
CiscoCertified Network Professional Security
Domain 2Objective 8
2.8 Implement Access Control Policies, AVC, URL Filtering, Malware Protection, and Intrusion Prevention Using Cisco Secure Firewall (FTD) 350-701 Practice Questions (Page 2)
Part of the Network Security domain, which accounts for 25% of the 350-701 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–2 from this objective — we provide 18 practice questions to prepare you well beyond it. (estimate)
18questions here
4free pages
6concepts
25%of the exam
Questions 6–10
- 6
A company has a requirement to block all malware downloads, but they also have a business need to allow encrypted traffic (HTTPS) to a partner site that uses a self-signed certificate. They have FTD with AMP. What is the best way to handle this?
Select an answer first - 7
A company has a critical application that uses a proprietary protocol on a non-standard port. The security team wants to enable IPS, but the application generates traffic that triggers many false positives. They also want to ensure that the application is not disrupted. What is the best approach?
Select an answer first - 8
What is the primary purpose of Application Visibility and Control (AVC) on Cisco Secure Firewall (FTD)?
Select an answer first - 9
In a Cisco Secure Firewall (FTD) access control policy, which rule action allows traffic but does NOT inspect it for intrusions or malware?
Select an answer first - 10
What is the role of Advanced Malware Protection (AMP) in the FTD malware protection architecture?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-701” is a trademark of its owner, used for identification only.