75only - Ends in 0d 00h 00m 00s - Coupon code = 75only

Pass the Cisco CCNP Security 350-701 Questions and answers with Dumpstech

Exam 350-701 Premium Access

View all detail and faqs for the 350-701 exam

Practice at least 50% of the questions to maximize your chances of passing.
Viewing page 10 out of 16 pages
Viewing questions 136-150 out of questions
Questions # 136:

When choosing an algorithm to us, what should be considered about Diffie Hellman and RSA for key

establishment?

Options:

A.

RSA is an asymmetric key establishment algorithm intended to output symmetric keys

B.

RSA is a symmetric key establishment algorithm intended to output asymmetric keys

C.

DH is a symmetric key establishment algorithm intended to output asymmetric keys

D.

DH is an asymmetric key establishment algorithm intended to output symmetric keys

Questions # 137:

Which term describes when the Cisco Firepower downloads threat intelligence updates from Cisco Talos?

Options:

A.

consumption

B.

sharing

C.

analysis

D.

authoring

Questions # 138:

Which approach reduces the risk of social engineering attacks?

Options:

A.

Enabling NAT traversal for endpoint management

B.

Conducting regular security awareness training for all users

C.

Using port security to limit DHCP spoofing

D.

Restricting outbound TCP traffic to known subnets

Questions # 139:

A web hosting company must upgrade its older, unsupported on-premises servers. The company wants a cloud solution in which the cloud provider is responsible for:

Server patching

Application maintenance

Data center security

Disaster recovery

Which type of cloud meets the requirements?

Options:

A.

Hybrid

B.

IaaS

C.

SaaS

D.

PaaS

Questions # 140:

Which Cisco platform ensures that machines that connect to organizational networks have the recommended

antivirus definitions and patches to help prevent an organizational malware outbreak?

Options:

A.

Cisco WiSM

B.

Cisco ESA

C.

Cisco ISE

D.

Cisco Prime Infrastructure

Questions # 141:

What is a benefit of using Cisco Tetration?

Options:

A.

It collects telemetry data from servers and then uses software sensors to analyze flowinformation.

B.

It collects policy compliance data and process details.

C.

It collects enforcement data from servers and collects interpacket variation.

D.

It collects near-real time data from servers and inventories the software packages that exist onservers.

Questions # 142:

Which security control is required for identifying and neutralizing malicious code that attempts to execute on an endpoint?

Options:

A.

EPP

B.

XDR

C.

SWG

D.

CASB

Questions # 143:

Refer to the exhibit.

Question # 143

An engineer is implementing a network access control solution. Users can authenticate against the RADIUS server using 802.1X, and now the engineer wants to configure a downloadable access control list on the switchport using Cisco ISE. Which command must be used next on the Cisco Catalyst switch to complete the requirement?

Options:

A.

ip access-group ACL-NAME out

B.

switchport mode access

C.

authentication order mab dot1x

D.

radius-server vsa send authentication

Questions # 144:

Which open standard creates a framework for sharing threat intelligence in a machine-digestible format?

Options:

A.

OpenC2

B.

OpenlOC

C.

CybOX

D.

STIX

Questions # 145:

What is the primary difference between an Endpoint Protection Platform and an Endpoint Detection and

Response?

Options:

A.

EPP focuses on prevention, and EDR focuses on advanced threats that evade perimeter defenses.

B.

EDR focuses on prevention, and EPP focuses on advanced threats that evade perimeter defenses.

C.

EPP focuses on network security, and EDR focuses on device security.

D.

EDR focuses on network security, and EPP focuses on device security.

Questions # 146:

Which Cisco ASA Platform mode disables the threat detection features except for Advanced Threat Statistics?

Options:

A.

cluster

B.

transparent

C.

routed

D.

multiple context

Questions # 147:

A customer has various external HTTP resources available including Intranet. Extranet, and Internet, with a proxy configuration running in explicit mode Which method allows the client desktop browsers to be configured to select when to connect direct or when to use the proxy?

Options:

A.

Transparent mode

B.

Forward file

C.

PAC file

D.

Bridge mode

Questions # 148:

How does a Cisco Secure Firewall help to lower the risk of exfiltration techniques that steal customer data?

Options:

A.

Blocking UDP port 53

B.

Blocking TCP port 53

C.

Encrypting the DNS communication

D.

Inspecting the DNS traffic

Questions # 149:

What is the purpose of the Cisco Endpoint IoC feature?

Options:

A.

It is an incident response tool.

B.

It provides stealth threat prevention.

C.

It is a signature-based engine.

D.

It provides precompromise detection.

Questions # 150:

Which direction do attackers encode data in DNS requests during exfiltration using DNS tunneling?

Options:

A.

inbound

B.

north-south

C.

east-west

D.

outbound

Viewing page 10 out of 16 pages
Viewing questions 136-150 out of questions