
Dumps for Free Cisco 350-701 Practice Exam Questions [Dec 15, 2024]
350-701 Dumps PDF And Certification Training
NEW QUESTION # 152
Which Cisco security solution determines if an endpoint has the latest OS updates and patches installed on the system?
- A. Cisco Endpoint Security Analytics
- B. Cisco AMP for Endpoints
- C. Endpoint Compliance Scanner
- D. Security Posture Assessment Service
Answer: D
NEW QUESTION # 153
How is ICMP used an exfiltration technique?
- A. by sending large numbers of ICMP packets with a targeted hosts source IP address using an IP broadcast address
- B. by encrypting the payload in an ICMP packet to carry out command and control tasks on a compromised host
- C. by flooding the destination host with unreachable packets
- D. by overwhelming a targeted host with ICMP echo-request packets
Answer: B
NEW QUESTION # 154
What is the benefit of installing Cisco AMP for Endpoints on a network?
- A. It provides operating system patches on the endpoints for security.
- B. It provides flow-based visibility for the endpoints' network connections.
- C. It enables behavioral analysis to be used for the endpoints.
- D. It protects endpoint systems through application control and real-time scanning.
Answer: D
Explanation:
Explanation
https://www.cisco.com/c/en/us/solutions/collateral/enterprise-networks/advanced-malware-protection/at-a-glance
NEW QUESTION # 155
What is the function of the crypto is a kmp key cisc406397954 address 0.0.0.0 0.0.0.0 command when establishing an IPsec VPN tunnel?
- A. lt configures the pre-shared authentication key
- B. It configures the local address for the VPN server.
- C. It prevents all IP addresses from connecting to the VPN server.
- D. It defines what data is going to be encrypted via the VPN
Answer: A
Explanation:
The function of the crypto is a kmp key cisc406397954 address 0.0.0.0 0.0.0.0 command when establishing an IPsec VPN tunnel is to configure the pre-shared authentication key. This command specifies the key that will be used to authenticate the Internet Key Exchange (IKE) phase 1 negotiation between the IPsec peers. The key is associated with the address 0.0.0.0 0.0.0.0, which means that it will apply to any peer that initiates or responds to the IKE negotiation. This is a common configuration for dynamic IPsec VPN scenarios, such as Dynamic Multipoint VPN (DMVPN) or Easy VPN, where the IP addresses of the peers are not known in advance. However, this is also a less secure configuration, as it exposes the VPN server to potential brute-force attacks from any source. A more secure configuration would be to specify the exact IP address or subnet of the peer, or to use certificates instead of pre-shared keys.
References:
* Implementing and Operating Cisco Security Core Technologies (SCOR) v1.0, Module 4: Securing the Cloud, Lesson 2: Site-to-Site VPNs, Topic: IPsec VPN Configuration
* Cisco IOS Security Configuration Guide: Securing User Services, Release 12.4 - Configuring Internet Key Exchange for IPsec VPNs [Support] - Cisco, Configuring IKE Policies, Step 3: crypto isakmp key keystring [address | hostname] [mask | no-xauth] [netmask mask]
NEW QUESTION # 156
Which Cisco network security device supports contextual awareness?
- A. Firepower
- B. CISCO ASA
- C. ISE
- D. Cisco IOS
Answer: C
NEW QUESTION # 157
Which network monitoring solution uses streams and pushes operational data to provide a near real-time view of activity?
- A. SMTP
- B. syslog
- C. SNMP
- D. model-driven telemetry
Answer: D
Explanation:
Reference: https://developer.cisco.com/docs/ios-xe/#!streaming-telemetry-quick-start-guide
NEW QUESTION # 158
Which two criteria must a certificate meet before the WSA uses it to decrypt application traffic? (Choose two.)
- A. It must reside in the trusted store of the endpoint.
- B. It must reside in the trusted store of the WSA.
- C. it must contain a SAN.
- D. It must have been signed by an internal CA.
- E. It must include the current date.
Answer: B,C
Explanation:
The WSA uses a root certificate and a private key to decrypt HTTPS traffic. The root certificate must reside in the trusted store of the WSA, and it must be able to sign server certificates on the fly. The server certificates that the WSA generates must contain a SAN (Subject Alternative Name) field, which specifies the hostnames or IP addresses that the certificate is valid for. The SAN field is required by modern browsers and applications to verify the identity of the server. If the WSA does not include a SAN field in the server certificate, the browser or application may reject the connection or display a warning message.
The other options are not correct because:
* A. The current date is not a criterion for the WSA to use a certificate to decrypt application traffic. The WSA checks the validity period of the certificate, which includes the start date and the end date. The current date must be within the validity period, but it does not have to be the same as the start date or the end date.
* C. The root certificate that the WSA uses to decrypt HTTPS traffic does not have to reside in the trusted store of the endpoint. However, the endpoint must trust the root certificate in order to accept the server certificate that the WSA generates. This can be achieved by manually installing the root certificate on the endpoint, or by using a group policy or a certificate management system to distribute the root certificate to the endpoints.
* D. The root certificate that the WSA uses to decrypt HTTPS traffic does not have to be signed by an internal CA. The WSA can generate its own self-signed root certificate, or it can use a root certificate that is signed by an external CA. However, the root certificate must be trusted by the endpoints, as explained in option C.
References := : WSA Certificate Usage for HTTPS Decryption : [User Guide for AsyncOS 12.0 for Cisco Web Security Appliances - GD (General Deployment) - Create Decryption Policies to Control HTTPS Traffic]
NEW QUESTION # 159
Which type of dashboard does Cisco DNA Center provide for complete control of the network?
- A. service management
- B. application management
- C. centralized management
- D. distributed management
Answer: C
Explanation:
Cisco's DNA Center is the only centralized network management system to bring all of this functionality into a single pane of glass.
Cisco's DNA Center is the only centralized network management system to bring all of this functionality into a single pane of glass.
Cisco's DNA Center is the only centralized network management system to bring all of this functionality into a single pane of glass.
NEW QUESTION # 160
Which MDM configuration provides scalability?
- A. BYOD support without extra appliance or licenses
- B. automatic device classification with level 7 fingerprinting
- C. pushing WPA2-Enterprise settings automatically to devices
- D. enabling use of device features such as camera use
Answer: A
Explanation:
Mobile device management (MDM) is a solution that allows organizations to manage and secure mobile devices such as smartphones and tablets. MDM can provide scalability by supporting BYOD (bring your own device) scenarios without requiring extra appliance or licenses. BYOD allows employees to use their personal devices for work purposes, which can reduce costs and increase productivity. However, BYOD also introduces security and compliance risks, which MDM can mitigate by enforcing policies, monitoring device status, and performing remote actions. MDM can also integrate with other Cisco security solutions such as Identity Services Engine (ISE) and Umbrella to provide additional protection and visibility. According to the Cisco SCOR course, MDM can provide the following benefits for BYOD1:
* Simplify device enrollment and configuration
* Automate device compliance checks and remediation
* Apply granular policies based on device type, user role, location, and network
* Enable secure access to corporate resources and applications
* Protect data at rest and in transit with encryption and VPN
* Detect and respond to device threats and vulnerabilities
* Wipe or lock devices in case of loss or theft
References: 1: Implementing and Operating Cisco Security Core Technologies (SCOR) v1.0 - Module 4:
Secure Connectivity - Lesson 4.3: Mobile Device Management (MDM)
NEW QUESTION # 161
What is the result of running thecrypto isakmp key ciscXXXXXXXX address 172.16.0.0command?
- A. authenticates the IKEv2 peers in the 172.16.0.0/16 range by using the key ciscXXXXXXXX
- B. authenticates the IKEv1 peers in the 172.16.0.0/16 range by using the key ciscXXXXXXXX
- C. authenticates the IP address of the 172.16.0.0/32 peer by using the key ciscXXXXXXXX
- D. secures all the certificates in the IKE exchange by using the key ciscXXXXXXXX
Answer: C
NEW QUESTION # 162
Which solution supports high availability in routed or transparent mode as well as in northbound and southbound deployments?
- A. Cisco Firepower NGFW Virtual appliance with Cisco FMC
- B. Cisco FTD with Cisco FMC
- C. Cisco Firepower NGFW physical appliance with Cisco. FMC
- D. Cisco FTD with Cisco ASDM
Answer: B
NEW QUESTION # 163
Which type of dashboard does Cisco DNA Center provide for complete control of the network?
- A. service management
- B. application management
- C. centralized management
- D. distributed management
Answer: C
Explanation:
Cisco's DNA Center is the only centralized network management system to bring all of this functionality into a single pane of glass.
Cisco's DNA Center is the only centralized network management system to bring all of this functionality into a single pane of glass.
Reference:
Cisco's DNA Center is the only centralized network management system to bring all of this functionality into a single pane of glass.
NEW QUESTION # 164
Which VMware platform does Cisco ACI integrate with to provide enhanced visibility, provide policy integration and deployment, and implement security policies with access lists?
- A. VMware horizons
- B. VMwarevRealize
- C. VMware APIC
- D. VMware fusion
Answer: B
NEW QUESTION # 165
A user has a device in the network that is receiving too many connection requests from multiple machines.
Which type of attack is the device undergoing?
- A. slowloris
- B. pharming
- C. SYN flood
- D. phishing
Answer: C
Explanation:
A SYN flood is a type of denial-of-service (DoS) attack that exploits the TCP three-way handshake process to exhaust the resources of a target server. The attacker sends a large number of SYN packets to the target server, each with a spoofed source IP address. The target server allocates resources for each incoming SYN packet and responds with a SYN-ACK packet to the spoofed address. However, the spoofed address never sends back the final ACK packet to complete the connection, leaving the target server with many half-open connections that eventually fill up its connection table. This prevents the target server from accepting new legitimate connections and causes service disruption123 References: 1: Implementing and Operating Cisco Security Core Technologies (SCOR) v1.0 course overview 2: SYN Flood Explained. How to Prevent this Attack from Taking over your ... 3: What is a SYN flood attack? | Cloudflare
NEW QUESTION # 166
In which form of attack is alternate encoding, such as hexadecimal representation, most often observed?
- A. Smurf
- B. rootkit exploit
- C. distributed denial of service
- D. cross-site scripting
Answer: D
Explanation:
Explanation
Cross site scripting (also known as XSS) occurs when a web application gathers malicious data from a user. The data is usually gathered in the form of a hyperlink which contains malicious content within it. The user will most likely click on this link from another website, instant message, or simply just reading a web board or email message.
Usually the attacker will encode the malicious portion of the link to the site in HEX (or other encoding methods) so the request is less suspicious looking to the user when clicked on.
For example the code below is written in hex: <a
href=javascript:alert&#
x28'XSS')>Click Here</a>
is equivalent to:
<a href=javascript:alert('XSS')>Click Here</a>
Note: In the format "&#xhhhh", hhhh is the code point in hexadecimal form.
NEW QUESTION # 167
......
How to schedule Implementing and Operating Cisco Security Core Technologies (SCOR 350-701)
- Log into your account at Pearson VUE
- Select Proctored Exams and enter the exam number 350-701
- Follow the prompts to register
Check your preparation for Cisco 350-701 On-Demand Exam: https://www.dumps4pdf.com/350-701-valid-braindumps.html
Practice Exam 350-701 Realistic Dumps Verified Questions: https://drive.google.com/open?id=1nuCjsgv3_yrZLyTyV_HtrUg6Ctadh9yS