[2026] 300-740 Exam Dumps, Test Engine Practice Test Questions [Q52-Q75]

Share

[2026] 300-740 Exam Dumps, Test Engine Practice Test Questions

Pass 300-740 exam [Sep 06, 2026] Updated 201 Questions

NEW QUESTION # 52
Cisco Secure Workload is used for:

  • A. Enforcing security policies within application workloads
  • B. Reducing application functionality
  • C. Encrypting email communications
  • D. Increasing the workload on servers

Answer: A


NEW QUESTION # 53
In the event of a security breach, it's crucial to _________ the incident to the relevant stakeholders and authorities.

  • A. report
  • B. delete
  • C. ignore
  • D. fabricate

Answer: A


NEW QUESTION # 54
Endpoint posture policies help ensure that:

  • A. Network performance is degraded
  • B. Devices meet security standards before accessing network resources
  • C. Users can bypass security measures
  • D. Devices have unlimited access to resources

Answer: B


NEW QUESTION # 55

Refer to the exhibit. An engineer must create a policy in Cisco Secure Firewall Management Center to prevent restricted users from being able to browse any business or mobile phone shopping websites. The indicated policy was applied; however, the restricted users still can browse on the mobile phone shopping websites during business hours. What should be done to meet the requirement?

  • A. Set Dest Networks to Business Mobile Phones Shopping.
  • B. Set Time Range for rule 4 of Access Controlled Groups to All.
  • C. Set Dest Zones to Business Mobile Phones Shopping.
  • D. Move rule 4 Access Controlled Groups to the top.

Answer: D

Explanation:
In Cisco Secure Firewall Management Center (FMC), access control policies are processed top-down- meaning the first matching rule is applied, and the remaining are ignored. Based on the exhibit, Rule 4 (Access Controlled Groups) is likely being shadowed by a broader rule above it that permits web traffic. To ensure restricted users are denied access to mobile phone shopping categories, Rule 4 must be moved to the top of the rule hierarchy.
Cisco SCAZT (Section 5: Visibility and Assurance, Pages 94-97) describes best practices for rule ordering and inspection logic. Moving the specific block rule (Rule 4) higher ensures it's enforced before general allow rules are evaluated.
Reference: Designing and Implementing Secure Cloud Access for Users and Endpoints (SCAZT), Section 5, Pages 94-97


NEW QUESTION # 56
Multifactor authentication typically requires something you know, something you have, and something you _________.

  • A. forget
  • B. delete
  • C. encrypt
  • D. are

Answer: D


NEW QUESTION # 57
Cisco Secure Cloud Insights is designed to:

  • A. Ignore cloud resources for simplified management
  • B. Reduce the effectiveness of cloud security posture management
  • C. Focus only on physical data center assets
  • D. Provide visibility into cloud assets and their relationships for security purposes

Answer: D


NEW QUESTION # 58
What is a primary function of the Cisco Extended Detection and Response (XDR) solution?

  • A. To decrease network performance
  • B. To provide comprehensive threat detection, investigation, and response across multiple security layers
  • C. To simplify hacker access
  • D. To limit visibility into network traffic

Answer: B


NEW QUESTION # 59
The importance of VPN policies for remote users is to ensure:

  • A. That remote users have a slower connection to prioritize office users
  • B. Remote users cannot access sensitive corporate resources
  • C. Secure and encrypted access to corporate resources from any location
  • D. The use of public Wi-Fi networks for corporate access

Answer: C


NEW QUESTION # 60
An engineer configures trusted endpoints with Active Directory with Device Health to determine if an endpoint complies with the policy posture. After a week, an alert is received by one user, reporting problems accessing an application. When the engineer verifies the authentication report, this error is found:
"Endpoint is not trusted because Cisco Secure Endpoint check failed, Check user's endpoint in Cisco Secure Endpoint." Which action must the engineer take to permit access to the application again?

  • A. Verify the Cisco Secure Endpoint admin panel, check the Inbox tab, verify the status of the machine, and after a complete process of analysis, mark the computer as Resolved to permit the user to authenticate again.
  • B. Verify the Duo admin panel, check the EndPoints tab, verify the status of the machine, and after a complete process of analysis, mark the computer as Resolved to permit the user to authenticate again.
  • C. Verify the Trusted Endpoints policy to verify the status of the machine, and after a complete process of analysis, permit the machine to have access to the application.
  • D. Verify the Cisco Secure Endpoint admin panel and approve the access to the user on the Management tab after a complete virus check of the user's laptop.

Answer: A

Explanation:
Cisco Secure Endpoint (formerly AMP for Endpoints) includes an "Inbox" tab where detected threats and flagged endpoints are listed. When Duo Trusted Endpoints integration is in place, an endpoint may be denied access if it fails posture checks. The correct workflow includes reviewing the machine's status in Cisco Secure Endpoint and marking the incident as "Resolved" in the Inbox tab to restore authentication.
This process is described in SCAZT Section 2 (User and Device Security, Pages 44-46) for enforcing endpoint trust with Secure Endpoint and Duo Trusted Endpoints integration.
Reference: Designing and Implementing Secure Cloud Access for Users and Endpoints (SCAZT), Section 2, Pages 44-46


NEW QUESTION # 61
In the context of cloud security, which of the following is a recommended mitigation strategy against account takeover attacks?

  • A. Use of simple passwords
  • B. Sharing credentials among team members for convenience
  • C. Implementation of multi-factor authentication (MFA)
  • D. Regularly decreasing permissions and access rights

Answer: C


NEW QUESTION # 62

Refer to the exhibit. An engineer must enable access to Salesforce using Cisco Umbrella and Cisco Cloudlock. These actions were performed:
* From Salesforce, add the Cloudlock IP address to the allow list
* From Cloudlock, authorize Salesforce
However, Salesforce access via Cloudlock is still unauthorized. What should be done to meet the requirements?

  • A. From the Salesforce admin page, grant network access to Cloudlock
  • B. From the Cloudlock dashboard, grant API access to Salesforce.
  • C. From the Salesforce admin page, grant API access to Cloudlock.
  • D. From the Cloudlock dashboard, grant network access to Salesforce.

Answer: A

Explanation:
When integrating Cisco Cloudlock with SaaS platforms like Salesforce, two core authorizations are required:
network access and API authorization. In the scenario, Cloudlock has been authorized in Salesforce, and its IP has been allow-listed. However, if access is still denied, the most likely cause is that Salesforce has not been configured to accept traffic from Cloudlock's IP range - a process handled from the Salesforce admin panel.
To resolve the issue, network access must be explicitly granted to Cloudlock from within Salesforce. This ensures that Salesforce accepts requests initiated by Cloudlock for monitoring and enforcement.
Reference: Designing and Implementing Secure Cloud Access for Users and Endpoints (SCAZT), Section 4:
Application and Data Security, Pages 85-87.
Also supported by Cisco Cloudlock for Salesforce Deployment Guide.


NEW QUESTION # 63


Refer to the exhibit. An engineer is investigating an issue by using Cisco Secure Cloud Analytics. The engineer confirms that the connections are unauthorized and informs the incident management team. Which two actions must be taken next? (Choose two.)

  • A. Reinstall the host from a recent backup.
  • B. Create a firewall rule that has a source of Any, a destination of linux-gcp-east-4c, and a protocol of SSH.
  • C. Quarantine the host
  • D. Reinstall the host from scratch.
  • E. Create a firewall rule that has a source of linux-gcp-east-4c, a destination of Any, and a protocol of SSH.

Answer: B,C

Explanation:
Based on the alert of "Geographically Unusual Remote Access" from Secure Cloud Analytics and the SSH logs from foreign IPs, this device (linux-gcp-east-4c) has likely been compromised. According to SCAZT Section 6: Threat Response (Pages 114-117):
B: Isolating/quarantining the host is an immediate incident response step to prevent lateral movement and data exfiltration.
E: A firewall rule blocking inbound SSH to the GCP VM from external sources would be the appropriate access control response to prevent recurrence.
Options A and C (reinstallation) may be used later during recovery but are not immediate containment steps.
Blocking outgoing SSH (Option D) is less relevant than restricting inbound SSH in this scenario.
Reference: Designing and Implementing Secure Cloud Access for Users and Endpoints (SCAZT), Threat Response, Pages 114-117


NEW QUESTION # 64
The MITRE ATT&CK framework is primarily used for:

  • A. Understanding and categorizing attack techniques and tactics
  • B. Simplifying application development processes
  • C. Enhancing network throughput
  • D. Developing new attack vectors

Answer: A


NEW QUESTION # 65
Security services edge (SSE) combines which of the following services for enhanced security at the network edge?

  • A. Secure Web Gateway (SWG)
  • B. Zero Trust Network Access (ZTNA)
  • C. Cloud Access Security Broker (CASB)
  • D. Uninterruptible Power Supply (UPS)

Answer: A,B,C


NEW QUESTION # 66
The function of a reverse proxy includes:

  • A. Acting as an intermediary for requests from clients seeking resources from servers
  • B. Directly exposing internal network architecture to the internet
  • C. Slowing down the access to web services
  • D. Decreasing the security of web applications

Answer: A


NEW QUESTION # 67
The process of analyzing telemetry reports helps in:

  • A. Determining the scope and impact of a security threat
  • B. Reducing the efficiency of security operations
  • C. Ignoring critical security alerts
  • D. Focusing solely on external threats

Answer: A


NEW QUESTION # 68

Refer to the exhibit. An engineer must configure SAML SSO in Cisco ISE to use Microsoft Azure AD as an identity provider. These configurations were performed:
* Configure a SAML IdP in ISE.
* Configure the Azure AD IdP settings.
Which two actions must the engineer take in Cisco ISE? (Choose two.)

  • A. Configure the External Identity Sources settings.
  • B. Add a SAML IdP.
  • C. Configure the Internal Identity Source Sequence setting.
  • D. Configure SAML groups in ISE.
  • E. Upload metadata from Azure AD to ISE.

Answer: A,E

Explanation:
When integrating Cisco ISE with Azure AD using SAML SSO:
B: The Azure AD metadata must be uploaded into ISE to establish trust and allow token validation.
D: External Identity Sources settings must be configured in ISE to recognize and process authentication requests via SAML-based identity providers like Azure AD.
These are mandatory steps for enabling browser-based SSO authentication in ISE as explained in SCAZT Section 2 (User and Device Security, Pages 42-44), which describes federated identity integration.
Note: Option A is already completed as stated in the prompt. Options C and E are not essential to the authentication flow in this SAML context.
Reference: Designing and Implementing Secure Cloud Access for Users and Endpoints (SCAZT), Section 2, Pages 42-44


NEW QUESTION # 69
Which tool is specifically designed for analyzing application dependencies and network traffic to ensure security and compliance?

  • A. All of the above
  • B. Cisco Umbrella
  • C. Cisco Duo
  • D. Cisco Secure Workload

Answer: D


NEW QUESTION # 70
Cloud security attack tactics often include:

  • A. Enhancing cloud service offerings
  • B. Social media marketing strategies
  • C. Physical security breaches
  • D. Exploiting misconfigured cloud storage

Answer: D


NEW QUESTION # 71
Which of the following are core components of the MITRE ATT&CK framework?
(Multiple Correct Answers)

  • A. SSL Certificates
  • B. TTPs (Tactics, Techniques, and Procedures)
  • C. Credential access methods
  • D. Defense evasion techniques

Answer: B,C,D


NEW QUESTION # 72
Based on telemetry reports, actions might include adjusting _________ to better protect against identified threats.

  • A. marketing strategies
  • B. security policies
  • C. hiring practices
  • D. office layouts

Answer: B


NEW QUESTION # 73
Which component of the Cisco Security Reference Architecture focuses on identifying and analyzing threats?

  • A. Security operations toolset
  • B. Network security
  • C. User/device security
  • D. Threat intelligence

Answer: D


NEW QUESTION # 74
Configuring SAML/SSO is beneficial because:

  • A. It disables the need for encryption
  • B. It allows users to use the same password across all systems, reducing security
  • C. It simplifies user experience by allowing a single set of credentials for multiple services
  • D. It increases the number of passwords a user must remember

Answer: C


NEW QUESTION # 75
......

Cisco 300-740 Real 2026 Braindumps Mock Exam Dumps: https://www.exam4pdf.com/300-740-dumps-torrent.html

Cisco 300-740 Actual Questions and 100% Cover Real Exam Questions: https://drive.google.com/open?id=1aeMBikYg6-FunZ5YmGTshyK-vEAO0Yza