Real 350-701 Dumps - Cisco Correct Answers updated on 2021 [Q169-Q193]

Share

Use Real 350-701 Dumps - Cisco Correct Answers updated on 2021

CCNP Security 350-701 Exam Practice Dumps


Endpoint Protection & Detection – 15%

  • Configuring and verifying the outbreak quarantines & control to restrict infection;
  • Explaining the use cases as well as the role of a multifactor authentication (MFA) methodology;
  • Explaining the role of endpoint device management and asset inventory like MDM;
  • Describing the role of the endpoint patching strategy.
  • Describing retrospective security, antimalware, antivirus, Indication of Compromise, dynamic file analysis, as well as endpoint-sourced telemetry;
  • Comparing Endpoint Protection Platforms as well as Endpoint Detection & Response (EDR) solutions;
  • Describing the solutions for endpoint posture assessment to deliver endpoint security;
  • Explaining the justifications for endpoint-based security;

NEW QUESTION 169
An engineer has enabled LDAP accept queries on a listener. Malicious actors must be prevented from quickly identifying all valid recipients. What must be done on the Cisco ESA to accomplish this goal?

  • A. Use Bounce Verification
  • B. Bypass LDAP access queries in the recipient access table.
  • C. Configure Directory Harvest Attack Prevention
  • D. Configure incoming content filters.

Answer: C

Explanation:
Explanation

 

NEW QUESTION 170
Refer to the exhibit.

What does the number 15 represent in this configuration?

  • A. number of possible failed attempts until the SNMPv3 user is locked out
  • B. privilege level for an authorized user to this router
  • C. interval in seconds between SNMPv3 authentication attempts
  • D. access list that identifies the SNMP devices that can access the router

Answer: D

 

NEW QUESTION 171
Refer to the exhibit.

Which command was used to display this output?

  • A. show dot1x all summary
  • B. show dot1x all
  • C. show dot1x
  • D. show dot1x interface gi1/0/12

Answer: B

 

NEW QUESTION 172
What are two features of NetFlow flow monitoring? (Choose two.)

  • A. Can be used to track multicast, MPLS, or bridged traffic.
  • B. Include the flow record and the flow importer
  • C. Copies all ingress flow information to an interface
  • D. Does not required packet sampling on interfaces
  • E. Can track ingress and egress information

Answer: A,E

 

NEW QUESTION 173
After deploying a Cisco ESA on your network, you notice that some messages fail to reach their destinations.
Which task can you perform to determine where each message was lost?

  • A. Perform a trace.
  • B. Generate a system report.
  • C. Configure the trackingconfig command to enable message tracking.
  • D. Review the log files.

Answer: C

Explanation:
Explanation Message tracking helps resolve help desk calls by giving a detailed view of message flow. For example, if a message was not delivered as expected, you can determine if it was found to contain a virus or placed in a spam quarantine - or if it is located somewhere else in the mail stream. Reference: https://www.cisco.com/c/en/us/td/docs/security/esa/esa12-0/user_guide/ b_ESA_Admin_Guide_12_0/b_ESA_Admin_Guide_12_0_chapter_011110.html Message tracking helps resolve help desk calls by giving a detailed view of message flow. For example, if a message was not delivered as expected, you can determine if it was found to contain a virus or placed in a spam quarantine - or if it is located somewhere else in the mail stream.
Reference:
Explanation Message tracking helps resolve help desk calls by giving a detailed view of message flow. For example, if a message was not delivered as expected, you can determine if it was found to contain a virus or placed in a spam quarantine - or if it is located somewhere else in the mail stream. Reference: https://www.cisco.com/c/en/us/td/docs/security/esa/esa12-0/user_guide/ b_ESA_Admin_Guide_12_0/b_ESA_Admin_Guide_12_0_chapter_011110.html

 

NEW QUESTION 174
Refer to the exhibit.

What will occur when this device tries to connect to the port?

  • A. 802 1X will work and the device will be allowed on the network
  • B. 802.1X will not work, but MAB will start and allow the device on the network.
  • C. 802 1X and MAB will both be used and ISE can use policy to determine the access level
  • D. 802.1X will not work and the device will not be allowed network access

Answer: C

 

NEW QUESTION 175
Which attribute has the ability to change during the RADIUS CoA?

  • A. Accessibility
  • B. Membership
  • C. Authorization
  • D. NTP

Answer: C

Explanation:
The RADIUS Change of Authorization (CoA) feature provides a mechanism to change the attributes of an authentication, authorization, and accounting (AAA) session after it is authenticated.
The RADIUS Change of Authorization (CoA) feature provides a mechanism to change the attributes of an authentication, authorization, and accounting (AAA) session after it is authenticated.
Reference:
sy-book/sec-rad-coa.html
The RADIUS Change of Authorization (CoA) feature provides a mechanism to change the attributes of an authentication, authorization, and accounting (AAA) session after it is authenticated.
sy-book/sec-rad-coa.html

 

NEW QUESTION 176
Drag and drop the Firepower Next Generation Intrusion Prevention System detectors from the left onto the correct definitions on the right.

Answer:

Explanation:

 

NEW QUESTION 177
Refer to the exhibit.

Which command was used to generate this output and to show which ports are authenticating with dot1x or mab?

  • A. show dot1x all
  • B. show authentication registrations
  • C. show authentication method
  • D. show authentication sessions

Answer: D

 

NEW QUESTION 178
Which policy is used to capture host information on the Cisco Firepower Next Generation Intrusion Prevention System?

  • A. Access Control
  • B. Correlation
  • C. Intrusion
  • D. Network Discovery

Answer: D

Explanation:
Explanation The Firepower System uses network discovery and identity policies to collect host, application, and user data for traffic on your network. You can use certain types of discovery and identity data to build a comprehensive map of your network assets, perform forensic analysis, behavioral profiling, access control, and mitigate and respond to the vulnerabilities and exploits to which your organization is susceptible. You can configure your network discovery policy to perform host and application detection. Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-configguide-v64/introduction_to_network_discovery_and_identity.html The Firepower System uses network discovery and identity policies to collect host, application, and user data for traffic on your network. You can use certain types of discovery and identity data to build a comprehensive map of your network assets, perform forensic analysis, behavioral profiling, access control, and mitigate and respond to the vulnerabilities and exploits to which your organization is susceptible.
You can configure your network discovery policy to perform host and application detection.
Explanation The Firepower System uses network discovery and identity policies to collect host, application, and user data for traffic on your network. You can use certain types of discovery and identity data to build a comprehensive map of your network assets, perform forensic analysis, behavioral profiling, access control, and mitigate and respond to the vulnerabilities and exploits to which your organization is susceptible. You can configure your network discovery policy to perform host and application detection. Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-configguide-v64/introduction_to_network_discovery_and_identity.html

 

NEW QUESTION 179
Which cloud service model offers an environment for cloud consumers to develop and deploy applications without needing to manage or maintain the underlying cloud infrastructure?

  • A. IaaS
  • B. XaaS
  • C. PaaS
  • D. SaaS

Answer: C

Explanation:
Cloud computing can be broken into the following three basic models:
+ Infrastructure as a Service (IaaS): IaaS describes a cloud solution where you are renting infrastructure. You purchase virtual power to execute your software as needed. This is much like running a virtual server on your own equipment, except you are now running a virtual server on a virtual disk. This model is similar to a utility company model because you pay for what you use.
+ Platform as a Service (PaaS): PaaS provides everything except applications. Services provided by this model include all phases of the system development life cycle (SDLC) and can use application programming interfaces (APIs), website portals, or gateway software. These solutions tend to be proprietary, which can cause problems if the customer moves away from the provider's platform.
+ Software as a Service (SaaS): SaaS is designed to provide a complete packaged solution. The software is rented out to the user. The service is usually provided through some type of front end or web portal. While the end user is free to use the service from anywhere, the company pays a peruse fee.

 

NEW QUESTION 180
In which two ways does Easy Connect help control network access when used with Cisco TrustSec? (Choose two)

  • A. It allows for the assignment of Security Group Tags and does not require 802.1x to be configured on the switch or the endpoint.
  • B. It integrates with third-party products to provide better visibility throughout the network.
  • C. It creates a dashboard in Cisco ISE that provides full visibility of all connected endpoints.
  • D. It allows multiple security products to share information and work together to enhance security posture in the network.
  • E. It allows for managed endpoints that authenticate to AD to be mapped to Security Groups (PassiveID).

Answer: A,E

Explanation:
Explanation
Easy Connect simplifies network access control and segmentation by allowing the assignment of Security Group Tags to endpoints without requiring 802.1X on those endpoints, whether using wired or wireless connectivity.
Reference:
easy-connect-configuration-guide.pdf

 

NEW QUESTION 181
In which two ways does a system administrator send web traffic transparently to the Web Security Appliance? (Choose two.)

  • A. configure the proxy IP address in the web-browser settings
  • B. configure policy-based routing on the network infrastructure
  • C. reference a Proxy Auto Config file
  • D. configure AD Group Policies to push proxy settings
  • E. use Web Cache Communication Protocol

Answer: B,E

 

NEW QUESTION 182
Which attack is preventable by Cisco ESA but not by the Cisco WSA?

  • A. phishing
  • B. SQL injection
  • C. buffer overflow
  • D. DoS

Answer: A

Explanation:
Explanation Explanation The following are the benefits of deploying Cisco Advanced Phishing Protection on the Cisco Email Security Gateway: Prevents the following: + Attacks that use compromised accounts and social engineering. + Phishing, ransomware, zero-day attacks and spoofing. + BEC with no malicious payload or URL. Reference: https://www.cisco.com/c/en/us/td/docs/security/esa/esa13-5/user_guide/b_ESA_Admin_Guide_13- 5/m_advanced_phishing_protection.html Explanation The following are the benefits of deploying Cisco Advanced Phishing Protection on the Cisco Email Security Gateway:
Prevents the following:
+ Attacks that use compromised accounts and social engineering.
+ Phishing, ransomware, zero-day attacks and spoofing.
+ BEC with no malicious payload or URL.
Reference:
Explanation Explanation The following are the benefits of deploying Cisco Advanced Phishing Protection on the Cisco Email Security Gateway: Prevents the following: + Attacks that use compromised accounts and social engineering. + Phishing, ransomware, zero-day attacks and spoofing. + BEC with no malicious payload or URL. Reference: https://www.cisco.com/c/en/us/td/docs/security/esa/esa13-5/user_guide/b_ESA_Admin_Guide_13- 5/m_advanced_phishing_protection.html

 

NEW QUESTION 183
Refer to the exhibit.

What does the number 15 represent in this configuration?

  • A. number of possible failed attempts until the SNMPv3 user is locked out
  • B. privilege level for an authorized user to this router
  • C. interval in seconds between SNMPv3 authentication attempts
  • D. access list that identifies the SNMP devices that can access the router

Answer: D

 

NEW QUESTION 184
What is a benefit of conducting device compliance checks?

  • A. B
  • B. A

Answer: A

Explanation:

 

NEW QUESTION 185
Which exfiltration method does an attacker use to hide and encode data inside DNS requests and queries?

  • A. DNS tunneling
  • B. DNSCrypt
  • C. DNS security
  • D. DNSSEC

Answer: A

Explanation:
Explanation
DNS Tunneling is a method of cyber attack that encodes the data of other programs or protocols in DNS queries and responses. DNS tunneling often includes data payloads that can be added to an attacked DNS server and used to control a remote server and applications.

 

NEW QUESTION 186
A network engineer has entered the snmp-server user andy myv3 auth sha cisco priv aes 256 cisc0383320506 command and needs to send SNMP information to a host at 10.255.254.1. Which command achieves this goal?

  • A. snmp-server host inside 10.255.254.1 version 3 andy
  • B. snmp-server host inside 10.255.254.1 snmpv3 andy
  • C. snmp-server host inside 10.255.254.1 snmpv3 myv3
  • D. snmp-server host inside 10.255.254.1 version 3 myv3

Answer: D

Explanation:
Explanation/Reference: https://www.cisco.com/c/m/en_us/techdoc/dc/reference/cli/nxos/commands/sm/snmp-server- host.html

 

NEW QUESTION 187
An engineer notices traffic interruption on the network. Upon further investigation, it is learned that broadcast packets have been flooding the network. What must be configured, based on a predefined threshold, to address this issue?

  • A. Bridge Protocol Data Unit guard
  • B. storm control
  • C. embedded event monitoring
  • D. access control lists

Answer: B

Explanation:
Storm control prevents traffic on a LAN from being disrupted by a broadcast, multicast, or unicast storm on one of the physical interfaces. A LAN storm occurs when packets flood the LAN, creating excessive traffic and degrading network performance. Errors in the protocol-stack implementation, mistakes in network configurations, or users issuing a denial-of-service attack can cause a storm.
By using the "storm-control broadcast level [falling-threshold]" we can limit the broadcast traffic on the switch.

 

NEW QUESTION 188
How does Cisco Advanced Phishing Protection protect users?

  • A. It utilizes sensors that send messages securely.
  • B. It validates the sender by using DKIM.
  • C. It determines which identities are perceived by the sender
  • D. It uses machine learning and real-time behavior analytics.

Answer: D

Explanation:
Reference:

https://www.cisco.com/c/dam/en/us/products/collateral/security/cloud-email-security/at-a-glance-c45-740894.pdf

 

NEW QUESTION 189
An organization is using Cisco Firepower and Cisco Meraki MX for network security and needs to centrally manage cloud policies across these platforms. Which software should be used to accomplish this goal?

  • A. Cisco Defense Orchestrator
  • B. Cisco Configuration Professional
  • C. Cisco DNA Center
  • D. Cisco Secureworks

Answer: A

Explanation:
Explanation Explanation Cisco Defense Orchestrator is a cloud-based management solution that allows you to manage security policies and device configurations with ease across multiple Cisco and cloud-native security platforms. Cisco Defense Orchestrator features: .... Management of hybrid environments: Managing a mix of firewalls running the ASA, FTD, and Meraki MX software is now easy, with the ability to share policy elements across platforms. Reference: https://www.cisco.com/c/en/us/products/collateral/security/defense-orchestrator/datasheet-c78- 736847.html Explanation Cisco Defense Orchestrator is a cloud-based management solution that allows you to manage security policies and device configurations with ease across multiple Cisco and cloud-native security platforms.
Cisco Defense Orchestrator features:
....
Management of hybrid environments: Managing a mix of firewalls running the ASA, FTD, and Meraki MX software is now easy, with the ability to share policy elements across platforms.
Reference:
Explanation Explanation Cisco Defense Orchestrator is a cloud-based management solution that allows you to manage security policies and device configurations with ease across multiple Cisco and cloud-native security platforms. Cisco Defense Orchestrator features: .... Management of hybrid environments: Managing a mix of firewalls running the ASA, FTD, and Meraki MX software is now easy, with the ability to share policy elements across platforms. Reference: https://www.cisco.com/c/en/us/products/collateral/security/defense-orchestrator/datasheet-c78- 736847.html

 

NEW QUESTION 190
An engineer is configuring a Cisco ESA and wants to control whether to accept or reject email messages to a recipient address. Which list contains the allowed recipient addresses?

  • A. SAT
  • B. BAT
  • C. RAT
  • D. HAT

Answer: C

 

NEW QUESTION 191
What is the primary role of the Cisco Email Security Appliance?

  • A. Mail Transfer Agent
  • B. Mail User Agent
  • C. Mail Delivery Agent
  • D. Mail Submission Agent

Answer: A

Explanation:
Explanation Cisco Email Security Appliance (ESA) protects the email infrastructure and employees who use email at work by filtering unsolicited and malicious email before it reaches the user. Cisco ESA easily integrates into existing email infrastructures with a high degree of flexibility. It does this by acting as a Mail Transfer Agent (MTA) within the email-delivery chain. Another name for an MTA is a mail relay. Reference: https://www.cisco.com/c/dam/en/us/td/docs/solutions/SBA/February2013/ Cisco_SBA_BN_EmailSecurityUsingCiscoESADeploymentGuide-Feb2013.pdf Cisco Email Security Appliance (ESA) protects the email infrastructure and employees who use email at work by filtering unsolicited and malicious email before it reaches the user. Cisco ESA easily integrates into existing email infrastructures with a high degree of flexibility. It does this by acting as a Mail Transfer Agent (MTA) within the email-delivery chain. Another name for an MTA is a mail relay.
Reference:
Explanation Cisco Email Security Appliance (ESA) protects the email infrastructure and employees who use email at work by filtering unsolicited and malicious email before it reaches the user. Cisco ESA easily integrates into existing email infrastructures with a high degree of flexibility. It does this by acting as a Mail Transfer Agent (MTA) within the email-delivery chain. Another name for an MTA is a mail relay. Reference: https://www.cisco.com/c/dam/en/us/td/docs/solutions/SBA/February2013/ Cisco_SBA_BN_EmailSecurityUsingCiscoESADeploymentGuide-Feb2013.pdf

 

NEW QUESTION 192
An engineer has enabled LDAP accept queries on a listener. Malicious actors must be prevented from quickly identifying all valid recipients. What must be done on the Cisco ESA to accomplish this goal?

  • A. Use Bounce Verification
  • B. Bypass LDAP access queries in the recipient access table.
  • C. Configure Directory Harvest Attack Prevention
  • D. Configure incoming content filters.

Answer: C

Explanation:
Reference:

 

NEW QUESTION 193
......


Understanding functional and technical aspects of Implementing and Operating Cisco Security Core Technologies (SCOR 350-701) Secure Network Access, Visibility, and Enforcement

The following will be discussed in CISCO 350-701 dumps:

  • Configure and verify network access device functionality such as 802.1X, MAB, WebAuth
  • Explain exfiltration techniques (DNS tunneling, HTTPS, email, FTP/SSH/SCP/SFTP, ICMP, Messenger, IRC, NTP)
  • Describe identity management and secure network access concepts such as guest services, profiling, posture assessment and BYOD
  • Describe network access with CoA
  • Describe the benefits of device compliance and application control
  • Describe the benefits of network telemetry

The benefit in Obtaining the Implementing and Operating Cisco Security Core Technologies (SCOR 350-701)

This exam will help you:

  • Implement security principles within an enterprise network
  • Earn 64 CE credits toward recertification
  • Configure, troubleshoot, and manage enterprise wired and wireless networks

This exam is for:

  • Network administrators
  • Network support technicians
  • Help desk technicians
  • Mid-level network engineers

Get ready to pass the 350-701 Exam right now using our CCNP Security  Exam Package: https://www.examboosts.com/Cisco/350-701-practice-exam-dumps.html

350-701 Premium Files Test pdf - Free Dumps Collection: https://drive.google.com/open?id=1HuH6AMc63HyDDswG461RS66QqRyYepnU