Get 2022 Updated Free Cisco 350-701 Exam Questions & Answer [Q184-Q207]

Share

Get 2022 Updated Free Cisco 350-701 Exam Questions & Answer

350-701 Dumps PDF and Test Engine Exam Questions


Understanding functional and technical aspects of Implementing and Operating Cisco Security Core Technologies (SCOR 350-701) Content Security

The following will be discussed in CISCO 350-701 dumps:

  • Configure and verify email security features such as SPAM filtering, antimalware filtering, DLP, block listing, and email encryption
  • Implement traffic redirection and capture methods
  • Configure and verify web and email security deployment methods to protect onpremises and remote users (inbound and outbound controls and policy management)
  • Describe web proxy identity and authentication including transparent user identification
  • Describe the components, capabilities, and benefits of Cisco Umbrella
  • Compare the components, capabilities, and benefits of local and cloud-based email and web solutions (ESA, CES, WSA)
  • Configure and verify web security controls on Cisco Umbrella (identities, URL content settings, destination lists, and reporting)
  • Configure and verify secure internet gateway and web security features such as block listing, URL filtering, malware scanning, URL categorization, web application filtering, and TLS decryption

 

NEW QUESTION 184
Which threat involves software being used to gain unauthorized access to a computer system?

  • A. NTP amplification
  • B. ping of death
  • C. virus
  • D. HTTP flood

Answer: C

 

NEW QUESTION 185
Refer to the exhibit.

A network administrator configured a site-to-site VPN tunnel between two Cisco IOS routers, and hosts are unable to communicate between two sites of VPN. The network administrator runs the debug crypto isakmp sa command to track VPN status What is the problem according to this command output?

  • A. encryption algorithm mismatch
  • B. interesting traffic was not applied
  • C. hashing algorithm mismatch
  • D. authentication key mismatch

Answer: D

 

NEW QUESTION 186
Refer to the exhibit.

An organization is using DHCP Snooping within their network. A user on VLAN 41 on a new switch is complaining that an IP address is not being obtained. Which command should be configured on the switch interface in order to provide the user with network connectivity?

  • A. ip dhcp snooping trust
  • B. ip dhcp snooping verify mac-address
  • C. ip dhcp snooping vlan 41
  • D. ip dhcp snooping limit 41

Answer: A

Explanation:
To understand DHCP snooping we need to learn about DHCP spoofing attack first.
DHCP spoofing is a type of attack in that the attacker listens for DHCP Requests from clients and answers them with fake DHCP Response before the authorized DHCP Response comes to the clients. The fake DHCP Response often gives its IP address as the client default gateway -> all the traffic sent from the client will go through the attacker computer, the attacker becomes a "man-in-the-middle".
The attacker can have some ways to make sure its fake DHCP Response arrives first. In fact, if the attacker is "closer" than the DHCP Server then he doesn't need to do anything. Or he can DoS the DHCP Server so that it can't send the DHCP Response.
DHCP snooping can prevent DHCP spoofing attacks. DHCP snooping is a Cisco Catalyst feature that determines which switch ports can respond to DHCP requests. Ports are identified as trusted and untrusted.
Only ports that connect to an authorized DHCP server are trusted, and allowed to send all types of DHCP messages. All other ports on the switch are untrusted and can send only DHCP requests. If a DHCP response is seen on an untrusted port, the port is shut down.
The port connected to a DHCP server should be configured as trusted port with the "ip dhcp snooping trust" command. Other ports connecting to hosts are untrusted ports by default.
In this question, we need to configure the uplink to "trust" (under interface Gi1/0/1) as shown below.

 

NEW QUESTION 187
Which CLI command is used to register a Cisco FirePower sensor to Firepower Management Center?

  • A. configure manager <key> add host
  • B. configure manager delete
  • C. configure manager add <host><key
  • D. configure system add <host><key>

Answer: C

 

NEW QUESTION 188
Which cloud model is a collaborative effort where infrastructure is shared and jointly accessed by several organizations from a specific group?

  • A. community
  • B. hybrid
  • C. private
  • D. public

Answer: A

 

NEW QUESTION 189
Which components does a southbound API within a software-defined network architecture communicate?

  • A. controllers within the network
  • B. applications
  • C. appliances
  • D. devices such as routers and switches

Answer: D

 

NEW QUESTION 190
An engineer is configuring AMP for endpoints and wants to block certain files from executing. Which outbreak control method is used to accomplish this task?

  • A. simple detections
  • B. advanced custom detections
  • C. application blocking list
  • D. device flow correlation

Answer: C

 

NEW QUESTION 191
In which cloud services model is the tenant responsible for virtual machine OS patching?

  • A. IaaS
  • B. SaaS
  • C. UCaaS
  • D. PaaS

Answer: A

Explanation:
Explanation
Only in On-site (on-premises) and IaaS we (tenant) manage O/S (Operating System).

 

NEW QUESTION 192
Drag and drop the descriptions from the left onto the correct protocol versions on the right.

Answer:

Explanation:

Explanation

 

NEW QUESTION 193
How is Cisco Umbrella configured to log only security events?

  • A. in the Reporting settings
  • B. per network in the Deployments section
  • C. per policy
  • D. in the Security Settings section

Answer: C

Explanation:
Explanation/Reference: https://docs.umbrella.com/deployment-umbrella/docs/log-management

 

NEW QUESTION 194
An engineer needs a cloud solution that will monitor traffic, create incidents based on events, and integrate with other cloud solutions via an API. Which solution should be used to accomplish this goal?

  • A. CASB
  • B. Adaptive MFA
  • C. Cisco Cloudlock
  • D. SIEM

Answer: C

Explanation:
Explanation Explanation + Cisco Cloudlock continuously monitors cloud environments with a cloud Data Loss Prevention (DLP) engine to identify sensitive information stored in cloud environments in violation of policy. + Cloudlock is API-based. + Incidents are a key resource in the Cisco Cloudlock application. They are triggered by the Cloudlock policy engine when a policy detection criteria result in a match in an object (document, field, folder, post, or file). Reference: https://docs.umbrella.com/cloudlock-documentation/docs/endpoints Note: + Security information and event management (SIEM) platforms collect log and event data from security systems, networks and computers, and turn it into actionable security insights. + An incident is a record of the triggering of an alerting policy. Cloud Monitoring opens an incident when a condition of an alerting policy has been met.
Explanation
+ Cisco Cloudlock continuously monitors cloud environments with a cloud Data Loss Prevention (DLP) engine to identify sensitive information stored in cloud environments in violation of policy.
+ Cloudlock is API-based.
+ Incidents are a key resource in the Cisco Cloudlock application. They are triggered by the Cloudlock policy engine when a policy detection criteria result in a match in an object (document, field, folder, post, or file).
Reference:
Note:
+ Security information and event management (SIEM) platforms collect log and event data from security systems, networks and computers, and turn it into actionable security insights.
+ An incident is a record of the triggering of an alerting policy. Cloud Monitoring opens an incident when a Explanation Explanation + Cisco Cloudlock continuously monitors cloud environments with a cloud Data Loss Prevention (DLP) engine to identify sensitive information stored in cloud environments in violation of policy. + Cloudlock is API-based. + Incidents are a key resource in the Cisco Cloudlock application. They are triggered by the Cloudlock policy engine when a policy detection criteria result in a match in an object (document, field, folder, post, or file). Reference: https://docs.umbrella.com/cloudlock-documentation/docs/endpoints Note: + Security information and event management (SIEM) platforms collect log and event data from security systems, networks and computers, and turn it into actionable security insights. + An incident is a record of the triggering of an alerting policy. Cloud Monitoring opens an incident when a condition of an alerting policy has been met.

 

NEW QUESTION 195
Which two features of Cisco Email Security can protect your organization against email threats? (choose two)

  • A. Time-based one-time passwords
  • B. NetFlow
  • C. Data loss prevention
  • D. Geolocation-based filtering
  • E. Heuristic-based filtering

Answer: C,D

 

NEW QUESTION 196
Refer to the exhibit.

An engineer is implementing a certificate based VPN. What is the result of the existing configuration?

  • A. The OU of the IKEv2 peer certificate is encrypted when the OU is set to MANGLER
  • B. Only an IKEv2 peer that has an OU certificate attribute set to MANGLER establishes an IKEv2 SA successfully
  • C. The OU of the IKEv2 peer certificate is used as the identity when matching an IKEv2 authorization policy.
  • D. The OU of the IKEv2 peer certificate is set to MANGLER

Answer: C

 

NEW QUESTION 197
Which two tasks allow NetFlow on a Cisco ASA 5500 Series firewall? (Choose two.)

  • A. Create an ACL to allow UDP traffic on port 9996.
  • B. Create a class map to match interesting traffic.
  • C. Apply NetFlow Exporter to the outside interface in the inbound direction.
  • D. Enable NetFlow Version 9.
  • E. Define a NetFlow collector by using the flow-export command.

Answer: C,E

 

NEW QUESTION 198
What is a prerequisite when integrating a Cisco ISE server and an AD domain?

  • A. Synchronize the clocks of the Cisco ISE server and the AD server
    The following are the prerequisites to integrate Active Directory with Cisco ISE.
    + Use the Network Time Protocol (NTP) server settings to synchronize the time between the Cisco ISE server and Active Directory. You can configure NTP settings from Cisco ISE CLI.
    + If your Active Directory structure has multidomain forest or is divided into multiple forests, ensure that trust relationships exist between the domain to which Cisco ISE is connected and the other domains that have user and machine information to which you need access. For more information on establishing trust relationships, refer to Microsoft Active Directory documentation.
    + You must have at least one global catalog server operational and accessible by Cisco ISE, in the domain to which you are joining Cisco ISE.
  • B. Place the Cisco ISE server and the AD server in the same subnet
  • C. Configure a common DNS server
  • D. Configure a common administrator account

Answer: A

Explanation:
Reference:
/b_ISE_AD_integration_2x.html#reference_8DC463597A644A5C9CF5D582B77BB24F

 

NEW QUESTION 199
Which exfiltration method does an attacker use to hide and encode data inside DNS requests and queries?

  • A. DNSCrypt
  • B. DNSSEC
  • C. DNS tunneling
  • D. DNS security

Answer: C

Explanation:
Explanation/Reference: https://learn-umbrella.cisco.com/cloud-security/dns-tunneling

 

NEW QUESTION 200
Which algorithm provides encryption and authentication for data plane communication?

  • A. SHA-96
  • B. SHA-384
  • C. AES-GCM
  • D. AES-256

Answer: C

 

NEW QUESTION 201
Which two behavioral patterns characterize a ping of death attack? (Choose two.)

  • A. The attack is fragmented into groups of 8 octets before transmission.
  • B. Publicly accessible DNS servers are typically used to execute the attack.
  • C. The attack is fragmented into groups of 16 octets before transmission.
  • D. Malformed packets are used to crash systems.
  • E. Short synchronized bursts of traffic are used to disrupt TCP connections.

Answer: A,D

Explanation:
Explanation/Reference: https://en.wikipedia.org/wiki/Ping_of_death

 

NEW QUESTION 202
An engineer integrates Cisco FMC and Cisco ISE using pxGrid Which role is assigned for Cisco FMC?

  • A. client
  • B. server
  • C. controller
  • D. publisher

Answer: D

 

NEW QUESTION 203
Which Cisco AMP file disposition valid?

  • A. dirty
  • B. non malicious
  • C. pristine
  • D. malware

Answer: D

 

NEW QUESTION 204
An engineer is trying to securely connect to a router and wants to prevent insecure algorithms from being used.
However, the connection is failing. Which action should be taken to accomplish this goal?

  • A. Disable telnet using the no ip telnet command.
  • B. Enable the SSH server using the ip ssh server command.
  • C. Generate the RSA key using the crypto key generate rsa command.
  • D. Configure the port using the ip ssh port 22 command.

Answer: C

Explanation:
In this question, the engineer was trying to secure the connection so maybe he was trying to allow SSH to the device. But maybe something went wrong so the connection was failing (the connection used to be good). So maybe he was missing the "crypto key generate rsa" command.

 

NEW QUESTION 205
What is provided by the Secure Hash Algorithm in a VPN?

  • A. authentication
  • B. integrity
  • C. key exchange
  • D. encryption

Answer: B

Explanation:
Explanation The HMAC-SHA-1-96 (also known as HMAC-SHA-1) encryption technique is used by IPSec to ensure that a message has not been altered. (-> Therefore answer "integrity" is the best choice). HMAC-SHA-1 uses the SHA-1 specified in FIPS-190-1, combined with HMAC (as per RFC 2104), and is described in RFC 2404. Reference: https://www.ciscopress.com/articles/article.asp?p=24833&seqNum=4 The HMAC-SHA-1-96 (also known as HMAC-SHA-1) encryption technique is used by IPSec to ensure that a message has not been altered. (-> Therefore answer "integrity" is the best choice). HMAC-SHA-1 uses the SHA-1 specified in FIPS-190-1, combined with HMAC (as per RFC 2104), and is described in RFC 2404.
Explanation The HMAC-SHA-1-96 (also known as HMAC-SHA-1) encryption technique is used by IPSec to ensure that a message has not been altered. (-> Therefore answer "integrity" is the best choice). HMAC-SHA-1 uses the SHA-1 specified in FIPS-190-1, combined with HMAC (as per RFC 2104), and is described in RFC 2404. Reference: https://www.ciscopress.com/articles/article.asp?p=24833&seqNum=4

 

NEW QUESTION 206
An organization has two machines hosting web applications. Machine 1 is vulnerable to SQL injection while machine 2 is vulnerable to buffer overflows. What action would allow the attacker to gain access to machine 1 but not machine 2?

  • A. sending continuous pings
  • B. overflowing the buffer's memory
  • C. inserting malicious commands into the database
  • D. sniffing the packets between the two hosts

Answer: C

 

NEW QUESTION 207
......

Verified 350-701 exam dumps Q&As with Correct 358 Questions and Answers: https://www.exam4pdf.com/350-701-dumps-torrent.html

Get New 350-701 Certification – Valid Exam Dumps Questions: https://drive.google.com/open?id=1SQT61C1mnrw_XiACxS8rRQn5b-ns2q0C