DON'T WANT TO MISS A THING?

Certification Exam Passing Tips

Latest exam news and discount info

Curated and up-to-date by our experts

Yes, send me the newsletter

Free Cisco 350-701 SCOR Practice Questions 2026 Part1 | Cisco Security Core

Are you preparing for the Cisco 350-701 certification exam? SPOTO offers the Cisco 350-701 Premium File; all questions are aligned with the latest exam content and come with expert-provided answers. Our question banks cover the latest question types, core concepts, and detailed explanations, helping you familiarize yourself with the exam format and difficulty level. Whether you are reviewing core concepts or simulating a real exam environment, these resources will rapidly boost your confidence and readiness.
For over two decades, SPOTO has successfully helped numerous IT professionals secure their ideal positions at Fortune 500 companies. Download now to start practicing efficiently and ensure a high score on the actual exam. Don't miss this opportunity to pass your certification exam with ease!
Take other online exams

Question #1
An engineer is configuring a Cisco ESA and wants to control whether to accept or reject email messages to a recipient address.Which list contains the allowed recipient addresses?
A. SAT
B. BAT
C. HAT
D. RAT
View answer
Correct Answer: D

View The Updated 350-701 Exam Questions

SPOTO Provides 100% Real 350-701 Exam Questions for You to Pass Your 350-701 Exam!

Question #2
Which action controls the amount of URI text that is stored in Cisco WSA logs files?
A. Configure the datasecurityconfig command
B. Configure the advancedproxyconfig command with the HTTPS subcommand
C. Configure a small log-entry size
D. Configure a maximum packet size
View answer
Correct Answer: B
Question #3
[Endpoint Protection and Detection]An engineer must deploy a Cisco Secure Web Appliance. Antimalware scanning must use the Outbreak Heuristics antimalware category on files identified as malware before performing any other processes. What must be configured on the Secure Web Appliance to meet the requirements?
A. Sophos scanning engine
B. Webroot scanning engine
C. McAfee scanning engine
D. Adaptive Scanning
E. Reveal Answer
View answer
Correct Answer: D
Question #4
What is a difference between FlexVPN and DMVPN?
A. DMVPN uses IKEv1 or IKEv2, FlexVPN only uses IKEv1
B. DMVPN uses only IKEv1 FlexVPN uses only IKEv2
C. FlexVPN uses IKEv2, DMVPN uses IKEv1 or IKEv2
D. FlexVPN uses IKEv1 or IKEv2, DMVPN uses only IKEv2
View answer
Correct Answer: C
Question #5
Which two endpoint measures are used to minimize the chances of falling victim to phishing and social engineering attacks? (Choose two)
A. Patch for cross-site scripting
B. Perform backups to the private cloud
C. Protect against input validation and character escapes in the endpoint
D. Install a spam and virus email filter
E. Protect systems with an up-to-date antimalware program
View answer
Correct Answer: DE
Question #6
Which two application layer preprocessors are used by Firepower Next Generation Intrusion PreventionSystem? (Choose two)
A. packet decoder
B. SIP
C. modbus
D. inline normalization
E. SSL
View answer
Correct Answer: BE
Question #7
Which two behavioral patterns characterize a ping of death attack? (Choose two.)
A. The attack is fragmented into groups of 16 octets before transmission
B. The attack is fragmented into groups of 8 octets before transmission
C. Short synchronized bursts of traffic are used to disrupt TCP connections
D. Malformed packets are used to crash systems
E. Publicly accessible DNS servers are typically used to execute the attack
View answer
Correct Answer: BD
Question #8
[Security Concepts]Which two descriptions of AES encryption are true? (Choose two)
A. ES is less secure than 3DES
B. ES is more secure than 3DES
C. ES can use a 168-bit key for encryption
D. ES can use a 256-bit key for encryption
E. ES encrypts and decrypts a key three times in sequence
View answer
Correct Answer: BD
Question #9
After deploying a Cisco ESA on your network, you notice that some messages fail to reach their destinations.Which task can you perform to determine where each message was lost?
A. Configure the trackingconfig command to enable message tracking
B. Generate a system report
C. Review the log files
D. Perform a trace
View answer
Correct Answer: A
Question #10
Which form of attack is launched using botnets?
A. EIDDOS
B. virus
C. DDOS
D. TCP flood
View answer
Correct Answer: C
Question #11
The main function of northbound APIs in the SDN architecture is to enable communication between which two areas of a network?
A. SDN controller and the cloud
B. management console and the SDN controller
C. management console and the cloud
D. SDN controller and the management solution
View answer
Correct Answer: D
Question #12
Which two features are used to configure Cisco ESA with a multilayer approach to fight viruses and malware?(Choose two)
A. Sophos engine
B. white list
C. RAT
D. outbreak filters
E. DLP
View answer
Correct Answer: AD
Question #13
Which two request of REST API are valid on the Cisco ASA Platform? (Choose two)
A. put
B. options
C. get
D. push
E. connect
View answer
Correct Answer: AC
Question #14
Which ASA deployment mode can provide separation of management on a shared appliance?
A. DMZ multiple zone mode
B. transparent firewall mode
C. multiple context mode
D. routed mode
View answer
Correct Answer: C
Question #15
Which flaw does an attacker leverage when exploiting SQL injection vulnerabilities?
A. user input validation in a web page or web application
B. Linux and Windows operating systems
C. database
D. web page images
View answer
Correct Answer: A
Question #16
[Security Concepts]Which two request of REST API are valid on the Cisco ASA Platform? (Choose two)
A. put
B. options
C. get
D. push
E. connect
View answer
Correct Answer: AC
Question #17
Which two conditions are prerequisites for stateful failover for IPsec? (Choose two)
A. Only the IKE configuration that is set up on the active device must be duplicated on the standby device; theIPsec configuration is copied automatically
B. The active and standby devices can run different versions of the Cisco IOS software but must be the same type of device
C. The IPsec configuration that is set up on the active device must be duplicated on the standby device
D. Only the IPsec configuration that is set up on the active device must be duplicated on the standby device;the IKE configuration is copied automatically
E. The active and standby devices must run the same version of the Cisco IOS software and must be the same type of device
View answer
Correct Answer: CE
Question #18
Which statement describes a traffic profile on a Cisco Next Generation Intrusion Prevention System?
A. It allows traffic if it does not meet the profile
B. It defines a traffic baseline for traffic anomaly deduction
C. It inspects hosts that meet the profile with more intrusion rules
D. It blocks traffic if it does not meet the profile
View answer
Correct Answer: B
Question #19
Which deployment model is the most secure when considering risks to cloud adoption?
A. Public Cloud
B. Hybrid Cloud
C. Community Cloud
D. Private Cloud
View answer
Correct Answer: D
Question #20
Which two preventive measures are used to control cross-site scripting? (Choose two)
A. Enable client-side scripts on a per-domain basis
B. Incorporate contextual output encoding/escaping
C. Disable cookie inspection in the HTML inspection engine
D. Run untrusted HTML input through an HTML sanitization engine
E. Same Site cookie attribute should not be used
View answer
Correct Answer: AB
Question #21
What is the primary role of the Cisco Email Security Appliance?
A. Mail Submission Agent
B. Mail Transfer Agent
C. Mail Delivery Agent
D. Mail User Agent
View answer
Correct Answer: B
Question #22
Which functions of an SDN architecture require southbound APIs to enable communication?
A. SDN controller and the network elements
B. management console and the SDN controller
C. management console and the cloud
D. SDN controller and the cloud
View answer
Correct Answer: A
Question #23
[Network Security]Which technology must be used to implement secure VPN connectivity among company branches over aprivate IP cloud with any-to-any scalable connectivity?
A. DMVPN
B. FlexVPN
C. IPsec DVTI
D. GET VPN
View answer
Correct Answer: D
Question #24
What is a characteristic of Firepower NGIPS inline deployment mode?
A. ASA with Firepower module cannot be deployed
B. It cannot take actions such as blocking traffic
C. It is out-of-band from traffic
D. It must have inline interface pairs configured
View answer
Correct Answer: D
Question #25
What must be used to detect malicious activity by leveraging global threat intelligence and correlating known attack patterns and malware behaviors with local threats by using machine learning?
A. isco Stealthwatch
B. isco Endpoint Security
C. isco Secure Firewall
D. isco Cognitive Threat Analytics
View answer
Correct Answer: D
Question #26
[Security Concepts]Which form of attack is launched using botnets?
A. IDDOS
B. irus
C. DOS
D. CP flood
View answer
Correct Answer: C
Question #27
What is the primary benefit of deploying an ESA in hybrid mode?
A. You can fine-tune its settings to provide the optimum balance between security and performance for your environment
B. It provides the lowest total cost of ownership by reducing the need for physical appliances
C. It provides maximum protection and control of outbound messages
D. It provides email security while supporting the transition to the cloud
View answer
Correct Answer: D
Question #28
[Security Concepts] What is the most commonly used protocol for network telemetry?
A. ASMTP
B. BSNMP
C. CTFTP
D. DNctFlow
View answer
Correct Answer: B
Question #29
What is the purpose of the Cisco Endpoint loC feature?
A. t is a signature-based engine
B. t provides precompromise detection
C. t provides stealth threat prevention
D. t is an incident response tool 6W
View answer
Correct Answer: D
Question #30
Which proxy mode must be used on Cisco WSA to redirect TCP traffic with WCCP?
A. transparent
B. redirection
C. forward
D. proxy gateway
View answer
Correct Answer: A
Question #31
What is the purpose of the Decrypt for Application Detection feature within the WSA Decryption options?
A. It decrypts HTTPS application traffic for unauthenticated users
B. It alerts users when the WSA decrypts their traffic
C. It decrypts HTTPS application traffic for authenticated users
D. It provides enhanced HTTPS application detection for AsyncOS
View answer
Correct Answer: D
Question #32
What is a feature of container orchestration?
A. ability to deploy Amazon ECS clusters by using the Cisco Container Platform data plane
B. ability to deploy Amazon EKS clusters by using the Cisco Container Platform data plane
C. ability to deploy Kubernetes clusters in air-gapped sites
D. automated daily updates
View answer
Correct Answer: C
Question #33
What is a capability of Cisco Secure Email Cloud Gateway compared to Cisco Secure Email Gateway?
A. ecure Email Cloud Gateway requires that a proxy be deployed to a web browser, and Secure Email Gateway requires a network reconfiguration
B. ecure Email Cloud Gateway protects email without having to deploy an infrastructure, and Secure Email Gateway requires a server infrastructure
C. ecure Email Cloud Gateway requires an ASA to redirect email by using WCCP, and Secure Email Gateway requires that the ASA be inline
D. ecure Email Cloud Gateway is an add-on that is deployed to a web browser by using a group policy, and Secure Email Gateway requires a server infrastructure
View answer
Correct Answer: B
Question #34
Which two risks is a company vulnerable to if it does not have a well-established patching solution for endpoints? (Choose two)
A. exploits
B. ARP spoofing
C. denial-of-service attacks
D. malware
E. eavesdropping
View answer
Correct Answer: AD
Question #35
An engineer wants to generate NetFlow records on traffic traversing the Cisco AS
A. Which Cisco ASAcommand must be used?
B. flow-export destination inside 1
C. ip flow monitor input
D. ip flow-export destination 1
E. flow exporter
View answer
Correct Answer: A
Question #36
An organization plans to upgrade its current email security solutions, and an engineer must deploy Cisco Secure Email. The requirements for the upgrade are:- Implement Data Loss Prevention- Implement mail encryption- Integrate with an existing Cisco IronPort Secure Email GatewaysolutionWhich Cisco Secure Email license needed to accomplish this task?
A. isco Secure Email Domain Protection
B. isco Secure Email Outbound Essentials
C. isco Secure Email Inbound Essentials
D. isco Secure Email Phishing Defense
View answer
Correct Answer: B
Question #37
[Security Concepts] What is the term for the concept of limiting communication between applications or containers on the same node?
A. Acontainer orchestration
B. Bsoftware-defined access
C. Cmicroservicing
D. Dmicrosegmentation
View answer
Correct Answer: D
Question #38
An engineer must configure Cisco AMP for Endpoints so that it contains a list of files that should not be executed by users. These files must not be quarantined. Which action meets this configuration requirement?
A. Modify the advanced custom detection list to include these files
B. Add a list for simple custom detection
C. Identify the network IPs and place them in a blocked list
D. Create an application control blocked applications list
View answer
Correct Answer: D
Question #39
Which Cisco security solution secures public, private, hybrid, and community clouds?
A. isco Cloudlock
B. isco ASAv
C. isco ISE
D. isco pxGrid
View answer
Correct Answer: A
Question #40
Which policy represents a shared set of features or parameters that define the aspects of a managed device that are likely to be similar to other managed devices in a deployment?
A. Group Policy
B. Access Control Policy
C. Device Management Policy
D. Platform Service Policy
View answer
Correct Answer: D
Question #41
What does the Cloudlock Apps Firewall do to mitigate security concerns from an application perspective?
A. It allows the administrator to quarantine malicious files so that the application can function, just not maliciously
B. It discovers and controls cloud apps that are connected to a company's corporate environment
C. It deletes any application that does not belong in the network
D. It sends the application information to an administrator to act on
View answer
Correct Answer: B
Question #42
Refer to the exhibit.What is a result of the configuration?
A. Traffic from the DMZ network is redirected
B. Traffic from the inside network is redirected
C. All TCP traffic is redirected
D. Traffic from the inside and DMZ networks is redirected
View answer
Correct Answer: D
Question #43
What is a feature of the open platform capabilities of Cisco DNA Center?
A. application adapters
B. domain integration
C. intent-based APIs
D. automation adapters
View answer
Correct Answer: C
Question #44
What is a feature of an endpoint detection and response solution?
A. Preventing attacks by identifying harmful events with machine learning and conduct-based defense
B. Rapidly and consistently observing and examining data to mitigate threats
C. Capturing and clarifying data on email, endpoints, and servers to mitigate threats
D. Ensuring the security of network devices by choosing which devices are allowed to reach the network
E. Reveal Answer
View answer
Correct Answer: B
Question #45
[Security Concepts] An organization has two machines hosting web applications. Machine 1 is vulnerable to SQL injection while machine 2 is vulnerable to buffer overflows. What action would allow the attacker to gain access to machine 1 but not machine 2?
A. Asniffing the packets between the two hosts
B. Bsending continuous pings
C. Coverflowing the buffer's memory
D. Dinserting malicious commands into the database
View answer
Correct Answer: D
Question #46
Why would a user choose an on-premises ESA versus the CES solution?
A. Sensitive data must remain onsite
B. Demand is unpredictable
C. The server team wants to outsource this service
D. ESA is deployed inline
View answer
Correct Answer: A
Question #47
In a PaaS model, which layer is the tenant responsible for maintaining and patching?
A. hypervisor
B. virtual machine
C. network
D. application
View answer
Correct Answer: D
Question #48
Refer to the exhibit. What does the API do when connected to a Cisco security appliance?
A. reate an SNMP pull mechanism for managing AMP
B. ather network telemetry information from AMP for endpoints
C. et the process and PID information from the computers in the network
D. ather the network interface information about the computers AMP sees
View answer
Correct Answer: D
Question #49
[Secure Network Access, Visibility, and Enforcement]Which algorithm provides encryption and authentication for data plane communication?
A. ES-GCM
B. HA-96
C. ES-256
D. HA-384
View answer
Correct Answer: A
Question #50
Which two probes are configured to gather attributes of connected endpoints using Cisco Identity ServicesEngine? (Choose two)
A. RADIUS
B. TACACS+
C. DHCP
D. sFlow
E. SMTP
View answer
Correct Answer: AC

View Answers after Submission

Please submit your email and WhatsApp to get the answers of questions.

Note: Please make sure your email ID and Whatsapp are valid so that you can get the correct exam results.

Email:
Whatsapp/phone number:
Contact Us