ExamGecko
Home Home / Cisco / 300-710

Cisco 300-710 Practice Test - Questions Answers, Page 24

Question list
Search
Search

List of questions

Search

Related questions











An engineer must deploy a Cisco FTD appliance via Cisco FMC to span a network segment to detect malware and threats. When setting the Cisco FTD interface mode, which sequence of actions meets this requirement?

A.

Set to passive, and configure an access control policy with an intrusion policy and a file policy defined

A.

Set to passive, and configure an access control policy with an intrusion policy and a file policy defined

Answers
B.

Set to passive, and configure an access control policy with a prefilter policy defined

B.

Set to passive, and configure an access control policy with a prefilter policy defined

Answers
C.

Set to none, and configure an access control policy with a prefilter policy defined

C.

Set to none, and configure an access control policy with a prefilter policy defined

Answers
D.

Set to none, and configure an access control policy with an intrusion policy and a file policy defined

D.

Set to none, and configure an access control policy with an intrusion policy and a file policy defined

Answers
Suggested answer: A

Refer to the exhibit.

An engineer is analyzing a Network Risk Report from Cisco FMC. Which application must the engineer take immediate action against to prevent unauthorized network use?

A.

Kerberos

A.

Kerberos

Answers
B.

YouTube

B.

YouTube

Answers
C.

Chrome

C.

Chrome

Answers
D.

TOR

D.

TOR

Answers
Suggested answer: D

An engineer wants to perform a packet capture on the Cisco FTD to confirm that the host using IP address 192 168.100.100 has the MAC address of 0042 7734.103 to help troubleshoot a connectivity issue What is the correct tcpdump command syntax to ensure that the MAC address appears in the packet capture output?

A.

-nm src 192.168.100.100

A.

-nm src 192.168.100.100

Answers
B.

-ne src 192.168.100.100

B.

-ne src 192.168.100.100

Answers
C.

-w capture.pcap -s 1518 host 192.168.100.100 mac

C.

-w capture.pcap -s 1518 host 192.168.100.100 mac

Answers
D.

-w capture.pcap -s 1518 host 192.168.100.100 ether

D.

-w capture.pcap -s 1518 host 192.168.100.100 ether

Answers
Suggested answer: B

Explanation:

Reference: https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/212474-workingwith-firepower-threat-defense-f.html

An administrator is adding a QoS policy to a Cisco FTD deployment. When a new rule is added to the policy and QoS is applied on 'Interfaces in Destination Interface Objects", no interface objects are available What is the problem?

A.

The FTD is out of available resources lor use. so QoS cannot be added

A.

The FTD is out of available resources lor use. so QoS cannot be added

Answers
B.

The network segments that the interfaces are on do not have contiguous IP space

B.

The network segments that the interfaces are on do not have contiguous IP space

Answers
C.

QoS is available only on routed interfaces, and this device is in transparent mode.

C.

QoS is available only on routed interfaces, and this device is in transparent mode.

Answers
D.

A conflict exists between the destination interface types that is preventing QoS from being added

D.

A conflict exists between the destination interface types that is preventing QoS from being added

Answers
Suggested answer: C

A Cisco FMC administrator wants to configure fastpathing of trusted network traffic to increase performance. In which type of policy would the administrator configure this feature?

A.

Identity policy

A.

Identity policy

Answers
B.

Prefilter policy

B.

Prefilter policy

Answers
C.

Network Analysis policy

C.

Network Analysis policy

Answers
D.

Intrusion policy

D.

Intrusion policy

Answers
Suggested answer: B

A network administrator is troubleshooting access to a website hosted behind a Cisco FTD device External clients cannot access the web server via HTTPS The IP address configured on the web server is 192 168 7.46 The administrator is running the command capture CAP interface outside match ip any 192.168.7.46 255.255.255.255 but cannot see any traffic in the capture Why is this occurring?

A.

The capture must use the public IP address of the web server.

A.

The capture must use the public IP address of the web server.

Answers
B.

The FTD has no route to the web server.

B.

The FTD has no route to the web server.

Answers
C.

The access policy is blocking the traffic.

C.

The access policy is blocking the traffic.

Answers
D.

The packet capture shows only blocked traffic

D.

The packet capture shows only blocked traffic

Answers
Suggested answer: A

Remote users who connect via Cisco AnyConnect to the corporate network behind a Cisco FTD device report that they get no audio when calling between remote users using their softphones. These same users can call internal users on the corporate network without any issues. What is the cause of this issue?

A.

The hairpinning feature is not available on FTD.

A.

The hairpinning feature is not available on FTD.

Answers
B.

Split tunneling is enabled for the Remote Access VPN on FTD

B.

Split tunneling is enabled for the Remote Access VPN on FTD

Answers
C.

FTD has no NAT policy that allows outside to outside communication

C.

FTD has no NAT policy that allows outside to outside communication

Answers
D.

The Enable Spoke to Spoke Connectivity through Hub option is not selected on FTD.

D.

The Enable Spoke to Spoke Connectivity through Hub option is not selected on FTD.

Answers
Suggested answer: A

An engineer must configure the firewall to monitor traffic within a single subnet without increasing the hop count of that traffic. How would the engineer achieve this?

A.

Configure Cisco Firepower as a transparent firewall

A.

Configure Cisco Firepower as a transparent firewall

Answers
B.

Set up Cisco Firepower as managed by Cisco FDM

B.

Set up Cisco Firepower as managed by Cisco FDM

Answers
C.

Configure Cisco Firepower in FXOS monitor only mode.

C.

Configure Cisco Firepower in FXOS monitor only mode.

Answers
D.

Set up Cisco Firepower in intrusion prevention mode

D.

Set up Cisco Firepower in intrusion prevention mode

Answers
Suggested answer: A

Which action must be taken on the Cisco FMC when a packet bypass is configured in case the Snort engine is down or a packet takes too long to process?

A.

Enable Inspect Local Router Traffic

A.

Enable Inspect Local Router Traffic

Answers
B.

Enable Automatic Application Bypass

B.

Enable Automatic Application Bypass

Answers
C.

Configure Fastpath rules to bypass inspection

C.

Configure Fastpath rules to bypass inspection

Answers
D.

Add a Bypass Threshold policy for failures

D.

Add a Bypass Threshold policy for failures

Answers
Suggested answer: B

An engineer is configuring multiple Cisco FTD appliances (or use in the network. Which rule must the engineer follow while defining interface objects in Cisco FMC for use with interfaces across multiple devices?

A.

An interface cannot belong to a security zone and an interface group

A.

An interface cannot belong to a security zone and an interface group

Answers
B.

Interface groups can contain multiple interface types

B.

Interface groups can contain multiple interface types

Answers
C.

Interface groups can contain interfaces from many devices.

C.

Interface groups can contain interfaces from many devices.

Answers
D.

Two security zones can contain the same interface

D.

Two security zones can contain the same interface

Answers
Suggested answer: C
Total 326 questions
Go to page: of 33