Weekend Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: Board70

350-701 Exam Dumps - Cisco CCNP Security Questions and Answers

Question # 4

A network engineer is configuring NetFlow top talkers on a Cisco router Drag and drop the steps in the process from the left into the sequence on the right

Options:

Buy Now
Question # 5

Which Cisco AMP feature allows an engineer to look back to trace past activities, such as file and process

activity on an endpoint?

Options:

A.

endpoint isolation

B.

advanced search

C.

advanced investigation

D.

retrospective security

Buy Now
Question # 6

Which API technology with SDN architecture is used to communicate with a controller and network devices such as routers and switches?

Options:

A.

REST APIs

B.

Northbound APIs

C.

Unprotected APIs

D.

Southbound APIs

Buy Now
Question # 7

What is a characteristic of Cisco ASA Netflow v9 Secure Event Logging?

Options:

A.

It tracks flow-create, flow-teardown, and flow-denied events.

B.

It provides stateless IP flow tracking that exports all records of a specific flow.

C.

It tracks the flow continuously and provides updates every 10 seconds.

D.

Its events match all traffic classes in parallel.

Buy Now
Question # 8

A network engineer is deciding whether to use stateful or stateless failover when configuring two Cisco ASAs for high availability. What is the connection status in both cases?

Options:

A.

Need to be reestablished with both stateful and stateless failover

B.

Need to be reestablished with stateful failover and preserved with stateless failover

C.

Preserved with both stateful and stateless failover

D.

Preserved with stateful failover and need to be reestablished with stateless failover

Buy Now
Question # 9

What is a function of Cisco AMP for Endpoints?

Options:

A.

It detects DNS attacks

B.

It protects against web-based attacks

C.

It blocks email-based attacks

D.

It automates threat responses of an infected host

Buy Now
Question # 10

What is an advantage of using a next-generation firewall compared to a traditional firewall?

Options:

A.

Next-generation firewalls have stateless inspection capabilities, and traditional firewalls use stateful inspection.

B.

Next-generation firewalls use dynamic packet filtering, and traditional firewalls use static packet filtering.

C.

Next-generation firewalls have threat intelligence feeds, and traditional firewalls use signature detection.

D.

Next-generation firewalls use intrusion prevention policies, and traditional firewalls use intrusion detection policies.

Buy Now
Question # 11

What is the difference between EPP and EDR?

Options:

A.

EDR focuses solely on prevention at the perimeter.

B.

Having an EPP solution allows an engineer to detect, investigate, and remediate modern threats.

C.

Having an EDR solution gives an engineer the capability to flag offending files at the first sign of malicious behavior.

D.

EPP focuses primarily on threats that have evaded front-line defenses that entered the environment.

Buy Now
Question # 12

Which kind of API that is used with Cisco DNA Center provisions SSIDs, QoS policies, and update software versions on switches?

Options:

A.

Integration

B.

Intent

C.

Event

D.

Multivendor

Buy Now
Question # 13

Elliptic curve cryptography is a stronger more efficient cryptography method meant to replace which current

encryption technology?

Options:

A.

3DES

B.

RSA

C.

DES

D.

AES

Buy Now
Question # 14

A company is experiencing exfiltration of credit card numbers that are not being stored on-premise. The

company needs to be able to protect sensitive data throughout the full environment. Which tool should be used

to accomplish this goal?

Options:

A.

Security Manager

B.

Cloudlock

C.

Web Security Appliance

D.

Cisco ISE

Buy Now
Question # 15

An engineer is configuring Dropbox integration with Cisco Cloudlock. Which action must be taken before granting API access in the Dropbox admin console?

Options:

A.

Authorize Dropbox within the Platform settings in the Cisco Cloudlock portal.

B.

Add Dropbox to the Cisco Cloudlock Authentication and API section in the Cisco Cloudlock portal.

C.

Send an API request to Cisco Cloudlock from Dropbox admin portal.

D.

Add Cisco Cloudlock to the Dropbox admin portal.

Buy Now
Question # 16

An organization is implementing AAA for their users. They need to ensure that authorization is verified for every command that is being entered by the network administrator. Which protocol must be configured in order to provide this capability?

Options:

A.

EAPOL

B.

SSH

C.

RADIUS

D.

TACACS+

Buy Now
Question # 17

Which Cisco firewall solution supports configuration via Cisco Policy Language?

Options:

A.

CBAC

B.

ZFW

C.

IPS

D.

NGFW

Buy Now
Question # 18

A large organization wants to deploy a security appliance in the public cloud to form a site-to-site VPN

and link the public cloud environment to the private cloud in the headquarters data center. Which Cisco

security appliance meets these requirements?

Options:

A.

Cisco Cloud Orchestrator

B.

Cisco ASAV

C.

Cisco WSAV

D.

Cisco Stealthwatch Cloud

Buy Now
Exam Code: 350-701
Exam Name: Implementing and Operating Cisco Security Core Technologies (SCOR 350-701)
Last Update: Sep 14, 2025
Questions: 726
350-701 pdf

350-701 PDF

$28.5  $94.99
350-701 Engine

350-701 Testing Engine

$33  $109.99
350-701 PDF + Engine

350-701 PDF + Testing Engine

$43.5  $144.99