Exam Details

  • Exam Code
    :350-701
  • Exam Name
    :Implementing and Operating Cisco Security Core Technologies (SCOR)
  • Certification
    :CCNP Security
  • Vendor
    :Cisco
  • Total Questions
    :753 Q&As
  • Last Updated
    :Apr 12, 2025

Cisco CCNP Security 350-701 Questions & Answers

  • Question 421:

    Which algorithm provides asymmetric encryption?

    A. RC4

    B. AES

    C. RSA

    D. 3DES

  • Question 422:

    Which public cloud provider supports the Cisco Next Generation Firewall Virtual?

    A. Google Cloud Platform

    B. Red Hat Enterprise Visualization

    C. VMware ESXi

    D. Amazon Web Services

  • Question 423:

    Refer to the exhibit.

    What will happen when the Python script is executed?

    A. The hostname will be translated to an IP address and printed.

    B. The hostname will be printed for the client in the client ID field.

    C. The script will pull all computer hostnames and print them.

    D. The script will translate the IP address to FODN and print it

  • Question 424:

    An engineer needs a cloud solution that will monitor traffic, create incidents based on events, and integrate with other cloud solutions via an API. Which solution should be used to accomplish this goal?

    A. SIEM

    B. CASB

    C. Adaptive MFA

    D. Cisco Cloudlock

  • Question 425:

    How does DNS Tunneling exfiltrate data?

    A. An attacker registers a domain that a client connects to based on DNS records and sends malware through that connection.

    B. An attacker opens a reverse DNS shell to get into the client's system and install malware on it.

    C. An attacker uses a non-standard DNS port to gain access to the organization's DNS servers in order to poison the resolutions.

    D. An attacker sends an email to the target with hidden DNS resolvers in it to redirect them to a malicious domain.

  • Question 426:

    An engineer notices traffic interruption on the network. Upon further investigation, it is learned that broadcast packets have been flooding the network. What must be configured, based on a predefined threshold, to address this issue?

    A. Bridge Protocol Data Unit guard

    B. embedded event monitoring

    C. storm control

    D. access control lists

  • Question 427:

    An organization has a Cisco ESA set up with policies and would like to customize the action assigned for violations. The organization wants a copy of the message to be delivered with a message added to flag it as a DLP violation. Which actions must be performed in order to provide this capability?

    A. deliver and send copies to other recipients

    B. quarantine and send a DLP violation notification

    C. quarantine and alter the subject header with a DLP violation

    D. deliver and add disclaimer text

  • Question 428:

    Refer to the exhibit.

    What will happen when this Python script is run?

    A. The compromised computers and malware trajectories will be received from Cisco AMP

    B. The list of computers and their current vulnerabilities will be received from Cisco AMP

    C. The compromised computers and what compromised them will be received from Cisco AMP

    D. The list of computers, policies, and connector statuses will be received from Cisco AMP

  • Question 429:

    Due to a traffic storm on the network, two interfaces were error-disabled, and both interfaces sent SNMP traps.

    Which two actions must be taken to ensure that interfaces are put back into service? (Choose two)

    A. Have Cisco Prime Infrastructure issue an SNMP set command to re-enable the ports after the pre configured interval.

    B. Use EEM to have the ports return to service automatically in less than 300 seconds.

    C. Enter the shutdown and no shutdown commands on the interfaces.

    D. Enable the snmp-server enable traps command and wait 300 seconds

    E. Ensure that interfaces are configured with the error-disable detection and recovery feature

  • Question 430:

    Refer to the exhibit.

    An organization is using DHCP Snooping within their network. A user on VLAN 41 on a new switch is complaining that an IP address is not being obtained. Which command should be configured on the switch interface in order to provide the user with network connectivity?

    A. ip dhcp snooping verify mac-address

    B. ip dhcp snooping limit 41

    C. ip dhcp snooping vlan 41

    D. ip dhcp snooping trust

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cisco exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 350-701 exam preparations and Cisco certification application, do not hesitate to visit our Vcedump.com to find your solutions here.