Courseiva
Back to Cisco SCOR / CCNP Security Core 350-701 questions

Scenario-based practice

Hard Difficulty Questions

Practise Cisco SCOR / CCNP Security Core 350-701 practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
350-701
exam code
Cisco
vendor

Scenario guide

How to approach hard difficulty questions

These are the questions most candidates get wrong. They require connecting multiple concepts, reading tricky output, or knowing edge-case behaviour that isn't on most study cards. Practising them trains you to operate under uncertainty — a necessary skill on the real exam.

Quick answer

Hard Difficulty Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related 350-701 topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmulti select
Full question →

A security analyst detects a DDoS attack targeting the company's web server. Which three attack types are classified as application layer attacks? (Choose three.)

Question 2hardmulti select
Full question →

An organization is adopting a cloud-first strategy and wants to ensure least-privilege access for cloud resources. Which THREE measures should be implemented as part of a cloud IAM strategy? (Select three.)

Question 3hardmulti select
Full question →

Which THREE of the following are key principles of the Cisco Zero Trust security model?

Question 4hardmulti select
Full question →

Which THREE of the following are valid methods to deploy Cisco AMP for Endpoints Connector on Windows endpoints?

Question 5hardmultiple choice
Full question →

A company uses FMC to manage FTD devices. After deploying a new intrusion policy, the analyst sees that no events are generated for a known vulnerability, even though the policy includes a rule for it. The analyst checks and the rule is enabled and the policy is applied. What is the most likely cause?

Question 6hardmultiple choice
Full question →

During an email security audit, it is discovered that some phishing emails are passing through the Cisco ESA. Analysis shows the emails have valid SPF and DKIM signatures but are classified as phishing. What additional Cisco ESA feature should be tuned to improve detection?

Question 7hardmultiple choice
Open the full VLAN trunking answer →

A financial company is deploying Cisco ISE with TrustSec to enforce segmentation between application tiers (web, app, DB). They have a Cisco Catalyst 9500 as the core, and Catalyst 9300s as access switches. The SXP is configured between ISE and core switch, and the core switch propagates SGTs to access switches via SGT inline tagging on trunk ports. The engineer has configured SGTs for web (SGT=2), app (SGT=3), DB (SGT=4). However, when testing from a web server (IP 10.1.1.10, SGT=2) to an app server (IP 10.1.2.20, SGT=3), the app server sees the traffic without SGT in the packet, so the access switch cannot enforce policy. The engineer checks 'show cts role-based sgt-map' on the core and sees the mapping for 10.1.1.10 -> 2. What is the most likely issue?

Question 8hardmultiple choice
Full question →

A security engineer is configuring Cisco Web Security Appliance (WSA) to block access to social media sites during business hours. The company wants to allow access to LinkedIn for the HR department. Which policy configuration approach should the engineer use?

Question 9hardmultiple choice
Full question →

An endpoint with MAC 0011.2233.4455 and user 'guest' authenticates but fails. However, the device is not assigned to quarantine. Which policy condition is most likely responsible for the unexpected behavior?

Exhibit

Refer to the exhibit.

! Cisco ISE Policy Set
Condition: EndPointCompliant EQUALS No OR DeviceType NOT_IN ["Windows", "Mac", "Linux"]
Result: VLAN_Quarantine (VLAN 999)

! Syslog message
ISE: Authentication failed for user 'guest' from MAC 0011.2233.4455. Reason: Invalid username or password.
Question 10hardmultiple choice
Full question →

A Cisco FTD device is deployed in inline mode and configured with an SSL policy to decrypt traffic. The policy uses 'Decrypt - Known Key' for traffic to an internal server. What is required for this decryption to work?

Question 11hardmulti select
Full question →

An organization wants to deploy endpoint hardening measures. Which three of the following are considered endpoint hardening techniques? (Choose three.)

Question 12hardmultiple choice
Full question →

A network administrator needs to provide network access to a legacy printer that does not support 802.1X. Which Cisco ISE feature should be used to authenticate this device?

Question 13hardmultiple choice
Full question →

A DevSecOps team is implementing secrets management for a cloud-native application. They want to avoid storing secrets in environment variables or code. Which solution should they use?

Question 14hardmultiple choice
Full question →

You are troubleshooting a Cisco ISE deployment where some endpoints are stuck in the 'Not Compliant' posture after a posture scan. ISE logs show 'Conditional NAC Agent result: Not Compliant due to missing required application.' The application is installed on the endpoint. What should you check?

Question 15hardmultiple choice
Read the full VPN explanation →

A network security engineer is configuring site-to-site IPsec VPN between two Cisco ASA firewalls using IKEv2. Which of the following configuration elements is required to define the encryption and integrity algorithms for the IPsec SA?

Question 16hardmultiple choice
Full question →

An engineer notices that the 'show authentication sessions' command on a switch shows a session in 'CRITICAL' state. What does this indicate?

Question 17hardmultiple choice
Full question →

During a security incident, it is observed that a server behind a Cisco ASA is being accessed repeatedly with different source IPs in a short time. The firewall logs show many dropped packets to the server's IP on port 443. What is the most effective mitigation to reduce the impact while maintaining legitimate access?

Question 18hardmultiple choice
Read the full DHCP explanation →

An engineer is troubleshooting a Cisco ISE deployment where some endpoints are not being profiled correctly. The administrator notices that the endpoints are not sending DHCP requests. Which profiling probe should be primarily used to identify these endpoints?

Question 19hardmultiple choice
Full question →

During an email security audit, it is discovered that encrypted emails sent between two partners are being silently dropped by the Cisco ESA. The ESA uses a policy that decrypts incoming S/MIME messages for scanning. What is the most likely cause of the dropped messages?

Question 20hardmultiple choice
Full question →

A Cisco ESA administrator notices that a large number of emails with malicious attachments are being delivered to users. Which feature should be configured to inspect attachments in a sandbox environment before delivery?

These 350-701 practice questions are part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style 350-701 questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.