Pre-Winter Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Cisco CCNP Security 350-701 Questions and answers with CertsForce

Viewing page 6 out of 16 pages
Viewing questions 76-90 out of questions
Questions # 76:

Refer to the exhibit.

Question # 76

How does Cisco Umbrella manage traffic that is directed toward risky domains?

Options:

A.

Traffic is proximed through the intelligent proxy.


B.

Traffic is managed by the security settings and blocked.


C.

Traffic is managed by the application settings, unhandled and allowed.


D.

Traffic is allowed but logged.


Expert Solution
Questions # 77:

How does Cisco Stealthwatch Cloud provide security for cloud environments?

Options:

A.

It delivers visibility and threat detection.


B.

It prevents exfiltration of sensitive data.


C.

It assigns Internet-based DNS protection for clients and servers.


D.

It facilitates secure connectivity between public and private networks.


Expert Solution
Questions # 78:

Question # 78

Refer to the exhibit. A network engineer must retrieve the interface configuration on a Cisco router by using the NETCONF API. The engineer uses a python script to automate the activity.

Which code snippet completes the script?

Options:

A.

Content-Type: application/vnd.yang.data+json


B.

Content-Type: application/vnd.yang.data


C.

Content-Type: application/vnd.yang.data+api


D.

Content-Type: applications/json/vnd.yang.data


Expert Solution
Questions # 79:

Cisco SensorBase gaihers threat information from a variety of Cisco products and services and performs analytics to find patterns on threats Which term describes this process?

Options:

A.

deployment


B.

consumption


C.

authoring


D.

sharing


Expert Solution
Questions # 80:

Which product allows Cisco FMC to push security intelligence observable to its sensors from other products?

Options:

A.

Encrypted Traffic Analytics


B.

Threat Intelligence Director


C.

Cognitive Threat Analytics


D.

Cisco Talos Intelligence


Expert Solution
Questions # 81:

What does endpoint isolation in Cisco AMP for Endpoints security protect from?

Options:

A.

an infection spreading across the network E


B.

a malware spreading across the user device


C.

an infection spreading across the LDAP or Active Directory domain from a user account


D.

a malware spreading across the LDAP or Active Directory domain from a user account


Expert Solution
Questions # 82:

Which process is used to obtain a certificate from a CA?

Options:

A.

Registration


B.

Enrollment


C.

Signing


D.

Approval


Expert Solution
Questions # 83:

An engineer has enabled LDAP accept queries on a listener. Malicious actors must be prevented from quickly

identifying all valid recipients. What must be done on the Cisco ESA to accomplish this goal?

Options:

A.

Configure incoming content filters


B.

Use Bounce Verification


C.

Configure Directory Harvest Attack Prevention


D.

Bypass LDAP access queries in the recipient access table


Expert Solution
Questions # 84:

An engineer is deploying a Cisco Secure Email Gateway and must configure a sender group that decides which mail policy will process the mail. The configuration must accept incoming mails and relay the outgoing mails from the internal server. Which component must be configured to accept the connection to the listener and meet these requirements on a Cisco Secure Email Gateway?

Options:

A.

RAT


B.

HAT


C.

Sender list


D.

Access list


Expert Solution
Questions # 85:

Which attack type attempts to shut down a machine or network so that users are not able to access it?

Options:

A.

smurf


B.

bluesnarfing


C.

MAC spoofing


D.

IP spoofing


Expert Solution
Questions # 86:

A network security engineer must export packet captures from the Cisco FMC web browser while troubleshooting an issue. When navigating to the address https:// < FMC IP > /capure/CAPI/pcap/test.pcap, an error 403: Forbidden is given instead of the PCAP file. Which action must the engineer take to resolve this issue?

Options:

A.

Disable the proxy setting on the browser


B.

Disable the HTTPS server and use HTTP instead


C.

Use the Cisco FTD IP address as the proxy server setting on the browser


D.

Enable the HTTPS server for the device platform policy


Expert Solution
Questions # 87:

An organization has noticed an increase in malicious content downloads and wants to use Cisco Umbrella to prevent this activity for suspicious domains while allowing normal web traffic. Which action will accomplish this task?

Options:

A.

Set content settings to High


B.

Configure the intelligent proxy.


C.

Use destination block lists.


D.

Configure application block lists.


Expert Solution
Questions # 88:

Based on the NIST 800-145 guide, which cloud architecture is provisioned for exclusive use by a specific group of consumers from different organizations and may be owned, managed, and operated by one or more of those organizations?

Options:

A.

hybrid cloud


B.

private cloud


C.

community cloud


D.

public cloud


Expert Solution
Questions # 89:

How is a cross-site scripting attack executed?

Options:

A.

Force a currently authenticated end user to execute unwanted actions on a web app


B.

Execute malicious client-side scripts injected to a client via a web app


C.

Inject a database query via the input data from the client to a web app


D.

Intercept communications between a client and a web server


Expert Solution
Questions # 90:

Which two application layer preprocessors are used by Firepower Next Generation Intrusion Prevention

System? (Choose two)

Options:

A.

packet decoder


B.

SIP


C.

modbus


D.

inline normalization


E.

SSL


Expert Solution
Viewing page 6 out of 16 pages
Viewing questions 76-90 out of questions