350-701 Dumps Special Discount for limited time Try FOR FREE [Q264-Q286]

Share

350-701 Dumps Special Discount for limited time Try FOR FREE

350-701 Dumps for success in Actual Exam Jul-2023]


Cisco 350-701 exam consists of 90-110 multiple-choice and simulation questions, and it takes 120 minutes to complete. 350-701 exam is available in English and Japanese and can be taken at any Pearson VUE testing center or online. 350-701 exam fee is $400, and candidates must pass the exam to earn the Cisco Certified Specialist – Security Core certification.


Cisco 350-701 Exam Certification Details:

Exam NameImplementing and Operating Cisco Security Core Technologies
Passing ScoreVariable (750-850 / 1000 Approx.)
Sample QuestionsCisco 350-701 Sample Questions
Duration120 minutes
Exam RegistrationPEARSON VUE


The Cisco 350-701 exam covers a wide range of topics such as network security, cloud security, content security, endpoint protection and detection, secure network access, visibility and enforcement, and secure network architecture. It is a comprehensive exam that ensures candidates have a thorough understanding of various security technologies, tools, and techniques.

 

NEW QUESTION # 264
Which characteristic is unique to a Cisco WSAv as compared to a physical appliance?

  • A. requires an additional license
  • B. supports VMware vMotion on VMware ESXi
  • C. supports SSL decryption
  • D. performs transparent redirection

Answer: B


NEW QUESTION # 265
An engineer configured a new network identity in Cisco Umbrella but must verify that traffic is being routed through the Cisco Umbrella network. Which action tests the routing?

  • A. Add the public IP address that the client computers are behind to a Core Identity
  • B. Browse
    to http://welcome.umbrella.com/ to validate that the new identity is working
  • C. Ensure that the client computers are pointing to the on-premises DNS servers.
  • D. Enable the Intelligent Proxy to validate that traffic is being routed correctly.

Answer: B


NEW QUESTION # 266
An attacker needs to perform reconnaissance on a target system to help gain access to it. The system has weak passwords, no encryption on the VPN links, and software bugs on the system's applications. Which vulnerability allows the attacker to see the passwords being transmitted in clear text?

  • A. weak passwords for authentication
  • B. improper file security
  • C. unencrypted links for traffic
  • D. software bugs on applications

Answer: C


NEW QUESTION # 267
Which two deployment model configurations are supported for Cisco FTDv in AWS? (Choose two.)

  • A. Cisco FTDv configured in routed mode and IPv6 configured
  • B. Cisco FTDv with two management interfaces and one traffic interface configured
  • C. . Cisco FTDv configured in routed mode and managed by a physical FMC appliance on premises
  • D. Cisco FTDv with one management interface and two traffic interfaces configured
  • E. Cisco FTDv configured in routed mode and managed by an FMCv installed in AWS

Answer: C,E


NEW QUESTION # 268
Drag and drop the suspicious patterns for the Cisco Tetration platform from the left onto the correct definitions on the right.

Answer:

Explanation:

Explanation


https://www.cisco.com/c/en/us/products/collateral/data-center-analytics/tetration-analytics/white-paper-c11-7403


NEW QUESTION # 269
Refer to the exhibit.
What is a result of the configuration?

  • A. Traffic from the inside network is redirected
  • B. All TCP traffic is redirected
  • C. Traffic from the DMZ network is redirected
  • D. Traffic from the inside and DMZ networks is redirected

Answer: D

Explanation:
The purpose of above commands is to redirect traffic that matches the ACL "redirect-acl" to the Cisco FirePOWER (SFR) module in the inline (normal) mode. In this mode, after the undesired traffic is dropped and any other actions that are applied by policy are performed, the traffic is returned to the ASA for further processing and ultimate transmission. The command "service-policy global_policy global" applies the policy to all of the interfaces. Reference: https://www.cisco.com/c/en/us/support/docs/security/asa-firepower-services/118644-configurefirepower-00.html FirePOWER (SFR) module in the inline (normal) mode. In this mode, after the undesired traffic is dropped and any other actions that are applied by policy are performed, the traffic is returned to the ASA for further processing and ultimate transmission.
The command "service-policy global_policy global" applies the policy to all of the interfaces.
The purpose of above commands is to redirect traffic that matches the ACL "redirect-acl" to the Cisco FirePOWER (SFR) module in the inline (normal) mode. In this mode, after the undesired traffic is dropped and any other actions that are applied by policy are performed, the traffic is returned to the ASA for further processing and ultimate transmission. The command "service-policy global_policy global" applies the policy to all of the interfaces. Reference: https://www.cisco.com/c/en/us/support/docs/security/asa-firepower-services/118644-configurefirepower-00.html


NEW QUESTION # 270
Which type of DNS abuse exchanges data between two computers even when there is no direct connection?

  • A. Network footprinting
  • B. Data exfiltration
  • C. Command-and-control communication
  • D. Malware installation

Answer: B

Explanation:
Malware installation: This may be done by hijacking DNS queries and responding with malicious IP addresses.
Command & Control communication: As part of lateral movement, after an initial compromise, DNS communications is abused to communicate with a C2 server. This typically involves making periodic DNS queries from a computer in the target network for a domain controlled by the adversary. The responses contain encoded messages that may be used to perform unauthorized actions in the target network.
Network footprinting: Adversaries use DNS queries to build a map of the network. Attackers live off the terrain so developing a map is important to them.
Data theft (exfiltration): Abuse of DNS to transfer data; this may be performed by tunneling other protocols like FTP, SSH through DNS queries and responses. Attackers make multiple DNS queries from a compromised computer to a domain owned by the adversary. DNS tunneling can also be used for executing commands and transferring malware into the target network.


NEW QUESTION # 271
Which two aspects of the cloud PaaS model are managed by the customer but not the provider? (Choose two.)

  • A. middleware
  • B. virtualization
  • C. applications
  • D. data
  • E. operating systems

Answer: C,D

Explanation:
Reference:
https://apprenda.com/library/paas/iaas-paas-saas-explained-compared/


NEW QUESTION # 272
A Cisco FTD engineer is creating a new IKEv2 policy called s2s00123456789 for their organization to allow for additional protocols to terminate network devices with. They currently only have one policy established and need the new policy to be a backup in case some devices cannot support the stronger algorithms listed in the primary policy. What should be done in order to support this?

  • A. Change the integrity algorithms to SHA* to support all SHA algorithms in the primary policy
  • B. Make the priority for the new policy 5 and the primary policy 1
  • C. Change the encryption to AES* to support all AES algorithms in the primary policy
  • D. Make the priority for the primary policy 10 and the new policy 1

Answer: B

Explanation:
All IKE policies on the device are sent to the remote peer regardless of what is in the selected policy section. The first IKE Policy matched by the remote peer will be selected for the VPN connection. Choose which policy is sent first using the priority field. Priority 1 will be sent first. Reference: https://www.cisco.com/c/en/us/support/docs/security-vpn/ipsec-negotiation-ike-protocols/215470- site-to-site-vpn-configuration-on-ftd-ma.html The first IKE Policy matched by the remote peer will be selected for the VPN connection. Choose which policy is sent first using the priority field. Priority 1 will be sent first.
All IKE policies on the device are sent to the remote peer regardless of what is in the selected policy section. The first IKE Policy matched by the remote peer will be selected for the VPN connection. Choose which policy is sent first using the priority field. Priority 1 will be sent first. Reference: https://www.cisco.com/c/en/us/support/docs/security-vpn/ipsec-negotiation-ike-protocols/215470- site-to-site-vpn-configuration-on-ftd-ma.html


NEW QUESTION # 273
Which two key and block sizes are valid for AES? (Choose two)

  • A. 64-bit block size, 112-bit key length
  • B. 192-bit block size, 256-bit key length
  • C. 64-bit block size, 168-bit key length
  • D. 128-bit block size, 192-bit key length
  • E. 128-bit block size, 256-bit key length

Answer: D,E

Explanation:
The AES encryption algorithm encrypts and decrypts data in blocks of 128 bits (block size). It can do this using 128-bit, 192-bit, or 256-bit keys


NEW QUESTION # 274
An organization is receiving SPAM emails from a known malicious domain. What must be configured in order to prevent the session during the initial TCP communication?

  • A. Configure policies to stop and reject communication
  • B. Configure the Cisco ESA to drop the malicious emails
  • C. Configure the Cisco ESA to reset the TCP connection
  • D. Configure policies to quarantine malicious emails

Answer: B


NEW QUESTION # 275
In which type of attack does the attacker insert their machine between two hosts that are communicating with each other?

  • A. cross-site scripting
  • B. man-in-the-middle
  • C. LDAP injection
  • D. insecure API

Answer: B


NEW QUESTION # 276
Drag and drop the concepts from the left onto the correct descriptions on the right

Answer:

Explanation:


NEW QUESTION # 277
Which attack is preventable by Cisco ESA but not by the Cisco WSA?

  • A. SQL injection
  • B. DoS
  • C. phishing
  • D. buffer overflow

Answer: C

Explanation:
Explanation
The following are the benefits of deploying Cisco Advanced Phishing Protection on the Cisco Email Security Gateway:
Prevents the following:
+ Attacks that use compromised accounts and social engineering.
+ Phishing, ransomware, zero-day attacks and spoofing.
+ BEC with no malicious payload or URL.
Reference:
/b_ESA_Admin_Guide_13-5/m_advanced_phishing_protection.html


NEW QUESTION # 278
An engineer needs to detect and quarantine a file named abc424400664 zip based on the MD5 signature of the file using the Outbreak Control list feature within Cisco Advanced Malware Protection (AMP) for Endpoints The configured detection method must work on files of unknown disposition Which Outbreak Control list must be configured to provide this?

  • A. Advanced Custom Detection
  • B. Simple Custom Detection
  • C. Blocked Application
  • D. Android Custom Detection

Answer: A


NEW QUESTION # 279
Drag and drop the NetFlow export formats from the left onto the descriptions on the right.

Answer:

Explanation:

:


NEW QUESTION # 280
An email administrator is setting up a new Cisco ESA. The administrator wants to enable the blocking of greymail for the end user. Which feature must the administrator enable first?

  • A. IP Reputation Filtering
  • B. Intelligent Multi-Scan
  • C. Anti-Virus Filtering
  • D. File Analysis

Answer: B


NEW QUESTION # 281
An engineer wants to generate NetFlow records on traffic traversing the Cisco ASA.
Which Cisco ASA command must be used?

  • A. flow-export destination inside 1.1.1.1 2055
  • B. ip flow-export destination 1.1.1.1 2055
  • C. ip flow monitor input
  • D. flow exporter

Answer: A

Explanation:
The syntax of this command is: flow-export destination interface-name ipv4-address | hostname udp-port This command is used on Cisco ASA to configure Network Secure Event Logging (NSEL) collector to which NetFlow packets are sent. The destination keyword indicates that a NSEL collector is being configured. + The interface-name argument is the name of the ASA and ASA Services Module interface through which the collector is reached. + The ipv4-address argument is the IP address of the machine running the collector application. + The hostname argument is the destination IP address or name of the collector. + The udp-port argument is the UDP port number to which NetFlow packets are sent. You can configure a maximum of five collectors. After a collector is configured, template records are automatically sent to all configured NSEL collectors. Reference: https://www.cisco.com/c/en/us/td/docs/security/asa/asa84/configuration/guide/asa_84_cli_config/ monitor_nsel.html This command is used on Cisco ASA to configure Network Secure Event Logging (NSEL) collector to which NetFlow packets are sent. The destination keyword indicates that a NSEL collector is being configured.
+ The interface-name argument is the name of the ASA and ASA Services Module interface through which the collector is reached.
+ The ipv4-address argument is the IP address of the machine running the collector application.
+ The hostname argument is the destination IP address or name of the collector.
+ The udp-port argument is the UDP port number to which NetFlow packets are sent.
You can configure a maximum of five collectors. After a collector is configured, template records are automatically sent to all configured NSEL collectors.
Reference:
The syntax of this command is: flow-export destination interface-name ipv4-address | hostname udp-port This command is used on Cisco ASA to configure Network Secure Event Logging (NSEL) collector to which NetFlow packets are sent. The destination keyword indicates that a NSEL collector is being configured. + The interface-name argument is the name of the ASA and ASA Services Module interface through which the collector is reached. + The ipv4-address argument is the IP address of the machine running the collector application. + The hostname argument is the destination IP address or name of the collector. + The udp-port argument is the UDP port number to which NetFlow packets are sent. You can configure a maximum of five collectors. After a collector is configured, template records are automatically sent to all configured NSEL collectors. Reference: https://www.cisco.com/c/en/us/td/docs/security/asa/asa84/configuration/guide/asa_84_cli_config/ monitor_nsel.html


NEW QUESTION # 282
What does Cisco AMP for Endpoints use to help an organization detect different families of malware?

  • A. Ethos Engine to perform fuzzy fingerprinting
  • B. Clam AV Engine to perform email scanning
  • C. Spero Engine with machine learning to perform dynamic analysis
  • D. Tetra Engine to detect malware when me endpoint is connected to the cloud

Answer: A

Explanation:
Explanation
ETHOS is the Cisco file grouping engine. It allows us to group families of files together so if we see variants of a malware, we mark the ETHOS hash as malicious and whole families of malware are instantly detected.
Reference:
ETHOS = Fuzzy Fingerprinting using static/passive heuristics


NEW QUESTION # 283
A Cisco Firepower administrator needs to configure a rule to allow a new application that has never been seen on the network. Which two actions should be selected to allow the traffic to pass without inspection? (Choose two.)

  • A. monitor
  • B. permit
  • C. reset
  • D. trust
  • E. allow

Answer: D,E

Explanation:
Explanation


NEW QUESTION # 284
In which two ways does Easy Connect help control network access when used with Cisco TrustSec? (Choose two)

  • A. It allows for managed endpoints that authenticate to AD to be mapped to Security Groups (PassiveID).
  • B. It allows multiple security products to share information and work together to enhance security posture in the network.
  • C. It integrates with third-party products to provide better visibility throughout the network.
  • D. It allows for the assignment of Security Group Tags and does not require 802.1x to be configured on the switch or the endpoint.
  • E. It creates a dashboard in Cisco ISE that provides full visibility of all connected endpoints.

Answer: A,D

Explanation:
Easy Connect simplifies network access control and segmentation by allowing the assignment of Security Group Tags to endpoints without requiring 802.1X on those endpoints, whether using wired or wireless connectivity. Reference: https://www.cisco.com/c/dam/en/us/solutions/collateral/enterprise-networks/trustsec/trustsec-witheasy-connect-configuration-guide.pdf Group Tags to endpoints without requiring 802.1X on those endpoints, whether using wired or wireless connectivity.
Easy Connect simplifies network access control and segmentation by allowing the assignment of Security Group Tags to endpoints without requiring 802.1X on those endpoints, whether using wired or wireless connectivity. Reference: https://www.cisco.com/c/dam/en/us/solutions/collateral/enterprise-networks/trustsec/trustsec-witheasy-connect-configuration-guide.pdf


NEW QUESTION # 285
An engineer has enabled LDAP accept queries on a listener. Malicious actors must be prevented from quickly identifying all valid recipients. What must be done on the Cisco ESA to accomplish this goal?

  • A. Use Bounce Verification
  • B. Configure Directory Harvest Attack Prevention
  • C. Configure incoming content filters.
  • D. Bypass LDAP access queries in the recipient access table.

Answer: B

Explanation:
Reference:


NEW QUESTION # 286
......

Accurate 350-701 Answers 365 Days Free Updates: https://endexam.2pass4sure.com/CCNPSecurity/350-701-actual-exam-braindumps.html