350-701 Training & Certification Get Latest CCNP Security Updated on Jan 06, 2022
Certification Training for 350-701 Exam Dumps Test Engine
Understanding functional and technical aspects of Implementing and Operating Cisco Security Core Technologies (SCOR 350-701) Content Security
The following will be discussed in CISCO 350-701 dumps:
- Implement traffic redirection and capture methods
- Configure and verify web security controls on Cisco Umbrella (identities, URL content settings, destination lists, and reporting)
- Configure and verify email security features such as SPAM filtering, antimalware filtering, DLP, block listing, and email encryption
- Describe web proxy identity and authentication including transparent user identification
- Configure and verify secure internet gateway and web security features such as block listing, URL filtering, malware scanning, URL categorization, web application filtering, and TLS decryption
- Configure and verify web and email security deployment methods to protect onpremises and remote users (inbound and outbound controls and policy management)
- Compare the components, capabilities, and benefits of local and cloud-based email and web solutions (ESA, CES, WSA)
- Describe the components, capabilities, and benefits of Cisco Umbrella
NEW QUESTION 39
Which solution combines Cisco IOS and IOS XE components to enable administrators to recognize applications, collect and send network metrics to Cisco Prime and other third-party management tools, and prioritize application traffic?
- A. Cisco Security Intelligence
- B. Cisco DNA Center
- C. Cisco Application Visibility and Control
- D. Cisco Model Driven Telemetry
Answer: C
NEW QUESTION 40
Which algorithm provides encryption and authentication for data plane communication?
- A. SHA-96
- B. SHA-384
- C. AES-GCM
- D. AES-256
Answer: C
NEW QUESTION 41
Drag and drop the threats from the left onto examples of that threat on the right
Answer:
Explanation:
NEW QUESTION 42
An engineer wants to generate NetFlow records on traffic traversing the Cisco ASA.
Which Cisco ASA command must be used?
- A. flow-export destination inside 1.1.1.1 2055
- B. flow exporter <name>
- C. ip flow monitor<name> input
- D. ip flow-export destination 1.1.1.1 2055
Answer: A
NEW QUESTION 43
Drag and drop the Firepower Next Generation Intrustion Prevention System detectors from the left onto the correct definitions on the right.
Answer:
Explanation:
NEW QUESTION 44
Drag and drop the common security threats from left onto the definitions on the right.
Answer:
Explanation:
NEW QUESTION 45
When choosing an algorithm to us what should be considered about Diffie Hellman and RSA for key establishment?
- A. RSA is an asymmetric key establishment algorithm Intended to output symmetric keys.
- B. RSA is a symmetric key establishment algorithm intended to output asymmetric keys.
- C. DH is a symmetric key establishment algorithm Intended to output asymmetric keys
- D. DH is on asymmetric key establishment algorithm intended to output symmetric keys.
Answer: D
NEW QUESTION 46
Which attack is commonly associated with C and C++ programming languages?
- A. buffer overflow
- B. water holing
- C. cross-site scripting
- D. DDoS
Answer: A
NEW QUESTION 47
An engineer used a posture check on a Microsoft Windows endpoint and discovered that the MS17-010 patch was not installed, which left the endpoint vulnerable to WannaCry ransomware.
Which two solutions mitigate the risk of this ransomware infection? (Choose two.)
- A. Set up a well-defined endpoint patching strategy to ensure that endpoints have critical vulnerabilities patched in a timely fashion.
- B. Configure a posture policy in Cisco Identity Services Engine to install the MS17-010 patch before allowing access on the network.
- C. Configure endpoint firewall policies to stop the exploit traffic from being allowed to run and replicate throughout the network.
- D. Set up a profiling policy in Cisco Identity Services Engine to check an endpoint patch level before allowing access on the network.
- E. Configure a posture policy in Cisco Identity Services Engine to check that an endpoint patch level is met before allowing access on the network.
Answer: B,E
NEW QUESTION 48
Which policy is used to capture host information on the Cisco Firepower Next Generation Intrusion Prevention System?
- A. Intrusion
- B. Correlation
- C. Access Control
- D. Network Discovery
Answer: D
Explanation:
Explanation The Firepower System uses network discovery and identity policies to collect host, application, and user data for traffic on your network. You can use certain types of discovery and identity data to build a comprehensive map of your network assets, perform forensic analysis, behavioral profiling, access control, and mitigate and respond to the vulnerabilities and exploits to which your organization is susceptible. You can configure your network discovery policy to perform host and application detection. Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-configguide-v64/introduction_to_network_discovery_and_identity.html The Firepower System uses network discovery and identity policies to collect host, application, and user data for traffic on your network. You can use certain types of discovery and identity data to build a comprehensive map of your network assets, perform forensic analysis, behavioral profiling, access control, and mitigate and respond to the vulnerabilities and exploits to which your organization is susceptible.
You can configure your network discovery policy to perform host and application detection.
Explanation The Firepower System uses network discovery and identity policies to collect host, application, and user data for traffic on your network. You can use certain types of discovery and identity data to build a comprehensive map of your network assets, perform forensic analysis, behavioral profiling, access control, and mitigate and respond to the vulnerabilities and exploits to which your organization is susceptible. You can configure your network discovery policy to perform host and application detection. Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-configguide-v64/introduction_to_network_discovery_and_identity.html
NEW QUESTION 49
Refer to the exhibit.
Which command was used to generate this output and to show which ports are authenticating with dot1x or mab?
- A. show authentication method
- B. show dot1x all
- C. show authentication sessions
- D. show authentication registrations
Answer: B
NEW QUESTION 50
Which technology reduces data loss by identifying sensitive information stored in public computing environments?
- A. Cisco HyperFlex
- B. Cisco SDA
- C. Cisco Firepower
- D. Cisco Cloudlock
Answer: D
NEW QUESTION 51
Where are individual sites specified to be blacklisted in Cisco Umbrella?
- A. application settings
- B. security settings
- C. content categories
- D. destination lists
Answer: D
Explanation:
Explanation A destination list is a list of internet destinations that can be blocked or allowed based on the administrative preferences for the policies applied to the identities within your organization. A destination is an IP address (IPv4), URL, or fully qualified domain name. You can add a destination list to Umbrella at any time; however, a destination list does not come into use until it is added to a policy. Reference: https://docs.umbrella.com/deployment-umbrella/docs/working-with-destination-lists A destination list is a list of internet destinations that can be blocked or allowed based on the administrative preferences for the policies applied to the identities within your organization. A destination is an IP address (IPv4), URL, or fully qualified domain name. You can add a destination list to Umbrella at any time; however, a destination list does not come into use until it is added to a policy.
Explanation A destination list is a list of internet destinations that can be blocked or allowed based on the administrative preferences for the policies applied to the identities within your organization. A destination is an IP address (IPv4), URL, or fully qualified domain name. You can add a destination list to Umbrella at any time; however, a destination list does not come into use until it is added to a policy. Reference: https://docs.umbrella.com/deployment-umbrella/docs/working-with-destination-lists
NEW QUESTION 52
What is the purpose of the certificate signing request when adding a new certificate for a server?
- A. It is the password for the certificate that is needed to install it with.
- B. It is the certificate that will be loaded onto the server
- C. It provides the server information so a certificate can be created and signed
- D. It provides the certificate client information so the server can authenticate against it when installing
Answer: C
Explanation:
Explanation
https://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_man_cert.html
NEW QUESTION 53
What are the two types of managed Intercloud Fabric deployment models? (Choose two.)
- A. Enterprise managed
- B. Service Provider managed
- C. User managed
- D. Hybrid managed
- E. Public managed
Answer: B,D
Explanation:
Reference:
NEW QUESTION 54
Which two probes are configured to gather attributes of connected endpoints using Cisco Identity Services Engine?
(Choose two.)
- A. RADIUS
- B. TACACS+
- C. DHCP
- D. SMTP
- E. sFlow
Answer: A,C
NEW QUESTION 55
Which VPN technology can support a multivendor environment and secure traffic between sites?
- A. DMVPN
- B. GET VPN
- C. FlexVPN
- D. SSL VPN
Answer: C
Explanation:
Explanation/Reference: https://www.cisco.com/c/en/us/products/collateral/routers/asr-1000-series-aggregation-services- routers/data_sheet_c78-704277.html
NEW QUESTION 56
Which group within Cisco writes and publishes a weekly newsletter to help cybersecurity professionals remain aware of the ongoing and most prevalent threats?
- A. DEVNET
- B. CSIRT
- C. PSIRT
- D. Talos
Answer: D
Explanation:
Explanation
https://talosintelligence.com/
NEW QUESTION 57
Why is it important to have logical security controls on endpoints even though the users are trained to spot security threats and the network devices already help prevent them?
- A. to prevent theft of the endpoints
- B. to expose the endpoint to more threats
- C. because defense-in-depth stops at the network
- D. because human error or insider threats will still exist
Answer: D
NEW QUESTION 58
An engineer configured a new network identity in Cisco Umbrella but must verify that traffic is being routed through the Cisco Umbrella network. Which action tests the routing?
- A. Enable the Intelligent Proxy to validate that traffic is being routed correctly.
- B. Ensure that the client computers are pointing to the on-premises DNS servers.
- C. Browse
to http://welcome.umbrella.com/ to validate that the new identity is working - D. Add the public IP address that the client computers are behind to a Core Identity
Answer: C
NEW QUESTION 59
After a recent breach, an organization determined that phishing was used to gain initial access to the network before regaining persistence. The information gained from the phishing attack was a result of users visiting known malicious websites. What must be done in order to prevent this from happening in the future?
- A. Modify an access policy
- B. Modify web proxy settings
- C. Modify outbound malware scanning policies
- D. Modify identification profiles
Answer: A
Explanation:
URL conditions in access control rules allow you to limit the websites that users on your network can access. This feature is called URL filtering. There are two ways you can use access control to specify URLs you want to block (or, conversely, allow): - With any license, you can manually specify individual URLs, groups of URLs, and URL lists and feeds to achieve granular, custom control over web traffic. - With a URL Filtering license, you can also control access to websites based on the URL's general classification, or category, and risk level, or reputation. The system displays this category and reputation data in connection logs, intrusion events, and application details. Using category and reputation data also simplifies policy creation and administration. It grants you assurance that the system will control web traffic as expected. Finally, because Cisco's threat intelligence is continually updated with new URLs, as well as new categories and risks for existing URLs, you can ensure that the system uses up-to-date information to filter requested URLs. Malicious sites that represent security threats such as malware, spam, botnets, and phishing may appear and disappear faster than you can update and deploy new policies. Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guidev60/Access_Control_Rules__URL_Filtering.html
- With any license, you can manually specify individual URLs, groups of URLs, and URL lists and feeds to achieve granular, custom control over web traffic.
- With a URL Filtering license, you can also control access to websites based on the URL's general classification, or category, and risk level, or reputation. The system displays this category and reputation data in connection logs, intrusion events, and application details.
Using category and reputation data also simplifies policy creation and administration. It grants you assurance that the system will control web traffic as expected. Finally, because Cisco's threat intelligence is continually updated with new URLs, as well as new categories and risks for existing URLs, you can ensure that the system uses up-to-date information to filter requested URLs. Malicious sites that represent security threats such as malware, spam, botnets, and phishing may appear and disappear faster than you can update and deploy new policies.
URL conditions in access control rules allow you to limit the websites that users on your network can access. This feature is called URL filtering. There are two ways you can use access control to specify URLs you want to block (or, conversely, allow): - With any license, you can manually specify individual URLs, groups of URLs, and URL lists and feeds to achieve granular, custom control over web traffic. - With a URL Filtering license, you can also control access to websites based on the URL's general classification, or category, and risk level, or reputation. The system displays this category and reputation data in connection logs, intrusion events, and application details. Using category and reputation data also simplifies policy creation and administration. It grants you assurance that the system will control web traffic as expected. Finally, because Cisco's threat intelligence is continually updated with new URLs, as well as new categories and risks for existing URLs, you can ensure that the system uses up-to-date information to filter requested URLs. Malicious sites that represent security threats such as malware, spam, botnets, and phishing may appear and disappear faster than you can update and deploy new policies. Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guidev60/Access_Control_Rules__URL_Filtering.html
NEW QUESTION 60
Refer to the exhibit A network engineer is testing NTP authentication and realizes that any device synchronizes time with this router and that NTP authentication is not enforced What is the cause of this issue?
- A. The router was not rebooted after the NTP configuration updated
- B. The hashing algorithm that was used was MD5 which is unsupported.
- C. The key was configured in plain text.
- D. NTP authentication is not enabled.
Answer: D
NEW QUESTION 61
The Cisco ASA must support TLS proxy for encrypted Cisco Unified Communications traffic.
Where must the ASA be added on the Cisco UC Manager platform?
- A. Certificate Trust List
- B. Endpoint Trust List
- C. Enterprise Proxy Service
- D. Secured Collaboration Proxy
Answer: A
Explanation:
Explanation/Reference: https://www.cisco.com/c/en/us/td/docs/security/asa/special/unified-communications/guide/unified- comm/unified-comm-tlsproxy.html
NEW QUESTION 62
......
Step by Step Guide to Prepare for 350-701 Exam: https://www.testkingpdf.com/350-701-testking-pdf-torrent.html
CCNP Security 350-701 Real Exam Questions and Answers FREE Updated: https://drive.google.com/open?id=1ihPcZ4BXAMaCu3mR90K7OspkccHnZAuA

