Pre-Winter Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

Cisco 350-701 - Implementing and Operating Cisco Security Core Technologies (SCOR 350-701 v2.0)

Page: 1 / 16
Total 801 questions

What are two recommended approaches to stop DNS tunneling for data exfiltration and command and control call backs? (Choose two.)

A.

Use intrusion prevention system.

B.

Block all TXT DNS records.

C.

Enforce security over port 53.

D.

Use next generation firewalls.

E.

Use Cisco Umbrella.

Which Cisco platform onboards the endpoint and can issue a CA signed certificate while also automatically configuring endpoint network settings to use the signed endpoint certificate, allowing the endpoint to gain network access?

A.

Cisco ISE

B.

Cisco NAC

C.

Cisco TACACS+

D.

Cisco WSA

What is a characteristic of traffic storm control behavior?

A.

Traffic storm control drops all broadcast and multicast traffic if the combined traffic exceeds the level withinthe interval.

B.

Traffic storm control cannot determine if the packet is unicast or broadcast.

C.

Traffic storm control monitors incoming traffic levels over a 10-second traffic storm control interval.

D.

Traffic storm control uses the Individual/Group bit in the packet source address to determine if the packet isunicast or broadcast.

Which two capabilities of Cisco Secure Workload facilitate the detection of lateral movement within data-center and cloud environments? (Choose two.)

A.

Dynamic updates to firewall rules based on user access

B.

Integration with threat intelligence for identifying malicious IP addresses

C.

Automatic blocking of all inbound and outbound traffic

D.

Real-time visibility into communication patterns between workloads

E.

Recommendations for implementing VLANs for network segmentation

Which attack gives unauthorized access to files on the web server?

A.

Distributed DoS

B.

Broadcast storm

C.

DHCP snooping

D.

Path traversal

What is a key difference between Cisco Firepower and Cisco ASA?

A.

Cisco ASA provides access control while Cisco Firepower does not.

B.

Cisco Firepower provides identity-based access control while Cisco ASA does not.

C.

Cisco Firepower natively provides intrusion prevention capabilities while Cisco ASA does not.

D.

Cisco ASA provides SSL inspection while Cisco Firepower does not.

For Cisco IOS PKI, which two types of Servers are used as a distribution point for CRLs? (Choose two)

A.

SDP

B.

LDAP

C.

subordinate CA

D.

SCP

E.

HTTP

In a PaaS model, which layer is the tenant responsible for maintaining and patching?

A.

hypervisor

B.

virtual machine

C.

network

D.

application

An engineer configured a new network identity in Cisco Umbrella but must verify that traffic is being routed

through the Cisco Umbrella network. Which action tests the routing?

A.

Ensure that the client computers are pointing to the on-premises DNS servers.

B.

Enable the Intelligent Proxy to validate that traffic is being routed correctly.

C.

Add the public IP address that the client computers are behind to a Core Identity.

D.

Browse to http://welcome.umbrella.com/ to validate that the new identity is working.

Drag and drop the steps from the left into the correct order on the right to enable AppDynamics to monitor an EC2 instance in Amazon Web Services.

Which telemetry data captures variations seen within the flow, such as the packets TTL, IP/TCP flags, and payload length?

A.

interpacket variation

B.

software package variation

C.

flow insight variation

D.

process details variation

Drag and drop the concepts from the left onto the correct descriptions on the right

A network engineer must configure a Cisco Secure Email Gateway to prompt users to enter two forms of information before gaining access. The Secure Email Gateway must also join a cluster machine using preshared keys. What must be configured to meet these requirements?

A.

Enable two-factor authentication through a RADIUS server and then join the cluster by using the Secure Email Gateway CLI.

B.

Enable two-factor authentication through a TACACS+ server and then join the cluster by using the Secure Email Gateway CLI.

C.

Enable two-factor authentication through a RADIUS server and then join the cluster by using the Secure Email Gateway GUI.

D.

Enable two-factor authentication through a TACACS+ server and then join the cluster by using the Secure Email Gateway GUI.

Refer to the exhibit.

A network administrator configured a site-to-site VPN tunnel between two Cisco IOS routers, and hosts are unable to communicate between two sites of VPN. The network administrator runs the debug crypto isakmp sa command to track VPN status. What is the problem according to this command output?

A.

hashing algorithm mismatch

B.

encryption algorithm mismatch

C.

authentication key mismatch

D.

interesting traffic was not applied

Which two services are provided by the Cisco Talos Incident Response group? (Choose two.)

A.

Security policy authorization

B.

Bug identification

C.

Automatic vulnerability remediation

D.

Threat hunting

E.

Cyber range training