[May 08, 2024] 350-701 Sample with Accurate & Updated Questions [Q24-Q49]

Share

[May 08, 2024] 350-701 Sample with Accurate & Updated Questions

350-701 Exam Info and Free Practice Test | DumpsTorrent


Cisco 350-701 exam is designed to evaluate the knowledge and skills of professionals in implementing and operating Cisco Security Core Technologies. Implementing and Operating Cisco Security Core Technologies certification exam is ideal for network security engineers, network administrators, and other IT professionals who want to demonstrate their expertise in securing their organization's networks and data.

 

NEW QUESTION # 24
In which two ways does the Cisco Advanced Phishing Protection solution protect users? (Choose two.)

  • A. It prevents use of compromised accounts and social engineering.
  • B. It prevents trojan horse malware using sensors.
  • C. It prevents all zero-day attacks coming from the Internet.
  • D. It automatically removes malicious emails from users' inbox.
  • E. It secures all passwords that are shared in video conferences.

Answer: A,D

Explanation:
Cisco Advanced Phishing Protection (AAP) is a solution that adds sophisticated machine learning capabilities to Cisco Email Security to block advanced identity deception attacks for inbound email by assessing its threat posture1. It also uses both global and local telemetry data combined with analytics and modeling to validate the reputation and authenticity of senders2. AAP provides sender authentication and BEC detection capabilities, and uses advanced machine learning techniques, real-time behavior analytics, relationship modeling and telemetry to protect against identity deception-based threats3.
In two ways, the Cisco Advanced Phishing Protection solution protects users:
* It prevents use of compromised accounts and social engineering. AAP detects and blocks phishing emails that attempt to impersonate legitimate senders, such as executives, partners, or customers, and trick users into revealing sensitive information or transferring funds. AAP analyzes the sender's identity, behavior, and relationship with the recipient, and assigns a risk score to the email. If the email is deemed suspicious or malicious, AAP can quarantine it, flag it, or deliver it with a warning4.
* It automatically removes malicious emails from users' inbox. AAP provides retrospective analysis and
* remediation capabilities, which means that it can identify and remove emails that were initially delivered but later found to be malicious. AAP leverages the Cisco Talos threat intelligence network and the Sensor-based solution to continuously monitor the threat landscape and update the email disposition accordingly. If an email is reclassified as malicious, AAP can automatically delete it from the users' inbox, or notify the administrator or the user to take action45.
The other options are incorrect because they do not accurately describe the functions of AAP. AAP does not prevent all zero-day attacks coming from the Internet, as it focuses on phishing and identity deception attacks.
AAP does not prevent trojan horse malware using sensors, as sensors are used to collect and analyze email data, not to block malware. AAP does not secure all passwords that are shared in video conferences, as it is not related to video conferencing security. Therefore, the correct answer is A and C. References:
* Cisco's Security Innovations to Protect the Endpoint and Email
* Cisco Advanced Phishing Protection - Cisco Video Portal
* Cisco Advanced Phishing Protection At A Glance - AVANTEC
* User Guide for Cisco Advanced Phishing Protection
* Cisco Secure Email Threat Defense - Cisco
* Integrating the Email Gateway with Cisco Advanced Phishing Protection


NEW QUESTION # 25
An organization wants to secure data in a cloud environment. Its security model requires that all users be authenticated and authorized. Security configuration and posture must be continuously validated before access is granted or maintained to applications and dat a. There is also a need to allow certain application traffic and deny all other traffic by default. Which technology must be used to implement these requirements?

  • A. Virtual routing and forwarding
  • B. Virtual LAN
  • C. Access control policy
  • D. Microsegmentation

Answer: D

Explanation:
Zero Trust is a security framework requiring all users, whether in or outside the organization's network, to be authenticated, authorized, and continuously validated for security configuration and posture before being granted or keeping access to applications and data. Zero Trust assumes that there is no traditional network edge; networks can be local, in the cloud, or a combination or hybrid with resources anywhere as well as workers in any location.
The Zero Trust model uses microsegmentation - a security technique that involves dividing perimeters into small zones to maintain separate access to every part of the network - to contain attacks.


NEW QUESTION # 26
Which suspicious pattern enables the Cisco Tetration platform to learn the normal behavior of users?

  • A. file access from a different user
  • B. interesting file access
  • C. user login suspicious behavior
  • D. privilege escalation

Answer: C

Explanation:
Reference:
https://www.cisco.com/c/en/us/products/collateral/data-center-analytics/tetration-analytics/whitepaper-c11-74038


NEW QUESTION # 27
What are two benefits of Flexible NetFlow records? (Choose two)

  • A. They allow the user to configure flow information to perform customized traffic identification
  • B. They provide attack prevention by dropping the traffic
  • C. They converge multiple accounting technologies into one accounting mechanism
  • D. They provide monitoring of a wider range of IP packet information from Layer 2 to 4
  • E. They provide accounting and billing enhancements

Answer: A,C

Explanation:
Reference:
https://www.cisco.com/en/US/docs/ios/fnetflow/configuration/guide/cust_fnflow_rec_mon_external_docbase_09 d9.html#wp1057997Note: Traditional NetFlow allows us to monitor from Layer 2 to 4 but Flexible NetFlow goes beyond theselayers.


NEW QUESTION # 28
Which capability is exclusive to a Cisco AMP public cloud instance as compared to a private cloud instance?

  • A. ETHOS detection engine
  • B. RBAC
  • C. SPERO detection engine
  • D. TETRA detection engine

Answer: A

Explanation:
ETHOS is one of the many detection engines that AMP uses to continuously protect you from malware. It is only available in the public cloud, as it requires a large amount of data and processing power to operate.
ETHOS uses machine learning to analyze the behavior and characteristics of files and determine their maliciousness. It can detect both known and unknown threats, as well as polymorphic and metamorphic malware that can change their appearance or code. ETHOS is part of the AMP cloud's dynamic analysis capabilities, which also include SPERO and Threat Grid12.
The private cloud instance of AMP does not have ETHOS, as it is meant to be an on-premises, self-contained solution that satisfies stringent privacy requirements. The private cloud instance also does not have SPERO or Threat Grid, unless they are deployed separately as additional appliances. The private cloud instance relies on the TETRA detection engine, which is a signature-based engine that can identify known malware. TETRA is updated regularly with new signatures from the AMP cloud, but it cannot detect unknown or zero-day threats as effectively as ETHOS34.
Therefore, the capability that is exclusive to the AMP public cloud instance as compared to the private cloud instance is the ETHOS detection engine. References: 1: Cisco Advanced Malware Protection Private Cloud Appliance Data Sheet 2: What is AMP Private Cloud 3: Deploy Cisco AMP Private Cloud on Cisco HyperFlex Systems 4: AMP Private Cloud vs Public Cloud Dashboard different


NEW QUESTION # 29
Under which two circumstances is a CoA issued? (Choose two.)

  • A. An endpoint is deleted on the Identity Service Engine server.
  • B. A new authentication rule was added to the policy on the Policy Service node.
  • C. An endpoint is profiled for the first time.
  • D. A new Identity Source Sequence is created and referenced in the authentication policy.
  • E. A new Identity Service Engine server is added to the deployment with the Administration personA.

Answer: A,C


NEW QUESTION # 30
Using Cisco Firepower's Security Intelligence policies, upon which two criteria is Firepower block based?
(Choose two)

  • A. MAC addresses
  • B. port numbers
  • C. URLs
  • D. protocol IDs
  • E. IP addresses

Answer: C,E

Explanation:
Explanation Explanation Security Intelligence Sources ... Custom Block lists or feeds (or objects or groups) Block specific IP addresses, URLs, or domain names using a manually-created list or feed (for IP addresses, you can also use network objects or groups.) For example, if you become aware of malicious sites or addresses that are not yet blocked by a feed, add these sites to a custom Security Intelligence list and add this custom list to the Block list in the Security Intelligence tab of your access control policy. Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/623/configuration/guide/fpmc-configguide-v623/security_intelligence_blacklisting.html Explanation Security Intelligence Sources
...
Custom Block lists or feeds (or objects or groups)
Block specific IP addresses, URLs, or domain names using a manually-created list or feed (for IP addresses, you can also use network objects or groups.) For example, if you become aware of malicious sites or addresses that are not yet blocked by a feed, add these sites to a custom Security Intelligence list and add this custom list to the Block list in the Security Intelligence tab of your access control policy.
Explanation Explanation Security Intelligence Sources ... Custom Block lists or feeds (or objects or groups) Block specific IP addresses, URLs, or domain names using a manually-created list or feed (for IP addresses, you can also use network objects or groups.) For example, if you become aware of malicious sites or addresses that are not yet blocked by a feed, add these sites to a custom Security Intelligence list and add this custom list to the Block list in the Security Intelligence tab of your access control policy. Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/623/configuration/guide/fpmc-configguide-v623/security_intelligence_blacklisting.html


NEW QUESTION # 31
Which role is a default guest type in Cisco ISE?

  • A. Contractor
  • B. Yearly
  • C. Monthly
  • D. Full-Time

Answer: A

Explanation:
https://www.cisco.com/c/en/us/td/docs/security/ise/1-4-1/admin_guide/b_ise_admin_guide_141/b_ise_admin_gu


NEW QUESTION # 32
Refer to the exhibit.

Which statement about the authentication protocol used in the configuration is true

  • A. There are separate authentication and authorization request packets
  • B. The authentication request contains only a password
  • C. The authentication request contains only a username
  • D. The authentication and authorization requests are grouped in a single packet

Answer: D


NEW QUESTION # 33
An organization is trying to implement micro-segmentation on the network and wants to be able to gain visibility on the applications within the network. The solution must be able to maintain and force compliance.
Which product should be used to meet these requirements?

  • A. Cisco AMP
  • B. Cisco Tetration
  • C. Cisco Umbrella
  • D. Cisco Stealthwatch

Answer: B

Explanation:
Reference:
https://www.cisco.com/c/en/us/products/collateral/data-center-analytics/tetration-analytics/solutionoverview-c22


NEW QUESTION # 34
An organization is trying to improve their Defense in Depth by blocking malicious destinations prior to a connection being established. The solution must be able to block certain applications from being used within the network. Which product should be used to accomplish this goal?

  • A. AMP
  • B. ISE
  • C. Cisco Firepower
  • D. Cisco Umbrella

Answer: D

Explanation:
ExplanationExplanationCisco Umbrella protects users from accessing malicious domains by proactively analyzing and blocking unsafe destinations - before a connection is ever made. Thus it can protect from phishing attacks by blocking suspicious domains when users click on the given links that an attacker sent.


NEW QUESTION # 35
Which feature does the laaS model provide?

  • A. software-defined network segmentation
  • B. dedicated, restricted workstations
  • C. automatic updates and patching of software
  • D. granular control of data

Answer: C


NEW QUESTION # 36
An engineer enabled SSL decryption for Cisco Umbrella intelligent proxy and needs to ensure that traffic is inspected without alerting end-users.

  • A. Import the Umbrella root CA into the trusted root store on the user's device.
  • B. Modify the user's browser settings to suppress errors from Umbrella.
  • C. Upload the organization root CA to the Umbrella admin portal
  • D. Restrict access to only websites with trusted third-party signed certificates.

Answer: A

Explanation:
SSL decryption allows the intelligent proxy to inspect traffic over HTTPS. Some websites may use self-signed certificates or certificates that are not trusted by the user's device. This may cause the browser to display a warning or an error message when accessing those websites through the intelligent proxy. To avoid this, the user's device needs to trust the Umbrella root CA, which is the certificate authority that signs the certificates for the websites that are proxied by Umbrella. By importing the Umbrella root CA into the trusted root store on the user's device, the browser will recognize the certificates as valid and will not alert the end-users12. References: 1: Enable SSL Decryption - Umbrella User Guide 2: Intelligent Proxy and SSL Decryption with Cisco Umbrella


NEW QUESTION # 37
What is a functional difference between Cisco AMP for Endpoints and Cisco Umbrella Roaming Client?

  • A. AMP for Endpoints authenticates users and provides segmentation, and the Umbrella Roaming Client allows only for VPN connectivity.
  • B. The Umbrella Roaming Client authenticates users and provides segmentation, and AMP for Endpoints allows only for VPN connectivity
  • C. AMP for Endpoints stops and tracks malicious activity on hosts, and the Umbrella Roaming Client tracks only URL-based threats.
  • D. The Umbrella Roaming client stops and tracks malicious activity on hosts, and AMP for Endpoints tracks only URL-based threats.

Answer: B


NEW QUESTION # 38
Which Cisco platform provides an agentless solution to provide visibility across the network including encrypted traffic analytics to detect malware in encrypted traffic without the need for decryption?

  • A. Cisco Stealthwatch
  • B. Cisco AnyConnect
  • C. Cisco Advanced Malware Protection
  • D. Cisco Identity Services Engine

Answer: A

Explanation:
Cisco Stealthwatch is a network security and visibility platform that provides an agentless solution to monitor network traffic and detect threats, including those in encrypted traffic. Stealthwatch uses Encrypted Traffic Analytics (ETA), a technology that leverages network telemetry and machine learning to identify malicious patterns and behaviors in encrypted traffic without decryption. ETA can also assess the cryptographic strength and compliance of the encryption protocols used in the network. Stealthwatch integrates with other Cisco security products, such as Cisco Identity Services Engine (ISE) and Cisco Advanced Malware Protection (AMP), to provide contextual information and threat intelligence for faster and more effective response.
Stealthwatch is the only Cisco platform that offers ETA as a solution to provide visibility across the network, including encrypted traffic analytics, to detect malware in encrypted traffic without the need for decryption. References := Some possible references are:
* Cisco Secure Network Analytics (Stealthwatch) - Cisco, Cisco
* Encrypted Traffic Analytics > Security | Cisco Press, Cisco Press
* Solutions - Encrypted Traffic Analytics with the New Cisco Network and Secure Network Analytics At-a-Glance - Cisco, Cisco
* Cisco Encrypted Traffic Analytics White Paper, Cisco


NEW QUESTION # 39
An organization is trying to implement micro-segmentation on the network and wants to be able to gain visibility on the applications within the network. The solution must be able to maintain and force compliance. Which product should be used to meet these requirements?

  • A. Cisco AMP
  • B. Cisco Tetration
  • C. Cisco Umbrella
  • D. Cisco Stealthwatch

Answer: B

Explanation:
Micro-segmentation secures applications by expressly allowing particular application traffic and, by default, denying all other traffic. Micro-segmentation is the foundation for implementing a zero-trust security model for application workloads in the data center and cloud.
Cisco Tetration is an application workload security platform designed to secure your compute instances across any infrastructure and any cloud. To achieve this, it uses behavior and attribute-driven microsegmentation policy generation and enforcement. It enables trusted access through automated, exhaustive context from various systems to automatically adapt security policies.
To generate accurate microsegmentation policy, Cisco Tetration performs application dependency mapping to discover the relationships between different application tiers and infrastructure services. In addition, the platform supports "what-if" policy analysis using real-time data or historical data to assist in the validation and risk assessment of policy application pre-enforcement to ensure ongoing application availability. The normalized microsegmentation policy can be enforced through the application workload itself for a consistent approach to workload microsegmentation across any environment, including virtualized, bare-metal, and container workloads running in any public cloud or any data center. Once the microsegmentation policy is enforced, Cisco Tetration continues to monitor for compliance deviations, ensuring the segmentation policy is up to date as the application behavior change.
Micro-segmentation secures applications by expressly allowing particular application traffic and, by default, denying all other traffic. Micro-segmentation is the foundation for implementing a zero-trust security model for application workloads in the data center and cloud.
Cisco Tetration is an application workload security platform designed to secure your compute instances across any infrastructure and any cloud. To achieve this, it uses behavior and attribute-driven microsegmentation policy generation and enforcement. It enables trusted access through automated, exhaustive context from various systems to automatically adapt security policies.
To generate accurate microsegmentation policy, Cisco Tetration performs application dependency mapping to discover the relationships between different application tiers and infrastructure services. In addition, the platform supports "what-if" policy analysis using real-time data or historical data to assist in the validation and risk assessment of policy application pre-enforcement to ensure ongoing application availability. The normalized microsegmentation policy can be enforced through the application workload itself for a consistent approach to workload microsegmentation across any environment, including virtualized, bare-metal, and container workloads running in any public cloud or any data center. Once the microsegmentation policy is enforced, Cisco Tetration continues to monitor for compliance deviations, ensuring the segmentation policy is up to date as the application behavior change.
Micro-segmentation secures applications by expressly allowing particular application traffic and, by default, denying all other traffic. Micro-segmentation is the foundation for implementing a zero-trust security model for application workloads in the data center and cloud.
Cisco Tetration is an application workload security platform designed to secure your compute instances across any infrastructure and any cloud. To achieve this, it uses behavior and attribute-driven microsegmentation policy generation and enforcement. It enables trusted access through automated, exhaustive context from various systems to automatically adapt security policies.
To generate accurate microsegmentation policy, Cisco Tetration performs application dependency mapping to discover the relationships between different application tiers and infrastructure services. In addition, the platform supports "what-if" policy analysis using real-time data or historical data to assist in the validation and risk assessment of policy application pre-enforcement to ensure ongoing application availability. The normalized microsegmentation policy can be enforced through the application workload itself for a consistent approach to workload microsegmentation across any environment, including virtualized, bare-metal, and container workloads running in any public cloud or any data center. Once the microsegmentation policy is enforced, Cisco Tetration continues to monitor for compliance deviations, ensuring the segmentation policy is up to date as the application behavior change.


NEW QUESTION # 40
How is data sent out to the attacker during a DNS tunneling attack?

  • A. as part of the UDP/53 packet payload
  • B. as part of the DNS response packet
  • C. as part of the TCP/53 packet header
  • D. as part of the domain name

Answer: D

Explanation:
Data is sent out to the attacker during a DNS tunneling attack as part of the domain name. DNS tunneling is a technique that encodes the data of other protocols or programs in DNS queries and responses. The attacker registers a domain, such as badsite.com, and points it to a server under their control, where a tunneling program is installed. The attacker infects a device with malware, which sends DNS queries to the attacker's server, using subdomains of badsite.com to encode the data. For example, the malware could send a query for
1234.badsite.com, where 1234 is the encoded data. The attacker's server decodes the data from the subdomain and sends back a DNS response, which may also contain encoded data in the answer section12. The other options are not correct, because they do not use the domain name to encode the data. The UDP/53 and TCP/53 packet payload and header are used to transport the DNS query and response, but they are not modified by the tunneling technique. The DNS response packet contains the answer to the query, but it is not the only way to send data to the attacker3. References:
* 1: DNS Tunneling attack - What is it, and how to protect ourselves?
* 2: What Is DNS Tunneling? - Palo Alto Networks
* 3: What Are DNS Attacks? - Palo Alto Networks


NEW QUESTION # 41
Which algorithm provides asymmetric encryption?

  • A. RSA
  • B. 3DES
  • C. AES
  • D. RC4

Answer: A

Explanation:
Asymmetric encryption, also known as public-key cryptography, is a type of encryption that uses a pair of keys to encrypt and decrypt data. The pair of keys includes a public key, which can be shared with anyone, and a private key, which is kept secret by the owner. In asymmetric encryption, the sender uses the recipient's public key to encrypt the data. The recipient then uses their private key to decrypt the data. This approach allows for secure communication between two parties without the need for both parties to have the same secret key. RSA is one of the most commonly used asymmetric encryption algorithms. It is based on the mathematical problem of factoring large numbers, which is believed to be hard to solve. RSA stands for Rivest-Shamir-Adleman, the names of the three inventors of the algorithm. RSA can be used for both encryption and digital signatures. To generate an RSA key pair, the following steps are performed:
* Choose two large prime numbers, p and q, and compute their product, n = pq. This is called the modulus.
* Choose a small number, e, that is relatively prime to (p-1)(q-1). This is called the public exponent.
* Compute a number, d, that satisfies the equation ed 1 (mod (p-1)(q-1)). This is called the private exponent.
* The public key is (n, e) and the private key is (n, d).
To encrypt a message, m, with the public key (n, e), the following formula is used:
* c = m^e mod n
To decrypt a ciphertext, c, with the private key (n, d), the following formula is used:
* m = c^d mod n
References :=
* [Implementing and Operating Cisco Security Core Technologies (SCOR) v1.0], Module 3: VPN Technologies, Lesson 3.1: Site-to-Site VPNs, Topic 3.1.2: IPsec VPNs
* What is Asymmetric Encryption? - GeeksforGeeks
* What is asymmetric encryption? | Asymmetric vs. symmetric ... - Cloudflare


NEW QUESTION # 42
An engineer needs a solution for TACACS+ authentication and authorization for device administration.
The engineer also wants to enhance wired and wireless network security by requiring users and endpoints to use 802.1X, MAB, or WebAuth. Which product meets all of these requirements?

  • A. Cisco Prime Infrastructure
  • B. Cisco Identity Services Engine
  • C. Cisco Stealthwatch
  • D. Cisco AMP for Endpoints

Answer: B

Explanation:
Cisco Identity Services Engine (ISE) is a product that provides comprehensive and scalable access policy enforcement for wired and wireless networks. ISE supports TACACS+ for device administration, which allows for granular control over the commands and actions that network administrators can perform on network devices. ISE also supports 802.1X, MAB, and WebAuth for network access, which enables authentication and authorization of users and endpoints based on various attributes, such as identity, device type, posture, location, and time. ISE can also integrate with other Cisco security products, such as Cisco Stealthwatch and Cisco AMP for Endpoints, to provide enhanced visibility and threat detection. Therefore, ISE is the product that meets all of the requirements stated in the question. References := Some possible references are:
* Implementing and Operating Cisco Security Core Technologies (SCOR) v1.0, Module 4: Secure Network Access, Identity Management, and Secure Access
* TACACS+ Configuration Guide, Configuring TACACS
* Cisco Identity Services Engine Administrator Guide, Release 2.7, Device Administration
* Cisco Identity Services Engine Administrator Guide, Release 2.7, Network Access Devices
* Cisco Identity Services Engine Administrator Guide, Release 2.7, Policy Sets


NEW QUESTION # 43
What limits communication between applications or containers on the same node?

  • A. Software-Defined Access
  • B. microsegmentation
  • C. microservicing
  • D. container orchestration

Answer: A


NEW QUESTION # 44
An engineer must configure Cisco AMP for Endpoints so that it contains a list of files that should not be executed by users. These files must not be quarantined. Which action meets this configuration requirement?

  • A. Modify the advanced custom detection list to include these files.
  • B. Add a list for simple custom detection.
  • C. Create an application control blocked applications list.
  • D. Identity the network IPs and place them in a blocked list.

Answer: C


NEW QUESTION # 45
A network administrator is configuring a switch to use Cisco ISE for 802.1X. An endpoint is failing authentication and is unable to access the network. Where should the administrator begin troubleshooting to verify the authentication details?

  • A. RADIUS Live Logs
  • B. Adaptive Network Control Policy List
  • C. Accounting Reports
  • D. Context Visibility

Answer: A

Explanation:
How To Troubleshoot ISE Failed Authentications & Authorizations
Check the ISE Live Logs
Login to the primary ISE Policy Administration Node (PAN).
Go to Operations > RADIUS > Live Logs
(Optional) If the event is not present in the RADIUS Live Logs, go to Operations > Reports > Reports > Endpoints and Users > RADIUS Authentications Check for Any Failed Authentication Attempts in the Log


NEW QUESTION # 46
What is the difference between deceptive phishing and spear phishing?

  • A. Deceptive phishing is an attacked aimed at a specific user in the organization who holds a C-level role.
  • B. Spear phishing is when the attack is aimed at the C-level executives of an organization
  • C. Deceptive phishing hijacks and manipulates the DNS server of the victim and redirects the user to a false webpage.
  • D. A spear phishing campaign is aimed at a specific person versus a group of people.

Answer: B


NEW QUESTION # 47
An organization has a requirement to collect full metadata information about the traffic going through their AWS cloud services They want to use this information for behavior analytics and statistics Which two actions must be taken to implement this requirement? (Choose two.)

  • A. Send syslog from AWS to Cisco Stealthwatch Cloud.
  • B. Send VPC Flow Logs to Cisco Stealthwatch Cloud.
  • C. Configure Cisco Stealthwatch Cloud to ingest AWS information
  • D. Configure Cisco Thousand Eyes to ingest AWS information.
  • E. Configure Cisco ACI to ingest AWS information.

Answer: C,D


NEW QUESTION # 48
Which Cisco command enables authentication, authorization, and accounting globally so that CoA is supported on the device?

  • A. aaa new-model
  • B. aaa server radius dynamic-author
  • C. ip device-tracking
  • D. auth-type all

Answer: A


NEW QUESTION # 49
......

Pass Cisco 350-701 Premium Files Test Engine pdf - Free Dumps Collection: https://guidetorrent.dumpstorrent.com/350-701-exam-prep.html