Which exfiltration method does an attacker use to hide and encode data inside DNS requests and queries?A. DNS tunnelingB. DNSCryptC. DNS securityD. DNSSECAnswer: AExplanation: 97Which algorithm provides encryption and authentication for data plane communication?A. AES-GCMB. SHA-96C. AES-256D. SHA-384Answer: AQUESTION 98How does Cisco Umbrella archive logs to an enterprise-owned storage?A. by using the Application Programming Interface to fetch the logsB. by sending logs via syslog to an on-premises or cloud-based syslog serverC. by the system administrator downloading the logs from the Cisco Umbrella web portalD. by being configured to send logs to a self-managed AWS S3 bucketAnswer: DExplanation: 99In which cloud services model is the tenant responsible for virtual machine OS patching?A. IaaSB. UCaaSC. PaaSD. SaaSAnswer: AExplanation: 100Which two descriptions of AES encryption are true? (Choose two.)A. AES is less secure than 3DES.B. AES is more secure than 3DES.C. AES can use a 168-bit key for encryption.D. AES can use a 256-bit key for encryption.E. AES encrypts and decrypts a key three times in sequence.Answer: BDExplanation: 101Which technology is used to improve web traffic performance by proxy caching?A. WSAB. FirepowerC. FireSIGHTD. ASAAnswer: AQUESTION 102Which two statements about a Cisco WSA configured in Transparent mode are true? (Choose two.)A. It can handle explicit HTTP requests.B. It requires a PAC file for the client web browser.C. It requires a proxy for the client web browser.D. WCCP v2-enabled devices can automatically redirect traffic destined to port 80.E. Layer 4 switches can automatically redirect traffic destined to port 80.Answer: DEQUESTION 103Which action controls the amount of URI text that is stored in Cisco WSA logs files?A. Configure the datasecurityconfig commandB. Configure the advancedproxyconfig command with the HTTPS subcommandC. Configure a small log-entry size.D. Configure a maximum packet size.Answer: BQUESTION 104Which technology reduces data loss by identifying sensitive information stored in public computing environments?A. Cisco SDAB. Cisco FirepowerC. Cisco HyperFlexD. Cisco CloudlockAnswer: DExplanation: 105Refer to the exhibit. What does the number 15 represent in this configuration? A. privilege level for an authorized user to this routerB. access list that identifies the SNMP devices that can access the routerC. interval in seconds between SNMPv3 authentication attemptsD. number of possible failed attempts until the SNMPv3 user is locked outAnswer: BQUESTION 106Which network monitoring solution uses streams and pushes operational data to provide a near real-time view of activity?A. SNMPB. SMTPC. syslogD. model-driven telemetryAnswer: DExplanation:!streaming-telemetry-quick-start-guideQUESTION 107Which feature is supported when deploying Cisco ASA within AWS public cloud?A. multiple context modeB. user deployment of Layer 3 networksC. IPv6D. clusteringAnswer: BExplanation: 108Which proxy mode must be used on Cisco WSA to redirect TCP traffic with WCCP?A. transparentB. redirectionC. forwardD. proxy gatewayAnswer: AExplanation: 109An MDM provides which two advantages to an organization with regards to device management? (Choose two.)A. asset inventory managementB. allowed application managementC. Active Directory group policy managementD. network device managementE. critical device managementAnswer: ABQUESTION 110Which Talos reputation center allows you to track the reputation of IP addresses for email and web traffic?A. IP Blacklist CenterB. File Reputation CenterC. AMP Reputation CenterD. IP and Domain Reputation CenterAnswer: DQUESTION 111Under which two circumstances is a CoA issued? (Choose two.)A. A new authentication rule was added to the policy on the Policy Service node.B. An endpoint is deleted on the Identity Service Engine server.C. A new Identity Source Sequence is created and referenced in the authentication policy.D. An endpoint is profiled for the first time.E. A new Identity Service Engine server is added to the deployment with the Administration personA.Answer: BDExplanation: 112Which statement about the configuration of Cisco ASA NetFlow v9 Secure Event Logging is true?A. To view bandwidth usage for NetFlow records, the QoS feature must be enabled.B. A sysopt command can be used to enable NSEL on a specific interface.C. NSEL can be used without a collector configured.D. A flow-export event type must be defined under a policy.Answer: DQUESTION 113Which benefit does endpoint security provide the overall security posture of an organization?A. It streamlines the incident response process to automatically perform digital forensics on the endpoint.B. It allows the organization to mitigate web-based attacks as long as the user is active in the domain.C. It allows the organization to detect and respond to threats at the edge of the network.D. It allows the organization to detect and mitigate threats that the perimeter security devices do not detect.Answer: DQUESTION 114An engineer configured a new network identity in Cisco Umbrella but must verify that traffic is being routed through the Cisco Umbrella network. Which action tests the routing?A. Ensure that the client computers are pointing to the on-premises DNS servers.B. Enable the Intelligent Proxy to validate that traffic is being routed correctly.C. Add the public IP address that the client computers are behind to a Core Identity.D. Browse to validate that the new identity is working.Answer: BQUESTION 115What is a language format designed to exchange threat intelligence that can be transported over the TAXII protocol?A. STIXB. XMPPC. pxGridD. SMTPAnswer: AQUESTION 116When using Cisco AMP for Networks, which feature copies a file to the Cisco AMP cloud for analysis?A. 