Practise command-choice questions where the task is to identify the correct verification, configuration or troubleshooting command.
Start Scenario PracticeAn organization wants to prevent users from accessing known malicious websites. Which Cisco WSA feature should be configured to block access based on website reputation?
Explanation: Cisco WSA uses Cisco Talos web reputation scores to block access to malicious websites based on their reputation.
A network administrator needs to configure Cisco WSA to decrypt HTTPS traffic for inspection. What is the first step that must be completed?
Explanation: The first step in configuring Cisco WSA for HTTPS decryption is to install a Certificate Authority (CA) certificate on the WSA and distribute it to client devices. This establishes trust because the WSA acts as a man-in-the-middle, generating a new certificate for each HTTPS session signed by this CA; without the CA certificate in the clients' trusted root store, browsers will display certificate warnings and block the connection.
Which TWO actions can be configured in a Cisco ESA DLP policy to respond to a violation involving outbound credit card numbers? (Choose two.)
Explanation: Cisco ESA DLP policies can automatically encrypt outbound messages containing sensitive data like credit card numbers. This ensures that even if the message is intercepted, the content remains protected, which is a common compliance requirement for PCI DSS.
A financial company is deploying Cisco ISE with TrustSec to enforce segmentation between application tiers (web, app, DB). They have a Cisco Catalyst 9500 as the core, and Catalyst 9300s as access switches. The SXP is configured between ISE and core switch, and the core switch propagates SGTs to access switches via SGT inline tagging on trunk ports. The engineer has configured SGTs for web (SGT=2), app (SGT=3), DB (SGT=4). However, when testing from a web server (IP 10.1.1.10, SGT=2) to an app server (IP 10.1.2.20, SGT=3), the app server sees the traffic without SGT in the packet, so the access switch cannot enforce policy. The engineer checks 'show cts role-based sgt-map' on the core and sees the mapping for 10.1.1.10 -> 2. What is the most likely issue?
Explanation: The core switch correctly maps IP 10.1.1.10 to SGT 2, as shown by 'show cts role-based sgt-map'. However, the access switch receives traffic without the SGT, meaning the SGT is not being propagated across the trunk. For SGT inline tagging to work, the trunk between core and access must have 'cts manual' enabled under the interface configuration. Without this, the SGT is stripped from the packet. Option C is correct because the missing 'cts manual' on the trunk prevents the access switch from seeing the SGT tag. Option A is incorrect because ISE policy controls authorization, not packet tagging. Option B is incorrect; the access switch lacking a security group ACL would not prevent the SGT from being present in the packet. Option D is incorrect; the SXP connection between ISE and core is functional since the core has the correct SGT mapping.
A Cisco FTD device is deployed in inline mode and configured with an SSL policy to decrypt traffic. The policy uses 'Decrypt - Known Key' for traffic to an internal server. What is required for this decryption to work?
Explanation: 'Decrypt - Known Key' requires the server's private key to be imported into the FTD so it can decrypt the traffic by impersonating the server.
+10 more scenario questions available
Practice all Which Command Should the Administrator Use Practice QuestionsPractise command-choice questions where the task is to identify the correct verification, configuration or troubleshooting command. These appear throughout the 350-701 and require you to apply your knowledge, not just recall facts.
Cisco doesn't publish an exact breakdown, but scenario-based questions (especially exhibit and command-output formats) make up a significant portion of the 350-701. Practicing each scenario type ensures you're ready for any format.
Yes. Courseiva provides free 350-701 scenario practice across all official exam domains. The platform includes scenario-based questions, command-output interpretation, topic-based practice, mock exams, and readiness tracking — no account required.
Launch a full Which Command Should the Administrator Use Practice Questions session with instant scoring and detailed explanations.
Start Scenario Practice →