Sample questions
Cisco SCOR / CCNP Security Core 350-701 practice questions
A company uses Cisco Stealthwatch Cloud for network visibility in AWS. They notice a spike in encrypted traffic from an EC2 instance to an unknown external IP. Which Stealthwatch C…
A security analyst notices traffic from an internal host to an external IP address on port 4444, and the host's CPU is high. The host has been running unknown processes. Which type…
A security analyst detects a DDoS attack targeting the company's web server. Which three attack types are classified as application layer attacks? (Choose three.)
Which Cisco product provides DNS-layer security to block malicious domains and prevent connections to malware command-and-control servers?
Which Cisco cloud-based security solution provides DNS-layer security to block requests to malicious domains?
A security analyst is tuning Snort rules to reduce false positives. The analyst identifies a rule that triggers on a common benign application. Which action should be taken to supp…
Which Cisco technology provides visibility into the performance of SaaS applications such as Microsoft 365?
A company uses Azure and wants to restrict network traffic between subnets. Which Azure resource should they use?
An organization is adopting a cloud-first strategy and wants to ensure least-privilege access for cloud resources. Which THREE measures should be implemented as part of a cloud IAM…
A network engineer is configuring OSPF on a Cisco router and needs to enable authentication between neighbors. The authentication type should be MD5. Which configuration step is re…
Which THREE of the following are key principles of the Cisco Zero Trust security model?
An organization uses Cisco Umbrella to block malicious domains. What is the primary security benefit of DNS-layer security?
An organization uses ISE for wireless LAN authentication via 802.1X with PEAP-MSCHAPv2. Users authenticate against Active Directory. Recently, some users report that after changing…
Secure Network Access, Visibility and EnforcementeasySee the answer and why each option is right or wrong →Which THREE of the following are valid methods to deploy Cisco AMP for Endpoints Connector on Windows endpoints?
A security engineer is evaluating authentication methods. Which authentication factor category does a fingerprint scanner fall under?
A company is deploying a multi-tier application in a Cisco cloud security environment. The web servers must be accessible from the internet, but the database servers should only be…
An organization wants to enforce multi-factor authentication for remote VPN access. Cisco AnyConnect is used as the VPN client. Which Cisco product integrates with AnyConnect to pr…
A security engineer is configuring a Cisco ASA to block traffic from a specific IP address. Which access control entry (ACE) should be applied to the inbound direction of the outsi…
An administrator wants to enforce identity-based policies on Cisco WSA by integrating with Active Directory. Which method allows the WSA to identify users transparently without req…
An organization wants to prevent users from accessing known malicious websites. Which Cisco WSA feature should be configured to block access based on website reputation?
An administrator notices that some users receive spam messages even though the ESA policy is set to 'Quarantine' for suspected spam. The messages are not found in the user's spam q…
A company uses FMC to manage FTD devices. After deploying a new intrusion policy, the analyst sees that no events are generated for a known vulnerability, even though the policy in…
A network administrator needs to configure Cisco WSA to decrypt HTTPS traffic for inspection. What is the first step that must be completed?
You are tasked with securing a new cloud deployment on AWS. The environment consists of a web application running on EC2 instances behind an Application Load Balancer (ALB), with d…