Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Security

Domain 6Objective 6

6.6 Describe Network Visibility and Enforcement Using Telemetry and Native AI/ML Capabilities with XDR and SIEM/SOAR Platforms Such as Splunk and Cisco XDR 350-701 Practice Questions (Page 3)

Part of the Network Access, Visibility, and Enforcement domain, which accounts for 15% of the 350-701 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–2 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)

31questions here
7free pages
7concepts
15%of the exam

Questions 11–15

  1. 11foundation · easy

    How does Cisco XDR use telemetry to enhance threat detection?

    Select an answer first
  2. 12expert · hard

    A SOC uses Splunk as its SIEM and wants to automate the response to a specific type of alert: a user account being locked out multiple times. The SOC wants to automatically unlock the account if the lockouts are due to a known application issue, but escalate to a human if the lockouts appear malicious. Which approach best achieves this?

    Select an answer first
  3. 13application · medium

    A company is evaluating security platforms and wants to ensure that when a threat is detected on an endpoint, the platform can automatically isolate the endpoint and also notify the SOC with context. Which platform capability is most aligned with this requirement?

    Select an answer first
  4. 14expert · hard

    A security team is planning to deploy a new SIEM. They have a mix of on-premises and cloud infrastructure, and they need to ensure that the SIEM can collect telemetry from all sources. They are considering using a combination of syslog, NetFlow, and API-based collectors. What is the primary advantage of this approach?

    Select an answer first
  5. 15application · medium

    A company uses Cisco XDR and wants to enforce a policy that automatically blocks a user's access to a specific cloud application if the XDR detects a compromised credential. Which Cisco XDR integration would enable this enforcement?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-701” is a trademark of its owner, used for identification only.