We at Crack4sure are committed to giving students who are preparing for the Cisco 350-701 Exam the most current and reliable questions . To help people study, we've made some of our Implementing and Operating Cisco Security Core Technologies (SCOR 350-701 v2.0) exam materials available for free to everyone. You can take the Free 350-701 Practice Test as many times as you want. The answers to the practice questions are given, and each answer is explained.
What is the purpose of a NetFlow version 9 template record?
What is the most common type of data exfiltration that organizations currently experience?
Which technology should be used to help prevent an attacker from stealing usernames and passwords of users within an organization?
Which two global commands must the network administrator implement to limit the attack surface of an internet-facing Cisco router? (Choose two.)
A network administrator needs to find out what assets currently exist on the network. Third-party systems need to be able to feed host data into Cisco Firepower. What must be configured to accomplish this?
Which benefit does DMVPN provide over GETVPN?
A network administrator is setting up Cisco FMC to send logs to Cisco Security Analytics and Logging (SaaS). The network administrator is anticipating a high volume of logging events from the firewalls and wants lo limit the strain on firewall resources. Which method must the administrator use to send these logs to Cisco Security Analytics and Logging?
An administrator configures a Cisco WSA to receive redirected traffic over ports 80 and 443. The organization requires that a network device with specific WSA integration capabilities be configured to send the traffic to the WSA to proxy the requests and increase visibility, while making this invisible to the users. What must be done on the Cisco WSA to support these requirements?
Based on the NIST 800-145 guide, which cloud architecture is provisioned for exclusive use by a specific group of consumers from different organizations and may be owned, managed, and operated by one or more of those organizations?
Which VPN technology supports a multivendor environment and secure traffic between sites?
Which technology enables integration between Cisco ISE and other platforms to gather and share
network and vulnerability data and SIEM and location information?
What are two things to consider when using PAC files with the Cisco WSA? (Choose two.)
Which Cisco security solution secures public, private, hybrid, and community clouds?
A network engineer must enable SSH and SCP on a Cisco IOS router. The engineer has already generated the encryption keys and enabled SCP services on the router. Which configuration action must be performed next?
Which baseline form of telemetry is recommended for network infrastructure devices?
Which IETF attribute is supported for the RADIUS CoA feature?
A Cisco AMP for Endpoints administrator configures a custom detection policy to add specific MD5 signatures The configuration is created in the simple detection policy section, but it does not work What is the reason for this failure?
Which feature is configured for managed devices in the device platform settings of the Firepower Management
Center?
When configuring ISAKMP for IKEv1 Phase1 on a Cisco IOS router, an administrator needs to input the
command crypto isakmp key cisco address 0.0.0.0. The administrator is not sure what the IP addressing in this command issued for. What would be the effect of changing the IP address from 0.0.0.0 to 1.2.3.4?
In which two ways does the Cisco Advanced Phishing Protection solution protect users? (Choose two.)
What is a capability of Cisco ASA Netflow?
What is a description of microsegmentation?
Which DevSecOps implementation process gives a weekly or daily update instead of monthly or quarterly in the applications?
A security engineer requires social-media websites to be blocked through Cisco Secure Firewall Threat Defense. Which configuration action must the engineer apply to meet the requirement?
Which type of protection encrypts RSA keys when they are exported and imported?
What are two ways that Cisco Container Platform provides value to customers who utilize cloud service providers? (Choose two.)
Which Cisco WSA feature supports access control using URL categories?
Which two methods must be used to add switches into the fabric so that administrators can control how switches are added into DCNM for private cloud management? (Choose two.)
Which two features of Cisco DNA Center are used in a Software Defined Network solution? (Choose two)
Which Splunk SOAR component automates multi-step security actions into a repeatable workflow?
Which algorithm provides encryption and authentication for data plane communication?
Which Cisco AMP feature allows an engineer to look back to trace past activities, such as file and process activity on an endpoint?
What is a difference between GRE over IPsec and IPsec with crypto map?
A network administrator is modifying a remote access VPN on an FTD managed by an FMC. The administrator wants to offload traffic to certain trusted domains. The administrator wants this traffic to go out of the client ' s local internet and send other internet-bound traffic over the VPN Which feature must the administrator configure?
After deploying a Cisco ESA on your network, you notice that some messages fail to reach their destinations.
Which task can you perform to determine where each message was lost?
Refer to the exhibit.
Refer to the exhibit. A Cisco ISE administrator adds a new switch to an 802.1X deployment and has difficulty with some endpoints gaining access.
Most PCs and IP phones can connect and authenticate using their machine certificate credentials. However printer and video cameras cannot base d on the interface configuration provided, what must be to get these devices on to the network using Cisco ISE for authentication and authorization while maintaining security controls?
Which Cisco security solution protects remote users against phishing attacks when they are not connected to
the VPN?
Which type of algorithm provides the highest level of protection against brute-force attacks?
An engineer must modify a policy to block specific addresses using Cisco Umbrella. The policy is created already and is actively u: of the default policy elements. What else must be done to accomplish this task?
Which two capabilities of Integration APIs are utilized with Cisco Catalyst Center? (Choose two.)
An email administrator is setting up a new Cisco ESA. The administrator wants to enable the blocking of greymail for the end user. Which feature must the administrator enable first?
What provides visibility and awareness into what is currently occurring on the network?
Refer to the exhibit. Which configuration item makes it possible to have the AAA session on the network?
When NetFlow is applied to an interface, which component creates the flow monitor cache that is used
to collect traffic based on the key and nonkey fields in the configured record?
Which policy does a Cisco Secure Web Appliance use to block or monitor URL requests based on the reputation score?
What is the difference between deceptive phishing and spear phishing?
Which security solution is used for posture assessment of the endpoints in a BYOD solution?
Which two preventive measures are used to control cross-site scripting? (Choose two)
What is a benefit of using Cisco CWS compared to an on-premises Cisco WSA?
A security engineer must protect endpoints when a file appears harmless during initial inspection but later shows malicious behavior. The solution must continuously observe process and file activity after execution and respond when a threat emerges. The infrastructure includes Cisco Secure Endpoint. Which feature must the engineer configure to meet the requirements?
An engineer is securing access to data served by a cloud-based application. The data must be protected from modification in transit, and its integrity must be validated. The following security measures have been implemented:
• Governance with role-based access control based on the principle of least privilege
• TLS 1.3 with signed certificates
• AES-256 with MD5
What must be configured to complete the secure implementation?
Which Talos reputation center allows you to track the reputation of IP addresses for email and web traffic?
Which metric is used by the monitoring agent to collect and output packet loss and jitter information?
Which portion of the network do EPP solutions solely focus on and EDR solutions do not?
What is a capability of a Trojan horse on a computer system?
Which direction do attackers encode data in DNS requests during exfiltration using DNS tunneling?
An engineer recently completed the system setup on a Cisco WSA Which URL information does the system send to SensorBase Network servers?
Which benefit does endpoint security provide the overall security posture of an organization?
Which Linux system call loads an eBPF program and manages eBPF maps within the kernel?
Which proxy mode must be used on Cisco WSA to redirect TCP traffic with WCCP?
In which cloud services model is the tenant responsible for virtual machine OS patching?
Which protocol provides the strongest throughput performance when using Cisco AnyConnect VPN?
Which configuration method provides the options to prevent physical and virtual endpoint devices that are in the same base EPG or uSeg from being able to communicate with each other with Vmware VDS or Microsoft vSwitch?
What is a benefit of flexible NetFlow records?
A facilities team is onboarding a fleet of badge readers and IP cameras through MAB authentication on Cisco Catalyst access switches integrated with Cisco ISE. After Cisco ISE profiles each endpoint, an authorization policy must dynamically move the device into a dedicated IoT VLAN that differs from the access VLAN statically defined on the port. The endpoints lack a supplicant and cannot automatically renew their DHCP addresses. The network engineer requires Cisco ISE to issue a Change of Authorization that forces each endpoint to re-establish connectivity and request a fresh DHCP lease under the new authorization policy. Which configuration action must be performed on Cisco ISE to meet the requirement?
Refer to the exhibit.
aaa new-model
aaa authentication dot1x default group ISE-SERVERS
aaa authorization network default group ISE-SERVERS
aaa accounting dot1x default start-stop group ISE-SERVERS
!
radius server RADIUS_SRV
address ipv4 172.16.10.12 auth-port 1812 acct-port 1813
key shared-secret C1sc0123
!
aaa group server radius ISE-SERVERS
server name RADIUS_SRV
radius-server vsa send authentication
radius-server vsa send accounting
radius-server attribute 6 on-for-login-auth
radius-server attribute 8 include-in-access-req
radius-server attribute 25 access-request include
ip device tracking
!
interface range GigabitEthernet1/0/1 - 48
switchport
switchport host
authentication priority dot1x mab
authentication order dot1x mab
A security engineer is integrating a new Cisco Catalyst access switch with Cisco ISE to enforce port-based network access control using 802.1X. The AAA RADIUS server group and access interfaces are configured on the Cisco Catalyst switch. Cisco ISE has authentication and authorization policies, the workstation supplicants are configured as expected, and connectivity between the switch and ISE is working. During testing, the workstations fail to trigger authentication sessions, and no RADIUS requests appear in the ISE logs or on the switch interfaces. Which two configuration commands must be added to the Cisco Catalyst switch? (Choose two.)
An engineer adds a custom detection policy to a Cisco AMP deployment and encounters issues with the
configuration. The simple detection mechanism is configured, but the dashboard indicates that the hash is not 64 characters and is non-zero. What is the issue?
Which public cloud provider supports the Cisco Next Generation Firewall Virtual?
Which standard is used to automate exchanging cyber threat information?
What are two ways a network administrator transparently identifies users using Active Directory on the Cisco WSA? (Choose two.)
An engineer is configuring IPsec VPN and needs an authentication protocol that is reliable and supports ACK
and sequence. Which protocol accomplishes this goal?
A Cisco FTD engineer is creating a new IKEv2 policy called s2s00123456789 for their organization to allow for additional protocols to terminate network devices with. They currently only have one policy established and need the new policy to be a backup in case some devices cannot support the stronger algorithms listed in the primary policy. What should be done in order to support this?
Which VMware platform does Cisco ACI integrate with to provide enhanced visibility, provide policy integration and deployment, and implement security policies with access lists?
Which two mechanisms are used to control phishing attacks? (Choose two)
How does DNS Tunneling exfiltrate data?
Which feature is used in a push model to allow for session identification, host reauthentication, and session termination?
What is the target in a phishing attack?
Email security has become a high-priority task for a security engineer at a large multi-national organization due to ongoing phishing campaigns. To help control this, the engineer has deployed an Incoming Content Filter with a URL reputation of (-10.00 to -6.00) on the Cisco Secure Email Gateway. Which action will the system perform to disable any links in messages that match the filter?
A company deploys an application that contains confidential data and has a hybrid hub-and-spoke topology. The hub resides in a public cloud environment, and the spoke resides on-premises. An engineer must secure the application to ensure that confidential data in transit between the hub-and-spoke servers is accessible only to authorized users. The engineer performs these configurations:
Segregation of duties
Role-based access control
Privileged access management
What must be implemented to protect the data in transit?
What is the difference between Cross-site Scripting and SQL Injection, attacks?
An engineer has been tasked with configuring a Cisco FTD to analyze protocol fields and detect anomalies in the traffic from industrial systems. What must be done to meet these requirements?
In which cloud services model is the customer responsible for scanning for and mitigation of application vulnerabilities?
A network engineer is configuring DMVPN and entered the crypto isakmp key cisc0380739941 address 0.0.0.0 command on hostA. The tunnel is not being established to hostB. What action is needed to authenticate the VPN?
Which RADIUS attribute can you use to filter MAB requests in an 802.1 x deployment?
An engineer is configuring Cisco WSA and needs to deploy it in transparent mode. Which configuration component must be used to accomplish this goal?
Which two endpoint measures are used to minimize the chances of falling victim to phishing and social
engineering attacks? (Choose two)
What is a benefit of using Cisco AVC (Application Visibility and Control) for application control?
Refer to the exhibit. The DHCP snooping database resides on router R1, and dynamic ARP inspection is configured only on switch SW2. Which ports must be configured as untrusted so that dynamic ARP inspection operates normally?
An organization uses Cisco FMC to centrally manage multiple Cisco FTD devices The default management port conflicts with other communications on the network and must be changed What must be done to ensure that all devices can communicate together?
What is a prerequisite when integrating a Cisco ISE server and an AD domain?
A financial services firm is concerned about employees inadvertently pasting sensitive customer account information into public generative AI websites. The security team needs to implement a solution that inspects outbound traffic and prevents the transmission of sensitive data to AI platforms. Which two configuration actions must the administrator perform on Cisco Secure Access to achieve the requirement? (Choose two.)
Drag and drop the cloud security assessment components from the left onto the definitions on the right.
An engineer configures new features within the Cisco Umbrella dashboard and wants to identify and proxy traffic that is categorized as risky domains and may contain safe and malicious content. Which action accomplishes these objectives?
Refer to the exhibit.
An engineer must configure a Cisco switch to perform PPP authentication via a TACACS server located at IP address 10.1.1.10. Authentication must fall back to the local database using the username LocalUser and password C1Sc0451069341l if the TACACS server is unreachable.
Drag and drop the commands from the left onto the corresponding configuration steps on the right.
Which cloud model is a collaborative effort where infrastructure is shared and jointly accessed by several organizations from a specific group?
Which two deployment modes does the Cisco ASA FirePower module support? (Choose two)
Which firewall mode does a Cisco Adaptive Security Appliance use to inspect Layer 2 traffic?
In which scenario is endpoint-based security the solution?
Which two devices support WCCP for traffic redirection? (Choose two.)
Which action configures the IEEE 802.1X Flexible Authentication feature to support Layer 3 authentication mechanisms?
Refer to the exhibit.
Consider that any feature of DNS requests, such as the length off the domain name
and the number of subdomains, can be used to construct models of expected behavior to which
observed values can be compared. Which type of malicious attack are these values associated with?
A security engineer is deploying an IPsec site-to-site VPN between headquarters and a remote plant, protected by Cisco Secure Firewall Threat Defense managed by Cisco Secure Firewall Management Center. The following configurations have already been completed:
Matching IKEv2 proposals, preshared keys, and IPsec transform sets
Access control rules permitting the traffic
Crypto maps applied to the outside interfaces
VPN traffic exempted from inspection
During a packet capture on the firewall, the engineer observes that the traffic is translated to the public IP address, preventing tunnel establishment. Which configuration action must be performed next?
A Cisco Firepower administrator needs to configure a rule to allow a new application that has never been seen
on the network. Which two actions should be selected to allow the traffic to pass without inspection? (Choose
two)
Under which two circumstances is a CoA issued? (Choose two)
Which attack is commonly associated with C and C++ programming languages?
What is provided by the Secure Hash Algorithm in a VPN?
Which two risks is a company vulnerable to if it does not have a well-established patching solution for
endpoints? (Choose two)
What are two workload security models? (Choose two.)
After a recent breach, an organization determined that phishing was used to gain initial access to the network before regaining persistence. The information gained from the phishing attack was a result of users visiting known malicious websites. What must be done in order to prevent this from happening in the future?
What are two security benefits of an MDM deployment? (Choose two.)
A security engineer must configure a Splunk Universal Forwarder to send network traffic logs from Cisco Catalyst switches to a Splunk indexer cluster. Strict compliance requirements require all network traffic logs to be ingested into Splunk as an audit trail. The environment includes thousands of forwarders, and the data must be distributed across all indexers. Which two configuration actions must be performed? (Choose two.)
An engineer is configuring Cisco Umbrella and has an identity that references two different policies. Which action ensures that the policy that the identity must use takes precedence over the second one?
An engineer is implementing NTP authentication within their network and has configured both the client and server devices with the command ntp authentication-key 1 md5 Cisc392368270. The server at 1.1.1.1 is attempting to authenticate to the client at 1.1.1.2, however it is unable to do so. Which command is required to enable the client to accept the server’s authentication key?
What is a functional difference between Cisco AMP for Endpoints and Cisco Umbrella Roaming Client?
Which role is a default guest type in Cisco ISE?
Refer to the exhibit. What does this Python script accomplish?
What is the purpose of joining Cisco WSAs to an appliance group?
Refer to the exhibit.
A network administrator configured a site-to-site VPN tunnel between two Cisco IOS routers, and hosts are unable to communicate between two sites of VPN. The network administrator runs the debug crypto isakmp sa command to track VPN status. What is the problem according to this command output?
An engineer is implementing Cisco CES in an existing Microsoft Office 365 environment and must route inbound email to Cisco CE.. record must be modified to accomplish this task?
What provides total management for mobile and PC including managing inventory and device tracking, remote view, and live troubleshooting using the included native remote desktop support?
Which two activities are performed using Cisco Catalyst Center? (Choose two.)
What is the recommendation in a zero-trust model before granting access to corporate applications and
resources?
Why should organizations migrate to an MFA strategy for authentication?
Drag and drop the descriptions from the left onto the encryption algorithms on the right.
What is a benefit of using Cisco FMC over Cisco ASDM?
Which compliance status is shown when a configured posture policy requirement is not met?
Which security solution uses NetFlow to provide visibility across the network, data center, branch
offices, and cloud?
A network engineer must distribute an operating system image to a network device and activate the image on that device by using the Cisco Catalyst Center API. Which two API requests perform the required operations? (Choose two.)
Which two fields are defined in the NetFlow flow? (Choose two)
Which mitigation strategy should be used to protect against session hijacking attacks in a cloud environment?
A network administrator is configuring a rule in an access control policy to block certain URLs and selects the “Chat and Instant Messaging” category. Which reputation score should be selected to accomplish this goal?
A network security engineer must export packet captures from the Cisco FMC web browser while troubleshooting an issue. When navigating to the address https:// < FMC IP > /capure/CAPI/pcap/test.pcap, an error 403: Forbidden is given instead of the PCAP file. Which action must the engineer take to resolve this issue?
An administrator is adding a new switch onto the network and has configured AAA for network access control. When testing the configuration, the RADIUS authenticates to Cisco ISE but is being rejected. Why is the ip radius source-interface command needed for this configuration?
Which Cisco security solution integrates with cloud applications like Dropbox and Office 365 while protecting data from being exfiltrated?
Which two application layer preprocessors are used by Firepower Next Generation Intrusion Prevention
System? (Choose two)
Which two types of connectors are used to generate telemetry data from IPFIX records in a Cisco Secure Workload implementation? (Choose two.)
Refer to the exhibit.
During the rollout of a new site-to-site VPN between a headquarters Cisco Secure Firewall Threat Defense device and a partner firewall, the tunnel never completes IKEv1 Phase 1 and remains in the MM_WAIT_MSG_6 state. Reachability between the firewalls over the Internet is verified, ISAKMP UDP port 500 is permitted end-to-end, and the IKE Phase 1 policy parameters—including encryption, hashing, DH group, and lifetime—match exactly on both ends. Which configuration action must be performed to resolve the issue?
Which Cisco security solution provides patch management in the cloud?
When using Cisco AMP for Networks which feature copies a file to the Cisco AMP cloud for analysis?
What does Cisco AMP for Endpoints use to help an organization detect different families of malware?
What are two features of NetFlow flow monitoring? (Choose two)
Which statement about the configuration of Cisco ASA NetFlow v9 Secure Event Logging is true?
Refer to the exhibit.
What will occur when this device tries to connect to the port?
Which solution detects threats across a private network, public clouds, and encrypted traffic?
For which type of attack is multifactor authentication an effective deterrent?
How is Cisco Umbrella configured to log only security events?
Which encryption algorithm provides highly secure VPN communications?
A group of hospitals is collaborating to transition from an on-premises infrastructure to a cloud solution. The solution must be cost-effective, flexible, scalable, and support large volumes of data traffic. Each hospital has its own rules and policies that require direct control over its processes. Sensitive data, including patient records, must remain on-premises. Which type of cloud must be used?
Which type of encryption uses a public key and private key?
An organization is trying to implement micro-segmentation on the network and wants to be able to gain visibility on the applications within the network. The solution must be able to maintain and force compliance. Which product should be used to meet these requirements?
What are two DDoS attack categories? (Choose two)
Which form of attack is launched using botnets?
Why is it important for the organization to have an endpoint patching strategy?
A security test performed on one of the applications shows that user input is not validated. Which security vulnerability is the application more susceptible to because of this lack of validation?
Refer to the exhibit.
What does the number 15 represent in this configuration?
An organization recently installed a Cisco WSA and would like to take advantage of the AVC engine to allow the organization to create a policy to control application specific activity. After enabling the AVC engine, what must be done to implement this?
Which functions of an SDN architecture require southbound APIs to enable communication?
A hacker initiated a social engineering attack and stole username and passwords of some users within a company. Which product should be used as a solution to this problem?
Why is it important to implement MFA inside of an organization?
Which security product enables administrators to deploy Kubernetes clusters in air-gapped sites without needing Internet access?
What is a description of microsegmentation?
What is a characteristic of Dynamic ARP Inspection?
Which solution for remote workers enables protection, detection, and response on the endpoint against known and unknown threats?
What is a feature of NetFlow Secure Event Logging?
A network engineer must create an access control list on a Cisco Adaptive Security Appliance firewall. The access control list must permit HTTP traffic to the internet from the organization ' s inside network 192.168.1.0/24. Which IOS command must oe used to create the access control list?
Which capability allows an administrator to configure forensics rules in Cisco Secure Workload?
What is the difference between deceptive phishing and spear phishing?
Which service allows a user to export application usage and performance statistics with Cisco Application Visibility and Control?
What can be integrated with Cisco Threat Intelligence Director to provide information about security threats,
which allows the SOC to proactively automate responses to those threats?
What must be used to share data between multiple security products?
Which information is required when adding a device to Firepower Management Center?
Which Talos reputation center allows for tracking the reputation of IP addresses for email and web traffic?
What do tools like Jenkins, Octopus Deploy, and Azure DevOps provide in terms of application and
infrastructure automation?
In which form of attack is alternate encoding, such as hexadecimal representation, most often observed?
Which ID store requires that a shadow user be created on Cisco ISE for the admin login to work?
An engineer notices traffic interruption on the network. Upon further investigation, it is learned that broadcast
packets have been flooding the network. What must be configured, based on a predefined threshold, to
address this issue?
An organization wants to use Cisco FTD or Cisco ASA devices. Specific URLs must be blocked from being
accessed via the firewall which requires that the administrator input the bad URL categories that the
organization wants blocked into the access policy. Which solution should be used to meet this requirement?
An engineer is configuring Dropbox integration with Cisco Cloudlock. Which action must be taken before granting API access in the Dropbox admin console?
A logistics company issues corporate laptops that must automatically establish a Cisco Secure Client VPN tunnel whenever users are outside the office and connected to an untrusted external network. Cisco Secure Firewall Threat Defense is the VPN headend and is already configured with remote-access profiles, address pools, and a PKI that distributes both machine and user certificates to endpoints. Management requires the tunnel to come up unattended before any user signs in to a laptop. Device-based authentication must be used, and the client must distinguish the corporate LAN from outside networks. The VPN must be connected when a user is outside the corporate network. Which configuration action must be performed to meet the requirements?
An organization has noticed an increase in malicious content downloads and wants to use Cisco Umbrella to prevent this activity for suspicious domains while allowing normal web traffic. Which action will accomplish this task?
Refer to the exhibit.
A site-to-site IKEv2 VPN between two Cisco Secure Firewall Threat Defense devices at a healthcare organization completes IKE Phase 1 successfully but fails during CREATE_CHILD_SA. The engineer captures the debug output from the initiating Cisco Secure Firewall. Which action must be performed to resolve the issue?
Which solution is more secure than the traditional use of a username and password and encompasses at least two of the methods of authentication?
A network engineer is tasked with configuring a Cisco ISE server to implement external authentication against Active Directory. What must be considered about the authentication requirements? (Choose two.)
An administrator is configuring a DHCP server to better secure their environment. They need to be able to ratelimit the traffic and ensure that legitimate requests are not dropped. How would this be accomplished?
Refer to the exhibit. Traffic is not passing through IPsec site-to-site VPN on the Secure Firewall Threat Defense appliance. What is causing this issue?
How does the Cisco WSA enforce bandwidth restrictions for web applications?
Which type of DNS abuse exchanges data between two computers even when there is no direct connection?
Refer to the exhibit.
An engineer configures an IPsec VPN between two Cisco Secure Firewall Threat Defense devices named FTD1 and FTD2. However, the hosts behind FTD1 and FTD2 cannot communicate with each other. The engineer runs a debug command to troubleshoot the issue. What must be configured to resolve the issue?
Refer to the exhibit.
Which command was used to generate this output and to show which ports are
authenticating with dot1x or mab?
An MDM provides which two advantages to an organization with regards to device management? (Choose two)
Refer to the exhibit. Which task is the Python script performing by using the Cisco Umbrella API?
A network engineer has entered the snmp-server user andy myv3 auth sha cisco priv aes 256
cisc0380739941 command and needs to send SNMP information to a host at 10.255.254.1. Which command achieves this goal?
Which action configures the IEEE 802.1X Flexible Authentication feature lo support Layer 3 authentication mechanisms?
Which two statements about a Cisco WSA configured in Transparent mode are true? (Choose two)
A mall provides security services to customers with a shared appliance. The mall wants separation of
management on the shared appliance. Which ASA deployment mode meets these needs?
Drag and drop the features of Cisco ASA with Firepower from the left onto the benefits on the right.
Which threat intelligence standard contains malware hashes?
A customer has various external HTTP resources available including Intranet. Extranet, and Internet, with a proxy configuration running in explicit mode Which method allows the client desktop browsers to be configured to select when to connect direct or when to use the proxy?
What is the purpose of a denial-of-service attack?
An engineer needs to configure an access control policy rule to always send traffic for inspection without
using the default action. Which action should be configured for this rule?
A network engineer entered the snmp-server user asmith myv7 auth sha cisco priv aes 256
cisc0xxxxxxxxx command and needs to send SNMP information to a host at 10.255.255.1. Which
command achieves this goal?
The main function of northbound APIs in the SDN architecture is to enable communication between which two areas of a network?
An engineer is configuring cloud logging on Cisco ASA and needs events to compress. Which component must be configured to accomplish this goal?
Which Cisco IOS XE command rejects packets with a source IP address that fails a reverse-path-forwarding prefix check on the ingress interface?
A Cisco Secure Email Gateway network administrator has been tasked to use a newly installed service to help create policy based on the reputation verdict. During testing, it is discovered that the Secure Email Gateway is not dropping files that have an undetermined verdict. What is causing this issue?
Refer to the exhibit.
How does Cisco Umbrella manage traffic that is directed toward risky domains?
An organization is receiving SPAM emails from a known malicious domain. What must be configured in order to
prevent the session during the initial TCP communication?
Which functionality does Incident Manager provide in Cisco XDR?
Refer to the exhibit.
What will happen when this Python script is run?
Why would a user choose an on-premises ESA versus the CES solution?
Drag and drop the deployment models from the left onto the explanations on the right.
An organization wants to implement a cloud-delivered and SaaS-based solution to provide visibility and threat detection across the AWS network. The solution must be deployed without software agents and rely on AWS VPC flow logs instead. Which solution meets these requirements?
When wired 802.1X authentication is implemented, which two components are required? (Choose two)
An engineer needs to detect and quarantine a file named abc424400664 zip based on the MD5 signature of the file using the Outbreak Control list feature within Cisco Advanced Malware Protection (AMP) for Endpoints The configured detection method must work on files of unknown disposition Which Outbreak Control list must be configured to provide this?
What is the primary benefit of deploying an ESA in hybrid mode?
A company is experiencing exfiltration of credit card numbers that are not being stored on-premise. The
company needs to be able to protect sensitive data throughout the full environment. Which tool should be used
to accomplish this goal?
When a Cisco WSA checks a web request, what occurs if it is unable to match a user-defined policy?
Which API technology with SDN architecture is used to communicate with a controller and network devices such as routers and switches?
What are two benefits of using an MDM solution? (Choose two.)
Which technology reduces data loss by identifying sensitive information stored in public computing
environments?
Which command enables 802.1X globally on a Cisco switch?
Which option is the main function of Cisco Firepower impact flags?
Refer to the exhibit.
What will happen when the Python script is executed?
A network administrator is configuring a switch to use Cisco ISE for 802.1X. An endpoint is failing
authentication and is unable to access the network. Where should the administrator begin troubleshooting to verify the authentication details?
An organization is selecting a cloud architecture and does not want to be responsible for patch management of the operating systems. Why should the organization select either Platform as a Service or Infrastructure as a Service for this environment?
What are two Trojan malware attacks? (Choose two)
Which Cisco ISE feature helps to detect missing patches and helps with remediation?
What Cisco command shows you the status of an 802.1X connection on interface gi0/1?
Which solution allows an administrator to provision, monitor, and secure mobile devices on Windows and Mac computers from a centralized dashboard?
Which threat involves software being used to gain unauthorized access to a computer system?
Refer to the exhibit. An engineer must enable secure SSH protocols and enters this configuration. What are two results of running this set of commands on a Cisco router? (Choose two.)
Email security has become a high priority task for a security engineer at a large multi-national organization due to ongoing phishing campaigns. To help control this, the engineer has deployed an Incoming Content Filter with a URL reputation of (-10 00 to -6 00) on the Cisco ESA Which action will the system perform to disable any links in messages that match the filter?
Which protocol does the BYOD component in Cisco ISE use to obtain a unique device certificate from an internal CA?
In which two ways does Easy Connect help control network access when used with Cisco TrustSec? (Choose two)
Which API method and required attribute are used to add a device into Cisco DNA Center with the native API?
3 Months Free Update
3 Months Free Update
3 Months Free Update