A Python script is parsing a JSON response from the Cisco Secure Firewall Management Center (FMC) API which returns a list of network objects. Each object is a dictionary containing keys like 'name', 'value', and 'id'. To efficiently store and look up these objects by their unique ID, which Python data structure is most appropriate for the final collection?
Answer and explanation
Correct answer: C
A dictionary is the ideal data structure for this use case. Using the unique object ID as the key allows for constant time O(1) lookups, which is highly efficient. A list would require iterating through it to find an object by ID (O(n) complexity), a tuple is immutable, and a set does not store key-value pairs.
Question 2
During a git merge operation from a feature branch into the main branch, a conflict occurs in a Python script that defines firewall policies. The conflict marker >>>>>> feature-branch-name indicates the incoming changes. What is the correct procedure to resolve this conflict and complete the merge?
Answer and explanation
Correct answer: D
The standard procedure for resolving a Git merge conflict is to manually edit the conflicted file(s). The developer must decide which changes to keep, remove the >>>>>> markers, and create the final, correct version of the code. After saving the file, git add stages the resolved file, and git commit (or git merge --continue) completes the merge process.
Question 3
A security automation script needs to query the Cisco Umbrella Investigate API to check the reputation of thousands of domains from a log file. The script must process these as quickly as possible. The Investigate API allows for multiple concurrent requests. Which API consumption pattern is most suitable for this task?
Answer and explanation
Correct answer: B
For tasks involving many independent, I/O-bound operations like API calls, an asynchronous pattern is far more efficient. Libraries such as asyncio allow the script to send multiple requests concurrently without waiting for each one to complete. This significantly reduces the total execution time compared to a synchronous approach, which would be bottlenecked by network latency for each individual request.
Question 4
Multiple answers
A security developer is creating a new Python project to interact with Cisco ISE and FMC APIs. To ensure project dependencies are isolated and reproducible, they decide to use a virtual environment. Which two commands are essential for creating the virtual environment and installing the required libraries from a requirements.txt file? (Select TWO)
Answer and explanation
Correct answers: A, C
Question 5
True or False: The Cisco Secure Firewall Management Center (FMC) REST API allows for direct manipulation of running configurations on a managed firewall device without requiring a deployment action.
Answer and explanation
Correct answer: B
The statement is false. The FMC REST API modifies the configuration database on the FMC itself. Any changes made via the API, such as creating objects or modifying access policies, are staged. They do not take effect on the managed devices until a deployment task is initiated, either through the UI or via a separate API call.
Question 6
A network automation engineer needs to create a new host object on a Cisco Secure Firewall Management Center (FMC) via the REST API. Which API endpoint path is used to create this type of object?
Answer and explanation
Correct answer: C
The correct endpoint to create network objects like hosts, networks, or ranges is within the object model of a specific domain. A POST request to /api/fmc_config/v1/domain/{domainUUID}/object/hosts with the appropriate JSON payload will create a new host object in the specified domain.
Question 7
A SOC analyst identifies a compromised endpoint with IP address 10.10.50.100. They need to use a Python script to immediately quarantine the device using the Cisco ISE ERS API. The script will add the endpoint's MAC address to a 'Quarantined_Endpoints' identity group, which has a restrictive authorization policy. The following diagram shows the high-level workflow:
[SOC Script] [Cisco ISE]
| |
1. |-- Find Endpoint --▶|
| by IP Address |
| |
2. |◀-- Return MAC & ID--|
| |
3. |-- Update Endpoint --▶|
| (Set Group ID) |
| |
4. |◀-- 200 OK ---------|
Which ERS API call is used in Step 3 to update the endpoint's group membership?
Answer and explanation
Correct answer: C
To update an existing resource in the ISE ERS API, a PUT request is used. First, the script must retrieve the unique ID of the endpoint (as shown in Step 2). Then, it sends a PUT request to the specific endpoint's resource URL (/ers/config/endpoint/{id}). The request body must contain the full object definition, including the groupId field updated with the UUID of the target identity group.
Question 8
An automation script that updates an access control policy on Cisco FMC is failing. The script successfully authenticates and creates a new network object, but the subsequent API call to add a rule using this object fails with a 404 Not Found error, referencing the new object's ID. The object is visible in the FMC UI. What is the most likely reason for this failure?
Answer and explanation
Correct answer: B
A common cause for this issue is a domain mismatch. Objects in FMC are scoped to a specific domain. If the script creates the network object in the Global domain but then tries to add a rule to a policy in a child domain (e.g., 'DomainA'), the API will return a 404 error because the object does not exist within the context of 'DomainA'. The API calls for both object creation and policy modification must use the same, correct domain UUID.
Question 9
A financial services company is implementing a zero-trust network access model. They have Cisco ISE for network access control and Cisco FMC managing their firewalls. The security team wants to automate policy enforcement based on real-time endpoint posture.
The requirement is to dynamically adjust an endpoint's firewall access policy based on its Security Group Tag (SGT) assigned by ISE. When an endpoint connects and is profiled by ISE, it is assigned an SGT (e.g., 'Corporate_Assets', 'BYOD_Devices', 'Quarantine'). This SGT information must be shared with the FMC, which will then enforce a corresponding SGT-based access control rule, granting or restricting access to critical applications.
This solution must be highly available and scalable, providing near real-time updates without relying on manual intervention or periodic polling. The communication between ISE and FMC must be secure and use a standardized Cisco framework for security product integration.
Which combination of technologies and APIs provides the most efficient and scalable solution to meet these requirements?
Answer and explanation
Correct answer: C
This is the native, most efficient, and scalable solution designed by Cisco for this exact purpose. Cisco pxGrid (Platform Exchange Grid) provides a publish/subscribe messaging bus for security products to share context. By configuring ISE as a publisher of session information (including IP-to-SGT mappings) and FMC as a subscriber, the FMC receives near real-time updates. This allows the firewall to enforce SGT-based policies dynamically without the complexity and delay of polling or syslog parsing. This method is secure, highly scalable, and the intended best practice.
Question 10
What is the primary architectural pattern of Cisco pxGrid?
Answer and explanation
Correct answer: C
Cisco pxGrid is fundamentally a publish/subscribe messaging framework. Security products (like ISE) can act as 'publishers' of specific topics (like session information). Other products or custom scripts can act as 'subscribers' to receive real-time updates on those topics. This decoupled, event-driven architecture allows for scalable and efficient context sharing across a multi-vendor security ecosystem.