100% Pass Top-selling 350-701 Exams - New 2024 Cisco Pratice Exam
CCNP Security Dumps 350-701 Exam for Full Questions - Exam Study Guide
NEW QUESTION # 37
An engineer wants to generate NetFlow records on traffic traversing the Cisco ASA. Which Cisco ASA command must be used?
- A. ip flow monitor<name> input
- B. ip flow-export destination 1.1.1.1 2055
- C. flow-export destination inside 1.1.1.1 2055
- D. flow exporter <name>
Answer: C
NEW QUESTION # 38
An administrator is configuring N I P on Cisco ASA via ASDM and needs to ensure that rogue NTP servers cannot insert themselves as the authoritative time source Which two steps must be taken to accomplish this task? (Choose two)
- A. Specify the NTP version
- B. Set the authentication key
- C. Configure the NTP stratum
- D. Set the NTP DNS hostname
- E. Choose the interface for syncing to the NTP server
Answer: B,D
NEW QUESTION # 39
An organization is using Cisco Firepower and Cisco Meraki MX for network security and needs to centrally manage cloud policies across these platforms. Which software should be used to accomplish this goal?
- A. Cisco Defense Orchestrator
- B. Cisco Configuration Professional
- C. Cisco DNA Center
- D. Cisco Secureworks
Answer: A
Explanation:
Explanation Explanation Cisco Defense Orchestrator is a cloud-based management solution that allows you to manage security policies and device configurations with ease across multiple Cisco and cloud-native security platforms. Cisco Defense Orchestrator features: .... Management of hybrid environments: Managing a mix of firewalls running the ASA, FTD, and Meraki MX software is now easy, with the ability to share policy elements across platforms. Reference: https://www.cisco.com/c/en/us/products/collateral/security/defense-orchestrator/datasheet-c78- 736847.html Explanation Cisco Defense Orchestrator is a cloud-based management solution that allows you to manage security policies and device configurations with ease across multiple Cisco and cloud-native security platforms.
Cisco Defense Orchestrator features:
....
Management of hybrid environments: Managing a mix of firewalls running the ASA, FTD, and Meraki MX software is now easy, with the ability to share policy elements across platforms.
Reference:
Explanation Explanation Cisco Defense Orchestrator is a cloud-based management solution that allows you to manage security policies and device configurations with ease across multiple Cisco and cloud-native security platforms. Cisco Defense Orchestrator features: .... Management of hybrid environments: Managing a mix of firewalls running the ASA, FTD, and Meraki MX software is now easy, with the ability to share policy elements across platforms. Reference: https://www.cisco.com/c/en/us/products/collateral/security/defense-orchestrator/datasheet-c78- 736847.html
NEW QUESTION # 40
What does Cisco AMP for Endpoints use to help an organization detect different families of malware?
- A. Clam AV Engine to perform email scanning
- B. Tetra Engine to detect malware when me endpoint is connected to the cloud
- C. Spero Engine with machine learning to perform dynamic analysis
- D. Ethos Engine to perform fuzzy fingerprinting
Answer: D
Explanation:
ETHOS is the Cisco file grouping engine. It allows us to group families of files together so if we see variants of a malware, we mark the ETHOS hash as malicious and whole families of malware are instantly detected.
ETHOS is the Cisco file grouping engine. It allows us to group families of files together so if we see variants of a malware, we mark the ETHOS hash as malicious and whole families of malware are instantly detected.
Reference:
ETHOS = Fuzzy Fingerprinting using static/passive heuristics
ETHOS is the Cisco file grouping engine. It allows us to group families of files together so if we see variants of a malware, we mark the ETHOS hash as malicious and whole families of malware are instantly detected.
ETHOS = Fuzzy Fingerprinting using static/passive heuristics
NEW QUESTION # 41
Refer to the exhibit.
When configuring a remote access VPN solution terminating on the Cisco ASA, an administrator would like to utilize an external token authentication mechanism in conjunction with AAA authentication using machine certificates. Which configuration item must be modified to allow this?
- A. DHCP Servers
- B. Group Policy
- C. SAML Server
- D. Method
Answer: D
Explanation:
In order to use AAA along with an external token authentication mechanism, set the "Method" as "Both" in the Authentication.
NEW QUESTION # 42
Which algorithm is an NGE hash function?
- A. SHA-1
- B. MD5
- C. SISHA-2
- D. HMAC
Answer: C
NEW QUESTION # 43
DoS attacks are categorized as what?
- A. phishing attacks
- B. flood attacks
- C. virus attacks
- D. trojan attacks
Answer: B
NEW QUESTION # 44
Which two risks is a company vulnerable to if it does not have a well-established patching solution for endpoints? (Choose two.)
- A. malware
- B. exploits
- C. eavesdropping
- D. denial-of-service attacks
- E. ARP spoofing
Answer: B,C
NEW QUESTION # 45
What is a language format designed to exchange threat intelligence that can be transported over the TAXII protocol?
- A. SMTP
- B. XMPP
- C. pxGrid
- D. STIX
Answer: D
Explanation:
Explanation/Reference: https://www.cisco.com/c/en/us/td/docs/security/web_security/scancenter/administrator/guide/ b_ScanCenter_Administrator_Guide/b_ScanCenter_Administrator_Guide_chapter_0100011.pdf
NEW QUESTION # 46
What is a capability of Cisco ASA Netflow?
- A. It sends NetFlow data records from active and standby ASAs in an active standby failover pair
- B. It filters NSEL events based on traffic
- C. It logs all event types only to the same collector
- D. It generates NSEL events even if the MPF is not configured
Answer: B
Explanation:
https://www.cisco.com/c/en/us/td/docs/security/wsa/wsa11-0/user_guide/b_WSA_UserGuide/b_WSA_UserGuide_chapter_01101.html Policy Order The order in which policies are listed in a policy table determines the priority with which they are applied to Web requests. Web requests are checked against policies beginning at the top of the table and ending at the first policy matched. Any policies below that point in the table are not processed. If no user-defined policy is matched against a Web request, then the global policy for that policy type is applied. Global policies are always positioned last in Policy tables and cannot be re-ordered.
NEW QUESTION # 47
Which attribute has the ability to change during the RADIUS CoA?
- A. accessibility
- B. authorization
- C. NTP
- D. membership
Answer: C
NEW QUESTION # 48
An engineer must force an endpoint to re-authenticate an already authenticated session without disrupting the endpoint to apply a new or updated policy from ISE. Which CoA type achieves this goal?
- A. CoA Reauth
- B. Port Bounce
- C. CoA Terminate
- D. CoA Session Query
Answer: A
NEW QUESTION # 49
What must be configured in Cisco ISE to enforce reauthentication of an endpoint session when an endpoint is deleted from an identity group?
- A. external identity source
- B. SNMP probe
- C. posture assessment
- D. CoA
Answer: D
Explanation:
Cisco ISE allows a global configuration to issue a Change of Authorization (CoA) in the Profiler Configuration page that enables the profiling service with more control over endpoints that are already authenticated.
One of the settings to configure the CoA type is "Reauth". This option is used to enforce reauthentication of an already authenticated endpoint when it is profiled.
Cisco ISE allows a global configuration to issue a Change of Authorization (CoA) in the Profiler Configuration page that enables the profiling service with more control over endpoints that are already authenticated.
One of the settings to configure the CoA type is "Reauth". This option is used to enforce reauthentication of an already authenticated endpoint when it is profiled.
Reference:
b_ise_admin_guide_sample_chapter_010101.html
Cisco ISE allows a global configuration to issue a Change of Authorization (CoA) in the Profiler Configuration page that enables the profiling service with more control over endpoints that are already authenticated.
One of the settings to configure the CoA type is "Reauth". This option is used to enforce reauthentication of an already authenticated endpoint when it is profiled.
b_ise_admin_guide_sample_chapter_010101.html
NEW QUESTION # 50
An engineer configures new features within the Cisco Umbrella dashboard and wants to identify and proxy traffic that is categorized as risky domains and may contain safe and malicious content. Which action accomplishes these objectives?
- A. Configure intelligent proxy within Cisco Umbrella to intercept and proxy the requests for only those categories.
- B. Configure URL filtering within Cisco Umbrella to track the URLs and proxy the requests for those categories and below.
- C. Create a new site within Cisco Umbrella to block requests from those categories so they can be sent to the proxy device.
- D. Upload the threat intelligence database to Cisco Umbrella for the most current information on reputations and to have the destination lists block them.
Answer: A
NEW QUESTION # 51
Which Cisco DNA Center Intent API action is used to retrieve the number of devices known to a DNA Center?
- A. GET
https://fqdnOrlPofDnaCenterPlatform/dna/intent/api/v1/networkdevice?parameter1=value¶meter2=va - B. GET https://fqdnOrlPofDnaCenterPlatform/dna/intent/api/v
1/networkdevice/startIndex/recordsToReturn - C. GET https://fqdnOrlPofDnaCenterPlatform/dna/intent/api/v1/network-device/count
- D. GET https://fqdnOrlPofDnaCenterPlatform/dna/intent/api/v1/network-device
Answer: C
NEW QUESTION # 52
Refer to the exhibit. What is the function of the Python script code snippet for the Cisco ASA REST API?
- A. changes the hostname of the Cisco ASA
- B. deletes a global rule from policies
- C. obtains the saved configuration of the Cisco ASA firewall
- D. adds a global rule into policies
Answer: D
NEW QUESTION # 53
What is the difference between a vulnerability and an exploit?
- A. An exploit is a hypothetical event that causes a vulnerability in the network
- B. An exploit is a weakness that can cause a vulnerability in the network
- C. A vulnerability is a weakness that can be exploited by an attacker
- D. A vulnerability is a hypothetical event for an attacker to exploit
Answer: C
Explanation:
vulnerability is a flaw or gap in the security of a system or network that can be exploited by an attacker to compromise its functionality, integrity, confidentiality, or availability. A vulnerability can exist in the design, implementation, configuration, or operation of a system or network, and can be caused by human errors, software bugs, hardware defects, or environmental factors. A vulnerability can be exploited by an attacker using various methods, such as malware, phishing, brute force, denial-of-service, or injection attacks. A vulnerability can also be exploited by an insider who has legitimate access to the system or network, but abuses their privileges for malicious purposes. A vulnerability can be discovered by security researchers, ethical hackers, or malicious hackers, and can be reported to the vendor or the public for remediation or exploitation. A vulnerability can be mitigated by applying patches, updates, or configuration changes, or by using security tools such as firewalls, antivirus, or encryption.
An exploit is a piece of code, data, or technique that takes advantage of a vulnerability to perform unauthorized or malicious actions on a system or network. An exploit can be used to gain access, escalate privileges, execute commands, steal data, disrupt services, or damage resources. An exploit can be delivered by various means, such as email attachments, web links, removable media, or network packets. An exploit can be developed by security researchers, ethical hackers, or malicious hackers, and can be shared or sold on the dark web or other platforms for testing or attacking purposes. An exploit can be detected by security tools such as intrusion detection systems, antivirus, or anti-exploit software.
The difference between a vulnerability and an exploit is that a vulnerability is a potential weakness that can be exploited, while an exploit is an actual attack that uses a vulnerability. A vulnerability can exist without being exploited, but an exploit cannot exist without a vulnerability. A vulnerability can be fixed or prevented, but an exploit can only be blocked or stopped. References :=
* Exploit vs Vulnerability: What's the Difference? - InfoSec Insights
* Difference Between Vulnerability and Exploit - GeeksforGeeks
* Exploit vs. Vulnerability: What Is the Difference? - Coralogix
* Exploit vs Vulnerability: What's the Difference? - Cybers Guards
NEW QUESTION # 54
Which method is used to deploy certificates and configure the supplicant on mobile devices to gain access to network resources?
- A. BYOD on boarding
- B. Client provisioning
- C. MAC authentication bypass
- D. Simple Certificate Enrollment Protocol
Answer: A
NEW QUESTION # 55
Refer to the exhibit.
A network administrator configures command authorization for the admin5 user. What is the admin5 user able to do on HQ_Router after this configuration?
- A. complete all configurations
- B. complete no configurations
- C. set the IP address of an interface
- D. add subinterfaces
Answer: B
Explanation:
The user "admin5" was configured with privilege level 5. In order to allow configuration (enter global configuration mode), we must type this command: (config)#privilege exec level 5 configure terminal Without this command, this user cannot do any configuration. Note: Cisco IOS supports privilege levels from 0 to 15, but the privilege levels which are used by default are privilege level 1 (user EXEC) and level privilege 15 (privilege EXEC)
NEW QUESTION # 56
Refer to the exhibit.
Traffic is not passing through IPsec site-to-site VPN on the Firepower Threat Defense appliance. What is causing this issue?
- A. The access control policy is not allowing VPN traffic in.
- B. Site-to-site VPN preshared keys are mismatched.
- C. No split-tunnel policy is defined on the Firepower Threat Defense appliance.
- D. Site-to-site VPN peers are using different encryption algorithms.
Answer: C
Explanation:
Reference: https://www.cisco.com/c/en/us/support/docs/security-vpn/ipsec-negotiation-ike-protocols/215470- site-to-site-vpn-configuration-on-ftd-ma.html
NEW QUESTION # 57
Which two criteria must a certificate meet before the WSA uses it to decrypt application traffic? (Choose two.)
- A. it must contain a SAN.
- B. It must reside in the trusted store of the endpoint.
- C. It must reside in the trusted store of the WSA.
- D. It must have been signed by an internal CA.
- E. It must include the current date.
Answer: A,C
Explanation:
The WSA uses a root certificate and a private key to decrypt HTTPS traffic. The root certificate must reside in the trusted store of the WSA, and it must be able to sign server certificates on the fly. The server certificates that the WSA generates must contain a SAN (Subject Alternative Name) field, which specifies the hostnames or IP addresses that the certificate is valid for. The SAN field is required by modern browsers and applications to verify the identity of the server. If the WSA does not include a SAN field in the server certificate, the browser or application may reject the connection or display a warning message.
The other options are not correct because:
* A. The current date is not a criterion for the WSA to use a certificate to decrypt application traffic. The WSA checks the validity period of the certificate, which includes the start date and the end date. The current date must be within the validity period, but it does not have to be the same as the start date or the end date.
* C. The root certificate that the WSA uses to decrypt HTTPS traffic does not have to reside in the trusted store of the endpoint. However, the endpoint must trust the root certificate in order to accept the server certificate that the WSA generates. This can be achieved by manually installing the root certificate on the endpoint, or by using a group policy or a certificate management system to distribute the root certificate to the endpoints.
* D. The root certificate that the WSA uses to decrypt HTTPS traffic does not have to be signed by an internal CA. The WSA can generate its own self-signed root certificate, or it can use a root certificate that is signed by an external CA. However, the root certificate must be trusted by the endpoints, as explained in option C.
References := : WSA Certificate Usage for HTTPS Decryption : [User Guide for AsyncOS 12.0 for Cisco Web Security Appliances - GD (General Deployment) - Create Decryption Policies to Control HTTPS Traffic]
NEW QUESTION # 58
Which solution stops unauthorized access to the system if a user's password is compromised?
- A. MFA
- B. AMP
- C. SSL
- D. VPN
Answer: A
NEW QUESTION # 59
Which function is included when Cisco AMP is added to web security?
- A. detailed analytics of the unknown file's behavior
- B. phishing detection on emails
- C. threat prevention on an infected endpoint
- D. multifactor, authentication-based user identity
Answer: A
NEW QUESTION # 60
An engineer used a posture check on a Microsoft Windows endpoint and discovered that the MS17-010 patch was not installed, which left the endpoint vulnerable to WannaCry ransomware. Which two solutions mitigate the risk of this ransomware infection? (Choose two.)
- A. Set up a well-defined endpoint patching strategy to ensure that endpoints have critical vulnerabilities patched in a timely fashion.
- B. Configure a posture policy in Cisco Identity Services Engine to install the MS17-010 patch before allowing access on the network.
- C. Configure endpoint firewall policies to stop the exploit traffic from being allowed to run and replicate throughout the network.
- D. Set up a profiling policy in Cisco Identity Service Engine to check and endpoint patch level before allowing access on the network.
- E. Configure a posture policy in Cisco Identity Services Engine to check that an endpoint patch level is met before allowing access on the network.
Answer: B,E
NEW QUESTION # 61
An organization wants to secure data in a cloud environment. Its security model requires that all users be authenticated and authorized. Security configuration and posture must be continuously validated before access is granted or maintained to applications and dat a. There is also a need to allow certain application traffic and deny all other traffic by default. Which technology must be used to implement these requirements?
- A. Virtual LAN
- B. Microsegmentation
- C. Access control policy
- D. Virtual routing and forwarding
Answer: B
Explanation:
Explanation
Zero Trust is a security framework requiring all users, whether in or outside the organization's network, to be authenticated, authorized, and continuously validated for security configuration and posture before being granted or keeping access to applications and data. Zero Trust assumes that there is no traditional network edge; networks can be local, in the cloud, or a combination or hybrid with resources anywhere as well as workers in any location.
The Zero Trust model uses microsegmentation - a security technique that involves dividing perimeters into small zones to maintain separate access to every part of the network - to contain attacks.
NEW QUESTION # 62
......
Authentic Best resources for 350-701 Online Practice Exam: https://prepaway.dumptorrent.com/350-701-braindumps-torrent.html