75only - Ends in 0d 00h 00m 00s - Coupon code = 75only

Pass the Cisco CCNP Security 350-701 Questions and answers with Dumpstech

Exam 350-701 Premium Access

View all detail and faqs for the 350-701 exam

Practice at least 50% of the questions to maximize your chances of passing.
Viewing page 5 out of 16 pages
Viewing questions 61-75 out of questions
Questions # 61:

A company deploys an application that contains confidential data and has a hybrid hub-and-spoke topology. The hub resides in a public cloud environment, and the spoke resides on-premises. An engineer must secure the application to ensure that confidential data in transit between the hub-and-spoke servers is accessible only to authorized users. The engineer performs these configurations:

Segregation of duties

Role-based access control

Privileged access management

What must be implemented to protect the data in transit?

Options:

A.

MD5

B.

AES-256

C.

SHA-512

D.

TLS 1.3

Questions # 62:

Refer to the exhibit.

Question # 62

A site-to-site IKEv2 VPN between a Cisco Secure Firewall Threat Defense device with public IP address 203.0.113.10 and a third-party firewall with public IP address 198.51.100.20 is failing to establish at a logistics company. The engineer enables IKEv2 debugging on the FTD and captures the output. Which action must be performed to resolve the issue?

Options:

A.

Change the DH group in the IKEv2 policy from Group 20 to Group 14 to match the group negotiated during IKE_SA_INIT.

B.

Verify that the pre-shared key configured on the VPN peer object exactly matches the key on the remote peer, including case, special characters, and any leading or trailing spaces.

C.

Update the IKEv2 policy to remove SHA-384 and use only SHA-256, aligning Phase 1 integrity with the algorithm agreed upon during IKE_SA_INIT.

D.

Switch both peers to certificate-based authentication by enrolling an identity certificate from the corporate CA and sharing the CA certificate with the remote peer.

Questions # 63:

Which two capabilities of Cisco Secure Workload facilitate the detection of lateral movement within data-center and cloud environments? (Choose two.)

Options:

A.

Dynamic updates to firewall rules based on user access

B.

Integration with threat intelligence for identifying malicious IP addresses

C.

Automatic blocking of all inbound and outbound traffic

D.

Real-time visibility into communication patterns between workloads

E.

Recommendations for implementing VLANs for network segmentation

Questions # 64:

A network administrator configures Dynamic ARP Inspection on a switch. After Dynamic ARP Inspection is applied, all users on that switch are unable to communicate with any destination. The network administrator checks the interface status of all interfaces, and there is no err-disabled interface. What is causing this problem?

Options:

A.

DHCP snooping has not been enabled on all VLANs.

B.

The ip arp inspection limit command is applied on all interfaces and is blocking the traffic of all users.

C.

Dynamic ARP Inspection has not been enabled on all VLANs

D.

The no ip arp inspection trust command is applied on all user host interfaces

Questions # 65:

Which Dos attack uses fragmented packets to crash a target machine?

Options:

A.

smurf

B.

MITM

C.

teardrop

D.

LAND

Questions # 66:

What do tools like Jenkins, Octopus Deploy, and Azure DevOps provide in terms of application and

infrastructure automation?

Options:

A.

continuous integration and continuous deployment

B.

cloud application security broker

C.

compile-time instrumentation

D.

container orchestration

Questions # 67:

Refer to the exhibit.

Question # 67

The DHCP snooping database resides on router R1, and dynamic ARP inspection is configured only on switch SW2. Which ports must be configured as untrusted so that dynamic ARP inspection operates normally?

Options:

A.

P2 and P3 only

B.

P5, P6, and P7 only

C.

P1, P2, P3, and P4 only

D.

P2, P3, and P6 only

Questions # 68:

What are two differences between a Cisco WSA that is running in transparent mode and one running in explicit mode? (Choose two)

Options:

A.

The Cisco WSA responds with its own IP address only if it is running in explicit mode.

B.

The Cisco WSA is configured in a web browser only if it is running in transparent mode.

C.

The Cisco WSA responds with its own IP address only if it is running in transparent mode.

D.

The Cisco WSA uses a Layer 3 device to redirect traffic only if it is running in transparent mode.

E.

When the Cisco WSA is running in transparent mode, it uses the WSA ' s own IP address as the HTTP request destination.

Questions # 69:

An engineer is trying to securely connect to a router and wants to prevent insecure algorithms from being used.

However, the connection is failing. Which action should be taken to accomplish this goal?

Options:

A.

Disable telnet using the no ip telnet command.

B.

Enable the SSH server using the ip ssh server command.

C.

Configure the port using the ip ssh port 22 command.

D.

Generate the RSA key using the crypto key generate rsa command.

Questions # 70:

Which Cisco platform processes behavior baselines, monitors for deviations, and reviews for malicious processes in data center traffic and servers while performing software vulnerability detection?

Options:

A.

Cisco Tetration

B.

Cisco ISE

C.

Cisco AMP for Network

D.

Cisco AnyConnect

Questions # 71:

In which type of attack does the attacker insert their machine between two hosts that are communicating with each other?

Options:

A.

LDAP injection

B.

man-in-the-middle

C.

cross-site scripting

D.

insecure API

Questions # 72:

Drag and drop the cryptographic algorithms for IPsec from the left onto the cryptographic processes on the right.

Question # 72

Options:

Questions # 73:

Which baseline form of telemetry is recommended for network infrastructure devices?

Options:

A.

SDNS

B.

NetFlow

C.

passive taps

D.

SNMP

Questions # 74:

Which function is performed by certificate authorities but is a limitation of registration authorities?

Options:

A.

accepts enrollment requests

B.

certificate re-enrollment

C.

verifying user identity

D.

CRL publishing

Questions # 75:

What are two recommended approaches to stop DNS tunneling for data exfiltration and command and control call backs? (Choose two.)

Options:

A.

Use intrusion prevention system.

B.

Block all TXT DNS records.

C.

Enforce security over port 53.

D.

Use next generation firewalls.

E.

Use Cisco Umbrella.

Viewing page 5 out of 16 pages
Viewing questions 61-75 out of questions