Weekend Special Sale 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale75best

Free Cisco 350-701 Practice Exam with Questions & Answers | Set: 10

Questions 136

Refer to the exhibit.

350-701 Question 136

Which type of authentication is in use?

Options:
A.

LDAP authentication for Microsoft Outlook

B.

POP3 authentication

C.

SMTP relay server authentication

D.

external user and relay mail authentication

Cisco 350-701 Premium Access
Questions 137

A security policy administrator configures a Cisco Secure Access SIA DNS policy to block all social media categories for the Marketing Active Directory group. While testing from one of the user machines, access to the domain https://socialmediaexample.org is allowed. When searching for this domain in User Activity Search, no queries for that specific domain are returned. Consider these facts:

    The test user is part of the Marketing Active Directory group.

    The domain socialmediaexample.org belongs to the social media category.

    The user is configured with the Umbrella Roaming Client for DNS redirection.

    All other social media websites are properly blocked for the same user and match the correct policy.

Which configuration must the administrator implement in Cisco Secure Access to meet the requirement?

Options:
A.

Enable HTTPS inspection in the web policy because this is an HTTPS site.

B.

Add socialmediaexample.org to the External Domains list.

C.

Enable the intelligent proxy to identify this domain properly.

D.

Add socialmediaexample.org to the Internal Domains list.

Questions 138

A facilities team is onboarding a fleet of badge readers and IP cameras through MAB authentication on Cisco Catalyst access switches integrated with Cisco ISE. After Cisco ISE profiles each endpoint, an authorization policy must dynamically move the device into a dedicated IoT VLAN that differs from the access VLAN statically defined on the port. The endpoints lack a supplicant and cannot automatically renew their DHCP addresses. The network engineer requires Cisco ISE to issue a Change of Authorization that forces each endpoint to re-establish connectivity and request a fresh DHCP lease under the new authorization policy. Which configuration action must be performed on Cisco ISE to meet the requirement?

Options:
A.

Configure the authorization profile to send a CoA-Reauth to the access switch.

B.

Configure the authentication policy to send a CoA-Terminate to reconnect the endpoint.

C.

Configure the authorization profile to send a Port-Bounce CoA to the switch.

D.

Configure the authorization policy to send a CoA-Reconnect and rely on the idle timeout.

Questions 139

Which two endpoint measures are used to minimize the chances of falling victim to phishing and social

engineering attacks? (Choose two)

Options:
A.

Patch for cross-site scripting.

B.

Perform backups to the private cloud.

C.

Protect against input validation and character escapes in the endpoint.

D.

Install a spam and virus email filter.

E.

Protect systems with an up-to-date antimalware program

Questions 140

350-701 Question 140

Refer to the exhibit. An engineer must configure an incoming mail policy so that each email sent from usera1@example.com to a domain of @cisco.com is scanned for antispam and advanced malware protection. All other settings will use the default behavior. What must be configured in the incoming mail policy to meet the requirements?

Options:
A.

Policy Name: Default Policy  Sender: usera1@example.com  Recipient: @cisco.com

B.

Policy Name: usera1 policy  Sender: usera1@example.com  Recipient: @cisco.com

C.

Policy Name: Anti-Malware policy  Sender: usera1@example.com  Recipient: @cisco.com

D.

Policy Name: cisco.com policy  Sender: usera1@example.com  Recipient: @cisco.com

Questions 141

Which two configurations must be made on Cisco ISE and on Cisco TrustSec devices to force a session to be adjusted after a policy change is made? (Choose two)

Options:
A.

posture assessment

B.

aaa authorization exec default local

C.

tacacs-server host 10.1.1.250 key password

D.

aaa server radius dynamic-author

E.

CoA

Questions 142

For which type of attack is multifactor authentication an effective deterrent?

Options:
A.

Ping of death

B.

Teardrop

C.

SYN flood

D.

Phishing

Questions 143

Which feature is configured for managed devices in the device platform settings of the Firepower Management

Center?

Options:
A.

quality of service

B.

time synchronization

C.

network address translations

D.

intrusion policy

Questions 144

Refer to the exhibit.

350-701 Question 144

A Cisco Secure Endpoint malware event shows that a file was convicted as malicious and that its remediation status is Quarantine Failed. Before escalating the incident, the analyst must determine what can be concluded from the available event data. What is occurring based on the logs?

Options:
A.

The event data does not establish whether the threat remains present or was remediated through another mechanism.

B.

The failed-quarantine status proves that the endpoint was unable to apply the configured remediation policy.

C.

The failed-quarantine status proves that the file remained accessible to the operating system after the remediation attempt.

D.

The failed-quarantine status proves that the threat continued executing after the remediation attempt.

Questions 145

Which public cloud provider supports the Cisco Next Generation Firewall Virtual?

Options:
A.

Google Cloud Platform

B.

Red Hat Enterprise Visualization

C.

VMware ESXi

D.

Amazon Web Services

Questions 146

Which action controls the amount of URI text that is stored in Cisco WSA logs files?

Options:
A.

Configure the datasecurityconfig command

B.

Configure the advancedproxyconfig command with the HTTPS subcommand

C.

Configure a small log-entry size.

D.

Configure a maximum packet size.

Questions 147

Which mitigation strategy should be used to protect against session hijacking attacks in a cloud environment?

Options:
A.

Implement input validation.

B.

Use secure cookies.

C.

Apply the principle of least privilege.

D.

Use anti-cross-site request forgery tokens.

Questions 148

Refer to the exhibit.

350-701 Question 148

A site-to-site IKEv2 VPN between a Cisco Secure Firewall Threat Defense device with public IP address 203.0.113.10 and a third-party firewall with public IP address 198.51.100.20 is failing to establish at a logistics company. The engineer enables IKEv2 debugging on the FTD and captures the output. Which action must be performed to resolve the issue?

Options:
A.

Change the DH group in the IKEv2 policy from Group 20 to Group 14 to match the group negotiated during IKE_SA_INIT.

B.

Verify that the pre-shared key configured on the VPN peer object exactly matches the key on the remote peer, including case, special characters, and any leading or trailing spaces.

C.

Update the IKEv2 policy to remove SHA-384 and use only SHA-256, aligning Phase 1 integrity with the algorithm agreed upon during IKE_SA_INIT.

D.

Switch both peers to certificate-based authentication by enrolling an identity certificate from the corporate CA and sharing the CA certificate with the remote peer.

Questions 149

Which capability allows an administrator to configure forensics rules in Cisco Secure Workload?

Options:
A.

Custom clauses

B.

MITRE ATT & CK framework only predefined

C.

Cisco Secure Workload predefined

D.

Windows or Linux application

Questions 150

Which system performs compliance checks and remote wiping?

Options:
A.

MDM

B.

ISE

C.

AMP

D.

OTP

Cisco Related Exams

How to pass Cisco 300-710 - Securing Networks with Cisco Firepower (300-710 SNCF) v1.2 Exam
How to pass Cisco 300-715 - Implementing and Configuring Cisco Identity Services Engine (SISE) v1.1 (300-715 SISE) Exam
How to pass Cisco 300-720 - Securing Email with Cisco Email Security Appliance (300-720 SESA) Exam
How to pass Cisco 300-725 - Securing the Web with Cisco Web Security Appliance (300-725 SWSA) Exam
How to pass Cisco 300-730 - Implementing Secure Solutions with Virtual Private Networks (SVPN) Exam
How to pass Cisco 300-735 - Automating and Programming Cisco Security Solutions (300-735 SAUTO) Exam
How to pass Cisco 300-740 - Designing and Implementing Secure Cloud Access for Users and Endpoints Exam
How to pass Cisco 300-745 - Designing Cisco Security Infrastructure Exam

Cisco Free Exams

Cisco Free Exams
Examstrack offers free Cisco exam materials and practice tests to aid your Cisco certification journey.