350-701 Exam Details

  • Exam Code
    :350-701
  • Exam Name
    :Implementing and Operating Cisco Security Core Technologies (SCOR)
  • Certification
    :CCIE Security
  • Vendor
    :Cisco
  • Total Questions
    :784 Q&As
  • Last Updated
    :May 30, 2026

Cisco 350-701 Online Questions & Answers

  • Question 281:

    Which two commands are required when configuring a flow-export action on a Cisco ASA? (Choose two.)

    A. flow-export event-type
    B. policy-map
    C. access-list
    D. flow-export template timeout-rate 15
    E. access-group

  • Question 282:

    Refer to the exhibit.

    A network administrator configures command authorization for the admin5 user. What is the admin5 user able to do on HQ_Router after this configuration?

    A. set the IP address of an interface
    B. complete no configurations
    C. complete all configurations
    D. add subinterfaces

  • Question 283:

    Which function is performed by certificate authorities but is a limitation of registration authorities?

    A. accepts enrollment requests
    B. certificate re-enrollment
    C. verifying user identity
    D. CRL publishing

  • Question 284:

    Which security mechanism is designed to protect against "offline brute-force" attacks?

    A. Token
    B. MFA
    C. Salt
    D. CAPTCHA

  • Question 285:

    What is a benefit of using Cisco AVC for application control?

    A. dynamic application scanning
    B. management of application sessions
    C. retrospective application analysis
    D. zero-trust approach

  • Question 286:

    Which threat intelligence standard contains malware hashes?

    A. advanced persistent threat
    B. open command and control
    C. structured threat information expression
    D. trusted automated exchange of indicator information

  • Question 287:

    What are two workload security models? (Choose two.)

    A. SaaS
    B. PaaS
    C. off-premises
    D. on-premises
    E. IaaS

  • Question 288:

    Which cryptographic process provides origin confidentiality, integrity, and origin authentication for packets?

    A. IKEv1
    B. AH
    C. ESP
    D. IKEv2

  • Question 289:

    A network engineer has configured a NTP server on a Cisco ASA. The Cisco ASA has IP reachability to the NTP server and is not filtering any traffic. The show ntp association detail command indicates that the configured NTP server is unsynchronized and has a stratum of 16. What is the cause of this issue?

    A. Resynchronization of NTP is not forced
    B. NTP is not configured to use a working server.
    C. An access list entry for UDP port 123 on the inside interface is missing.
    D. An access list entry for UDP port 123 on the outside interface is missing.

  • Question 290:

    Which Cisco ISE feature helps to detect missing patches and helps with remediation?

    A. posture assessment
    B. profiling policy
    C. authentication policy
    D. enabling probes

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cisco exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 350-701 exam preparations and Cisco certification application, do not hesitate to visit our Vcedump.com to find your solutions here.