BEST Verified Cisco 350-701 Exam Questions (2024) [Q152-Q170]

Share

BEST Verified Cisco 350-701 Exam Questions (2024) 

The Best Practice Test Preparation for the 350-701 Certification Exam


Cisco 350-701 exam is a certification that validates the skills and knowledge of professionals who are responsible for implementing and operating Cisco Security Core Technologies. 350-701 exam is designed to test the candidate's understanding of security protocols, tools, and technologies that are used to secure networks against potential threats. Implementing and Operating Cisco Security Core Technologies certification is highly respected in the IT industry and is recognized globally.


Cisco 350-701 certification exam is an excellent option for security professionals who wish to validate their knowledge and expertise in implementing and operating Cisco security core technologies. Implementing and Operating Cisco Security Core Technologies certification is globally recognized, highly respected, and covers a broad range of topics that are essential for security professionals to ensure the security of their networks and devices. Candidates who pass the exam can enhance their career prospects and demonstrate their competency in the field of network security.


Cisco 350-701 exam is designed to test the individual’s knowledge on various security technologies such as network security, cloud security, endpoint protection, and secure network access. 350-701 exam covers a wide range of topics, including network security architecture, secure network design, secure protocols, secure remote access, and endpoint security. By passing 350-701 exam, the candidate demonstrates their proficiency in securing network infrastructures and their ability to handle security issues that arise.

 

NEW QUESTION # 152
Which telemetry data captures variations seen within the flow, such as the packets TTL, IP/TCP flags, and payload length?

  • A. flow insight variation
  • B. software package variation
  • C. interpacket variation
  • D. process details variation

Answer: C

Explanation:
The telemetry information consists of three types of data: + Flow information: This information contains details about endpoints, protocols, ports, when the flow started, how long the flow was active, etc. + Interpacket variation: This information captures any interpacket variations within the flow. Examples include variation in Time To Live (TTL), IP and TCP flags, payload length, etc + Context details: Context information is derived outside the packet header. It includes details about variation in buffer utilization, packet drops within a flow, association with tunnel endpoints, etc. Reference: https://www.cisco.com/c/dam/global/en_uk/products/switches/ cisco_nexus_9300_ex_platform_switches_white_paper_uki.pdf
+ Flow information: This information contains details about endpoints, protocols, ports, when the flow started, how long the flow was active, etc.
+ Interpacket variation: This information captures any interpacket variations within the flow. Examples include variation in Time To Live (TTL), IP and TCP flags, payload length, etc
+ Context details: Context information is derived outside the packet header. It includes details about variation in buffer utilization, packet drops within a flow, association with tunnel endpoints, etc.
Reference:
The telemetry information consists of three types of data: + Flow information: This information contains details about endpoints, protocols, ports, when the flow started, how long the flow was active, etc. + Interpacket variation: This information captures any interpacket variations within the flow. Examples include variation in Time To Live (TTL), IP and TCP flags, payload length, etc + Context details: Context information is derived outside the packet header. It includes details about variation in buffer utilization, packet drops within a flow, association with tunnel endpoints, etc. Reference: https://www.cisco.com/c/dam/global/en_uk/products/switches/ cisco_nexus_9300_ex_platform_switches_white_paper_uki.pdf


NEW QUESTION # 153
Using Cisco Firepower's Security Intelligence policies, upon which two criteria is Firepower block based?
(Choose two)

  • A. URLs
  • B. MAC addresses
  • C. protocol IDs
  • D. IP addresses
  • E. port numbers

Answer: A,D

Explanation:
Explanation Explanation Security Intelligence Sources ... Custom Block lists or feeds (or objects or groups) Block specific IP addresses, URLs, or domain names using a manually-created list or feed (for IP addresses, you can also use network objects or groups.) For example, if you become aware of malicious sites or addresses that are not yet blocked by a feed, add these sites to a custom Security Intelligence list and add this custom list to the Block list in the Security Intelligence tab of your access control policy. Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/623/configuration/guide/fpmc-configguide-v623/security_intelligence_blacklisting.html Explanation Security Intelligence Sources
...
Custom Block lists or feeds (or objects or groups)
Block specific IP addresses, URLs, or domain names using a manually-created list or feed (for IP addresses, you can also use network objects or groups.) For example, if you become aware of malicious sites or addresses that are not yet blocked by a feed, add these sites to a custom Security Intelligence list and add this custom list to the Block list in the Security Intelligence tab of your access control policy.
Explanation Explanation Security Intelligence Sources ... Custom Block lists or feeds (or objects or groups) Block specific IP addresses, URLs, or domain names using a manually-created list or feed (for IP addresses, you can also use network objects or groups.) For example, if you become aware of malicious sites or addresses that are not yet blocked by a feed, add these sites to a custom Security Intelligence list and add this custom list to the Block list in the Security Intelligence tab of your access control policy. Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/623/configuration/guide/fpmc-configguide-v623/security_intelligence_blacklisting.html


NEW QUESTION # 154
What is a capability of Cisco ASA Netflow?

  • A. It sends NetFlow data records from active and standby ASAs in an active standby failover pair.
  • B. It filters NSEL events based on traffic.
  • C. It generates NSEL events even if the MPF is not configured.
  • D. It logs ll event types only to the same collector.

Answer: B


NEW QUESTION # 155
What are the two most commonly used authentication factors in multifactor authentication? (Choose two.)

  • A. knowledge factor
  • B. encryption factor
  • C. time factor
  • D. biometric factor
  • E. confidentiality factor

Answer: A,D


NEW QUESTION # 156
Which policy is used to capture host information on the Cisco Firepower Next Generation Intrusion Prevention System?

  • A. Network Discovery
  • B. Intrusion
  • C. Access Control
  • D. Correlation

Answer: A

Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-configguide-v64/introdu


NEW QUESTION # 157
Refer to the exhibit.

A network engineer is testing NTP authentication and realizes that any device synchronizes time with this router and that NTP authentication is not enforced What is the cause of this issue?

  • A. NTP authentication is not enabled.
  • B. The router was not rebooted after the NTP configuration updated.
  • C. The key was configured in plain text.
  • D. The hashing algorithm that was used was MD5. which is unsupported.

Answer: A


NEW QUESTION # 158
Which algorithm provides asymmetric encryption?

  • A. RSA
  • B. 3DES
  • C. RC4
  • D. AES

Answer: A

Explanation:
Reference:
https://securityboulevard.com/2020/05/types-of-encryption-5-encryption-algorithms-how-to-choose-the-right-one/#:~:text=Standard%20asymmetric%20encryption%20algorithms%20include,%2C%20El%20Gamal%2C%20and%20DSA.


NEW QUESTION # 159
Drag and drop the descriptions from the left onto the correct protocol versions on the right.

Answer:

Explanation:

Explanation


NEW QUESTION # 160
After a recent breach, an organization determined that phishing was used to gain initial access to the network before regaining persistence. The information gained from the phishing attack was a result of users visiting known malicious websites. What must be done in order to prevent this from happening in the future?

  • A. Modify outbound malware scanning policies
  • B. Modify web proxy settings
  • C. Modify an access policy
  • D. Modify identification profiles

Answer: C

Explanation:
URL conditions in access control rules allow you to limit the websites that users on your network can access. This feature is called URL filtering. There are two ways you can use access control to specify URLs you want to block (or, conversely, allow):
- With any license, you can manually specify individual URLs, groups of URLs, and URL lists and feeds to achieve granular, custom control over web traffic.
- With a URL Filtering license, you can also control access to websites based on the URL's general classification, or category, and risk level, or reputation. The system displays this category and reputation data in connection logs, intrusion events, and application details.
Using category and reputation data also simplifies policy creation and administration. It grants you assurance that the system will control web traffic as expected. Finally, because Cisco's threat intelligence is continually updated with new URLs, as well as new categories and risks for existing URLs, you can ensure that the system uses up-to-date information to filter requested URLs. Malicious sites that represent security threats such as malware, spam, botnets, and phishing may appear and disappear faster than you can update and deploy new policies.
Reference:
- With any license, you can manually specify individual URLs, groups of URLs, and URL lists and feeds to achieve granular, custom control over web traffic.
- With a URL Filtering license, you can also control access to websites based on the URL's general classification, or category, and risk level, or reputation. The system displays this category and reputation data in connection logs, intrusion events, and application details.
Using category and reputation data also simplifies policy creation and administration. It grants you assurance that the system will control web traffic as expected. Finally, because Cisco's threat intelligence is continually updated with new URLs, as well as new categories and risks for existing URLs, you can ensure that the system uses up-to-date information to filter requested URLs. Malicious sites that represent security threats such as malware, spam, botnets, and phishing may appear and disappear faster than you can update and deploy new policies.
URL conditions in access control rules allow you to limit the websites that users on your network can access. This feature is called URL filtering. There are two ways you can use access control to specify URLs you want to block (or, conversely, allow):
- With any license, you can manually specify individual URLs, groups of URLs, and URL lists and feeds to achieve granular, custom control over web traffic.
- With a URL Filtering license, you can also control access to websites based on the URL's general classification, or category, and risk level, or reputation. The system displays this category and reputation data in connection logs, intrusion events, and application details.
Using category and reputation data also simplifies policy creation and administration. It grants you assurance that the system will control web traffic as expected. Finally, because Cisco's threat intelligence is continually updated with new URLs, as well as new categories and risks for existing URLs, you can ensure that the system uses up-to-date information to filter requested URLs. Malicious sites that represent security threats such as malware, spam, botnets, and phishing may appear and disappear faster than you can update and deploy new policies.


NEW QUESTION # 161
What is the benefit of integrating Cisco ISE with a MDM solution?

  • A. It provides compliance checks for access to the network
  • B. It provides network device administration access
  • C. It provides the ability to update other applications on the mobile device
  • D. It provides the ability to add applications to the mobile device through Cisco ISE

Answer: A

Explanation:
Explanation https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ISE_admin_guide_24/ m_ise_interoperability_mdm.html
https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ISE_admin_guide_24/ Explanation https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ISE_admin_guide_24/ m_ise_interoperability_mdm.html


NEW QUESTION # 162
A network engineer has been tasked with adding a new medical device to the network. Cisco ISE is being used as the NAC server, and the new device does not have a supplicant available. What must be done in order to securely connect this device to the network?

  • A. Use MAB with posture assessment.
  • B. Use MAB with profiling
  • C. Use 802.1X with profiling.
  • D. Use 802.1X with posture assessment.

Answer: B

Explanation:
Explanation
As the new device does not have a supplicant, we cannot use 802.1X.
MAC Authentication Bypass (MAB) is a fallback option for devices that don't support 802.1x. It is virtually always used in deployments in some way shape or form. MAB works by having the authenticator take the connecting device's MAC address and send it to the authentication server as its username and password. The authentication server will check its policies and send back an Access-Accept or Access-Reject just like it would with 802.1x.
Cisco ISE Profiling Services provides dynamic detection and classification of endpoints connected to the network. Using MAC addresses as the unique identifier, ISE collects various attributes for each network endpoint to build an internal endpoint database. The classification process matches the collected attributes to prebuilt or user-defined conditions, which are then correlated to an extensive library of profiles. These profiles include a wide range of device types, including mobile clients (iPads, Android tablets, Chromebooks, and so on), desktop operating systems (for example, Windows, Mac OS X, Linux, and others), and numerous non-user systems such as printers, phones, cameras, and game consoles.
Once classified, endpoints can be authorized to the network and granted access based on their profile. For example, endpoints that match the IP phone profile can be placed into a voice VLAN using MAC Authentication Bypass (MAB) as the authentication method. Another example is to provide differentiated network access to users based on the device used. For example, employees can get full access when accessing the network from their corporate workstation but be granted limited network access when accessing the network from their personal iPhone.


NEW QUESTION # 163
Drag and drop the capabilities of Cisco Firepower versus Cisco AMP from the left into the appropriate category on the right.

Answer:

Explanation:


NEW QUESTION # 164
Which type of data does the Cisco Stealthwatch system collect and analyze from routers, switches, and firewalls?

  • A. NTP
  • B. syslog
  • C. SNMP
  • D. NetFlow

Answer: D


NEW QUESTION # 165
How does DNS Tunneling exfiltrate data?

  • A. An attacker sends an email to the target with hidden DNS resolvers in it to redirect them to a malicious domain.
  • B. An attacker registers a domain that a client connects to based on DNS records and sends malware through that connection.
  • C. An attacker opens a reverse DNS shell to get into the client's system and install malware on it.
  • D. An attacker uses a non-standard DNS port to gain access to the organization's DNS servers in order to poison the resolutions.

Answer: B

Explanation:
DNS tunneling is a technique that exploits the DNS protocol to tunnel malware and other data through a client-server model. DNS tunneling can be used for data exfiltration, command and control, or IP-over-DNS tunneling. DNS tunneling works by encoding the information of other protocols or programs in DNS queries and responses. An attacker registers a domain, such as badsite.com, and sets up a malicious DNS server that can interpret the encoded data. The attacker then infects a client with malware that can send and receive DNS queries to the attacker's domain. The malware can use DNS queries to request commands from the attacker, or to send sensitive data to the attacker. The DNS queries and responses look like normal DNS traffic, but they contain hidden data that can bypass network defenses123. References := 1: What Is DNS Tunneling? - Palo Alto Networks 2: What is DNS Tunneling? - Check Point Software 3: What Is DNS Tunneling and How to Detect and Prevent Attacks


NEW QUESTION # 166
Which Cisco ISE feature helps to detect missing patches and helps with remediation?

  • A. profiling policy
  • B. authentication policy
  • C. enabling probes
  • D. posture assessment

Answer: D

Explanation:
Posture assessment is a feature of Cisco ISE that allows you to check the compliance of endpoints with corporate security policies before allowing them to access the network1. Posture assessment can detect missing patches on endpoints and help with remediation by applying the appropriate posture policy and requirement2. Posture assessment can also check for the presence and status of security software, such as antivirus, antispyware, firewall, and so on3. Posture assessment is one of the core security technologies covered in the Implementing and Operating Cisco Security Core Technologies (SCOR) course4, which prepares you for the Cisco CCNP Security and CCIE Security certifications and for senior-level security roles. References: 1: Posture Service 2: Configure Posture Policies 3: Posture Conditions 4: Implementing and Operating Cisco Security Core Technologies (SCOR) v1.0


NEW QUESTION # 167
What are two functions of TAXII in threat intelligence sharing? (Choose two.)

  • A. determines the "what" of threat intelligence
  • B. exchanges trusted anomaly intelligence information
  • C. allows users to describe threat motivations and abilities
  • D. determines how threat intelligence information is relayed
  • E. Supports STIX information

Answer: D,E

Explanation:
TAXII, short for Trusted Automated eXchange of Intelligence Information, is a protocol that defines how cyber threat information can be shared via services and message exchanges. It is designed specifically to support STIX information, which is a standardized language for expressing and exchanging cyber threat information. TAXII enables organizations to share STIX information by defining an API that aligns with common sharing models, such as hub and spoke, source/subscriber, and peer-to-peer. TAXII also defines four services that allow users to discover, manage, receive, and request STIX information. Therefore, TAXII supports STIX information and determines how threat intelligence information is relayed. TAXII does not determine the "what" of threat intelligence, as that is the role of STIX. TAXII does not allow users to describe threat motivations and abilities, as that is also part of STIX. TAXII does not exchange trusted anomaly intelligence information, as that is a specific type of threat intelligence that may or may not be represented in STIX. References:
* What are STIX/TAXII Standards I Resources I Anomali
* Cyber Threat Intelligence Technical Committee - GitHub Pages


NEW QUESTION # 168
An administrator configures a Cisco WSA to receive redirected traffic over ports 80 and 443. The organization requires that a network device with specific WSA integration capabilities be configured to send the traffic to the WSA to proxy the requests and increase visibility, while making this invisible to the users. What must be done on the Cisco WSA to support these requirements?

  • A. Use PAC keys to allow only the required network devices to send the traffic to the Cisco WSA
  • B. Use the Layer 4 setting in the Cisco WSA to receive explicit forward requests from the network device
  • C. Configure active traffic redirection using WPAD in the Cisco WSA and on the network device
  • D. Configure transparent traffic redirection using WCCP in the Cisco WSA and on the network device

Answer: D


NEW QUESTION # 169
How does Cisco Advanced Phishing Protection protect users?

  • A. It uses machine learning and real-time behavior analytics.
  • B. It utilizes sensors that send messages securely.
  • C. It validates the sender by using DKIM.
  • D. It determines which identities are perceived by the sender

Answer: A

Explanation:
Cisco Advanced Phishing Protection provides sender authentication and BEC detection capabilities. It uses advanced machine learning techniques, real-time behavior analytics, relationship modeling, and telemetry to protect against identity deception-based threats. Reference: https://docs.ces.cisco.com/docs/advanced-phishing-protection Cisco Advanced Phishing Protection provides sender authentication and BEC detection capabilities. It uses advanced machine learning techniques, real-time behavior analytics, relationship modeling, and telemetry to protect against identity deception-based threats. Reference: https://docs.ces.cisco.com/docs/advanced-phishing-protection


NEW QUESTION # 170
......

350-701 Exam Dumps, Practice Test Questions BUNDLE PACK: https://braindumps.exam4tests.com/350-701-pdf-braindumps.html