Which two risks is a company vulnerable to if it does not have a well-established patching solution for
endpoints? (Choose two)
An administrator configures a new destination list in Cisco Umbrella so that the organization can block specific domains for its devices. What should be done to ensure that all subdomains of domain.com are blocked?
Refer to the exhibit.
aaa new-model
aaa authentication dot1x default group ISE-SERVERS
aaa authorization network default group ISE-SERVERS
aaa accounting dot1x default start-stop group ISE-SERVERS
!
radius server RADIUS_SRV
address ipv4 172.16.10.12 auth-port 1812 acct-port 1813
key shared-secret C1sc0123
!
aaa group server radius ISE-SERVERS
server name RADIUS_SRV
radius-server vsa send authentication
radius-server vsa send accounting
radius-server attribute 6 on-for-login-auth
radius-server attribute 8 include-in-access-req
radius-server attribute 25 access-request include
ip device tracking
!
interface range GigabitEthernet1/0/1 - 48
switchport
switchport host
authentication priority dot1x mab
authentication order dot1x mab
A security engineer is integrating a new Cisco Catalyst access switch with Cisco ISE to enforce port-based network access control using 802.1X. The AAA RADIUS server group and access interfaces are configured on the Cisco Catalyst switch. Cisco ISE has authentication and authorization policies, the workstation supplicants are configured as expected, and connectivity between the switch and ISE is working. During testing, the workstations fail to trigger authentication sessions, and no RADIUS requests appear in the ISE logs or on the switch interfaces. Which two configuration commands must be added to the Cisco Catalyst switch? (Choose two.)
An engineer needs to configure an access control policy rule to always send traffic for inspection without
using the default action. Which action should be configured for this rule?
An engineer is configuring their router to send NetfFow data to Stealthwatch which has an IP address of 1 1 11 using the flow record Stea!thwatch406397954 command Which additional command is required to complete the flow record?
Which solution supports high availability in routed or transparent mode as well as in northbound and
southbound deployments?
Which feature requires a network discovery policy on the Cisco Firepower Next Generation Intrusion Prevention
System?
Which open standard creates a framework for sharing threat intelligence in a machine-digestible format?
Which Cisco AMP feature allows an engineer to look back to trace past activities, such as file and process activity on an endpoint?
What is a benefit of using Cisco AVC (Application Visibility and Control) for application control?
An administrator is establishing a new site-to-site VPN connection on a Cisco IOS router. The organization
needs to ensure that the ISAKMP key on the hub is used only for terminating traffic from the IP address of
172.19.20.24. Which command on the hub will allow the administrator to accomplish this?
An organization is implementing URL blocking using Cisco Umbrella. The users are able to go to some sites but other sites are not accessible due to an error. Why is the error occurring?
An engineer notices traffic interruption on the network. Upon further investigation, it is learned that broadcast
packets have been flooding the network. What must be configured, based on a predefined threshold, to
address this issue?
What are two functions of TAXII in threat intelligence sharing? (Choose two.)
Which protocol does Cisco Duo use to transport authentication assertions for single sign-on?
A Cisco Secure Email Gateway network administrator has been tasked to use a newly installed service to help create policy based on the reputation verdict. During testing, it is discovered that the Secure Email Gateway is not dropping files that have an undetermined verdict. What is causing this issue?
Drag and drop the NetFlow export formats from the left onto the descriptions on the right.
When a Cisco Secure Web Appliance checks a web request, what occurs if it is unable to match a user-defined policy?
Which capability allows an administrator to configure forensics rules in Cisco Secure Workload?
How does the Cisco WSA enforce bandwidth restrictions for web applications?
An engineer must deploy a Cisco Secure Web Appliance. Antimalware scanning must use the Outbreak Heuristics antimalware category on files identified as malware before performing any other processes. What must be configured on the Secure Web Appliance to meet the requirements?
What can be integrated with Cisco Threat Intelligence Director to provide information about security threats,
which allows the SOC to proactively automate responses to those threats?
A security administrator is designing an email protection solution for an onsite email server and must meet these requirements:
Remove malware from email before it reaches corporate premises
Drop emails with risky links automatically
Block access to newly infected sites with real-time URL analysis
Which solution must be used?
A network administrator needs to find out what assets currently exist on the network. Third-party systems need to be able to feed host data into Cisco Firepower. What must be configured to accomplish this?
Which Cisco solution does Cisco Umbrella integrate with to determine if a URL is malicious?
In which two ways does a system administrator send web traffic transparently to the Web Security Appliance?
(Choose two)
Refer to the exhibit.
An engineer configured wired 802.1x on the network and is unable to get a laptop to authenticate. Which port configuration is missing?
Which baseline form of telemetry is recommended for network infrastructure devices?
A user has a device in the network that is receiving too many connection requests from multiple machines.
Which type of attack is the device undergoing?
Which cloud model is a collaborative effort where infrastructure is shared and jointly accessed by several organizations from a specific group?
Which Cisco platform provides an agentless solution to provide visibility across the network including encrypted traffic analytics to detect malware in encrypted traffic without the need for decryption?
A network engineer must distribute an operating system image to a network device and activate the image on that device by using the Cisco Catalyst Center API. Which two API requests perform the required operations? (Choose two.)
Which two types of connectors are used to generate telemetry data from IPFIX records in a Cisco Secure Workload implementation? (Choose two.)
Which firewall mode does a Cisco Adaptive Security Appliance use to inspect Layer 2 traffic?
Refer to the exhibit.
How does Cisco Umbrella manage traffic that is directed toward risky domains?
When Cisco and other industry organizations publish and inform users of known security findings and
vulnerabilities, which name is used?
Which solution combines Cisco IOS and IOS XE components to enable administrators to recognize applications, collect and send network metrics to Cisco Prime and other third-party management tools, and prioritize application traffic?
A network engineer is trying to figure out whether FlexVPN or DMVPN would fit better in their environment.
They have a requirement for more stringent security multiple security associations for the connections, more efficient VPN establishment as well consuming less bandwidth. Which solution would be best for this and why?
Which mitigation strategy should be used to protect against session hijacking attacks in a cloud environment?
When MAB is configured for use within the 802.1X environment, an administrator must create a policy that allows the devices onto the network. Which information is used for the username and password?
An engineer enabled SSL decryption for Cisco Umbrella intelligent proxy and needs to ensure that traffic is inspected without alerting end-users. Which action accomplishes this goal?
A security engineer must add destinations into a destination list in Cisco Umbrella. What describes the application of these changes?
Refer to the exhibit.
A site-to-site IKEv2 VPN between a Cisco Secure Firewall Threat Defense device with public IP address 203.0.113.10 and a third-party firewall with public IP address 198.51.100.20 is failing to establish at a logistics company. The engineer enables IKEv2 debugging on the FTD and captures the output. Which action must be performed to resolve the issue?
In a federated single sign-on environment, which protocol exchanges XML-based assertions between an identity provider and a service provider for authentication?
An MDM provides which two advantages to an organization with regards to device management? (Choose two)
Drag and drop the VPN functions from the left onto the descriptions on the right.
Which two deployment model configurations are supported for Cisco FTDv in AWS? (Choose two)
Which factor must be considered when choosing the on-premise solution over the cloud-based one?
Email security has become a high priority task for a security engineer at a large multi-national organization due to ongoing phishing campaigns. To help control this, the engineer has deployed an Incoming Content Filter with a URL reputation of (-10 00 to -6 00) on the Cisco ESA Which action will the system perform to disable any links in messages that match the filter?
Which two solutions help combat social engineering and phishing at the endpoint level? (Choose two.)
In which cloud services model is the customer responsible for scanning for and mitigation of application vulnerabilities?
Which Cisco security solution gives the most complete view of the relationships and evolution of Internet domains IPs, and flies, and helps to pinpoint attackers ' infrastructures and predict future threat?
What is a key feature of the Bring Your Own Device (BYOD) capability in Cisco ISE?
An engineer must modify an existing remote access VPN using a Cisco AnyConnect Secure Mobility client solution and a Cisco Secure Firewall. Currently, all the traffic generate by the user Is sent to the VPN tunnel and the engineer must now exclude some servers and access them directly instead. Which element must be modified to achieve this goat?
Which two capabilities of Integration APIs are utilized with Cisco DNA center? (Choose two)
A Cisco Secure Cloud Analytics administrator is setting up a private network monitor sensor to monitor an on-premises environment. Which two pieces of information from the sensor are used to link to the Secure Cloud Analytics portal? (Choose two.)
Refer to the exhibit. When configuring this access control rule in Cisco FMC, what happens with the traffic destined to the DMZ_inside zone once the configuration is deployed?
Which method is used to deploy certificates and configure the supplicant on mobile devices to gain access to
network resources?
Which DevSecOps practice helps reduce vulnerabilities introduced through external open-source components?
Refer to the exhibit.
A newly installed stack of Cisco Catalyst switches has been integrated with Cisco ISE for 802.1X port control and downloadable access control list (dACL) enforcement. Test workstations authenticate successfully, but the expected dACL never appears in the port configuration, leaving all traffic unrestricted. Packet captures confirm that Cisco ISE transmits the correct attributes, yet the switches classify them as “unknown” and ignore the instructions. A review of the running configuration shows complete AAA and 802.1X configuration. Which configuration command must be added to resolve the issue?
Drag and drop the suspicious patterns for the Cisco Tetration platform from the left onto the correct definitions on the right.
For which two conditions can an endpoint be checked using ISE posture assessment? (Choose two)
Why is it important to have logical security controls on endpoints even though the users are trained to spot security threats and the network devices already help prevent them?
Which Cisco solution integrates industry-leading artificial intelligence and machine learning analytics and an assurance database to review the security posture and maintain visibility of an organization’s cloud environment?
What are two functionalities of northbound and southbound APIs within Cisco SDN architecture? (Choose two.)
What does Cisco AMP for Endpoints use to help an organization detect different families of malware?
Which DoS attack uses fragmented packets in an attempt to crash a target machine?
An organization wants to secure users, data, and applications in the cloud. The solution must be API-based and
operate as a cloud-native CASB. Which solution must be used for this implementation?
Which Cisco platform onboards the endpoint and can issue a CA signed certificate while also automatically configuring endpoint network settings to use the signed endpoint certificate, allowing the endpoint to gain network access?
Which Cisco solution provides a comprehensive view of Internet domains. IP addresses, and autonomous systems to help pinpoint attackers and malicious infrastructures?
A network engineer entered the snmp-server user asmith myv7 auth sha cisco priv aes 256
cisc0xxxxxxxxx command and needs to send SNMP information to a host at 10.255.255.1. Which
command achieves this goal?
In which situation should an Endpoint Detection and Response solution be chosen versus an Endpoint
Protection Platform?
Refer to the exhibit. An engineer is implementing a certificate-based VPN. What is the result of the existing configuration?
An engineer is configuring guest WLAN access using Cisco ISE and the Cisco WLC. Which action temporarily gives guest endpoints access dynamically while maintaining visibility into who or what is connecting?
Which security principle advocates rapid cryptographic algorithm replacement to defend against quantum-computing threats?
An engineer is implementing Cisco CES in an existing Microsoft Office 365 environment and must route inbound email to Cisco CE.. record must be modified to accomplish this task?
What is the primary difference between an Endpoint Protection Platform and an Endpoint Detection and
Response?
An organization is using Cisco Firepower and Cisco Meraki MX for network security and needs to centrally
manage cloud policies across these platforms. Which software should be used to accomplish this goal?
Which cryptographic process provides origin confidentiality, integrity, and origin authentication for packets?
Which statement about the configuration of Cisco ASA NetFlow v9 Secure Event Logging is true?
An engineer is configuring web filtering for a network using Cisco Umbrella Secure Internet Gateway.
The requirement is that all traffic needs to be filtered. Using the SSL decryption feature, which type of
certificate should be presented to the end-user to accomplish this goal?
Refer to the exhibit. All servers are in the same VLAN/Subnet. DNS Server-1 and DNS Server-2 must communicate with each other, and all servers must communicate with default gateway multilayer switch. Which type of private VLAN ports should be configured to prevent communication between DNS servers and the file server?
Which two are valid suppression types on a Cisco Next Generation Intrusion Prevention System? (Choose two)
Which two configurations must be made on Cisco ISE and on Cisco TrustSec devices to force a session to be adjusted after a policy change is made? (Choose two)
Which system facilitates deploying microsegmentation and multi-tenancy services with a policy-based container?
Why is it important for the organization to have an endpoint patching strategy?
A network administrator is configuring a rule in an access control policy to block certain URLs and selects the “Chat and Instant Messaging” category. Which reputation score should be selected to accomplish this goal?
Which technology enables integration between Cisco ISE and other platforms to gather and share
network and vulnerability data and SIEM and location information?
What is the function of the Internet Key Exchange (IKE) protocol in an IPsec VPN?
What is a required prerequisite to enable malware file scanning for the Secure Internet Gateway?
An engineer must implement a file transfer solution between a company ' s data center and branches. The company has numerous servers hosted in a hybrid cloud implementation. The file transfer protocol must support authentication, protect the data against unauthorized access, and ensure that users cannot list directories or remove files remotely. Which protocol must be used?
What is an advantage of using a next-generation firewall compared to a traditional firewall?
A security engineer must configure a Splunk Universal Forwarder to send network traffic logs from Cisco Catalyst switches to a Splunk indexer cluster. Strict compliance requirements require all network traffic logs to be ingested into Splunk as an audit trail. The environment includes thousands of forwarders, and the data must be distributed across all indexers. Which two configuration actions must be performed? (Choose two.)
Refer to the exhibit.
An engineer creates a Python script to make an API call to Cisco Secure Access. Which output should be expected from the script?
In which type of attack does the attacker insert their machine between two hosts that are communicating with each other?
Which two authentication protocols are supported by the Cisco WSA? (Choose two.)
A network engineer has configured a NTP server on a Cisco ASA. The Cisco ASA has IP reachability to the
NTP server and is not filtering any traffic. The show ntp association detail command indicates that the
configured NTP server is unsynchronized and has a stratum of 16. What is the cause of this issue?
Which type of API is being used when a controller within a software-defined network architecture dynamically
makes configuration changes on switches within the network?
Which two deployment modes does the Cisco ASA FirePower module support? (Choose two)
Which type of data does the Cisco Stealthwatch system collect and analyze from routers, switches, and firewalls?
A security engineer is tasked with configuring TACACS on a Cisco ASA firewall. The engineer must be able to access the firewall command line interface remotely. The authentication must fall back to the local user database of the Cisco ASA firewall. AAA server group named TACACS-GROUP is already configured with TACACS server IP address 192.168.10.10 and key C1sc0512222832!. Which configuration must be done next to meet the requirement?
A company wants to migrate to the cloud to reduce operational costs. The company requires full control to modify and patch its applications. The cloud provider must be responsible for managing everything else, and all data must be secured at rest. Which cloud service model must be used to meet these requirements?
After a recent breach, an organization determined that phishing was used to gain initial access to the network before regaining persistence. The information gained from the phishing attack was a result of users visiting known malicious websites. What must be done in order to prevent this from happening in the future?
An engineer is deploying a Cisco Secure Email Gateway and must configure a sender group that decides which mail policy will process the mail. The configuration must accept incoming mails and relay the outgoing mails from the internal server. Which component must be configured to accept the connection to the listener and meet these requirements on a Cisco Secure Email Gateway?
What are two advantages of using Cisco Any connect over DMVPN? (Choose two)
What is the function of the crypto is a kmp key cisc406397954 address 0.0.0.0 0.0.0.0 command when establishing an IPsec VPN tunnel?
An engineer is configuring AMP for endpoints and wants to block certain files from executing. Which outbreak
control method is used to accomplish this task?
Which API technology with SDN architecture is used to communicate with a controller and network devices such as routers and switches?
Drag and drop the concepts from the left onto the correct descriptions on the right
Refer to the exhibit.
Traffic is not passing through IPsec site-to-site VPN on the Firepower Threat Defense appliance. What is causing this issue?
When a transparent authentication fails on the Web Security Appliance, which type of access does the end user get?
Drag and drop the threats from the left onto examples of that threat on the right
A mall provides security services to customers with a shared appliance. The mall wants separation of
management on the shared appliance. Which ASA deployment mode meets these needs?
Which two services must remain as on-premises equipment when a hybrid email solution is deployed? (Choose two)
An organization wants to improve its cybersecurity processes and to add intelligence to its data The organization wants to utilize the most current intelligence data for URL filtering, reputations, and vulnerability information that can be integrated with the Cisco FTD and Cisco WSA What must be done to accomplish these objectives?
Which feature of a secure CI/CD pipeline defends container workloads against detected exploits, application flaws, configuration errors, and policy violations?
Which security solution is used for posture assessment of the endpoints in a BYOD solution?
Drag and drop the Firepower Next Generation Intrusion Prevention System detectors from the left onto the correct definitions on the right.
Drag and drop the solutions from the left onto the solution ' s benefits on the right.
Which action must be taken in the AMP for Endpoints console to detect specific MD5 signatures on endpoints and then quarantine the files?
Which PKI enrollment method allows the user to separate authentication and enrollment actions and also
provides an option to specify HTTP/TFTP commands to perform file retrieval from the server?
Refer to the exhibit.
What will occur when this device tries to connect to the port?
Refer to the exhibit. An engineer must configure a new Cisco ISE backend server as a RADIUS server to provide AAA for all access requests from the client to the ISE-Frontend server.
Which Cisco ISE configuration must be used?
An administrator configures a Cisco WSA to receive redirected traffic over ports 80 and 443. The organization requires that a network device with specific WSA integration capabilities be configured to send the traffic to the WSA to proxy the requests and increase visibility, while making this invisible to the users. What must be done on the Cisco WSA to support these requirements?
Which two parameters are used for device compliance checks? (Choose two.)
Which security solution uses NetFlow to provide visibility across the network, data center, branch offices, and cloud?
A hacker initiated a social engineering attack and stole username and passwords of some users within a company. Which product should be used as a solution to this problem?
Which protocol does the BYOD component in Cisco ISE use to obtain a unique device certificate from an internal CA?
Which Talos reputation center allows for tracking the reputation of IP addresses for email and web traffic?
Which Cisco AMP feature allows an engineer to look back to trace past activities, such as file and process
activity on an endpoint?
How does Cisco Workload Optimization Manager help mitigate application performance issues?
Which risk is created when using an Internet browser to access cloud-based service?
An engineer is trying to decide between using L2TP or GRE over IPsec for their site-to-site VPN implementation. What must be un solution?
Which technology reduces data loss by identifying sensitive information stored in public computing
environments?
A network engineer is configuring DMVPN and entered the crypto isakmp key cisc0380739941 address 0.0.0.0 command on hostA. The tunnel is not being established to hostB. What action is needed to authenticate the VPN?
Which feature of Cisco ASA allows VPN users to be postured against Cisco ISE without requiring an inline
posture node?
Drag and drop the cloud security assessment components from the left onto the definitions on the right.
Which Cisco cloud security software centrally manages policies on multiple platforms such as Cisco ASA, Cisco Firepower, Cisco Meraki, and AWS?
What is a characteristic of a bridge group in ASA Firewall transparent mode?
Which SNMPv3 configuration must be used to support the strongest security possible?
An engineer is implementing NAC for LAN users on a segmented network. The engineer confirms that the device of each user is supported and the Cisco switch configuration is correct.
Which configuration should be made next to ensure there are no authentication issues?
When a Cisco WSA checks a web request, what occurs if it is unable to match a user-defined policy?
An administrator configures new authorization policies within Cisco ISE and has difficulty profiling the devices. Attributes for the new Cisco IP phones that are profiled based on the RADIUS authentication are seen however the attributes for CDP or DHCP are not. What should the administrator do to address this issue?
Which functions of an SDN architecture require southbound APIs to enable communication?
A company has 5000 Windows users on its campus. Which two precautions should IT take to prevent WannaCry ransomware from spreading to all clients? (Choose two.)
What is the recommendation in a zero-trust model before granting access to corporate applications and resources?
Which type of algorithm provides the highest level of protection against brute-force attacks?
Which two features of Cisco Email Security can protect your organization against email threats? (Choose two)
Which Cisco security solution secures public, private, hybrid, and community clouds?
An engineer must implement an external application that authenticates against the Cisco Secure Email Threat Defense API to perform automated message searches. The application already presents a user bearer token, but the API requires an additional authentication header with each request. The engineer must configure the external application to include the required header alongside the bearer token so that the API calls are accepted. Which header must be configured?
Which ASA deployment mode can provide separation of management on a shared appliance?
When planning a VPN deployment, for which reason does an engineer opt for an active/active FlexVPN
configuration as opposed to DMVPN?
Which two global commands must the network administrator implement to limit the attack surface of an internet-facing Cisco router? (Choose two.)
Which two capabilities of Cisco Secure Workload facilitate the detection of lateral movement within data-center and cloud environments? (Choose two.)
Which technology should be used to help prevent an attacker from stealing usernames and passwords of users within an organization?
An engineer needs to configure a Cisco Secure Email Gateway (SEG) to prompt users to enter multiple forms of identification before gaining access to the SEG. The SEG must also join a cluster using the preshared key of cisc421555367. What steps must be taken to support this?
A security policy administrator configures a Cisco Secure Access SIA DNS policy to block all social media categories for the Marketing Active Directory group. While testing from one of the user machines, access to the domain https://socialmediaexample.org is allowed. When searching for this domain in User Activity Search, no queries for that specific domain are returned. Consider these facts:
The test user is part of the Marketing Active Directory group.
The domain socialmediaexample.org belongs to the social media category.
The user is configured with the Umbrella Roaming Client for DNS redirection.
All other social media websites are properly blocked for the same user and match the correct policy.
Which configuration must the administrator implement in Cisco Secure Access to meet the requirement?
An engineer has enabled LDAP accept queries on a listener. Malicious actors must be prevented from quickly
identifying all valid recipients. What must be done on the Cisco ESA to accomplish this goal?
Which action configures the IEEE 802.1X Flexible Authentication feature to support Layer 3 authentication mechanisms?
An organization is using DNS services for their network and want to help improve the security of the DNS infrastructure. Which action accomplishes this task?
Refer to the exhibit.
A network administrator configures command authorization for the admin5 user. What is the admin5 user able to do on HQ_Router after this configuration?
Drag and drop the security solutions from the left onto the benefits they provide on the right.
An administrator enables Cisco Threat Intelligence Director on a Cisco FMC. Which process uses STIX and allows uploads and downloads of block lists?
II
An engineer musí set up 200 new laptops on a network and wants to prevent the users from moving their laptops around to simplify administration Which switch port MAC address security setting must be used?
A network engineer is tasked with configuring a Cisco ISE server to implement external authentication against Active Directory. What must be considered about the authentication requirements? (Choose two.)
Which two commands are required when configuring a flow-export action on a Cisco ASA? (Choose two.)
A network engineer has entered the snmp-server user andy myv3 auth sha cisco priv aes 256
cisc0380739941 command and needs to send SNMP information to a host at 10.255.254.1. Which command achieves this goal?
When a next-generation endpoint security solution is selected for a company, what are two key
deliverables that help justify the implementation? (Choose two.)
Which RADIUS attribute can you use to filter MAB requests in an 802.1 x deployment?
Drag and drop the features of Cisco ASA with Firepower from the left onto the benefits on the right.
The Cisco ASA must support TLS proxy for encrypted Cisco Unified Communications traffic. Where must the
ASA be added on the Cisco UC Manager platform?
Which two functions does the Cisco Advanced Phishing Protection solution perform in trying to protect from phishing attacks? (Choose two.)
Which feature enforces continuous connectivity by preventing users from disconnecting the Cisco Secure Client tunnel?
A network engineer must enable SSH and SCP on a Cisco IOS router. The engineer has already generated the encryption keys and enabled SCP services on the router. Which configuration action must be performed next?
What is the role of Cisco Umbrella Roaming when it is installed on an endpoint?
An organization recently installed a Cisco Secure Web Appliance and would like to take advantage of the AVC engine to allow the organization to create a policy to control application-specific activity. After enabling the AVC engine, what must be done to implement this?
Which OWASP LLM risk involves an attacker embedding hidden instructions in user input to manipulate the model’s behavior?
A Cisco Firepower administrator needs to configure a rule to allow a new application that has never been seen
on the network. Which two actions should be selected to allow the traffic to pass without inspection? (Choose
two)