Courseiva

Cisco Designing and Implementing Secure Cloud Access for Users and Endpoints (SCAZT, 300-740, CCNP Security) (SCAZT) (SCAZT) — Questions 151225

316 questions total · 5pages · All types, answers revealed

Page 2

Page 3 of 5

Page 4
151
MCQeasy

Which menu in the SecureX dashboard allows you to manage the API clients for third-party integrations?

A.Global Settings
B.User Management
C.API Clients
D.Integration Modules
AnswerC

This is the designated area for managing API access.

Why this answer

The 'API Clients' section under Administration allows for the generation and management of keys for external integrations.

152
Multi-Selectmedium

Which TWO of the following are primary components of the Cisco SASE security stack?

Select 2 answers
A.Cisco Umbrella SIG
B.Cisco Webex
C.Cisco Identity Services Engine (ISE)
D.Cisco Duo
E.Cisco Meraki Go
AnswersA, D

Umbrella provides the web security and firewall-as-a-service.

Why this answer

Cisco Umbrella SIG and Duo are the core pillars of the Cisco SASE security offering.

153
MCQmedium

What is the primary benefit of using 'SAML' (Security Assertion Markup Language) for cloud application authentication?

A.It prevents unauthorized access to the local network.
B.It enables SSO, reducing the risk associated with password sprawl.
C.It automatically updates the user's password every 30 days.
D.It encrypts all data sent to the cloud provider.
AnswerB

SSO improves security by centralizing authentication and reducing the need for multiple passwords.

Why this answer

SAML enables Single Sign-On (SSO), allowing users to authenticate once and access multiple cloud applications securely.

154
MCQmedium

A user is attempting to access a SaaS application, but the session is blocked by Cisco Cloudlock due to a detected policy violation. Which component is responsible for analyzing the API calls and triggering the remediation?

A.Cloudlock CASB API engine
B.Duo Authentication Proxy
C.AnyConnect SASE client
D.Umbrella SIG proxy
AnswerA

The Cloudlock engine connects via API to SaaS apps to monitor and remediate violations.

Why this answer

Cisco Cloudlock utilizes API-based integration to monitor SaaS environments and enforce security policies, such as DLP or anomaly detection.

155
MCQmedium

You are configuring a Cisco Cloudlock policy to detect sensitive data in a Salesforce environment. You need to identify instances where credit card numbers are shared publicly. Which specific policy category should you configure?

A.User Behavior Analytics
B.Data Exposure
C.Application Firewall
D.Threat Intelligence
AnswerB

Data Exposure policies in Cloudlock are designed to monitor and remediate public or external file/record sharing.

Why this answer

The Cisco Cloudlock Data Loss Prevention engine uses specific policy categories to identify PII/PCI data, and 'Data Exposure' is the correct category for monitoring sharing settings.

156
MCQeasy

Which component of SecureX tracks the history of all executed playbooks, allowing you to debug failed automated responses?

A.Event Logs
B.Casebook Timeline
C.Workflow Execution History
D.Deployment Log
AnswerC

This provides a full audit trail and debug logs.

Why this answer

The 'Workflow Execution' or 'Run History' section within the Orchestration module shows every triggered instance and its outcome.

157
Multi-Selectmedium

Which TWO things must be done to successfully protect a legacy VPN with Duo?

Select 2 answers
A.Join the VPN to the Active Directory domain
B.Configure the VPN to use the Authentication Proxy as its RADIUS server
C.Install the Duo agent on the VPN headend device
D.Define the VPN device as a RADIUS client in the Duo Admin Panel
E.Enable SAML on the VPN device
AnswersB, D

VPN sends auth requests via RADIUS to the proxy.

Why this answer

You need to configure the VPN to point to the Duo Authentication Proxy for RADIUS, and define the proxy as a RADIUS client in the Duo Admin Panel.

158
MCQeasy

You are configuring Cisco Umbrella to protect roaming users. Which component must be installed on the endpoint to ensure consistent policy enforcement when the user is off-VPN?

A.Secure Firewall Management Center
B.Umbrella Virtual Appliance
C.AnyConnect Management VPN Tunnel
D.Cisco Umbrella Roaming Client
AnswerD

The Roaming Client is designed to provide DNS-layer security for off-network endpoints.

Why this answer

The Umbrella Roaming Client is the specific agent required to ensure DNS traffic is intercepted and redirected to Umbrella resolvers for policy application.

159
MCQmedium

To ensure compliance, you must ensure that all emails containing credit card numbers sent via O365 are encrypted. How is this achieved within the Cloudlock framework?

A.Configure a DLP policy to trigger an 'Apply Sensitivity Label' action.
B.Reset the user's password.
C.Enable TLS 1.3 for all outgoing mail.
D.Create a firewall rule to block the email.
AnswerA

Correct. This integrates with O365's Information Protection to trigger encryption.

Why this answer

Cloudlock policies can trigger automated actions such as applying sensitivity labels or encryption policies in the underlying SaaS application upon detecting sensitive content.

160
MCQmedium

You need to ensure that an incident response playbook in Cisco SecureX automatically updates a case in the Casebook feature. Which action is required in the workflow design?

A.Post to Incident API
B.Update Evidence Store
C.Add Observation to Casebook
D.Sync with Incident Management
AnswerC

The Add Observation node is the correct method to update existing cases.

Why this answer

Using the 'Casebook' activity module allows the playbook to create or update incidents directly within the SecureX Casebook.

161
MCQeasy

Which feature in Cisco Umbrella is used to categorize web traffic for reporting and filtering?

A.DNS Destination Lists
B.Network Tunnels
C.Content Categories
D.Identity Providers
AnswerC

Content Categories allow for broad traffic grouping.

Why this answer

Umbrella Content Categories allow administrators to group websites (e.g., 'Adult', 'Gambling') to apply policies and view categorized traffic reports.

162
MCQeasy

Which component of the Cisco SASE architecture provides the primary security enforcement point for remote users browsing the web from untrusted networks?

A.Cisco Umbrella SIG
B.Cisco Firepower Threat Defense (FTD)
C.Cisco Meraki MX
D.Cisco Identity Services Engine (ISE)
AnswerA

Umbrella SIG provides web security, DNS-layer security, and firewall-as-a-service.

Why this answer

The Cisco Umbrella Secure Internet Gateway (SIG) provides the cloud-native security stack for remote users.

163
MCQmedium

You want to monitor the health of your Cisco Secure Firewall Management Center (FMC) from within SecureX. Which integration component is required?

A.AnyConnect Management module
B.Cisco Defense Orchestrator module
C.Secure Firewall Management Center module
D.Cisco Smart Licensing module
AnswerC

This specific module allows SecureX to pull data directly from the FMC instance.

Why this answer

The FMC integration module must be enabled in SecureX so that events and device health status can be queried.

164
Multi-Selecthard

Which THREE factors can be evaluated by Duo Device Health during an access request?

Select 3 answers
A.Active Internet connection speed
B.OS version and patch level
C.User's current GPS location
D.Disk Encryption status
E.Antivirus status
AnswersB, D, E

Standard check for managed devices.

Why this answer

Duo Device Health inspects disk encryption, OS updates, and antivirus status as part of its posture assessment.

165
Multi-Selecthard

When configuring a Duo authentication policy for a SaaS app, which THREE device health indicators can be required?

Select 3 answers
A.Security software (AV) active
B.Monitor CPU utilization
C.Hard drive space capacity
D.OS version status
E.Full disk encryption enabled
AnswersA, D, E

Required for endpoint integrity.

Why this answer

Duo's policy engine can require that endpoints have disk encryption enabled, up-to-date operating systems, and activated security software.

166
Multi-Selectmedium

Which TWO configuration parameters are required when setting up the Duo Authentication Proxy for an LDAP source?

Select 2 answers
A.The user's personal Duo device ID
B.The LDAP server hostname or IP address
C.The public DNS server address
D.The bind credentials (distinguished name and password)
E.The root password of the Active Directory domain
AnswersB, D

Necessary for connectivity.

Why this answer

To connect to LDAP, the proxy needs the server address and the service account credentials to perform searches.

167
MCQeasy

When configuring a custom dashboard in Cisco SecureX, what is the primary purpose of adding 'Tiles' from the 'Asset' category?

A.To stream live raw packet captures from the firewall.
B.To visualize the current state and status of registered network and endpoint devices.
C.To display the history of threat intelligence research performed by analysts.
D.To configure administrative access levels for other dashboard users.
AnswerB

Asset tiles are specifically designed to summarize the health and posture of the infrastructure.

Why this answer

Asset tiles provide a real-time summary of the current security posture, such as vulnerable software versions or missing patches across the environment.

168
MCQeasy

Which Cisco technology provides the 'Visibility' aspect of SecureX, allowing you to see traffic patterns across cloud and hybrid environments?

A.Secure Cloud Analytics
B.Secure Email
C.Secure Network Analytics
D.Secure Malware Analytics
AnswerA

This tool focuses on traffic visibility.

Why this answer

Secure Cloud Analytics (formerly Stealthwatch Cloud) provides network traffic visibility and behavior analysis.

169
Multi-Selectmedium

Which THREE factors influence the risk rating of an application in Cisco Umbrella's App Discovery tool?

Select 3 answers
A.Compliance certifications
B.Server location
C.Encryption support
D.Data protection standards
E.Number of employees
AnswersA, C, D

SOC2, ISO, etc., impact the score.

Why this answer

Risk ratings are calculated based on an application's data privacy policies, compliance certifications, and security features.

170
MCQeasy

Where do you view the aggregate security posture score across all integrated Cisco cloud security products in the SecureX dashboard?

A.Cisco Defense Orchestrator
B.Cisco Stealthwatch Cloud
C.Cisco Umbrella Dashboard
D.SecureX Dashboard
AnswerD

SecureX acts as the umbrella dashboard for all Cisco security integrations.

Why this answer

The SecureX dashboard provides a centralized view, and the 'Posture' or 'Health' widgets are designed to aggregate these metrics.

171
MCQhard

You are creating a custom dashboard in SecureX and need to display data from Cisco Secure Endpoint (AMP for Endpoints). Which component must be properly configured first?

A.Cisco Threat Intelligence Grid
B.DNS Layer Security Policy
C.Secure Endpoint Integration Module
D.SecureX Orchestration Workflow
AnswerC

The integration module is required to authenticate and pull data into the SecureX platform.

Why this answer

The integration module acts as the bridge; without it, the dashboard has no data source to query.

172
MCQhard

You are troubleshooting a connection issue where a remote user cannot access a private cloud application via the Cisco Secure Access ZTNA connector. Which step is most likely to resolve the issue?

A.Increase the timeout value on the client browser.
B.Flush the DNS cache on the corporate firewall.
C.Check the health status of the ZTNA connector in the Secure Access dashboard.
D.Reboot the user's laptop.
AnswerC

The connector must have an 'Active' status to route traffic to the private application.

Why this answer

Verifying the connectivity of the ZTNA connector to the private resource is the first diagnostic step to ensure the tunnel is active.

173
Multi-Selectmedium

Which TWO features of Cisco Umbrella assist in preventing data loss?

Select 2 answers
A.DNS query logs
B.Local firewall rules
C.Data Loss Prevention (DLP)
D.Automated DNS updates
E.File inspection (sandboxing)
AnswersC, E

DLP inspects for sensitive data patterns.

Why this answer

Umbrella uses DLP patterns and file inspection to prevent sensitive data from being uploaded to unauthorized locations.

174
MCQeasy

Which component is required to enable Active Directory integration with Umbrella for user-level reporting?

A.SAML Provider
B.Umbrella AD Connector
C.Virtual Appliance
D.AnyConnect Agent
E.Cisco Secure Firewall
AnswerB

This maps users/groups to their internal IPs.

Why this answer

The Umbrella AD Connector is the specific software component that syncs AD data to the Umbrella cloud.

175
MCQmedium

In Cisco Umbrella, what is the primary purpose of defining a 'Cloud Application' in the 'App Discovery' dashboard?

A.To identify and govern Shadow IT usage across the enterprise.
B.To pre-authenticate users for that SaaS.
C.To increase bandwidth for authorized SaaS apps.
D.To bypass SSL inspection for the application.
AnswerA

The primary intent of App Discovery is to track and control unauthorized SaaS usage.

Why this answer

App Discovery allows administrators to see which shadow IT applications are in use and decide whether to block or monitor them via policy.

176
MCQhard

You need to handle a case where an endpoint device is not reachable during an isolation attempt. How should the workflow respond?

A.Delete the device object
B.Notify administrator of failure
C.Retry indefinitely
D.Ignore and continue
AnswerB

Alerting the team is the correct action for an unreachable device.

Why this answer

The workflow should use error handling to transition to a 'failed' state and alert an admin, as the device may be offline or the agent disconnected.

177
Multi-Selectmedium

Which THREE of the following are primary functions of a Cloud Access Security Broker (CASB) regarding application and data security?

Select 3 answers
A.Physical access control for data centers.
B.Local area network traffic routing.
C.Automated threat protection for user sessions.
D.Visibility into Shadow IT usage.
E.Enforcement of DLP policies in the cloud.
AnswersC, D, E

Correct. CASB detects and blocks malicious session activity.

Why this answer

CASB provides visibility, compliance, threat protection, and data security for cloud applications.

178
MCQeasy

How do you access the 'SecureX' suite from another Cisco security console like FMC?

A.Click the SecureX ribbon or icon in the navigation bar
B.Run a command from the CLI
C.You must type the URL manually into the browser
D.Request access via email
AnswerA

This is the standard, integrated way to access the suite.

Why this answer

Most Cisco security consoles provide a 'SecureX' link or icon in the navigation bar that allows single sign-on access to the integrated platform.

179
MCQhard

When deploying the Cisco Secure Access AnyConnect module, what is the primary role of the Umbrella DNS module within it?

A.To intercept and secure DNS queries
B.To manage local network segmentation
C.To authenticate users to the cloud
D.To encrypt traffic payloads
AnswerA

The DNS module provides the DNS-layer security component.

Why this answer

The Umbrella DNS module inside AnyConnect intercepts DNS queries and sends them to Umbrella resolvers for security filtering.

180
MCQmedium

An administrator is configuring Cisco Umbrella for a branch office and needs to ensure that all DNS requests are inspected for malicious domains without requiring a client-side agent. Which configuration approach should the administrator implement?

A.Deploy the Umbrella Virtual Appliance (VA) in a DMZ and configure it for direct Internet access.
B.Enable the 'DNS over HTTPS' feature in the browser settings for all end-user workstations.
C.Establish an IPsec tunnel from the branch edge router to the Umbrella data center.
D.Configure a PAC file on each endpoint to route traffic to the Umbrella Roaming Client.
AnswerC

Creating an IPsec tunnel at the network level ensures all DNS traffic is securely forwarded and inspected.

Why this answer

Network tunnels, such as IPsec or GRE, are used to forward DNS traffic from network devices to Umbrella, providing protection for all devices on the network without agents.

181
MCQmedium

When configuring Duo Trust Monitor, what is the primary purpose of 'Baseline' behavior?

A.To identify normal authentication patterns for users
B.To enforce MFA for every authentication attempt
C.To synchronize identity sources from LDAP
D.To define the static list of allowed IP addresses
AnswerA

Trust Monitor learns user behavior patterns to flag anomalies.

Why this answer

Trust Monitor establishes a baseline of normal user activity to detect deviations that may indicate an account compromise.

182
MCQmedium

A user is using a managed laptop. How does 'Device Posture' in the Cisco SASE model verify that an antivirus solution is active?

A.By requesting the antivirus vendor to send a status email.
B.By checking the user's browser history.
C.By scanning the user's files remotely.
D.By querying the OS security APIs via the Secure Client agent.
AnswerD

The agent on the endpoint performs the necessary local checks.

Why this answer

The Cisco Secure Client (AnyConnect) periodically checks the system's security posture and reports status to the policy engine before allowing connectivity.

183
MCQmedium

You are troubleshooting a lack of visibility in the SecureX 'Device Trajectory' view for a roaming laptop. The device is connected to the network via AnyConnect, but SecureX is not showing the internal IP history. Which configuration is required to ensure this data is visible?

A.Install the SecureX plugin on the local endpoint.
B.Enable 'Visibility' settings in the AnyConnect profile editor.
C.Configure the Cisco ISE to send RADIUS accounting packets to SecureX.
D.Configure the Secure Endpoint connector to report to the SecureX cloud.
AnswerD

Secure Endpoint must be connected to SecureX to provide the telemetry required for device trajectory.

Why this answer

SecureX Device Trajectory requires the 'AMP for Endpoints' (Secure Endpoint) connector to be active and properly feeding data.

184
MCQeasy

Which type of file allows you to import and share a complete workflow design between different SecureX organizations?

A.YAML File
B.JSON File
C.CSV File
D.XML File
AnswerB

JSON is the standard format for sharing SecureX workflows.

Why this answer

Workflows can be exported and imported as JSON files, which contain the full structure and configuration of the orchestration steps.

185
Multi-Selectmedium

Which TWO ways does Cisco SecureX simplify the management of security operations?

Select 2 answers
A.By providing a centralized console for multi-product investigation
B.By automatically hiring new security analysts
C.By providing physical onsite security guard scheduling
D.By automating common tasks through orchestration workflows
E.By acting as a hardware firewall replacement
AnswersA, D

This is a primary goal of SecureX.

Why this answer

SecureX simplifies operations by providing a single point of investigation and automating repetitive tasks via orchestration.

186
Multi-Selecthard

Which THREE factors influence the performance of a SASE deployment?

Select 3 answers
A.Encryption processing overhead
B.The number of users logged into the console
C.Internet circuit quality
D.The version of the office software
E.Distance to the nearest cloud edge node
AnswersA, C, E

Encrypting/decrypting traffic takes time.

Why this answer

Performance is affected by the distance to the cloud node, encryption overhead, and the quality of the internet path.

187
MCQmedium

An organization is migrating to a Secure Internet Gateway (SIG) architecture. They currently have an on-premises firewall blocking all traffic except for specific ports. What is the recommended method to forward traffic to the SIG while maintaining existing security policy consistency?

A.Configure an IPsec tunnel from the firewall to the Cisco SIG headend.
B.Configure port forwarding for all traffic on the firewall to an external DNS proxy.
C.Disable the existing firewall to prevent conflicts with the SIG cloud services.
D.Replace the existing firewall with an Umbrella Roaming Client.
AnswerA

IPsec tunnels are the standard way to backhaul traffic to the SIG for unified security policy enforcement.

Why this answer

Using an IPsec tunnel ensures that the traffic is encrypted and consistently tagged for the SIG to apply the appropriate security policies.

188
Multi-Selecthard

Which TWO logging methods can be used to export Umbrella logs for SIEM analysis?

Select 2 answers
A.Direct API integration for SIEM
B.Export logs to an Amazon S3 bucket
C.Logging to the local printer
D.Sending logs via email
E.Local disk logging on the user endpoint
AnswersA, B

Automates log ingestion for security platforms.

Why this answer

Umbrella supports log exports via S3 buckets or direct API integration with SIEM platforms.

189
MCQeasy

Which section in the Cisco Secure Firewall Management Center (FMC) is primarily used to view security events generated by intrusion policies?

A.Policies > Intrusion
B.Analysis > Intrusions > Events
C.Objects > Object Management
D.System > Updates
AnswerB

This path is specifically designed to show logged intrusion events.

Why this answer

The 'Analysis' section is where you navigate to view security events, intrusion events, and connection logs.

190
Multi-Selectmedium

Which TWO ways does Cisco Secure Cloud Analytics provide visibility into encrypted traffic?

Select 2 answers
A.TLS fingerprinting
B.Analyzing the local browser history files
C.Installing a root CA on all mobile devices
D.Full payload decryption at the cloud edge
E.Behavioral analysis of flow patterns
AnswersA, E

Fingerprinting identifies the client/server type without decryption.

Why this answer

Secure Cloud Analytics uses TLS fingerprinting and behavioral analysis to infer the nature of encrypted sessions without needing full packet decryption.

191
MCQmedium

In the context of the Duo Authentication Proxy, what is the 'fail_mode' parameter used for?

A.To decide whether to permit local password caching
B.To set the timeout for LDAP queries
C.To define how to handle requests when the cloud service is unreachable
D.To enable logging for failed authentication attempts
AnswerC

Safe mode allows access; closed mode denies it.

Why this answer

The 'fail_mode' (safe or closed) determines whether the proxy allows or denies access when it cannot communicate with the Duo cloud.

192
Multi-Selecthard

Which THREE actions can be automated via the Cisco Secure Firewall integration in SecureX?

Select 3 answers
A.Update network objects
B.Physical interface configuration
C.Clear connection logs
D.Modify access control policies
E.Reset appliance to factory
AnswersA, C, D

Useful for dynamic blocking of IPs.

Why this answer

Automations include updating network objects, modifying access control lists, and clearing connection logs to respond to threats.

193
MCQhard

When configuring a webhook from an external source to trigger a SecureX orchestration workflow, what is the mandatory authentication requirement?

A.API Client ID and Secret with appropriate scopes
B.LDAP credentials
C.A shared static password
D.An SSH private key
AnswerA

The API credentials provide the necessary permissions to trigger workflows via the SecureX API.

Why this answer

SecureX webhooks require an API token or a specifically configured authentication header to prevent unauthorized workflow execution.

194
MCQmedium

Which component is required to allow Umbrella to perform SSL decryption on web traffic?

A.DNS-over-HTTPS setup
B.VPN client configuration
C.Public IP whitelisting
D.Deployment of the Umbrella Root CA
AnswerD

Trusting the Root CA is mandatory for man-in-the-middle decryption.

Why this answer

To perform SSL decryption, the Umbrella Root CA certificate must be installed on all client endpoints to prevent browser certificate warnings.

195
Multi-Selectmedium

When building a custom API integration in SecureX, which TWO authentication protocols are commonly supported for secure access?

Select 2 answers
A.API Key
B.Kerberos
C.NTLM
D.OAuth2
E.LDAP
AnswersA, D

API keys are a common and simple authentication method.

Why this answer

OAuth2 and API Keys are the two most common methods for authenticating API requests in modern security platforms.

196
MCQeasy

Which Cisco product facilitates 'Cloud-to-Cloud' security by monitoring activities in SaaS platforms like Microsoft 365?

A.Cisco Cloudlock
B.Cisco Firepower
C.Cisco Duo
D.Cisco Umbrella
AnswerA

Cloudlock is the designated CASB product for SaaS security.

Why this answer

Cisco Cloudlock (part of the Secure Access suite) is a CASB that integrates via API to monitor and protect SaaS applications.

197
MCQmedium

When using Umbrella's 'Selective Proxy', how is the determination made to route traffic through the proxy vs. direct to destination?

A.Based on the domain categorization
B.Based on the packet source IP
C.Based on the browser type
D.Based on the time of day
AnswerA

Risky domains are proxied, safe ones are passed through.

Why this answer

The Selective Proxy uses a list of domains (like those known to host malware) to decide whether to route traffic through the proxy for deep inspection.

198
MCQmedium

When designing a cloud security architecture, why is 'logging and observability' so critical?

A.To automatically block all incoming traffic.
B.To reduce the cost of cloud storage.
C.To increase the speed of the internet connection.
D.To ensure compliance and enable efficient threat hunting.
AnswerD

Visibility is the foundation of security operations.

Why this answer

Centralized logging provides the necessary data for threat hunting, compliance auditing, and troubleshooting in a distributed cloud environment.

199
Multi-Selectmedium

When designing a SOAR playbook for cloud security incidents, which TWO factors are critical for ensuring successful execution?

Select 2 answers
A.Input validation logic
B.Full administrative privileges
C.Manual intervention steps
D.Correct API permissions for integrated tools
E.Frequent database reindexing
AnswersA, D

Validating input prevents errors from malformed data.

Why this answer

Proper permissions and clear input validation are required for automated workflows to function reliably in a cloud environment.

200
Multi-Selecthard

Which THREE items are included in a Cisco Cloudlock 'Incident' report?

Select 3 answers
A.BIOS version
B.Severity level
C.Policy name
D.User's home Wi-Fi SSID
E.User identity
AnswersB, C, E

Helps prioritize the response.

Why this answer

Cloudlock incidents provide detailed context including the user involved, the severity of the violation, and the specific file or resource affected.

201
MCQmedium

An organization is deploying Cisco Umbrella SIG to enforce Zero Trust access. You must configure the selective decryption policy. Which setting ensures that specific sensitive traffic, such as financial and healthcare sites, is bypassed for inspection to comply with privacy regulations?

A.Apply a 'Transparent Proxy' setting on the local Cisco ASA firewall.
B.Configure a Web Policy rule with a 'Decrypt' action and specify the sensitive categories in the 'Bypass' list.
C.Enable 'HTTPS Inspection' in the Cloud Security global settings and select 'Bypass All' for all categories.
D.Set the 'Block' action for sensitive categories in the Destination Lists.
AnswerB

This is the correct procedural step in Umbrella to exclude traffic from inspection.

Why this answer

Within the Cisco Umbrella dashboard, the SSL Decryption policy allows administrators to define bypass lists for specific categories or domains to prevent sensitive traffic from being decrypted.

202
MCQhard

A company wants to prevent users from using personal devices for work. Which Duo policy is most effective for this?

A.Browser version policy
B.Geographic location policy
C.MFA prompt frequency policy
D.Trusted Endpoints policy with certificate requirement
AnswerD

Certificates act as a unique identifier for managed devices.

Why this answer

By enforcing 'Trusted Endpoints' and requiring a device certificate, only IT-provisioned and managed devices will be permitted.

203
MCQhard

An organization uses Duo Access Gateway (DAG) to protect on-premises applications. They want to transition to Duo SSO. What is the primary difference in architecture?

A.Duo SSO eliminates the need for on-premises server infrastructure for the identity provider
B.Duo SSO supports only SAML 1.0 protocols
C.Duo SSO requires a dedicated hardware appliance
D.Duo SSO requires the installation of the Duo Authentication Proxy on a local server
AnswerA

Duo SSO moves the IDP function to the cloud.

Why this answer

Duo SSO is a cloud-native IDP, whereas DAG acts as a local proxy requiring on-premises server infrastructure.

204
MCQmedium

A global company needs to ensure that users in different regions have the lowest latency when accessing cloud applications. How should the SASE architecture be configured?

A.Manually configure the proxy settings for each user based on their country.
B.Install an on-premises proxy server in every region.
C.Direct all traffic to a single corporate data center before cloud access.
D.Ensure users are routed through the global anycast network to the nearest Umbrella data center.
AnswerD

Anycast is the key technology that routes users to the optimal node.

Why this answer

Cisco Umbrella uses a globally distributed anycast network, which automatically routes users to the nearest data center, minimizing latency.

205
MCQmedium

You are configuring Cisco Secure Cloud Analytics (formerly Stealthwatch Cloud) to trigger an automated response when a suspicious S3 bucket access pattern is detected. Which integration method is best suited for executing a pre-defined playbook in response to this alert?

A.Utilize a Cisco SecureX Orchestration workflow triggered by a webhook from Secure Cloud Analytics.
B.Deploy a Cisco Firepower Management Center (FMC) to block the S3 IP range.
C.Enable the 'Auto-Block' checkbox in the Cloud Analytics Global Settings.
D.Directly configure the S3 bucket policy to deny all traffic.
E.Configure an AWS Lambda function directly in the Cloud Analytics console.
AnswerA

SecureX Orchestration workflows are specifically designed to ingest webhooks from security tools and execute automated response steps.

Why this answer

Cisco Secure Cloud Analytics integrates with Cisco SecureX via Webhooks or API to trigger Orchestration workflows, which are the standard method for executing SOAR playbooks.

206
Multi-Selecthard

When managing a large-scale incident in SecureX, which THREE features assist in collaborative investigation?

Select 3 answers
A.Casebook sharing
B.Incident timeline
C.Global password reset
D.Automated host re-imaging
E.Snapshot capture
AnswersA, B, E

Multiple analysts can view the same case.

Why this answer

Casebook, snapshots, and the shared incident timeline facilitate team collaboration during incident response.

207
MCQmedium

A user is attempting to access a cloud application protected by Duo SSO. The Duo prompt shows 'Access Denied: Your device is not running a supported browser'. Where is this restriction defined?

A.In the Active Directory GPO for the user
B.In the Duo Authentication Proxy configuration file
C.In the Duo Application configuration under 'Browser Restrictions'
D.In the local browser settings of the client machine
AnswerC

Duo policies allow administrators to restrict access based on browser versions and types.

Why this answer

Browser restrictions are defined within the Duo Policy applied to the specific application or user group.

208
Multi-Selecthard

Which TWO methods can be used to identify internal clients in Cisco Umbrella reports?

Select 2 answers
A.Umbrella Virtual Appliance (VA)
B.DHCP relay settings
C.Umbrella Roaming Client
D.Public IP address of the ISP
E.DNS-over-HTTPS
AnswersA, C

VAs report the internal IP to the Umbrella dashboard.

Why this answer

Internal clients are identified by either the local IP address (via VA) or the Roaming Client ID.

209
MCQeasy

What is the purpose of the 'Enrollment Email' sent by Duo?

A.To notify the user of a security breach
B.To allow the user to register their authentication device
C.To provide instructions on how to use VPN
D.To reset the user's domain password
AnswerB

This simplifies the onboarding process.

Why this answer

The enrollment email allows users to self-register their devices, reducing the burden on IT support teams.

210
MCQeasy

What is the purpose of the 'Casebook' in Cisco SecureX?

A.Monitor network traffic
B.Group observables for investigation
C.Configure firewall policies
D.Automate endpoint isolation
AnswerB

Casebook is for incident tracking and evidence collection.

Why this answer

Casebook serves as an incident management workbench, allowing analysts to group observables and evidence for investigation.

211
MCQmedium

You are integrating Cisco Umbrella with your incident response process. When a domain is flagged as malicious, you want to automatically add the domain to a 'Blocked' destination list. Which API or service should the SecureX Orchestration workflow utilize to achieve this?

A.Umbrella Management API.
B.Cisco Cloudlock API.
C.Umbrella Enforcement API.
D.Umbrella Discovery API.
E.SecureX Threat Intelligence API.
AnswerC

The Enforcement API is explicitly designed for third-party systems to push malicious domains into Umbrella destination lists.

Why this answer

The Cisco Umbrella Reporting and Enforcement API is the correct interface for programmatically modifying destination lists in Umbrella.

212
Multi-Selectmedium

Which THREE factors are typically considered when evaluating 'Device Posture' in a Zero Trust environment?

Select 3 answers
A.The user's home internet speed
B.Disk encryption status
C.Antivirus status
D.The user's favorite website
E.Operating system patch level
AnswersB, C, E

Ensuring data is encrypted on the device is a key security policy.

Why this answer

Posture checks commonly look at OS patches, antivirus status, and disk encryption to determine device health.

213
MCQeasy

What is the primary function of the 'Reporting' section in Cisco Defense Orchestrator?

A.Providing visibility into policy usage and device status
B.Configuring VPN settings
C.Scanning for malware on endpoints
D.Automating firmware updates
AnswerA

This is the primary purpose of reports in CDO.

Why this answer

The reporting section in CDO provides visibility into policy usage, device status, and configuration changes across the managed fleet.

214
MCQeasy

What is the primary function of the 'Threat Response' module within SecureX?

A.DNS query caching
B.Unified investigation across multiple security products
C.Automated patch management for Windows servers
D.Hardware inventory reporting
AnswerB

Threat Response allows analysts to pivot across various integrated products to investigate incidents.

Why this answer

Threat Response is the core module used to aggregate data from multiple sources (endpoints, DNS, network) to perform investigations.

215
Multi-Selecthard

Which THREE of the following are components of the Duo 'Trusted Endpoints' solution?

Select 3 answers
A.An MDM/UEM solution for device management
B.Duo policy configured to require trusted endpoints
C.Local firewall on the endpoint
D.Device certificate on the endpoint
E.Active Directory domain controller
AnswersA, B, D

Provides the management state.

Why this answer

Trusted endpoints rely on device certificates, an management platform (like MDM), and the Duo policy to verify device identity.

216
MCQeasy

What is the primary benefit of deploying a 'Managed' SaaS application configuration in Cisco Umbrella?

A.Faster internet speed.
B.Granular policy enforcement and visibility.
C.Reduced cloud storage costs.
D.Automatic software updates.
AnswerB

This allows for specific control over SaaS usage.

Why this answer

Managed applications allow for granular visibility and enforcement policies to be applied specifically to those apps, as opposed to generic web traffic.

217
MCQhard

When using SecureX Threat Response, you perform a search for a specific IP address. Which sources are queried to build the investigation graph?

A.Only the locally cached logs from the browser
B.All enabled integration modules in SecureX
C.The public DNS whois database only
D.The local host file on the analyst's workstation
AnswerB

It queries all modules to get the most comprehensive intelligence.

Why this answer

Threat Response aggregates data from all connected integration modules, such as Umbrella, Secure Endpoint, and Firepower, to build a holistic graph.

218
MCQhard

When configuring Cisco Umbrella for SaaS, how does SSL inspection impact the visibility of application traffic?

A.It blocks all encrypted traffic.
B.It decreases application performance.
C.It removes the need for DNS filtering.
D.It enables deep packet inspection of SaaS content.
AnswerD

Decryption is required for content-level inspection.

Why this answer

SSL inspection decrypts traffic, allowing the proxy to inspect the actual payload, which is essential for granular visibility and DLP enforcement within SaaS apps.

219
Multi-Selectmedium

When managing incidents in SecureX, which TWO actions can be performed directly from a Casebook?

Select 2 answers
A.Manage user passwords
B.Modify firewall firmware
C.Trigger a workflow
D.Delete all historical logs
E.Add observables to the case
AnswersC, E

Workflows can be launched from the Casebook interface.

Why this answer

Casebook allows analysts to add observables for investigation and trigger pre-configured workflows to automate response.

220
MCQmedium

You are using SecureX Orchestration. What is the difference between a 'Global' and a 'Local' workflow variable?

A.Global variables can only be set via the CLI
B.Local variables are faster to process
C.Local variables can be encrypted, while global cannot
D.Global variables are shared across workflows, while local variables are scoped to a single workflow
AnswerD

This is the correct architectural distinction between the two.

Why this answer

Global variables are accessible across different workflows within the organization, while local variables are confined to the specific workflow execution they reside in.

221
MCQeasy

Which Duo feature allows an administrator to visualize the percentage of users who have successfully registered their mobile devices?

A.Duo Authentication Log
B.Duo Dashboard
C.Duo Policy Editor
D.Duo Trust Monitor
AnswerB

The dashboard displays high-level enrollment statistics.

Why this answer

The Duo Admin Panel Dashboard provides analytics and reporting on enrollment progress.

222
Multi-Selectmedium

When integrating Cisco Umbrella with a SaaS application, which TWO methods can be used to ensure secure user authentication?

Select 2 answers
A.SNMP monitoring
B.Local LDAP database
C.Duo MFA integration
D.WPA2-Enterprise
E.SAML integration with an IdP
AnswersC, E

Duo adds a second layer of verification for SaaS access.

Why this answer

Umbrella can work with IdPs (like Duo or Azure AD) to enforce SAML-based authentication and ensure consistent security posture.

223
MCQeasy

Which of the following is a key component of the SecureX 'Dashboard' customization?

A.Modifying the SecureX source code
B.Editing the backend SQL database
C.Adding and configuring Widgets
D.Installing custom browser plugins
E.Changing the global CSS file
AnswerC

Widgets are the building blocks of the SecureX dashboard.

Why this answer

SecureX allows users to add, remove, and resize 'Widgets' to tailor the view to their specific needs.

224
MCQmedium

Why is 'SSL/TLS Inspection' necessary in a SASE architecture?

A.To allow the security stack to inspect encrypted payloads for threats and sensitive data.
B.To allow the ISP to monitor user traffic.
C.To accelerate the connection for the end user.
D.To replace the need for end-to-end encryption.
AnswerA

Visibility is required to enforce security policies on encrypted traffic.

Why this answer

Without decryption, security tools cannot see the content of encrypted traffic, allowing threats or data leaks to pass undetected.

225
Multi-Selecteasy

You are reviewing the SecureX 'Threat Response' module. Which THREE actions can you perform directly from the investigation canvas once you have identified a malicious file hash? (Choose three.)

Select 3 answers
A.Modify the global DNS configuration for the ISP.
B.Search for the hash across integrated security products.
C.Execute a remote shell on the endpoint to delete the file.
D.Pivot to the file trajectory in Secure Endpoint.
E.Isolate the endpoint via Secure Endpoint.
AnswersB, D, E

The 'Search' function is the primary capability of Threat Response.

Why this answer

The canvas allows for pivoting to intelligence reports, initiating file isolation, and searching for the file across the entire environment.

Page 2

Page 3 of 5

Page 4

All pages