Summer Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exams65

ExamsBrite Dumps

Implementing and Operating Cisco Security Core Technologies (SCOR 350-701 v2.0) Question and Answers

Implementing and Operating Cisco Security Core Technologies (SCOR 350-701 v2.0)

Last Update Sep 16, 2026
Total Questions : 801

We are offering FREE 350-701 Cisco exam questions. All you do is to just go and sign up. Give your details, prepare 350-701 free exam questions and then go for complete pool of Implementing and Operating Cisco Security Core Technologies (SCOR 350-701 v2.0) test questions that will help you more.

350-701 pdf

350-701 PDF

$40.25  $114.99
350-701 Engine

350-701 Testing Engine

$47.25  $134.99
350-701 PDF + Engine

350-701 PDF + Testing Engine

$61.25  $174.99
Questions 1

How does Cisco Stealthwatch Cloud provide security for cloud environments?

Options:

A.  

It delivers visibility and threat detection.

B.  

It prevents exfiltration of sensitive data.

C.  

It assigns Internet-based DNS protection for clients and servers.

D.  

It facilitates secure connectivity between public and private networks.

Discussion 0
Questions 2

What is the difference between a vulnerability and an exploit?

Options:

A.  

A vulnerability is a hypothetical event for an attacker to exploit

B.  

A vulnerability is a weakness that can be exploited by an attacker

C.  

An exploit is a weakness that can cause a vulnerability in the network

D.  

An exploit is a hypothetical event that causes a vulnerability in the network

Discussion 0
Questions 3

A network engineer has configured a NTP server on a Cisco ASA. The Cisco ASA has IP reachability to the

NTP server and is not filtering any traffic. The show ntp association detail command indicates that the

configured NTP server is unsynchronized and has a stratum of 16. What is the cause of this issue?

Options:

A.  

Resynchronization of NTP is not forced

B.  

NTP is not configured to use a working server.

C.  

An access list entry for UDP port 123 on the inside interface is missing.

D.  

An access list entry for UDP port 123 on the outside interface is missing.

Discussion 0
Questions 4

Refer to the exhibit.

Which command was used to display this output?

Options:

A.  

show dot1x all

B.  

show dot1x

C.  

show dot1x all summary

D.  

show dot1x interface gi1/0/12

Discussion 0
Questions 5

A company is experiencing exfiltration of credit card numbers that are not being stored on-premise. The

company needs to be able to protect sensitive data throughout the full environment. Which tool should be used

to accomplish this goal?

Options:

A.  

Security Manager

B.  

Cloudlock

C.  

Web Security Appliance

D.  

Cisco ISE

Discussion 0
Questions 6

Drag and drop the NetFlow export formats from the left onto the descriptions on the right.

Options:

Discussion 0
Questions 7

When Cisco and other industry organizations publish and inform users of known security findings and

vulnerabilities, which name is used?

Options:

A.  

Common Security Exploits

B.  

Common Vulnerabilities and Exposures

C.  

Common Exploits and Vulnerabilities

D.  

Common Vulnerabilities, Exploits and Threats

Discussion 0
Questions 8

What is a benefit of using telemetry over SNMP to configure new routers for monitoring purposes?

Options:

A.  

Telemetry uses a pull mehod, which makes it more reliable than SNMP

B.  

Telemetry uses push and pull, which makes it more scalable than SNMP

C.  

Telemetry uses push and pull which makes it more secure than SNMP

D.  

Telemetry uses a push method which makes it faster than SNMP

Discussion 0
Questions 9

A security engineer must configure a Splunk Universal Forwarder to send network traffic logs from Cisco Catalyst switches to a Splunk indexer cluster. Strict compliance requirements require all network traffic logs to be ingested into Splunk as an audit trail. The environment includes thousands of forwarders, and the data must be distributed across all indexers. Which two configuration actions must be performed? (Choose two.)

Options:

A.  

Configure outputs.conf with the DNS names and indexing ports of all indexers within the cluster.

B.  

Implement a large output queue in outputs.conf and disable automatic load balancing.

C.  

Configure the forwarder to write logs to a local file share and schedule a batch job to copy the data into the indexers.

D.  

Use a deployment server to push an application containing outputs.conf to all Universal Forwarders.

E.  

Configure a single primary indexer in outputs.conf and enable a forced connection.

Discussion 0
Questions 10

How does Cisco Secure Endpoint provide next-generation protection?

Options:

A.  

It integrates with Cisco FTD devices.

B.  

It encrypts data on user endpoints to protect against ransomware.

C.  

It leverages an endpoint protection platform and endpoint detection and response.

D.  

It utilizes Cisco pxGrid, which allows Secure Endpoint to pull threat feeds from threat intelligence centers.

Discussion 0
Questions 11

What does endpoint isolation in Cisco AMP for Endpoints security protect from?

Options:

A.  

an infection spreading across the network E

B.  

a malware spreading across the user device

C.  

an infection spreading across the LDAP or Active Directory domain from a user account

D.  

a malware spreading across the LDAP or Active Directory domain from a user account

Discussion 0
Questions 12

An administrator needs to configure the Cisco ASA via ASDM such that the network management system

can actively monitor the host using SNMPv3. Which two tasks must be performed for this configuration?

(Choose two.)

Options:

A.  

Specify the SNMP manager and UDP port.

B.  

Specify an SNMP user group

C.  

Specify a community string.

D.  

Add an SNMP USM entry

E.  

Add an SNMP host access entry

Discussion 0
Questions 13

An engineer configured a new network identity in Cisco Umbrella but must verify that traffic is being routed

through the Cisco Umbrella network. Which action tests the routing?

Options:

A.  

Ensure that the client computers are pointing to the on-premises DNS servers.

B.  

Enable the Intelligent Proxy to validate that traffic is being routed correctly.

C.  

Add the public IP address that the client computers are behind to a Core Identity.

D.  

Browse to http://welcome.umbrella.com/ to validate that the new identity is working.

Discussion 0
Questions 14

What is the function of Cisco Cloudlock for data security?

Options:

A.  

data loss prevention

B.  

controls malicious cloud apps

C.  

detects anomalies

D.  

user and entity behavior analytics

Discussion 0
Questions 15

Which technology limits communication between nodes on the same network segment to individual applications?

Options:

A.  

serverless infrastructure

B.  

microsegmentation

C.  

SaaS deployment

D.  

machine-to-machine firewalling

Discussion 0
Questions 16

An organization has noticed an increase in malicious content downloads and wants to use Cisco Umbrella to prevent this activity for suspicious domains while allowing normal web traffic. Which action will accomplish this task?

Options:

A.  

Set content settings to High

B.  

Configure the intelligent proxy.

C.  

Use destination block lists.

D.  

Configure application block lists.

Discussion 0
Questions 17

Refer to the exhibit. When configuring this access control rule in Cisco FMC, what happens with the traffic destined to the DMZ_inside zone once the configuration is deployed?

Options:

A.  

All traffic from any zone will be allowed to the DMZ_inside zone only after inspection.

B.  

No traffic will be allowed through to the DMZ_inside zone regardless of if it ' s trusted or not.

C.  

No traffic will be allowed through to the DMZ_inside zone unless it ' s already trusted.

D.  

All traffic from any zone to the DMZ_inside zone will be permitted with no further inspection.

Discussion 0
Questions 18

A network security engineer must export packet captures from the Cisco FMC web browser while troubleshooting an issue. When navigating to the address https:// < FMC IP > /capure/CAPI/pcap/test.pcap, an error 403: Forbidden is given instead of the PCAP file. Which action must the engineer take to resolve this issue?

Options:

A.  

Disable the proxy setting on the browser

B.  

Disable the HTTPS server and use HTTP instead

C.  

Use the Cisco FTD IP address as the proxy server setting on the browser

D.  

Enable the HTTPS server for the device platform policy

Discussion 0
Questions 19

Which VPN provides scalability for organizations with many remote sites?

Options:

A.  

DMVPN

B.  

site-to-site iPsec

C.  

SSL VPN

D.  

GRE over IPsec

Discussion 0
Questions 20

Which feature requires a network discovery policy on the Cisco Firepower Next Generation Intrusion Prevention

System?

Options:

A.  

Security Intelligence

B.  

Impact Flags

C.  

Health Monitoring

D.  

URL Filtering

Discussion 0
Questions 21

An engineer needs behavioral analysis to detect malicious activity on the hosts, and is configuring the

organization’s public cloud to send telemetry using the cloud provider’s mechanisms to a security device. Which

mechanism should the engineer configure to accomplish this goal?

Options:

A.  

mirror port

B.  

Flow

C.  

NetFlow

D.  

VPC flow logs

Discussion 0
Questions 22

Which type of data does the Cisco Stealthwatch system collect and analyze from routers, switches, and firewalls?

Options:

A.  

NTP

B.  

syslog

C.  

SNMP

D.  

NetFlow

Discussion 0
Questions 23

Which policy does a Cisco Secure Web Appliance use to block or monitor URL requests based on the reputation score?

Options:

A.  

Encryption

B.  

Enforcement Security

C.  

Cisco Data Security

D.  

Outbound Malware Scanning

Discussion 0
Questions 24

Which interface mode does a Cisco Secure IPS device use to block suspicious traffic?

Options:

A.  

Passive

B.  

Inline

C.  

Promiscuous

D.  

Active

Discussion 0
Questions 25

An organization is implementing AAA for their users. They need to ensure that authorization is verified for every command that is being entered by the network administrator. Which protocol must be configured in order to provide this capability?

Options:

A.  

EAPOL

B.  

SSH

C.  

RADIUS

D.  

TACACS+

Discussion 0
Questions 26

What is the term for having information about threats and threat actors that helps mitigate harmful events that would otherwise compromise networks or systems?

Options:

A.  

trusted automated exchange

B.  

Indicators of Compromise

C.  

The Exploit Database

D.  

threat intelligence

Discussion 0
Questions 27

An engineer must deploy a Cisco Secure Web Appliance. Antimalware scanning must use the Outbreak Heuristics antimalware category on files identified as malware before performing any other processes. What must be configured on the Secure Web Appliance to meet the requirements?

Options:

A.  

Sophos scanning engine

B.  

Webroot scanning engine

C.  

McAfee scanning engine

D.  

Adaptive Scanning

Discussion 0
Questions 28

Which PKI enrollment method allows the user to separate authentication and enrollment actions and also

provides an option to specify HTTP/TFTP commands to perform file retrieval from the server?

Options:

A.  

url

B.  

terminal

C.  

profile

D.  

selfsigned

Discussion 0
Questions 29

A network engineer is configuring a Cisco Catalyst switch. The network engineer must prevent traffic on the network from being interrupted by broadcast packets flooding the network using a predefined threshold. What must be configured on the switch?

Options:

A.  

DHCP Snooping

B.  

Embedded Event Monitoring

C.  

Storm Control

D.  

Loop Guard

Discussion 0
Questions 30

When network telemetry is implemented, what is important to be enabled across all network infrastructure devices to correlate different sources?

Options:

A.  

CDP

B.  

NTP

C.  

syslog

D.  

DNS

Discussion 0
Questions 31

An engineer is configuring IPsec VPN and needs an authentication protocol that is reliable and supports ACK

and sequence. Which protocol accomplishes this goal?

Options:

A.  

AES-192

B.  

IKEv1

C.  

AES-256

D.  

ESP

Discussion 0
Questions 32

How is ICMP used an exfiltration technique?

Options:

A.  

by flooding the destination host with unreachable packets

B.  

by sending large numbers of ICMP packets with a targeted hosts source IP address using an IP broadcast address

C.  

by encrypting the payload in an ICMP packet to carry out command and control tasks on a compromised host

D.  

by overwhelming a targeted host with ICMP echo-request packets

Discussion 0
Questions 33

A network engineer must distribute an operating system image to a network device and activate the image on that device by using the Cisco Catalyst Center API. Which two API requests perform the required operations? (Choose two.)

Options:

A.  

POST /dna/intent/api/v1/image/distribution

B.  

POST /dna/intent/api/v1/onboarding/pnp-device/import

C.  

POST /dna/intent/api/v1/image/activation/device

D.  

POST /dna/intent/api/v1/network/{site_id}

E.  

POST /dna/intent/api/v1/template-programmer/project/{project_id}/template

Discussion 0
Questions 34

Which two methods are available in Cisco Secure Web Appliance to process client requests when configured in Transparent mode? (Choose two.)

Options:

A.  

WCCP

B.  

Browser settings

C.  

WPAD

D.  

PAC files

E.  

PBR

Discussion 0
Questions 35

An engineer is configuring web filtering for a network using Cisco Umbrella Secure Internet Gateway.

The requirement is that all traffic needs to be filtered. Using the SSL decryption feature, which type of

certificate should be presented to the end-user to accomplish this goal?

Options:

A.  

third-party

B.  

self-signed

C.  

organization owned root

D.  

SubCA

Discussion 0
Questions 36

A network administrator needs a solution to match traffic and allow or deny the traffic based on the type of application, not just the source or destination address and port used. Which kind of security product must the network administrator implement to meet this requirement?

Options:

A.  

Next-generation Intrusion Prevention System

B.  

Next-generation Firewall

C.  

Web Application Firewall

D.  

Intrusion Detection System

Discussion 0
Questions 37

An engineer must enable Outbreak Filters globally on an AsyncOS for Cisco Secure Email Gateway to protect the network from large-scale malware attacks. Drag and drop the steps from the left into the sequence on the right to complete the configuration.

Options:

Discussion 0
Questions 38

In which two customer environments is the Cisco Secure Web Appliance Virtual connector traffic direction method selected? (Choose two.)

Options:

A.  

Customer needs to support roaming users.

B.  

Customer does not own Cisco hardware and needs Transparent Redirection (WCCP).

C.  

Customer owns ASA Appliance and Virtual Form Factor is required.

D.  

Customer does not own Cisco hardware and needs Explicit Proxy.

E.  

Customer owns ASA Appliance and SSL Tunneling is required.

Discussion 0
Questions 39

Which type of DNS abuse exchanges data between two computers even when there is no direct connection?

Options:

A.  

Malware installation

B.  

Command-and-control communication

C.  

Network footprinting

D.  

Data exfiltration

Discussion 0
Questions 40

Which Cisco Advanced Malware protection for Endpoints deployment architecture is designed to keep data

within a network perimeter?

Options:

A.  

cloud web services

B.  

network AMP

C.  

private cloud

D.  

public cloud

Discussion 0
Questions 41

An organization wants to implement a cloud-delivered and SaaS-based solution to provide visibility and threat detection across the AWS network. The solution must be deployed without software agents and rely on AWS VPC flow logs instead. Which solution meets these requirements?

Options:

A.  

Cisco Stealthwatch Cloud

B.  

Cisco Umbrella

C.  

NetFlow collectors

D.  

Cisco Cloudlock

Discussion 0
Questions 42

Which action configures the IEEE 802.1X Flexible Authentication feature to support Layer 3 authentication mechanisms?

Options:

A.  

Add MAB into the switch to allow redirection to a Layer 3 device for authentication.

B.  

Identify the devices using this feature and create a policy that allows them to pass Layer 2 authentication.

C.  

Modify the Dot1x configuration on the VPN server to send Layer 3 authentications to an external authentication database.

D.  

Configure WebAuth so the hosts are redirected to a web page for authentication.

Discussion 0
Questions 43

An organization wants to use Cisco FTD or Cisco ASA devices. Specific URLs must be blocked from being

accessed via the firewall which requires that the administrator input the bad URL categories that the

organization wants blocked into the access policy. Which solution should be used to meet this requirement?

Options:

A.  

Cisco ASA because it enables URL filtering and blocks malicious URLs by default, whereas Cisco FTDdoes not

B.  

Cisco ASA because it includes URL filtering in the access control policy capabilities, whereas Cisco FTD does not

C.  

Cisco FTD because it includes URL filtering in the access control policy capabilities, whereas Cisco ASA does not

D.  

Cisco FTD because it enables URL filtering and blocks malicious URLs by default, whereas Cisco ASA does not

Discussion 0
Questions 44

A security engineer is tasked with configuring TACACS on a Cisco ASA firewall. The engineer must be able to access the firewall command line interface remotely. The authentication must fall back to the local user database of the Cisco ASA firewall. AAA server group named TACACS-GROUP is already configured with TACACS server IP address 192.168.10.10 and key C1sc0512222832!. Which configuration must be done next to meet the requirement?

Options:

A.  

aaa authentication ssh console LOCAL TACACS-GROUP

B.  

aaa authentication ssh console TACACS-GROUP LOCAL

C.  

aaa authentication serial console LOCAL TACACS-GROUP

D.  

aaa authentication http console TACACS-GROUP LOCAL

Discussion 0
Questions 45

Which API method and required attribute are used to add a device into Cisco DNA Center with the native API?

Options:

A.  

GET and serialNumber

B.  

userSudiSerlalNos and deviceInfo

C.  

POST and name

D.  

lastSyncTime and pid

Discussion 0
Questions 46

What is a key difference between Cisco Firepower and Cisco ASA?

Options:

A.  

Cisco ASA provides access control while Cisco Firepower does not.

B.  

Cisco Firepower provides identity-based access control while Cisco ASA does not.

C.  

Cisco Firepower natively provides intrusion prevention capabilities while Cisco ASA does not.

D.  

Cisco ASA provides SSL inspection while Cisco Firepower does not.

Discussion 0
Questions 47

Drag and drop the Cisco CWS redirection options from the left onto the capabilities on the right.

Options:

Discussion 0
Questions 48

An engineer must configure Cisco AMP for Endpoints so that it contains a list of files that should not be executed by users. These files must not be quarantined. Which action meets this configuration requirement?

Options:

A.  

Identity the network IPs and place them in a blocked list.

B.  

Modify the advanced custom detection list to include these files.

C.  

Create an application control blocked applications list.

D.  

Add a list for simple custom detection.

Discussion 0
Questions 49

An engineer has enabled LDAP accept queries on a listener. Malicious actors must be prevented from quickly

identifying all valid recipients. What must be done on the Cisco ESA to accomplish this goal?

Options:

A.  

Configure incoming content filters

B.  

Use Bounce Verification

C.  

Configure Directory Harvest Attack Prevention

D.  

Bypass LDAP access queries in the recipient access table

Discussion 0
Questions 50

How is a cross-site scripting attack executed?

Options:

A.  

Force a currently authenticated end user to execute unwanted actions on a web app

B.  

Execute malicious client-side scripts injected to a client via a web app

C.  

Inject a database query via the input data from the client to a web app

D.  

Intercept communications between a client and a web server

Discussion 0
Questions 51

A security engineer is deploying an IPsec site-to-site VPN between headquarters and a remote plant, protected by Cisco Secure Firewall Threat Defense managed by Cisco Secure Firewall Management Center. The following configurations have already been completed:

    Matching IKEv2 proposals, preshared keys, and IPsec transform sets

    Access control rules permitting the traffic

    Crypto maps applied to the outside interfaces

    VPN traffic exempted from inspection

During a packet capture on the firewall, the engineer observes that the traffic is translated to the public IP address, preventing tunnel establishment. Which configuration action must be performed next?

Options:

A.  

Configure NAT exemption for traffic between the interesting subnet pairs.

B.  

Create a tunnel group with preshared-key authentication under connection profiles.

C.  

Enable IKEv2 fragmentation on both peers to reduce packet size.

D.  

Attach the new VPN policy to the global prefilter default action.

Discussion 0
Questions 52

How is data sent out to the attacker during a DNS tunneling attack?

Options:

A.  

as part of the UDP/53 packet payload

B.  

as part of the domain name

C.  

as part of the TCP/53 packet header

D.  

as part of the DNS response packet

Discussion 0
Questions 53

An administrator is configuring N I P on Cisco ASA via ASDM and needs to ensure that rogue NTP servers cannot insert themselves as the authoritative time source Which two steps must be taken to accomplish this task? (Choose two)

Options:

A.  

Specify the NTP version

B.  

Configure the NTP stratum

C.  

Set the authentication key

D.  

Choose the interface for syncing to the NTP server

E.  

Set the NTP DNS hostname

Discussion 0
Questions 54

Which two solutions help combat social engineering and phishing at the endpoint level? (Choose two.)

Options:

A.  

Cisco Umbrella

B.  

Cisco ISE

C.  

Cisco DNA Center

D.  

Cisco TrustSec

E.  

Cisco Duo Security

Discussion 0
Questions 55

In which two ways does Easy Connect help control network access when used with Cisco TrustSec? (Choose two)

Options:

A.  

It allows multiple security products to share information and work together to enhance security posture in the network.

B.  

It creates a dashboard in Cisco ISE that provides full visibility of all connected endpoints.

C.  

It allows for the assignment of Security Group Tags and does not require 802.1x to be configured on the switch or the endpoint.

D.  

It integrates with third-party products to provide better visibility throughout the network.

E.  

It allows for managed endpoints that authenticate to AD to be mapped to Security Groups (PassiveID).

Discussion 0
Questions 56

Which action must be taken in the AMP for Endpoints console to detect specific MD5 signatures on endpoints and then quarantine the files?

Options:

A.  

Configure an advanced custom detection list.

B.  

Configure an IP Block & Allow custom detection list

C.  

Configure an application custom detection list

D.  

Configure a simple custom detection list

Discussion 0
Questions 57

What is a key feature of the Bring Your Own Device (BYOD) capability in Cisco ISE?

Options:

A.  

Provide temporary Internet access for the personal devices of guest users.

B.  

Assess the security posture of personal devices before network access is allowed.

C.  

Fully manage network devices based on their characteristics before access is allowed.

D.  

Encrypt endpoint data according to predefined security policies.

Discussion 0
Questions 58

Which technology provides the benefit of Layer 3 through Layer 7 innovative deep packet inspection,

enabling the platform to identify and output various applications within the network traffic flows?

Options:

A.  

Cisco NBAR2

B.  

Cisco ASAV

C.  

Account on Resolution

D.  

Cisco Prime Infrastructure

Discussion 0
Questions 59

An engineer must force an endpoint to re-authenticate an already authenticated session without disrupting the

endpoint to apply a new or updated policy from ISE. Which CoA type achieves this goal?

Options:

A.  

Port Bounce

B.  

CoA Terminate

C.  

CoA Reauth

D.  

CoA Session Query

Discussion 0
Questions 60

Which portion of the network do EPP solutions solely focus on and EDR solutions do not?

Options:

A.  

server farm

B.  

perimeter

C.  

core

D.  

East-West gateways

Discussion 0
Questions 61

A security test performed on one of the applications shows that user input is not validated. Which security vulnerability is the application more susceptible to because of this lack of validation?

Options:

A.  

denial -of-service

B.  

cross-site request forgery

C.  

man-in-the-middle

D.  

SQL injection

Discussion 0
Questions 62

Drag and drop the solutions from the left onto the solution ' s benefits on the right.

Options:

Discussion 0
Questions 63

An organization is trying to implement micro-segmentation on the network and wants to be able to gain visibility on the applications within the network. The solution must be able to maintain and force compliance. Which product should be used to meet these requirements?

Options:

A.  

Cisco Umbrella

B.  

Cisco AMP

C.  

Cisco Stealthwatch

D.  

Cisco Tetration

Discussion 0
Questions 64

What is the function of the Context Directory Agent?

Options:

A.  

maintains users’ group memberships

B.  

relays user authentication requests from Web Security Appliance to Active Directory

C.  

reads the Active Directory logs to map IP addresses to usernames

D.  

accepts user authentication requests on behalf of Web Security Appliance for user identification

Discussion 0
Questions 65

Which feature within Cisco Umbrella allows for the ability to inspect secure HTTP traffic?

Options:

A.  

File Analysis

B.  

SafeSearch

C.  

SSL Decryption

D.  

Destination Lists

Discussion 0
Questions 66

What are two functionalities of SDN Northbound APIs? (Choose two.)

Options:

A.  

Northbound APIs provide a programmable interface for applications to dynamically configure the network.

B.  

Northbound APIs form the interface between the SDN controller and business applications.

C.  

OpenFlow is a standardized northbound API protocol.

D.  

Northbound APIs use the NETCONF protocol to communicate with applications.

E.  

Northbound APIs form the interface between the SDN controller and the network switches or routers.

Discussion 0
Questions 67

What is the purpose of the Cisco Endpoint loC feature?

Options:

A.  

It provides stealth threat prevention.

B.  

lt is a signature-based engine.

C.  

lt is an incident response tool

D.  

It provides precompromise detection.

Discussion 0
Questions 68

Why is it important to have a patching strategy for endpoints?

Options:

A.  

to take advantage of new features released with patches

B.  

so that functionality is increased on a faster scale when it is used

C.  

so that known vulnerabilities are targeted and having a regular patch cycle reduces risks

D.  

so that patching strategies can assist with disabling nonsecure protocols in applications

Discussion 0
Questions 69

Which process is used to obtain a certificate from a CA?

Options:

A.  

Registration

B.  

Enrollment

C.  

Signing

D.  

Approval

Discussion 0
Questions 70

What is a function of the Layer 4 Traffic Monitor on a Cisco WSA?

Options:

A.  

blocks traffic from URL categories that are known to contain malicious content

B.  

decrypts SSL traffic to monitor for malicious content

C.  

monitors suspicious traffic across all the TCP/UDP ports

D.  

prevents data exfiltration by searching all the network traffic for specified sensitive information

Discussion 0
Questions 71

What is the recommendation in a zero-trust model before granting access to corporate applications and resources?

Options:

A.  

To use a wired network, not wireless

B.  

To use strong passwords

C.  

To use multifactor authentication

D.  

To disconnect from the network when inactive

Discussion 0
Questions 72

Which standard is used to automate exchanging cyber threat information?

Options:

A.  

TAXII

B.  

MITRE

C.  

IoC

D.  

STIX

Discussion 0
Questions 73

Which type of attack is social engineering?

Options:

A.  

trojan

B.  

phishing

C.  

malware

D.  

MITM

Discussion 0
Questions 74

Which two actions does the Cisco ISE posture module provide that ensures endpoint security? (Choose two.)

Options:

A.  

A centralized management solution is deployed.

B.  

Patch management remediation is performed.

C.  

The latest antivirus updates are applied before access is allowed.

D.  

Assignments to endpoint groups are made dynamically, based on endpoint attributes.

E.  

Endpoint supplicant configuration is deployed.

Discussion 0
Questions 75

What is the primary benefit of deploying an ESA in hybrid mode?

Options:

A.  

You can fine-tune its settings to provide the optimum balance between security and performance for your environment

B.  

It provides the lowest total cost of ownership by reducing the need for physical appliances

C.  

It provides maximum protection and control of outbound messages

D.  

It provides email security while supporting the transition to the cloud

Discussion 0
Questions 76

Which Cisco platform onboards the endpoint and can issue a CA signed certificate while also automatically configuring endpoint network settings to use the signed endpoint certificate, allowing the endpoint to gain network access?

Options:

A.  

Cisco ISE

B.  

Cisco NAC

C.  

Cisco TACACS+

D.  

Cisco WSA

Discussion 0
Questions 77

When wired 802.1X authentication is implemented, which two components are required? (Choose two)

Options:

A.  

authentication server: Cisco Identity Service Engine

B.  

supplicant: Cisco AnyConnect ISE Posture module

C.  

authenticator: Cisco Catalyst switch

D.  

authenticator: Cisco Identity Services Engine

E.  

authentication server: Cisco Prime Infrastructure

Discussion 0
Questions 78

What is a benefit of performing device compliance?

Options:

A.  

Verification of the latest OS patches

B.  

Device classification and authorization

C.  

Providing multi-factor authentication

D.  

Providing attribute-driven policies

Discussion 0
Questions 79

Which functionality does Incident Manager provide in Cisco XDR?

Options:

A.  

It calculates the time usually required for incident identification.

B.  

It determines the time required to resolve an issue.

C.  

It enables backup activities when a threat has been misidentified.

D.  

It prioritizes the steps required to recover from an incident.

Discussion 0
Questions 80

What is the term for when an endpoint is associated to a provisioning WLAN that is shared with guest

access, and the same guest portal is used as the BYOD portal?

Options:

A.  

single-SSID BYOD

B.  

multichannel GUI

C.  

dual-SSID BYOD

D.  

streamlined access

Discussion 0
Questions 81

Drag and drop the security responsibilities from the left onto the corresponding cloud service models on the right.

Options:

Discussion 0
Questions 82

An engineer is configuring Cisco Secure Endpoint to enhance security by preventing the execution of certain files by users. The engineer needs to ensure that the specific executable file name Cisco_Software_0505446151.exe is blocked from running while never being quarantined. What must the engineer configure to meet the requirement?

Options:

A.  

Create advanced custom detection list.

B.  

Configure application control blocked applications list.

C.  

Implement simple custom detection list.

D.  

Enable scheduled scans to detect and block the executable files.

Discussion 0
Questions 83

What is a benefit of a Cisco Secure Email Gateway Virtual as compared to a physical Secure Email Gateway?

Options:

A.  

simplifies the distribution of software updates

B.  

provides faster performance

C.  

provides an automated setup process

D.  

enables the allocation of additional resources

Discussion 0
Questions 84

What can be integrated with Cisco Threat Intelligence Director to provide information about security threats,

which allows the SOC to proactively automate responses to those threats?

Options:

A.  

Cisco Umbrella

B.  

External Threat Feeds

C.  

Cisco Threat Grid

D.  

Cisco Stealthwatch

Discussion 0
Questions 85

Which characteristic is unique to a Cisco WSAv as compared to a physical appliance?

Options:

A.  

supports VMware vMotion on VMware ESXi

B.  

requires an additional license

C.  

performs transparent redirection

D.  

supports SSL decryption

Discussion 0
Questions 86

What are two DDoS attack categories? (Choose two)

Options:

A.  

sequential

B.  

protocol

C.  

database

D.  

volume-based

E.  

screen-based

Discussion 0
Questions 87

Refer to the exhibit. An engineer must configure an incoming mail policy so that each email sent from usera1@example.com to a domain of @cisco.com is scanned for antispam and advanced malware protection. All other settings will use the default behavior. What must be configured in the incoming mail policy to meet the requirements?

Options:

A.  

Policy Name: Default Policy  Sender: usera1@example.com  Recipient: @cisco.com

B.  

Policy Name: usera1 policy  Sender: usera1@example.com  Recipient: @cisco.com

C.  

Policy Name: Anti-Malware policy  Sender: usera1@example.com  Recipient: @cisco.com

D.  

Policy Name: cisco.com policy  Sender: usera1@example.com  Recipient: @cisco.com

Discussion 0
Questions 88

An engineer is configuring Cisco WSA and needs to enable a separated email transfer flow from the Internet and from the LAN. Which deployment mode must be used to accomplish this goal?

Options:

A.  

single interface

B.  

multi-context

C.  

transparent

D.  

two-interface

Discussion 0
Questions 89

A network engineer is deciding whether to use stateful or stateless failover when configuring two Cisco ASAs for high availability. What is the connection status in both cases?

Options:

A.  

Need to be reestablished with both stateful and stateless failover

B.  

Need to be reestablished with stateful failover and preserved with stateless failover

C.  

Preserved with both stateful and stateless failover

D.  

Preserved with stateful failover and need to be reestablished with stateless failover

Discussion 0
Questions 90

Refer to the exhibit.

=== Cisco Secure Endpoint - Detection Event ===

Endpoint : LAB-WKSTN-047 User: user1

Policy Group : Lab-Workstations Mode: Audit

Engine : ETHOS (fuzzy fingerprint)

Disposition : Malicious

File : C:\Users\user1\AppData\Local\Temp\svchost32.exe

SHA256 : 3a9f2c1d...e881b4a7

Parent Process: winword.exe

Threat Name : W32.Trojan.GenericKD.Agent

Retrospective : Previously UNKNOWN

Disposition changed to MALICIOUS at 09:31:55 UTC

File Activity : Created, Executed

Network : TCP outbound - > 91.205.188.47:4444

DNS query: c2-update.pharmadomain.ru

Quarantine : NOT quarantined (Audit mode active)

A security analyst at a pharmaceutical company is reviewing a Cisco Secure Endpoint malware-detection alert triggered on a laboratory workstation. The analyst observes the event data above. Which two things are occurring? (Choose two.)

Options:

A.  

The antivirus engine update interval on workstation LAB-WKSTN-047 is too infrequent.

B.  

The endpoint is running in Audit mode; the file was detected but not quarantined.

C.  

The endpoint is running in Audit mode; the file was detected and quarantined.

D.  

The file executed, was spawned by winword.exe, and opened an outbound connection to external command-and-control infrastructure.

E.  

The parent file winword.exe is on a custom application allow list, permitting the malicious file to execute.

Discussion 0
Questions 91

Which cloud service model offers an environment for cloud consumers to develop and deploy applications

without needing to manage or maintain the underlying cloud infrastructure?

Options:

A.  

PaaS

B.  

XaaS

C.  

IaaS

D.  

SaaS

Discussion 0
Questions 92

Which type of API is being used when a security application notifies a controller within a software-defined network architecture about a specific security threat?

Options:

A.  

westbound AP

B.  

southbound API

C.  

northbound API

D.  

eastbound API

Discussion 0
Questions 93

Which Cisco Umbrella package supports selective proxy for Inspection of traffic from risky domains?

Options:

A.  

SIG Advantage

B.  

DNS Security Essentials

C.  

SIG Essentials

D.  

DNS Security Advantage

Discussion 0
Questions 94

Drag and drop the VPN functions from the left onto the descriptions on the right.

Options:

Discussion 0
Questions 95

A network engineer is deploying multiple Cisco Secure Firewall Threat Defense devices across two data centers. The solution has the following requirements:

    Management must have no Internet dependency.

    Management must remain accessible during major outages.

    Policy management must be centralized.

Which solution must be implemented to meet the requirements?

Options:

A.  

Deploy an on-premises Cisco Secure Firewall Management Center high-availability pair with a dedicated out-of-band network.

B.  

Deploy one Cisco Secure Firewall Management Center per data center with in-band network management.

C.  

Use Cisco Security Cloud Control over the Internet with no on-premises managers.

D.  

Manage each firewall locally with Cisco Secure Firewall Device Manager over the production network.

Discussion 0
Questions 96

Which algorithm provides encryption and authentication for data plane communication?

Options:

A.  

AES-GCM

B.  

SHA-96

C.  

AES-256

D.  

SHA-384

Discussion 0
Questions 97

An organization has DHCP servers set up to allocate IP addresses to clients on the LAN. What must be done to ensure the LAN switches prevent malicious DHCP traffic while also distributing IP addresses to the correct endpoints?

Options:

A.  

Configure Dynamic ARP inspection and add entries in the DHCP snooping database.

B.  

Configure DHCP snooping and set trusted interfaces for all client connections.

C.  

Configure Dynamic ARP inspection and antispoofing ACLs in the DHCP snooping database.

D.  

Configure DHCP snooping and set a trusted interface for the DHCP server.

Discussion 0
Questions 98

Which Cisco DNA Center Intent API action is used to retrieve the number of devices known to a DNA Center?

Options:

A.  

GET https://fqdnOrlPofDnaCenterPlatform/dna/intent/api/v1/network-device/count

B.  

GET https://fqdnOrlPofDnaCenterPlatform/dna/intent/api/v1/network-device

C.  

GET https://fqdnOrlPofDnaCenterPlatform/dna/intent/api/v1/networkdevice?parameter1=value & parameter2=value & ....

D.  

GET https://fqdnOrlPofDnaCenterPlatform/dna/intent/api/v 1/networkdevice/startIndex/recordsToReturn

Discussion 0
Questions 99

What is a required prerequisite to enable malware file scanning for the Secure Internet Gateway?

Options:

A.  

Enable IP Layer enforcement.

B.  

Activate the Advanced Malware Protection license

C.  

Activate SSL decryption.

D.  

Enable Intelligent Proxy.

Discussion 0
Questions 100

A user has a device in the network that is receiving too many connection requests from multiple machines.

Which type of attack is the device undergoing?

Options:

A.  

phishing

B.  

slowloris

C.  

pharming

D.  

SYN flood

Discussion 0
Questions 101

For Cisco IOS PKI, which two types of Servers are used as a distribution point for CRLs? (Choose two)

Options:

A.  

SDP

B.  

LDAP

C.  

subordinate CA

D.  

SCP

E.  

HTTP

Discussion 0
Questions 102

What is the default action before identifying the URL during HTTPS inspection in Cisco Secure Firewall Threat Defense software?

Options:

A.  

reset

B.  

buffer

C.  

pass

D.  

drop

Discussion 0
Questions 103

What is the primary difference between an Endpoint Protection Platform and an Endpoint Detection and

Response?

Options:

A.  

EPP focuses on prevention, and EDR focuses on advanced threats that evade perimeter defenses.

B.  

EDR focuses on prevention, and EPP focuses on advanced threats that evade perimeter defenses.

C.  

EPP focuses on network security, and EDR focuses on device security.

D.  

EDR focuses on network security, and EPP focuses on device security.

Discussion 0
Questions 104

An organization wants to secure data in a cloud environment. Its security model requires that all users be

authenticated and authorized. Security configuration and posture must be continuously validated before access is granted or maintained to applications and data. There is also a need to allow certain application traffic and deny all other traffic by default. Which technology must be used to implement these requirements?

Options:

A.  

Virtual routing and forwarding

B.  

Microsegmentation

C.  

Access control policy

D.  

Virtual LAN

Discussion 0
Questions 105

An engineer is trying to decide between using L2TP or GRE over IPsec for their site-to-site VPN implementation. What must be un solution?

Options:

A.  

L2TP is an IP packet encapsulation protocol, and GRE over IPsec is a tunneling protocol.

B.  

L2TP uses TCP port 47 and GRE over IPsec uses UDP port 1701.

C.  

GRE over IPsec adds its own header, and L2TP does not.

D.  

GRE over IPsec cannot be used as a standalone protocol, and L2TP can.

Discussion 0
Questions 106

A security policy administrator configures a Cisco Secure Access SIA DNS policy to block all social media categories for the Marketing Active Directory group. While testing from one of the user machines, access to the domain https://socialmediaexample.org is allowed. When searching for this domain in User Activity Search, no queries for that specific domain are returned. Consider these facts:

    The test user is part of the Marketing Active Directory group.

    The domain socialmediaexample.org belongs to the social media category.

    The user is configured with the Umbrella Roaming Client for DNS redirection.

    All other social media websites are properly blocked for the same user and match the correct policy.

Which configuration must the administrator implement in Cisco Secure Access to meet the requirement?

Options:

A.  

Enable HTTPS inspection in the web policy because this is an HTTPS site.

B.  

Add socialmediaexample.org to the External Domains list.

C.  

Enable the intelligent proxy to identify this domain properly.

D.  

Add socialmediaexample.org to the Internal Domains list.

Discussion 0
Questions 107

Refer to the exhibit.

What will happen when the Python script is executed?

Options:

A.  

The hostname will be translated to an IP address and printed.

B.  

The hostname will be printed for the client in the client ID field.

C.  

The script will pull all computer hostnames and print them.

D.  

The script will translate the IP address to FODN and print it

Discussion 0
Questions 108

Refer to the exhibit,

which command results in these messages when attempting to troubleshoot an iPsec VPN connection?

Options:

A.  

debug crypto isakmp

B.  

debug crypto ipsec endpoint

C.  

debug crypto Ipsec

D.  

debug crypto isakmp connection

Discussion 0
Questions 109

Which risk is created when using an Internet browser to access cloud-based service?

Options:

A.  

misconfiguration of infrastructure, which allows unauthorized access

B.  

intermittent connection to the cloud connectors

C.  

vulnerabilities within protocol

D.  

insecure implementation of API

Discussion 0
Questions 110

An attacker needs to perform reconnaissance on a target system to help gain access to it. The system has weak passwords, no encryption on the VPN links, and software bugs on the system’s applications. Which

vulnerability allows the attacker to see the passwords being transmitted in clear text?

Options:

A.  

weak passwords for authentication

B.  

unencrypted links for traffic

C.  

software bugs on applications

D.  

improper file security

Discussion 0
Questions 111

What is a feature of NetFlow Secure Event Logging?

Options:

A.  

It exports only records that indicate significant events in a flow.

B.  

It filters NSEL events based on the traffic and event type through RSVP.

C.  

It delivers data records to NSEL collectors through NetFlow over TCP only.

D.  

It supports v5 and v8 templates.

Discussion 0
Questions 112

An engineer adds a custom detection policy to a Cisco AMP deployment and encounters issues with the

configuration. The simple detection mechanism is configured, but the dashboard indicates that the hash is not 64 characters and is non-zero. What is the issue?

Options:

A.  

The engineer is attempting to upload a hash created using MD5 instead of SHA-256

B.  

The file being uploaded is incompatible with simple detections and must use advanced detections

C.  

The hash being uploaded is part of a set in an incorrect format

D.  

The engineer is attempting to upload a file instead of a hash

Discussion 0
Questions 113

A Cisco Secure Cloud Analytics administrator is setting up a private network monitor sensor to monitor an on-premises environment. Which two pieces of information from the sensor are used to link to the Secure Cloud Analytics portal? (Choose two.)

Options:

A.  

Unique service key

B.  

NAT ID

C.  

SSL certificate

D.  

Public IP address

E.  

Private IP address

Discussion 0
Questions 114

A company has 5000 Windows users on its campus. Which two precautions should IT take to prevent WannaCry ransomware from spreading to all clients? (Choose two.)

Options:

A.  

Segment different departments to different IP blocks and enable Dynamic ARp inspection on all VLANs

B.  

Ensure that noncompliant endpoints are segmented off to contain any potential damage.

C.  

Ensure that a user cannot enter the network of another department.

D.  

Perform a posture check to allow only network access to (hose Windows devices that are already patched.

E.  

Put all company users in the trusted segment of NGFW and put all servers to the DMZ segment of the Cisco NGFW. ni

Discussion 0
Questions 115

How does a cloud access security broker function?

Options:

A.  

It is an authentication broker to enable single sign-on and multi-factor authentication for a cloud solution

B.  

lt integrates with other cloud solutions via APIs and monitors and creates incidents based on events from the cloud solution

C.  

It acts as a security information and event management solution and receives syslog from other cloud solutions.

D.  

It scans other cloud solutions being used within the network and identifies vulnerabilities

Discussion 0
Questions 116

What is the result of the ACME-Router(config)#login block-for 100 attempts 4 within 60 command on a Cisco IOS router?

Options:

A.  

lf four log in attempts fail in 100 seconds, wait for 60 seconds to next log in prompt.

B.  

After four unsuccessful log in attempts, the line is blocked for 100 seconds and only permit IP addresses are permitted in ACL

C.  

After four unsuccessful log in attempts, the line is blocked for 60 seconds and only permit IP addresses are permitted in ACL1

D.  

If four failures occur in 60 seconds, the router goes to quiet mode for 100 seconds.

Discussion 0
Questions 117

Which two key and block sizes are valid for AES? (Choose two)

Options:

A.  

64-bit block size, 112-bit key length

B.  

64-bit block size, 168-bit key length

C.  

128-bit block size, 192-bit key length

D.  

128-bit block size, 256-bit key length

E.  

192-bit block size, 256-bit key length

Discussion 0
Questions 118

Which VMware platform does Cisco ACI integrate with to provide enhanced visibility, provide policy integration and deployment, and implement security policies with access lists?

Options:

A.  

VMware APIC

B.  

VMwarevRealize

C.  

VMware fusion

D.  

VMware horizons

Discussion 0
Questions 119

A Cisco ESA network administrator has been tasked to use a newly installed service to help create policy based on the reputation verdict. During testing, it is discovered that the Cisco ESA is not dropping files that have an undetermined verdict. What is causing this issue?

Options:

A.  

The policy was created to send a message to quarantine instead of drop

B.  

The file has a reputation score that is above the threshold

C.  

The file has a reputation score that is below the threshold

D.  

The policy was created to disable file analysis

Discussion 0
Questions 120

What is a benefit of using Cisco Tetration?

Options:

A.  

It collects telemetry data from servers and then uses software sensors to analyze flowinformation.

B.  

It collects policy compliance data and process details.

C.  

It collects enforcement data from servers and collects interpacket variation.

D.  

It collects near-real time data from servers and inventories the software packages that exist onservers.

Discussion 0
Questions 121

Email security has become a high-priority task for a security engineer at a large multi-national organization due to ongoing phishing campaigns. To help control this, the engineer has deployed an Incoming Content Filter with a URL reputation of (-10.00 to -6.00) on the Cisco Secure Email Gateway. Which action will the system perform to disable any links in messages that match the filter?

Options:

A.  

FilterAction

B.  

ScreenAction

C.  

Quarantine

D.  

Defang

Discussion 0
Questions 122

Which Cisco solution does Cisco Umbrella integrate with to determine if a URL is malicious?

Options:

A.  

AMP

B.  

AnyConnect

C.  

DynDNS

D.  

Talos

Discussion 0
Questions 123

After deploying a Cisco ESA on your network, you notice that some messages fail to reach their destinations.

Which task can you perform to determine where each message was lost?

Options:

A.  

Configure the trackingconfig command to enable message tracking.

B.  

Generate a system report.

C.  

Review the log files.

D.  

Perform a trace.

Discussion 0
Questions 124

Which two features of Cisco Email Security can protect your organization against email threats? (Choose two)

Options:

A.  

Time-based one-time passwords

B.  

Data loss prevention

C.  

Heuristic-based filtering

D.  

Geolocation-based filtering

E.  

NetFlow

Discussion 0
Questions 125

An administrator enables Cisco Threat Intelligence Director on a Cisco FMC. Which process uses STIX and allows uploads and downloads of block lists?

Options:

A.  

consumption

B.  

sharing

C.  

editing

D.  

authoring

Discussion 0
Questions 126

After a recent breach, an organization determined that phishing was used to gain initial access to the network before regaining persistence. The information gained from the phishing attack was a result of users visiting known malicious websites. What must be done in order to prevent this from happening in the future?

Options:

A.  

Modify an access policy

B.  

Modify identification profiles

C.  

Modify outbound malware scanning policies

D.  

Modify web proxy settings

Discussion 0
Questions 127

Which two activities are performed using Cisco Catalyst Center? (Choose two.)

Options:

A.  

DHCP

B.  

Design

C.  

Provision

D.  

DNS

E.  

Accounting

Discussion 0
Questions 128

Which Cisco platform processes behavior baselines, monitors for deviations, and reviews for malicious processes in data center traffic and servers while performing software vulnerability detection?

Options:

A.  

Cisco Tetration

B.  

Cisco ISE

C.  

Cisco AMP for Network

D.  

Cisco AnyConnect

Discussion 0
Questions 129

Refer to the exhibit. What does this Python script accomplish?

Options:

A.  

It allows authentication with TLSv1 SSL protocol

B.  

It authenticates to a Cisco ISE with an SSH connection.

C.  

lt authenticates to a Cisco ISE server using the username of ersad

D.  

It lists the LDAP users from the external identity store configured on Cisco ISE

Discussion 0
Questions 130

A security engineer requires social-media websites to be blocked through Cisco Secure Firewall Threat Defense. Which configuration action must the engineer apply to meet the requirement?

Options:

A.  

Enable global settings with default URL filtering.

B.  

Configure a file policy in an access control policy.

C.  

Apply web filtering in an access control policy.

D.  

Block the social-media URL category in the destination-network condition of an access control rule.

Discussion 0
Questions 131

Which Cisco security solution determines if an endpoint has the latest OS updates and patches installed on the system?

Options:

A.  

Cisco Endpoint Security Analytics

B.  

Cisco AMP for Endpoints

C.  

Endpoint Compliance Scanner

D.  

Security Posture Assessment Service

Discussion 0
Questions 132

With Cisco AMP for Endpoints, which option shows a list of all files that have been executed in your

environment?

Options:

A.  

Prevalence

B.  

File analysis

C.  

Detections

D.  

Vulnerable software

E.  

Threat root cause

Discussion 0
Questions 133

What are two advantages of using Cisco Any connect over DMVPN? (Choose two)

Options:

A.  

It provides spoke-to-spoke communications without traversing the hub

B.  

It allows different routing protocols to work over the tunnel

C.  

It allows customization of access policies based on user identity

D.  

It allows multiple sites to connect to the data center

E.  

It enables VPN access for individual users from their machines

Discussion 0
Questions 134

Which two statements about a Cisco WSA configured in Transparent mode are true? (Choose two)

Options:

A.  

It can handle explicit HTTP requests.

B.  

It requires a PAC file for the client web browser.

C.  

It requires a proxy for the client web browser.

D.  

WCCP v2-enabled devices can automatically redirect traffic destined to port 80.

E.  

Layer 4 switches can automatically redirect traffic destined to port 80.

Discussion 0
Questions 135

What is the benefit of integrating Cisco ISE with a MDM solution?

Options:

A.  

It provides compliance checks for access to the network

B.  

It provides the ability to update other applications on the mobile device

C.  

It provides the ability to add applications to the mobile device through Cisco ISE

D.  

It provides network device administration access

Discussion 0
Questions 136

Which kind of API that is used with Cisco DNA Center provisions SSIDs, QoS policies, and update software versions on switches?

Options:

A.  

Integration

B.  

Intent

C.  

Event

D.  

Multivendor

Discussion 0
Questions 137

What Cisco command shows you the status of an 802.1X connection on interface gi0/1?

Options:

A.  

show authorization status

B.  

show authen sess int gi0/1

C.  

show connection status gi0/1

D.  

show ver gi0/1

Discussion 0
Questions 138

Which two cryptographic algorithms are used with IPsec? (Choose two)

Options:

A.  

AES-BAC

B.  

AES-ABC

C.  

HMAC-SHA1/SHA2

D.  

Triple AMC-CBC

E.  

AES-CBC

Discussion 0
Questions 139

What are two benefits of using Cisco Duo as an MFA solution? (Choose two.)

Options:

A.  

grants administrators a way to remotely wipe a lost or stolen device

B.  

provides simple and streamlined login experience for multiple applications and users

C.  

native integration that helps secure applications across multiple cloud platforms or on-premises environments

D.  

encrypts data that is stored on endpoints

E.  

allows for centralized management of endpoint device applications and configurations

Discussion 0
Questions 140

An engineer is securing access to data served by a cloud-based application. The data must be protected from modification in transit, and its integrity must be validated. The following security measures have been implemented:

• Governance with role-based access control based on the principle of least privilege

• TLS 1.3 with signed certificates

• AES-256 with MD5

What must be configured to complete the secure implementation?

Options:

A.  

3DES instead of AES

B.  

DES instead of TLS 1.3

C.  

SHA-512 instead of MD5

D.  

SSLv3 instead of MD5

Discussion 0
Questions 141

An engineer enabled SSL decryption for Cisco Umbrella intelligent proxy and needs to ensure that traffic is inspected without alerting end-users. Which action accomplishes this goal?

Options:

A.  

Restrict access to only websites with trusted third-party signed certificates.

B.  

Modify the user’s browser settings to suppress errors from Cisco Umbrella.

C.  

Upload the organization root CA to Cisco Umbrella.

D.  

Install the Cisco Umbrella root CA onto the user’s device.

Discussion 0
Questions 142

What is a feature of Cisco NetFlow Secure Event Logging for Cisco ASAs?

Options:

A.  

Multiple NetFlow collectors are supported

B.  

Advanced NetFlow v9 templates and legacy v5 formatting are supported

C.  

Secure NetFlow connections are optimized for Cisco Prime Infrastructure

D.  

Flow-create events are delayed

Discussion 0
Questions 143

Which capability allows an administrator to configure forensics rules in Cisco Secure Workload?

Options:

A.  

Custom clauses

B.  

MITRE ATT & CK framework only predefined

C.  

Cisco Secure Workload predefined

D.  

Windows or Linux application

Discussion 0
Questions 144

Based on the NIST 800-145 guide, which cloud architecture may be owned, managed, and operated by one or more of the organizations in the community, a third party, or some combination of them, and it may exist on or off premises?

Options:

A.  

hybrid cloud

B.  

private cloud

C.  

public cloud

D.  

community cloud

Discussion 0
Questions 145

Refer to the exhibit.

What conclusion should an administrator draw about the URL malicious-domain-example.com?

Options:

A.  

The domain is blocked solely because it is newly registered, regardless of the Threat Score.

B.  

The domain is a legacy site that has been compromised, as indicated by its domain age.

C.  

The domain is safe because its Security Score is 25/100.

D.  

The high Threat Score together with DNS tunneling, malware hosting, and DGA indicators shows active malicious behavior.

Discussion 0
Questions 146

What are two characteristics of the RESTful architecture used within Cisco DNA Center? (Choose two.)

Options:

A.  

REST uses methods such as GET, PUT, POST, and DELETE.

B.  

REST codes can be compiled with any programming language.

C.  

REST is a Linux platform-based architecture.

D.  

The POST action replaces existing data at the URL path.

E.  

REST uses HTTP to send a request to a web service.

Discussion 0
Questions 147

Refer to the exhibit. Which configuration item makes it possible to have the AAA session on the network?

Options:

A.  

aaa authorization exec default ise

B.  

aaa authentication enable default enable

C.  

aaa authorization network default group ise

D.  

aaa authorization login console ise

Discussion 0
Questions 148

Which product allows Cisco FMC to push security intelligence observable to its sensors from other products?

Options:

A.  

Encrypted Traffic Analytics

B.  

Threat Intelligence Director

C.  

Cognitive Threat Analytics

D.  

Cisco Talos Intelligence

Discussion 0
Questions 149

Which two devices support WCCP for traffic redirection? (Choose two.)

Options:

A.  

Cisco Secure Web Appliance

B.  

Cisco IOS

C.  

proxy server

D.  

Cisco ASA

E.  

Cisco IPS

Discussion 0
Questions 150

Which security control is required for identifying and neutralizing malicious code that attempts to execute on an endpoint?

Options:

A.  

EPP

B.  

XDR

C.  

SWG

D.  

CASB

Discussion 0
Questions 151

What are two ways that Cisco Container Platform provides value to customers who utilize cloud service providers? (Choose two.)

Options:

A.  

Allows developers to create code once and deploy to multiple clouds

B.  

helps maintain source code for cloud deployments

C.  

manages Docker containers

D.  

manages Kubernetes clusters

E.  

Creates complex tasks for managing code

Discussion 0
Questions 152

When a Cisco Secure Web Appliance checks a web request, what occurs if it is unable to match a user-defined policy?

Options:

A.  

It applies the next identification profile policy.

B.  

It applies the advanced policy.

C.  

It applies the global policy.

D.  

It blocks the request.

Discussion 0
Questions 153

Which algorithm provides asymmetric encryption?

Options:

A.  

RC4

B.  

AES

C.  

RSA

D.  

3DES

Discussion 0
Questions 154

Which attribute has the ability to change during the RADIUS CoA?

Options:

A.  

NTP

B.  

Authorization

C.  

Accessibility

D.  

Membership

Discussion 0
Questions 155

What are two reasons for implementing a multifactor authentication solution such as Duo Security provide to an

organization? (Choose two)

Options:

A.  

flexibility of different methods of 2FA such as phone callbacks, SMS passcodes, and push notifications

B.  

single sign-on access to on-premises and cloud applications

C.  

integration with 802.1x security using native Microsoft Windows supplicant

D.  

secure access to on-premises and cloud applications

E.  

identification and correction of application vulnerabilities before allowing access to resources

Discussion 0
Questions 156

Which type of dashboard does Cisco DNA Center provide for complete control of the network?

Options:

A.  

service management

B.  

centralized management

C.  

application management

D.  

distributed management

Discussion 0
Questions 157

Which Cisco DNA Center RESTful PNP API adds and claims a device into a workflow?

Options:

A.  

api/v1/fie/config

B.  

api/v1/onboarding/pnp-device/import

C.  

api/v1/onboarding/pnp-device

D.  

api/v1/onboarding/workflow

Discussion 0
Questions 158

Which two protocols must be configured to authenticate end users to the Cisco WSA? (Choose two.)

Options:

A.  

TACACS+

B.  

CHAP

C.  

NTLMSSP

D.  

RADIUS

E.  

Kerberos

Discussion 0
Questions 159

Drag and drop the cryptographic algorithms for IPsec from the left onto the cryptographic processes on the right.

Options:

Discussion 0
Questions 160

A security engineer is deploying an IPsec site-to-site VPN between headquarters and a remote plant, protected by Cisco Secure Firewall Threat Defense managed by Cisco Secure Firewall Management Center. The following configurations have already been completed:

    Matching IKEv2 proposals, preshared keys, and IPsec transform sets

    Access control rules permitting the traffic

    Crypto maps applied to the outside interfaces

    VPN traffic exempted from inspection

During a packet capture on the firewall, the engineer observes that the traffic is translated to the public IP address, preventing tunnel establishment. Which configuration action must be performed next?

Options:

A.  

Configure NAT exemption for traffic between the interesting subnet pairs.

B.  

Create a tunnel group with preshared-key authentication under connection profiles.

C.  

Enable IKEv2 fragmentation on both peers to reduce packet size.

D.  

Attach the new VPN policy to the global prefilter default action.

Discussion 0
Questions 161

An engineer needs to configure a Cisco Secure Email Gateway (SEG) to prompt users to enter multiple forms of identification before gaining access to the SEG. The SEG must also join a cluster using the preshared key of cisc421555367. What steps must be taken to support this?

Options:

A.  

Enable two-factor authentication through a RADIUS server, and then join the cluster via the SEG GUI.

B.  

Enable two-factor authentication through a TACACS+ server, and then join the cluster via the SEG CLI.

C.  

Enable two-factor authentication through a RADIUS server, and then join the cluster via the SEG CLI

D.  

Enable two-factor authentication through a TACACS+ server, and then join the cluster via the SEG GUI.

Discussion 0
Questions 162

Which feature is used in a push model to allow for session identification, host reauthentication, and session termination?

Options:

A.  

AAA attributes

B.  

CoA request

C.  

AV pair

D.  

carrier-grade NAT

Discussion 0
Questions 163

An engineer is implementing NTP authentication within their network and has configured both the client and server devices with the command ntp authentication-key 1 md5 Cisc392368270. The server at 1.1.1.1 is attempting to authenticate to the client at 1.1.1.2, however it is unable to do so. Which command is required to enable the client to accept the server’s authentication key?

Options:

A.  

ntp peer 1.1.1.1 key 1

B.  

ntp server 1.1.1.1 key 1

C.  

ntp server 1.1.1.2 key 1

D.  

ntp peer 1.1.1.2 key 1

Discussion 0
Questions 164

A Cisco AMP for Endpoints administrator configures a custom detection policy to add specific MD5 signatures The configuration is created in the simple detection policy section, but it does not work What is the reason for this failure?

Options:

A.  

The administrator must upload the file instead of the hash for Cisco AMP to use.

B.  

The MD5 hash uploaded to the simple detection policy is in the incorrect format

C.  

The APK must be uploaded for the application that the detection is intended

D.  

Detections for MD5 signatures must be configured in the advanced custom detection policies

Discussion 0
Questions 165

Which two functions does the Cisco Advanced Phishing Protection solution perform in trying to protect from phishing attacks? (Choose two.)

Options:

A.  

blocks malicious websites and adds them to a block list

B.  

does a real-time user web browsing behavior analysis

C.  

provides a defense for on-premises email deployments

D.  

uses a static algorithm to determine malicious

E.  

determines if the email messages are malicious

Discussion 0
Questions 166

What is the most commonly used protocol for network telemetry?

Options:

A.  

SMTP

B.  

SNMP

C.  

TFTP

D.  

NctFlow

Discussion 0
Questions 167

A network administrator is configuring a switch to use Cisco ISE for 802.1X. An endpoint is failing

authentication and is unable to access the network. Where should the administrator begin troubleshooting to verify the authentication details?

Options:

A.  

Adaptive Network Control Policy List

B.  

Context Visibility

C.  

Accounting Reports

D.  

RADIUS Live Logs

Discussion 0
Questions 168

Which action configures the IEEE 802.1X Flexible Authentication feature lo support Layer 3 authentication mechanisms?

Options:

A.  

Identity the devices using this feature and create a policy that allows them to pass Layer 2 authentication.

B.  

Configure WebAuth so the hosts are redirected to a web page for authentication.

C.  

Modify the Dot1x configuration on the VPN server lo send Layer 3 authentications to an external authentication database

D.  

Add MAB into the switch to allow redirection to a Layer 3 device for authentication.

Discussion 0
Questions 169

A security engineer must protect endpoints when a file appears harmless during initial inspection but later shows malicious behavior. The solution must continuously observe process and file activity after execution and respond when a threat emerges. The infrastructure includes Cisco Secure Endpoint. Which feature must the engineer configure to meet the requirements?

Options:

A.  

File Reputation

B.  

Continuous Behavioral Monitoring

C.  

Forensic Analysis

D.  

System Process Protection

Discussion 0
Questions 170

A network engineer has entered the snmp-server user andy myv3 auth sha cisco priv aes 256

cisc0380739941 command and needs to send SNMP information to a host at 10.255.254.1. Which command achieves this goal?

Options:

A.  

snmp-server host inside 10.255.254.1 version 3 andy

B.  

snmp-server host inside 10.255.254.1 version 3 myv3

C.  

snmp-server host inside 10.255.254.1 snmpv3 andy

D.  

snmp-server host inside 10.255.254.1 snmpv3 myv3

Discussion 0
Questions 171

Which Splunk SOAR component automates multi-step security actions into a repeatable workflow?

Options:

A.  

Alert

B.  

Action

C.  

Data model

D.  

Playbook

Discussion 0
Questions 172

Which Cisco Firewall solution requires zone definition?

Options:

A.  

CBAC

B.  

Cisco AMP

C.  

ZBFW

D.  

Cisco ASA

Discussion 0
Questions 173

When a Cisco WSA checks a web request, what occurs if it is unable to match a user-defined policy?

Options:

A.  

It blocks the request.

B.  

It applies the global policy.

C.  

It applies the next identification profile policy.

D.  

It applies the advanced policy.

Discussion 0
Questions 174

Refer to the exhibit. An engineer must configure a new Cisco ISE backend server as a RADIUS server to provide AAA for all access requests from the client to the ISE-Frontend server.

Which Cisco ISE configuration must be used?

Options:

A.  

Set 10.11.1.2 as a network device in ISE-Frontend. Set port 1700/2083 for RADIUS authentication.

B.  

Set 10.11.1.1 as the external RADIUS server in ISE-Frontend. Set ports 1812/1813 for authentication and accounting.

C.  

Set 10.11.1.2 as the external RADIUS server in ISE-Frontend. Set ports 1812/1813 for authentication and accounting.

D.  

Set 10.11.1.1 as a network device in ISE-Frontend. Set ports 1700/2083 for RADIUS authentication.

Discussion 0
Questions 175

Which two kinds of attacks are prevented by multifactor authentication? (Choose two)

Options:

A.  

phishing

B.  

brute force

C.  

man-in-the-middle

D.  

DDOS

E.  

teardrop

Discussion 0
Questions 176

Which solution offers automated blocking of known threats and visibility into zero-day attack behavior, with the ability to respond directly from the console?

Options:

A.  

EPP solution with an HIDS integration

B.  

Cloud-native antivirus with offline update support

C.  

EDR with behavioral analytics and remote containment

D.  

Secure Email Gateway with phishing sandboxing

Discussion 0
Questions 177

What are the two types of managed Intercloud Fabric deployment models? (Choose two.)

Options:

A.  

Public managed

B.  

Service Provider managed

C.  

Enterprise managed

D.  

User managed

E.  

Hybrid managed

Discussion 0
Questions 178

What is a functional difference between Cisco AMP for Endpoints and Cisco Umbrella Roaming Client?

Options:

A.  

The Umbrella Roaming client stops and tracks malicious activity on hosts, and AMP for Endpoints tracks only URL-based threats.

B.  

The Umbrella Roaming Client authenticates users and provides segmentation, and AMP for Endpoints allows only for VPN connectivity

C.  

AMP for Endpoints authenticates users and provides segmentation, and the Umbrella Roaming Client allows only for VPN connectivity.

D.  

AMP for Endpoints stops and tracks malicious activity on hosts, and the Umbrella Roaming Client tracks only URL-based threats.

Discussion 0
Questions 179

Which suspicious pattern enables the Cisco Tetration platform to learn the normal behavior of users?

Options:

A.  

file access from a different user

B.  

interesting file access

C.  

user login suspicious behavior

D.  

privilege escalation

Discussion 0
Questions 180

Refer to the exhibit.

What does the number 15 represent in this configuration?

Options:

A.  

privilege level for an authorized user to this router

B.  

access list that identifies the SNMP devices that can access the router

C.  

interval in seconds between SNMPv3 authentication attempts

D.  

number of possible failed attempts until the SNMPv3 user is locked out

Discussion 0
Questions 181

Refer to the exhibit.

A threat analyst is investigating the domain federatedplantmesh.garden after it appeared in DNS logs from several roaming users. In the Cisco Secure Access Investigate dashboard, the analyst notes that several individual indicators, including Lexical, TLD, and Geo Popularity, are not strongly elevated, yet the overall Risk Score is 100. What is occurring?

Options:

A.  

The overall score of 100 is inconsistent and likely a dashboard-rendering error; the domain must be queried again before the classification is trusted.

B.  

The infrastructure fields are blank, but the Umbrella Block Status of 100/100 and the malware security category identify the non-resolving domain as high risk.

C.  

The Keyword Score of 83 is the only elevated indicator driving the overall score, and the classification is invalid unless confirmed through the Dispute Categorization link.

D.  

The Dispute Categorization link means that the malware classification is contested, and the blank IP and ASN fields confirm that the domain has no active threat infrastructure.

Discussion 0
Questions 182

What are two facts about WSA HTTP proxy configuration with a PAC file? (Choose two.)

Options:

A.  

It is defined as a Transparent proxy deployment.

B.  

In a dual-NIC configuration, the PAC file directs traffic through the two NICs to the proxy.

C.  

The PAC file, which references the proxy, is deployed to the client web browser.

D.  

It is defined as an Explicit proxy deployment.

E.  

It is defined as a Bridge proxy deployment.

Discussion 0
Questions 183

An engineer must implement a file transfer solution between a company ' s data center and branches. The company has numerous servers hosted in a hybrid cloud implementation. The file transfer protocol must support authentication, protect the data against unauthorized access, and ensure that users cannot list directories or remove files remotely. Which protocol must be used?

Options:

A.  

SCP

B.  

SSH

C.  

FTPS

D.  

SFTP

Discussion 0
Questions 184

A network administrator is modifying a remote access VPN on an FTD managed by an FMC. The administrator wants to offload traffic to certain trusted domains. The administrator wants this traffic to go out of the client ' s local internet and send other internet-bound traffic over the VPN Which feature must the administrator configure?

Options:

A.  

dynamic split tunneling

B.  

local LAN access

C.  

dynamic access policies

D.  

reverse route injection

Discussion 0
Questions 185

A company identified a phishing vulnerability during a pentest. What are two ways the company can protect employees from the attack? (Choose two.)

Options:

A.  

using Cisco Umbrella

B.  

using Cisco FTD

C.  

using Cisco ISE

D.  

using Cisco Secure Email Gateway

E.  

using an inline IPS/IDS in the network

Discussion 0
Questions 186

Which feature requires that network telemetry be enabled?

Options:

A.  

per-interface stats

B.  

SNMP trap notification

C.  

Layer 2 device discovery

D.  

central syslog system

Discussion 0
Questions 187

A network engineer must monitor user and device behavior within the on-premises network. This data must be sent to the Cisco Stealthwatch Cloud analytics platform for analysis. What must be done to meet this

requirement using the Ubuntu-based VM appliance deployed in a VMware-based hypervisor?

Options:

A.  

Configure a Cisco FMC to send syslogs to Cisco Stealthwatch Cloud

B.  

Deploy the Cisco Stealthwatch Cloud PNM sensor that sends data to Cisco Stealthwatch Cloud

C.  

Deploy a Cisco FTD sensor to send network events to Cisco Stealthwatch Cloud

D.  

Configure a Cisco FMC to send NetFlow to Cisco Stealthwatch Cloud

Discussion 0
Questions 188

Which Talos reputation center allows for tracking the reputation of IP addresses for email and web traffic?

Options:

A.  

IP and Domain Reputation Center

B.  

File Reputation Center

C.  

IP Slock List Center

D.  

AMP Reputation Center

Discussion 0
Questions 189

Which two components do southbound APIs use to communicate with downstream devices? (Choose two.)

Options:

A.  

services running over the network

B.  

OpenFlow

C.  

external application APIs

D.  

applications running over the network

E.  

OpFlex

Discussion 0
Questions 190

Why is it important to implement MFA inside of an organization?

Options:

A.  

To prevent man-the-middle attacks from being successful.

B.  

To prevent DoS attacks from being successful.

C.  

To prevent brute force attacks from being successful.

D.  

To prevent phishing attacks from being successful.

Discussion 0
Questions 191

Refer to the exhibit.

An engineer must configure a Cisco switch to perform PPP authentication via a TACACS server located at IP address 10.1.1.10. Authentication must fall back to the local database using the username LocalUser and password C1Sc0451069341l if the TACACS server is unreachable.

Drag and drop the commands from the left onto the corresponding configuration steps on the right.

Options:

Discussion 0
Questions 192

Which solution combines Cisco IOS and IOS XE components to enable administrators to recognize

applications, collect and send network metrics to Cisco Prime and other third-party management tools, and prioritize application traffic?

Options:

A.  

Cisco Security Intelligence

B.  

Cisco Application Visibility and Control

C.  

Cisco Model Driven Telemetry

D.  

Cisco DNA Center

Discussion 0
Questions 193

Which Cisco ASA Platform mode disables the threat detection features except for Advanced Threat Statistics?

Options:

A.  

cluster

B.  

transparent

C.  

routed

D.  

multiple context

Discussion 0
Questions 194

What are two characteristics of Cisco Catalyst Center APIs? (Choose two.)

Options:

A.  

Postman is required to utilize Cisco Catalyst Center API calls.

B.  

They are Cisco proprietary.

C.  

They do not support Python scripts.

D.  

They view the overall health of the network.

E.  

They quickly provision new devices.

Discussion 0
Questions 195

Which two authentication protocols are supported by the Cisco WSA? (Choose two.)

Options:

A.  

WCCP

B.  

NTLM

C.  

TLS

D.  

SSL

E.  

LDAP

Discussion 0
Questions 196

Which posture assessment requirement provides options to the client for remediation and requires the

remediation within a certain timeframe?

Options:

A.  

Audit

B.  

Mandatory

C.  

Optional

D.  

Visibility

Discussion 0
Questions 197

Which two global commands must the network administrator implement to limit the attack surface of an internet-facing Cisco router? (Choose two.)

Options:

A.  

no service password-recovery

B.  

no cdp run

C.  

service tcp-keepalives-in

D.  

no ip http server

E.  

ip ssh version 2

Discussion 0
Questions 198

A network engineer is trying to figure out whether FlexVPN or DMVPN would fit better in their environment.

They have a requirement for more stringent security multiple security associations for the connections, more efficient VPN establishment as well consuming less bandwidth. Which solution would be best for this and why?

Options:

A.  

DMVPN because it supports IKEv2 and FlexVPN does not

B.  

FlexVPN because it supports IKEv2 and DMVPN does not

C.  

FlexVPN because it uses multiple SAs and DMVPN does not

D.  

DMVPN because it uses multiple SAs and FlexVPN does not

Discussion 0
Questions 199

An engineer is deploying a Cisco Secure Email Gateway and must ensure it reaches the Cisco update servers to retrieve new rules. The engineer must now manually configure the Outbreak Filter rules on an AsyncOS for Cisco Secure Email Gateway. Only outdated rules must be replaced. Up-to-date rules must be retained. Which action must the engineer take next to complete the configuration?

Options:

A.  

Select Outbreak Filters

B.  

Perform a backup/restore of the database

C.  

Use the outbreakconfig command in CLI

D.  

Click Update Rules Now

Discussion 0
Questions 200

Which type of attack is MFA an effective deterrent for?

Options:

A.  

ping of death

B.  

phishing

C.  

teardrop

D.  

syn flood

Discussion 0
Questions 201

What is the intent of a basic SYN flood attack?

Options:

A.  

to solicit DNS responses

B.  

to exceed the threshold limit of the connection queue

C.  

to flush the register stack to re-initiate the buffers

D.  

to cause the buffer to overflow

Discussion 0
Questions 202

Which telemetry data captures variations seen within the flow, such as the packets TTL, IP/TCP flags, and payload length?

Options:

A.  

interpacket variation

B.  

software package variation

C.  

flow insight variation

D.  

process details variation

Discussion 0
Questions 203

Refer to the exhibit.

An administrator is adding a new Cisco FTD device to their network and wants to manage it with Cisco FMC.

The Cisco FTD is not behind a NAT device. Which command is needed to enable this on the Cisco FTD?

Options:

A.  

configure manager add DONTRESOLVE kregistration key >

B.  

configure manager add < FMC IP address > < registration key > 16

C.  

configure manager add DONTRESOLVE < registration key > FTD123

D.  

configure manager add < FMC IP address > < registration key >

Discussion 0
Questions 204

An organization deploys multiple Cisco FTD appliances and wants to manage them using one centralized

solution. The organization does not have a local VM but does have existing Cisco ASAs that must migrate over

to Cisco FTDs. Which solution meets the needs of the organization?

Options:

A.  

Cisco FMC

B.  

CSM

C.  

Cisco FDM

D.  

CDO

Discussion 0
Questions 205

In which cloud services model is the customer responsible for scanning for and mitigation of application vulnerabilities?

Options:

A.  

PaaS

B.  

VMaaS

C.  

IaaS

D.  

SaaS

Discussion 0
Questions 206

What is the purpose of a denial-of-service attack?

Options:

A.  

to disrupt the normal operation of a targeted system by overwhelming It

B.  

to exploit a security vulnerability on a computer system to steal sensitive information

C.  

to prevent or limit access to data on a computer system by encrypting It

D.  

to spread throughout a computer system by self-replicating to additional hosts

Discussion 0
Questions 207

Which solution is made from a collection of secure development practices and guidelines that developers must follow to build secure applications?

Options:

A.  

AFL

B.  

Fuzzing Framework

C.  

Radamsa

D.  

OWASP

Discussion 0
Questions 208

Which solution for remote workers enables protection, detection, and response on the endpoint against known and unknown threats?

Options:

A.  

Cisco AMP for Endpoints

B.  

Cisco AnyConnect

C.  

Cisco Umbrella

D.  

Cisco Duo

Discussion 0
Questions 209

An administrator is adding a new switch onto the network and has configured AAA for network access control. When testing the configuration, the RADIUS authenticates to Cisco ISE but is being rejected. Why is the ip radius source-interface command needed for this configuration?

Options:

A.  

Only requests that originate from a configured NAS IP are accepted by a RADIUS server

B.  

The RADIUS authentication key is transmitted only from the defined RADIUS source interface

C.  

RADIUS requests are generated only by a router if a RADIUS source interface is defined.

D.  

Encrypted RADIUS authentication requires the RADIUS source interface be defined

Discussion 0
Questions 210

What is the purpose of the Cisco Endpoint IoC feature?

Options:

A.  

It is an incident response tool.

B.  

It provides stealth threat prevention.

C.  

It is a signature-based engine.

D.  

It provides precompromise detection.

Discussion 0
Questions 211

Which ASA deployment mode can provide separation of management on a shared appliance?

Options:

A.  

DMZ multiple zone mode

B.  

transparent firewall mode

C.  

multiple context mode

D.  

routed mode

Discussion 0
Questions 212

Which deployment model is the most secure when considering risks to cloud adoption?

Options:

A.  

Public Cloud

B.  

Hybrid Cloud

C.  

Community Cloud

D.  

Private Cloud

Discussion 0
Questions 213

How many interfaces per bridge group does an ASA bridge group deployment support?

Options:

A.  

up to 2

B.  

up to 4

C.  

up to 8

D.  

up to 16

Discussion 0
Questions 214

Which category includes DoS Attacks?

Options:

A.  

Virus attacks

B.  

Trojan attacks

C.  

Flood attacks

D.  

Phishing attacks

Discussion 0
Questions 215

Which benefit does endpoint security provide the overall security posture of an organization?

Options:

A.  

It streamlines the incident response process to automatically perform digital forensics on the endpoint.

B.  

It allows the organization to mitigate web-based attacks as long as the user is active in the domain.

C.  

It allows the organization to detect and respond to threats at the edge of the network.

D.  

It allows the organization to detect and mitigate threats that the perimeter security devices do not detect.

Discussion 0
Questions 216

Drag and drop the capabilities of Cisco Firepower versus Cisco AMP from the left into the appropriate category on the right.

Options:

Discussion 0
Questions 217

During a recent security audit a Cisco IOS router with a working IPSEC configuration using IKEv1 was flagged for using a wildcard mask with the crypto isakmp key command The VPN peer is a SOHO router with a dynamically assigned IP address Dynamic DNS has been configured on the SOHO router to map the dynamic IP address to the host name of vpn sohoroutercompany.com In addition to the command crypto isakmp key Cisc425007536 hostname vpn.sohoroutercompany.com what other two commands are now required on the Cisco IOS router for the VPN to continue to function after the wildcard command is removed? (Choose two)

Options:

A.  

ip host vpn.sohoroutercompany.eom < VPN Peer IP Address >

B.  

crypto isakmp identity hostname

C.  

Add the dynamic keyword to the existing crypto map command

D.  

fqdn vpn.sohoroutercompany.com < VPN Peer IP Address >

E.  

ip name-server < DNS Server IP Address >

Discussion 0
Questions 218

Drag and drop the posture assessment flow actions from the left into a sequence on the right.

Options:

Discussion 0
Questions 219

Which statement about the configuration of Cisco ASA NetFlow v9 Secure Event Logging is true?

Options:

A.  

To view bandwidth usage for NetFlow records, the QoS feature must be enabled.

B.  

A sysopt command can be used to enable NSEL on a specific interface.

C.  

NSEL can be used without a collector configured.

D.  

A flow-export event type must be defined under a policy

Discussion 0
Questions 220

Which two application layer preprocessors are used by Firepower Next Generation Intrusion Prevention

System? (Choose two)

Options:

A.  

packet decoder

B.  

SIP

C.  

modbus

D.  

inline normalization

E.  

SSL

Discussion 0
Questions 221

With which components does a southbound API within a software-defined network architecture communicate?

Options:

A.  

controllers within the network

B.  

applications

C.  

appliances

D.  

devices such as routers and switches

Discussion 0
Questions 222

Which component of Cisco umbrella architecture increases reliability of the service?

Options:

A.  

Anycast IP

B.  

AMP Threat grid

C.  

Cisco Talos

D.  

BGP route reflector

Discussion 0
Questions 223

How does Cisco Umbrella protect clients when they operate outside of the corporate network?

Options:

A.  

by modifying the registry for DNS lookups

B.  

by using Active Directory group policies to enforce Cisco Umbrella DNS servers

C.  

by using the Cisco Umbrella roaming client

D.  

by forcing DNS queries to the corporate name servers

Discussion 0
Questions 224

An engineer is configuring Cisco Secure Endpoint to enhance network security by specifying a large set of external IP addresses that must be monitored for potential threats. The engineer is configuring an IP List and must add the IP addresses to the list. Which configuration action must the engineer take next to meet the requirement?

Options:

A.  

Add the IP addresses using the global bulk configuration wizard.

B.  

Automate a threat-feed subscription using an API.

C.  

Use the data-upload function and import a file formatted as JSON.

D.  

Use the Add Multiple Rows feature and paste all addresses into the input field.

Discussion 0
Questions 225

Refer to the exhibit. A network engineer must configure a Cisco router to send traps using SNMPv3. The engineer configures a remote user to receive traps and sets the security level to use authentication without privacy. Which command completes the configuration?

Options:

A.  

snmp-server host 10.12.8.4 informs version 3 noauthno remoteuser config

B.  

snmp-server host 10.12.8.4 informs version 3 noauthnoPriv remoteuser config

C.  

snmp-server user TrapUser group2 remote 10.12.8.4 v3 auth md5 password1

D.  

snmp-server user TrapUser group2 remote 10.12.8.4 v3 auth md5 password1 priv access des56

Discussion 0
Questions 226

What is a characteristic of Cisco ASA Netflow v9 Secure Event Logging?

Options:

A.  

It tracks flow-create, flow-teardown, and flow-denied events.

B.  

It provides stateless IP flow tracking that exports all records of a specific flow.

C.  

It tracks the flow continuously and provides updates every 10 seconds.

D.  

Its events match all traffic classes in parallel.

Discussion 0
Questions 227

How does Cisco Workload Optimization portion of the network do EPP solutions solely performance issues?

Options:

A.  

It deploys an AWS Lambda system

B.  

It automates resource resizing

C.  

It optimizes a flow path

D.  

It sets up a workload forensic score

Discussion 0
Questions 228

What is the purpose of threat intelligence in the Cisco Security Reference Architecture?

Options:

A.  

To assist with threat monitoring and incident response

B.  

To manage access control and authentication mechanisms

C.  

To analyze network traffic and identify potential vulnerabilities

D.  

To ensure compliance with industry regulations

Discussion 0
Questions 229

What is a prerequisite when integrating a Cisco ISE server and an AD domain?

Options:

A.  

Place the Cisco ISE server and the AD server in the same subnet

B.  

Configure a common administrator account

C.  

Configure a common DNS server

D.  

Synchronize the clocks of the Cisco ISE server and the AD server

Discussion 0
Questions 230

Which MDM configuration provides scalability?

Options:

A.  

pushing WPA2-Enterprise settings automatically to devices

B.  

enabling use of device features such as camera use

C.  

BYOD support without extra appliance or licenses

D.  

automatic device classification with level 7 fingerprinting

Discussion 0
Questions 231

Drag and drop the deployment models from the left onto the explanations on the right.

Options:

Discussion 0
Questions 232

Which open source tool does Cisco use to create graphical visualizations of network telemetry on Cisco IOS XE devices?

Options:

A.  

InfluxDB

B.  

Splunk

C.  

SNMP

D.  

Grafana

Discussion 0
Questions 233

A network administrator needs to find out what assets currently exist on the network. Third-party systems need to be able to feed host data into Cisco Firepower. What must be configured to accomplish this?

Options:

A.  

a Network Discovery policy to receive data from the host

B.  

a Threat Intelligence policy to download the data from the host

C.  

a File Analysis policy to send file data into Cisco Firepower

D.  

a Network Analysis policy to receive NetFlow data from the host

Discussion 0
Questions 234

What is a characteristic of Dynamic ARP Inspection?

Options:

A.  

DAI determines the validity of an ARP packet based on valid IP to MAC address bindings from the DHCPsnooping binding database.

B.  

In a typical network, make all ports as trusted except for the ports connecting to switches, which areuntrusted

C.  

DAI associates a trust state with each switch.

D.  

DAI intercepts all ARP requests and responses on trusted ports only.

Discussion 0
Questions 235

What is a language format designed to exchange threat intelligence that can be transported over the TAXII

protocol?

Options:

A.  

STIX

B.  

XMPP

C.  

pxGrid

D.  

SMTP

Discussion 0
Questions 236

Which encryption algorithm provides highly secure VPN communications?

Options:

A.  

3DES

B.  

AES 256

C.  

AES 128

D.  

DES

Discussion 0
Questions 237

What is a benefit of using Cisco Umbrella?

Options:

A.  

DNS queries are resolved faster.

B.  

Attacks can be mitigated before the application connection occurs.

C.  

Files are scanned for viruses before they are allowed to run.

D.  

It prevents malicious inbound traffic.

Discussion 0
Questions 238

Refer to the exhibit.

An engineer configures an IPsec VPN between two Cisco Secure Firewall Threat Defense devices named FTD1 and FTD2. However, the hosts behind FTD1 and FTD2 cannot communicate with each other. The engineer runs a debug command to troubleshoot the issue. What must be configured to resolve the issue?

Options:

A.  

Transform set

B.  

Crypto access control list

C.  

NAT traversal

D.  

Preshared secret

Discussion 0
Questions 239

An organization is receiving SPAM emails from a known malicious domain. What must be configured in order to

prevent the session during the initial TCP communication?

Options:

A.  

Configure the Cisco ESA to drop the malicious emails

B.  

Configure policies to quarantine malicious emails

C.  

Configure policies to stop and reject communication

D.  

Configure the Cisco ESA to reset the TCP connection

Discussion 0
Questions 240

An engineer has been tasked with implementing a solution that can be leveraged for securing the cloud users,

data, and applications. There is a requirement to use the Cisco cloud native CASB and cloud cybersecurity

platform. What should be used to meet these requirements?

Options:

A.  

Cisco Umbrella

B.  

Cisco Cloud Email Security

C.  

Cisco NGFW

D.  

Cisco Cloudlock

Discussion 0