300-735 Automating Cisco Security Solutions (SAUTO) Practice Questions
Prepare for 300-735 with more than an answer.
- 1
A security analyst needs to write a script to retrieve all high-priority intrusion events from an FMC within a specific 4-hour window from the previous day. Which set of query parameters should be included in the GET request to the intrusion events API endpoint?
Show answer details
Correct answer: D
The FMC API uses a powerful
filterparameter for querying. To get high-priority events, the filter would bepriority:1(where 1 represents high priority). To specify a precise time window, thestartTimeandendTimeparameters must be used with appropriate timestamp values (e.g., ISO 8601 format). Combining these parameters allows for a targeted and efficient query of the event database. - 2
A security architect is designing an automated threat response system. The goal is to automatically isolate any corporate endpoint where a process matching a known malicious hash is detected. The system uses Cisco ISE and a custom application. Which TWO pxGrid capabilities are required for the application to achieve this? (Select TWO)
Show answer details
Correct answer: B, E
- 3
An engineer uses the Cisco Secure Firewall Device Manager (FDM) API to push a new interface configuration to a device. The API call is successful and returns a
202 Acceptedstatus code, but the changes are not immediately active on the firewall. What is the mandatory next step in the automation workflow to make the changes take effect?Show answer details
Correct answer: A
Similar to FMC, changes made via the FDM API are staged in a pending configuration. A
202 Acceptedresponse indicates the change has been accepted but not yet applied. To apply the pending changes, a separate API call must be made to trigger the deployment process. The correct endpoint for this is/api/fdm/v1/operational/deploy. - 4
What is the primary function of the Cisco Umbrella Investigate API?
Show answer details
Correct answer: B
The Umbrella Investigate API provides access to a massive database of threat intelligence gathered from Cisco's global network. It allows developers and security tools to query for the reputation, categorization, and related infrastructure of domains, IPs, URLs, and file hashes. This is distinct from the Umbrella Enforcement or Reporting APIs, which are used for policy management and logging.
- 5
A security analyst needs to automate the submission of a suspicious file for sandboxing and analysis using the Cisco Secure Malware Analytics (Threat Grid) API. The script has the file content available. Which API endpoint and HTTP method should be used to submit this file?
Show answer details
Correct answer: B
To submit a new file for analysis, a POST request must be made to the
/api/v2/samplesendpoint. The request body should be amultipart/form-datapayload containing the file itself, along with other optional parameters likevm(to specify the analysis environment),private(to control visibility), and tags. - 6
A Python script is parsing a JSON response from the Cisco Secure Firewall Management Center (FMC) API which returns a list of network objects. Each object is a dictionary containing keys like 'name', 'value', and 'id'. To efficiently store and look up these objects by their unique ID, which Python data structure is most appropriate for the final collection?
Show answer details
Correct answer: C
A dictionary is the ideal data structure for this use case. Using the unique object ID as the key allows for constant time O(1) lookups, which is highly efficient. A list would require iterating through it to find an object by ID (O(n) complexity), a tuple is immutable, and a set does not store key-value pairs.
- 7
During a
git mergeoperation from a feature branch into the main branch, a conflict occurs in a Python script that defines firewall policies. The conflict marker>>>>>> feature-branch-nameindicates the incoming changes. What is the correct procedure to resolve this conflict and complete the merge?Show answer details
Correct answer: D
The standard procedure for resolving a Git merge conflict is to manually edit the conflicted file(s). The developer must decide which changes to keep, remove the
>>>>>>markers, and create the final, correct version of the code. After saving the file,git addstages the resolved file, andgit commit(orgit merge --continue) completes the merge process. - 8
A security automation script needs to query the Cisco Umbrella Investigate API to check the reputation of thousands of domains from a log file. The script must process these as quickly as possible. The Investigate API allows for multiple concurrent requests. Which API consumption pattern is most suitable for this task?
Show answer details
Correct answer: B
For tasks involving many independent, I/O-bound operations like API calls, an asynchronous pattern is far more efficient. Libraries such as
asyncioallow the script to send multiple requests concurrently without waiting for each one to complete. This significantly reduces the total execution time compared to a synchronous approach, which would be bottlenecked by network latency for each individual request. - 9
A security developer is creating a new Python project to interact with Cisco ISE and FMC APIs. To ensure project dependencies are isolated and reproducible, they decide to use a virtual environment. Which two commands are essential for creating the virtual environment and installing the required libraries from a
requirements.txtfile? (Select TWO)Show answer details
Correct answer: A, C
- 10
True or False: The Cisco Secure Firewall Management Center (FMC) REST API allows for direct manipulation of running configurations on a managed firewall device without requiring a deployment action.
Show answer details
Correct answer: B
The statement is false. The FMC REST API modifies the configuration database on the FMC itself. Any changes made via the API, such as creating objects or modifying access policies, are staged. They do not take effect on the managed devices until a deployment task is initiated, either through the UI or via a separate API call.
