[Jun-2023] 350-701 Braindumps – 350-701 Questions to Get Better Grades
350-701 Exam Dumps - Try Best 350-701 Exam Questions - BraindumpsIT
NEW QUESTION # 75
Refer to the exhibit.
Refer to the exhibit. What function does the API key perform while working with https://api.amp.cisco.com/v1/computers?
- A. plays dent ID
- B. HTTP authorization
- C. HTTP authentication
- D. imports requests
Answer: C
NEW QUESTION # 76
When a transparent authentication fails on the Web Security Appliance, which type of access does the end user get?
- A. limited Internet
- B. full Internet
- C. blocked
- D. guest
Answer: C
NEW QUESTION # 77
Which license is required for Cisco Security Intelligence to work on the Cisco Next Generation Intrusion Prevention System?
- A. protect
- B. matware
- C. URL filtering
- D. control
Answer: A
NEW QUESTION # 78
An organization is trying to implement micro-segmentation on the network and wants to be able to gain visibility on the applications within the network. The solution must be able to maintain and force compliance. Which product should be used to meet these requirements?
- A. Cisco Tetration
- B. Cisco AMP
- C. Cisco Umbrella
- D. Cisco Stealthwatch
Answer: A
Explanation:
Micro-segmentation secures applications by expressly allowing particular application traffic and, by default, denying all other traffic. Micro-segmentation is the foundation for implementing a zero-trust security model for application workloads in the data center and cloud.
Cisco Tetration is an application workload security platform designed to secure your compute instances across any infrastructure and any cloud. To achieve this, it uses behavior and attribute-driven microsegmentation policy generation and enforcement. It enables trusted access through automated, exhaustive context from various systems to automatically adapt security policies.
To generate accurate microsegmentation policy, Cisco Tetration performs application dependency mapping to discover the relationships between different application tiers and infrastructure services. In addition, the platform supports "what-if" policy analysis using real-time data or historical data to assist in the validation and risk assessment of policy application pre-enforcement to ensure ongoing application availability. The normalized microsegmentation policy can be enforced through the application workload itself for a consistent approach to workload microsegmentation across any environment, including virtualized, bare-metal, and container workloads running in any public cloud or any data center. Once the microsegmentation policy is enforced, Cisco Tetration continues to monitor for compliance deviations, ensuring the segmentation policy is up to date as the application behavior change.
Micro-segmentation secures applications by expressly allowing particular application traffic and, by default, denying all other traffic. Micro-segmentation is the foundation for implementing a zero-trust security model for application workloads in the data center and cloud.
Cisco Tetration is an application workload security platform designed to secure your compute instances across any infrastructure and any cloud. To achieve this, it uses behavior and attribute-driven microsegmentation policy generation and enforcement. It enables trusted access through automated, exhaustive context from various systems to automatically adapt security policies.
To generate accurate microsegmentation policy, Cisco Tetration performs application dependency mapping to discover the relationships between different application tiers and infrastructure services. In addition, the platform supports "what-if" policy analysis using real-time data or historical data to assist in the validation and risk assessment of policy application pre-enforcement to ensure ongoing application availability. The normalized microsegmentation policy can be enforced through the application workload itself for a consistent approach to workload microsegmentation across any environment, including virtualized, bare-metal, and container workloads running in any public cloud or any data center. Once the microsegmentation policy is enforced, Cisco Tetration continues to monitor for compliance deviations, ensuring the segmentation policy is up to date as the application behavior change.
Micro-segmentation secures applications by expressly allowing particular application traffic and, by default, denying all other traffic. Micro-segmentation is the foundation for implementing a zero-trust security model for application workloads in the data center and cloud.
Cisco Tetration is an application workload security platform designed to secure your compute instances across any infrastructure and any cloud. To achieve this, it uses behavior and attribute-driven microsegmentation policy generation and enforcement. It enables trusted access through automated, exhaustive context from various systems to automatically adapt security policies.
To generate accurate microsegmentation policy, Cisco Tetration performs application dependency mapping to discover the relationships between different application tiers and infrastructure services. In addition, the platform supports "what-if" policy analysis using real-time data or historical data to assist in the validation and risk assessment of policy application pre-enforcement to ensure ongoing application availability. The normalized microsegmentation policy can be enforced through the application workload itself for a consistent approach to workload microsegmentation across any environment, including virtualized, bare-metal, and container workloads running in any public cloud or any data center. Once the microsegmentation policy is enforced, Cisco Tetration continues to monitor for compliance deviations, ensuring the segmentation policy is up to date as the application behavior change.
NEW QUESTION # 79
Drag and drop the common security threats from the left onto the definitions on the right.
Answer:
Explanation:
NEW QUESTION # 80
A network administrator is configuring a switch to use Cisco ISE for 802.1X. An endpoint is failing authentication and is unable to access the network. Where should the administrator begin troubleshooting to verify the authentication details?
- A. Adaptive Network Control Policy List
- B. Accounting Reports
- C. RADIUS Live Logs
- D. Context Visibility
Answer: C
Explanation:
How To Troubleshoot ISE Failed Authentications & Authorizations
Check the ISE Live Logs
Login to the primary ISE Policy Administration Node (PAN).
Go to Operations > RADIUS > Live Logs
(Optional) If the event is not present in the RADIUS Live Logs, go to Operations > Reports > Reports > Endpoints and Users > RADIUS Authentications Check for Any Failed Authentication Attempts in the Log
NEW QUESTION # 81
A network administrator is configuring a switch to use Cisco ISE for 802.1X. An endpoint is failing authentication and is unable to access the network. Where should the administrator begin troubleshooting to verify the authentication details?
- A. Adaptive Network Control Policy List
- B. Accounting Reports
- C. RADIUS Live Logs
- D. Context Visibility
Answer: C
Explanation:
How To Troubleshoot ISE Failed Authentications & Authorizations
Check the ISE Live Logs
Login to the primary ISE Policy Administration Node (PAN).
Go to Operations > RADIUS > Live Logs
(Optional) If the event is not present in the RADIUS Live Logs, go to Operations > Reports > Reports > Endpoints and Users > RADIUS Authentications Check for Any Failed Authentication Attempts in the Log
NEW QUESTION # 82
Which two capabilities does TAXII support? (Choose two)
- A. Pull messaging
- B. Exchange
- C. Correlation
- D. Binding
- E. Mitigating
Answer: A,D
Explanation:
Explanation
The Trusted Automated eXchangeof Indicator Information (TAXII) specifies mechanisms for exchanging structured cyber threat information between parties over the network.
TAXII exists to provide specific capabilities to those interested in sharing structured cyber threat information.
TAXII Capabilities are the highest level at which TAXII actions can be described. There are three capabilities that this version of TAXII supports: push messaging, pull messaging, and discovery.
Although there is no "binding" capability in the list but it is the best answer here.
NEW QUESTION # 83
What are two benefits of using Cisco Duo as an MFA solution? (Choose two.)
- A. native integration that helps secure applications across multiple cloud platforms or on-premises environments
- B. provides simple and streamlined login experience for multiple applications and users
- C. encrypts data that is stored on endpoints
- D. allows for centralized management of endpoint device applications and configurations
- E. grants administrators a way to remotely wipe a lost or stolen device
Answer: A,B
NEW QUESTION # 84
Drag and drop the steps from the left into the correct order on the right to enable AppDynamics to monitor an EC2 instance in Amazon Web Services.
Answer:
Explanation:
Explanation
NEW QUESTION # 85
What is a benefit of using Cisco Umbrella?
- A. It prevents malicious inbound traffic.
- B. DNS queries are resolved faster.
- C. Files are scanned for viruses before they are allowed to run.
- D. Attacks can be mitigated before the application connection occurs.
Answer: D
NEW QUESTION # 86
Under which two circumstances is a CoA issued? (Choose two)
- A. An endpoint is profiled for the first time.
- B. A new Identity Service Engine server is added to the deployment with the Administration persona
- C. A new authentication rule was added to the policy on the Policy Service node.
- D. A new Identity Source Sequence is created and referenced in the authentication policy.
- E. An endpoint is deleted on the Identity Service Engine server.
Answer: A,E
Explanation:
The profiling service issues the change of authorization in the following cases:
- Endpoint deleted-When an endpoint is deleted from the Endpoints page and the endpoint is disconnected or removed from the network.
An exception action is configured-If you have an exception action configured per profile that leads to an unusual or an unacceptable event from that endpoint. The profiling service moves the endpoint to the corresponding static profile by issuing a CoA.
- An endpoint is profiled for the first time-When an endpoint is not statically assigned and profiled for the first time; for example, the profile changes from an unknown to a known profile.
+ An endpoint identity group has changed-When an endpoint is added or removed from an endpoint identity group that is used by an authorization policy.
The profiling service issues a CoA when there is any change in an endpoint identity group, and the endpoint identity group is used in the authorization policy for the following:
++ The endpoint identity group changes for endpoints when they are dynamically profiled
++ The endpoint identity group changes when the static assignment flag is set to true for a dynamic endpoint - An endpoint profiling policy has changed and the policy is used in an authorization policy-When an endpoint profiling policy changes, and the policy is included in a logical profile that is used in an authorization policy. The endpoint profiling policy may change due to the profiling policy match or when an endpoint is statically assigned to an endpoint profiling policy, which is associated to a logical profile. In both the cases, the profiling service issues a CoA, only when the endpoint profiling policy is used in an authorization policy.
Reference:
b_ise_admin_guide_20_chapter_010100.html
NEW QUESTION # 87
Which two deployment model configurations are supported for Cisco FTDv in AWS? (Choose two.)
- A. Cisco FTDv with two management interfaces and one traffic interface configured
- B. Cisco FTDv configured in routed mode and managed by a physical FMC appliance on premises
- C. Cisco FTDv configured in routed mode and IPv6 configured
- D. Cisco FTDv with one management interface and two traffic interfaces configured
- E. Cisco FTDv configured in routed mode and managed by an FMCv installed in AWS
Answer: B,E
Explanation:
Explanation/Reference: https://www.cisco.com/c/en/us/products/collateral/security/adaptive-security-virtual-appliance-asav/ white-paper-c11-740505.html
NEW QUESTION # 88
In which two ways does a system administrator send web traffic transparently to the Web Security Appliance?
(Choose two)
- A. configure the proxy IP address in the web-browser settings
- B. reference a Proxy Auto Config file
- C. configure policy-based routing on the network infrastructure
- D. use Web Cache Communication Protocol
- E. configure Active Directory Group Policies to push proxy settings
Answer: C,D
NEW QUESTION # 89
Drag and drop the capabilities from the left onto the correct technologies on the right.
Answer:
Explanation:
NEW QUESTION # 90
A company is experiencing exfiltration of credit card numbers that are not being stored on-premise. The company needs to be able to protect sensitive data throughout the full environment Which tool should be used to accomplish this goal?
- A. Cisco ISE
- B. Security Manager
- C. Cloudlock
- D. Web Security Appliance
Answer: C
Explanation:
Explanation
https://www.cisco.com/c/dam/en/us/products/collateral/security/cloudlock/cisco-cloudlock-cloud-data-securityda
NEW QUESTION # 91
A network administrator is configuring a rule in an access control policy to block certain URLs and selects the "Chat and Instant Messaging" category. Which reputation score should be selected to accomplish this goal?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: C
Explanation:
We choose "Chat and Instant Messaging" category in "URL Category":
To block certain URLs we need to choose URL Reputation from 6 to 10.
NEW QUESTION # 92
Which algorithm is an NGE hash function?
- A. MD5
- B. SHA-1
- C. SHA-2
- D. HMAC
Answer: C
NEW QUESTION # 93
How is Cisco Umbrella configured to log only security events?
- A. in the Reporting settings
- B. per network in the Deployments section
- C. per policy
- D. in the Security Settings section
Answer: C
Explanation:
Explanation The logging of your identities' activities is set per-policy when you first create a policy. By default, logging is on and set to log all requests an identity makes to reach destinations. At any time after you create a policy, you can change what level of identity activity Umbrella logs. From the Policy wizard, log settings are: Log All Requests-For full logging, whether for content, security or otherwise Log Only Security Events-For security logging only, which gives your users more privacy-a good setting for people with the roaming client installed on personal devices Don't Log Any Requests-Disables all logging. If you select this option, most reporting for identities with this policy will not be helpful as nothing is logged to report on. Reference: https://docs.umbrella.com/deployment-umbrella/docs/log-management The logging of your identities' activities is set per-policy when you first create a policy. By default, logging is on and set to log all requests an identity makes to reach destinations. At any time after you create a policy, you can change what level of identity activity Umbrella logs.
From the Policy wizard, log settings are:
Log All Requests-For full logging, whether for content, security or otherwise Log Only Security Events-For security logging only, which gives your users more privacy-a good setting for people with the roaming client installed on personal devices Don't Log Any Requests-Disables all logging. If you select this option, most reporting for identities with this policy will not be helpful as nothing is logged to report on.
Explanation The logging of your identities' activities is set per-policy when you first create a policy. By default, logging is on and set to log all requests an identity makes to reach destinations. At any time after you create a policy, you can change what level of identity activity Umbrella logs. From the Policy wizard, log settings are: Log All Requests-For full logging, whether for content, security or otherwise Log Only Security Events-For security logging only, which gives your users more privacy-a good setting for people with the roaming client installed on personal devices Don't Log Any Requests-Disables all logging. If you select this option, most reporting for identities with this policy will not be helpful as nothing is logged to report on. Reference: https://docs.umbrella.com/deployment-umbrella/docs/log-management
NEW QUESTION # 94
An engineer is configuring cloud logging using a company-managed Amazon S3 bucket for Cisco Umbrella logs. What benefit does this configuration provide for accessing log data?
- A. Data can be stored offline for 30 days.
- B. It is included m the license cost for the multi-org console of Cisco Umbrella
- C. It can grant third-party SIEM integrations write access to the S3 bucket
- D. No other applications except Cisco Umbrella can write to the S3 bucket
Answer: A
NEW QUESTION # 95
Which two protocols must be configured to authenticate end users to the Web Security Appliance? (Choose two.)
- A. NTLMSSP
- B. Kerberos
- C. TACACS+
- D. CHAP
- E. RADIUS
Answer: A,B
NEW QUESTION # 96
An administrator configures a new destination list in Cisco Umbrella so that the organization can block specific domains for its devices. What should be done to ensure that all subdomains of domain.com are blocked?
- A. Configure the *.com address in the block list.
- B. Configure the *.domain.com address in the block list
- C. Configure the domain.com address in the block list
- D. Configure the *.domain.com address in the block list
Answer: B
NEW QUESTION # 97
Drag and drop the VPN functions from the left onto the description on the right.
Answer:
Explanation:
NEW QUESTION # 98
After deploying a Cisco ESA on your network, you notice that some messages fail to reach their destinations.
Which task can you perform to determine where each message was lost?
- A. Perform a trace.
- B. Configure the trackingconfig command to enable message tracking.
- C. Generate a system report.
- D. Review the log files.
Answer: B
NEW QUESTION # 99
......
Necessary Prerequisites
In all, there are no mandatory requirements for attempting such an exam. Still, it will be great to have the following skills before registering for the official test:
- Be familiar with the fundamentals of security for networks.
- Should have worked with the Cisco IOS networking facets and the related concepts;
- Be familiar with TCP/IP and Ethernet networking;
- Have proven skills in utilizing the Windows OS;
Verified 350-701 exam dumps Q&As with Correct 600 Questions and Answers: https://www.braindumpsit.com/350-701_real-exam.html
Get New 350-701 Certification – Valid Exam Dumps Questions: https://drive.google.com/open?id=1cbQ0ZAm98TdCmaTR9bnWEywbO0jCtspu