Certification Topics of 350-701 Exam PDF Recently Updated Questions
350-701 Exam Prep Guide: Prep guide for the 350-701 Exam
Secure Network Visibility, Access, and Enforcement – 15%
- Describing the exfiltration methods, including HTTPS, IRC, DNS tunneling, email, Messenger, and others;
- Describing the network telemetry benefits;
- Configuring and verifying the function of network access device, such as 802.1X, WebAuth, and MAB;
- Explaining the capacity, benefits, and components of the security products & solutions, such as Cisco Stealthwatch, Cisco Umbrella Investigate, Cisco Stealthwatch Cloud, Cisco pxGrid, and others.
NEW QUESTION 83
Which two application layer preprocessors are used by Firepower Next Generation Intrusion Prevention System? (Choose two)
- A. inline normalization
- B. SSL
- C. SIP
- D. modbus
- E. packet decoder
Answer: B,C
Explanation:
Application layer protocols can represent the same data in a variety of ways. The Firepower System provides application layer protocol decoders that normalize specific types of packet data into formats that the intrusion rules engine can analyze. Normalizing application-layer protocol encodings allows the rules engine to effectively apply the same content-related rules to packets whose data is represented differently and obtain meaningful results.
Application layer protocols can represent the same data in a variety of ways. The Firepower System provides application layer protocol decoders that normalize specific types of packet data into formats that the intrusion rules engine can analyze. Normalizing application-layer protocol encodings allows the rules engine to effectively apply the same content-related rules to packets whose data is represented differently and obtain meaningful results.
Reference:
FirePower uses many preprocessors, including DNS, FTP/Telnet, SIP, SSL, SMTP, SSH preprocessors.
Application layer protocols can represent the same data in a variety of ways. The Firepower System provides application layer protocol decoders that normalize specific types of packet data into formats that the intrusion rules engine can analyze. Normalizing application-layer protocol encodings allows the rules engine to effectively apply the same content-related rules to packets whose data is represented differently and obtain meaningful results.
FirePower uses many preprocessors, including DNS, FTP/Telnet, SIP, SSL, SMTP, SSH preprocessors.
NEW QUESTION 84
An organization uses Cisco FMC to centrally manage multiple Cisco FTD devices. The default management port conflicts with other communications on the network and must be changed. What must be done to ensure that all devices can communicate together?
- A. Set the tunnel port to 8305
The FMC and managed devices communicate using a two-way, SSL-encrypted communication channel, which by default is on port 8305. - B. Change the management port on Cisco FMC so that it pushes the change to all managed Cisco FTD devices
- C. Manually change the management port on Cisco FMC and all managed Cisco FTD devices
- D. Set the tunnel to go through the Cisco FTD
Answer: C
Explanation:
Cisco strongly recommends that you keep the default settings for the remote management port, but if the management port conflicts with other communications on your network, you can choose a different port. If you change the management port, you must change it for all devices in your deployment that need to communicate with each other.
NEW QUESTION 85
Drag and drop the Firepower Next Generation Intrusion Prevention System detectors from the left onto the correct definitions on the right.
Answer:
Explanation:
NEW QUESTION 86
Which two protocols must be configured to authenticate end users to the Web Security Appliance? (Choose two.)
- A. CHAP
- B. RADIUS
- C. Kerberos
- D. NTLMSSP
- E. TACACS+
Answer: C,D
NEW QUESTION 87
A network administrator is configuring a rule in an access control policy to block certain URLs and selects the "Chat and Instant Messaging" category. Which reputation score should be selected to accomplish this goal?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: D
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/esa/esa111/user_guide/b_ESA_Admin_Guide_11_1/b_ESA_Admin_Guide_chapter_01111.html
NEW QUESTION 88
Which two capabilities does an MDM provide? (Choose two.)
- A. unified management of mobile devices, Macs, and PCs from a centralized dashboard
- B. manual identification and classification of client devices
- C. delivery of network malware reports to an inbox in a schedule
- D. unified management of Android and Apple devices from a centralized dashboard
- E. enforcement of device security policies from a centralized dashboard
Answer: A,E
NEW QUESTION 89
How does Cisco Stealthwatch Cloud provide security for cloud environments?
- A. It facilitates secure connectivity between public and private networks.
- B. It delivers visibility and threat detection.
- C. It assigns Internet-based DNS protection for clients and servers.
- D. It prevents exfiltration of sensitive data.
Answer: B
Explanation:
Explanation
Cisco Stealthwatch Cloud: Available as an SaaS product offer to provide visibility and threat detection within public cloud infrastructures such as Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP).
NEW QUESTION 90
What is the difference between a vulnerability and an exploit?
- A. A vulnerability is a weakness that can be exploited by an attacker
- B. An exploit is a hypothetical event that causes a vulnerability in the network
- C. An exploit is a weakness that can cause a vulnerability in the network
- D. A vulnerability is a hypothetical event for an attacker to exploit
Answer: A
NEW QUESTION 91
Which type of attack is social engineering?
- A. malware
- B. MITM
- C. phishing
- D. trojan
Answer: C
NEW QUESTION 92
An engineer needs behavioral analysis to detect malicious activity on the hosts, and is configuring the organization's public cloud to send telemetry using the cloud provider's mechanisms to a security device. Which mechanism should the engineer configure to accomplish this goal?
- A. Flow
- B. VPC flow logs
- C. NetFlow
- D. mirror port
Answer: C
Explanation:
https://www.cisco.com/c/en/us/products/collateral/data-center-analytics/tetration-analytics/q-and-a-c67-737402.html
NEW QUESTION 93 
Refer to the exhibit. Which command was used to display this output?
- A. show dot1x all summary
- B. show dot1x interface gi1/0/12
- C. show dot1x
- D. show dot1x all
Answer: D
Explanation:
Explanation/Reference: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_8021x/configuration/xe-3se/3850/sec- user-8021x-xe-3se-3850-book/config-ieee-802x-pba.html
NEW QUESTION 94
What is the purpose of the Decrypt for Application Detection feature within the WSA Decryption options?
- A. It decrypts HTTPS application traffic for authenticated users.
- B. It decrypts HTTPS application traffic for unauthenticated users.
- C. It provides enhanced HTTPS application detection for AsyncOS.
- D. It alerts users when the WSA decrypts their traffic.
Answer: C
Explanation:
Explanation/Reference: https://www.cisco.com/c/en/us/td/docs/security/wsa/wsa11-7/user_guide/ b_WSA_UserGuide_11_7/b_WSA_UserGuide_11_7_chapter_01011.html
NEW QUESTION 95
What are the two most commonly used authentication factors in multifactor authentication? (Choose two.)
- A. encryption factor
- B. knowledge factor
- C. time factor
- D. biometric factor
- E. confidentiality factor
Answer: B,D
NEW QUESTION 96
Which two features of Cisco DNA Center are used in a Software Defined Network solution? (Choose two)
- A. accounting
- B. assurance
- C. authentication
- D. encryption
- E. automation
Answer: B,E
Explanation:
What Cisco DNA Center enables you to do
Automate: Save time by using a single dashboard to manage and automate your network. Quickly scale your business with intuitive workflows and reusable templates. Configure and provision thousands of network devices across your enterprise in minutes, not hours.
Secure policy: Deploy group-based secure access and network segmentation based on business needs. With Cisco DNA Center, you apply policy to users and applications instead of to your network devices. Automation reduces manual operations and the costs associated with human errors, resulting in more uptime and improved security. Assurance then assesses the network and uses context to turn data into intelligence, making sure that changes in the network device policies achieve your intent.
Assurance: Monitor, identify, and react in real time to changing network and wireless conditions. Cisco DNA Center uses your network's wired and wireless devices to create sensors everywhere, providing real-time feedback based on actual network conditions. The Cisco DNA Assurance engine correlates network sensor insights with streaming telemetry and compares this with the current context of these data sources. With a quick check of the health scores on the Cisco DNA Center dashboard, you can see where there is a performance issue and identify the most likely cause in minutes.
Extend ecosystem: With the new Cisco DNA Center platform, IT can now integrate Cisco® solutions and thirdparty technologies into a single network operation for streamlining IT workflows and increasing business value and innovation. Cisco DNA Center allows you to run the network with open interfaces with IT and business applications, integrates across IT operations and technology domains, and can manage heterogeneous network devices.
What Cisco DNA Center enables you to do
Automate: Save time by using a single dashboard to manage and automate your network. Quickly scale your business with intuitive workflows and reusable templates. Configure and provision thousands of network devices across your enterprise in minutes, not hours.
Secure policy: Deploy group-based secure access and network segmentation based on business needs. With Cisco DNA Center, you apply policy to users and applications instead of to your network devices. Automation reduces manual operations and the costs associated with human errors, resulting in more uptime and improved security. Assurance then assesses the network and uses context to turn data into intelligence, making sure that changes in the network device policies achieve your intent.
Assurance: Monitor, identify, and react in real time to changing network and wireless conditions. Cisco DNA Center uses your network's wired and wireless devices to create sensors everywhere, providing real-time feedback based on actual network conditions. The Cisco DNA Assurance engine correlates network sensor insights with streaming telemetry and compares this with the current context of these data sources. With a quick check of the health scores on the Cisco DNA Center dashboard, you can see where there is a performance issue and identify the most likely cause in minutes.
Extend ecosystem: With the new Cisco DNA Center platform, IT can now integrate Cisco® solutions and thirdparty technologies into a single network operation for streamlining IT workflows and increasing business value and innovation. Cisco DNA Center allows you to run the network with open interfaces with IT and business applications, integrates across IT operations and technology domains, and can manage heterogeneous network devices.
Reference:
What Cisco DNA Center enables you to do
Automate: Save time by using a single dashboard to manage and automate your network. Quickly scale your business with intuitive workflows and reusable templates. Configure and provision thousands of network devices across your enterprise in minutes, not hours.
Secure policy: Deploy group-based secure access and network segmentation based on business needs. With Cisco DNA Center, you apply policy to users and applications instead of to your network devices. Automation reduces manual operations and the costs associated with human errors, resulting in more uptime and improved security. Assurance then assesses the network and uses context to turn data into intelligence, making sure that changes in the network device policies achieve your intent.
Assurance: Monitor, identify, and react in real time to changing network and wireless conditions. Cisco DNA Center uses your network's wired and wireless devices to create sensors everywhere, providing real-time feedback based on actual network conditions. The Cisco DNA Assurance engine correlates network sensor insights with streaming telemetry and compares this with the current context of these data sources. With a quick check of the health scores on the Cisco DNA Center dashboard, you can see where there is a performance issue and identify the most likely cause in minutes.
Extend ecosystem: With the new Cisco DNA Center platform, IT can now integrate Cisco® solutions and thirdparty technologies into a single network operation for streamlining IT workflows and increasing business value and innovation. Cisco DNA Center allows you to run the network with open interfaces with IT and business applications, integrates across IT operations and technology domains, and can manage heterogeneous network devices.
NEW QUESTION 97
Which two activities can be done using Cisco DNA Center? (Choose two.)
- A. DNS
- B. design
- C. accounting
- D. provision
- E. DHCP
Answer: B,D
Explanation:
Explanation/Reference: https://www.cisco.com/c/en/us/td/docs/cloud-systems-management/network-automation-and- management/dna-center/1-2-1/user_guide/b_dnac_ug_1_2_1/b_dnac_ug_1_2_chapter_00.pdf
NEW QUESTION 98
Drag and drop the suspicious patterns for the Cisco Tetration platform from the left onto the correct definitions on the right.
Answer:
Explanation:
Explanation

https://www.cisco.com/c/en/us/products/collateral/data-center-analytics/tetration-analytics/white-paper-c11-7403
NEW QUESTION 99
A network engineer is trying to figure out whether FlexVPN or DMVPN would fit better in their environment.
They have a requirement for more stringent security multiple security associations for the connections, more efficient VPN establishment as well consuming less bandwidth. Which solution would be best for this and why?
- A. FlexVPN because it supports IKEv2 and DMVPN does not
- B. FlexVPN because it uses multiple SAs and DMVPN does not
- C. DMVPN because it supports IKEv2 and FlexVPN does not
- D. DMVPN because it uses multiple SAs and FlexVPN does not
Answer: B
Explanation:
Explanation
FlexVPN supports IKEv2 -> Answer A is not correct.
DMVPN supports both IKEv1 & IKEv2 -> Answer B is not correct.
FlexVPN support multiple SAs -> Answer D is not correct.
NEW QUESTION 100
Which encryption algorithm provides highly secure VPN communications?
- A. AES 128
- B. AES 256
- C. 3DES
- D. DES
Answer: B
NEW QUESTION 101
What are two differences between a Cisco WSA that is running in transparent mode and one running in explicit mode? (Choose two.)
- A. The Cisco WSA responds with its own IP address only if it is running in transparent mode.
- B. When the Cisco WSA is running in transparent mode, it uses the WSA's own IP address as the HTTP request destination.
- C. The Cisco WSA uses a Layer 3 device to redirect traffic only if it is running in transparent mode.
- D. The Cisco WSA responds with its own IP address only if it is running in explicit mode.
- E. The Cisco WSA is configured in a web browser only if it is running in transparent mode.
Answer: A,B
NEW QUESTION 102
A Cisco FTD engineer is creating a new IKEv2 policy called s2s00123456789 for their organization to allow for additional protocols to terminate network devices with. They currently only have one policy established and need the new policy to be a backup in case some devices cannot support the stronger algorithms listed in the primary policy. What should be done in order to support this?
- A. Change the integrity algorithms to SHA* to support all SHA algorithms in the primary policy
- B. Change the encryption to AES* to support all AES algorithms in the primary policy
- C. Make the priority for the primary policy 10 and the new policy 1
- D. Make the priority for the new policy 5 and the primary policy 1
Answer: D
Explanation:
All IKE policies on the device are sent to the remote peer regardless of what is in the selected policy section.
The first IKE Policy matched by the remote peer will be selected for the VPN connection. Choose which policy is sent first using the priority field. Priority 1 will be sent first.
All IKE policies on the device are sent to the remote peer regardless of what is in the selected policy section.
The first IKE Policy matched by the remote peer will be selected for the VPN connection. Choose which policy is sent first using the priority field. Priority 1 will be sent first.
Reference:
All IKE policies on the device are sent to the remote peer regardless of what is in the selected policy section.
The first IKE Policy matched by the remote peer will be selected for the VPN connection. Choose which policy is sent first using the priority field. Priority 1 will be sent first.
NEW QUESTION 103
Refer to the exhibit.
An organization is using DHCP Snooping within their network. A user on VLAN 41 on a new switch is complaining that an IP address is not being obtained. Which command should be configured on the switch interface in order to provide the user with network connectivity?
- A. ip dhcp snooping limit 41
- B. ip dhcp snooping trust
- C. ip dhcp snooping vlan 41
- D. ip dhcp snooping verify mac-address
Answer: B
Explanation:
Explanation
Explanation
To understand DHCP snooping we need to learn about DHCP spoofing attack first.
DHCP spoofing is a type of attack in that the attacker listens for DHCP Requests from clients and answers them with fake DHCP Response before the authorized DHCP Response comes to the clients. The fake DHCP Response often gives its IP address as the client default gateway -> all the traffic sent from the client will go through the attacker computer, the attacker becomes a "man-in-the-middle".
The attacker can have some ways to make sure its fake DHCP Response arrives first. In fact, if the attacker is "closer" than the DHCP Server then he doesn't need to do anything. Or he can DoS the DHCP Server so that it can't send the DHCP Response.
DHCP snooping can prevent DHCP spoofing attacks. DHCP snooping is a Cisco Catalyst feature that determines which switch ports can respond to DHCP requests. Ports are identified as trusted and untrusted.
Only ports that connect to an authorized DHCP server are trusted, and allowed to send all types of DHCP messages. All other ports on the switch are untrusted and can send only DHCP requests. If a DHCP response is seen on an untrusted port, the port is shut down.
The port connected to a DHCP server should be configured as trusted port with the "ip dhcp snooping trust" command. Other ports connecting to hosts are untrusted ports by default.
In this question, we need to configure the uplink to "trust" (under interface Gi1/0/1) as shown below.
NEW QUESTION 104
A company is experiencing exfiltration of credit card numbers that are not being stored on-premise. The company needs to be able to protect sensitive data throughout the full environment Which tool should be used to accomplish this goal?
- A. Cisco ISE
- B. Cloudlock
- C. Security Manager
- D. Web Security Appliance
Answer: B
Explanation:
Reference:
https://www.cisco.com/c/dam/en/us/products/collateral/security/cloudlock/cisco-cloudlock-cloud-data-securitydatasheet.pdf
NEW QUESTION 105
Drag and drop the NetFlow export formats from the left onto the descriptions on the right.
Answer:
Explanation:
NEW QUESTION 106
A mall provides security services to customers with a shared appliance. The mall wants separation of management on the shared appliance. Which ASA deployment mode meets these needs?
- A. multiple context mode
- B. multiple zone mode
- C. routed mode
- D. transparent mode
Answer: A
NEW QUESTION 107
An engineer has been tasked with configuring a Cisco FTD to analyze protocol fields and detect anomalies in the traffic from industrial systems. What must be done to meet these requirements?
- A. Configure intrusion rules for the DNP3 preprocessor
- B. Enable traffic analysis in the Cisco FTD
- C. Modify the access control policy to trust the industrial traffic
- D. Implement pre-filter policies for the CIP preprocessor
Answer: D
Explanation:
The Modbus, DNP3, and CIP SCADA preprocessors detect traffic anomalies and provide data to intrusion rules. Therefore in this question only answer A or answer C is correct.
The DNP3 preprocessor detects anomalies in DNP3 traffic and decodes the DNP3 protocol for processing by the rules engine, which uses DNP3 keywords to access certain protocol fields.
The Common Industrial Protocol (CIP) is a widely used application protocol that supports industrial automation applications. EtherNet/IP is an implementation of CIP that is used on Ethernet-based networks.The CIP preprocessor detects CIP and ENIP traffic running on TCP or UDP and sends it to the intrusion rules engine.
You can use CIP and ENIP keywords in custom intrusion rules to detect attacks in CIP and ENIP traffic.
The Modbus, DNP3, and CIP SCADA preprocessors detect traffic anomalies and provide data to intrusion rules. Therefore in this question only answer A or answer C is correct.
The DNP3 preprocessor detects anomalies in DNP3 traffic and decodes the DNP3 protocol for processing by the rules engine, which uses DNP3 keywords to access certain protocol fields.
The Common Industrial Protocol (CIP) is a widely used application protocol that supports industrial automation applications. EtherNet/IP is an implementation of CIP that is used on Ethernet-based networks.The CIP preprocessor detects CIP and ENIP traffic running on TCP or UDP and sends it to the intrusion rules engine.
You can use CIP and ENIP keywords in custom intrusion rules to detect attacks in CIP and ENIP traffic.
Reference:
Both DNP3 and CIP preprocessors can be used to detect traffic anomalies but we choose CIP as it is widely used in industrial applications.
Note:
+ An intrusion rule is a specified set of keywords and arguments that the system uses to detect attempts to exploit vulnerabilities in your network. As the system analyzes network traffic, it compares packets against the conditions specified in each rule, and triggers the rule if the data packet meets all the conditions specified in the rule. + Preprocessor rules, which are rules associated with preprocessors and packet decoder detection options in the network analysis policy. Most preprocessor rules are disabled by default.
The Modbus, DNP3, and CIP SCADA preprocessors detect traffic anomalies and provide data to intrusion rules. Therefore in this question only answer A or answer C is correct.
The DNP3 preprocessor detects anomalies in DNP3 traffic and decodes the DNP3 protocol for processing by the rules engine, which uses DNP3 keywords to access certain protocol fields.
The Common Industrial Protocol (CIP) is a widely used application protocol that supports industrial automation applications. EtherNet/IP is an implementation of CIP that is used on Ethernet-based networks.The CIP preprocessor detects CIP and ENIP traffic running on TCP or UDP and sends it to the intrusion rules engine.
You can use CIP and ENIP keywords in custom intrusion rules to detect attacks in CIP and ENIP traffic.
Both DNP3 and CIP preprocessors can be used to detect traffic anomalies but we choose CIP as it is widely used in industrial applications.
Note:
Both DNP3 and CIP preprocessors can be used to detect traffic anomalies but we choose CIP as it is widely used in industrial applications.
Note:
+ An intrusion rule is a specified set of keywords and arguments that the system uses to detect attempts to exploit vulnerabilities in your network. As the system analyzes network traffic, it compares packets against the conditions specified in each rule, and triggers the rule if the data packet meets all the conditions specified in the rule. + Preprocessor rules, which are rules associated with preprocessors and packet decoder detection options in the network analysis policy. Most preprocessor rules are disabled by default.
NEW QUESTION 108
......
Cisco SCOR 350-701 Practice Test Questions, Cisco SCOR 350-701 Exam Practice Test Questions
Cisco 350-701 SCOR: Implementing and Operating Cisco Security Core Technologies is a qualifying exam associated with three certifications, namely CCIE Security, CCNP Security, and Cisco Certified Specialist – Security Core.
2022 New Preparation Guide of Cisco 350-701 Exam: https://vcepractice.pass4guide.com/350-701-dumps-questions.html