ExamGecko
Home Home / Cisco / 350-701

Cisco 350-701 Practice Test - Questions Answers, Page 57

Question list
Search
Search

Which feature must be configured before implementing NetFlow on a router?

A.

SNMPv3

A.

SNMPv3

Answers
B.

syslog

B.

syslog

Answers
C.

VRF

C.

VRF

Answers
D.

IP routing

D.

IP routing

Answers
Suggested answer: D

What is an advantage of the Cisco Umbrella roaming client?

A.

the ability to see all traffic without requiring TLS decryption

A.

the ability to see all traffic without requiring TLS decryption

Answers
B.

visibility into IP-based threats by tunneling suspicious IP connections

B.

visibility into IP-based threats by tunneling suspicious IP connections

Answers
C.

the ability to dynamically categorize traffic to previously uncategorized sites

C.

the ability to dynamically categorize traffic to previously uncategorized sites

Answers
D.

visibility into traffic that is destined to sites within the office environment

D.

visibility into traffic that is destined to sites within the office environment

Answers
Suggested answer: B

What is a function of Cisco AMP for Endpoints?

A.

It detects DNS attacks

A.

It detects DNS attacks

Answers
B.

It protects against web-based attacks

B.

It protects against web-based attacks

Answers
C.

It blocks email-based attacks

C.

It blocks email-based attacks

Answers
D.

It automates threat responses of an infected host

D.

It automates threat responses of an infected host

Answers
Suggested answer: D

An engineer is implementing DHCP security mechanisms and needs the ability to add additional attributes to profiles that are created within Cisco ISE Which action accomplishes this task?

A.

Define MAC-to-lP address mappings in the switch to ensure that rogue devices cannot get an IP address

A.

Define MAC-to-lP address mappings in the switch to ensure that rogue devices cannot get an IP address

Answers
B.

Use DHCP option 82 to ensure that the request is from a legitimate endpoint and send the information to Cisco ISE

B.

Use DHCP option 82 to ensure that the request is from a legitimate endpoint and send the information to Cisco ISE

Answers
C.

Modify the DHCP relay and point the IP address to Cisco ISE.

C.

Modify the DHCP relay and point the IP address to Cisco ISE.

Answers
D.

Configure DHCP snooping on the switch VLANs and trust the necessary interfaces

D.

Configure DHCP snooping on the switch VLANs and trust the necessary interfaces

Answers
Suggested answer: D

Which feature requires that network telemetry be enabled?

A.

per-interface stats

A.

per-interface stats

Answers
B.

SNMP trap notification

B.

SNMP trap notification

Answers
C.

Layer 2 device discovery

C.

Layer 2 device discovery

Answers
D.

central syslog system

D.

central syslog system

Answers
Suggested answer: D

Refer to the exhibit

When configuring this access control rule in Cisco FMC, what happens with the traffic destined to the DMZ_inside zone once the configuration is deployed?

A.

All traffic from any zone to the DMZ_inside zone will be permitted with no further inspection

A.

All traffic from any zone to the DMZ_inside zone will be permitted with no further inspection

Answers
B.

No traffic will be allowed through to the DMZ_inside zone regardless of if it's trusted or not

B.

No traffic will be allowed through to the DMZ_inside zone regardless of if it's trusted or not

Answers
C.

All traffic from any zone will be allowed to the DMZ_inside zone only after inspection

C.

All traffic from any zone will be allowed to the DMZ_inside zone only after inspection

Answers
D.

No traffic will be allowed through to the DMZ_inside zone unless it's already trusted

D.

No traffic will be allowed through to the DMZ_inside zone unless it's already trusted

Answers
Suggested answer: A

An engineer is trying to decide whether to use Cisco Umbrella, Cisco CloudLock, Cisco Stealthwatch, or Cisco AppDynamics Cloud Monitoring for visibility into data transfers as well as protection against data exfiltration Which solution best meets these requirements?

A.

Cisco CloudLock

A.

Cisco CloudLock

Answers
B.

Cisco AppDynamics Cloud Monitoring

B.

Cisco AppDynamics Cloud Monitoring

Answers
C.

Cisco Umbrella

C.

Cisco Umbrella

Answers
D.

Cisco Stealthwatch

D.

Cisco Stealthwatch

Answers
Suggested answer: D

An engineer needs to detect and quarantine a file named abc424400664 zip based on the MD5 signature of the file using the Outbreak Control list feature within Cisco Advanced Malware Protection (AMP) for Endpoints The configured detection method must work on files of unknown disposition Which Outbreak Control list must be configured to provide this?

A.

Blocked Application

A.

Blocked Application

Answers
B.

Simple Custom Detection

B.

Simple Custom Detection

Answers
C.

Advanced Custom Detection

C.

Advanced Custom Detection

Answers
D.

Android Custom Detection

D.

Android Custom Detection

Answers
Suggested answer: C

With regard to RFC 5176 compliance, how many IETF attributes are supported by the RADIUS CoA feature?

A.

3

A.

3

Answers
B.

5

B.

5

Answers
C.

10

C.

10

Answers
D.

12

D.

12

Answers
Suggested answer: B

Explanation:

https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_aaa/configuration/xe-16-10/sec-usr-aaa-xe-16-10-book/sec-rad-coa.pdf

An engineer is configuring cloud logging using a company-managed Amazon S3 bucket for Cisco Umbrella logs. What benefit does this configuration provide for accessing log data?

A.

It is included m the license cost for the multi-org console of Cisco Umbrella

A.

It is included m the license cost for the multi-org console of Cisco Umbrella

Answers
B.

It can grant third-party SIEM integrations write access to the S3 bucket

B.

It can grant third-party SIEM integrations write access to the S3 bucket

Answers
C.

No other applications except Cisco Umbrella can write to the S3 bucket

C.

No other applications except Cisco Umbrella can write to the S3 bucket

Answers
D.

Data can be stored offline for 30 days.

D.

Data can be stored offline for 30 days.

Answers
Suggested answer: D
Total 631 questions
Go to page: of 64