Exam Name

Advanced Security Architecture System Engineer


1. Cisco 500-265 exam test could be registered online or at your local exam center.

Pearson VUE (virtual university enterprise)
If you sign up for an exam in the United States and Canada, you can visit VUE website, or dial 1-800-829-nets (6387), choose 1, and press 4.

For countries and territories outside the United States and Canada, please contact VUE for details.

Thomson Prometric
If you sign up for an exam in the United States and Canada, you can visit Prometric, or call 1-800-829-nets (6387), choose 1, and press 4.

For countries and regions outside the United States and Canada, please contact Prometric for detailed information.

In the United States and Canada, you can register for the first six weeks in advance, and the deadline is the day of the test.
Candidates usually have to wait five days after taking a test before they can take the test again.

Question No : 1

Which feature of content security enables administrators to block Facebook videos while allowing posts and messages?
A. dynamic content analysis
B. Cisco Application Visibility and Control
C. centralized management and reporting
D. encryption
Answer: B

Question No : 2

in the Cisco TrustSec"User to Datacenter Access Control"use case,which users typically have access to the company data center?
D.noncompliant users
Answer: B

Question No : 3

In addition to web security and email security,which feature is a main component of the Cisco web and email security solution?
A.Next-Generation Firewall
B.malware protection
C.Next-Generation Intrusion Prevention System
D.DNS-layer security
Answer: B

Question No : 4

Which feature of Cisco Cyber Threat Defense uses more than 40 detectors to process every HTTP or HTTPS request the network?
A.event classification
B.relationship modeling
C.trust modeling
D.anomaly derection
Answer: A

Question No : 5

Which three values should you use to position Cisco security solutions? (Choose three.)
A. time-to-value
B. protection
C. control
D. integration
E. flexibility
F. agility
G. scalability
Answer: B,C,E

Question No : 6

Which option is a primary feature of Cisco TrustSec?
A.firewall policy automation
B.device profiling and onboarding
C.SSL decryption
D.dynamic role-based access control
E.context-aware access
F.secure remote access
Answer: D

Question No : 7

At which point is a threat triggered during the entity modeling phase?
A.whenever a similar request is made
B.when the significance threshold is reached
C.whenever a suspicious file enters the network
D.Threats are not triggered in this phase.
Answer: B

Question No : 8

If a customer complains that employees access websites for work but then waste time with games and videos, which solution should you suggest, and why?
A. Cisco AMP, for protection before, during, and after attacks
B. Cisco WSA, for its URL filtering ability
C. Cisco RSA, for its data loss prevention
D. Cisco WSA, for its application visibility and control
E. Cisco ESA, for its global threat operations
F. Cisco ESA, for its antivirus capabilities
Answer: D

Question No : 9

Which three options describe the main problems with traditional security solutions? (Choose three.)
A. fragmented solutions
B. the lack of management solutions
C. missing components
D. solutions being pieced together
E. the lack of a cloud solution
F. the lack of a firewall
G. security gaps
Answer: A,D,G

Question No : 10

Why do companies need the quickly scalable Cisco Secure Data Center virtualization and cloud technology solution?
A. Fifty-six percent of employees who leave a company take private information with them.
B. Competitors are gaining a 33 percent market share.
C. Administrators are allowing a growing number of BYOD devices.
D. Staff is unable to keep up with newer data center technology.
E. Provisioning time for data centers has decreased from eight weeks to 15 minutes.
F. Management is expected to decrease IT budgets by 25 percent.
Answer: E

Question No : 11

Which two option are benefits of combining web security and remote access VPN?(Choose two)
A.Restrict BYOD usage.
B.Defend the network against web malware and sateguard web usage.
C.Extend proven web security to roaming users.
D.Stop all threats from getting in and spreading.
E.Block threats at the DNS layer
Answer: BC

Question No : 12

Which two statements about the identity-based policy controls are true?(Choose two)
A.Stop threats from getting in and spreading.
B.Manage identity policies.
C.Monitor web and email traffic.
D.Control all access from one place.
E.Identify malicious files.
Answer: AB

Question No : 13

Which option is a standalone Cisco Firepower NGIPS appliance?
A.Firepower 4100 Series
B.Firepower 7000 Series
C.ASA Plus
D.NGIPSv for VMware
Answer: B

Question No : 14

Which feature of URL filtering uses contextual data to produce a highly granular score of -10 to 10 for URLs?
A.file sandboxing
B.file trajectory
C.reputation filtering
D.identity access and control
Answer: C

Question No : 15

Which two features of Cisco AnyConnect contribute to secure remote access? (Choose two.)
A. guest access management
B. superior clientless network access
C. accelerated security options
D. compliance and tracking
E. context-aware access
F. extensive BYOD support
G. centralized management
Answer: B,F

Question No : 16

Which tow features are part of Cisco ldentity Services Engine?(Choose two)
A.sercure remote access
B.guest access management
C.SSL decryption
D.application visibility and control
E.device profiling
F.file-type blocking
Answer: BD

Question No : 17

What is the primary reason that customers need content security today?
A. Companies are more spread out than ever before.
B. Organizations need to block high-risk websites.
C. Network traffic is growing at an exponential rate.
D. Storage is moving from on-premises to cloud-based.
E. More business is done using the web and email than ever before.
Answer: E

Question No : 18

Which option is an ideal security application solution for a cloud data center use case?
A.Cisco ASA 5505-X physical appliance with Cisco Adaptive Security Managr
B.Cisco Firepower NGFW physical appliance with Cisco Dafense Orchestrator
C.Cisco Firepower NGFW virtual appliance with Cisco Firepower Management Center
D.Cisco Firepower Threat Defense physical appliance for Amazon Web Services with Cisco Firepower Management Center
Answer: C

Question No : 19

Which Cisco IPS feature adapts in real time to detect and block intrusions that range from neverbefore-seen worms to the most sophisticated and subtle criminal attacks?
A. file-type detection
B. intelligent detection
C. user identity tracking
D. SSL decryption
E. impact assessment
F. automated policy tuning
Answer: B

Question No : 20

Which quality is an example of the Cisco value of fiexibility?
A.the only comprehensive policy enforcement tool
B.best continuous analysis
C.better ability to scale and alter your environment
D.faster threat identification
E.enhanced remediation
Answer: D
