Weekend Special Sale 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale75best

Free Cisco 350-701 Practice Exam with Questions & Answers | Set: 14

Questions 196

What is a feature of Cisco NetFlow Secure Event Logging for Cisco ASAs?

Options:
A.

Multiple NetFlow collectors are supported

B.

Advanced NetFlow v9 templates and legacy v5 formatting are supported

C.

Secure NetFlow connections are optimized for Cisco Prime Infrastructure

D.

Flow-create events are delayed

Cisco 350-701 Premium Access
Questions 197

An administrator configures new authorization policies within Cisco ISE and has difficulty profiling the devices. Attributes for the new Cisco IP phones that are profiled based on the RADIUS authentication are seen however the attributes for CDP or DHCP are not. What should the administrator do to address this issue?

Options:
A.

Configure the ip dhcp snooping trust command on the DHCP interfaces to get the information to Cisco ISE

B.

Configure the authentication port-control auto feature within Cisco ISE to identify the devices that are trying to connect

C.

Configure a service template within the switch to standardize the port configurations so that the correct information is sent to Cisco ISE

D.

Configure the device sensor feature within the switch to send the appropriate protocol information

Questions 198

What causes alert fatigue in Cisco XDR?

Options:
A.

Alerts lacking sufficient context to be accurate

B.

Reauthentication of an active endpoint during a vulnerability incident

C.

Notifications from too few devices in a data-breach event

D.

Automatic policy enforcement during a suspicious event

Questions 199

An organization recently installed a Cisco Secure Web Appliance and would like to take advantage of the AVC engine to allow the organization to create a policy to control application-specific activity. After enabling the AVC engine, what must be done to implement this?

Options:
A.

Use an access policy group to configure application control settings.

B.

Use security services to configure the traffic monitor.

C.

Use URL categorization to prevent the application traffic.

D.

Use web security reporting to validate engine functionality.

Questions 200

Which statement about IOS zone-based firewalls is true?

Options:
A.

An unassigned interface can communicate with assigned interfaces

B.

Only one interface can be assigned to a zone.

C.

An interface can be assigned to multiple zones.

D.

An interface can be assigned only to one zone.

Questions 201

Which open standard creates a framework for sharing threat intelligence in a machine-digestible format?

Options:
A.

OpenC2

B.

OpenlOC

C.

CybOX

D.

STIX

Questions 202

Which capability is exclusive to a Cisco AMP public cloud instance as compared to a private cloud instance?

Options:
A.

RBAC

B.

ETHOS detection engine

C.

SPERO detection engine

D.

TETRA detection engine

Questions 203

Which method of attack is used by a hacker to send malicious code through a web application to an unsuspecting user to request that the victim ' s web browser executes the code?

Options:
A.

buffer overflow

B.

browser WGET

C.

SQL injection

D.

cross-site scripting

Questions 204

When wired 802.1X authentication is implemented, which two components are required? (Choose two)

Options:
A.

authentication server: Cisco Identity Service Engine

B.

supplicant: Cisco AnyConnect ISE Posture module

C.

authenticator: Cisco Catalyst switch

D.

authenticator: Cisco Identity Services Engine

E.

authentication server: Cisco Prime Infrastructure

Questions 205

A security engineer is deploying an IPsec site-to-site VPN between headquarters and a remote plant, protected by Cisco Secure Firewall Threat Defense managed by Cisco Secure Firewall Management Center. The following configurations have already been completed:

    Matching IKEv2 proposals, preshared keys, and IPsec transform sets

    Access control rules permitting the traffic

    Crypto maps applied to the outside interfaces

    VPN traffic exempted from inspection

During a packet capture on the firewall, the engineer observes that the traffic is translated to the public IP address, preventing tunnel establishment. Which configuration action must be performed next?

Options:
A.

Configure NAT exemption for traffic between the interesting subnet pairs.

B.

Create a tunnel group with preshared-key authentication under connection profiles.

C.

Enable IKEv2 fragmentation on both peers to reduce packet size.

D.

Attach the new VPN policy to the global prefilter default action.

Questions 206

What is a characteristic of traffic storm control behavior?

Options:
A.

Traffic storm control drops all broadcast and multicast traffic if the combined traffic exceeds the level withinthe interval.

B.

Traffic storm control cannot determine if the packet is unicast or broadcast.

C.

Traffic storm control monitors incoming traffic levels over a 10-second traffic storm control interval.

D.

Traffic storm control uses the Individual/Group bit in the packet source address to determine if the packet isunicast or broadcast.

Questions 207

Which feature is used to restrict communication between interfaces on a Cisco ASA?

Options:
A.

VLAN subinterfaces

B.

Traffic zones

C.

Security levels

D.

VxLAN interfaces

Questions 208

A network engineer is deciding whether to use stateful or stateless failover when configuring two Cisco ASAs for high availability. What is the connection status in both cases?

Options:
A.

Need to be reestablished with both stateful and stateless failover

B.

Need to be reestablished with stateful failover and preserved with stateless failover

C.

Preserved with both stateful and stateless failover

D.

Preserved with stateful failover and need to be reestablished with stateless failover

Questions 209

For which two conditions can an endpoint be checked using ISE posture assessment? (Choose two)

Options:
A.

Windows service

B.

computer identity

C.

user identity

D.

Windows firewall

E.

default browser

Questions 210

Where are individual sites specified to be block listed in Cisco Umbrella?

Options:
A.

Application settings

B.

Security settings

C.

Destination lists

D.

Content categories

Cisco Related Exams

How to pass Cisco 300-710 - Securing Networks with Cisco Firepower (300-710 SNCF) v1.2 Exam
How to pass Cisco 300-715 - Implementing and Configuring Cisco Identity Services Engine (SISE) v1.1 (300-715 SISE) Exam
How to pass Cisco 300-720 - Securing Email with Cisco Email Security Appliance (300-720 SESA) Exam
How to pass Cisco 300-725 - Securing the Web with Cisco Web Security Appliance (300-725 SWSA) Exam
How to pass Cisco 300-730 - Implementing Secure Solutions with Virtual Private Networks (SVPN) Exam
How to pass Cisco 300-735 - Automating and Programming Cisco Security Solutions (300-735 SAUTO) Exam
How to pass Cisco 300-740 - Designing and Implementing Secure Cloud Access for Users and Endpoints Exam
How to pass Cisco 300-745 - Designing Cisco Security Infrastructure Exam

Cisco Free Exams

Cisco Free Exams
Examstrack offers free Cisco exam materials and practice tests to aid your Cisco certification journey.