Cisco CCNP Security Core (SCOR) 350-701 practice questions

211 free questions with answers and explanations.

Practice test
  1. 201.A security engineer is designing a secure network access solution for a new branch office. The solution must provide granular access control based on user roles and device posture, and integrate with existing Active Directory for user authentication. Which Cisco technology is best suited to meet these requirements?Endpoint Security and Secure Network Access
  2. 202.A global enterprise is deploying Cisco Secure Client (formerly AnyConnect) for remote access VPN. The security team requires that remote users' devices must meet specific security posture requirements (e.g., up-to-date antivirus, operating system patches) before being granted VPN access. Which Cisco Secure Client module is primarily responsible for performing this endpoint posture assessment?Endpoint Security and Secure Network Access
  3. 203.A security analyst is investigating a suspected data exfiltration incident from an endpoint. The endpoint is running an Endpoint Detection and Response (EDR) solution. Which EDR capability would be most effective in determining the scope and method of the data exfiltration?Endpoint Security and Secure Network Access
  4. 204.A network security administrator is configuring a Cisco Catalyst switch to enforce secure network access using 802.1X. The requirement is for the switch to dynamically assign an endpoint to a specific VLAN based on the user's group membership in Active Directory, as determined by a RADIUS server. Which RADIUS attribute is primarily used by the Authentication Server to communicate the dynamic VLAN assignment to the switch?Endpoint Security and Secure Network Access
  5. 205.A network security engineer is implementing an access control solution for critical server infrastructure. The solution must ensure that access is granted based on the user's role and departmental affiliation, rather than individual user accounts, and that these policies can be consistently applied across diverse network devices and operating systems. Which access control model is best suited for this requirement?Visibility and Enforcement
  6. 206.A security architect is designing an endpoint security solution for a critical industrial control system (ICS) environment. Due to the sensitive nature and strict operational requirements, traditional active agents cannot be installed on all devices, and network segmentation must be extremely granular. Which approach would best integrate Zero Trust principles into this challenging environment?Endpoint Security and Secure Network Access
  7. 207.A network security engineer is designing a solution to protect internal network segments from unauthorized lateral movement. The design requires granular control over traffic flow between virtual machines within the same subnet, without hair-pinning traffic to a physical firewall. Which technology best addresses this requirement?Visibility and Enforcement
  8. 208.A network architect is designing a secure guest Wi-Fi solution for a corporate environment. The solution must ensure that guest users can access the internet but are strictly isolated from the internal corporate network and cannot communicate with each other. Which combination of technologies would best achieve these requirements?Visibility and Enforcement
  9. 209.A network security team is deploying a new secure network access solution for its campus network. The solution needs to dynamically assign users to specific VLANs and apply different access policies based on their authentication credentials and the health status of their endpoint device. Which component of an 802.1X deployment is responsible for communicating the authorization decision, including VLAN assignment, back to the network access device?Endpoint Security and Secure Network Access
  10. 210.A security engineer is designing a content security architecture for an organization with a hybrid workforce, including remote users and branch offices, all requiring consistent security policies and threat protection. The solution must integrate network security functions like secure web gateway (SWG), cloud access security broker (CASB), and zero-trust network access (ZTNA) into a unified cloud-native platform. Which architectural model best fits these requirements?Content Security
  11. 211.A network administrator is configuring a Cisco Secure Web Appliance (WSA) to prevent users from accessing websites categorized as 'Gambling' or 'Malicious Sites'. Which content security feature should the administrator configure to achieve this objective?Content Security