Pass the Cisco CCNP Security 350-701 Questions and answers with CertsForce

Viewing page 2 out of 15 pages
Viewing questions 16-30 out of questions
Questions # 16:

What is a benefit of flexible NetFlow records?

Options:

A.

They are used for security


B.

They are used for accounting


C.

They monitor a packet from Layer 2 to Layer 5


D.

They have customized traffic identification


Expert Solution
Questions # 17:

What are two workload security models? (Choose two.)

Options:

A.

SaaS


B.

PaaS


C.

off-premises


D.

on-premises


E.

IaaS


Expert Solution
Questions # 18:

Which type of data does the Cisco Stealthwatch system collect and analyze from routers, switches, and firewalls?

Options:

A.

NTP


B.

syslog


C.

SNMP


D.

NetFlow


Expert Solution
Questions # 19:

When a Cisco Secure Web Appliance checks a web request, what occurs if it is unable to match a user-defined policy?

Options:

A.

It applies the next identification profile policy.


B.

It applies the advanced policy.


C.

It applies the global policy.


D.

It blocks the request.


Expert Solution
Questions # 20:

Which algorithm is an NGE hash function?

Options:

A.

HMAC


B.

SHA-1


C.

MD5


D.

SISHA-2


Expert Solution
Questions # 21:

An engineer must deploy Cisco Secure Email with Cloud URL Analysis and must meet these requirements:

    To protect the network from large-scale virus outbreaks

    To protect the network from non-viral attacks such as phishing scams and malware distribution

    To provide active analysis of the structure of the URL and information about the domain and page contents

Which two prerequisites must the engineer ensure are configured? (Choose two.)

Options:

A.

Scanning enabled for each Verdict, Prepend Subject and Deliver.


B.

Outbreak Filters must be enabled globally.


C.

Enable TLS by setting to Preferred to the Default Domain.


D.

Service Logs must be enabled.


E.

Enable Rejected Connection Logging.


Expert Solution
Questions # 22:

What provides the ability to program and monitor networks from somewhere other than the DNAC GUI?

Options:

A.

NetFlow


B.

desktop client


C.

ASDM


D.

API


Expert Solution
Questions # 23:

Which Cisco product provides proactive endpoint protection and allows administrators to centrally manage the

deployment?

Options:

A.

NGFW


B.

AMP


C.

WSA


D.

ESA


Expert Solution
Questions # 24:

A company deploys an application that contains confidential data and has a hybrid hub-and-spoke topology. The hub resides in a public cloud environment, and the spoke resides on-premises. An engineer must secure the application to ensure that confidential data in transit between the hub-and-spoke servers is accessible only to authorized users. The engineer performs these configurations:

    Segregation of duties

    Role-based access control

    Privileged access management

What must be implemented to protect the data in transit?

Options:

A.

MD5


B.

AES-256


C.

SHA-512


D.

TLS 1.3


Expert Solution
Questions # 25:

With regard to RFC 5176 compliance, how many IETF attributes are supported by the RADIUS CoA feature?

Options:

A.

3


B.

5


C.

10


D.

12


Expert Solution
Questions # 26:

How does Cisco AMP for Endpoints provide next-generation protection?

Options:

A.

It encrypts data on user endpoints to protect against ransomware.


B.

It leverages an endpoint protection platform and endpoint detection and response.


C.

It utilizes Cisco pxGrid, which allows Cisco AMP to pull threat feeds from threat intelligence centers.


D.

It integrates with Cisco FTD devices.


Expert Solution
Questions # 27:

Which risk is created when using an Internet browser to access cloud-based service?

Options:

A.

misconfiguration of infrastructure, which allows unauthorized access


B.

intermittent connection to the cloud connectors


C.

vulnerabilities within protocol


D.

insecure implementation of API


Expert Solution
Questions # 28:

A network engineer is deciding whether to use stateful or stateless failover when configuring two ASAs for high availability. What is the connection status in both cases?

Options:

A.

need to be reestablished with stateful failover and preserved with stateless failover


B.

preserved with stateful failover and need to be reestablished with stateless failover


C.

preserved with both stateful and stateless failover


D.

need to be reestablished with both stateful and stateless failover


Expert Solution
Questions # 29:

What is an advantage of using a next-generation firewall compared to a traditional firewall?

Options:

A.

Next-generation firewalls have stateless inspection capabilities, and traditional firewalls use stateful inspection.


B.

Next-generation firewalls use dynamic packet filtering, and traditional firewalls use static packet filtering.


C.

Next-generation firewalls have threat intelligence feeds, and traditional firewalls use signature detection.


D.

Next-generation firewalls use intrusion prevention policies, and traditional firewalls use intrusion detection policies.


Expert Solution
Questions # 30:

What is a benefit of using Cisco Umbrella?

Options:

A.

DNS queries are resolved faster.


B.

Attacks can be mitigated before the application connection occurs.


C.

Files are scanned for viruses before they are allowed to run.


D.

It prevents malicious inbound traffic.


Expert Solution
Viewing page 2 out of 15 pages
Viewing questions 16-30 out of questions