Cisco Certified Security Operations Center (SCOR) Exam
Achieve Cisco certification in Security Operations Center with exam code 350-701.
Certification Overview
- Exam name: CCNP 350-701 SCOR
- Vendor: Cisco
- Exam code: 350-701
- Duration: 120 minutes
- Total questions: 100
- Passing score: 80%
About This Certification
The Cisco Certified Security Operations Center (SCOR) certification assesses expertise in security operations and incident response. The exam encompasses four primary domains: Security Concepts, Security Monitoring, Security Analysis, and Incident Response. Candidates are expected to demonstrate proficiency in various technologies and services, including Cisco SecureX, Cisco Umbrella, Cisco Firepower, and Cisco Identity Services Engine. Additionally, the exam evaluates knowledge of security frameworks and methodologies relevant to operational security. The certification validates the ability to implement security measures and respond effectively to incidents within an organizational context. Candidates must also understand the integration of security tools and the importance of continuous monitoring to protect against threats. The exam format consists of 100 questions to be completed within 120 minutes, with a passing score set at 80%.
Who Should Take This Exam?
Security Analyst, Security Engineer, Incident Responder, Network Security Administrator, IT Security Manager, Cybersecurity Consultant
Prerequisites
Valid CCNA certification or equivalent networking experience.
Topics Covered
- Topics to be announced
Question Types
- Multiple Choice (Single Answer)
- Multiple Choice (Multiple Answers)
- Drag and Drop
- Scenario-Based
CCNP 350-701 SCOR Practice Questions
Our question bank contains 724+ practice questions for this certification. Sample questions from each exam chapter. Expand a question to see the answer choices. With a subscription, you get unlimited practice exams with randomized questions from our full question bank.
Security Concepts
How does endpoint security enhance the overall security posture of an organization?
- It streamlines the incident response process to automatically perform digital forensics on the endpoint.
- It allows the organization to mitigate web-based attacks as long as the user is active in the domain.
- It allows the organization to detect and respond to threats at the edge of the network.
- It allows the organization to detect and mitigate threats that the perimeter security devices do not detect.
What feature does Cisco DNA Center's open platform capabilities offer?
- intent-based APIs
- automation adapters
- domain integration
- application adapters
What are two functions supported by TAXII?
- Exchange
- Pull messaging
- Binding
- Correlation
- Mitigating
Network Security
What SNMPv3 configuration should be used to ensure the highest level of security?
- asa-host(config)#snmp-server group myv3 v3 priv asa-host(config)#snmp-server user andy myv3 auth sha cisco priv des ciscXXXXXXXX asa-host (config)#snmp-server host inside 10.255.254.1 version 3 andy
- asa-host(config)#snmp-server group myv3 v3 noauth asa-host(config)#snmp-server user andy myv3 auth sha cisco priv aes 256 ciscXXXXXXXX asa-host(config)#snmp-server host inside 10.255.254.1 version 3 andy
- asa-host(config)#snmpserver group myv3 v3 noauth asa-host(config)#snmp-server user andy myv3 auth sha cisco priv 3des ciscXXXXXXXX asa-host(config)#snmp-server host inside 10.255.254.1 version 3 andy
- asa-host(config)#snmp-server group myv3 v3 priv asa-host(config)#snmp-server user andy myv3 auth sha cisco priv aes 256 ciscXXXXXXXX asa-host (config)#snmp-server host inside 10.255.254.1 version 3 andy
A mall wants separate management on a shared appliance for providing security services to customers. Which ASA deployment mode fulfills these requirements?
- routed mode
- transparent mode
- multiple context mode
- multiple zone mode
What policy on Cisco Firepower Management Center is utilized to gather alerts from health modules on managed devices?
- health policy
- system policy
- correlation policy
- access control policy
- health awareness policy
Securing the Cloud
When assessing risks to cloud adoption, which deployment model is considered the most secure?
- Public Cloud
- Hybrid Cloud
- Community Cloud
- Private Cloud
An engineer has received a task to deploy a solution capable of securing cloud users, data, and applications. The requirement is to utilize the Cisco cloud native CASB and cloud cybersecurity platform. What solution should be implemented to fulfill these requirements?
- Cisco Umbrella
- Cisco Cloud Email Security
- Cisco NGFW
- Cisco Cloudlock
An engineer wants to use behavioral analysis to spot harmful actions on hosts. They're setting up the organization's public cloud to send telemetry to a security device using the cloud provider's tools. What mechanism should the engineer set up for this purpose?
- mirror port
- Flow
- NetFlow
- VPC flow logs
Content Security
What action can one take to test whether traffic is being routed through the Cisco Umbrella network after configuring a new network identity in Cisco Umbrella?
- Ensure that the client computers are pointing to the on-premises DNS servers.
- Enable the Intelligent Proxy to validate that traffic is being routed correctly.
- Add the public IP address that the client computers are behind to a Core Identity.
- Browse to http://welcome.umbrella.com/ to validate that the new identity is working.
What does the Context Directory Agent do?
- maintains users' group memberships
- relays user authentication requests from Web Security Appliance to Active Directory
- reads the Active Directory logs to map IP addresses to usernames
- accepts user authentication requests on behalf of Web Security Appliance for user identification
What are two features of Cisco Email Security that can safeguard your organization from email threats?
- Time-based one-time passwords
- Data loss prevention
- Heuristic-based filtering
- Geolocation-based filtering
- NetFlow
Endpoint Protection and Detection
What makes implementing MFA important within an organization?
- To prevent man-in-the-middle attacks from being successful
- To prevent DoS attacks from being successful.
- To prevent brute force attacks from being successful.
- To prevent phishing attacks from being successful.
What advantage does installing Cisco AMP for Endpoints bring to a network?
- It provides operating system patches on the endpoints for security
- It provides flow-based visibility for the endpoints network connections
- It enables behavioral analysis to be used for the endpoints
- It protects endpoint systems through application control and real-time scanning
When should an organization opt for an Endpoint Detection and Response (EDR) solution instead of an Endpoint Protection Platform (EPP)?
- when there is a need for traditional anti-malware detection
- when there is no need to have the solution centrally managed
- when there is no firewall on the network
- when there is a need to have more advanced detection capabilities
Secure Network Access, Visibility, and Enforcement
Which two engines are included in Cognitive Threat Analytics for detection and analytics?
- data exfiltration
- command and control communication
- intelligent proxy
- snort
- URL categorization
What method is employed to distribute certificates and configure the supplicant on mobile devices for accessing network resources?
- BYOD onboarding
- Simple Certificate Enrollment Protocol
- Client provisioning
- MAC authentication bypass
A network admin is setting up a switch to utilize Cisco ISE for 802.1X. An endpoint can't get through authentication and can't connect to the network. Where should the admin start troubleshooting to confirm the authentication details?
- Adaptive Network Control Policy List
- Context Visibility
- Accounting Reports
- RADIUS Live Logs
Frequently Asked Questions
How many questions are on the exam?
The CCNP 350-701 SCOR exam contains 100 questions.
What is the passing score?
You need 80% to pass.
How long is the exam?
You have 120 minutes to complete the exam.
Practice with realistic mock exams to prepare for your Cisco certification.