Pre-Winter Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Cisco CCNP Security 350-701 Questions and answers with CertsForce

Viewing page 7 out of 16 pages
Viewing questions 91-105 out of questions
Questions # 91:

What is a benefit of using Cisco Tetration?

Options:

A.

It collects telemetry data from servers and then uses software sensors to analyze flowinformation.


B.

It collects policy compliance data and process details.


C.

It collects enforcement data from servers and collects interpacket variation.


D.

It collects near-real time data from servers and inventories the software packages that exist onservers.


Expert Solution
Questions # 92:

Refer to the exhibit.

Question # 92

What will happen when the Python script is executed?

Options:

A.

The hostname will be translated to an IP address and printed.


B.

The hostname will be printed for the client in the client ID field.


C.

The script will pull all computer hostnames and print them.


D.

The script will translate the IP address to FODN and print it


Expert Solution
Questions # 93:

What is the primary benefit of deploying an ESA in hybrid mode?

Options:

A.

You can fine-tune its settings to provide the optimum balance between security and performance for your environment


B.

It provides the lowest total cost of ownership by reducing the need for physical appliances


C.

It provides maximum protection and control of outbound messages


D.

It provides email security while supporting the transition to the cloud


Expert Solution
Questions # 94:

A network engineer must distribute an operating system image to a network device and activate the image on that device by using the Cisco Catalyst Center API. Which two API requests perform the required operations? (Choose two.)

Options:

A.

POST /dna/intent/api/v1/image/distribution


B.

POST /dna/intent/api/v1/onboarding/pnp-device/import


C.

POST /dna/intent/api/v1/image/activation/device


D.

POST /dna/intent/api/v1/network/{site_id}


E.

POST /dna/intent/api/v1/template-programmer/project/{project_id}/template


Expert Solution
Questions # 95:

Refer to the exhibit. A network engineer must configure a Cisco router to send traps using SNMPv3. The engineer configures a remote user to receive traps and sets the security level to use authentication without privacy. Which command completes the configuration?

Options:

A.

snmp-server host 10.12.8.4 informs version 3 noauthno remoteuser config


B.

snmp-server host 10.12.8.4 informs version 3 noauthnoPriv remoteuser config


C.

snmp-server user TrapUser group2 remote 10.12.8.4 v3 auth md5 password1


D.

snmp-server user TrapUser group2 remote 10.12.8.4 v3 auth md5 password1 priv access des56


Expert Solution
Questions # 96:

An organization is selecting a cloud architecture and does not want to be responsible for patch management of the operating systems. Why should the organization select either Platform as a Service or Infrastructure as a Service for this environment?

Options:

A.

Platform as a Service because the customer manages the operating system


B.

Infrastructure as a Service because the customer manages the operating system


C.

Platform as a Service because the service provider manages the operating system


D.

Infrastructure as a Service because the service provider manages the operating system


Expert Solution
Questions # 97:

Where are individual sites specified to be blacklisted in Cisco Umbrella?

Options:

A.

application settings


B.

content categories


C.

security settings


D.

destination lists


Expert Solution
Questions # 98:

Drag and drop the security responsibilities from the left onto the corresponding cloud service models on the right.

Question # 98


Expert Solution
Questions # 99:

Question # 99

Refer to the exhibit. Which task is the Python script performing by using the Cisco Umbrella API?

Options:

A.

Creating a list of the latest security events


B.

Copying a list of the latest security activity


C.

Retrieving a list of the latest security events


D.

Sending a list of the latest security activity


Expert Solution
Questions # 100:

Drag and drop the exploits from the left onto the type of security vulnerability on the right.

Question # 100


Expert Solution
Questions # 101:

In which scenario is endpoint-based security the solution?

Options:

A.

inspecting encrypted traffic


B.

device profiling and authorization


C.

performing signature-based application control


D.

inspecting a password-protected archive


Expert Solution
Questions # 102:

An engineer is configuring Cisco Secure Endpoint to enhance security by preventing the execution of certain files by users. The engineer needs to ensure that the specific executable file name Cisco_Software_0505446151.exe is blocked from running while never being quarantined. What must the engineer configure to meet the requirement?

Options:

A.

Create advanced custom detection list.


B.

Configure application control blocked applications list.


C.

Implement simple custom detection list.


D.

Enable scheduled scans to detect and block the executable files.


Expert Solution
Questions # 103:

What is a key feature of the Bring Your Own Device (BYOD) capability in Cisco ISE?

Options:

A.

Provide temporary Internet access for the personal devices of guest users.


B.

Assess the security posture of personal devices before network access is allowed.


C.

Fully manage network devices based on their characteristics before access is allowed.


D.

Encrypt endpoint data according to predefined security policies.


Expert Solution
Questions # 104:

Which capability allows an administrator to configure forensics rules in Cisco Secure Workload?

Options:

A.

Custom clauses


B.

MITRE ATT & CK framework only predefined


C.

Cisco Secure Workload predefined


D.

Windows or Linux application


Expert Solution
Questions # 105:

Why is it important to implement MFA inside of an organization?

Options:

A.

To prevent man-the-middle attacks from being successful.


B.

To prevent DoS attacks from being successful.


C.

To prevent brute force attacks from being successful.


D.

To prevent phishing attacks from being successful.


Expert Solution
Viewing page 7 out of 16 pages
Viewing questions 91-105 out of questions