Pre-Winter Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: buysanta

Exact2Pass Menu

Implementing and Operating Cisco Security Core Technologies (SCOR 350-701 v2.0)

Last Update 20 hours ago Total Questions : 801

The Implementing and Operating Cisco Security Core Technologies (SCOR 350-701 v2.0) content is now fully updated, with all current exam questions added 20 hours ago. Deciding to include 350-701 practice exam questions in your study plan goes far beyond basic test preparation.

You'll find that our 350-701 exam questions frequently feature detailed scenarios and practical problem-solving exercises that directly mirror industry challenges. Engaging with these 350-701 sample sets allows you to effectively manage your time and pace yourself, giving you the ability to finish any Implementing and Operating Cisco Security Core Technologies (SCOR 350-701 v2.0) practice test comfortably within the allotted time.

Question # 136

Which solution detects threats across a private network, public clouds, and encrypted traffic?

A.

Cisco Stealthwatch

B.

Cisco CTA

C.

Cisco Encrypted Traffic Analytics

D.

Cisco Umbrella

Question # 137

An organization has noticed an increase in malicious content downloads and wants to use Cisco Umbrella to prevent this activity for suspicious domains while allowing normal web traffic. Which action will accomplish this task?

A.

Set content settings to High

B.

Configure the intelligent proxy.

C.

Use destination block lists.

D.

Configure application block lists.

Question # 138

Refer to the exhibit.

A network engineer is testing NTP authentication and realizes that any device synchronizes time with this router and that NTP authentication is not enforced What is the cause of this issue?

A.

The key was configured in plain text.

B.

NTP authentication is not enabled.

C.

The hashing algorithm that was used was MD5. which is unsupported.

D.

The router was not rebooted after the NTP configuration updated.

Question # 139

Which two global commands must the network administrator implement to limit the attack surface of an internet-facing Cisco router? (Choose two.)

A.

no service password-recovery

B.

no cdp run

C.

service tcp-keepalives-in

D.

no ip http server

E.

ip ssh version 2

Question # 140

An engineer needs behavioral analysis to detect malicious activity on the hosts, and is configuring the

organization’s public cloud to send telemetry using the cloud provider’s mechanisms to a security device. Which

mechanism should the engineer configure to accomplish this goal?

A.

mirror port

B.

Flow

C.

NetFlow

D.

VPC flow logs

Question # 141

Which algorithm is an NGE hash function?

A.

HMAC

B.

SHA-1

C.

MD5

D.

SISHA-2

Question # 142

In a PaaS model, which layer is the tenant responsible for maintaining and patching?

A.

hypervisor

B.

virtual machine

C.

network

D.

application

Question # 143

What is the purpose of a denial-of-service attack?

A.

to disrupt the normal operation of a targeted system by overwhelming It

B.

to exploit a security vulnerability on a computer system to steal sensitive information

C.

to prevent or limit access to data on a computer system by encrypting It

D.

to spread throughout a computer system by self-replicating to additional hosts

Question # 144

Which attack type attempts to shut down a machine or network so that users are not able to access it?

A.

smurf

B.

bluesnarfing

C.

MAC spoofing

D.

IP spoofing

Question # 145

A company wants to enforce security policy using Cisco Secure Access Secure Internet Access. The design requirements are:

    Block adult-content and gambling categories for all users.

    Inspect file downloads for malware.

    Bypass TLS decryption for financial and healthcare domains because of compliance requirements.

    Allow the Marketing department to use social media while keeping file scanning active for downloads from those sites.

Which two configuration actions must the engineer perform in Cisco Secure Access to meet the requirements? (Choose two.)

A.

Configure a Marketing policy with higher precedence to allow social-networking sites, and apply a decryption-bypass list for financial and healthcare domains.

B.

Disable TLS decryption globally and rely on DNS-layer reputation to block adult-content and gambling sites.

C.

Use destination allow lists for financial and healthcare sites to prevent SSL inspection, with malware scanning enabled in full-inspection mode for all traffic.

D.

Create a global policy that blocks adult-content and gambling categories with TLS inspection enabled, and create a higher-precedence Marketing policy that allows social-networking sites.

E.

Implement one global policy that blocks adult-content and gambling categories, and add a web-application allow rule for social networking.

Question # 146

When using Cisco AMP for Networks which feature copies a file to the Cisco AMP cloud for analysis?

A.

Spero analysis

B.

dynamic analysis

C.

sandbox analysis

D.

malware analysis

Question # 147

Which Secure Email Gateway implementation method segregates inbound and outbound email?

A.

Pair of logical listeners on a single physical interface with two unique logical IPv4 addresses and one IPv6 address

B.

One listener on one logical IPv4 address on a single logical interface

C.

Pair of logical IPv4 listeners and a pair of IPv6 listeners on two physically separate interfaces

D.

One listener on a single physical interface

Question # 148

How does a Cisco Secure Firewall help to lower the risk of exfiltration techniques that steal customer data?

A.

Blocking UDP port 53

B.

Blocking TCP port 53

C.

Encrypting the DNS communication

D.

Inspecting the DNS traffic

Question # 149

Client workstations are experiencing extremely poor response time. An engineer suspects that an attacker is eavesdropping and making independent connections while relaying messages between victims to make them think they are talking to each other over a private connection. Which feature must be enabled and configured to provide relief from this type of attack?

A.

Link Aggregation

B.

Reverse ARP

C.

private VLANs

D.

Dynamic ARP Inspection

Question # 150

A logistics company issues corporate laptops that must automatically establish a Cisco Secure Client VPN tunnel whenever users are outside the office and connected to an untrusted external network. Cisco Secure Firewall Threat Defense is the VPN headend and is already configured with remote-access profiles, address pools, and a PKI that distributes both machine and user certificates to endpoints. Management requires the tunnel to come up unattended before any user signs in to a laptop. Device-based authentication must be used, and the client must distinguish the corporate LAN from outside networks. The VPN must be connected when a user is outside the corporate network. Which configuration action must be performed to meet the requirements?

A.

Configure a Management VPN tunnel with user-certificate authentication for unattended connectivity.

B.

Configure Trusted Network Detection and Start Before Login with machine-certificate authentication for the client.

C.

Configure Trusted Network Detection using cached domain credentials for client authentication.

D.

Implement Start Before Login paired with user-certificate authentication in the profile.

Go to page: