Weekend Special Sale 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale75best

Free Cisco 350-701 Practice Exam with Questions & Answers | Set: 2

Questions 16

After deploying a Cisco ESA on your network, you notice that some messages fail to reach their destinations.

Which task can you perform to determine where each message was lost?

Options:
A.

Configure the trackingconfig command to enable message tracking.

B.

Generate a system report.

C.

Review the log files.

D.

Perform a trace.

Cisco 350-701 Premium Access
Questions 17

What is a description of microsegmentation?

Options:
A.

Environments deploy a container orchestration platform, such as Kubernetes, to manage the application delivery.

B.

Environments apply a zero-trust model and specify how applications on different servers or containers can communicate.

C.

Environments deploy centrally managed host-based firewall rules on each server or container.

D.

Environments implement private VLAN segmentation to group servers with similar applications.

Questions 18

Drag and drop the threats from the left onto examples of that threat on the right

350-701 Question 18

Options:
Questions 19

In an IaaS cloud services model, which security function is the provider responsible for managing?

Options:
A.

Internet proxy

B.

firewalling virtual machines

C.

CASB

D.

hypervisor OS hardening

Questions 20

Drag and drop the capabilities from the left onto the correct technologies on the right.

350-701 Question 20

Options:
Questions 21

Which feature within Cisco Umbrella allows for the ability to inspect secure HTTP traffic?

Options:
A.

File Analysis

B.

SafeSearch

C.

SSL Decryption

D.

Destination Lists

Questions 22

How does Cisco Secure Endpoint provide next-generation protection?

Options:
A.

It integrates with Cisco FTD devices.

B.

It encrypts data on user endpoints to protect against ransomware.

C.

It leverages an endpoint protection platform and endpoint detection and response.

D.

It utilizes Cisco pxGrid, which allows Secure Endpoint to pull threat feeds from threat intelligence centers.

Questions 23

An engineer needs behavioral analysis to detect malicious activity on the hosts, and is configuring the

organization’s public cloud to send telemetry using the cloud provider’s mechanisms to a security device. Which

mechanism should the engineer configure to accomplish this goal?

Options:
A.

mirror port

B.

Flow

C.

NetFlow

D.

VPC flow logs

Questions 24

An organization received a large amount of SPAM messages over a short time period. In order to take action on the messages, it must be determined how harmful the messages are and this needs to happen dynamically.

What must be configured to accomplish this?

Options:
A.

Configure the Cisco WSA to modify policies based on the traffic seen

B.

Configure the Cisco ESA to receive real-time updates from Talos

C.

Configure the Cisco WSA to receive real-time updates from Talos

D.

Configure the Cisco ESA to modify policies based on the traffic seen

Questions 25

A switch with Dynamic ARP Inspection enabled has received a spoofed ARP response on a trusted interface.

How does the switch behave in this situation?

Options:
A.

It forwards the packet after validation by using the MAC Binding Table.

B.

It drops the packet after validation by using the IP & MAC Binding Table.

C.

It forwards the packet without validation.

D.

It drops the packet without validation.

Questions 26

Drag and drop the deployment models from the left onto the explanations on the right.

350-701 Question 26

Options:
Questions 27

Which two Cisco ISE components must be configured for BYOD? (Choose two.)

Options:
A.

local WebAuth

B.

central WebAuth

C.

null WebAuth

D.

guest

E.

dual

Questions 28

A network administrator is configuring a role in an access control policy to block certain URLs and selects the " Chat and instant Messaging " category. which reputation score should be selected to accomplish

this goal?

Options:
A.

3

B.

5

C.

10

D.

1

Questions 29

What is a benefit of using GET VPN over FlexVPN within a VPN deployment?

Options:
A.

GET VPN supports Remote Access VPNs

B.

GET VPN natively supports MPLS and private IP networks

C.

GET VPN uses multiple security associations for connections

D.

GET VPN interoperates with non-Cisco devices

Questions 30

Which Cisco Secure Endpoint feature tracks the propagation and execution path of a malicious file across the environment?

Options:
A.

Exclusion Lists

B.

Device Flow Correlation

C.

Incident Manager

D.

File Trajectory

Cisco Related Exams

How to pass Cisco 300-710 - Securing Networks with Cisco Firepower (300-710 SNCF) v1.2 Exam
How to pass Cisco 300-715 - Implementing and Configuring Cisco Identity Services Engine (SISE) v1.1 (300-715 SISE) Exam
How to pass Cisco 300-720 - Securing Email with Cisco Email Security Appliance (300-720 SESA) Exam
How to pass Cisco 300-725 - Securing the Web with Cisco Web Security Appliance (300-725 SWSA) Exam
How to pass Cisco 300-730 - Implementing Secure Solutions with Virtual Private Networks (SVPN) Exam
How to pass Cisco 300-735 - Automating and Programming Cisco Security Solutions (300-735 SAUTO) Exam
How to pass Cisco 300-740 - Designing and Implementing Secure Cloud Access for Users and Endpoints Exam
How to pass Cisco 300-745 - Designing Cisco Security Infrastructure Exam

Cisco Free Exams

Cisco Free Exams
Examstrack offers free Cisco exam materials and practice tests to aid your Cisco certification journey.