Pre-Winter Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Cisco CCNP Security 350-701 Questions and answers with CertsForce

Viewing page 5 out of 16 pages
Viewing questions 61-75 out of questions
Questions # 61:

Which two aspects of the cloud PaaS model are managed by the customer but not the provider? (Choose two)

Options:

A.

virtualization


B.

middleware


C.

operating systems


D.

applications


E.

data


Expert Solution
Questions # 62:

In which two ways does a system administrator send web traffic transparently to the Web Security Appliance?

(Choose two)

Options:

A.

configure Active Directory Group Policies to push proxy settings


B.

configure policy-based routing on the network infrastructure


C.

reference a Proxy Auto Config file


D.

configure the proxy IP address in the web-browser settings


E.

use Web Cache Communication Protocol


Expert Solution
Questions # 63:

A networking team must harden an organization ' s network from VLAN hopping attacks. The team disables Dynamic Trunking Protocol and puts any unused ports in an unused VLAN. A trunk port is used as a trunk link. What must the team configure next to harden the network against VLAN hopping attacks?

Options:

A.

disable STP on the network devices


B.

dedicated VLAN ID for all trunk ports


C.

DHCP snooping on all the switches


D.

enable port-based network access control


Expert Solution
Questions # 64:

An engineer is configuring Dropbox integration with Cisco Cloudlock. Which action must be taken before granting API access in the Dropbox admin console?

Options:

A.

Authorize Dropbox within the Platform settings in the Cisco Cloudlock portal.


B.

Add Dropbox to the Cisco Cloudlock Authentication and API section in the Cisco Cloudlock portal.


C.

Send an API request to Cisco Cloudlock from Dropbox admin portal.


D.

Add Cisco Cloudlock to the Dropbox admin portal.


Expert Solution
Questions # 65:

Which two configurations must be made on Cisco ISE and on Cisco TrustSec devices to force a session to be adjusted after a policy change is made? (Choose two)

Options:

A.

posture assessment


B.

aaa authorization exec default local


C.

tacacs-server host 10.1.1.250 key password


D.

aaa server radius dynamic-author


E.

CoA


Expert Solution
Questions # 66:

What is the primary role of the Cisco Email Security Appliance?

Options:

A.

Mail Submission Agent


B.

Mail Transfer Agent


C.

Mail Delivery Agent


D.

Mail User Agent


Expert Solution
Questions # 67:

Which CLI command is used to enable URL filtering support for shortened URLs on the Cisco ESA?

Options:

A.

webadvancedconfig


B.

websecurity advancedconfig


C.

outbreakconfig


D.

websecurity config


Expert Solution
Questions # 68:

What is a required prerequisite to enable malware file scanning for the Secure Internet Gateway?

Options:

A.

Enable IP Layer enforcement.


B.

Activate the Advanced Malware Protection license


C.

Activate SSL decryption.


D.

Enable Intelligent Proxy.


Expert Solution
Questions # 69:

Using Cisco Firepower’s Security Intelligence policies, upon which two criteria is Firepower block based?

(Choose two)

Options:

A.

URLs


B.

protocol IDs


C.

IP addresses


D.

MAC addresses


E.

port numbers


Expert Solution
Questions # 70:

A security engineer is deploying an IPsec site-to-site VPN between headquarters and a remote plant, protected by Cisco Secure Firewall Threat Defense managed by Cisco Secure Firewall Management Center. The following configurations have already been completed:

    Matching IKEv2 proposals, preshared keys, and IPsec transform sets

    Access control rules permitting the traffic

    Crypto maps applied to the outside interfaces

    VPN traffic exempted from inspection

During a packet capture on the firewall, the engineer observes that the traffic is translated to the public IP address, preventing tunnel establishment. Which configuration action must be performed next?

Options:

A.

Configure NAT exemption for traffic between the interesting subnet pairs.


B.

Create a tunnel group with preshared-key authentication under connection profiles.


C.

Enable IKEv2 fragmentation on both peers to reduce packet size.


D.

Attach the new VPN policy to the global prefilter default action.


Expert Solution
Questions # 71:

An engineer is configuring Cisco WSA and needs to enable a separated email transfer flow from the Internet and from the LAN. Which deployment mode must be used to accomplish this goal?

Options:

A.

single interface


B.

multi-context


C.

transparent


D.

two-interface


Expert Solution
Questions # 72:

What must be enabled to secure SaaS-based applications?

Options:

A.

modular policy framework


B.

two-factor authentication


C.

application security gateway


D.

end-to-end encryption


Expert Solution
Questions # 73:

Refer to the exhibit.

aaa new-model

aaa authentication dot1x default group ISE-SERVERS

aaa authorization network default group ISE-SERVERS

aaa accounting dot1x default start-stop group ISE-SERVERS

!

radius server RADIUS_SRV

address ipv4 172.16.10.12 auth-port 1812 acct-port 1813

key shared-secret C1sc0123

!

aaa group server radius ISE-SERVERS

server name RADIUS_SRV

radius-server vsa send authentication

radius-server vsa send accounting

radius-server attribute 6 on-for-login-auth

radius-server attribute 8 include-in-access-req

radius-server attribute 25 access-request include

ip device tracking

!

interface range GigabitEthernet1/0/1 - 48

switchport

switchport host

authentication priority dot1x mab

authentication order dot1x mab

A security engineer is integrating a new Cisco Catalyst access switch with Cisco ISE to enforce port-based network access control using 802.1X. The AAA RADIUS server group and access interfaces are configured on the Cisco Catalyst switch. Cisco ISE has authentication and authorization policies, the workstation supplicants are configured as expected, and connectivity between the switch and ISE is working. During testing, the workstations fail to trigger authentication sessions, and no RADIUS requests appear in the ISE logs or on the switch interfaces. Which two configuration commands must be added to the Cisco Catalyst switch? (Choose two.)

Options:

A.

Configure the dot1x system-auth-control command globally.


B.

Implement the aaa server radius dynamic-author command globally.


C.

Apply the dot1x pae authenticator command under interfaces that require 802.1X.


D.

Configure the ip radius source-interface command globally.


E.

Add the mab command under all switch interfaces.


Expert Solution
Questions # 74:

Which two devices support WCCP for traffic redirection? (Choose two.)

Options:

A.

Cisco Secure Web Appliance


B.

Cisco IOS


C.

proxy server


D.

Cisco ASA


E.

Cisco IPS


Expert Solution
Questions # 75:

Which Cisco IOS XE command rejects packets with a source IP address that fails a reverse-path-forwarding prefix check on the ingress interface?

Options:

A.

ip verify unicast source reachable-via both


B.

ip verify unicast source reachable-via rx


C.

ip verify unicast source reachable-via tx


D.

ip verify unicast source reachable-via any


Expert Solution
Viewing page 5 out of 16 pages
Viewing questions 61-75 out of questions