Implementing and Operating Cisco Security Core Technologies (SCOR 350-701 v2.0) Questions and Answers
Which baseline form of telemetry is recommended for network infrastructure devices?
Which two capabilities does an MDM provide? (Choose two.)
A security engineer must configure a Splunk Universal Forwarder to send network traffic logs from Cisco Catalyst switches to a Splunk indexer cluster. Strict compliance requirements require all network traffic logs to be ingested into Splunk as an audit trail. The environment includes thousands of forwarders, and the data must be distributed across all indexers. Which two configuration actions must be performed? (Choose two.)
An organization is trying to implement micro-segmentation on the network and wants to be able to gain visibility on the applications within the network. The solution must be able to maintain and force compliance. Which product should be used to meet these requirements?
A network engineer is deciding whether to use stateful or stateless failover when configuring two Cisco ASAs for high availability. What is the connection status in both cases?
Which system performs compliance checks and remote wiping?
A network administrator is configuring a switch to use Cisco ISE for 802.1X. An endpoint is failing
authentication and is unable to access the network. Where should the administrator begin troubleshooting to verify the authentication details?
Which Cisco ASA Platform mode disables the threat detection features except for Advanced Threat Statistics?
What are two recommended approaches to stop DNS tunneling for data exfiltration and command and control call backs? (Choose two.)
Which feature requires that network telemetry be enabled?
Which ESA implementation method segregates inbound and outbound email?
An administrator is configuring a DHCP server to better secure their environment. They need to be able to ratelimit the traffic and ensure that legitimate requests are not dropped. How would this be accomplished?
Which Cisco security solution provides patch management in the cloud?
Which Cisco ISE feature helps to detect missing patches and helps with remediation?
Which action controls the amount of URI text that is stored in Cisco WSA logs files?
An engineer is configuring Cisco Secure Endpoint to enhance network security by specifying a large set of external IP addresses that must be monitored for potential threats. The engineer is configuring an IP List and must add the IP addresses to the list. Which configuration action must the engineer take next to meet the requirement?
An engineer enabled SSL decryption for Cisco Umbrella intelligent proxy and needs to ensure that traffic is inspected without alerting end-users. Which action accomplishes this goal?
Refer to the exhibit. A network engineer must configure a Cisco router to send traps using SNMPv3. The engineer configures a remote user to receive traps and sets the security level to use authentication without privacy. Which command completes the configuration?
What causes alert fatigue in Cisco XDR?
A pharmaceutical research facility has implemented a “Clean Room” network segment to protect sensitive research data and automated manufacturing equipment. Strict compliance requirements mandate that all network traffic logs from the Cisco Secure Firewall serving the segment be forwarded to Splunk for auditing. A Splunk Universal Forwarder is deployed locally on the log-collection servers to monitor syslog files. The engineer must configure the Universal Forwarder to monitor the local syslog files and assign a specific source type for proper ingestion into Splunk. Which stanza configuration must be used to meet the requirements?
Which type of API is being used when a controller within a software-defined network architecture dynamically
makes configuration changes on switches within the network?
Refer to the exhibit.
Which command was used to display this output?
Which type of algorithm provides the highest level of protection against brute-force attacks?
Refer to the exhibit.
During the rollout of a new site-to-site VPN between a headquarters Cisco Secure Firewall Threat Defense device and a partner firewall, the tunnel never completes IKEv1 Phase 1 and remains in the MM_WAIT_MSG_6 state. Reachability between the firewalls over the Internet is verified, ISAKMP UDP port 500 is permitted end-to-end, and the IKE Phase 1 policy parameters—including encryption, hashing, DH group, and lifetime—match exactly on both ends. Which configuration action must be performed to resolve the issue?
Under which two circumstances is a CoA issued? (Choose two)
An organization wants to secure users, data, and applications in the cloud. The solution must be API-based and
operate as a cloud-native CASB. Which solution must be used for this implementation?
A customer has various external HTTP resources available including Intranet. Extranet, and Internet, with a proxy configuration running in explicit mode Which method allows the client desktop browsers to be configured to select when to connect direct or when to use the proxy?
Which Cisco firewall solution supports configuration via Cisco Policy Language?
A security policy administrator configures a Cisco Secure Access SIA DNS policy to block all social media categories for the Marketing Active Directory group. While testing from one of the user machines, access to the domain is allowed. When searching for this domain in User Activity Search, no queries for that specific domain are returned. Consider these facts:
The test user is part of the Marketing Active Directory group.
The domain socialmediaexample.org belongs to the social media category.
The user is configured with the Umbrella Roaming Client for DNS redirection.
All other social media websites are properly blocked for the same user and match the correct policy.
Which configuration must the administrator implement in Cisco Secure Access to meet the requirement?
Which statement about the configuration of Cisco ASA NetFlow v9 Secure Event Logging is true?
Which security solution is used for posture assessment of the endpoints in a BYOD solution?
For Cisco IOS PKI, which two types of Servers are used as a distribution point for CRLs? (Choose two)
II
An engineer musí set up 200 new laptops on a network and wants to prevent the users from moving their laptops around to simplify administration Which switch port MAC address security setting must be used?
What is a benefit of using Cisco CWS compared to an on-premises Cisco WSA?
An engineer is implementing DHCP security mechanisms and needs the ability to add additional attributes to profiles that are created within Cisco ISE Which action accomplishes this task?
Drag and drop the posture assessment flow actions from the left into a sequence on the right.
How does Cisco Stealthwatch Cloud provide security for cloud environments?
What are two characteristics of the RESTful architecture used within Cisco DNA Center? (Choose two.)
What is the difference between EPP and EDR?
What are two ways a network administrator transparently identifies users using Active Directory on the Cisco WSA? (Choose two.)
Which DevSecOps implementation process gives a weekly or daily update instead of monthly or quarterly in the applications?
What is a benefit of using GET VPN over FlexVPN within a VPN deployment?
Cisco SensorBase gaihers threat information from a variety of Cisco products and services and performs analytics to find patterns on threats Which term describes this process?
What is a functional difference between a Cisco ASA and a Cisco IOS router with Zone-based policy firewall?
Which two activities are performed using Cisco Catalyst Center? (Choose two.)
How is ICMP used an exfiltration technique?
Which Secure Email Gateway implementation method segregates inbound and outbound email?
Refer to the exhibit.
A security engineer is publishing a public web server located in the DMZ of a Cisco Secure Firewall Threat Defense device managed by Cisco Secure Firewall Management Center. The required network objects, Webserver_Private and Webserver_Public, are already defined, and an Auto NAT static rule mapping the public address to the private DMZ address is in place. The web server must be reachable from any source on the Internet. The engineer must configure a new Access Control Rule within the existing Access Control Policy. Which two configuration actions must be performed to meet the requirements? (Choose two.)
Refer to the exhibit.
Consider that any feature of DNS requests, such as the length off the domain name
and the number of subdomains, can be used to construct models of expected behavior to which
observed values can be compared. Which type of malicious attack are these values associated with?
What are two things to consider when using PAC files with the Cisco WSA? (Choose two.)
Which solution is more secure than the traditional use of a username and password and encompasses at least two of the methods of authentication?
An administrator configures new authorization policies within Cisco ISE and has difficulty profiling the devices. Attributes for the new Cisco IP phones that are profiled based on the RADIUS authentication are seen however the attributes for CDP or DHCP are not. What should the administrator do to address this issue?
How does Cisco Umbrella protect clients when they operate outside of the corporate network?
A network engineer entered the snmp-server user asmith myv7 auth sha cisco priv aes 256
cisc0xxxxxxxxx command and needs to send SNMP information to a host at 10.255.255.1. Which
command achieves this goal?
What is a key feature of the Bring Your Own Device (BYOD) capability in Cisco ISE?
A network security engineer must export packet captures from the Cisco FMC web browser while troubleshooting an issue. When navigating to the address < FMC IP > /capure/CAPI/pcap/test.pcap, an error 403: Forbidden is given instead of the PCAP file. Which action must the engineer take to resolve this issue?
What is the difference between a vulnerability and an exploit?
What is a description of microsegmentation?
What is a required prerequisite to enable malware file scanning for the Secure Internet Gateway?
What are two Detection and Analytics Engines of Cognitive Threat Analytics? (Choose two)
Where are individual sites specified to be blacklisted in Cisco Umbrella?
When a Cisco WSA checks a web request, what occurs if it is unable to match a user-defined policy?
A network engineer is deciding whether to use stateful or stateless failover when configuring two ASAs for high availability. What is the connection status in both cases?
Which Cisco security solution integrates with cloud applications like Dropbox and Office 365 while protecting data from being exfiltrated?
Based on the NIST 800-145 guide, which cloud architecture is provisioned for exclusive use by a specific group of consumers from different organizations and may be owned, managed, and operated by one or more of those organizations?
Refer to the exhibit. A network engineer must retrieve the interface configuration on a Cisco router by using the NETCONF API. The engineer uses a python script to automate the activity.
Which code snippet completes the script?
Refer to the exhibit.
An engineer must configure a Cisco switch to perform PPP authentication via a TACACS server located at IP address 10.1.1.10. Authentication must fall back to the local database using the username LocalUser and password C1Sc0451069341l if the TACACS server is unreachable.
Drag and drop the commands from the left onto the corresponding configuration steps on the right.
Which endpoint solution protects a user from a phishing attack?
Which cloud service offering allows customers to access a web application that is being hosted, managed, and maintained by a cloud service provider?
Which portion of the network do EPP solutions solely focus on and EDR solutions do not?
Drag and drop the descriptions from the left onto the correct protocol versions on the right.
An engineer needs a solution for TACACS+ authentication and authorization for device administration.
The engineer also wants to enhance wired and wireless network security by requiring users and endpoints to
use 802.1X, MAB, or WebAuth. Which product meets all of these requirements?
Where are individual sites specified to be block listed in Cisco Umbrella?
Which PKI enrollment method allows the user to separate authentication and enrollment actions and also
provides an option to specify HTTP/TFTP commands to perform file retrieval from the server?
What is the purpose of the Decrypt for Application Detection feature within the WSA Decryption options?
A security administrator must implement a network intrusion policy in Cisco Secure Firewall to block new potential threats without sacrificing network performance. The administrator plans to create a base policy with a broad rule set optimized to protect the environment without significantly affecting throughput. Which type of policy should the administrator create?
How does Cisco Secure Endpoint provide next-generation protection?
Which risk is created when using an Internet browser to access cloud-based service?
Refer to the exhibit.
Traffic is not passing through IPsec site-to-site VPN on the Firepower Threat Defense appliance. What is causing this issue?
What are two benefits of using an MDM solution? (Choose two.)
When choosing an algorithm to us, what should be considered about Diffie Hellman and RSA for key
establishment?
What is a language format designed to exchange threat intelligence that can be transported over the TAXII
protocol?
Refer to the exhibit.
How does Cisco Umbrella manage traffic that is directed toward risky domains?
Which two features of Cisco Email Security can protect your organization against email threats? (Choose two)
In a federated single sign-on environment, which protocol exchanges XML-based assertions between an identity provider and a service provider for authentication?
A facilities team is onboarding a fleet of badge readers and IP cameras through MAB authentication on Cisco Catalyst access switches integrated with Cisco ISE. After Cisco ISE profiles each endpoint, an authorization policy must dynamically move the device into a dedicated IoT VLAN that differs from the access VLAN statically defined on the port. The endpoints lack a supplicant and cannot automatically renew their DHCP addresses. The network engineer requires Cisco ISE to issue a Change of Authorization that forces each endpoint to re-establish connectivity and request a fresh DHCP lease under the new authorization policy. Which configuration action must be performed on Cisco ISE to meet the requirement?
Which solution combines Cisco IOS and IOS XE components to enable administrators to recognize applications, collect and send network metrics to Cisco Prime and other third-party management tools, and prioritize application traffic?
An organization has a requirement to collect full metadata information about the traffic going through their AWS cloud services They want to use this information for behavior analytics and statistics Which two actions must be taken to implement this requirement? (Choose two.)
What is the term for having information about threats and threat actors that helps mitigate harmful events that would otherwise compromise networks or systems?
Which two devices support WCCP for traffic redirection? (Choose two.)
Which technology must be used to implement secure VPN connectivity among company branches over a
private IP cloud with any-to-any scalable connectivity?
An organization has two systems in their DMZ that have an unencrypted link between them for communication.
The organization does not have a defined password policy and uses several default accounts on the systems.
The application used on those systems also have not gone through stringent code reviews. Which vulnerability
would help an attacker brute force their way into the systems?
A network administrator configures Dynamic ARP Inspection on a switch. After Dynamic ARP Inspection is applied, all users on that switch are unable to communicate with any destination. The network administrator checks the interface status of all interfaces, and there is no err-disabled interface. What is causing this problem?
What is a difference between GRE over IPsec and IPsec with crypto map?
Which method of attack is used by a hacker to send malicious code through a web application to an unsuspecting user to request that the victim ' s web browser executes the code?
What is the function of the crypto is a kmp key cisc406397954 address 0.0.0.0 0.0.0.0 command when establishing an IPsec VPN tunnel?
An engineer enabled SSL decryption for Cisco Umbrella intelligent proxy and needs to ensure that traffic is inspected without alerting end-users.
Which attribute has the ability to change during the RADIUS CoA?
What is a feature of an endpoint detection and response solution?
When MAB is configured for use within the 802.1X environment, an administrator must create a policy that allows the devices onto the network. Which information is used for the username and password?
Which API method and required attribute are used to add a device into Cisco DNA Center with the native API?
A small organization needs to reduce the VPN bandwidth load on their headend Cisco ASA in order to
ensure that bandwidth is available for VPN users needing access to corporate resources on the10.0.0.0/24 local HQ network. How is this accomplished without adding additional devices to the
network?
What are two characteristics of Cisco Catalyst Center APIs? (Choose two.)
Which benefit does endpoint security provide the overall security posture of an organization?
Which proxy mode must be used on Cisco WSA to redirect TCP traffic with WCCP?
Which ASA deployment mode can provide separation of management on a shared appliance?
In which two customer environments is the Cisco Secure Web Appliance Virtual connector traffic direction method selected? (Choose two.)
What is a functional difference between Cisco Secure Endpoint and Cisco Umbrella Roaming Client?
An organization wants to improve its cybersecurity processes and to add intelligence to its data The organization wants to utilize the most current intelligence data for URL filtering, reputations, and vulnerability information that can be integrated with the Cisco FTD and Cisco WSA What must be done to accomplish these objectives?
Which feature must be configured before implementing NetFlow on a router?
Which Cisco solution integrates industry-leading artificial intelligence and machine learning analytics and an assurance database to review the security posture and maintain visibility of an organization’s cloud environment?
Which form of attack is launched using botnets?
Which Cisco DNA Center Intent API action is used to retrieve the number of devices known to a DNA Center?
An engineer has enabled LDAP accept queries on a listener. Malicious actors must be prevented from quickly
identifying all valid recipients. What must be done on the Cisco ESA to accomplish this goal?
Refer to the exhibit.
A network engineer is testing NTP authentication and realizes that any device synchronizes time with this router and that NTP authentication is not enforced What is the cause of this issue?
Which suspicious pattern enables the Cisco Tetration platform to learn the normal behavior of users?
A user has a device in the network that is receiving too many connection requests from multiple machines.
Which type of attack is the device undergoing?
Which method is used to deploy certificates and configure the supplicant on mobile devices to gain access to
network resources?
Which two protocols must be configured to authenticate end users to the Web Security Appliance? (Choose two.)
Which two global commands must the network administrator implement to limit the attack surface of an internet-facing Cisco router? (Choose two.)
Which two actions does the Cisco identity Services Engine posture module provide that ensures endpoint security?(Choose two.)
An engineer must modify a policy to block specific addresses using Cisco Umbrella. The policy is created already and is actively used by devices, using many of the default policy elements.
What else must be done to accomplish this task?
What is the Cisco API-based broker that helps reduce compromises, application risks, and data breaches in an environment that is not on-premise?
A network engineer is configuring NetFlow top talkers on a Cisco router Drag and drop the steps in the process from the left into the sequence on the right
Which feature is configured for managed devices in the device platform settings of the Firepower Management
Center?
An engineer is trying to decide between using L2TP or GRE over IPsec for their site-to-site VPN implementation. What must be un solution?
An organization wants to provide visibility and to identify active threats in its network using a VM. The
organization wants to extract metadata from network packet flow while ensuring that payloads are not retained
or transferred outside the network. Which solution meets these requirements?
What are two reasons for implementing a multifactor authentication solution such as Duo Security provide to an
organization? (Choose two)
A network engineer is configuring DMVPN and entered the crypto isakmp key cisc0380739941 address 0.0.0.0 command on hostA. The tunnel is not being established to hostB. What action is needed to authenticate the VPN?
What are two facts about WSA HTTP proxy configuration with a PAC file? (Choose two.)
Which two solutions help combat social engineering and phishing at the endpoint level? (Choose two.)
Which solution is made from a collection of secure development practices and guidelines that developers must follow to build secure applications?
Which technology should be used to help prevent an attacker from stealing usernames and passwords of users within an organization?
Which technology reduces data loss by identifying sensitive information stored in public computing
environments?
A network administrator is configuring a rule in an access control policy to block certain URLs and selects the “Chat and Instant Messaging” category. Which reputation score should be selected to accomplish this goal?
What are two benefits of workload security? (Choose two.)
Refer to the exhibit.
What is the result of this Python script of the Cisco DNA Center API?
Which action configures the IEEE 802.1X Flexible Authentication feature to support Layer 3 authentication mechanisms?
A network administrator needs to find out what assets currently exist on the network. Third-party systems need to be able to feed host data into Cisco Firepower. What must be configured to accomplish this?
Refer to the exhibit.
What does the API key do while working with
During a recent security audit a Cisco IOS router with a working IPSEC configuration using IKEv1 was flagged for using a wildcard mask with the crypto isakmp key command The VPN peer is a SOHO router with a dynamically assigned IP address Dynamic DNS has been configured on the SOHO router to map the dynamic IP address to the host name of vpn sohoroutercompany.com In addition to the command crypto isakmp key Cisc425007536 hostname vpn.sohoroutercompany.com what other two commands are now required on the Cisco IOS router for the VPN to continue to function after the wildcard command is removed? (Choose two)
What is a difference between DMVPN and sVTI?
Which two Cisco Umbrella security categories are used to prevent command-and-control callbacks on port 53 and protect users from being tricked into providing confidential information? (Choose two.)
Which statement describes a traffic profile on a Cisco Next Generation Intrusion Prevention System?
Which type of information does threat intelligence gather to identify potential threats using common adversary techniques?
An organization wants to implement a cloud-delivered and SaaS-based solution to provide visibility and threat detection across the AWS network. The solution must be deployed without software agents and rely on AWS VPC flow logs instead. Which solution meets these requirements?
A networking team must harden an organization ' s network from VLAN hopping attacks. The team disables Dynamic Trunking Protocol and puts any unused ports in an unused VLAN. A trunk port is used as a trunk link. What must the team configure next to harden the network against VLAN hopping attacks?
Which function is performed by certificate authorities but is a limitation of registration authorities?
Which solution for remote workers enables protection, detection, and response on the endpoint against known and unknown threats?
Which industry standard is used to integrate Cisco ISE and pxGrid to each other and with other
interoperable security platforms?
Refer to the exhibit.
An engineer configured wired 802.1x on the network and is unable to get a laptop to authenticate. Which port configuration is missing?
What is the benefit of installing Cisco AMP for Endpoints on a network?
What is the process of performing automated static and dynamic analysis of files against preloaded
behavioral indicators for threat analysis?
What does the Cloudlock Apps Firewall do to mitigate security concerns from an application perspective?
Which two services are provided by the Cisco Talos Incident Response group? (Choose two.)
What are two benefits of using Cisco Duo as an MFA solution? (Choose two.)
Which RADIUS attribute can you use to filter MAB requests in an 802.1 x deployment?
A network engineer is deploying multiple Cisco Secure Firewall Threat Defense devices across two data centers. The solution has the following requirements:
Management must have no Internet dependency.
Management must remain accessible during major outages.
Policy management must be centralized.
Which solution must be implemented to meet the requirements?
When network telemetry is implemented, what is important to be enabled across all network infrastructure devices to correlate different sources?
Which Dos attack uses fragmented packets to crash a target machine?
Which two key and block sizes are valid for AES? (Choose two)
What is a function of Cisco AMP for Endpoints?
Which Cisco Umbrella package supports selective proxy for Inspection of traffic from risky domains?
Refer to the exhibit.
A network administrator configured a site-to-site VPN tunnel between two Cisco IOS routers, and hosts are unable to communicate between two sites of VPN. The network administrator runs the debug crypto isakmp sa command to track VPN status. What is the problem according to this command output?
A group of hospitals is collaborating to transition from an on-premises infrastructure to a cloud solution. The solution must be cost-effective, flexible, scalable, and support large volumes of data traffic. Each hospital has its own rules and policies that require direct control over its processes. Sensitive data, including patient records, must remain on-premises. Which type of cloud must be used?
What is a benefit of using Cisco Umbrella?
Email security has become a high priority task for a security engineer at a large multi-national organization due to ongoing phishing campaigns. To help control this, the engineer has deployed an Incoming Content Filter with a URL reputation of (-10 00 to -6 00) on the Cisco ESA Which action will the system perform to disable any links in messages that match the filter?
Which security solution uses NetFlow to provide visibility across the network, data center, branch offices, and cloud?
Which information is required when adding a device to Firepower Management Center?
Refer to the exhibit. When configuring this access control rule in Cisco FMC, what happens with the traffic destined to the DMZ_inside zone once the configuration is deployed?
An organization uses Cisco FMC to centrally manage multiple Cisco FTD devices. The default management
port conflicts with other communications on the network and must be changed. What must be done to ensure
that all devices can communicate together?
Why would a user choose an on-premises ESA versus the CES solution?
Refer to the exhibit. What function does the API key perform while working with
Which cloud model is a collaborative effort where infrastructure is shared and jointly accessed by several organizations from a specific group?
An engineer must modify an existing remote access VPN using a Cisco AnyConnect Secure Mobility client solution and a Cisco Secure Firewall. Currently, all the traffic generate by the user Is sent to the VPN tunnel and the engineer must now exclude some servers and access them directly instead. Which element must be modified to achieve this goat?
Refer to the exhibit.
=== Cisco Secure Endpoint - Detection Event ===
Endpoint : LAB-WKSTN-047 User: user1
Policy Group : Lab-Workstations Mode: Audit
Engine : ETHOS (fuzzy fingerprint)
Disposition : Malicious
File : C:\Users\user1\AppData\Local\Temp\svchost32.exe
SHA256 : 3a9f2c1d...e881b4a7
Parent Process: winword.exe
Threat Name : W32.Trojan.GenericKD.Agent
Retrospective : Previously UNKNOWN
Disposition changed to MALICIOUS at 09:31:55 UTC
File Activity : Created, Executed
Network : TCP outbound - > 91.205.188.47:4444
DNS query: c2-update.pharmadomain.ru
Quarantine : NOT quarantined (Audit mode active)
A security analyst at a pharmaceutical company is reviewing a Cisco Secure Endpoint malware-detection alert triggered on a laboratory workstation. The analyst observes the event data above. Which two things are occurring? (Choose two.)
Which threat intelligence standard contains malware hashes?
Which Cisco command enables authentication, authorization, and accounting globally so that CoA is supported on the device?
Which VMware platform does Cisco ACI integrate with to provide enhanced visibility, provide policy integration and deployment, and implement security policies with access lists?
Which command is used to log all events to a destination colector 209.165.201.107?
What is the recommendation in a zero-trust model before granting access to corporate applications and
resources?
What is the result of the ACME-Router(config)#login block-for 100 attempts 4 within 60 command on a Cisco IOS router?
Which feature is used in a push model to allow for session identification, host reauthentication, and session termination?
For which two conditions can an endpoint be checked using ISE posture assessment? (Choose two)
Which type of attack is social engineering?
Drag and drop the Cisco CWS redirection options from the left onto the capabilities on the right.
The security architect has concluded that the optimal mail flow positions the existing Cisco Secure Email Gateways as the first termination point for inbound messages, while Cisco Secure Email Threat Defense is positioned between the Secure Email Gateways and the cloud mail platform. The security engineer has been asked to configure the incoming-traffic domain setting in Cisco Secure Email Threat Defense so that it reflects the Secure Email Gateway handling inbound messages ahead of the service. Which domain configuration for incoming traffic must be selected to meet the requirement?
Which two cryptographic algorithms are used with IPsec? (Choose two)
A network engineer has entered the snmp-server user andy myv3 auth sha cisco priv aes 256
cisc0380739941 command and needs to send SNMP information to a host at 10.255.254.1. Which command achieves this goal?
An engineer is implementing NAC for LAN users on a segmented network. The engineer confirms that the device of each user is supported and the Cisco switch configuration is correct.
Which configuration should be made next to ensure there are no authentication issues?
Which security principle advocates rapid cryptographic algorithm replacement to defend against quantum-computing threats?
What is a prerequisite when integrating a Cisco ISE server and an AD domain?
Which two risks is a company vulnerable to if it does not have a well-established patching solution for
endpoints? (Choose two)
Which compliance status is shown when a configured posture policy requirement is not met?
An engineer is configuring IPsec VPN and needs an authentication protocol that is reliable and supports ACK
and sequence. Which protocol accomplishes this goal?
A logistics company issues corporate laptops that must automatically establish a Cisco Secure Client VPN tunnel whenever users are outside the office and connected to an untrusted external network. Cisco Secure Firewall Threat Defense is the VPN headend and is already configured with remote-access profiles, address pools, and a PKI that distributes both machine and user certificates to endpoints. Management requires the tunnel to come up unattended before any user signs in to a laptop. Device-based authentication must be used, and the client must distinguish the corporate LAN from outside networks. The VPN must be connected when a user is outside the corporate network. Which configuration action must be performed to meet the requirements?
In a PaaS model, which layer is the tenant responsible for maintaining and patching?
What is a difference between a DoS attack and a DDoS attack?
Refer to the exhibit. Which task is the Python script performing by using the Cisco Umbrella API?
Which two application layer preprocessors are used by Firepower Next Generation Intrusion Prevention
System? (Choose two)
How does Cisco Workload Optimization Manager help mitigate application performance issues?
How does a Cisco Secure Firewall help to lower the risk of exfiltration techniques that steal customer data?
Which attack is commonly associated with C and C++ programming languages?
Refer to the exhibit.
A site-to-site IKEv2 VPN between two Cisco Secure Firewall Threat Defense devices at a healthcare organization completes IKE Phase 1 successfully but fails during CREATE_CHILD_SA. The engineer captures the debug output from the initiating Cisco Secure Firewall. Which action must be performed to resolve the issue?
What are two functionalities of SDN Northbound APIs? (Choose two.)
Which term describes when the Cisco Firepower downloads threat intelligence updates from Cisco Talos?
A Cisco ISE engineer configures Central Web Authentication (CWA) for wireless guest access and must have the guest endpoints redirect to the guest portal for authentication and authorization. While testing the policy, the engineer notices that the device is not redirected and instead gets full guest access. What must be done for the redirect to work?
An organization has two machines hosting web applications. Machine 1 is vulnerable to SQL injection while machine 2 is vulnerable to buffer overflows. What action would allow the attacker to gain access to machine 1 but not machine 2?
An administrator is adding a new Cisco ISE node to an existing deployment. What must be done to ensure that the addition of the node will be successful when inputting the FQDN?
In which form of attack is alternate encoding, such as hexadecimal representation, most often observed?
Which ID store requires that a shadow user be created on Cisco ISE for the admin login to work?
How does DNS Tunneling exfiltrate data?
Why is it important for the organization to have an endpoint patching strategy?
When a next-generation endpoint security solution is selected for a company, what are two key
deliverables that help justify the implementation? (Choose two.)
What is the purpose of threat intelligence in the Cisco Security Reference Architecture?
Which solution detects threats across a private network, public clouds, and encrypted traffic?
An engineer is deploying a Cisco Secure Email Gateway and must ensure it reaches the Cisco update servers to retrieve new rules. The engineer must now manually configure the Outbreak Filter rules on an AsyncOS for Cisco Secure Email Gateway. Only outdated rules must be replaced. Up-to-date rules must be retained. Which action must the engineer take next to complete the configuration?
Refer to the exhibit.
A site-to-site IKEv2 VPN between a Cisco Secure Firewall Threat Defense device with public IP address 203.0.113.10 and a third-party firewall with public IP address 198.51.100.20 is failing to establish at a logistics company. The engineer enables IKEv2 debugging on the FTD and captures the output. Which action must be performed to resolve the issue?
What is a difference between Cisco AMP for Endpoints and Cisco Umbrella?
A company deploys an application that contains confidential data and has a hybrid hub-and-spoke topology. The hub resides in a public cloud environment, and the spoke resides on-premises. An engineer must secure the application to ensure that confidential data in transit between the hub-and-spoke servers is accessible only to authorized users. The engineer performs these configurations:
Segregation of duties
Role-based access control
Privileged access management
What must be implemented to protect the data in transit?
What is a difference between SQL injection and buffer overflow?
Which term describes when the Cisco Secure Firewall downloads threat intelligence updates from Cisco Tables?
A network engineer must enable SSH and SCP on a Cisco IOS router. The engineer has already generated the encryption keys and enabled SCP services on the router. Which configuration action must be performed next?
What is the role of Cisco Umbrella Roaming when it is installed on an endpoint?
An engineer used a posture check on a Microsoft Windows endpoint and discovered that the MS17-010 patch
was not installed, which left the endpoint vulnerable to WannaCry ransomware. Which two solutions mitigate
the risk of this ransom ware infection? (Choose two)
A security engineer requires social-media websites to be blocked through Cisco Secure Firewall Threat Defense. Which configuration action must the engineer apply to meet the requirement?
An MDM provides which two advantages to an organization with regards to device management? (Choose two)
Which exfiltration method does an attacker use to hide and encode data inside DNS requests and queries?
Which two types of policies are used by ZTNA to provide access to an application? (Choose two.)
Drag and drop the capabilities from the left onto the correct technologies on the right.
Which solution stops unauthorized access to the system if a user ' s password is compromised?
Which component of a Cisco IOS NetFlow solution enables the aggregation of data packets into flows?
An administrator has been tasked with configuring the Cisco Secure Email Gateway to ensure there are no viruses before quarantined emails are delivered. In addition, delivery of mail from known bad mail servers must be prevented. Which two actions must be taken in order to meet these requirements? (Choose two.)
Which two aspects of the cloud PaaS model are managed by the customer but not the provider? (Choose two)
For a given policy in Cisco Umbrella, how should a customer block website based on a custom list?
A network engineer is tasked with configuring a Cisco ISE server to implement external authentication against Active Directory. What must be considered about the authentication requirements? (Choose two.)
What is a characteristic of Dynamic ARP Inspection?
What is a feature of the open platform capabilities of Cisco DNA Center?
An engineer must enable Outbreak Filters globally on an AsyncOS for Cisco Secure Email Gateway to protect the network from large-scale malware attacks. Drag and drop the steps from the left into the sequence on the right to complete the configuration.
What are two DDoS attack categories? (Choose two)






