Cisco 300-710 Practice Test - Questions Answers, Page 29
List of questions
Related questions
Which action must be taken to configure an isolated bridge group for IRB mode on a Cisco Secure Firewall device?
Add the restricted segment to the ACL.
Leave BVI interface name empty.
Define the NAT pool for the blocked traffic.
Remove the route from the routing table.
An administrator must fix a network problem whereby traffic from the inside network to a webserver is not getting through an instance of Cisco Secure Firewall Threat Defense. Which command must the administrator use to capture packets to the webserver that are dropped by Secure Firewall Throat Defense and resold the issue?
capture CAP int OUTSIDE match ip any host WEBSERVERIP
capture CAP type asp-drop all headers-only
capture CAP int INSIDE match ip any host WEBSERVERIP
capture CAP int INSIDE match tcp any 80 host WEBSERVERlP 80
What is the role of realms in the Cisco ISE and Cisco FMC integration?
AD definition
TACACS+ database
Cisco ISE context
Cisco Secure Firewall VDC
A network administrator is trying to configure Active Directory authentication for VPN authentication to a Cisco Secure Firewall Threat Defence instance that is registered with Cisco Secure Firewall Management Center. Which system settings must be configured first in Secure Firewall Management Center to accomplish the goal?
Device, Remote Access VPN
System, Realms
Policies, Authentication
Authentication, Device
A network administrator is trying to configure an access rule to allow access to a specific banking site over HTTPS. Which method must the administrator use to meet the requirement?
Enable SSL decryption and specify the URL.
Define the URL to be blocked and set the application to HTTP.
Define the URL to be blocked and disable SSL inspection.
Block the category of banking and define the application of WWW.
An engineer is configuring a Cisco Secure Firewall Threat Defence device managed by Cisco Secure Firewall Management Centre. The device must have SSH enabled and the accessible from the inside interface for remote administration. Which type of policy must the engineer configure to accomplish this?
Identify
Access control
Prefilter
Platform settings
Which component simplifies incident investigation with Cisco Threat Response?
Cisco AMP client
local CVE database
Cisco Secure Firewall appliance
browser plug-in
Refer to the exhibit.
A company is deploying a pair of Cisco Secure Firewall Threat defence devices named FTD1 and FTD2. FTD1 and FTD2 have been configured as an active/standby pair with a failover link but without a stateful link. What must be implemented next to ensure that users on the internal network still communicate with outside devices if FTD1 fails?
Disable port security on the switch interfaces connected to FTD1 and FTD2.
Set maximum secured addresses to two on the switch interfaces on FTD1 and FTD2.
Connect and configure a stateful link and thon deploy the changes.
Configure the spanning-tree PortFasI feature on SW1 and FTD2
A network engineer must configure IPS mode on a Cisco Secure firewall Threat Defense device to inspect traffic and act as an IDS. The engineer already configured the passive-interface on the secure firewall threat Defence device and SPAN on the switch. What must be configured next by the engineer?
intrusion policy on the Secure Firewall Threat Defense device
active Interface on me Secure Firewall threat Defense device
DHCP on the switch
active SPAN port on the switch
An administrator is attempting to add a Cisco Secure Firewall Threat Defence device to Cisco Secure Firewall Management Center with a password of Cisco0480846211 480846211. The private IP address of the FMC server is 192.168.75.201. Which command must be used in order to accomplish this task?
configure manager add 192.168.75.201/24 <reg_key>
configure manager add 192.16875.201 <reg_key>
configure manager add 192.168.45.45 <reg_key> <nal-ld>
configure manager add 192.168.75.201 255.255.255.0 <reg_key>
Question