350-701 Exam Details

  • Exam Code
    :350-701
  • Exam Name
    :Implementing and Operating Cisco Security Core Technologies (SCOR)
  • Certification
    :CCIE Security
  • Vendor
    :Cisco
  • Total Questions
    :784 Q&As
  • Last Updated
    :May 30, 2026

Cisco 350-701 Online Questions & Answers

  • Question 371:

    What are two recommended approaches to stop DNS tunneling for data exfiltration and command and control call backs? (Choose two.)

    A. Use intrusion prevention system.
    B. Block all TXT DNS records.
    C. Enforce security over port 53.
    D. Use next generation firewalls.
    E. Use Cisco Umbrella.

  • Question 372:

    Based on the NIST 800-145 guide, which cloud architecture is provisioned for exclusive use by a specific group of consumers from different organizations and may be owned, managed, and operated by one or more of those organizations?

    A. community cloud
    B. private cloud
    C. public cloud
    D. hybrid cloud

  • Question 373:

    Which two methods must be used to add switches into the fabric so that administrators can control how switches are added into DCNM for private cloud management? (Choose two.)

    A. Cisco Cloud Director
    B. Cisco Prime Infrastructure
    C. PowerOn Auto Provisioning
    D. Seed IP
    E. CDP AutoDiscovery

  • Question 374:

    Refer to the exhibit.

    Which type of authentication is in use?

    A. LDAP authentication for Microsoft Outlook
    B. POP3 authentication
    C. SMTP relay server authentication
    D. external user and relay mail authentication

  • Question 375:

    A large organization wants to deploy a security appliance in the public cloud to form a site-to-site VPN and link the public cloud environment to the private cloud in the headquarters data center.

    Which Cisco security appliance meets these requirements?

    A. Cisco Cloud Orchestrator
    B. Cisco ASAv
    C. Cisco WSAv
    D. Cisco Stealthwatch Cloud

  • Question 376:

    A malicious user gained network access by spoofing printer connections that were authorized using MAB on four different switch ports at the same time. What two catalyst switch security features will prevent further violations? (Choose two)

    A. DHCP Snooping
    B. 802.1AE MacSec
    C. Port security
    D. IP Device track
    E. Dynamic ARP inspection
    F. Private VLANs

  • Question 377:

    Which two services must remain as on-premises equipment when a hybrid email solution is deployed? (Choose two)

    A. DDoS
    B. antispam
    C. antivirus
    D. encryption
    E. DLP

  • Question 378:

    Which SNMPv3 configuration must be used to support the strongest security possible?

    A. asa-host(config)#snmp-server group myv3 v3 privasa-host(config)#snmp-server user andy myv3 auth sha cisco priv des ciscXXXXXXXX asa-host(config)#snmp-server host inside 10.255.254.1 version 3 andy
    B. asa-host(config)#snmp-server group myv3 v3 noauth asa-host(config)#snmp-server user andy myv3 auth sha cisco priv aes 256 ciscXXXXXXXX asa-host(config)#snmp-server host inside 10.255.254.1 version 3 andy
    C. asa-host(config)#snmpserver group myv3 v3 noauth asa-host(config)#snmp-server user andy myv3 auth sha cisco priv 3des ciscXXXXXXXX asa-host(config)#snmp-server host inside 10.255.254.1 version 3 andy
    D. asa-host(config)#snmp-server group myv3 v3 privasa-host(config)#snmp-server user andy myv3 auth sha cisco priv aes 256 ciscXXXXXXXX asa-host(config)#snmp-server host inside 10.255.254.1 version 3 andy

  • Question 379:

    How is data sent out to the attacker during a DNS tunneling attack?

    A. as part of the UDP/53 packet payload
    B. as part of the domain name
    C. as part of the TCP/53 packet header
    D. as part of the DNS response packet

  • Question 380:

    Refer to the exhibit.

    Refer to the exhibit. A Cisco ISE administrator adds a new switch to an 802.1X deployment and has difficulty with some endpoints gaining access.

    Most PCs and IP phones can connect and authenticate using their machine certificate credentials. However printer and video cameras cannot base d on the interface configuration provided, what must be to get these devices on to the network using Cisco ISE for authentication and authorization while maintaining security controls?

    A. Change the default policy in Cisco ISE to allow all devices not using machine authentication .
    B. Enable insecure protocols within Cisco ISE in the allowed protocols configuration.
    C. Configure authentication event fail retry 2 action authorize vlan 41 on the interface
    D. Add mab to the interface configuration.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cisco exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 350-701 exam preparations and Cisco certification application, do not hesitate to visit our Vcedump.com to find your solutions here.