Reinforce 350-701 concepts with active-recall study cards covering all 6 blueprint domains. Each card shows the question on the front and the correct answer with a full explanation on the back.
Flashcards work through active recall — the process of retrieving information from memory rather than passively re-reading it. Research consistently shows that active recall produces stronger, longer-lasting memory than re-reading study guides. For 350-701 preparation, this means flashcards are one of the highest-return study tools available.
Attempt recall first
Read the 350-701 question on each card, pause, and attempt to formulate the answer in your own words before revealing. This retrieval attempt — even if wrong — dramatically strengthens memory compared to immediately reading the answer.
Review wrong cards again
When you get a card wrong, note it and add it back to your review pile. Spaced repetition — seeing difficult cards more frequently — is the mechanism that makes flashcard study far more efficient than linear reading.
Study by domain
Group your 350-701 flashcard sessions by domain for the first 3–4 weeks. Master one domain before moving to the next. In the final week, shuffle all cards together to test cross-domain recall — which is what the real 350-701 exam requires.
Short sessions beat marathon reviews
20–30 flashcard cards per session, done daily, produces better retention than a single 200-card marathon session. Five short daily sessions per week over 4 weeks gives you over 400 total card reviews — enough to reliably pass 350-701.
Sample cards from the 350-701 flashcard bank. Read the question, think of the answer, then read the explanation below.
A company is moving its on-premises applications to AWS EC2 instances. According to the shared responsibility model, which of the following is the customer's responsibility?
Patching the guest operating system
In IaaS, the cloud provider manages the physical infrastructure (hosts, network, hypervisor), while the customer is responsible for securing the guest OS, applications, and data. Patching the OS is a customer responsibility.
An organization uses multiple SaaS applications and wants to enforce data loss prevention (DLP) policies to prevent sensitive data from being shared externally. Which cloud security solution should be deployed?
Cloud Access Security Broker (CASB)
A Cloud Access Security Broker (CASB) is deployed to enforce security policies, including DLP, for cloud applications and services. It acts as an intermediary between users and SaaS applications, providing visibility and control to prevent sensitive data from being shared externally.
An engineer is configuring a Cisco ASA and needs to ensure that traffic from the outside interface to a web server on the DMZ is allowed. The inside interface is security level 100 and the DMZ is level 50. The outside interface is level 0. Which statement about the default traffic flow is true?
Traffic from outside to DMZ is denied implicitly because outside level is lower than DMZ level.
Cisco ASA assigns security levels 0-100, and the default implicit rule permits traffic from a higher security level to a lower one while denying traffic from a lower level to a higher level. The outside interface (level 0) is lower than the DMZ (level 50), so traffic from outside to DMZ is implicitly denied. Any permitted outside-to-DMZ traffic must be explicitly allowed via an ACL.
A network administrator is configuring NAT on a Cisco ASA to allow internal users to access the internet using a single public IP address. The internal network uses RFC 1918 addresses. Which type of NAT should be configured?
PAT (Port Address Translation)
PAT (Port Address Translation) allows many internal IPs to share a single public IP by using unique source ports. Dynamic NAT would require a pool of public IPs, and static NAT provides one-to-one mapping.
A company uses Cisco Firepower Threat Defense (FTD) managed by FMC. They need to create an access control policy that allows traffic from specific source IPs to a web server, but blocks all other traffic. How should the rule base be ordered?
Place the permit rule first, then the block rule.
Cisco FTD access control policies evaluate rules top-down, first-match. The permit rule for specific source IPs must appear before the block rule so that matching traffic is allowed; the subsequent block rule then catches all remaining traffic. If the block rule were first, it would match all traffic (including the intended permitted sources) and drop it, making the permit rule unreachable.
Which security model requires that all subjects and devices are untrusted by default, and access is granted only after verification, regardless of the network location?
Zero Trust
Zero Trust is a security model based on the principle of 'never trust, always verify', requiring continuous authentication and authorization.
An organization wants to ensure that digital certificates issued by its internal CA are validated for revocation in real-time. Which protocol should be implemented to allow clients to check certificate status without downloading a full CRL?
OCSP
OCSP (Online Certificate Status Protocol, RFC 6960) allows a client to query a responder for the revocation status of a specific certificate in real time, returning 'good', 'revoked', or 'unknown' without downloading the entire CRL. This satisfies the requirement for real-time revocation checking with minimal bandwidth. OCSP is the standard replacement for CRL-based checking in latency-sensitive environments.
During a penetration test, an attacker sends a malicious payload to a web application that causes the server to execute arbitrary SQL commands on the backend database. Which type of attack is being performed?
SQL Injection
SQL injection occurs when user input is improperly sanitized and concatenated into SQL queries, allowing attackers to execute arbitrary SQL commands.
A security administrator is configuring a Cisco Firepower NGFW to detect and block application-layer DDoS attacks. Which type of DDoS attack is characterized by overwhelming a server with incomplete HTTP requests, causing resource exhaustion?
Slowloris
Slowloris is an application-layer DDoS attack that sends partial HTTP requests to keep connections open, exhausting server resources.
A security administrator notices that a significant volume of spam is bypassing the Cisco ESA's anti-spam filters. Upon investigation, they find that the messages have a mid-range SBRS score of 5.0. Which action should the administrator take to improve spam detection?
Increase the SBRS threshold to 7.0
The SenderBase Reputation Score (SBRS) ranges from -10 to +10, with lower scores indicating a higher likelihood of spam and higher scores indicating more legitimate senders. The SBRS threshold is the score below which messages are classified as spam. By default, the threshold may be set low (e.g., 3.0), allowing messages with a mid-range score of 5.0 (which is relatively legitimate) to bypass filters. To catch these messages, the administrator should raise the threshold (e.g., to 7.0), so that messages with scores below 7.0 are considered spam, thus including the 5.0 messages. Option A would reverse score interpretation, causing confusion; Option B would lower the threshold, reducing spam detection because fewer messages would be below the threshold; Option D disables the feature entirely.
A Cisco WSA administrator wants to block access to social media sites for all users during work hours. The proxy is deployed in explicit mode. Which policy type should the administrator use to enforce this restriction?
Access policy
An Access Policy in Cisco WSA defines which users/groups can access which categories or URLs, and what action (allow, block, monitor) applies. Blocking social media during work hours is a classic access policy use case, often combined with a time-range condition.
A company is deploying Cisco ISE for guest access. They want to provide a self-service portal where guests can register their devices and receive a temporary username and password. Which ISE component is used to accomplish this?
Guest Portal
C is correct because the Guest Portal in Cisco ISE is specifically designed to provide a self-service registration page where guests can create their own accounts, receive temporary credentials, and gain network access. This portal handles the entire guest lifecycle, including sponsor approval if required, and can deliver the username/password via SMS, email, or on-screen display.
A network administrator wants to implement 802.1X on a Cisco switch port for a device that does not support 802.1X. Which feature should be configured to allow the device to connect?
MAC Authentication Bypass (MAB)
MAC Authentication Bypass (MAB) is the correct feature because it allows a device that does not support 802.1X supplicant software to authenticate by using its MAC address as the identity. The switch acts as a proxy, sending the MAC address as the username and password to the RADIUS server, which can then grant or deny access based on the MAC address in its database.
A security administrator notices that several endpoints in the finance department are exhibiting unusual network behavior, including connections to known malicious IP addresses. The administrator has deployed Cisco Secure Endpoint (formerly AMP for Endpoints) with TETRA and has enabled the built-in firewall. What is the best course of action to quickly identify the root cause and contain the threat?
Use the Cisco Secure Endpoint console to review the TETRA engine's real-time traffic analysis and isolate the affected endpoints.
Cisco Secure Endpoint with TETRA provides real-time traffic analysis and endpoint isolation capabilities directly from the console. The TETRA engine inspects network flows using behavioral analysis and machine learning, and the administrator can immediately isolate affected endpoints to prevent lateral movement while reviewing the root cause.
The 350-701 flashcard bank covers all 6 official blueprint domains published by Cisco. Cards are distributed proportionally, so domains with higher exam weight have more cards.
Domain Coverage
Cloud Security
Network Security
Security Concepts
Content Security
Secure Network Access, Visibility and Enforcement
Endpoint Protection and Detection
Both flashcards and practice questions are evidence-based study tools. The difference is in what they train:
Flashcards — concept retention
Best for memorising definitions, acronyms, protocol behaviours, command syntax, and conceptual distinctions. Use flashcards to build the foundational vocabulary that 350-701 questions assume you know.
Best in: weeks 1–3
Practice tests — application
Best for applying concepts to realistic scenarios, eliminating distractors, and building exam stamina.350-701 questions test scenario reasoning — not just recall — so practice tests are essential.
Best in: weeks 3–6
The most effective 350-701 study plan combines both: use flashcards for the first 2–3 weeks to build conceptual foundations, then shift to practice tests and mock exams in the final 2–3 weeks to apply and benchmark that knowledge. Most candidates who pass on their first attempt use both tools.
Yes. Courseiva provides free 350-701 flashcards across all official exam domains. Every card includes the correct answer and a full explanation of why it is right and why the distractors are wrong. The platform also includes topic-based practice, mock exams, and readiness tracking — no account required.
Courseiva has 795+ original 350-701 flashcards across all 6 exam blueprint domains. New cards are added regularly as the question bank grows. All cards are checked against the official Cisco exam objectives, with editorial oversight from an experienced network and security engineer.
Courseiva flashcards are purpose-built for IT certification exams. Unlike generic flashcard platforms where content quality varies, every Courseiva card is mapped to the official 350-701 exam blueprint, written by engineers who hold the certification, and includes a full explanation of the correct answer and why the distractors are wrong. This explanation quality is what separates genuine learning from rote memorisation.
Courseiva is a web platform — an internet connection is required. For offline study, we recommend creating free Courseiva account, using the platform in your browser, and using your device's offline capabilities if your browser supports offline web apps.
Save your results, see which domains need more work, and get spaced repetition recommendations — all free.
Sign Up FreeFree forever · Every certification included