Pass the Cisco CCNP Security 350-701 Questions and answers with CertsForce

Viewing page 6 out of 15 pages
Viewing questions 76-90 out of questions
Questions # 76:

A small organization needs to reduce the VPN bandwidth load on their headend Cisco ASA in order to

ensure that bandwidth is available for VPN users needing access to corporate resources on the10.0.0.0/24 local HQ network. How is this accomplished without adding additional devices to the

network?

Options:

A.

Use split tunneling to tunnel traffic for the 10.0.0.0/24 network only.


B.

Configure VPN load balancing to distribute traffic for the 10.0.0.0/24 network,


C.

Configure VPN load balancing to send non-corporate traffic straight to the internet.


D.

Use split tunneling to tunnel all traffic except for the 10.0.0.0/24 network.


Expert Solution
Questions # 77:

What is a characteristic of traffic storm control behavior?

Options:

A.

Traffic storm control drops all broadcast and multicast traffic if the combined traffic exceeds the level withinthe interval.


B.

Traffic storm control cannot determine if the packet is unicast or broadcast.


C.

Traffic storm control monitors incoming traffic levels over a 10-second traffic storm control interval.


D.

Traffic storm control uses the Individual/Group bit in the packet source address to determine if the packet isunicast or broadcast.


Expert Solution
Questions # 78:

What is a key difference between Cisco Firepower and Cisco ASA?

Options:

A.

Cisco ASA provides access control while Cisco Firepower does not.


B.

Cisco Firepower provides identity-based access control while Cisco ASA does not.


C.

Cisco Firepower natively provides intrusion prevention capabilities while Cisco ASA does not.


D.

Cisco ASA provides SSL inspection while Cisco Firepower does not.


Expert Solution
Questions # 79:

When planning a VPN deployment, for which reason does an engineer opt for an active/active FlexVPN

configuration as opposed to DMVPN?

Options:

A.

Multiple routers or VRFs are required.


B.

Traffic is distributed statically by default.


C.

Floating static routes are required.


D.

HSRP is used for faliover.


Expert Solution
Questions # 80:

Which feature requires that network telemetry be enabled?

Options:

A.

per-interface stats


B.

SNMP trap notification


C.

Layer 2 device discovery


D.

central syslog system


Expert Solution
Questions # 81:

What is the most commonly used protocol for network telemetry?

Options:

A.

SMTP


B.

SNMP


C.

TFTP


D.

NctFlow


Expert Solution
Questions # 82:

What is the target in a phishing attack?

Options:

A.

perimeter firewall


B.

IPS


C.

web server


D.

endpoint


Expert Solution
Questions # 83:

What is a feature of an endpoint detection and response solution?

Options:

A.

Preventing attacks by identifying harmful events with machine learning and conduct-based defense


B.

Rapidly and consistently observing and examining data to mitigate threats


C.

Capturing and clarifying data on email, endpoints, and servers to mitigate threats


D.

Ensuring the security of network devices by choosing which devices are allowed to reach the network


Expert Solution
Questions # 84:

Refer to the exhibit.

Question # 84

What does the number 15 represent in this configuration?

Options:

A.

privilege level for an authorized user to this router


B.

access list that identifies the SNMP devices that can access the router


C.

interval in seconds between SNMPv3 authentication attempts


D.

number of possible failed attempts until the SNMPv3 user is locked out


Expert Solution
Questions # 85:

Which parameter is required when configuring a Netflow exporter on a Cisco Router?

Options:

A.

DSCP value


B.

Source interface


C.

Exporter name


D.

Exporter description


Expert Solution
Questions # 86:

Which API is used for Content Security?

Options:

A.

NX-OS API


B.

IOS XR API


C.

OpenVuln API


D.

AsyncOS API


Expert Solution
Questions # 87:

An organization uses Cisco FMC to centrally manage multiple Cisco FTD devices The default management port conflicts with other communications on the network and must be changed What must be done to ensure that all devices can communicate together?

Options:

A.

Set the sftunnel to go through the Cisco FTD


B.

Change the management port on Cisco FMC so that it pushes the change to all managed Cisco FTD devices


C.

Set the sftunnel port to 8305.


D.

Manually change the management port on Cisco FMC and all managed Cisco FTD devices


Expert Solution
Questions # 88:

Drag and drop the common security threats from the left onto the definitions on the right.

Question # 88


Expert Solution
Questions # 89:

Refer to the exhibit.

Question # 89

Traffic is not passing through IPsec site-to-site VPN on the Firepower Threat Defense appliance. What is causing this issue?

Options:

A.

No split-tunnel policy is defined on the Firepower Threat Defense appliance.


B.

The access control policy is not allowing VPN traffic in.


C.

Site-to-site VPN peers are using different encryption algorithms.


D.

Site-to-site VPN preshared keys are mismatched.


Expert Solution
Questions # 90:

An engineer is configuring guest WLAN access using Cisco ISE and the Cisco WLC. Which action temporarily gives guest endpoints access dynamically while maintaining visibility into who or what is connecting?

Options:

A.

Modify the WLC configuration to require local WLC logins for the authentication prompts.


B.

Configure ISE and the WLC for guest redirection and services using a self-registered portal.


C.

Configure ISE and the WLC for guest redirection and services using a hotspot portal.


D.

Modify the WLC configuration to allow any endpoint to access an internet-only VLAN.


Expert Solution
Viewing page 6 out of 15 pages
Viewing questions 76-90 out of questions