Courseiva

Cisco SCOR / CCNP Security Core 350-701 (350-701) — Questions 976978

978 questions total · 14pages · All types, answers revealed

Page 13

Page 14 of 14

976
MCQmedium

An organization wants to protect their web application hosted on AWS from common exploits like SQL injection. Which Cisco service should they use?

A.Cisco Firepower Next-Generation Firewall (NGFW)
B.Cisco Identity Services Engine (ISE)
C.Cisco Stealthwatch
D.Cisco Web Security Appliance (WSA)
AnswerA

Correct: Firepower NGFW with IPS (including virtual versions like FTDv) can detect and block SQL injection via deep packet inspection and IPS signatures.

Why this answer

Cisco Firepower Next-Generation Firewall (NGFW) with Intrusion Prevention System (IPS) can detect and block SQL injection attacks by inspecting HTTP traffic for malicious payloads. It provides application-layer protection through signature-based and behavioral analysis. The other options: ISE is for identity and access management, Stealthwatch for network visibility, and WSA is a web proxy without native WAF capabilities.

977
MCQeasy

Which protocol does Cisco ISE use to communicate with the pxGrid controller for sharing contextual data?

A.JSON-RPC over certificate-based TLS
B.REST API over HTTPS
C.TACACS+
D.RADIUS
AnswerA

pxGrid uses JSON-RPC over TLS with mutual certificate authentication.

Why this answer

Cisco ISE uses the JSON-RPC protocol over certificate-based TLS to communicate with the pxGrid controller for sharing contextual data. This ensures encrypted, authenticated, and structured messaging between ISE and other pxGrid-enabled services, such as Cisco Threat Response or third-party integrations.

Exam trap

Cisco often tests the distinction between pxGrid communication (JSON-RPC over TLS) and other ISE APIs (REST over HTTPS), leading candidates to mistakenly choose REST API because they associate HTTPS with secure data exchange.

How to eliminate wrong answers

Option B is wrong because REST API over HTTPS is used for northbound API calls (e.g., external systems querying ISE), not for pxGrid controller communication, which requires a persistent, bidirectional messaging protocol. Option C is wrong because TACACS+ is a legacy AAA protocol for device administration (authorization and accounting), not for real-time contextual data sharing via pxGrid. Option D is wrong because RADIUS is used for network access authentication, authorization, and accounting, and does not support the pub/sub or topic-based messaging required by pxGrid.

978
Multi-Selectmedium

An organization is planning to deploy Cisco FTD in a high-availability pair. Which two statements about active/active failover are true? (Choose two.)

Select 2 answers
A.It requires multiple context mode.
B.Both units can actively pass traffic.
C.Stateful failover is supported.
D.It is the default failover mode.
E.Configuration is not synchronized.
AnswersA, B

Correct; active/active is only supported in multiple context mode.

Why this answer

Active/active failover requires multiple context mode and both units can process traffic simultaneously. Stateful failover is supported only in active/standby.

Page 13

Page 14 of 14