Network Security for Implementing and Operating Cisco Security Core Technologies (SCOR 350-701)
This page covers the Network Security domain of the Implementing and Operating Cisco Security Core Technologies (SCOR 350-701) certification. Master Cybersecurity offers 60 practice questions in this domain, drawn from the same content we use across our timed exam simulations. Below are five sample questions with full answer explanations.
Sample Practice Questions
Question 1
Which two request methods of REST API are valid on the Cisco ASA Platform? (Choose two.)- A. put
- B. options
- C. get
- D. push
- E. connect
Explanation
The correct answers are: A. put, C. get.
The REST API on Cisco Secure Firewall ASA exposes configuration and monitoring objects over HTTPS using the standard create, read, update, and delete verbs, so GET retrieves an object or a whole collection and PUT replaces or creates an object at a known resource path. POST adds new objects, PATCH modifies selected attributes, and DELETE removes them, and those five methods are the complete supported set, which makes GET and PUT the valid choices here. Push is not an HTTP method at all; the word is used loosely to describe deploying configuration, so it never appears on a REST request line. CONNECT and OPTIONS are genuine HTTP methods but serve other purposes, since CONNECT asks a proxy to open a tunnel to an origin server and OPTIONS asks which methods a resource supports, typically during a browser preflight check; neither is implemented as a way to read or change ASA configuration. Remember the API also requires the HTTPS server and an authenticated management user before any call succeeds.
Question 2
Which VPN technology can support a multivendor environment and secure traffic between sites?- A. SSL VPN
- B. GET VPN
- C. FlexVPN
- D. DMVPN
Explanation
The correct answer is: C. FlexVPN.
FlexVPN is the unified IKEv2 framework in Cisco IOS, and because it leans on standard IKEv2 with virtual tunnel interfaces rather than any proprietary overlay signalling, a FlexVPN headend can build a site-to-site tunnel with a third-party IKEv2 peer, which is precisely what a mixed-vendor estate needs; its multi-SA support also lets one tunnel interface carry several traffic selectors for those interoperable peers. Client-based and clientless SSL VPN is a remote access technology letting individual users reach internal resources through a browser or the Cisco Secure Client, not a way to join two sites. GETVPN depends on GDOI group key distribution with a key server issuing the KEK and TEK, so every group member has to be a Cisco device. DMVPN depends on NHRP running over multipoint GRE, again Cisco-specific signalling, so a spoke from another vendor cannot register with the hub.
Question 3
Which technology must be used to implement secure VPN connectivity among company branches over a private IP cloud with any-to-any scalable connectivity?- A. DMVPN
- B. FlexVPN
- C. IPsec DVTI
- D. GET VPN
Explanation
The correct answer is: D. GET VPN.
GETVPN is the tunnelless design: group members pull a shared key set, a KEK for rekeying and a TEK for data, from a key server using GDOI, and encryption preserves the original IP header so the provider's private IP or MPLS core keeps routing each packet natively to any other member. That yields immediate any-to-any connectivity with no overlay to build, no hub hairpin and therefore lower latency, and it scales because adding a member adds no tunnels. DMVPN can reach spoke-to-spoke, but NHRP resolution through the hub is still required and every pair needs a dynamic tunnel built and maintained. FlexVPN likewise builds point-to-point or dynamically instantiated tunnel interfaces terminating on a headend, so a full mesh means state for every pair. IPsec with a dynamic virtual tunnel interface is a hub-side template for inbound spoke or client sessions, which again concentrates traffic on the headend instead of permitting direct any-to-any flows.
Question 4
What is a commonality between DMVPN and FlexVPN technologies?- A. FlexVPN and DMVPN use the new key management protocol, IKEv2
- B. FlexVPN and DMVPN use IS-IS routing protocol to communicate with spokes
- C. IOS routers run the same NHRP code for DMVPN and FlexVPN
- D. FlexVPN and DMVPN use the same hashing algorithms
Explanation
The correct answer is: C. IOS routers run the same NHRP code for DMVPN and FlexVPN.
Both designs sit on the same IOS next hop resolution protocol implementation: DMVPN uses NHRP to map tunnel addresses to physical next hops across a multipoint GRE cloud, and FlexVPN reuses that identical NHRP code for spoke registration and for direct spoke-to-spoke shortcuts, so a router runs one NHRP process whichever framework is deployed. The suggestion that both rely on IKEv2 is only half right, because FlexVPN is IKEv2 only while DMVPN runs happily with IKEv1 or IKEv2, making key management a difference rather than a commonality. Neither framework is tied to IS-IS; both are routing-protocol agnostic overlays that in practice carry EIGRP, OSPF or BGP. Hashing algorithms come from whichever IKE proposals and IPsec transform sets the administrator configures, so they are a matter of local policy and not something either technology fixes for you.
Question 5
Which protocol provides the strongest throughput performance when using Cisco AnyConnect VPN?- A. DTLSv1
- B. TLSv1
- C. TLSv1.1
- D. TLSv1.2
Explanation
The correct answer is: A. DTLSv1.
The Cisco Secure Client, formerly AnyConnect, can carry tunnelled traffic inside TLS over TCP or inside DTLS over UDP, and DTLS delivers the best throughput because it avoids running a reliable transport inside another reliable transport. With TLS the tunnel is TCP, so a lost packet belonging to an inner TCP session triggers retransmission and reordering work at both layers, which multiplies latency and collapses throughput for bulk transfers, voice and video. DTLS keeps the same certificate-based session security but rides datagrams, letting the inner protocol handle its own loss recovery, which is why it becomes the preferred data channel once the control channel is established. The three TLS entries are all TCP-based, and the differences between those versions are cryptographic and protocol hardening improvements rather than performance ones, so picking a newer TLS version raises the security floor without delivering the throughput advantage datagram transport provides.
Other Implementing and Operating Cisco Security Core Technologies (SCOR 350-701) domains
- Content Security (38 questions)
- Endpoint Protection and Detection (13 questions)
- Secure Network Access, Visibility, and Enforcement (41 questions)
- Securing the Cloud (26 questions)
- Security Concepts (102 questions)