Authentic Best resources for 350-701 Test Engine Practice Exam [Q139-Q163]

Share

Authentic Best resources for 350-701 Test Engine Practice Exam

[2021] 350-701 PDF Questions - Perfect Prospect To Go With Exam4PDF Practice Exam

NEW QUESTION 139
What are two Trojan malware attacks? (Choose two)

  • A. rootkit
  • B. smurf
  • C. sync
  • D. frontdoor
  • E. backdoor

Answer: A,E

 

NEW QUESTION 140
Drag and drop the NetFlow export formats from the left onto the descriptions on the right.

Answer:

Explanation:

 

NEW QUESTION 141
After a recent breach, an organization determined that phishing was used to gain initial access to the network before regaining persistence. The information gained from the phishing attack was a result of users visiting known malicious websites. What must be done in order to prevent this from happening in the future?

  • A. Modify outbound malware scanning policies
  • B. Modify web proxy settings
  • C. Modify identification profiles.
  • D. Modify an access policy.

Answer: B

Explanation:
Explanation

 

NEW QUESTION 142
What is a characteristic of a bridge group in ASA Firewall transparent mode''

  • A. It is a Layer 3 segment and includes one port and customizable access rules.
  • B. It allows ARP traffic with a single access rule.
  • C. It has an IP address on its BVI interface and is used for management traffic.
  • D. It includes multiple interfaces and access rules between interfaces are customizable

Answer: D

Explanation:
Explanation

 

NEW QUESTION 143
Which two deployment model configurations are supported for Cisco FTDv in AWS? (Choose two.)

  • A. Cisco FTDv with one management interface and two traffic interfaces configured
  • B. Cisco FTDv with two management interfaces and one traffic interface configured
  • C. Cisco FTDv configured in routed mode and managed by an FMCv installed in AWS
  • D. Cisco FTDv configured in routed mode and IPv6 configured
  • E. Cisco FTDv configured in routed mode and managed by a physical FMC appliance on premises

Answer: A,C

 

NEW QUESTION 144
What are two Detection and Analytics Engines of Cognitive Threat Analytics? (Choose two.)

  • A. intelligent proxy
  • B. URL categorization
  • C. snort
  • D. data exfiltration
  • E. command and control communication

Answer: D,E

Explanation:
Explanation/Reference: https://www.cisco.com/c/dam/en/us/products/collateral/security/cognitive-threat-analytics/at-a- glance-c45-736555.pdf

 

NEW QUESTION 145
In which two ways does a system administrator send web traffic transparently to the Web Security Appliance? (Choose two.)

  • A. configure policy-based routing on the network infrastructure
  • B. snmp-server host inside 10.255.254.1 version 3 myv3
  • C. reference a Proxy Auto Config file
  • D. configure the proxy IP address in the web-browser settings
  • E. configure Active Directory Group Policies to push proxy settings

Answer: B,C

 

NEW QUESTION 146
Which capability is exclusive to a Cisco AMP public cloud instance as compared to a private cloud instance?

  • A. SPERO detection engine
  • B. RBAC
  • C. TETRA detection engine
  • D. ETHOS detection engine

Answer: D

 

NEW QUESTION 147
Which two features of Cisco DNA Center are used in a Software Defined Network solution? (Choose two.)

  • A. authentication
  • B. automation
  • C. encryption
  • D. accounting
  • E. assurance

Answer: B,E

 

NEW QUESTION 148
What is a capability of Cisco ASA Netflow?

  • A. It logs all event types only to the same collector
  • B. It generates NSEL events even if the MPF is not configured
  • C. It sends NetFlow data records from active and standby ASAs in an active standby failover pair
  • D. It filters NSEL events based on traffic

Answer: D

 

NEW QUESTION 149
Which type of dashboard does Cisco DNA Center provide for complete control of the network?

  • A. application management
  • B. service management
  • C. centralized management
  • D. distributed management

Answer: C

Explanation:
Cisco's DNA Center is the only centralized network management system to bring all of this functionality into a single pane of glass.

 

NEW QUESTION 150
Drag and drop the capabilities of Cisco Firepower versus Cisco AMP from the left into the appropriate category on the right.

Answer:

Explanation:

https://www.cisco.com/c/en/us/products/collateral/security/ngips/datasheet-c78-742472.html
https://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide-v60/Reference_a_wrapper_Chapter_topic_here.html
https://www.cisco.com/c/en/us/solutions/collateral/enterprise-networks/advanced-malware-protection/solution-overview-c22-734228.html

 

NEW QUESTION 151
When configuring ISAKMP for IKEv1 Phase1 on a Cisco IOS router, an administrator needs to input the command crypto isakmp key cisco address 0.0.0.0. The administrator is not sure what the IP addressing in this command issued for. What would be the effect of changing the IP address from 0.0.0.0 to 1.2.3.4?

  • A. All IP addresses other than 1.2.3.4 will be allowed
  • B. The key server that is managing the keys for the connection will be at 1.2.3.4
  • C. The address that will be used as the crypto validation authority
  • D. The remote connection will only be allowed from 1.2.3.4

Answer: D

Explanation:
Explanation The command crypto isakmp key cisco address 1.2.3.4 authenticates the IP address of the 1.2.3.4 peer by using the key cisco. The address of "0.0.0.0" will authenticate any address with this key

 

NEW QUESTION 152
The Cisco ASA must support TLS proxy for encrypted Cisco Unified Communications traffic. Where must the ASA be added on the Cisco UC Manager platform?

  • A. Endpoint Trust List
  • B. Certificate Trust List
  • C. Secured Collaboration Proxy
  • D. Enterprise Proxy Service

Answer: B

 

NEW QUESTION 153
What is the primary benefit of deploying an ESA in hybrid mode?

  • A. It provides the lowest total cost of ownership by reducing the need for physical appliances.
  • B. They correlate data about intrusions and vulnerability.
  • C. You can fine-tune its settings to provide the optimum balance between security and performance for your environment.
  • D. They identify data that the ASA sends to the Firepower module.

Answer: B

 

NEW QUESTION 154
Which two prevention techniques are used to mitigate SQL injection attacks? (Choose two.)

  • A. Secure the connection between the web and the app tier.
  • B. Use prepared statements and parameterized queries.
  • C. Block SQL code execution in the web application database login.
  • D. Check integer, float, or Boolean string parameters to ensure accurate values.
  • E. Write SQL code instead of using object-relational mapping libraries.

Answer: B,D

 

NEW QUESTION 155
An engineer wants to generate NetFlow records on traffic traversing the Cisco ASA.
Which Cisco ASA command must be used?

  • A. ip flow-export destination 1.1.1.1 2055
  • B. ip flow monitor<name> input
  • C. flow-export destination inside 1.1.1.1 2055
  • D. flow exporter <name>

Answer: C

 

NEW QUESTION 156
What is the result of running the crypto isakmp key ciscXXXXXXXX address 172.16.0.0 command?

  • A. authenticates the IP address of the 172.16.0.0/32 peer by using the key ciscXXXXXXXX
  • B. authenticates the IKEv1 peers in the 172.16.0.0/16 range by using the key ciscXXXXXXXX
  • C. secures all the certificates in the IKE exchange by using the key ciscXXXXXXXX
  • D. authenticates the IKEv2 peers in the 172.16.0.0/16 range by using the key ciscXXXXXXXX

Answer: A

Explanation:
Explanation/Reference: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/security/a1/sec-a1-cr-book/sec-cr- c4.html#wp6039879000

 

NEW QUESTION 157
An engineer is configuring a Cisco ESA and wants to control whether to accept or reject email messages to a recipient address. Which list contains the allowed recipient addresses?

  • A. SAT
  • B. BAT
  • C. RAT
  • D. HAT

Answer: C

 

NEW QUESTION 158
What is the role of an endpoint in protecting a user from a phishing attack?

  • A. Ensure that antivirus and anti malware software is up to date.
  • B. Utilize 802.1X network security to ensure unauthorized access to resources.
  • C. Use machine learning models to help identify anomalies and determine expected sending behavior.
  • D. Use Cisco Stealthwatch and Cisco ISE Integration.

Answer: C

 

NEW QUESTION 159
Which two risks is a company vulnerable to if it does not have a well-established patching solution for endpoints? (Choose two.)

  • A. malware
  • B. eavesdropping
  • C. ARP spoofing
  • D. exploits
  • E. denial-of-service attacks

Answer: A,C

 

NEW QUESTION 160
An organization has a Cisco ESA set up with policies and would like to customize the action assigned for violations. The organization wants a copy of the message to be delivered with a message added to flag it as a DLP violation. Which actions must be performed in order to provide this capability?

  • A. deliver and send copies to other recipients
  • B. deliver and add disclaimer text
  • C. quarantine and send a DLP violation notification
  • D. quarantine and alter the subject header with a DLP violation

Answer: B

Explanation:
Explanation Explanation You specify primary and secondary actions that the appliance will take when it detects a possible DLP violation in an outgoing message. Different actions can be assigned for different violation types and severities. Primary actions include: - Deliver - Drop - Quarantine Secondary actions include: - Sending a copy to a policy quarantine if you choose to deliver the message. The copy is a perfect clone of the original, including the Message ID. Quarantining a copy allows you to test the DLP system before deployment in addition to providing another way to monitor DLP violations. When you release the copy from the quarantine, the appliance delivers the copy to the recipient, who will have already received the original message. - Encrypting messages. The appliance only encrypts the message body. It does not encrypt the message headers. - Altering the subject header of messages containing a DLP violation. - Adding disclaimer text to messages. - Sending messages to an alternate destination mailhost. - Sending copies (bcc) of messages to other recipients. (For example, you could copy messages with critical DLP violations to a compliance officer's mailbox for examination.) - Sending a DLP violation notification message to the sender or other contacts, such as a manager or DLP compliance officer. Reference: https://www.cisco.com/c/en/us/td/docs/security/esa/esa12-0/user_guide/ b_ESA_Admin_Guide_12_0/b_ESA_Admin_Guide_chapter_010001.html Explanation You specify primary and secondary actions that the appliance will take when it detects a possible DLP violation in an outgoing message. Different actions can be assigned for different violation types and severities.
Primary actions include:
- Deliver
- Drop
- Quarantine
Secondary actions include:
- Sending a copy to a policy quarantine if you choose to deliver the message. The copy is a perfect clone of the original, including the Message ID. Quarantining a copy allows you to test the DLP system before deployment in addition to providing another way to monitor DLP violations. When you release the copy from the quarantine, the appliance delivers the copy to the recipient, who will have already received the original message.
- Encrypting messages. The appliance only encrypts the message body. It does not encrypt the message headers.
- Altering the subject header of messages containing a DLP violation.
- Adding disclaimer text to messages.
- Sending messages to an alternate destination mailhost.
- Sending copies (bcc) of messages to other recipients. (For example, you could copy messages with critical DLP violations to a compliance officer's mailbox for examination.)
- Sending a DLP violation notification message to the sender or other contacts, such as a manager or DLP compliance officer.
Reference:
Explanation Explanation You specify primary and secondary actions that the appliance will take when it detects a possible DLP violation in an outgoing message. Different actions can be assigned for different violation types and severities. Primary actions include: - Deliver - Drop - Quarantine Secondary actions include: - Sending a copy to a policy quarantine if you choose to deliver the message. The copy is a perfect clone of the original, including the Message ID. Quarantining a copy allows you to test the DLP system before deployment in addition to providing another way to monitor DLP violations. When you release the copy from the quarantine, the appliance delivers the copy to the recipient, who will have already received the original message. - Encrypting messages. The appliance only encrypts the message body. It does not encrypt the message headers. - Altering the subject header of messages containing a DLP violation. - Adding disclaimer text to messages. - Sending messages to an alternate destination mailhost. - Sending copies (bcc) of messages to other recipients. (For example, you could copy messages with critical DLP violations to a compliance officer's mailbox for examination.) - Sending a DLP violation notification message to the sender or other contacts, such as a manager or DLP compliance officer. Reference: https://www.cisco.com/c/en/us/td/docs/security/esa/esa12-0/user_guide/ b_ESA_Admin_Guide_12_0/b_ESA_Admin_Guide_chapter_010001.html

 

NEW QUESTION 161
Which service allows a user export application usage and performance statistics with Cisco Application Visibility and control?

  • A. NetFlow
  • B. 802.1X
  • C. SNORT
  • D. SNMP

Answer: A

 

NEW QUESTION 162
An engineer used a posture check on a Microsoft Windows endpoint and discovered that the MS17-010 patch was not installed, which left the endpoint vulnerable to WannaCry ransomware. Which two solutions mitigate the risk of this ransom ware infection? (Choose two)

  • A. Set up a profiling policy in Cisco Identity Service Engine to check and endpoint patch level before allowing access on the network.
  • B. Set up a well-defined endpoint patching strategy to ensure that endpoints have critical vulnerabilities patched in a timely fashion.
  • C. Configure endpoint firewall policies to stop the exploit traffic from being allowed to run and replicate throughout the network.
  • D. Configure a posture policy in Cisco Identity Services Engine to check that an endpoint patch level is met before allowing access on the network.
  • E. Configure a posture policy in Cisco Identity Services Engine to install the MS17-010 patch before allowing access on the network.

Answer: D,E

Explanation:
Explanation
A posture policy is a collection of posture requirements, which are associated with one or more identity groups, and operating systems. We can configure ISE to check for the Windows patch at Work Centers > Posture > Posture Elements > Conditions > File.
In this example, we are going to use the predefined file check to ensure that our Windows 10 clients have the critical security patch installed to prevent the Wanna Cry malware.

 

NEW QUESTION 163
......

Best updated resource for 350-701 Online Practice Exam: https://www.exam4pdf.com/350-701-dumps-torrent.html

Realistic Practice 350-701 Implementing and Operating Cisco Security Core Technologies Exam Braindumps: https://drive.google.com/open?id=1cHt98ZKZS1SbAXsQeoa-9XX4xI1UjJVK