Skip to content

300-735 Automating Cisco Security Solutions (SAUTO) Practice Questions

Prepare for 300-735 with more than an answer.

206 questions in the full set20 sample questionsUpdated Aug 16, 2021
  1. 1

    A security analyst needs to write a script to retrieve all high-priority intrusion events from an FMC within a specific 4-hour window from the previous day. Which set of query parameters should be included in the GET request to the intrusion events API endpoint?

    Show answer details

    Correct answer: D

    The FMC API uses a powerful filter parameter for querying. To get high-priority events, the filter would be priority:1 (where 1 represents high priority). To specify a precise time window, the startTime and endTime parameters must be used with appropriate timestamp values (e.g., ISO 8601 format). Combining these parameters allows for a targeted and efficient query of the event database.

  2. 2

    A security architect is designing an automated threat response system. The goal is to automatically isolate any corporate endpoint where a process matching a known malicious hash is detected. The system uses Cisco ISE and a custom application. Which TWO pxGrid capabilities are required for the application to achieve this? (Select TWO)

    Show answer details

    Correct answer: B, E

  3. 3

    An engineer uses the Cisco Secure Firewall Device Manager (FDM) API to push a new interface configuration to a device. The API call is successful and returns a 202 Accepted status code, but the changes are not immediately active on the firewall. What is the mandatory next step in the automation workflow to make the changes take effect?

    Show answer details

    Correct answer: A

    Similar to FMC, changes made via the FDM API are staged in a pending configuration. A 202 Accepted response indicates the change has been accepted but not yet applied. To apply the pending changes, a separate API call must be made to trigger the deployment process. The correct endpoint for this is /api/fdm/v1/operational/deploy.

  4. 4

    What is the primary function of the Cisco Umbrella Investigate API?

    Show answer details

    Correct answer: B

    The Umbrella Investigate API provides access to a massive database of threat intelligence gathered from Cisco's global network. It allows developers and security tools to query for the reputation, categorization, and related infrastructure of domains, IPs, URLs, and file hashes. This is distinct from the Umbrella Enforcement or Reporting APIs, which are used for policy management and logging.

  5. 5

    A security analyst needs to automate the submission of a suspicious file for sandboxing and analysis using the Cisco Secure Malware Analytics (Threat Grid) API. The script has the file content available. Which API endpoint and HTTP method should be used to submit this file?

    Show answer details

    Correct answer: B

    To submit a new file for analysis, a POST request must be made to the /api/v2/samples endpoint. The request body should be a multipart/form-data payload containing the file itself, along with other optional parameters like vm (to specify the analysis environment), private (to control visibility), and tags.

  6. 6

    A Python script is parsing a JSON response from the Cisco Secure Firewall Management Center (FMC) API which returns a list of network objects. Each object is a dictionary containing keys like 'name', 'value', and 'id'. To efficiently store and look up these objects by their unique ID, which Python data structure is most appropriate for the final collection?

    Show answer details

    Correct answer: C

    A dictionary is the ideal data structure for this use case. Using the unique object ID as the key allows for constant time O(1) lookups, which is highly efficient. A list would require iterating through it to find an object by ID (O(n) complexity), a tuple is immutable, and a set does not store key-value pairs.

  7. 7

    During a git merge operation from a feature branch into the main branch, a conflict occurs in a Python script that defines firewall policies. The conflict marker >>>>>> feature-branch-name indicates the incoming changes. What is the correct procedure to resolve this conflict and complete the merge?

    Show answer details

    Correct answer: D

    The standard procedure for resolving a Git merge conflict is to manually edit the conflicted file(s). The developer must decide which changes to keep, remove the >>>>>> markers, and create the final, correct version of the code. After saving the file, git add stages the resolved file, and git commit (or git merge --continue) completes the merge process.

  8. 8

    A security automation script needs to query the Cisco Umbrella Investigate API to check the reputation of thousands of domains from a log file. The script must process these as quickly as possible. The Investigate API allows for multiple concurrent requests. Which API consumption pattern is most suitable for this task?

    Show answer details

    Correct answer: B

    For tasks involving many independent, I/O-bound operations like API calls, an asynchronous pattern is far more efficient. Libraries such as asyncio allow the script to send multiple requests concurrently without waiting for each one to complete. This significantly reduces the total execution time compared to a synchronous approach, which would be bottlenecked by network latency for each individual request.

  9. 9

    A security developer is creating a new Python project to interact with Cisco ISE and FMC APIs. To ensure project dependencies are isolated and reproducible, they decide to use a virtual environment. Which two commands are essential for creating the virtual environment and installing the required libraries from a requirements.txt file? (Select TWO)

    Show answer details

    Correct answer: A, C

  10. 10

    True or False: The Cisco Secure Firewall Management Center (FMC) REST API allows for direct manipulation of running configurations on a managed firewall device without requiring a deployment action.

    Show answer details

    Correct answer: B

    The statement is false. The FMC REST API modifies the configuration database on the FMC itself. Any changes made via the API, such as creating objects or modifying access policies, are staged. They do not take effect on the managed devices until a deployment task is initiated, either through the UI or via a separate API call.

Create an account to continue.