350-701 Braindumps PDF, Cisco 350-701 Exam Cram
New 2024 350-701 Sample Questions Reliable 350-701 Test Engine
NEW QUESTION # 294
A network security engineer must export packet captures from the Cisco FMC web browser while troubleshooting an issue. When navigating to the address https://<FMC IP>/capure/CAPI/pcap/test.pcap, an error 403: Forbidden is given instead of the PCAP file. Which action must the engineer take to resolve this issue?
- A. Use the Cisco FTD IP address as the proxy server setting on the browser
- B. Disable the HTTPS server and use HTTP instead
- C. Disable the proxy setting on the browser
- D. Enable the HTTPS server for the device platform policy
Answer: D
NEW QUESTION # 295
Which VMware platform does Cisco ACI integrate with to provide enhanced visibility, provide policy integration and deployment, and implement security policies with access lists?
- A. VMwarevRealize
- B. VMware APIC
- C. VMware fusion
- D. VMware horizons
Answer: B
Explanation:
VMware APIC is a platform that integrates with Cisco ACI to provide enhanced visibility, policy integration and deployment, and security policies with access lists. VMware APIC is a virtual appliance that runs on VMware vSphere and communicates with the Cisco APIC controller. VMware APIC allows administrators to create and manage Cisco ACI policies for VMware virtual machines and networks. VMware APIC also provides a unified view of the physical and virtual network topology, health, and statistics. VMware APIC supports the following modes of Cisco ACI and VMware integration:
* VMware VDS: When integrated with Cisco ACI, the VMware vSphere Distributed Switch (VDS)
* enables administrators to configure VM networking in the ACI fabric.
* Cisco ACI Virtual Edge: Cisco ACI Virtual Edge is a distributed service that provides Layer 4 to Layer
7 services for applications running on VMware vSphere.
* Cisco Application Virtual Switch (AVS): Cisco AVS is a distributed virtual switch that provides policy-based network services for VMware vSphere environments. References:
* Cisco ACI with VMware VDS Integration
* Cisco ACI and VMware NSX-T Data Center Integration
* Cisco ACI and VMware: The Perfect Pair
* Setting the Record Straight: Confusion about ACI on VMware Technologies
NEW QUESTION # 296
Which baseline form of telemetry is recommended for network infrastructure devices?
- A. NetFlow
- B. SDNS
- C. passive taps
- D. SNMP
Answer: A
Explanation:
NetFlow is a baseline form of telemetry that is recommended for network infrastructure devices. NetFlow is a technology that collects and exports information about IP traffic flows on enabled interfaces. NetFlow can provide valuable insight into the network performance, utilization, behavior, and security. NetFlow can help identify anomalies, such as DDoS attacks, malware, or misconfigurations, by comparing the current traffic patterns with the normal or baseline ones. NetFlow can also help with capacity planning, troubleshooting, and forensic analysis. NetFlow is supported on various Cisco platforms, such as routers, switches, firewalls, and IPS sensors. NetFlow can export data to different collectors and analyzers, such as Cisco Security Monitoring, Analysis and Response System (CS-MARS), Cisco Traffic Anomaly Detectors and Cisco Guard DDoS Mitigation Appliances, Cisco Network Analysis Module (NAM), and other third-party tools. References:
NEW QUESTION # 297
Which statement describes a traffic profile on a Cisco Next Generation Intrusion Prevention System?
- A. It inspects hosts that meet the profile with more intrusion rules.
- B. It defines a traffic baseline for traffic anomaly deduction.
- C. It allows traffic if it does not meet the profile.
- D. It blocks traffic if it does not meet the profile.
Answer: B
NEW QUESTION # 298
Which two probes are configured to gather attributes of connected endpoints using Cisco Identity Services Engine? (Choose two.)
- A. TACACS+
- B. sFlow
- C. RADIUS
- D. DHCP
- E. SMTP
Answer: C,D
Explanation:
Explanation/Reference: https://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_prof_pol.html
NEW QUESTION # 299
When web policies are configured in Cisco Umbrella, what provides the ability to ensure that domains are blocked when they host malware, command and control, phishing, and more threats?
- A. Application Control
- B. Security Category Blocking
- C. Content Category Blocking
- D. File Analysis
Answer: B
NEW QUESTION # 300
Which two deployment model configurations are supported for Cisco FTDv in AWS? (Choose two)
- A. Cisco FTDv configured in routed mode and managed by an FMCv installed in AWS
- B. Cisco FTDv configured in routed mode and IPv6 configured
- C. Cisco FTDv with one management interface and two traffic interfaces configured
- D. Cisco FTDv with two management interfaces and one traffic interface configured
- E. Cisco FTDv configured in routed mode and managed by a physical FMC appliance on premises
Answer: A,E
Explanation:
Cisco FTDv in AWS can be deployed in two different deployment models: single-instance and cluster. In both models, the FTDv can be configured in routed mode and managed by either an FMCv installed in AWS or a physical FMC appliance on premises. The FTDv can also use Geneve encapsulation for traffic interfaces to support AWS Gateway Load Balancer (GWLB) integration. The following table summarizes the supported deployment model configurations for FTDv in AWS:
Table
Deployment Model
Management Mode
Traffic Mode
Geneve Encapsulation
Single-instance
FMCv in AWS
Routed
Optional
Single-instance
FMC on premises
Routed
Optional
Cluster
FMCv in AWS
Routed
Required
Cluster
FMC on premises
Routed
Required
References :=
* Deploy the Threat Defense Virtual on AWS - Cisco
* Deploy a Threat Defense Virtual Cluster on AWS - Cisco
* Configure Geneve Interfaces in Secure FTDv - Cisco
* Deployment of Cisco Secure FTDv and FMCv instances in AWS - Terraform
* Solved: FTD virtual appliance in AWS - Cisco Community
NEW QUESTION # 301
A network administrator is using the Cisco ESA with AMP to upload files to the cloud for analysis. The network is congested and is affecting communication. How will the Cisco ESA handle any files which need analysis?
- A. AMP calculates the SHA-256 fingerprint, caches it, and periodically attempts the upload.
- B. The file upload is abandoned.
- C. The file is queued for upload when connectivity is restored.
- D. The ESA immediately makes another attempt to upload the file.
Answer: B
Explanation:
The appliance will try once to upload the file; if upload is not successful, for example because of connectivity problems, the file may not be uploaded. If the failure was because the file analysis server was overloaded, the upload will be attempted once more.
Reference:
In this question, it stated "the network is congested" (not the file analysis server was overloaded) so the appliance will not try to upload the file again.
NEW QUESTION # 302
Which type of data does the Cisco Stealthwatch system collect and analyze from routers, switches, and firewalls?
- A. NetFlow
- B. NTP
- C. SNMP
- D. syslog
Answer: A
NEW QUESTION # 303
Drag and drop the Firepower Next Generation Intrusion Prevention System detectors from the left onto the correct definitions on the right.
Answer:
Explanation:
NEW QUESTION # 304
An organization wants to secure data in a cloud environment. Its security model requires that all users be authenticated and authorized. Security configuration and posture must be continuously validated before access is granted or maintained to applications and dat a. There is also a need to allow certain application traffic and deny all other traffic by default. Which technology must be used to implement these requirements?
- A. Access control policy
- B. Virtual routing and forwarding
- C. Virtual LAN
- D. Microsegmentation
Answer: A
Explanation:
Zero Trust is a security framework requiring all users, whether in or outside the organization's network, to be authenticated, authorized, and continuously validated for security configuration and posture before being granted or keeping access to applications and data. Zero Trust assumes that there is no traditional network edge; networks can be local, in the cloud, or a combination or hybrid with resources anywhere as well as workers in any location.
The Zero Trust model uses microsegmentation - a security technique that involves dividing perimeters into small zones to maintain separate access to every part of the network - to contain attacks.
NEW QUESTION # 305
A Cisco AMP for Endpoints administrator configures a custom detection policy to add specific MD5 signatures The configuration is created in the simple detection policy section, but it does not work What is the reason for this failure?
- A. Detections for MD5 signatures must be configured in the advanced custom detection policies
- B. The administrator must upload the file instead of the hash for Cisco AMP to use.
- C. The MD5 hash uploaded to the simple detection policy is in the incorrect format
- D. The APK must be uploaded for the application that the detection is intended
Answer: A
Explanation:
The reason for the failure is that detections for MD5 signatures must be configured in the advanced custom detection policies, not in the simple detection policy section. The simple detection policy section allows users to create a list of SHA-256 hashes of files that they want to block or quarantine on the endpoints. The SHA-256 hash is a more secure and unique identifier of a file than the MD5 hash, which can have collisions or duplicates. The advanced custom detection policy section allows users to create more complex and flexible rules to detect and block files based on various criteria, such as file name, size, type, signature, or MD5 hash.
The advanced custom detection policy section also supports wildcards and regular expressions to match multiple files or patterns. Therefore, if the administrator wants to add specific MD5 signatures to the custom detection policy, they should use the advanced custom detection policy section instead of the simple detection policy section.
References:
* Configure a Simple Custom Detection List on the AMP for Endpoints Portal - Cisco, Step 4: On the Add SHA-256 option, paste the SHA-256 code previously collected from the specific file you want to block, as shown in the image.
* Create an Advanced Custom Detection List in Cisco Secure Endpoint - Cisco, Step 3: Next, Edit that new Signature Set, and Add Signature.
Win.Exploit.CVE_2020_0601:1::06072A8648CE3D02010606072A8648CE3D020130.
NEW QUESTION # 306
What is the purpose of joining Cisco WSAs to an appliance group?
- A. It simplifies the task of patching multiple appliances.
- B. The group supports improved redundancy
- C. All WSAs in the group can view file analysis results.
- D. It supports cluster operations to expedite the malware analysis process.
Answer: C
NEW QUESTION # 307
An organization wants to secure data in a cloud environment. Its security model requires that all users be authenticated and authorized. Security configuration and posture must be continuously validated before access is granted or maintained to applications and dat a. There is also a need to allow certain application traffic and deny all other traffic by default. Which technology must be used to implement these requirements?
- A. Microsegmentation
- B. Virtual routing and forwarding
- C. Access control policy
- D. Virtual LAN
Answer: A
Explanation:
Zero Trust is a security framework requiring all users, whether in or outside the organization's network, to be authenticated, authorized, and continuously validated for security configuration and posture before being granted or keeping access to applications and data. Zero Trust assumes that there is no traditional network edge; networks can be local, in the cloud, or a combination or hybrid with resources anywhere as well as workers in any location.
The Zero Trust model uses microsegmentation - a security technique that involves dividing perimeters into small zones to maintain separate access to every part of the network - to contain attacks.
NEW QUESTION # 308
A network engineer is configuring NetFlow top talkers on a Cisco router Drag and drop the steps in the process from the left into the sequence on the right
Answer:
Explanation:
NEW QUESTION # 309
What are two benefits of Flexible NetFlow records? (Choose two)
- A. They provide accounting and billing enhancements
- B. They converge multiple accounting technologies into one accounting mechanism
- C. They provide attack prevention by dropping the traffic
- D. They provide monitoring of a wider range of IP packet information from Layer 2 to 4
- E. They allow the user to configure flow information to perform customized traffic identification
Answer: A,E
Explanation:
NetFlow is typically used for several key customer applications, including the following:
...
Billing and accounting. NetFlow data provides fine-grained metering (for instance, flow data includes details such as IP addresses, packet and byte counts, time stamps, type of service (ToS), and application ports) for highly flexible and detailed resource utilization accounting. Service providers may use the information for billing based on time of day, bandwidth usage, application usage, quality of service, and so on. Enterprise customers may use the information for departmental charge back or cost allocation for resource utilization.
NetFlow is typically used for several key customer applications, including the following:
...
Billing and accounting. NetFlow data provides fine-grained metering (for instance, flow data includes details such as IP addresses, packet and byte counts, time stamps, type of service (ToS), and application ports) for highly flexible and detailed resource utilization accounting. Service providers may use the information for billing based on time of day, bandwidth usage, application usage, quality of service, and so on. Enterprise customers may use the information for departmental charge back or cost allocation for resource utilization.
NetFlow is typically used for several key customer applications, including the following:
...
Billing and accounting. NetFlow data provides fine-grained metering (for instance, flow data includes details such as IP addresses, packet and byte counts, time stamps, type of service (ToS), and application ports) for highly flexible and detailed resource utilization accounting. Service providers may use the information for billing based on time of day, bandwidth usage, application usage, quality of service, and so on. Enterprise customers may use the information for departmental charge back or cost allocation for resource utilization.
Reference:
If the predefined Flexible NetFlow records are not suitable for your traffic requirements, you can create a userdefined (custom) record using the Flexible NetFlow collect and match commands. Before you can create a customized record, you must decide the criteria that you are going to use for the key and nonkey fields.
cust_fnflow_rec_mon_external_docbase_0900e4b18055d0d2_4container_external_docbase_0900e4b181b413 d9.html#wp1057997 Note: Traditional NetFlow allows us to monitor from Layer 2 to 4 but Flexible NetFlow goes beyond these layers.
If the predefined Flexible NetFlow records are not suitable for your traffic requirements, you can create a userdefined (custom) record using the Flexible NetFlow collect and match commands. Before you can create a customized record, you must decide the criteria that you are going to use for the key and nonkey fields.
cust_fnflow_rec_mon_external_docbase_0900e4b18055d0d2_4container_external_docbase_0900e4b181b413 d9.html#wp1057997 Note: Traditional NetFlow allows us to monitor from Layer 2 to 4 but Flexible NetFlow goes beyond these If the predefined Flexible NetFlow records are not suitable for your traffic requirements, you can create a userdefined (custom) record using the Flexible NetFlow collect and match commands. Before you can create a customized record, you must decide the criteria that you are going to use for the key and nonkey fields.
cust_fnflow_rec_mon_external_docbase_0900e4b18055d0d2_4container_external_docbase_0900e4b181b413 d9.html#wp1057997 Note: Traditional NetFlow allows us to monitor from Layer 2 to 4 but Flexible NetFlow goes beyond these layers.
NEW QUESTION # 310
What is a commonality between DMVPN and FlexVPN technologies?
- A. FlexVPN and DMVPN use the same hashing algorithms
- B. FlexVPN and DMVPN use IS-IS routing protocol to communicate with spokes
- C. FlexVPN and DMVPN use the new key management protocol
- D. IOS routers run the same NHRP code for DMVPN and FlexVPN
Answer: D
Explanation:
In its essence, FlexVPN is the same as DMVPN. Connections between devices are still point-to-point GRE tunnels, spoke-to-spoke connectivity is still achieved with NHRP redirect message, IOS routers even run the same NHRP code for both DMVPN and FlexVPN, which also means that both are Cisco's proprietary technologies.
NEW QUESTION # 311
A network administrator configures Dynamic ARP Inspection on a switch. After Dynamic ARP Inspection is applied, all users on that switch are unable to communicate with any destination. The network administrator checks the interface status of all interfaces, and there is no err-disabled interface. What is causing this problem?
- A. Dynamic ARP Inspection has not been enabled on all VLANs
- B. The ip arp inspection limit command is applied on all interfaces and is blocking the traffic of all users.
- C. DHCP snooping has not been enabled on all VLANs.
- D. The no ip arp inspection trust command is applied on all user host interfaces
Answer: D
Explanation:
Dynamic ARP inspection (DAI) is a security feature that validates ARP packets in a network. It intercepts, logs, and discards ARP packets with invalid IP-to-MAC address bindings. This capability protects the network from certain man-in-the-middle attacks. After enabling DAI, all ports become untrusted ports.
NEW QUESTION # 312
Which two prevention techniques are used to mitigate SQL injection attacks? (Choose two)
- A. Write SQL code instead of using object-relational mapping libraries.
- B. Use prepared statements and parameterized queries.
- C. Secure the connection between the web and the app tier.
- D. Check integer, float, or Boolean string parameters to ensure accurate values.
- E. Block SQL code execution in the web application database login.
Answer: B,E
Explanation:
SQL injection attacks are a type of code injection technique that exploit the use of dynamic SQL queries in web applications. Attackers can inject malicious SQL statements into user input fields, such as login forms, search boxes, or URLs, and execute them on the underlying database. This can result in unauthorized access, data theft, data corruption, or denial of service.
To prevent SQL injection attacks, web developers should use the following techniques:
* Use prepared statements and parameterized queries: Prepared statements are SQL queries that are precompiled and executed with user-supplied parameters. Parameterized queries are SQL queries that use placeholders for user input and bind them to actual values at runtime. Both techniques separate the SQL code from the user input, making it impossible for attackers to inject SQL commands into the query. For example, in Java, PreparedStatement is a class that implements parameterized queries. In PHP, PDO and mysqli are extensions that support prepared statements.
* Block SQL code execution in the web application database login: Web applications should use a dedicated database user account with limited privileges to connect to the database. This account should only have the permissions necessary to perform the required operations, such as select, insert, update, or delete. It should not have the permissions to execute arbitrary SQL commands, such as create, drop, alter, grant, or revoke. This way, even if an attacker manages to inject SQL code into the query, the database will reject it due to insufficient privileges.
References:
* [Implementing and Operating Cisco Security Core Technologies (SCOR) v1.0], Module 5: Securing the Cloud, Lesson 5.2: Cloud Application Security, Topic 5.2.2: SQL Injection
* SQL Injection Prevention - OWASP Cheat Sheet Series
* How to Prevent SQL Injection: 5 Key Prevention Methods - eSecurityPlanet
* How to Protect Against SQL Injection Attacks
NEW QUESTION # 313
An administrator configures new authorization policies within Cisco ISE and has difficulty profiling the devices. Attributes for the new Cisco IP phones that are profiled based on the RADIUS authentication are seen however the attributes for CDP or DHCP are not. What should the administrator do to address this issue?
- A. Configure the device sensor feature within the switch to send the appropriate protocol information
- B. Configure the authentication port-control auto feature within Cisco ISE to identify the devices that are trying to connect
- C. Configure a service template within the switch to standardize the port configurations so that the correct information is sent to Cisco ISE
- D. Configure the ip dhcp snooping trust command on the DHCP interfaces to get the information to Cisco ISE
Answer: A
Explanation:
Device sensor is a feature of access devices. It allows to collect information about connected endpoints. Mostly, information collected by Device Sensor can come from the following protocols:
+ Cisco Discovery Protocol (CDP)
+ Link Layer Discovery Protocol (LLDP)
+ Dynamic Host Configuration Protocol (DHCP)
Device sensor is a feature of access devices. It allows to collect information about connected endpoints. Mostly, information collected by Device Sensor can come from the following protocols:
+ Cisco Discovery Protocol (CDP)
+ Link Layer Discovery Protocol (LLDP)
+ Dynamic Host Configuration Protocol (DHCP)
Reference:
Device sensor is a feature of access devices. It allows to collect information about connected endpoints. Mostly, information collected by Device Sensor can come from the following protocols:
+ Cisco Discovery Protocol (CDP)
+ Link Layer Discovery Protocol (LLDP)
+ Dynamic Host Configuration Protocol (DHCP)
NEW QUESTION # 314
......
Feel Cisco 350-701 Dumps PDF Will likely be The best Option: https://pdftorrent.dumpexams.com/350-701-vce-torrent.html