Pass 350-701 Exam with Updated 350-701 Exam Dumps PDF 2021 [Q31-Q55]

Share

Pass 350-701 Exam with Updated 350-701 Exam Dumps PDF 2021

350-701 Exam Dumps - Free Demo & 365 Day Updates


Career Prospects

The certificates available after clearing the Cisco 350-701 exam allow the successful candidates to explore a wide range of security job roles. The certified professionals can consider taking one of the following positions: a Technical Solutions Architect, a Consulting Systems Engineer, a Network Administrator, a Network Designer, a Network Engineer, a Network Manager, a Security Engineer, and a Systems Engineer. According to PayScale, the average salary associated with these job titles is around $113,000 per year in the United States. However, the exact remuneration will depend on numerous factors, such as one’s level of experience, location, as well as type of hiring organization.

 

NEW QUESTION 31
Which solution combines Cisco IOS and IOS XE components to enable administrators to recognize applications, collect and send network metrics to Cisco Prime and other third-party management tools, and prioritize application traffic?

  • A. Cisco Model Driven Telemetry
  • B. Cisco Application Visibility and Control
  • C. Cisco DNA Center
  • D. Cisco Security Intelligence

Answer: B

Explanation:
The Cisco Application Visibility and Control (AVC) solution leverages multiple technologies to recognize, analyze, and control over 1000 applications, including voice and video, email, file sharing, gaming, peer-to-peer (P2P), and cloud-based applications. AVC combines several Cisco IOS/IOS XE components, as well as communicating with external tools, to integrate the following functions into a powerful solution...
The Cisco Application Visibility and Control (AVC) solution leverages multiple technologies to recognize, analyze, and control over 1000 applications, including voice and video, email, file sharing, gaming, peer-to-peer (P2P), and cloud-based applications. AVC combines several Cisco IOS/IOS XE components, as well as communicating with external tools, to integrate the following functions into a powerful solution...
Reference:
avc_tech_overview.html
The Cisco Application Visibility and Control (AVC) solution leverages multiple technologies to recognize, analyze, and control over 1000 applications, including voice and video, email, file sharing, gaming, peer-to-peer (P2P), and cloud-based applications. AVC combines several Cisco IOS/IOS XE components, as well as communicating with external tools, to integrate the following functions into a powerful solution...
avc_tech_overview.html

 

NEW QUESTION 32
What provides visibility and awareness into what is currently occurring on the network?

  • A. CMX
  • B. Telemetry
  • C. Prime Infrastructure
  • D. WMI

Answer: B

Explanation:
Explanation : Telemetry - Information and/or data that provides awareness and visibility into what is occurring on the network at any given time from networking devices, appliances, applications or servers in which the core function of the device is not to generate security alerts designed to detect unwanted or malicious activity from computer networks. Reference: https://www.cisco.com/c/dam/en_us/about/doing_business/legal/service_descriptions/docs/activethreat-analytics-premier.pdf Explanation:
Telemetry - Information and/or data that provides awareness and visibility into what is occurring on the network at any given time from networking devices, appliances, applications or servers in which the core function of the device is not to generate security alerts designed to detect unwanted or malicious activity from computer networks.
Explanation : Telemetry - Information and/or data that provides awareness and visibility into what is occurring on the network at any given time from networking devices, appliances, applications or servers in which the core function of the device is not to generate security alerts designed to detect unwanted or malicious activity from computer networks. Reference: https://www.cisco.com/c/dam/en_us/about/doing_business/legal/service_descriptions/docs/activethreat-analytics-premier.pdf

 

NEW QUESTION 33
Which type of dashboard does Cisco DNA Center provide for complete control of the network?

  • A. application management
  • B. distributed management
  • C. service management
  • D. centralized management

Answer: D

Explanation:
Cisco's DNA Center is the only centralized network management system to bring all of this functionality into a single pane of glass.
Reference:
dna-center-faq-cte-en.html

 

NEW QUESTION 34
Which two fields are defined in the NetFlow flow? (Choose two)

  • A. Layer 4 protocol type
  • B. output logical interface
  • C. destination port
  • D. class of service bits
  • E. type of service byte

Answer: C,E

Explanation:
Explanation
Explanation
Cisco standard NetFlow version 5 defines a flow as a unidirectional sequence of packets that all share seven values which define a unique key for the flow:
+ Ingress interface (SNMP ifIndex)
+ Source IP address
+ Destination IP address
+ IP protocol
+ Source port for UDP or TCP, 0 for other protocols
+ Destination port for UDP or TCP, type and code for ICMP, or 0 for other protocols
+ IP Type of Service
Note: A flow is a unidirectional series of packets between a given source and destination.

 

NEW QUESTION 35
In a PaaS model, which layer is the tenant responsible for maintaining and patching?

  • A. virtual machine
  • B. application
  • C. network
  • D. hypervisor

Answer: B

 

NEW QUESTION 36
Drag and drop the Firepower Next Generation Intrustion Prevention System detectors from the left onto the correct definitions on the right.

Answer:

Explanation:

 

NEW QUESTION 37
Which exfiltration method does an attacker use to hide and encode data inside DNS requests and queries?

  • A. DNSSEC
  • B. DNS security
  • C. DNSCrypt
  • D. DNS tunneling

Answer: D

Explanation:
Explanation/Reference: https://learn-umbrella.cisco.com/cloud-security/dns-tunneling

 

NEW QUESTION 38
Which cloud service model offers an environment for cloud consumers to develop and deploy applications without needing to manage or maintain the underlying cloud infrastructure?

  • A. XaaS
  • B. IaaS
  • C. SaaS
  • D. PaaS

Answer: D

Explanation:
Cloud computing can be broken into the following three basic models:
+ Infrastructure as a Service (IaaS): IaaS describes a cloud solution where you are renting infrastructure. You purchase virtual power to execute your software as needed. This is much like running a virtual server on your own equipment, except you are now running a virtual server on a virtual disk. This model is similar to a utility company model because you pay for what you use.
+ Platform as a Service (PaaS): PaaS provides everything except applications. Services provided by this model include all phases of the system development life cycle (SDLC) and can use application programming interfaces (APIs), website portals, or gateway software. These solutions tend to be proprietary, which can cause problems if the customer moves away from the provider's platform.
+ Software as a Service (SaaS): SaaS is designed to provide a complete packaged solution. The software is rented out to the user. The service is usually provided through some type of front end or web portal. While the end user is free to use the service from anywhere, the company pays a peruse fee.

 

NEW QUESTION 39
Which cloud model is a collaborative effort where infrastructure is shared and jointly accessed by several organizations from a specific group?

  • A. Public
  • B. Private
  • C. Community
  • D. Hybrid

Answer: C

Explanation:
Community Cloud allows system and services to be accessible by group of organizations. It shares the infrastructure between several organizations from a specific community. It may be managed internally by organizations or by the third-party.

 

NEW QUESTION 40
Drag and drop the suspicious patterns for the Cisco Tetration platform from the left onto the correct definitions on the right.

Answer:

Explanation:

 

NEW QUESTION 41
An organization is using Cisco Firepower and Cisco Meraki MX for network security and needs to centrally manage cloud policies across these platforms. Which software should be used to accomplish this goal?

  • A. Cisco Defense Orchestrator
  • B. Cisco DNA Center
  • C. Cisco Secureworks
  • D. Cisco Configuration Professional

Answer: A

Explanation:
Explanation Explanation Cisco Defense Orchestrator is a cloud-based management solution that allows you to manage security policies and device configurations with ease across multiple Cisco and cloud-native security platforms. Cisco Defense Orchestrator features: .... Management of hybrid environments: Managing a mix of firewalls running the ASA, FTD, and Meraki MX software is now easy, with the ability to share policy elements across platforms. Reference: https://www.cisco.com/c/en/us/products/collateral/security/defense-orchestrator/datasheet-c78- 736847.html Explanation Cisco Defense Orchestrator is a cloud-based management solution that allows you to manage security policies and device configurations with ease across multiple Cisco and cloud-native security platforms.
Cisco Defense Orchestrator features:
....
Management of hybrid environments: Managing a mix of firewalls running the ASA, FTD, and Meraki MX software is now easy, with the ability to share policy elements across platforms.
Reference:
Explanation Explanation Cisco Defense Orchestrator is a cloud-based management solution that allows you to manage security policies and device configurations with ease across multiple Cisco and cloud-native security platforms. Cisco Defense Orchestrator features: .... Management of hybrid environments: Managing a mix of firewalls running the ASA, FTD, and Meraki MX software is now easy, with the ability to share policy elements across platforms. Reference: https://www.cisco.com/c/en/us/products/collateral/security/defense-orchestrator/datasheet-c78- 736847.html

 

NEW QUESTION 42
Which functions of an SDN architecture require southbound APIs to enable communication?

  • A. management console and the SDN controller
  • B. SDN controller and the cloud
  • C. management console and the cloud
  • D. SDN controller and the network elements

Answer: D

Explanation:
The Southbound API is used to communicate between Controllers and network devices

 

NEW QUESTION 43
A network engineer has entered the snmp-server user andy myv3 auth sha cisco priv aes 256 cisc0380739941 command and needs to send SNMP information to a host at 10.255.254.1. Which command achieves this goal?

  • A. snmp-server host inside 10.255.254.1 snmpv3 andy
  • B. snmp-server host inside 10.255.254.1 version 3 andy
  • C. snmp-server host inside 10.255.254.1 version 3 myv3
  • D. snmp-server host inside 10.255.254.1 snmpv3 myv3

Answer: B

Explanation:
The command "snmp-server user user-name group-name [remote ip-address [udp-port port]] {v1 | v2c | v3 [encrypted] [auth {md5 | sha} auth-password]} [access access-list]" adds a new user (in this case "andy") to an SNMPv3 group (in this case group name "myv3") and configures a password for the user.
In the "snmp-server host" command, we need to:
+ Specify the SNMP version with key word "version {1 | 2 | 3}"
+ Specify the username ("andy"), not group name ("myv3").
Note: In "snmp-server host inside ..." command, "inside" is the interface name of the ASA interface through which the NMS (located at 10.255.254.1) can be reached.

 

NEW QUESTION 44
A user has a device in the network that is receiving too many connection requests from multiple machines. Which type of attack is the device undergoing?

  • A. phishing
  • B. SYN flood
  • C. pharming
  • D. slowloris

Answer: B

Explanation:
Reference:
https://www.cisco.com/c/en/us/products/security/what-is-a-ddos-attack.html#~types-of-ddos-attacks

 

NEW QUESTION 45
What is the primary difference between an Endpoint Protection Platform and an Endpoint Detection and Response?

  • A. EPP focuses on network security, and EDR focuses on device security.
  • B. EDR focuses on network security, and EPP focuses on device security.
  • C. EPP focuses on prevention, and EDR focuses on advanced threats that evade perimeter defenses.
  • D. EDR focuses on prevention, and EPP focuses on advanced threats that evade perimeter defenses.

Answer: C

Explanation:
Explanation/Reference: https://www.cisco.com/c/en/us/products/security/endpoint-security/what-is-endpoint-detection- response-edr.html

 

NEW QUESTION 46
What does the Cloudlock Apps Firewall do to mitigate security concerns from an application perspective?

  • A. It discovers and controls cloud apps that are connected to a company's corporate environment.
  • B. It deletes any application that does not belong in the network.
  • C. It sends the application information to an administrator to act on.
  • D. It allows the administrator to quarantine malicious files so that the application can function, just not maliciously.

Answer: A

 

NEW QUESTION 47
When wired 802.1X authentication is implemented, which two components are required? (Choose two.)

  • A. authenticator: Cisco Identity Services Engine
  • B. authentication server: Cisco Prime Infrastructure
  • C. supplicant: Cisco AnyConnect ISE Posture module
  • D. authenticator: Cisco Catalyst switch
  • E. authentication server: Cisco Identity Service Engine

Answer: D,E

 

NEW QUESTION 48
What is the benefit of installing Cisco AMP for Endpoints on a network?

  • A. It provides flow-based visibility for the endpoints' network connections.
  • B. It enables behavioral analysis to be used for the endpoints.
  • C. It provides operating system patches on the endpoints for security.
  • D. It protects endpoint systems through application control and real-time scanning.

Answer: D

Explanation:
https://www.cisco.com/c/en/us/solutions/collateral/enterprise-networks/advanced-malware-protection/at-a-glance-c45-731874.html

 

NEW QUESTION 49
An organization received a large amount of SPAM messages over a short time period. In order to take action on the messages, it must be determined how harmful the messages are and this needs to happen dynamically. What must be configured to accomplish this?

  • A. Configure the Cisco ESA to modify policies based on the traffic seen.
  • B. Configure the Cisco ESA to receive real-time updates from Talos
  • C. Configure the Cisco WSA to receive real-time updates from Talos.
  • D. Configure the Cisco WSA to modify policies based on the traffic seen.

Answer: D

Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/esa/esa120/user_guide/b_ESA_Admin_Guide_12_0/b_ESA_Admin_Guide_chapter_01100.html

 

NEW QUESTION 50
Drag and drop the Firepower Next Generation Intrustion Prevention System detectors from the left onto the correct definitions on the right.

Answer:

Explanation:

 

NEW QUESTION 51
Which two behavioral patterns characterize a ping of death attack? (Choose two.)

  • A. Short synchronized bursts of traffic are used to disrupt TCP connections.
  • B. The attack is fragmented into groups of 16 octets before transmission.
  • C. Publicly accessible DNS servers are typically used to execute the attack.
  • D. Malformed packets are used to crash systems.
  • E. The attack is fragmented into groups of 8 octets before transmission.

Answer: D,E

 

NEW QUESTION 52
Refer to the exhibit.

What is a result of the configuration?

  • A. Traffic from the DMZ network is redirected
  • B. All TCP traffic is redirected
  • C. Traffic from the inside and DMZ networks is redirected
  • D. Traffic from the inside network is redirected

Answer: C

 

NEW QUESTION 53
Which service allows a user export application usage and performance statistics with Cisco Application Visibility and control?

  • A. SNORT
  • B. SNMP
  • C. NetFlow
  • D. 802.1X

Answer: C

 

NEW QUESTION 54
A network administrator is using the Cisco ESA with AMP to upload files to the cloud for analysis. The network is congested and is affecting communication. How will the Cisco ESA handle any files which need analysis?

  • A. The ESA immediately makes another attempt to upload the file.
  • B. The file is queued for upload when connectivity is restored.
  • C. The file upload is abandoned.
  • D. AMP calculates the SHA-256 fingerprint, caches it, and periodically attempts the upload.

Answer: D

Explanation:

https://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/118796-technote-esa-00.html

 

NEW QUESTION 55
......

350-701 Dumps - Pass Your Certification Exam: https://www.exams4sures.com/Cisco/350-701-practice-exam-dumps.html

Free Sales Ending Soon - Use Real  350-701 PDF Questions: https://drive.google.com/open?id=1t5zKOHK91Homq-7kENs32IdMdl2asoiQ