350-701 Exam Details

  • Exam Code
    :350-701
  • Exam Name
    :Implementing and Operating Cisco Security Core Technologies (SCOR)
  • Certification
    :CCIE Security
  • Vendor
    :Cisco
  • Total Questions
    :784 Q&As
  • Last Updated
    :May 30, 2026

Cisco 350-701 Online Questions & Answers

  • Question 361:

    A network administrator is configuring a switch to use Cisco ISE for 802.1X. An endpoint is failing authentication and is unable to access the network. Where should the administrator begin troubleshooting to verify the authentication details?

    A. Adaptive Network Control Policy List
    B. Context Visibility
    C. Accounting Reports
    D. RADIUS Live Logs

  • Question 362:

    Refer to the exhibit.

    Traffic is not passing through IPsec site-to-site VPN on the Firepower Threat Defense appliance. What is causing this issue?

    A. No split-tunnel policy is defined on the Firepower Threat Defense appliance.
    B. The access control policy is not allowing VPN traffic in.
    C. Site-to-site VPN peers are using different encryption algorithms.
    D. Site-to-site VPN preshared keys are mismatched.

  • Question 363:

    An engineer is trying to securely connect to a router and wants to prevent insecure algorithms from being used.

    However, the connection is failing. Which action should be taken to accomplish this goal?

    A. Disable telnet using the no ip telnet command.
    B. Enable the SSH server using the ip ssh server command.
    C. Configure the port using the ip ssh port 22 command.
    D. Generate the RSA key using the crypto key generate rsa command.

  • Question 364:

    An organization recently installed a Cisco WSA and would like to take advantage of the AVC engine to allow the organization to create a policy to control application specific activity. After enabling the AVC engine, what must be done to implement this?

    A. Use security services to configure the traffic monitor, .
    B. Use URL categorization to prevent the application traffic.
    C. Use an access policy group to configure application control settings.
    D. Use web security reporting to validate engine functionality

  • Question 365:

    An engineer is configuring Cisco WSA and needs to deploy it in transparent mode. Which configuration component must be used to accomplish this goal?

    A. MDA on the router
    B. PBR on Cisco WSA
    C. WCCP on switch
    D. DNS resolution on Cisco WSA

  • Question 366:

    An administrator is establishing a new site-to-site VPN connection on a Cisco IOS router.

    The organization needs to ensure that the ISAKMP key on the hub is used only for terminating traffic from the IP address of 172.19.20.24. Which command on the hub will allow the administrator to accomplish this?

    A. crypto ca identity 172.19.20.24
    B. crypto isakmp key Cisco0123456789 172.19.20.24
    C. crypto enrollment peer address 172.19.20.24
    D. crypto isakmp identity address 172.19.20.24

  • Question 367:

    Which option is the main function of Cisco Firepower impact flags?

    A. They alert administrators when critical events occur.
    B. They highlight known and suspected malicious IP addresses in reports.
    C. They correlate data about intrusions and vulnerability.
    D. They identify data that the ASA sends to the Firepower module.

  • Question 368:

    Which ASA deployment mode can provide separation of management on a shared appliance?

    A. DMZ multiple zone mode
    B. transparent firewall mode
    C. multiple context mode
    D. routed mode

  • Question 369:

    Which Cisco ISE service checks the state of all the endpoints connecting to a network for compliance with corporate security policies?

    A. Threat Centric NAC service
    B. posture service
    C. Cisco TrustSec
    D. compliance module

  • Question 370:

    A network administrator is setting up a site-to-site VPN from a Cisco FTD to a cloud environment. After the administrator configures the VPN on both sides, they still cannot reach the cloud environment. Which command must the administrator run on the FTD to verify that the VPN is encrypting traffic in both directions?

    A. show crypto ipsec sa
    B. show crypto ipsec stats
    C. show vpn-sessiondb detail l2l
    D. show crypto isakmp sa

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cisco exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 350-701 exam preparations and Cisco certification application, do not hesitate to visit our Vcedump.com to find your solutions here.