Cisco 350-701 Practice Test - Questions Answers, Page 17
List of questions
Related questions
What provides the ability to program and monitor networks from somewhere other than the DNAC GUI?
NetFlow
desktop client
ASDM
API
An organization has two machines hosting web applications. Machine 1 is vulnerable to SQL injection while machine 2 is vulnerable to buffer overflows. What action would allow the attacker to gain access to machine 1 but not machine 2?
sniffing the packets between the two hosts
sending continuous pings
overflowing the buffer's memory
inserting malicious commands into the database
An organization is trying to improve their Defense in Depth by blocking malicious destinations prior to a connection being established. The solution must be able to block certain applications from being used within the network. Which product should be used to accomplish this goal?
Cisco Firepower
Cisco Umbrella
ISE
AMP
A company is experiencing exfiltration of credit card numbers that are not being stored on-premise.
The company needs to be able to protect sensitive data throughout the full environment. Which tool should be used to accomplish this goal?
Security Manager
Cloudlock
Web Security Appliance
Cisco ISE
An engineer is trying to securely connect to a router and wants to prevent insecure algorithms from being used.
However, the connection is failing. Which action should be taken to accomplish this goal?
Disable telnet using the no ip telnet command.
Enable the SSH server using the ip ssh server command.
Configure the port using the ip ssh port 22 command.
Generate the RSA key using the crypto key generate rsa command.
A network administrator is using the Cisco ESA with AMP to upload files to the cloud for analysis. The network is congested and is affecting communication. How will the Cisco ESA handle any files which need analysis?
AMP calculates the SHA-256 fingerprint, caches it, and periodically attempts the upload.
The file is queued for upload when connectivity is restored.
The file upload is abandoned.
The ESA immediately makes another attempt to upload the file.
Which type of algorithm provides the highest level of protection against brute-force attacks?
PFS
HMAC
MD5
SHA
What must be configured in Cisco ISE to enforce reauthentication of an endpoint session when an endpoint is deleted from an identity group?
posture assessment
CoA
external identity source
SNMP probe
A network administrator is configuring a rule in an access control policy to block certain URLs and selects the "Chat and Instant Messaging" category. Which reputation score should be selected to accomplish this goal?
1
3
5
10
Which group within Cisco writes and publishes a weekly newsletter to help cybersecurity professionals remain aware of the ongoing and most prevalent threats?
PSIRT
Talos
CSIRT
DEVNET
Question