[Full-Version] 2024 New 350-701 Actual Exam Dumps, Cisco Practice Test
Study HIGH Quality 350-701 Free Study Guides and Exams Tutorials
NEW QUESTION # 67
After deploying a Cisco ESA on your network, you notice that some messages fail to reach their destinations.
Which task can you perform to determine where each message was lost?
- A. Review the log files.
- B. Generate a system report.
- C. Configure the trackingconfig command to enable message tracking.
- D. Perform a trace.
Answer: C
Explanation:
Message tracking helps resolve help desk calls by giving a detailed view of message flow. For example, if a message was not delivered as expected, you can determine if it was found to contain a virus or placed in a spam quarantine - or if it is located somewhere else in the mail stream. Reference: https://www.cisco.com/c/en/us/td/docs/security/esa/esa12-0/user_guide/ b_ESA_Admin_Guide_12_0/b_ESA_Admin_Guide_12_0_chapter_011110.html Reference:
Message tracking helps resolve help desk calls by giving a detailed view of message flow. For example, if a message was not delivered as expected, you can determine if it was found to contain a virus or placed in a spam quarantine - or if it is located somewhere else in the mail stream. Reference: https://www.cisco.com/c/en/us/td/docs/security/esa/esa12-0/user_guide/ b_ESA_Admin_Guide_12_0/b_ESA_Admin_Guide_12_0_chapter_011110.html
NEW QUESTION # 68
Which method of attack is used by a hacker to send malicious code through a web application to an unsuspecting user to request that the victim's web browser executes the code?
- A. browser WGET
- B. cross-site scripting
- C. SQL injection
- D. buffer overflow
Answer: B
NEW QUESTION # 69
What is the difference between Cross-site Scripting and SQL Injection, attacks?
- A. Cross-site Scripting is a brute force attack targeting remote sites, whereas SQL Injection is a social engineering attack.
- B. Cross-site Scripting is an attack where code is executed from the server side, whereas SQL Injection is an attack where code is executed from the client side.
- C. Cross-site Scripting is when executives in a corporation are attacked, whereas SQL Injection is when a database is manipulated.
- D. Cross-site Scripting is an attack where code is injected into a database, whereas SQL Injection is an attack where code is injected into a browser.
Answer: D
NEW QUESTION # 70
v
Refer to the exhibit When configuring this access control rule in Cisco FMC, what happens with the traffic destined to the DMZjnside zone once the configuration is deployed?
- A. All traffic from any zone to the DMZ_inside zone will be permitted with no further inspection
- B. No traffic will be allowed through to the DMZ_inside zone regardless of if it's trusted or not
- C. All traffic from any zone will be allowed to the DMZ_inside zone only after inspection
- D. No traffic will be allowed through to the DMZ_inside zone unless it's already trusted
Answer: A
Explanation:
The access control rule in the exhibit has the following characteristics:
* The rule name is DMZ_Rule and it is enabled.
* The action set for this rule is Trust, meaning traffic matching this rule will not be subjected to further inspection.
* The source zones are not specified, meaning any zone can match this rule.
* The destination zone is DMZ_Inside, meaning only traffic destined to this zone can match this rule.
Therefore, the effect of this rule is that all traffic from any zone to the DMZ_Inside zone will be permitted with no further inspection. This is the correct answer, option A.
The other options are incorrect because they do not match the configuration of the rule or the behavior of the Trust action. Option B is incorrect because traffic will be allowed through to the DMZ_Inside zone, not blocked. Option C is incorrect because traffic will not be inspected before being allowed to the DMZ_Inside zone. Option D is incorrect because traffic does not need to be trusted to be allowed to the DMZ_Inside zone. References:
* Firepower Management Center Configuration Guide, Version 6.6 - Access Control Rules
* Firepower Management Center Device Configuration Guide, 7.1 - Access Control Policies
* How to Deploy FMC/FTD part 2 - Access Control Policies
NEW QUESTION # 71
Refer to the exhibit.
Which statement about the authentication protocol used in the configuration is true
- A. There are separate authentication and authorization request packets
- B. The authentication request contains only a password
- C. The authentication request contains only a username
- D. The authentication and authorization requests are grouped in a single packet
Answer: D
NEW QUESTION # 72
Which two Cisco ISE components must be configured for BYOD? (Choose two.)
- A. null WebAuth
- B. guest
- C. dual
- D. central WebAuth
- E. local WebAuth
Answer: B,D
NEW QUESTION # 73
Which action must be taken in the AMP for Endpoints console to detect specific MD5 signatures on endpoints and then quarantine the files?
- A. Configure an advanced custom detection list.
- B. Configure an IP Block & Allow custom detection list
- C. Configure a simple custom detection list
- D. Configure an application custom detection list
Answer: C
Explanation:
A simple custom detection list is a feature of AMP for Endpoints that allows you to specify a list of file hashes (MD5, SHA-1, or SHA-256) that you want to detect, block, and quarantine on your endpoints. You can create a simple custom detection list from the Outbreak Control section of the AMP for Endpoints console, and apply it to a policy that is assigned to your endpoints. When the AMP connector on the endpoint encounters a file that matches the hash in the list, it will perform the action that you specified, such as blocking the file execution, sending an alert, or quarantining the file. A simple custom detection list is useful when you want to quickly and easily block specific files that are known to be malicious or unwanted, without having to create a complex signature or rule12 References := 1: Configure a Simple Custom Detection List on the AMP for Endpoints Portal 2: Create an Advanced Custom Detection List in Cisco Secure Endpoint
NEW QUESTION # 74
Which two features are used to configure Cisco ESA with a multilayer approach to fight viruses and malware? (Choose two).
- A. RAT
- B. DLP
- C. Sophos engine
- D. outbreak filters
- E. white list
Answer: C,D
NEW QUESTION # 75
Which PKI enrollment method allows the user to separate authentication and enrollment actions and also provides an option to specify HTTP/TFTP commands to perform file retrieval from the server?
- A. selfsigned
- B. terminal
- C. profile
- D. url
Answer: C
Explanation:
Reference:
https://www.cisco.com/c/en/us/support/docs/security-vpn/public-key-infrastructure-pki/211333-IOSPKI-Deploym
NEW QUESTION # 76
Which MDM configuration provides scalability?
- A. enabling use of device features such as camera use
- B. BYOD support without extra appliance or licenses
- C. pushing WPA2-Enterprise settings automatically to devices
- D. automatic device classification with level 7 fingerprinting
Answer: B
Explanation:
Mobile device management (MDM) is a solution that allows organizations to manage and secure mobile devices such as smartphones and tablets. MDM can provide scalability by supporting BYOD (bring your own device) scenarios without requiring extra appliance or licenses. BYOD allows employees to use their personal devices for work purposes, which can reduce costs and increase productivity. However, BYOD also introduces security and compliance risks, which MDM can mitigate by enforcing policies, monitoring device status, and performing remote actions. MDM can also integrate with other Cisco security solutions such as Identity Services Engine (ISE) and Umbrella to provide additional protection and visibility. According to the Cisco SCOR course, MDM can provide the following benefits for BYOD1:
* Simplify device enrollment and configuration
* Automate device compliance checks and remediation
* Apply granular policies based on device type, user role, location, and network
* Enable secure access to corporate resources and applications
* Protect data at rest and in transit with encryption and VPN
* Detect and respond to device threats and vulnerabilities
* Wipe or lock devices in case of loss or theft
References: 1: Implementing and Operating Cisco Security Core Technologies (SCOR) v1.0 - Module 4:
Secure Connectivity - Lesson 4.3: Mobile Device Management (MDM)
NEW QUESTION # 77
Drag and drop the descriptions from the left onto the correct protocol versions on the right.
Answer:
Explanation:
NEW QUESTION # 78
Drag and drop the cryptographic algorithms for IPsec from the left onto the cryptographic processes on the right.
Answer:
Explanation:
NEW QUESTION # 79
An engineer notices traffic interruption on the network. Upon further investigation, it is learned that broadcast packets have been flooding the network. What must be configured, based on a predefined threshold, to address this issue?
- A. Bridge Protocol Data Unit guard
- B. storm control
- C. access control lists
- D. embedded event monitoring
Answer: B
Explanation:
ExplanationExplanationStorm control prevents traffic on a LAN from being disrupted by a broadcast, multicast, or unicast storm on one of the physical interfaces. A LAN storm occurs when packets flood the LAN, creating excessive traffic and degrading network performance. Errors in the protocol-stack implementation, mistakes in network configurations, or users issuing a denial-of-service attack can cause a storm.By using the "storm-control broadcast level [falling-threshold]" we can limit the broadcast traffic on the switch.
NEW QUESTION # 80
Drag and drop the NetFlow export formats from the left onto the descriptions on the right.
Answer:
Explanation:
NEW QUESTION # 81
Which two prevention techniques are used to mitigate SQL injection attacks? (Choose two)
- A. Secure the connection between the web and the app tier.
- B. Write SQL code instead of using object-relational mapping libraries.
- C. Use prepared statements and parameterized queries.
- D. Check integer, float, or Boolean string parameters to ensure accurate values.
- E. Block SQL code execution in the web application database login.
Answer: C,E
Explanation:
SQL injection attacks are a type of code injection technique that exploit the use of dynamic SQL queries in web applications. Attackers can inject malicious SQL statements into user input fields, such as login forms, search boxes, or URLs, and execute them on the underlying database. This can result in unauthorized access, data theft, data corruption, or denial of service.
To prevent SQL injection attacks, web developers should use the following techniques:
* Use prepared statements and parameterized queries: Prepared statements are SQL queries that are precompiled and executed with user-supplied parameters. Parameterized queries are SQL queries that use placeholders for user input and bind them to actual values at runtime. Both techniques separate the SQL code from the user input, making it impossible for attackers to inject SQL commands into the query. For example, in Java, PreparedStatement is a class that implements parameterized queries. In PHP, PDO and mysqli are extensions that support prepared statements.
* Block SQL code execution in the web application database login: Web applications should use a dedicated database user account with limited privileges to connect to the database. This account should only have the permissions necessary to perform the required operations, such as select, insert, update, or delete. It should not have the permissions to execute arbitrary SQL commands, such as create, drop, alter, grant, or revoke. This way, even if an attacker manages to inject SQL code into the query, the database will reject it due to insufficient privileges.
References:
* [Implementing and Operating Cisco Security Core Technologies (SCOR) v1.0], Module 5: Securing the Cloud, Lesson 5.2: Cloud Application Security, Topic 5.2.2: SQL Injection
* SQL Injection Prevention - OWASP Cheat Sheet Series
* How to Prevent SQL Injection: 5 Key Prevention Methods - eSecurityPlanet
* How to Protect Against SQL Injection Attacks
NEW QUESTION # 82
Drag and drop the concepts from the left onto the correct descriptions on the right
Answer:
Explanation:
NEW QUESTION # 83
Drag and drop the descriptions from the left onto the correct protocol versions on the right.
Answer:
Explanation:
NEW QUESTION # 84
Which CoA response code is sent if an authorization state is changed successfully on a Cisco IOS device?
- A. CoA-NCL
- B. COA-MAB
- C. CoA-ACK
- D. CoA-NAK
Answer: C
NEW QUESTION # 85
Which type of data does the Cisco Stealthwatch system collect and analyze from routers, switches, and firewalls?
- A. syslog
- B. NTP
- C. NetFlow
- D. SNMP
Answer: C
NEW QUESTION # 86
Drag and drop the common security threats from the left onto the definitions on the right.
Answer:
Explanation:
NEW QUESTION # 87
What is the purpose of the Cisco Endpoint IoC feature?
- A. It provides stealth threat prevention.
- B. It is a signature-based engine.
- C. It is an incident response tool.
- D. It provides precompromise detection.
Answer: C
Explanation:
Reference: https://docs.amp.cisco.com/Cisco%20Endpoint%20IOC%20Attributes.pdf The Endpoint Indication of Compromise (IOC) feature is a powerful incident response tool for scanning of post-compromise indicators across multiple computers.
NEW QUESTION # 88
What is a functional difference between Cisco AMP for Endpoints and Cisco Umbrella Roaming Client?
- A. AMP for Endpoints stops and tracks malicious activity on hosts, and the Umbrella Roaming Client tracks only URL-based threats.
- B. AMP for Endpoints authenticates users and provides segmentation, and the Umbrella Roaming Client allows only for VPN connectivity.
- C. The Umbrella Roaming client stops and tracks malicious activity on hosts, and AMP for Endpoints tracks only URL-based threats.
- D. The Umbrella Roaming Client authenticates users and provides segmentation, and AMP for Endpoints allows only for VPN connectivity
Answer: A
NEW QUESTION # 89
What is the concept of Cl/CD pipelining?
- A. Each project phase is independent from other phases to maintain adaptiveness and continual improvement
- B. The project code is centrally maintained and each code change should trigger an automated build and test sequence
- C. The project is split into several phases where one phase cannot start before the previous phase finishes successfully.
- D. The project is split into time-limited cycles and focuses on pair programming for continuous code review
Answer: C
NEW QUESTION # 90
Which Cisco cloud security software centrally manages policies on multiple platforms such as Cisco ASA, Cisco Firepower, Cisco Meraki, and AWS?
- A. Cisco Defense Orchestrator
- B. Cisco Configuration Professional
- C. Cisco DNAC
- D. Cisco Secureworks
Answer: A
Explanation:
Cisco Defense Orchestrator (CDO) is a cloud-based management solution that allows you to manage security policies and device configurations with ease across multiple Cisco and cloud-native security platforms. CDO centrally manages elements of policy and configuration across Cisco ASA, Cisco Firepower, Cisco Meraki, and AWS1. CDO also provides visibility, automation, and orchestration capabilities to simplify and unify security operations2. The other options are not cloud security software that can centrally manage policies on multiple platforms. Cisco Configuration Professional is a device management tool for Cisco routers and switches. Cisco Secureworks is a security services provider that offers threat intelligence and incident response. Cisco DNAC is a network controller that automates and assures services across campus, branch, and edge networks. References :=
* Cisco Defense Orchestrator Data Sheet
* Cisco Defense Orchestrator
NEW QUESTION # 91
When planning a VPN deployment, for which reason does an engineer opt for an active/active FlexVPN configuration as opposed to DMVPN?
- A. Multiple routers or VRFs are required.
- B. Floating static routes are required.
- C. HSRP is used for faliover.
- D. Traffic is distributed statically by default.
Answer: A
Explanation:
An active/active FlexVPN configuration allows for multiple routers or VRFs to act as hubs for different VPN groups, providing load balancing and redundancy1. This is useful when the VPN deployment has a large number of spokes or different security policies for different groups of spokes. DMVPN, on the other hand, only supports a single hub or a pair of hubs in active/standby mode for each VPN group2. This limits the scalability and flexibility of DMVPN deployments. Therefore, an engineer would opt for an active/active FlexVPN configuration as opposed to DMVPN when multiple routers or VRFs are required. References :=
* Cisco FlexVPN: Benefits and Best Practices
* Cisco DMVPN Design Guide
NEW QUESTION # 92
......
Get 100% Real Free CCNP Security 350-701 Sample Questions: https://certificationsdesk.examslabs.com/Cisco/CCNPSecurity/best-350-701-exam-dumps.html