Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Pass the Cisco CCNP Security 350-701 Questions and answers with ValidTests

Exam 350-701 All Questions
Exam 350-701 Premium Access

View all detail and faqs for the 350-701 exam

Viewing page 4 out of 15 pages
Viewing questions 46-60 out of questions
Questions # 46:

Refer to the exhibit.

Question # 46

Refer to the exhibit. A Cisco ISE administrator adds a new switch to an 802.1X deployment and has difficulty with some endpoints gaining access.

Most PCs and IP phones can connect and authenticate using their machine certificate credentials. However printer and video cameras cannot base d on the interface configuration provided, what must be to get these devices on to the network using Cisco ISE for authentication and authorization while maintaining security controls?

Options:

A.

Change the default policy in Cisco ISE to allow all devices not using machine authentication .

B.

Enable insecure protocols within Cisco ISE in the allowed protocols configuration.

C.

Configure authentication event fail retry 2 action authorize vlan 41 on the interface

D.

Add mab to the interface configuration.

Expert Solution
Questions # 47:

Question # 47

Refer to the exhibit. A network engineer must retrieve the interface configuration on a Cisco router by using the NETCONF API. The engineer uses a python script to automate the activity.

Which code snippet completes the script?

Options:

A.

Content-Type: application/vnd.yang.data+json

B.

Content-Type: application/vnd.yang.data

C.

Content-Type: application/vnd.yang.data+api

D.

Content-Type: applications/json/vnd.yang.data

Expert Solution
Questions # 48:

Which two parameters are used for device compliance checks? (Choose two.)

Options:

A.

endpoint protection software version

B.

Windows registry values

C.

DHCP snooping checks

D.

DNS integrity checks

E.

device operating system version

Expert Solution
Questions # 49:

In which scenario is endpoint-based security the solution?

Options:

A.

inspecting encrypted traffic

B.

device profiling and authorization

C.

performing signature-based application control

D.

inspecting a password-protected archive

Expert Solution
Questions # 50:

Drag and drop the deployment models from the left onto the explanations on the right.

Question # 50

Options:

Expert Solution
Questions # 51:

An organization wants to use Cisco FTD or Cisco ASA devices. Specific URLs must be blocked from being

accessed via the firewall which requires that the administrator input the bad URL categories that the

organization wants blocked into the access policy. Which solution should be used to meet this requirement?

Options:

A.

Cisco ASA because it enables URL filtering and blocks malicious URLs by default, whereas Cisco FTDdoes not

B.

Cisco ASA because it includes URL filtering in the access control policy capabilities, whereas Cisco FTD does not

C.

Cisco FTD because it includes URL filtering in the access control policy capabilities, whereas Cisco ASA does not

D.

Cisco FTD because it enables URL filtering and blocks malicious URLs by default, whereas Cisco ASA does not

Expert Solution
Questions # 52:

Drag and drop the solutions from the left onto the solution's benefits on the right.

Question # 52

Options:

Expert Solution
Questions # 53:

When a Cisco Secure Web Appliance checks a web request, what occurs if it is unable to match a user-defined policy?

Options:

A.

It applies the next identification profile policy.

B.

It applies the advanced policy.

C.

It applies the global policy.

D.

It blocks the request.

Expert Solution
Questions # 54:

Which two capabilities does TAXII support? (Choose two)

Options:

A.

Exchange

B.

Pull messaging

C.

Binding

D.

Correlation

E.

Mitigating

Expert Solution
Questions # 55:

Which two methods are available in Cisco Secure Web Appliance to process client requests when configured in Transparent mode? (Choose two.)

Options:

A.

WCCP

B.

Browser settings

C.

WPAD

D.

PAC files

E.

PBR

Expert Solution
Questions # 56:

What must be configured on Cisco Secure Endpoint to create a custom detection tile list to detect and quarantine future files?

Options:

A.

Use the simple custom detection feature and add each detection to the list.

B.

Add a network IP block allowed list to the configuration and add the blocked files.

C.

Create an advanced custom detection and upload the hash of each file

D.

Configure an application control allowed applications list to block the files

Expert Solution
Questions # 57:

An engineer is configuring cloud logging on Cisco ASA and needs events to compress. Which component must be configured to accomplish this goal?

Options:

A.

CDO event viewer

B.

SWC service

C.

Cisco analytics

D.

SDC VM

Expert Solution
Questions # 58:

Refer to the exhibit.

Question # 58

Which type of authentication is in use?

Options:

A.

LDAP authentication for Microsoft Outlook

B.

POP3 authentication

C.

SMTP relay server authentication

D.

external user and relay mail authentication

Expert Solution
Questions # 59:

Question # 59

Refer to the exhibit. What is the result of using this authentication protocol in the configuration?

Options:

A.

The authentication request contains only a username.

B.

The authentication request contains only a password.

C.

There are separate authentication and authorization request packets.

D.

The authentication and authorization requests are grouped in a single packet.

Expert Solution
Questions # 60:

What is a benefit of using Cisco Umbrella?

Options:

A.

DNS queries are resolved faster.

B.

Attacks can be mitigated before the application connection occurs.

C.

Files are scanned for viruses before they are allowed to run.

D.

It prevents malicious inbound traffic.

Expert Solution
Viewing page 4 out of 15 pages
Viewing questions 46-60 out of questions