Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free Cisco Designing and Implementing Secure Cloud Access for Users and Endpoints 300-740 Exam Questions

Page: 1 / 7 Total 61 questions

Want more questions? Get Premium Access.

Question 1

Refer to the exhibit.

Refer to the exhibit. An engineer must configure a global allow list in Cisco Umbrella for the cisco.com domain. All other domains must be blocked. After creating a new policy and adding the cisco.com domain, the engineer attempts to access a site outside of cisco.com and is successful. Which additional Security Settings action must be taken to meet the requirement?

Correct Answer: C. Enable Allow-Only Mode

Question 2

What does the MITRE ATT&CK framework catalog?

Correct Answer: A. Techniques utilized in cyber attacks

Question 3

An administrator must deploy an endpoint posture policy for all users. The organization wants to have all endpoints checked against antimalware definitions and operating system updates and ensure that the correct Secure Client modules are installed properly. How must the administrator meet the requirements?

Correct Answer: C. Create the required posture policy within Cisco ISE, configure redirection on the NAD, and ensure that the client provisioning policy is correct.

Question 4

How does Cisco XDR perform threat prioritization by using its visibility across multiple platforms?

Correct Answer: B. By correlating detection risk and asset value at risk

Question 5

Refer to the exhibit.

Refer to the exhibit. An engineer must implement a remote access VPN solution that provides user and device verification. The company uses Active Directory for user authentication and ID certificates for device identity. Users are currently able to connect using only a valid username and password, even if their computer is missing the required certificate.

Which command from the Cisco ASA tunnel-group completes the requirement of verifying device identity in addition to user identity?

Correct Answer: B. webvpn authorize-device

Question 6

Refer to the exhibit.

Refer to the exhibit. An engineer is analyzing a Cisco Secure Firewall Management Center report. Which activity does the output verify?

Correct Answer: D. A DNS response from IP address 10.1.108.100 was blocked.

Question 7

Which types of algorithm does a web application firewall use for zero-day DDoS protection?

Correct Answer: D. Adaptive and behavioral-based
Explanation:

Comprehensive and Detailed Explanation From Exact Extract:

According to the SCAZT documentation, web application firewalls (WAFs) designed to protect against zero-day Distributed Denial of Service (DDoS) attacks leverage adaptive and behavioral-based algorithms. These algorithms dynamically analyze traffic patterns, baseline normal behavior, and detect anomalies that could indicate novel or zero-day attacks. Unlike signature-based detection, adaptive and behavioral methods adjust in real-time to emerging threats, learning from ongoing traffic without relying on pre-defined rules. This proactive approach enables rapid detection and mitigation of unknown DDoS vectors, critical for cloud and network security where threats evolve constantly.


Question 8

Refer to the exhibit.

Refer to the exhibit. An engineer must provide RDP access to the AWS virtual machines and HTTPS access to the Google Cloud Platform virtual machines. All other connectivity must be blocked. The indicated rules were applied to the firewall; however, none of the virtual machines in AWS and Google Cloud Platform are accessible. What should be done to meet the requirement?

Correct Answer: A. Move rule 2 to the first position.

Question 9

Which concept is used in the Cisco SAFE key reference model?

Correct Answer: A. Secure Domains

Question 10

An organization is distributed across several sites. Each site is connected to the main HQ using site-to-site VPNs implemented using Secure Firewall Threat Defense. Which functionality must be implemented if the security manager wants to send SaaS traffic directly to the internet?

Correct Answer: C. Policy-based routing