Courseiva

Cisco Designing and Implementing Secure Cloud Access for Users and Endpoints (SCAZT, 300-740, CCNP Security) (SCAZT) (SCAZT) — Questions 301316

316 questions total · 5pages · All types, answers revealed

Page 4

Page 5 of 5

301
MCQhard

You are utilizing Cisco Umbrella to block access to unsanctioned SaaS apps. You want to allow access to O365 but restrict users to only your corporate tenant. Which feature should you enable?

A.URL filtering
B.DNS Layer Security
C.SSL Decryption
D.Tenant Restrictions
AnswerD

This is the standard mechanism to pin users to a corporate tenant.

Why this answer

Tenant Restrictions (often via headers) allow you to ensure that users can only log in to your specific organization's tenant for SaaS applications.

302
Multi-Selecthard

Which THREE types of information are analyzed by Cisco Secure Workload (Tetration) to enforce micro-segmentation?

Select 3 answers
A.The color of the server rack
B.User identity context
C.Process-level information
D.User's home address
E.Network flow telemetry
AnswersB, C, E

Linking flows to users provides better security context.

Why this answer

Tetration analyzes process information, user context, and network flow data to define policies.

303
MCQeasy

Which term describes the unauthorized use of cloud applications by employees within an organization?

A.Zero Trust
B.Cloud-Native
C.Shadow IT
D.BYOD
AnswerC

Correct definition for unauthorized SaaS usage.

Why this answer

Shadow IT refers to applications or software used within an organization without explicit IT department approval.

304
MCQmedium

A security architect is designing a SASE solution. What is the significance of 'Identity-Based Segmentation' in this design?

A.It allows for faster internet speeds by bypassing the firewall.
B.It allows for access control based on user identity rather than network topology.
C.It enables automatic IP address assignment for cloud users.
D.It reduces the complexity of managing VLANs.
AnswerB

This is the fundamental shift from traditional network segmentation to identity-centric security.

Why this answer

Identity-based segmentation allows for granular access control, ensuring users can only access applications they are authorized to use, regardless of their location.

305
MCQmedium

When using SecureX to orchestrate response, which action is best suited for blocking a URL globally?

A.Endpoint Host File Modification
B.Umbrella Policy Update
C.FMC Rule Update
D.Cloud Access Security Broker Rule
AnswerB

Updating the Umbrella policy is the standard way to block URLs.

Why this answer

Cisco Umbrella provides global URL blocking through its DNS-layer security and proxy features, manageable via API.

306
Multi-Selectmedium

Which THREE data types are commonly supported by the Cisco Cloudlock DLP engine for pattern matching?

Select 3 answers
A.Unencrypted binary firmware images
B.Passport Numbers
C.System BIOS versions
D.Credit Card Numbers
E.Social Security Numbers
AnswersB, D, E

Passport numbers are supported under PII templates.

Why this answer

Cloudlock uses a wide variety of predefined regex and pattern matching templates for common sensitive data, including credit cards, social security numbers, and passport numbers.

307
MCQeasy

What is the main advantage of using a Secure Internet Gateway (SIG) over a traditional on-premises firewall?

A.Lower bandwidth costs
B.Consistent protection for off-network users
C.Faster internal LAN speed
D.Elimination of the need for DNS
AnswerB

SIG extends the security perimeter to wherever the user is.

Why this answer

A SIG provides security for users regardless of their location, unlike an on-premises firewall which only protects the office network.

308
MCQmedium

A user is traveling and needs to access a cloud application. The user has no cellular service but has Wi-Fi. Which authentication method is best suited for this scenario?

A.Duo Mobile generated passcode (TOTP)
B.Duo Push
C.SMS Passcode
D.Duo Phone Callback
AnswerA

TOTP codes work offline on the device.

Why this answer

Duo Mobile can generate TOTP (Time-based One-Time Password) codes offline, which can be entered into the prompt.

309
MCQhard

You are seeing 'SSL Inspection Error' in your logs. What is the most likely cause?

A.The Umbrella Root CA is not trusted on the client
B.The destination server is down
C.The policy is set to 'Allow'
D.The tunnel is disconnected
AnswerA

Without the CA, the browser detects a MITM attack.

Why this answer

SSL inspection errors typically occur when the client cannot validate the certificate presented by the proxy, often due to the missing Root CA.

310
Multi-Selecteasy

Which THREE factors are evaluated by the Umbrella policy engine when processing a DNS request?

Select 3 answers
A.The local browser version
B.The color of the hardware
C.The time of the request
D.The identity of the user or device
E.The destination of the request
AnswersC, D, E

Time-based rules are supported in Umbrella policies.

Why this answer

Policies are based on identities (who), destination categories (where), and security settings (what).

311
MCQhard

When troubleshooting a Cisco Umbrella roaming client visibility issue, what does the 'Diagnostic Tool' verify?

A.The encryption strength of the local database
B.Connectivity to the Umbrella service and policy sync status
C.The local CPU usage of the machine
D.Active Directory domain controller sync
AnswerB

This is the primary function of the diagnostic tool.

Why this answer

The diagnostic tool checks for service connectivity, configuration sync, and DNS resolver reachability to ensure the agent is talking to the cloud.

312
MCQeasy

An administrator notices that sensitive data is being shared via Microsoft Teams. Where in the Cloudlock dashboard should they navigate to identify which specific users are sharing the files?

A.Platform > Users > Provisioning.
B.Platform > Settings > API Configuration.
C.Platform > Threat Intelligence.
D.Platform > Incidents dashboard.
AnswerD

Correct. The Incidents dashboard provides granular details on users and files involved in policy violations.

Why this answer

The 'Security Audit' or 'Incidents' dashboard provides a breakdown of users involved in data exposure incidents in SaaS applications like Teams.

313
MCQmedium

When automating threat response using SecureX, you want to verify if a file hash is malicious using Talos Intelligence. Which tool provides this lookup capability?

A.Secure Cloud Analytics
B.Threat Intelligence
C.Endpoint Compliance
D.Identity Services Engine
AnswerB

Threat Intelligence is the module that interfaces with Talos data.

Why this answer

SecureX Threat Intelligence provides access to Talos intelligence data, which can be queried via the UI or API.

314
MCQhard

You are designing a secure remote access solution for a hybrid cloud environment. Which Cisco technology should you implement to replace a traditional VPN while enforcing Zero Trust principles?

A.Cisco Secure Access (ZTNA)
B.Cisco Stealthwatch Cloud
C.Cisco Meraki Client VPN
D.Cisco Firepower VPN
AnswerA

ZTNA provides granular, application-specific access, which is the core of Zero Trust remote access.

Why this answer

Cisco Secure Access (the ZTNA offering) provides per-application access based on identity and posture, replacing the broad network access of a VPN.

315
Multi-Selecthard

Which THREE types of activities are commonly used in SecureX orchestration playbooks for threat containment?

Select 3 answers
A.Update firewall access policy
B.Clear browser cache
C.Isolate endpoint
D.Restart the operating system
E.Disable user account
AnswersA, C, E

Network blocking stops the spread at the perimeter.

Why this answer

Containment activities usually involve modifying firewall rules, isolating endpoints, and disabling user accounts to prevent further spread.

316
MCQhard

When implementing a ZTNA solution, which factor is most crucial when defining an 'Application Access Policy'?

A.The identity of the user and the specific application they require.
B.The physical location of the cloud data center.
C.The source IP address of the user's laptop.
D.The user's department in Active Directory.
AnswerA

Zero Trust focuses on user-to-app, not net-to-net connectivity.

Why this answer

In ZTNA, policies must be defined based on the user identity and the specific application, rather than network segments.

Page 4

Page 5 of 5

All pages