ExamGecko
Home Home / Cisco / 300-710

Cisco 300-710 Practice Test - Questions Answers, Page 3

Question list
Search
Search

List of questions

Search

Related questions











Within an organization's high availability environment where both firewalls are passing traffic, traffic must be segmented based on which department it is destined for. Each department is situated on a different LAN. What must be configured to meet these requirements?

A.

span EtherChannel clustering

A.

span EtherChannel clustering

Answers
B.

redundant interfaces

B.

redundant interfaces

Answers
C.

high availability active/standby firewalls

C.

high availability active/standby firewalls

Answers
D.

multi-instance firewalls

D.

multi-instance firewalls

Answers
Suggested answer: D

An engineer is configuring a Cisco IPS to protect the network and wants to test a policy before deploying it. A copy of each incoming packet needs to be monitored while traffic flow remains constant. Which IPS mode should be implemented to meet these requirements?

A.

Inline tap

A.

Inline tap

Answers
B.

passive

B.

passive

Answers
C.

transparent

C.

transparent

Answers
D.

routed

D.

routed

Answers
Suggested answer: A

A network security engineer must replace a faulty Cisco FTD device in a high availability pair. Which action must be taken while replacing the faulty unit?

A.

Shut down the Cisco FMC before powering up the replacement unit.

A.

Shut down the Cisco FMC before powering up the replacement unit.

Answers
B.

Ensure that the faulty Cisco FTD device remains registered to the Cisco FMC.

B.

Ensure that the faulty Cisco FTD device remains registered to the Cisco FMC.

Answers
C.

Unregister the faulty Cisco FTD device from the Cisco FMC

C.

Unregister the faulty Cisco FTD device from the Cisco FMC

Answers
D.

Shut down the active Cisco FTD device before powering up the replacement unit.

D.

Shut down the active Cisco FTD device before powering up the replacement unit.

Answers
Suggested answer: C

An administrator is optimizing the Cisco FTD rules to improve network performance, and wants to bypass inspection for certain traffic types to reduce the load on the Cisco FTD. Which policy must be configured to accomplish this goal?

A.

prefilter

A.

prefilter

Answers
B.

intrusion

B.

intrusion

Answers
C.

identity

C.

identity

Answers
D.

URL filtering

D.

URL filtering

Answers
Suggested answer: A

A Cisco FTD has two physical interfaces assigned to a BVI. Each interface is connected to a different VLAN on the same switch. Which firewall mode is the Cisco FTD set up to support?

A.

active/active failover

A.

active/active failover

Answers
B.

transparent

B.

transparent

Answers
C.

routed

C.

routed

Answers
D.

high availability clustering

D.

high availability clustering

Answers
Suggested answer: B

An organization is migrating their Cisco ASA devices running in multicontext mode to Cisco FTD devices. Which action must be taken to ensure that each context on the Cisco ASA is logically separated in the Cisco FTD devices?

A.

Add a native instance to distribute traffic to each Cisco FTD context.

A.

Add a native instance to distribute traffic to each Cisco FTD context.

Answers
B.

Add the Cisco FTD device to the Cisco ASA port channels.

B.

Add the Cisco FTD device to the Cisco ASA port channels.

Answers
C.

Configure a container instance in the Cisco FTD for each context in the Cisco ASA.

C.

Configure a container instance in the Cisco FTD for each context in the Cisco ASA.

Answers
D.

Configure the Cisco FTD to use port channels spanning multiple networks.

D.

Configure the Cisco FTD to use port channels spanning multiple networks.

Answers
Suggested answer: C

Which firewall design allows a firewall to forward traffic at layer 2 and layer 3 for the same subnet?

A.

Cisco Firepower Threat Defense mode

A.

Cisco Firepower Threat Defense mode

Answers
B.

transparent mode

B.

transparent mode

Answers
C.

routed mode

C.

routed mode

Answers
D.

integrated routing and bridging

D.

integrated routing and bridging

Answers
Suggested answer: B

Explanation:

Topic 2, Configuration

Which two OSPF routing features are configured in Cisco FMC and propagated to Cisco FTD? (Choose two.)

A.

OSPFv2 with IPv6 capabilities

A.

OSPFv2 with IPv6 capabilities

Answers
B.

virtual links

B.

virtual links

Answers
C.

SHA authentication to OSPF packets

C.

SHA authentication to OSPF packets

Answers
D.

area boundary router type 1 LSA filtering

D.

area boundary router type 1 LSA filtering

Answers
E.

MD5 authentication to OSPF packets

E.

MD5 authentication to OSPF packets

Answers
Suggested answer: B, E

Explanation:

Reference:

https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-configguide-v62/ospf_for_firepower_threat_defense.html

When creating a report template, how can the results be limited to show only the activity of a specific subnet?

A.

Create a custom search in Firepower Management Center and select it in each section of the report.

A.

Create a custom search in Firepower Management Center and select it in each section of the report.

Answers
B.

Add an Input Parameter in the Advanced Settings of the report, and set the type to Network/IP.

B.

Add an Input Parameter in the Advanced Settings of the report, and set the type to Network/IP.

Answers
C.

Add a Table View section to the report with the Search field defined as the network in CIDR format.

C.

Add a Table View section to the report with the Search field defined as the network in CIDR format.

Answers
D.

Select IP Address as the X-Axis in each section of the report.

D.

Select IP Address as the X-Axis in each section of the report.

Answers
Suggested answer: B

Explanation:

Reference: https://www.cisco.com/c/en/us/td/docs/security/firesight/541/user-guide/FireSIGHTSystem-UserGuide-v5401/Reports.html#87267

What is the disadvantage of setting up a site-to-site VPN in a clustered-units environment?

A.

VPN connections can be re-established only if the failed master unit recovers.

A.

VPN connections can be re-established only if the failed master unit recovers.

Answers
B.

Smart License is required to maintain VPN connections simultaneously across all cluster units.

B.

Smart License is required to maintain VPN connections simultaneously across all cluster units.

Answers
C.

VPN connections must be re-established when a new master unit is elected.

C.

VPN connections must be re-established when a new master unit is elected.

Answers
D.

Only established VPN connections are maintained when a new master unit is elected.

D.

Only established VPN connections are maintained when a new master unit is elected.

Answers
Suggested answer: C

Explanation:

Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/fxos/clustering/ftd-clustersolution.html#concept_g32_yml_y2b

Total 326 questions
Go to page: of 33