Pre-Winter Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Pass the Cisco CCNP Security 350-701 Questions and answers with ValidTests

Exam 350-701 All Questions
Exam 350-701 Premium Access

View all detail and faqs for the 350-701 exam

Viewing page 17 out of 17 pages
Viewing questions 241-255 out of questions
Questions # 241:

What are two benefits of workload security? (Choose two.)

Options:

A.

Tracked application security

B.

Automated patching

C.

Reduced attack surface

D.

Scalable security policies

E.

Workload modeling

Expert Solution
Questions # 242:

Which function is included when Cisco AMP is added to web security?

Options:

A.

multifactor, authentication-based user identity

B.

detailed analytics of the unknown file's behavior

C.

phishing detection on emails

D.

threat prevention on an infected endpoint

Expert Solution
Questions # 243:

Which solution for remote workers enables protection, detection, and response on the endpoint against known and unknown threats?

Options:

A.

Cisco AMP for Endpoints

B.

Cisco AnyConnect

C.

Cisco Umbrella

D.

Cisco Duo

Expert Solution
Questions # 244:

An organization is using DNS services for their network and want to help improve the security of the DNS infrastructure. Which action accomplishes this task?

Options:

A.

Use DNSSEC between the endpoints and Cisco Umbrella DNS servers.

B.

Modify the Cisco Umbrella configuration to pass queries only to non-DNSSEC capable zones.

C.

Integrate Cisco Umbrella with Cisco CloudLock to ensure that DNSSEC is functional.

D.

Configure Cisco Umbrella and use DNSSEC for domain authentication to authoritative servers.

Expert Solution
Questions # 245:

Drag and drop the VPN functions from the left onto the description on the right.Question # 245

Options:

Expert Solution
Questions # 246:

An organization has two systems in their DMZ that have an unencrypted link between them for communication.

The organization does not have a defined password policy and uses several default accounts on the systems.

The application used on those systems also have not gone through stringent code reviews. Which vulnerability

would help an attacker brute force their way into the systems?

Options:

A.

weak passwords

B.

lack of input validation

C.

missing encryption

D.

lack of file permission

Expert Solution
Questions # 247:

Which feature within Cisco ISE verifies the compliance of an endpoint before providing access to the

network?

Options:

A.

Posture

B.

Profiling

C.

pxGrid

D.

MAB

Expert Solution
Questions # 248:

What is a characteristic of Dynamic ARP Inspection?

Options:

A.

DAI determines the validity of an ARP packet based on valid IP to MAC address bindings from the DHCPsnooping binding database.

B.

In a typical network, make all ports as trusted except for the ports connecting to switches, which areuntrusted

C.

DAI associates a trust state with each switch.

D.

DAI intercepts all ARP requests and responses on trusted ports only.

Expert Solution
Questions # 249:

Which two Cisco ISE components must be configured for BYOD? (Choose two.)

Options:

A.

local WebAuth

B.

central WebAuth

C.

null WebAuth

D.

guest

E.

dual

Expert Solution
Questions # 250:

Using Cisco Firepower’s Security Intelligence policies, upon which two criteria is Firepower block based?

(Choose two)

Options:

A.

URLs

B.

protocol IDs

C.

IP addresses

D.

MAC addresses

E.

port numbers

Expert Solution
Questions # 251:

Which network monitoring solution uses streams and pushes operational data to provide a near real-time view

of activity?

Options:

A.

SNMP

B.

SMTP

C.

syslog

D.

model-driven telemetry

Expert Solution
Questions # 252:

A company deploys an application that contains confidential data and has a hybrid hub-and-spoke topology. The hub resides in a public cloud environment, and the spoke resides on-premises. An engineer must secure the application to ensure that confidential data in transit between the hub-and-spoke servers is accessible only to authorized users. The engineer performs these configurations:

    Segregation of duties

    Role-based access control

    Privileged access management

What must be implemented to protect the data in transit?

Options:

A.

MD5

B.

AES-256

C.

SHA-512

D.

TLS 1.3

Expert Solution
Questions # 253:

What are two DDoS attack categories? (Choose two)

Options:

A.

sequential

B.

protocol

C.

database

D.

volume-based

E.

screen-based

Expert Solution
Questions # 254:

An organization wants to improve its cybersecurity processes and to add intelligence to its data The organization wants to utilize the most current intelligence data for URL filtering, reputations, and vulnerability information that can be integrated with the Cisco FTD and Cisco WSA What must be done to accomplish these objectives?

Options:

A.

Create a Cisco pxGrid connection to NIST to import this information into the security products for policy use

B.

Create an automated download of the Internet Storm Center intelligence feed into the Cisco FTD and Cisco WSA databases to tie to the dynamic access control policies.

C.

Download the threat intelligence feed from the IETF and import it into the Cisco FTD and Cisco WSA databases

D.

Configure the integrations with Talos Intelligence to take advantage of the threat intelligence that it provides.

Expert Solution
Questions # 255:

When network telemetry is implemented, what is important to be enabled across all network infrastructure devices to correlate different sources?

Options:

A.

CDP

B.

NTP

C.

syslog

D.

DNS

Expert Solution
Viewing page 17 out of 17 pages
Viewing questions 241-255 out of questions