Skip to main content

300-740 Real Exam Questions

Designing and Implementing Secure Cloud Access for Users and Endpoints

61 questions available · Page 1 of 7

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

What helps prevent drive-by compromise?

  1. A

    Ad blockers

  2. B

    VPN

  3. C

    Incognito browsing

  4. D

    Browsing known websites

Show answer and explanation

Correct answer: A

Question 2 Single choice

Refer to the exhibit.

An engineer must analyze the Cisco Secure Cloud Analytics report.

What is occurring?

  1. A

    Persistent remote-control connections

  2. B

    Distributed DDoS attack

  3. C

    Geographically unusual remote access

  4. D

    Memory exhaustion attempt toward port 22

Show answer and explanation

Correct answer: C

Question 3 Drag & drop

DRAG DROP

Drag and drop the tasks from the left into order on the right to implement adding Duo multifactor authentication to Meraki Client VPN login.

Question diagram
Show answer and explanation
Correct answer diagram
Question 4 Single choice

Refer to the exhibit.

An engineer must provide RDP access to the AWS virtual machines and HTTPS access to the Google

Cloud Platform virtual machines. All other connectivity must be blocked. The indicated rules were applied
to the firewall; however, none of the virtual machines in AWS and Google Cloud Platform are accessible.

What should be done to meet the requirement?

  1. A

    Move rule 2 to the first position.

  2. B

    Configure a NAT overload rule

  3. C

    Configure a virtual private cloud firewall rule

  4. D

    Move rule 1 to the last position

Show answer and explanation

Correct answer: D

Question 5 Multiple choice

Refer to the exhibit.

An engineer must block internal users from accessing Facebook and Facebook Apps. All other access must be allowed. The indicated policy was created in Cisco Secure Firewall Management Center and
deployed to the internet edge firewall; however, users still can access Facebook.

Which two actions must be taken to meet the requirement? (Choose two.)

  1. A

    Set Destination Zones to outside for rule 2.

  2. B

    Set Source Zones to inside for rule 2.

  3. C

    Set Applications to Facebook and Facebook Apps for rule 2.

  4. D

    Set Destination Zones to outside for rule 1.

  5. E

    Set Source Zones to inside for rule 1.

Show answer and explanation

Correct answers: D, E

Question 6 Single choice

Refer to the exhibit.

An engineer must enable access to Salesforce using Cisco Umbrella and Cisco Cloudlock. These actions were performed:

From Salesforce, add the Cloudlock IP address to the allow list From Cloudlock, authorize Salesforce However, Salesforce access via Cloudlock is still unauthorized.

What should be done to meet the requirements?

  1. A

    From the Salesforce admin page, grant API access to Cloudlock.

  2. B

    From the Salesforce admin page, grant network access to Cloudlock

  3. C

    From the Cloudlock dashboard, grant API access to Salesforce.

  4. D

    From the Cloudlock dashboard, grant network access to Salesforce.

Show answer and explanation

Correct answer: B

Question 7 Single choice

Refer to the exhibit.

An engineer must configure Cisco ASA so that the Secure Client deployment is removed when the user laptop disconnects from the VPN. The indicated configuration was applied to the Cisco ASA firewall.

Which command must be run to meet the requirement?

  1. A

    client-bypass-protocol enable

  2. B

    anyconnect keep-installer none

  3. C

    anyconnect firewall-rule client-interface

  4. D

    D. client-bypass-protocol disable

Show answer and explanation

Correct answer: B

Question 8 Multiple choice

Refer to the exhibit.

An engineer is investigating an issue by using Cisco Secure Cloud Analytics. The engineer confirms that the connections are unauthorized and informs the incident management team.

Which two actions must be taken next? (Choose two.)

  1. A

    Reinstall the host from a recent backup.

  2. B

    Quarantine the host

  3. C

    Reinstall the host from scratch.

  4. D

    Create a firewall rule that has a source of linux-gcp-east-4c, a destination of Any, and a protocol of
    SSH.

  5. E

    Create a firewall rule that has a source of Any, a destination of linux-gcp-east-4c, and a protocol of
    SSH.

Show answer and explanation

Correct answers: B, E

Question 9 Single choice

Refer to the exhibit.

An engineer is troubleshooting an incident by using Cisco Secure Cloud Analytics.

What is the cause of the issue?

  1. A

    An attacker installed an SSH server on the host.

  2. B

    An attacker opened port 22 on the host.

  3. C

    An FTP client was installed on a domain controller.

  4. D

    An FTP client was installed on a workstation.

Show answer and explanation

Correct answer: C

Question 10 Multiple choice

Refer to the exhibit.

An engineer is investigating the critical alert received in Cisco Secure Network Analytics. The engineer confirms that the incident is valid.

Which two actions must be taken? (Choose two.)

  1. A

    Inform the incident management team.

  2. B

    Block IP address 66.77.197.165

  3. C

    Uninstall the Conduit software.

  4. D

    Shut down the host.

  5. E

    Quarantine the host

Show answer and explanation

Correct answers: A, E