300-710 Exam Questions
437 real 300-710 exam questions with expert-verified answers and explanations. Page 7 of 9.
- Question #305Configuration
A company is deploying AMP private cloud. The AMP private cloud instance has already been deployed by the server administrator. The server administrator provided the hostname of th...
AMP Private CloudFMC IntegrationSSL CertificatesSecure Connection - Question #306Configuration
A security engineer is deploying Cisco Secure Endpoint to detect a zero day malware attack with an SHA-256 hash of 47ea931f3e9dc23ec0b0885a80663e30ea013d493f8e88224b570a0464084628....
Cisco Secure EndpointMalware detectionZero-day threatCustom detections - Question #307Configuration
A security engineer must create a malware and file policy on a Cisco Secure Firewall Threat Defense device. The solution must ensure that PDF, DOCX, and XLSX files are not sent to...
Cisco FTDMalware PolicyLocal AnalysisFile Type Control - Question #308Configuration
Encrypted Visibility Engine (EVE) is enabled under which tab on an access control policy in Cisco Secure Firewall Management Center?
EVEFMCAccess Control PolicyGUI - Question #309Configuration
An engineer is configuring a Cisco Secure Firewall Threat Defense device managed by Cisco Secure Firewall Management Center. The device must have SSH enabled and be accessible from...
FTD SSH configurationFMC Platform SettingsRemote administrationFirewall management - Question #310Configuration
What is the result when two users modify a VPN policy at the same time on a Cisco Secure Firewall Management Center managed device?
Cisco FMCConcurrent AdministrationPolicy ManagementConfiguration Behavior - Question #311Configuration
A network administrator is configuring a BVI interface on a routed FTD. The administrator wants to isolate traffic on the interfaces connected to the bridge group and not have the...
FTD BridgingBVIVRFNetwork Isolation - Question #312Management and Troubleshooting
Which file format can standard reports from Cisco Secure Firewall Management Center be downloaded in?
FMC ReportingReport Export FormatsData Export - Question #313Configuration
Remote users who connect via Cisco Secure Client to the corporate network behind a Cisco Secure Firewall Threat Defense device are reporting no audio on calls when calling between...
Cisco FTDRemote Access VPNNAT PoliciesHairpinning - Question #314Configuration
An administrator is configuring the interface of a Cisco Secure Firewall Threat Defense firewall device in a passive IPS deployment. The device and interface have been identified....
Passive IPSFTD Interface ConfigurationSecurity ZonesIPS Policy - Question #315Deployment
Which two statements are valid regarding the licensing model used on Cisco Secure Firewall Threat Defense Virtual appliances? (Choose two.)
Licensing ModelFTD VirtualSmart LicensingCloud Platforms - Question #316Configuration
A company is deploying Cisco Secure Firewall Threat Defense with IPS. What must be implemented in inline mode to pass the traffic without inspection during spikes and ensure that n...
FTD IPSSnort FailsafeInline modeTraffic handling - Question #317Configuration
A Cisco Secure Firewall Threat Defense device is configured in inline IPS mode to inspect all traffic that passes through the interfaces in the inline set. Which setting in the inl...
Cisco FTDInline IPSFail-OpenVDB Updates - Question #318Integration
Which two features can be used with Cisco Secure Firewall Threat Defense remote access VPN? (Choose two.)
Remote Access VPNDuo MFACisco ISE IntegrationRapid Threat Containment - Question #319Configuration
Which rule action is only available in Snort 3?
Snort 3Rule actionsIPS configurationPacket manipulation - Question #320Configuration
A company is deploying a Cisco Secure IPS device configured in inline mode with a single Interface set that contains four interface pairs. Which two configurations must be implemen...
Cisco Secure IPSInline ModeInterface SetsSecurity ZonesFlow Identification - Question #321Integration
Cisco SecureX is classified as which type of threat detection and response solution?
Cisco SecureXXDRThreat DetectionSecurity Solutions - Question #322Management and Troubleshooting
An administrator configures new threat intelligence sources and must validate that the feeds are being downloaded and that the intelligence is being used within the Cisco Secure Fi...
Threat IntelligenceFMCMonitoringValidation - Question #323Configuration
Cisco Security Analytics and Logging SaaS licenses come with how many days of data retention by default?
Cisco Security Analytics and LoggingCSALData RetentionLicensing - Question #324Management and Troubleshooting
An external vendor is reporting that they are unable to access an ordering website hosted behind a Cisco Secure Firewall Threat Defense device. The administrator of the device want...
FTD TroubleshootingFMC ToolsPacket TracerPacket Capture - Question #325Configuration
An organization created a custom application that is being flagged by Cisco Secure Endpoint. The application must be exempt from being flagged. What is the process to meet the requ...
Cisco Secure EndpointWhitelistingApplication ExemptionFile Hashing - Question #326Configuration
An engineer is configuring a new dashboard within Cisco Secure Firewall Management Center and is having trouble implementing a custom widget. When a custom analysis widget is confi...
FMC DashboardCustom WidgetsAnalysis Widget ConfigurationFMC UI - Question #327Deployment
A network engineer is planning on deploying a Cisco Secure Firewall Threat Defense Virtual appliance in transparent mode. Which two virtual environments support this configuration?...
FTDv deploymentVirtualization platformsTransparent modeHypervisor compatibility - Question #328Configuration
An engineer is configuring a Cisco Secure Firewall Threat Defense device and wants to create a new intrusion rule based on the detection of a specific pattern in the data payload f...
Intrusion RulesSNORT RulesFirepower Threat DefenseRule Syntax - Question #329Integration
What is the role of realms in the Cisco ISE and Cisco Secure Firewall Management Center integration?
Cisco ISESecure FirewallIntegrationIdentity Management - Question #330Configuration
A network engineer must configure IPS mode on a Secure Firewall Threat Defense device to inspect traffic and act as an IDS. The engineer already configured the passive-interface on...
IPS/IDSCisco FTDIntrusion PolicyNetwork Security - Question #331Configuration
A software development company hosts the website https://dev.company.com for contractors to share code for projects they are working on with internal developers. The web server is...
Cisco Secure Firewall Threat DefenseMalware DefenseFile PolicyAccess Control Policy - Question #332Configuration
A network engineer must configure an existing firewall to have a NAT configuration. The new configuration must support more than two interfaces per context. The firewall has previo...
FTD ModesRouted ModeNAT ConfigurationFMC Registration - Question #333Integration
A security engineer manages a firewall console and an endpoint console and finds it challenging and time consuming to review events and modify blocking of specific files in both co...
Cisco Secure FMCCisco Secure EndpointIntegrationCentralized Management - Question #334Configuration
An engineer must create an access control policy on a Cisco Secure Firewall Threat Defense device. The company has a contact center that utilizes VoIP heavily, and it is critical t...
Firewall Access Control PolicyCisco FTDVoIP PerformanceTrust Rule Action - Question #335Configuration
An engineer must permit SSH on the inside interface of a Cisco Secure Firewall Threat Defense device. SSH is currently permitted only on the management interface. Which type of pol...
Cisco FTDPlatform policyDevice accessSSH configuration - Question #336Management and Troubleshooting
When packet capture is used on a Cisco Secure Firewall Threat Defense device and the packet flow is waiting on the malware query, which Snort verdict appears?
Cisco FTDSnort VerdictsMalware InspectionPacket Capture - Question #337Management and Troubleshooting
A network administrator is deploying a new Cisco Secure Firewall Threat Defense (FTD) firewall. After Cisco Secure FTD is deployed, inside clients have intermittent connectivity to...
Proxy ARPNATTroubleshootingCisco FTD - Question #338Management and Troubleshooting
An administrator receives reports that users cannot access a cloud-hosted web server. The access control policy was recently updated with several new policy additions and URL filte...
TroubleshootingAccess Control PolicyURL FilteringConnection Events - Question #339Configuration
A network administrator wants to configure a Cisco Secure Firewall Threat Defense instance managed by Cisco Secure Firewall Management Center to block traffic to known cryptomining...
Firewall Management CenterAccess PolicySecurity IntelligenceThreat Blocking - Question #340Management and Troubleshooting
A network engineer detects a connectivity issue between Cisco Secure Firewall Management Center and Cisco Secure Firewall Threat Defense. Initial troubleshooting indicates that hea...
FMC-FTD CommunicationSecure Channel TroubleshootingProcess ManagementCLI Utilities - Question #341Management and Troubleshooting
A network administrator is reviewing a packet capture. The packet capture from inside of Cisco Secure Firewall Threat Defense shows the inbound TCP traffic. However, the outbound T...
Firewall TroubleshootingRoutingPacket Capture AnalysisNetwork Flow - Question #342Management and Troubleshooting
An engineer is troubleshooting an intermittent connectivity issue on a Cisco Secure Firewall Threat Defense appliance and must collect 24 hours' worth of data. The engineer started...
Packet CaptureTroubleshootingCisco FTDBuffer Limits - Question #343Configuration
A network administrator is setting up a new highly available Cisco Secure Firewall Threat Defense (FTD) pair. The administrator wants to monitor that the interfaces on the secondar...
FTD High AvailabilityInterface ConfigurationReachability MonitoringSecondary IP Address - Question #344Management and Troubleshooting
An administrator must fix a network problem whereby traffic from the inside network to a webserver is not getting through an instance of Cisco Secure Firewall Threat Defense. Which...
Packet CaptureTroubleshootingCisco Secure Firewall Threat DefenseASP Drop - Question #345Management and Troubleshooting
Users report that Cisco Duo 2FA fails when they attempt to connect to the VPN on a Cisco Secure Firewall Threat Defense (FTD) device. IT staff have VPN profiles that do not require...
Cisco DuoMFAVPNCertificates - Question #346Management and Troubleshooting
Refer to the exhibit. A security engineer must improve security in an organization and is producing a risk mitigation strategy to present to management for approval. Which action m...
Risk MitigationDNS SecurityNetwork Threat Analysis - Question #347Configuration
An engineer is tasked with configuring a custom intrusion rule on Cisco Secure Firewall Management Center to detect and block the malicious traffic pattern with specific payload co...
IPS Policy ConfigurationCustom Intrusion RulesTraffic BlockingCisco Secure Firewall FMC - Question #348Configuration
A network administrator is trying to configure Active Directory authentication for VPN authentication to a Cisco Secure Firewall Threat Defence instance that is registered with Cis...
Cisco Secure Firewall FMCActive Directory authenticationVPN authenticationRealms - Question #349Configuration
A network administrator is trying to configure an access rule to allow access to a specific banking site over HTTPS. Which method must the administrator use to meet the requirement...
SSL DecryptionHTTPS FilteringAccess RulesURL Filtering - Question #350Integration
Which component simplifies incident investigation with Cisco Threat Response?
Cisco Threat ResponseIncident InvestigationBrowser ExtensionSecurity Operations - Question #351Deployment
Refer to the exhibit. A company is deploying a pair of Cisco Secure Firewall Threat Defense devices named FTD1 and FTD2. FTD1 and FTD2 have been configured as an active/standby pai...
Cisco Secure Firewall Threat Defense (FTD)High Availability (HA)Active/Standby FailoverStateful Link - Question #352Deployment
An administrator is attempting to add a Cisco Secure Firewall Threat Defence device to Cisco Secure Firewall Management Center with a password of Cisco0480846211 480846211. The pri...
Cisco Secure Firewall Threat Defense (FTD)Cisco Secure Firewall Management Center (FMC)Device RegistrationCommand Syntax - Question #353Integration
A company is deploying Cisco Secure Endpoint private cloud. The Secure Endpoint private cloud instance has already been deployed by the server administrator. The server administrat...
FMC IntegrationSecure Endpoint Private CloudSSL CertificatesSecure Integration - Question #354Management and Troubleshooting
Network users experience issues when accessing a server on a different network segment. An engineer investigates the issue by performing packet capture on Cisco Secure Firewall Thr...
Packet CaptureTroubleshootingCisco Secure Firewall Threat DefenseMemory Management