300-735 Sample Questions

300-735 Sample Questions & Answers

Free Automating Cisco Security Solutions (SAUTO) practice questions with worked answers and explanations. See how the ExamJungle simulator prepares you — then jump into the full test.

Launch the full 300-735 simulator →

Showing 10 of 20 free samples.

  1. Question 1Beginner

    Network Security · API-based firewall configuration (objects, rules, intrusion policies)

    A network automation engineer needs to create a new host object on a Cisco Secure Firewall Management Center (FMC) via the REST API. Which API endpoint path is used to create this type of object?

    Show answer & explanation

    Correct answer: C

    The correct endpoint to create network objects like hosts, networks, or ranges is within the object model of a specific domain. A POST request to /api/fmc_config/v1/domain/{domainUUID}/object/hosts with the appropriate JSON payload will create a new host object in the specified domain.

  2. Question 2Intermediate

    Network Security · API capabilities of Cisco Identity Services Engine (ISE)

    A SOC analyst identifies a compromised endpoint with IP address 10.10.50.100. They need to use a Python script to immediately quarantine the device using the Cisco ISE ERS API. The script will add the endpoint's MAC address to a 'Quarantined_Endpoints' identity group, which has a restrictive authorization policy. The following diagram shows the high-level workflow:

    [SOC Script] [Cisco ISE]
    | |
    1. |-- Find Endpoint --▶|
    | by IP Address |
    | |
    2. |◀-- Return MAC & ID--|
    | |
    3. |-- Update Endpoint --▶|
    | (Set Group ID) |
    | |
    4. |◀-- 200 OK ---------|
    

    Which ERS API call is used in Step 3 to update the endpoint's group membership?

    Show answer & explanation

    Correct answer: C

    To update an existing resource in the ISE ERS API, a PUT request is used. First, the script must retrieve the unique ID of the endpoint (as shown in Step 2). Then, it sends a PUT request to the specific endpoint's resource URL (/ers/config/endpoint/{id}). The request body must contain the full object definition, including the groupId field updated with the UUID of the target identity group.

  3. Question 3Intermediate

    Network Security · API-based firewall configuration (objects, rules, intrusion policies)

    An automation script that updates an access control policy on Cisco FMC is failing. The script successfully authenticates and creates a new network object, but the subsequent API call to add a rule using this object fails with a 404 Not Found error, referencing the new object's ID. The object is visible in the FMC UI. What is the most likely reason for this failure?

    Show answer & explanation

    Correct answer: B

    A common cause for this issue is a domain mismatch. Objects in FMC are scoped to a specific domain. If the script creates the network object in the Global domain but then tries to add a rule to a policy in a child domain (e.g., 'DomainA'), the API will return a 404 error because the object does not exist within the context of 'DomainA'. The API calls for both object creation and policy modification must use the same, correct domain UUID.

  4. Question 4Advanced

    Network Security · pxGrid APIs and capabilities

    A financial services company is implementing a zero-trust network access model. They have Cisco ISE for network access control and Cisco FMC managing their firewalls. The security team wants to automate policy enforcement based on real-time endpoint posture.

    The requirement is to dynamically adjust an endpoint's firewall access policy based on its Security Group Tag (SGT) assigned by ISE. When an endpoint connects and is profiled by ISE, it is assigned an SGT (e.g., 'Corporate_Assets', 'BYOD_Devices', 'Quarantine'). This SGT information must be shared with the FMC, which will then enforce a corresponding SGT-based access control rule, granting or restricting access to critical applications.

    This solution must be highly available and scalable, providing near real-time updates without relying on manual intervention or periodic polling. The communication between ISE and FMC must be secure and use a standardized Cisco framework for security product integration.

    Which combination of technologies and APIs provides the most efficient and scalable solution to meet these requirements?

    Show answer & explanation

    Correct answer: C

    This is the native, most efficient, and scalable solution designed by Cisco for this exact purpose. Cisco pxGrid (Platform Exchange Grid) provides a publish/subscribe messaging bus for security products to share context. By configuring ISE as a publisher of session information (including IP-to-SGT mappings) and FMC as a subscriber, the FMC receives near real-time updates. This allows the firewall to enforce SGT-based policies dynamically without the complexity and delay of polling or syslog parsing. This method is secure, highly scalable, and the intended best practice.

  5. Question 5Beginner

    Network Security · pxGrid APIs and capabilities

    What is the primary architectural pattern of Cisco pxGrid?

    Show answer & explanation

    Correct answer: C

    Cisco pxGrid is fundamentally a publish/subscribe messaging framework. Security products (like ISE) can act as 'publishers' of specific topics (like session information). Other products or custom scripts can act as 'subscribers' to receive real-time updates on those topics. This decoupled, event-driven architecture allows for scalable and efficient context sharing across a multi-vendor security ecosystem.

  6. Question 6Intermediate

    Network Security · Python scripts for pxGrid integration

    A developer is writing a Python script to act as a pxGrid client. After successfully connecting to the pxGrid controller and looking up the 'SessionDirectory' service, what is the next logical API call to start receiving session information?

    Show answer & explanation

    Correct answer: B

    The pxGrid 2.0 architecture uses WebSockets for subscriptions. After discovering the service node that provides the 'SessionDirectory' capability, the client must establish a persistent WebSocket connection to that node. Over this connection, it sends a subscribe message and then begins receiving real-time session events (creations, updates, deletions) as they occur.

  7. Question 7Intermediate

    Network Security · API-based firewall configuration (objects, rules, intrusion policies)

    A network administrator is tasked with automating the creation of 500 new access control rules in Cisco FMC. The rule details (source IP, destination IP, port, action) are provided in a CSV file. Manually creating these rules is not feasible. What is the most efficient approach to accomplish this task?

    Show answer & explanation

    Correct answer: B

    This is a classic automation use case for the FMC API. A script (Python is common) can easily parse the CSV data. For each row, it can dynamically create the necessary network/port objects if they don't exist, and then construct the JSON payload for a new access rule. A POST request is then made for each rule. This approach is highly flexible, repeatable, and scalable.

  8. Question 8Advanced

    Network Security · API capabilities of Cisco Secure Firewall Management Center

    A Python script designed to manage Cisco FMC objects is intermittently failing with a 401 Unauthorized error, even though the authentication process to get a token succeeds and the token is correctly included in the X-auth-access-token header. The script runs for about 45 minutes, processing a large number of objects. What is the most likely cause of this error?

    Show answer & explanation

    Correct answer: B

    The FMC API authentication process provides both an access token (typically valid for 30 minutes) and a refresh token. For long-running scripts, the initial access token will expire. The correct behavior is for the script to use the refresh token (via a POST to /api/fmc_platform/v1/auth/refreshtoken) to obtain a new access token before the old one expires. Failure to implement this refresh logic is a common cause of 401 Unauthorized errors in scripts that run longer than the token's lifetime.

  9. Question 9Intermediate

    Network Security · Cisco Secure Network Analytics APIs

    A security operations team is building a script to continuously pull security events from the Cisco Secure Network Analytics (SNA/Stealthwatch) API for ingestion into a data lake. They notice that aggressive polling is causing the API to respond with 429 Too Many Requests errors. What is the recommended best practice for handling API rate limiting in this scenario?

    Show answer & explanation

    Correct answer: B

    The industry-standard best practice for handling rate limiting (HTTP 429 errors) is to implement an exponential backoff strategy. When a 429 response is received, the script should wait for a short period before retrying. If the retry also fails, the waiting period should be increased (e.g., doubled). This prevents the script from overwhelming the API server and allows it to gracefully recover once the rate limit window has passed. Many APIs also provide a Retry-After header indicating how long to wait.

  10. Question 10Beginner

    Network Security · API capabilities of Cisco Identity Services Engine (ISE)

    When using the Cisco ISE Endpoint Protection Service (EPS) via the REST API to trigger a quarantine action on an endpoint, which HTTP method is used?

    Show answer & explanation

    Correct answer: C

    The ISE EPS API uses the PUT method to apply mitigation actions like quarantine. The API call is made to an endpoint like /eps/ise/eps/quarantine/mac/{macaddress}. The PUT method is used here to create or replace the state of the resource (the quarantine status for the specified MAC address).

Ready for the real thing?

The full 300-735 simulator has every exam-style question, timed mode, and instant scoring.