Sign In
Home/Cisco/Implementing and Operating Cisco Security Core Technologies (SCOR 350-701)/Free questions

Implementing and Operating Cisco Security Core Technologies (SCOR 350-701) — Free Practice Questions

10 free sample questions from a bank of 842, with the correct answers and explanations. No signup required — start practising right now.

1Which functions of an SDN architecture require southbound APIs to enable communication?
  • SDN controller and the network elements
  • management console and the SDN controller
  • management console and the cloud
  • SDN controller and the cloud
Answer: A

The short version

A — Southbound APIs connect the SDN controller to the network elements. The controller pushes forwarding instructions down to switches and routers while northbound APIs serve applications above it.

Key concepts in this question

  • Southbound API: the controller-to-device interface (for example OpenFlow or device protocols) carrying flow and policy down.
  • Northbound API: the application-to-controller interface exposing network abstractions upward.
  • Controller position: the middle layer translating application intent into device forwarding entries.

Why A is correct

SDN splits into applications on top, the controller in the middle, and network elements at the bottom. The controller-to-element link faces downward, which is the definition of southbound, and it is the path over which forwarding tables and policies are programmed. The banked key names exactly that pair.

Why the others are wrong

  • B. The management console talks to the controller through northbound interfaces, facing upward toward applications, not southbound.
  • C. Console-to-cloud is an orchestration relationship, not the controller-driven device-programming path southbound defines.
  • D. Controller-to-cloud integration uses northbound or cloud APIs for services, not southbound device control.

350-701 exam tip

South means down to switches: picture the controller pressing policy downward and the direction question answers itself.

2Which two behavioral patterns characterize a ping of death attack? (Choose two.)
  • The attack is fragmented into groups of 16 octets before transmission.
  • The attack is fragmented into groups of 8 octets before transmission.
  • Short synchronized bursts of traffic are used to disrupt TCP connections.
  • Malformed packets are used to crash systems.
  • Publicly accessible DNS servers are typically used to execute the attack.
Answer: B, D

The short version

B and D — Ping of death fragments in 8-octet units and uses malformed packets to crash systems. Oversized ICMP echo requests are sliced along 8-byte boundaries and reassembled beyond the legal IP size, corrupting or crashing vulnerable stacks.

Key concepts in this question

  • Ping of death: oversized or malformed ICMP that breaks reassembly on unpatched systems.
  • 8-octet fragments: IP fragment offsets are counted in 8-byte units, fixing the granularity.
  • Malformed-packet crash: reassembly past 65,535 bytes overflows buffers and crashes the target.

Why B and D are correct

IP fragmentation arithmetic forces every fragment offset to be a multiple of 8 octets, so the attack's fragments follow 8-byte grouping, and the reassembled datagram exceeds the maximum IP size. That malformed result is the crash vector: the victim's stack cannot handle the illegal reassembled packet and fails. Both halves together describe the attack, matching the banked keys.

Why the others are wrong

  • A. Sixteen-octet grouping contradicts the IP fragment-offset unit; granularity is 8 octets, not 16.
  • C. Short synchronized bursts disrupting TCP describe low-rate TCP-targeted DoS, not oversized ICMP reassembly.
  • E. Public DNS servers characterize amplification and reflection attacks, a different family from ping of death.

350-701 exam tip

Eight is enough to kill: 8-octet fragments plus a malformed oversized ping equals ping of death.

3Which information is required when adding a device to Firepower Management Center?
  • username and password
  • encryption method
  • device serial number
  • registration key
Answer: D

The short version

D — Adding a device to FMC requires the registration key. The sensor is preconfigured with a shared key that FMC uses to authenticate and complete the pairing.

Key concepts in this question

  • Firepower Management Center: the central manager that pairs with sensors for policy and health.
  • Registration key: the shared secret (NAT ID plus key) set on the device before adding it.
  • Pairing handshake: FMC presents the key to claim the waiting device.

Why D is correct

The documented onboarding flow configures a registration key on the managed device, then the administrator adds the device in FMC by supplying that same key (with the device's NAT ID where applicable). The matching key authenticates the pairing and establishes management, which is why the banked key names it as the required information.

Why the others are wrong

  • A. Device CLI credentials are not the pairing credential FMC asks for during the add operation.
  • B. No encryption-method selection is entered when adding the device; the secure channel follows from the key exchange.
  • C. The serial number is inventory data, not the shared secret that authorizes management pairing.

350-701 exam tip

No key, no pairing: FMC onboarding questions always resolve to the registration key.

4What can be integrated with Cisco Threat Intelligence Director to provide information about security threats, which allows the SOC to proactively automate responses to those threats?
  • Cisco Umbrella
  • External Threat Feeds
  • Cisco Threat Grid
  • Cisco Stealthwatch
Answer: B

The short version

B — Threat Intelligence Director consumes External Threat Feeds. STIX and TAXII feeds deliver observables and IOCs that TID converts into Firepower intelligence for automated SOC response.

Key concepts in this question

  • Threat Intelligence Director: the FMC feature that operationalizes third-party intelligence as enforceable objects.
  • External Threat Feeds: STIX/TAXII sources publishing indicators the SOC subscribes to.
  • Automated response: turning feed indicators into blocks and monitoring without manual rule writing.

Why B is correct

TID exists precisely to ingest outside intelligence: it polls configured STIX/TAXII feeds, normalizes the indicators into observable lists, and publishes them to managed devices so threats are blocked proactively. That feed-to-enforcement pipeline is the integration the stem describes and the banked key names.

Why the others are wrong

  • A. Umbrella provides DNS-layer enforcement, not the STIX/TAXII feed input TID is built around.
  • C. Threat Grid supplies sandbox malware verdicts to AMP and Firepower workflows, not TID's external feed subscription.
  • D. Stealthwatch contributes flow-based network analytics, a separate detection plane from TID feed ingestion.

350-701 exam tip

TID eats external feeds: threat-intel automation on this exam always starts with STIX/TAXII.

5Which Cisco command enables authentication, authorization, and accounting globally so that CoA is supported on the device?
  • aaa server radius dynamic-author
  • auth-type all
  • aaa new-model
  • ip device-tracking
Answer: C

The short version

C — aaa new-model globally enables AAA so CoA is supported. Change of Authorization rides on RADIUS dynamic authorization, which requires the AAA subsystem to be active first.

Key concepts in this question

  • aaa new-model: the global command that switches the device to AAA processing.
  • CoA: RADIUS Change of Authorization letting ISE alter a live session (re-authenticate, quarantine, disconnect).
  • Ordering rule: the CoA listener is useless until AAA itself is enabled device-wide.

Why C is correct

CoA messages are an AAA feature: the device can only honor dynamic-author requests once AAA is running globally. aaa new-model is the command that activates AAA processing on the platform, unlocking authorization handling including CoA support. The banked key therefore names the prerequisite command, not the CoA listener itself.

Why the others are wrong

  • A. aaa server radius dynamic-author configures the CoA listener, but without globally enabled AAA it has nothing to work with.
  • B. No auth-type all command enables AAA globally; it is a distractor against the real global command.
  • D. ip device-tracking follows endpoint attachment for visibility features and does not enable AAA or CoA.

350-701 exam tip

CoA needs AAA first: global enable with new-model before any dynamic-author line.

6What is a characteristic of Firepower NGIPS inline deployment mode?
  • ASA with Firepower module cannot be deployed
  • It cannot take actions such as blocking traffic
  • It is out-of-band from traffic
  • It must have inline interface pairs configured
Answer: D

The short version

D — Inline NGIPS requires inline interface pairs. Traffic enters one member of the pair and exits the other, placing the sensor directly in the forwarding path.

Key concepts in this question

  • Inline mode: the sensor sits in-path and can allow, block, or modify traffic in real time.
  • Inline interface pair: two linked interfaces forming the in-and-out path through the sensor.
  • Passive contrast: monitor or tap modes observe copies and cannot block.

Why D is correct

An inline sensor must physically or logically intercept the flow, which demands a paired ingress and egress interface so packets pass through inspection before continuing. Configuring those inline pairs is what makes blocking actions possible, and it is the defining characteristic the banked key states.

Why the others are wrong

  • A. ASA with Firepower modules can absolutely be deployed inline; the option's claimed impossibility is false.
  • B. Blocking traffic is the signature capability of inline mode; inability to act describes passive deployments instead.
  • C. Out-of-band placement describes passive monitoring, the opposite of the in-path inline design.

350-701 exam tip

Inline means in-path pairs: no interface pair, no inline blocking — that pairing is the whole answer.

7A mall provides security services to customers with a shared appliance. The mall wants separation of management on the shared appliance. Which ASA deployment mode meets these needs?
  • routed mode
  • multiple zone mode
  • multiple context mode
  • transparent mode
Answer: C

The short version

C — Multiple context mode gives each customer separated management. Each context acts as a virtual firewall with its own configuration, policies, and administrators on the shared appliance.

Key concepts in this question

  • Multiple context mode: virtualization of one ASA into independent logical firewalls.
  • Management separation: per-context admins who cannot see or change other tenants' configs.
  • Shared hardware: one appliance serving many customers with isolated policy planes.

Why C is correct

The mall needs one box with divided control, which is exactly what contexts provide: every tenant receives a self-contained virtual firewall, including its own management access, while sharing the physical appliance. Routed or transparent modes still present a single management plane, so only multiple context mode satisfies the separation requirement and the banked key.

Why the others are wrong

  • A. Routed mode changes Layer 3 forwarding behavior but keeps a single shared configuration and admin plane.
  • B. Multiple zone mode is not an ASA deployment mode; zoning belongs to other platforms' policy concepts.
  • D. Transparent mode makes the ASA a Layer 2 bump in the wire yet still under one management domain.

350-701 exam tip

Shared box with split brains means contexts: separation-of-management questions always land on multiple context mode.

8What is managed by Cisco Security Manager?
  • Cisco WLC
  • Cisco ESA
  • Cisco WSA
  • Cisco ASA
Answer: D

The short version

D — Cisco Security Manager manages the Cisco ASA. CSM is the enterprise manager for ASA firewalls, pushing consistent firewall policy across many appliances.

Key concepts in this question

  • Cisco Security Manager: the centralized manager for firewall and related security platforms.
  • ASA fit: the firewall appliance family inside CSM's managed portfolio.
  • Adjacent appliances: ESA, WSA, and WLC each report to different dedicated managers.

Why D is correct

CSM's role is scalable firewall administration, and the ASA is its flagship managed firewall: discovery, policy deployment, and audit all run through CSM for ASA estates. The other listed products belong to email, web, and wireless management planes, leaving the ASA as the correct managed device and the banked key.

Why the others are wrong

  • A. The Wireless LAN Controller is managed by wireless managers such as Prime Infrastructure, not CSM.
  • B. The Email Security Appliance is managed by its own SMA and email-security tooling, not CSM.
  • C. The Web Security Appliance likewise reports to web-security management, not CSM.

350-701 exam tip

CSM equals firewalls named ASA: email, web, and wireless boxes each live under their own managers.

9An organization is trying to improve their Defense in Depth by blocking malicious destinations prior to a connection being established. The solution must be able to block certain applications from being used within the network. Which product should be used to accomplish this goal?
  • Cisco Firepower
  • Cisco Umbrella
  • Cisco ISE
  • Cisco AMP
Answer: B

The short version

B — Cisco Umbrella blocks malicious destinations before connection and enforces app control. DNS-layer enforcement stops resolution of bad domains and applies destination and application policy up front.

Key concepts in this question

  • Defense in depth: layered controls that catch threats at successive stages, starting pre-connection.
  • DNS-layer blocking: refusing to resolve malicious domains so sessions never establish.
  • Application control: denying sanctioned or risky cloud apps as part of destination policy.

Why B is correct

Umbrella sits at the DNS layer, ahead of the connection: when users request a malicious or policy-blocked destination, Umbrella refuses or redirects the lookup and applies application rules before any session forms. That pre-connection destination plus application enforcement is precisely the requirement, making Umbrella the banked key.

Why the others are wrong

  • A. Firepower inspects traffic that is already connecting rather than blocking at pre-connection DNS resolution.
  • C. ISE governs identity-based network access and authorization, not malicious-destination blocking.
  • D. AMP dissects files and tracks malware trajectory after delivery rather than preventing the initial connection.

350-701 exam tip

Before they connect, Umbrella: pre-connection destination blocking always points at DNS-layer enforcement.

10An engineer notices traffic interruptions on the network. Upon further investigation, it is learned that broadcast packets have been flooding the network. What must be configured, based on a predefined threshold, to address this issue?
  • Storm Control
  • embedded event monitoring
  • access control lists
  • Bridge Protocol Data Unit guard
Answer: A

The short version

A — Configure Storm Control with a predefined threshold. It watches broadcast, multicast, and unknown-unicast rates per port and drops excess traffic once the level is crossed.

Key concepts in this question

  • Broadcast storm: runaway flooded frames that saturate links and interrupt legitimate traffic.
  • Storm Control: the port-level suppressor that polices flooded-traffic rates.
  • Threshold action: traffic beyond the configured level is dropped while normal traffic passes.

Why A is correct

Flooding symptoms call for a rate-based suppressor, not a filter or a script. Storm Control measures flooded frames against the administrator's threshold and discards the surplus, directly containing the broadcast flood described in the stem. That threshold-driven suppression is the banked key.

Why the others are wrong

  • B. Embedded event monitoring runs scripted responses to events; it does not police per-port flood rates.
  • C. Access control lists filter by addresses and protocols, not by volume exceeding a storm threshold.
  • D. BPDU guard shuts ports receiving spanning-tree BPDUs on PortFast edges; it does nothing against broadcast floods.

350-701 exam tip

Storm in the stem means Storm Control: flood-by-volume problems always end at the threshold suppressor.

Want the full bank of 842 questions for Implementing and Operating Cisco Security Core Technologies (SCOR 350-701)? See all practice exams.