Summer Certification Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the Cisco CCNP Security 350-701 Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam 350-701 Premium Access

View all detail and faqs for the 350-701 exam


764 Students Passed

88% Average Score

97% Same Questions
Viewing page 13 out of 15 pages
Viewing questions 181-195 out of questions
Questions # 181:

An engineer must deploy Cisco Secure Email with Cloud URL Analysis and must meet these requirements:

    To protect the network from large-scale virus outbreaks

    To protect the network from non-viral attacks such as phishing scams and malware distribution

    To provide active analysis of the structure of the URL and information about the domain and page contents

Which two prerequisites must the engineer ensure are configured? (Choose two.)

Options:

A.

Scanning enabled for each Verdict, Prepend Subject and Deliver.

B.

Outbreak Filters must be enabled globally.

C.

Enable TLS by setting to Preferred to the Default Domain.

D.

Service Logs must be enabled.

E.

Enable Rejected Connection Logging.

Questions # 182:

Which two capabilities of Integration APIs are utilized with Cisco Catalyst Center? (Choose two.)

Options:

A.

Create new SSIDs on a wireless LAN controller

B.

Connect to ITSM platforms

C.

Automatically deploy new virtual routers

D.

Upgrade software on switches and routers

E.

Third party reporting

Questions # 183:

What are two ways a network administrator transparently identifies users using Active Directory on the Cisco WSA? (Choose two.)

Options:

A.

Create an LDAP authentication realm and disable transparent user identification.

B.

Create NTLM or Kerberos authentication realm and enable transparent user identification.

C.

Deploy a separate Active Directory agent such as Cisco Context Directory Agent.

D.

The eDirectory client must be installed on each client workstation.

E.

Deploy a separate eDirectory server; the dent IP address is recorded in this server.

Questions # 184:

Which attack type attempts to shut down a machine or network so that users are not able to access it?

Options:

A.

smurf

B.

bluesnarfing

C.

MAC spoofing

D.

IP spoofing

Questions # 185:

Which two configurations must be made on Cisco ISE and on Cisco TrustSec devices to force a session to be adjusted after a policy change is made? (Choose two)

Options:

A.

posture assessment

B.

aaa authorization exec default local

C.

tacacs-server host 10.1.1.250 key password

D.

aaa server radius dynamic-author

E.

CoA

Questions # 186:

What is a benefit of conducting device compliance checks?

Options:

A.

It indicates what type of operating system is connecting to the network.

B.

It validates if anti-virus software is installed.

C.

It scans endpoints to determine if malicious activity is taking place.

D.

It detects email phishing attacks.

Questions # 187:

An organization wants to secure data in a cloud environment. Its security model requires that all users be

authenticated and authorized. Security configuration and posture must be continuously validated before access is granted or maintained to applications and data. There is also a need to allow certain application traffic and deny all other traffic by default. Which technology must be used to implement these requirements?

Options:

A.

Virtual routing and forwarding

B.

Microsegmentation

C.

Access control policy

D.

Virtual LAN

Questions # 188:

In which situation should an Endpoint Detection and Response solution be chosen versus an Endpoint Protection Platform?

Options:

A.

When there is a need to have more advanced detection capabilities

B.

When there is a need for traditional anti-malware detection

C.

When there is no need to have the solution centrally managed

D.

When there is no firewall on the network

Questions # 189:

Refer to the exhibit.

Question # 189

Traffic is not passing through IPsec site-to-site VPN on the Firepower Threat Defense appliance. What is causing this issue?

Options:

A.

No split-tunnel policy is defined on the Firepower Threat Defense appliance.

B.

The access control policy is not allowing VPN traffic in.

C.

Site-to-site VPN peers are using different encryption algorithms.

D.

Site-to-site VPN preshared keys are mismatched.

Questions # 190:

Which technology reduces data loss by identifying sensitive information stored in public computing

environments?

Options:

A.

Cisco SDA

B.

Cisco Firepower

C.

Cisco HyperFlex

D.

Cisco Cloudlock

Questions # 191:

Due to a traffic storm on the network, two interfaces were error-disabled, and both interfaces sent SNMP traps.

Which two actions must be taken to ensure that interfaces are put back into service? (Choose two)

Options:

A.

Have Cisco Prime Infrastructure issue an SNMP set command to re-enable the ports after the preconfigured interval.

B.

Use EEM to have the ports return to service automatically in less than 300 seconds.

C.

Enter the shutdown and no shutdown commands on the interfaces.

D.

Enable the snmp-server enable traps command and wait 300 seconds

E.

Ensure that interfaces are configured with the error-disable detection and recovery feature

Questions # 192:

An organization has noticed an increase in malicious content downloads and wants to use Cisco Umbrella to prevent this activity for suspicious domains while allowing normal web traffic. Which action will accomplish this task?

Options:

A.

Set content settings to High

B.

Configure the intelligent proxy.

C.

Use destination block lists.

D.

Configure application block lists.

Questions # 193:

Which VPN provides scalability for organizations with many remote sites?

Options:

A.

DMVPN

B.

site-to-site iPsec

C.

SSL VPN

D.

GRE over IPsec

Questions # 194:

What is the term for when an endpoint is associated to a provisioning WLAN that is shared with guest

access, and the same guest portal is used as the BYOD portal?

Options:

A.

single-SSID BYOD

B.

multichannel GUI

C.

dual-SSID BYOD

D.

streamlined access

Questions # 195:

A network administrator needs a solution to match traffic and allow or deny the traffic based on the type of application, not just the source or destination address and port used. Which kind of security product must the network administrator implement to meet this requirement?

Options:

A.

Next-generation Intrusion Prevention System

B.

Next-generation Firewall

C.

Web Application Firewall

D.

Intrusion Detection System

Viewing page 13 out of 15 pages
Viewing questions 181-195 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.