Implementing and Operating Cisco Security Core Technologies (350-701) Exam Prep
Free practice questions

Free SCOR Practice Questions

10 exam-style questions with answers and explanations, straight from our 1,030-question bank. Tap an answer to check yourself. When you're ready, take the scored version in the free practice test.

Start the free practice test → ★★★★★4.9/5 from 2,400+ candidates · No signup

These 10 free SCOR questions are organized by exam domain, so you can see how each part of the Implementing and Operating Cisco Security Core Technologies (350-701) blueprint is tested. Reveal the answer and explanation under each question.

Domain 1: Security Concepts 20% of exam

Question 1

An engineering assistant uses retrieval-augmented generation to answer questions for two customer tenants. Users authenticate successfully, and every document in the shared vector store retains its tenant label. Nevertheless, a Tenant A user receives passages from Tenant B: the retrieval service searches all documents by similarity when building the model context. Each customer must continue receiving answers from its own documents. Where does the missing security check belong?

Show answer & explanation

Correct answer: D - During retrieval, by excluding documents the requesting user is not authorized to access.

Question 2

Only one patch can be deployed before tonight's maintenance window closes. Both fixes have passed testing and require comparable downtime. An internet-facing VPN gateway has a CVSS v4.0 Base score of 8.2 and provides access to a production administration network; the vendor confirms active exploitation of its vulnerability. A training-lab service has a Base score of 9.4, is isolated from production, and has no observed exploitation. What should the team prioritize, and why?

Show answer & explanation

Correct answer: B - Prioritize the VPN despite its High base severity, given active exploitation and production exposure.

Question 3

A manufacturer distributes firmware to gateways administered by different customers. Each gateway must verify the publisher and detect tampering. Compromising one gateway must not give an attacker the credentials needed to approve altered firmware for the others. Image confidentiality is unnecessary, and every gateway supports the listed mechanisms. What should the manufacturer deploy for quantum-resistant publisher authentication?

Show answer & explanation

Correct answer: C - Sign the image with ML-DSA and provision the publisher's public verification key.

Domain 2: Network Security 25% of exam

Question 4

An FTD 7.6 appliance receives a new plaintext TCP connection from 10.44.8.25 to 10.60.4.10:8080. Prefiltering sends it for analysis. The deployed access control rules are ordered as follows: 1. Monitor: 10.44.8.0/24 to 10.60.4.10, TCP/8080 2. Trust: 10.44.0.0/16 to 10.60.0.0/16, any port 3. Allow: 10.44.8.0/24 to 10.60.4.10, TCP/8080, intrusion policy attached The connection succeeds, but rule 3 records no hits. How can the engineer apply intrusion inspection to this application without changing how other connections are handled?

Show answer & explanation

Correct answer: B - Move rule 3 above rule 2, retaining its match conditions and intrusion policy.

Question 5

A policy-based site-to-site VPN on FTD 7.7 has an established IKEv2 SA and an installed Child SA for local 10.24.0.0/24 and remote 10.91.0.0/24. Fresh connections from 10.24.0.40 to 10.91.0.25 fail, and the local IPsec encapsulation counter does not increase. Packet-tracer reports: Route: correct outside interface Access control: allow NAT: source 10.24.0.40 translated to outside address 198.51.100.14 The intended identity-NAT rule has zero hits and follows the matching broad manual PAT rule in the same NAT section. Which correction fits these results?

Show answer & explanation

Correct answer: C - Move the subnet-specific identity-NAT rule before PAT, then verify encryption of the untranslated flow.

Domain 3: Cloud Security 15% of exam

Question 6

A Kubernetes payments pod has labels app=payments and quarantine=yes. The cluster enforces NetworkPolicy, and these are the only policies selecting this pod: allow-frontend: selects app=payments; permits ingress on TCP 8443 from role=frontend pods in the same namespace. quarantine: selects quarantine=yes; policyTypes=[Ingress]; ingress=[]. Both policies are active, yet a frontend pod can still establish new TCP 8443 connections to the quarantined pod. Neither uses host networking. Which policy change closes that path while preserving frontend access to the other payments replicas?

Show answer & explanation

Correct answer: A - Exclude quarantined pods from the destination selector of allow-frontend while retaining its existing source and port conditions.

Domain 4: Secure Service Edge 10% of exam

Question 7

Remote HR users intermittently lose access to payroll through Cisco Secure Access. Successful and failed attempts have the same identity, posture result, and matching Private Access Allow rule. Both members of the resource connector group report healthy and resolve payroll.hr.example to the same address. Connector C1 completes TCP 443 connections to that address; C2 sends SYN packets but receives no response. The group must remain redundant. What is the appropriate repair?

Show answer & explanation

Correct answer: C - Repair the private network path between C2 and the payroll service on TCP 443.

Domain 5: Endpoint Protection and Detection 15% of exam

Question 8

Live Cisco Secure Endpoint telemetry shows a credential-stealing process uploading data from one employee workstation to a confirmed attacker-controlled address. The connector is online, isolation is enabled, and the communication paths needed for remote investigation have been tested under isolation. No other host shows related activity. Select the immediate response that contains the confirmed compromise and preserves remote investigation.

Show answer & explanation

Correct answer: A - Isolate the workstation through Secure Endpoint and confirm isolation before investigating persistence and exposure.

Question 9

Authorized phishing simulations from drills@training.example are being quarantined by a matching Cisco Secure Email Threat Defense policy exception. Adding that address to Microsoft Safe Senders did not help. Reclassifying and restoring one test message also left subsequent tests quarantined. Security has approved leaving future simulation messages from this exact sender in recipients' inboxes while retaining the current handling of other phishing messages. Which policy edit implements that exception?

Show answer & explanation

Correct answer: A - Place a higher-ranked incoming exception for drills@training.example that leaves its Phishing-verdict messages in the inbox.

Domain 6: Network Access, Visibility, and Enforcement 15% of exam

Question 10

A switch port carries separate authenticated sessions for an IP phone and a workstation connected through it. The workstation has completed ISE posture remediation and now needs its authorized application access restored. The revised authorization changes only its downloadable ACL; its VLAN and IP address stay the same. The phone is carrying a call, and the switch supports session-specific reauthentication. Which CoA operation fits these constraints?

Show answer & explanation

Correct answer: D - Reauthenticate the workstation's session so its authorization is reevaluated without cycling the shared physical port.

That's 10 of 1,030

The full bank has 1,020 more SCOR questions with explanations.

Continue in the free practice test →

View plans