Cisco CCNP Security Core (SCOR) 350-701 practice questions

211 free questions with answers and explanations.

Practice test
  1. 51.A security engineer is troubleshooting an issue where a Cisco Secure Email Gateway (ESA) is blocking legitimate emails due to a high spam score, despite the sender being a trusted partner. The engineer has verified that the sender's IP address is not on any public blacklists. Which ESA feature should be adjusted to allow emails from this specific sender to bypass most spam checks?Content Security
  2. 52.A financial institution is implementing a bring-your-own-device (BYOD) policy and requires a solution to ensure that all personal devices connecting to the corporate network comply with security policies, such as having up-to-date antivirus software and a locked screen. If a device is non-compliant, it should be placed in a restricted network segment. Which technology is best suited for this requirement?Endpoint Security and Secure Network Access
  3. 53.A company is implementing a Zero Trust security model. As part of this, every network access attempt, regardless of origin (internal or external), must be explicitly verified and authorized before granting access. This verification must be continuous, meaning access can be revoked if the user or device posture changes during a session. Which Zero Trust principle does this scenario primarily highlight?Endpoint Security and Secure Network Access
  4. 54.A security analyst is reviewing a recent data breach incident where customer credit card numbers were stolen from a compromised database. The investigation reveals that the database was accessible over the internet without proper authentication, and the data was stored in plain text. Which core security principle was primarily violated in this incident?Security Concepts
  5. 55.A cloud security engineer is designing a secure network architecture for a new application deployed in a public cloud. The application requires strict isolation between its different tiers (web, application, database) and needs to control traffic flow based on IP addresses and ports. Which cloud security technology is most appropriate for enforcing these granular network segmentation policies within the virtual private cloud?Cloud Security
  6. 56.A security analyst is investigating a potential data exfiltration attempt where sensitive corporate documents were reportedly uploaded to an unsanctioned cloud storage service. The organization uses Cisco Firepower Threat Defense (FTD) appliances with a Firepower Management Center (FMC). Which FMC feature provides the most effective way to identify and block the specific content of these documents from leaving the network, regardless of the application or protocol used?Content Security
  7. 57.An organization is implementing a new policy that requires all employees to attend annual cybersecurity awareness training sessions. The primary goal of these sessions is to educate employees about common phishing attacks, safe browsing habits, and the importance of strong passwords. This initiative directly addresses which aspect of security best practices?Security Concepts
  8. 58.A security analyst is conducting a post-incident review after a successful ransomware attack. The review reveals that the organization lacked a clear understanding of its critical assets, their dependencies, and the business impact of their compromise. This deficiency significantly hampered effective incident response and prioritization. To prevent similar issues in the future, the organization needs to strengthen its efforts in which key area of security operations?Security Concepts
  9. 59.A company requires strict adherence to data residency regulations, mandating that certain categories of sensitive customer data must not be stored or processed outside a specific geographic region. The company uses cloud-based applications (SaaS) extensively. Which content security technology is best suited to enforce these data residency policies and prevent unauthorized data transfers to non-compliant cloud storage locations?Content Security
  10. 60.A large enterprise is evaluating different approaches to manage its cybersecurity posture. They are considering adopting a standardized set of guidelines and best practices, such as NIST Cybersecurity Framework or ISO 27001, to help them establish, implement, maintain, and continually improve their information security. This strategic decision is about implementing a:Security Concepts
  11. 61.An organization is deploying Cisco Secure Client (formerly AnyConnect) for remote access VPN. The security team wants to ensure that only devices meeting specific security criteria, such as having a compliant operating system version, enabled firewall, and up-to-date antivirus, are allowed to establish a VPN connection. Which Cisco component should be integrated with the remote access VPN solution to perform this comprehensive posture assessment and enforce access policies?Endpoint Security and Secure Network Access
  12. 62.A security analyst is investigating a potential data exfiltration attempt from a cloud storage bucket. The incident response plan requires immediate notification to the security team and automated blocking of the suspicious IP address at the network edge. Which cloud security automation and orchestration component is responsible for triggering predefined actions based on security events?Cloud Security
  13. 63.A company recently migrated its entire IT infrastructure to a cloud provider. The security team is now reviewing the shared responsibility model. They need to define clearly who is accountable for securing the operating system, network configuration, and data encryption. This exercise is a key component of which security concept?Security Concepts
  14. 64.A security architect is designing a content security solution for an enterprise with a large number of remote users who frequently access cloud applications. The solution must ensure consistent security policies, inspect encrypted traffic, and manage access to sanctioned and unsanctioned cloud services, regardless of the user's location or device. Which content security technology is best suited to meet these requirements?Content Security
  15. 65.A company is migrating its on-premises applications to a public cloud provider. They need to ensure that network traffic between their on-premises data center and the cloud environment is encrypted and secure, without exposing internal IP addresses to the public internet. Which cloud security technology best addresses this requirement?Cloud Security
  16. 66.A development team frequently uses cloud-based services and needs to securely access internal corporate resources from various locations, including home offices and public Wi-Fi. The security policy mandates that all data in transit to corporate resources must be encrypted and that the integrity of the communication must be guaranteed. Which VPN technology provides both data confidentiality and integrity through strong encryption and hashing algorithms, suitable for this remote access scenario?Endpoint Security and Secure Network Access
  17. 67.A security engineer is configuring a Cisco Firepower Threat Defense (FTD) device to protect internal users from malicious websites. The requirement is to block access to all gambling-related websites and generate an alert when a user attempts to access any site categorized as 'Adult.' Which content security feature should the engineer configure to meet these requirements?Content Security
  18. 68.A network administrator is deploying a new wireless network that must support both corporate devices using 802.1X with EAP-TLS for strong authentication and guest devices requiring a simple, temporary access method. The solution needs to dynamically assign different VLANs and access policies based on the authentication method and device type. Which secure network access design best accommodates these diverse requirements?Endpoint Security and Secure Network Access
  19. 69.A security engineer needs to implement content security for a remote workforce that uses various devices (laptops, tablets, smartphones) to access both corporate on-premise resources and cloud applications. The solution must ensure that all traffic is inspected for threats and adheres to company policies, regardless of the user's location or network. Which content security strategy would be most effective and scalable for this scenario?Content Security
  20. 70.A network security architect is designing a content security solution for a large enterprise that requires inspecting encrypted traffic for threats without compromising user privacy or application functionality. Which content security technology is best suited to achieve this by acting as a trusted intermediary?Content Security
  21. 71.A security engineer is deploying a Cisco Secure Email Gateway (ESA) and needs to implement policies that block emails containing specific keywords or phrases, such as 'confidential' or 'internal use only', when sent to external recipients. Which type of policy on the ESA is primarily used to achieve this content-based filtering?Content Security
  22. 72.A software development team is adopting a serverless architecture for a new application. They are concerned about the security implications of third-party libraries and dependencies used in their Lambda functions. To mitigate supply chain risks, they want to ensure that only approved and scanned code is deployed to production, and that functions are regularly checked for known vulnerabilities. Which security best practice is most relevant for addressing these concerns in a serverless environment?Cloud Security
  23. 73.A security administrator is evaluating a Cisco Secure Email Gateway (formerly ESA) for advanced threat protection. The organization frequently deals with highly targeted phishing campaigns that include zero-day malware attachments. Which feature of the ESA would provide the most effective defense against such sophisticated threats by analyzing suspicious files in a safe, isolated environment?Content Security
  24. 74.A cloud security engineer needs to implement a solution that automatically detects and remediates misconfigurations in their AWS environment, such as publicly exposed S3 buckets, overly permissive IAM policies, or unencrypted EBS volumes. Which cloud security tool category is purpose-built for this type of continuous posture management?Cloud Security
  25. 75.A security team is implementing a new intrusion detection system (IDS). Before deploying it to the production network, they want to ensure it effectively identifies malicious traffic patterns without generating excessive false positives. They decide to deploy the IDS in a passive 'tap' mode for a period, collecting alerts and comparing them against known legitimate and malicious activities. Which phase of the security operations lifecycle does this activity primarily fall under?Security Concepts
  26. 76.A company is migrating its on-premises applications to a public cloud provider. They need to ensure that all data in transit between their on-premises data center and the cloud environment is encrypted and protected from eavesdropping. The solution must also provide a secure, private connection that bypasses the public internet for sensitive workloads. Which cloud connectivity option would best fulfill these requirements?Cloud Security
  27. 77.A large enterprise is deploying a new secure network access solution for its remote workforce. The solution must provide secure connectivity to internal resources, prevent unauthorized access, and ensure that remote devices comply with security policies before granting access. Which secure network access technology is best suited to meet these requirements by establishing an encrypted tunnel and enforcing endpoint posture assessment?Endpoint Security and Secure Network Access
  28. 78.A security architect is designing an endpoint security architecture that must protect against both known and unknown threats, including zero-day exploits and polymorphic malware. The solution needs to integrate advanced threat detection capabilities with automated response actions. Which combination of endpoint security technologies best addresses this requirement?Endpoint Security and Secure Network Access
  29. 79.A managed security service provider (MSSP) is offering a new service to protect client endpoints from a wide range of threats, including malware, ransomware, and fileless attacks. The service must include advanced detection capabilities, the ability to contain threats, and a forensic investigation console. Which Cisco Secure Endpoint feature provides a centralized view and control over these advanced detection and response capabilities across all managed endpoints?Endpoint Security and Secure Network Access
  30. 80.A company is implementing a Zero Trust network architecture. As part of this, all endpoint devices, regardless of their location (on-premise or remote), must be continuously monitored for compliance and potential threats. Access to network resources will be granted only after a device's security posture is verified in real-time. Which endpoint security technology is fundamental to achieving this continuous monitoring and real-time posture assessment in a Zero Trust environment?Endpoint Security and Secure Network Access
  31. 81.A large organization is implementing a content security strategy across its global network. They need to ensure consistent security policies are applied to all web traffic, regardless of user location (on-premise, remote, or branch office), and that threat intelligence is shared in real-time across all security enforcement points. Which architectural approach best addresses these requirements?Content Security
  32. 82.A security architect is designing a cloud-native application that will process sensitive customer data. The application will leverage microservices deployed in a public cloud environment. Which security principle is most critical to ensure that a breach in one microservice does not compromise the entire application's data?Cloud Security
  33. 83.A development team is implementing a CI/CD pipeline for a cloud-native application. The security team wants to integrate security checks early in the development process to identify vulnerabilities in code and configurations before deployment. They aim to 'shift left' security. Which practice is most aligned with this 'shift left' security principle in a CI/CD pipeline?Cloud Security
  34. 84.A software development team is adopting a 'shift-left' security approach, integrating security testing and code reviews earlier in the development lifecycle. This aims to identify and remediate vulnerabilities before they reach production. Which security concept does this strategy best exemplify?Security Concepts
  35. 85.A security operations center (SOC) receives an alert indicating unusually high outbound network traffic from an internal server, destined for an unknown external IP address. Further investigation reveals that the server is communicating with a known command-and-control (C2) server associated with a specific malware family. This information about the C2 server and malware family is an example of:Security Concepts
  36. 86.A large e-commerce company is experiencing frequent web-based attacks, including SQL injection and cross-site scripting, targeting their cloud-hosted application. They need a security solution that can detect and prevent these specific application-layer attacks before they reach the backend servers, without requiring modifications to the application code. Which cloud security technology is best suited for this task?Cloud Security
  37. 87.A security architect is designing a content security solution for a global enterprise that uses Cisco Firepower Threat Defense (FTD) devices. The organization requires a centralized management console for all FTD appliances, consistent policy enforcement across multiple geographic regions, and unified reporting for security events. Which Cisco management platform best meets these requirements?Content Security
  38. 88.A security engineer is implementing a secure network access solution for IoT devices. These devices have limited processing power and do not support 802.1X or complex authentication protocols. The solution must provide secure network access and allow for device profiling to assign appropriate network segments. Which approach is most suitable for authenticating and authorizing these constrained IoT devices?Endpoint Security and Secure Network Access
  39. 89.A security operations center (SOC) receives a report from a third-party vendor detailing newly discovered vulnerabilities in a widely used software library, along with potential exploit techniques and indicators of compromise (IoCs). The SOC team uses this information to update their detection rules and patch management priorities. Which security concept does this scenario primarily illustrate?Security Concepts
  40. 90.A company is migrating its on-premises data warehouse to a public cloud provider. During the planning phase, the security team identifies a critical requirement: all data in transit between the on-premises network and the cloud data warehouse, as well as data at rest within the cloud storage, must be encrypted using FIPS 140-2 validated modules. Which cloud security control is most directly responsible for ensuring data at rest encryption meets this standard?Cloud Security
  41. 91.A network security administrator is configuring 802.1X authentication on a Cisco Catalyst switch. The goal is to ensure that only authenticated devices can access the network, and if authentication fails, the port should be placed into a state that prevents any traffic flow. Which 802.1X port control mode should be configured to achieve this strict security requirement?Endpoint Security and Secure Network Access
  42. 92.A multinational corporation is considering outsourcing its entire IT infrastructure to a cloud service provider (CSP). Before finalizing the contract, their legal and security teams are meticulously reviewing the CSP's Service Level Agreements (SLAs), compliance certifications (e.g., ISO 27001, SOC 2), and data processing agreements to ensure they meet the company's stringent data protection requirements and regulatory obligations across all operating regions. What specific area of security governance is being addressed by this comprehensive due diligence?Security Concepts
  43. 93.A cloud security engineer needs to implement a solution to automatically identify and remediate misconfigurations in cloud resources, such as open S3 buckets, overly permissive IAM policies, and unencrypted databases. This solution should continuously monitor the cloud environment and provide actionable insights. Which type of cloud security tool is best suited for this purpose?Cloud Security
  44. 94.A company uses a public cloud provider for its infrastructure. The security team needs to ensure that all administrative access to cloud resources is logged, and that these logs are immutable and can be used for auditing and forensic investigations. Which cloud service or feature is primarily responsible for recording API calls and configuration changes made to cloud resources?Cloud Security
  45. 95.A security operations center (SOC) receives an alert from its SIEM indicating multiple failed login attempts from an unknown IP address targeting a critical production server, followed by a successful login using a legitimate but rarely used administrative account. The SOC team immediately isolates the server, forces a password reset for the compromised account, and begins forensic analysis. Which security operation concept is the SOC team primarily demonstrating?Security Concepts
  46. 96.A security analyst is investigating a suspected malware infection originating from a user's web browser. The company uses a Cisco Umbrella deployment for DNS-layer security. Upon reviewing the Umbrella logs, the analyst observes that the user attempted to access a domain classified as 'Malware' which was subsequently blocked. What is the primary mechanism by which Cisco Umbrella prevented the malware infection in this scenario?Content Security
  47. 97.A security engineer is troubleshooting an issue where legitimate web traffic to a critical business application is being unexpectedly blocked by a Cisco Firepower Threat Defense (FTD) device. The application uses a custom, non-standard port and relies on specific HTTP headers for authentication. Which two components should the engineer primarily investigate to resolve this issue and ensure proper application access while maintaining security?Content Security
  48. 98.A cloud security team is implementing a new Intrusion Detection System (IDS) for their virtual network infrastructure. They need to analyze traffic flowing between different virtual machines (VMs) within the same virtual network, as well as traffic leaving and entering the virtual network from the internet. Which cloud networking feature is essential for enabling the IDS to passively monitor all relevant network traffic?Cloud Security
  49. 99.A security engineer is designing a content security architecture for a distributed enterprise with multiple branch offices and a central data center. Each branch office has local internet breakout, and the company utilizes both on-premise applications and SaaS cloud services. The design must ensure consistent content security policies, centralized management, and efficient threat intelligence sharing across all locations and cloud environments. Which architectural approach best meets these requirements?Content Security
  50. 100.A company is performing a detailed analysis of potential vulnerabilities in their web application. They are specifically focusing on identifying weaknesses that could be exploited by malicious actors, such as SQL injection flaws, cross-site scripting (XSS), and insecure direct object references (IDOR). This activity is a core part of which process?Security Concepts