Get ready to pass the 350-701 Exam right now using our CCNP Security Exam Package [Q164-Q186]

Share

 Get ready to pass the 350-701 Exam right now using our CCNP Security  Exam Package

A fully updated 2021 350-701 Exam Dumps exam guide from training expert Exam4PDF

NEW QUESTION 164
When choosing an algorithm to us, what should be considered about Diffie Hellman and RSA for key establishment?

  • A. RSA is a symmetric key establishment algorithm intended to output asymmetric keys
  • B. DH is on asymmetric key establishment algorithm intended to output symmetric keys
  • C. RSA is an asymmetric key establishment algorithm intended to output symmetric keys
  • D. DH is a symmetric key establishment algorithm intended to output asymmetric keys

Answer: B

Explanation:
Explanation
Diffie Hellman (DH) uses a private-public key pair to establish a shared secret, typically a symmetric key. DH is not a symmetric algorithm - it is an asymmetric algorithm used to establish a shared secret for a symmetric key algorithm.

 

NEW QUESTION 165
Which Cisco command enables authentication, authorization, and accounting globally so that CoA is supported on the device?

  • A. ip device-tracking
  • B. aaa server radius dynamic-author
  • C. aaa new-model
  • D. auth-type all

Answer: B

 

NEW QUESTION 166
Which two fields are defined in the NetFlow flow? {Choose two.)

  • A. output logical interface
  • B. class of service bits
  • C. destination port
  • D. type of service byte
  • E. Layer 4 protocol type

Answer: C,D

Explanation:
Explanation

 

NEW QUESTION 167
An organization deploys multiple Cisco FTD appliances and wants to manage them using one centralized solution The organization does not have a local VM but does have existing Cisco ASAs that must migrate over to Cisco FTDs Which solution meets the needs of the organization?

  • A. CSM
  • B. Cisco FDM
  • C. CDO
  • D. Cisco FMC

Answer: A

 

NEW QUESTION 168
DRAG DROP
Drag and drop the capabilities from the left onto the correct technologies on the right.
Select and Place:

Answer:

Explanation:

 

NEW QUESTION 169
Which function is the primary function of Cisco AMP threat Grid?

  • A. monitoring network traffic
  • B. applying a real-time URI blacklist
  • C. automated malware analysis
  • D. automated email encryption

Answer: C

 

NEW QUESTION 170
What is a characteristic of a bridge group in ASA Firewall transparent mode''

  • A. It is a Layer 3 segment and includes one port and customizable access rules.
  • B. It allows ARP traffic with a single access rule.
  • C. It has an IP address on its BVI interface and is used for management traffic.
  • D. It includes multiple interfaces and access rules between interfaces are customizable

Answer: D

Explanation:
Explanation

 

NEW QUESTION 171
What is a characteristic of Cisco ASA NetFlow v9 Secure Event Logging?

  • A. It provides stateless IP flow tracking that exports all records of a specific flow.
  • B. It tracks the flow continuously and provides updates every 10 seconds.
  • C. Its events match all traffic classes in parallel.
  • D. It tracks flow-create, flow-teardown, and flow-denied events.

Answer: D

Explanation:
Explanation/Reference: https://www.cisco.com/c/en/us/td/docs/security/asa/asa92/configuration/general/asa-general-cli/ monitor-nsel.html

 

NEW QUESTION 172
Which technology reduces data loss by identifying sensitive information stored in public computing environments?

  • A. Cisco Firepower
  • B. Cisco Cloudlock
  • C. Cisco HyperFlex
  • D. Cisco SDA

Answer: D

 

NEW QUESTION 173
A switch with Dynamic ARP Inspection enabled has received a spoofed ARP response on a trusted interface. How does the switch behave in this situation?

  • A. It forwards the packet after validation by using the MAC Binding Table.
  • B. It drops the packet after validation by using the IP & MAC Binding Table.
  • C. It drops the packet Without validation.
  • D. It forwards the packet without validation.

Answer: D

 

NEW QUESTION 174
A network administrator is using the Cisco ESA with AMP to upload files to the cloud for analysis. The network is congested and is affecting communication. How will the Cisco ESA handle any files which need analysis?

  • A. The ESA immediately makes another attempt to upload the file.
  • B. AMP calculates the SHA-256 fingerprint, caches it, and periodically attempts the upload.
  • C. The file upload is abandoned.
  • D. The file is queued for upload when connectivity is restored.

Answer: B

Explanation:

https://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/118796-technote-esa-00.html

 

NEW QUESTION 175
Which solution protects hybrid cloud deployment workloads with application visibility and segmentation?

  • A. Tetration
  • B. Stealthwatch
  • C. Firepower
  • D. Nexus

Answer: A

 

NEW QUESTION 176
Which information is required when adding a device to Firepower Management Center?

  • A. registration key
  • B. username and password
  • C. encryption method
  • D. device serial number

Answer: A

 

NEW QUESTION 177
Which cloud model is a collaborative effort where infrastructure is shared and jointly accessed by several organizations from a specific group?

  • A. public
  • B. hybrid
  • C. private
  • D. community

Answer: D

 

NEW QUESTION 178
An organization configures Cisco Umbrella to be used for its DNS services. The organization must be able to block traffic based on the subnet that the endpoint is on but it sees only the requests from its public IP address instead of each internal IP address. What must be done to resolve this issue?

  • A. Use the tenant control features to identify each subnet being used and track the connections within the Cisco Umbrella dashboard
  • B. Install the Microsoft Active Directory Connector to give IP address information stitched to the requests in the Cisco Umbrella dashboard
  • C. Set up a Cisco Umbrella virtual appliance to internally field the requests and see the traffic of each IP address
  • D. Configure an internal domain within Cisco Umbrella to help identify each address and create policy from the domains

Answer: D

 

NEW QUESTION 179
Which protocol provides the strongest throughput performance when using Cisco AnyConnect VPN?

  • A. TLSv1
  • B. DTLSv1
  • C. TLSv1.2
  • D. TLSv1.1

Answer: B

Explanation:
Explanation/Reference: https://www.cisco.com/c/en/us/support/docs/security/anyconnect-secure-mobility-client/215331- anyconnect-implementation-and-performanc.html

 

NEW QUESTION 180
What is a prerequisite when integrating a Cisco ISE server and an AD domain?

  • A. Synchronize the clocks of the Cisco ISE server and the AD server
  • B. Configure a common DNS server
  • C. Configure a common administrator account
  • D. Place the Cisco ISE server and the AD server in the same subnet

Answer: A

Explanation:
The following are the prerequisites to integrate Active Directory with Cisco ISE.
+ Use the Network Time Protocol (NTP) server settings to synchronize the time between the Cisco ISE server and Active Directory. You can configure NTP settings from Cisco ISE CLI.
+ If your Active Directory structure has multidomain forest or is divided into multiple forests, ensure that trust relationships exist between the domain to which Cisco ISE is connected and the other domains that have user and machine information to which you need access. For more information on establishing trust relationships, refer to Microsoft Active Directory documentation.
+ You must have at least one global catalog server operational and accessible by Cisco ISE, in the domain to which you are joining Cisco ISE.
Reference:
/b_ISE_AD_integration_2x.html#reference_8DC463597A644A5C9CF5D582B77BB24F

 

NEW QUESTION 181
An engineer is trying to securely connect to a router and wants to prevent insecure algorithms from being used. However, the connection is failing. Which action should be taken to accomplish this goal?

  • A. Configure the port using the ip ssh port 22 command.
  • B. Enable the SSH server using the ip ssh server command.
  • C. Disable telnet using the no ip telnet command.
  • D. Generate the RSA key using the crypto key generate rsa command.

Answer: D

Explanation:
https://learningnetwork.cisco.com/s/question/0D53i00000KsrhK/rsa-key

 

NEW QUESTION 182
A network engineer has been tasked with adding a new medical device to the network. Cisco ISE is being used as the NAC server, and the new device does not have a supplicant available. What must be done in order to securely connect this device to the network?

  • A. Use 802.1X with posture assessment.
  • B. Use 802.1X with profiling.
  • C. Use MAB with posture assessment.
  • D. Use MAB with profiling

Answer: D

Explanation:
Explanation
As the new device does not have a supplicant, we cannot use 802.1X.
MAC Authentication Bypass (MAB) is a fallback option for devices that don't support 802.1x. It is virtually always used in deployments in some way shape or form. MAB works by having the authenticator take the connecting device's MAC address and send it to the authentication server as its username and password. The authentication server will check its policies and send back an Access-Accept or Access-Reject just like it would with 802.1x.
Cisco ISE Profiling Services provides dynamic detection and classification of endpoints connected to the network. Using MAC addresses as the unique identifier, ISE collects various attributes for each network endpoint to build an internal endpoint database. The classification process matches the collected attributes to prebuilt or user-defined conditions, which are then correlated to an extensive library of profiles. These profiles include a wide range of device types, including mobile clients (iPads, Android tablets, Chromebooks, and so on), desktop operating systems (for example, Windows, Mac OS X, Linux, and others), and numerous non-user systems such as printers, phones, cameras, and game consoles.
Once classified, endpoints can be authorized to the network and granted access based on their profile. For example, endpoints that match the IP phone profile can be placed into a voice VLAN using MAC Authentication Bypass (MAB) as the authentication method. Another example is to provide differentiated network access to users based on the device used. For example, employees can get full access when accessing the network from their corporate workstation but be granted limited network access when accessing the network from their personal iPhone.

 

NEW QUESTION 183
What are two reasons for implementing a multifactor authentication solution such as Duo Security provide to an organization? (Choose two)

  • A. flexibility of different methods of 2FA such as phone callbacks, SMS passcodes, and push notifications
  • B. integration with 802.1x security using native Microsoft Windows supplicant
  • C. secure access to on-premises and cloud applications
  • D. single sign-on access to on-premises and cloud applications
  • E. identification and correction of application vulnerabilities before allowing access to resources

Answer: A,C

Explanation:
Explanation
Two-factor authentication adds a second layer of security to your online accounts. Verifying your identity using a second factor (like your phone or other mobile device) prevents anyone but you from logging in, even if they know your password.
Note: Single sign-on (SSO) is a property of identity and access management that enables users to securely authenticate with multiple applications and websites by logging in only once with just one set of credentials (username and password). With SSO, the application or website that the user is trying to access relies on a trusted third party to verify that users are who they say they are.

 

NEW QUESTION 184
What is an attribute of the DevSecOps process?

  • A. isolated security team
  • B. mandated security controls and check lists
  • C. development security
  • D. security scanning and theoretical vulnerabilities

Answer: C

Explanation:
Explanation
Explanation
DevSecOps (development, security, and operations) is a concept used in recent years to describe how to move security activities to the start of the development life cycle and have built-in security practices in the continuous integration/continuous deployment (CI/CD) pipeline. Thus minimizing vulnerabilities and bringing security closer to IT and business objectives.
Three key things make a real DevSecOps environment:
+ Security testing is done by the development team.
+ Issues found during that testing is managed by the development team.
+ Fixing those issues stays within the development team.

 

NEW QUESTION 185
Drag and drop the Firepower Next Generation Intrustion Prevention System detectors from the left onto the correct definitions on the right.

Answer:

Explanation:

 

NEW QUESTION 186
......

Master 2021 Latest The Questions CCNP Security and Pass 350-701  Real Exam!: https://www.exam4pdf.com/350-701-dumps-torrent.html

Practice To 350-701 - Exam4PDF Remarkable Practice On your Implementing and Operating Cisco Security Core Technologies Exam: https://drive.google.com/open?id=1cgIm1UExaf5YktDnORMbmzjORveGXcD6