2026年最新のCiscoテスト350-701問題集豪華セット無料最新の問題集をゲット! [Q413-Q438]

Share

2026年最新のCiscoテスト350-701問題集豪華セット無料最新の問題集をゲット!

完全版350-701練習テスト727特別な問題と解答が待ってます!今すぐゲットせよ!

質問 # 413
Which information is required when adding a device to Firepower Management Center?

  • A. device serial number
  • B. encryption method
  • C. registration key
  • D. username and password

正解:C

解説:
When adding a device to Firepower Management Center, you need to provide a registration key, which is a unique alphanumeric string that you create and enter on both the device and the Firepower Management Center. The registration key is used to authenticate the device and the Firepower Management Center to each other. You do not need to provide the username and password, encryption method, or device serial number when adding a device to Firepower Management Center1. References: 1: How to Manage a Device with the Firepower Management Center - Configure the Managed Device


質問 # 414
Refer to the exhibit,

which command results in these messages when attempting to troubleshoot an iPsec VPN connection?

  • A. debug crypto ipsec endpoint
  • B. debug crypto isakmp connection
  • C. debug crypto isakmp
  • D. debug crypto Ipsec

正解:C


質問 # 415
An engineer has been tasked with implementing a solution that can be leveraged for securing the cloud users, data, and applications. There is a requirement to use the Cisco cloud native CASB and cloud cybersecurity platform. What should be used to meet these requirements?

  • A. Cisco NGFW
  • B. Cisco Cloud Email Security
  • C. Cisco Cloudlock
  • D. Cisco Umbrella

正解:C

解説:
Explanation:
Cisco Cloudlock: Secure your cloud users, data, and applications with the cloud-native Cloud Access Security Broker (CASB) and cloud cybersecurity platform.
Reference: https://www.cisco.com/c/dam/en/us/products/collateral/security/cloud-web-security/at-a-glance- c45- 738565.pdf


質問 # 416
Drag and drop the Firepower Next Generation Intrustion Prevention System detectors from the left onto the correct definitions on the right.

正解:

解説:


質問 # 417
Which system performs compliance checks and remote wiping?

  • A. AMP
  • B. ISE
  • C. OTP
  • D. MDM

正解:D

解説:
MDM stands for Mobile Device Management, which is a system that performs compliance checks and remote wiping on mobile devices. MDM allows administrators to enforce security policies, monitor device status, and remotely manage devices in case of loss, theft, or compromise. MDM can also integrate with other Cisco security solutions, such as ISE, AMP, and Umbrella, to provide enhanced protection and visibility for mobile devices. References:
* Mobile Device Management (MDM) - Cisco
* Implementing and Operating Cisco Security Core Technologies (SCOR) - Module 5: Secure Network Access


質問 # 418
Drag and drop the suspicious patterns for the Cisco Tetration platform from the left onto the correct definitions on the right.

正解:

解説:


質問 # 419
What is a benefit of performing device compliance?

  • A. Providing attribute-driven policies
  • B. Providing multi-factor authentication
  • C. Verification of the latest OS patches
  • D. Device classification and authorization

正解:C


質問 # 420
When using Cisco AMP for Networks which feature copies a file to the Cisco AMP cloud for analysis?

  • A. sandbox analysis
  • B. Spero analysis
  • C. dynamic analysis
  • D. malware analysis

正解:C

解説:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guidev60/Referen Spero analysis only uploads the signature of the (executable) files to the AMP cloud. It does not upload thewhole file. Dynamic analysis sends files to AMP ThreatGrid.Dynamic Analysis submits (the whole) files to Cisco Threat Grid (formerly AMP Threat Grid). Cisco ThreatGrid runs the file in a sandbox environment, analyzes the file's behavior to determine whether the file ismalicious, and returns a threat score that indicates the likelihood that a file contains malware. From the threatscore, you can view a dynamic analysis summary report with the reasons for the assigned threat score. Youcan also look in Cisco Threat Grid to view detailed reports for files that your organization submitted, as well asscrubbed reports with limited data for files that your organization did not submit.Local malware analysis allows a managed device to locally inspect executables, PDFs, office documents, andother types of files for the most common types of malware, using a detection rule set provided by the CiscoTalos Security Intelligence and Research Group (Talos). Because local analysis does not query the AMP cloud,and does not run the file, local malware analysis saves time and system resources. -> Malware analysis doesnot upload files to anywhere, it only checks the files locally.There is no sandbox analysis feature, it is just a method of dynamic analysis that runs suspicious files in avirtual machine.


質問 # 421
Which two application layer preprocessors are used by Firepower Next Generation Intrusion Prevention System? (Choose two)

  • A. packet decoder
  • B. modbus
  • C. inline normalization
  • D. SIP
  • E. SSL

正解:D、E

解説:
Application layer protocols can represent the same data in a variety of ways. The Firepower System provides application layer protocol decoders that normalize specific types of packet data into formats that the intrusion rules engine can analyze. Normalizing application-layer protocol encodings allows the rules engine to effectively apply the same content-related rules to packets whose data is represented differently and obtain meaningful results.
Application layer protocols can represent the same data in a variety of ways. The Firepower System provides application layer protocol decoders that normalize specific types of packet data into formats that the intrusion rules engine can analyze. Normalizing application-layer protocol encodings allows the rules engine to effectively apply the same content-related rules to packets whose data is represented differently and obtain meaningful results.
Reference:
FirePower uses many preprocessors, including DNS, FTP/Telnet, SIP, SSL, SMTP, SSH preprocessors.
Application layer protocols can represent the same data in a variety of ways. The Firepower System provides application layer protocol decoders that normalize specific types of packet data into formats that the intrusion rules engine can analyze. Normalizing application-layer protocol encodings allows the rules engine to effectively apply the same content-related rules to packets whose data is represented differently and obtain meaningful results.
FirePower uses many preprocessors, including DNS, FTP/Telnet, SIP, SSL, SMTP, SSH preprocessors.


質問 # 422
Which two descriptions of AES encryption are true? (Choose two.)

  • A. AES can use a 256-bit key for encryption.
  • B. AES encrypts and decrypts a key three times in sequence.
  • C. AES is more secure than 3DES.
  • D. AES can use a 168-bit key for encryption.
  • E. AES is less secure than 3DES.

正解:A、C


質問 # 423
Refer to the exhibit.

Which statement about the authentication protocol used in the configuration is true

  • A. The authentication and authorization requests are grouped in a single packet
  • B. The authentication request contains only a password
  • C. There are separate authentication and authorization request packets
  • D. The authentication request contains only a username

正解:A


質問 # 424
An administrator is trying to determine which applications are being used in the network but does not want the network devices to send metadata to Cisco Firepower. Which feature should be used to accomplish this?

  • A. Network Discovery
  • B. Packet Tracer
  • C. Access Control
  • D. NetFlow

正解:D

解説:
NetFlow is a network protocol developed by Cisco for the collection and monitoring of network traffic flow data generated by NetFlow-enabled routers and switches. The flows do not contain actual packet data, but rather the metadata for communications. It is a standard form of session data that details who, what, when, and where of network traffic -> Answer A is not correct.
Reference:
white-paper-c11-736595.html


質問 # 425
A network engineer has configured a NTP server on a Cisco ASA. The Cisco ASA has IP reachability to the NTP server and is not filtering any traffic.
The show ntp association detail command indicates that the configured NTP server is unsynchronized and has a stratum of 16. What is the cause of this issue?

  • A. NTP is not configured to use a working server.
  • B. An access list entry for UDP port 123 on the outside interface is missing.
  • C. Resynchronization of NTP is not forced
  • D. An access list entry for UDP port 123 on the inside interface is missing.

正解:A


質問 # 426
Where are individual sites specified to be blacklisted in Cisco Umbrella?

  • A. content categories
  • B. security settings
  • C. destination lists
  • D. application settings

正解:C

解説:
A destination list is a list of internet destinations that can be blocked or allowed based on the administrative preferences for the policies applied to the identities within your organization. A destination is an IP address (IPv4), URL, or fully qualified domain name. You can add a destination list to Umbrella at any time; however, a destination list does not come into use until it is added to a policy.


質問 # 427
What are two DDoS attack categories? (Choose two.)

  • A. protocol
  • B. database
  • C. volume-based
  • D. scree-based
  • E. sequential

正解:A、C

解説:
Explanation
https://www.cisco.com/c/en/us/products/security/what-is-a-ddos-attack.html


質問 # 428
What is a difference between GRE over IPsec and IPsec with crypto map?

  • A. Multicast traffic is supported by IPsec with crypto map.
  • B. GRE over IPsec supports non-IP protocols.
  • C. GRE provides its own encryption mechanism.
  • D. IPsec with crypto map oilers better scalability.

正解:B

解説:
The difference between GRE over IPsec and IPsec with crypto map is that GRE (Generic Routing Encapsulation) over IPsec can encapsulate and transport non-IP protocols across an IP network, whereas IPsec with crypto map is typically used for IP traffic. GRE tunnels wrapped in IPsec provide a way to transport multicast traffic and other protocol types across an IPsec VPN, offering greater flexibility in the types of traffic that can be secured.


質問 # 429
An engineer needs behavioral analysis to detect malicious activity on the hosts, and is configuring the organization's public cloud to send telemetry using the cloud provider's mechanisms to a security device.
Which mechanism should the engineer configure to accomplish this goal?

  • A. VPC flow logs
  • B. NetFlow
  • C. mirror port
  • D. Flow

正解:B

解説:
Explanation
https://www.cisco.com/c/en/us/products/collateral/data-center-analytics/tetration-analytics/q-and-a-c67-737402.h


質問 # 430
An engineer needs to detect and quarantine a file named abc424400664 zip based on the MD5 signature of the file using the Outbreak Control list feature within Cisco Advanced Malware Protection (AMP) for Endpoints The configured detection method must work on files of unknown disposition Which Outbreak Control list must be configured to provide this?

  • A. Simple Custom Detection
  • B. Blocked Application
  • C. Advanced Custom Detection
  • D. Android Custom Detection

正解:A

解説:
Simple Custom Detection is a feature of Cisco AMP for Endpoints that allows administrators to block specific files based on their SHA-256 or MD5 hashes. This feature can be used to detect and quarantine files of unknown disposition, such as abc424400664.zip, by adding their hashes to a custom list in the AMP portal.
The list can then be applied to a policy that is assigned to the endpoints. Simple Custom Detection works on files of any type, size, or platform, unlike the other options that are either platform-specific (Android Custom Detection), size-limited (Blocked Application), or signature-based (Advanced Custom Detection). References: 1, 2, 3


質問 # 431
A network engineer is configuring NetFlow top talkers on a Cisco router Drag and drop the steps in the process from the left into the sequence on the right

正解:

解説:


質問 # 432
Which public cloud provider supports the Cisco Next Generation Firewall Virtual?

  • A. VMware ESXi
  • B. Google Cloud Platform
  • C. Amazon Web Services
  • D. Red Hat Enterprise Visualization

正解:C

解説:
Cisco Firepower NGFW Virtual (NGFWv) is the virtualized version of Cisco's Firepower next generation firewall.
The Cisco NGFW virtual appliance is available in the AWS and Azure marketplaces. In AWS, it can be deployed in routed and passive modes. Passive mode design requires ERSPAN, the Encapsulated Remote Switched Port Analyzer, which is currently not available in Azure.
In passive mode, NGFWv inspects packets like an Intrusion Detection System (IDS) appliance, but no action can be taken on the packet.
In routed mode NGFWv acts as a next hop for workloads. It can inspect packets and also take action on the packet based on rule and policy definitions.
Cisco Firepower NGFW Virtual (NGFWv) is the virtualized version of Cisco's Firepower next generation firewall.
The Cisco NGFW virtual appliance is available in the AWS and Azure marketplaces. In AWS, it can be deployed in routed and passive modes. Passive mode design requires ERSPAN, the Encapsulated Remote Switched Port Analyzer, which is currently not available in Azure.
In passive mode, NGFWv inspects packets like an Intrusion Detection System (IDS) appliance, but no action can be taken on the packet.
In routed mode NGFWv acts as a next hop for workloads. It can inspect packets and also take action on the packet based on rule and policy definitions.
Cisco Firepower NGFW Virtual (NGFWv) is the virtualized version of Cisco's Firepower next generation firewall.
The Cisco NGFW virtual appliance is available in the AWS and Azure marketplaces. In AWS, it can be deployed in routed and passive modes. Passive mode design requires ERSPAN, the Encapsulated Remote Switched Port Analyzer, which is currently not available in Azure.
In passive mode, NGFWv inspects packets like an Intrusion Detection System (IDS) appliance, but no action can be taken on the packet.
In routed mode NGFWv acts as a next hop for workloads. It can inspect packets and also take action on the packet based on rule and policy definitions.


質問 # 433
Which two risks is a company vulnerable to if it does not have a well-established patching solution for endpoints? (Choose two.)

  • A. ARP spoofing
  • B. eavesdropping
  • C. exploits
  • D. denial-of-service attacks
  • E. malware

正解:C、E


質問 # 434
Refer to the exhibit.

A network administrator configured a site-to-site VPN tunnel between two Cisco IOS routers, and hosts are unable to communicate between two sites of VPN. The network administrator runs the debug crypto isakmp sa command to track VPN status. What is the problem according to this command output?

  • A. interesting traffic was not applied
  • B. encryption algorithm mismatch
  • C. authentication key mismatch
  • D. hashing algorithm mismatch

正解:C


質問 # 435
Which protocol provides the strongest throughput performance when using Cisco AnyConnect VPN?

  • A. DTLSv1
  • B. TLSv1.2
  • C. TLSv1
  • D. TLSv1.1

正解:A

解説:
Explanation/Reference: https://www.cisco.com/c/en/us/support/docs/security/anyconnect-secure-mobility-client/215331- anyconnect-implementation-and-performanc.html


質問 # 436
Refer to the exhibit.

What will happen when this Python script is run?

  • A. The compromised computers and malware trajectories will be received from Cisco AMP
  • B. The list of computers and their current vulnerabilities will be received from Cisco AMP
  • C. The list of computers, policies, and connector statuses will be received from Cisco AMP
  • D. The compromised computers and what compromised them will be received from Cisco AMP

正解:C

解説:
The call to API of "https://api.amp.cisco.com/v1/computers" allows us to fetch list of computers across your organization that Advanced Malware Protection (AMP) sees The call to API of "https://api.amp.cisco.com/v1/computers" allows us to fetch list of computers across your organization that Advanced Malware Protection (AMP) sees Reference:
2Fcomputers&api_host=api.apjc.amp.cisco.com&api_resource=Computer&api_version=v1 The call to API of "https://api.amp.cisco.com/v1/computers" allows us to fetch list of computers across your organization that Advanced Malware Protection (AMP) sees
2Fcomputers&api_host=api.apjc.amp.cisco.com&api_resource=Computer&api_version=v1


質問 # 437
What are two Trojan malware attacks? (Choose two)

  • A. Backdoor
  • B. Smurf
  • C. Frontdoor
  • D. Rootkit
  • E. Sync

正解:A、D

解説:
A Trojan malware attack is a type of malicious code or software that disguises itself as a legitimate program or file to trick users into executing it. Once executed, the Trojan can perform various harmful actions on the infected system or network, such as stealing data, deleting files, or installing other malware. There are different types of Trojan malware attacks, depending on their purpose and behavior. Two common types are:
* Rootkit: A rootkit is a type of Trojan that hides itself and other malware from detection and removal by antivirus software or system tools. A rootkit can modify the operating system or the firmware of the device to gain persistent and privileged access to the system. A rootkit can also intercept and manipulate system calls, network traffic, or user input to conceal its activities or redirect them to malicious servers.
* Backdoor: A backdoor is a type of Trojan that creates a secret or unauthorized access point to the infected system or network. A backdoor can allow an attacker to remotely control the system, execute commands, upload or download files, or monitor the system activity. A backdoor can also be used to install other malware or launch further attacks on other systems or networks.
References:
[Implementing and Operating Cisco Security Core Technologies (SCOR) v1.0], Module 1: Malware Threats, Lesson 1: Identifying Malware Threats, Topic: Trojan Horse What is a Trojan? Is it a virus or is it malware? - Norton™ Trojan Horse Examples (2024): The 6 Worst Attacks Ever - SoftwareLab


質問 # 438
......

[2026年03月] 合格させるCisco 350-701試験一発合格保証:https://drive.google.com/open?id=1Wb6N9dfkBWrUgpqD3rvmdMdCVDGsqHbS

あなたの合格率を上げろう350-701試験問題集:https://www.goshiken.com/Cisco/350-701-mondaishu.html