Secure Network Access, Visibility, and Enforcement for Implementing and Operating Cisco Security Core Technologies (SCOR 350-701)
This page covers the Secure Network Access, Visibility, and Enforcement domain of the Implementing and Operating Cisco Security Core Technologies (SCOR 350-701) certification. Master Cybersecurity offers 41 practice questions in this domain, drawn from the same content we use across our timed exam simulations. Below are five sample questions with full answer explanations.
Sample Practice Questions
Question 1
What is a feature of the open platform capabilities of Cisco DNA Center?- A. application adapters
- B. domain integration
- C. intent-based APIs
- D. automation adapters
Explanation
The correct answer is: C. intent-based APIs.
The open platform story for Cisco Catalyst Center, formerly DNA Center, rests on its northbound intent-based APIs: a documented REST interface where an administrator or script declares a desired outcome, such as an SSID, a QoS policy, or a software image level, and the controller works out the device-by-device configuration needed to realize it, which is what makes the platform programmable by third-party tools and custom automation. Application adapters is not a construct of the platform; applications integrate through those REST APIs rather than through per-application adapters. Domain integration is not a platform capability either, although the controller does integrate with adjacent domains such as Identity Services Engine for policy and ITSM tools through separate integration APIs. Automation adapters likewise names no real feature; controller automation is driven by the intent APIs plus device packages and southbound plug-ins that extend support to multivendor hardware.
Question 2
Which two features of Cisco DNA Center are used in a Software Defined Network solution? (Choose two.)- A. accounting
- B. assurance
- C. automation
- D. authentication
- E. encryption
Explanation
The correct answers are: B. assurance, C. automation.
Cisco Catalyst Center, long known as Cisco DNA Center, is the controller for a software defined campus, and its two headline capabilities are automation and assurance. Automation covers the Design, Policy, and Provision workflows plus the Intent APIs that push consistent configuration to fabric devices, so an SD-Access site with its LISP control plane, VXLAN data plane, and TrustSec policy plane is built from expressed intent instead of box-by-box CLI. Assurance is the telemetry and analytics side, correlating device, client, and application health into actionable issues with suggested remediation and offering tools such as path trace and sensor tests. Accounting is an AAA function that records what an authenticated user did, delivered by RADIUS or TACACS+ on Cisco ISE rather than by the controller. Authentication likewise belongs to ISE, which the controller integrates with for identity and group based policy but does not perform itself. Encryption describes transport data protection such as MACsec or IPsec, not a controller feature that defines the software defined solution.
Question 3
Which two activities can be done using Cisco DNA Center? (Choose two.)- A. DHCP
- B. design
- C. accounting
- D. DNS
- E. provision
Explanation
The correct answers are: B. design, E. provision.
Cisco Catalyst Center, formerly Cisco DNA Center, is organised around a workflow whose stages are Design, Policy, Provision, and Assurance, so designing the network hierarchy of sites, buildings, and floors along with network settings, device credentials, IP address pools, and software images, and then provisioning devices against that design, are both core activities carried out in the controller. Provisioning is where a switch or wireless controller is claimed, assigned to a site, pushed its intended configuration, and added to an SD-Access fabric. DHCP and DNS are network services the controller consumes rather than provides: it stores the addresses of the DHCP and DNS servers as network settings and hands them to provisioned devices and IP pool definitions, while the servers themselves live elsewhere in the infrastructure. Accounting is an AAA function that records the actions of authenticated users and is delivered by RADIUS or TACACS+ on Cisco ISE, which the controller integrates with for identity and group based policy rather than performing that role itself.
Question 4
Which type of dashboard does Cisco DNA Center provide for complete control of the network?- A. distributed management
- B. service management
- C. application management
- D. centralized management
Explanation
The correct answer is: D. centralized management.
Cisco Catalyst Center, formerly DNA Center, presents a single centralized management dashboard spanning the entire enterprise network, so design, policy, provisioning, and assurance for campus switching, routing, and wireless all live behind one pane of glass with network-wide health scores, client and application experience data, and one place to express intent. Distributed management is the opposite model, where every device or site is configured on its own, and replacing that box-by-box approach is the whole reason the controller exists. Service management describes an ITSM discipline built around ticketing and change workflows, which the controller can integrate with but does not itself provide as its dashboard. Application management is only one slice of what the dashboard surfaces, delivered through Application Visibility and Control using NBAR2, Flexible NetFlow, and QoS, so it is a component of the view rather than the character of the dashboard as a whole.
Question 5
Which method is used to deploy certificates and configure the supplicant on mobile devices to gain access to network resources?- A. BYOD onboarding
- B. MAC authentication bypass
- C. client provisioning
- D. Simple Certificate Enrollment Protocol
Explanation
The correct answer is: A. BYOD onboarding.
BYOD onboarding is the flow that both issues a certificate and configures the supplicant on a mobile device, which is why it is the method that satisfies the whole requirement. During onboarding, Cisco ISE runs Native Supplicant Provisioning to write the wireless or wired 802.1X profile onto the endpoint, including the SSID, the EAP method, and the credential or certificate reference, and it enrols the device certificate as part of the same wizard. Simple Certificate Enrollment Protocol is only the transport that carries the certificate request to the issuing certificate authority; it delivers a certificate but has no mechanism for writing supplicant configuration, so it covers only half of what the question asks. MAC Authentication Bypass authenticates a device by its hardware address precisely because that device has no supplicant, so it is the opposite of supplicant configuration. Client provisioning refers to distributing posture and agent software such as the Secure Client modules rather than provisioning certificates and 802.1X profiles.
Other Implementing and Operating Cisco Security Core Technologies (SCOR 350-701) domains
- Content Security (38 questions)
- Endpoint Protection and Detection (13 questions)
- Network Security (60 questions)
- Securing the Cloud (26 questions)
- Security Concepts (102 questions)