Exam Details

  • Exam Code
    :350-701
  • Exam Name
    :Implementing and Operating Cisco Security Core Technologies (SCOR)
  • Certification
    :CCNP Security
  • Vendor
    :Cisco
  • Total Questions
    :753 Q&As
  • Last Updated
    :Apr 12, 2025

Cisco CCNP Security 350-701 Questions & Answers

  • Question 511:

    What is a characteristic of a bridge group in ASA Firewall transparent mode?

    A. It includes multiple interfaces and access rules between interfaces are customizable

    B. It is a Layer 3 segment and includes one port and customizable access rules

    C. It allows ARP traffic with a single access rule

    D. It has an IP address on its BVI interface and is used for management traffic

  • Question 512:

    Refer to the exhibit.

    A network administrator configures command authorization for the admin5 user. What is the admin5 user able to do on HQ_Router after this configuration?

    A. set the IP address of an interface

    B. complete no configurations

    C. complete all configurations

    D. add subinterfaces

  • Question 513:

    Which two behavioral patterns characterize a ping of death attack? (Choose two)

    A. The attack is fragmented into groups of 16 octets before transmission.

    B. The attack is fragmented into groups of 8 octets before transmission.

    C. Short synchronized bursts of traffic are used to disrupt TCP connections.

    D. Malformed packets are used to crash systems.

    E. Publicly accessible DNS servers are typically used to execute the attack.

  • Question 514:

    What does the Cloudlock Apps Firewall do to mitigate security concerns from an application perspective?

    A. It allows the administrator to quarantine malicious files so that the application can function, just not maliciously.

    B. It discovers and controls cloud apps that are connected to a company's corporate environment.

    C. It deletes any application that does not belong in the network.

    D. It sends the application information to an administrator to act on.

  • Question 515:

    Which capability is exclusive to a Cisco AMP public cloud instance as compared to a private cloud instance?

    A. RBAC

    B. ETHOS detection engine

    C. SPERO detection engine

    D. TETRA detection engine

  • Question 516:

    Which RADIUS attribute can you use to filter MAB requests in an 802.1 x deployment?

    A. 1

    B. 2

    C. 6

    D. 31

  • Question 517:

    Which algorithm provides encryption and authentication for data plane communication?

    A. AES-GCM

    B. SHA-96

    C. AES-256

    D. SHA-384

  • Question 518:

    An organization has two machines hosting web applications. Machine 1 is vulnerable to SQL injection while machine 2 is vulnerable to buffer overflows. What action would allow the attacker to gain access to machine 1 but not machine 2?

    A. sniffing the packets between the two hosts

    B. sending continuous pings

    C. overflowing the buffer's memory

    D. inserting malicious commands into the database

  • Question 519:

    What is a commonality between DMVPN and FlexVPN technologies?

    A. FlexVPN and DMVPN use IS-IS routing protocol to communicate with spokes

    B. FlexVPN and DMVPN use the new key management protocol

    C. FlexVPN and DMVPN use the same hashing algorithms

    D. IOS routers run the same NHRP code for DMVPN and FlexVPN

  • Question 520:

    Which two conditions are prerequisites for stateful failover for IPsec? (Choose two)

    A. Only the IKE configuration that is set up on the active device must be duplicated on the standby device; the IPsec configuration is copied automatically

    B. The active and standby devices can run different versions of the Cisco IOS software but must be the same type of device.

    C. The IPsec configuration that is set up on the active device must be duplicated on the standby device

    D. Only the IPsec configuration that is set up on the active device must be duplicated on the standby device; the IKE configuration is copied automatically.

    E. The active and standby devices must run the same version of the Cisco IOS software and must be the same type of device

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cisco exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 350-701 exam preparations and Cisco certification application, do not hesitate to visit our Vcedump.com to find your solutions here.