500-260 Exam Questions
73 real 500-260 exam questions with expert-verified answers and explanations. Page 1 of 2.
- Question #1
An access policy that uses URL reputation values is defined. Which option best describes what happens if a reputation is not available for a URL?
- Question #2
Detection of an exploit kit that is installed on a device is an example of which IoC event category?
- Question #3
A file-type embedded attack is an example of which IoC event category?
- Question #4
Which Cisco SFR feature license is needed to allow a high school security administration to implement a policy to allow student access to only high-reputation websites?
- Question #5
Which Cisco Fire POWER services license must the administrator have to detect and monitor the unauthorized command-and-control network traffic?
- Question #6
Which two Cisco ASA licensing features are correct with Cisco ASA Software Version 8.3 and later? (Choose two.)
- Question #7
Which Cisco ASA CLI command is used to enable HTTPS (Cisco ASDM) access from any inside host on the 10.1.16.0/20 subnet?
- Question #8
Which four unicast or multicast routing protocols are supported by the Cisco ASA appliance? (Choose four.)
- Question #9
Refer to the exhibit. Which Cisco ASA CLI commands configure these static routes in the Cisco ASA routing table?
- Question #10
On the Cisco ASA, tcp-map can be applied to a traffic class using which MPF CLI configuration command?
- Question #11
In one custom dynamic application, the inside client connects to an outside server using TCP port 4444 and negotiates return client traffic in the port range of 5000 to 5500. The s...
- Question #12
Refer to the exhibit. Which traffic is permitted on the inside interface without any interface ACLs configured?
- Question #13
Refer to the exhibit. When the user "contractor" Cisco AnyConnect tunnel is established, what type of Cisco ASA user restrictions are applied to the tunnel?
- Question #14
You are configuring bookmarks for the clientless SSL VPN portal without the use of plug-ins. Which three bookmark types are supported? (Choose three.)
- Question #15
When preconfiguring a Cisco AnyConnect profile for the user group, which file is output by the Cisco AnyConnect profile editor?
- Question #16
Datagram Transport Layer Security (DTLS) was introduced to solve performance issues. Which three are characteristics of DTLS? (Choose three.)
- Question #17
Which three options are characteristics of Web Type ACLs? (Choose three.)
- Question #18
Your IT department needs to run a custom-built TCP application within the clientless SSL VPN tunnel. The network administrator suggests running the smart tunnel application. Which...
- Question #19
When deploying clientless SSL VPN advanced application access, the administrator needs to collect information about the end-user system. Which three input parameters of an end-user...
- Question #20
Which license is required on the Cisco ASA NGFW for an administrator to manage it securely from a remote laptop?
- Question #21
A security administrator suspects that an internal system has been infected by malware and communicates with an external server. Which Cisco ASA NGFW license must the administrator...
- Question #22
In which two ways is the Cisco ASA CWS subscription licensed? (Choose two.)
- Question #26
Which security technique should be implemented to remediate after a threat is discovered?
- Question #27
Which port should be allowed to support communications between Sourcefire User Agent and FireSIGHT Management Center?
- Question #28
Which access policy action should be applied if traffic is to pass without applying any additional inspection?
- Question #29
Which threat score rating is the default value that identifies malware?
- Question #30
What are two benefits that are provided by file trajectory services? (Choose two.)
- Question #31
Refer to the exhibit. Which statement describes the effect of the configuration?
- Question #32
Which option is correct for configuring the SRF for passive, out-of-band traffic evaluation?
- Question #33
An SFR module has been installed in the adaptive security appliance. Which command must be executed on the module to establish connectivity to FireSIGHT Management Center?
- Question #34
Which three policy types are configured using Fire SIGHT Management Center? (Choose three.)
- Question #35
Which application is required to enable Microsoft Active Directory identity integration for FirePOWER services?
- Question #36
Which option best describes the role of an IoC?
- Question #37
Files may be submitted to the cloud-based sandbox for dynamic analysis using which two ports? (Choose two.)
- Question #38
Which two settings are configurable as part of a health policy? (Choose two.)
- Question #39
Which three Fire POWER services features require a subscription license? (Choose three.)
- Question #40
Which impact flag indicates that action is to be taken immediately?
- Question #41
Which three actions are supported by file policies? (Choose three.)
- Question #42
Which statement describes what happens during a file-disposition check for malware?
- Question #43
Which three options are assignable file dispositions? (Choose three.)
- Question #44
On Cisco ASA Software Version 8.3 and later, which two statements correctly describe the NAT table or NAT operations? (Choose two.)
- Question #45
An inside client on the 10.0.0.0/8 network connects to an outside server on the 172.16.0.0/16 network using TCP and the server port of 2001. The inside client negotiates a client p...
- Question #46
When the Cisco ASA appliance is processing packets, which action is performed first?
- Question #47
Refer to the exhibit. Which command enables the stateful failover option?
- Question #48
Which three action ranges are in the NG IPS profile? (Choose three.)
- Question #49
Refer to the exhibit. After a remote user established a Cisco AnyConnect session from a wireless card through the Cisco ASA appliance of a partner to a remote server, the user open...
- Question #50
Refer to the exhibit. A NOC engineer needs to tune some postlogin parameters on an SSL VPN tunnel. From the information shown, where should the engineer navigate to, in order to fi...
- Question #51
The "HTTPS decryption" feature is enabled with the default settings and decryption and IPS policies have been applied to the traffic. Which statement describes what happens when a...
- Question #52
Which three elements are reported in an IPS for NGFW event? (Choose three.)
- Question #53
When establishing a Cisco AnyConnect SSL VPN tunnel, a system administrator wants to restrict remote home office users to either print to their local printer or send the remaining...