsCisco Stealthwatch CloudNetwork Traffic Analysis - Question #361
What is the function of the crypto isakmp key cisc123456789 address 192.168.50.1 255.255.255.255 command when establishing an IPsec VPN tunnel?
IPsec VPNISAKMPPre-shared keyCisco IOS commands - Question #362
An organization wants to improve its cybersecurity processes and to add intelligence to its data. The organization wants to utilize the most current intelligence data for URL filte...
Threat IntelligenceCisco FTDCisco WSATalos Intelligence - Question #363Network Security
A network security engineer must export packet captures from the Cisco FMC web browser while troubleshooting an issue. When navigating to the address Error! Hyperlink reference not...
Cisco FMCPacket Capture ExportHTTPS ConfigurationTroubleshooting - Question #364
Refer to the exhibit. Consider that any feature of DNS requests, such as the length of the domain name and the number of subdomains, can be used to construct models of expected beh...
DNS anomaly detectionMalware C2 communicationWorm attacks - Question #365
An engineer needs to add protection for data in transit and have headers in the email message. Which configuration is needed to accomplish this goal?
Email encryptionData in transit securitySecurity appliances - Question #366
How does a cloud access security broker function?
CASBCloud securityAPI integrationSecurity monitoring - Question #367
An engineer integrates Cisco FMC and Cisco ISE using pxGrid. Which role is assigned for Cisco FMC?
Cisco FMCCisco ISEpxGridIntegration roles - Question #368Network Security
Which configuration method provides the options to prevent physical and virtual endpoint devices that are in the same base EPG or uSeg from being able to communicate with each othe...
ACIEPGintra-EPG isolationmicro-segmentation - Question #369Security Concepts and Network Security Solutions - understanding the roles and benefits of Cisco security technologies including NGIPS, AMP for Endpoints, Collective Security Intelligence, and Contextual Awareness (CCNA Security / CyberOps / SCOR 350-701)
Drag and Drop Question Drag and drop the security solutions from the left onto the benefits they provide on the right. Answer:
Cisco Security ArchitectureNGIPSAMP for EndpointsThreat Intelligence - Question #370
Which statement describes a serverless application?
ServerlessFaaSCloud Computing Concepts - Question #371
Which baseline form of telemetry is recommended for network infrastructure devices?
Network telemetryNetFlowNetwork monitoringSNMP - Question #372
In which scenario is endpoint-based security the solution?
Endpoint securityApplication control - Question #373
Refer to the exhibit. What is the result of the Python script?
Python scriptingREST APIAPI authenticationHTTP methods - Question #374
Why is it important to patch endpoints consistently?
Patch managementVulnerability management - Question #375
An engineer enabled SSL decryption for Cisco Umbrella intelligent proxy and needs to ensure that traffic is inspected without alerting end-users. Which action accomplishes this goa...
Cisco UmbrellaSSL decryptionCertificate managementRoot CA installation - Question #376Content Security
What is the purpose of joining Cisco WSAs to an appliance group?
Cisco WSAAppliance groupsMalware analysis - Question #377
Why should organizations migrate to an MFA strategy for authentication?
Multi-Factor AuthenticationAuthentication strategySecurity principles - Question #378Secure Network Access, Visibility, and Enforcement
Which technology should be used to help prevent an attacker from stealing usernames and passwords of users within an organization?
Multifactor authenticationCredential protectionIdentity security - Question #379
For which type of attack is multifactor authentication an effective deterrent?
Multifactor authenticationPhishing - Question #380
Which Cisco cloud security software centrally manages policies on multiple platforms such as Cisco ASA, Cisco Firepower, Cisco Meraki, and AWS?
Cisco Defense OrchestratorCloud security managementCentralized policy management - Question #381
Which Cisco security solution determines if an endpoint has the latest OS updates and patches installed on the system?
Endpoint securitySecurity posture assessmentCompliance scanning - Question #382Content Security
Using Cisco Cognitive Threat Analytics, which platform automatically blocks risky sites, and test unknown sites for hidden advanced threats before allowing users to click them?
Cisco Web Security ApplianceWeb securityThreat intelligence - Question #383
What are two things to consider when using PAC files with the Cisco WSA? (Choose two.)
PAC filesCisco WSAWSA proxy configuration - Question #384Network Security
What is a description of microsegmentation?
microsegmentationzero-trustnetwork segmentationnetwork security - Question #385
Which Cisco WSA feature supports access control using URL categories?
Cisco WSAURL FilteringAccess Control - Question #386Network Security
Which technology limits communication between nodes on the same network segment to individual applications?
MicrosegmentationNetwork SecurityApplication Security - Question #387
Which IETF attribute is supported for the RADIUS CoA feature?
RADIUS CoAIETF attributes - Question #388
When a transparent authentication fails on the Web Security Appliance, which type of access does the end user get?
WSA authenticationTransparent authenticationAuthentication failure handlingUser access control - Question #389Cloud Security
What are two ways that Cisco Container Platform provides value to customers who utilize cloud service providers? (Choose two.)
Cisco Container PlatformKubernetes managementMulti-cloud deployment - Question #390
Which solution for remote workers enables protection, detection, and response on the endpoint against known and unknown threats?
Cisco AMP for EndpointsEndpoint securityMalware protection - Question #391
Which two actions does the Cisco Identity Services Engine posture module provide that ensures endpoint security? (Choose two.)
Cisco ISEISE postureEndpoint securityPatch management - Question #392Endpoint Protection and Detection
What is an advantage of the Cisco Umbrella roaming client?
Cisco UmbrellaRoaming clientDNS securityEndpoint protection - Question #393Visibility and Enforcement
Which Cisco platform provides an agentless solution to provide visibility across the network including encrypted traffic analytics to detect malware in encrypted traffic without th...
Cisco StealthwatchEncrypted Traffic AnalyticsNetwork VisibilityMalware Detection - Question #394
Which two Cisco ISE components must be configured for BYOD? (Choose two.)
Cisco ISEBYODISE components - Question #395
What are two ways a network administrator transparently identifies users using Active Directory on the Cisco WSA? (Choose two.)
Cisco WSAActive Directory IntegrationUser IdentificationCisco CDA - Question #396Secure Network Access, Visibility, and Enforcement
Which two parameters are used for device compliance checks? (Choose two.)
Device complianceEndpoint securityOS version checksRegistry checks - Question #397Network Security / Endpoint Security – Understanding Network Access Control (NAC) posture assessment workflows and how devices are evaluated and remediated before being granted network access (commonly aligned with CompTIA Security+, CCNA Security, or Cisco ISE certification objectives).
Drag and Drop Question Drag and drop the posture assessment flow actions from the left into a sequence on the right. Answer:
Network Access ControlPosture AssessmentNACZero Trust - Question #398
Which system performs compliance checks and remote wiping?
MDMRemote wipe - Question #399Content Security
An engineer is configuring Cisco Secure Email Gateway and needs to enable a separated email transfer flow from the Internet and from the LAN. Which deployment mode must be used to...
Cisco Secure Email GatewayDeployment modesEmail flow segregationNetwork interface configuration - Question #400Secure Network Access, Visibility, and Enforcement
A network engineer is tasked with configuring a Cisco ISE server to implement external authentication against Active Directory. What must be considered about the authentication req...
Cisco ISEActive Directory integrationLDAPMSCHAPv2 - Question #401Content Security
Which method of attack is used by a hacker to send malicious code through a web application to an unsuspecting user to request that the victim's web browser executes the code?
Cross-site scripting (XSS)Web application attacksClient-side vulnerabilitiesMalicious code execution