Pre-Winter Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Cisco CCNP Security 350-701 Questions and answers with CertsForce

Viewing page 2 out of 16 pages
Viewing questions 16-30 out of questions
Questions # 16:

Which Secure Email Gateway implementation method segregates inbound and outbound email?

Options:

A.

Pair of logical listeners on a single physical interface with two unique logical IPv4 addresses and one IPv6 address


B.

One listener on one logical IPv4 address on a single logical interface


C.

Pair of logical IPv4 listeners and a pair of IPv6 listeners on two physically separate interfaces


D.

One listener on a single physical interface


Expert Solution
Questions # 17:

When a Cisco WSA checks a web request, what occurs if it is unable to match a user-defined policy?

Options:

A.

It blocks the request.


B.

It applies the global policy.


C.

It applies the next identification profile policy.


D.

It applies the advanced policy.


Expert Solution
Questions # 18:

A security policy administrator configures a Cisco Secure Access SIA DNS policy to block all social media categories for the Marketing Active Directory group. While testing from one of the user machines, access to the domain https://socialmediaexample.org is allowed. When searching for this domain in User Activity Search, no queries for that specific domain are returned. Consider these facts:

    The test user is part of the Marketing Active Directory group.

    The domain socialmediaexample.org belongs to the social media category.

    The user is configured with the Umbrella Roaming Client for DNS redirection.

    All other social media websites are properly blocked for the same user and match the correct policy.

Which configuration must the administrator implement in Cisco Secure Access to meet the requirement?

Options:

A.

Enable HTTPS inspection in the web policy because this is an HTTPS site.


B.

Add socialmediaexample.org to the External Domains list.


C.

Enable the intelligent proxy to identify this domain properly.


D.

Add socialmediaexample.org to the Internal Domains list.


Expert Solution
Questions # 19:

What are two things to consider when using PAC files with the Cisco WSA? (Choose two.)

Options:

A.

If the WSA host port is changed, the default port redirects web traffic to the correct port automatically.


B.

PAC files use if-else statements to determine whether to use a proxy or a direct connection for traffic between the PC and the host.


C.

The WSA hosts PAC files on port 9001 by default.


D.

The WSA hosts PAC files on port 6001 by default.


E.

By default, they direct traffic through a proxy when the PC and the host are on the same subnet.


Expert Solution
Questions # 20:

Which VMware platform does Cisco ACI integrate with to provide enhanced visibility, provide policy integration and deployment, and implement security policies with access lists?

Options:

A.

VMware APIC


B.

VMwarevRealize


C.

VMware fusion


D.

VMware horizons


Expert Solution
Questions # 21:

An engineer must force an endpoint to re-authenticate an already authenticated session without disrupting the

endpoint to apply a new or updated policy from ISE. Which CoA type achieves this goal?

Options:

A.

Port Bounce


B.

CoA Terminate


C.

CoA Reauth


D.

CoA Session Query


Expert Solution
Questions # 22:

An administrator has been tasked with configuring the Cisco Secure Email Gateway to ensure there are no viruses before quarantined emails are delivered. In addition, delivery of mail from known bad mail servers must be prevented. Which two actions must be taken in order to meet these requirements? (Choose two.)

Options:

A.

Deploy the Secure Email Gateway in the DMZ.


B.

Use outbreak filters from Cisco Talos.


C.

Configure a recipient access table.


D.

Enable a message tracking service.


E.

Scan quarantined emails using AntiVirus signatures.


Expert Solution
Questions # 23:

Which option is the main function of Cisco Firepower impact flags?

Options:

A.

They alert administrators when critical events occur.


B.

They highlight known and suspected malicious IP addresses in reports.


C.

They correlate data about intrusions and vulnerability.


D.

They identify data that the ASA sends to the Firepower module.


Expert Solution
Questions # 24:

An engineer is configuring Cisco WSA and needs to deploy it in transparent mode. Which configuration component must be used to accomplish this goal?

Options:

A.

MDA on the router


B.

PBR on Cisco WSA


C.

WCCP on switch


D.

DNS resolution on Cisco WSA


Expert Solution
Questions # 25:

Which SNMPv3 configuration must be used to support the strongest security possible?

Options:

A.

asa-host(config)#snmp-server group myv3 v3 privasa-host(config)#snmp-server user andy myv3 auth sha cisco priv des ciscXXXXXXXXasa-host(config)#snmp-server host inside 10.255.254.1 version 3 andy


B.

asa-host(config)#snmp-server group myv3 v3 noauthasa-host(config)#snmp-server user andy myv3 auth sha cisco priv aes 256 ciscXXXXXXXXasa-host(config)#snmp-server host inside 10.255.254.1 version 3 andy


C.

asa-host(config)#snmpserver group myv3 v3 noauthasa-host(config)#snmp-server user andy myv3 auth sha cisco priv 3des ciscXXXXXXXXasa-host(config)#snmp-server host inside 10.255.254.1 version 3 andy


D.

asa-host(config)#snmp-server group myv3 v3 privasa-host(config)#snmp-server user andy myv3 auth sha cisco priv aes 256 ciscXXXXXXXXasa-host(config)#snmp-server host inside 10.255.254.1 version 3 andy


Expert Solution
Questions # 26:

Which two types of policies are used by ZTNA to provide access to an application? (Choose two.)

Options:

A.

Context


B.

Access


C.

Site-to-site


D.

Identity


E.

Remote access


Expert Solution
Questions # 27:

An administrator configures new authorization policies within Cisco ISE and has difficulty profiling the devices. Attributes for the new Cisco IP phones that are profiled based on the RADIUS authentication are seen however the attributes for CDP or DHCP are not. What should the administrator do to address this issue?

Options:

A.

Configure the ip dhcp snooping trust command on the DHCP interfaces to get the information to Cisco ISE


B.

Configure the authentication port-control auto feature within Cisco ISE to identify the devices that are trying to connect


C.

Configure a service template within the switch to standardize the port configurations so that the correct information is sent to Cisco ISE


D.

Configure the device sensor feature within the switch to send the appropriate protocol information


Expert Solution
Questions # 28:

How many interfaces per bridge group does an ASA bridge group deployment support?

Options:

A.

up to 2


B.

up to 4


C.

up to 8


D.

up to 16


Expert Solution
Questions # 29:

What is the process In DevSecOps where all changes In the central code repository are merged and synchronized?

Options:

A.

CD


B.

EP


C.

CI


D.

QA


Expert Solution
Questions # 30:

Which OWASP LLM risk involves an attacker embedding hidden instructions in user input to manipulate the model’s behavior?

Options:

A.

Output Truncation


B.

Prompt Injection


C.

System Prompt Leakage


D.

Data Exfiltration


Expert Solution
Viewing page 2 out of 16 pages
Viewing questions 16-30 out of questions