350-701 — Frequently Asked Questions
Community-vetted answers to 66 common questions about this exam.
Questions from real practice questions
Each Q&A comes from a specific community question — follow the link for its full analysis.
Which Two Methods Belong in an AAA Authentication Method List?
In aaa authentication login, login is the service keyword that names and applies the method list to line access; it is not itself a method. Valid method keywords include line, enable, local, group, and none.
default is the reserved method-list name used when no named list is applied to the login service. It appears before the method keywords, so it cannot be one of the methods inside the list.
Why Does IKEv1 IPsec Tunnel Show 'Proxy Identities Not Supported'?
Cisco's IPsec debug emits that message when the traffic selectors from the ACLs are not reversible between peers, so the phase 2 proposal is invalidated.
No; those typically show phase 1 negotiation or authentication failures, while 'proxy identities not supported' specifically flags mismatched interesting-traffic ACLs.
IaaS Model Features and Customer Responsibilities
In IaaS, the customer is responsible for patching the guest OS and applications. Automatic patching is a feature of PaaS or SaaS models.
While customers manage data, 'granular control' is vague. SDN segmentation is a specific, technical feature enabled by the IaaS networking layer.
Preventing Unauthorized DHCP Servers on Cisco Switches
Option 82 inserts relay agent info into requests for tracking. It does not filter or drop incoming DHCPOFFER packets from unauthorized servers.
Yes. An inbound ACL on the switch port or VLAN interface can filter DHCP reply packets based on source MAC/IP, blocking rogue servers.
What Is a Feature of an Endpoint Detection and Response Solution?
Option D describes preventing attacks with machine learning and conduct-based defense, which aligns with EPP or NGAV prevention. EDR's core feature is detection and response, as option C states.
Cisco AMP can use machine learning as an enabling technology, but the question asks for the defining EDR feature. SCOR separates EDR detection/response from EPP prevention controls.
How to Manually Update Outbreak Filter Rules on Cisco Secure Email Gateway?
outbreakconfig only displays and configures existing Outbreak Filter settings on the appliance; it does not contact Cisco's update servers. The rule download is performed by the Update Rules Now action in the GUI.
The refresh is incremental: AsyncOS compares local rule versions with Cisco's servers and downloads only changed rules, so up-to-date rules are retained as the question requires.
What Are Two Targets in Cross-Site Scripting Attacks?
An image is a delivery vector — a malicious img tag or a poorly validated image upload — but the target is what the injected script reaches: the victim's cookie or the application's input.
A header can carry a reflected payload in edge cases, but Cisco's two canonical targets are the user cookie and application input; a header is a transport path, not the stolen asset.
How Do You Quarantine Future Files in Cisco Secure Endpoint?
Advanced Custom Detections are for complex IOC logic, not for uploading a simple list of file hashes and setting quarantine; that is what Simple Custom Detections do.
Yes, Simple Custom Detections support a quarantine action; you upload SHA-256 hashes and choose Quarantine, Block, or Monitor/Audit as the protection action.
What Is Considered a Cloud Data Breach in Cisco 350-701?
Exploiting cloud application access is an attack method that can lead to a breach; the breach itself is the resulting leak or exposure of private information, as Cisco's SCOR cloud security terms describe.
They treat "cloud application" as the unique cloud keyword, but the question asks what a data breach is, and the breach is defined by leaked private information, not the access path.
Which Component Compresses Cisco ASA Cloud Logging Events?
The SDC VM hosts the Security Event Connector (SEC), which receives ASA syslog and NSEL events, compresses them, and forwards them to the Cisco cloud; the CDO event viewer only displays events.
No. Official SAL documentation shows the on-premises SDC VM's Security Event Connector performs compression; SWC is not the configured compression component for ASA cloud logging.
Cisco ASA Transparent Mode for Same-Subnet Traffic Filtering
Routed mode requires IP addresses on each interface and routes between subnets, so it would force readdressing. Transparent mode bridges the same subnet and still applies ACLs for higher-level filtering.
No. Multiple context mode is a virtualization feature that creates separate virtual firewalls; it does not by itself provide Layer 2 same-subnet filtering without readdressing.
What Is a Feature of Cisco DNA Center Open Platform Capabilities?
Intent APIs are Cisco DNA Center's northbound REST APIs that expose platform capabilities and provide policy-based abstraction, matching the documented open platform feature in option C.
No, those terms are distractors for this 350-701 item; Cisco DNA Center's documented open platform capability is Intent APIs, not generic adapter types.
Which Switch Port MAC Security Setting Prevents Laptop Movement?
Static requires manually entering each MAC address on each port, which contradicts the goal of simplifying administration for 200 new laptops.
Once a laptop's MAC is learned on a port and stored as sticky, connecting that laptop to another protected port triggers a port-security violation.
Which Two Devices Support WCCP for Traffic Redirection?
Because the option names an operating system, not a device, and the stem asks which two devices support WCCP; IOS-based routers are not offered as a separate device option.
It is the WCCP cache engine that joins a service group and receives redirected web requests, while the Cisco ASA acts as the WCCP-capable redirector in that pairing.
Classified Data Connection Algorithms
RSA is used for key exchange or signatures, not bulk data encryption. It is too slow for encrypting large data streams compared to AES.
No, SHA-384 is a hashing algorithm used for integrity verification. It does not encrypt data but ensures it hasn't been altered.
Which Security Mechanism Protects Against Offline Brute-Force Attacks?
MFA only challenges an attacker during a live login. Once password hashes are stolen, cracking happens locally with no server contact, so second factors never come into play.
It cannot stop guessing outright, but it kills precomputed rainbow tables and forces unique cracking work per account. Paired with bcrypt, scrypt or Argon2, cracking becomes impractical.
Limiting Cisco Router Attack Surface: Global Commands
Configuring SSH version 2 secures the protocol but does not reduce the attack surface by closing a service port or hiding device info like CDP or HTTP do.
No, it prevents unauthorized physical access to recover passwords but does not mitigate remote network-based attacks or reduce the number of active services.
Cisco Firewall Solution with Policy Language Support
It refers to the structured method of defining inspection policies between security zones, replacing the older interface-based ACL approach.
No. NGFW is a functional category including app-awareness, while ZFW is a specific configuration model available on Cisco IOS devices.
DHCP Snooping MAC Address Verification Drop Conditions
It triggers when the source MAC in the Ethernet frame differs from the Client Hardware Address in the DHCP payload on an untrusted port.
No, it only blocks DHCP offers/acks from untrusted ports. Other DHCP messages like Discover/Request are allowed to pass through.
Cisco ISE Guest WLAN Access Configuration
Hotspot portals often allow anonymous or social-media-only login, which limits detailed visibility into specific individual identities compared to self-registration.
Yes, self-registration allows guests to create their own accounts dynamically, reducing administrative overhead while maintaining unique identity tracking.
Cisco ASA SAL Integration Prerequisites
CDO acts as the central management plane that authenticates the ASA and configures the secure tunnel to the SAL cloud.
No, the ASA must be registered and managed via CDO to establish the authorized connection for Security Analytics and Logging.
Microsegmentation for Application and Container Communication
Orchestration manages deployment and scaling but doesn't enforce the granular network policies needed to limit communication.
Microsegmentation applies policies at the workload level (containers/VMs), whereas VLANs segment at the network switch level.
DMVPN vs IPsec VPN: High Availability and Failover
Standard IPsec site-to-site typically requires full-mesh configurations for spoke-to-spoke, whereas DMVPN enables dynamic spoke-to-spoke tunnels without pre-configuring every pair.
Yes, DMVPN is a Cisco proprietary technology. Standard IPsec is an open standard supported by most network vendors.
Configuring IEEE 802.1X Flexible Authentication for Layer 3
MAB is a Layer 2 authentication method. It authenticates devices based on their MAC address before any Layer 3 IP communication is established.
WebAuth requires the host to have an IP address and be able to send HTTP/HTTPS requests to a captive portal, which are Layer 3 and Layer 4 functions.
Cisco Secure Web Appliance Invalid Certificate Handling
Rejecting terminates the connection, preventing the WSA from scanning the content for malware or policy violations.
It allows the decryption process to continue for inspection, though specific trust policies may still apply.
Configuring HAT for Incoming Mail on Cisco Email Security Appliance
HAT controls incoming connections from senders (inbound), while RAT validates recipients for outgoing mail (outbound).
No, access lists only filter IPs. HATs are required to map senders to specific mail policies for content processing.
Definition of Phishing in Cybersecurity
No. Spam is unsolicited bulk communication (Option C). Phishing involves fraud and impersonation to deceive users (Option D).
Phishing is broad and targets anyone (Option D). Spear phishing targets specific individuals or organizations (Option A).
WSA HTTPS Reputation Bypass Decryption
ACLs match traffic to policies but do not contain the reputation logic itself. Disabling the policy directly prevents inspection for matched traffic.
Yes, it reduces visibility. It should only be done for sites with verified good reputations to balance security and performance.
Modifying Cisco AnyConnect Split Tunnel via Group Policy
Split tunneling and exclusion lists are configured within the Group Policy object under the Advanced settings for Remote Access VPN.
No, NAT exemption only prevents address translation. It does not determine whether traffic enters the VPN tunnel or exits locally; Group Policy controls that.
Configuring Switch Port Authentication Violation Replace Action
Restrict drops packets from unauthorized hosts and generates syslog messages, while replace removes the current authenticated session and allows the new host to authenticate immediately.
No, errdisable recovery applies to port-security, STP, or other physical/logical errors. 802.1X violations are handled by the 'authentication violation' command.
Configuring Malware Quarantine on Cisco Secure Email Gateway
Modifying the Default Policy affects all users globally. The exhibit shows a specific 'usera1' policy, indicating a need for granular control over that specific user's mail flow.
Yes, policies are evaluated top-down. The first matching policy wins. Placing a specific policy above the Default ensures it is processed first for those users.
SPAN Configuration for Traffic Baseline on Cisco Switch
WCCP is used to redirect live traffic to a service engine for processing (like filtering). It changes the traffic flow. SPAN is non-intrusive and copies traffic for observation only, which is required for baselining.
SPAN mirrors traffic within the same switch. RSPAN (Remote SPAN) requires a dedicated VLAN to carry mirrored traffic across multiple switches to a remote destination.
Cisco Secure Web Appliance Deployment Modes Comparison
Hybrid mode uses an on-prem appliance for caching and inspection while syncing policies with Umbrella. Cloud Connector redirects all traffic to Umbrella without local inspection.
No, Layer 4 traffic monitoring requires local packet inspection which is not performed in Cloud Connector mode as traffic is tunneled to the cloud.