Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free Cisco Implementing and Operating Cisco Security Core Technologies 350-701 Exam Questions

Page: 1 / 54 Total 802 questions

Want more questions? Get Premium Access.

Question 1

[Network Security]

Refer to the exhibit,

which command results in these messages when attempting to troubleshoot an iPsec VPN connection?

Correct Answer: A. debug crypto isakmp
Explanation:

The command that results in these messages when attempting to troubleshoot an iPsec VPN connection isdebug crypto isakmp. This command displays debug information about the Internet Key Exchange (IKE) protocol, which is used to establish security associations (SAs) for IPsec VPNs. The messages in the exhibit show various steps and statuses of the IKE negotiation process, such as creating and deleting peer structures, receiving and sending packets, and checking the compatibility of the security policies and proposals.The other commands are either invalid (debug crypto ipsec endpointanddebug crypto isakmp connection) or display different information (debug crypto ipsecshows the details of the IPsec encryption and decryption operations).Reference:

https://www.cisco.com/c/en/us/training-events/training-certifications/training/training-services/courses/implementing-and-operating-cisco-security-core-technologies-scor.html

https://www.cisco.com/c/en/us/support/docs/security-vpn/ipsec-negotiation-ike-protocols/5409-ipsec-debug-00.html


Question 2

[Security Concepts]

Which Cisco security solution gives the most complete view of the relationships and evolution of Internet domains IPs, and flies, and helps to pinpoint attackers' infrastructures and predict future threat?

Correct Answer: C. Cisco Umbrella Investigate
Explanation:

Cisco Umbrella Investigate is a cloud-based service that provides interactive threat intelligence on domains, IPs, and files. It helps security analysts to uncover the attacker's infrastructure and predict future threats by analyzing the relationships and evolution of internet domains, IPs, and files. It also integrates with other Cisco security solutions, such as Cisco Secure Network Analytics, Cisco Secure Cloud Analytics, and Cisco pxGrid, to provide a holistic view of the network and cloud security posture. Cisco Umbrella Investigate is based on the data collected by Cisco Umbrella, which processes more than 620 billion DNS requests per day from over 190 countries. Cisco Umbrella Investigate uses statistical and machine learning models to automatically score and classify the data, and provides a risk score for each domain, IP, and file, along with the contributing factors and historical context. Cisco Umbrella Investigate also allows security analysts to query the data using a web-based console or an API, and to visualize the results using graphs, tables, and maps. Cisco Umbrella Investigate is the most complete and interactive threat intelligence solution that helps to prevent cyber attacks before they happen.Reference:=

Some possible references are:

Cisco Umbrella Investigate

Cyber Attack Prevention - Cisco Umbrella

Cisco Umbrella Investigate - Cisco Umbrella


Question 3

[Secure Network Access, Visibility, and Enforcement]

Which IETF attribute is supported for the RADIUS CoA feature?

Correct Answer: A. 24 State
Explanation:

The RADIUS CoA feature supports the IETF attribute 24 State, which is used to identify the session for which the CoA request is intended. The State attribute is sent by the device in the Access-Accept message and must be echoed back by the RADIUS server in the CoA-Request message. The other attributes are not supported for the RADIUS CoA feature.

To understand the concept of RADIUS CoA and the supported attributes, you can refer to the following sections of the source book:

Section 1.1.2: Describe the concepts of network security

Section 1.1.2.6: Describe the concepts of RADIUS CoA

Section 1.1.2.7: Describe the concepts of supported IETF attributes


Implementing and Operating Cisco Security Core Technologies (SCOR) v1.0

RADIUS Change of Authorization - Cisco

RADIUS attribute for change of authorization - Ruckus Networks

Question 4

[Network Security]

Refer to the exhibit.

When configuring a remote access VPN solution terminating on the Cisco ASA, an administrator would like to utilize an external token authentication mechanism in conjunction with AAA authentication using machine

certificates. Which configuration item must be modified to allow this?

Correct Answer: B. Method
Explanation:

In order to use AAA along with an external token authentication mechanism, set the ''Method'' as ''Both'' in

the Authentication.


Question 5

[Endpoint Protection and Detection]

A network administrator is configuring a switch to use Cisco ISE for 802.1X. An endpoint is failing

authentication and is unable to access the network. Where should the administrator begin troubleshooting to verify the authentication details?

Correct Answer: D. RADIUS Live Logs
Explanation:

How To Troubleshoot ISE Failed Authentications & Authorizations

Check the ISE Live Logs

Login to the primary ISE Policy Administration Node (PAN).

Go to Operations > RADIUS > Live Logs

(Optional) If the event is not present in the RADIUS Live Logs, go to Operations > Reports > Reports >

Endpoints and Users > RADIUS Authentications

Check for Any Failed Authentication Attempts in the Log


Question 6

[Security Concepts]

How does Cisco Workload Optimization portion of the network do EPP solutions solely performance issues?

Correct Answer: B. It automates resource resizing
Explanation:

Cisco Workload Optimization Manager (CWOM) is a decision-automation engine that provides workloads with the exact resources they need at the right time in accordance with business policies, freeing IT teams to focus on innovation rather than the maintenance of their IT environment1.CWOM is part of the Cisco SecureX platform, which integrates various security solutions, including endpoint protection platforms (EPPs), to provide a unified and simplified security experience2. CWOM does not deploy an AWS Lambda system, optimize a flow path, or set up a workload forensic score. These are not related to CWOM's functionality or EPP solutions.CWOM automates resource resizing, which means it can dynamically adjust the CPU, memory, disk, and network resources allocated to each workload based on real-time demand and performance metrics1.This helps EPP solutions to solely address performance issues by ensuring that workloads have the optimal resources to run efficiently and securely, without overprovisioning or underutilizing resources3.Reference:1:Cisco Workload Optimization Manager (CWOM) - Cisco,2:Endpoint Protection Platform (EPP) Definition - Cisco,3:Cisco Intersight Workload Optimizer Data Sheet


Question 7

[Security Concepts]

Which method of attack is used by a hacker to send malicious code through a web application to an unsuspecting user to request that the victim's web browser executes the code?

Correct Answer: D. cross-site scripting
Explanation:

Cross-site scripting (XSS) is the method of attack that is used by a hacker to send malicious code through a web application to an unsuspecting user to request that the victim's web browser executes the code. XSS is a type of injection attack that exploits the lack of input validation or output encoding in a web application. An attacker can craft a malicious script and embed it in a web page or a URL that is sent to the user. When the user visits the web page or clicks the URL, the script is executed by the user's browser, which may not be able to distinguish it from legitimate code.The script can then perform various actions, such as stealing cookies, session tokens, or other sensitive information, redirecting the user to a malicious site, or performing actions on behalf of the user12. The other options are not correct, because they are not methods of attack that use web applications to execute malicious code on the user's browser.Buffer overflow is a type of attack that exploits a memory vulnerability in a program or system, where an attacker can overwrite the memory beyond the allocated buffer and execute arbitrary code3.Browser WGET is a command-line tool that can be used to download files from the web, but it is not an attack method by itself4.SQL injection is a type of attack that exploits a database vulnerability in a web application, where an attacker can inject malicious SQL statements into a user input field and execute them on the database server5.Reference:

1: What is Cross-Site Scripting (XSS)? - Cisco

2: Cross-Site Scripting (XSS) - OWASP

3: What is a Buffer Overflow? - Cisco

4: GNU Wget 1.21.1 Manual

5: What is SQL Injection (SQLi)? - Cisco


Question 8

[Secure Network Access, Visibility, and Enforcement]

In which two ways does Easy Connect help control network access when used with Cisco TrustSec? (Choose two)

Correct Answer: C. It allows for the assignment of Security Group Tags and does not require 802.1x to be configured on the switch or the endpoint.; E. It allows for managed endpoints that authenticate to AD to be mapped to Security Groups (PassiveID).
Explanation:

Easy Connect simplifies network access control and segmentation by allowing the assignment of Security

Group Tags to endpoints without requiring 802.1X on those endpoints, whether using wired or wireless

connectivity.


Question 9

[Security Concepts]

Which technology provides the benefit of Layer 3 through Layer 7 innovative deep packet inspection,

enabling the platform to identify and output various applications within the network traffic flows?

Correct Answer: A. Cisco NBAR2
Explanation:

Cisco NBAR2 is a classification engine that recognizes and classifies a wide variety of protocols and applications based on their deep packet inspection (DPI) signatures. NBAR2 enables the platform to identify and output various applications within the network traffic flows, such as web, email, voice, video, and so on. NBAR2 also supports custom protocols and applications, allowing the platform to classify traffic based on user-defined criteria. NBAR2 helps the platform to apply the appropriate quality of service (QoS), security, and policy for each application or protocol.Reference:=

Some possible references are:

Cisco NBAR2

Classifying Network Traffic Using NBAR

Next Generation NBAR (NBAR2)


Question 10

[Network Security]

Which feature of Cisco ASA allows VPN users to be postured against Cisco ISE without requiring an inline

posture node?

Correct Answer: A. RADIUS Change of Authorization
Explanation:

RADIUS Change of Authorization (CoA) is a feature of Cisco ASA that allows VPN users to be postured against Cisco ISE without requiring an inline posture node. RADIUS CoA enables the ISE to send a message to the ASA to change the authorization attributes of an existing VPN session, such as the assigned IP address, ACL, or group policy.This way, the ISE can dynamically adjust the access level of the VPN user based on the posture assessment results, without the need for an intermediate device to enforce the policy change12.RADIUS CoA is supported by the ASA since version 9.2.13.Reference:1:ASA Version 9.2.1 VPN Posture with ISE Configuration Example - Cisco2:How To: ISE and ASA Integration using CoA for Posture - Cisco Community3:How To Configure Posture with AnyConnect Compliance ... - Cisco Community


Question 11

[Securing the Cloud]

An engineer is trying to decide whether to use Cisco Umbrella, Cisco CloudLock, Cisco Stealthwatch, or Cisco AppDynamics Cloud Monitoring for visibility into data transfers as well as protection against data exfiltration Which solution best meets these requirements?

Correct Answer: A. Cisco CloudLock
Explanation:

Cisco CloudLock is a cloud-native cloud access security broker (CASB) that helps you move to the cloud safely. It protects your cloud users, data, and apps. CloudLock's simple, open, and automated approach uses APIs to manage the risks in your cloud app ecosystem.With CloudLock you can more easily combat data breaches while meeting compliance regulations1.

Cisco CloudLock provides the following features that meet the requirements of visibility into data transfers as well as protection against data exfiltration:

User security: Cloudlock uses advanced machine learning algorithms to detect anomalies based on multiple factors.It also identifies activities outside allowed countries and spots actions that seem to take place at impossible speeds across distances1.

Data security: Cloudlock's data loss prevention (DLP) technology continuously monitors cloud environments to detect and secure sensitive information. It provides countless out-of-the-box policies as well as highly tunable custom policies.It also supports inline and out-of-band data inspection and blocking capabilities to protect sensitive data12.

App security: The Cloudlock Apps Firewall discovers and controls cloud apps connected to your corporate environment.You can see a crowd-sourced Community Trust Rating for individual apps, and you can ban or allowlist them based on risk1.

The other solutions do not provide the same level of visibility and protection as Cisco CloudLock:

Cisco Umbrella is a cloud-delivered network security service that provides DNS-layer security, secure web gateway, cloud-delivered firewall, cloud access security broker, and threat intelligence3.It does not offer data security features such as DLP, data inspection, and data blocking4.

Cisco AppDynamics Cloud Monitoring is a cloud-native application performance management solution that helps you monitor, troubleshoot, and optimize your cloud applications. It does not offer user security, data security, or app security features as a CASB solution.

Cisco Stealthwatch is a network traffic analysis solution that provides visibility and threat detection across your network, endpoints, and cloud. It does not offer data security features such as DLP, data inspection, and data blocking.

:3: Cisco Umbrella Packages - Cisco Umbrella1: Cisco Cloudlock - Cisco2: Cisco Cloudlock Cisco Cloudlock: Secure Cloud Data4: Easy to Deploy & Simple to Manage CASB Solution - Cisco Umbrella : Cisco AppDynamics Cloud Monitoring : Cisco Stealthwatch - Cisco


Question 12

[Security Concepts]

Which solution is made from a collection of secure development practices and guidelines that developers must follow to build secure applications?

Correct Answer: D. OWASP
Explanation:

OWASP stands forOpen Web Application Security Project, a non-profit organization that provides resources for web application security.OWASP has developed a number of standards, projects, events, and news on topics such as web application security, supply chain security, and cyber risk mitigation1. One of the most widely recognized OWASP resources is theOWASP Top 10, a standard awareness document for developers and web application security.It represents a broad consensus about the most critical security risks to web applications, such as broken access control, cryptographic failures, injection, and insecure design2. The OWASP Top 10 is updated periodically based on data analysis and community feedback.The latest edition was released in 20213.By following the OWASP Top 10 and other OWASP resources, developers can build more secure applications that minimize these risks.Reference:=1: OWASP Foundation, the Open Source Foundation for Application Security2: OWASP Top Ten | OWASP Foundation3: OWASP Top 10:2021


Question 13

[Network Security]

A small organization needs to reduce the VPN bandwidth load on their headend Cisco ASA in order to

ensure that bandwidth is available for VPN users needing access to corporate resources on the10.0.0.0/24 local HQ network. How is this accomplished without adding additional devices to the

network?

Correct Answer: A. Use split tunneling to tunnel traffic for the 10.0.0.0/24 network only.
Explanation:

Split tunneling is a feature that allows VPN users to access both the corporate network and the internet at the same time. By using split tunneling, only the traffic destined for the 10.0.0.0/24 network will be encrypted and sent through the VPN tunnel, while the rest of the traffic will be sent directly to the internet. This reduces the VPN bandwidth load on the headend Cisco ASA and ensures that bandwidth is available for VPN users needing access to corporate resources. Split tunneling can be configured on the ASA by using the split-tunnel-network-list value command under the group-policy attributes. The network list should include the 10.0.0.0/24 network as the only entry.Reference:Implementing and Operating Cisco Security Core Technologies (SCOR) v1.0, Module 5: Secure Connectivity, Lesson 5.1: Implementing Site-to-Site VPNs on Cisco Routers and ASA Firewalls, Topic 5.1.3: Configuring Site-to-Site VPNs on Cisco ASA Firewalls, Subtopic 5.1.3.2: Configuring Split Tunneling.


Question 14

[Endpoint Protection and Detection]

Refer to the exhibit. What function does the API key perform while working with https://api.amp.cisco.com/v1/computers?

Correct Answer: C. HTTP authentication
Explanation:

The API key is a secret token that is used to authenticate the client to the server. It is functionally equivalent to a username and password, and should be treated as such. The API key is passed as part of the HTTP header in the request, using theAuthorization: Basicscheme. The API key is combined with the client ID and encoded in base64 format. For example, if the client ID isd16aff14860af496e848and the API key isd01ed435-b00d-4a4d-a299-1806ac117e72, the HTTP header would look like this:

Authorization: Basic ZDE2YWZmMTQ4NjBhZjQ5NmU4NDg6ZDAxZWQ0MzUtYjAwZC00YTRkLWEyOTktMTgwNmFjMTE3ZTcy

The server then decodes the header and verifies the credentials. If the credentials are valid, the server grants access to the requested resource. If the credentials are invalid, the server returns an HTTP 401 Unauthorized error.

The API key performs the function of HTTP authentication, which is the process of verifying the identity of the client. HTTP authentication is different from HTTP authorization, which is the process of determining the permissions of the client. HTTP authorization is based on the scope of the API credential, which can be either read-only or read & write. The scope determines what actions the client can perform on the Cisco AMP for Endpoints data.

Importing requests is not a function of the API key, but rather a Python module that allows sending HTTP requests. Playing dent ID is not a meaningful term in this context. Therefore, the correct answer is C.Reference:

Secure Endpoint API - Cisco DevNet

Overview of the Cisco AMP for Endpoints API - Cisco

Configure AMP for Endpoints Event Stream Feature - Cisco


Question 15

[Security Concepts]

Which type of encryption uses a public key and private key?

Correct Answer: A. Asymmetric
Explanation:

Asymmetric encryption, also known as public key cryptography, uses two different keys for encryption and decryption: a public key and a private key. The public key can be shared with anyone, while the private key must be kept secret. Data encrypted with the public key can only be decrypted with the private key, and vice versa. This ensures that only the intended recipient can access the encrypted data, and that the sender can prove their identity with a digital signature. Asymmetric encryption is widely used for securing Internet communications, such as TLS/SSL, which enables HTTPS. Some examples of asymmetric encryption algorithms are RSA, Diffie-Hellman, and Elliptic Curve Cryptography. The other options are not correct because they do not use a public key and private key. Symmetric encryption uses the same key for encryption and decryption, and is faster and more efficient than asymmetric encryption. However, symmetric encryption requires a secure way to exchange the key between the sender and the receiver, which can be facilitated by asymmetric encryption. Linear and nonlinear encryption are not types of encryption, but rather properties of encryption algorithms. A linear encryption algorithm is one that can be expressed as a linear function, such as XOR. A nonlinear encryption algorithm is one that involves more complex mathematical operations, such as modular arithmetic or S-boxes. Nonlinear encryption algorithms are generally more secure and resistant to cryptanalysis than linear encryption algorithms.Reference:=

Public-key cryptography - Wikipedia

How does public key cryptography work? - Cloudflare

Public and private encryption keys | PreVeil

AES encryption, what are public and private keys?