Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free Cisco 350-701 Practice Exam with Questions & Answers | Set: 3

Questions 31

A networking team must harden an organization's network from VLAN hopping attacks. The team disables Dynamic Trunking Protocol and puts any unused ports in an unused VLAN. A trunk port is used as a trunk link. What must the team configure next to harden the network against VLAN hopping attacks?

Options:
A.

disable STP on the network devices

B.

dedicated VLAN ID for all trunk ports

C.

DHCP snooping on all the switches

D.

enable port-based network access control

Cisco 350-701 Premium Access
Questions 32

An engineer is deploying Cisco Advanced Malware Protection (AMP) for Endpoints and wants to create a policy that prevents users from executing file named abc424952615.exe without quarantining that file What type of Outbreak Control list must the SHA.-256 hash value for the file be added to in order to accomplish this?

Options:
A.

Advanced Custom Detection

B.

Blocked Application

C.

Isolation

D.

Simple Custom Detection

Questions 33

Which cryptographic process provides origin confidentiality, integrity, and origin authentication for packets?

Options:
A.

IKEv1

B.

AH

C.

ESP

D.

IKEv2

Questions 34

A Cisco ISE engineer configures Central Web Authentication (CWA) for wireless guest access and must have the guest endpoints redirect to the guest portal for authentication and authorization. While testing the policy, the engineer notices that the device is not redirected and instead gets full guest access. What must be done for the redirect to work?

Options:
A.

Tag the guest portal in the CWA part of the Common Tasks section of the authorization profile for the authorization policy line that the unauthenticated devices hit.

B.

Use the track movement option within the authorization profile for the authorization policy line that the unauthenticated devices hit.

C.

Create an advanced attribute setting of Cisco:cisco-gateway-id=guest within the authorization profile for the authorization policy line that the unauthenticated devices hit.

D.

Add the DACL name for the Airespace ACL configured on the WLC in the Common Tasks section of the authorization profile for the authorization policy line that the unauthenticated devices hit.

Questions 35

Which solution combines Cisco IOS and IOS XE components to enable administrators to recognize

applications, collect and send network metrics to Cisco Prime and other third-party management tools, and prioritize application traffic?

Options:
A.

Cisco Security Intelligence

B.

Cisco Application Visibility and Control

C.

Cisco Model Driven Telemetry

D.

Cisco DNA Center

Questions 36

What is a difference between FlexVPN and DMVPN?

Options:
A.

DMVPN uses IKEv1 or IKEv2, FlexVPN only uses IKEv1

B.

DMVPN uses only IKEv1 FlexVPN uses only IKEv2

C.

FlexVPN uses IKEv2, DMVPN uses IKEv1 or IKEv2

D.

FlexVPN uses IKEv1 or IKEv2, DMVPN uses only IKEv2

Questions 37

In which situation should an Endpoint Detection and Response solution be chosen versus an Endpoint Protection Platform?

Options:
A.

When there is a need to have more advanced detection capabilities

B.

When there is a need for traditional anti-malware detection

C.

When there is no need to have the solution centrally managed

D.

When there is no firewall on the network

Questions 38

What is a feature of container orchestration?

Options:
A.

ability to deploy Amazon ECS clusters by using the Cisco Container Platform data plane

B.

ability to deploy Amazon EKS clusters by using the Cisco Container Platform data plane

C.

ability to deploy Kubernetes clusters in air-gapped sites

D.

automated daily updates

Questions 39

What is the role of Cisco Umbrella Roaming when it is installed on an endpoint?

Options:
A.

To protect the endpoint against malicious file transfers

B.

To ensure that assets are secure from malicious links on and off the corporate network

C.

To establish secure VPN connectivity to the corporate network

D.

To enforce posture compliance and mandatory software

Questions 40

Refer to the exhibit.

350-701 Question 40

When configuring a remote access VPN solution terminating on the Cisco ASA, an administrator would like to utilize an external token authentication mechanism in conjunction with AAA authentication using machine

certificates. Which configuration item must be modified to allow this?

Options:
A.

Group Policy

B.

Method

C.

SAML Server

D.

DHCP Servers

Questions 41

What does the Cloudlock Apps Firewall do to mitigate security concerns from an application perspective?

Options:
A.

It allows the administrator to quarantine malicious files so that the application can function, just notmaliciously.

B.

It discovers and controls cloud apps that are connected to a company’s corporate environment.

C.

It deletes any application that does not belong in the network.

D.

It sends the application information to an administrator to act on.

Questions 42

What are two Detection and Analytics Engines of Cognitive Threat Analytics? (Choose two)

Options:
A.

data exfiltration

B.

command and control communication

C.

intelligent proxy

D.

snort

E.

URL categorization

Questions 43

Cisco SensorBase gaihers threat information from a variety of Cisco products and services and performs analytics to find patterns on threats Which term describes this process?

Options:
A.

deployment

B.

consumption

C.

authoring

D.

sharing

Questions 44

What is the benefit of integrating Cisco ISE with a MDM solution?

Options:
A.

It provides compliance checks for access to the network

B.

It provides the ability to update other applications on the mobile device

C.

It provides the ability to add applications to the mobile device through Cisco ISE

D.

It provides network device administration access

Questions 45

Which two commands are required when configuring a flow-export action on a Cisco ASA? (Choose two.)

Options:
A.

flow-export event-type

B.

policy-map

C.

access-list

D.

flow-export template timeout-rate 15

E.

access-group

Cisco Related Exams

Cisco Free Exams

Cisco Free Exams
Examstrack offers free Cisco exam materials and practice tests to aid your Cisco certification journey.