Free 350-701 Exam Braindumps (page: 86)

Page 86 of 153

An engineer is adding a Cisco DUO solution to the current TACACS+ deployment using Cisco ISE. The engineer wants to authenticate users using their account when they log into network devices.
Which action accomplishes this task?

  1. Configure Cisco DUO with the external Active Directory connector and tie it to the policy set within Cisco ISE.
  2. Install and configure the Cisco DUO Authentication Proxy and configure the identity source sequence within Cisco ISE
  3. Create an identity policy within Cisco ISE to send all authentication requests to Cisco DUO.
  4. Modify the current policy with the condition MFASourceSequence DUO=true in the authorization conditions within Cisco ISE

Answer(s): B



A Cisco AMP for Endpoints administrator configures a custom detection policy to add specific MD5 signatures The configuration is created in the simple detection policy section, but it does not work What is the reason for this failure?

  1. The administrator must upload the file instead of the hash for Cisco AMP to use.
  2. The MD5 hash uploaded to the simple detection policy is in the incorrect format
  3. The APK must be uploaded for the application that the detection is intended
  4. Detections for MD5 signatures must be configured in the advanced custom detection policies

Answer(s): D



An organization is selecting a cloud architecture and does not want to be responsible for patch management of the operating systems.
Why should the organization select either Platform as a Service or Infrastructure as a Service for this environment?

  1. Platform as a Service because the customer manages the operating system
  2. Infrastructure as a Service because the customer manages the operating system
  3. Platform as a Service because the service provider manages the operating system
  4. Infrastructure as a Service because the service provider manages the operating system

Answer(s): C



An administrator is adding a new Cisco ISE node to an existing deployment.
What must be done to ensure that the addition of the node will be successful when inputting the FQDN?

  1. Change the IP address of the new Cisco ISE node to the same network as the others.
  2. Make the new Cisco ISE node a secondary PAN before registering it with the primary.
  3. Open port 8905 on the firewall between the Cisco ISE nodes
  4. Add the DNS entry for the new Cisco ISE node into the DNS server

Answer(s): D



Page 86 of 153



Post your Comments and Discuss Cisco® 350-701 exam with other Community members:

David A commented on January 16, 2024
Good Colombia
Anonymous
upvote

Kim commented on May 25, 2023
I just purchased and downloaded my files. Everything looks good so far.
UNITED STATES
upvote