These are the questions most candidates get wrong. They require connecting multiple concepts, reading tricky output, or knowing edge-case behaviour that isn't on most study cards. Practising them trains you to operate under uncertainty — a necessary skill on the real exam.
Start Scenario PracticeA security analyst detects a DDoS attack targeting the company's web server. Which three attack types are classified as application layer attacks? (Choose three.)
Explanation: Application layer DDoS attacks target specific applications, such as HTTP floods, Slowloris, and DNS query floods.
An organization is adopting a cloud-first strategy and wants to ensure least-privilege access for cloud resources. Which THREE measures should be implemented as part of a cloud IAM strategy? (Select three.)
Explanation: Managed identities (such as Azure Managed Identities or AWS IAM Roles for EC2) eliminate the need to store credentials in code or configuration files. The cloud provider automatically rotates the credentials and binds the identity to the compute resource, enforcing least-privilege by granting only the permissions required for that resource to function.
Which THREE of the following are key principles of the Cisco Zero Trust security model?
Explanation: 'Never trust, always verify' is the foundational principle of the Cisco Zero Trust security model, which mandates that no user, device, or network segment is trusted by default, regardless of its location relative to the network perimeter. This principle eliminates implicit trust and requires authentication and authorization for every access request, aligning with the Zero Trust architecture defined in NIST SP 800-207.
Which THREE of the following are valid methods to deploy Cisco AMP for Endpoints Connector on Windows endpoints?
Explanation: Group Policy Software Installation (MSI) is a valid deployment method for Cisco AMP for Endpoints Connector on Windows endpoints because it allows administrators to distribute the AMP connector MSI package via Active Directory Group Policy Objects (GPOs). This method leverages Windows Installer technology for silent, automated installation across domain-joined machines, ensuring consistent deployment without user interaction.
A company uses FMC to manage FTD devices. After deploying a new intrusion policy, the analyst sees that no events are generated for a known vulnerability, even though the policy includes a rule for it. The analyst checks and the rule is enabled and the policy is applied. What is the most likely cause?
Explanation: In a Cisco Firepower deployment, the access control policy (ACP) is evaluated before the intrusion policy. If the ACP is configured to block traffic matching the vulnerability's characteristics, the traffic never reaches the intrusion policy for inspection, so no intrusion events are generated even if the intrusion rule is enabled and applied.
+15 more scenario questions available
Practice all Hard Difficulty QuestionsThese are the questions most candidates get wrong. They require connecting multiple concepts, reading tricky output, or knowing edge-case behaviour that isn't on most study cards. Practising them trains you to operate under uncertainty — a necessary skill on the real exam. These appear throughout the 350-701 and require you to apply your knowledge, not just recall facts.
Cisco doesn't publish an exact breakdown, but scenario-based questions (especially exhibit and command-output formats) make up a significant portion of the 350-701. Practicing each scenario type ensures you're ready for any format.
Yes. Courseiva provides free 350-701 scenario practice across all official exam domains. The platform includes scenario-based questions, command-output interpretation, topic-based practice, mock exams, and readiness tracking — no account required.
Launch a full Hard Difficulty Questions session with instant scoring and detailed explanations.
Start Scenario Practice →