Courseiva
Back to Cisco SCOR / CCNP Security Core 350-701 questions

Scenario-based practice

Select Two (Multi-Select) Questions

Practise Cisco SCOR / CCNP Security Core 350-701 practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
350-701
exam code
Cisco
vendor

Scenario guide

How to approach select two (multi-select) questions

Multi-select questions tell you to 'Choose TWO' or 'Choose THREE'. Getting partial credit is not a thing — you must select all correct answers with no incorrect ones. The stem always states how many to choose, so trust it. These questions require precision, not best-guess elimination.

Quick answer

Select Two (Multi-Select) Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related 350-701 topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmulti select
Full question →

A security analyst detects a DDoS attack targeting the company's web server. Which three attack types are classified as application layer attacks? (Choose three.)

Question 2hardmulti select
Full question →

An organization is adopting a cloud-first strategy and wants to ensure least-privilege access for cloud resources. Which THREE measures should be implemented as part of a cloud IAM strategy? (Select three.)

Question 3hardmulti select
Full question →

Which THREE of the following are key principles of the Cisco Zero Trust security model?

Question 4hardmulti select
Full question →

Which THREE of the following are valid methods to deploy Cisco AMP for Endpoints Connector on Windows endpoints?

Question 5mediummulti select
Full question →

Which TWO actions can be configured in a Cisco ESA DLP policy to respond to a violation involving outbound credit card numbers? (Choose two.)

Question 6mediummulti select
Full question →

Which THREE are valid components of an IKEv2 exchange? (Choose three.)

Question 7easymulti select
Full question →

Which two actions are valid actions in a Cisco Firepower access control rule? (Choose two.)

Question 8mediummulti select
Full question →

Which THREE are characteristics of Cisco ISE profiler service?

Question 9mediummulti select
Full question →

Which TWO of the following are valid methods for Cisco ISE to collect endpoint attributes for profiling? (Choose TWO)

Question 10hardmulti select
Full question →

An organization wants to deploy endpoint hardening measures. Which three of the following are considered endpoint hardening techniques? (Choose three.)

Question 11hardmulti select
Full question →

A company wants to implement a Zero Trust architecture. Which THREE principles should be included? (Choose three.)

Question 12hardmulti select
Full question →

A company is planning to deploy a Zero Trust architecture. Which two principles are fundamental to Zero Trust?

Question 13easymulti select
Full question →

Which THREE of the following are indicators of compromise (IOCs) that can be detected by Cisco AMP for Endpoints?

Question 14hardmulti select
Full question →

Which THREE of the following are features of Cisco Identity Services Engine (ISE) that can be used to enforce network access control?

Question 15mediummulti select
Full question →

A company is designing a network segmentation strategy using firewalls. Which THREE considerations are important for a defense-in-depth approach?

Question 16mediummulti select
Full question →

An organization is planning to deploy Cisco FTD in a high-availability pair. Which two statements about active/active failover are true? (Choose two.)

Question 17hardmulti select
Full question →

Which THREE of the following are common indicators of a DDoS attack at the network layer?

Question 18mediummulti select
Full question →

A security analyst is investigating a Business Email Compromise (BEC) attack. Which two indicators are commonly associated with BEC attacks? (Choose two.)

Question 19mediummulti select
Full question →

A company is using Cisco WSA with transparent proxy via WCCP. The security team wants to identify which users are accessing banned websites and also enforce bandwidth limits for video streaming. Which TWO features should be configured on the WSA?

Question 20mediummulti select
Full question →

An organization wants to block access to malicious websites using Cisco Umbrella. Which two protection layers are available with the Umbrella SIG? (Choose two.)

These 350-701 practice questions are part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style 350-701 questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.