Pre-Winter Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

Cisco 350-701 - Implementing and Operating Cisco Security Core Technologies (SCOR 350-701 v2.0)

Page: 14 / 16
Total 801 questions

Which Cisco Umbrella package supports selective proxy for Inspection of traffic from risky domains?

A.

SIG Advantage

B.

DNS Security Essentials

C.

SIG Essentials

D.

DNS Security Advantage

An organization wants to provide visibility and to identify active threats in its network using a VM. The

organization wants to extract metadata from network packet flow while ensuring that payloads are not retained

or transferred outside the network. Which solution meets these requirements?

A.

Cisco Umbrella Cloud

B.

Cisco Stealthwatch Cloud PNM

C.

Cisco Stealthwatch Cloud PCM

D.

Cisco Umbrella On-Premises

Which Cisco product provides proactive endpoint protection and allows administrators to centrally manage the

deployment?

A.

NGFW

B.

AMP

C.

WSA

D.

ESA

What are two security benefits of an MDM deployment? (Choose two.)

A.

robust security policy enforcement

B.

privacy control checks

C.

on-device content management

D.

distributed software upgrade

E.

distributed dashboard

What is a difference between GRE over IPsec and IPsec with crypto map?

A.

Multicast traffic is supported by IPsec with crypto map.

B.

GRE over IPsec supports non-IP protocols.

C.

GRE provides its own encryption mechanism.

D.

IPsec with crypto map oilers better scalability.

Refer to the exhibit.

An engineer configured wired 802.1x on the network and is unable to get a laptop to authenticate. Which port configuration is missing?

A.

authentication open

B.

dotlx reauthentication

C.

cisp enable

D.

dot1x pae authenticator

When a transparent authentication fails on the Web Security Appliance, which type of access does the end user get?

A.

guest

B.

limited Internet

C.

blocked

D.

full Internet

Which two features of Cisco Email Security can protect your organization against email threats? (Choose two)

A.

Time-based one-time passwords

B.

Data loss prevention

C.

Heuristic-based filtering

D.

Geolocation-based filtering

E.

NetFlow

A large retail enterprise is deploying Cisco Secure Private Access to enable remote employees to reach internal applications without manual intervention. The IT department requires a seamless, zero-touch enrollment process in which users are registered and authenticated transparently without requiring end-user action. The architecture must support robust high availability for back-end connectivity to ensure continuous access to private resources. Which configuration approach must the administrator implement to meet the requirement?

A.

Implement ZTA with Certificate Enrollment and multiple Connector Groups associated with the private resource.

B.

Configure ZTA with SAML Enrollment and multiple Connector Groups associated with the private resource.

C.

Define a VPN Machine Tunnel with Certificate Enrollment and Connector Groups associated with the private resource.

D.

Apply ZTA with SAML Enrollment, including passwordless enrollment, and a single Connector associated with the private resource.

Which type of API is being used when a controller within a software-defined network architecture dynamically

makes configuration changes on switches within the network?

A.

westbound AP

B.

southbound API

C.

northbound API

D.

eastbound API

An administrator configures a new destination list in Cisco Umbrella so that the organization can block specific domains for its devices. What should be done to ensure that all subdomains of domain.com are blocked?

A.

Configure the *.com address in the block list.

B.

Configure the *.domain.com address in the block list

C.

Configure the *.domain.com address in the block list

D.

Configure the domain.com address in the block list

A financial services firm is concerned about employees inadvertently pasting sensitive customer account information into public generative AI websites. The security team needs to implement a solution that inspects outbound traffic and prevents the transmission of sensitive data to AI platforms. Which two configuration actions must the administrator perform on Cisco Secure Access to achieve the requirement? (Choose two.)

A.

Apply an AI Guardrail rule to block uploads to unauthorized AI domains.

B.

Implement a strict firewall rule to block all outbound traffic on port 443 for the entire organization.

C.

Disable all web-browser access for employees to prevent them from navigating to any external websites.

D.

Configure a DLP policy to inspect outbound traffic for sensitive data patterns.

E.

Enable the local endpoint firewall to block all traffic to known AI-service IP addresses.

What is the term for when an endpoint is associated to a provisioning WLAN that is shared with guest

access, and the same guest portal is used as the BYOD portal?

A.

single-SSID BYOD

B.

multichannel GUI

C.

dual-SSID BYOD

D.

streamlined access

An engineer is trying to securely connect to a router and wants to prevent insecure algorithms from being used.

However, the connection is failing. Which action should be taken to accomplish this goal?

A.

Disable telnet using the no ip telnet command.

B.

Enable the SSH server using the ip ssh server command.

C.

Configure the port using the ip ssh port 22 command.

D.

Generate the RSA key using the crypto key generate rsa command.

Refer to the exhibit. An engineer must configure an incoming mail policy so that each email sent from usera1@example.com to a domain of @cisco.com is scanned for antispam and advanced malware protection. All other settings will use the default behavior. What must be configured in the incoming mail policy to meet the requirements?

A.

Policy Name: Default Policy  Sender: usera1@example.com  Recipient: @cisco.com

B.

Policy Name: usera1 policy  Sender: usera1@example.com  Recipient: @cisco.com

C.

Policy Name: Anti-Malware policy  Sender: usera1@example.com  Recipient: @cisco.com

D.

Policy Name: cisco.com policy  Sender: usera1@example.com  Recipient: @cisco.com