Courseiva

CCNA Network And Cloud Security Questions

59 questions · Network And Cloud Security · All types, answers revealed

1
Multi-Selectmedium

Which THREE items must be configured to successfully implement an Umbrella SIG tunnel?

Select 3 answers
A.Public IP address of the branch
B.IKEv2 and IPsec security parameters
C.An active subscription to a VPN provider
D.Policy-Based Routing (PBR) on the router
E.Internal DNS server IP
AnswersA, B, D

Needed to establish the tunnel endpoint.

Why this answer

A tunnel needs the remote IP address, the encryption parameters (IKEv2), and the traffic to be routed through the tunnel.

2
MCQmedium

Which Cisco Umbrella feature allows you to categorize destinations and apply custom block or allow lists?

A.Content Categories
B.Identity Providers
C.Policy Rules
D.Destination Lists
AnswerD

Destination Lists are the mechanism for custom allow/block lists.

Why this answer

Destination Lists allow administrators to manually define domains, IPs, or URLs that should be blocked or allowed regardless of global categories.

3
Multi-Selecthard

Which THREE pieces of information are displayed in the Umbrella 'Activity Search' report?

Select 3 answers
A.Identity that initiated the request
B.Action taken (Allowed/Blocked)
C.Internal hard drive serial number
D.User's password
E.Timestamp of the request
AnswersA, B, E

Identifies the user/device.

Why this answer

Activity logs show the time of the request, the identity that made it, and the action taken (allowed/blocked).

4
MCQmedium

You are deploying Umbrella Virtual Appliances (VAs) in a local Active Directory environment. What is the primary purpose of the VA in this deployment?

A.To bypass the ISP DNS settings
B.To provide identity-based reporting for internal clients
C.To cache web content locally
D.To decrypt HTTPS traffic
AnswerB

VAs integrate with AD to provide granular identity information.

Why this answer

The VA is used to map internal IP addresses to specific identities in the Umbrella dashboard, allowing for per-user or per-group reporting.

5
Multi-Selecteasy

Which TWO components are essential for a complete Cisco Umbrella deployment on end-user laptops?

Select 2 answers
A.A dedicated VPN server
B.Umbrella Roaming Client
C.Cisco Secure Client (AnyConnect)
D.Local Active Directory
E.A physical router
AnswersB, C

Essential for DNS protection.

Why this answer

Roaming client handles DNS, while the AnyConnect module integrates with the broader security suite.

6
Multi-Selectmedium

Which THREE components are critical for a successful cloud network segmentation strategy?

Select 3 answers
A.Access Rules controlling cross-segment traffic
B.Clearly defined Resource Segments
C.A flat network architecture
D.Defined User Identity Groups
E.Shared administrative credentials
AnswersA, B, D

Policies enforce the isolation.

Why this answer

Effective segmentation requires clear definitions of user groups, resource groups, and the access policies that govern their interaction.

7
MCQmedium

You want to restrict access to specific cloud apps (e.g., Dropbox). Which Umbrella feature is used?

A.Content Categories
B.Application Control
C.Firewall Rules
D.URL Filtering
AnswerB

This feature manages SaaS application visibility and blocking.

Why this answer

Application Control allows administrators to discover and block access to specific cloud applications.

8
MCQhard

You are analyzing a 'Domain Blocked' event in Umbrella. The explanation says 'Proxy'. What does this imply?

A.The user is not authenticated
B.The request was blocked by the firewall
C.The traffic was caught by the selective proxy
D.The domain was blocked by the DNS resolver
AnswerC

The proxy allows for deeper inspection and URL-level filtering.

Why this answer

If the block reason is 'Proxy', it means the traffic was routed through the Umbrella SIG proxy and was blocked by a web policy (such as URL filtering or file inspection).

9
MCQhard

You are troubleshooting an Umbrella SIG tunnel connection. The IPsec tunnel is up, but users report timeouts. What is the most likely cause if the tunnel MTU is not adjusted correctly?

A.MTU mismatch causing packet fragmentation
B.DNS resolution failure in the tunnel
C.Incorrect IKEv2 Phase 2 proposal
D.Missing Proxy PAC file
AnswerA

IPsec adds overhead; if the path MTU is not adjusted, large packets are dropped.

Why this answer

When using SIG tunnels, packet fragmentation can occur if the MTU is not set correctly to account for the IPsec overhead, leading to dropped traffic.

10
MCQeasy

When configuring a SIG tunnel in Umbrella, which protocol is typically used to establish the encrypted connection between the branch office firewall and the Umbrella data center?

A.GRE (Generic Routing Encapsulation)
B.TLS 1.3
C.SSH Tunneling
D.IKEv2/IPsec
AnswerD

IPsec is the standard protocol for SIG site-to-site connectivity.

Why this answer

Umbrella SIG tunnels primarily use IKEv2/IPsec to establish secure connections for traffic redirection.

11
MCQmedium

In Cisco Secure Access, you need to configure a Global Policy to block access to specific cloud applications based on risk levels. Where do you define this logic?

A.Policy > Global Policy > Access Rules
B.Global Settings > Cloud Connectors
C.Connectors > Internet Gateway
D.Devices > Endpoint Profiles
AnswerA

Access Rules define the permit/deny logic for web and cloud destinations.

Why this answer

The Secure Access policy engine uses Access Rules within the Global Policy section to define application-specific restrictions.

12
MCQhard

When migrating from an explicit proxy to the Umbrella SIG, what is the primary challenge for legacy applications?

A.Hardcoded proxy configurations may break
B.The OS must be upgraded
C.The local DNS server will fail
D.The bandwidth requirement increases
AnswerA

Cloud SIG requires specific configurations or auto-proxy support.

Why this answer

Legacy applications often have hardcoded proxy settings or require specific authentication methods that may not be supported by the cloud SIG.

13
MCQeasy

What does the 'Umbrella dashboard' allow you to do regarding DNS security?

A.Provision new ISP links
B.Manage local server hardware
C.Flash router firmware
D.Configure global security policies and view reports
AnswerD

This is the primary function of the management interface.

Why this answer

The dashboard provides centralized management, reporting, and policy enforcement for DNS-based security across an entire organization.

14
MCQhard

You have a branch office with a static IP. You want to secure it without a local virtual appliance. What is the best method?

A.Use a PAC file
B.Use an IP-based Network Identity
C.Use DNS-over-HTTPS
D.Use the Umbrella Roaming Client
AnswerB

Network identities link static public IPs to policies.

Why this answer

Configuring network identity in Umbrella by defining the public IP (Network Identity) allows the gateway to associate traffic with your organization without a tunnel or VA.

15
MCQhard

A user is experiencing 'SSL Certificate Mismatch' errors. You suspect it is caused by the Umbrella proxy. How do you resolve this permanently?

A.Disable SSL decryption in the policy
B.Update the browser
C.Install the Umbrella Root CA certificate on the endpoint
D.Add the domain to the 'Always Allow' list
AnswerC

This builds the necessary trust chain.

Why this answer

The issue stems from the client not trusting the proxy's certificate. Installing the Umbrella Root CA certificate ensures the client validates the proxy as a trusted entity.

16
Multi-Selecthard

Which THREE items are necessary for troubleshooting a failed 'Umbrella AD Connector' sync?

Select 3 answers
A.Logs located on the server running the connector
B.Connector service account permissions
C.The physical server motherboard model
D.Domain Controller accessibility
E.The local printer driver version
AnswersA, B, D

Primary source for troubleshooting sync errors.

Why this answer

Sync issues require checking the connectivity to the DC, the service account permissions, and the logs on the connector server.

17
Multi-Selectmedium

Which TWO features are part of the Cisco Secure Access suite for remote users?

Select 2 answers
A.Physical Router Management
B.Zero Trust Network Access (ZTNA)
C.Wireless Controller provisioning
D.Secure Web Gateway (SWG)
E.Local DHCP Server
AnswersB, D

ZTNA provides secure access to private applications.

Why this answer

Secure Access includes both ZTNA (Zero Trust Network Access) and SWG (Secure Web Gateway) functionality.

18
MCQeasy

What is the primary benefit of the Cisco Umbrella 'Global Network' architecture?

A.It acts as an ISP replacement
B.It eliminates the need for bandwidth
C.It automatically updates the OS
D.It provides low-latency connectivity via Anycast
AnswerD

Anycast routes traffic to the optimal PoP.

Why this answer

The anycast network ensures users connect to the nearest data center, minimizing latency and providing high availability.

19
Multi-Selectmedium

Which TWO pieces of information are required for a 'Network Identity' in Umbrella?

Select 2 answers
A.The internal DHCP server IP
B.The local VLAN ID
C.A friendly name for the location
D.The ISP account number
E.Public IP address
AnswersC, E

Used for reporting labels.

Why this answer

A network identity is defined by the public IP address and a descriptive name to identify the location in reports.

20
MCQhard

You notice that some of your users are bypassing the Umbrella SIG by using a personal VPN. What is the most effective way to prevent this with Cisco products?

A.Block 'Proxy and Filter Avoidance' categories in the Web Policy
B.Install a local firewall on all machines
C.Set the TTL on DNS queries to 0
D.Disable the user's internet
AnswerA

This policy category specifically blocks VPN/proxy tools.

Why this answer

Blocking known VPN/Proxy categories within the Web Policy is the standard way to restrict unauthorized tunnel usage.

21
MCQhard

A user on a corporate laptop is unable to reach a specific SaaS application that is blocked by the Cisco Secure Access SIG. How can you verify the specific rule causing this block?

A.Use the Activity Search tool in the Secure Access dashboard
B.Check the firewall NAT table
C.Run 'nslookup' on the destination
D.Check the local endpoint hosts file
E.Review the Umbrella roaming client logs on the device
AnswerA

This provides granular visibility into policy matches.

Why this answer

The Activity Search tool in the Secure Access dashboard allows administrators to query logs and see the exact policy and rule ID that triggered the block.

22
MCQhard

You are implementing Cisco Secure Access and want to use PAC files for browsers. Where must the PAC file be hosted for automatic proxy configuration?

A.Inside the browser settings directly
B.On the Secure Access cloud gateway
C.On an accessible HTTP/HTTPS web server
D.In the local Windows Registry
AnswerC

The browser fetches the script from a reachable location.

Why this answer

PAC files must be accessible via an HTTP/HTTPS URL, typically hosted on a web server or a managed service provided by the vendor.

23
Multi-Selecteasy

Which TWO conditions must be met for a user to be effectively managed by the Umbrella Roaming Client?

Select 2 answers
A.The organization's policy must be configured in the dashboard
B.The device must have the roaming client installed
C.The device must be on the local LAN
D.The user must be logged in as an administrator
E.The device must be a server
AnswersA, B

Policies determine the agent's behavior.

Why this answer

The client must be installed on the device and the organization must be registered in the dashboard.

24
MCQeasy

Where do you manage the Umbrella Roaming Client deployment configuration?

A.Dashboard > Reporting
B.Dashboard > Policies
C.Dashboard > Settings > API
D.Dashboard > Deployments
AnswerD

Deployments is the centralized location for agents.

Why this answer

The Umbrella dashboard under 'Deployments' allows for the management and download of the Roaming Client installers.

25
MCQmedium

When troubleshooting DNS queries in Umbrella, which command is most useful on a local machine to see if it is using the Umbrella resolvers?

A.ping 8.8.8.8
B.ipconfig /flushdns
C.nslookup debug.opendns.com
D.tracert 208.67.222.222
AnswerC

This is the standard test for Umbrella DNS resolution.

Why this answer

Running 'nslookup debug.opendns.com' confirms if the query is being answered by the Umbrella infrastructure.

26
Multi-Selecteasy

Which THREE types of traffic are typically protected by a SIG?

Select 3 answers
A.Internal VoIP phone calls
B.DNS queries
C.Local printer traffic
D.HTTP/HTTPS web traffic
E.Non-web traffic (e.g., FTP, SSH via tunnels)
AnswersB, D, E

Core functionality of Umbrella.

Why this answer

SIGs protect web (HTTP/S), DNS, and in some models, non-web traffic that is routed through the gateway.

27
MCQmedium

You are setting up cloud network segmentation. In the context of Secure Access, how are groups of resources isolated from each other?

A.By assigning different DNS suffixes
B.By using Access Rules and Policies
C.By physical VLANs
D.By physical cable separation
AnswerB

Policies define the isolation logic between segments.

Why this answer

Security Policies and Access Rules are used to control traffic flows between segments in the cloud environment.

28
MCQmedium

You are integrating Cisco Secure Access with an IdP. What protocol is used to facilitate this authentication?

A.LDAP
B.SNMP
C.SAML 2.0
D.ICMP
AnswerC

SAML is the industry standard for cloud IdP integration.

Why this answer

SAML (Security Assertion Markup Language) is the standard protocol used by Cisco Secure Access for cloud-based identity federation.

29
Multi-Selectmedium

Which THREE actions can be taken in an Umbrella policy based on content categories?

Select 3 answers
A.Block access
B.Warn the user
C.Send an email alert to the user
D.Allow access
E.Encrypt the traffic
AnswersA, B, D

Prevents the user from visiting the site.

Why this answer

Categories can be blocked, allowed, or set to 'Warn', which prompts the user before continuing.

30
MCQmedium

What is the purpose of 'Internal Networks' in the Umbrella dashboard?

A.To cache internal traffic
B.To define user groups
C.To identify traffic from specific office locations
D.To segment internal VLANs
AnswerC

Internal Networks allow per-location policy/reporting.

Why this answer

Internal Networks allow you to group your office egress IP addresses so that policy can be applied specifically to those locations.

31
MCQeasy

You are configuring Cisco Umbrella to protect roaming users. Which component must be installed on the endpoint to ensure consistent policy enforcement when the user is off-VPN?

A.Secure Firewall Management Center
B.Umbrella Virtual Appliance
C.AnyConnect Management VPN Tunnel
D.Cisco Umbrella Roaming Client
AnswerD

The Roaming Client is designed to provide DNS-layer security for off-network endpoints.

Why this answer

The Umbrella Roaming Client is the specific agent required to ensure DNS traffic is intercepted and redirected to Umbrella resolvers for policy application.

32
MCQeasy

Which component is required to enable Active Directory integration with Umbrella for user-level reporting?

A.SAML Provider
B.Umbrella AD Connector
C.Virtual Appliance
D.AnyConnect Agent
E.Cisco Secure Firewall
AnswerB

This maps users/groups to their internal IPs.

Why this answer

The Umbrella AD Connector is the specific software component that syncs AD data to the Umbrella cloud.

33
MCQhard

When deploying the Cisco Secure Access AnyConnect module, what is the primary role of the Umbrella DNS module within it?

A.To intercept and secure DNS queries
B.To manage local network segmentation
C.To authenticate users to the cloud
D.To encrypt traffic payloads
AnswerA

The DNS module provides the DNS-layer security component.

Why this answer

The Umbrella DNS module inside AnyConnect intercepts DNS queries and sends them to Umbrella resolvers for security filtering.

34
MCQmedium

An administrator is configuring Cisco Umbrella for a branch office and needs to ensure that all DNS requests are inspected for malicious domains without requiring a client-side agent. Which configuration approach should the administrator implement?

A.Deploy the Umbrella Virtual Appliance (VA) in a DMZ and configure it for direct Internet access.
B.Enable the 'DNS over HTTPS' feature in the browser settings for all end-user workstations.
C.Establish an IPsec tunnel from the branch edge router to the Umbrella data center.
D.Configure a PAC file on each endpoint to route traffic to the Umbrella Roaming Client.
AnswerC

Creating an IPsec tunnel at the network level ensures all DNS traffic is securely forwarded and inspected.

Why this answer

Network tunnels, such as IPsec or GRE, are used to forward DNS traffic from network devices to Umbrella, providing protection for all devices on the network without agents.

35
MCQmedium

An organization is migrating to a Secure Internet Gateway (SIG) architecture. They currently have an on-premises firewall blocking all traffic except for specific ports. What is the recommended method to forward traffic to the SIG while maintaining existing security policy consistency?

A.Configure an IPsec tunnel from the firewall to the Cisco SIG headend.
B.Configure port forwarding for all traffic on the firewall to an external DNS proxy.
C.Disable the existing firewall to prevent conflicts with the SIG cloud services.
D.Replace the existing firewall with an Umbrella Roaming Client.
AnswerA

IPsec tunnels are the standard way to backhaul traffic to the SIG for unified security policy enforcement.

Why this answer

Using an IPsec tunnel ensures that the traffic is encrypted and consistently tagged for the SIG to apply the appropriate security policies.

36
Multi-Selecthard

Which TWO logging methods can be used to export Umbrella logs for SIEM analysis?

Select 2 answers
A.Direct API integration for SIEM
B.Export logs to an Amazon S3 bucket
C.Logging to the local printer
D.Sending logs via email
E.Local disk logging on the user endpoint
AnswersA, B

Automates log ingestion for security platforms.

Why this answer

Umbrella supports log exports via S3 buckets or direct API integration with SIEM platforms.

37
MCQmedium

Which component is required to allow Umbrella to perform SSL decryption on web traffic?

A.DNS-over-HTTPS setup
B.VPN client configuration
C.Public IP whitelisting
D.Deployment of the Umbrella Root CA
AnswerD

Trusting the Root CA is mandatory for man-in-the-middle decryption.

Why this answer

To perform SSL decryption, the Umbrella Root CA certificate must be installed on all client endpoints to prevent browser certificate warnings.

38
MCQmedium

When using Umbrella's 'Selective Proxy', how is the determination made to route traffic through the proxy vs. direct to destination?

A.Based on the domain categorization
B.Based on the packet source IP
C.Based on the browser type
D.Based on the time of day
AnswerA

Risky domains are proxied, safe ones are passed through.

Why this answer

The Selective Proxy uses a list of domains (like those known to host malware) to decide whether to route traffic through the proxy for deep inspection.

39
Multi-Selecthard

Which TWO methods can be used to identify internal clients in Cisco Umbrella reports?

Select 2 answers
A.Umbrella Virtual Appliance (VA)
B.DHCP relay settings
C.Umbrella Roaming Client
D.Public IP address of the ISP
E.DNS-over-HTTPS
AnswersA, C

VAs report the internal IP to the Umbrella dashboard.

Why this answer

Internal clients are identified by either the local IP address (via VA) or the Roaming Client ID.

40
MCQhard

You have a requirement to perform 'File Analysis' on downloads. Which Umbrella product component must be enabled?

A.Roaming Client
B.DNS-layer security
C.Umbrella SIG
D.Virtual Appliance
AnswerC

SIG allows for file inspection and malware sandboxing.

Why this answer

File Analysis requires the Umbrella SIG (Secure Internet Gateway) with the Cisco Talos malware inspection engine enabled.

41
Multi-Selecthard

Which TWO settings must be correctly configured to ensure that Cisco Secure Access provides effective decryption and inspection of HTTPS traffic?

Select 2 answers
A.Set the DNS server to the ISP's DNS resolver.
B.Install the Cisco Secure Access Root Certificate on all client devices.
C.Enable 'SSL Inspection' within the specific Web Policy rules.
D.Disable all firewall rules on the local machine.
E.Configure the browser to use a specific proxy server IP.
AnswersB, C

Endpoints must trust the proxy certificate to avoid SSL warnings.

Why this answer

HTTPS inspection requires the deployment of a root CA to endpoints and the configuration of inspection rules in the policy.

42
Multi-Selecteasy

Which TWO of the following are primary benefits of Cisco Umbrella DNS-layer security?

Select 2 answers
A.Requires manual firewall updates
B.Uses a cloud-native architecture
C.Requires a physical appliance at every site
D.Only works on corporate-managed devices
E.Blocks threats before a connection is established
AnswersB, E

Umbrella is a cloud-native SaaS solution.

Why this answer

DNS-layer security blocks threats before connection occurs and requires no additional hardware.

43
MCQhard

You are troubleshooting a scenario where users are unable to access a specific internal cloud resource after migrating to Cisco Secure Access. The traffic is being blocked by a default policy. How should you modify the traffic flow to ensure internal traffic stays off the SIG?

A.Configure a Tunnel Exclusion in the Secure Access tunnel settings for the internal IP ranges.
B.Disable the 'Inspect Traffic' setting globally in the Secure Access dashboard.
C.Update the DNS policy to include internal domain suffixes as exceptions.
D.Assign the users to a separate Group Policy that has no web filtering enabled.
AnswerA

Tunnel exclusions allow specific traffic to bypass the SIG, ensuring internal resources remain reachable.

Why this answer

Configuring a PAC file or using Tunnel Exclusions ensures that traffic destined for internal ranges bypasses the SIG tunnel.

44
MCQmedium

You want to ensure that users are warned before visiting a newly registered domain. Which feature in Cisco Umbrella handles this?

A.Application Settings
B.Security Settings
C.Platform Logs
D.Web Policy Categories
AnswerB

Newly registered domains are a security category.

Why this answer

Newly registered domains are a security category in Umbrella that can be blocked or warned to prevent users from accessing potentially malicious sites.

45
MCQeasy

What is the role of a 'Policy' in Cisco Umbrella?

A.To configure hardware settings
B.To monitor bandwidth usage
C.To manage API credentials
D.To define security and filtering rules for identities
AnswerD

Policies are the core logic of the Umbrella platform.

Why this answer

A policy defines the set of rules (security, content, application control) applied to specific identities (users, networks, roaming clients).

46
Multi-Selectmedium

Which THREE items are considered primary components of the Cisco Umbrella 'Identity' structure when creating security policies?

Select 3 answers
A.Roaming Computer
B.Network (IP-based)
C.MAC Address of the Printer
D.Active Directory User/Group
E.Public Cloud Instance ID
AnswersA, B, D

Endpoints with the roaming client are a primary identity type.

Why this answer

Umbrella policies are applied based on identities, which include networks, roaming computers, and Active Directory objects.

47
MCQmedium

Which method is the most secure way to authenticate users for Cisco Secure Access?

A.Local user accounts
B.SAML 2.0 integration with an IdP
C.Using the default admin account
D.Static IP-based authentication
AnswerB

SAML is the recommended standard for enterprise identity.

Why this answer

Integrating with an IdP via SAML ensures multi-factor authentication and centralized lifecycle management.

48
MCQeasy

In Cisco Umbrella, which component is used to associate internal IP addresses with Active Directory user identities for granular policy reporting?

A.Umbrella Virtual Appliance
B.Cisco Secure Endpoint
C.AnyConnect Management Tunnel
D.Umbrella Roaming Client
AnswerA

Virtual Appliances identify users by querying AD and reporting the IP-to-user mapping to Umbrella.

Why this answer

The Umbrella Virtual Appliance (VA) facilitates the mapping of internal IP addresses to AD users and groups.

49
MCQmedium

In Secure Access, how are 'Traffic Forwarding' profiles used?

A.To set up load balancing
B.To encrypt cloud storage
C.To define user roles
D.To define how traffic is routed to the cloud gateway
AnswerD

Forwarding profiles manage the tunnel/proxy steering.

Why this answer

Traffic Forwarding profiles define which traffic (web, non-web, specific ports) should be sent to the Secure Access cloud.

50
MCQeasy

What is the function of an Umbrella 'Integrations' key?

A.To sign digital certificates
B.To automate API-based policy and log management
C.To encrypt DNS queries
D.To identify roaming clients
AnswerB

API keys allow external tools to interact with Umbrella.

Why this answer

API keys are used to integrate Umbrella with other systems like SIEMs or threat intelligence platforms to automate policy updates.

51
MCQhard

You are implementing Cisco Secure Access and need to configure a Global Policy that restricts access to unsanctioned SaaS applications based on their risk score. Where should this policy be applied in the Secure Access dashboard?

A.Under Policy > Network Policies > DNS Policy
B.Under Settings > Device Management > SaaS Controls
C.Under Connect > Network > Cloud Firewalls
D.Under Policy > Access Policies > Web Policy > CASB
AnswerD

The CASB section within Web Policies is the designated location for controlling SaaS app access via risk scoring.

Why this answer

Cloud Access Security Broker (CASB) settings within the Secure Access portal allow for application risk scoring and policy enforcement.

52
MCQeasy

Which report in Cisco Umbrella provides the most direct view of security threats identified in your environment?

A.Top Identities
B.Application Usage
C.Security Activity
D.Web Activity
AnswerC

This is the primary report for threat analysis.

Why this answer

The Security Activity report details all blocked threats, including malware, phishing, and command-and-control attempts.

53
MCQmedium

You need to ensure that all web traffic from a branch office is inspected by the Umbrella SIG. Which configuration step is mandatory on your perimeter router?

A.Install the Roaming Client on the router
B.Create a PBR (Policy Based Routing) to direct traffic to the tunnel
C.Define an ACL to permit all traffic to Umbrella
D.Enable DNS-over-HTTPS on the router
AnswerB

PBR is used to divert specific traffic into the tunnel interface.

Why this answer

The router must be configured to route traffic destined for the internet through the tunnel interface pointing to the Umbrella data center.

54
MCQmedium

A company wants to prevent users from bypassing security policies by using unauthorized VPNs or proxies. Which feature in Cisco Umbrella should be enabled to mitigate this risk?

A.Deploy the Cisco Secure Endpoint agent to detect unauthorized VPN software.
B.Enable the 'Web Proxy' feature in the Global Settings.
C.Select the 'Proxy and VPN' category within the Destination Lists of the Web Policy.
D.Configure an SSL Inspection rule for all traffic.
AnswerC

Categorization allows for the blocking of known VPN and proxy services used to circumvent policies.

Why this answer

The 'Proxy and VPN' category in the Umbrella destination lists allows administrators to block access to services that can bypass security filters.

55
Multi-Selectmedium

Which THREE actions are required when configuring a new IPsec tunnel for the Cisco SIG (Secure Internet Gateway)?

Select 3 answers
A.Install a client-side agent on every endpoint behind the router.
B.Enable the 'AnyConnect Tunnel' feature on the device.
C.Configure the local firewall with the correct Cisco SIG headend IP address.
D.Configure IKEv2 proposal settings on the local edge device.
E.Define the tunnel endpoint IP address in the Umbrella dashboard.
AnswersC, D, E

The router must know where to send the tunneled traffic.

Why this answer

Configuring an IPsec tunnel requires defining the tunnel details, the IKEv2 settings, and the specific traffic selectors or identity management.

56
MCQeasy

Which Cisco Umbrella report provides the most granular visibility into the specific security categories triggered by user traffic?

A.Total Requests Report
B.Activity Search Report
C.Security Overview Report
D.Destination List Report
AnswerB

Activity Search offers the most granular data regarding policy hits and category blocks.

Why this answer

The 'Activity Search' report allows administrators to filter by category, identity, and destination to identify specific security violations.

57
MCQeasy

What is the main advantage of using a Secure Internet Gateway (SIG) over a traditional on-premises firewall?

A.Lower bandwidth costs
B.Consistent protection for off-network users
C.Faster internal LAN speed
D.Elimination of the need for DNS
AnswerB

SIG extends the security perimeter to wherever the user is.

Why this answer

A SIG provides security for users regardless of their location, unlike an on-premises firewall which only protects the office network.

58
MCQhard

You are seeing 'SSL Inspection Error' in your logs. What is the most likely cause?

A.The Umbrella Root CA is not trusted on the client
B.The destination server is down
C.The policy is set to 'Allow'
D.The tunnel is disconnected
AnswerA

Without the CA, the browser detects a MITM attack.

Why this answer

SSL inspection errors typically occur when the client cannot validate the certificate presented by the proxy, often due to the missing Root CA.

59
Multi-Selecteasy

Which THREE factors are evaluated by the Umbrella policy engine when processing a DNS request?

Select 3 answers
A.The local browser version
B.The color of the hardware
C.The time of the request
D.The identity of the user or device
E.The destination of the request
AnswersC, D, E

Time-based rules are supported in Umbrella policies.

Why this answer

Policies are based on identities (who), destination categories (where), and security settings (what).

Ready to test yourself?

Try a timed practice session using only Network And Cloud Security questions.