Dependable 350-701 Exam Dumps to Become Cisco Certified [Q411-Q431]

Share

Dependable 350-701 Exam Dumps to Become Cisco Certified

Get Ready with 350-701 Exam Dumps (2026)

NEW QUESTION # 411
A Cisco Secure Cloud Analytics administrator is setting up a private network monitor sensor to monitor an on- premises environment. Which two pieces of information from the sensor are used to link to the Secure Cloud Analytics portal? (Choose two.)

  • A. NAT ID
  • B. Private IP address
  • C. Unique service key
  • D. SSL certificate
  • E. Public IP address

Answer: A,C


NEW QUESTION # 412
Which policy is used to capture host information on the Cisco Firepower Next Generation Intrusion Prevention System?

  • A. Intrusion
  • B. Correlation
  • C. Network Discovery
  • D. Access Control

Answer: C

Explanation:
The Firepower System uses network discovery and identity policies to collect host, application, and user data for traffic on your network. You can use certain types of discovery and identity data to build a comprehensive map of your network assets, perform forensic analysis, behavioral profiling, access control, and mitigate and respond to the vulnerabilities and exploits to which your organization is susceptible.
You can configure your network discovery policy to perform host and application detection.


NEW QUESTION # 413
Drag and drop the steps from the left into the correct order on the right to enable AppDynamics to monitor an EC2 instance in Amazon Web Services.

Answer:

Explanation:


NEW QUESTION # 414
Which parameter is required when configuring a Netflow exporter on a Cisco Router?

  • A. Source interface
  • B. DSCP value
  • C. Exporter description
  • D. Exporter name

Answer: D

Explanation:
Explanation
An example of configuring a NetFlow exporter is shown below:
flow exporter Exporter
destination 192.168.100.22
transport udp 2055


NEW QUESTION # 415
Which characteristic is unique to a Cisco WSAv as compared to a physical appliance?

  • A. supports VMware vMotion on VMware ESXi
  • B. requires an additional license
  • C. performs transparent redirection
  • D. supports SSL decryption

Answer: A


NEW QUESTION # 416
Which two capabilities of Integration APIs are utilized with Cisco DNA center? (Choose two)

  • A. Third party reporting
  • B. Create new SSIDs on a wireless LAN controller
  • C. Automatically deploy new virtual routers
  • D. Upgrade software on switches and routers
  • E. Connect to ITSM platforms

Answer: A,E

Explanation:
Reference:
https://developer.cisco.com/docs/dna-center/#!cisco-dna-center-platform-overview/integration-api-westbound


NEW QUESTION # 417
What is the function of SDN southbound API protocols?

  • A. to enable the controller to use REST
  • B. to allow for the dynamic configuration of control plane applications
  • C. to enable the controller to make changes
  • D. to allow for the static configuration of control plane applications

Answer: C

Explanation:
Explanation Explanation Southbound APIs enable SDN controllers to dynamically make changes based on real-time demands and scalability needs. Reference: https://www.ciscopress.com/articles/article.asp?p=3004581&seqNum=2 Explanation Southbound APIs enable SDN controllers to dynamically make changes based on real-time demands and scalability needs.
Explanation Explanation Southbound APIs enable SDN controllers to dynamically make changes based on real-time demands and scalability needs. Reference: https://www.ciscopress.com/articles/article.asp?p=3004581&seqNum=2

Note: Southbound APIs helps us communicate with data plane (not control plane) applications


NEW QUESTION # 418
A network administrator is configuring a role in an access control policy to block certain URLs and selects the
"Chat and instant Messaging" category. which reputation score should be selected to accomplish this goal?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: D

Explanation:
To block certain URLs based on the "Chat and Instant Messaging" category, the network administrator should select a reputation score of 5. A reputation score is a numerical value that indicates the likelihood of a URL being malicious or unwanted. The lower the score, the higher the risk. A score of 5 means that the URL is suspicious or potentially harmful, and should be blocked or inspected12. A score of 3 means that the URL is unknown or unverified, and may be allowed or blocked depending on the policy settings12. A score of 10 means that the URL is trustworthy or benign, and should be allowed12. A score of 1 means that the URL is malicious or high-risk, and should be blocked12. Therefore, a score of 5 is the most appropriate to block the
"Chat and Instant Messaging" category, which may contain unwanted or problematic websites. References:
* Reputation score, section "Reputation score".
* Web content filtering, section "What is web content filtering?".


NEW QUESTION # 419
What are two workloaded security models? (Choose two)

  • A. off-premises
  • B. IaaS
  • C. SaaS
  • D. PaaS
  • E. on-premises

Answer: B,E

Explanation:
Workloaded security models are ways of protecting applications, services, and capabilities that run on a cloud resource. Virtual machines, databases, containers, and applications are all considered cloud workloads. There are different types of cloud deployment models, such as public, private, hybrid, and multicloud. Depending on the deployment model, the cloud workload security can vary in terms of responsibility, visibility, and control.
Infrastructure as a service (IaaS) is a cloud deployment model where the cloud provider offers the basic computing infrastructure, such as servers, storage, and networking, as a service. The customer is responsible for installing, configuring, and managing the operating systems, applications, and security of the workloads that run on the cloud infrastructure. IaaS provides the customer with more flexibility and control over the workload security, but also more complexity and overhead.
On-premises is a deployment model where the customer owns and operates the entire IT infrastructure, including the hardware, software, and security. The customer has full responsibility and control over the workload security, but also the highest cost and maintenance. On-premises deployment can offer more security and compliance than cloud deployment, depending on the customer's security posture and practices.
https://www.cisco.com/site/us/en/products/security/secure-workload/index.html
https://www.checkpoint.com/cyber-hub/cloud-security/what-is-cloud-workload-security/


NEW QUESTION # 420
Which technology reduces data loss by identifying sensitive information stored in public computing environments?

  • A. Cisco HyperFlex
  • B. Cisco Cloudlock
  • C. Cisco SDA
  • D. Cisco Firepower

Answer: B


NEW QUESTION # 421
Which two fields are defined in the NetFlow flow? {Choose two.)

  • A. output logical interface
  • B. class of service bits
  • C. destination port
  • D. type of service byte
  • E. Layer 4 protocol type

Answer: C,D

Explanation:


NEW QUESTION # 422
Which solution is more secure than the traditional use of a username and password and encompasses at least two of the methods of authentication?

  • A. Kerberos security solution
  • B. multifactor authentication
  • C. RADIUS/LDAP authentication
  • D. single-sign on

Answer: B

Explanation:
Multifactor authentication (MFA) is a solution that requires the user to provide two or more verification factors to gain access to a resource, such as an application, online account, or a VPN. MFA is more secure than the traditional use of a username and password because it reduces the risk of identity theft, phishing, and credential compromise. MFA can use different types of factors, such as something the user knows (e.g., password, PIN), something the user has (e.g., smartphone, token, smart card), or something the user is (e.g., fingerprint, facial recognition). MFA can be implemented using various methods, such as security defaults, Conditional Access policies, or third-party solutions123. References:
https://support.microsoft.com/en-us/topic/what-is-multifactor-authentication-e5e39437-121c-be60-d123- eda06bddf661
https://www.onelogin.com/learn/what-is-mfa


NEW QUESTION # 423
What are two DDoS attack categories? (Choose two)

  • A. sequential
  • B. database
  • C. volume-based
  • D. screen-based
  • E. protocol

Answer: C,E

Explanation:
Explanation Explanation There are three basic categories of attack: + volume-based attacks, which use high traffic to inundate the network bandwidth + protocol attacks, which focus on exploiting server resources + application attacks, which focus on web applications and are considered the most sophisticated and serious type of attacks Reference: https://www.esecurityplanet.com/networks/types-of-ddos-attacks/ Explanation There are three basic categories of attack:
+ volume-based attacks, which use high traffic to inundate the network bandwidth
+ protocol attacks, which focus on exploiting server resources
Explanation Explanation There are three basic categories of attack: + volume-based attacks, which use high traffic to inundate the network bandwidth + protocol attacks, which focus on exploiting server resources + application attacks, which focus on web applications and are considered the most sophisticated and serious type of attacks Reference: https://www.esecurityplanet.com/networks/types-of-ddos-attacks/


NEW QUESTION # 424
Refer to the exhibit.

What is the result of this Python script of the Cisco DNA Center API?

  • A. receives information about a switch
  • B. adds authentication to a switch
  • C. adds a switch to Cisco DNA Center

Answer: C


NEW QUESTION # 425
An organization has a Cisco ESA set up with policies and would like to customize the action assigned for violations. The organization wants a copy of the message to be delivered with a message added to flag it as a DLP violation. Which actions must be performed in order to provide this capability?

  • A. deliver and send copies to other recipients
  • B. deliver and add disclaimer text
  • C. quarantine and alter the subject header with a DLP violation
  • D. quarantine and send a DLP violation notification

Answer: B

Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/esa/esa12-0/user_guide/b_ESA_Admin_Guide_12_0/b_ESA_Ad


NEW QUESTION # 426
Drag and drop the common security threats from the left onto the definitions on the right.

Answer:

Explanation:


NEW QUESTION # 427
What two mechanisms are used to redirect users to a web portal to authenticate to ISE for guest services? (Choose two.)

  • A. local web auth
  • B. TACACS+
  • C. single sign-on
  • D. multiple factor auth
  • E. central web auth

Answer: A,E


NEW QUESTION # 428

Refer to the exhibit. What is the result of the Python script?

  • A. It uses the POST HTTP method to obtain a token to be used for authentication.
  • B. It uses the GET HTTP method to obtain a username and password to be used for authentication
  • C. It uses the POST HTTP method to obtain a username and password to be used for authentication.
  • D. It uses the GET HTTP method to obtain a token to be used for authentication.

Answer: A

Explanation:
The Python script is using the dnac_login function to authenticate to a Cisco DNA Center server and obtain a token that can be used for subsequent API calls. The function takes three parameters: host, username, and password. It constructs a URL for the authentication endpoint, which is https://{}/api/system/v1/auth/token. It then uses the requests library to send a POST HTTP request to the URL, passing the username and password as HTTP Basic Authentication credentials, and setting the headers to indicate the expected content type and response format. The function also disables the SSL verification by setting the verify parameter to False. This is not recommended for production environments, as it exposes the script to potential security risks. The function then returns the token value from the JSON response, which is accessed by using the response.json()["Token"] syntax. The token can then be used as a bearer token for subsequent API calls to the Cisco DNA Center server. References:
* Implementing and Operating Cisco Security Core Technologies (SCOR) v1.0, Module 9: Content Security, Lesson 9.3: Cisco DNA Center APIs
* Cisco DNA Center Platform API Reference, Authentication API
* Refer to the exhibit. What will happen when the Python script is executed?


NEW QUESTION # 429
Drag and drop the NetFlow export formats from the left onto the descriptions on the right.

Answer:

Explanation:


NEW QUESTION # 430
Drag and drop the cloud security assessment components from the left onto the definitions on the right.

Answer:

Explanation:


NEW QUESTION # 431
......

Download Exam 350-701 Practice Test Questions with 100% Verified Answers: https://braindumps.actual4exams.com/350-701-real-braindumps.html