[Sep-2021] Pass 350-701 Exam in First Attempt Updated350-701 Real4Prep Exam Question
CCNP Security Dumps 350-701 Exam for Full Questions - Exam Study Guide
NEW QUESTION 24
What are two list types within AMP for Endpoints Outbreak Control? (Choose two.)
- A. URL
- B. simple custom detections
- C. command and control
- D. allowed applications
- E. blocked ports
Answer: B,D
Explanation:
Explanation/Reference: https://docs.amp.cisco.com/en/A4E/AMP%20for%20Endpoints%20User%20Guide.pdf chapter 2
NEW QUESTION 25
Drag and drop the descriptions from the left onto the encryption algorithms on the right.
Answer:
Explanation:
Explanation
NEW QUESTION 26
.
Refer to the exhibit What will happen when the Python script is executed?
- A. The hostname will be printed for the client in the client ID field.
- B. The script will translate the IP address to FODN and print it
- C. The script will pull all computer hostnames and print them.
- D. The hostname will be translated to an IP address and printed.
Answer: C
NEW QUESTION 27
Drag and drop the suspicious patterns for the Cisco Tetration platform from the left onto the correct definitions on the right.
Answer:
Explanation:
Explanation

https://www.cisco.com/c/en/us/products/collateral/data-center-analytics/tetration-analytics/white-paper-c11-7403
NEW QUESTION 28
What features does Cisco FTDv provide over ASAv?
- A. Cisco FTDv runs on VMWare while Cisco ASAv does not.
- B. Cisco FTDv supports URL filtering while ASAV does not.
- C. Cisco FTDv runs on AWS while Cisco ASAV does not.
- D. Cisco FTDv provides IGB of firewall throughput while Cisco ASAv does not.
Answer: B
NEW QUESTION 29
DRAG DROP
Drag and drop the steps from the left into the correct order on the right to enable AppDynamics to monitor an EC2 instance in Amazon Web Services.
Select and Place:
Answer:
Explanation:
NEW QUESTION 30
An organization has a Cisco Stealthwatch Cloud deployment in their environment. Cloud logging is working as expected, but logs are not being received from the on-premise network, what action will resolve this issue?
- A. Configure security appliances to send NetFlow to Cisco Stealthwatch Cloud
- B. Configure security appliances to send syslogs to Cisco Stealthwatch Cloud
- C. Deploy a Cisco Stealthwatch Cloud sensor on the network to send data to Cisco Stealthwatch Cloud You can also monitor on-premises networks in your organizations using Cisco Stealthwatch Cloud. In order to do so, you need to deploy at least one Cisco Stealthwatch Cloud Sensor appliance (virtual or physical appliance).
- D. Deploy a Cisco FTD sensor to send events to Cisco Stealthwatch Cloud
Answer: C
NEW QUESTION 31
Which protocol provides the strongest throughput performance when using Cisco AnyConnect VPN?
- A. BJTLSvl
- B. DTLSv1
- C. TLSv1.2
- D. TLSv1.1
Answer: B
NEW QUESTION 32
Which option is the main function of Cisco Firepower impact flags?
- A. They correlate data about intrusions and vulnerability.
- B. They alert administrators when critical events occur.
- C. They highlight known and suspected malicious IP addresses in reports.
- D. They identify data that the ASA sends to the Firepower module.
Answer: A
NEW QUESTION 33
When planning a VPN deployment, for which reason does an engineer opt for an active/active FlexVPN configuration as opposed to DMVPN?
- A. Floating static routes are required.
- B. Traffic is distributed statically by default.
- C. HSRP is used for fallover.
- D. Multiple routers or VRFs are required.
Answer: B
NEW QUESTION 34
An organization is receiving SPAM emails from a known malicious domain. What must be configured in order to prevent the session during the initial TCP communication?
- A. Configure the Cisco ESA to drop the malicious emails
- B. Configure the Cisco ESA to reset the TCP connection
- C. Configure policies to stop and reject communication
- D. Configure policies to quarantine malicious emails
Answer: A
NEW QUESTION 35
How does Cisco Advanced Phishing Protection protect users?
- A. It determines which identities are perceived by the sender
- B. It uses machine learning and real-time behavior analytics.
- C. It utilizes sensors that send messages securely.
- D. It validates the sender by using DKIM.
Answer: B
Explanation:
https://www.cisco.com/c/dam/en/us/products/collateral/security/cloud-email-security/at-a-glance-c45-740894.pdf
NEW QUESTION 36
After deploying a Cisco ESA on your network, you notice that some messages fail to reach their destinations.
Which task can you perform to determine where each message was lost?
- A. Review the log files.
- B. Perform a trace.
- C. Generate a system report.
- D. Configure the trackingconfig command to enable message tracking.
Answer: D
NEW QUESTION 37
What is the primary role of the Cisco Email Security Appliance?
- A. Mail Submission Agent
- B. Mail Delivery Agent
- C. Mail User Agent
- D. Mail Transfer Agent
Answer: D
NEW QUESTION 38
What provides the ability to program and monitor networks from somewhere other than the DNAC GUI?
- A. ASDM
- B. NetFlow
- C. API
- D. desktop client
Answer: C
NEW QUESTION 39
An organization received a large amount of SPAM messages over a short time period. In order to take action on the messages, it must be determined how harmful the messages are and this needs to happen dynamically. What must be configured to accomplish this?
- A. Configure the Cisco ESA to modify policies based on the traffic seen.
- B. Configure the Cisco WSA to receive real-time updates from Talos.
- C. Configure the Cisco ESA to receive real-time updates from Talos
- D. Configure the Cisco WSA to modify policies based on the traffic seen.
Answer: D
Explanation:
https://www.cisco.com/c/en/us/td/docs/security/esa/esa120/user_guide/b_ESA_Admin_Guide_12_0/b_ESA_Admin_Guide_chapter_01100.html
NEW QUESTION 40
Which two behavioral patterns characterize a ping of death attack? (Choose two)
- A. The attack is fragmented into groups of 8 octets before transmission.
- B. Malformed packets are used to crash systems.
- C. The attack is fragmented into groups of 16 octets before transmission.
- D. Publicly accessible DNS servers are typically used to execute the attack.
- E. Short synchronized bursts of traffic are used to disrupt TCP connections.
Answer: A,B
Explanation:
Explanation
Ping of Death (PoD) is a type of Denial of Service (DoS) attack in which an attacker attempts to crash, destabilize, or freeze the targeted computer or service by sending malformed or oversized packets using a simple ping command.
A correctly-formed ping packet is typically 56 bytes in size, or 64 bytes when the ICMP header is considered, and 84 including Internet Protocol version 4 header. However, any IPv4 packet (including pings) may be as large as 65,535 bytes. Some computer systems were never designed to properly handle a ping packet larger than the maximum packet size because it violates the Internet Protocol documented Like other large but well-formed packets, a ping of death is fragmented into groups of 8 octets before transmission. However, when the target computer reassembles the malformed packet, a buffer overflow can occur, causing a system crash and potentially allowing the injection of malicious code.
NEW QUESTION 41
Which algorithm provides asymmetric encryption?
- A. AES
- B. RSA
- C. 3DES
- D. RC4
Answer: B
Explanation:
Reference:
https://securityboulevard.com/2020/05/types-of-encryption-5-encryption-algorithms-how-to-choose-the-right-one/#:~:text=Standard%20asymmetric%20encryption%20algorithms%20include,%2C%20El%20Gamal%2C%20and%20DSA.
NEW QUESTION 42
Drag and drop the capabilities from the left onto the correct technologies on the right.
Answer:
Explanation:
NEW QUESTION 43
An engineer is implementing NTP authentication within their network and has configured both the client and server devices with the command nip authentication-key 1 md5 Clse392368270. The server at 1.1-1.1 is attempting to authenticate to the client at 1.1-12. however is unable to do so. Which command is required to enable the client to accept the server's authenhcation key?
- A. ntp peer 1.1.1.1 key 1
- B. ntp server 1.1.1.1 key 1
- C. ntp peer 1.1.1.2 key 1
- D. ntp server 1.1.1.2 key 1
Answer: B
Explanation:
Explanation
To configure an NTP enabled router to require authentication when other devices connect to it, use the following commands:
NTP_Server(config)#ntp authentication-key 2 md5 securitytut
NTP_Server(config)#ntp authenticate
NTP_Server(config)#ntp trusted-key 2
Then you must configure the same authentication-key on the client router:
NTP_Client(config)#ntp authentication-key 2 md5 securitytut
NTP_Client(config)#ntp authenticate
NTP_Client(config)#ntp trusted-key 2
NTP_Client(config)#ntp server 10.10.10.1 key 2
Note: To configure a Cisco device as a NTP client, use the command ntp server <IP address>. For example:
Router(config)#ntp server 10.10.10.1. This command will instruct the router to query 10.10.10.1 for the time.
NEW QUESTION 44
An engineer needs behavioral analysis to detect malicious activity on the hosts, and is configuring the organization's public cloud to send telemetry using the cloud provider's mechanisms to a security device. Which mechanism should the engineer configure to accomplish this goal?
- A. Flow
- B. NetFlow
- C. mirror port
- D. VPC flow logs
Answer: D
Explanation:
https://www.cisco.com/c/en/us/products/collateral/data-center-analytics/tetration-analytics/q-and-a-c67-737402.html
NEW QUESTION 45
An engineer has enabled LDAP accept queries on a listener. Malicious actors must be prevented from quickly identifying all valid recipients. What must be done on the Cisco ESA to accomplish this goal?
- A. Configure Directory Harvest Attack Prevention
- B. Bypass LDAP access queries in the recipient access table.
- C. Configure incoming content filters.
- D. Use Bounce Verification
Answer: C
Explanation:
Explanation
NEW QUESTION 46
An organization recently installed a Cisco WSA and would like to take advantage of the AVC engine to allow the organization to create a policy to control application specific activity. After enabling the AVC engine, what must be done to implement this?
- A. Use security services to configure the traffic monitor, .
- B. Use an access policy group to configure application control settings.
- C. Use URL categorization to prevent the application traffic.
- D. Use web security reporting to validate engine functionality
Answer: B
Explanation:
Explanation
Explanation
The Application Visibility and Control (AVC) engine lets you create policies to control application activity on the network without having to fully understand the underlying technology of each application. You can configure application control settings in Access Policy groups. You can block or allow applications individually or according to application type. You can also apply controls to particular application types.
NEW QUESTION 47
Using Cisco Firepower's Security Intelligence policies, upon which two criteria is Firepower block based? (Choose two.)
- A. protocol IDs
- B. IP addresses
- C. port numbers
- D. MAC addresses
- E. URLs
Answer: B,E
Explanation:
NEW QUESTION 48
......
Authentic Best resources for 350-701 Online Practice Exam: https://www.real4prep.com/350-701-exam.html
Get the superior quality 350-701 Dumps with explanations waiting just for you, get it now: https://drive.google.com/open?id=1qsVF9UdacUYoCmD0sN8ertTn-kQc_xBl