
CiscoCertified Network Professional Security
Domain 6Objective 5
6.5 Explain Exfiltration Techniques Such as DNS Tunneling, HTTPS, Email, FTP/SSH/SCP/SFTP, ICMP, Messenger, IRC, NTP, and Cloud Storage 350-701 Practice Questions (Page 4)
Part of the Network Access, Visibility, and Enforcement domain, which accounts for 15% of the 350-701 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–2 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)
35questions here
7free pages
9concepts
15%of the exam
Questions 16–20
- 16
How can an attacker use email to exfiltrate sensitive data from a corporate network?
Select an answer first - 17
Which technique is used by DNS tunneling to exfiltrate data from a network?
Select an answer first - 18
How can IRC be used as a covert channel for data exfiltration?
Select an answer first - 19
A security analyst is reviewing network traffic and finds that a server is sending NTP requests to an external time server. The requests are more frequent than normal, and the response packets are larger than expected. The analyst also sees DNS queries with long subdomains and ICMP echo requests with unusual payloads. The analyst needs to determine which technique is being used for the primary exfiltration channel. Which finding would MOST strongly indicate NTP abuse?
Select an answer first - 20
How can ICMP packets be used to exfiltrate data?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-701” is a trademark of its owner, used for identification only.