Use the best ways of preparing for 350-701 Exam Dumps with PracticeTorrent Cisco 350-701 dump PDF [2021]
Cisco 350-701 exam candidates will surely pass the Exam if they consider the 350-701 dumps learning material presented by PracticeTorrent.
NEW QUESTION 49
An organization has two systems in their DMZ that have an unencrypted link between them for communication. The organization does not have a defined password policy and uses several default accounts on the systems. The application used on those systems also have not gone through stringent code reviews. Which vulnerability would help an attacker brute force their way into the systems?
- A. weak passwords
- B. lack of file permission
- C. lack of input validation
- D. missing encryption
Answer: D
NEW QUESTION 50
Refer to the exhibit.
Which type of authentication is in use?
- A. external user and relay mail authentication
- B. SMTP relay server authentication
- C. LDAP authentication for Microsoft Outlook
- D. POP3 authentication
Answer: C
NEW QUESTION 51
A customer has various external HTTP resources available including Intranet Extranet and Internet, with a proxy configuration running in explicit mode. Which method allows the client desktop browsers to be configured to select when to connect direct or when to use the proxy?
- A. Transport mode
- B. Bridge mode
- C. Forward file
- D. PAC file
Answer: A
NEW QUESTION 52
Which form of attack is launched using botnets?
- A. TCP flood
- B. DDOS
- C. EIDDOS
- D. virus
Answer: B
Explanation:
Explanation
A botnet is a collection of internet-connected devices infected by malware that allow hackers to control them.
Cyber criminals use botnets to instigate botnet attacks, which include malicious activities such as credentials leaks, unauthorized access, data theft and DDoS attacks.
NEW QUESTION 53
Refer to the exhibit.
Which command was used to generate this output and to show which ports are authenticating with dot1x or mab?
- A. show authentication registrations
- B. show dot1x all
- C. show authentication method
- D. show authentication sessions
Answer: B
NEW QUESTION 54
A Cisco ESA administrator has been tasked with configuring the Cisco ESA to ensure there are no viruses before quarantined emails are delivered. In addition, delivery of mail from known bad mail servers must be prevented. Which two actions must be taken in order to meet these requirements? (Choose two)
- A. Deploy the Cisco ESA in the DMZ
- B. Use outbreak filters from SenderBase
- C. Scan quarantined emails using AntiVirus signatures.
- D. Configure a recipient access table
- E. Enable a message tracking service
Answer: B,C
Explanation:
We should scan emails using AntiVirus signatures to make sure there are no viruses attached in emails.
Note: A virus signature is the fingerprint of a virus. It is a set of unique data, or bits of code, that allow it to be identified. Antivirus software uses a virus signature to find a virus in a computer file system, allowing to detect, quarantine, and remove the virus.
SenderBase is an email reputation service designed to help email administrators research senders, identify legitimate sources of email, and block spammers. When the Cisco ESA receives messages from known or highly reputable senders, it delivers them directly to the end user without any content scanning. However, when the Cisco ESA receives email messages from unknown or less reputable senders, it performs antispam and antivirus scanning.
Reference:
/b_ESA_Admin_Guide_12_0/b_ESA_Admin_Guide_12_0_chapter_0100100.html
NEW QUESTION 55
An organization uses Cisco FMC to centrally manage multiple Cisco FTD devices The default management port conflicts with other communications on the network and must be changed What must be done to ensure that all devices can communicate together?
- A. Change the management port on Cisco FMC so that it pushes the change to all managed Cisco FTD devices
- B. Set the sftunnel to go through the Cisco FTD
- C. Set the sftunnel port to 8305
- D. Manually change the management port on Cisco FMC and all managed Cisco FTD devices
Answer: A
NEW QUESTION 56
What is the benefit of installing Cisco AMP for Endpoints on a network?
- A. It provides operating system patches on the endpoints for security.
- B. It protects endpoint systems through application control and real-time scanning.
- C. It provides flow-based visibility for the endpoints' network connections.
- D. It enables behavioral analysis to be used for the endpoints.
Answer: B
Explanation:
Reference:
https://www.cisco.com/c/en/us/solutions/collateral/enterprise-networks/advanced-malware-protection/at-a-glance-c45-731874.html
NEW QUESTION 57
What is the purpose of the certificate signing request when adding a new certificate for a server?
- A. It provides the server information so a certificate can be created and signed
- B. It is the certificate that will be loaded onto the server
- C. It is the password for the certificate that is needed to install it with.
- D. It provides the certificate client information so the server can authenticate against it when installing
Answer: A
Explanation:
Explanation
https://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_man_cert.html
NEW QUESTION 58
An attacker needs to perform reconnaissance on a target system to help gain access to it. The system has weak passwords, no encryption on the VPN links, and software bugs on the system's applications. Which vulnerability allows the attacker to see the passwords being transmitted in clear text?
- A. weak passwords for authentication
- B. improper file security
- C. software bugs on applications
- D. unencrypted links for traffic
Answer: D
Explanation:
Explanation
https://www.cisco.com/ELearning/bulk/public/celc/CRS/media/targets/resources_mod07/7_3_5_improving_secu
NEW QUESTION 59
Refer to the exhibit.
A network administrator configures command authorization for the admm5 user. What is the admin5 user able to do on HQ_Router after this configuration?
- A. add subinterfaces
- B. complete all configurations
- C. complete no configurations
- D. set the IP address of an interface
Answer: C
NEW QUESTION 60
What is the Cisco API-based broker that helps reduce compromises, application risks, and data breaches in an environment that is not on-premise?
- A. Cisco Umbrella
- B. Cisco App Dynamics
- C. Cisco Cloudlock
- D. Cisco AMP
Answer: C
Explanation:
Reference:
NEW QUESTION 61
An MDM provides which two advantages to an organization with regards to device management? (Choose two.)
- A. asset inventory management
- B. critical device management
- C. Active Directory group policy management
- D. network device management
- E. allowed application management
Answer: A,E
Explanation:
Explanation
NEW QUESTION 62
Which feature is configured for managed devices in the device platform settings of the Firepower Management Center?
- A. network address translations
- B. time synchronization
- C. quality of service
- D. intrusion policy
Answer: B
NEW QUESTION 63
How does Cisco Workload Optimization Manager help mitigate application performance issues?
- A. It automates resource resizing.
- B. It optimizes a flow path
- C. It deploys an AWS Lambda system
- D. it sets up a workload forensic score
Answer: A
NEW QUESTION 64
Due to a traffic storm on the network, two interfaces were error-disabled, and both interfaces sent SNMP traps. Which two actions must be taken to ensure that interfaces are put back into service? (Choose two)
- A. Have Cisco Prime Infrastructure issue an SNMP set command to re-enable the ports after the preconfigured interval.
- B. Enter the shutdown and no shutdown commands on the interfaces.
- C. Enable the snmp-server enable traps command and wait 300 seconds
- D. Use EEM to have the ports return to service automatically in less than 300 seconds.
- E. Ensure that interfaces are configured with the error-disable detection and recovery feature You can also bring up the port by using these commands:
+ The "shutdown" interface configuration command followed by the "no shutdown" interface configuration command restarts the disabled port.
+ The "errdisable recovery cause ..." global configuration command enables the timer to automatically recover error-disabled state, and the "errdisable recovery interval interval" global configuration command specifies the time to recover error-disabled state.
Answer: B,E
NEW QUESTION 65
Which two features are used to configure Cisco ESA with a multilayer approach to fight viruses and malware? (Choose two).
- A. RAT
- B. white list
- C. DLP
- D. Sophos engine
- E. outbreak filters
Answer: D,E
NEW QUESTION 66
An organization wants to provide visibility and to identify active threats in its network using a VM. The organization wants to extract metadata from network packet flow while ensuring that payloads are not retained or transferred outside the network Which solution meets these requirements?
- A. Cisco Umbrella On-Premises
- B. Cisco Umbrella Cloud
- C. Cisco Stealthwatch Cloud PCM
- D. Cisco Stealthwatch Cloud PNM
Answer: B
NEW QUESTION 67
Drag and drop the descriptions from the left onto the correct protocol versions on the right.
Answer:
Explanation:
Explanation
NEW QUESTION 68
What does Cisco AMP for Endpoints use to help an organization detect different families of malware?
- A. Ethos Engine to perform fuzzy fingerprinting
- B. Clam AV Engine to perform email scanning
- C. Tetra Engine to detect malware when me endpoint is connected to the cloud
- D. Spero Engine with machine learning to perform dynamic analysis
Answer: A
Explanation:
Explanation
ETHOS is the Cisco file grouping engine. It allows us to group families of files together so if we see variants of a malware, we mark the ETHOS hash as malicious and whole families of malware are instantly detected.
Reference:
ETHOS = Fuzzy Fingerprinting using static/passive heuristics
NEW QUESTION 69
A network administrator is using the Cisco ESA with AMP to upload files to the cloud for analysis. The network is congested and is affecting communication. How will the Cisco ESA handle any files which need analysis?
- A. The ESA immediately makes another attempt to upload the file.
- B. The file upload is abandoned.
- C. The file is queued for upload when connectivity is restored.
- D. AMP calculates the SHA-256 fingerprint, caches it, and periodically attempts the upload.
Answer: B
Explanation:
Explanation The appliance will try once to upload the file; if upload is not successful, for example because of connectivity problems, the file may not be uploaded. If the failure was because the file analysis server was overloaded, the upload will be attempted once more. Reference: https://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/118796-technoteesa-00.html In this question, it stated "the network is congested" (not the file analysis server was overloaded) so the appliance will not try to upload the file again.
The appliance will try once to upload the file; if upload is not successful, for example because of connectivity problems, the file may not be uploaded. If the failure was because the file analysis server was overloaded, the upload will be attempted once more.
Reference:
In this question, it stated "the network is congested" (not the file analysis server was overloaded) so the Explanation The appliance will try once to upload the file; if upload is not successful, for example because of connectivity problems, the file may not be uploaded. If the failure was because the file analysis server was overloaded, the upload will be attempted once more. Reference: https://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/118796-technoteesa-00.html In this question, it stated "the network is congested" (not the file analysis server was overloaded) so the appliance will not try to upload the file again.
NEW QUESTION 70
Drag and drop the NetFlow export formats from the left onto the descriptions on the right.
Answer:
Explanation:
NEW QUESTION 71
Which Cisco platform ensures that machines that connect to organizational networks have the recommended antivirus definitions and patches to help prevent an organizational malware outbreak?
- A. Cisco WiSM
- B. Cisco ISE
- C. Cisco ESA
- D. Cisco Prime Infrastructure
Answer: B
Explanation:
Explanation
A posture policy is a collection of posture requirements, which are associated with one or more identity groups, and operating systems. We can configure ISE to check for the Windows patch at Work Centers > Posture > Posture Elements > Conditions > File.
In this example, we are going to use the predefined file check to ensure that our Windows 10 clients have the critical security patch installed to prevent the Wanna Cry malware; and we can also configure ISE to update the client with this patch.
NEW QUESTION 72
Which IPS engine detects ARP spoofing?
- A. Atomic ARP Engine
- B. Service Generic Engine
- C. AIC Engine
- D. ARP Inspection Engine
Answer: A
NEW QUESTION 73
......
Full 350-701 Practice Test and 330 unique questions with explanations waiting just for you, get it now: https://drive.google.com/open?id=1jZDCZeBl5huiTsn3mxZ1aGDFMM6itliY
Accurate & Verified Answers As Seen in the Real Exam here: https://www.practicetorrent.com/350-701-practice-exam-torrent.html