Pass the Cisco CCNP Security 350-701 Questions and answers with CertsForce

Viewing page 15 out of 15 pages
Viewing questions 211-225 out of questions
Questions # 211:

Which two actions does the Cisco ISE posture module provide that ensures endpoint security? (Choose two.)

Options:

A.

A centralized management solution is deployed.


B.

Patch management remediation is performed.


C.

The latest antivirus updates are applied before access is allowed.


D.

Assignments to endpoint groups are made dynamically, based on endpoint attributes.


E.

Endpoint supplicant configuration is deployed.


Expert Solution
Questions # 212:

A security engineer must create a policy based on the reputation verdict of a file from a Cisco Secure Email Gateway. The file with an undetermined verdict must be dropped. Which action must the security engineer take to meet the requirement?

Options:

A.

Configure threshold settings for files with no score to be allowed.


B.

Set up a policy to automatically drop files with no reputation score.


C.

Implement a policy to disable file analysis.


D.

Create a policy to send a file to quarantine.


Expert Solution
Questions # 213:

An engineer must modify a policy to block specific addresses using Cisco Umbrella. The policy is created already and is actively u: of the default policy elements. What else must be done to accomplish this task?

Options:

A.

Add the specified addresses to the identities list and create a block action.


B.

Create a destination list for addresses to be allowed or blocked.


C.

Use content categories to block or allow specific addresses.


D.

Modify the application settings to allow only applications to connect to required addresses.


Expert Solution
Questions # 214:

An engineer is configuring Cisco WSA and needs to enable a separated email transfer flow from the Internet and from the LAN. Which deployment mode must be used to accomplish this goal?

Options:

A.

single interface


B.

multi-context


C.

transparent


D.

two-interface


Expert Solution
Questions # 215:

Which cryptographic process provides origin confidentiality, integrity, and origin authentication for packets?

Options:

A.

IKEv1


B.

AH


C.

ESP


D.

IKEv2


Expert Solution
Questions # 216:

What is a difference between GETVPN and IPsec?

Options:

A.

GETVPN reduces latency and provides encryption over MPLS without the use of a central hub


B.

GETVPN provides key management and security association management


C.

GETVPN is based on IKEv2 and does not support IKEv1


D.

GETVPN is used to build a VPN network with multiple sites without having to statically configure all devices


Expert Solution
Questions # 217:

When using Cisco AMP for Networks which feature copies a file to the Cisco AMP cloud for analysis?

Options:

A.

Spero analysis


B.

dynamic analysis


C.

sandbox analysis


D.

malware analysis


Expert Solution
Viewing page 15 out of 15 pages
Viewing questions 211-225 out of questions