You must be able to read a firewall or IPS scenario and predict the resulting action: which FMC rule action applies, how ASA MPF class-map and policy-map chain together, what a Snort rule detects, and whether a given FTD mode can block traffic. The critical point is knowing exactly when traffic is allowed, dropped, or only alerted.
Start practicing
Network Security — choose a session length
Free · No account required
Domain overview
Network Security is 20% of the 350-701 SCOR exam and covers enforcing policy on Cisco firewalls and IPS: FMC-managed FTD access control, ASA Modular Policy Framework, Snort rule actions and detection logic, and deployment modes like passive and inline. Questions are scenario-based, asking you to predict device behavior or name the correct configuration component.
Exam objectives
FMC access control rule actions on FTD, including Interactive Block versus Block and Allow
Cisco ASA Modular Policy Framework components: class-map, policy-map, and service-policy
Snort rule structure and detection types, including header actions and content matching
FTD deployment modes such as passive, inline, and routed, and their traffic-handling behavior
Confusing Interactive Block with Block: Interactive Block still permits the connection after showing a user warning page, while Block drops it outright.
Mixing up MPF class-map types: matching traffic with a class-map versus applying actions with a policy-map and activating it with service-policy.
Assuming a passive FTD can block or reset traffic; passive mode only monitors and alerts, it does not drop packets.
Click any question to see the full explanation and answer options, or start a focused practice session above.
An engineer is configuring a Cisco ASA and needs to ensure that traffic from the outside interface to a web server on the DMZ is allowed. The inside interface is security level 100 and the DMZ is level 50. The outside interface is level 0. Which statement about the default traffic flow is true?
2A network administrator is configuring NAT on a Cisco ASA to allow internal users to access the internet using a single public IP address. The internal network uses RFC 1918 addresses. Which type of NAT should be configured?
3A company uses Cisco Firepower Threat Defense (FTD) managed by FMC. They need to create an access control policy that allows traffic from specific source IPs to a web server, but blocks all other traffic. How should the rule base be ordered?
4A security administrator is investigating an alert from an IPS that detected a SQL injection attempt. The alert was triggered by a signature that looks for specific patterns in the traffic. What type of detection method is this?
5A Cisco Firepower administrator configures an access control policy with a rule that trusts traffic from a specific source network. What is the effect of the trust action on the traffic?
6An engineer is deploying a Cisco FTD in inline mode and wants to inspect SSL/TLS traffic using the 'decrypt-resign' action. What must be configured on the client devices to avoid certificate errors?
7A company is deploying Cisco AnyConnect SSL VPN and wants to enforce different access policies based on the endpoint's antivirus status. Which feature should be used?
8A Cisco ASA is configured with a site-to-site VPN using IKEv2. Which component defines the encryption and authentication algorithms for the IPsec tunnel?
9An engineer configures a Cisco FTD in a high-availability pair with active/standby failover. The primary unit fails, and the standby takes over. After the primary recovers, what must be done to ensure it resumes as active?
10A company uses Cisco Firepower with FMC and wants to block access to social media websites for all users. Which feature should be used to create this policy?
11A Cisco FTD is deployed in inline mode and configured with an access control policy. The policy includes rules with actions: Trust, Allow, Block, and Interactive Block. Which two statements about these actions are correct? (Choose two.)
12An engineer is configuring a Cisco ASA to support a DMZ segment. Which three of the following are best practices for DMZ design? (Choose three.)
13An administrator configures a Cisco ASA with an interface named 'inside' at security level 100 and 'outside' at security level 0. Which statement about traffic flow is true?
14A network engineer is configuring NAT on a Cisco ASA for internal servers to be accessible from the internet. One server (10.1.1.10) must always be reachable via a fixed public IP (203.0.113.10). Which NAT type should be used?
15Which Snort rule action causes the FTD to drop a packet and generate an alert?
16An organization needs to inspect traffic between two internal zones (e.g., HR and IT) on a Cisco FTD. Which deployment mode is appropriate?
17An administrator is configuring a site-to-site IKEv2 VPN between two Cisco ASAs. Which configuration component defines the encryption and authentication algorithms for the IPsec SA?
18What is the primary difference between signature-based and anomaly-based intrusion detection?
19An organization deploys Cisco FTD in a high-availability pair using active/standby. If the active unit fails, what happens to existing connections?
20A Cisco FMC administrator needs to create a file policy to detect malware in HTTP downloads. The policy should allow the file to be delivered if it is known clean, block if known malicious, and allow but capture for analysis if unknown. Which combination of actions is required?
21Which Cisco FTD feature provides application visibility and control (AVC) to identify and block applications like Facebook or Skype?
22An administrator configures a Cisco ASA with a DMZ interface at security level 50. Traffic from the inside (level 100) to the DMZ (level 50) is allowed by default. What additional configuration is needed to allow traffic from the DMZ to the inside?
23A security engineer is tuning Snort rules on a Cisco FTD to reduce false positives. Which action should be taken if a rule is generating alerts for legitimate traffic?
24An organization uses Cisco AnyConnect SSL VPN with DTLS enabled. What is the primary benefit of DTLS?
25A network architect is designing a DMZ for a web server that must be accessible from the internet. The server should not initiate connections to the internal network. Which firewall rule best achieves this?
26An engineer is configuring a Cisco ASA for site-to-site IKEv2 VPN with a VTI. Which two statements about VTI are true? (Choose two.)
27On a Cisco ASA, which table holds information about translated addresses for active connections?
28An engineer is tuning Snort signatures on a Cisco FTD to reduce false positives. A rule triggers on legitimate traffic that matches a known exploit pattern but is actually benign. Which tuning technique would be most appropriate to suppress the alerts without completely disabling the rule?
29A Cisco FTD is deployed in inline mode and is configured with a file policy to detect malware. When a file is transferred, the FTD computes a SHA-256 hash and checks it against AMP cloud. The cloud returns 'unavailable' for the hash. What action will the FTD take by default?
30Which type of VPN on Cisco ASA is typically used for site-to-site connectivity and encrypts all traffic between two sites?
31Which of the following is a characteristic of a stateful firewall like Cisco ASA?
32A Cisco FTD is configured with SSL/TLS inspection using the 'decrypt-known-key' method. Which traffic can be decrypted with this method?
33A network engineer is deploying a Cisco FTD in active/standby high availability. Which statement is true about the configuration synchronization?
34A company is designing a network segmentation strategy using firewalls. Which THREE considerations are important for a defense-in-depth approach?
35Which interface security level is assigned to the inside interface on a Cisco ASA by default?
36An engineer wants to configure NAT on a Cisco ASA such that multiple internal hosts share a single public IP address when accessing the internet. Which NAT type should be used?
37A Cisco FTD device managed by FMC is processing traffic. An access control rule is configured with the action 'Interactive Block'. What behavior does this action trigger?
38In a Snort intrusion detection rule, which part specifies the action to take when the rule matches?
39Which deployment mode allows a Cisco Firepower NGFW to inspect traffic without being in the direct forwarding path?
40A network engineer is configuring a site-to-site VPN between two Cisco ASAs using IKEv2. Which component defines the encryption and hash algorithms for Phase 2?
41An engineer observes that the Cisco ASA connection table shows a consistent number of entries for UDP traffic, but the xlate table shows no entries. What is the most likely reason?
42Which Cisco Firepower feature uses SHA-256 hashes to determine the disposition of files and block malware?
43On a Cisco ASA, which command applies a policy-map globally to all interfaces?
44A Cisco FTD device is configured with an SSL decryption rule using 'Decrypt - Known Key'. In which scenario is this action appropriate?
45In Cisco ASA modular policy framework, what is the function of a class-map?
46A security analyst is tuning Snort IPS rules to reduce false positives. Which TWO strategies are effective?
47An engineer is configuring a Cisco AnyConnect SSL VPN for remote access. Which TWO features are commonly used to control access based on endpoint security posture?
48A Cisco FTD device is deployed in inline mode and is configured with an access control policy that includes an Intrusion Policy set to 'Balanced Security and Connectivity' and a File Policy with Malware & File blocking enabled. Traffic from a host inside to an external server is allowed by an access control rule. The administrator notices that a file download (PDF) is being blocked even though the file has a good reputation. What is the most likely cause?
49An organization is deploying Cisco Firepower Threat Defense (FTD) in a high-availability (HA) pair in active/standby mode. Which statement about state synchronization is true?
50A security analyst is reviewing Snort rule output and sees an alert with the following details: action: alert, protocol: tcp, src: any, dst: any, content: 'malicious'. What type of detection is this rule using?
51A company uses Cisco Firepower Management Center (FMC) to manage multiple FTD devices. They want to create an access control policy that allows traffic from a specific user group (Active Directory) to access a web server on the internet, but blocks all other traffic from that group to the internet. Which identity source should be configured in FMC?
52A network architect is designing a DMZ for a web server farm. The ASA firewall will have three interfaces: inside (level 100), DMZ (level 50), and outside (level 0). They want to allow HTTP traffic from the internet to the DMZ web servers and also allow the web servers to initiate connections to the inside for database updates. What is the minimal ACL configuration to achieve this?
53A Cisco FTD administrator is configuring SSL/TLS inspection. They want to inspect encrypted traffic to an external website that uses a certificate signed by a public CA. Which SSL/TLS inspection action should be used to decrypt this traffic?
54An organization is deploying Cisco AnyConnect VPN with split tunneling. They want to ensure that only traffic destined for the corporate network goes through the VPN tunnel, while internet-bound traffic goes directly. Which configuration element on the ASA controls this?
55Which Cisco Firepower management option is used for on-box management of a single FTD device, without a separate management center?
56A security engineer is tuning an IPS to reduce false positives. They notice that legitimate traffic is triggering a signature for a worm that uses a specific HTTP GET request. The engineer wants to disable the signature for that specific traffic pattern but keep it enabled for other traffic. What is the best approach?
57A Cisco FTD device is configured with an access control policy that has multiple rules. The first rule is 'Allow' for all traffic from the internal network to the internet. The second rule is 'Block' for traffic from a specific internal host to any destination. However, the administrator notices that the specific host can still access the internet. What is the most likely cause?
58A company is using Cisco ASA with AnyConnect VPN. They want to implement Dynamic Access Policy (DAP) to enforce access based on device compliance. Which two attributes can DAP use to evaluate endpoint posture? (Choose two.)
59A network engineer is configuring a Cisco ASA to use the Modular Policy Framework (MPF) for advanced traffic inspection. Which three components are part of the MPF? (Choose three.)
60A security analyst is investigating a potential intrusion and suspects that the IPS is missing some attacks (false negatives). Which two factors can contribute to false negatives in signature-based IPS? (Choose two.)
61A network administrator is configuring site-to-site VPN between two Cisco ASA firewalls using IKEv2. The administrator wants to ensure that the VPN tunnel uses the most secure encryption algorithm available. Which encryption algorithm should be selected in the IKEv2 proposal?
62Which statement accurately describes the difference between signature-based and anomaly-based intrusion detection?
63An engineer is configuring Cisco Firepower Threat Defense (FTD) in inline NGFW mode. The access control policy must block all traffic from geolocation 'North Korea' and allow all other traffic. Which type of rule should be used and in what order should it be placed?
64In Cisco Firepower Management Center (FMC), which action in an access control rule will send a TCP RST to the source and destination and log the event?
65A Cisco ASA is configured with dynamic PAT to translate internal addresses to a single outside IP address. A user on the inside initiates a connection to an external web server. The ASA creates a connection entry. Which table is checked first when a return packet arrives from the web server?
66An FTD device is deployed in passive mode. Which statement about its traffic processing is true?
67Which of the following is a benefit of using Dynamic Access Policy (DAP) for AnyConnect SSL VPN?
68In Cisco Firepower, a file policy is configured with a rule that detects malware. The action is set to 'Malware Cloud Lookup'. What happens if the SHA-256 hash of a file is unknown to the AMP cloud?
69Which component of a Snort rule specifies the action to take when the rule conditions are matched?
70An engineer wants to configure high availability on a pair of Cisco Firepower Threat Defense (FTD) devices. Which HA mode supports active/standby failover with stateful replication of connection information?
71In Cisco Firepower, an access control policy has multiple rules. Rule 1: Allow HTTP from any to any. Rule 2: Block HTTP from 10.0.0.0/8 to any. A packet from 10.0.0.1 to 192.168.1.1 with destination port 80 is inspected. What action is taken?
72Which of the following is a characteristic of a 'false negative' in intrusion detection?
73A network security engineer is configuring Cisco ASA for remote access VPN using AnyConnect. Which two components must be configured to enable split tunneling? (Choose two.)
74An engineer needs to allow inbound HTTP traffic from the internet to a web server in the DMZ on a Cisco ASA. The DMZ interface security level is 50, and the outside interface is 0. Which interface direction should the access control entry be applied?
75A network administrator is configuring a site-to-site VPN between two Cisco ASA firewalls using IKEv2. Which component defines the encryption and authentication algorithms for the IPsec SA?
76A Cisco FTD device is deployed inline and configured with an access control policy that includes a rule to block traffic from a specific source IP address. However, traffic from that IP is still passing through. What is the most likely cause?
77On a Cisco ASA, which NAT type allows multiple internal hosts to share a single public IP address by using different source ports?
78A security engineer is configuring a Cisco FTD high availability pair in active/standby mode. Which statement is true about the failover configuration?
79A Cisco ASA is configured with a modular policy framework to inspect HTTP traffic. The class-map matches HTTP traffic, and the policy-map applies inspection. Which command correctly applies the policy to an interface?
80Which Cisco Firepower management option allows direct device management without a separate server, using a web interface on the FTD itself?
81An engineer wants to block traffic from a specific country on a Cisco FTD. Which feature should be used in the access control policy?
82A Cisco FTD is configured with a file policy to detect malware. The policy includes a rule to block files with a SHA-256 hash that is known to be malicious. Which component provides the SHA-256 disposition?
83Which VPN technology allows Cisco AnyConnect clients to use UDP for transport to avoid TCP overhead and improve performance?
84An engineer is tuning an IPS on a Cisco FTD to reduce false positives. Which three techniques are effective? (Choose three.)
85An organization is using Cisco FMC with FTD devices. They want to detect and block malware in HTTP traffic. Which policy component must be configured to inspect files and submit SHA-256 hashes to AMP cloud for disposition?
86Which of the following is a characteristic of anomaly-based intrusion detection compared to signature-based detection?
87A network security engineer is configuring site-to-site IPsec VPN between two Cisco ASA firewalls using IKEv2. Which of the following configuration elements is required to define the encryption and integrity algorithms for the IPsec SA?
88In a Cisco FTD deployment, which management option allows on-box management without the need for a separate FMC server?
89A network security engineer is deploying a Cisco Firepower Threat Defense (FTD) device in a high-availability active/standby pair. The engineer wants to ensure that the standby unit can take over immediately if the active unit fails, without dropping existing connections. Which feature should be configured to meet this requirement?
90A security administrator is deploying a Cisco Firepower Threat Defense (FTD) device managed by a Firepower Management Center (FMC) in a high-availability pair. The administrator wants to ensure that if the primary FTD fails, the secondary takes over with minimal disruption. Which failover configuration should be used?
91A security engineer is configuring a Cisco Identity Services Engine (ISE) to authenticate employees using 802.1X. The engineer wants to ensure that only domain-joined Windows computers are allowed on the network, while personal devices are denied. Which ISE feature should be used to achieve this?
92A security engineer is deploying Cisco Identity Services Engine (ISE) to enforce 802.1X wired authentication for corporate laptops and MAB for printers. The engineer must ensure that the corporate laptops are placed into the correct VLAN after authentication, while printers are placed into a quarantine VLAN until they are profiled. Which ISE policy element should be configured to dynamically assign the VLAN to the switch port?
93A security engineer is configuring a Cisco Firepower Threat Defense (FTD) device managed by Firepower Management Center (FMC). The engineer wants to ensure that all traffic from the 10.10.10.0/24 network to any destination on port 443 is inspected by the Snort engine and also logged to the FMC. The access control policy currently has a default action of 'Block'. Which configuration step must be taken to achieve this requirement?
94A security engineer is configuring a Cisco Firepower Threat Defense (FTD) device managed by Firepower Management Center (FMC). The engineer needs to inspect traffic for a specific application and block it, while allowing all other traffic. The application uses dynamic ports and can be identified by its payload. Which FMC feature should be used to achieve this?
95An engineer is configuring a Cisco ASA firewall to allow external users to access an internal web server using HTTPS. The internal server IP is 10.1.1.10, and the public IP is 203.0.113.5. Which ASA feature should be configured to map the public IP to the internal server?
96A security administrator is configuring Cisco TrustSec on a switch and wants to assign a Security Group Tag (SGT) to traffic based on the user's identity without relying on 802.1X supplicant configuration on the endpoint. Which feature should be used to dynamically assign the SGT?
97An engineer is deploying Cisco Umbrella for DNS-layer security. The engineer wants to block access to malicious domains for all users on the corporate network without installing any software on endpoints. Which deployment method should be used?
98A network security engineer is deploying Cisco Identity Services Engine (ISE) to enforce endpoint compliance. The engineer wants to check that endpoints have the latest antivirus definitions and OS patches before allowing network access. Which ISE feature should be used to perform this check?
99An engineer is deploying Cisco Firepower Threat Defense (FTD) managed by Firepower Management Center (FMC) and must ensure that management traffic between FTD and FMC is protected. The FTD management interface is on a separate management network. Which configuration on the FTD is required to secure the FMC-to-FTD management connection?
100An administrator is configuring a Cisco ASA firewall for AnyConnect VPN. The administrator wants to ensure that after a user authenticates, the VPN session is terminated if the endpoint does not have the latest antivirus signature. Which ASA feature should be configured?
101A security administrator is configuring Cisco Umbrella to block malicious domains for an organization. The administrator wants to ensure that DNS requests from roaming users are filtered even when they are off the corporate network. Which Umbrella component should be deployed on the roaming endpoints?
102A network administrator is configuring a Cisco ASA firewall for VPN load balancing. The administrator wants to distribute incoming AnyConnect VPN sessions across multiple ASA devices in a cluster. Which feature should be configured?
103A network security engineer is configuring a Cisco ASA to support AnyConnect VPN clients. The ASA uses a self-signed certificate for the outside interface. Remote users report that they cannot establish the VPN connection and receive a certificate warning. The engineer wants to eliminate the warning and ensure proper certificate validation. Which action should be taken?
104A security analyst is investigating alerts in Cisco Stealthwatch. The analyst notices a large number of flows from an internal host to multiple external IP addresses on port 445. The analyst suspects a worm infection. Which Stealthwatch feature should be used to quickly identify the internal host and its peers?
105A network security administrator is configuring a Cisco Firepower Threat Defense (FTD) device managed by FMC to inspect traffic traversing an inline set. The administrator wants to ensure that packets that fail to match any access control rule are logged and blocked. Which action should be configured as the default action in the access control policy?
106A network engineer is configuring 802.1X authentication on Cisco switches. The engineer wants to ensure that if the RADIUS server becomes unreachable, authenticated endpoints remain connected while new endpoints are denied access. Which feature should be configured?
107A security administrator is configuring Cisco Identity Services Engine (ISE) for wired 802.1X authentication. The administrator wants to ensure that devices that do not support 802.1X supplicants can still access the network after being profiled. Which ISE feature should be configured to allow these devices to authenticate using their MAC address?
108A security engineer is configuring Cisco Identity Services Engine (ISE) for wired 802.1X authentication. The engineer wants to ensure that if the RADIUS server is unavailable, the switch allows devices to connect to a limited VLAN for remediation. Which feature should be configured on the switch?
109A network security engineer is configuring a Cisco Firepower Threat Defense (FTD) device managed by Firepower Management Center (FMC). The engineer wants to inspect traffic for threats but also needs to ensure that traffic is not blocked due to false positives during the tuning phase. Which action should be selected in the access control rule?
110A network security engineer is implementing Cisco TrustSec in a campus network. The engineer needs to enableSecurity Group Tagging (SGT) on Cisco Catalyst switches to classify traffic. Which two methods can be used to assign SGTs to packets? (Choose two.)
111A security analyst is investigating alerts generated by Cisco Stealthwatch. The analyst notices a high volume of alerts indicating data exfiltration attempts from an internal host to an external IP address. The analyst wants to quickly identify the application protocol being used for the exfiltration. Which Stealthwatch feature should the analyst use to determine the application protocol?
112A security administrator is deploying Cisco AnyConnect for remote access VPN on Cisco ASA. The administrator wants to ensure that the VPN connection uses certificate-based authentication for the headend and also allows users to authenticate with username and password. Which two configurations are required on the ASA to support this? (Choose two.)
113A network security engineer is deploying a Cisco FTD device managed by FMC. The organization requires that outbound HTTP traffic be scanned for malware, but the security team wants to avoid decrypting traffic that contains sensitive personal health information. Which FTD feature should be configured to prevent decryption of specific traffic based on URL categories while still allowing the connection?
114An engineer is configuring a Cisco FTD device to inspect traffic between two internal networks. The engineer wants to ensure that the FTD can block malicious traffic based on the latest threat intelligence without manual updates. Which FTD feature should be configured?
115A network security engineer is troubleshooting a Cisco FTD device that is not blocking traffic that should be denied by an access control rule. The rule is configured to block traffic from a specific source IP to a specific destination IP. The engineer verifies that the rule is enabled and placed correctly in the policy. What is the most likely reason the traffic is not being blocked?
You must be able to read a firewall or IPS scenario and predict the resulting action: which FMC rule action applies, how ASA MPF class-map and policy-map chain together, what a Snort rule detects, and whether a given FTD mode can block traffic. The critical point is knowing exactly when traffic is allowed, dropped, or only alerted.
The Courseiva 350-701 question bank contains 115 questions in the Network Security domain, covering the 20% of the exam attributed to this domain in the official Cisco blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Network Security domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included