CCNP Security 350-701 SCOR Practice Test 14

CCNP Security 350-701 SCOR Practice Test 14 (Hard) - Intrusion Prevention Systems (IPS) and NGFW Policies

CISCO CCNP Security Exam Logo

1 / 10

Which deployment mode allows an IPS sensor to actively drop malicious traffic in real time, as opposed to only alerting on it after the fact?

2 / 10

Which detection method compares observed network traffic patterns directly against a database of known attack patterns to identify malicious traffic?

3 / 10

Which detection method builds a baseline of what constitutes 'normal' network behavior and flags significant deviations from that baseline, making it useful for identifying previously unknown (zero-day) threats?

4 / 10

In Cisco Firepower NGFW policy design, which type of policy is primarily responsible for matching traffic based on application, user identity, URL category, and zone, then determining whether that traffic is allowed, blocked, or further inspected?

5 / 10

Which NGFW capability allows policy decisions to be based on the specific application generating traffic (such as identifying Dropbox traffic on port 443) rather than relying solely on port and protocol numbers?

6 / 10

Which action would an IPS take on a per-rule basis to record detailed information about a triggered signature while still permitting the matched traffic to continue, useful during initial tuning before enforcing a block?

7 / 10

Which concept describes an IPS incorrectly flagging legitimate, benign traffic as malicious, potentially disrupting normal business operations if the rule is set to block?

8 / 10

Which Cisco Talos-driven capability continuously updates IPS signature sets and reputation data to protect against newly discovered threats without requiring a full software upgrade?

9 / 10

Which NGFW/IPS design consideration most directly affects the ability to inspect traffic that is encrypted with TLS, since encrypted payloads cannot be pattern-matched without additional processing?

10 / 10

Which combination of NGFW policy elements would most effectively balance strong security with minimal disruption when initially deploying application-based blocking rules in a production network?

Your score is

The average score is 0%

0%