Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Security

Domain 3Objective 2

3.2 Select Security Capabilities, Deployment Models, Cloud Security Frameworks, and Policy Management to Secure the Cloud 350-701 Practice Questions (Page 3)

Part of the Cloud Security domain, which accounts for 15% of the 350-701 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–2 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)

29questions here
6free pages
5concepts
15%of the exam

Questions 11–15

  1. 11foundation · easy

    Which security capability is primarily used to detect and remediate misconfigurations in cloud infrastructure, such as an open storage bucket?

    Select an answer first
  2. 12expert · hard

    A security team is using a CSPM tool to assess their cloud environment. The tool reports a high number of 'critical' findings, but the team is overwhelmed and cannot remediate everything at once. They need a method to prioritize the findings based on the actual risk to the business. Which approach is most effective?

    Select an answer first
  3. 13application · medium

    A financial institution must keep customer transaction data within its own data center to meet strict regulatory requirements, but wants to leverage cloud-based analytics tools for non-sensitive reporting. Which deployment model best satisfies both the data-residency mandate and the need for cloud innovation?

    Select an answer first
  4. 14application · medium

    A multinational company uses a hybrid cloud. They need to enforce a policy that grants different levels of access to cloud resources based on the user's role and location, while ensuring that data stored in a specific region is not accessed from outside that region. Which policy management approach should be used?

    Select an answer first
  5. 15application · medium

    A company needs to enforce a policy that prevents sensitive data from being uploaded to unsanctioned cloud storage services. They also need to discover which unsanctioned services are being used. Which tool should they deploy?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-701” is a trademark of its owner, used for identification only.