Cisco · Free Practice Questions · Last reviewed May 2026
36real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
A company is moving its on-premises applications to AWS EC2 instances. According to the shared responsibility model, which of the following is the customer's responsibility?
Hypervisor security
Network infrastructure hardening
Patching the guest operating system
Under the shared responsibility model, AWS secures the hypervisor, host infrastructure and physical facilities, while the customer retains control of everything from the guest OS upward. Patching the guest operating system on EC2 instances therefore falls to the customer, satisfying the scenario's requirement to identify customer-side duties.
Physical security of the data center
An organization uses multiple SaaS applications and wants to enforce data loss prevention (DLP) policies to prevent sensitive data from being shared externally. Which cloud security solution should be deployed?
Cloud Access Security Broker (CASB)
A CASB sits between users and SaaS applications, providing visibility and enforcing DLP policies that detect and block sensitive data leaving the organisation. It satisfies the requirement to prevent external sharing across multiple SaaS apps through inline inspection and policy control.
Web Application Firewall (WAF)
Cloud Security Posture Management (CSPM)
Cloud Workload Protection Platform (CWPP)
An organization wants to implement zero trust principles for cloud access. Which of the following is a key component of a zero trust architecture in the cloud?
Site-to-site VPN to cloud
Strong perimeter firewall
Multi-factor authentication (MFA) for all access
MFA verifies identity per session rather than trusting network perimeter, matching zero trust's verify-explicitly principle. Each cloud access request requires a second factor, so stolen credentials alone fail. This satisfies the stem's requirement for a key zero-trust component controlling all access.
Single sign-on with one password
Which of the following is the primary function of a Cloud Security Posture Management (CSPM) tool?
Block malicious domains at the DNS layer
Protect workloads from malware
Monitor and remediate cloud misconfigurations against benchmarks
CSPM continuously compares cloud resource configurations against security benchmarks such as CIS, detecting drift and misconfigurations, then triggering remediation. This directly satisfies the requirement to identify and fix insecure settings across cloud accounts, rather than inspecting runtime workloads or network traffic.
Provide DLP for SaaS applications
A company uses Cisco Umbrella to provide DNS-layer security. An employee tries to visit a website that is hosting malware, but the domain is not yet categorized. How does Umbrella handle this request?
The request is redirected to a captive portal for user awareness
The request is allowed because the domain is not categorized
The request is blocked if the domain is identified as malicious by Umbrella's threat intelligence
Umbrella's threat intelligence is applied at the DNS layer regardless of category, so an uncategorised domain already flagged as malicious is blocked before any connection occurs. This satisfies the scenario where the domain lacks a category but is known malicious.
The request is proxied through the intelligent proxy for inspection
An organization is deploying containerized applications in a Kubernetes cluster on AWS EKS. They need to ensure that container images are scanned for vulnerabilities before deployment. Which approach aligns with DevSecOps best practices?
Scan container images after deployment using a runtime scanner
Integrate image scanning into the CI/CD pipeline before pushing to registry
Scanning within the CI/CD pipeline catches vulnerabilities before the image reaches the registry, enabling the build to fail early. This shift-left approach satisfies the requirement that images be scanned prior to deployment, rather than after they are already available.
Manually review images before deployment
Only scan base images, not application layers
Want more Cloud Security practice?
Practice this domainAn engineer is configuring a Cisco ASA and needs to ensure that traffic from the outside interface to a web server on the DMZ is allowed. The inside interface is security level 100 and the DMZ is level 50. The outside interface is level 0. Which statement about the default traffic flow is true?
Traffic from outside to DMZ is allowed implicitly because the ASA inspects all interfaces equally.
Traffic from outside to DMZ is denied implicitly because outside level is lower than DMZ level.
ASA default behaviour permits traffic from higher to lower security levels and denies lower to higher. Outside (0) to DMZ (50) flows from lower to higher, so it is implicitly denied unless an explicit ACL permits it, matching the stated level comparison.
Traffic from outside to DMZ is allowed implicitly because outside is level 0 and DMZ is level 50.
Traffic from outside to DMZ is allowed implicitly because both are lower than inside.
A network administrator is configuring NAT on a Cisco ASA to allow internal users to access the internet using a single public IP address. The internal network uses RFC 1918 addresses. Which type of NAT should be configured?
Dynamic NAT
Static NAT
Identity NAT
PAT (Port Address Translation)
PAT maps many internal RFC 1918 addresses to one public IP using unique source ports, satisfying the single-public-address constraint. Static NAT and dynamic NAT without overload require a pool of public addresses, so they cannot serve the whole internal network through one registered IP.
A company uses Cisco Firepower Threat Defense (FTD) managed by FMC. They need to create an access control policy that allows traffic from specific source IPs to a web server, but blocks all other traffic. How should the rule base be ordered?
Place the block rule first, then the permit rule.
Place the permit rule first, then the block rule.
FTD evaluates access control rules top-down and stops at the first match, so the specific permit rule for the web server's source IPs must precede the block rule. Ordering the block rule first would deny that traffic before the permit is ever evaluated.
Use a single rule with permit and block conditions combined.
Order does not matter because FMC processes rules in parallel.
A security administrator is investigating an alert from an IPS that detected a SQL injection attempt. The alert was triggered by a signature that looks for specific patterns in the traffic. What type of detection method is this?
Signature-based detection
Signature-based detection matches traffic against predefined patterns representing known attack strings, exactly as the stem describes. The SQL injection signature inspects packet payloads for those specific patterns, so the alert is triggered by pattern matching rather than anomaly or behaviour analysis.
Behavioral detection
Heuristic detection
Anomaly-based detection
A Cisco Firepower administrator configures an access control policy with a rule that trusts traffic from a specific source network. What is the effect of the trust action on the traffic?
The traffic is blocked and logged.
The traffic is allowed without further inspection.
The trust action in a Firepower access control rule bypasses further intrusion and file inspection for matching traffic, forwarding it immediately. This satisfies the scenario where traffic from a trusted source network is allowed without additional deep inspection.
The traffic is allowed and inspected by the intrusion policy.
The traffic is allowed but subject to file policy.
An engineer is deploying a Cisco FTD in inline mode and wants to inspect SSL/TLS traffic using the 'decrypt-resign' action. What must be configured on the client devices to avoid certificate errors?
Disable certificate validation on all client browsers.
Install the organization's CA certificate in the client's trusted root store.
Decrypt-resign makes the FTD re-sign inspected traffic with its own CA-generated certificate, so clients see an untrusted issuer. Adding that organisation CA certificate to each device's trusted root store restores trust and prevents browser certificate warnings during TLS inspection.
Install the FTD's self-signed certificate on each client.
Use 'decrypt-known-key' instead, which does not require client configuration.
Want more Network Security practice?
Practice this domainWhich security model requires that all subjects and devices are untrusted by default, and access is granted only after verification, regardless of the network location?
Least Privilege
Defense in Depth
CIA Triad
Zero Trust
Zero Trust assumes no implicit trust based on network location, verifying every subject and device before granting access. This directly satisfies the requirement that all entities remain untrusted by default regardless of where they connect.
An organization wants to ensure that digital certificates issued by its internal CA are validated for revocation in real-time. Which protocol should be implemented to allow clients to check certificate status without downloading a full CRL?
SCEP
EST
OCSP
OCSP queries a responder for the revocation status of a single certificate, returning a real-time response without downloading the full CRL. This satisfies the requirement for immediate revocation checking while avoiding the latency and bandwidth cost of CRL retrieval.
CRL
During a penetration test, an attacker sends a malicious payload to a web application that causes the server to execute arbitrary SQL commands on the backend database. Which type of attack is being performed?
Cross-Site Request Forgery (CSRF)
Buffer Overflow
Cross-Site Scripting (XSS)
SQL Injection
Untrusted input reaching the database layer lets the attacker inject SQL syntax that the backend executes as commands, so the web application performs arbitrary queries against the database. This injection flaw matches the stem's arbitrary SQL execution constraint directly.
A security administrator is configuring a Cisco Firepower NGFW to detect and block application-layer DDoS attacks. Which type of DDoS attack is characterized by overwhelming a server with incomplete HTTP requests, causing resource exhaustion?
UDP Flood
ICMP Flood
Slowloris
Slowloris opens many partial HTTP connections and holds them open with incomplete headers, exhausting the server's connection pool without high bandwidth. Firepower's application-layer inspection detects these prolonged half-open sessions, satisfying the requirement to block resource-exhaustion attacks that evade volumetric thresholds.
SYN Flood
Which cryptographic algorithm is considered deprecated and should be avoided due to known vulnerabilities, especially when used in digital signatures and certificate signing?
SHA-256
SHA-3
AES-256
MD5
MD5 produces 128-bit hashes and suffers practical collision attacks, so forged inputs can share a digest. This breaks signature and certificate integrity guarantees, making it the deprecated algorithm the stem seeks when digital signatures and certificate signing are involved.
An attacker uses ARP spoofing to intercept traffic between two devices on the same subnet. After successfully becoming a man-in-the-middle, the attacker can then perform which further attack to downgrade HTTPS connections to HTTP?
SSL stripping
SSL stripping intercepts the victim's HTTP request before TLS negotiation and rewrites HTTPS links to HTTP, proxying the session so the padlock never appears. This downgrade attack is only possible after ARP spoofing has placed the attacker in the path.
Session hijacking
DNS cache poisoning
Typosquatting
Want more Security Concepts practice?
Practice this domainA security administrator notices that a significant volume of spam is bypassing the Cisco ESA's anti-spam filters. Upon investigation, they find that the messages have a mid-range SBRS score of 5.0. Which action should the administrator take to improve spam detection?
Change the SBRS score interpretation to positive
Lower the SBRS threshold to 3.0
Increase the SBRS threshold to 7.0
Raising the threshold to 7.0 means any message with an SBRS below 7.0 is classified as spam. Since the problematic messages have a score of 5.0, they would now be caught, improving spam detection.
Disable SenderBase reputation checks
A Cisco WSA administrator wants to block access to social media sites for all users during work hours. The proxy is deployed in explicit mode. Which policy type should the administrator use to enforce this restriction?
Access policy
Access policies in explicit mode define who may reach which categories and are evaluated per user request, so blocking social media during work hours is enforced by a time-based access policy rule rather than identification or decryption profiles.
Identity policy
Routing policy
Decryption policy
Which Cisco content security solution uses DNS to block access to malicious domains and provides cloud-based proxy protection?
Cisco WSA
Cisco ESA
Cisco Firepower NGFW
Cisco Umbrella
Cisco Umbrella resolves DNS requests through its global recursive resolvers, blocking malicious domains before any connection is made, and layers cloud-delivered proxy inspection for content and URL filtering. This DNS-layer enforcement satisfies the requirement for cloud-based proxy protection.
A company is implementing DMARC for its domain. The administrator wants to instruct receivers to reject emails that fail SPF or DKIM checks. Which DMARC policy should the administrator set?
p=quarantine
p=none
p=reject
The p=reject policy instructs receiving mail servers to reject messages failing SPF or DKIM alignment outright, satisfying the requirement to reject rather than quarantine or monitor. p=quarantine only diverts to spam, and p=none merely reports.
p=deny
Which Cisco WSA feature allows administrators to control bandwidth usage per user or group by limiting the amount of bandwidth consumed for specific applications?
URL filtering
AVC (Application Visibility and Control)
Bandwidth controls
Bandwidth controls in Cisco WSA let administrators cap throughput consumed by specific applications, applied per user or group. This directly satisfies the stem's requirement to limit bandwidth usage per user or group for chosen applications, rather than merely blocking or allowing them.
Decryption policies
A security analyst receives an alert that a user clicked a link in an email that led to a malicious website. The email was allowed by the Cisco ESA because it passed SPF, DKIM, and DMARC checks. Later analysis reveals the email was sent from a compromised account within the same domain. Which type of attack best describes this scenario?
Account takeover (BEC)
SPF, DKIM and DMARC all pass because the message genuinely originated from the same domain, so authentication cannot detect it. The compromised internal mailbox sending the malicious link is account takeover, specifically business email compromise, matching the scenario's insider-origin characteristic.
Malspam
Spear phishing
Whaling
Want more Content Security practice?
Practice this domain15% of exam · 6 sample questions below
A company is deploying Cisco ISE for guest access. They want to provide a self-service portal where guests can register their devices and receive a temporary username and password. Which ISE component is used to accomplish this?
BYOD Portal
Mobile Device Management (MDM)
Guest Portal
The Guest Portal is the ISE persona that hosts the self-service registration page, letting guests create their own accounts and receive temporary credentials. It satisfies the requirement for guest self-registration by binding the web portal to the guest sponsor and guest access policies.
Profiler Service
A network administrator wants to implement 802.1X on a Cisco switch port for a device that does not support 802.1X. Which feature should be configured to allow the device to connect?
802.1X with EAP-MSCHAPv2
Downloadable ACL (dACL)
Web Authentication (WA)
MAC Authentication Bypass (MAB)
MAB authenticates the device by its MAC address against a RADIUS server, allowing non-802.1X-capable devices to gain port access. Configuring MAB as a fallback on the switch port satisfies the stem's constraint that the connecting device does not support 802.1X supplicant authentication.
An organization is using Cisco ISE to enforce posture compliance. Endpoints that are non-compliant should be placed into a quarantine VLAN. Which ISE policy component is used to assign the VLAN?
Authorization profile
The authorization profile holds the VLAN and dACL settings that ISE returns in the RADIUS Access-Accept. Assigning the quarantine VLAN to non-compliant endpoints is done by referencing that VLAN in the authorization profile, satisfying the posture requirement.
Policy set
Profiling policy
Authentication policy
A security engineer is configuring Cisco ISE to enforce SGT-based access control. The engineer creates an SGACL on the switch that permits traffic from SGT 10 to SGT 20. However, traffic from SGT 10 to SGT 20 is still being dropped. The engineer verifies that the SGTs are correctly assigned. What is a possible reason for the drop?
SXP is not configured
The CTRL protocol is not enabled
The PAC on the switch is expired
There is a deny SGACL with a higher priority that matches the traffic
SGACL enforcement evaluates all matching entries by priority, and the first match wins. A deny rule with a higher priority than the permit for SGT 10 to SGT 20 is evaluated first, so the traffic is dropped despite the correct permit existing.
Which THREE of the following are required for a successful 802.1X authentication on a Cisco switch? (Choose THREE)
Security Group Tag (SGT) must be assigned
A downloadable ACL (dACL) must be configured on ISE
The switch must be configured as a RADIUS client to ISE
The switch acts as the authenticator, forwarding EAP frames to ISE as a RADIUS client, so RADIUS client configuration with the shared secret is mandatory. Without it, the switch cannot relay authentication requests to the external server.
The switch port must be configured with 'authentication port-control auto'
Configuring `authentication port-control auto` places the switch port in the 802.1X-controlled state, so the port forwards only EAPOL traffic until the supplicant authenticates successfully. Without this command the port stays unauthorised, blocking the Extensible Authentication Protocol exchange the stem requires for successful authentication.
The endpoint must have a valid credential (certificate or password)
A valid credential is the supplicant's identity proof, which the endpoint transmits inside EAPoL frames for the authenticator to relay to RADIUS. Without it, Microsoft Entra ID or any authentication server cannot verify identity, so the switch port stays unauthorised in the closed state. This satisfies the stem's requirement for endpoint-side authentication material.
Which TWO of the following are features of Cisco TrustSec? (Choose TWO)
Security Group Tag Exchange Protocol (SXP)
SXP propagates Security Group Tags between TrustSec domains and legacy network devices that cannot natively carry SGTs in hardware. It satisfies the requirement by enabling tag transport across non-TrustSec-capable hops, preserving group-based policy enforcement end to end.
Security Group Tag (SGT) assignment
SGT assignment tags a packet with the source's security group, enabling group-based policy enforcement without IP-based ACLs. It satisfies the requirement by classifying traffic at ingress so downstream devices apply role-based rules, which is a core TrustSec function.
IPsec VPN
Network Access Control (NAC)
802.1X authentication
Want more Secure Network Access, Visibility and Enforcement practice?
Practice this domain10% of exam · 6 sample questions below
A security administrator notices that several endpoints in the finance department are exhibiting unusual network behavior, including connections to known malicious IP addresses. The administrator has deployed Cisco Secure Endpoint (formerly AMP for Endpoints) with TETRA and has enabled the built-in firewall. What is the best course of action to quickly identify the root cause and contain the threat?
Disable the built-in firewall on the endpoints to allow full traffic inspection by the TETRA engine.
Use the Cisco Secure Endpoint console to review the TETRA engine's real-time traffic analysis and isolate the affected endpoints.
Reviewing TETRA's continuous file and traffic telemetry in the Cisco Secure Endpoint console exposes the root cause, while the console's endpoint isolation function cuts the malicious connections without disrupting other finance hosts. This directly satisfies the stem's requirement to identify the cause quickly and contain the threat.
Wait for the weekly threat report from Cisco Talos to identify the malware family and then apply a signature update.
Uninstall the Cisco Secure Endpoint connector and reinstall it with a fresh policy.
An organization wants to prevent malware from executing on endpoints by using a file reputation service. Which Cisco technology provides cloud-based file reputation and analysis for endpoint protection?
Cisco Stealthwatch
Cisco Identity Services Engine (ISE)
Cisco Firepower NGFW
Cisco Secure Endpoint (AMP for Endpoints)
Cisco Secure Endpoint (AMP for Endpoints) queries Cisco Talos cloud intelligence for file reputation and retrospective verdicts, blocking known malware before execution. This cloud-based reputation service directly satisfies the stem's requirement to prevent malware executing on endpoints.
A company is deploying Cisco Secure Endpoint and wants to ensure that endpoints are protected against zero-day exploits. Which two features should be enabled to provide this protection? (Choose two.)
File Reputation
Exploit Prevention
Exploit Prevention blocks memory-corruption techniques such as heap spraying and return-oriented programming, defeating exploitation attempts before a signature exists. This directly satisfies the zero-day constraint, since unknown threats cannot be matched by signature-based detection. It complements behavioural analysis by stopping the exploit primitive itself rather than waiting for malicious payload execution.
Malware Analytics (sandboxing)
Malware Analytics submits suspicious files to a cloud sandbox, detonating them in an isolated environment to observe behaviour. This detects previously unknown zero-day exploits through behavioural indicators rather than signatures, satisfying the requirement for protection against threats with no existing signature.
Application Control
Device Control
A company with 5,000 endpoints is using Cisco Secure Endpoint. The security team receives an alert that a specific file (SHA256: 8f4a...b2c) has been detected as malware on 10 endpoints. The file has been quarantined on those endpoints. The team wants to ensure that no other endpoints in the organization have this file. Which feature should be used to locate the file across all endpoints?
The Policy editor with file blacklist
Orbital Advanced Search
Orbital Advanced Search runs real-time SQL-like queries across all endpoints' telemetry, letting the team hunt for the specific SHA256 hash enterprise-wide. This satisfies the constraint of locating the quarantined file on any remaining endpoints beyond the ten already detected.
TETRA traffic analysis
The AMP Dashboard with event filters
Which TWO configuration steps are required to enable Cisco AMP for Endpoints to use the Threat Grid appliance for file analysis?
Configure the AMP connector policy to submit files to the on-premises Threat Grid appliance.
The AMP connector policy must be configured so endpoints submit files for analysis to the on-premises Threat Grid appliance rather than the public cloud. This satisfies the stem's requirement to direct file submission to the local appliance.
Enable SSL decryption in the AMP connector policy.
Register the Threat Grid appliance in the AMP cloud as a private analysis provider.
The Threat Grid appliance must be registered in the AMP cloud as a private analysis provider, establishing the trust relationship and identifier the cloud uses to route submissions. This satisfies the stem's requirement enabling on-premises appliance integration.
Ensure the firewall allows inbound traffic to the Threat Grid appliance from the internet.
Install the Cisco Threat Grid Connector on each endpoint.
A security engineer is deploying Cisco AMP for Endpoints to protect against malware. The company wants to block all executables from running in the Downloads folder except those signed by a specific trusted publisher. Which policy configuration should the engineer use?
Use the default malware protection policy, which automatically blocks untrusted executables in Downloads.
Create an Application Control rule to block all executables in the Downloads folder and add an exception for the trusted publisher.
Application Control enforces allowlisting by publisher signature, so blocking all Downloads executables while permitting the trusted publisher's signed binaries satisfies both constraints in one rule. Signature-based exceptions operate at execution, unlike simple path blocking, which cannot distinguish publishers.
Configure an Exclusion for the Downloads folder and then use a Custom Detection for untrusted executables.
Enable Simple Custom Detections with the SHA-256 hashes of all known executables.
Want more Endpoint Protection and Detection practice?
Practice this domainThe 350-701 exam has 90 questions and must be completed in 120 minutes. Cisco passing scores vary by exam version and are not always publicly listed. Check the official Cisco exam page before booking.
CLI output interpretation, network topology analysis, routing behaviour, switching concepts, troubleshooting, and configuration questions.
The exam covers 6 domains: Cloud Security, Network Security, Security Concepts, Content Security, Secure Network Access, Visibility and Enforcement, Endpoint Protection and Detection. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official Cisco 350-701 exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.