Weekend Special Sale 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale75best

Free Cisco 350-701 Practice Exam with Questions & Answers | Set: 3

Questions 31

Refer to the exhibit.

350-701 Question 31

An engineer is implementing a certificate based VPN. What is the result of the existing configuration?

Options:
A.

The OU of the IKEv2 peer certificate is used as the identity when matching an IKEv2 authorization policy.

B.

Only an IKEv2 peer that has an OU certificate attribute set to MANGLER establishes an IKEv2 SA successfully

C.

The OU of the IKEv2 peer certificate is encrypted when the OU is set to MANGLER

D.

The OU of the IKEv2 peer certificate is set to MANGLER

Cisco 350-701 Premium Access
Questions 32

Which command is used to log all events to a destination colector 209.165.201.107?

Options:
A.

CiscoASA(config-pmap-c)#flow-export event-type flow-update destination 209.165.201.10

B.

CiscoASA(config-cmap)# flow-export event-type all destination 209.165.201.

C.

CiscoASA(config-pmap-c)#flow-export event-type all destination 209.165.201.10

D.

CiscoASA(config-cmap)#flow-export event-type flow-update destination 209.165.201.10

Questions 33

Which Cisco platform ensures that machines that connect to organizational networks have the recommended

antivirus definitions and patches to help prevent an organizational malware outbreak?

Options:
A.

Cisco WiSM

B.

Cisco ESA

C.

Cisco ISE

D.

Cisco Prime Infrastructure

Questions 34

A network engineer must create an access control list on a Cisco Adaptive Security Appliance firewall. The access control list must permit HTTP traffic to the internet from the organization ' s inside network 192.168.1.0/24. Which IOS command must oe used to create the access control list?

Options:
A.

B.

C.

D.

Questions 35

What are two functions of TAXII in threat intelligence sharing? (Choose two.)

Options:
A.

determines the " what " of threat intelligence

B.

Supports STIX information

C.

allows users to describe threat motivations and abilities

D.

exchanges trusted anomaly intelligence information

E.

determines how threat intelligence information is relayed

Questions 36

Which Cisco Secure Client module is integrated with Splunk Enterprise to provide monitoring capabilities to administrators to allow them to view endpoint application usage?

Options:
A.

Umbrella Roaming Security

B.

Network Visibility

C.

AMP Enabler

D.

ISE Posture

Questions 37

When a Cisco WSA checks a web request, what occurs if it is unable to match a user-defined policy?

Options:
A.

It blocks the request.

B.

It applies the global policy.

C.

It applies the next identification profile policy.

D.

It applies the advanced policy.

Questions 38

Refer to the exhibit.

350-701 Question 38

Which command was used to display this output?

Options:
A.

show dot1x all

B.

show dot1x

C.

show dot1x all summary

D.

show dot1x interface gi1/0/12

Questions 39

An engineer integrates Cisco FMC and Cisco ISE using pxGrid Which role is assigned for Cisco FMC?

Options:
A.

client

B.

server

C.

controller

D.

publisher

Questions 40

Refer to the exhibit.

350-701 Question 40

What conclusion should an administrator draw about the URL malicious-domain-example.com?

Options:
A.

The domain is blocked solely because it is newly registered, regardless of the Threat Score.

B.

The domain is a legacy site that has been compromised, as indicated by its domain age.

C.

The domain is safe because its Security Score is 25/100.

D.

The high Threat Score together with DNS tunneling, malware hosting, and DGA indicators shows active malicious behavior.

Questions 41

Which IETF attribute is supported for the RADIUS CoA feature?

Options:
A.

24 State

B.

30 Calling-Station-ID

C.

42 Acct-Session-ID

D.

81 Message-Authenticator

Questions 42

350-701 Question 42

Refer to the exhibit. What function does the API key perform while working with https://api.amp.cisco.com/v1/computers?

Options:
A.

imports requests

B.

HTTP authorization

C.

HTTP authentication

D.

plays dent ID

Questions 43

A network engineer is configuring DMVPN and entered the crypto isakmp key cisc0380739941 address 0.0.0.0 command on hostA. The tunnel is not being established to hostB. What action is needed to authenticate the VPN?

Options:
A.

Change isakmp to ikev2 in the command on hostA.

B.

Enter the command with a different password on hostB.

C.

Enter the same command on hostB.

D.

Change the password on hostA to the default password.

Questions 44

350-701 Question 44

Refer to the exhibit. A network engineer must retrieve the interface configuration on a Cisco router by using the NETCONF API. The engineer uses a python script to automate the activity.

Which code snippet completes the script?

Options:
A.

Content-Type: application/vnd.yang.data+json

B.

Content-Type: application/vnd.yang.data

C.

Content-Type: application/vnd.yang.data+api

D.

Content-Type: applications/json/vnd.yang.data

Questions 45

Refer to the exhibit.

350-701 Question 45

What are two indications of the Cisco Firepower Services Module configuration?

(Choose two.)

Options:
A.

The module is operating in IDS mode.

B.

Traffic is blocked if the module fails.

C.

The module fails to receive redirected traffic.

D.

The module is operating in IPS mode.

E.

Traffic continues to flow if the module fails.

Cisco Related Exams

How to pass Cisco 300-710 - Securing Networks with Cisco Firepower (300-710 SNCF) v1.2 Exam
How to pass Cisco 300-715 - Implementing and Configuring Cisco Identity Services Engine (SISE) v1.1 (300-715 SISE) Exam
How to pass Cisco 300-720 - Securing Email with Cisco Email Security Appliance (300-720 SESA) Exam
How to pass Cisco 300-725 - Securing the Web with Cisco Web Security Appliance (300-725 SWSA) Exam
How to pass Cisco 300-730 - Implementing Secure Solutions with Virtual Private Networks (SVPN) Exam
How to pass Cisco 300-735 - Automating and Programming Cisco Security Solutions (300-735 SAUTO) Exam
How to pass Cisco 300-740 - Designing and Implementing Secure Cloud Access for Users and Endpoints Exam
How to pass Cisco 300-745 - Designing Cisco Security Infrastructure Exam

Cisco Free Exams

Cisco Free Exams
Examstrack offers free Cisco exam materials and practice tests to aid your Cisco certification journey.