Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
[Security Concepts]
Which function is performed by certificate authorities but is a limitation of registration authorities?
Certificate authorities (CAs) are responsible for issuing, renewing, revoking, and publishing digital certificates. They also maintain a certificate revocation list (CRL), which is a database of revoked certificates that can be checked by relying parties to verify the validity of a certificate. Registration authorities (RAs) are entities that assist CAs with the verification of user identities and enrollment requests. They do not issue certificates themselves, nor do they have access to the CRL. Therefore, CRL publishing is a function that is performed by CAs but is a limitation of RAs.Reference:=
Some possible references are:
Implementing and Operating Cisco Security Core Technologies (SCOR) v1.0, Module 4: Secure Connectivity, Lesson 4.1: VPN Fundamentals, Topic 4.1.1: Public Key Infrastructure (PKI)
Easy guide to SSL certificate authorities, Namecheap
How exactly are registration authorities related to certificate authorities?, Information Security Stack Exchange
[Security Concepts]
Refer to the exhibit.

What are two indications of the Cisco Firepower Services Module configuration?
(Choose two.)
sfr {fail-open | fail-close
[monitor-only]} <- There's a couple different options here. The first one is fail-open which means that if the Firepower software module is unavailable, the ASA will continue to forward traffic. fail-close means that if the Firepower module fails, the traffic will stop flowing. While this doesn't seem ideal, there might be a use case for it when securing highly regulated environments. The monitor-only switch can be used with both and basically puts the Firepower services into IDS-mode only. This might be useful for initial testing or setup.
[Security Concepts]
What is the concept of Cl/CD pipelining?
Cl/CD pipelining is a method of software development that aims to deliver software faster and more reliably by automating the process of integrating, testing, and deploying code changes. Cl stands for continuous integration, which means that every code change is merged into a shared repository and verified by automated tests. CD stands for continuous delivery, which means that the code is always in a deployable state and can be released to production environments with minimal human intervention. Cl/CD pipelining enables developers to collaborate more effectively, detect and fix errors earlier, and deliver value to customers more frequently. Cl/CD pipelining is a key practice of DevOps, a culture and set of processes that bridge the gap between development and operations teams.Reference:
https://www.redhat.com/en/topics/devops/what-cicd-pipeline
https://about.gitlab.com/topics/ci-cd/cicd-pipeline/
[Network Security]
What is a functional difference between a Cisco ASA and a Cisco IOS router with Zone-based policy firewall?
The Cisco ASA and the Cisco IOS router with Zone-Based Policy Firewall (ZFW) have different default behaviors when it comes to traffic filtering.The Cisco ASA follows adefault deny-all policythat prohibits traffic between firewall security zones until an explicit policy is applied to allow desirable traffic1.The Cisco IOS router with ZFW, on the other hand, starts out byallowing all traffic, even on untrusted interfaces, until a zone-pair policy is applied to restrict or inspect traffic2. This means that the Cisco ASA provides a higher level of security by default, while the Cisco IOS router with ZFW requires more configuration to harden the router.However, the Cisco IOS router with ZFW also offers more flexibility and granularity in defining firewall policies, as well as more advanced features such as DMVPN, GET VPN, and Policy-Based Routing, which are not supported by the Cisco ASA23.Reference:
2: IOS Firewall vs. ASA - Cisco Community
1: Understand the Zone-Based Policy Firewall Design - Cisco
4: What is a functional difference between a Cisco ASA and a Cisco IOS router with Zone-based policy firewall?
5: What is a functional difference between a Cisco ASA and Cisco IOS router with Zone-based policy firewall?
3: Cisco Zone-Based Firewall Reporting -- Plixer
[Security Concepts]
What provides visibility and awareness into what is currently occurring on the network?
Telemetry -- Information and/or data that provides awareness and visibility into what is occurring on the network
at any given time from networking devices, appliances, applications or servers in which the core function of the
device is not to generate security alerts designed to detect unwanted or malicious activity from computer
networks.
727 questions covering all exam domains, starting from $20
Exam domains verified against: Official Cisco 350-701 exam guide, last checked September 2026.
Understand network security strategies and firewall-based intrusion prevention to protect infrastructure. Learn network segmentation with VLANs and Layer 2 security, plus NetFlow components and configuration for security monitoring.
Evaluate cloud service models including SaaS, PaaS, and IaaS across public, private, hybrid, and community environments. Assess cloud service frameworks, perform security evaluations, and implement security measures appropriate to each cloud deployment type.
Deploy web proxy redirection and traffic capture strategies, then configure user identification and authentication. Operate Cisco Secure Email Gateway, Cisco Secure Email Cloud Gateway, and Cisco Secure Web Appliance across hybrid cloud systems.
Deploy web proxy redirection and traffic capture strategies, then configure user identification and authentication. Operate Cisco Secure Email Gateway, Cisco Secure Email Cloud Gateway, and Cisco Secure Web Appliance across hybrid cloud systems.
Compare Endpoint Protection Platforms with Endpoint Detection and Response solutions, then configure antimalware using Cisco Secure Endpoint. Establish outbreak control and quarantine procedures, and deploy multifactor authentication strategies for endpoint devices.
Configure network access control mechanisms including 802.1X, MAC Authentication Bypass, and WebAuth for guest services and BYOD policies. Apply identity management and posture assessment, then use Change of Authorization mechanisms for detailed network access control.
Common questions about the exam itself