Pre-Winter Sale - Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70dumps

350-701 Questions and Answers

Question # 6

Which two risks is a company vulnerable to if it does not have a well-established patching solution for

endpoints? (Choose two)

A.

exploits

B.

ARP spoofing

C.

denial-of-service attacks

D.

malware

E.

eavesdropping

Full Access
Question # 7

Which algorithm provides asymmetric encryption?

A.

RC4

B.

AES

C.

RSA

D.

3DES

Full Access
Question # 8

Where are individual sites specified to be block listed in Cisco Umbrella?

A.

Application settings

B.

Security settings

C.

Destination lists

D.

Content categories

Full Access
Question # 9

An administrator configures a new destination list in Cisco Umbrella so that the organization can block specific domains for its devices. What should be done to ensure that all subdomains of domain.com are blocked?

A.

Configure the *.com address in the block list.

B.

Configure the *.domain.com address in the block list

C.

Configure the *.domain.com address in the block list

D.

Configure the domain.com address in the block list

Full Access
Question # 10

Refer to the exhibit.

aaa new-model

aaa authentication dot1x default group ISE-SERVERS

aaa authorization network default group ISE-SERVERS

aaa accounting dot1x default start-stop group ISE-SERVERS

!

radius server RADIUS_SRV

address ipv4 172.16.10.12 auth-port 1812 acct-port 1813

key shared-secret C1sc0123

!

aaa group server radius ISE-SERVERS

server name RADIUS_SRV

radius-server vsa send authentication

radius-server vsa send accounting

radius-server attribute 6 on-for-login-auth

radius-server attribute 8 include-in-access-req

radius-server attribute 25 access-request include

ip device tracking

!

interface range GigabitEthernet1/0/1 - 48

switchport

switchport host

authentication priority dot1x mab

authentication order dot1x mab

A security engineer is integrating a new Cisco Catalyst access switch with Cisco ISE to enforce port-based network access control using 802.1X. The AAA RADIUS server group and access interfaces are configured on the Cisco Catalyst switch. Cisco ISE has authentication and authorization policies, the workstation supplicants are configured as expected, and connectivity between the switch and ISE is working. During testing, the workstations fail to trigger authentication sessions, and no RADIUS requests appear in the ISE logs or on the switch interfaces. Which two configuration commands must be added to the Cisco Catalyst switch? (Choose two.)

A.

Configure the dot1x system-auth-control command globally.

B.

Implement the aaa server radius dynamic-author command globally.

C.

Apply the dot1x pae authenticator command under interfaces that require 802.1X.

D.

Configure the ip radius source-interface command globally.

E.

Add the mab command under all switch interfaces.

Full Access
Question # 11

Which process is used to obtain a certificate from a CA?

A.

Registration

B.

Enrollment

C.

Signing

D.

Approval

Full Access
Question # 12

What is a difference between weak passwords and missing encryption?

A.

Weak passwords allow programs to be renamed, and missing encryption hides .exe extensions.

B.

Weak passwords cause programs to crash, and missing encryption sends data to a memory location.

C.

Weak passwords consume bandwidth, and missing encryption allows user information to be hijacked.

D.

Weak passwords are guessed easily, and missing encryption allows information to be decrypted.

Full Access
Question # 13

Which problem Is solved by deploying a multicontext firewall?

A.

overlapping IP addressing plan

B.

more secure policy

C.

resilient high availability design

D.

faster inspection

Full Access
Question # 14

An engineer needs to configure an access control policy rule to always send traffic for inspection without

using the default action. Which action should be configured for this rule?

A.

monitor

B.

allow

C.

block

D.

trust

Full Access
Question # 15

An engineer is configuring their router to send NetfFow data to Stealthwatch which has an IP address of 1 1 11 using the flow record Stea!thwatch406397954 command Which additional command is required to complete the flow record?

A.

transport udp 2055

B.

match ipv4 ttl

C.

cache timeout active 60

D.

destination 1.1.1.1

Full Access
Question # 16

Which two fields are defined in the NetFlow flow? (Choose two)

A.

type of service byte

B.

class of service bits

C.

Layer 4 protocol type

D.

destination port

E.

output logical interface

Full Access
Question # 17

Which solution supports high availability in routed or transparent mode as well as in northbound and

southbound deployments?

A.

Cisco FTD with Cisco ASDM

B.

Cisco FTD with Cisco FMC

C.

Cisco Firepower NGFW physical appliance with Cisco. FMC

D.

Cisco Firepower NGFW Virtual appliance with Cisco FMC

Full Access
Question # 18

Which feature requires a network discovery policy on the Cisco Firepower Next Generation Intrusion Prevention

System?

A.

Security Intelligence

B.

Impact Flags

C.

Health Monitoring

D.

URL Filtering

Full Access
Question # 19

Which function is included when Cisco AMP is added to web security?

A.

multifactor, authentication-based user identity

B.

detailed analytics of the unknown file ' s behavior

C.

phishing detection on emails

D.

threat prevention on an infected endpoint

Full Access
Question # 20

What are two characteristics of Cisco Catalyst Center APIs? (Choose two.)

A.

Postman is required to utilize Cisco Catalyst Center API calls.

B.

They are Cisco proprietary.

C.

They do not support Python scripts.

D.

They view the overall health of the network.

E.

They quickly provision new devices.

Full Access
Question # 21

How does DNS Tunneling exfiltrate data?

A.

An attacker registers a domain that a client connects to based on DNS records and sends malware throughthat connection.

B.

An attacker opens a reverse DNS shell to get into the client’s system and install malware on it.

C.

An attacker uses a non-standard DNS port to gain access to the organization’s DNS servers in order topoison the resolutions.

D.

An attacker sends an email to the target with hidden DNS resolvers in it to redirect them to a maliciousdomain.

Full Access
Question # 22

Which open standard creates a framework for sharing threat intelligence in a machine-digestible format?

A.

OpenC2

B.

OpenlOC

C.

CybOX

D.

STIX

Full Access
Question # 23

Which Cisco AMP feature allows an engineer to look back to trace past activities, such as file and process activity on an endpoint?

A.

Retrospective security

B.

Endpoint isolation

C.

Advanced investigation

D.

Advanced search

Full Access
Question # 24

What is a benefit of using Cisco AVC (Application Visibility and Control) for application control?

A.

management of application sessions

B.

retrospective application analysis

C.

zero-trust approach

D.

dynamic application scanning

Full Access
Question # 25

An administrator is establishing a new site-to-site VPN connection on a Cisco IOS router. The organization

needs to ensure that the ISAKMP key on the hub is used only for terminating traffic from the IP address of

172.19.20.24. Which command on the hub will allow the administrator to accomplish this?

A.

crypto ca identity 172.19.20.24

B.

crypto isakmp key Cisco0123456789 172.19.20.24

C.

crypto enrollment peer address 172.19.20.24

D.

crypto isakmp identity address 172.19.20.24

Full Access
Question # 26

What causes alert fatigue in Cisco XDR?

A.

Alerts lacking sufficient context to be accurate

B.

Reauthentication of an active endpoint during a vulnerability incident

C.

Notifications from too few devices in a data-breach event

D.

Automatic policy enforcement during a suspicious event

Full Access
Question # 27

An organization is implementing URL blocking using Cisco Umbrella. The users are able to go to some sites but other sites are not accessible due to an error. Why is the error occurring?

A.

Client computers do not have the Cisco Umbrella Root CA certificate installed.

B.

IP-Layer Enforcement is not configured.

C.

Intelligent proxy and SSL decryption is disabled in the policy.

D.

Client computers do not have an SSL certificate deployed from an internal CA server.

Full Access
Question # 28

An engineer notices traffic interruption on the network. Upon further investigation, it is learned that broadcast

packets have been flooding the network. What must be configured, based on a predefined threshold, to

address this issue?

A.

Bridge Protocol Data Unit guard

B.

embedded event monitoring

C.

storm control

D.

access control lists

Full Access
Question # 29

What are two functions of TAXII in threat intelligence sharing? (Choose two.)

A.

determines the " what " of threat intelligence

B.

Supports STIX information

C.

allows users to describe threat motivations and abilities

D.

exchanges trusted anomaly intelligence information

E.

determines how threat intelligence information is relayed

Full Access
Question # 30

Which protocol does Cisco Duo use to transport authentication assertions for single sign-on?

A.

SCEP

B.

SAML

C.

SCP

D.

EAP

Full Access
Question # 31

What are two functions of secret key cryptography? (Choose two)

A.

key selection without integer factorization

B.

utilization of different keys for encryption and decryption

C.

utilization of large prime number iterations

D.

provides the capability to only know the key on one side

E.

utilization of less memory

Full Access
Question # 32

A Cisco Secure Email Gateway network administrator has been tasked to use a newly installed service to help create policy based on the reputation verdict. During testing, it is discovered that the Secure Email Gateway is not dropping files that have an undetermined verdict. What is causing this issue?

A.

The file has a reputation score that is below the threshold.

B.

The file has a reputation score that is above the threshold.

C.

The policy was created to disable file analysis.

D.

The policy was created to send a message to quarantine instead of drop.

Full Access
Question # 33

Drag and drop the NetFlow export formats from the left onto the descriptions on the right.

Question # 33

Full Access
Question # 34

When a Cisco Secure Web Appliance checks a web request, what occurs if it is unable to match a user-defined policy?

A.

It applies the next identification profile policy.

B.

It applies the advanced policy.

C.

It applies the global policy.

D.

It blocks the request.

Full Access
Question # 35

Which capability allows an administrator to configure forensics rules in Cisco Secure Workload?

A.

Custom clauses

B.

MITRE ATT & CK framework only predefined

C.

Cisco Secure Workload predefined

D.

Windows or Linux application

Full Access
Question # 36

How does the Cisco WSA enforce bandwidth restrictions for web applications?

A.

It implements a policy route to redirect application traffic to a lower-bandwidth link.

B.

It dynamically creates a scavenger class QoS policy and applies it to each client that connects through the WSA.

C.

It sends commands to the uplink router to apply traffic policing to the application traffic.

D.

It simulates a slower link by introducing latency into application traffic.

Full Access
Question # 37

An engineer must deploy a Cisco Secure Web Appliance. Antimalware scanning must use the Outbreak Heuristics antimalware category on files identified as malware before performing any other processes. What must be configured on the Secure Web Appliance to meet the requirements?

A.

Sophos scanning engine

B.

Webroot scanning engine

C.

McAfee scanning engine

D.

Adaptive Scanning

Full Access
Question # 38

What can be integrated with Cisco Threat Intelligence Director to provide information about security threats,

which allows the SOC to proactively automate responses to those threats?

A.

Cisco Umbrella

B.

External Threat Feeds

C.

Cisco Threat Grid

D.

Cisco Stealthwatch

Full Access
Question # 39

A security administrator is designing an email protection solution for an onsite email server and must meet these requirements:

Remove malware from email before it reaches corporate premises

Drop emails with risky links automatically

Block access to newly infected sites with real-time URL analysis

Which solution must be used?

A.

Cisco Secure Email Cloud

B.

Cisco Security for Office 365

C.

Cisco Stealthwatch Cloud

D.

Cisco Secure Email and Web Manager Cloud

Full Access
Question # 40

A network administrator needs to find out what assets currently exist on the network. Third-party systems need to be able to feed host data into Cisco Firepower. What must be configured to accomplish this?

A.

a Network Discovery policy to receive data from the host

B.

a Threat Intelligence policy to download the data from the host

C.

a File Analysis policy to send file data into Cisco Firepower

D.

a Network Analysis policy to receive NetFlow data from the host

Full Access
Question # 41

Which Cisco solution does Cisco Umbrella integrate with to determine if a URL is malicious?

A.

AMP

B.

AnyConnect

C.

DynDNS

D.

Talos

Full Access
Question # 42

What are two workloaded security models? (Choose two)

A.

SaaS

B.

IaaS

C.

on-premises

D.

off-premises

E.

PaaS

Full Access
Question # 43

Where are individual sites specified to be blacklisted in Cisco Umbrella?

A.

application settings

B.

content categories

C.

security settings

D.

destination lists

Full Access
Question # 44

In which two ways does a system administrator send web traffic transparently to the Web Security Appliance?

(Choose two)

A.

configure Active Directory Group Policies to push proxy settings

B.

configure policy-based routing on the network infrastructure

C.

reference a Proxy Auto Config file

D.

configure the proxy IP address in the web-browser settings

E.

use Web Cache Communication Protocol

Full Access
Question # 45

Refer to the exhibit.

Question # 45

An engineer configured wired 802.1x on the network and is unable to get a laptop to authenticate. Which port configuration is missing?

A.

authentication open

B.

dotlx reauthentication

C.

cisp enable

D.

dot1x pae authenticator

Full Access
Question # 46

What is the difference between deceptive phishing and spear phishing?

A.

Deceptive phishing is an attack aimed at a specific user in the organization who holds a C-level role.

B.

A spear phishing campaign is aimed at a specific person versus a group of people.

C.

Spear phishing is when the attack is aimed at the C-level executives of an organization.

D.

Deceptive phishing hijacks and manipulates the DNS server of the victim and redirects the user to a false webpage.

Full Access
Question # 47

Which baseline form of telemetry is recommended for network infrastructure devices?

A.

SDNS

B.

NetFlow

C.

passive taps

D.

SNMP

Full Access
Question # 48

A user has a device in the network that is receiving too many connection requests from multiple machines.

Which type of attack is the device undergoing?

A.

phishing

B.

slowloris

C.

pharming

D.

SYN flood

Full Access
Question # 49

Which cloud model is a collaborative effort where infrastructure is shared and jointly accessed by several organizations from a specific group?

A.

Hybrid

B.

Community

C.

Private

D.

Public

Full Access
Question # 50

Which Cisco platform provides an agentless solution to provide visibility across the network including encrypted traffic analytics to detect malware in encrypted traffic without the need for decryption?

A.

Cisco Advanced Malware Protection

B.

Cisco Stealthwatch

C.

Cisco Identity Services Engine

D.

Cisco AnyConnect

Full Access
Question # 51

A network engineer must distribute an operating system image to a network device and activate the image on that device by using the Cisco Catalyst Center API. Which two API requests perform the required operations? (Choose two.)

A.

POST /dna/intent/api/v1/image/distribution

B.

POST /dna/intent/api/v1/onboarding/pnp-device/import

C.

POST /dna/intent/api/v1/image/activation/device

D.

POST /dna/intent/api/v1/network/{site_id}

E.

POST /dna/intent/api/v1/template-programmer/project/{project_id}/template

Full Access
Question # 52

Which two types of connectors are used to generate telemetry data from IPFIX records in a Cisco Secure Workload implementation? (Choose two.)

A.

ADC

B.

ERSPAN

C.

Cisco ASA

D.

NetFlow

E.

Cisco Secure Workload

Full Access
Question # 53

Which firewall mode does a Cisco Adaptive Security Appliance use to inspect Layer 2 traffic?

A.

Routed

B.

Passive

C.

Inline

D.

Transparent

Full Access
Question # 54

Refer to the exhibit.

Question # 54

How does Cisco Umbrella manage traffic that is directed toward risky domains?

A.

Traffic is proximed through the intelligent proxy.

B.

Traffic is managed by the security settings and blocked.

C.

Traffic is managed by the application settings, unhandled and allowed.

D.

Traffic is allowed but logged.

Full Access
Question # 55

When Cisco and other industry organizations publish and inform users of known security findings and

vulnerabilities, which name is used?

A.

Common Security Exploits

B.

Common Vulnerabilities and Exposures

C.

Common Exploits and Vulnerabilities

D.

Common Vulnerabilities, Exploits and Threats

Full Access
Question # 56

Which solution combines Cisco IOS and IOS XE components to enable administrators to recognize applications, collect and send network metrics to Cisco Prime and other third-party management tools, and prioritize application traffic?

A.

Cisco Catalyst Center

B.

Cisco Security Intelligence

C.

Cisco Model Driven Telemetry

D.

Cisco Application Visibility and Control

Full Access
Question # 57

A network engineer is trying to figure out whether FlexVPN or DMVPN would fit better in their environment.

They have a requirement for more stringent security multiple security associations for the connections, more efficient VPN establishment as well consuming less bandwidth. Which solution would be best for this and why?

A.

DMVPN because it supports IKEv2 and FlexVPN does not

B.

FlexVPN because it supports IKEv2 and DMVPN does not

C.

FlexVPN because it uses multiple SAs and DMVPN does not

D.

DMVPN because it uses multiple SAs and FlexVPN does not

Full Access
Question # 58

Which mitigation strategy should be used to protect against session hijacking attacks in a cloud environment?

A.

Implement input validation.

B.

Use secure cookies.

C.

Apply the principle of least privilege.

D.

Use anti-cross-site request forgery tokens.

Full Access
Question # 59

When MAB is configured for use within the 802.1X environment, an administrator must create a policy that allows the devices onto the network. Which information is used for the username and password?

A.

The MAB uses the IP address as username and password.

B.

The MAB uses the call-station-ID as username and password.

C.

Each device must be set manually by the administrator.

D.

The MAB uses the MAC address as username and password.

Full Access
Question # 60

An engineer enabled SSL decryption for Cisco Umbrella intelligent proxy and needs to ensure that traffic is inspected without alerting end-users. Which action accomplishes this goal?

A.

Restrict access to only websites with trusted third-party signed certificates.

B.

Modify the user’s browser settings to suppress errors from Cisco Umbrella.

C.

Upload the organization root CA to Cisco Umbrella.

D.

Install the Cisco Umbrella root CA onto the user’s device.

Full Access
Question # 61

A security engineer must add destinations into a destination list in Cisco Umbrella. What describes the application of these changes?

A.

The changes are applied immediately it the destination list is part or a policy.

B.

The destination list must be removed from the policy before changes are made to It.

C.

The changes are applied only after the configuration is saved in Cisco Umbrella.

D.

The user role of Block Page Bypass or higher is needed to perform these changes.

Full Access
Question # 62

Refer to the exhibit.

Question # 62

A site-to-site IKEv2 VPN between a Cisco Secure Firewall Threat Defense device with public IP address 203.0.113.10 and a third-party firewall with public IP address 198.51.100.20 is failing to establish at a logistics company. The engineer enables IKEv2 debugging on the FTD and captures the output. Which action must be performed to resolve the issue?

A.

Change the DH group in the IKEv2 policy from Group 20 to Group 14 to match the group negotiated during IKE_SA_INIT.

B.

Verify that the pre-shared key configured on the VPN peer object exactly matches the key on the remote peer, including case, special characters, and any leading or trailing spaces.

C.

Update the IKEv2 policy to remove SHA-384 and use only SHA-256, aligning Phase 1 integrity with the algorithm agreed upon during IKE_SA_INIT.

D.

Switch both peers to certificate-based authentication by enrolling an identity certificate from the corporate CA and sharing the CA certificate with the remote peer.

Full Access
Question # 63

What is a key difference between Cisco Firepower and Cisco ASA?

A.

Cisco ASA provides access control while Cisco Firepower does not.

B.

Cisco Firepower provides identity-based access control while Cisco ASA does not.

C.

Cisco Firepower natively provides intrusion prevention capabilities while Cisco ASA does not.

D.

Cisco ASA provides SSL inspection while Cisco Firepower does not.

Full Access
Question # 64

In a federated single sign-on environment, which protocol exchanges XML-based assertions between an identity provider and a service provider for authentication?

A.

SAML

B.

OAuth 2.0

C.

LDAP

D.

RADIUS

Full Access
Question # 65

An MDM provides which two advantages to an organization with regards to device management? (Choose two)

A.

asset inventory management

B.

allowed application management

C.

Active Directory group policy management

D.

network device management

E.

critical device management

Full Access
Question # 66

Drag and drop the VPN functions from the left onto the descriptions on the right.

Question # 66

Full Access
Question # 67

Which two deployment model configurations are supported for Cisco FTDv in AWS? (Choose two)

A.

Cisco FTDv configured in routed mode and managed by an FMCv installed in AWS

B.

Cisco FTDv with one management interface and two traffic interfaces configured

C.

Cisco FTDv configured in routed mode and managed by a physical FMC appliance on premises

D.

Cisco FTDv with two management interfaces and one traffic interface configured

E.

Cisco FTDv configured in routed mode and IPv6 configured

Full Access
Question # 68

Which factor must be considered when choosing the on-premise solution over the cloud-based one?

A.

With an on-premise solution, the provider is responsible for the installation and maintenance of the product, whereas with a cloud-based solution, the customer is responsible for it

B.

With a cloud-based solution, the provider is responsible for the installation, but the customer is responsible for the maintenance of the product.

C.

With an on-premise solution, the provider is responsible for the installation, but the customer is responsible for the maintenance of the product.

D.

With an on-premise solution, the customer is responsible for the installation and maintenance of theproduct, whereas with a cloud-based solution, the provider is responsible for it.

Full Access
Question # 69

Email security has become a high priority task for a security engineer at a large multi-national organization due to ongoing phishing campaigns. To help control this, the engineer has deployed an Incoming Content Filter with a URL reputation of (-10 00 to -6 00) on the Cisco ESA Which action will the system perform to disable any links in messages that match the filter?

A.

Defang

B.

Quarantine

C.

FilterAction

D.

ScreenAction

Full Access
Question # 70

Which two solutions help combat social engineering and phishing at the endpoint level? (Choose two.)

A.

Cisco Umbrella

B.

Cisco ISE

C.

Cisco DNA Center

D.

Cisco TrustSec

E.

Cisco Duo Security

Full Access
Question # 71

In which cloud services model is the customer responsible for scanning for and mitigation of application vulnerabilities?

A.

PaaS

B.

VMaaS

C.

IaaS

D.

SaaS

Full Access
Question # 72

Which Cisco security solution gives the most complete view of the relationships and evolution of Internet domains IPs, and flies, and helps to pinpoint attackers ' infrastructures and predict future threat?

A.

Cisco Secure Network Analytics

B.

Cisco Secure Cloud Analytics

C.

Cisco Umbrella Investigate

D.

Cisco pxGrid

Full Access
Question # 73

What is a key feature of the Bring Your Own Device (BYOD) capability in Cisco ISE?

A.

Provide temporary Internet access for the personal devices of guest users.

B.

Assess the security posture of personal devices before network access is allowed.

C.

Fully manage network devices based on their characteristics before access is allowed.

D.

Encrypt endpoint data according to predefined security policies.

Full Access
Question # 74

An engineer must modify an existing remote access VPN using a Cisco AnyConnect Secure Mobility client solution and a Cisco Secure Firewall. Currently, all the traffic generate by the user Is sent to the VPN tunnel and the engineer must now exclude some servers and access them directly instead. Which element must be modified to achieve this goat?

A.

NAT exemption

B.

encryption domain

C.

routing table

D.

group policy

Full Access
Question # 75

Which two capabilities of Integration APIs are utilized with Cisco DNA center? (Choose two)

A.

Upgrade software on switches and routers

B.

Third party reporting

C.

Connect to ITSM platforms

D.

Create new SSIDs on a wireless LAN controller

E.

Automatically deploy new virtual routers

Full Access
Question # 76

How is DNS tunneling used to exfiltrate data out of a corporate network?

A.

It corrupts DNS servers by replacing the actual IP address with a rogue address to collect information or start other attacks.

B.

It encodes the payload with random characters that are broken into short strings and the DNS serverrebuilds the exfiltrated data.

C.

It redirects DNS requests to a malicious server used to steal user credentials, which allows further damageand theft on the network.

D.

It leverages the DNS server by permitting recursive lookups to spread the attack to other DNS servers.

Full Access
Question # 77

A Cisco Secure Cloud Analytics administrator is setting up a private network monitor sensor to monitor an on-premises environment. Which two pieces of information from the sensor are used to link to the Secure Cloud Analytics portal? (Choose two.)

A.

Unique service key

B.

NAT ID

C.

SSL certificate

D.

Public IP address

E.

Private IP address

Full Access
Question # 78

Question # 78

Refer to the exhibit. When configuring this access control rule in Cisco FMC, what happens with the traffic destined to the DMZ_inside zone once the configuration is deployed?

A.

All traffic from any zone will be allowed to the DMZ_inside zone only after inspection.

B.

No traffic will be allowed through to the DMZ_inside zone regardless of if it ' s trusted or not.

C.

No traffic will be allowed through to the DMZ_inside zone unless it ' s already trusted.

D.

All traffic from any zone to the DMZ_inside zone will be permitted with no further inspection.

Full Access
Question # 79

What is the benefit of integrating Cisco ISE with a MDM solution?

A.

It provides compliance checks for access to the network

B.

It provides the ability to update other applications on the mobile device

C.

It provides the ability to add applications to the mobile device through Cisco ISE

D.

It provides network device administration access

Full Access
Question # 80

What is managed by Cisco Security Manager?

A.

access point

B.

WSA

C.

ASA

D.

ESA

Full Access
Question # 81

Which security solution protects users leveraging DNS-layer security?

A.

Cisco ISE

B.

Cisco FTD

C.

Cisco Umbrella

D.

Cisco ASA

Full Access
Question # 82

Which endpoint solution protects a user from a phishing attack?

A.

Cisco Identity Services Engine

B.

Cisco AnyConnect with ISE Posture module

C.

Cisco AnyConnect with Network Access Manager module

D.

Cisco AnyConnect with Umbrella Roaming Security module

Full Access
Question # 83

Which IETF attribute is supported for the RADIUS CoA feature?

A.

24 State

B.

30 Calling-Station-ID

C.

42 Acct-Session-ID

D.

81 Message-Authenticator

Full Access
Question # 84

Which method is used to deploy certificates and configure the supplicant on mobile devices to gain access to

network resources?

A.

BYOD on boarding

B.

Simple Certificate Enrollment Protocol

C.

Client provisioning

D.

MAC authentication bypass

Full Access
Question # 85

Which threat intelligence standard contains malware hashes?

A.

advanced persistent threat

B.

open command and control

C.

structured threat information expression

D.

trusted automated exchange of indicator information

Full Access
Question # 86

Which DevSecOps practice helps reduce vulnerabilities introduced through external open-source components?

A.

Performing static routing configuration checks

B.

Conducting software composition analysis during builds

C.

Using dynamic routing between Kubernetes clusters

D.

Setting up round-robin DNS resolution for service discovery

Full Access
Question # 87

Refer to the exhibit.

Question # 87

A newly installed stack of Cisco Catalyst switches has been integrated with Cisco ISE for 802.1X port control and downloadable access control list (dACL) enforcement. Test workstations authenticate successfully, but the expected dACL never appears in the port configuration, leaving all traffic unrestricted. Packet captures confirm that Cisco ISE transmits the correct attributes, yet the switches classify them as “unknown” and ignore the instructions. A review of the running configuration shows complete AAA and 802.1X configuration. Which configuration command must be added to resolve the issue?

A.

radius-server vsa send accounting

B.

aaa authorization network default group radius

C.

radius-server vsa send authentication

D.

aaa authorization exec default group radius

Full Access
Question # 88

Drag and drop the suspicious patterns for the Cisco Tetration platform from the left onto the correct definitions on the right.

Question # 88

Full Access
Question # 89

Which attack is preventable by Cisco ESA but not by the Cisco WSA?

A.

buffer overflow

B.

DoS

C.

SQL injection

D.

phishing

Full Access
Question # 90

For which two conditions can an endpoint be checked using ISE posture assessment? (Choose two)

A.

Windows service

B.

computer identity

C.

user identity

D.

Windows firewall

E.

default browser

Full Access
Question # 91

Why is it important to have logical security controls on endpoints even though the users are trained to spot security threats and the network devices already help prevent them?

A.

to prevent theft of the endpoints

B.

because defense-in-depth stops at the network

C.

to expose the endpoint to more threats

D.

because human error or insider threats will still exist

Full Access
Question # 92

What is a feature of an endpoint detection and response solution?

A.

Preventing attacks by identifying harmful events with machine learning and conduct-based defense

B.

Rapidly and consistently observing and examining data to mitigate threats

C.

Capturing and clarifying data on email, endpoints, and servers to mitigate threats

D.

Ensuring the security of network devices by choosing which devices are allowed to reach the network

Full Access
Question # 93

Which Cisco solution integrates industry-leading artificial intelligence and machine learning analytics and an assurance database to review the security posture and maintain visibility of an organization’s cloud environment?

A.

Cisco CSR1000v

B.

Cisco Secure Workload

C.

Cisco DNA

D.

Cisco FTD

Full Access
Question # 94

Which two mechanisms are used to control phishing attacks? (Choose two)

A.

Enable browser alerts for fraudulent websites.

B.

Define security group memberships.

C.

Revoke expired CRL of the websites.

D.

Use antispyware software.

E.

Implement email filtering techniques.

Full Access
Question # 95

What are two functionalities of northbound and southbound APIs within Cisco SDN architecture? (Choose two.)

A.

Southbound APIs are used to define how SDN controllers integrate with applications.

B.

Southbound interfaces utilize device configurations such as VLANs and IP addresses.

C.

Northbound APIs utilize RESTful API methods such as GET, POST, and DELETE.

D.

Southbound APIs utilize CLI, SNMP, and RESTCONF.

E.

Northbound interfaces utilize OpenFlow and OpFlex to integrate with network devices.

Full Access
Question # 96

How does Cisco AMP for Endpoints provide next-generation protection?

A.

It encrypts data on user endpoints to protect against ransomware.

B.

It leverages an endpoint protection platform and endpoint detection and response.

C.

It utilizes Cisco pxGrid, which allows Cisco AMP to pull threat feeds from threat intelligence centers.

D.

It integrates with Cisco FTD devices.

Full Access
Question # 97

What does Cisco AMP for Endpoints use to help an organization detect different families of malware?

A.

Ethos Engine to perform fuzzy fingerprinting

B.

Tetra Engine to detect malware when me endpoint is connected to the cloud

C.

Clam AV Engine to perform email scanning

D.

Spero Engine with machine learning to perform dynamic analysis

Full Access
Question # 98

Which DoS attack uses fragmented packets in an attempt to crash a target machine?

A.

teardrop

B.

smurf

C.

LAND

D.

SYN flood

Full Access
Question # 99

How is ICMP used an exfiltration technique?

A.

by flooding the destination host with unreachable packets

B.

by sending large numbers of ICMP packets with a targeted hosts source IP address using an IP broadcast address

C.

by encrypting the payload in an ICMP packet to carry out command and control tasks on a compromised host

D.

by overwhelming a targeted host with ICMP echo-request packets

Full Access
Question # 100

An organization wants to secure users, data, and applications in the cloud. The solution must be API-based and

operate as a cloud-native CASB. Which solution must be used for this implementation?

A.

Cisco Cloudlock

B.

Cisco Cloud Email Security

C.

Cisco Firepower Next-Generation Firewall

D.

Cisco Umbrella

Full Access
Question # 101

Which Cisco platform onboards the endpoint and can issue a CA signed certificate while also automatically configuring endpoint network settings to use the signed endpoint certificate, allowing the endpoint to gain network access?

A.

Cisco ISE

B.

Cisco NAC

C.

Cisco TACACS+

D.

Cisco WSA

Full Access
Question # 102

Which Cisco solution provides a comprehensive view of Internet domains. IP addresses, and autonomous systems to help pinpoint attackers and malicious infrastructures?

A.

Cisco Threat Indication Database

B.

Cisco Advanced Malware Investigate

C.

Cisco Umbrella Investigate

D.

Cisco Secure Workload Cloud

Full Access
Question # 103

A network engineer entered the snmp-server user asmith myv7 auth sha cisco priv aes 256

cisc0xxxxxxxxx command and needs to send SNMP information to a host at 10.255.255.1. Which

command achieves this goal?

A.

snmp-server host inside 10.255.255.1 version 3 myv7

B.

snmp-server host inside 10.255.255.1 snmpv3 myv7

C.

snmp-server host inside 10.255.255.1 version 3 asmith

D.

snmp-server host inside 10.255.255.1 snmpv3 asmith

Full Access
Question # 104

In which situation should an Endpoint Detection and Response solution be chosen versus an Endpoint

Protection Platform?

A.

when there is a need for traditional anti-malware detection

B.

when there is no need to have the solution centrally managed

C.

when there is no firewall on the network

D.

when there is a need to have more advanced detection capabilities

Full Access
Question # 105

Question # 105

Refer to the exhibit. An engineer is implementing a certificate-based VPN. What is the result of the existing configuration?

A.

The OU of the IKEv2 peer certificate is encrypted when the OU is set to MANGLER.

B.

The OU of the IKEv2 peer certificate is used as the identity when matching an IKEv2 authorization policy.

C.

Only an IKEv2 peer that has an OU certificate attribute set to MANGLER establishes an IKEv2 SA successfully.

D.

The OU of the IKEv2 peer certificate is set to MANGLER.

Full Access
Question # 106

What is a function of 3DES in reference to cryptography?

A.

It hashes files.

B.

It creates one-time use passwords.

C.

It encrypts traffic.

D.

It generates private keys.

Full Access
Question # 107

An engineer is configuring guest WLAN access using Cisco ISE and the Cisco WLC. Which action temporarily gives guest endpoints access dynamically while maintaining visibility into who or what is connecting?

A.

Modify the WLC configuration to require local WLC logins for the authentication prompts.

B.

Configure ISE and the WLC for guest redirection and services using a self-registered portal.

C.

Configure ISE and the WLC for guest redirection and services using a hotspot portal.

D.

Modify the WLC configuration to allow any endpoint to access an internet-only VLAN.

Full Access
Question # 108

Which security principle advocates rapid cryptographic algorithm replacement to defend against quantum-computing threats?

A.

Crypto agility

B.

Zero trust

C.

Network slicing

D.

Key escrow

Full Access
Question # 109

An engineer is implementing Cisco CES in an existing Microsoft Office 365 environment and must route inbound email to Cisco CE.. record must be modified to accomplish this task?

A.

CNAME

B.

MX

C.

SPF

D.

DKIM

Full Access
Question # 110

What is the primary difference between an Endpoint Protection Platform and an Endpoint Detection and

Response?

A.

EPP focuses on prevention, and EDR focuses on advanced threats that evade perimeter defenses.

B.

EDR focuses on prevention, and EPP focuses on advanced threats that evade perimeter defenses.

C.

EPP focuses on network security, and EDR focuses on device security.

D.

EDR focuses on network security, and EPP focuses on device security.

Full Access
Question # 111

An organization is using Cisco Firepower and Cisco Meraki MX for network security and needs to centrally

manage cloud policies across these platforms. Which software should be used to accomplish this goal?

A.

Cisco Defense Orchestrator

B.

Cisco Secureworks

C.

Cisco DNA Center

D.

Cisco Configuration Professional

Full Access
Question # 112

Which cryptographic process provides origin confidentiality, integrity, and origin authentication for packets?

A.

IKEv1

B.

AH

C.

ESP

D.

IKEv2

Full Access
Question # 113

What is the intent of a basic SYN flood attack?

A.

to solicit DNS responses

B.

to exceed the threshold limit of the connection queue

C.

to flush the register stack to re-initiate the buffers

D.

to cause the buffer to overflow

Full Access
Question # 114

Which statement about the configuration of Cisco ASA NetFlow v9 Secure Event Logging is true?

A.

To view bandwidth usage for NetFlow records, the QoS feature must be enabled.

B.

A sysopt command can be used to enable NSEL on a specific interface.

C.

NSEL can be used without a collector configured.

D.

A flow-export event type must be defined under a policy

Full Access
Question # 115

What is an attribute of Cisco Talos?

A.

Introduction of attributes that use objects and narrative relations

B.

Fast and intelligent responses based on threat data

C.

Cyber threat intelligence interchange and maintenance

D.

Cyber threats posing as authorized users and devices

Full Access
Question # 116

An engineer is configuring web filtering for a network using Cisco Umbrella Secure Internet Gateway.

The requirement is that all traffic needs to be filtered. Using the SSL decryption feature, which type of

certificate should be presented to the end-user to accomplish this goal?

A.

third-party

B.

self-signed

C.

organization owned root

D.

SubCA

Full Access
Question # 117

Question # 117

Refer to the exhibit. All servers are in the same VLAN/Subnet. DNS Server-1 and DNS Server-2 must communicate with each other, and all servers must communicate with default gateway multilayer switch. Which type of private VLAN ports should be configured to prevent communication between DNS servers and the file server?

A.

Configure GigabitEthernet0/1 as community port, GigabitEthernet0/2 as isolated port, and GigabitEthernet0/3 and GigabitEthernet0/4 as promiscuous ports.

B.

Configure GigabitEthernet0/1 as community port, GigabitEthernet0/2 as promiscuous port, Gigabit Ethernet0/3 and GigabitEthernet0/4 as isolated ports C. Configure GigabitEthernet0/1 as promiscuous port, GigabitEthernet0/2 as isolated port and GigabitEthernet0/3 and GrgabitEthernet0/4 as community ports

C.

Configure GigabitEthernet0/1 as promiscuous port, GigabitEthernet0/2 as community port, and GigabitEthernet0/3 and GrgabitEthernet0/4 as isolated ports.

Full Access
Question # 118

Which two are valid suppression types on a Cisco Next Generation Intrusion Prevention System? (Choose two)

A.

Port

B.

Rule

C.

Source

D.

Application

E.

Protocol

Full Access
Question # 119

Which two configurations must be made on Cisco ISE and on Cisco TrustSec devices to force a session to be adjusted after a policy change is made? (Choose two)

A.

posture assessment

B.

aaa authorization exec default local

C.

tacacs-server host 10.1.1.250 key password

D.

aaa server radius dynamic-author

E.

CoA

Full Access
Question # 120

Which system facilitates deploying microsegmentation and multi-tenancy services with a policy-based container?

A.

SDLC

B.

Docker

C.

Lambda

D.

Contiv

Full Access
Question # 121

What is the primary role of the Cisco Email Security Appliance?

A.

Mail Submission Agent

B.

Mail Transfer Agent

C.

Mail Delivery Agent

D.

Mail User Agent

Full Access
Question # 122

Why is it important for the organization to have an endpoint patching strategy?

A.

so the organization can identify endpoint vulnerabilities

B.

so the internal PSIRT organization is aware of the latest bugs

C.

so the network administrator is notified when an existing bug is encountered

D.

so the latest security fixes are installed on the endpoints

Full Access
Question # 123

A network administrator is configuring a rule in an access control policy to block certain URLs and selects the “Chat and Instant Messaging” category. Which reputation score should be selected to accomplish this goal?

A.

1

B.

3

C.

5

D.

10

Full Access
Question # 124

Which technology enables integration between Cisco ISE and other platforms to gather and share

network and vulnerability data and SIEM and location information?

A.

pxGrid

B.

NetFlow

C.

SNMP

D.

Cisco Talos

Full Access
Question # 125

What is the function of the Internet Key Exchange (IKE) protocol in an IPsec VPN?

A.

Handle packet filtering

B.

Negotiate tunnel parameters

C.

Manage data transfers

D.

Encrypt data packets

Full Access
Question # 126

What is a required prerequisite to enable malware file scanning for the Secure Internet Gateway?

A.

Enable IP Layer enforcement.

B.

Activate the Advanced Malware Protection license

C.

Activate SSL decryption.

D.

Enable Intelligent Proxy.

Full Access
Question # 127

An engineer must implement a file transfer solution between a company ' s data center and branches. The company has numerous servers hosted in a hybrid cloud implementation. The file transfer protocol must support authentication, protect the data against unauthorized access, and ensure that users cannot list directories or remove files remotely. Which protocol must be used?

A.

SCP

B.

SSH

C.

FTPS

D.

SFTP

Full Access
Question # 128

Which ESA implementation method segregates inbound and outbound email?

A.

one listener on a single physical Interface

B.

pair of logical listeners on a single physical interface with two unique logical IPv4 addresses and one IPv6 address

C.

pair of logical IPv4 listeners and a pair Of IPv6 listeners on two physically separate interfaces

D.

one listener on one logical IPv4 address on a single logical interface

Full Access
Question # 129

What is an advantage of using a next-generation firewall compared to a traditional firewall?

A.

Next-generation firewalls have stateless inspection capabilities, and traditional firewalls use stateful inspection.

B.

Next-generation firewalls use dynamic packet filtering, and traditional firewalls use static packet filtering.

C.

Next-generation firewalls have threat intelligence feeds, and traditional firewalls use signature detection.

D.

Next-generation firewalls use intrusion prevention policies, and traditional firewalls use intrusion detection policies.

Full Access
Question # 130

A security engineer must configure a Splunk Universal Forwarder to send network traffic logs from Cisco Catalyst switches to a Splunk indexer cluster. Strict compliance requirements require all network traffic logs to be ingested into Splunk as an audit trail. The environment includes thousands of forwarders, and the data must be distributed across all indexers. Which two configuration actions must be performed? (Choose two.)

A.

Configure outputs.conf with the DNS names and indexing ports of all indexers within the cluster.

B.

Implement a large output queue in outputs.conf and disable automatic load balancing.

C.

Configure the forwarder to write logs to a local file share and schedule a batch job to copy the data into the indexers.

D.

Use a deployment server to push an application containing outputs.conf to all Universal Forwarders.

E.

Configure a single primary indexer in outputs.conf and enable a forced connection.

Full Access
Question # 131

Refer to the exhibit.

Question # 131

An engineer creates a Python script to make an API call to Cisco Secure Access. Which output should be expected from the script?

A.

Endpoint token

B.

Device URL

C.

Access token

D.

Client secret

Full Access
Question # 132

In which type of attack does the attacker insert their machine between two hosts that are communicating with each other?

A.

LDAP injection

B.

man-in-the-middle

C.

cross-site scripting

D.

insecure API

Full Access
Question # 133

Which two authentication protocols are supported by the Cisco WSA? (Choose two.)

A.

WCCP

B.

NTLM

C.

TLS

D.

SSL

E.

LDAP

Full Access
Question # 134

A network engineer has configured a NTP server on a Cisco ASA. The Cisco ASA has IP reachability to the

NTP server and is not filtering any traffic. The show ntp association detail command indicates that the

configured NTP server is unsynchronized and has a stratum of 16. What is the cause of this issue?

A.

Resynchronization of NTP is not forced

B.

NTP is not configured to use a working server.

C.

An access list entry for UDP port 123 on the inside interface is missing.

D.

An access list entry for UDP port 123 on the outside interface is missing.

Full Access
Question # 135

What is a benefit of performing device compliance?

A.

Verification of the latest OS patches

B.

Device classification and authorization

C.

Providing multi-factor authentication

D.

Providing attribute-driven policies

Full Access
Question # 136

Which type of API is being used when a controller within a software-defined network architecture dynamically

makes configuration changes on switches within the network?

A.

westbound AP

B.

southbound API

C.

northbound API

D.

eastbound API

Full Access
Question # 137

Which two deployment modes does the Cisco ASA FirePower module support? (Choose two)

A.

transparent mode

B.

routed mode

C.

inline mode

D.

active mode

E.

passive monitor-only mode

Full Access
Question # 138

Which type of data does the Cisco Stealthwatch system collect and analyze from routers, switches, and firewalls?

A.

NTP

B.

syslog

C.

SNMP

D.

NetFlow

Full Access
Question # 139

A security engineer is tasked with configuring TACACS on a Cisco ASA firewall. The engineer must be able to access the firewall command line interface remotely. The authentication must fall back to the local user database of the Cisco ASA firewall. AAA server group named TACACS-GROUP is already configured with TACACS server IP address 192.168.10.10 and key C1sc0512222832!. Which configuration must be done next to meet the requirement?

A.

aaa authentication ssh console LOCAL TACACS-GROUP

B.

aaa authentication ssh console TACACS-GROUP LOCAL

C.

aaa authentication serial console LOCAL TACACS-GROUP

D.

aaa authentication http console TACACS-GROUP LOCAL

Full Access
Question # 140

What is the primary benefit of deploying an ESA in hybrid mode?

A.

You can fine-tune its settings to provide the optimum balance between security and performance for your environment

B.

It provides the lowest total cost of ownership by reducing the need for physical appliances

C.

It provides maximum protection and control of outbound messages

D.

It provides email security while supporting the transition to the cloud

Full Access
Question # 141

A company wants to migrate to the cloud to reduce operational costs. The company requires full control to modify and patch its applications. The cloud provider must be responsible for managing everything else, and all data must be secured at rest. Which cloud service model must be used to meet these requirements?

A.

IaaS

B.

Hybrid cloud

C.

PaaS

D.

SaaS

Full Access
Question # 142

After a recent breach, an organization determined that phishing was used to gain initial access to the network before regaining persistence. The information gained from the phishing attack was a result of users visiting known malicious websites. What must be done in order to prevent this from happening in the future?

A.

Modify an access policy

B.

Modify identification profiles

C.

Modify outbound malware scanning policies

D.

Modify web proxy settings

Full Access
Question # 143

Why should organizations migrate to an MFA strategy for authentication?

A.

Single methods of authentication can be compromised more easily than MFA.

B.

Biometrics authentication leads to the need for MFA due to its ability to be hacked easily.

C.

MFA methods of authentication are never compromised.

D.

MFA does not require any piece of evidence for an authentication mechanism.

Full Access
Question # 144

An engineer is deploying a Cisco Secure Email Gateway and must configure a sender group that decides which mail policy will process the mail. The configuration must accept incoming mails and relay the outgoing mails from the internal server. Which component must be configured to accept the connection to the listener and meet these requirements on a Cisco Secure Email Gateway?

A.

RAT

B.

HAT

C.

Sender list

D.

Access list

Full Access
Question # 145

What are two advantages of using Cisco Any connect over DMVPN? (Choose two)

A.

It provides spoke-to-spoke communications without traversing the hub

B.

It allows different routing protocols to work over the tunnel

C.

It allows customization of access policies based on user identity

D.

It allows multiple sites to connect to the data center

E.

It enables VPN access for individual users from their machines

Full Access
Question # 146

Which statement about IOS zone-based firewalls is true?

A.

An unassigned interface can communicate with assigned interfaces

B.

Only one interface can be assigned to a zone.

C.

An interface can be assigned to multiple zones.

D.

An interface can be assigned only to one zone.

Full Access
Question # 147

What is the function of the crypto is a kmp key cisc406397954 address 0.0.0.0 0.0.0.0 command when establishing an IPsec VPN tunnel?

A.

It defines what data is going to be encrypted via the VPN

B.

lt configures the pre-shared authentication key

C.

It prevents all IP addresses from connecting to the VPN server.

D.

It configures the local address for the VPN server.

Full Access
Question # 148

An engineer is configuring AMP for endpoints and wants to block certain files from executing. Which outbreak

control method is used to accomplish this task?

A.

device flow correlation

B.

simple detections

C.

application blocking list

D.

advanced custom detections

Full Access
Question # 149

Which API technology with SDN architecture is used to communicate with a controller and network devices such as routers and switches?

A.

REST APIs

B.

Northbound APIs

C.

Unprotected APIs

D.

Southbound APIs

Full Access
Question # 150

What is a benefit of using Cisco FMC over Cisco ASDM?

A.

Cisco FMC uses Java while Cisco ASDM uses HTML5.

B.

Cisco FMC provides centralized management while Cisco ASDM does not.

C.

Cisco FMC supports pushing configurations to devices while Cisco ASDM does not.

D.

Cisco FMC supports all firewall products whereas Cisco ASDM only supports Cisco ASA devices

Full Access
Question # 151

Drag and drop the concepts from the left onto the correct descriptions on the right

Question # 151

Full Access
Question # 152

Refer to the exhibit.

Question # 152

Traffic is not passing through IPsec site-to-site VPN on the Firepower Threat Defense appliance. What is causing this issue?

A.

No split-tunnel policy is defined on the Firepower Threat Defense appliance.

B.

The access control policy is not allowing VPN traffic in.

C.

Site-to-site VPN peers are using different encryption algorithms.

D.

Site-to-site VPN preshared keys are mismatched.

Full Access
Question # 153

When a transparent authentication fails on the Web Security Appliance, which type of access does the end user get?

A.

guest

B.

limited Internet

C.

blocked

D.

full Internet

Full Access
Question # 154

Drag and drop the threats from the left onto examples of that threat on the right

Question # 154

Full Access
Question # 155

A mall provides security services to customers with a shared appliance. The mall wants separation of

management on the shared appliance. Which ASA deployment mode meets these needs?

A.

routed mode

B.

transparent mode

C.

multiple context mode

D.

multiple zone mode

Full Access
Question # 156

What is the function of the Context Directory Agent?

A.

maintains users’ group memberships

B.

relays user authentication requests from Web Security Appliance to Active Directory

C.

reads the Active Directory logs to map IP addresses to usernames

D.

accepts user authentication requests on behalf of Web Security Appliance for user identification

Full Access
Question # 157

Which two services must remain as on-premises equipment when a hybrid email solution is deployed? (Choose two)

A.

DDoS

B.

antispam

C.

antivirus

D.

encryption

E.

DLP

Full Access
Question # 158

An organization wants to improve its cybersecurity processes and to add intelligence to its data The organization wants to utilize the most current intelligence data for URL filtering, reputations, and vulnerability information that can be integrated with the Cisco FTD and Cisco WSA What must be done to accomplish these objectives?

A.

Create a Cisco pxGrid connection to NIST to import this information into the security products for policy use

B.

Create an automated download of the Internet Storm Center intelligence feed into the Cisco FTD and Cisco WSA databases to tie to the dynamic access control policies.

C.

Download the threat intelligence feed from the IETF and import it into the Cisco FTD and Cisco WSA databases

D.

Configure the integrations with Talos Intelligence to take advantage of the threat intelligence that it provides.

Full Access
Question # 159

Which feature of a secure CI/CD pipeline defends container workloads against detected exploits, application flaws, configuration errors, and policy violations?

A.

Control groups

B.

Separation of duties

C.

Runtime protection

D.

Cloud-native firewalling

Full Access
Question # 160

Which security solution is used for posture assessment of the endpoints in a BYOD solution?

A.

Cisco FTD

B.

Cisco ASA

C.

Cisco Umbrella

D.

Cisco ISE

Full Access
Question # 161

Drag and drop the Firepower Next Generation Intrusion Prevention System detectors from the left onto the correct definitions on the right.

Question # 161

Full Access
Question # 162

Which Cisco security solution provides patch management in the cloud?

A.

Cisco Umbrella

B.

Cisco ISE

C.

Cisco CloudLock

D.

Cisco Tetration

Full Access
Question # 163

What is the purpose of joining Cisco WSAs to an appliance group?

A.

All WSAs in the group can view file analysis results.

B.

The group supports improved redundancy

C.

It supports cluster operations to expedite the malware analysis process.

D.

It simplifies the task of patching multiple appliances.

Full Access
Question # 164

Which encryption algorithm provides highly secure VPN communications?

A.

3DES

B.

AES 256

C.

AES 128

D.

DES

Full Access
Question # 165

Drag and drop the solutions from the left onto the solution ' s benefits on the right.

Question # 165

Full Access
Question # 166

What are two features of NetFlow flow monitoring? (Choose two)

A.

Can track ingress and egress information

B.

Include the flow record and the flow importer

C.

Copies all ingress flow information to an interface

D.

Does not required packet sampling on interfaces

E.

Can be used to track multicast, MPLS, or bridged traffic

Full Access
Question # 167

Which action must be taken in the AMP for Endpoints console to detect specific MD5 signatures on endpoints and then quarantine the files?

A.

Configure an advanced custom detection list.

B.

Configure an IP Block & Allow custom detection list

C.

Configure an application custom detection list

D.

Configure a simple custom detection list

Full Access
Question # 168

Which PKI enrollment method allows the user to separate authentication and enrollment actions and also

provides an option to specify HTTP/TFTP commands to perform file retrieval from the server?

A.

url

B.

terminal

C.

profile

D.

selfsigned

Full Access
Question # 169

Refer to the exhibit.

Question # 169

What will occur when this device tries to connect to the port?

A.

802.1X will not work, but MAB will start and allow the device on the network.

B.

802.1X will not work and the device will not be allowed network access

C.

802 1X will work and the device will be allowed on the network

D.

802 1X and MAB will both be used and ISE can use policy to determine the access level

Full Access
Question # 170

Question # 170

Refer to the exhibit. An engineer must configure a new Cisco ISE backend server as a RADIUS server to provide AAA for all access requests from the client to the ISE-Frontend server.

Which Cisco ISE configuration must be used?

A.

Set 10.11.1.2 as a network device in ISE-Frontend. Set port 1700/2083 for RADIUS authentication.

B.

Set 10.11.1.1 as the external RADIUS server in ISE-Frontend. Set ports 1812/1813 for authentication and accounting.

C.

Set 10.11.1.2 as the external RADIUS server in ISE-Frontend. Set ports 1812/1813 for authentication and accounting.

D.

Set 10.11.1.1 as a network device in ISE-Frontend. Set ports 1700/2083 for RADIUS authentication.

Full Access
Question # 171

An administrator configures a Cisco WSA to receive redirected traffic over ports 80 and 443. The organization requires that a network device with specific WSA integration capabilities be configured to send the traffic to the WSA to proxy the requests and increase visibility, while making this invisible to the users. What must be done on the Cisco WSA to support these requirements?

A.

Configure transparent traffic redirection using WCCP in the Cisco WSA and on the network device

B.

Configure active traffic redirection using WPAD in the Cisco WSA and on the network device

C.

Use the Layer 4 setting in the Cisco WSA to receive explicit forward requests from the network device

D.

Use PAC keys to allow only the required network devices to send the traffic to the Cisco WSA

Full Access
Question # 172

Which two parameters are used for device compliance checks? (Choose two.)

A.

endpoint protection software version

B.

Windows registry values

C.

DHCP snooping checks

D.

DNS integrity checks

E.

device operating system version

Full Access
Question # 173

Which security solution uses NetFlow to provide visibility across the network, data center, branch offices, and cloud?

A.

Cisco CTA

B.

Cisco Encrypted Traffic Analytics

C.

Cisco Umbrella

D.

Cisco Secure Network Analytics

Full Access
Question # 174

A hacker initiated a social engineering attack and stole username and passwords of some users within a company. Which product should be used as a solution to this problem?

A.

Cisco NGFW

B.

Cisco AnyConnect

C.

Cisco AMP for Endpoints

D.

Cisco Duo

Full Access
Question # 175

Which protocol does the BYOD component in Cisco ISE use to obtain a unique device certificate from an internal CA?

A.

CMP

B.

SCEP

C.

SFTP

D.

OCSP

Full Access
Question # 176

What features does Cisco FTDv provide over ASAv?

A.

Cisco FTDv runs on VMWare while ASAv does not

B.

Cisco FTDv provides 1GB of firewall throughput while Cisco ASAv does not

C.

Cisco FTDv runs on AWS while ASAv does not

D.

Cisco FTDv supports URL filtering while ASAv does not

Full Access
Question # 177

Which Talos reputation center allows for tracking the reputation of IP addresses for email and web traffic?

A.

IP and Domain Reputation Center

B.

File Reputation Center

C.

IP Slock List Center

D.

AMP Reputation Center

Full Access
Question # 178

Which Cisco AMP feature allows an engineer to look back to trace past activities, such as file and process

activity on an endpoint?

A.

endpoint isolation

B.

advanced search

C.

advanced investigation

D.

retrospective security

Full Access
Question # 179

How does Cisco Workload Optimization Manager help mitigate application performance issues?

A.

It deploys an AWS Lambda system

B.

It automates resource resizing

C.

It optimizes a flow path

D.

It sets up a workload forensic score

Full Access
Question # 180

Which attribute has the ability to change during the RADIUS CoA?

A.

NTP

B.

Authorization

C.

Accessibility

D.

Membership

Full Access
Question # 181

What are two functions of IKEv1 but not IKEv2? (Choose two)

A.

NAT-T is supported in IKEv1 but rot in IKEv2.

B.

With IKEv1, when using aggressive mode, the initiator and responder identities are passed cleartext

C.

With IKEv1, mode negotiates faster than main mode

D.

IKEv1 uses EAP authentication

E.

IKEv1 conversations are initiated by the IKE_SA_INIT message

Full Access
Question # 182

Which risk is created when using an Internet browser to access cloud-based service?

A.

misconfiguration of infrastructure, which allows unauthorized access

B.

intermittent connection to the cloud connectors

C.

vulnerabilities within protocol

D.

insecure implementation of API

Full Access
Question # 183

An engineer is trying to decide between using L2TP or GRE over IPsec for their site-to-site VPN implementation. What must be un solution?

A.

L2TP is an IP packet encapsulation protocol, and GRE over IPsec is a tunneling protocol.

B.

L2TP uses TCP port 47 and GRE over IPsec uses UDP port 1701.

C.

GRE over IPsec adds its own header, and L2TP does not.

D.

GRE over IPsec cannot be used as a standalone protocol, and L2TP can.

Full Access
Question # 184

Which technology reduces data loss by identifying sensitive information stored in public computing

environments?

A.

Cisco SDA

B.

Cisco Firepower

C.

Cisco HyperFlex

D.

Cisco Cloudlock

Full Access
Question # 185

What is the function of SDN southbound API protocols?

A.

to allow for the dynamic configuration of control plane applications

B.

to enable the controller to make changes

C.

to enable the controller to use REST

D.

to allow for the static configuration of control plane applications

Full Access
Question # 186

A network engineer is configuring DMVPN and entered the crypto isakmp key cisc0380739941 address 0.0.0.0 command on hostA. The tunnel is not being established to hostB. What action is needed to authenticate the VPN?

A.

Change isakmp to ikev2 in the command on hostA.

B.

Enter the command with a different password on hostB.

C.

Enter the same command on hostB.

D.

Change the password on hostA to the default password.

Full Access
Question # 187

What is the difference between a vulnerability and an exploit?

A.

A vulnerability is a hypothetical event for an attacker to exploit

B.

A vulnerability is a weakness that can be exploited by an attacker

C.

An exploit is a weakness that can cause a vulnerability in the network

D.

An exploit is a hypothetical event that causes a vulnerability in the network

Full Access
Question # 188

Which feature of Cisco ASA allows VPN users to be postured against Cisco ISE without requiring an inline

posture node?

A.

RADIUS Change of Authorization

B.

device tracking

C.

DHCP snooping

D.

VLAN hopping

Full Access
Question # 189

Drag and drop the cloud security assessment components from the left onto the definitions on the right.

Question # 189

Full Access
Question # 190

Which Cisco cloud security software centrally manages policies on multiple platforms such as Cisco ASA, Cisco Firepower, Cisco Meraki, and AWS?

A.

Cisco Defense Orchestrator

B.

Cisco Configuration Professional

C.

Cisco Secureworks

D.

Cisco DNAC

Full Access
Question # 191

What is a characteristic of a bridge group in ASA Firewall transparent mode?

A.

It includes multiple interfaces and access rules between interfaces are customizable

B.

It is a Layer 3 segment and includes one port and customizable access rules

C.

It allows ARP traffic with a single access rule

D.

It has an IP address on its BVI interface and is used for management traffic

Full Access
Question # 192

Which SNMPv3 configuration must be used to support the strongest security possible?

A.

asa-host(config)#snmp-server group myv3 v3 privasa-host(config)#snmp-server user andy myv3 auth sha cisco priv des ciscXXXXXXXXasa-host(config)#snmp-server host inside 10.255.254.1 version 3 andy

B.

asa-host(config)#snmp-server group myv3 v3 noauthasa-host(config)#snmp-server user andy myv3 auth sha cisco priv aes 256 ciscXXXXXXXXasa-host(config)#snmp-server host inside 10.255.254.1 version 3 andy

C.

asa-host(config)#snmpserver group myv3 v3 noauthasa-host(config)#snmp-server user andy myv3 auth sha cisco priv 3des ciscXXXXXXXXasa-host(config)#snmp-server host inside 10.255.254.1 version 3 andy

D.

asa-host(config)#snmp-server group myv3 v3 privasa-host(config)#snmp-server user andy myv3 auth sha cisco priv aes 256 ciscXXXXXXXXasa-host(config)#snmp-server host inside 10.255.254.1 version 3 andy

Full Access
Question # 193

An engineer is implementing NAC for LAN users on a segmented network. The engineer confirms that the device of each user is supported and the Cisco switch configuration is correct.

Which configuration should be made next to ensure there are no authentication issues?

A.

Disable the host firewall.

B.

Enable TACACS+ on the switch.

C.

Open TCP port 49.

D.

Permit UDP port 1812.

Full Access
Question # 194

When a Cisco WSA checks a web request, what occurs if it is unable to match a user-defined policy?

A.

It blocks the request.

B.

It applies the global policy.

C.

It applies the next identification profile policy.

D.

It applies the advanced policy.

Full Access
Question # 195

An administrator configures new authorization policies within Cisco ISE and has difficulty profiling the devices. Attributes for the new Cisco IP phones that are profiled based on the RADIUS authentication are seen however the attributes for CDP or DHCP are not. What should the administrator do to address this issue?

A.

Configure the ip dhcp snooping trust command on the DHCP interfaces to get the information to Cisco ISE

B.

Configure the authentication port-control auto feature within Cisco ISE to identify the devices that are trying to connect

C.

Configure a service template within the switch to standardize the port configurations so that the correct information is sent to Cisco ISE

D.

Configure the device sensor feature within the switch to send the appropriate protocol information

Full Access
Question # 196

Which functions of an SDN architecture require southbound APIs to enable communication?

A.

SDN controller and the network elements

B.

management console and the SDN controller

C.

management console and the cloud

D.

SDN controller and the cloud

Full Access
Question # 197

A company has 5000 Windows users on its campus. Which two precautions should IT take to prevent WannaCry ransomware from spreading to all clients? (Choose two.)

A.

Segment different departments to different IP blocks and enable Dynamic ARp inspection on all VLANs

B.

Ensure that noncompliant endpoints are segmented off to contain any potential damage.

C.

Ensure that a user cannot enter the network of another department.

D.

Perform a posture check to allow only network access to (hose Windows devices that are already patched.

E.

Put all company users in the trusted segment of NGFW and put all servers to the DMZ segment of the Cisco NGFW. ni

Full Access
Question # 198

What is the recommendation in a zero-trust model before granting access to corporate applications and resources?

A.

To use a wired network, not wireless

B.

To use strong passwords

C.

To use multifactor authentication

D.

To disconnect from the network when inactive

Full Access
Question # 199

Which type of algorithm provides the highest level of protection against brute-force attacks?

A.

PFS

B.

HMAC

C.

MD5

D.

SHA

Full Access
Question # 200

Which two features of Cisco Email Security can protect your organization against email threats? (Choose two)

A.

Time-based one-time passwords

B.

Data loss prevention

C.

Heuristic-based filtering

D.

Geolocation-based filtering

E.

NetFlow

Full Access
Question # 201

What is a function of the Layer 4 Traffic Monitor on a Cisco WSA?

A.

blocks traffic from URL categories that are known to contain malicious content

B.

decrypts SSL traffic to monitor for malicious content

C.

monitors suspicious traffic across all the TCP/UDP ports

D.

prevents data exfiltration by searching all the network traffic for specified sensitive information

Full Access
Question # 202

Which Cisco security solution secures public, private, hybrid, and community clouds?

A.

Cisco ISE

B.

Cisco ASAv

C.

Cisco Cloudlock

D.

Cisco pxGrid

Full Access
Question # 203

What is a benefit of using Cisco Tetration?

A.

It collects telemetry data from servers and then uses software sensors to analyze flowinformation.

B.

It collects policy compliance data and process details.

C.

It collects enforcement data from servers and collects interpacket variation.

D.

It collects near-real time data from servers and inventories the software packages that exist onservers.

Full Access
Question # 204

An engineer must implement an external application that authenticates against the Cisco Secure Email Threat Defense API to perform automated message searches. The application already presents a user bearer token, but the API requires an additional authentication header with each request. The engineer must configure the external application to include the required header alongside the bearer token so that the API calls are accepted. Which header must be configured?

A.

x-api-key

B.

token-id

C.

client_secret

D.

x-auth-token

Full Access
Question # 205

How is a cross-site scripting attack executed?

A.

Force a currently authenticated end user to execute unwanted actions on a web app

B.

Execute malicious client-side scripts injected to a client via a web app

C.

Inject a database query via the input data from the client to a web app

D.

Intercept communications between a client and a web server

Full Access
Question # 206

How does Cisco Advanced Phishing Protection protect users?

A.

It validates the sender by using DKIM.

B.

It determines which identities are perceived by the sender

C.

It utilizes sensors that send messages securely.

D.

It uses machine learning and real-time behavior analytics.

Full Access
Question # 207

Which ASA deployment mode can provide separation of management on a shared appliance?

A.

DMZ multiple zone mode

B.

transparent firewall mode

C.

multiple context mode

D.

routed mode

Full Access
Question # 208

When planning a VPN deployment, for which reason does an engineer opt for an active/active FlexVPN

configuration as opposed to DMVPN?

A.

Multiple routers or VRFs are required.

B.

Traffic is distributed statically by default.

C.

Floating static routes are required.

D.

HSRP is used for faliover.

Full Access
Question # 209

Which two global commands must the network administrator implement to limit the attack surface of an internet-facing Cisco router? (Choose two.)

A.

no service password-recovery

B.

no cdp run

C.

service tcp-keepalives-in

D.

no ip http server

E.

ip ssh version 2

Full Access
Question # 210

Which two capabilities of Cisco Secure Workload facilitate the detection of lateral movement within data-center and cloud environments? (Choose two.)

A.

Dynamic updates to firewall rules based on user access

B.

Integration with threat intelligence for identifying malicious IP addresses

C.

Automatic blocking of all inbound and outbound traffic

D.

Real-time visibility into communication patterns between workloads

E.

Recommendations for implementing VLANs for network segmentation

Full Access
Question # 211

Which technology should be used to help prevent an attacker from stealing usernames and passwords of users within an organization?

A.

RADIUS-based REAP

B.

fingerprinting

C.

Dynamic ARP Inspection

D.

multifactor authentication

Full Access
Question # 212

An engineer needs to configure a Cisco Secure Email Gateway (SEG) to prompt users to enter multiple forms of identification before gaining access to the SEG. The SEG must also join a cluster using the preshared key of cisc421555367. What steps must be taken to support this?

A.

Enable two-factor authentication through a RADIUS server, and then join the cluster via the SEG GUI.

B.

Enable two-factor authentication through a TACACS+ server, and then join the cluster via the SEG CLI.

C.

Enable two-factor authentication through a RADIUS server, and then join the cluster via the SEG CLI

D.

Enable two-factor authentication through a TACACS+ server, and then join the cluster via the SEG GUI.

Full Access
Question # 213

A security policy administrator configures a Cisco Secure Access SIA DNS policy to block all social media categories for the Marketing Active Directory group. While testing from one of the user machines, access to the domain https://socialmediaexample.org is allowed. When searching for this domain in User Activity Search, no queries for that specific domain are returned. Consider these facts:

    The test user is part of the Marketing Active Directory group.

    The domain socialmediaexample.org belongs to the social media category.

    The user is configured with the Umbrella Roaming Client for DNS redirection.

    All other social media websites are properly blocked for the same user and match the correct policy.

Which configuration must the administrator implement in Cisco Secure Access to meet the requirement?

A.

Enable HTTPS inspection in the web policy because this is an HTTPS site.

B.

Add socialmediaexample.org to the External Domains list.

C.

Enable the intelligent proxy to identify this domain properly.

D.

Add socialmediaexample.org to the Internal Domains list.

Full Access
Question # 214

An engineer has enabled LDAP accept queries on a listener. Malicious actors must be prevented from quickly

identifying all valid recipients. What must be done on the Cisco ESA to accomplish this goal?

A.

Configure incoming content filters

B.

Use Bounce Verification

C.

Configure Directory Harvest Attack Prevention

D.

Bypass LDAP access queries in the recipient access table

Full Access
Question # 215

Which action configures the IEEE 802.1X Flexible Authentication feature to support Layer 3 authentication mechanisms?

A.

Add MAB into the switch to allow redirection to a Layer 3 device for authentication.

B.

Identify the devices using this feature and create a policy that allows them to pass Layer 2 authentication.

C.

Modify the Dot1x configuration on the VPN server to send Layer 3 authentications to an external authentication database.

D.

Configure WebAuth so the hosts are redirected to a web page for authentication.

Full Access
Question # 216

An organization is using DNS services for their network and want to help improve the security of the DNS infrastructure. Which action accomplishes this task?

A.

Use DNSSEC between the endpoints and Cisco Umbrella DNS servers.

B.

Modify the Cisco Umbrella configuration to pass queries only to non-DNSSEC capable zones.

C.

Integrate Cisco Umbrella with Cisco CloudLock to ensure that DNSSEC is functional.

D.

Configure Cisco Umbrella and use DNSSEC for domain authentication to authoritative servers.

Full Access
Question # 217

Refer to the exhibit.

Question # 217

A network administrator configures command authorization for the admin5 user. What is the admin5 user able to do on HQ_Router after this configuration?

A.

set the IP address of an interface

B.

complete no configurations

C.

complete all configurations

D.

add subinterfaces

Full Access
Question # 218

Drag and drop the security solutions from the left onto the benefits they provide on the right.

Question # 218

Full Access
Question # 219

What is a difference between DMVPN and sVTI?

A.

DMVPN supports tunnel encryption, whereas sVTI does not.

B.

DMVPN supports dynamic tunnel establishment, whereas sVTI does not.

C.

DMVPN supports static tunnel establishment, whereas sVTI does not.

D.

DMVPN provides interoperability with other vendors, whereas sVTI does not.

Full Access
Question # 220

An administrator enables Cisco Threat Intelligence Director on a Cisco FMC. Which process uses STIX and allows uploads and downloads of block lists?

A.

consumption

B.

sharing

C.

editing

D.

authoring

Full Access
Question # 221

II

An engineer musí set up 200 new laptops on a network and wants to prevent the users from moving their laptops around to simplify administration Which switch port MAC address security setting must be used?

A.

sticky

B.

static

C.

aging

D.

maximum

Full Access
Question # 222

Which system performs compliance checks and remote wiping?

A.

MDM

B.

ISE

C.

AMP

D.

OTP

Full Access
Question # 223

What is a benefit of conducting device compliance checks?

A.

It indicates what type of operating system is connecting to the network.

B.

It validates if anti-virus software is installed.

C.

It scans endpoints to determine if malicious activity is taking place.

D.

It detects email phishing attacks.

Full Access
Question # 224

A network engineer is tasked with configuring a Cisco ISE server to implement external authentication against Active Directory. What must be considered about the authentication requirements? (Choose two.)

A.

RADIUS communication must be permitted between the ISE server and the domain controller.

B.

The ISE account must be a domain administrator in Active Directory to perform JOIN operations.

C.

Active Directory only supports user authentication by using MSCHAPv2.

D.

LDAP communication must be permitted between the ISE server and the domain controller.

E.

Active Directory supports user and machine authentication by using MSCHAPv2.

Full Access
Question # 225

What is a feature of container orchestration?

A.

ability to deploy Amazon ECS clusters by using the Cisco Container Platform data plane

B.

ability to deploy Amazon EKS clusters by using the Cisco Container Platform data plane

C.

ability to deploy Kubernetes clusters in air-gapped sites

D.

automated daily updates

Full Access
Question # 226

Which two commands are required when configuring a flow-export action on a Cisco ASA? (Choose two.)

A.

flow-export event-type

B.

policy-map

C.

access-list

D.

flow-export template timeout-rate 15

E.

access-group

Full Access
Question # 227

A network engineer has entered the snmp-server user andy myv3 auth sha cisco priv aes 256

cisc0380739941 command and needs to send SNMP information to a host at 10.255.254.1. Which command achieves this goal?

A.

snmp-server host inside 10.255.254.1 version 3 andy

B.

snmp-server host inside 10.255.254.1 version 3 myv3

C.

snmp-server host inside 10.255.254.1 snmpv3 andy

D.

snmp-server host inside 10.255.254.1 snmpv3 myv3

Full Access
Question # 228

When a next-generation endpoint security solution is selected for a company, what are two key

deliverables that help justify the implementation? (Choose two.)

A.

signature-based endpoint protection on company endpoints

B.

macro-based protection to keep connected endpoints safe

C.

continuous monitoring of all files that are located on connected endpoints

D.

email integration to protect endpoints from malicious content that is located in email

E.

real-time feeds from global threat intelligence centers

Full Access
Question # 229

In which scenario is endpoint-based security the solution?

A.

inspecting encrypted traffic

B.

device profiling and authorization

C.

performing signature-based application control

D.

inspecting a password-protected archive

Full Access
Question # 230

Which RADIUS attribute can you use to filter MAB requests in an 802.1 x deployment?

A.

1

B.

2

C.

6

D.

31

Full Access
Question # 231

Drag and drop the features of Cisco ASA with Firepower from the left onto the benefits on the right.

Question # 231

Full Access
Question # 232

The Cisco ASA must support TLS proxy for encrypted Cisco Unified Communications traffic. Where must the

ASA be added on the Cisco UC Manager platform?

A.

Certificate Trust List

B.

Endpoint Trust List

C.

Enterprise Proxy Service

D.

Secured Collaboration Proxy

Full Access
Question # 233

Which two functions does the Cisco Advanced Phishing Protection solution perform in trying to protect from phishing attacks? (Choose two.)

A.

blocks malicious websites and adds them to a block list

B.

does a real-time user web browsing behavior analysis

C.

provides a defense for on-premises email deployments

D.

uses a static algorithm to determine malicious

E.

determines if the email messages are malicious

Full Access
Question # 234

Which feature enforces continuous connectivity by preventing users from disconnecting the Cisco Secure Client tunnel?

A.

Always-On

B.

Smart Tunnel

C.

Path MTU Discovery

D.

Allow Local LAN Access

Full Access
Question # 235

A network engineer must enable SSH and SCP on a Cisco IOS router. The engineer has already generated the encryption keys and enabled SCP services on the router. Which configuration action must be performed next?

A.

Enable SSHv2 in the configuration.

B.

Restrict access to specific SSH commands.

C.

Enable SCP strict host-key checking.

D.

Add an ACL to deny access from the LAN.

Full Access
Question # 236

What is the role of Cisco Umbrella Roaming when it is installed on an endpoint?

A.

To protect the endpoint against malicious file transfers

B.

To ensure that assets are secure from malicious links on and off the corporate network

C.

To establish secure VPN connectivity to the corporate network

D.

To enforce posture compliance and mandatory software

Full Access
Question # 237

An organization recently installed a Cisco Secure Web Appliance and would like to take advantage of the AVC engine to allow the organization to create a policy to control application-specific activity. After enabling the AVC engine, what must be done to implement this?

A.

Use an access policy group to configure application control settings.

B.

Use security services to configure the traffic monitor.

C.

Use URL categorization to prevent the application traffic.

D.

Use web security reporting to validate engine functionality.

Full Access
Question # 238

What are two Trojan malware attacks? (Choose two)

A.

Frontdoor

B.

Rootkit

C.

Smurf

D.

Backdoor

E.

Sync

Full Access
Question # 239

Which OWASP LLM risk involves an attacker embedding hidden instructions in user input to manipulate the model’s behavior?

A.

Output Truncation

B.

Prompt Injection

C.

System Prompt Leakage

D.

Data Exfiltration

Full Access
Question # 240

A Cisco Firepower administrator needs to configure a rule to allow a new application that has never been seen

on the network. Which two actions should be selected to allow the traffic to pass without inspection? (Choose

two)

A.

permit

B.

trust

C.

reset

D.

allow

E.

monitor

Full Access