exam questions

Exam 350-701 All Questions

View all questions & answers for the 350-701 exam

Exam 350-701 topic 1 question 237 discussion

Actual exam question from Cisco's 350-701
Question #: 237
Topic #: 1
[All 350-701 Questions]

An engineer used a posture check on a Microsoft Windows endpoint and discovered that the MS17-010 patch was not installed, which left the endpoint vulnerable to WannaCry ransomware.
Which two solutions mitigate the risk of this ransomware infection? (Choose two.)

  • A. Configure a posture policy in Cisco Identity Services Engine to install the MS17-010 patch before allowing access on the network.
  • B. Set up a profiling policy in Cisco Identity Services Engine to check an endpoint patch level before allowing access on the network.
  • C. Configure a posture policy in Cisco Identity Services Engine to check that an endpoint patch level is met before allowing access on the network.
  • D. Configure endpoint firewall policies to stop the exploit traffic from being allowed to run and replicate throughout the network.
  • E. Set up a well-defined endpoint patching strategy to ensure that endpoints have critical vulnerabilities patched in a timely fashion.
Show Suggested Answer Hide Answer
Suggested Answer: CE 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Sorel
Highly Voted 4 years, 8 months ago
I'm struggling to find a good link on this, but seems to me that ISE will not patch an endpoint by himself, instead it relies on WSUS for this. So, A is probably incorect, and the right answer is CE. Anyone else?
upvoted 26 times
bigdadzzz
4 years, 4 months ago
https://www.cisco.com/c/en/us/td/docs/security/ise/2-1/admin_guide/b_ise_admin_guide_21/b_ise_admin_guide_20_chapter_010110.html
upvoted 2 times
...
...
Monnezzo
Highly Voted 4 years, 5 months ago
It's A and C source: https://community.cisco.com/t5/security-documents/how-to-integrate-cisco-ise-with-microsoft-sccm-for-patch/ta-p/3725035#toc-hId--2070782007
upvoted 10 times
nep1019
1 year, 9 months ago
Disagree. Your link says that ISE only sees that SCCM shows that there are patches needed. It then uses AnyConnect to trigger SCCM to install the patch. Answer A specifically states that ISE installs the patch. There is nowhere in any guide that says ISE installs a patch. Further if you look at the posture policy section of the admin guide, it says nothing about pushing patches. Answer A mentions the configuring a posture policy.
upvoted 1 times
...
...
Nian
Most Recent 2 months ago
Selected Answer: AC
I believe A is correct - A posture policy can be made with the remediation action that redirects the user to a remediation portal where they must install the MS17-010 patch before regaining full access.
upvoted 1 times
...
iluvmicrosoft
1 year ago
anyone consider D? if your a client w tcp 445 open?? you could have been vulnerable.. file servers w tcp 445 ok.. but clients??
upvoted 1 times
...
XvidalX
1 year, 2 months ago
Selected Answer: CE
ISE does not intall patches , remediation policies does not install patches , Remediation policies does trigger installations by third party systems... A is malformed answer , C and E are totally correct
upvoted 4 times
Premium_Pils
8 months, 3 weeks ago
E seems to be more logical
upvoted 1 times
...
...
nep1019
1 year, 9 months ago
If you go look at the posture policy section of the admin guide (https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ISE_admin_guide_24/m_client_posture_policies.html#task_DBFD37F536134843BC81C4DFEF34A8EC) you see that there is nothing in there that allows ISE to INSTALL a patch which is what it says for answer A). Can it be integrated with SCCM to invoke an action in SCCM to update with a patch? Yes. Can ISE itself install that patch? No. Answer is C and E.
upvoted 2 times
...
Tuxzinator
2 years, 2 months ago
Selected Answer: AC
Option C specifically addresses the vulnerability that was exploited by the WannaCry ransomware, which is the MS17-010 patch that was not installed on the endpoint. By configuring a posture policy to check that the endpoint patch level is met before allowing access to the network, the organization can ensure that all endpoints have the necessary patches installed to mitigate the risk of this ransomware. Option E is still a good solution in general to ensure that endpoints are patched in a timely fashion, but it does not specifically address the vulnerability that was exploited by the WannaCry ransomware.
upvoted 3 times
...
psuoh
2 years, 3 months ago
Selected Answer: CE
https://community.cisco.com/t5/network-access-control/ise-posture-windows-updates/td-p/3575621
upvoted 2 times
...
psuoh
2 years, 3 months ago
ISE wouldn't know how to patch an Windows OS. It needs integration with some patching system.
upvoted 1 times
...
Anonymous983475
2 years, 3 months ago
Selected Answer: CE
ICE can check for patches not install them in the end user's OS
upvoted 2 times
...
nomanlands
2 years, 10 months ago
A and C is correct. SCCM will integrate to do the patching as others mentioned and E is only not an option as it asks what can be done to mitigate THIS ransomware infection and not best practices overall.
upvoted 1 times
west33637
2 years, 4 months ago
it asks what can be done to mitigate 'THE RISK' of this ransomware infection. Not to mitigate the ransomware itself. C and E mitigate the risk. ISE itself does not patch systems.
upvoted 1 times
...
...
Iarn
3 years ago
Selected Answer: AC
People are saying patching isnt possible from ISE but the doco show it is configurable. https://community.cisco.com/t5/security-documents/how-to-integrate-cisco-ise-with-microsoft-sccm-for-patch/ta-p/3725035#toc-hId--2070782007 Step 1 Go to Workcentre-> Posture-> Policy Elements-> Condition-> Patch management. Add a patch management condition to check for up-to-date patch status. This conditions checks if there are any pending patches to be installed in the SCCM client.
upvoted 3 times
...
MoII
3 years, 5 months ago
I'd go with A and C here.
upvoted 2 times
...
jaciro11
3 years, 5 months ago
Hello TEAM, Well you want to check if a specified KB its patched in your system, okay nice the Answer is: A. Configure a posture policy in Cisco Identity Services Engine to install the MS17-010 patch before allowing access on the network. but I think the appropriate answer for this is C. Configure a posture policy in Cisco Identity Services Engine to check that an endpoint patch level is met before allowing access on the network. Well that's means A and C its the same but C its more completed answer. So the answer is C and E
upvoted 3 times
...
Steve122
3 years, 6 months ago
A: Patch will be installed by ISE NAC agent on endpoint C: ISE checks the endpoint first if that is compliant (NAC agent) B: Make no sense "profiling policy"
upvoted 2 times
...
beeker98106
3 years, 6 months ago
A+C is correct, just confirmed
upvoted 4 times
stalkr3
2 years ago
confirmed by who?
upvoted 4 times
...
...
jshow
3 years, 9 months ago
A and C for me ....question states for THIS expolit
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago