Cisco 350-701 - Implementing and Operating Cisco Security Core Technologies (SCOR 350-701 v2.0)
What does Cisco AMP for Endpoints use to help an organization detect different families of malware?
An engineer is configuring their router to send NetfFow data to Stealthwatch which has an IP address of 1 1 11 using the flow record Stea!thwatch406397954 command Which additional command is required to complete the flow record?
Refer to the exhibit.
=== Cisco Secure Endpoint - Detection Event ===
Endpoint : LAB-WKSTN-047 User: user1
Policy Group : Lab-Workstations Mode: Audit
Engine : ETHOS (fuzzy fingerprint)
Disposition : Malicious
File : C:\Users\user1\AppData\Local\Temp\svchost32.exe
SHA256 : 3a9f2c1d...e881b4a7
Parent Process: winword.exe
Threat Name : W32.Trojan.GenericKD.Agent
Retrospective : Previously UNKNOWN
Disposition changed to MALICIOUS at 09:31:55 UTC
File Activity : Created, Executed
Network : TCP outbound - > 91.205.188.47:4444
DNS query: c2-update.pharmadomain.ru
Quarantine : NOT quarantined (Audit mode active)
A security analyst at a pharmaceutical company is reviewing a Cisco Secure Endpoint malware-detection alert triggered on a laboratory workstation. The analyst observes the event data above. Which two things are occurring? (Choose two.)
A Cisco ISE engineer configures Central Web Authentication (CWA) for wireless guest access and must have the guest endpoints redirect to the guest portal for authentication and authorization. While testing the policy, the engineer notices that the device is not redirected and instead gets full guest access. What must be done for the redirect to work?
Which exfiltration method does an attacker use to hide and encode data inside DNS requests and queries?
Refer to the exhibit.
Traffic is not passing through IPsec site-to-site VPN on the Firepower Threat Defense appliance. What is causing this issue?
Refer to the exhibit. The DHCP snooping database resides on router R1, and dynamic ARP inspection is configured only on switch SW2. Which ports must be configured as untrusted so that dynamic ARP inspection operates normally?
A web hosting company must upgrade its older, unsupported on-premises servers. The company wants a cloud solution in which the cloud provider is responsible for:
Server patching
Application maintenance
Data center security
Disaster recovery
Which type of cloud meets the requirements?
Refer to the exhibit.
During the rollout of a new site-to-site VPN between a headquarters Cisco Secure Firewall Threat Defense device and a partner firewall, the tunnel never completes IKEv1 Phase 1 and remains in the MM_WAIT_MSG_6 state. Reachability between the firewalls over the Internet is verified, ISAKMP UDP port 500 is permitted end-to-end, and the IKE Phase 1 policy parameters—including encryption, hashing, DH group, and lifetime—match exactly on both ends. Which configuration action must be performed to resolve the issue?
What is the difference between a site-to-site VPN and a remote-access VPN?
Which attack is preventable by Cisco ESA but not by the Cisco WSA?
An engineer is implementing DHCP security mechanisms and needs the ability to add additional attributes to profiles that are created within Cisco ISE Which action accomplishes this task?
Which feature requires that network telemetry be enabled?
An engineer is adding a Cisco DUO solution to the current TACACS+ deployment using Cisco ISE. The engineer wants to authenticate users using their account when they log into network devices. Which action accomplishes this task?
What is the benefit of installing Cisco AMP for Endpoints on a network?
