0% found this document useful (0 votes)
312 views30 pages

300-710 SNCF Exam

The document provides questions and answers related to Cisco Firepower Threat Defense and Cisco Firepower Management Center. It contains 18 multiple choice questions covering topics like Cisco FTD clustering, high availability, interface types, routing protocols, and more. The questions are from a Cisco 300-710 exam preparation PDF.

Uploaded by

Jorge Armas
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
312 views30 pages

300-710 SNCF Exam

The document provides questions and answers related to Cisco Firepower Threat Defense and Cisco Firepower Management Center. It contains 18 multiple choice questions covering topics like Cisco FTD clustering, high availability, interface types, routing protocols, and more. The questions are from a Cisco 300-710 exam preparation PDF.

Uploaded by

Jorge Armas
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
  • Introduction
  • Product Questions: 80 Version: 7.0
  • Questioning Sequence
  • Advanced Deployment
  • Networking Protocols
  • Application Integration
  • Configuration Templates
  • Operational Commands
  • Firewall Management
  • QoS Configurations
  • Policy Enforcement
  • Packet Capture
  • Data Reporting
  • Insights and Analysis
  • Technical Procedures
  • Error Management
  • Client Configuration Commands
  • Troubleshooting Tools
  • System Limitations
  • Security Certificates
  • Database Management
  • Malware Detection
  • Remediation Options
  • Assessment and Analyses
  • Deployment Modes
  • Analyzing Firepower
  • Network Security Policy
  • Routing Configurations
  • System Migration
  • Final Considerations

Questions & Answers PDF P-1

Cisco
300-710 Exam
Cisco Securing Networks with Cisco Firepower Exam
Questions & Answers PDF P-2

Product Questions: 80
Version: 7.0
Question: 1

What is a result of enabling Cisco FTD clustering?

A. For the dynamic routing feature, if the master unit fails, the newly elected master unit maintains
all existing connections.
B. Integrated Routing and Bridging is supported on the master unit.
C. Site-to-site VPN functionality is limited to the master unit, and all VPN connections are dropped if
the master unit fails.
D. All Firepower appliances can support Cisco FTD clustering.

Answer: C

Explanation:
Reference:
[Link]
guide-v64/clustering_for_the_firepower_threat_defense.html

Question: 2

Which two conditions are necessary for high availability to function between two Cisco FTD devices?
(Choose two.)

A. The units must be the same version


B. Both devices can be part of a different group that must be in the same domain when configured
within the FMC.
C. The units must be different models if they are part of the same series.
D. The units must be configured only for firewall routed mode.
E. The units must be the same model.

Answer: AE

Explanation:
Reference:

[Link]
[Link]

Question: 3
Questions & Answers PDF P-3

On the advanced tab under inline set properties, which allows interfaces to emulate a passive
interface?

A. transparent inline mode


B. TAP mode
C. strict TCP enforcement
D. propagate link state

Answer: D

Explanation:
Reference:
[Link]
guide-v64/inline_sets_and_passive_interfaces_for_firepower_threat_defense.html

Question: 4

What are the minimum requirements to deploy a managed device inline?

A. inline interfaces, security zones, MTU, and mode


B. passive interface, MTU, and mode
C. inline interfaces, MTU, and mode
D. passive interface, security zone, MTU, and mode

Answer: C

Explanation:
Reference:

[Link]
guide-v65/ips_device_deployments_and_configuration.html

Question: 5

What is the difference between inline and inline tap on Cisco Firepower?

A. Inline tap mode can send a copy of the traffic to another device.
B. Inline tap mode does full packet capture.
C. Inline mode cannot do SSL decryption.
D. Inline mode can drop malicious traffic.

Answer: D

Question: 6
Questions & Answers PDF P-4

With Cisco Firepower Threat Defense software, which interface mode must be configured to
passively receive traffic that passes through the appliance?

A. inline set
B. passive
C. routed
D. inline tap

Answer: B

Explanation:
Reference:
[Link]
guide-v64/interface_overview_for_firepower_threat_defense.html

Question: 7

Which two deployment types support high availability? (Choose two.)

A. transparent
B. routed
C. clustered
D. intra-chassis multi-instance

E. virtual appliance in public cloud

Answer: AB

Explanation:
Reference:
[Link]
guide-v61/firepower_threat_defense_high_availability.html

Question: 8

Which protocol establishes network redundancy in a switched Firepower device deployment?

A. STP
B. HSRP
C. GLBP
D. VRRP

Answer: A

Explanation:
Reference:
Questions & Answers PDF P-5

[Link]
guide-v62/firepower_threat_defense_high_availability.html

Question: 9

Which interface type allows packets to be dropped?

A. passive
B. inline
C. ERSPAN
D. TAP

Answer: B

Explanation:
Reference:
[Link]
firepower- [Link]

Question: 10

Which Cisco Firepower Threat Defense, which two interface settings are required when configuring a
routed interface? (Choose two.)

A. Redundant Interface
B. EtherChannel
C. Speed
D. Media Type
E. Duplex

Answer: CE

Explanation:
[Link]
610/fptd-fdm- [Link]

Question: 11

Which two dynamic routing protocols are supported in Firepower Threat Defense without using
FlexConfig? (Choose two.)

A. EIGRP
B. OSPF
C. static routing
D. IS-IS
E. BGP
Questions & Answers PDF P-6

Answer: CE

Explanation:
Reference:
[Link]
660/fptd- [Link]

Question: 12

Which policy rule is included in the deployment of a local DMZ during the initial deployment of a
Cisco NGFW through the Cisco FMC GUI?

A. a default DMZ policy for which only a user can change the IP addresses.
B. deny ip any
C. no policy rule is included
D. permit ip any

Answer: C

Question: 13

What are two application layer preprocessors? (Choose two.)

A. CIFS
B. IMAP
C. SSL
D. DNP3
E. ICMP

Answer: BC

Explanation:
Reference:
[Link]
guide-v60/Application_Layer_Preprocessors.html

Question: 14

Which two OSPF routing features are configured in Cisco FMC and propagated to Cisco FTD? (Choose
two.)

A. OSPFv2 with IPv6 capabilities


B. virtual links
C. SHA authentication to OSPF packets
D. area boundary router type 1 LSA filtering
Questions & Answers PDF P-7

E. MD5 authentication to OSPF packets

Answer: BD

Explanation:
Reference:
[Link]
guide-v62/ospf_for_firepower_threat_defense.html

Question: 15

When creating a report template, how can the results be limited to show only the activity of a
specific subnet?

A. Create a custom search in Firepower Management Center and select it in each section of the
report.
B. Add an Input Parameter in the Advanced Settings of the report, and set the type to Network/IP.
C. Add a Table View section to the report with the Search field defined as the network in CIDR
format.
D. Select IP Address as the X-Axis in each section of the report.

Answer: B

Explanation:
Reference:
[Link]
UserGuide-v5401/[Link]#87267

Question: 16

What is the disadvantage of setting up a site-to-site VPN in a clustered-units environment?

A. VPN connections can be re-established only if the failed master unit recovers.
B. Smart License is required to maintain VPN connections simultaneously across all cluster units.
C. VPN connections must be re-established when a new master unit is elected.
D. Only established VPN connections are maintained when a new master unit is elected.

Answer: C

Explanation:
Reference:
[Link]
[Link]#concept_g32_yml_y2b

Question: 17
Questions & Answers PDF P-8

Which two statements about bridge-group interfaces in Cisco FTD are true? (Choose two.)

A. The BVI IP address must be in a separate subnet from the connected network.

B. Bridge groups are supported in both transparent and routed firewall modes.
C. Bridge groups are supported only in transparent firewall mode.
D. Bidirectional Forwarding Detection echo packets are allowed through the FTD when using bridge-
group members.
E. Each directly connected network must be on the same subnet.

Answer: CD

Explanation:
Reference:
[Link]
guide-v62/transparent_or_routed_firewall_mode_for_firepower_threat_defense.html

Question: 18

Which command is run on an FTD unit to associate the unit to an FMC manager that is at IP address
[Link], and that has the registration key Cisco123?

A. configure manager local [Link] Cisco123


B. configure manager add Cisco123 [Link]
C. configure manager local Cisco123 [Link]
D. configure manager add [Link] Cisco123

Answer: D

Explanation:
Reference:
[Link]
[Link]#id_106101

Question: 19

Which two actions can be used in an access control policy rule? (Choose two.)

A. Block with Reset


B. Monitor
C. Analyze
D. Discover
E. Block ALL

Answer: AB

Explanation:
Questions & Answers PDF P-9

Reference:
[Link]
firepower-module-user-guide-v541/[Link]#71854

Question: 20

Which two routing options are valid with Cisco Firepower Threat Defense? (Choose two.)

A. BGPv6
B. ECMP with up to three equal cost paths across multiple interfaces
C. ECMP with up to three equal cost paths across a single interface
D. BGPv4 in transparent firewall mode
E. BGPv4 with nonstop forwarding

Answer: AC

Explanation:
Reference:
[Link]
guide-v601/fpmc-config-guide-v60_chapter_01100011.html#ID-2101-0000000e

Question: 21

Which object type supports object overrides?

A. time range
B. security group tag
C. network object
D. DNS server group

Answer: C

Explanation:
Reference:
[Link]
guide- v60/Reusable_Objects.html#concept_8BFE8B9A83D742D9B647A74F7AD50053

Question: 22

Which Cisco Firepower rule action displays an HTTP warning page?

A. Monitor
B. Block
C. Interactive Block
D. Allow with Warning
Questions & Answers PDF P-10

Answer: C

Explanation:
Reference:
[Link]
UserGuide-v5401/[Link]#76698

Question: 23

What is the result of specifying of QoS rule that has a rate limit that is greater than the maximum
throughput of an interface?

A. The rate-limiting rule is disabled.


B. Matching traffic is not rate limited.
C. The system rate-limits all traffic.
D. The system repeatedly generates warnings.

Answer: B

Explanation:
Reference:
[Link]
guide-v62/quality_of_service_qos.pdf

Question: 24

Which Firepower feature allows users to configure bridges in routed mode and enables devices to
perform Layer 2 switching between interfaces?

A. FlexConfig
B. BDI
C. SGT
D. IRB

Answer: D

Explanation:
Reference:
[Link]
Firepower_System_Release_Notes_Version_620/new_features_and_functionality.html

Question: 25

In which two places can thresholding settings be configured? (Choose two.)


Questions & Answers PDF P-11

A. on each IPS rule


B. globally, within the network analysis policy
C. globally, per intrusion policy
D. on each access control rule
E. per preprocessor, within the network analysis policy

Answer: AC

Explanation:
Reference:
[Link]
firepower-module-user-guide-v541/[Link]

Question: 26

In which two ways do access control policies operate on a Cisco Firepower system? (Choose two.)

A. Traffic inspection can be interrupted temporarily when configuration changes are deployed.
B. The system performs intrusion inspection followed by file inspection.
C. They can block traffic based on Security Intelligence data.
D. File policies use an associated variable set to perform intrusion prevention.
E. The system performs a preliminary inspection on trusted traffic to validate that it matches the
trusted parameters.

Answer: AC

Explanation:
Reference:
[Link]
guide-v60/Access_Control_Using_Intrusion_and_File_Policies.html

Question: 27

Which two types of objects are reusable and supported by Cisco FMC? (Choose two.)

A. dynamic key mapping objects that help link HTTP and HTTPS GET requests to Layer 7 application
protocols.
B. reputation-based objects that represent Security Intelligence feeds and lists, application filters
based on category and reputation, and file lists
C. network-based objects that represent IP address and networks, port/protocols pairs, VLAN tags,
security zones, and origin/destination country
D. network-based objects that represent FQDN mappings and networks, port/protocol pairs, VXLAN
tags, security zones and origin/destination country
E. reputation-based objects, such as URL categories

Answer: BC
Questions & Answers PDF P-12

Explanation:
Reference:
[Link]
guide-v62/reusable_objects.html#ID-2243-00000414

Question: 28

What is the benefit of selecting the trace option for packet capture?

A. The option indicates whether the packet was dropped or successful.


B. The option indicated whether the destination host responds through a different path.
C. The option limits the number of packets that are captured.
D. The option captures details of each packet.

Answer: C

Question: 29

After deploying a network-monitoring tool to manage and monitor networking devices in your
organization, you realize that you need to manually upload an MIB for the Cisco FMC. In which folder
should you upload the MIB file?

A. /etc/sf/[Link]
B. /sf/etc/[Link]
C. /etc/sf/[Link]
D. system/etc/[Link]

Answer: C

Explanation:
Reference:
[Link]
firepower-module-user-guide-v541/[Link]

Question: 30

Which command is run at the CLI when logged in to an FTD unit, to determine whether the unit is
managed locally or by a remote FMC server?

A. system generate-troubleshoot
B. show configuration session
C. show managers
D. show running-config | include manager

Answer: C
Questions & Answers PDF P-13

Explanation:
Reference:
[Link]
b_Command_Reference_for_Firepower_Threat_Defense/c_3.html

Question: 31

Which command should be used on the Cisco FTD CLI to capture all the packets that hit an interface?

A. configure coredump packet-engine enable


B. capture-traffic
C. capture
D. capture WORD

Answer: B

Explanation:
Reference:
[Link]
b_Command_Reference_for_Firepower_Threat_Defense/ac_1.html

Question: 32

How many report templates does the Cisco Firepower Management Center support?

A. 20
B. 10
C. 5
D. unlimited

Answer: D

Explanation:
Reference:
[Link]
guide- v60/Working_with_Reports.html

Question: 33

Which action should be taken after editing an object that is used inside an access control policy?

A. Delete the existing object in use.


B. Refresh the Cisco FMC GUI for the access control policy.
C. Redeploy the updated configuration.
D. Create another rule using a different object name.
Questions & Answers PDF P-14

Answer: C

Explanation:
Reference:
[Link]
guide-v63/reusable_objects.html

Question: 34

Which Cisco Firepower feature is used to reduce the number of events received in a period of time?

A. rate-limiting
B. suspending
C. correlation
D. thresholding

Answer: D

Explanation:
Reference:
[Link]
firepower-module-user-guide-v541/[Link]

Question: 35

Which report template field format is available in Cisco FMC?

A. box lever chart


B. arrow chart
C. bar chart
D. benchmark chart

Answer: C

Explanation:
Reference:
[Link]
guide- v60/Working_with_Reports.html

Question: 36

Which group within Cisco does the Threat Response team use for threat analysis and research?

A. Cisco Deep Analytics


B. OpenDNS Group
C. Cisco Network Response
Questions & Answers PDF P-15

D. Cisco Talos

Answer: D

Explanation:
Reference:
[Link]

Question: 37

Drag and drop the steps to restore an automatic device registration failure on the standby Cisco FMC
from the left into the correct order on the right. Not all options are used.

Answer:

Explanation
Explanation:
Reference:
Questions & Answers PDF P-16

[Link]
guide-v62/firepower_management_center_high_availability.html#id_32288

Question: 38
Which CLI command is used to generate firewall debug messages on a Cisco Firepower?

A. system support firewall-engine-debug


B. system support ssl-debug
C. system support platform
D. system support dump-table

Answer: A

Explanation:
Reference:
[Link]
[Link]

Question: 39

Which command-line mode is supported from the Cisco Firepower Management Center CLI?

A. privileged
B. user
C. configuration
D. admin

Answer: C

Explanation:
Reference:
[Link]
guide-v66/command_line_reference.pdf

Question: 40

Which command is entered in the Cisco FMC CLI to generate a troubleshooting file?

A. show running-config
B. show tech-support chassis
C. system support diagnostic-cli
D. sudo sf_troubleshoot.pl

Answer: D

Explanation:
Questions & Answers PDF P-17

Reference:
[Link]
[Link]

Question: 41

Which CLI command is used to control special handling of ClientHello messages?

A. system support ssl-client-hello-tuning


B. system support ssl-client-hello-display
C. system support ssl-client-hello-force-reset
D. system support ssl-client-hello-enabled

Answer: D

Answer: D
Explanation:
Reference:
[Link]
guide-v61/firepower_command_line_reference.html

Question: 42

Which command is typed at the CLI on the primary Cisco FTD unit to temporarily stop running high-
availability?

A. configure high-availability resume


B. configure high-availability disable
C. system support network-options
D. configure high-availability suspend

Answer: B
Questions & Answers PDF P-18

Explanation:
Reference:
[Link]
guide-v61/firepower_threat_defense_high_availability.html

Question: 43

Which command must be run to generate troubleshooting files on an FTD?

A. system support view-files


B. sudo sf_troubleshoot.pl
C. system generate-troubleshoot all
D. show tech-support

Answer: B

Explanation:
Reference:
[Link]
[Link]

Question: 44

When do you need the file-size command option during troubleshooting with packet capture?

A. when capture packets are less than 16 MB


B. when capture packets are restricted from the secondary memory
C. when capture packets exceed 10 GB
D. when capture packets exceed 32 MB

Answer: D

Explanation:
Reference:
[Link]
guide-v62/troubleshooting_the_system.html

Question: 45

What is a functionality of port objects in Cisco FMC?

A. to mix transport protocols when setting both source and destination port conditions in a rule
B. to represent protocols other than TCP, UDP, and ICMP
C. to represent all protocols in the same way
D. to add any protocol other than TCP or UDP for source port conditions in access control rules.
Questions & Answers PDF P-19

Answer: B

Explanation:
Reference:
[Link]
guide-v62/reusable_objects.html

Question: 46

Within Cisco Firepower Management Center, where does a user add or modify widgets?

A. dashboard
B. reporting
C. context explorer
D. summary tool

Answer: A

Explanation:
Reference:
[Link]
guide- v60/Using_Dashboards.html

Question: 47

A network engineer is configuring URL Filtering on Firepower Threat Defense. Which two port
requirements on the Firepower Management Center must be validated to allow communication with
the cloud service? (Choose two.)

A. outbound port TCP/443


B. inbound port TCP/80
C. outbound port TCP/8080
D. inbound port TCP/443
E. outbound port TCP/80

Answer: AE

Explanation:
Reference:
[Link]
guide-v60/SecurityInternet_Accessand_Communication_Ports.html

Question: 48
Questions & Answers PDF P-20

What is the maximum bit size that Cisco FMC supports for HTTPS certificates?

A. 1024
B. 8192
C. 4096
D. 2048

Answer: D

Explanation:
Reference:
[Link]
guide-v61/system_configuration.html

Question: 49

Which limitation applies to Cisco Firepower Management Center dashboards in a multidomain


environment?

A. Child domains can view but not edit dashboards that originate from an ancestor domain.
B. Child domains have access to only a limited set of widgets from ancestor domains.
C. Only the administrator of the top ancestor domain can view dashboards.
D. Child domains cannot view dashboards that originate from an ancestor domain.

Answer: D

Explanation:
Reference:
[Link]
guide- v60/Using_Dashboards.html

Question: 50

Which two statements about deleting and re-adding a device to Cisco FMC are true? (Choose two.)

A. An option to re-apply NAT and VPN policies during registration is available, so users do not need to
re- apply the policies after registration is completed.
B. Before re-adding the device in Cisco FMC, you must add the manager back in the device.
C. No option to delete and re-add a device is available in the Cisco FMC web interface.
D. The Cisco FMC web interface prompts users to re-apply access control policies.
E. No option to re-apply NAT and VPN policies during registration is available, so users need to re-
apply the policies after registration is completed.

Answer: DE

Explanation:
Questions & Answers PDF P-21

Reference:
[Link]
guide- v60/Device_Management_Basics.html

Question: 51

What is a behavior of a Cisco FMC database purge?

A. User login and history data are removed from the database if the User Activity check box is
selected.
B. Data can be recovered from the device.
C. The appropriate process is restarted.
D. The specified data is removed from Cisco FMC and kept for two weeks.

Answer: C

Explanation:
Reference:
[Link]
guide-v62/management_center_database_purge.pdf

Question: 52

Which two packet captures does the FTD LINA engine support? (Choose two.)

A. Layer 7 network ID
B. source IP
C. application ID
D. dynamic firewall importing
E. protocol

Answer: BE

Explanation:
Reference:
[Link]
[Link]

Question: 53

Which two features of Cisco AMP for Endpoints allow for an uploaded file to be blocked? (Choose
two.)

A. application blocking
B. simple custom detection
C. file repository
Questions & Answers PDF P-22

D. exclusions
E. application whitelisting

Answer: AB

Question: 54

Which action should you take when Cisco Threat Response notifies you that AMP has identified a file
as malware?

A. Add the malicious file to the block list.


B. Send a snapshot to Cisco for technical support.
C. Forward the result of the investigation to an external threat-analysis engine.
D. Wait for Cisco Threat Response to automatically block the malware.

Answer: A

Question: 55

Which Cisco Advanced Malware Protection for Endpoints policy is used only for monitoring endpoint
actively?

A. Windows domain controller


B. audit
C. triage
D. protection

Answer: B

Explanation:
Reference:
[Link]
[Link]

Question: 56

What is a valid Cisco AMP file disposition?

A. non-malicious
B. malware
C. known-good
D. pristine

Answer: B

Explanation:
Questions & Answers PDF P-23

Reference:
[Link]
guide- v60/Reference_a_wrapper_Chapter_topic_here.html

Question: 57

In a Cisco AMP for Networks deployment, which disposition is returned if the cloud cannot be
reached?

A. unavailable
B. unknown
C. clean
D. disconnected

Answer: B

Question: 58

Which two remediation options are available when Cisco FMC is integrated with Cisco ISE? (Choose
two.)

A. dynamic null route configured


B. DHCP pool disablement
C. quarantine
D. port shutdown
E. host shutdown

Answer: CD

Explanation:
Reference:
[Link]
[Link]

Question: 59

Which connector is used to integrate Cisco ISE with Cisco FMC for Rapid Threat Containment?

A. pxGrid
B. FTD RTC
C. FMC RTC
D. ISEGrid

Answer: A
Questions & Answers PDF P-24

Question: 60

What is the maximum SHA level of filtering that Threat Intelligence Director supports?

A. SHA-1024
B. SHA-4096
C. SHA-512
D. SHA-256

Answer: D

Explanation:
Reference:
[Link]
guide-v623/cisco_threat_intelligence_directortid_.html

Question: 61

Refer to the exhibit.

And engineer is analyzing the Attacks Risk Report and finds that there are over 300 instances of new
operating systems being seen on the network How is the Firepower configuration updated to protect
these new operating systems?

A. Cisco Firepower automatically updates the policies.


B. The administrator requests a Remediation Recommendation Report from Cisco Firepower
C. Cisco Firepower gives recommendations to update the policies.
D. The administrator manually updates the policies.

Answer: C

Ref: [Link]
config-guide-v60/Tailoring_Intrusion_Protection_to_Your_Network_Assets.html
Questions & Answers PDF P-25

Question: 62

An engineer is implementing Cisco FTD in the network and is determining which Firepower mode to
use. The organization needs to have multiple virtual Firepower devices working separately inside of
the FTD appliance to provide traffic segmentation Which deployment mode should be configured in
the Cisco Firepower Management Console to support these requirements?

A. multiple deployment
B. single-context
C. single deployment
D. multi-instance

Answer: D

Question: 63

A network engineer is extending a user segment through an FTD device for traffic inspection without
creating another IP subnet How is this accomplished on an FTD device in routed mode?

A. by leveraging the ARP to direct traffic through the firewall


B. by assigning an inline set interface
C. by using a BVI and create a BVI IP address in the same subnet as the user segment
D. by bypassing protocol inspection by leveraging pre-filter rules

Answer: C

[Link]
guide-v64/transparent_or_routed_firewall_mode_for_firepower_threat_defense.html

Question: 64

An engineer is configuring a second Cisco FMC as a standby device but is unable to register with the
active unit. What is causing this issue?

A. The primary FMC currently has devices connected to it.


B. The code versions running on the Cisco FMC devices are different
C. The licensing purchased does not include high availability
D. There is only 10 Mbps of bandwidth between the two devices.

Answer: B

[Link]
guide-v62/firepower_management_center_high_availability.html

Question: 65
Questions & Answers PDF P-26

After using Firepower for some time and learning about how it interacts with the network, an
administrator is trying to correlate malicious activity with a user Which widget should be configured
to provide this visibility on the Cisco Firepower dashboards?

A. Custom Analysis
B. Current Status
C. Current Sessions
D. Correlation Events

Answer: D

Question: 66

An engineer has been asked to show application usages automatically on a monthly basis and send
the information to management What mechanism should be used to accomplish this task?

A. event viewer
B. reports
C. dashboards
D. context explorer

Answer: B

Question: 67

An engineer is setting up a new Firepower deployment and is looking at the default FMC policies to
start the implementation During the initial trial phase, the organization wants to test some common
Snort rules while still allowing the majority of network traffic to pass Which default policy should be
used?

A. Maximum Detection
B. Security Over Connectivity
C. Balanced Security and Connectivity
D. Connectivity Over Security

Answer: C

[Link]
623/[Link]

Question: 68

An engineer currently has a Cisco FTD device registered to the Cisco FMC and is assigned the address
of 10 10.50.12. The organization is upgrading the addressing schemes and there is a requirement to
convert the addresses to a format that provides an adequate amount of addresses on the network
What should the engineer do to ensure that the new addressing takes effect and can be used for the
Questions & Answers PDF P-27

Cisco FTD to Cisco FMC connection?

A. Delete and reregister the device to Cisco FMC


B. Update the IP addresses from IFV4 to IPv6 without deleting the device from Cisco FMC
C. Format and reregister the device to Cisco FMC.
D. Cisco FMC does not support devices that use IPv4 IP addresses.

Answer: B

Question: 69

A security engineer is configuring an Access Control Policy for multiple branch locations These
locations share a common rule set and utilize a network object called INSIDE_NET which contains the
locally significant internal network subnets at each location What technique will retain the policy
consistency at each location but allow only the locally significant network subnet within the
applicable rules?

A. utilizing policy inheritance


B. utilizing a dynamic ACP that updates from Cisco Talos
C. creating a unique ACP per device
D. creating an ACP with an INSIDE_NET network object and object overrides

Answer: A

Question: 70

An engineer is troubleshooting application failures through a FTD deployment. While using the FMC
CLI. it has been determined that the traffic in question is not matching the desired policy. What
should be done to correct this?

A. Use the system support firewall-engine-debug command to determine which rules the traffic
matching and modify the rule accordingly
B. Use the system support application-identification-debug command to determine which rules the
traffic matching and modify the rule accordingly
C. Use the system support firewall-engine-dump-user-f density-data command to change the policy
and allow the application through the firewall.
D. Use the system support network-options command to fine tune the policy.

Answer: A

Question: 71

An administrator is attempting to remotely log into a switch in the data centre using SSH and is
unable to connect. How does the administrator confirm that traffic is reaching the firewall?

A. by running Wireshark on the administrator's PC


Questions & Answers PDF P-28

B. by performing a packet capture on the firewall.


C. by running a packet tracer on the firewall.
D. by attempting to access it from a different workstation.

Answer: B

Question: 72

What is the advantage of having Cisco Firepower devices send events to Cisco Threat response via
the security services exchange portal directly as opposed to using syslog?

A. Firepower devices do not need to be connected to the internet.


B. All types of Firepower devices are supported.
C. Supports all devices that are running supported versions of Firepower
D. An on-premises proxy server does not need to set up and maintained

Answer: B

Question: 73

An organization has noticed that malware was downloaded from a website that does not currently
have a known bad reputation. How will this issue be addresses globally in the quickest way possible
and with the least amount of impact?

A. by denying outbound web access


B. Cisco Talos will automatically update the policies.
C. by Isolating the endpoint
D. by creating a URL object in the policy to block the website

Answer: D

Question: 74

An administrator is working on a migration from Cisco ASA to the Cisco FTD appliance and needs to
test the rules without disrupting the traffic. Which policy type should be used to configure the ASA
rules during this phase of the migration?

A. identity
B. Intrusion
C. Access Control
D. Prefilter

Answer: C

Question: 75
Questions & Answers PDF P-29

Which two routing options are valid with Cisco FTD? (Choose Two)

A. BGPv4 in transparent firewall mode


B. BGPv6
C. BGPv4 with nonstop forwarding
D. ECMP with up to three equal cost paths across a single interface
E. ECMP with up to three equal cost paths across multiple interfaces

Answer: C D

Question: 76

With Cisco FTD integrated routing and bridging, which interface does the bridge group use to
communicate with a routed interface?

A. switch virtual
B. bridge group member
C. bridge virtual
D. subinterface

Answer: B

Question: 77

While configuring FTD, a network engineer wants to ensure that traffic passing through the appliance
does not require routing or Vlan rewriting. Which interface mode should the engineer implement to
accomplish this task?

A. passive
B. transparent
C. Inline tap
D. Inline set

Answer: B

Question: 78

The event dashboard within the Cisco FMC has been inundated with low priority intrusion drop
events, which are overshadowing high priority events. An engineer has been tasked with reviewing
the policies and reducing the low priority events. Which action should be configured to accomplish
this task?

A. generate events
B. drop packet
C. drop connection
D. drop and generate
Questions & Answers PDF P-30

Answer: D

Question: 79

An engineer is configuring a cisco FTD appliance in IPS-only mode and needs to utilize fail-to-wire
interfaces. Which interface mode should be used to meet these requirements?

A. transparent
B. routed
C. passive
D. inline set

Answer: D

Question: 80

Which two considerations must be made when deleting and re-adding devices while managing them
via Cisco FMC (Choose two).

A. Before re-adding the device In Cisco FMC, the manager must be added back.
B. The Cisco FMC web interface prompts users to re-apply access control policies.
C. Once a device has been deleted, It must be reconfigured before it is re-added to the Cisco FMC.
D. An option to re-apply NAT and VPN policies during registration is available, so users do not need to
re-apply the polices after registration is completed.
E. There is no option to re-apply NAT and VPN policies during registration is available, so users need
to re-apply the policies after registration is completed.

Answer: BE

Questions & Answers PDF
P-1
Cisco
300-710 Exam
Cisco Securing Networks with Cisco Firepower Exam
Questions & Answers PDF
P-2
Product Questions: 80
Version: 7.0
Question: 1
What is a result of enabling Cisco FTD clustering?
Questions & Answers PDF
P-3
On the advanced tab under inline set properties, which allows interfaces to emulate a passive
int
Questions & Answers PDF
P-4
With Cisco Firepower Threat Defense software, which interface mode must be configured to
passivel
Questions & Answers PDF
P-5
https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-
gui
Questions & Answers PDF
P- (https://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide
Questions & Answers PDF
P-7
E. MD5 authentication to OSPF packets
Answer: BD
Explanation:
Reference:
https://www.cisco.com/c/
Questions & Answers PDF
P-8
Which two statements about bridge-group interfaces in Cisco FTD are true? (Choose two.)
A. The BV
Questions & Answers PDF
P-9
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firesight/541/firepower-module-user-gui
Questions & Answers PDF
P-10
Answer: C
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firesight/541/u

You might also like