
CiscoCertified Network Professional Security
Domain 2Objective 2
2.2 Describe Security Monitoring and Telemetry Technologies 350-701 Practice Questions (Page 4)
Part of the Network Security domain, which accounts for 25% of the 350-701 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–2 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
12concepts
25%of the exam
Questions 16–20
- 16
A security team is evaluating an NTA tool that uses machine learning to detect anomalies. They have a mix of legacy protocols (e.g., SMBv1) and modern traffic. The NTA tool has been flagging normal SMBv1 traffic as anomalous because it is rare in the environment. The team wants to reduce false positives without losing detection of real threats. What should they do?
Select an answer first - 17
A SOC wants to automate the response to phishing emails reported by users. The current process involves manually checking the email headers, querying threat intelligence, and blocking the sender if malicious. They want to reduce response time and ensure consistency. Which technology should they use?
Select an answer first - 18
A company is deploying a SIEM and must comply with a regulation that requires retaining security logs for at least 12 months. They have limited storage budget and want to ensure that the SIEM can still query recent logs quickly. Which storage strategy should they implement?
Select an answer first - 19
A security analyst is investigating a slow data exfiltration that involves small amounts of data sent over long-lived connections. They have NetFlow data showing the flows, but they need to see the actual content to confirm if sensitive data is being leaked. They also need to minimize the performance impact on the production network. Which approach should they take?
Select an answer first - 20
A security team wants to detect insider threats and compromised accounts that exhibit unusual behavior, such as a user accessing servers at odd hours or transferring large amounts of data. They have flow data from NetFlow and want to use behavioral analytics to identify anomalies. Which technology should they deploy?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-701” is a trademark of its owner, used for identification only.