Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free Cisco 300-740 Practice Exam with Questions & Answers

Questions 1

A security analyst detects an employee endpoint making connections to a malicious IP on the internet and downloaded a file named Test0511127691C.pdf. The analyst discovers the machine is infected by trojan malware. What must the analyst do to mitigate the threat using Cisco Secure Endpoint?

Options:
A.

Identify the malicious IPs and place them in a blocked list

B.

Create an IP Block list and add the IP address of the affected endpoint

C.

Enable scheduled scans to detect and block the executable files

D.

Start isolation of the machine on the Computers tab

Cisco 300-740 Premium Access
Questions 2

300-740 Question 2

Refer to the exhibit. An engineer must configure a global allow list in Cisco Umbrella for the cisco.com domain. All other domains must be blocked. After creating a new policy and adding the cisco.com domain, the engineer attempts to access a site outside of cisco.com and is successful. Which additional Security Settings action must be taken to meet the requirement?

Options:
A.

Limit Content Access.

B.

Enforce SafeSearch.

C.

Enable Allow-Only Mode

D.

Apply Destination List.

Questions 3

300-740 Question 3

Refer to the exhibit. A security engineer must configure a posture policy in Cisco ISE to ensure that employee laptops have a critical patch for WannaCry installed before they can access the network. Which posture condition must the engineer configure?

Options:
A.

Patch Management Condition

B.

File Condition

C.

Anti-Virus Condition

D.

Anti-Malware Condition

Questions 4

A recent InfraGard news release indicates the need to establish a risk ranking for all on-premises and cloud services. The ACME Corporation already performs risk assessments for on-premises services and has applied a risk ranking to them. However, the cloud services that were used lack risk rankings. What Cisco Umbrella function should be used to meet the requirement?

Options:
A.

Secure Internet Gateway

B.

Domain Name Server Filtering

C.

URL Categorization by Talos

D.

App Discovery

Questions 5

An administrator received an incident report indicating suspicious activity of a user using a corporate device. The manager requested that the credentials of user user1@cisco.com be reset and synced via the Active Directory. Removing the account should be avoided and used for further investigation on data leak. Which configuration must the administrator apply on the Duo Admin Panel?

Options:
A.

Delete the user in the Users tab option and sync it with the domain controller.

B.

Quarantine the user from all the policies on the Policies tab, including associated devices.

C.

Request the password change on the Device tab on managed devices.

D.

Disable the account on the Users tab and reset the password from the Active Directory.

Questions 6

300-740 Question 6

Refer to the exhibit. An engineer must enable access to Salesforce using Cisco Umbrella and Cisco Cloudlock. These actions were performed:

    From Salesforce, add the Cloudlock IP address to the allow list

    From Cloudlock, authorize Salesforce

However, Salesforce access via Cloudlock is still unauthorized. What should be done to meet the requirements?

Options:
A.

From the Salesforce admin page, grant API access to Cloudlock.

B.

From the Salesforce admin page, grant network access to Cloudlock

C.

From the Cloudlock dashboard, grant API access to Salesforce.

D.

From the Cloudlock dashboard, grant network access to Salesforce.

Questions 7

300-740 Question 7

300-740 Question 7

Refer to the exhibit. An engineer is investigating an issue by using Cisco Secure Cloud Analytics. The engineer confirms that the connections are unauthorized and informs the incident management team. Which two actions must be taken next? (Choose two.)

Options:
A.

Reinstall the host from a recent backup.

B.

Quarantine the host

C.

Reinstall the host from scratch.

D.

Create a firewall rule that has a source of linux-gcp-east-4c, a destination of Any, and a protocol of SSH.

E.

Create a firewall rule that has a source of Any, a destination of linux-gcp-east-4c, and a protocol of SSH.

Questions 8

According to Cisco Security Reference Architecture, which solution provides threat intelligence and malware analytics?

Options:
A.

Cisco pxGrid

B.

Cisco XDR

C.

Cisco Talos

D.

Cisco Umbrella

Questions 9

300-740 Question 9

Refer to the exhibit. An engineer must configure a remote access IPsec/IKEv2 VPN that will use SHA-512 on a Cisco ASA firewall. The indicated configuration was applied to the firewall; however, the tunnel fails to establish. Which command must be run to meet the requirement?

Options:
A.

integrity sha512

B.

protocol esp encryption sha512

C.

ipsec-proposal sha512

D.

encryption sha512

Questions 10

Which mitigation technique does a web application firewall use to protect a web server against DDoS attacks?

Options:
A.

Source-specific ACL

B.

Standard ACL

C.

Packet filtering

D.

Rate-based rules

Exam Code: 300-740
Certification Provider: Cisco
Exam Name: Designing and Implementing Secure Cloud Access for Users and Endpoints (SCAZT)
Last Update: Oct 15, 2025
Questions: 61
PDF + Testing Engine
$174.99
$70
Testing Engine
$134.99
$54
PDF (Q&A)
$114.99
$46

Cisco Related Exams

How to pass Cisco 300-710 - Securing Networks with Cisco Firepower (300-710 SNCF) Exam
How to pass Cisco 300-715 - Implementing and Configuring Cisco Identity Services Engine (SISE) v4.0 (300-715 SISE) Exam
How to pass Cisco 300-720 - Securing Email with Cisco Email Security Appliance (300-720 SESA) Exam
How to pass Cisco 300-725 - Securing the Web with Cisco Web Security Appliance (300-725 SWSA) Exam
How to pass Cisco 300-730 - Implementing Secure Solutions with Virtual Private Networks (SVPN) Exam
How to pass Cisco 300-735 - Automating and Programming Cisco Security Solutions (300-735 SAUTO) Exam
How to pass Cisco 350-701 - Implementing and Operating Cisco Security Core Technologies (SCOR 350-701) Exam

Cisco Free Exams

Cisco Free Exams
Examstrack offers free Cisco exam materials and practice tests to aid your Cisco certification journey.