首页 > 题库 > 350-701
« 返回题库列表

2026 思科CCNP 350-701 SCOR历年真题与题库解析|安全核心考试备考资料汇总

问题 #1
Which standard is used to automate exchanging cyber threat information?
A. STIX
B. IoC
C. MITRE
D. TAXII
正确答案:D
问题 #2
An engineer adds a custom detection policy to a Cisco AMP deployment and encounters issues with the configuration. The simple detection mechanism is configured, but the dashboard indicates that the hash is not 64 characters and is non-zero. What is the is
A. The hash being uploaded is part of a set in an incorrect format.
B. The engineer is attempting to upload a hash created using MD5 instead of SHA-256.
C. The file being uploaded is incompatible with simple detections and must use advanced detections.
D. The engineer is attempting to upload a file instead of a hash.
正确答案:B
问题 #3
Which two services must remain as on premises equipment when a hybrid email solution is deployed? (Choose two.)
A. DLP
B. antivirus
C. antispam
D. DDoS
E. Encryption
正确答案:AE
问题 #4
An organization has a Cisco Secure Cloud Analytics deployment in their environment. Cloud logging is working as expected, but logs are not being received from the on-premise network. What action will resolve this issue?
A. Deploy a Cisco Stealthwatch Cloud sensor on the network to send data to Cisco Stealthwatch Cloud.
B. Configure security appliances to send syslogs to Cisco Stealthwatch Cloud.
C. Deploy a Cisco FTD sensor to send events to Cisco Stealthwatch Cloud.
D. Configure security appliances to send NetFlow to Cisco Stealthwatch Cloud.
正确答案:A
问题 #5
Which two solutions help combat social engineering and phishing at the endpoint level? (Choose two.)
A. Cisco Umbrella
B. Cisco ISE
C. Cisco Duo Security
D. Cisco DNA Center
E. Cisco TrustSec
正确答案:AC
问题 #6
What are two characteristics of the RESTful architecture used within Cisco DNA Center? (Choose two.)
A. REST is a Linux platform-based architecture.
B. REST uses HTTP to send a request to a web service.
C. REST uses methods such as GET, PUT, POST, and DELETE.
D. REST codes can be compiled with any programming language.
E. The POST action replaces existing data at the URL path.
正确答案:BC
问题 #7
Which feature must be configured before implementing NetFlow on a router?
A. syslog
B. IP routing
C. SNMPv3
D. VRF
正确答案:B
问题 #8
Which capability is provided by application visibility and control?
A. data encryption
B. deep packet inspection
C. reputation filtering
D. data obfuscation
正确答案:B
问题 #9
Which solution protects hybrid cloud deployment workloads with application visibility and segmentation?
A. Nexus
B. Secure Network Analytics
C. Secure Firewall
D. Secure Workload
正确答案:D
问题 #10
An organization is using CSR1000 routers in their private cloud infrastructure. They must upgrade their code to address vulnerabilities within their running code version. Who is responsible for these upgrades?
A. The organization must update the code for the devices they manage.
B. The CSR1000v is upgraded automatically as new code becomes available.
C. The cloud service provider must be asked to perform the upgrade.
D. The cloud vendor is responsible for updating all code hosted in the cloud.
正确答案:A
问题 #11
Which action must be taken in the AMP for Endpoints console to detect specific MD5 signatures on endpoints and then quarantine the files?
A. Configure an advanced custom detection list.
B. Configure a simple custom detection list.
C. Configure an application custom detection list.
D. Configure an IP Block & Allow custom detection list.
正确答案:A
问题 #12
Which function is included when Cisco AMP is added to web security?
A. multifactor, authentication-based user identity
B. phishing detection on emails
C. threat prevention on an infected endpoint
D. detailed analytics of the unknown file's behavior
正确答案:D
问题 #13
Which DoS attack uses fragmented packets in an attempt to crash a target machine?
A. SYN flood
B. LAND
C. smurf
D. teardrop
正确答案:D
问题 #14
Which feature is used in a push model to allow for session identification, host reauthentication, and session termination?
A. AV pair
B. CoA request
C. carrier-grade NAT
D. AAA attributes
正确答案:B
问题 #15
Which configuration method provides the option to prevent physical and virtual endpoint devices that are in the same base EPG or uSeg from being able to communicate with each other with VMware VDS or Microsoft vSwitch?
A. placement in separate EPGs
B. inter-VLAN security
C. inter-EPG isolation
D. intra-EPG isolation
正确答案:D
问题 #16
Which two features are used to configure Cisco ESA with a multilayer approach to fight viruses and malware? (Choose two.)
A. Sophos engine
B. RAT
C. DLP
D. outbreak filters
E. white list
正确答案:AD
问题 #17
Which VMware platform does Cisco ACI integrate with to provide enhanced visibility, provide policy integration and deployment, and implement security policies with access lists?
A. VMware horizons
B. VMware fusion
C. VMware APIC
D. VMware vRealize
正确答案:D
问题 #18
An organization is trying to implement micro-segmentation on the network and wants to be able to gain visibility on the applications within the network. The solution must be able to maintain and force compliance. Which product should be used to meet these
A. Cisco Secure Network Analytics
B. Cisco AMP
C. Cisco Umbrella
D. Cisco Secure Workload
正确答案:D
问题 #19
An administrator configures a new destination list in Cisco Umbrella so that the organization can block specific domains for its devices. What should be done to ensure that all subdomains of domain.com are blocked?
A. Configure the domain.com address in the block list.
B. Configure the *.domain.com address in the block list.
C. Configure the *.com address in the block list.
D. Configure the *domain.com address in the block list.
正确答案:A
问题 #20
Which two activities are performed using Cisco DNA Center? (Choose two.)
A. provision
B. DNS
C. accounting
D. design
E. DHCP
正确答案:AD
问题 #21
An engineer enabled SSL decryption for Cisco Umbrella intelligent proxy and needs to ensure that traffic is inspected without alerting end-users. Which action accomplishes this goal?
A. Modify the user's browser settings to suppress errors from Umbrell
A.
B. Restrict access to only websites with trusted third-party signed certificates.
C. Upload the organization root CA to the Umbrella admin portal.
D. Import the Umbrella root CA into the trusted root store on the user's device.
正确答案:D
问题 #22
Which feature only implements on the Cisco ASA in the transparent mode?
A. inspect anycast traffic
B. inspect traffic between hosts in the same subnet
C. stateful inspection
D. inspect application layer of the traffic sent between hosts
正确答案:B
问题 #23
What is the term for the concept of limiting communication between applications or containers on the same node?
A. microservicing
B. microsegmentation
C. container orchestration
D. software-defined access
正确答案:B
问题 #24
An organization has noticed an increase in malicious content downloads and wants to use Cisco Umbrella to prevent this activity for suspicious domains while allowing normal web traffic. Which action will accomplish this task?
A. Use destination block lists.
B. Configure application block lists.
C. Set content settings to High.
D. Configure the intelligent proxy.
正确答案:D
问题 #25
Which product allows Cisco FMC to push security intelligence observables to its sensors from other products?
A. Cognitive Threat Analytics
B. Threat Intelligence Director
C. Encrypted Traffic Analytics
D. Cisco Talos Intelligence
正确答案:B
问题 #26
Why should organizations migrate to a multifactor authentication strategy?
A. Multifactor authentication methods of authentication are never compromised.
B. Single methods of authentication can be compromised more easily than multifactor authentication.
C. Biometrics authentication leads to the need for multifactor authentication due to its ability to be hacked easily.
D. Multifactor authentication does not require any piece of evidence for an authentication mechanism.
正确答案:B
问题 #27
A network engineering team wants to configure web reputation URL filtering in Cisco vManage by setting the web reputation to Moderate Risk. Which reputation score must be configured in vManage for the URL filtering?
A. 40
B. 60
C. 65
D. 80
正确答案:B
问题 #28
An engineer is onboarding a teleworker to Cisco Umbrella. After the worker's home network identity is configured, which additional action must be taken to complete the network registration?
A. Point the home modem DHCP to Cisco Umbrella DHCP.
B. Set up a point-to-point VPN with the head-office.
C. Point the home modem DNS to Cisco Umbrella DNS.
D. Change the public IP addresses from static to dynamic.
正确答案:C
问题 #29
Which flaw does an attacker leverage when exploiting SQL injection vulnerabilities?
A. web page images
B. Linux and Windows operating systems
C. user input validation in a web page or web application
D. database
正确答案:C
问题 #30
Which two behavioral patterns characterize a ping of death attack? (Choose two.)
A. The attack is fragmented into groups of 8 octets before transmission.
B. The attack is fragmented into groups of 16 octets before transmission.
C. Short synchronized bursts of traffic are used to disrupt TCP connections.
D. Publicly accessible DNS servers are typically used to execute the attack.
E. Malformed packets are used to crash systems.
正确答案:AE
问题 #31
An email administrator is setting up a new Cisco ESA. The administrator wants to enable the blocking of greymail for the end user. Which feature must the administrator enable first?
A. IP Reputation Filtering
B. Anti-Virus Filtering
C. File Analysis
D. Intelligent Multi-Scan
正确答案:D
问题 #32
What is a benefit of using telemetry over SNMP to configure new routers for monitoring purposes?
A. Telemetry uses a pull method, which makes it more reliable than SNMP.
B. Telemetry uses a push method, which makes it faster than SNMP.
C. Telemetry uses push and pull, which makes it more secure than SNMP.
D. Telemetry uses push and pull, which makes it more scalable than SNMP.
正确答案:B
问题 #33
Which two capabilities does TAXII support? (Choose two.)
A. correlation
B. pull messaging
C. exchange
D. mitigating
E. binding
正确答案:BC
问题 #34
What are two functionalities of northbound and southbound APIs within Cisco SDN architecture? (Choose two.)
A. Southbound APIs are used to define how SDN controllers integrate with applications.
B. Southbound interfaces utilize device configurations such as VLANs and IP addresses.
C. Southbound APIs utilize CLI, SNMP, and RESTCONF.
D. Northbound interfaces utilize OpenFlow and OpFlex to integrate with network devices.
E. Northbound APIs utilize RESTful API methods such as GET, POST, and DELETE.
正确答案:CE
问题 #35
What is a description of microsegmentation?
A. Environments deploy a container orchestration platform, such as Kubernetes, to manage the application delivery.
B. Environments implement private VLAN segmentation to group servers with similar applications.
C. Environments deploy centrally managed host-based firewall rules on each server or container.
D. Environments apply a zero-trust model and specify how applications on different servers or containers can communicate.
正确答案:D
问题 #36
An engineer has been tasked with configuring a Cisco FTD to analyze protocol fields and detect anomalies in the traffic from industrial systems. What must be done to meet these requirements?
A. Enable traffic analysis in the Cisco FTD.
B. Modify the access control policy to trust the industrial traffic.
C. Implement pre-filter policies for the CIP preprocessor.
D. Configure intrusion rules for the DNP3 preprocessor.
正确答案:D
问题 #37
Which two deployment model configurations are supported for Cisco FTDv in AWS? (Choose two.)
A. Cisco FTDv configured in routed mode and IPv6 configured
B. Cisco FTDv with two management interfaces and one traffic interface configured
C. Cisco FTDv configured in routed mode and managed by a physical FMC appliance on premises
D. Cisco FTDv with one management interface and two traffic interfaces configured
E. Cisco FTDv configured in routed mode and managed by an FMCv installed in AWS
正确答案:CE
问题 #38
For a given policy in Cisco Umbrella, how should a customer block websites based on a custom list?
A. by adding the websites to a blocked type destination list
B. by specifying blocked domains in the policy settings
C. by specifying the websites in a custom blocked category
D. by adding the website IP addresses to the Cisco Umbrella blocklist
正确答案:A
问题 #39
Which action adds IOCs to customize detections for a new attack?
A. Use the Initiate Endpoint IOC scan feature to gather the IOC information and push it to clients.
B. Upload the IOCs into the Installed Endpoint IOC feature within Cisco AMP for Endpoints.
C. Modify the base policy within Cisco AMP for Endpoints to include simple custom detections.
D. Add a custom advanced detection to include the IOCs needed within Cisco AMP for Endpoints.
正确答案:B
问题 #40
An engineer is configuring Cisco WSA and needs to enable a separated email transfer flow from the Internet and from the LAN. Which deployment mode must be used to accomplish this goal?
A. multi-context
B. single interface
C. transparent
D. two-interface
正确答案:D
问题 #41
An administrator is adding a new Cisco ISE node to an existing deployment. What must be done to ensure that the addition of the node will be successful when inputting the FQDN?
A. Add the DNS entry for the new Cisco ISE node into the DNS server.
B. Open port 8905 on the firewall between the Cisco ISE nodes.
C. Change the IP address of the new Cisco ISE node to the same network as the others.
D. Make the new Cisco ISE node a secondary PAN before registering it with the primary.
正确答案:A
问题 #42
Which two endpoint measures are used to minimize the chances of falling victim to phishing and social engineering attacks? (Choose two.)
A. Perform backups to the private cloud.
B. Patch for cross site scripting.
C. Install a spam and virus email filter.
D. Protect systems with an up-to-date antimalware program.
E. Protect against input validation and character escapes in the endpoint.
正确答案:CD
问题 #43
Which two algorithms must be used when an engineer is creating a connection that will have classified data across it? (Choose two.)
A. ECDSA-256
B. AES-256
C. SHA-384
D. RC4
E. RSA-3072
正确答案:BC
问题 #44
Which IETF attribute is supported for the RADIUS CoA feature?
A. 81 Message-Authenticator
B. 42 Acct-Session-ID
C. 24 State
D. 30 Calling-Station-ID
正确答案:C
问题 #45
A company identified a phishing vulnerability during a pentest. What are two ways the company can protect employees from the attack? (Choose two.)
A. using Cisco FTD
B. using Cisco ESA
C. using Cisco Umbrella
D. using an inline IPS/IDS in the network
E. using Cisco ISE
正确答案:BC
问题 #46
Which feature is supported when deploying Cisco ASAv within the AWS public cloud?
A. user deployment of Layer 3 networks
B. clustering
C. multiple context mode
D. IPv6
正确答案:A
问题 #47
When web policies are configured in Cisco Umbrella, what provides the ability to ensure that domains are blocked when they host malware, command and control, phishing, and more threats?
A. Security Category Blocking
B. File Analysis
C. Application Control
D. Content Category Blocking
正确答案:A
问题 #48
An engineer configures new features within the Cisco Umbrella dashboard and wants to identify and proxy traffic that is categorized as risky domains and may contain safe and malicious content. Which action accomplishes these objectives?
A. Configure URL filtering within Cisco Umbrella to track the URLs and proxy the requests for those categories and below.
B. Configure intelligent proxy within Cisco Umbrella to intercept and proxy the requests for only those categories.
C. Create a new site within Cisco Umbrella to block requests from those categories so they can be sent to the proxy device.
D. Upload the threat intelligence database to Cisco Umbrella for the most current information on reputations and to have the destination lists block them.
正确答案:B
问题 #49
An engineer needs to configure cloud logging on Cisco ASA with SAL integration. Which parameter must be considered for this configuration?
A. All CSM versions are supported.
B. Onboard Cisco ASA device to CDO is needed.
C. Events can be viewed only from one regional cloud.
D. Required storage size can be allocated dynamically.
正确答案:B
问题 #50
What is a difference between encrypted passwords and hardcoded passwords?
A. Encrypted passwords are generated by an application user, and hardcoded passwords are generated randomly.
B. Encrypted passwords are stored in a database, and hardcoded passwords are embedded in the source code.
C. Encrypted passwords are easier to obtain, and hardcoded passwords are known only to developers.
D. Encrypted passwords are used for frontend applications, and hardcoded passwords are used for backend applications.
正确答案:B
问题 #51
A network administrator needs a solution to match traffic and allow or deny the traffic based on the type of application, not just the source or destination address and port used. Which kind of security product must the network administrator implement to
A. next-generation firewall
B. web application firewall
C. intrusion detection system
D. next-generation intrusion prevention system
正确答案:D
问题 #52
A security engineer must add destinations into a destination list in Cisco Umbrella. What describes the application of these changes?
A. The changes are applied only after the configuration is saved in Cisco Umbrell
A.
B. The destination list must be removed from the policy before changes are made to it.
C. The changes are applied immediately if the destination list is part of a policy.
D. The user role of Block Page Bypass or higher is needed to perform these changes.
正确答案:C
问题 #53
What is a feature of an endpoint detection and response solution?
A. ensuring the security of network devices by choosing which devices are allowed to reach the network
B. preventing attacks by identifying harmful events with machine learning and conduct-based defense
C. rapidly and consistently observing and examining data to mitigate threats
D. capturing and clarifying data on email, endpoints, and servers to mitigate threats
正确答案:C
问题 #54
Which file type is supported when performing a bulk upload of destinations into a destination list on Cisco Umbrella?
A. CSV
B. TXT
C. XLS
D. RTF
正确答案:B
问题 #55
What is the benefit of integrating Cisco ISE with an MDM solution?
A. It provides compliance checks for access to the network.
B. It provides the ability to add applications to the mobile device through Cisco ISE.
C. It provides the ability to update other applications on the mobile device.
D. It provides network device administration access.
正确答案:A
问题 #56
An engineer must configure a Cisco Secure Email Gateway to use DLP for a company. The company also wants to see the content of emails that violate the DLP policy. Which configuration must be modified in the Data Loss Prevention Settings section to meet th
A. DLP Message Action
B. Secure Reply All
C. Matched Content Logging
D. Secure Message Forwarding
正确答案:C
问题 #57
An organization has a Cisco Secure Cloud Analytics deployment in their environment. Cloud logging is working as expected, but logs are not being received from the on-premise network. What action will resolve this issue?
A. Deploy a Secure Cloud Analytics sensor on the network to send data to Secure Cloud Analytics.
B. Configure security appliances to send syslogs to Secure Cloud Analytics.
C. Deploy a Cisco FTD sensor to send events to Secure Cloud Analytics.
D. Configure security appliances to send NetFlow to Secure Cloud Analytics.
正确答案:A
问题 #58
What are the two types of managed Intercloud Fabric deployment models? (Choose two.)
A. Service Provider managed
B. User managed
C. Hybrid managed
D. Public managed
E. Enterprise managed
正确答案:AE
问题 #59
Which telemetry data captures variations seen within the flow, such as the packets TTL, IP/TCP flags, and payload length?
A. interpacket variation
B. process details variation
C. flow insight variation
D. software package variation
正确答案:A
问题 #60
Which API technology with SDN architecture is used to communicate with a controller and network devices such as routers and switches?
A. rest APIs
B. unprotected APIs
C. northbound APIs
D. southbound APIs
正确答案:D
问题 #61
What is a difference between GRE over IPsec and IPsec with crypto map?
A. GRE over IPsec supports non-IP protocols.
B. Multicast traffic is supported by IPsec with crypto map.
C. IPsec with crypto map offers better scalability.
D. GRE provides its own encryption mechanism.
正确答案:A
问题 #62
Which technology must be used to implement secure VPN connectivity among company branches over a private IP cloud with any-to-any scalable connectivity?
A. DMVPN
B. GET VPN
C. FlexVPN
D. IPsec DVTI
正确答案:B
问题 #63
An engineer must modify a policy to block specific addresses using Cisco Umbrella. The policy is created already and is actively used by devices, using many of the default policy elements. What else must be done to accomplish this task?
A. Modify the application settings to allow only applications to connect to required addresses.
B. Use content categories to block or allow specific addresses.
C. Create a destination list for addresses to be allowed or blocked.
D. Add the specified addresses to the identities list and create a block action.
正确答案:C
问题 #64
An organization uses Cisco FMC to centrally manage multiple Cisco FTD devices. The default management port conflicts with other communications on the network and must be changed. What must be done to ensure that all devices can communicate together?
A. Set the sftunnel to go through the Cisco FTD.
B. Change the management port on Cisco FMC so that it pushes the change to all managed Cisco FTD devices.
C. Set the sftunnel port to 8305.
D. Manually change the management port on Cisco FMC and all managed Cisco FTD devices.
正确答案:D
问题 #65
Which type of API is being used when a security application notifies a controller within a software-defined network architecture about a specific security threat?
A. westbound API
B. southbound API
C. eastbound API
D. northbound API
正确答案:D
问题 #66
What is a required prerequisite to enable malware file scanning for the Secure Internet Gateway?
A. Activate SSL decryption.
B. Enable IP Layer enforcement.
C. Enable Intelligent Proxy.
D. Activate the Advanced Malware Protection license.
正确答案:C
问题 #67
Which feature requires a network discovery policy on the Cisco Firepower NGIPS?
A. security intelligence
B. impact flags
C. URL filtering
D. health monitoring
正确答案:B
问题 #68
Which method must be used to connect Cisco Secure Workload to external orchestrators at a client site when the client does not allow incoming connections?
A. GRE tunnel
B. reverse tunnel
C. source NAT
D. destination NAT
正确答案:B
问题 #69
Which action configures the IEEE 802.1X Flexible Authentication feature to support Layer 3 authentication mechanisms?
A. Configure WebAuth so the hosts are redirected to a web page for authentication.
B. Add MAB into the switch to allow redirection to a Layer 3 device for authentication.
C. Modify the Dot1X configuration on the VPN server to send Layer 3 authentications to an external authentication database.
D. Identify the devices using this feature and create a policy that allows them to pass Layer 2 authentication.
正确答案:A
问题 #70
Which open standard creates a framework for sharing threat intelligence in a machine-digestible format?
A. CybOX
B. STIX
C. OpenC2
D. OpenIOC
正确答案:D
问题 #71
Which two probes are configured to gather attributes of connected endpoints using Cisco Identity Services Engine? (Choose two.)
A. DHCP
B. sFlow
C. SMTP
D. RADIUS
E. TACACS+
正确答案:AD
问题 #72
When wired 802.1X authentication is implemented, which two components are required? (Choose two.)
A. supplicant: Cisco AnyConnect ISE Posture module
B. authentication server: Cisco Prime Infrastructure
C. authenticator: Cisco Identity Services Engine
D. authenticator: Cisco Catalyst switch
E. authentication server: Cisco Identity Services Engine
正确答案:DE
问题 #73
What is a commonality between DMVPN and FlexVPN technologies?
A. FlexVPN and DMVPN use the new key management protocol, IKEv2.
B. IOS routers run the same NHRP code for DMVPN and FlexVPN.
C. FlexVPN and DMVPN use IS-IS routing protocol to communicate with spokes.
D. FlexVPN and DMVPN use the same hashing algorithms.
正确答案:B
问题 #74
A switch with Dynamic ARP Inspection enabled has received a spoofed ARP response on a trusted interface. How does the switch behave in this situation?
A. It drops the packet without validation.
B. It forwards the packet after validation by using the IP & MAC Binding Table.
C. It drops the packet after validation by using the IP & MAC Binding Table.
D. It forwards the packet without validation.
正确答案:D
问题 #75
An administrator has been tasked with configuring the Cisco Secure Email Gateway to ensure there are no viruses before quarantined emails are delivered. In addition, delivery of mail from known bad mail servers must be prevented. Which two actions must be
A. Use outbreak filters from SenderBase.
B. Scan quarantined emails using AntiVirus signatures.
C. Enable a message tracking service.
D. Configure a recipient access table.
E. Deploy the Cisco ESA in the DMZ.
正确答案:AB
问题 #76
An organization wants to use Cisco FTD or Cisco ASA devices. Specific URLs must be blocked from being accessed via the firewall, which requires that the administrator input the bad URL categories that the organization wants blocked into the access policy.
A. Cisco ASA because it includes URL filtering in the access control policy capabilities, whereas Cisco FTD does not.
B. Cisco FTD because it enables URL filtering and blocks malicious URLs by default, whereas Cisco ASA does not.
C. Cisco ASA because it enables URL filtering and blocks malicious URLs by default, whereas Cisco FTD does not.
D. Cisco FTD because it includes URL filtering in the access control policy capabilities, whereas Cisco ASA does not.
正确答案:D
问题 #77
A Cisco AMP for Endpoints administrator configures a custom detection policy to add specific MD5 signatures. The configuration is created in the simple detection policy section, but it does not work. What is the reason for this failure?
A. The administrator must upload the file instead of the hash for Cisco AMP to use.
B. The APK must be uploaded for the application that the detection is intended.
C. The MD5 hash uploaded to the simple detection policy is in the incorrect format.
D. Detections for MD5 signatures must be configured in the advanced custom detection policies.
正确答案:D
问题 #78
An organization wants to implement a cloud-delivered and SaaS based solution to provide visibility and threat detection across the AWS network. The solution must be deployed without software agents and rely on AWS VPC flow logs instead. Which solution mee
A. Cisco Umbrella
B. NetFlow collectors
C. Cisco Secure Cloud Analytics
D. Cisco Cloudlock
正确答案:C
问题 #79
Which solution for remote workers enables protection, detection, and response on the endpoint against known and unknown threats?
A. Cisco Umbrella
B. Cisco Secure Endpoint
C. Cisco Secure Client
D. Cisco Duo
正确答案:B
问题 #80
Which Cisco solution extends network visibility, threat detection, and analytics to public cloud environments?
A. Cisco CloudLock
B. Cisco Stealthwatch Cloud
C. Cisco Umbrella
D. Cisco AppDynamics
正确答案:B
问题 #81
When an assessment of cloud services and applications is conducted, which tool is used to show user activity and data usage across the applications?
A. Cisco ISE
B. Cisco AMP Private Cloud
C. Cisco CloudLock
D. Cisco ASA
正确答案:C
问题 #82
Which action blocks specific IP addresses whenever a computer with Cisco AMP for Endpoints installed connects to the network?
A. Create an advanced custom detection policy and add the IP addresses.
B. Create an application block list and add the IP addresses.
C. Create an IP Block & Allow list and add the IP addresses.
D. Create a simple custom detection policy and add the IP addresses.
正确答案:C
问题 #83
Which CLI command is used to enable URL filtering support for shortened URLs on the Cisco ESA?
A. websecurityconfig
B. webadvancedconfig
C. websecurityadvancedconfig
D. outbreakconfig
正确答案:C
问题 #84
A network administrator is shipping a Cisco ASA to a remote retail site. The administrator wants to ensure that the device configuration cannot be accessed by someone at the site with physical access and a console cable. Which command must be used to miti
A. config-register 0x00000041
B. no service password-recovery
C. aaa authentication console
D. no service sw-reset-button
正确答案:C
问题 #85
Which solution provides end-to-end visibility of applications and insights about application performance?
A. Cisco Secure Cloud Analytics
B. Cisco Secure Workload
C. Cisco AppDynamics
D. Cisco Cloudlock
正确答案:C
问题 #86
What is a capability of EPP compared to EDR?
A. EPP prevents attacks on a website, and EDR focuses on protecting computers and servers.
B. EPP prevents attacks on an endpoint, and EDR detects attacks that penetrate the environment.
C. EPP prevents attacks on an endpoint, and EDR focuses on protecting email and web servers.
D. EPP prevents attacks made via email, and EDR prevents attacks on a web server.
正确答案:B
问题 #87
How should an organization gain visibility into encrypted flows leaving the organization?
A. Add Cisco Secure Firewall IPS.
B. Enable a VPN for more sensitive dat
A.
C. Implement AAA for external users.
D. Decrypt and inspect the HTTPS traffic.
正确答案:D
问题 #88
How does a Cisco Secure Firewall help to lower the risk of exfiltration techniques that steal customer data?
A. blocking UDP port 53
B. blocking TCP port 53
C. encrypting the DNS communication
D. inspecting the DNS traffic
正确答案:D
问题 #89
An administrator is implementing management plane protection and must configure an interface on a Cisco router to only terminate management packets that are destined for the router. Which set of IOS commands must be used to complete the implementation?
A. #control-plane #management-plane #vrf network #interface GigabitEthernet 0/6 #allow protocol ssh #allow peer ssh
B. #control-plane #management-plane #inband #vrf network #interface GigabitEthernet 0/6 #allow protocol ssh
C. #control-plane #management-plane #vrf network #interface GigabitEthernet 0/6 #allow protocol ssh
D. #control-plane #management-plane #out-of-band #vrf network #interface GigabitEthernet 0/6 #allow protocol ssh
正确答案:D
问题 #90
What is an attribute of Cisco Talos?
A. cyber threats posing as authorized users and devices
B. introduction of attributes that use objects and narrative relations
C. fast and intelligent responses based on threat data
D. cyber threat intelligence interchange and maintenance
正确答案:D
问题 #91
What is the definition of phishing?
A. sending fraudulent communications that appear to come from a reputable source
B. malicious email spoofing attack that targets a specific organization or individual
C. any kind of unwanted, unsolicited digital communication that gets sent out in bulk
D. impersonation of an authorized website to deceive users into entering their credentials
正确答案:A
问题 #92
What is a capability of the Cisco ISE guest service in the web-based portal?
A. provides sponsors with a portal to create and manage accounts for visitors
B. allows Cisco Technical Assistance Center to create a temporary root account
C. creates an open SSID to give Wi-Fi access to guests without authentication
D. gives consultants a self-service platform for password resets
正确答案:A
问题 #93
A company named Org.Co plans to migrate a messaging app to a software as a service offering. A security engineer must protect data-at-rest and data in transit, and the solution must enforce policy-based security control automatically. What must be integra
A. next generation firewall
B. Cloud Workload Protection
C. Cloud Access Security Broker
D. Perimeter Extended Detection and Response
正确答案:C

即刻预约

免费试听-咨询课程-获取免费资料