
Brilliant 300-710 Exam Dumps Get 300-710 Dumps PDF
300-710 Dumps PDF - 300-710 Real Exam Questions Answers
NEW QUESTION # 33
Which policy rule is included in the deployment of a local DMZ during the initial deployment of a Cisco NGFW through the Cisco FMC GUI?
- A. permit ip any
- B. a default DMZ policy for which only a user can change the IP addresses.
- C. no policy rule is included
- D. deny ip any
Answer: C
Explanation:
Section: Deployment
NEW QUESTION # 34
An engineer is configuring a second Cisco FMC as a standby device but is unable to register with the active unit. What is causing this issue?
- A. The code versions running on the Cisco FMC devices are different
- B. The primary FMC currently has devices connected to it.
- C. The licensing purchased does not include high availability
- D. There is only 10 Mbps of bandwidth between the two devices.
Answer: A
Explanation:
https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/firepower_management_center_high_availability.html
NEW QUESTION # 35
Which two considerations must be made when deleting and re-adding devices while managing them via Cisco FMC (Choose two).
- A. An option to re-apply NAT and VPN policies during registration is available, so users do not need to re-apply the polices after registration is completed.
- B. Once a device has been deleted, It must be reconfigured before it is re-added to the Cisco FMC.
- C. Before re-adding the device In Cisco FMC, the manager must be added back.
- D. The Cisco FMC web interface prompts users to re-apply access control policies.
- E. There is no option to re-apply NAT and VPN policies during registration is available, so users need to re-apply the policies after registration is completed.
Answer: D,E
NEW QUESTION # 36
An engineer is setting up a new Firepower deployment and is looking at the default FMC policies to start the implementation During the initial trial phase, the organization wants to test some common Snort rules while still allowing the majority of network traffic to pass Which default policy should be used?
- A. Connectivity Over Security
- B. Security Over Connectivity
- C. Balanced Security and Connectivity
- D. Maximum Detection
Answer: C
Explanation:
https://www.cisco.com/c/en/us/td/docs/security/firepower/623/fdm/fptd-fdm-config-guide-623/fptd-fdm-intrusion.html
NEW QUESTION # 37
Which two deployment types support high availability? (Choose two.)
- A. clustered
- B. virtual appliance in public cloud
- C. routed
- D. intra-chassis multi-instance
- E. transparent
Answer: C,E
Explanation:
Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/610/configuration/guide/fpmc-config-guide-v61/firepower_threat_defense_high_availability.html
NEW QUESTION # 38
In a multi-tennent deployment where multiple domains are in use. which update should be applied outside of the Global Domain?
- A. minor upgrade
- B. local import of major upgrade
- C. local import of intrusion rules
- D. Cisco Geolocation Database
Answer: C
NEW QUESTION # 39
An engineer is attempting to create a new dashboard within the Cisco FMC to have a single view with widgets from many of the other dashboards. The goal is to have a mixture of threat and security related widgets along with Cisco Firepower device health information. Which two widgets must be configured to provide this information? (Choose two.)
- A. Intrusion Events
- B. Current Sessions
- C. Appliance Status
- D. Correlation Information
- E. Network Compliance
Answer: A,C
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-config-guide-v64/ dashboards.html#ID-2206-00000283
NEW QUESTION # 40
Which Cisco Firepower rule action displays an HTTP warning page?
- A. Block
- B. Monitor
- C. Interactive Block
- D. Allow with Warning
Answer: C
Explanation:
Reference: https://www.cisco.com/c/en/us/td/docs/security/firesight/541/user-guide/FireSIGHT-System-UserGuide-v5401/AC-Rules-Tuning-Overview.html#76698
NEW QUESTION # 41
Which command must be run to generate troubleshooting files on an FTD?
- A. system support view-files
- B. system generate-troubleshoot all
- C. sudo sf_troubleshoot.pl
- D. show tech-support
Answer: B
Explanation:
Reference: https://www.cisco.com/c/en/us/support/docs/security/sourcefire-defense-center/117663-technote- SourceFire-00.html
NEW QUESTION # 42
A network engineer is configuring URL Filtering on Cisco FTD. Which two port requirements on the FMC must be validated to allow communication with the cloud service? (Choose two.)
- A. outbound port TCP/80
- B. outbound port TCP/8080
- C. inbound port TCP/443
- D. outbound port TCP/443
- E. inbound port TCP/80
Answer: A,D
Explanation:
Section: Management and Troubleshooting
Explanation/Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide- v60/Security__Internet_Access__and_Communication_Ports.html
NEW QUESTION # 43
An organization has a Cisco FTD that uses bridge groups to pass traffic from the inside interfaces to the outside interfaces. They are unable to gather information about neighbouring Cisco devices or use multicast in their environment. What must be done to resolve this issue?
- A. Change the firewall mode to transparent.
- B. Create a bridge group with the firewall interfaces.
- C. Change the firewall mode to routed.
- D. Create a firewall rule to allow CDP traffic.
Answer: A
Explanation:
"In routed firewall mode, broadcast and multicast traffic is blocked even if you allow it in an access rule..." "The bridge group does not pass CDP packets packets..." https://www.cisco.com/c/en/us/td/docs/security/asa/asa913/configuration/general/asa-913-general-config/intro-fw.html Passing Traffic Not Allowed in Routed Mode In routed mode, some types of traffic cannot pass through the ASA even if you allow it in an access rule. The bridge group, however, can allow almost any traffic through using either an access rule (for IP traffic) or an EtherType rule (for non-IP traffic):
IP traffic-In routed firewall mode, broadcast and "multicast traffic is blocked even if you allow it in an access rule," including unsupported dynamic routing protocols and DHCP (unless you configure DHCP relay). Within a bridge group, you can allow this traffic with an access rule (using an extended ACL).
Non-IP traffic-AppleTalk, IPX, BPDUs, and MPLS, for example, can be configured to go through using an EtherType rule.
Note
"The bridge group does not pass CDP packets packets, or any packets that do not have a valid EtherType greater than or equal to 0x600. An exception is made for BPDUs and IS-IS, which are supported. "
NEW QUESTION # 44
Which two routing options are valid with Cisco Firepower Threat Defense? (Choose two.)
- A. BGPv4 in transparent firewall mode
- B. BGPv4 with nonstop forwarding
- C. ECMP with up to three equal cost paths across multiple interfaces
- D. BGPv6
- E. ECMP with up to three equal cost paths across a single interface
Answer: D,E
Explanation:
Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/601/configuration/guide/fpmc-config-guide-v601/fpmc-config-guide-v60_chapter_01100011.html#ID-2101-0000000e
NEW QUESTION # 45
Which Cisco Advanced Malware Protection for Endpoints policy is used only for monitoring endpoint actively?
- A. protection
- B. audit
- C. triage
- D. Windows domain controller
Answer: B
NEW QUESTION # 46
While configuring FTD, a network engineer wants to ensure that traffic passing through the appliance does not require routing or Vlan rewriting. Which interface mode should the engineer implement to accomplish this task?
- A. transparent
- B. Inline set
- C. passive
- D. Inline tap
Answer: C
NEW QUESTION # 47
Which group within Cisco does the Threat Response team use for threat analysis and research?
- A. OpenDNS Group
- B. Cisco Deep Analytics
- C. Cisco Network Response
- D. Cisco Talos
Answer: D
Explanation:
Reference: https://www.cisco.com/c/en/us/products/security/threat-response.html#~benefits
NEW QUESTION # 48
An organization wants to secure traffic from their branch office to the headquarter building using Cisco Firepower devices, They want to ensure that their Cisco Firepower devices are not wasting resources on inspecting the VPN traffic. What must be done to meet these requirements?
- A. Tune the intrusion policies in order to allow the VPN traffic through without inspection
- B. Enable a flexconfig policy to re-classify VPN traffic so that it no longer appears as interesting traffic
- C. Configure the Cisco Firepower devices to ignore the VPN traffic using prefilter policies
- D. Configure the Cisco Firepower devices to bypass the access control policies for VPN traffic.
Answer: B
NEW QUESTION # 49
An engineer must define a URL object on Cisco FMC. What is the correct method to specify the URL without performing SSL inspection?
- A. Specify all subdomains in the object group.
- B. Specify the protocol in the object.
- C. Use Subject Common Name value.
- D. Include all URLs from CRL Distribution Points.
Answer: A
NEW QUESTION # 50
An engineer is monitoring network traffic from their sales and product development departments, which are on two separate networks What must be configured in order to maintain data privacy for both departments?
- A. Use one pair of inline set in TAP mode for both departments
- B. Use passive IDS ports for both departments
- C. Use 802 1Q mime set Trunk interfaces with VLANs to maintain logical traffic separation
- D. Use a dedicated IPS inline set for each department to maintain traffic separation
Answer: C
NEW QUESTION # 51
A network administrator discovers that a user connected to a file server and downloaded a malware file. The Cisc FMC generated an alert for the malware event, however the user still remained connected. Which Cisco APM file rule action within the Cisco FMC must be set to resolve this issue?
- A. Local Malware Analysis
- B. Malware Cloud Lookup
- C. Reset Connection
- D. Detect Files
Answer: C
NEW QUESTION # 52
Refer to the exhibit. What must be done to fix access to this website while preventing the same communication to all other websites?
- A. Create an intrusion policy rule to have Snort allow port 80 to only 172.1.1.50.
- B. Create an intrusion policy rule to have Snort allow port 443 to only 172.1.1.50.
- C. Create an access control policy rule to allow port 80 to only 172.1.1.50.
- D. Create an access control policy rule to allow port 443 to only 172.1.1.50.
Answer: C
NEW QUESTION # 53
In which two ways do access control policies operate on a Cisco Firepower system? (Choose two.)
- A. They can block traffic based on Security Intelligence data.
- B. Traffic inspection can be interrupted temporarily when configuration changes are deployed.
- C. The system performs a preliminary inspection on trusted traffic to validate that it matches the trusted parameters.
- D. File policies use an associated variable set to perform intrusion prevention.
- E. The system performs intrusion inspection followed by file inspection.
Answer: A,B
Explanation:
Section: Configuration
Explanation/Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide- v60/Access_Control_Using_Intrusion_and_File_Policies.html
NEW QUESTION # 54
An engineer is configuring Cisco FMC and wants to limit the time allowed for processing packets through the interface However if the time is exceeded the configuration must allow packets to bypass detection What must be configured on the Cisco FMC to accomplish this task?
- A. Cisco ISE Security Group Tag
- B. Automatic Application Bypass
- C. Inspect Local Traffic Bypass
- D. Fast-Path Rules Bypass
Answer: B
NEW QUESTION # 55
Which connector is used to integrate Cisco ISE with Cisco FMC for Rapid Threat Containment?
- A. FTD RTC
- B. FMC RTC
- C. ISEGrid
- D. pxGrid
Answer: D
Explanation:
Section: Integration
NEW QUESTION # 56
Network traffic coining from an organization's CEO must never be denied. Which access control policy configuration option should be used if the deployment engineer is not permitted to create a rule to allow all traffic?
- A. Configure a trust policy for the CEO.
- B. Create a NAT policy just for the CEO.
- C. Change the intrusion policy from security to balance.
- D. Configure firewall bypass.
Answer: A
NEW QUESTION # 57
......
Valid 300-710 Test Answers & Cisco 300-710 Exam PDF: https://freetorrent.dumpsmaterials.com/300-710-real-torrent.html
