300-710 Exam Questions
437 real 300-710 exam questions with expert-verified answers and explanations. Page 8 of 9.
- Question #355Deployment
An engineer must change the mode of a Cisco Secure Firewall Threat Defense (FTD) firewall in the Cisco Secure Firewall Management Center (FMC) inventory. The engineer must take the...
FTD managementCLI accessConsole portDevice mode - Question #356Management and Troubleshooting
Refer to the exhibit. An engineer generates troubleshooting files in Cisco Secure Firewall Management Center (FMC). A successfully completed task is removed before the files are do...
FMC TroubleshootingExpert ModeFile ManagementSystem Auditing - Question #357Configuration
An administrator is configuring a new report template off. of a saved search within Cisco Secure Firewall Management Centre. The goal is to use the malware analysis report template...
FMC ReportingSaved SearchesReport TemplatesData Compatibility - Question #358Deployment
An engineer is implementing a new Cisco Secure Firewall. The firewall must filler traffic between the three subnets: - LAN 192.168.101.0/24 - DMZ 192.168.200.0/24 - WAN 10.0.0.0/30...
Firewall ModesRouted ModeCisco Secure FirewallNetwork Segmentation - Question #359Management and Troubleshooting
An engineer must replace a Cisco Secure Firewall high-availability device due to a failure. When the replacement device arrives, the engineer must separate the high-availability pa...
Cisco Secure FirewallHigh Availability (HA)FMC ManagementDevice Replacement - Question #360Configuration
Refer to the exhibit. A Cisco Secure Firewall Threat Defense (FTD) device is deployed in inline mode with an inline set. The network engineer wants router R2 to remove the directly...
FTD Inline ModeLink State PropagationNetwork Resiliency - Question #361Integration
Which component is needed to perform rapid threat containment with Cisco FMC?
Cisco FMCThreat ContainmentCisco ISEIntegration - Question #362Configuration
Which action must be taken to permit communication between a bridge group and routed interface on Cisco Secure Firewall?
Firewall RulesAccess ControlCisco FTDNetwork Security - Question #363Deployment
An engineer is deploying a Cisco ASA Secure Firewall module. The engineer must be able to examine traffic without impacting the network, and the ASA has been deployed with a single...
Cisco ASADeployment ModesTraffic MonitoringTransparent Firewall - Question #364Deployment
An engineer is setting up a new Cisco Secure Firewall Threat Defense appliance to replace the current firewall. The company requests that inline sets be used and that when one inte...
Cisco FTDInline SetsPropagate Link StateHigh Availability - Question #365Configuration
An engineer must implement Cisco Secure Firewall transparent mode due to a new server recently being added that must communicate with an existing server that is currently separated...
Transparent ModeCisco Secure FirewallLayer 2 BridgingBridge Domain - Question #366Configuration
Refer to the exhibit. An engineer is configuring a high-availability solution that has the hardware devices and software versions: - two Cisco Secure Firewall 9300 Security Applian...
High AvailabilityFTD ConfigurationFirewall ClusteringPrerequisites - Question #367Configuration
An engineer is deploying a Cisco Secure Firewall Management Center appliance. The company must send data to Cisco Secure Network Analytics appliances. Which two actions must the en...
NetFlow ConfigurationFMC IntegrationSecure Network AnalyticsFirewall Configuration - Question #368Configuration
A network administrator is trying to configure a previously created file policy on a new access policy. Which action must the administrator take before applying the file policy?
File PolicyAccess Control PolicyCisco FirepowerSecurity Policy Configuration - Question #369Configuration
A security engineer must add a new policy to block UDP traffic to one server. The engineer adds a new object. Which action must the engineer take next to identify all the UDP ports...
Security PolicyFirewall ConfigurationUDP TrafficNetwork Objects - Question #370Configuration
Refer to the exhibit. An engineer is configuring access control rules on a Cisco Secure Firewall Threat Defense device. The access control rules must include a file policy with rul...
Cisco FTDAccess Control PolicyFile PolicySecurity Actions - Question #371Configuration
An engineer must deny ICMP traffic to the networks of separate departments that use Cisco Secure Firewall Management Center. The engineer must use the same object on the relevant d...
FMCNetwork ObjectsObject OverridesPolicy Configuration - Question #372Configuration
Refer to the exhibit. An engineer is deploying a new instance of Cisco Secure Firewall Threat Defense. Which action must the engineer take next so that Client_A and Client_B receiv...
Access Control PolicyDHCP RelayFirewall ConfigurationCisco Secure Firewall Threat Defense - Question #373Configuration
A VPN administrator converted an instance of Cisco Secure Firewall Threat Defense, which is managed by Cisco Secure Firewall Management Center, from using LDAP to LDAPS for remote...
LDAPSVPN AuthenticationCisco FTDCisco FMCCertificates - Question #374Configuration
A network administrator is configuring a transparent Cisco Secure Firewall Threat Defense registered to a Cisco Secure Firewall Management Center. The administrator wants to config...
Cisco FTDTransparent ModeBridge GroupARPDefault Configuration - Question #375Management and Troubleshooting
A network administrator manages a network with multiple firewalls in a data center. The administrator must change a next-generation firewall from routed to transparent mode. Which...
Firewall ModesFTD DeregistrationFMC ManagementRouted vs Transparent Mode - Question #376Configuration
A security engineer sees an alert on Cisco Secure Endpoint console showing a malicious verdict for a file with the SHA-256 hash 0488537078abcdef048853abcdef048853abcdef048853abcdef...
Cisco Secure EndpointThreat MitigationCustom File ListSecurity Policy - Question #377Management and Troubleshooting
An engineer must configure and generate a report in Cisco Secure Firewall Management Center. The report must allow for the addition of headers and footers, and it will contain many...
FMC ReportingReport FormatsHeaders/FootersSecure Firewall Management Center - Question #378Management and Troubleshooting
An engineer must investigate a connectivity issue by using Cisco Secure Firewall Management Center to access the Packet Capture feature on a Cisco Secure Firewall Threat Defense de...
Packet CaptureCisco FTD/FMCSnortTroubleshooting - Question #379Deployment
An engineer is deploying failover capabilities for a pair of Cisco Secure Firewall devices. The core switch keeps the MAC address of the previously active unit in the ARP table. Wh...
FailoverHigh AvailabilityVirtual MACARP - Question #380Deployment
An engineer must deploy a Cisco Secure Firewall Threat Defense instance. The company wants the Secure Firewall Threat Defense deployment to allow business traffic in the event of a...
Cisco Secure Firewall Threat DefenseIPSFail OpenDeployment Modes - Question #381Configuration
Which firewall mode is Cisco Secure Firewall Threat Defense in when two physical interfaces are assigned to a named BVI?
Cisco FTDFirewall ModesTransparent ModeBVI - Question #382Configuration
A network administrator wants to configure a default policy to block malicious sites based on the requested URL lookup. Which feature meets the requirement?
URL FilteringSecurity PoliciesWeb SecurityThreat Prevention - Question #383Configuration
An engineer must implement static route tracking on Cisco Secure Firewall Threat Defense and reroute traffic by using a backup path if the primary path fails. The engineer already...
Static RoutingRoute TrackingFloating Static RoutesCisco Secure Firewall Threat Defense - Question #384Configuration
A network engineer wants to disable the HTTP response page and interactive blocking of the entire access control policy in Cisco Secure Firewall Management Center. What must be sel...
FMC configurationAccess Control PolicyBlocking response pagesSecurity policy settings - Question #385Configuration
An engineer must reconfigure an NTP server on an IPSv device that is managed by using Cisco Secure Firewall Management Center. The engineer verified secure communications between S...
NTP ConfigurationCisco FMCIPSv DevicePlatform Settings Policy - Question #386Configuration
A network administrator is setting up a Cisco Secure Firewall Threat Defense to peer via BGP with two ISPs. The administrator wants traffic to certain IP ranges to prefer to come i...
BGPRouting PolicyRoute MapsTraffic Engineering - Question #387Configuration
A network administrator is configuring an instance of Cisco Secure Firewall Threat Defense, which is registered to Cisco Secure Firewall Management Center, to prevent internal user...
Firewall policiesFile policyAccess control policyCisco Secure Firewall Threat Defense - Question #388Management and Troubleshooting
An engineer must export a packet capture from Cisco Secure Firewall Management Center to assist in troubleshooting an issue on a Secure Firewall Threat Defense device. When the eng...
Packet Capture ExportFMC TroubleshootingPlatform PolicyHTTPS Configuration - Question #389Management and Troubleshooting
Which Cisco Secure Firewall Management Center widget is authorized only for users with administrator access?
Cisco Secure FMCUser Access ControlLicensingDashboard Widgets - Question #390Configuration
Refer to the exhibit. An engineer is troubleshooting connectivity issues over a VPN tunnel. Users from the 192.168.68.0/24 network report that they cannot connect to a remote web s...
VPN ConfigurationIPsecAccess Control ListsFirewall Troubleshooting - Question #391Configuration
Refer to the exhibit. An engineer analyzes a Network Risk Report from Cisco Secure Firewall Management Center. What should the engineer recommend implementing to mitigate the risk?
Risk MitigationThreat IntelligenceFirewall Access ControlCisco FMC - Question #392Configuration
A security engineer is reviewing a Cisco Secure Endpoint public cloud instance. The engineer discovers a malicious verdict for a SHA-256 hash of 689efc1ecdc23ec0b0885a80663e30ea013...
Cisco Secure EndpointCustom DetectionsFile BlockingThreat Mitigation - Question #393Management and Troubleshooting
Refer to the exhibit. A network engineer is analyzing a Network Risk Report generated in Cisco Secure Firewall Management Center that focuses on network security and efficient band...
Network SecurityApplication Control (AVC)Bandwidth ManagementRisk Management - Question #396Configuration
An engineer must configure an inline set on a Cisco Secure IPS by using the Cisco Secure Firewall Management Center. The inline set must make a copy of each packet before analyzing...
Cisco Secure IPSFMCInline SetStrict TCP Enforcement - Question #397Deployment
Refer to the exhibit. An engineer is configuring an instance of Cisco Secure Firewall Threat Defense with a Secure Firewall Threat Defense interface in IPS Inline Pair mode. What m...
Cisco FTDIPS Inline PairInterface ConfigurationLink State Propagation - Question #398Integration
A network engineer must monitor threat events from the console of Cisco Secure Firewall Management Center. The engineer integrates the Cisco Secure Firewall Malware Defense in Secu...
FMC IntegrationSecure EndpointCloud ConnectionMalware Defense - Question #399Integration
An engineer is integrating Cisco Secure Endpoint with Cisco Secure Firewall Management Center in high availability mode. Malware events detected by Secure Endpoint must also be rec...
Secure Endpoint IntegrationFMC Cloud ConnectivityHigh AvailabilityNetwork Configuration - Question #400Management and Troubleshooting
An engineer must perform a packet capture on a Cisco Secure Firewall Threat Defense device to confirm the MAC address of the host using IP address 192.168.100.100 while troubleshoo...
Packet CapturetcpdumpTroubleshootingMAC Addresses - Question #401Configuration
How is IRB on next-generation firewall running in transparent mode supported?
IRBTransparent ModeBVIFirewall Configuration - Question #402Management and Troubleshooting
Refer to the exhibit. A client that has IP address 192.168.67.102 reports issues when connecting to a remote server. Based on the topology and output of packet tracer tool, which a...
TroubleshootingClient ConnectivityPacket TracerApplication Layer Issues - Question #403Configuration
An engineer must configure a remote access VPN on Cisco Secure Firewall Management Center. The engineer created a new remote access VPN policy and updated the access control policy...
Remote Access VPNCisco Secure FirewallFMCVPN Client IP Pool - Question #405Configuration
An engineer must configure a correlation policy in Cisco Secure Firewall Management Center to detect when an IP address from an internal network communicates with a known malicious...
Cisco FMCCorrelation PolicyConnection TrackingExternal Dynamic List - Question #406Integration
An engineer must integrate Cisco Secure Endpoint with Cisco Secure Firewall Management Center. The company deploys Secure Endpoint to the public cloud and plans to use the same pub...
Secure Endpoint IntegrationSecure Firewall Management CenterMalware DefenseCloud Security Integration - Question #407Configuration
Which feature sets up multiple interfaces on a Cisco Secure Firewall Threat Defense to be on the same subnet?
FTD Interface ConfigurationBVILayer 2 Bridging