Free 350-701 Practice Test Questions and Answers (2026)

Last Update Check

View Mode
Q: 1
[Security Concepts] What are two DDoS attack categories? (Choose two)
Options
30 comments in the community discussion
2
Option A is correct. Only asymmetric encryption actually uses a separate public and private key pair, like RSA or ECC. Symmetric (B) always just has one secret shared between both sides. Pretty sure exam reports confirm this logic but open to debate if someone has seen it otherwise.
1
B/D. Both are actual DDoS attack types, not seeing any Cisco books mention sequential or screen-based.
Q: 2
[Security Concepts] Which Cisco DNA Center Intent API action is used to retrieve the number of devices known to a DNA Center?
Options
34 comments in the community discussion
1
Its B. Had something like this in a mock and the endpoint without '/count' gave device details as well as a total device number in the response payload. I think just calling the network-device endpoint gets you what you need. Might be missing a detail here but pretty sure that's how it went.
1
Nah, I don’t think it’s B. A is the only one with /network-device/count, which is how you get just the device count without all the details. B returns device info instead, easy to mix up here.
Q: 3
[Security Concepts] Which technology should be used to help prevent an attacker from stealing usernames and passwords of users within an organization?
Options
23 comments in the community discussion
3
C or D? Seen people get tripped up by this, but IOS zone-based firewalls only let an interface be in one zone at a time. Option D matches what I remember from the config guides, not as flexible as some other firewalls. Correct me if I'm off here.
2
Option D, Saw similar wording in practice, MFA is what actually stops attackers with stolen credentials from getting in.
Q: 4
[Security Concepts] Based on the NIST 800-145 guide, which cloud architecture is provisioned for exclusive use by a specific group of consumers from different organizations and may be owned, managed, and operated by one or more of those organizations?
Options
34 comments in the community discussion
3
Option C, seen this in official guide and practice test questions before.
1
B , private cloud. "Exclusive use" makes me think of dedicated resources for one group, even if it's across orgs. Not sure if community is right here but open to being corrected.
Q: 5
[Security Concepts] Which algorithm provides asymmetric encryption?
Options
34 comments in the community discussion
2
C vs D? I think it's C (RSA) since it's the only asymmetric choice. D (3DES) is a trap because it's legacy but still symmetric like AES and RC4. Pretty sure C's correct but let me know if I'm missing something.
1
I get the confusion here, but C for RSA.
Q: 6
[Security Concepts] Which security product enables administrators to deploy Kubernetes clusters in air-gapped sites without needing Internet access?
Options
24 comments in the community discussion
2
Nah, not B here. C is the one purpose-built for air-gapped Kubernetes, while B is a distractor that trips people up by name similarity. Unless something changed recently, it's definitely C.
1
C , but Cisco needs to stop messing with these product names. Seen similar in exam reports and only Cisco Container Platform is meant for air-gapped Kubernetes. The others don’t fit offline use.
Q: 7

DRAG DROP [Network Security] Drag and drop the VPN functions from the left onto the description on the right.

Drag & Drop
32 comments in the community discussion
6
SHA-1 → ensures data integrity, ISAKMP → defines IKE SAs, AES → confidentiality, RSA → authentication. Only thing is if they asked about signing or digital signatures, could maybe flip SHA-1 and RSA in a weird context, but for VPNs pretty sure this matches Cisco docs. Let me know if I'm missing an edge case.
4
SHA-1 to ensures data integrity, ISAKMP to defines IKE SAs, AES to ensures data confidentiality, RSA to provides authentication. Seen a similar mapping in official practice labs. Pretty sure that's right for VPN fundamentals, but open if anyone has seen different options on their exam.
Q: 8
[Endpoint Protection and Detection] An engineer needs a solution for TACACS+ authentication and authorization for device administration. The engineer also wants to enhance wired and wireless network security by requiring users and endpoints to use 802.1X, MAB, or WebAuth. Which product meets all of these requirements?
Options
31 comments in the community discussion
2
encountered exactly similar question in my exam, on my practice set, it's B.
2
These Cisco product names always trip people up, it's like they want us to confuse Prime and ISE every exam. Option B
Q: 9

DRAG DROP [Security Concepts] Drag and drop the features of Cisco ASA with Firepower from the left onto the benefits on the right.

Drag & Drop
28 comments in the community discussion
4
Don’t think NGIPS should be on the detection/blocking/remediation line. AMP is Cisco’s advanced malware solution, so more aligned with that benefit. The proper mapping is: AMP → detection/blocking/remediation, Full Context Awareness → policy enforcement with visibility, Collective Security Intelligence → real-time thre
4
AMP → detection, blocking and remediation; Full Context Awareness → policy enforcement with user/VM visibility; Collective Security Intelligence → real-time threat intelligence; NGIPS → threat prevention and mitigation for known/unknown threats. Got this mapping from Cisco docs too. Only slight uncertainty is if AMP an
Q: 10

DRAG DROP [Security Concepts] Drag and drop the capabilities from the left onto the correct technologies on the right. Cisco 350-701 question

Drag & Drop
43 comments in the community discussion
6
Next Generation Intrusion Prevention System matches with "superior threat prevention and mitigation for known and unknown threats," while Advanced Malware Protection is about "detection, blocking, tracking, analysis, and remediation." App-layer control lines up with "application control and URL filtering," and WSA i
6
NGIPS → superior threat prevention, AMP → detection/blocking/analysis/remediation, app control/URL filtering → application-layer, WSA → integrated web protection.
Q: 11
[Endpoint Protection and Detection] Which Cisco ISE feature helps to detect missing patches and helps with remediation?
Options
5 comments in the community discussion
1
B tbh. You need ntp server 1.1.1.1 key 1 on the client so it uses key 1 with that NTP server. The other choices are flipped or use wrong IP. Pretty sure that's it, but open to corrections.
Its A
Q: 12
[Content Security] An organization received a large amount of SPAM messages over a short time period. In order to take action on the messages, it must be determined how harmful the messages are and this needs to happen dynamically. What must be configured to accomplish this?
Options
7 comments in the community discussion
C or D but D makes more sense since Cisco ESA can actually change policies on the fly based on observed email traffic, which helps react dynamically to spam surges. WSA isn't really for email so I'm sticking with D. Anyone disagree?
D tbh, seen similar logic in official guide and some practice exams too.
Q: 13
[Security Concepts] Which two risks is a company vulnerable to if it does not have a well-established patching solution for endpoints? (Choose two)
Options
9 comments in the community discussion
5
C. DevSecOps is all about building security into development, not just doing scans or isolating security teams. Think C fits best here.
1
Its A and D. Similar question showed up in official practice, check the Cisco exam guide for more on this.
Q: 14
[Security Concepts] What is a benefit of using Cisco AVC (Application Visibility and Control) for application control?
Options
6 comments in the community discussion
Nah, I think D is better here. AVC is all about real-time monitoring which lines up with dynamic application scanning. A looks tempting but isn't really what AVC focuses on. Pretty sure D is correct, open to other takes though.
I don’t think it’s D. A was the pick on a similar question in one of my mock tests.
Q: 15
[Security Operations] Which security solution uses NetFlow to provide visibility across the network, data center, branch offices, and cloud?
Options
11 comments in the community discussion
1
D , Umbrella always pops up as a network-wide solution so it’s tempting. NetFlow mention is tricky though.
1
Option B, had something like this in a mock and Stealthwatch was correct there too.
Q: 16
[Security Concepts] What is managed by Cisco Security Manager?
Options
12 comments in the community discussion
5
C. had something like this in a mock exam and it was ASA for sure.
2
A imo
Q: 17

DRAG DROP [Secure Network Access, Visibility, and Enforcement] Refer to the exhibit. Cisco 350-701 question An engineer must configure a Cisco switch to perform PPP authentication via a TACACS server located at IP address 10.1.1.10. Authentication must fall back to the local database using the username LocalUser and password C1Sc0451069341l if the TACACS server is unreachable. Drag and drop the commands from the left onto the corresponding configuration steps on the right. Cisco 350-701 question

Drag & Drop
7 comments in the community discussion
5
aaa new-model, tacacs-server host 10.1.1.10, tacacs-server key, aaa authentication ppp test group tacacs+ local
4
aaa new-model → tacacs-server host 10.1.1.10 → tacacs-server key → aaa authentication ppp test group tacacs+ local. Saw this order in the official guide and labs, looks like the standard setup flow for PPP + TACACS fallback.
Q: 18
[Security Concepts] What is the Cisco API-based broker that helps reduce compromises, application risks, and data breaches in an environment that is not on-premise?
Options
4 comments in the community discussion
2
C or B. I picked C because dynamically categorizing uncategorized traffic seems like a strong benefit, especially for new threats. Pretty sure Umbrella can handle unknown sites well, but not 100% if that's main advantage over tunneling suspicious IPs.
B tbh, since Cisco Umbrella offers cloud-delivered security and protects users when they're offsite. I know it's not strictly API-based like Cloudlock, but Umbrella is focused on securing cloud access and apps too. I might be mixing up product features a bit though, so correct me if I'm way off.
Q: 19

DRAG DROP [Security Concepts] Drag and drop the Firepower Next Generation Intrusion Prevention System detectors from the left onto the correct definitions on the right. Cisco 350-701 question

Drag & Drop
6 comments in the community discussion
Seen similar on practice, I'd map it as: Distributed PortScan → many-to-one, Decoy PortScan → one-to-one with spoofing, Port Sweep → one-to-many single port, PortScan Detection → one-to-one multiple ports. Not 100% sure if Decoy and Distributed trip people up sometimes, though.
Nah, I think Distributed PortScan should be matched with many-to-one. Trap is mixing up port sweep and decoy.
Q: 20

DRAG DROP An engineer must configure AsyncOS for Cisco Secure Web Appliance to push log files to a syslog server using the SCP retrieval method. Drag and drop the steps from the left into the sequence on the right to complete the configuration. Cisco 350-701 question

Drag & Drop
5 comments in the community discussion
5
Step 1: Set SCP as log subscription, Step 2: Add SSH public host key, Step 3: Add keys to remote, Step 4: Commit-order matters since trust setup can't be after subscription is saved. Saw one where skipping host key flipped it.
4
Not quite right, I think the correct mapping is file access from a different user → learns normal behavior, interesting file access → sensitive files, user login suspicious behavior → access failures/methods, privilege escalation → process lineage movement. Trap is mixing up the first two!
Question 1 of 20

What's covered in this practice questions set

2: Network Security · 9 questions

📖 About this Domain

This domain covers the implementation of core network security controls and architectures. It focuses on securing network access, traffic, and devices using fundamental security technologies like Layer 2 controls, NGFW, and VPNs.

🎓 What You Will Learn

  • You will learn to implement Layer 2 security controls like 802.1X, port security, and DHCP snooping to mitigate LAN-based attacks.
  • You will learn to configure and verify network security solutions including NGFW, NGIPS, and NetFlow for traffic inspection and visibility.
  • You will learn the fundamentals of VPN technologies, including the components of IPsec like IKE, ESP, and AH for secure remote access.
  • You will learn to implement infrastructure protection mechanisms such as Control Plane Policing (CoPP) and Unicast RPF to secure network devices.

🛠️ Skills You Will Build

  • You will build skills to configure network segmentation and zoning to isolate traffic and reduce the attack surface.
  • You will build skills to deploy and manage secure remote access solutions using IPsec and SSL VPNs.
  • You will build skills to harden network devices and implement secure management access using protocols like SNMPv3 and SSH.
  • You will build skills to analyze network traffic using tools like SPAN, RSPAN, and NetFlow for security monitoring.

💡 Top Tips to Prepare

  • Focus on hands-on configuration of Layer 2 security features like DAI and IP Source Guard in a lab environment.
  • Master the IPsec framework, including the differences between IKEv1 and IKEv2 phases, and the roles of ESP and AH.
  • Understand the traffic flow and policy enforcement on Next-Generation Firewalls (NGFW) and Next-Generation IPS (NGIPS).
  • Practice interpreting syslog and NetFlow data to identify security events and anomalies on the network.

3: Securing the Cloud · 3 questions

📖 About this Domain

This domain covers security solutions and concepts for public, private, hybrid, and multicloud environments. It focuses on comparing key cloud security technologies like CASB, CWPP, and CSPM, and integrating security into modern development pipelines.

🎓 What You Will Learn

  • Compare cloud security solutions like Cloud Access Security Broker (CASB), Cloud Workload Protection Platform (CWPP), and Cloud Security Posture Management (CSPM).
  • Describe security concepts for modern cloud environments, including DevSecOps, CI/CD pipelines, and container security for Docker and Kubernetes.
  • Explain security considerations for serverless architectures and the use of cloud-native controls such as security groups and network ACLs.
  • Understand secure network design principles for the cloud, including segmentation, microsegmentation, and Zero Trust architecture.

🛠️ Skills You Will Build

  • Ability to evaluate and select appropriate security solutions (CASB, CWPP, CSPM) for different cloud deployment models.
  • Capability to integrate security practices into DevOps and CI/CD pipelines to implement a DevSecOps model.
  • Competence in securing cloud-native applications, including containers, Kubernetes clusters, and serverless functions.
  • Proficiency in designing secure cloud networks using principles like microsegmentation, Zero Trust, and encryption.

💡 Top Tips to Prepare

  • Focus on the distinct functions and use cases of CASB, CWPP, and CSPM, as comparing them is a key objective.
  • Understand the security challenges and solutions specific to containers like Docker and orchestrators like Kubernetes.
  • Master cloud-native security controls like security groups and network ACLs, and how they differ from traditional on-premises firewalls.
  • Grasp the core tenets of Zero Trust and how it applies to cloud environments, particularly with microsegmentation.

6: Secure Network Access, Visibility, and Enforcement · 3 questions

📖 About this Domain

This domain covers network access control, visibility, and enforcement using core Cisco security solutions. It emphasizes endpoint compliance and identity-based access through Cisco ISE. It also details network telemetry and threat detection with Stealthwatch and micro-segmentation with Cisco Secure Workload.

🎓 What You Will Learn

  • You will learn to configure network access device functionality including 802.1X, MAB, and WebAuth for endpoint authentication.
  • You will learn to build and verify authentication and authorization policies within Cisco ISE policy sets.
  • You will learn the architecture of Cisco Stealthwatch Enterprise and Stealthwatch Cloud for network traffic analysis using NetFlow.
  • You will learn the concepts of application workload protection and policy enforcement using Cisco Secure Workload (formerly Tetration).

🛠️ Skills You Will Build

  • You will build skills to implement RADIUS-based network access control for wired and wireless endpoints.
  • You will build skills to create granular authorization profiles in Cisco ISE that assign dACLs and SGTs for policy enforcement.
  • You will build skills to interpret network telemetry from flow collectors and sensors to identify security incidents.
  • You will build skills to describe application dependency mapping and micro-segmentation policy for data center security.

💡 Top Tips to Prepare

  • Master the complete 802.1X operational flow, including EAP methods and the role of the supplicant, authenticator, and authentication server.
  • Practice configuring Cisco ISE policy sets, focusing on the differentiation between authentication and authorization rules.
  • Understand the architectural components of Stealthwatch, including the role of the SMC, Flow Collector, and Flow Sensor.
  • Differentiate the primary use cases for ISE, Stealthwatch, and Secure Workload in a zero-trust framework.

1: Security Concepts · 2 questions

📖 About this Domain

This domain covers foundational security principles, threat landscapes, and cryptographic components. It establishes the core knowledge for understanding network security architectures, threat intelligence, and concepts like Zero Trust and defense-in-depth.

🎓 What You Will Learn

  • You will learn to identify common threats, vulnerabilities using CVE/CVSS, and exploits including malware types and threat actor profiles.
  • You will learn to compare fundamental security concepts such as risk assessment, threat intelligence feeds, and the principle of least privilege.
  • You will learn to describe core cryptography components like PKI, hashing, symmetric vs. asymmetric encryption, and cipher suites.
  • You will learn to explain network security architecture principles for on-premises and cloud environments, including segmentation and SIEM/SOAR integration.

🛠️ Skills You Will Build

  • You will build the skill to differentiate between threat actors and analyze attack vectors using threat intelligence platforms.
  • You will build the skill to apply the Zero Trust security model and principles of least privilege to network design.
  • You will build the skill to interpret cryptographic elements in secure communications like SSL/TLS handshakes and SSH.
  • You will build the skill to differentiate between North-bound and South-bound APIs in an SDN architecture.

💡 Top Tips to Prepare

  • Focus on the practical differences between symmetric and asymmetric encryption, including their specific use cases in protocols.
  • Master the key tenets of Zero Trust and how it contrasts with traditional perimeter-based security models.
  • Practice interpreting CVSS scores and understanding the vulnerability management lifecycle from discovery to patching.
  • Understand the data flow and API functions within a Software-Defined Networking (SDN) architecture for security automation.

4: Content Security · 2 questions

📖 About this Domain

This domain covers the implementation of content security to protect against threats delivered via web and email traffic. It focuses on Cisco's security portfolio, including web proxies, email security gateways, and DNS-layer security. Key technologies include Cisco Secure Web Appliance (WSA), Secure Email Gateway (ESA), and Cisco Umbrella.

🎓 What You Will Learn

  • Implement web security using Cisco Secure Web Appliance (WSA) and Secure Web Cloud, including decryption policies and authentication methods.
  • Configure Cisco Secure Email Gateway (ESA) and Cloud Email Security (CES) to mitigate threats like spam, malware, and data loss.
  • Deploy Cisco Umbrella to provide DNS-layer security and block malicious destinations before a connection is established.
  • Utilize application visibility and control (AVC) to enforce granular policies on specific web applications and user activities.

🛠️ Skills You Will Build

  • Configuration of traffic redirection methods like Web Cache Communication Protocol (WCCP) and transparent proxy settings.
  • Policy creation for SSL/TLS decryption, URL filtering, and application control on a web security appliance.
  • Implementation of anti-spam, anti-virus, and outbreak filters on an email security gateway.
  • Deployment and policy enforcement within the Cisco Umbrella dashboard for DNS and web security.

💡 Top Tips to Prepare

  • Gain hands-on experience with the GUIs of Cisco WSA, ESA, and the Umbrella dashboard to understand policy configuration workflows.
  • Master the concepts of traffic redirection, specifically WCCPv2, and explicit proxy forwardings for web security deployments.
  • Understand the architectural differences between on-premises solutions versus their cloud-based counterparts like WSA vs. Secure Web Cloud.
  • Focus on SSL/TLS decryption policies, as inspecting encrypted traffic is a critical component of modern content security.

5: Endpoint Protection and Detection · 1 questions

📖 About this Domain

This domain covers the security of host systems using advanced endpoint solutions. It details the implementation of Endpoint Protection Platforms (EPP) and Endpoint Detection and Response (EDR). The focus is on threat detection, investigation, and response at the endpoint level.

🎓 What You Will Learn

  • You will learn to implement endpoint security controls including antimalware, host intrusion prevention, and application control.
  • You will learn to compare persistent agent and agentless endpoint posture assessment solutions for network access.
  • You will learn the core features of an EDR solution, such as threat hunting, investigation, and response.
  • You will learn to configure and verify Cisco AMP for Endpoints policies, groups, exclusions, and custom detections.

🛠️ Skills You Will Build

  • You will build the skill to deploy and manage Cisco AMP for Endpoints, including policy and group creation.
  • You will build the skill to interpret endpoint event data like file trajectory, network flow, and parent process information.
  • You will build the skill to configure outbreak controls and Indicators of Attack (IOA) for proactive threat mitigation.
  • You will build the skill to implement custom detections and exclusions to tune endpoint security performance.

💡 Top Tips to Prepare

  • Focus on Cisco AMP for Endpoints configuration, specifically policies for outbreak control and IOA rules.
  • Understand the functional differences between EPP for prevention and EDR for detection and response.
  • Practice analyzing file trajectory and process lineage within the AMP console to trace malware execution.
  • Master the role of asset and patch management as a critical component of endpoint security posture.

Premium Access Includes

  • Quiz Simulator
  • Exam Mode
  • Progress Tracking
  • Question Saving
  • Flash Cards
  • Drag & Drops
  • 3 Months Access
  • PDF Downloads
Get Premium Access
Scroll to Top