Courseiva

Cisco Designing and Implementing Secure Cloud Access for Users and Endpoints (SCAZT, 300-740, CCNP Security) (SCAZT) (SCAZT) — Questions 226300

316 questions total · 5pages · All types, answers revealed

Page 3

Page 4 of 5

Page 5
226
MCQhard

You need to ensure that an orchestration workflow only runs if a specific threat intelligence score exceeds a threshold. Which node type do you use?

A.Data Mapping Node
B.Process Node
C.Wait Node
D.Decision Node
AnswerD

Decision nodes allow for conditional branching based on data values.

Why this answer

A 'Decision' node with a numeric comparison operator is used to evaluate threat scores and determine the execution path.

227
MCQhard

You have a requirement to perform 'File Analysis' on downloads. Which Umbrella product component must be enabled?

A.Roaming Client
B.DNS-layer security
C.Umbrella SIG
D.Virtual Appliance
AnswerC

SIG allows for file inspection and malware sandboxing.

Why this answer

File Analysis requires the Umbrella SIG (Secure Internet Gateway) with the Cisco Talos malware inspection engine enabled.

228
MCQeasy

Which Cisco technology provides visibility and control over SaaS applications using API-based integration to inspect data at rest?

A.Cisco Cloudlock
B.Cisco Secure Firewall
C.Cisco Stealthwatch
D.Cisco Umbrella
AnswerA

Cloudlock uses APIs to scan data stored in cloud apps.

Why this answer

Cisco Cloudlock is an API-based CASB that monitors data at rest in SaaS applications by connecting directly to the cloud provider's APIs.

229
Multi-Selecthard

Which TWO settings must be correctly configured to ensure that Cisco Secure Access provides effective decryption and inspection of HTTPS traffic?

Select 2 answers
A.Set the DNS server to the ISP's DNS resolver.
B.Install the Cisco Secure Access Root Certificate on all client devices.
C.Enable 'SSL Inspection' within the specific Web Policy rules.
D.Disable all firewall rules on the local machine.
E.Configure the browser to use a specific proxy server IP.
AnswersB, C

Endpoints must trust the proxy certificate to avoid SSL warnings.

Why this answer

HTTPS inspection requires the deployment of a root CA to endpoints and the configuration of inspection rules in the policy.

230
MCQhard

In a Cisco Secure Access environment, you are applying an application-layer policy to restrict access to a specific SaaS application based on the user's geolocation. Which tool is used to define this access control rule?

A.Cloudlock API Gateway.
B.Web Security Appliance (WSA) Filter.
C.Secure Access Policy rules.
D.Identity Services Engine (ISE) Policy Sets.
AnswerC

Correct. Access policies in Cisco Secure Access define the 'Who, Where, What' for application access.

Why this answer

Cisco Secure Access uses Access Policies that integrate with Identity and Context-Aware settings to enforce location-based access to SaaS applications.

231
MCQmedium

You are integrating Cisco Umbrella into Cisco SecureX. You have successfully configured the API key and registered the organization. However, no Umbrella events are populating the SecureX dashboard. Which configuration step is the most likely cause of this visibility gap?

A.The SecureX ribbon must be manually refreshed in the browser for each user account.
B.Umbrella DNS policies are not blocking threats, so no events are generated.
C.The Umbrella organization must have 'Log Management' enabled to stream events to the SecureX integration.
D.The API credentials lack 'Read-Only' permission for the Umbrella dashboard.
AnswerC

Without enabling Log Management/Streaming for the specific integration, events will not flow to the SecureX cloud.

Why this answer

SecureX requires the 'Event Streaming' or 'Reporting' integration to be explicitly enabled within the Umbrella dashboard to push logs to the cloud-based event bus.

232
MCQeasy

Which Duo feature helps prevent phishing attacks by requiring the user to tap a button only after a verified authentication request?

A.Duo Phone Callback
B.Duo Push with number matching
C.Duo Hardware Tokens
D.Duo Passwordless
AnswerB

The user must enter a number displayed on the login screen into the Duo Mobile app.

Why this answer

Duo Push with number matching ensures the user is actively responding to the specific login event, preventing 'MFA fatigue' and accidental approvals.

233
Multi-Selectmedium

Which TWO pieces of information are required in the Duo Admin Panel to configure a new SAML application integration?

Select 2 answers
A.The Assertion Consumer Service (ACS) URL
B.The local RADIUS shared secret
C.The application's Entity ID
D.The server's public IP address
E.The user's Active Directory password
AnswersA, C

Required for SAML assertion delivery.

Why this answer

To link a SAML app, you need the Metadata file from the app or the manual entry of the Entity ID and Assertion Consumer Service (ACS) URL.

234
Multi-Selectmedium

Which THREE types of information are typically displayed in the Cisco Umbrella 'App Discovery' report?

Select 3 answers
A.Risk Score
B.User's home address
C.Application Name
D.Traffic Volume
E.Application's source code
AnswersA, C, D

Helps assess the security posture of the app.

Why this answer

The App Discovery report provides insights into application categories, risk levels, and usage statistics per app.

235
MCQhard

When integrating Cisco Cloudlock with O365, which authentication mechanism is required to allow the CASB to perform administrative actions, such as removing a malicious file share?

A.LDAP over TLS.
B.SAML 2.0 with manual certificate import.
C.Basic Authentication over SSL.
D.OAuth 2.0 delegated permissions.
AnswerD

Correct. Cloudlock uses OAuth 2.0 to obtain tokens necessary for API operations on SaaS resources.

Why this answer

Cisco Cloudlock requires OAuth 2.0 scopes granted via an administrative consent process to perform actions on behalf of the application in the O365 tenant.

236
Multi-Selecthard

Which THREE components are critical to consider when designing a 'cloud security reference architecture'?

Select 3 answers
A.Physical server cooling systems
B.Identity and Access Management (IAM)
C.Workload security
D.Secure Internet Gateway (SIG)
E.The brand of the office chair
AnswersB, C, D

Identity is the new perimeter in cloud security.

Why this answer

A complete architecture must account for identity, workload protection, and internet edge security.

237
Multi-Selecteasy

Which TWO of the following are primary benefits of Cisco Umbrella DNS-layer security?

Select 2 answers
A.Requires manual firewall updates
B.Uses a cloud-native architecture
C.Requires a physical appliance at every site
D.Only works on corporate-managed devices
E.Blocks threats before a connection is established
AnswersB, E

Umbrella is a cloud-native SaaS solution.

Why this answer

DNS-layer security blocks threats before connection occurs and requires no additional hardware.

238
Multi-Selectmedium

Which TWO of the following scenarios would lead to an 'Access Denied' message in the Duo Authentication Log?

Select 2 answers
A.The user has not enrolled a device yet
B.The user denied the push notification on their phone
C.The user forgot their password
D.The user's device did not meet the mandatory OS version policy
E.The Duo service is temporarily down
AnswersB, D

Result is access denied.

Why this answer

An access denied message can be triggered by a policy failure (like geo-blocking) or a user explicitly canceling the push request.

239
MCQhard

You are investigating a security incident and need to correlate logs from Cisco Secure Endpoint and Cisco Umbrella. What is the key piece of information needed to link these two sets of logs in SecureX?

A.The browser version used by the user
B.The source MAC address only
C.The time the laptop was manufactured
D.A shared identifier like an internal IP address or user identity
AnswerD

This is the 'glue' that allows correlation across platforms.

Why this answer

Both logs need a shared context such as an internal IP address or a user identity that is present in both data sources at the time of the event.

240
MCQeasy

Which capability does the Cisco SecureX 'Response' feature provide to an incident responder when analyzing a file hash detected in the cloud?

A.Automatic deletion of the file from all cloud storage buckets.
B.An automated way to reset user passwords in Azure AD.
C.A method to update cloud firewall rules via CLI.
D.The ability to generate a PDF report of cloud compliance.
E.The ability to search for the file across integrated product logs and take remediation actions.
AnswerE

This is the primary function of the Response capability within SecureX.

Why this answer

The 'Response' feature allows an analyst to pivot across integrated security products to search for the presence of an IOC, such as a file hash, across endpoints, email, and network traffic.

241
MCQmedium

You notice an employee is accessing a cloud app that is not approved by IT. Which Umbrella feature allows you to see this activity?

A.App Discovery
B.Activity Search
C.DNS Policy
D.SSL Inspection
AnswerA

Specifically designed to reveal shadow IT.

Why this answer

Shadow IT reporting within the App Discovery feature shows a list of applications accessed by users that have not been sanctioned by the IT department.

242
MCQmedium

A user is prompted for MFA but their phone is dead. Which administrative feature allows for a temporary bypass?

A.Issue a temporary bypass code in the Duo Admin Panel
B.Disable the user's account in Active Directory
C.Enable the 'Remembered Device' setting
D.Reset the user's password
AnswerA

This allows the user to bypass the prompt for a limited time/count.

Why this answer

Administrators can issue a temporary 'bypass code' that is valid for a single use or a set duration.

243
MCQhard

You are troubleshooting a scenario where users are unable to access a specific internal cloud resource after migrating to Cisco Secure Access. The traffic is being blocked by a default policy. How should you modify the traffic flow to ensure internal traffic stays off the SIG?

A.Configure a Tunnel Exclusion in the Secure Access tunnel settings for the internal IP ranges.
B.Disable the 'Inspect Traffic' setting globally in the Secure Access dashboard.
C.Update the DNS policy to include internal domain suffixes as exceptions.
D.Assign the users to a separate Group Policy that has no web filtering enabled.
AnswerA

Tunnel exclusions allow specific traffic to bypass the SIG, ensuring internal resources remain reachable.

Why this answer

Configuring a PAC file or using Tunnel Exclusions ensures that traffic destined for internal ranges bypasses the SIG tunnel.

244
MCQmedium

Which mechanism does Duo use to integrate with non-SAML cloud applications?

A.Duo API Gateway
B.Duo Universal Prompt
C.Duo Authentication Proxy for RADIUS/LDAP
D.Direct integration via browser extension
AnswerC

The proxy allows legacy protocols to be protected by Duo MFA.

Why this answer

For applications that do not support SAML/OIDC, Duo uses the Authentication Proxy to bridge RADIUS or LDAP requests to the Duo cloud.

245
MCQmedium

When designing a SOAR playbook, which mechanism ensures that the playbook does not trigger multiple times for the same alert?

A.Random delay node
B.Stateful deduplication check
C.Firewall rate limiting
D.Task sequencing
AnswerB

Checking if an incident is already in progress prevents duplicate runs.

Why this answer

Deduplication logic, often using a 'Case' status check or a stateful flag, prevents redundant executions.

246
MCQmedium

You want to ensure that users are warned before visiting a newly registered domain. Which feature in Cisco Umbrella handles this?

A.Application Settings
B.Security Settings
C.Platform Logs
D.Web Policy Categories
AnswerB

Newly registered domains are a security category.

Why this answer

Newly registered domains are a security category in Umbrella that can be blocked or warned to prevent users from accessing potentially malicious sites.

247
Multi-Selectmedium

Which TWO are common 'secure access design patterns' in a hybrid cloud?

Select 2 answers
A.Connecting all apps to the local LAN only
B.ZTNA for remote user access
C.Transit gateway inspection for inter-VPC traffic
D.Open access for all traffic
E.Public internet bypass for all traffic
AnswersB, C

This is the current best practice for user access.

Why this answer

Standard patterns include ZTNA for users and secure transit gateways for inter-cloud traffic.

248
MCQeasy

Which of the following is a requirement for using the Duo 'Remembered Devices' feature?

A.The user must be on the corporate network
B.The user must have a registered hardware token
C.The endpoint must be joined to a domain
D.The user's browser must accept cookies from the Duo domain
AnswerD

The session persistence relies on browser cookies.

Why this answer

Remembered Devices works by setting a cookie in the user's browser, which requires the browser to accept cookies from the Duo domain.

249
MCQmedium

You are implementing Cisco Duo Device Health for a Windows fleet. Users report that they are blocked from accessing cloud apps despite having valid credentials. The Duo Health app reports a missing OS security patch. Which component is responsible for enforcing this posture check during the authentication flow?

A.Microsoft Conditional Access Policy
B.Duo Access Policy
C.Duo Authentication Proxy
D.Duo Device Health Application
AnswerB

Policies configured in the Duo Admin Panel enforce the specific requirement for OS security patches.

Why this answer

The Duo Central/Duo Access Gateway (DAG) or Duo SSO evaluate the health status passed by the Duo Device Health application before granting access.

250
MCQmedium

Which Duo log would be most useful for troubleshooting a failure during the initial push notification delivery?

A.Directory Sync Log
B.Telephony Log
C.Administrative Actions Log
D.Authentication Log
AnswerD

This provides transaction-level detail, including MFA method success/failure.

Why this answer

The Authentication Log provides a detailed breakdown of each step in the MFA process, including push delivery status.

251
MCQhard

You are designing a secure access path for a BYOD device. What is the most effective approach to ensure the device does not compromise the network?

A.Provide the device with a permanent VPN connection.
B.Enforce ZTNA with device posture checks and MFA.
C.Require the device to join the corporate Active Directory domain.
D.Configure an open SSID for BYOD devices.
AnswerB

This combination validates the identity and the security state of the device before granting access.

Why this answer

ZTNA ensures that the device is checked for posture and the user is authenticated before allowing access, regardless of device ownership.

252
MCQmedium

When monitoring compliance in Cisco Defense Orchestrator (CDO), which action should you perform to identify out-of-sync configurations across your Cisco ASA and Firepower Threat Defense devices?

A.Perform a 'Check for Changes' operation
B.Run a packet capture on the ASA interface
C.Generate a Compliance Report in SecureX
D.Reset the device credentials
AnswerA

This triggers a scan to compare the local device state with the intended policy managed in CDO.

Why this answer

CDO provides a 'Conflict Detection' and 'Out-of-Sync' state indicator that identifies differences between the device config and the CDO-managed policy.

253
MCQeasy

What is the role of a 'Policy' in Cisco Umbrella?

A.To configure hardware settings
B.To monitor bandwidth usage
C.To manage API credentials
D.To define security and filtering rules for identities
AnswerD

Policies are the core logic of the Umbrella platform.

Why this answer

A policy defines the set of rules (security, content, application control) applied to specific identities (users, networks, roaming clients).

254
Multi-Selectmedium

What are TWO primary ways to trigger an orchestration workflow in SecureX?

Select 2 answers
A.Scheduled reboot
B.Console-based typing
C.Manual triggering
D.Webhook ingestion
E.Direct database injection
AnswersC, D

Users can run workflows on demand.

Why this answer

Workflows can be initiated manually via the UI or automatically via external events sent through webhooks.

255
Multi-Selectmedium

Which THREE items are considered primary components of the Cisco Umbrella 'Identity' structure when creating security policies?

Select 3 answers
A.Roaming Computer
B.Network (IP-based)
C.MAC Address of the Printer
D.Active Directory User/Group
E.Public Cloud Instance ID
AnswersA, B, D

Endpoints with the roaming client are a primary identity type.

Why this answer

Umbrella policies are applied based on identities, which include networks, roaming computers, and Active Directory objects.

256
MCQhard

When designing a Zero Trust architecture using Cisco Secure Access, how does the 'Device Posture' check specifically influence the access decision for a managed laptop?

A.It switches the user's connection to a VPN tunnel.
B.It forces a mandatory password reset if the device is out of compliance.
C.It checks the user's IP address against a geo-blocking database.
D.It requires the presence of an MDM-enrolled certificate or specific registry key before authorizing the session.
AnswerD

Device posture checks are granular and look for specific configurations like certificates or managed state.

Why this answer

Device posture checks in Cisco Secure Access verify the health and security configuration of the endpoint before granting access to protected applications.

257
MCQmedium

Which method is the most secure way to authenticate users for Cisco Secure Access?

A.Local user accounts
B.SAML 2.0 integration with an IdP
C.Using the default admin account
D.Static IP-based authentication
AnswerB

SAML is the recommended standard for enterprise identity.

Why this answer

Integrating with an IdP via SAML ensures multi-factor authentication and centralized lifecycle management.

258
MCQmedium

In Cisco Defense Orchestrator, why would an object show a 'Read Only' status?

A.The object was imported from a device and is not yet managed as a CDO object
B.The object is stored on a read-only disk partition
C.The object is currently being used in a policy
D.The user lacks administrator privileges
AnswerA

CDO keeps imported objects read-only until they are explicitly managed.

Why this answer

Objects are often read-only in CDO if they were imported from a device and have not been 'claimed' or converted into a CDO-managed object yet.

259
MCQhard

You are setting up a secure hybrid cloud environment. How do you implement 'Micro-segmentation' between virtual machines in the same subnet?

A.Rely on the cloud provider's default network ACLs.
B.Place each VM in a different subnet.
C.Configure a VLAN for every virtual machine.
D.Use host-based security policies or a distributed SDN firewall.
AnswerD

Micro-segmentation requires enforcement at the workload level, not the network perimeter.

Why this answer

Micro-segmentation is achieved using host-based firewalls or SDN controllers (like those provided by Cisco Secure Workload/Tetration) to enforce policy at the individual workload level.

260
MCQhard

If you configure an API-based connector for a new SaaS app in Cisco Cloudlock, when does the initial scan typically begin?

A.At midnight, based on the system clock.
B.Only when the first user logs in.
C.After an administrator manually clicks 'Start'.
D.Immediately upon saving the configuration.
AnswerD

The scan initiates as soon as authorization is granted.

Why this answer

After the OAuth handshake and the 'Save' of the connector configuration, Cloudlock triggers an initial scan of the application's environment (e.g., all files in Google Drive).

261
Multi-Selectmedium

Which TWO aspects of threat response are improved by using SecureX orchestration?

Select 2 answers
A.Reduced response time
B.Consistent execution
C.Increased manual oversight
D.Hardware performance
E.Network latency
AnswersA, B

Automation is faster than manual response.

Why this answer

Orchestration reduces response time by automating manual steps and minimizes human error through consistent, programmatic actions.

262
Multi-Selectmedium

Which THREE mechanisms are commonly used by a CASB to enforce access control to SaaS applications?

Select 3 answers
A.Local host firewall rules.
B.Direct switch-to-server connection.
C.API-based integration.
D.Reverse Proxy.
E.Forward Proxy.
AnswersC, D, E

Correct. API allows granular policy enforcement.

Why this answer

CASB enforces access via API integration, forward proxy, and reverse proxy architectures.

263
MCQeasy

What is the primary goal of the 'Cisco SASE' framework?

A.To increase the cost of cloud services.
B.To replace all physical firewalls in the data center.
C.To converge networking and security services into a single cloud-delivered offering.
D.To provide a new type of internet provider service.
AnswerC

The convergence of SD-WAN and SIG is the core of the SASE architecture.

Why this answer

Cisco SASE combines networking and security capabilities into a single cloud-native service to provide secure, optimized access to users wherever they are.

264
MCQmedium

When performing automated threat hunting, you need to query multiple cloud platforms. Which SecureX feature enables this unified query?

A.Federated Search
B.Snapshot Analysis
C.Centralized Dashboard
D.Aggregated Logging
AnswerA

Federated search aggregates results from multiple sources.

Why this answer

SecureX Threat Response allows for federated searches across integrated threat intelligence and security product APIs.

265
MCQmedium

You are investigating an authentication failure. The log shows 'Error: User not found in directory'. What does this imply?

A.The user is not present in the Active Directory group synced to Duo
B.The Duo Authentication Proxy cannot reach the AD server
C.The user's password is expired in AD
D.The Duo service is experiencing an outage
AnswerA

The lookup fails because the user is missing in the synced directory object.

Why this answer

This error occurs when the Duo cloud service attempts to check a user's status against the synced directory, but the user does not exist or was not successfully synced.

266
MCQhard

You observe that Cisco Secure Cloud Analytics is not reporting any 'Watchlist' alerts. What is the most likely reason?

A.The traffic does not match the criteria defined in the Watchlists
B.The analytics engine is offline
C.The SecureX integration is disabled
D.The cloud gateway is using an outdated SSL certificate
AnswerA

No matches equals no alerts; this is the most common operational reason.

Why this answer

Watchlists in Secure Cloud Analytics are specific user-defined triggers; if no traffic matches those specific criteria, no alerts will be generated.

267
MCQmedium

Which Cisco Cloudlock policy type should be used to detect when a user logs in from an unusual geographic location?

A.Data Exposure
B.Cross-platform threat
C.Application firewall
D.User Behavior Analytics
AnswerD

UBA monitors login patterns and locations.

Why this answer

User Behavior Analytics (UBA) specifically includes checks for 'Impossible Travel' and unusual login locations.

268
MCQhard

During the design of a SOAR playbook for cloud incident response, you need to ensure that evidence collection is preserved in a compliant manner. Which action is recommended when integrating with Cisco Secure Endpoint for forensic data collection?

A.Manually SSH into the VM to copy /var/log files.
B.Execute 'Get Forensic Snapshot' through the Secure Endpoint integration.
C.Copy files to a local public-facing FTP server for review.
D.Delete the VM and restore from a known good backup.
E.Trigger a full disk wipe of the instance.
AnswerB

This is the official method to automate forensic data collection and store it centrally in the cloud.

Why this answer

Using the 'Get File' or 'Get Forensic Snapshot' features within the Secure Endpoint integration ensures that artifacts are captured and stored directly into the Secure Endpoint cloud for later analysis, maintaining chain of custody.

269
MCQeasy

In Cisco Umbrella, which component is used to associate internal IP addresses with Active Directory user identities for granular policy reporting?

A.Umbrella Virtual Appliance
B.Cisco Secure Endpoint
C.AnyConnect Management Tunnel
D.Umbrella Roaming Client
AnswerA

Virtual Appliances identify users by querying AD and reporting the IP-to-user mapping to Umbrella.

Why this answer

The Umbrella Virtual Appliance (VA) facilitates the mapping of internal IP addresses to AD users and groups.

270
Multi-Selecthard

Which TWO methods are used to verify compliance against security policies in Cisco Defense Orchestrator?

Select 2 answers
A.Generating compliance reports on policy configurations
B.Running the 'Check for Changes' feature to detect drift
C.Rebooting all security appliances
D.Executing a manual traceroute from every endpoint
E.Manually re-configuring the entire firewall
AnswersA, B

Reporting provides audit visibility.

Why this answer

CDO verifies compliance via the 'Check for Changes' functionality and by generating reports on policy status.

271
MCQhard

You are creating a custom report in SecureX for compliance auditing. You need to include data from both Cisco Secure Endpoint and Cisco Secure Firewall. What is the requirement to make this possible?

A.The devices must be on the same VLAN
B.You must use the CLI to enable the report feature
C.Both integration modules must be configured and authenticated in SecureX
D.They must be in the same physical rack
AnswerC

Data ingestion is required before reporting can occur.

Why this answer

Both products must have their respective integration modules enabled and active in the same SecureX organization for their data to be available for combined reporting.

272
MCQhard

An administrator needs to ensure that only managed devices can access SaaS applications via Cisco Duo. Which configuration step is mandatory in the Duo Admin Panel to ensure the device is recognized as 'Managed'?

A.Configure the Duo Authentication Proxy for RADIUS bypass
B.Enable 'Trusted Endpoints' in the Duo Admin panel without certificate deployment
C.Enable 'Require Device Health' in the application policy and ensure the Duo Device Health application is installed
D.Assign a static IP address to every endpoint
AnswerC

This combination ensures the endpoint reports its health data and identity to the Duo cloud.

Why this answer

To identify a device as managed, the administrator must deploy the Duo Device Health application and ensure the device certificate is present.

273
MCQmedium

In SecureX orchestration, which object type is used to store sensitive API keys used by workflows?

A.Variable
B.Credential
C.Vault Asset
D.Global Constant
AnswerB

Credential objects are specifically designed for secrets management.

Why this answer

Credential objects provide a secure way to store secrets, ensuring they are encrypted and not visible in plaintext within the workflow designer.

274
MCQmedium

In Secure Access, how are 'Traffic Forwarding' profiles used?

A.To set up load balancing
B.To encrypt cloud storage
C.To define user roles
D.To define how traffic is routed to the cloud gateway
AnswerD

Forwarding profiles manage the tunnel/proxy steering.

Why this answer

Traffic Forwarding profiles define which traffic (web, non-web, specific ports) should be sent to the Secure Access cloud.

275
MCQeasy

What is the function of an Umbrella 'Integrations' key?

A.To sign digital certificates
B.To automate API-based policy and log management
C.To encrypt DNS queries
D.To identify roaming clients
AnswerB

API keys allow external tools to interact with Umbrella.

Why this answer

API keys are used to integrate Umbrella with other systems like SIEMs or threat intelligence platforms to automate policy updates.

276
MCQhard

A user is experiencing 'Access Denied' when trying to access a cloud resource. You are using the SecureX 'Pivot' menu to investigate. What are you looking for in the logs?

A.Policy enforcement logs showing a 'Deny' action
B.CPU utilization trends
C.Successful authentication logs
D.Packet drop counters on the switch
AnswerA

Finding the specific policy that triggered the block is the goal of the investigation.

Why this answer

The Pivot menu allows you to jump to related logs; you are specifically looking for the 'Action' field set to 'Deny' along with the corresponding policy ID.

277
Multi-Selecthard

Which THREE factors influence the user experience when using Duo Passwordless?

Select 3 answers
A.The browser or platform's support for WebAuthn
B.The presence of a platform authenticator (e.g., Windows Hello)
C.The user's active directory password strength
D.The Duo Policy settings for the application
E.The user's network speed
AnswersA, B, D

Essential for the protocol.

Why this answer

Duo Passwordless experience is shaped by the platform authenticator, the configured policy, and the application's support for WebAuthn.

278
Multi-Selecteasy

Which THREE components are part of the Cisco SecureX suite?

Select 3 answers
A.Threat Response
B.Cisco IOS-XE CLI
C.Dashboard
D.Cisco Webex Meetings
E.Orchestration
AnswersA, C, E

A core module of SecureX.

Why this answer

SecureX includes threat response, orchestration, and dashboarding as its primary components.

279
MCQhard

You are implementing Cisco Secure Access and need to configure a Global Policy that restricts access to unsanctioned SaaS applications based on their risk score. Where should this policy be applied in the Secure Access dashboard?

A.Under Policy > Network Policies > DNS Policy
B.Under Settings > Device Management > SaaS Controls
C.Under Connect > Network > Cloud Firewalls
D.Under Policy > Access Policies > Web Policy > CASB
AnswerD

The CASB section within Web Policies is the designated location for controlling SaaS app access via risk scoring.

Why this answer

Cloud Access Security Broker (CASB) settings within the Secure Access portal allow for application risk scoring and policy enforcement.

280
MCQmedium

In the context of SASE, what is the primary role of the 'Global Anycast Network'?

A.To hide the internal IP addresses of the users.
B.To manage user credentials across multiple cloud providers.
C.To provide high availability and optimal latency by routing traffic to the nearest security node.
D.To encrypt traffic between the user and the cloud.
AnswerC

This is the core benefit of anycast for SASE performance.

Why this answer

Anycast allows the enterprise to use a single IP address to reach the nearest Umbrella data center, improving performance and reliability.

281
Multi-Selecthard

Which THREE conditions must be met for a user to be able to use the 'Self-Service Portal' for device enrollment?

Select 3 answers
A.Self-enrollment must be enabled in the global settings
B.The user must be in a synced directory group
C.The Duo Authentication Proxy must be in 'Bypass' mode
D.The device must be joined to the domain
E.The user must have an active email address
AnswersA, B, E

This is the policy trigger.

Why this answer

Self-service enrollment requires directory integration, an accessible URL, and an enabled policy.

282
MCQeasy

Which report in Cisco Umbrella provides the most direct view of security threats identified in your environment?

A.Top Identities
B.Application Usage
C.Security Activity
D.Web Activity
AnswerC

This is the primary report for threat analysis.

Why this answer

The Security Activity report details all blocked threats, including malware, phishing, and command-and-control attempts.

283
MCQmedium

What is the primary function of the Duo 'Telephony Credits'?

A.To unlock premium reporting features
B.To provide hardware tokens to employees
C.To cover the costs of SMS and voice call authentication
D.To pay for the monthly Duo license fee
AnswerC

These methods consume telephony credits.

Why this answer

Telephony credits are used specifically for SMS and voice-call-based MFA, as these incur costs from telecommunication providers.

284
Multi-Selectmedium

Which TWO of the following are benefits of using the Duo Authentication Proxy for on-premises AD integration?

Select 2 answers
A.Local storage of user credentials
B.Provides an offline authentication database
C.Secure transport of authentication requests to Duo Cloud
D.Automated synchronization of AD users and groups to Duo
E.Direct replacement of the Active Directory domain controller
AnswersC, D

The proxy encrypts all traffic to the cloud.

Why this answer

The proxy handles directory syncing and provides a secure, encrypted tunnel to the Duo cloud.

285
MCQeasy

Which component in the Cisco SecureX suite allows you to build custom, automated security tasks?

A.Device Inventory
B.Threat Response
C.Security Analytics
D.Orchestration
AnswerD

Orchestration is the engine for building custom workflows.

Why this answer

SecureX Orchestration is the low-code/no-code engine used to create workflows and automate tasks.

286
Multi-Selecthard

You are setting up visibility for a hybrid-cloud environment using SecureX. Which THREE of the following represent valid data sources that can be integrated to provide comprehensive threat context? (Choose three.)

Select 3 answers
A.Cisco Secure Firewall (Firepower Management Center).
B.Third-party SIEM data raw ingestion.
C.Cisco Umbrella.
D.Cisco Secure Endpoint (AMP for Endpoints).
E.Cisco Meraki Dashboard (non-MR).
AnswersA, C, D

FMC provides network-level flow and threat detection telemetry.

Why this answer

SecureX integrates natively with Umbrella, Secure Endpoint (AMP), and Secure Firewall (Firepower) to aggregate telemetry.

287
MCQmedium

You need to ensure that all web traffic from a branch office is inspected by the Umbrella SIG. Which configuration step is mandatory on your perimeter router?

A.Install the Roaming Client on the router
B.Create a PBR (Policy Based Routing) to direct traffic to the tunnel
C.Define an ACL to permit all traffic to Umbrella
D.Enable DNS-over-HTTPS on the router
AnswerB

PBR is used to divert specific traffic into the tunnel interface.

Why this answer

The router must be configured to route traffic destined for the internet through the tunnel interface pointing to the Umbrella data center.

288
MCQmedium

When designing an automated threat response for cloud-native applications, why is it critical to include a 'Human-in-the-loop' (HITL) step in the orchestration workflow?

A.Because the Cisco SecureX platform requires a manual key-press to initiate any network-based isolation.
B.To ensure that automated remediation actions are reviewed and approved before impacting production services.
C.Because the SOAR platform cannot execute more than one API call without human confirmation.
D.To provide evidence for the automated audit log.
E.To comply with API rate-limiting requirements on cloud provider platforms.
AnswerB

This provides a safety mechanism for critical actions like isolating production assets.

Why this answer

HITL is critical in automated workflows to prevent false positives from causing business disruption, especially when the remediation involves blocking critical services or isolating production servers.

289
MCQmedium

A company wants to prevent users from bypassing security policies by using unauthorized VPNs or proxies. Which feature in Cisco Umbrella should be enabled to mitigate this risk?

A.Deploy the Cisco Secure Endpoint agent to detect unauthorized VPN software.
B.Enable the 'Web Proxy' feature in the Global Settings.
C.Select the 'Proxy and VPN' category within the Destination Lists of the Web Policy.
D.Configure an SSL Inspection rule for all traffic.
AnswerC

Categorization allows for the blocking of known VPN and proxy services used to circumvent policies.

Why this answer

The 'Proxy and VPN' category in the Umbrella destination lists allows administrators to block access to services that can bypass security filters.

290
MCQmedium

Which component of Cisco's secure cloud access architecture is responsible for performing URL filtering and malware scanning on traffic destined for SaaS applications?

A.Cisco Secure Endpoint
B.Cisco Umbrella
C.Cisco Cloudlock
D.Cisco Adaptive Security Appliance
AnswerB

Umbrella performs URL filtering and proxying of web traffic.

Why this answer

Cisco Umbrella acts as a secure web gateway (SWG) to inspect traffic flow and perform URL filtering and malware analysis.

291
MCQhard

A administrator wants to implement 'Strict' device health checks. What happens if a device reports an unknown OS version?

A.The user is redirected to a temporary guest portal
B.The user is prompted to upgrade the OS manually
C.The user is granted read-only access
D.The access attempt is blocked by the policy
AnswerD

Strict policies enforce a 'deny' if the device does not explicitly meet health requirements.

Why this answer

Under a 'Strict' policy, if the device health app cannot confirm a supported, patched OS, the access request is denied.

292
MCQmedium

A company is using Cisco Tetration (Secure Workload) for data center visibility. They need to generate a compliance report that shows communication flows between 'PCI-scoped' and 'Non-PCI-scoped' workloads. Which feature should be used to define this boundary?

A.Annotation Policies.
B.Inventory Filters.
C.Flow Search.
D.Scopes.
AnswerD

Scopes allow for granular grouping and policy analysis within defined segments of the data center.

Why this answer

The 'Scopes' feature in Secure Workload allows for the hierarchical organization of assets and the definition of boundaries for policy analysis and reporting.

293
Multi-Selectmedium

Which THREE actions are required when configuring a new IPsec tunnel for the Cisco SIG (Secure Internet Gateway)?

Select 3 answers
A.Install a client-side agent on every endpoint behind the router.
B.Enable the 'AnyConnect Tunnel' feature on the device.
C.Configure the local firewall with the correct Cisco SIG headend IP address.
D.Configure IKEv2 proposal settings on the local edge device.
E.Define the tunnel endpoint IP address in the Umbrella dashboard.
AnswersC, D, E

The router must know where to send the tunneled traffic.

Why this answer

Configuring an IPsec tunnel requires defining the tunnel details, the IKEv2 settings, and the specific traffic selectors or identity management.

294
MCQmedium

When syncing users from Active Directory to Duo, what is the role of the 'Duo Authentication Proxy'?

A.To facilitate directory synchronization between AD and Duo
B.To enforce hardware-based encryption on AD servers
C.To store user passwords locally
D.To serve as the primary identity provider for the cloud
AnswerA

The proxy is used to sync directory objects to the cloud.

Why this answer

The proxy acts as the bridge that performs LDAP/AD queries and pushes user objects to the Duo cloud.

295
Multi-Selecthard

Which THREE components are required to successfully deploy a webhook-based trigger for SecureX orchestration?

Select 3 answers
A.DNS zone configuration
B.Authentication token
C.Public IP address for the trigger
D.JSON payload structure
E.Endpoint URL
AnswersB, D, E

Required to verify the source of the webhook.

Why this answer

Webhooks require a defined endpoint, an authentication method (often an API key/token), and a payload format to function correctly.

296
Multi-Selectmedium

Which TWO methods can be used to bypass Duo authentication in an emergency?

Select 2 answers
A.Rename the user's AD account
B.Reset the user's password to '12345'
C.Add the user to a group that has a 'Bypass' policy applied
D.Set the global MFA mode to 'Bypass' for all users
E.Issue a temporary bypass code to the user
AnswersC, E

Effective method for temporary emergency access.

Why this answer

Temporary bypass codes and a 'Bypass' policy setting for a specific user group are the standard emergency options.

297
Multi-Selecthard

Which THREE of the following are supported by the Duo Authentication Proxy?

Select 3 answers
A.Windows Logon authentication
B.Direct SAML 2.0 Identity Provider hosting
C.LDAP authentication
D.SQL database direct authentication
E.RADIUS authentication
AnswersA, C, E

Supported via specific agent/proxy workflows.

Why this answer

The proxy supports RADIUS, LDAP, and generic HTTP-based integrations for authentication.

298
MCQeasy

Which Cisco Umbrella report provides the most granular visibility into the specific security categories triggered by user traffic?

A.Total Requests Report
B.Activity Search Report
C.Security Overview Report
D.Destination List Report
AnswerB

Activity Search offers the most granular data regarding policy hits and category blocks.

Why this answer

The 'Activity Search' report allows administrators to filter by category, identity, and destination to identify specific security violations.

299
Multi-Selecthard

Which THREE factors should be considered when designing an IaaS security architecture using Cisco Secure Workload (formerly Tetration)?

Select 3 answers
A.Physical switch port mirroring
B.Global firewall rule consolidation
C.Identity-based policy enforcement
D.Application dependency mapping
E.Host-based sensor deployment
AnswersC, D, E

Policies should be tied to workload identity rather than IP addresses.

Why this answer

Secure Workload focuses on visibility, micro-segmentation, and policy enforcement across hybrid clouds.

300
Multi-Selectmedium

What are TWO benefits of integrating Cisco Secure Email with SecureX orchestration?

Select 2 answers
A.Real-time video monitoring
B.Global threat purging
C.Manual email routing
D.Automated threat extraction
E.Hardware load balancing
AnswersB, D

Can remove malicious emails from all user mailboxes.

Why this answer

Integration allows for automatic extraction of malicious indicators from emails and the ability to purge threats across the organization.

Page 3

Page 4 of 5

Page 5

All pages