● Implementing and Operating Cisco Security Core Technologies v2.0 (350-701 SCOR v2.0) Exam Materials






Question #1
Comment Image Comment Image Comment Image

A recent change left network engineers unable to SSH into a branch Cisco Catalyst switch. Network engineer confirms that the TACACS server group TACACS-GROUP is defined but not reachable. There is no fallback configured to the local database when TACACS+ is down. Security policy requires TACACS+ for primary authentication with automatic fallback to local accounts. Which configuration command must be added to resolve the issue? (Choose one answer)

  • A. aaa authentication login group TACACS-GROUP local
  • B. aaa authentication login ssh LOCAL TACACS-GROUP
  • C. aaa authentication login default group TACACS-GROUP local
  • D. aaa authentication serial console TACACS-GROUP LOCAL
Question #2
Comment Image Comment Image Comment Image

A large retail enterprise is deploying Cisco Secure Private Access to enable remote employees to reach internal applications without manual intervention. The IT department requires a seamless, zero-touch enrollment process where users are registered and authenticated transparently without requiring end-user action. The architecture must support robust high availability for back-end connectivity to ensure continuous access to private resources. Which configuration approach must the administrator implement to meet the requirement? (Choose one answer)

  • A. Define VPN Machine Tunnel with Certificates Enrollment and Connector Groups associated with the private resource.
  • B. Apply ZTA with SAML Enrollment including passwordless Enrollment and single Connector associated with the private resource.
  • C. Configure ZTA with SAML Enrollment and multiple Connector Groups associated with the private resource.
  • D. Implement ZTA with Certificate Enrollment and multiple Connector Groups associated with the private resource.
Question #3
Comment Image Comment Image Comment Image

Which authentication framework is employed to validate user credentials during the device initial enrollment handshake with MDM? (Choose one answer)

  • A. OIDC
  • B. CHAP
  • C. PAP
  • D. Kerberos
Question #4
Comment Image Comment Image Comment Image

Which OWASP LLM risk involves an attacker embedding hidden instructions in user input to manipulate the model's behavior? (Choose one answer)

  • A. Output Truncation
  • B. Prompt Injection
  • C. Data Exfiltration
  • D. System Prompt Leakage
Question #5
Comment Image Comment Image Comment Image

A network engineer is configuring NTP authentication on a Cisco Catalyst Switch to ensure secure time synchronization. The engineer configures the client and NTP server by running the ntp authentication-key 10 md5 CiscoR45745212 command. The engineer must associate the NTP client at IP address 10.10.10.2 with the NTP server at IP address 10.10.10.1 using the correct key. Which configuration completes the requirement? (Choose one answer)

  • A. ntp peer 10.10.10.1 key 10
  • B. ntp peer 10.10.10.2 key 10
  • C. ntp server 10.10.10.1 key 10
  • D. ntp server 10.10.10.2 key 10
Question #6
Comment Image Comment Image Comment Image

A healthcare organization is deploying Cisco Secure Access to prevent protected health information from being shared with generative AI services. The security team requires that real-time DLP inspection occur only on traffic destined for AI applications, with minimal false positives on general web browsing. The policy must also allow tuning based on proximity and match counts of PHI identifiers. Which configuration must the engineer perform to meet the requirement? (Choose one answer)

  • A. Implement an API-based DLP rule referencing a custom PHI data classification with tuned proximity and match-count thresholds, scoped to the generative AI application category.
  • B. Configure a real-time DLP rule referencing a built-in PHI data classification with default thresholds, scoped to a web profile that includes all internet traffic.
  • C. Deploy a real-time DLP rule referencing a built-in PHI data classification with tuned match-count thresholds, scoped to a web profile filtered by destination domain lists for known AI vendors.
  • D. Apply a real-time DLP rule referencing a custom PHI data classification with tuned proximity and match-count thresholds, scoped to a web profile filtered by the generative AI application category.
Question #7
Comment Image Comment Image Comment Image

Which IPS analysis technique matches traffic against a database of known attack patterns? (Choose one answer)

  • A. Anomaly-based detection
  • B. Heuristic detection
  • C. Signature-based detection
  • D. Behavioral analytics
Question #8
Comment Image Comment Image Comment Image

A multinational logistics firm is transitioning from a traditional VPN-based remote access model to Cisco Secure Private Access ZTA. The firm is migrating its existing legacy inventory management applications to a ZTA framework to minimize the attack surface. Security requirements mandate that access to the applications must be based on Zero Trust Principles. The solution must ensure that traffic is tunneled through secure connectors without exposing the application directly to the internet. Which configuration must be performed within the private resource definition to accomplish the task? (Choose two answers)

  • A. Apply specific hostnames and port protocols, bind it to an access policy that evaluates user group membership.
  • B. Configure CIDR-based network range and associate it with an access policy that enforces device posture and evaluates user group membership.
  • C. Create hostnames and port protocols tunneled through secure connector and bind it to an access policy that uses user group and device posture status.
  • D. Define specific hostnames, bind it to an access policy that evaluates user group membership while applying a posture bypass rule.
Question #9
Comment Image Comment Image Comment Image

Refer to the exhibit. What conclusion should an administrator draw about the URL malicious-domain-example.com? (Choose one answer)

  • A. domain is safe as Security Score is 25/100
  • B. high Threat Score along with the presence of DNS Tunneling and DGA
  • C. domain is a legacy site that has been compromised with Domain Age of 4 days
  • D. domain is blocked because it is newly registered domain regardless of the Threat Score
Question #10
Comment Image Comment Image Comment Image

Which compliance status is shown in EPP when a configured posture policy requirement is not met? (Choose one answer)

  • A. unknown
  • B. compliant
  • C. noncompliant
  • D. authorized