Complete list of current Q & A>> Download Implementing and Operating Cisco Security Core Technologies (350-701) – Quiz 1 / 15 Category: Implementing and Operating Cisco Security Core Technologies (350-701) 1. How is DNS tunneling used to exfiltrate data out of a corporate network? A. It leverages the DNS server by permitting recursive lookups to spread the attack to other DNS servers B. It encodes the payload with random characters that are broken into short strings and the DNS server rebuilds the exfiltrated data C. It redirects DNS requests to a malicious server used to steal user credentials, which allows further damage and theft on the network D. It corrupts DNS servers by replacing the actual IP address with a rogue address to collect information or start other attacks 2 / 15 Category: Implementing and Operating Cisco Security Core Technologies (350-701) 2. What are two rootkit types? (Choose two.) A. registry B. buffer mode C. user mode D. bootloader E. virtual 3 / 15 Category: Implementing and Operating Cisco Security Core Technologies (350-701) 3. Which two kinds of attacks are prevented by multifactor authentication? (Choose two.) A. phishing B. brute force C. man-in-the-middle D. DDOS E. tear drop 4 / 15 Category: Implementing and Operating Cisco Security Core Technologies (350-701) 4. Which two prevention techniques are used to mitigate SQL injection attacks? (Choose two.) A. Check integer, float, or Boolean string parameters to ensure accurate values. B. Use prepared statements and parameterized queries. C. Secure the connection between the web and the app tier. D. Write SQL code instead of using object-relational mapping libraries. E. Block SQL code execution in the web application database login 5 / 15 Category: ServiceNow CSA 5. Which attack is commonly associated with C and C++ programming languages? A. cross-site scripting B. water holing C. DDoS D. buffer overflow 6 / 15 Category: Implementing and Operating Cisco Security Core Technologies (350-701) 6. Which two mechanisms are used to control phishing attacks? (Choose two.) A. Enable browser alerts for fraudulent websites. B. Define security group memberships. C. Revoke expired CRL of the websites. D. Use antispyware software. E. Implement email filtering techniques. 7 / 15 Category: Implementing and Operating Cisco Security Core Technologies (350-701) 7. Which functions of an SDN architecture require southbound APIs to enable communication? A. SDN controller and the network elements B. management console and the SDN controller C. management console and the cloud D. SDN controller and the cloud 8 / 15 Category: Implementing and Operating Cisco Security Core Technologies (350-701) 8. Which two request methods of REST API are valid on the Cisco ASA Platform? (Choose two.) A. put B. options C. get D. push E. connect 9 / 15 Category: Implementing and Operating Cisco Security Core Technologies (350-701) 9. The main function of northbound APIs in the SDN architecture is to enable communication between which two areas of a network? A. SDN controller and the cloud B. management console and the SDN controller C. management console and the cloud D. SDN controller and the management solution 10 / 15 Category: Implementing and Operating Cisco Security Core Technologies (350-701) 10. What is a feature of the open platform capabilities of Cisco DNA Center? A. application adapters B. domain integration C. intent-based APIs D. automation adapters 11 / 15 Category: Implementing and Operating Cisco Security Core Technologies (350-701) 11. Which form of attack is launched using botnets? A. TCP flood B. DDOS C. DOS D. virus 12 / 15 Category: Implementing and Operating Cisco Security Core Technologies (350-701) 12. In which form of attack is alternate encoding, such as hexadecimal representation, most often observed? A. smurf B. distributed denial of service C. cross-site scripting D. rootkit exploit 13 / 15 Category: Implementing and Operating Cisco Security Core Technologies (350-701) 13. Which flaw does an attacker leverage when exploiting SQL injection vulnerabilities? A. user input validation in a web page or web application B. Linux and Windows operating systems C. database D. web page images 14 / 15 Category: Implementing and Operating Cisco Security Core Technologies (350-701) 14. What is the difference between deceptive phishing and spear phishing? A. Deceptive phishing is an attacked aimed at a specific user in the organization who holds a C-level role. B. A spear phishing campaign is aimed at a specific person versus a group of people. C. Spear phishing is when the attack is aimed at the C-level executives of an organization. D. Deceptive phishing hijacks and manipulates the DNS server of the victim and redirects the user to a false webpage 15 / 15 Category: Implementing and Operating Cisco Security Core Technologies (350-701) 15. Which two behavioral patterns characterize a ping of death attack? (Choose two.) A. The attack is fragmented into groups of 16 octets before transmission. B. The attack is fragmented into groups of 8 octets before transmission. C. Short synchronized bursts of traffic are used to disrupt TCP connections. D. Malformed packets are used to crash systems. E. Publicly accessible DNS servers are typically used to execute the attack. Your score is 0% Restart quiz Send feedback