350-701 · domain
troubleshooting
Practise Cisco SCOR / CCNP Security Core 350-701 troubleshooting practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice troubleshooting questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about troubleshooting
troubleshooting questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common troubleshooting exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All troubleshooting questions (978)
Click any question to see the full explanation, or start a practice session above.
Which THREE of the following are valid considerations when deploying Cisco Advanced Malware Protection (AMP) for Networks on a Firepower system? (Choose three.)
Hard2A security analyst discovers that an endpoint was infected by a file that initially received a 'clean' disposition from Cisco AMP. The analyst needs to identify all other endpoints that executed the same file and examine their trajectory. Which approach should be used to find these endpoints in the AMP console?
Hard3Which Cisco TrustSec feature uses a classification packet to carry security group information across network devices?
Easy4A network engineer is implementing Cisco TrustSec in an enterprise network. Which two components are required for TrustSec to function correctly? (Choose two.)
Medium5A company is deploying Cisco Secure Endpoint and wants to ensure that endpoints are protected against zero-day exploits. Which two features should be enabled to provide this protection? (Choose two.)
Medium6A security analyst notices that a file that was initially allowed by Cisco AMP for Endpoints has later been determined to be malicious. The analyst needs to investigate the file's propagation across endpoints. Which Cisco AMP feature should the analyst use to view the timeline of events?
Medium7A company uses Cisco Firepower Threat Defense (FTD) managed by FMC. They need to create an access control policy that allows traffic from specific source IPs to a web server, but blocks all other traffic. How should the rule base be ordered?
Medium8An organization is adopting a zero trust model for cloud access. Which three principles should be implemented? (Select three.)
Medium9Refer to the exhibit. The tunnel is established but no traffic is encrypted. What is the most likely issue?
Easy10A company is deploying Cisco ISE for network access control. Which three policies must be configured to enforce access based on device posture? (Choose three)
Hard11A DevOps team is integrating security into their CI/CD pipeline. They want to automatically scan Terraform scripts for misconfigurations before deployment. Which tool is specifically designed for this purpose?
Medium12A multinational corporation is implementing ISE for wired network access using 802.1X with EAP-TLS certificate authentication. Their Windows 10 laptops have certificates issued by an internal PKI. During testing, some users report that they are repeatedly prompted to select a certificate after connecting, and eventually authentication fails. ISE logs show 'Authentication failed - No matching certificate found'. The engineer checks the client machine and sees multiple certificates, including the correct one, in the personal store. The ISE endpoint identity store is populated with the user's AD credentials. What is the most likely cause of this failure?
Medium13A cloud security architect is designing a zero-trust architecture for an enterprise using AWS and Azure. They need to enforce micro-segmentation between application tiers. Which Cisco solution is most appropriate?
Medium14A company is connecting multiple VPCs in AWS to a shared services VPC using AWS Transit Gateway. They want to inspect east-west traffic between VPCs with a common security policy. Which design best achieves this using Cisco solutions?
Hard15An incident responder uses the Cisco AMP for Endpoints console to investigate a potential malware outbreak. The endpoint shows multiple files with high prevalence and cloud verdicts of 'unknown'. The responder wants to quickly identify files that were executed from a malicious parent process. Which console feature best assists this analysis?
Medium16An administrator configures Cisco ISE for guest access with a sponsor portal. What is the primary purpose of the sponsor portal?
Medium17A company wants to prevent users from downloading executable files (.exe) from the internet via the WSA. Which policy type should be configured?
Easy18A cloud security architect is designing zero trust for a multi-cloud environment. Which principle is most critical?
Hard19A security engineer needs to block access to social media websites for all users except those in the HR department. The solution must integrate with Active Directory. Which Cisco WSA feature should be used?
Medium20An organization wants to deploy Cisco ISE to authenticate devices that do not support 802.1X supplicant software, such as printers and IoT sensors. Which authentication method should be configured on the switch port to allow these devices network access?
Medium21A Cisco FTD is deployed in inline mode and is configured with a file policy to detect malware. When a file is transferred, the FTD computes a SHA-256 hash and checks it against AMP cloud. The cloud returns 'unavailable' for the hash. What action will the FTD take by default?
Medium22A security engineer is troubleshooting an issue where users can bypass the Cisco WSA by using HTTPS. What must be enabled on the WSA to inspect encrypted traffic?
Hard23A security engineer is configuring Cisco Firepower NGFW to block social media applications. Which feature should be used to achieve this?
Medium24In a Cisco ISE deployment, after a device passes posture assessment, ISE needs to dynamically change the VLAN assignment for the device. Which protocol or feature enables ISE to send a new authorization policy to the network access device without requiring the endpoint to reauthenticate?
Hard25Cisco ISE performs profiling to identify device type. Which probe collects information by querying the device's MAC address OUI and DHCP options?
Medium26A web application accepts user input and directly includes it in SQL queries without sanitization. An attacker submits a single quote (') to cause a syntax error. What is this attack called?
Medium27A security analyst is investigating an incident on an endpoint protected by Cisco AMP. The analyst needs to isolate the compromised process and prevent it from communicating with other processes or the network. Which EDR capability should be used to achieve this?
Hard28A network engineer is implementing TrustSec on a Cisco switch. The goal is to tag traffic from the engineering VLAN with Security Group Tag (SGT) 10 and enforce policies on upstream switches. Which configuration is required on the access switch to propagate the SGT?
Medium29A security engineer is analyzing logs from a Cisco ASA. They notice that a specific internal host is generating a high volume of outbound TCP SYN packets to multiple external IP addresses on port 443, but no SYN-ACK responses are received. What is the most likely explanation?
Hard30An administrator wants to enforce identity-based policies on Cisco WSA by integrating with Active Directory. Which method allows the WSA to identify users transparently without requiring client software?
Medium31A security engineer is designing cloud workload protection (CWPP) for a hybrid environment with VMs and containers. Which TWO capabilities should a CWPP solution provide? (Choose two.)
Hard32A network administrator is configuring Cisco ASA with FirePOWER services. The administrator wants to inspect SSL traffic but is concerned about certificate pinning in modern applications. Which action should the administrator take to ensure that SSL inspection does not break applications that use certificate pinning?
Hard33A company is designing a network segmentation strategy using firewalls. Which THREE considerations are important for a defense-in-depth approach?
Medium34A security engineer is implementing a zero trust architecture. Which TWO principles are foundational to zero trust? (Choose two.)
Medium35A Cisco FTD is configured with SSL/TLS inspection using the 'decrypt-known-key' method. Which traffic can be decrypted with this method?
Medium36An organization uses Cisco ISE to enforce posture compliance. After a user's machine is patched, ISE sends a command to the switch to reclassify the endpoint from a restricted VLAN to a full-access VLAN. Which ISE feature accomplishes this?
Medium37A Cisco WSA receives intermittent complaints that legitimate websites are being blocked. The access policy uses reputation scoring and URL filtering. The administrator checks the logs and finds that the blocked requests have a web reputation score of -2.0. What action should be taken to allow these legitimate sites while still blocking malicious ones?
Hard38Refer to the exhibit. An engineer configured 802.1X on two switch ports. On Gi1/0/1, a VoIP phone and a PC are connected via a hub. On Gi1/0/2, only a single PC is connected. Which port will successfully authenticate both devices, and what is the issue with the other port?
Hard39A company uses Cisco ISE for posture assessment. They require that all endpoints meet a certain set of compliance rules before being granted network access. Which service is responsible for performing the posture assessment on the endpoint?
Medium40An organization deploys Cisco FTD in a high-availability pair using active/standby. If the active unit fails, what happens to existing connections?
Medium41A company uses Amazon Web Services (AWS) and wants to integrate with Cisco Defense Orchestrator (CDO) for centralized security management. Which THREE capabilities does CDO provide when managing AWS security services? (Choose three.)
Medium42An engineer is troubleshooting a user who cannot access the network after successful 802.1X authentication. The user's PC receives an IP address from DHCP, but cannot reach the internet. The switch port is in the correct VLAN (10) after authentication. The ISE posture policy requires the user to install a corporate certificate, but the user skipped that step. What is the most likely cause of the internet access failure?
Medium43A Cisco FTD is deployed in inline mode and configured with an access control policy. The policy includes rules with actions: Trust, Allow, Block, and Interactive Block. Which two statements about these actions are correct? (Choose two.)
Medium44An engineer configures a Cisco ASA in a DMZ architecture. The DMZ hosts web servers that need to be accessible from the internet. Which security level should be assigned to the DMZ interface to ensure proper traffic flow without additional ACLs for return traffic?
Medium45A Cisco FTD device is deployed inline and configured with an access control policy that includes a rule to block traffic from a specific source IP address. However, traffic from that IP is still passing through. What is the most likely cause?
Hard46An organization is deploying Cisco Firepower Threat Defense (FTD) in a high-availability (HA) pair in active/standby mode. Which statement about state synchronization is true?
Medium47A company wants to use Cisco Umbrella to block access to malicious domains. They have deployed the Umbrella roaming client on all endpoints. However, traffic from a specific application is still reaching a known malicious domain. What is the most likely reason?
Easy48A network engineer is trying to establish a site-to-site IPsec VPN between two Cisco routers. The IKEv2 proposal uses AES-256 encryption and SHA-256 hash. On the remote router, the configuration shows only AES-128 and SHA-1. What will happen during IKEv2 negotiation?
Medium49Refer to the exhibit. An engineer configured ISE to use both Active Directory and LDAP for authentication. Users from Active Directory are unable to authenticate. What is the most likely reason?
Easy50A multinational company has recently deployed Cisco WSA with explicit proxy for 10,000 users across two data centers. The WSA is configured with multiple identities based on IP subnets and authentication via LDAP. Users in the R&D department (subnet 192.168.10.0/24) are configured with an access policy that blocks all social media, but they can access web-based email like Gmail. The administrator receives complaints that R&D users cannot access a critical partner's HTTPS website (https://portal.partner.com) that is not categorized. The access policy for R&D has a default action of 'Monitor' for uncategorized URLs, but the site is blocked. The web reputation score for the site is +1.5 (low risk). The global web reputation threshold is set to -1.0. The administrator checks the access logs and sees that the request is denied with the reason 'URL is blocked by policy'. The R&D policy has an explicit 'Deny' action for the URL category 'Uncategorized URLs' set to 'Block', but the default action for the policy is 'Monitor'. The identity matching is correct. What is the most likely cause and solution?
Hard51A company deploys a web application firewall (WAF) from Cisco on AWS Marketplace. They want to integrate with AWS CloudTrail for logging. What is the primary benefit?
Medium52After deploying a Cisco Cloudlock policy, a user reports that a sanctioned application (Salesforce) is being blocked for file downloads. What is the most likely cause?
Hard53A security administrator notices that several endpoints in the finance department are exhibiting unusual network behavior, including connections to known malicious IP addresses. The administrator has deployed Cisco Secure Endpoint (formerly AMP for Endpoints) with TETRA and has enabled the built-in firewall. What is the best course of action to quickly identify the root cause and contain the threat?
Medium54A Cisco FTD device managed by FMC is processing traffic. An access control rule is configured with the action 'Interactive Block'. What behavior does this action trigger?
Hard55An organization is implementing a zero trust strategy for cloud access. They require that all access to cloud resources be authenticated and authorized based on user identity and device health, with session risk assessment. Which Azure AD feature should they primarily use?
Hard56Which Cisco security product provides network visibility and traffic analytics using NetFlow and IPFIX?
Easy57An attacker injects a malicious SQL query into a web application's login form, bypassing authentication. Which type of exploitation is this?
Medium58A network administrator notices that an endpoint running the AMP connector is not sending events to the cloud. The connector status shows 'Connected' in the AMP console. What is the most likely cause?
Easy59A company uses Cisco Umbrella for cloud-delivered security. Users report that some websites are incorrectly blocked. The security team wants to allow a specific website temporarily while investigating. Which action should the administrator take?
Easy60An engineer is configuring Dynamic Access Policy (DAP) on an ASA for AnyConnect VPN. They want to assign different access policies based on the client's anti-virus status and device posture. What must be configured to obtain this information?
Medium61A user reports slow performance when accessing cloud-based applications. Which Cisco tool provides visibility into SaaS application performance?
Medium62Which THREE of the following are required for a successful 802.1X authentication on a Cisco switch? (Choose THREE)
Hard63A company is deploying workloads in AWS and wants to ensure that the security groups are not overly permissive. They need to continuously monitor for misconfigurations and compare against the CIS AWS Foundations Benchmark. Which tool should be used?
Medium64A network administrator is configuring site-to-site VPN between two Cisco ASA firewalls using IKEv2. The administrator wants to ensure that the VPN tunnel uses the most secure encryption algorithm available. Which encryption algorithm should be selected in the IKEv2 proposal?
Medium65You are troubleshooting a Cisco ISE deployment where some endpoints are stuck in the 'Not Compliant' posture after a posture scan. ISE logs show 'Conditional NAC Agent result: Not Compliant due to missing required application.' The application is installed on the endpoint. What should you check?
Hard66Refer to the exhibit. Enter the command output from a Cisco Umbrella deployment. An administrator observes that 25 DNS queries were blocked. What does this indicate?
Hard67An organization is experiencing repeated SQL injection attacks. A security analyst is tasked with recommending mitigations. Which THREE actions are most effective in preventing SQL injection? (Choose three.)
Hard68A company is deploying Cisco Web Security Appliance (WSA) to enforce acceptable use policies. Users report that some legitimate websites are being blocked incorrectly. The security team wants to allow these sites while still blocking known malware sites. Which action should the administrator take?
Medium69A security analyst notices that a user is receiving a high volume of emails from unknown senders with links to malicious sites. The ESA is configured with Cisco TALOS threat intelligence. Which ESA feature should the analyst configure to block these emails based on the reputation of the sender before they reach the user's inbox?
Medium70A user in the Engineering group reports that they cannot access a banking website (https://www.examplebank.com). The website is categorized as 'Financial' by the WSA. Based on the exhibit, what is the most likely cause?
Hard71Which TWO of the following are valid action types that can be assigned to a file in an AMP policy rule?
Hard72An engineer configures a Cisco ASA firewall with three interfaces: inside (security level 100), outside (security level 0), and DMZ (security level 50). Traffic from the inside network to the DMZ network is sourced from 10.1.1.0/24 and destined to 192.168.1.0/24. The inside interface is configured with IP 10.1.1.1, DMZ interface with IP 192.168.1.1. An ACL on the inside interface permits IP traffic from 10.1.1.0/24 to 192.168.1.0/24. What happens when a packet from 10.1.1.10 to 192.168.1.10 arrives at the inside interface?
Medium73A network engineer is troubleshooting an IPsec VPN tunnel that fails to establish. The configuration includes a crypto map with a matching access list. Which command should be used to verify the security associations and error counters for the IPsec phase?
Easy74Which Cisco content security solution uses DNS to block access to malicious domains and provides cloud-based proxy protection?
Easy75A security analyst is reviewing Snort rule output and sees an alert with the following details: action: alert, protocol: tcp, src: any, dst: any, content: 'malicious'. What type of detection is this rule using?
Easy76An engineer is configuring Cisco Firepower Threat Defense (FTD) in inline NGFW mode. The access control policy must block all traffic from geolocation 'North Korea' and allow all other traffic. Which type of rule should be used and in what order should it be placed?
Hard77A company uses Cisco ISE for network access control. They want to allow employee-owned devices to access the guest network after a simple registration, while corporate devices get full access. Which ISE configuration best achieves this?
Medium78A small business uses Cisco AMP for Endpoints with a cloud-based console. The owner receives an email from Cisco that the AMP connector on a specific endpoint has gone offline. The endpoint is a Windows 10 laptop used for remote work. The owner checks the AMP console and sees the endpoint's last check-in was three days ago. The owner contacts the remote user, who says the laptop is running normally and they can access the internet. What should the owner do to resolve the issue?
Easy79An organization wants to implement MAC Authentication Bypass (MAB) for devices that do not support 802.1X. Which configuration is required on a Cisco switch to allow MAB fallback?
Easy80A company uses Cisco Firepower with FMC and wants to block access to social media websites for all users. Which feature should be used to create this policy?
Medium81Which TWO actions are best practices when configuring a Cisco WSA to block malicious websites? (Choose two.)
Medium82Refer to the exhibit. The file invoice.pdf was determined to be malicious by the AMP cloud, yet the endpoint allowed it to execute. What is the most likely reason?
Medium83In a Snort intrusion detection rule, which part specifies the action to take when the rule matches?
Medium84A company is implementing a cloud security posture management (CSPM) solution. Which TWO of the following are primary functions of CSPM?
Medium85A security engineer is configuring Cisco AMP for Endpoints to protect against memory injection attacks. Which feature should be enabled to block exploits that attempt to inject malicious code into legitimate processes?
Medium86Which THREE elements are essential components of a secure network architecture according to Cisco's SAFE model? (Choose three.)
Hard87In the shared responsibility model for PaaS, which of the following is typically the customer's responsibility?
Easy88During a security incident, an analyst uses Cisco AMP for Endpoints to remotely investigate a compromised endpoint. The analyst needs to isolate the endpoint from the network while preserving the ability to continue the investigation. Which AMP action should be taken?
Hard89An administrator is troubleshooting an issue where emails sent to a specific external domain are being delayed by up to 30 minutes. The Cisco ESA is configured with multiple mail exchangers (MX) for delivery. The logs show that the ESA is attempting delivery to the primary MX, which is unresponsive, and failing over to the secondary MX after 30 minutes. What change should be made to reduce the delivery delay?
Hard90A security administrator is investigating an alert from an IPS that detected a SQL injection attempt. The alert was triggered by a signature that looks for specific patterns in the traffic. What type of detection method is this?
Easy91Refer to the exhibit. Based on the exhibit, what is the current state of the client and what action should the network administrator take to allow full network access?
Hard92A security administrator is evaluating Cisco Umbrella for cloud-delivered security. Which TWO capabilities are provided by the Secure Internet Gateway (SIG) feature? (Choose two.)
Medium93A company using Cisco Web Security Appliance (WSA) in explicit proxy mode has enabled HTTPS decryption with a custom CA certificate. A user reports that a specific banking website displays a certificate error message. The administrator verifies that the WSA is generating a certificate for that site. What is the most likely cause of the error?
Hard94A security team wants to gain visibility into shadow IT usage of cloud applications and enforce data loss prevention policies. Which cloud security control should they deploy?
Medium95An engineer configures a Cisco FTD in a high-availability pair with active/standby failover. The primary unit fails, and the standby takes over. After the primary recovers, what must be done to ensure it resumes as active?
Hard96A network administrator is deploying Cisco ISE for network access control. The network includes printers and IP phones that do not support 802.1X. Which TWO methods can be used to authenticate these devices?
Medium97A Cisco FMC administrator needs to create a file policy to detect malware in HTTP downloads. The policy should allow the file to be delivered if it is known clean, block if known malicious, and allow but capture for analysis if unknown. Which combination of actions is required?
Hard98A company is deploying Cisco Umbrella to enforce security policies for remote users. They want to ensure that DNS requests from roaming clients are routed through Umbrella's DNS resolvers. However, some users are bypassing Umbrella by using third-party DNS servers like Google (8.8.8.8). Which configuration should be applied to prevent this?
Hard99Which TWO of the following are features of Cisco Umbrella? (Choose two.)
Easy100A DevSecOps team is integrating security into their CI/CD pipeline. They want to scan infrastructure-as-code templates for misconfigurations and container images for vulnerabilities. Which two tools are appropriate? (Select two.)
Medium101An administrator wants to dynamically change the VLAN assignment for a user after a posture assessment determines that the endpoint is missing a critical patch. Which ISE feature accomplishes this?
Medium102A small business uses Cisco Duo for multi-factor authentication. They want to ensure that employees accessing cloud apps from personal devices are compliant with device security policies. Which Duo feature should they use?
Easy103A DevSecOps team is integrating security into their CI/CD pipeline. They want to scan Terraform configuration files for misconfigurations before deployment. Which tool is specifically designed for that purpose?
Hard104A company is deploying Cisco Email Security Appliance (ESA) to protect against phishing attacks. The security team wants to implement two security features to detect malicious URLs in emails. Which two features should be enabled? (Choose two.)
Medium105Which authentication protocol is used in Cisco ISE for certificate-based 802.1X authentication?
Easy106Cisco ISE is performing profiling on a network. It receives a DHCP request from a device with vendor class identifier 'MSFT 5.0' and an HTTP user-agent 'Mozilla/5.0 (Windows NT 10.0)'. Which probes are most likely used to collect this information?
Hard107A security administrator is configuring a Cisco Firepower system for network discovery and wants to identify hosts and services on the network. Which two actions must be configured to enable network discovery? (Choose two.)
Medium108A company is implementing a Zero Trust architecture. The security team needs to ensure that all traffic between workloads in a private cloud is encrypted and mutually authenticated. Which solution best meets these requirements?
Medium109A Cisco WSA administrator wants to apply different web usage policies based on user group membership. Which two methods can be used to identify users transparently? (Choose two.)
Medium110Refer to the exhibit. An ISE administrator sees this error in the logs. What is the most likely cause?
Hard111A company is using Cisco ASA with AnyConnect VPN. They want to implement Dynamic Access Policy (DAP) to enforce access based on device compliance. Which two attributes can DAP use to evaluate endpoint posture? (Choose two.)
Hard112Which TWO are valid methods for implementing Network Admission Control (NAC) in a Cisco environment?
Medium113Drag and drop the steps to configure 802.1X port-based authentication on a Cisco switch in the correct order.
Medium114An organization is implementing privileged access management (PAM) with Cisco SecureX and CyberArk. Which feature allows administrators to grant temporary elevated privileges for a specific task, after which the privileges are automatically revoked?
Hard115In Cisco AMP for Endpoints, which technology prevents exploit techniques such as code injection and memory corruption at runtime without relying on signatures?
Hard116A company wants to deploy a site-to-site VPN between two branch offices using Cisco IOS routers. The security policy requires that all traffic between the sites must be encrypted and authenticated using strong encryption. The engineer chooses IPsec with IKEv2. Which IPsec transform set configuration provides the strongest encryption and authentication?
Easy117A DevOps team is deploying microservices in Azure Kubernetes Service (AKS). They need to enforce inter-container communication policies based on labels. Which Cisco solution provides micro-segmentation for containers in AKS?
Hard118Which THREE of the following are benefits of using Cisco ISE for network access control?
Medium119An organization wants to prevent users from accessing known malicious websites. Which Cisco WSA feature should be configured to block access based on website reputation?
Easy120A Cisco WSA appliance is configured with explicit proxy mode. Users report that they cannot access external HTTPS websites, but HTTP works fine. The proxy logs show 'SSL handshake failed' errors. What is the most likely reason?
Hard121A Cisco ASA is configured with dynamic PAT to translate internal addresses to a single outside IP address. A user on the inside initiates a connection to an external web server. The ASA creates a connection entry. Which table is checked first when a return packet arrives from the web server?
Medium122An engineer applies the ACL shown in the exhibit to the inbound direction of interface GigabitEthernet0/0. The goal is to block all traffic from host 10.1.1.100 to the 192.168.0.0/16 network. However, traffic from 10.1.1.100 to 192.168.1.1 is still being permitted. What is the most likely reason?
Medium123Which EAP method used with 802.1X provides certificate-based mutual authentication and is commonly used with Cisco ISE?
Medium124An organization is experiencing a DDoS attack that floods the network with large volumes of traffic, overwhelming bandwidth. Which three types of DDoS attacks are primarily volumetric? (Choose three.)
Medium125A security engineer is tuning Snort rules on a Cisco FTD to reduce false positives. Which action should be taken if a rule is generating alerts for legitimate traffic?
Medium126Drag and drop the steps to configure a Cisco ISE as a RADIUS server for network access control into the correct order.
Medium127A company is deploying a cloud-native application using microservices on AWS. They need to ensure that inter-service communication is encrypted and authenticated. The security team wants to use mutual TLS (mTLS) without managing individual certificates. Which solution should they implement?
Medium128A financial company has a data center with Cisco FTD firewalls in a high-availability pair. They use Cisco ISE for network access control and Cisco Stealthwatch for network visibility. Recently, they deployed a new web application that is accessed by both internal employees and external customers. The application uses HTTPS on port 443. After deployment, the security team notices that the FTD is dropping some HTTPS sessions that appear legitimate. The drops are inconsistent and seem to occur only during peak hours. The FTD logs show the drop reason as 'TCP state violation'. The team has verified that the web server and clients are configured correctly. The Stealthwatch reports show no anomalies. What is the most likely cause and solution?
Hard129An organization is implementing TrustSec to enforce micro-segmentation. The Security Group Tag (SGT) is assigned to a user via ISE after authentication. However, traffic from this user to a server with SGT 5 is being dropped. The administrator checks the SGACL configuration on the switch and finds the following: 'permit ip source 2 destination 5'. What is the most likely reason for the traffic being dropped?
Hard130Refer to the exhibit. An IPsec VPN tunnel between two routers is not passing traffic. IKE phase 1 is not complete (MM_NO_STATE). Phase 2 has no SA. Which issue is most likely causing the problem?
Medium131A security engineer is configuring the Cisco ESA to block spam. The engineer wants to rely on a reputation-based system that scores senders based on global email traffic patterns. Which technology should be used?
Medium132Which NAT type on a Cisco ASA translates both the source and destination IP addresses and is typically used to allow external hosts to access internal servers?
Easy133A security administrator is configuring a Cisco Firepower NGFW to detect and block application-layer DDoS attacks. Which type of DDoS attack is characterized by overwhelming a server with incomplete HTTP requests, causing resource exhaustion?
Medium134Which TWO of the following are valid methods for deploying Cisco Firepower Threat Defense (FTD) in high availability?
Medium135A network engineer is implementing Cisco TrustSec. Which two components are required to enforce Security Group Access Control List (SGACL) policies? (Choose two)
Medium136An engineer is deploying Cisco Firepower Threat Defense (FTD) in inline mode and needs to decrypt SSL traffic for inspection. Which two methods are supported by FTD for SSL decryption? (Choose two.)
Hard137Which TWO of the following are valid methods for deploying Cisco WSA? (Choose TWO.)
Medium138Refer to the exhibit. An analyst reviews the log from a Cisco Secure Endpoint connector. The file 'invoice.pdf.exe' was quarantined. What best describes the detection process that occurred?
Hard139A company is moving workloads to Google Cloud and needs private connectivity between its on-premises data center and VPC without traversing the internet. Which service should be used?
Medium140Refer to the exhibit. A security engineer reviews the Cisco Secure Endpoint policy. If an endpoint is offline when a user downloads a file, what will happen?
Easy141An organization is deploying Cisco Secure Endpoint (AMP) in a high-security environment where endpoints are air-gapped from the internet. The security team needs to maintain up-to-date threat intelligence without direct cloud access. They have a dedicated local server that can download feeds from the AMP cloud once and distribute to endpoints. The server runs the AMP Private Cloud software. However, after installation, endpoints are not receiving updates. The team verifies that the Private Cloud server can reach the AMP cloud via a managed proxy. The endpoints can communicate with the Private Cloud server on TCP 443. What is the most likely cause of the update failure?
Medium142Which Cisco NGFW technology can be used to block social media categories such as Facebook and Twitter during business hours?
Medium143Which Cisco content security solution provides DNS-layer protection and a cloud proxy to enforce security policies?
Medium144A network administrator is configuring port security on a Cisco switch port connected to a single endpoint. The requirement is that only the first device that connects to the port is allowed, and any subsequent device that attempts to connect must trigger an error-disabled state. Which two features must be configured to meet this requirement?
Medium145Refer to the exhibit. A network administrator configured IP Source Guard and DHCP Snooping on a switch. A host connected to GigabitEthernet0/2 with MAC address 0050.7966.6801 has been assigned IP 192.168.1.10 via DHCP. The host now tries to use IP 192.168.1.20. What will happen?
Hard146A company is deploying Cisco ISE for network access control. They need to authenticate devices that do not support 802.1X, such as printers and IP phones. Which TWO methods can be used to authenticate these devices? (Choose two.)
Hard147A junior engineer is configuring MAB (MAC Authentication Bypass) on a Cisco switch for legacy printers. After configuration, the printers are still being placed into the default VLAN instead of the authorized VLAN. Which configuration is missing?
Easy148Which THREE of the following are valid characteristics of a next-generation firewall (NGFW) compared to a traditional stateful firewall? (Choose three.)
Hard149A network engineer is configuring a Cisco ASA to use the Modular Policy Framework (MPF) for advanced traffic inspection. Which three components are part of the MPF? (Choose three.)
Medium150An organization requires that endpoints must have antivirus running and up-to-date patches before being granted full network access. Cisco ISE is used for authentication. Which ISE component enforces these requirements?
Medium151A company uses Cisco ISE for network access control. They have deployed TrustSec and want to enforce segmentation using Security Group Tags (SGTs). The network team reports that SGTs are not being propagated correctly. Which protocol is responsible for SGT propagation between switches?
Medium152During a phishing simulation, an employee receives an email that appears to be from the CEO requesting an urgent wire transfer. This type of attack is known as:
Hard153A network engineer is configuring Cisco ISE to assign Security Group Tags (SGTs) to endpoints based on their identity and role. Which two components are required for TrustSec SGT classification and enforcement? (Choose two.)
Medium154What is the primary purpose of a digital signature?
Easy155A company has a hybrid cloud environment with workloads in AWS and Azure, and an on-premises data center. They use Cisco Tetration for micro-segmentation and Cisco CloudCenter for orchestration. Recently, they deployed a new multi-tier application in AWS: a web tier, an application tier, and a database tier, all across multiple Availability Zones. After deployment, the application is unreachable. The security team reviews Tetration policies and finds that a policy is in place to allow traffic between tiers, but the web tier cannot communicate with the application tier. The Tetration agent status shows all agents are healthy. The administrator checks the AWS security groups and notices that the web tier's security group allows inbound HTTP from 0.0.0.0/0, but the application tier's security group does not allow inbound traffic from the web tier's subnet. The application tier's security group only allows inbound traffic from the on-premises CIDR block in error. The network team requests a fix that does not impact other ongoing audits. What should the administrator do?
Hard156An organization is using Cisco ISE to enforce posture compliance. Endpoints that are non-compliant should be placed into a quarantine VLAN. Which ISE policy component is used to assign the VLAN?
Medium157A company uses AWS and Azure and wants to protect its cloud workloads (VMs and containers) from threats. Which TWO technologies are specifically designed for workload protection in the cloud?
Hard158A network administrator is configuring NAT on a Cisco ASA to allow internal users to access the internet using a single public IP address. The internal network uses RFC 1918 addresses. Which type of NAT should be configured?
Medium159A security engineer is configuring a Cisco Firepower Threat Defense (FTD) device managed by FMC. They want to create a rule that blocks access to social media applications regardless of port or protocol. Which policy should be used?
Hard160A Cisco ISE administrator is configuring guest access with a sponsor portal. Which type of guest account requires approval from a sponsor before network access is granted?
Hard161Match each threat type to its definition.
Medium162Which email authentication method allows the domain owner to publish a policy that instructs receiving mail servers on how to handle messages that fail SPF and DKIM checks?
Medium163Which Cisco security product provides identity-based access control and policy enforcement for wired and wireless networks?
Medium164A cloud engineer is deploying a web application on AWS and needs to control inbound and outbound traffic at both the instance and subnet levels. Which two AWS security controls should they configure? (Select two.)
Easy165During a penetration test, an attacker sends a malicious payload to a web application that causes the server to execute arbitrary SQL commands on the backend database. Which type of attack is being performed?
Hard166Which deployment mode allows a Cisco Firepower NGFW to inspect traffic without being in the direct forwarding path?
Easy167In Cisco Firepower, an access control policy has multiple rules. Rule 1: Allow HTTP from any to any. Rule 2: Block HTTP from 10.0.0.0/8 to any. A packet from 10.0.0.1 to 192.168.1.1 with destination port 80 is inspected. What action is taken?
Hard168Drag and drop the steps to configure a Cisco IOS router as a Zone-Based Firewall (ZBF) in the correct order.
Medium169A security team is evaluating cloud security solutions. Which TWO of the following are core capabilities of a Cloud Access Security Broker (CASB)?
Medium170A security analyst is investigating a malware outbreak that occurred on endpoints protected by Cisco AMP for Endpoints. The malware was initially undetected but later identified as malicious based on new threat intelligence. Which THREE capabilities of AMP allow the analyst to trace the infection and remediate?
Hard171A security engineer wants to implement file reputation analysis using Cisco AMP for Endpoints. The policy must block files that are known to be malicious in the cloud and quarantine unknown files for further analysis. Which AMP policy configuration achieves this?
Medium172Which security principle ensures that a user or system is granted only the minimum permissions necessary to perform a specific function?
Easy173A company is migrating critical workloads to AWS and wants to ensure secure connectivity between their on-premises network and the VPC. Which TWO actions should be taken to meet this requirement?
Medium174A network security engineer is configuring Cisco ASA for remote access VPN using AnyConnect. Which two components must be configured to enable split tunneling? (Choose two.)
Medium175A company is implementing cloud security posture management (CSPM). Which Cisco product provides CSPM capabilities?
Easy176A company uses Cisco AMP for Endpoints and also deploys Cisco Firepower Next-Generation Firewall (NGFW) with AMP integration. The security team wants to see endpoint detections in the Firepower Management Center (FMC). What must be configured to enable this integration?
Medium177A Cisco FTD device is configured with an access control policy that has multiple rules. The first rule is 'Allow' for all traffic from the internal network to the internet. The second rule is 'Block' for traffic from a specific internal host to any destination. However, the administrator notices that the specific host can still access the internet. What is the most likely cause?
Hard178A security team is implementing CSPM to ensure cloud compliance. Which three checks would a CSPM tool typically perform? (Choose three.)
Hard179A network administrator has configured the above on a Cisco switch port for a device that supports both MAB and 802.1X. The device sends an EAPOL-start but the switch responds with an EAP-Request/Identity. The device does not respond to the EAP-Request/Identity. After a timeout, the switch attempts MAB. However, MAB also fails because the RADIUS server does not have the MAC address. Which of the following best describes the final port state?
Hard180A security team is troubleshooting an incident where a compromised application running in a Kubernetes cluster on AWS EKS is being used to exfiltrate data to an external IP. They have deployed Cisco Secure Workload. How would the agent on the container report the exfiltration attempt?
Hard181A company has deployed Cisco AnyConnect VPN for remote access. They want to enforce that only company-managed devices with compliant antivirus and disk encryption can connect. Which solution should be added to the ASA?
Medium182An engineer is troubleshooting an IPsec VPN between two Cisco routers. The tunnel is up, but traffic is not passing. The encryption domain on both sides is correctly configured. What is the most likely cause?
Hard183A financial services company recently migrated from a legacy web filter to Cisco WSA in explicit proxy mode. The company has 5000 users across three offices, each connected via MPLS. The WSA is deployed in the data center. A week after deployment, users in the remote office report that web pages load extremely slowly, while users in the main office near the data center experience normal speeds. The network team confirms there is no WAN congestion. The WSA administrator checks the logs and sees that the remote users are being authenticated via NTLM and that the WSA's CPU and memory usage are below 50%. However, the number of concurrent connections from the remote office is very high, with many connections in a TIME_WAIT state. What is the most likely cause of the slow web performance for remote users?
Hard184A security analyst is investigating a malware incident on an endpoint protected by Cisco AMP for Endpoints. The Device Trajectory shows that a file named 'invoice.exe' was detonated from a USB drive. The file's cloud verdict was 'Unknown' at the time of execution. The analyst sees that the file spawned multiple child processes that made outbound connections to a malicious IP. The AMP policy has 'Exploit Prevention' enabled but 'File Reputation' is set to 'Monitor' only. The analyst wants to prevent similar incidents in the future without blocking legitimate applications. Which action should the analyst recommend?
Hard185A network administrator is configuring Cisco Umbrella for web security. They want to ensure that all DNS requests from branch offices are sent to Umbrella for policy enforcement, but they have limited control over the branch routers. What is the most effective deployment method?
Hard186On a Cisco ASA, which table holds information about translated addresses for active connections?
Easy187A company is migrating a web application to AWS and wants to protect against DDoS attacks at the application layer. Which Cisco security solution should they deploy?
Medium188An enterprise migrated its e-commerce application to AWS. They use Cisco Secure Workload (Tetration) for microsegmentation. After enabling enforcement, legitimate traffic between the web tier and database tier is being blocked. The security team verified that the policy allows the traffic based on labels. The Tetration console shows the enforcement mode as 'active blocking'. The database server is in a different VPC, and the web server is in a public subnet. The agents are running on both workloads and report correctly. Which configuration step is most likely missing?
Hard189Which THREE attributes can be used in an ISE authorization policy based on endpoint identity?
Hard190Based on the exhibit, what does the 'Isolated: Yes' status indicate?
Easy191During an email security audit, it is discovered that some phishing emails are passing through the Cisco ESA. Analysis shows the emails have valid SPF and DKIM signatures but are classified as phishing. What additional Cisco ESA feature should be tuned to improve detection?
Hard192Which type of VPN on Cisco ASA is typically used for site-to-site connectivity and encrypts all traffic between two sites?
Easy193A remote user is unable to connect to the corporate VPN using Cisco AnyConnect. The user has internet access and can reach the ASA's public IP. The ASA administrator checks and sees that the remote access VPN configuration is correct. What is the most likely client-side issue?
Medium194In AWS, which resource acts as a stateful firewall at the instance level to control inbound and outbound traffic?
Medium195An organization uses Cisco ESA to enforce DLP policies. Which of the following is an example of a DLP policy that can be configured on the ESA?
Medium196A network architect is designing a DMZ for a web server farm. The ASA firewall will have three interfaces: inside (level 100), DMZ (level 50), and outside (level 0). They want to allow HTTP traffic from the internet to the DMZ web servers and also allow the web servers to initiate connections to the inside for database updates. What is the minimal ACL configuration to achieve this?
Medium197A security administrator is tasked with implementing a solution that provides single sign-on (SSO) for users accessing multiple enterprise applications. The solution must support SAML 2.0 and integrate with the existing Microsoft Active Directory. Which component is essential for this architecture?
Easy198A network administrator notices that users in the finance department are unable to access a legitimate business web application that uses custom port 8443. The WSA is configured with a decryption policy that decrypts all traffic on port 443. What is the most likely cause of the issue?
Hard199An organization wants to implement multi-factor authentication (MFA) for VPN access using Cisco AnyConnect and Duo. Which TWO authentication factors can Duo provide? (Choose two.)
Medium200A security engineer is investigating a suspicious process on an endpoint. Using Cisco Secure Endpoint, which EDR capability allows the engineer to isolate the process and prevent it from executing further?
Hard201Which Cisco security product is primarily used for endpoint threat detection and retrospective security?
Medium202An organization uses Cisco Umbrella's Secure Internet Gateway (SIG). Which of the following sets of capabilities is typically included in a SIG solution?
Medium203Which TWO of the following are common causes of email delivery delays in Cisco Email Security Appliance (ESA)? (Select exactly two.)
Easy204A company is using Cisco ISE for guest access. They have configured a guest portal with a self-registration page. Some guests report that after registering, they are not redirected to the success page but instead see a '401 Unauthorized' error. What is the most likely cause?
Hard205A company wants to implement software-defined segmentation using Cisco ISE and TrustSec. Which component is responsible for assigning the Security Group Tag (SGT) to packets at the ingress?
Medium206A network administrator is troubleshooting why users in the marketing department cannot access a specific cloud storage site through the Cisco WSA. The access policy for marketing is set to 'Monitor' for the File Sharing category, but the site is blocked. What is the most likely reason?
Medium207An engineer is designing a cloud security solution using Cisco SD-WAN with cloud on-ramp. They want to ensure that traffic to a specific IaaS provider is inspected by the Cisco Umbrella SIG. Which configuration is necessary on the SD-WAN edge?
Medium208A security administrator is deploying a Cisco ASA in a DMZ architecture. The inside interface is security 100, outside interface is security 0, and DMZ interface is security 50. Which TWO statements about traffic flow are correct?
Medium209A company uses Azure and wants to restrict network traffic between subnets. Which Azure resource should they use?
Medium210Which authentication factor relies on something the user is, such as a fingerprint or retina scan?
Easy211Drag and drop the steps to troubleshoot an IPsec VPN failure where Phase 1 is not completing into the correct order.
Medium212An engineer is deploying Cisco ISE for posture assessment. Which THREE conditions can ISE check during posture assessment before granting full network access? (Choose three.)
Hard213A company is designing a remote access VPN solution using Cisco ASA with load balancing. Which three features are essential for high availability and redundancy? (Choose three.)
Hard214An organization uses multiple SaaS applications and wants to enforce data loss prevention (DLP) policies to prevent sensitive data from being shared externally. Which cloud security solution should be deployed?
Medium215An organization is using Cisco Firepower Threat Defense (FTD) with URL filtering to block access to social media sites during work hours. After implementation, users can still access Facebook and Twitter. The access control policy is configured correctly with a URL category condition. What should the administrator verify first?
Easy216An organization wants to deploy 802.1X for network access control. Which component is responsible for forwarding authentication requests from the endpoint to the authentication server?
Medium217A security team is implementing a DevSecOps pipeline for containerized applications. Which TWO of the following practices should be included to ensure container security?
Medium218Match each protocol to its default port number.
Medium219A company is deploying a new ASA firewall in a DMZ design. They need to allow web traffic from the internet to a web server in the DMZ, while also permitting outbound traffic from the DMZ to the internet for software updates. Which access control approach best meets these requirements with minimal risk?
Medium220A security team wants to enforce data loss prevention (DLP) policies across multiple sanctioned cloud applications used by employees. Which cloud security solution is best suited for this task?
Medium221An organization uses AWS with a VPC and wants to inspect all traffic between instances in the same subnet using Cisco Firepower. What must be implemented?
Hard222An employee receives an email that appears to be from the company's IT department requesting their login credentials. This is an example of which type of attack?
Medium223Which TWO actions can be configured in a Cisco ESA DLP policy to respond to a violation involving outbound credit card numbers? (Choose two.)
Medium224A cloud operations team reports that after enabling Cisco Secure Cloud Analytics (CSCA) for an AWS account, some legitimate traffic is being flagged as suspicious. The team has fine-tuned the ML models but false positives persist. Which additional step should they take?
Hard225An organization requires that all endpoint traffic be verified against a security policy before being forwarded. Which Cisco umbrella solution provides this capability?
Medium226An engineer is troubleshooting traffic drops on a Cisco Firepower Threat Defense (FTD) device. The traffic is allowed by the access control policy but is being dropped. Which feature should the engineer check to identify the cause of the drop?
Hard227An organization wants to enforce multi-factor authentication (MFA) for VPN access using Cisco AnyConnect. Which Cisco product integrates with AnyConnect to provide MFA via push notifications or one-time passwords?
Easy228A security team implements a policy where users must provide a password and a one-time code from a mobile app. Which authentication factors are being used?
Medium229Which TWO of the following are valid methods for Cisco ISE to collect endpoint attributes for profiling? (Choose TWO)
Medium230A network administrator is configuring Cisco Firepower Threat Defense (FTD) in routed mode to provide intrusion prevention (IPS) for internal traffic. They create an access control rule that allows traffic from the internal network (10.0.0.0/8) to the internet, and they attach an intrusion policy to this rule. After deploying the configuration, they generate known malicious traffic from a test host and observe that no alerts are triggered in the Firepower Management Center (FMC). The administrator checks the FTD and confirms that the Snort process is running, and the rule is at the top of the access control policy with action 'Allow'. What is the most likely cause of this issue?
Medium231An organization uses Cisco Umbrella to secure remote users. The security team wants to ensure that all DNS queries from endpoints are forwarded to Umbrella even when users are off the corporate network. Which deployment method achieves this?
Medium232An engineer is tuning an IPS on a Cisco FTD to reduce false positives. Which three techniques are effective? (Choose three.)
Hard233An organization wants to implement URL filtering based on user identity. The Cisco WSA must integrate with which directory service to apply policies per user or group?
Medium234A network administrator is configuring Cisco WSA to intercept web traffic transparently. Which protocol should be used to redirect traffic from the router to the WSA?
Medium235Refer to the exhibit. A Cisco ASA firewall is deployed in a cloud environment. After applying this ACL to an interface, users report that they cannot access cloud instances from on-premises. What is the most likely cause?
Medium236An organization wants to enforce a policy that blocks outbound emails containing Social Security numbers. Which feature of Cisco ESA should be configured?
Medium237A security analyst is monitoring the Cisco FMC and notices a high number of false positives from an intrusion rule that detects SQL injection attempts. The legitimate web application frequently generates similar patterns. Which course of action would reduce false positives while maintaining detection for actual attacks?
Medium238A university is deploying 802.1X authentication for wired access using Cisco ISE. The network consists of Cisco Catalyst switches. The authentication is working for most users, but some users in a specific building are experiencing frequent authentication failures, especially during peak hours. The switches in that building are configured with RADIUS settings pointing to ISE. ISE logs show that authentication requests are being sent but sometimes time out. The network team suspects that the issue is related to RADIUS server load balancing, as the ISE deployment includes two nodes in a distributed model. What is the most likely cause of the timeouts?
Hard239A company is deploying Cisco ISE to enforce access policies based on endpoint posture. Endpoints must be compliant before being granted full network access. Which policy type is used to define the compliance requirements?
Medium240Which TWO are valid considerations for deploying Cisco Firepower NGIPS with inline mode? (Choose two.)
Hard241Which Cisco security solution provides DNS-layer security to block access to malicious domains before a connection is established?
Easy242Which THREE of the following are common indicators of a DDoS attack at the network layer?
Hard243A network administrator is configuring Cisco ISE to authenticate devices that do not support 802.1X supplicant software. Which authentication method should be used for these non-supplicant devices?
Hard244Refer to the exhibit. An administrator has configured the router with zone-based firewall rules. Traffic from the DMZ zone to the OUTSIDE zone is being dropped, although traffic from the INSIDE zone to the OUTSIDE zone flows normally. The DMZ zone is configured with security-level 50 and the INSIDE zone with 100. What is the most likely cause of the dropped traffic?
Medium245A company uses Microsoft Azure and has deployed Cisco CloudCenter for workload lifecycle management. They also use Cisco Firepower NGFW in Azure. A security analyst notices that the Firepower logs show outbound connections from a workload to an IP address in a known threat feed. The workload is a Linux server that runs a custom application. The analyst checks Azure Network Security Groups (NSGs) and finds that outbound traffic is not restricted. The company's policy requires that all outbound traffic be inspected and logged. The analyst wants to block the specific IP while allowing other outbound traffic. Which action should be taken?
Hard246A company uses Cisco AMP for Endpoints and wants to deploy it on mobile devices running iOS and Android. Which deployment method is supported for these platforms?
Medium247An engineer is configuring a Cisco ASA to allow traffic from the inside (security level 100) to the outside (security level 0). They create an access list permitting HTTP traffic from inside to outside and apply it to the inside interface inbound. What is the expected behavior?
Easy248A network administrator wants to deploy Cisco WSA as a transparent proxy using WCCP. Which traffic redirection method does WCCP use?
Medium249A company is deploying Cisco AnyConnect SSL VPN and wants to enforce different access policies based on the endpoint's antivirus status. Which feature should be used?
Medium250In a Cisco TrustSec deployment, security group tags (SGTs) are used to represent user and device roles. These tags must be propagated across the network. Which protocol is used to carry SGT information in Ethernet frames?
Hard251Which TWO of the following are valid methods for deploying Cisco Web Security Appliance in a network? (Choose two.)
Easy252Which TWO of the following are valid detection methods used by Cisco AMP for Endpoints to identify malicious activity?
Medium253In the shared responsibility model for cloud services, which layer is the customer responsible for managing in an IaaS environment?
Easy254Which TWO of the following are correct about Cisco Umbrella's multi-layered security approach? (Choose two.)
Hard255A security engineer is configuring Cisco WSA to block access to a new social media site that is not in any predefined URL category. Which action should the engineer take to ensure the site is blocked for all users?
Easy256An organization uses Cisco AMP for Endpoints and wants to perform a remote investigation on an infected endpoint. The security analyst needs to isolate the endpoint from the network while collecting forensic data. Which AMP feature should be used?
Medium257Which TWO of the following are required to configure a site-to-site IPsec VPN on a Cisco IOS router?
Easy258Which TWO of the following are features of Cisco TrustSec? (Choose TWO)
Easy259An organization uses AWS WAF to protect its web application. They need to block requests from a specific geographic region. What should they configure?
Hard260A university IT team manages 1,000 macOS laptops for students using Cisco AMP for Endpoints. They receive reports that some students' laptops are running slowly and fans are spinning constantly. The team checks the AMP console and sees that these endpoints are performing constant file scans on user directories. The team suspects that the AMP scanning is causing high CPU usage. They want to optimize performance without compromising security. The laptops use the default AMP policy with real-time scanning enabled. What should the team do?
Medium261During an incident response, a forensic analyst finds that an attacker used a script to modify ARP tables, enabling them to intercept and modify traffic between two hosts. Which attack technique was used?
Hard262A security analyst notices that a Cisco Firepower Threat Defense (FTD) device is not applying file policies to detect malware in HTTP traffic. The access control policy has an HTTPS decryption rule that decrypts traffic from external sources. The file policy is associated with the same rule. What is the missing configuration?
Medium263Refer to the exhibit. A network administrator reviews the ISE live log for a successful 802.1X authentication. After authentication, the user is unable to make VoIP calls. What is the most likely cause?
Medium264A SOC analyst notices that a user downloaded a malicious file from a website. The Cisco WSA is configured with AMP file scanning. However, the file was not blocked. Which scenario best explains why AMP failed to detect the file?
Hard265A government agency is deploying Cisco ISE with a posture agent to ensure endpoints comply with security policies before accessing the network. The posture policy requires that all Windows computers have antivirus (AV) software running. The engineer configures a condition 'AV installed and running' and binds it to an authorization profile that grants full access if compliant, or quarantine if not. During testing, a computer that has AV installed and running (verified manually) is placed in quarantine. ISE logs show 'Posture - AV condition not satisfied'. The engineer checks the ISE posture configuration: the AV condition uses a default Cisco AV dictionary. What is the most likely cause?
Easy266Which Cisco security product provides multi-factor authentication through push notifications, TOTP, and hardware tokens?
Easy267An organization uses Cisco Umbrella to block malicious domains. What is the primary security benefit of DNS-layer security?
Medium268A security engineer needs to prevent secrets (e.g., API keys) from being stored in code repositories. Which DevSecOps practice should be implemented?
Hard269A user in the marketing group reports that they cannot access twitter.com. The access policy summary is shown in the exhibit. What is the most likely reason?
Medium270A large enterprise has deployed Cisco ISE for network access control. The network consists of multiple access switches and wireless LAN controllers. The security team wants to enforce that only domain-joined Windows computers with up-to-date antivirus can access the corporate network. Non-compliant devices should be placed in a quarantine VLAN with limited access to remediation servers. The ISE policies are configured with posture assessment. However, during a test, a non-compliant Windows computer is granted full network access instead of being quarantined. The ISE logs show that the posture assessment passed, but the computer's antivirus is outdated. What is the most likely reason for this behavior?
Medium271A global company uses Cisco Umbrella to enforce security policies across roaming users. Recently, a user reported that they could not access a legitimate business application while connected to a guest Wi-Fi at an airport. The application is categorized as 'Productivity' in Umbrella. Other users outside the office can access it. What is the most likely reason?
Hard272Which component of the CIA triad ensures that data is not altered by unauthorized entities during transmission?
Easy273A cloud security team is deploying Cisco Tetration (Secure Workload) in a hybrid cloud environment. Which three are prerequisites for workload discovery and policy enforcement? (Choose three.)
Hard274A network team is configuring Cisco FTD for a new branch office. They want to allow outbound web traffic but block all inbound traffic except for a specific public server. Which policy type should be used to allow the return traffic for outbound connections?
Medium275An administrator configures a Cisco ASA with a DMZ interface at security level 50. Traffic from the inside (level 100) to the DMZ (level 50) is allowed by default. What additional configuration is needed to allow traffic from the DMZ to the inside?
Easy276An organization needs to inspect traffic between two internal zones (e.g., HR and IT) on a Cisco FTD. Which deployment mode is appropriate?
Medium277An organization wants to implement privileged access management (PAM) for critical servers. They require just-in-time access and session recording. Which solution integrates with Cisco SecureX to provide these capabilities?
Medium278Match each security technology to its primary function.
Medium279Which Cisco email security feature uses SHA-256 hash lookups to detect known malware in email attachments?
Easy280Which TWO actions can be taken on a malicious file detected by Cisco AMP for Endpoints?
Easy281Which type of malware is characterized by encrypting files on a victim's system and demanding payment for the decryption key?
Medium282Cisco ISE uses profiling to identify the type of device connecting to the network. Which probe helps ISE identify a device by analyzing the DHCP requests it sends?
Easy283An engineer wants to block traffic from a specific country on a Cisco FTD. Which feature should be used in the access control policy?
Medium284An organization wants to enforce granular data loss prevention (DLP) policies for SaaS applications like Google Drive and Salesforce. Which Cisco product provides cloud access security broker (CASB) functionality with DLP capabilities?
Easy285Which THREE of the following are capabilities of Cisco Email Security Appliance (ESA) for content filtering? (Choose three.)
Medium286In Cisco ASA modular policy framework, what is the function of a class-map?
Medium287A company uses a Cisco FMC to manage multiple FTD devices. They want to decrypt SSL/TLS traffic from internal users to external websites using a known private key. Which SSL decryption method should they use?
Medium288A network administrator wants to block access to a specific URL category on the Cisco WSA but allow access to all other categories. Which action should be taken in the Access Policy?
Easy289A security analyst is investigating a Business Email Compromise (BEC) attack. Which two indicators are commonly associated with BEC attacks? (Choose two.)
Medium290Which VPN technology allows Cisco AnyConnect clients to use UDP for transport to avoid TCP overhead and improve performance?
Medium291Which THREE of the following are common challenges when securing multi-cloud environments? (Choose three.)
Hard292A company is deploying Cisco ISE for guest access. They want to provide a self-service portal where guests can register their devices and receive a temporary username and password. Which ISE component is used to accomplish this?
Medium293A security analyst notices that a file initially deemed 'unknown' by Cisco AMP for Endpoints was later reclassified as 'malicious'. The analyst needs to investigate the propagation of this file across endpoints. Which Cisco AMP feature provides a timeline view of file activity and spread?
Medium294Which TWO of the following are indicators of compromise (IOCs) that can be detected by Cisco AMP for Endpoints?
Easy295A network administrator wants to implement 802.1X authentication on a switch port that connects a printer. The printer does not support 802.1X, so the administrator configures MAC Authentication Bypass (MAB) as a fallback method. Which command must be included in the switch port configuration to ensure MAB is attempted after 802.1X times out?
Easy296A company is deploying a new remote access solution for teleworkers. They need to ensure that only company-owned devices can connect, and that the devices meet security posture requirements. Which combination of technologies should be used?
Medium297Which TWO methods can be used to propagate SGT information between devices that do not support SGT inline tagging?
Medium298During a ransomware attack, an endpoint protected by AMP for Endpoints successfully blocked the ransomware file. Which AMP policy action was likely applied?
Easy299An attacker intercepts traffic between a client and a server and modifies the communication without either party knowing. Which type of attack is being performed?
Hard300A company is using Cisco WSA with transparent proxy via WCCP. The security team wants to identify which users are accessing banned websites and also enforce bandwidth limits for video streaming. Which TWO features should be configured on the WSA?
Medium301A security analyst is reviewing logs and identifies numerous ICMP echo requests from an external IP address to multiple internal hosts. Which type of reconnaissance activity is this?
Easy302A security engineer is configuring Cisco Umbrella to block HTTPS traffic to malicious sites. However, they want to inspect SSL-encrypted traffic selectively to avoid breaking applications. Which Umbrella feature should they use?
Medium303What is the primary difference between signature-based and anomaly-based intrusion detection?
Easy304A security engineer deploys Cisco Advanced Malware Protection (AMP) for Endpoints with cloud-based detection. After installation, a sample malware is executed on a test endpoint, but the AMP console shows no detection or trajectory data. The endpoint shows a 'Connected' status. What is the most likely reason for the lack of detection?
Hard305A company is deploying Cisco Umbrella for web security. They want to enforce that all DNS requests from remote users using VPN are filtered. Which deployment method should be used?
Easy306Which THREE considerations must be taken when deploying SSL decryption on a Cisco WSA in explicit proxy mode?
Medium307A company wants to protect against DNS-based attacks by filtering malicious domains and providing secure DNS resolution. Which Cisco product should be deployed?
Medium308During a security audit, a penetration tester discovers that a Cisco ASA firewall is configured with a rule that permits traffic from the inside interface with a source IP address in the RFC 1918 range to the outside interface. The rule uses the 'inspect' command for HTTP and FTP. Which potential vulnerability does this configuration introduce?
Hard309Refer to the exhibit. An engineer has configured IP Source Guard and DHCP Snooping. A host with MAC 00:11:22:33:44:55 on Gi0/0 is assigned IP 192.168.1.10 via DHCP. However, the host cannot ping its default gateway 192.168.1.1. What is the most likely cause?
Medium310Refer to the exhibit. This JSON policy is part of a Cisco Cloudlock DLP configuration. What will happen when a user attempts to upload a file containing the word 'secret' to a cloud storage service?
Medium311Refer to the exhibit. An ASA is configured with the above access-list and NAT rule. A web server is reachable from the internet via the public IP 203.0.113.10. However, internal users from the inside network cannot access the web server using its public IP address. What is the most likely cause?
Medium312A financial institution with a flat Layer 2 network has experienced a ransomware incident where an infected workstation in the accounting department propagated laterally to a server in the finance department. The network spans 10 switches connected in a star topology with a collapsed core. The IT team wants to implement segmentation to contain such threats in the future, without requiring major hardware upgrades and with minimal change to IP addressing. The network currently uses a single VLAN with /16 subnet. Which of the following approaches would BEST achieve the segmentation goal, considering the constraints?
Hard313An organization is migrating to AWS and wants to ensure that all internet-bound traffic from VPCs is inspected by a central security appliance. Which AWS service should be used to redirect this traffic?
Easy314An administrator configures Cisco Email Security Appliance (ESA) to add a disclaimer to all outgoing emails using a content filter. The filter is enabled and matches all outgoing mail. However, some users report that the disclaimer is missing from their sent emails. Which action should the administrator take to troubleshoot?
Medium315A university is using Cisco ISE to provide secure wireless access for students and faculty. The wireless network uses WPA2-Enterprise with PEAP-MSCHAPv2. Recently, some faculty members reported that they cannot connect to the wireless network from their personal laptops, while student devices connect without issues. The faculty members are using the same SSID and entering their credentials correctly. The ISE logs show that the authentication attempts from faculty devices are failing with 'RADIUS Access-Reject' due to incorrect credentials. However, the faculty members are certain they are using the correct password. The IT department has verified that the user accounts in Active Directory are active and not locked. What is the most likely cause of the issue?
Medium316A Cisco ASA is configured with a modular policy framework to inspect HTTP traffic. The class-map matches HTTP traffic, and the policy-map applies inspection. Which command correctly applies the policy to an interface?
Hard317A company uses Cisco Umbrella to protect its remote users. The security team notices that some users are able to bypass Umbrella by using a different DNS resolver. Which deployment method ensures that all DNS traffic is forced through Umbrella?
Easy318Refer to the exhibit. A switch port is configured for 802.1X with MAB. The switch has reached its maximum number of authentication sessions (platform limit). When a new device attempts to connect, what happens?
Hard319An organization uses Cisco ISE for network access control. After a user authenticates via 802.1X, a posture assessment determines that the user's antivirus definitions are outdated. What ISE feature can be used to dynamically restrict the user's network access until the issue is resolved?
Medium320Which TWO benefits does the Cisco ESA provide for email security? (Choose two.)
Easy321Which TWO are best practices for securing Cisco ASA remote access VPN? (Choose two.)
Medium322A security administrator is configuring Cisco ISE for guest access. Which TWO components are required to allow guests to self-register and obtain network access? (Choose two.)
Medium323An organization wants to use Cisco Umbrella SIG to enforce security policy for remote users. Which deployment method allows Umbrella to inspect traffic for all ports and protocols, not just DNS?
Hard324A financial institution uses Cisco Firepower Threat Defense (FTD) for intrusion prevention and SSL decryption. The security team recently enabled SSL decryption on the FTD to inspect encrypted traffic. After the change, some internal applications that use client certificates for authentication stopped working. The FMC shows that SSL decryption is configured to inspect traffic to specific destination IPs. The applications are using a custom port (TCP 8443) for HTTPS. The administrator has already added the custom port to the SSL decryption policy. What is the most likely reason the applications are failing?
Hard325A Cisco ASA has three interfaces: inside (100), outside (0), and DMZ (50). A static NAT rule is configured to map the DMZ server 10.1.1.10 to outside address 200.1.1.10. An ACL on the outside interface permits traffic to 200.1.1.10. A host on the internet sends a packet to 200.1.1.10. What happens when the packet hits the outside interface?
Medium326A network administrator is configuring Cisco ISE to enforce access control based on user authentication. The company requires that only users who authenticate via Active Directory are allowed access to the corporate wireless network. Which policy should be configured in ISE to accomplish this?
Easy327A Cisco ESA administrator notices that a large number of emails with malicious attachments are being delivered to users. Which feature should be configured to inspect attachments in a sandbox environment before delivery?
Hard328An organization wants to implement multi-factor authentication (MFA) for administrative access to network devices. Which two methods can be used with Cisco Duo to provide MFA for admin access? (Choose two.)
Medium329An organization uses ISE for wireless LAN authentication via 802.1X with PEAP-MSCHAPv2. Users authenticate against Active Directory. Recently, some users report that after changing their domain password, they cannot connect to the wireless network for about 30 minutes. What is the most likely cause?
Easy330Which THREE of the following are valid methods to deploy Cisco AMP for Endpoints Connector on Windows endpoints?
Hard331A company uses Cisco Web Security Appliance (WSA) to filter web traffic. The security team wants to block access to a specific category of websites (e.g., 'Social Networking') for all users except the HR department. Which WSA feature should be used to achieve this policy?
Easy332A company wants to implement a Zero Trust architecture. Which THREE principles should be included? (Choose three.)
Hard333An organization wants to enforce multi-factor authentication for remote VPN access. Cisco AnyConnect is used as the VPN client. Which Cisco product integrates with AnyConnect to provide MFA capabilities such as push notifications and one-time passwords?
Easy334An organization is using Cisco ESA and wants to ensure that outgoing emails containing credit card numbers are blocked before leaving the network. Which feature should be configured?
Medium335A network administrator is configuring Cisco ISE for guest access. The company requires a solution where guests can create their own accounts and receive network access after a sponsor approves. Which two components must be configured? (Choose two.)
Medium336Which Cisco technology uses SHA-256 file hashes to determine if a file is malicious by querying a cloud database?
Easy337A network administrator needs to configure Cisco WSA to decrypt HTTPS traffic for inspection. What is the first step that must be completed?
Easy338A company uses FMC to manage FTD devices. After deploying a new intrusion policy, the analyst sees that no events are generated for a known vulnerability, even though the policy includes a rule for it. The analyst checks and the rule is enabled and the policy is applied. What is the most likely cause?
Hard339An administrator notices that some users receive spam messages even though the ESA policy is set to 'Quarantine' for suspected spam. The messages are not found in the user's spam quarantine. What is the most likely cause?
Medium340A company uses Cisco Umbrella to protect remote users. They want to ensure that SSL-encrypted traffic to malicious websites is inspected, but without breaking compliance with privacy regulations. Which Umbrella feature should they enable?
Medium341During 802.1X authentication, which component acts as the intermediary that forwards authentication requests between the client and the authentication server?
Medium342A company is implementing a Zero Trust architecture. Which THREE principles are core to the Zero Trust model? (Choose three.)
Hard343An organization wants to implement a security model where no user or device is trusted by default, regardless of whether they are inside or outside the network perimeter. Which concept does this describe?
Medium344A company wants to implement two-factor authentication for remote VPN access using Cisco AnyConnect. They need a solution that supports push notifications to a mobile app. Which Cisco product meets this requirement?
Medium345Which THREE are valid components of an IKEv2 exchange? (Choose three.)
Medium346A company uses Cisco Secure Workload to enforce microsegmentation across multiple AWS accounts. After enabling enforcement, they find that the policies are only applied to workloads in the primary account. What is the most likely reason?
Hard347An engineer is configuring a Cisco ASA for site-to-site IKEv2 VPN with a VTI. Which two statements about VTI are true? (Choose two.)
Hard348An engineer is configuring Cisco ISE for guest access. The requirement is that guests must accept an acceptable use policy (AUP) before being granted network access. Which portal type should be used?
Medium349Refer to the exhibit. What is the effect of this NAT rule on the Cisco FTD device deployed in the cloud?
Easy350A security engineer is configuring Cisco Web Security Appliance (WSA) to block access to social media sites during business hours. The company wants to allow access to LinkedIn for the HR department. Which policy configuration approach should the engineer use?
Hard351An engineer is configuring Cisco Secure Endpoint (AMP) connectors. Which deployment is supported for the macOS platform?
Easy352To protect against phishing attacks that use fraudulent emails to trick users into revealing credentials, which email authentication technology verifies the sending domain's DNS records for a digital signature?
Easy353An organization wants to deploy endpoint hardening by allowing only approved applications to run. Which technology should be implemented to achieve this?
Medium354In a Cisco ISE deployment, a network administrator needs to dynamically change the VLAN assignment for an endpoint after a posture assessment determines that the endpoint is non-compliant. Which ISE feature enables this dynamic change without re-authentication?
Medium355A DevOps team is deploying containers in Kubernetes and needs to enforce network security policies between pods. Which Cisco solution is designed for this?
Medium356Which of the following is a characteristic of a 'false negative' in intrusion detection?
Medium357A company has deployed Cisco AMP for Endpoints and wants to receive immediate notification when a file is detected as malicious by the cloud sandbox analysis. Which policy setting should be enabled?
Medium358During a security incident, it is observed that a server behind a Cisco ASA is being accessed repeatedly with different source IPs in a short time. The firewall logs show many dropped packets to the server's IP on port 443. What is the most effective mitigation to reduce the impact while maintaining legitimate access?
Hard359An administrator is configuring DLP on the Cisco ESA to block social security numbers (SSNs) in outgoing email. The policy is set to 'Drop' for SSN matches, but some emails containing SSNs are still being delivered. What step should the administrator take to troubleshoot?
Medium360A DevOps team is deploying containerized applications on Kubernetes and needs to ensure that only authorized images are run. Which solution should they integrate with Kubernetes to enforce image trust and scanning?
Easy361During an email security audit, it is discovered that encrypted emails sent between two partners are being silently dropped by the Cisco ESA. The ESA uses a policy that decrypts incoming S/MIME messages for scanning. What is the most likely cause of the dropped messages?
Hard362A security analyst sees multiple AMP events for 'Trojan.Generic.37283212' on several endpoints. After updating the AMP signatures, the detection still occurs. What is the best next step to reduce false positives?
Medium363Which THREE of the following are features of Cisco Identity Services Engine (ISE) that can be used to enforce network access control?
Hard364A security engineer is configuring a cloud access security broker (CASB) to protect a SaaS application used by employees. The primary concern is to prevent sensitive data from being uploaded to the application. Which deployment mode should the engineer choose?
Easy365A company with 500 employees uses Cisco Web Security Appliance (WSA) as a proxy. They have a policy to block access to social media sites during working hours (9 AM - 5 PM) for all users except the marketing team. The marketing team must have unrestricted access at all times. The WSA is configured with a time-based access policy that blocks the 'Social Networking' category from 9 AM to 5 PM, and an identity policy that identifies the marketing team by Active Directory group. However, marketing users report that they are blocked from social media during working hours. What is the most likely cause?
Easy366A security team deploys Cisco AMP for Endpoints and wants to detect and block memory injection attacks. Which AMP feature should be enabled to achieve this?
Hard367An engineer is configuring a Cisco ASA and needs to ensure that traffic from the outside interface to a web server on the DMZ is allowed. The inside interface is security level 100 and the DMZ is level 50. The outside interface is level 0. Which statement about the default traffic flow is true?
Easy368A network engineer is troubleshooting an issue where users on a specific VLAN cannot access the internet through a Cisco ASA firewall. The ASA has a default route pointing to the ISP router. The security policy includes an ACL that permits all traffic from the inside interface to the outside interface. What is the most likely cause of the problem?
Medium369An organization using Cisco WSA in transparent proxy mode with WCCP redirect notices that some HTTPS traffic is not being decrypted for inspection. The administrator has enabled SSL decryption but certain traffic still bypasses. What is the most likely cause?
Medium370A large enterprise with over 2,000 employees recently experienced a security breach. An attacker gained initial access through a phishing email and then moved laterally across the network to reach a critical database server. The network currently has a flat Layer 2 topology with all devices in a single large VLAN. The company wants to prevent lateral movement in the future while maintaining operational simplicity. They have a Cisco ISE deployment already but it is only used for wireless guest access. The security team is evaluating options. Option A: Deploy 802.1X with dynamic VLAN assignment across all wired ports. This would authenticate users and assign them to different VLANs based on identity. Option B: Implement micro-segmentation using Cisco TrustSec with Security Group Tags (SGTs) on the existing switches and enforce SGT-based policies on the firewalls. This would allow traffic control between groups regardless of IP. Option C: Install a next-generation firewall at the internet edge and enable IPS to block known attack signatures. Option D: Upgrade all access switches to support Private VLANs (PVLANs) and configure promiscuous ports for servers. Which solution BEST addresses the lateral movement problem while leveraging existing infrastructure?
Hard371A network engineer is troubleshooting an issue where an endpoint is failing to authenticate via 802.1X on a Cisco switch. The switch port is in unauthorized state. Which step should the engineer take first to identify the root cause?
Easy372An organization wants to provide guest wireless access with a captive portal. Which Cisco ISE portal type should be used?
Medium373Which THREE components are part of a Cisco Cloud Web Security (CWS) deployment with on-premises connectors? (Choose three.)
Hard374An organization wants to restrict administrative access to Cisco network devices based on the time of day and source IP address. Which technology should be used?
Easy375A security analyst wants to detect misconfigurations in cloud storage buckets using Cisco Secure Cloud Analytics (formerly Stealthwatch Cloud). What must be configured first?
Easy376Which Cisco product provides privileged access management (PAM) capabilities such as just-in-time access, session recording, and password vaulting through integration with CyberArk?
Easy377A company uses a SaaS application for customer relationship management. In the cloud shared responsibility model, which security controls are the customer's primary responsibility?
Easy378A security team wants to gain visibility into shadow IT usage of SaaS applications and enforce DLP policies for data shared via cloud apps. Which cloud security solution should they deploy?
Medium379Which THREE of the following are true regarding HTTPS decryption on Cisco Web Security Appliance (WSA)? (Choose three.)
Easy380During a cloud migration, an organization notices increased latency in AWS workloads when using Cisco Firepower for traffic inspection. What is the most likely cause?
Hard381An administrator configures a Cisco ASA with the following Modular Policy Framework (MPF) commands: class-map type inspect http match any policy-map type inspect http http_policy parameters protocol-violation action reset service-policy http_policy global What is the result of this configuration?
Medium382A company is experiencing an increase in spear-phishing attacks targeting executives. Which TWO Cisco ESA features should be configured to mitigate this threat?
Medium383An attacker uses a tool to scan a target network for open ports and running services. Which type of reconnaissance does this represent?
Medium384Which TWO of the following are authentication methods used for wired network access in Cisco ISE?
Easy385A company is planning to deploy a Zero Trust architecture. Which two principles are fundamental to Zero Trust?
Hard386A security administrator receives an alert that an email with an attachment was blocked by the Cisco Email Security Appliance (ESA). The attachment was identified as malware using cloud lookup. Which technology was used to detect the threat?
Medium387An organization discovers that a man-in-the-middle attack was successfully performed using a forged certificate issued by a trusted CA. The legitimate CA’s private key was compromised. Which PKI component was breached?
Hard388Which component in an 802.1X deployment is responsible for relaying authentication messages between the client and the authentication server?
Easy389A security engineer is configuring Cisco Umbrella to enforce web security for remote users. The requirement is to block threats by intercepting DNS requests and only perform SSL decryption on specific high-risk categories. Which Umbrella feature should be used for selective SSL inspection?
Hard390A company wants to implement privileged access management (PAM) to secure administrative credentials. They need a solution that provides just-in-time access and session recording. Which product integrated with Cisco SecureX can fulfill these requirements?
Medium391An analyst reviews an AMP for Endpoints event where a file was detected as malware but later determined to be a false positive. The analyst wants to prevent this file from being flagged in the future. What is the recommended action?
Hard392Which TWO are valid options for configuring a switch port to handle authentication failures in an 802.1X environment? (Select two.)
Hard393A financial institution uses Cisco ESA and wants to protect against spear phishing attacks targeting executives. The security team configures DMARC with a 'reject' policy for the corporate domain. Additionally, they want to ensure that emails from external sources claiming to be from the CEO are flagged and quarantined. Which THREE security measures should be implemented?
Hard394An organization uses AWS and Azure. They deploy Cisco Secure Workload to enforce microsegmentation. They discover that after deploying agents on EC2 instances, some traffic is misclassified due to overlapping IPs across multiple VPCs. Which configuration change best resolves this?
Medium395A company is deploying Cisco Umbrella with the Intelligent Proxy feature. Under what condition does the Intelligent Proxy perform SSL decryption?
Hard396A laptop fails to authenticate via 802.1X on a Cisco switch. The switch logs show: 'Authentication failed for user 'jdoe' on interface GigabitEthernet1/0/24: EAP session timeout.' What is the most likely cause?
Medium397A security engineer is configuring Cisco ISE to enforce SGT-based access control. The engineer creates an SGACL on the switch that permits traffic from SGT 10 to SGT 20. However, traffic from SGT 10 to SGT 20 is still being dropped. The engineer verifies that the SGTs are correctly assigned. What is a possible reason for the drop?
Hard398An administrator wants to block the download of executable files (.exe) via HTTP using Cisco WSA. Which approach is most effective?
Easy399An administrator is troubleshooting authentication failures for VPN users. The RADIUS server is reachable via ping, but users receive 'AAA authentication failed'. Which command should be used to test communication with the RADIUS server?
Easy400Which Cisco product provides advanced malware protection for endpoints, including file analysis and retrospective security?
Medium401A Cisco FTD device is configured with an SSL decryption rule using 'Decrypt - Known Key'. In which scenario is this action appropriate?
Hard402A security team is investigating an email threat that bypassed the Cisco ESA. The email appears to be from the CFO asking for a wire transfer. Which THREE of the following are characteristics of this attack? (Choose THREE.)
Hard403A network administrator is configuring Cisco ISE for posture assessment. A Windows laptop connects to the network and passes 802.1X authentication. ISE then checks if the antivirus software is running and if the OS patches are up to date. If the posture check fails, ISE should dynamically restrict the endpoint to a remediation VLAN. Which mechanism allows ISE to change the VLAN assignment after authentication without requiring the user to reauthenticate?
Hard404A company is deploying Cisco Secure Web (WSA) and wants to integrate with Active Directory for user-based policies. The proxy is in transparent mode. Which technology allows the WSA to identify users transparently without requiring client configuration?
Medium405Which Snort rule action causes the FTD to drop a packet and generate an alert?
Easy406Which TWO of the following are common security objectives of the Cisco TrustSec solution? (Choose two.)
Easy407Which THREE of the following are recommended best practices for configuring Cisco AMP for Endpoints to minimize false positives while maintaining strong detection?
Medium408An organization uses Cisco Firepower NGFW to enforce content security policies. The security team wants to block all social media traffic during business hours but allow access during lunch breaks. Additionally, they want to detect and alert on any SSL connections to unknown destinations that might indicate data exfiltration. Which THREE capabilities of the NGFW should be combined to achieve these objectives?
Hard409A security architect is designing a zero-trust model for cloud access. Which of the following is a core principle of zero trust in the cloud?
Hard410Which TWO are common causes for CoA (Change of Authorization) failures in a Cisco ISE deployment? (Choose two.)
Hard411Refer to the exhibit. An administrator sees that the file invoice_2024.exe was blocked by both Cisco AMP and ESA. However, a user claims the attachment was delivered. What is the most likely cause?
Hard412Drag and drop the steps to configure a site-to-site IPsec VPN on a Cisco ASA into the correct order.
Medium413An organization uses Cisco AnyConnect SSL VPN with DTLS enabled. What is the primary benefit of DTLS?
Hard414What is the primary purpose of a digital signature?
Medium415An engineer is troubleshooting a Cisco ASA firewall and notices that traffic from a specific subnet is being dropped. The engineer wants to verify if the drop is due to an access control list (ACL) or an inspection policy. Which command should be used to see the reason for packet drops?
Easy416A company is deploying Cisco ESA and wants to protect against malware delivered via email attachments. Which TWO features can be used together to provide both signature-based detection and behavioral analysis?
Medium417Which TWO of the following are valid methods for authenticating VPN users in a Cisco AnyConnect deployment?
Medium418An organization is implementing privileged access management (PAM) using Cisco SecureX and CyberArk. Which PAM capability provides temporary elevated access that is automatically revoked after a set period?
Easy419An enterprise uses multiple IaaS providers (AWS, Azure, GCP). They need a single solution to enforce consistent security policies across all cloud environments. Which Cisco product provides multi-cloud security posture management?
Medium420A network engineer is deploying TrustSec using SGT over VXLAN in a data center fabric. The fabric switches are configured as VXLAN Tunnel Endpoints (VTEPs). The engineer must ensure that SGT information is propagated from the border leaves to the spine. Which mechanism should be used?
Medium421A security administrator is configuring a Cisco FTD device using FMC. The goal is to block traffic from a specific country and allow all other traffic. Which action should be taken in the access control policy?
Medium422An organization is using Cisco Firepower NGFW to enforce content filtering. They want to block social media applications like Facebook and Twitter but allow LinkedIn for business purposes. Which feature should be used to differentiate between these applications?
Medium423A security engineer is tuning an IPS to reduce false positives. They notice that legitimate traffic is triggering a signature for a worm that uses a specific HTTP GET request. The engineer wants to disable the signature for that specific traffic pattern but keep it enabled for other traffic. What is the best approach?
Medium424A SOC analyst is investigating a BEC attack. Which three indicators should be examined in the email headers to detect the spoofing? (Choose three.)
Hard425Which security concept involves creating multiple layers of defense so that if one layer is breached, subsequent layers still provide protection?
Easy426Which Cisco technology uses SenderBase reputation scores (SBRS) to evaluate incoming email?
Easy427An attacker performs a DNS cache poisoning attack on a recursive DNS server. What is the primary impact of this attack?
Medium428A company is deploying Cisco TrustSec to enforce micro-segmentation between data center servers. Security team wants to use Security Group Tags (SGTs) assigned dynamically via ISE. Which method should the engineer use to propagate SGTs to the access switches that connect the servers, assuming the network uses Cisco Nexus 9000 switches and ISE as the policy server?
Medium429A company uses Cisco ISE for network access control. They want to authenticate users connecting via VPN using multi-factor authentication. Which solution integrates with ISE to provide MFA for AnyConnect VPN?
Hard430An engineer is configuring an access control policy on Cisco FMC for FTD. The policy must allow HTTP traffic from the inside zone to the outside zone, but block all other traffic. Which rule configuration is correct?
Medium431A multinational corporation uses Cisco AMP for Endpoints with cloud-based file reputation. The security team notices that a file that was previously determined to be clean (disposition: clean) is now reported as malicious by a threat intelligence feed. However, AMP has not taken any action on endpoints that already executed the file. The administrator confirms that retrospective security is enabled. What should the administrator check first to ensure that the file is remediated on all affected endpoints?
Medium432Which THREE features are available in Cisco Umbrella to protect against DNS-based threats? (Choose three.)
Hard433Which THREE capabilities are provided by Cisco ISE's visibility services within the Secure Network Access domain? (Choose three.)
Hard434A security administrator is evaluating symmetric encryption algorithms for a new VPN deployment. Which algorithm uses a 128-bit block size and supports key sizes of 128, 192, and 256 bits?
Hard435Which type of firewall is best suited to inspect application-layer traffic and protect against exploits like SQL injection?
Easy436A company wants to block social media access for employees during work hours. Which Cisco Firepower NGFW feature should be used to achieve this?
Easy437A company deploys Cisco Duo for multi-factor authentication to protect VPN access. Employees use AnyConnect to connect to the corporate network. After entering their credentials, they receive a push notification on their mobile device. Which Duo authentication method is being used?
Medium438A security engineer is deploying Cisco AMP for Endpoints and wants to ensure that the client can detect and block memory injection attacks. Which AMP feature should be enabled to provide this protection?
Medium439A security engineer is configuring Cisco ISE for 802.1X authentication using EAP-TLS. What must be deployed on the endpoints to support this authentication method?
Hard440On a Cisco ASA, which command applies a policy-map globally to all interfaces?
Easy441A university is using Cisco WSA to filter web traffic for its students and staff. The WSA is configured with transparent proxy mode and uses Active Directory for authentication. Recently, the IT department received complaints that some users cannot access certain educational websites that are correctly categorized as 'Education'. The WSA policy has a default rule that blocks all categories except those explicitly allowed. The 'Education' category is set to 'Allow'. However, affected users are shown a block page with the reason 'Web Reputation: Low Reputation'. The Web Reputation threshold is set to -5.0. The IT team checked the reputation scores of the blocked sites and found they are around -4.5. What is the most likely reason for the block?
Hard442A network engineer is designing a multi-cloud architecture with AWS and Azure. The company needs consistent security policies across both cloud providers and on-premises data centers. Which Cisco solution should the engineer recommend?
Medium443A hospital is deploying Cisco ISE for network access control. They have a mix of employee laptops, medical devices (e.g., infusion pumps), and guest smartphones. The network uses Cisco Catalyst 9300 switches and Aironet 3700 series access points. For medical devices, the policy must use Machine Authentication (MAB) since they are 802.1X incapable. The ISE policy authenticates via MAB and then assigns the device to a specific VLAN for medical devices. During a pilot, the network team notices that some infusion pumps (MAC: 00:1A:2B:3C:4D:5E) are failing MAB authentication. The switch logs show 'Authentication failed for MAC 001a.2b3c.4d5e on interface GigabitEthernet1/0/10'. ISE logs show 'Authentication failed - RADIUS server rejected - Reason: Invalid Endpoint ID'. The engineer has verified the MAC address is in the ISE endpoint repository with correct identity group. What should the engineer check next to resolve this issue?
Hard444An organization wants to connect its on-premises data center to an AWS VPC privately, avoiding the public internet. Which AWS service provides a dedicated, private connection?
Medium445An organization is using Cisco ESA to protect against email-borne threats. They notice that some phishing emails are not being caught by the anti-spam engine. The emails contain malicious URLs that are rewritten by the ESA. Which feature should be verified to ensure the rewritten URLs are properly analyzed?
Medium446A security engineer notices that several endpoints in the HR department have been infected with ransomware despite having Cisco AMP for Endpoints deployed. The AMP policy is set to 'Detect' for all file types. What is the most likely reason the ransomware was not blocked?
Medium447An organization is deploying Cisco Cloud Workload Protection (CWP) in AWS. Which THREE of the following components are part of a standard CWP architecture?
Hard448An email administrator receives reports of a targeted phishing campaign where attackers impersonate the CEO to request wire transfers. Which Cisco ESA feature provides the best defense against this Business Email Compromise (BEC) attack?
Hard449A network engineer is configuring site-to-site IPsec VPN on a Cisco ASA using IKEv2. Which two components are required for IKEv2 configuration? (Choose two.)
Easy450Which TWO of the following are components of Cisco TrustSec?
Easy451An endpoint running Cisco AMP for Endpoints is suspected of being compromised. The security analyst needs to isolate the process and perform a live investigation. Which EDR capability should the analyst use?
Hard452Which cryptographic algorithm is a symmetric block cipher commonly used in modern VPNs and is considered secure?
Easy453Which Cisco cloud-based security solution provides DNS-layer security to block requests to malicious domains?
Easy454A security analyst is tuning Snort rules to reduce false positives. The analyst identifies a rule that triggers on a common benign application. Which action should be taken to suppress alerts for that specific traffic without disabling the rule entirely?
Medium455Which Cisco technology provides visibility into the performance of SaaS applications such as Microsoft 365?
Easy456A company is deploying cloud workload protection for their Azure VMs. They want to ensure that security policies are automatically adjusted based on workload changes. Which technology should they implement?
Easy457An organization wants to implement Privileged Access Management (PAM) using Cisco SecureX and CyberArk. Which THREE capabilities are typically associated with PAM solutions? (Choose three.)
Hard458Which TWO of the following are best practices when configuring Cisco Email Security Appliance (ESA) anti-spam filters? (Choose two.)
Medium459An organization is implementing email authentication to prevent domain spoofing. They have deployed SPF and DKIM. Which additional record should they publish to instruct receiving mail servers on how to handle emails that fail SPF or DKIM checks?
Hard460Which of the following is a characteristic of a zero trust security model?
Easy461An attacker sends a flood of SYN packets with spoofed IP addresses to a server, causing it to allocate resources for half-open connections until it can no longer accept legitimate traffic. This is which type of DDoS attack?
Hard462An administrator is configuring Dynamic Access Policies (DAP) on a Cisco ASA for AnyConnect VPN. Which two attributes can be used to create DAP rules? (Choose two.)
Medium463A security administrator is implementing Cisco AMP for Endpoints and wants to identify files that were initially allowed but later determined to be malicious. Which feature allows the administrator to see the propagation of such a file across the environment?
Easy464Which TWO of the following are benefits of using Cisco Cloudlock for cloud security? (Choose two.)
Medium465A company wants to allow employees to access webmail services but block any upload of attachments that contain malware. Which feature of Cisco WSA should be configured?
Easy466In the shared responsibility model, which is the customer's responsibility in a SaaS model?
Easy467A company is implementing Cisco Umbrella to provide DNS-layer security. They want to block access to known malicious domains while allowing all other traffic. Which policy configuration should be used?
Easy468In a Cisco TrustSec deployment, you want to dynamically assign SGTs based on user authentication. Which mechanism should you use?
Hard469An ASA firewall is configured as shown. A web server is behind the ASA with IP 10.1.1.100. Which additional configuration is required to allow HTTPS traffic from the internet to the web server?
Medium470A company uses Cisco Umbrella to block malicious domains. An endpoint user reports that they cannot access a legitimate business website. The website resolves to a domain that is not on any block list. What is the most likely cause?
Easy471A company is using Cisco Umbrella for cloud security. Which two features are part of the Secure Internet Gateway (SIG) functionality? (Choose two.)
Medium472Refer to the exhibit. The crypto map is applied to an interface. Which additional configuration is necessary for IPsec to function correctly?
Hard473In the shared responsibility model for PaaS, which component is the customer responsible for managing?
Easy474An administrator is configuring a site-to-site IKEv2 VPN between two Cisco ASAs. Which configuration component defines the encryption and authentication algorithms for the IPsec SA?
Hard475Which of the following is the primary function of a Cloud Security Posture Management (CSPM) tool?
Easy476An administrator configures Cisco Email Security Appliance (ESA) with an outbreak filter to handle a new ransomware variant. The outbreak filter is set to 'Quarantine' for messages with a threat score above 70. After deployment, some legitimate emails with a threat score of 75 are quarantined. The administrator wants to reduce false positives without compromising security. Which configuration change should be made?
Hard477A network security engineer is deploying Cisco Firepower Threat Defense (FTD) in a data center. The requirement is to inspect traffic between two internal VLANs while allowing the firewall to enforce access control policies based on source and destination zones. Which deployment mode should the engineer use?
Medium478An organization wants to implement EDR capabilities for endpoints. Which three actions are typically associated with EDR? (Choose three.)
Hard479A company wants to implement Zero Trust principles in their cloud environment. Which THREE of the following are key Zero Trust tenets?
Easy480An organization is adopting zero trust principles for cloud access. Which THREE components should be implemented to enforce identity as the new perimeter?
Medium481Refer to the exhibit. A network administrator is troubleshooting device tracking on a Cisco switch. The output shows two devices in VLAN 100. The switch is configured with IPv6 first-hop security features. The administrator notices that the device with MAC address aaaa.bbbb.cccc is not receiving RA guard protection. What is the most likely reason?
Hard482Which TWO statements about Cisco Umbrella SIG are true?
Medium483Which of the following is an example of a passive reconnaissance technique?
Easy484A company deploys Cisco ASA with clientless SSL VPN to provide remote access to internal web-based applications. Users connect via a web browser and authenticate using RADIUS. The security policy requires that users re-authenticate after 15 minutes of inactivity. The administrator configures the group-policy with 'vpn-idle-timeout 15' and 'vpn-session-timeout 60'. After testing, the administrator finds that users can still access the internal web applications even after the VPN session has timed out. The administrator checks the ASA logs and confirms that the VPN session is indeed terminated. The web applications are standard HTTP-based and do not have their own session timeout mechanisms. What is the most likely cause of this issue?
Medium485A network engineer is troubleshooting an issue where users on VLAN 10 cannot access the internet, but they can reach internal resources. The firewall is configured with a default route pointing to the ISP router. The engineer notices that NAT is configured but traffic is not being translated. Which configuration is most likely missing?
Medium486An organization wants to prevent employees from accessing social media websites during work hours. Which Cisco WSA feature should be used to enforce this policy?
Easy487A company is using Cisco WSA with explicit proxy mode. The security team wants to enforce HTTPS inspection for all web traffic from the finance department to detect malicious content in encrypted connections. However, they want to exclude traffic to financial institutions' websites due to compliance reasons. Which configuration approach should be used to achieve this?
Hard488Which TWO Cisco solutions provide virtual firewall capabilities in public cloud environments? (Choose two.)
Easy489A security engineer is evaluating Cisco solutions to detect and respond to network anomalies, including potential insider threats, by analyzing NetFlow data and behavioral patterns. Which Cisco product is best suited?
Hard490Which TWO of the following are capabilities of Cisco Orbital?
Medium491A security team is implementing secure access for remote users connecting from untrusted networks. They want to enforce DNS-layer security even when users are off the corporate network. Which Cisco Umbrella feature should be deployed on the endpoints?
Medium492An organization wants to enforce endpoint posture compliance before granting network access. In Cisco ISE, which component performs the actual checks on the endpoint to verify antivirus status and patch levels?
Easy493You are a security engineer for a multinational corporation with 5,000 employees. The company uses Cisco Umbrella for DNS-layer security, Cisco Web Security Appliance (WSA) for proxy services in the data center, and Cisco Email Security Appliance (ESA) for email security. Recently, the security team has received multiple reports of users receiving phishing emails that bypass the ESA. The emails contain links to malicious websites that are also not blocked by Umbrella or WSA. Upon investigation, you find that the phishing emails use newly registered domains (less than 24 hours old) and the malicious websites are hosted on cloud infrastructure with frequently changing IP addresses. The company's current security policies rely on signature-based detection and static blocklists. Which action should you take to most effectively mitigate these threats?
Hard494A Cisco FTD administrator is configuring SSL/TLS inspection. They want to inspect encrypted traffic to an external website that uses a certificate signed by a public CA. Which SSL/TLS inspection action should be used to decrypt this traffic?
Hard495A security engineer needs to choose a hashing algorithm for storing passwords. Which of the following should be avoided due to known collision vulnerabilities?
Hard496A global enterprise with over 20,000 endpoints has been using Cisco AMP for Endpoints for two years. They recently migrated to a new SIEM and want to forward AMP events in near real-time. The security operations team notices that the SIEM is receiving duplicate events for the same file execution, causing alert fatigue. The AMP console shows that the 'Send to Syslog' action is enabled on two different policies, and both policies are applied to the same groups of endpoints. The team also uses the AMP APIs to pull data. The network engineer wants to eliminate duplicate events without losing any critical alerts. Which course of action should the engineer take?
Hard497A financial services company uses a multi-cloud strategy with workloads in AWS and Azure. They must comply with PCI DSS, which requires encryption of cardholder data at rest and in transit. The security team has implemented the following: 1) AWS S3 buckets use server-side encryption with AWS KMS (SSE-KMS). 2) Azure Blob Storage uses Azure Storage Service Encryption (SSE) with Azure Key Vault. 3) All traffic between VPCs and VNets uses IPsec VPN tunnels. During an audit, the assessor notes that data stored in AWS S3 is encrypted with a key that is also used for a development environment. Additionally, logs from Azure Blob Storage are accessible to a group of developers with read-only permissions. Which action should the security team take to address the compliance gaps?
Hard498Which Cisco Umbrella feature provides protection against malicious domains by blocking DNS requests to known bad sites?
Medium499Match each Cisco security solution to its primary use case.
Medium500A security engineer is configuring Cisco WSA in explicit proxy mode. Which traffic interception method is being used when each endpoint browser is configured with the proxy address?
Hard501Which TWO of the following are core components of the Cisco Identity Services Engine (ISE) for policy enforcement?
Easy502Which TWO of the following are true about MACsec?
Hard503Which Cisco Firepower management option allows direct device management without a separate server, using a web interface on the FTD itself?
Easy504An engineer is implementing Cisco ISE posture assessment for corporate Windows laptops. The requirement: endpoints that are missing critical Microsoft security patches must be quarantined in a remediation VLAN. The ISE posture policy uses an 'Application Condition' to check for the patch. However, some laptops with missing patches are still allowed access. During testing, the engineer notices that the posture agent reports 'NAC Agent: Posture Unknown' for those laptops. What is the most likely cause?
Hard505Which THREE are key components of Cisco's Cloud Security architecture? (Choose three.)
Hard506A company deploys Cisco ISE for network access control. They need to allow guests to access the internet via a self-registration portal. Which two components must be configured? (Choose two.)
Medium507An administrator is configuring Cisco ESA to protect against Business Email Compromise (BEC) attacks. Which TWO of the following features are most effective in detecting and mitigating BEC?
Medium508Which two controls are considered part of a zero-trust architecture for cloud access? (Choose two.)
Medium509A company deploys a Cisco ASAv in AWS for VPN termination. They need to enforce multi-factor authentication (MFA) for remote access VPN users. Which Cisco solution integrates with ASAv to provide MFA?
Medium510A small business uses Cisco Umbrella to protect its 50 employees. One employee reports that they cannot access a specific website (www.example.com) that is required for their work. The administrator checks the Umbrella dashboard and sees that the domain is categorized as 'Social Networking' and is blocked by the company's policy. However, the employee argues that the website is actually a business tool. The administrator verifies that the website is indeed legitimate. What is the best course of action to restore access while maintaining security?
Easy511A hospital uses Cisco ESA for email security. The compliance team requires that all emails containing protected health information (PHI) be encrypted before leaving the organization. The administrator has configured a content filter that matches emails containing patterns like 'Patient ID: [0-9]{9}' and sends them to the encryption service. However, some encrypted emails are being rejected by the recipient's mail server because the encryption is applied after the email has already been processed. What is the most likely reason for this issue?
Easy512An engineer wants to configure NAT on a Cisco ASA such that multiple internal hosts share a single public IP address when accessing the internet. Which NAT type should be used?
Medium513Which TWO of the following are valid approaches to mitigate ARP spoofing attacks on a switched network?
Medium514An organization uses Cisco ISE for guest access. They want to allow guests to create their own accounts through a web portal while requiring approval from a sponsor before network access is granted. Which guest access method should be configured?
Medium515A security analyst is investigating a potential intrusion and suspects that the IPS is missing some attacks (false negatives). Which two factors can contribute to false negatives in signature-based IPS? (Choose two.)
Medium516A company is moving its data to AWS and wants to use Cisco Cloudlock for cloud access security broker (CASB) capabilities. Which deployment mode is required for Cloudlock to inspect traffic for shadow IT discovery?
Easy517An organization uses Azure for its cloud workloads. To protect web applications from common exploits like SQL injection and cross-site scripting, they need to deploy a web application firewall (WAF) that integrates with Azure Application Gateway. Which Azure WAF SKU should they choose?
Hard518A company is deploying Cisco Umbrella SIG to protect against malware and phishing. The security team wants to ensure that even if a user clicks on a malicious link in an email, the traffic is inspected and blocked if needed. Which TWO features of Umbrella can be used to provide this protection?
Medium519A Cisco FTD is configured with an access control policy that includes a rule to allow traffic from a specific source subnet. However, traffic is being blocked. Which TWO possible causes should be checked?
Hard520A Cisco ASA is configured with a site-to-site VPN using IKEv2. Which component defines the encryption and authentication algorithms for the IPsec tunnel?
Easy521A network engineer is troubleshooting an 802.1X deployment where some Windows 10 endpoints fail to authenticate. Logs show that the client sends an EAPoL-Start but never receives an EAP-Request/Identity. The switch port configuration is: interface GigabitEthernet0/1 switchport mode access authentication port-control auto dot1x pae authenticator Which additional command is most likely needed?
Easy522Match each Cisco ASA feature to its description.
Medium523Which TWO of the following are required for successful registration of an AMP for Endpoints connector with the cloud?
Medium524A security analyst is investigating an alert from Cisco Secure Endpoint indicating that an endpoint has been infected with ransomware. The analyst wants to determine the initial infection vector. Which feature of Cisco Secure Endpoint should the analyst use to trace the chain of events leading to the infection?
Hard525Which THREE are recommended best practices for deploying Cisco AMP for Endpoints in a large enterprise?
Medium526A multinational company has deployed a Cisco Firepower 4100 series device as the perimeter firewall. The network consists of multiple internal segments: a corporate LAN (192.168.1.0/24), a data center (10.10.0.0/16), and a guest wireless network (172.16.0.0/16). The firewall is configured with the following access control policy rules: 1. Allow from any to any (for testing, but currently enabled) 2. Allow from corporate LAN to data center (destination ports TCP/443, TCP/8443) 3. Block from guest wireless to data center 4. Allow from any to internet (destination any) Recently, the security team discovered that a host in the guest network (172.16.5.50) is communicating with a server in the data center (10.10.10.100) on TCP port 443. The security team wants to immediately block this traffic without affecting other legitimate communications. Which action should be taken first?
Hard527A security engineer is configuring Cisco Umbrella to block malicious domains. They need to ensure that internal DNS queries from remote users using Cisco AnyConnect are protected. Which deployment method should they use?
Medium528A security administrator is configuring a Cisco CloudLock policy for a SaaS application. The policy must detect and alert on sharing of files containing personally identifiable information (PII) with external users. Which TWO actions should the administrator take? (Choose two.)
Hard529A company is deploying a cloud-based web application and wants to protect against OWASP Top 10 attacks. Which THREE security controls should they implement? (Select three.)
Easy530A security architect is designing network access control for a campus network. The requirement is to authenticate users before granting network access and to enforce policies based on user identity and device posture. Which solution should be deployed?
Easy531An attacker intercepts ARP packets on a local network and associates their MAC address with the IP address of a legitimate host. This is an example of which attack?
Medium532An organization wants to block access to malicious websites using Cisco Umbrella. Which two protection layers are available with the Umbrella SIG? (Choose two.)
Medium533Which TWO actions are recommended best practices for securing web traffic using Cisco Umbrella?
Medium534Which THREE of the following are key principles of the Cisco Zero Trust security model?
Hard535A security engineer reviews the security group rules for an EC2 instance. Based on the exhibit, which security concern should be addressed immediately?
Hard536A security team is implementing DevSecOps practices. Which TWO actions should be taken to secure secrets (e.g., API keys, passwords) in a CI/CD pipeline? (Choose two.)
Medium537A network administrator configures Cisco ISE to identify devices by analyzing DHCP requests, HTTP user agents, and SNMP queries. Which ISE feature is being used?
Medium538A security administrator notices that a file initially classified as 'unknown' by Cisco AMP for Endpoints was later determined to be malicious after execution. Which feature allows the administrator to see the file's propagation and impact on endpoints?
Easy539An FTD device is deployed in passive mode. Which statement about its traffic processing is true?
Hard540A guest device in VLAN 200 attempts to reach a server at 10.10.1.1. What happens to the traffic?
Easy541A network engineer is tasked with securing email communications. Which TWO Cisco products are specifically designed for email security? (Choose two.)
Medium542During a security incident, an investigator wants to identify all endpoints that communicated with a known malicious IP address within the last 24 hours. Which Cisco tool is best suited for this forensic analysis?
Hard543During a security incident, an analyst needs to isolate a compromised endpoint and perform remote forensic analysis using Cisco AMP for Endpoints. Which capability allows the analyst to execute commands on the endpoint remotely?
Hard544A network administrator is configuring IKEv2 on a Cisco router and wants to ensure that the router does not initiate connections but only responds to incoming IKEv2 requests. Which configuration command should be applied?
Hard545A network security engineer needs to block malicious file downloads on endpoints regardless of the user's location. Which Cisco solution should be integrated with the company's existing endpoint protection platform to achieve cloud-delivered threat intelligence?
Easy546A network administrator is troubleshooting intermittent authentication failures on a switch port configured for 802.1X with MAB fallback. Users can connect but get dropped after a few minutes. What is the most likely cause?
Easy547An administrator needs to enforce 802.1X authentication for devices that do not support 802.1X supplicants. Which method should be configured on Cisco ISE to allow these devices to authenticate?
Easy548A large enterprise uses Cisco Firepower Threat Defense (FTD) as its next-generation firewall. The network team recently deployed a new application that uses HTTPS for all communications. Users report that the application is slow and sometimes fails to load pages. The security team suspects that SSL inspection might be causing the issue. The FTD is configured with an SSL policy that decrypts all HTTPS traffic using a self-signed certificate. The internal CA is not trusted by the application servers. Which action should the engineer take to resolve the performance and connectivity issues while maintaining security visibility?
Easy549Refer to the exhibit. A user is unable to access Dropbox, which is a high-risk application. The administrator wants to allow Dropbox but still block other high-risk apps. What is the most efficient way to achieve this?
Medium550What is the primary function of a Certificate Revocation List (CRL) in a PKI?
Medium551An organization is deploying Cisco WSA in explicit proxy mode. Which three considerations are important for this deployment? (Choose three.)
Hard552During a security incident, a SOC analyst notices that a malicious file was executed on an endpoint. Using Cisco AMP for Endpoints, which feature should the analyst use to visualize the file's propagation and activities across the network over time?
Hard553Refer to the exhibit. A file with SHA256 hash 'a1b2c3d4e5f6...' is detected on an endpoint. The threat grid returns a score of 90 for this file. What action is taken by AMP?
Medium554A company uses Cisco Web Security Appliance (WSA) with transparent proxy mode. Recently, they enabled NTLM authentication. Some users are intermittently prompted for credentials while browsing. What is the most likely cause of this behavior?
Medium555A company uses Cisco Umbrella to enforce web security. After deploying a new policy that blocks all social media sites, users report that they cannot access a corporate Salesforce instance that uses a social login feature. Which Umbrella setting should be adjusted to resolve the issue without weakening the policy?
Medium556Which three components are part of the CIA triad?
Easy557An organization is using Cisco ESA and wants to ensure that emails sent from their domain are authenticated using a cryptographic signature. Which email authentication method should be configured?
Medium558An attacker intercepts communication between a client and server by spoofing ARP messages to associate the attacker's MAC address with the server's IP. This is an example of which type of attack?
Medium559Drag and drop the steps to configure a Cisco router as a DHCP server in the correct order.
Medium560A network administrator is configuring endpoint protection policies for a large enterprise. The requirement is to allow only approved software to run on endpoints, while blocking all other executables. Which Cisco Secure Endpoint feature should be configured? (Choose two.)
Medium561A network administrator is configuring Cisco ISE profiling to identify devices on the network. Which probe allows ISE to identify device type by analyzing the HTTP User-Agent string?
Medium562Which component of a Snort rule specifies the action to take when the rule conditions are matched?
Easy563Which component in the 802.1X architecture is responsible for relaying authentication messages between the client and the authentication server?
Easy564A Cisco WSA administrator wants to prioritize bandwidth for video conferencing applications while limiting recreational streaming. Which feature should be configured?
Medium565Which THREE of the following are valid components of Cisco ISE's visibility and enforcement architecture?
Hard566A company uses Cisco AnyConnect for remote access VPN. They want to allow only specific Active Directory groups to access the corporate network. Which feature on the ASA or FTD should be configured to enforce this?
Medium567A security team is designing an endpoint protection strategy for a mix of Windows and macOS endpoints. They want to use Cisco AMP for Endpoints with centralized management. Which deployment approach minimizes administrative overhead?
Medium568What is the primary purpose of DMARC in email authentication?
Easy569An organization wants to enforce that specific sensitive files are never executed on endpoints. Which AMP for Endpoints feature is most appropriate?
Easy570An administrator is configuring a Cisco ASA 5500-X to perform SSL inspection for outbound traffic. The users must be able to access HTTPS websites without certificate errors. Which configuration step is essential for the ASA to perform decryption?
Easy571A network engineer configures ISE for 802.1X with PEAP-MSCHAPv2. Users report intermittent authentication failures on certain switches. The engineer checks ISE logs and sees 'Authentication failed' with reason 'User not found in identity store'. What is the most likely issue?
Medium572A security engineer is configuring a Cisco Firepower NGFW to detect and block a new malware variant that communicates with a command-and-control server using encrypted DNS queries. Which Cisco security product is best suited to provide visibility into this malicious DNS traffic?
Hard573A company wants to deploy Cisco AMP for Endpoints to protect against advanced malware. Which best practice should be followed when configuring the policy for the first time?
Easy574A company uses Cisco Firepower Threat Defense (FTD) managed by FMC. They want to enable URL filtering based on user identity from an Active Directory (AD) source. Which configuration steps are required on the FMC?
Hard575Which security model requires that all subjects and devices are untrusted by default, and access is granted only after verification, regardless of the network location?
Easy576In a Cisco FTD deployment, which management option allows on-box management without the need for a separate FMC server?
Easy577Which TWO of the following are best practices for securing Cisco routers against unauthorized access? (Choose two.)
Medium578Cisco ISE is configured with posture assessment to ensure endpoints meet security requirements before gaining network access. After a posture check, ISE needs to dynamically change the VLAN assignment for a non-compliant endpoint. Which ISE feature enables this real-time change?
Medium579A cloud security engineer is evaluating CSPM (Cloud Security Posture Management) solutions. Which TWO capabilities are essential for a CSPM tool? (Select two.)
Medium580An engineer is configuring ISE for guest access via a sponsor portal. The policy requires that a sponsor must approve each guest. However, guests are being automatically approved without sponsor interaction. What is the most likely misconfiguration?
Medium581A security analyst observes that one endpoint is generating Alerts of type 'Trojan' in Cisco AMP, but other identical endpoints on the same software version show no issues. After verifying that the signature versions are consistent, what is the most likely cause of the discrepancy?
Hard582In a Cisco TrustSec deployment, after successful authentication, ISE assigns a Security Group Tag (SGT) to the user. Which protocol is used to propagate the SGT to the network devices for policy enforcement?
Hard583In Cisco ISE, which protocol is used for EAP-TLS authentication, and what is the primary requirement for the client to successfully authenticate?
Hard584A security analyst notices that a file previously marked as 'clean' on an endpoint was later determined to be malicious. Using Cisco Secure Endpoint, which feature allows the analyst to see the propagation of that file across the system and understand its impact?
Medium585A security team wants to enforce application whitelisting on endpoints to prevent unauthorized software execution. Which Cisco AMP for Endpoints feature can be used to implement this control?
Hard586A company wants to prevent sensitive data such as credit card numbers from being sent via email. Which Cisco ESA feature should be enabled?
Easy587An organization deploys Cisco ISE for network access control. After successful 802.1X authentication, a user's device is found to be missing critical patches via posture assessment. The administrator wants to dynamically move the user to a remediation VLAN without requiring the user to reconnect. Which ISE capability enables this?
Hard588An administrator is configuring Cisco ISE to profile endpoints. The administrator wants to ensure that endpoints are correctly identified based on MAC address and hostname. Which of the following is a prerequisite for successful profiling?
Easy589A multinational company needs to gain centralized visibility into cloud security posture across AWS, Azure, and GCP. Which Cisco product provides multi-cloud security posture management (CSPM) capabilities?
Easy590A security analyst notices that a user is downloading a file from a website. The Cisco WSA is configured to perform AMP file scanning. What happens when the file's SHA-256 hash is not found in the local cache?
Medium591A company with 5000 endpoints uses Cisco Secure Endpoint (AMP) and Cisco ISE. Users report that legitimate software installations are being quarantined, causing delays. The security team receives many alerts for file executions. The AMP policy is set to "High Security" with "Block Unknown" enabled. Network traffic is monitored by Cisco Stealthwatch. The team wants to reduce operational overhead while maintaining security. What should they do?
Easy592An engineer is designing a FlexVPN deployment with multiple hub routers and spoke routers. The spokes need to establish tunnels to the closest hub based on latency. Which feature should be configured to achieve dynamic hub selection?
Hard593Drag and drop the steps to configure NetFlow on a Cisco IOS router for traffic monitoring in the correct order.
Medium594A security team notices that an AWS Lambda function is allowed to access an S3 bucket containing PII. The Lambda role has an attached policy that grants s3:PutObject and s3:GetObject to the bucket. Which action would be the most effective to ensure least privilege?
Hard595A company's remote employees use Cisco AnyConnect to connect to the corporate network. The VPN is configured with split tunneling so that only traffic to the corporate subnet (10.0.0.0/8) goes through the tunnel, and all other traffic goes directly to the internet. Recently, several employees reported that they cannot access the corporate file server (IP 10.2.3.4) even though they can connect to the VPN. The network team checks the ASA configuration and confirms that the split tunnel ACL includes the corporate subnet. The AnyConnect client shows that it is connected. What is the most likely cause of the issue?
Medium596A security engineer is configuring Cisco Umbrella Intelligent Proxy to selectively decrypt and inspect HTTPS traffic. The goal is to balance security and user privacy by only inspecting traffic to high-risk domains. How does Intelligent Proxy decide which traffic to inspect?
Hard597An incident responder is analyzing an endpoint that was compromised despite AMP for Endpoints being deployed. The AMP logs show the malware file had a disposition of 'Unknown' shortly before compromise, but later changed to 'Malicious' after cloud analysis. What is the most likely reason the file was not blocked initially?
Hard598An ISE deployment uses TrustSec with SGTs assigned by Active Directory group membership. A group of users in the 'Finance' AD group is correctly receiving SGT 5, but a new user added to that group is getting SGT 0. The ISE policy is unchanged, and other users in the group work fine. What is the most likely cause?
Hard599A network engineer is configuring Cisco TrustSec on a switch to enforce segmentation. Which THREE components are required for TrustSec to assign a Security Group Tag (SGT) to a user after successful authentication via ISE?
Medium600Which Cisco product provides next-generation firewall (NGFW) capabilities, including application visibility and intrusion prevention?
Easy601Which TWO factors should be considered when designing a Cisco ISE deployment for network access control (NAC) in a multi-site environment? (Choose two.)
Easy602A multinational corporation is deploying Cisco ISE to enforce network access for both wired and wireless users. The company has 5,000 employees and 2,000 guest users daily. The ISE deployment consists of two nodes: a primary Administration Node (PAN) and a Monitoring Node (MNT). All policies are configured on the PAN. Recently, the company has experienced intermittent authentication failures during peak hours. The failures affect both wired 802.1X and wireless users. The syslogs show 'RADIUS request dropped' messages on the ISE nodes. The network team has verified that the RADIUS shared secret is correct and that the network devices can reach the ISE nodes. The ISE nodes have sufficient CPU and memory. However, the authentication failures correlate with times when the number of concurrent sessions exceeds 500. What is the most likely cause of the issue?
Hard603Which Cisco FTD feature provides application visibility and control (AVC) to identify and block applications like Facebook or Skype?
Medium604A security team is implementing Privileged Access Management (PAM) using CyberArk integrated with Cisco SecureX. They need to provide just-in-time access to a critical server for a specific task, with automatic password rotation after use. Which PAM capability addresses this requirement?
Hard605Which two conditions must be met for Cisco Firepower Threat Defense (FTD) to perform SSL decryption?
Easy606Which TWO are required to successfully deploy Cisco AMP for Endpoints in a Windows domain environment with Group Policy?
Easy607A company uses Cisco Threat Response (CTR) to investigate a potential breach. The analyst sees an observable (SHA256) with a score of 90 in the threat grid. However, the AMP connector on the endpoint shows 'Allow' for that file. What could cause this discrepancy?
Hard608Refer to the exhibit. The engineer configured a file type filter for executables on access policy Policy_A. However, .exe files from trusted_sites are still being allowed. What is the most likely reason for this behavior?
Medium609A network administrator is deploying Cisco AMP for Endpoints to protect against advanced malware. They want to ensure that if a file is initially allowed but later determined to be malicious, the file is automatically blocked and quarantined on all endpoints that have executed it. Which AMP feature should be configured?
Medium610An administrator configures a Cisco ASA with an interface named 'inside' at security level 100 and 'outside' at security level 0. Which statement about traffic flow is true?
Easy611A security architect is designing a solution to detect and block ransomware using Cisco AMP. The requirement is that when a file executes and attempts to encrypt files in a monitored directory, the event must be captured and the process terminated immediately. Which AMP feature set should be used?
Hard612An engineer is tuning Snort signatures on a Cisco FTD to reduce false positives. A rule triggers on legitimate traffic that matches a known exploit pattern but is actually benign. Which tuning technique would be most appropriate to suppress the alerts without completely disabling the rule?
Hard613Refer to the exhibit. What happened to the file 'crack.exe'?
Easy614An endpoint security engineer wants to protect against memory injection attacks on endpoints running Windows. Which Cisco AMP feature should be enabled?
Easy615A company is deploying a multi-tier application on AWS. The web servers must be accessible from the internet only on ports 80 and 443, while the database servers should be accessible only from the web servers on port 3306. Which combination of cloud network security controls should be used?
Hard616A security engineer is troubleshooting an issue where a known malicious file (SHA-256: 3a7c...f9e) is not being detected by Cisco Secure Endpoint on a Windows 10 endpoint. The file was downloaded from the internet. The policy has the 'File Reputation' setting set to 'Use cloud lookup', and the 'Exploit Prevention' module is enabled. The endpoint is connected to the internet and can reach the AMP cloud. What is the most likely reason for the missed detection?
Hard617A network engineer is troubleshooting 802.1X authentication on a Cisco switch. Users report that they cannot authenticate. The engineer verifies that the switch (authenticator) is configured correctly and the RADIUS server (ISE) is reachable. Which component is most likely misconfigured on the client side?
Medium618An engineer is troubleshooting why AMP for Endpoints is not detecting a specific malicious file. The file hash is available and other endpoints detected it. What is the most likely cause for the detection failure on this endpoint?
Hard619A security administrator notices that a significant volume of spam is bypassing the Cisco ESA's anti-spam filters. Upon investigation, they find that the messages have a mid-range SBRS score of 5.0. Which action should the administrator take to improve spam detection?
Medium620Which 802.1X component is responsible for enforcing access control on the network and relaying authentication messages between the client and the authentication server?
Easy621A security team is implementing endpoint hardening measures. They want to ensure that only approved applications can run, monitor for suspicious behavior, and have the ability to isolate processes if needed. Which THREE Cisco AMP features should they enable? (Choose three.)
Hard622Which TWO are valid methods for integrating Cisco Umbrella with an existing network to provide DNS-layer security?
Easy623Which two actions are valid actions in a Cisco Firepower access control rule? (Choose two.)
Easy624A network administrator is configuring an ASA to enforce that traffic between two internal zones must be inspected by the firewall. Which security principle is being applied?
Hard625A security analyst is tuning Snort IPS rules to reduce false positives. Which TWO strategies are effective?
Medium626An organization wants to prevent sensitive data such as credit card numbers from being sent via email. Which TWO features of Cisco ESA can be used to achieve this?
Easy627In Cisco Firepower Management Center (FMC), which action in an access control rule will send a TCP RST to the source and destination and log the event?
Easy628A company wants to enforce consistent security policies for Office 365, Salesforce, and Box. Which Cisco product provides CASB functionality with policy enforcement for SaaS applications?
Easy629A security administrator wants to enforce a policy that blocks upload of sensitive data to unauthorized cloud applications. Which technology should be used to gain visibility and control over sanctioned and unsanctioned SaaS applications?
Medium630Which THREE of the following are best practices for deploying Cisco Web Security Appliance (WSA) in a large enterprise environment? (Select exactly three.)
Hard631An administrator reviews the AMP event log shown in the exhibit. The same file hash appears in all events. What is the most likely explanation for the third event showing a 'TETRA Event' with 'Action: Quarantine' and 'Disposition: Unknown'?
Hard632Refer to the exhibit. A security analyst sees this syslog message on a Cisco ASA. What does it indicate?
Easy633A security administrator notices that a file initially classified as 'unknown' by Cisco AMP for Endpoints has been later determined to be malicious. Which Cisco AMP feature allows the administrator to see the file's propagation and impacts across endpoints?
Easy634A security analyst is configuring Cisco Secure Endpoint (AMP) to detect and respond to threats. Which TWO features are part of the Exploit Prevention capability? (Choose two.)
Medium635A company wants to deploy endpoint hardening measures to prevent unauthorized applications from executing. Which THREE techniques are commonly used for application control? (Choose three.)
Hard636A Cisco ESA administrator is investigating an increase in false positive detections from the outbreak filter. The filter is configured to use TALOS intelligence and has a threshold of 'Medium'. Which action would most effectively reduce false positives while maintaining protection against new outbreaks?
Hard637An attacker uses Shodan to discover internet-facing ICS devices and then performs banner grabbing. This is an example of which type of attack?
Easy638An organization has deployed Cisco AMP for Endpoints and wants to automatically isolate a host from the network when a high-severity malware detection occurs. Which integration must be configured to enable this automated response?
Medium639A Cisco WSA administrator needs to implement HTTPS inspection for traffic from internal users. The administrator wants to avoid decrypting traffic to financial and healthcare sites due to compliance requirements. Which THREE actions should the administrator take to configure this policy?
Hard640A company has a Cisco ASA firewall configured with multiple access-lists applied to the outside interface. The security team is investigating reports that legitimate HTTPS traffic to a public web server located on a DMZ is intermittently being blocked. The firewall configuration includes an ACL that permits traffic to the web server's IP address on TCP 443, but also includes a general deny rule for all other traffic. The engineer notices that the permit rule is placed after a deny rule that blocks traffic from a specific source subnet that is used by internal users for testing. The internal users report that they can access the web server, but external users sometimes experience timeouts. What is the most likely cause of the intermittent blocking?
Medium641A network administrator wants to deploy security products that provide network-based intrusion prevention and advanced threat detection. Which TWO Cisco products are most suitable? (Choose two.)
Medium642During a cloud migration, the security team uses Cisco CloudLock for DLP. They notice that the DLP engine is not scanning certain files in Google Drive shared with external users. The CloudLock admin console shows the connector status as 'connected'. What is the most likely cause?
Hard643An organization deploys Cisco Secure Firewall (formerly Firepower) in a public cloud environment (AWS). They need to inspect traffic between VPCs. What is the recommended deployment model?
Medium644A company uses Cisco Umbrella for DNS-layer security. They want to block access to known malicious IPs that may be resolved by non-DNS traffic. Which feature should they enable?
Easy645In a Cisco ISE 802.1X deployment, which component acts as the authenticator?
Easy646A multinational company has recently deployed Cisco Umbrella for DNS-layer security across all offices. The security team receives reports that users in the Asia-Pacific region cannot access a critical cloud-based CRM application (crm.company.com). The CRM is hosted by a third-party provider and uses a custom domain. The Umbrella dashboard shows that DNS requests for crm.company.com are being blocked with the reason 'Cisco Umbrella Intelligence Feed: Blocked Domain'. The domain is not part of any standard security category. The IT team has verified that the domain is legitimate and necessary for business operations. What should the administrator do to restore access while maintaining security?
Medium647A company deploys Cisco Firepower Threat Defense (FTD) in transparent mode. They create an access control rule to allow HTTP traffic from the inside network (10.10.10.0/24) to a web server at 192.168.1.100. The rule is configured with action 'Allow', a source zone 'inside', a destination zone 'outside', and an intrusion policy attached. After deployment, users report they cannot access the web server. The administrator verifies that the web server is reachable from other networks and that the FTD management interface is accessible. The FTD's packet capture shows no traffic matching the rule. The rule is listed first in the access control policy. What is the most likely cause of the problem?
Easy648A security analyst wants to investigate a remote endpoint that is suspected of being compromised. Using Cisco AMP for Endpoints, which capability allows the analyst to run commands on the endpoint and perform live analysis?
Medium649Which THREE steps should the administrator take to troubleshoot slow web browsing when using Cisco WSA? (Choose three.)
Medium650In a Cisco TrustSec environment, a network administrator observes that traffic between two endpoints in the same SGT group is being denied. The relevant switch has CTS configured with 'cts manual' and 'policy static sgt 10'. What is the most probable cause?
Hard651An organization wants to enforce MFA for all administrative access to their Azure environment and also require that access from non-compliant devices be blocked. Which Azure feature should they use?
Medium652Which component of Cisco AMP for Endpoints is responsible for preventing the execution of known malware by checking files against a continuously updated cloud database before they run?
Easy653A company wants to enforce that all outbound emails containing credit card numbers are blocked. Which Cisco ESA feature should be configured to achieve this?
Medium654A company is implementing DMARC for its domain. The administrator wants to instruct receivers to reject emails that fail SPF or DKIM checks. Which DMARC policy should the administrator set?
Medium655Match each VPN type to its characteristic.
Medium656Which Cisco Umbrella feature provides off-network protection by intercepting DNS requests on a user's device?
Easy657An organization is deploying Cisco AnyConnect VPN with split tunneling. They want to ensure that only traffic destined for the corporate network goes through the VPN tunnel, while internet-bound traffic goes directly. Which configuration element on the ASA controls this?
Medium658Which Cisco ISE node is responsible for authenticating endpoints and enforcing access policies?
Easy659An administrator is configuring Cisco ISE profiling using Device Sensor. Which two types of information can the Device Sensor collect from endpoints? (Choose two.)
Easy660A security analyst is investigating a compromised endpoint that is part of a botnet. The endpoint is running Cisco Secure Endpoint with TETRA. The analyst notices that the endpoint is communicating with a command-and-control (C2) server over HTTPS. Which TETRA feature would be most effective in detecting this traffic?
Medium661A company is using a SaaS application like Office 365. Which security responsibility falls on the customer according to the shared responsibility model?
Easy662Which of the following is a characteristic of anomaly-based intrusion detection compared to signature-based detection?
Easy663Which three actions are available in a Cisco Firepower access control rule? (Choose three.)
Easy664A network administrator is configuring 802.1X for wired access on a Cisco switch. The switch is configured for RADIUS using a Cisco ISE server. During testing, a client that supports 802.1X is unable to authenticate and fails to gain network access. The administrator checks the switch logs and sees "Authentication failed: invalid EAP code received". What is the most likely cause?
Easy665An organization is deploying Cisco TrustSec and uses SXP to propagate SGTs between routers that do not support SGT inline tagging. The SXP connection is established, but the SGT mappings are not being learned. The administrator checks 'show sxp connections' and sees the connection is in 'On' state. What is the most likely issue?
Hard666A security engineer is configuring Cisco Web Security Appliance (WSA) to block downloads of potentially malicious file types such as .exe and .scr. The engineer wants to ensure that these files are blocked even if they are hosted on trusted websites. Which TWO actions should the engineer take?
Easy667Which TWO methods can be used to enforce least privilege within a network infrastructure? (Choose two.)
Medium668Cisco ISE is configured to assign Security Group Tags (SGTs) to endpoints based on their identity. This is part of which Cisco security architecture?
Easy669Which THREE are valid methods to obtain security group tags (SGTs) on a Cisco switch? (Choose three.)
Medium670After applying a new extended ACL inbound on an interface, users report they can no longer reach a critical server on a different subnet. The ACL permits the server's IP and required ports. What is the most likely cause?
Easy671An engineer is configuring a Modular Policy Framework (MPF) on a Cisco ASA to inspect HTTP traffic and apply QoS. The engineer creates a class-map to match HTTP traffic using the 'match port tcp 80' command. However, the policy is not being applied correctly. What is the most likely reason?
Hard672A company uses Azure AD Conditional Access policies to enforce security for cloud applications. They need to require MFA for all external users accessing a sensitive SaaS app, but only when the access is from an untrusted network. Which condition should be configured in the policy?
Hard673A network administrator is deploying Cisco ISE for network access control. The administrator needs to profile devices that connect to the network. Which TWO probes can be used to gather information for device profiling? (Choose two.)
Medium674Which Cisco WSA feature allows administrators to control bandwidth usage per user or group by limiting the amount of bandwidth consumed for specific applications?
Easy675An organization wants to implement zero trust principles for cloud access. Which of the following is a key component of a zero trust architecture in the cloud?
Easy676A security analyst is investigating a potential insider threat. Which TWO indicators are most commonly associated with malicious insider activity? (Choose two.)
Medium677A company using Cisco ESA receives an email that appears to be from the CEO requesting an urgent wire transfer. The email fails SPF and DKIM checks but passes DMARC. What is the most likely explanation?
Hard678Which THREE symptoms indicate that a Cisco ESA is experiencing a mail loop?
Hard679A security team is implementing AWS WAF to protect a web application. They want to block requests that contain SQL injection patterns in the query string. Which AWS WAF component should be used?
Medium680In a DevSecOps pipeline, which tool would be used to scan Infrastructure as Code (IaC) templates for security misconfigurations?
Easy681A company wants to use Cisco DUO for MFA to protect access to its Azure AD applications. Which authentication method should be configured for cloud applications?
Easy682Which EAP method used with 802.1X requires a client-side certificate for authentication?
Easy683Which security model mandates that access decisions should be based on context, device posture, and user identity, and never trust any entity by default?
Medium684Match each Cisco security command to its function.
Medium685A Cisco ASA firewall is configured with multiple contexts. The administrator needs to allow traffic from a context to pass through the management context for management purposes. Which type of interface should be used for this inter-context communication?
Easy686A Cisco WSA administrator wants to block access to social media sites for all users during work hours. The proxy is deployed in explicit mode. Which policy type should the administrator use to enforce this restriction?
Medium687An organization wants to provide network access to guest users through Cisco ISE. Guests must register themselves and accept an acceptable use policy before gaining internet-only access. Which guest access method should be configured?
Medium688A Cisco FTD is deployed in a data center and needs to provide intrusion prevention and application control. Which two actions are available in an access control rule? (Choose two.)
Medium689A security team wants to inspect SSL-encrypted traffic from users accessing SaaS applications through Cisco Umbrella. Which feature should they enable?
Medium690A PKI administrator needs to check the revocation status of a certificate without causing a heavy load on the CA. Which protocol should be used?
Hard691An organization wants to deploy endpoint hardening measures. Which three capabilities are provided by Cisco AMP for Endpoints as part of EDR (Endpoint Detection and Response)? (Choose three.)
Hard692Cisco TrustSec uses Security Group Tags (SGTs) for policy enforcement. Which two components are required for TrustSec to function? (Choose two.)
Medium693An organization wants to grant temporary administrative access to a server for a specific task and automatically revoke the access after the task is completed. Which Cisco solution should be used?
Medium694An engineer is deploying a Cisco FTD in inline mode and wants to inspect SSL/TLS traffic using the 'decrypt-resign' action. What must be configured on the client devices to avoid certificate errors?
Hard695A Cisco FTD is configured with a file policy to detect malware. The policy includes a rule to block files with a SHA-256 hash that is known to be malicious. Which component provides the SHA-256 disposition?
Hard696During a cloud migration, an administrator notices that a workload in Azure is generating outbound traffic that is being blocked by the cloud security group. The workload requires connectivity to a specific SaaS application (Office 365) using TLS. The security group denies all outbound traffic except to specific IP ranges. Which action should the administrator take?
Hard697Cisco ISE posture assessment requires that endpoints meet certain security requirements before being granted network access. Which of the following is a typical posture requirement?
Medium698An attacker intercepts traffic between a client and server using ARP spoofing. Which type of attack is this?
Hard699A security architect is designing a hybrid cloud with AWS and on-premises data center. They need to enforce consistent security policies across both environments. Which approach is most effective?
Medium700An incident responder notices that an AMP connector on a critical server has stopped sending 'IP to Application' mapping events after a software update. Which step should be taken to restore this telemetry?
Medium701A security team wants to gain visibility into Shadow IT usage of SaaS applications and enforce data loss prevention policies. Which cloud security solution should they deploy?
Medium702In the shared responsibility model for cloud computing, which responsibility is managed by the customer in all service models (IaaS, PaaS, SaaS)?
Easy703Which THREE of the following are capabilities of Cisco Threat Response (CTR) that integrate with endpoint telemetry for accelerated detection and response?
Hard704A security analyst discovers that a user downloaded a CSV file containing social security numbers from a sanctioned cloud storage app, but no alert was generated. The DLP policy shown in the exhibit was applied. What is the most likely reason the policy failed to trigger?
Hard705A security engineer is configuring Cisco TrustSec on a network. Which TWO actions are required to enable TrustSec on a Cisco switch?
Medium706An engineer is configuring Cisco ISE for 802.1X authentication. The organization has a mix of devices, including some that do not support 802.1X supplicants. Which method should the engineer use to allow these non-supplicant devices to authenticate?
Medium707A Cisco FTD is configured with an access control policy that includes an intrusion policy. Which three actions can be set in an access control rule regarding intrusion inspection? (Choose three.)
Hard708A company's Cisco WSA is configured with explicit proxy mode. Users report that they can browse the internet but cannot access internal websites hosted on the company's intranet. What is the most likely cause?
Easy709A company is adopting a zero-trust security model for its cloud environment. Which THREE practices align with zero-trust principles? (Choose three.)
Medium710An organization using Cisco Firepower NGFW wants to block all social media traffic while allowing other web traffic. Which feature should be configured?
Medium711In Cisco ISE, profiling is used to identify device types. Which probe must be enabled for ISE to determine the operating system of a device by analyzing DHCP options?
Medium712Which statement accurately describes the difference between signature-based and anomaly-based intrusion detection?
Easy713In a PKI hierarchy, which component is responsible for issuing and revoking certificates for end entities, and is directly subordinate to the root CA?
Hard714A company is planning to use Cisco Umbrella to secure internet access for branch offices. They already have Cisco Meraki MX appliances at each branch. What is the best way to send DNS traffic from the branches to Umbrella?
Easy715In Cisco ESA, which feature uses TALOS intelligence to provide real-time protection against newly identified email threats before signature updates are available?
Hard716A large enterprise uses Cisco WSA with integrated Cisco Advanced Malware Protection (AMP) to inspect web traffic. The security policy dictates that all downloaded files should be scanned by AMP. Recently, a user downloaded a PDF file from a trusted vendor site, but the download was blocked by the WSA. The administrator checks the WSA logs and sees that the file was blocked due to AMP's 'File Reputation' score of 10 (high risk). However, the vendor confirms the file is legitimate. The administrator notes that the file is digitally signed by the vendor. What is the most appropriate next step to allow the file while maintaining security?
Hard717A security engineer is deploying Cisco AMP for Endpoints in an organization. To ensure that any malicious file that was initially allowed but later determined to be malicious can be traced, which feature should be used?
Medium718A large enterprise has deployed Cisco ISE for network access control with 802.1X and MAB across its wired and wireless networks. The network consists of Cisco Catalyst switches, Cisco Wireless LAN Controllers (WLCs), and ISE in a distributed deployment with three Policy Service Nodes (PSNs) and an Admin Node. Recently, the company implemented a new security policy requiring all endpoints to pass posture assessment before gaining full network access. The posture assessment uses AnyConnect ISE Posture Module. Shortly after the change, users report that some wired clients are unable to connect to the network. The ISE logs show that the authentication is successful, but the session is terminated immediately with a 'Session-Timeout' attribute set to 0. The network team notices that the affected clients are all connected to switches running older Cisco IOS versions. The ISE administrator confirms that the authorization profiles for the affected clients include a session-timeout of 1 hour. Which course of action should the network engineer take to resolve the issue?
Hard719A network administrator is configuring Cisco ISE for device profiling. The goal is to identify the type of device (e.g., Windows PC, iPhone, printer) connecting to the network. Which probe should be used to gather the DHCP option 60 (vendor class identifier) and option 12 (hostname) information?
Hard720A security engineer is configuring Cisco WSA for HTTPS inspection but notices that some encrypted traffic is being bypassed. The WSA is configured with a decryption policy that excludes traffic to financial websites. What is the most likely reason for the bypass?
Hard721Match each Cisco security product to its category.
Medium722A company with 500 endpoints uses Cisco AMP for Endpoints with a private cloud and a single Threat Grid appliance for file analysis. The security team notices that some endpoints are not receiving updates to the local malware signatures for over 24 hours. The AMP console shows these endpoints as 'Out of Date'. The network team confirms that the endpoints can reach the private cloud server on TCP port 443. The endpoints are running Windows 10 with the latest AMP connector version. The private cloud server has sufficient disk space and is running normally. The AMP console shows that the 'Update Policy' is enabled and set to download signatures every 4 hours. Which action should the administrator take to resolve the issue?
Medium723An engineer needs to allow inbound HTTP traffic from the internet to a web server in the DMZ on a Cisco ASA. The DMZ interface security level is 50, and the outside interface is 0. Which interface direction should the access control entry be applied?
Easy724Which interface security level is assigned to the inside interface on a Cisco ASA by default?
Easy725Refer to the exhibit. An engineer has configured the ACL on the GigabitEthernet0/0 interface. Which of the following is true about the effect of this ACL?
Hard726A network administrator wants to implement 802.1X on a Cisco switch port for a device that does not support 802.1X. Which feature should be configured to allow the device to connect?
Easy727An organization is adopting zero trust principles for cloud access. Which THREE measures are essential for implementing identity-centric security? (Choose three.)
Hard728A network engineer is troubleshooting an issue where a user's device is successfully authenticated via 802.1X, but the user cannot access the corporate network. ISE logs show that the user was granted access with a downloadable ACL (dACL). What could be the cause of no network access?
Medium729A company is deploying Cisco Cloud Web Security (CWS) using an on-premises connector. They want to authenticate users via Active Directory and apply granular policies based on user identity. Which authentication method should be configured on the connector?
Medium730An organization is adopting Cisco's security portfolio. Which THREE products are correctly paired with their primary function? (Choose three.)
Hard731A company's server is infected with malware that encrypts files and demands payment for decryption. Which type of malware is this?
Medium732Refer to the exhibit. A network analyst reviews a Stealthwatch flow analysis output. What is the most likely interpretation?
Medium733Refer to the exhibit. A network administrator applies the ACL to the interface. What is the effect on traffic inbound to the interface?
Medium734Which authentication factor does a fingerprint scanner represent?
Easy735An organization wants to prevent malware from executing on endpoints by using a file reputation service. Which Cisco technology provides cloud-based file reputation and analysis for endpoint protection?
Easy736During a network audit, an engineer finds that a switch configured for 802.1X is allowing a device to access the network without authentication. The switch logs show 'MAB failed', 'dot1x failed', but the port is in the forwarding state. The port configuration includes 'authentication fallback final mab' and 'dot1x timeout server-timeout 10'. What is the most likely explanation?
Hard737A network administrator is configuring a site-to-site VPN between two Cisco ASA firewalls using IKEv2. Which component defines the encryption and authentication algorithms for the IPsec SA?
Medium738A security engineer is configuring a Cisco FTD high availability pair in active/standby mode. Which statement is true about the failover configuration?
Medium739A cloud architect is designing a hybrid network between on-premises and AWS. They need to ensure traffic to the internet from the VPC uses the on-premises security stack for inspection. The VPC has an Internet Gateway (IGW). What must be configured to force outbound traffic to the on-premises firewall?
Hard740An organization uses Cisco ISE for network access control. They want to authenticate users with certificates for strong security. Which two EAP methods support certificate-based authentication? (Choose two.)
Medium741An organization uses Cisco Umbrella to protect remote users. The security team notices that some malicious domains are not blocked because users are bypassing the DNS layer by using direct IP connections or non-DNS protocols. Which Cisco Umbrella feature should be enabled to inspect all traffic, including non-web traffic, and enforce policies regardless of DNS resolution?
Hard742An organization implements a policy where every access request must be authenticated and authorized, even if it originates from within the internal network. Network segments are isolated, and lateral movement is restricted through microsegmentation. Which security model does this align with?
Hard743An engineer wants to configure high availability on a pair of Cisco Firepower Threat Defense (FTD) devices. Which HA mode supports active/standby failover with stateful replication of connection information?
Medium744Cisco AMP for Endpoints provides endpoint protection. Which two are core capabilities of AMP? (Choose two.)
Easy745An organization uses Cisco Umbrella for DNS-layer security. They want to block access to a newly discovered malicious domain (malware.example.com) immediately. Which action should the administrator take in the Umbrella dashboard?
Medium746A company wants to ensure that only authorized applications can run on endpoints. Which feature of Cisco AMP for Endpoints should be used to create a whitelist of allowed applications?
Easy747An organization is migrating from on-premises Cisco ESA to Cisco Cloud Email Security (CES). They need to ensure that email encryption policies remain consistent after migration. What is the best approach to migrate the encryption policies?
Medium748An engineer observes that the Cisco ASA connection table shows a consistent number of entries for UDP traffic, but the xlate table shows no entries. What is the most likely reason?
Hard749A company uses Cisco ISE for network access control. Users connecting via wired 802.1X are successfully authenticated but cannot reach the internet. The administrator checks the authorization policy and notices that the correct dACL is being applied. What is the most likely cause of the issue?
Medium750A multinational corporation is migrating its on-premises data center to a public cloud provider. The security policy requires that all traffic between cloud VPCs and the on-premises network must be inspected by a next-generation firewall (NGFW) deployed in the cloud. The on-premises network uses BGP for dynamic routing. Which design meets the requirement while minimizing latency and administrative overhead?
Hard751An organization uses Cisco Umbrella to block malicious domains. The security team notices that some malware traffic bypasses DNS-layer blocking because the malware uses hardcoded IP addresses. Which Umbrella feature should be enabled to additionally inspect traffic at the IP layer?
Medium752Which protocol does Cisco ISE use to communicate with network devices for 802.1X authentication?
Medium753During a security incident, an engineer needs to quickly quarantine an endpoint that is connected to a switch via 802.1X. The engineer wants to use ISE to send a Change of Authorization (CoA) to move the port to a restrictive VLAN. What must be configured on the switch to allow ISE to send CoA?
Hard754An organization wants to ensure that digital certificates issued by its internal CA are validated for revocation in real-time. Which protocol should be implemented to allow clients to check certificate status without downloading a full CRL?
Medium755A company wants to deploy a DMZ segment accessible from the internet. Which THREE considerations are critical for firewall zone design and security?
Hard756A company has deployed Cisco ISE for network access control. After a recent upgrade, the operations team notices that some users are being assigned incorrect authorization profiles. The ISE logs show that the users are being matched to the correct identity group, but the authorization result is different from expected. What is the most likely cause?
Hard757Drag and drop the steps to configure a Cisco ASA for remote access VPN using AnyConnect in the correct order.
Medium758An organization is adopting a zero-trust model for cloud access. Which component enforces conditional access policies based on user, device, location, and risk level in Azure AD?
Medium759A company deploys a solution that uses a root certificate authority (CA) and intermediate CAs to issue certificates. What is the term for the hierarchical structure of certificates from the root CA to the end entity?
Medium760A security engineer is configuring a Cisco Firepower NGFW to detect a buffer overflow attack. Which attack vector is this?
Hard761A small business uses Cisco Umbrella for DNS-layer security. They recently enabled multi-factor authentication (MFA) for all administration accounts. The IT manager is unable to log into the Umbrella dashboard; the login page accepts his password but then asks for an MFA code. However, he never set up MFA. He checks his email and finds no registration email. He is the only administrator. How should he regain access to the Umbrella dashboard?
Easy762An administrator is migrating an ASA firewall to a cloud environment and wants to use FlexConfig to push additional configuration. After applying the FlexConfig, the ASA does not show the expected commands. Which of the following is a likely reason?
Hard763A network administrator needs to provide network access to a legacy printer that does not support 802.1X. Which Cisco ISE feature should be used to authenticate this device?
Hard764An organization is deploying Cisco Duo for multi-factor authentication. Which TWO authentication methods can be used with Duo? (Choose two.)
Medium765A security administrator is reviewing firewall logs and notices that an internal user is generating excessive outbound DNS queries to a known malicious domain. The company uses Cisco Umbrella for DNS-layer security. How should the administrator investigate and block this traffic?
Medium766Which TWO benefits does centralized RADIUS authentication provide over local authentication on network devices? (Choose two.)
Easy767A security analyst needs to investigate a potential breach on an endpoint running Cisco AMP. The analyst wants to remotely execute commands to gather forensic data and potentially isolate the endpoint from the network. Which Cisco AMP EDR capability should the analyst use?
Medium768Which THREE are characteristics of Cisco Stealthwatch?
Hard769Drag and drop the steps to implement Cisco Umbrella (formerly OpenDNS) for DNS-layer security in the correct order.
Medium770A network engineer is troubleshooting 802.1X authentication failures. Which two components are required for a successful 802.1X authentication? (Choose two.)
Medium771Which Cisco security product provides DNS-layer security to block malicious domains and cloud-based threats?
Easy772A company uses Cisco Umbrella to provide DNS-layer security. An employee tries to visit a website that is hosting malware, but the domain is not yet categorized. How does Umbrella handle this request?
Medium773A security team is investigating a breach where the attacker gained access to a server using stolen credentials. Later, the attacker moved laterally and exfiltrated data. Which three security controls would best help detect and prevent lateral movement? (Choose three.)
Hard774A Cisco TrustSec deployment is being implemented to enforce micro-segmentation. The security team needs to ensure that Security Group Tags (SGTs) are propagated across the network. Which THREE methods can be used to distribute SGT information in a TrustSec environment? (Choose three.)
Medium775An email administrator sees the above log entry in the Cisco ESA. What will happen to the email?
Medium776Refer to the exhibit. A user attempts to SSH to the router. The RADIUS server is unreachable. What will happen?
Easy777A network engineer is configuring a site-to-site VPN between two Cisco ASAs using IKEv2. Which component defines the encryption and hash algorithms for Phase 2?
Medium778A security administrator is configuring URL filtering on Cisco FTD. Which three categories are commonly used in URL filtering policies? (Choose three.)
Medium779A network engineer is configuring Cisco Umbrella to secure remote users connecting to a SaaS application. The users are not assigned a static public IP and often connect from various locations. Which deployment method best protects these users?
Easy780During a security audit, it is discovered that some users are bypassing the proxy by using HTTPS tunnels over port 443. The WSA is configured with an explicit proxy mode. What additional configuration is needed to prevent such bypass?
Medium781A network engineer is troubleshooting an endpoint that failed to receive policy updates from the Cisco AMP cloud. The endpoint shows 'Out-of-Date' in the AMP console. The engineer verifies that the endpoint has outbound HTTPS access to the AMP cloud. What additional step should the engineer take to resolve the issue?
Medium782A company deploys Cisco ISE for network access control. They want to enforce that only employees with a valid certificate and a compliant posture can access the corporate Wi-Fi. Which policy combination should be used?
Medium783A SOC analyst notices that after deploying Cisco AMP for Endpoints, some legitimate business software is being blocked by the Exploit Prevention engine. What is the recommended action to allow this software while maintaining maximum security?
Medium784A security analyst notices traffic from an internal host to an external IP address on port 4444, and the host's CPU is high. The host has been running unknown processes. Which type of malware is most likely involved?
Medium785A security analyst detects a DDoS attack targeting the company's web server. Which three attack types are classified as application layer attacks? (Choose three.)
Hard786A company is moving its on-premises applications to AWS EC2 instances. According to the shared responsibility model, which of the following is the customer's responsibility?
Easy787A security engineer is configuring Duo for VPN authentication with AnyConnect. Which authentication factor does Duo provide in addition to the user's primary credentials?
Medium788A company is implementing zero trust architecture in the cloud. Which TWO principles are fundamental to zero trust? (Choose two.)
Medium789A company uses multiple cloud providers (AWS and Azure) and wants to unify security monitoring and policy enforcement. They have on-premises data centers as well. Which Cisco solution is best suited for this?
Medium790An organization uses Cisco Umbrella to block malicious domains. Which layer does Umbrella primarily operate at to prevent connections before they are established?
Medium791A company uses Cisco WSA in transparent mode. They want to bypass proxy processing for all traffic to a specific internal server (10.0.0.5) to reduce latency. They create an access policy with a custom URL category and add the server's IP to the 'Proxy Bypass' list. However, traffic to that server is still being proxied. What is the most likely cause?
Medium792A company uses Cisco AnyConnect for remote access VPN. Which two components are used to enforce policies based on endpoint posture? (Choose two.)
Medium793A security analyst notices that emails from a trusted partner's domain are being quarantined by the Cisco ESA. The analyst wants to verify the email authentication status. Which TWO authentication mechanisms should be checked?
Medium794Refer to the exhibit. A security administrator implements this S3 bucket policy to restrict access to the bucket 'my-bucket'. What type of condition is being used?
Easy795Which cloud security control is specifically designed to protect workloads such as VMs and containers from threats?
Easy796An organization wants to prevent outbound email containing credit card numbers from leaving the network. Which Cisco ESA feature should be configured?
Easy797A company uses multiple SaaS applications and wants to enforce data loss prevention (DLP) policies to prevent sensitive data from being shared externally. Which technology provides the ability to scan data in transit and at rest within these SaaS applications?
Medium798A network administrator wants to deploy Cisco AMP for Endpoints to protect endpoints. Which feature allows the detection of a file that was initially deemed benign but later discovered to be malicious?
Easy799In the shared responsibility model for PaaS, which of the following is the customer responsible for?
Easy800An organization uses Cisco ISE with TrustSec to assign Security Group Tags (SGTs) to endpoints based on their role. An endpoint initially receives an SGT for 'Employees' but after a posture check reveals missing antivirus updates, ISE changes the SGT to 'Quarantine'. Which ISE feature dynamically updates the SGT?
Hard801A company uses Cisco WSA with multiple authentication realms (LDAP, RADIUS, and local). They want to require multi-factor authentication (MFA) for external users but allow single sign-on (SSO) for internal corporate users. Which configuration approach should be used?
Hard802Refer to the exhibit. An administrator notices that DNS responses larger than 512 bytes are being dropped. Which configuration change should be made to allow larger DNS responses?
Hard803A company is using Azure and wants to enforce security compliance across their cloud resources. Which TWO services are part of CSPM (Cloud Security Posture Management) in Azure? (Choose two.)
Medium804A small business uses Cisco ISE to authenticate employees via Active Directory. The company has a single ISE node and two Catalyst 2960-X switches. Employees connect to the network and are successfully authenticated using 802.1X with PEAP. The business wants to provide guest wireless access using a separate SSID with a captive portal. The engineer configures a new WLAN on the WLC (Cisco 2504) pointing to the same ISE node. Guest users can associate to the WLAN and get an IP address, but when they open a browser, they do not see the captive portal page; instead, they get a 'Connection refused' error. The engineer verifies that the guest portal is enabled on ISE and the WLC is configured to use ISE for RADIUS. What is the most likely cause?
Easy805A company wants to provide both corporate and guest wireless access using the same access points. They require that guest users be placed into a separate VLAN and have internet-only access. Which Cisco solution should be used?
Medium806An administrator wants to prevent confidential data (e.g., credit card numbers) from being sent via email using Cisco ESA. Which feature should be enabled and configured with the appropriate dictionary?
Easy807The ISE logs show 'Authentication failed - RADIUS attribute Calling-Station-ID is missing' for a wired client. What is the most likely cause?
Easy808Refer to the exhibit. A security analyst notices this CloudTrail log entry. Which security best practice is being violated?
Hard809A security engineer is implementing Cisco Identity Services Engine (ISE) for 802.1X authentication. The requirement is to allow full network access for corporate devices that pass posture assessment, while providing limited access for guest devices. The engineer configures an authorization policy with conditions based on identity group and posture status. However, guest devices are still getting full access. What is the most likely cause?
Hard810Which cloud workload protection platform (CWPP) capability is essential for protecting containerized applications?
Medium811A Cisco Firepower administrator configures an access control policy with a rule that trusts traffic from a specific source network. What is the effect of the trust action on the traffic?
Medium812On a Cisco ASA, which NAT type allows multiple internal hosts to share a single public IP address by using different source ports?
Easy813What is the correct order of email authentication checks recommended by Cisco?
Easy814Which Cisco product provides DNS-layer security to block malicious domains and prevent connections to malware command-and-control servers?
Easy815To enforce zero trust principles in a cloud environment, an administrator requires all access to cloud resources to be authenticated and authorized based on user identity and device health. Which Cisco Duo feature enables policies that consider conditions such as location, device compliance, and risk level?
Medium816A user connected to port Gi1/0/1 cannot access the network. Based on the output, what is the most likely cause?
Medium817An organization wants to protect against Business Email Compromise (BEC) attacks where attackers spoof the CEO's email address to request wire transfers. Which email authentication method is specifically designed to help prevent domain spoofing by allowing senders to specify how email that fails authentication should be handled?
Easy818An organization wants to deploy Cisco Firepower in a high-availability pair with active/standby failover. Which management solution allows this configuration?
Medium819Refer to the exhibit. A network engineer applies a zone-based firewall policy to a router. Users in the INSIDE zone report they can access HTTP servers on the OUTSIDE zone but cannot resolve DNS names or access MS-SQL servers. What does the policy do to DNS and MS-SQL traffic?
Hard820In a DevSecOps pipeline, a team wants to prevent secrets (e.g., API keys) from being stored in source code. Which approach is most effective?
Hard821An administrator needs to ensure that only authorized hosts can connect to a switch port. The port is connected to a single PC. Which 802.1X host mode should be configured?
Easy822A financial company uses Cisco AMP for Endpoints to protect 500 Windows workstations. The security administrator notices that several endpoints in the accounting department are showing 'Out-of-Date' status for over a week. The administrator checks the AMP console and sees that the group policy for accounting has been modified to disable certain scanning features. The endpoints have Internet connectivity but are not updating their policy or receiving new definitions. The administrator suspects a misconfiguration. What should the administrator do first to resolve this issue?
Easy823Which encryption algorithm is classified as symmetric?
Easy824Which THREE actions should a security engineer take when configuring a Cisco AMP for Endpoints policy to minimize false positives while maintaining strong protection?
Hard825An organization wants to implement endpoint protection that uses behavioral analysis to detect ransomware. The solution must be able to roll back changes made by the ransomware after detection. Which Cisco endpoint security feature provides this capability?
Easy826An organization deploys AMP for Endpoints with the Orbital module to perform advanced endpoint telemetry. The team wants to create a query that retrieves all running processes with a network connection to an external IP address. Which Orbital query language syntax is correct?
Hard827Which Cisco ESA feature uses SHA-256 cloud lookups to detect malware in email attachments?
Easy828A security team suspects that malware is exfiltrating data by encoding it in DNS queries. Which Cisco security solution is specifically designed to analyze DNS traffic for malicious activity?
Hard829A security analyst notices a high number of false positives from an intrusion detection system (IDS) using signature-based detection. Which action would best reduce false positives while maintaining detection of real threats?
Medium830Refer to the exhibit. An engineer is analyzing an intrusion policy on Cisco Firepower Management Center (FMC). The network uses Windows servers and clients. A flood of HTTP traffic is being detected as a potential attack, but it is legitimate. Which preprocessor configuration change would most likely reduce false positives without losing detection of real attacks?
Hard831In a DevSecOps pipeline, a security engineer wants to automatically scan Infrastructure as Code (IaC) templates for security misconfigurations before deployment. Which tool is commonly used for static analysis of Terraform templates?
Easy832A network administrator is troubleshooting an issue where users in the Sales VLAN cannot access the internet through the Cisco Firepower Threat Defense (FTD) device. The FTD is configured with a security policy that allows traffic from the Sales subnet to any destination. However, the traffic is being blocked. Which feature should the administrator check first to resolve the issue?
Easy833During a threat hunt, you need to retrieve forensic data from a remote endpoint that is currently not communicating with the AMP cloud. Which Cisco tool enables you to perform an on-demand scan and collect telemetry from that endpoint even when it is offline?
Hard834Match each 802.1X component to its role.
Medium835A security architect is evaluating Cisco Cloud Security portfolio for SaaS access protection. Which two solutions provide inline traffic inspection for cloud applications? (Choose two.)
Easy836Refer to the exhibit. A network administrator is troubleshooting a wired client that has successfully authenticated using MAB. However, the client is unable to access resources beyond the local subnet. What is the most likely cause?
Easy837A security architect is designing a zero-trust architecture for a remote workforce using Cisco SD-WAN. The company requires that all traffic between branch sites and the data center is encrypted and authenticated, and that no device can access resources unless it has a valid certificate. Which technology should be used to enforce device identity?
Hard838A security analyst is investigating a potential ARP spoofing attack. Which two symptoms would indicate this type of attack?
Medium839Which three cryptographic algorithms are considered secure for use in modern systems? (Choose three.)
Medium840An organization is implementing Cisco Secure Cloud Insights (formerly CloudCenter). Which three capabilities does this tool provide? (Choose three.)
Medium841A security analyst notices unusual outbound traffic from an internal host to a known malicious IP address on TCP port 4444. The host is also exhibiting high CPU usage and running an unknown process. Which type of malware is most likely present?
Medium842A network architect is designing a DMZ for a web server that must be accessible from the internet. The server should not initiate connections to the internal network. Which firewall rule best achieves this?
Medium843A security administrator discovers that users are evading the corporate firewall by using SSH to tunnel HTTP traffic to external servers. Which action can be taken on a Cisco ASA firewall to detect and prevent this?
Hard844Which TWO of the following are capabilities of Cisco Umbrella SIG? (Choose TWO.)
Medium845A company has 500 users who work remotely and connect to cloud-based SaaS applications. The security team is concerned about malware downloads from these applications. They have deployed Cisco Umbrella with the SIG feature. However, after deployment, a test shows that downloading a file from Dropbox is not being inspected by the cloud security stack. The Umbrella dashboard indicates that the policy is active and the SIG feature is enabled. The network team confirms that the users are using the Umbrella roaming client and that the traffic is correctly forwarding to Umbrella. What is the most likely issue?
Medium846A network administrator is troubleshooting an issue where users cannot send emails with attachments larger than 10 MB through the Cisco Email Security Appliance (ESA). The ESA is configured with a mail flow policy that has a maximum message size of 20 MB. What is the most likely cause of the issue?
Hard847An organization is deploying containerized applications in a Kubernetes cluster on AWS EKS. They need to ensure that container images are scanned for vulnerabilities before deployment. Which approach aligns with DevSecOps best practices?
Hard848A network engineer notices that some Windows 10 clients fail to authenticate via 802.1X after a recent OS update. The supplicant shows 'EAPOL-Start' but never receives an EAP-Request/Identity. The switch port is configured with 'authentication port-control auto' and 'dot1x pae authenticator'. What is the most likely cause?
Medium849A security analyst is reviewing logs and sees multiple failed login attempts from a single IP address, followed by a successful login. Which type of attack does this represent?
Easy850A network administrator is configuring 802.1X authentication on Cisco switches for wired endpoints. Which protocol is used between the client (supplicant) and the switch (authenticator)?
Easy851Match each encryption algorithm to its type.
Medium852An engineer is configuring a Cisco AnyConnect SSL VPN for remote access. Which TWO features are commonly used to control access based on endpoint security posture?
Medium853A company is designing a secure segmentation strategy for a three-tier web application. They want to isolate the web, application, and database tiers while allowing only necessary traffic. Which design best achieves defense-in-depth while minimizing complexity?
Medium854An organization is deploying Cisco Secure Endpoint (AMP) for the first time in a Windows environment. The security team wants to ensure that any file executed from a USB drive is automatically scanned and blocked if malicious. Which policy feature should be enabled to achieve this?
Easy855Which of the following is a benefit of using Dynamic Access Policy (DAP) for AnyConnect SSL VPN?
Easy856Drag and drop the steps to recover a lost password on a Cisco IOS router in the correct order.
Medium857An engineer is configuring a Cisco ASA to allow inbound HTTPS traffic from the outside to a web server on the DMZ. The outside interface has security level 0, the DMZ interface has security level 50, and the inside has security level 100. Which set of commands correctly allows the traffic considering stateful inspection?
Medium858Which Cisco Firepower feature uses SHA-256 hashes to determine the disposition of files and block malware?
Medium859A security administrator is implementing a zero-trust architecture. Which two principles are core to the zero-trust model? (Choose two.)
Medium860You are a security engineer for a multinational corporation that uses a hybrid cloud environment with AWS and Azure. The company has deployed Cisco Cloudlock for SaaS security and Cisco Umbrella for DNS-layer security. Recently, the incident response team detected that an employee's credentials were compromised, and the attacker used them to access the company's Office 365 tenant. The attacker exfiltrated sensitive data by sending emails with attachments to external addresses. Cloudlock logs show that the data exfiltration occurred because the policy for 'Outbound Email with Attachments' was set to 'Allow' for all users. The attacker also used a personal Google Drive account to store stolen data, which was not detected by Cloudlock because Google Drive is not sanctioned. You need to recommend a course of action to prevent similar incidents. Which action should you take first?
Hard861A network administrator is configuring PKI for secure communications. Which TWO components are essential for a public key infrastructure? (Choose two.)
Easy862A network administrator is configuring management access on a Cisco router. The requirement is to provide encrypted remote access with AAA authentication and fallback to local credentials if the AAA server is unavailable. Which configuration best meets these requirements?
Medium863An organization is implementing a zero trust architecture. Which two principles are foundational to this model? (Choose two.)
Medium864A security analyst needs to enforce that all endpoints have antivirus software running and are up-to-date with patches before granting full network access. Which Cisco ISE feature should be used to enforce this policy?
Medium865A company uses Cisco Umbrella SIG to secure internet access for remote users. The security team wants to block access to social media websites but allow access to business-related websites that may share the same IP addresses. Which Umbrella feature should be used to enforce this granular control?
Medium866A network administrator is configuring Cisco Email Security Appliance (ESA) to prevent outgoing spam. The company wants to ensure that all outgoing emails contain a legal disclaimer and that any email with more than 20 recipients is delayed. Which two features should be combined?
Easy867An organization is using Microsoft 365 and wants to prevent sensitive data from being shared externally via email and OneDrive. Which Cisco cloud security product should they deploy?
Medium868Refer to the exhibit. A network engineer configures a site-to-site VPN between a Cisco router and an Azure VPN gateway. After configuration, the tunnel is not coming up. Which issue is most likely causing the problem?
Hard869A DevSecOps team is implementing secrets management for a cloud-native application. They want to avoid storing secrets in environment variables or code. Which solution should they use?
Hard870Which THREE are characteristics of Cisco ISE profiler service?
Medium871An engineer is troubleshooting a site-to-site IPsec VPN between two Cisco routers. The tunnel is not establishing. Which command would verify that IKE phase 1 negotiations have completed successfully?
Easy872Refer to the exhibit. An administrator in us-west-2 tries to launch an instance. The policy allows only us-east-1. What should the administrator do to successfully launch the instance?
Hard873A company is deploying Cisco Umbrella to protect against DNS-based threats. Which deployment method provides the most comprehensive coverage for all devices on the network without requiring per-device configuration?
Medium874A security engineer is evaluating a web application firewall (WAF) rule set. The application uses a custom REST API that accepts JSON payloads. Which WAF rule is most effective at preventing SQL injection attacks while minimizing false positives?
Hard875An organization has deployed Cisco WSA in explicit proxy mode. Users are required to authenticate using their Active Directory credentials. Which WSA feature enables transparent user identification without requiring users to manually log in?
Hard876An organization is deploying Cisco ESA and wants to ensure that outbound emails containing credit card numbers are blocked. The administrator configures a DLP policy to scan for credit card patterns. However, some legitimate emails with credit card numbers are being incorrectly blocked. What is the best approach to reduce false positives while still preventing data leakage?
Hard877A Cisco FTD device is deployed in inline mode and configured with an SSL policy to decrypt traffic. The policy uses 'Decrypt - Known Key' for traffic to an internal server. What is required for this decryption to work?
Hard878A company uses Cisco WSA to proxy web traffic. After configuring a decryption policy to inspect HTTPS traffic to a specific external site, users report they can still access the site without any warning or interruption. Which action should the administrator take to ensure HTTPS inspection is applied?
Medium879An enterprise wants to prevent data exfiltration from its SaaS applications to unauthorized personal cloud storage. Which Cisco solution should be deployed?
Easy880A company has a site-to-site VPN between two ASA firewalls using IKEv2. The tunnel was working but after an upgrade, it fails. The engineer verifies that the pre-shared keys match, IKE proposals are compatible, and the crypto ACL is correctly defined. What is the next likely cause to investigate?
Medium881An engineer notices that the 'show authentication sessions' command on a switch shows a session in 'CRITICAL' state. What does this indicate?
Hard882A security analyst observes a sustained increase in traffic from many different IP addresses to a single web application, causing CPU spikes. The traffic consists of legitimate-looking HTTP GET requests for the same resource. Which TWO types of attack could this be? (Choose two.)
Medium883Which of the following is a characteristic of a stateful firewall like Cisco ASA?
Easy884A company uses Cisco Firepower Management Center (FMC) to manage multiple FTD devices. They want to create an access control policy that allows traffic from a specific user group (Active Directory) to access a web server on the internet, but blocks all other traffic from that group to the internet. Which identity source should be configured in FMC?
Medium885An engineer is troubleshooting a Cisco WSA that is failing to block malware downloads from a specific cloud storage website. The URL filtering policy is set to block the 'Cloud Storage' category, and the Web Reputation score is set to block scores below -5.0. Users can still download files. What is the most likely cause?
Hard886A network engineer is deploying a Cisco FTD in active/standby high availability. Which statement is true about the configuration synchronization?
Hard887Based on the exhibit, what is the root cause of the AMP connector's inability to connect to the cloud?
Hard888A large enterprise is migrating legacy applications to AWS. The security team requires that all data in transit between the applications and the on-premises data center be encrypted and inspected for threats. They have deployed a Cisco Firepower NGFW on-premises and are using Amazon VPC with a VPN connection. The team is concerned about east-west traffic within the VPC also being inspected. They consider deploying Cisco Secure Firewall in the cloud (cFMC). However, budget constraints limit the number of virtual firewalls. Which design best meets the requirements while optimizing cost?
Medium889A large enterprise uses Cisco ISE with pxGrid to share context with Firepower for threat containment. When a Firepower detects an infected endpoint, it triggers a pxGrid quarantine action that changes the endpoint's authorization profile. The engineer observes that the quarantine is applied, but after the Firepower clears the threat, the endpoint does not regain its original access. What is the most likely reason?
Medium890Which TWO conditions must be met for a Cisco switch to initiate 802.1X authentication? (Choose two.)
Medium891An organization uses Cisco ESA to filter inbound email. The security team notices that some phishing emails are reaching users despite having an anti-spam policy. Further analysis reveals that the emails are sent from a domain that is gray-listed but not blocked. What should the administrator do to prevent these emails without impacting legitimate emails?
Medium892An organization implements multi-factor authentication requiring a password and a fingerprint scan. Which two authentication factors are being used?
Medium893A security analyst is investigating an alert from Cisco AMP for Endpoints. The analyst wants to perform remote actions on the endpoint. Which TWO actions are available in AMP for Endpoints? (Choose two.)
Medium894A company wants to ensure that no cloud workload has a public IP address attached to a network security policy that allows inbound SSH from the entire internet. Which Cisco security product can continuously monitor and alert on such misconfigurations?
Hard895An engineer is deploying Cisco ISE for guest access. The guest portal uses a self-provisioned username and password. To ensure secure credential transmission, which protocol should be enforced on the portal?
Hard896An administrator reviewed the log entry from the Cisco ESA exhibit. The DLP policy is set to 'Continue (with disclaimer)' for credit card matches. How should the policy be changed to prevent this data leakage?
Hard897A Cisco FTD device is deployed in inline mode and is configured with an access control policy that includes an Intrusion Policy set to 'Balanced Security and Connectivity' and a File Policy with Malware & File blocking enabled. Traffic from a host inside to an external server is allowed by an access control rule. The administrator notices that a file download (PDF) is being blocked even though the file has a good reputation. What is the most likely cause?
Hard898A network administrator wants to centrally manage and enforce access policies for wired and wireless users. Which Cisco product provides this functionality?
Easy899An organization is using Cisco FMC with FTD devices. They want to detect and block malware in HTTP traffic. Which policy component must be configured to inspect files and submit SHA-256 hashes to AMP cloud for disposition?
Medium900Which TWO are valid methods for determining the SGT (Security Group Tag) assigned to an endpoint in a TrustSec deployment?
Easy901A cloud security team is investigating a possible data exfiltration incident involving an AWS S3 bucket configured with cross-region replication. Which Cisco Cloudlock feature can detect unusual replication patterns that may indicate data theft?
Hard902Which Cisco security product is primarily designed to provide DNS-layer security by blocking requests to malicious domains?
Easy903An attacker uses ARP spoofing to intercept traffic between two devices on the same subnet. After successfully becoming a man-in-the-middle, the attacker can then perform which further attack to downgrade HTTPS connections to HTTP?
Medium904An organization is using Cisco Umbrella alongside Cisco AMP for Endpoints. A user reports that they cannot access a legitimate file-sharing website. However, the site is not categorized as malicious by Umbrella. What is the most likely reason for the block?
Hard905In the shared responsibility model for cloud security, which of the following is the customer responsible for in an IaaS deployment?
Easy906Refer to the exhibit. What is the most likely reason for the high number of 'No route to host' drops on a Cisco ASA?
Medium907A university is implementing 802.1X for student wireless networks using Cisco Wireless LAN Controllers (WLCs) and ISE. Students connect with their personal devices using PEAP-MSCHAPv2. During heavy usage, some students report authentication failures and sporadic disconnections. The network team examines the ISE live logs and sees many 'Authentication failed' entries with reason 'Internal error - unable to find a suitable proxy target'. The team has configured two ISE nodes as authentication proxies for the wireless subnets. What is the most likely cause of this issue?
Medium908An organization wants to deploy endpoint hardening measures. Which three of the following are considered endpoint hardening techniques? (Choose three.)
Hard909A company with 5,000 endpoints is using Cisco Secure Endpoint. The security team receives an alert that a specific file (SHA256: 8f4a...b2c) has been detected as malware on 10 endpoints. The file has been quarantined on those endpoints. The team wants to ensure that no other endpoints in the organization have this file. Which feature should be used to locate the file across all endpoints?
Hard910A network engineer is troubleshooting a site-to-site IPsec VPN that fails to establish. The IKE phase 1 completes successfully, but phase 2 fails. The debug output shows 'IPSEC(validate_proposal): transform set proposal mismatch'. Both peers have the same transform set configured. What is the most likely cause?
Hard911Which Cisco Duo authentication method involves a one-time code generated by a hardware token?
Easy912A network engineer is configuring 802.1X on a switch port that connects to a VoIP phone and a PC behind the phone. Which authentication method should be used to authenticate both devices separately?
Medium913An organization is implementing Privileged Access Management (PAM) using CyberArk integrated with Cisco SecureX. Which THREE capabilities are typically provided by such a PAM solution?
Hard914Refer to the exhibit. An engineer configures this interface for 802.1X. Users report that after successful authentication, they are forced to reauthenticate every hour even though the authentication session is still active. What configuration change should be made to prevent reauthentication unless triggered by a change?
Medium915Refer to the exhibit. A user has successfully authenticated via 802.1X. However, the SGT (Security Group Tag) assigned is 0, which is the default untagged value. Which configuration change would most likely allow ISE to assign a non-zero SGT for this user?
Medium916A DevOps team is building a CI/CD pipeline for a cloud-native application. They want to automatically check Terraform scripts for insecure configurations before deployment. Which tool should be integrated into the pipeline?
Medium917In the shared responsibility model for cloud security, which responsibility is the customer's in an IaaS deployment?
Easy918An engineer is configuring an ASA to allow inbound HTTP traffic from the outside to a server on the DMZ. The outside interface has security level 0 and the DMZ interface has security level 50. Which set of commands correctly implements the required access and NAT?
Medium919Which Cisco Firepower management option is used for on-box management of a single FTD device, without a separate management center?
Easy920A network administrator is configuring site-to-site IPsec VPN between two Cisco ASAs using IKEv2. They want to ensure that only specific subnets are encrypted, using Virtual Tunnel Interface (VTI). Which configuration element is essential for VTI?
Medium921An organization is deploying Cisco WSA to enforce acceptable use policies. The administrator wants to block access to social media and streaming video, while also decrypting HTTPS traffic for these categories. Which THREE configuration steps are required?
Hard922A network administrator wants to deploy Cisco WSA as a transparent proxy to inspect web traffic without changing browser settings. Which protocol should be used to redirect traffic to the WSA?
Medium923An organization uses Cisco ESA and wants to implement a policy that automatically encrypts emails containing credit card numbers before delivery. What feature should be used?
Medium924Refer to the exhibit. A host with IP address 10.0.0.5 sends traffic to destination 192.168.2.10. The traffic is not being translated. What is the most likely cause?
Medium925An engineer is configuring Cisco ISE for 802.1X authentication. The network has many printers and IP phones that do not support 802.1X supplicant software. Which ISE feature should be used to allow these devices to authenticate?
Medium926A large enterprise uses Cisco ISE for network access control with 802.1X authentication (PEAP-MSCHAPv2) on wired ports. Access switches are Cisco Catalyst 3850s running IOS-XE 16.9, and ISE is version 2.7 with all patches. Recently, users in the finance department report intermittent connectivity issues when connecting to the network. The issue is sporadic: a user may connect successfully one day, then fail multiple times the next day. Switch logs show frequent 'EAP timeout' errors for these users. The network team has verified that the RADIUS servers are reachable and have sufficient CPU and memory. The ISE logs show no authentication failures, only that some EAP conversations are dropped mid-exchange. What is the most likely cause of these intermittent failures?
Hard927A security analyst is investigating a malware outbreak. Analysis reveals a remote access trojan (RAT) that communicates with a command-and-control (C2) server. Which TWO behaviors are typical of a RAT? (Choose two.)
Medium928Which cryptographic algorithm is considered deprecated and should be avoided due to known vulnerabilities, especially when used in digital signatures and certificate signing?
Easy929A security analyst needs to investigate a potential breach on an endpoint. Cisco AMP for Endpoints provides several EDR capabilities. Which three actions can the analyst perform using AMP's EDR features? (Choose three.)
Hard930An enterprise is deploying a hybrid email security solution using Cisco Email Security Appliance (ESA) on-premises and Cisco Cloud Email Security (CES). The organization wants to use the cloud for spam filtering while the on-premises ESA handles DLP and encryption for sensitive data. Inbound emails should be processed by the cloud first, then sent to the on-premises ESA. Which architecture correctly implements this requirement?
Hard931When a certificate is revoked, which protocol allows a client to check the revocation status in real-time without downloading a full CRL?
Medium932An administrator is configuring 802.1X on a switch port for both an IP phone and a PC. Which two commands should be configured to support this scenario? (Choose two)
Medium933Which TWO configuration steps are required to enable Cisco AMP for Endpoints to use the Threat Grid appliance for file analysis?
Hard934A large enterprise recently migrated to Cisco Email Security Appliance (ESA) for inbound email filtering. The security team notices an increasing number of phishing emails that bypass the spam filter. Analysis shows that these emails originate from a legitimate but compromised domain (example-bank.com), use valid DKIM signatures, and have low spam scores due to carefully crafted benign text and embedded images. The team already has SenderBase enabled and uses the default spam threshold. The CEO received a convincing phishing email that led to a credential leak. Which course of action should the security team take to best mitigate this threat without causing significant false positives?
Hard935A company has deployed Cisco Umbrella with a virtual appliance (VA) for content filtering. Users report that some websites are not loading properly, and the helpdesk suspects that the VA is blocking legitimate traffic. The network administrator checks the VA dashboard and sees that the VA is passing traffic normally. However, the administrator notices that the VA's upstream DNS server is set to a public resolver (208.67.222.222) instead of the company's internal DNS servers. This causes internal hostnames to resolve incorrectly. The company uses Active Directory with domain-joined computers. What should the administrator do to resolve the issue?
Easy936A network engineer needs to implement a security solution that provides encryption, integrity, and authentication at Layer 2 between two switches. Which technology should be used?
Easy937While troubleshooting an issue where Cisco ESA occasionally fails to process inbound messages, the administrator checks the listener settings and sees that the 'Pool of listeners' option is configured. The mail logs show 'Connection refused' errors during peak hours. What is the most likely cause?
Hard938An engineer is configuring Cisco ISE for 802.1X authentication in a corporate network. A printer that does not support 802.1X needs to be granted network access. Which method should the engineer use to authenticate the printer?
Medium939A company receives a spear-phishing email that appears to come from the CEO requesting an urgent wire transfer. What type of email attack is this?
Medium940An S3 bucket policy is shown. What does the condition "aws:SecureTransport": "true" enforce?
Easy941Which TWO indicators of compromise (IOCs) can Cisco AMP for Endpoints detect and alert on?
Hard942A large enterprise uses Cisco TrustSec to enforce segmentation between departments. The network consists of Cisco Catalyst switches running IOS XE with IP ACLs and Security Group Tags (SGTs). The security policy requires that traffic from the Engineering group (SGT=10) to the Finance group (SGT=20) be allowed only to TCP port 443. The administrator configures a Security Group Access Control List (SGACL) on Cisco ISE with a permit statement for TCP 443 and a deny for all other traffic, and pushes it to the switches. After deployment, they notice that Engineering users can access Finance servers not only on TCP 443 but also on other ports. The administrator verifies that the SGACL is correctly configured on ISE and that the switches are receiving the SGTs. Additionally, the switches have IP ACLs on the interfaces. What is the most likely cause of this issue?
Hard943An organization has a Cisco ASA with two interfaces: inside (security 100) and outside (security 0). They want to allow traffic from inside to outside without NAT for a specific subnet. Which configuration achieves this?
Hard944A network engineer is configuring 802.1X on a Cisco switch for wired clients. After configuration, some clients fail authentication. The engineer notices that the clients are not sending any EAP packets. What is the most likely cause?
Easy945Refer to the exhibit. An engineer notices that a malicious file disguised as 'app.exe' in the FinanceApp folder (SHA-256 unknown to AMP) was blocked. However, another unknown executable in the same folder was also blocked, causing a false positive. What should the engineer change in the policy to allow only the legitimate 'app.exe' while still blocking unknown executables?
Hard946A security engineer is troubleshooting an issue where Cisco AMP for Endpoints is not detecting a known malware sample on a Windows endpoint. The endpoint is running Windows 10 with the latest AMP connector installed and is connected to the corporate network. The malware sample was downloaded from a trusted source for testing. Which configuration is most likely causing the lack of detection?
Medium947A company uses Cisco Umbrella SIG to enforce security policies. An employee attempts to visit a website categorized as 'Phishing' but the request is allowed. What is the most likely cause?
Medium948An engineer is configuring a Cisco ASA to support a DMZ segment. Which three of the following are best practices for DMZ design? (Choose three.)
Hard949A company uses Cisco Stealthwatch Cloud for network visibility in AWS. They notice a spike in encrypted traffic from an EC2 instance to an unknown external IP. Which Stealthwatch Cloud feature can analyze this traffic for threats without decrypting it?
Medium950An organization is adopting a cloud-first strategy and wants to ensure least-privilege access for cloud resources. Which THREE measures should be implemented as part of a cloud IAM strategy? (Select three.)
Hard951A network engineer is configuring OSPF on a Cisco router and needs to enable authentication between neighbors. The authentication type should be MD5. Which configuration step is required?
Medium952A security engineer is evaluating authentication methods. Which authentication factor category does a fingerprint scanner fall under?
Medium953A company is deploying a multi-tier application in a Cisco cloud security environment. The web servers must be accessible from the internet, but the database servers should only be reachable from the web servers. Which Cisco security controls should be used to enforce this?
Medium954A security engineer is configuring a Cisco ASA to block traffic from a specific IP address. Which access control entry (ACE) should be applied to the inbound direction of the outside interface?
Easy955In Cisco Firepower, a file policy is configured with a rule that detects malware. The action is set to 'Malware Cloud Lookup'. What happens if the SHA-256 hash of a file is unknown to the AMP cloud?
Hard956You are tasked with securing a new cloud deployment on AWS. The environment consists of a web application running on EC2 instances behind an Application Load Balancer (ALB), with data stored in an RDS database. The security requirements include: (1) protect against web application attacks (SQL injection, XSS), (2) ensure only authorized users can access the application, (3) monitor for anomalous behavior. You have decided to use AWS WAF for web application protection, AWS Cognito for user authentication, and Amazon GuardDuty for threat detection. However, the CISO also wants to integrate with Cisco's security portfolio for centralized management and visibility. Which Cisco product would best integrate with these AWS services to provide centralized security management?
Medium957Which two Cisco solutions can be used to provide cloud-based content security including DNS-layer protection and cloud proxy? (Choose two.)
Medium958A financial company is deploying Cisco ISE with TrustSec to enforce segmentation between application tiers (web, app, DB). They have a Cisco Catalyst 9500 as the core, and Catalyst 9300s as access switches. The SXP is configured between ISE and core switch, and the core switch propagates SGTs to access switches via SGT inline tagging on trunk ports. The engineer has configured SGTs for web (SGT=2), app (SGT=3), DB (SGT=4). However, when testing from a web server (IP 10.1.1.10, SGT=2) to an app server (IP 10.1.2.20, SGT=3), the app server sees the traffic without SGT in the packet, so the access switch cannot enforce policy. The engineer checks 'show cts role-based sgt-map' on the core and sees the mapping for 10.1.1.10 -> 2. What is the most likely issue?
Hard959An endpoint with MAC 0011.2233.4455 and user 'guest' authenticates but fails. However, the device is not assigned to quarantine. Which policy condition is most likely responsible for the unexpected behavior?
Hard960A security analyst receives an alert that a user clicked a link in an email that led to a malicious website. The email was allowed by the Cisco ESA because it passed SPF, DKIM, and DMARC checks. Later analysis reveals the email was sent from a compromised account within the same domain. Which type of attack best describes this scenario?
Hard961A Cisco FTD sensor is deployed in passive mode (IDS) and is receiving traffic via a network tap. The access control policy is configured with an intrusion policy set to 'Security over Connectivity'. However, the administrator notices that the sensor is not generating alerts for some attacks that were identified by a previous inline sensor. What is the most likely reason?
Hard962An organization wants to deploy AMP for Endpoints in an offline environment where endpoints cannot connect to the internet. Which deployment option is appropriate?
Easy963An engineer is troubleshooting a Cisco ISE deployment where some endpoints are not being profiled correctly. The administrator notices that the endpoints are not sending DHCP requests. Which profiling probe should be primarily used to identify these endpoints?
Hard964A network administrator is configuring 802.1X on a Cisco switch for corporate Windows laptops. The organization uses certificates for authentication. Which EAP method should be configured on the supplicant and ISE to provide certificate-based mutual authentication?
Medium965A company wants to implement network access control for IoT devices that do not support 802.1X. Which Cisco ISE feature can be used to grant these devices network access based on their MAC address?
Easy966A university is using Cisco ESA to manage email for 20,000 students and staff. They have implemented anti-spam and anti-virus policies. Recently, the IT helpdesk has been receiving complaints that legitimate emails from external senders (such as admissions notifications) are being marked as spam and quarantined. The administrators check the ESA and find that these emails are being flagged with a spam score above the threshold, but the content appears to be legitimate. The sending domains are not on any blacklist. The ESA is using default anti-spam settings. What should the administrator do to reduce false positives without compromising security?
Medium967A network engineer is configuring NAT on a Cisco ASA for internal servers to be accessible from the internet. One server (10.1.1.10) must always be reachable via a fixed public IP (203.0.113.10). Which NAT type should be used?
Medium968A network engineer is configuring Cisco ISE for wireless 802.1X authentication. The company wants to use certificate-based authentication for all corporate devices. Which EAP method should be configured?
Medium969A network security engineer is configuring site-to-site IPsec VPN between two Cisco ASA firewalls using IKEv2. Which of the following configuration elements is required to define the encryption and integrity algorithms for the IPsec SA?
Hard970In the 802.1X authentication process, which component is responsible for relaying authentication messages between the client and the authentication server?
Easy971A security engineer is deploying Cisco AMP for Endpoints to protect against malware. The company wants to block all executables from running in the Downloads folder except those signed by a specific trusted publisher. Which policy configuration should the engineer use?
Medium972An organization wants to enforce micro-segmentation in a data center to isolate application tiers. Which Cisco technology allows defining security policies based on endpoint groups rather than IP addresses?
Medium973Which THREE of the following are indicators of compromise (IOCs) that can be detected by Cisco AMP for Endpoints?
Easy974Which symmetric encryption algorithm is considered the current standard and is often used in VPNs and SSL/TLS?
Easy975A company uses AWS Organizations with multiple accounts. They need to enforce that all S3 buckets have encryption enabled. Which AWS service can centrally audit and automatically remediate non-compliant buckets?
Hard976An organization wants to protect their web application hosted on AWS from common exploits like SQL injection. Which Cisco service should they use?
Medium977Which protocol does Cisco ISE use to communicate with the pxGrid controller for sharing contextual data?
Easy978An organization is planning to deploy Cisco FTD in a high-availability pair. Which two statements about active/active failover are true? (Choose two.)
MediumOther domains
All 350-701 exam domains
Frequently asked questions
- What does the troubleshooting domain cover on the 350-701 exam?
- troubleshooting questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 978 troubleshooting questions in the 350-701 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only troubleshooting questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.