لا تريد أن تفوت شيئا؟

نصائح اجتياز امتحان الشهادة

آخر أخبار الامتحانات ومعلومات الخصم

برعاية وحديثة من قبل خبرائنا

نعم، أرسل لي النشرة الإخبارية

خذ اختبارات أخرى عبر الإنترنت

السؤال #1
An engineer is implementing a new Cisco Secure Firewall. The firewall must filter traffic between the three subnets:· LAN 192.168.101.0/24· DMZ 192.168.200.0/24· WAN 10.0.0.0/30Which firewall mode must the engineer implement?
A. network
B. routed
C. gateway
D. transparent
عرض الإجابة
اجابة صحيحة: B

View The Updated 300-710 Exam Questions

SPOTO Provides 100% Real 300-710 Exam Questions for You to Pass Your 300-710 Exam!

السؤال #2
A network administrator must create an EtherChannel interface on a Cisco Secure Firewall Threat Defense 9300 appliance registered with Cisco Secure Firewall Management Center for High Availability.Where must the administrator create the EtherChannel interface?
A. Cisco Secure Firewall Management Center GUI
B. Cisco Secure Firewall Management Center CLI
C. Cisco Secure Firewall Threat Defense CLI
D. Firepower eXtensible Operating System (FXOS) CLI
عرض الإجابة
اجابة صحيحة: D
السؤال #3
An engineer is configuring two new Cisco FTD devices to replace the existing high availability firewall pair in a highly secure environment. The information exchanged between the FTD devices over the failover link must be encrypted.Which protocol supports this on the Cisco FTD?
A. MACsec
B. IPsec
C. SSH
D. SSL
عرض الإجابة
اجابة صحيحة: B
السؤال #4
Which protocol is needed to exchange threat details in rapid threat containment on Cisco FMC?
A. SGT
B. SNMP v3
C. BFD
D. pxGrid
عرض الإجابة
اجابة صحيحة: D
السؤال #5
Which two TCP ports can allow the Cisco Firepower Management Center to communication with FireAMP cloud for file disposition information? (Choose two.)
A. 8080
B. 22
C. 8305
D. 32137
E. 443
عرض الإجابة
اجابة صحيحة: DE
السؤال #6
A network engineer is planning on deploying a Cisco Secure Firewall Threat Defense Virtual appliance in transparent mode.Which two virtual environments support this configuration? (Choose two.)
A. OSI
B. AWS
C. GCP
D. KVM
E. ESXi
عرض الإجابة
اجابة صحيحة: DE
السؤال #7
With Cisco FTD software, which interface mode must be configured to passively receive traffic that passes through the appliance?
A. nline set
B. assive
C. outed
D. nline tap
عرض الإجابة
اجابة صحيحة: D
السؤال #8
An engineer is setting up a new Firepower deployment and is looking at the default FMC policies to start the implementation. During the initial trial phase, the organization wants to test some common Snort rules while still allowing the majority of network traffic to pass.Which default policy should be used?
A. Balanced Security and Connectivity
B. Security Over Connectivity
C. Maximum Detection
D. Connectivity Over Security
عرض الإجابة
اجابة صحيحة: D
السؤال #9
A network engineer is planning on deploying a Cisco Secure Firewall Threat Defense Virtual appliance in transparent mode.Which two virtual environments support this configuration? (Choose two.)
A. OSI
B. AWS
C. GCP
D. KVM
E. ESXi
عرض الإجابة
اجابة صحيحة: DE
السؤال #10
Which command must be run to generate troubleshooting files on an FTD?
A. Asystem support view-files
B. Bsudo sf_troubleshoot
C. Csystem generate-troubleshoot all
D. Dshow tech-support
عرض الإجابة
اجابة صحيحة: C
السؤال #11
Which Cisco Firepower Threat Defense, which two interface settings are required when configuring a routed interface? (Choose two.)
A. edundant Interface
B. therChannel
C. peed
D. edia Type
E. uplex
عرض الإجابة
اجابة صحيحة: CE
السؤال #12
An organization has noticed that malware was downloaded from a website that does not currently have a known bad reputation. How will this issue be addressed globally in the quickest way possible and with the least amount of impact?
A. by creating a URL object in the policy to block the website
B. Cisco Talos will automatically update the policies
C. by denying outbound web access
D. by isolating the endpoint
عرض الإجابة
اجابة صحيحة: A
السؤال #13
Which interface type allows packets to be dropped?
A. assive
B. nline
C. RSPAN
D. AP
عرض الإجابة
اجابة صحيحة: B
السؤال #14
Network traffic coming from an organization's CEO must never be denied.Which access control policy configuration option should be used if the deployment engineer is not permitted to create a rule to allow all traffic?
A. Change the intrusion policy from security to balance
B. Configure a trust policy for the CEO
C. Configure firewall bypass
D. Create a NAT policy just for the CEO
عرض الإجابة
اجابة صحيحة: B
السؤال #15
An engineer is configuring a new dashboard within Cisco Secure Firewall Management Center and is having trouble implementing a custom widget. When a custom analysis widget is configured which option is mandatory for the system to display the information?
A. table
B. filter
C. title
D. results
E. Reveal Answer
عرض الإجابة
اجابة صحيحة: C
السؤال #16
An organization has a Cisco FTD that uses bridge groups to pass traffic from the inside interfaces to the outside interfaces. The organization is unable to gather information about neighboring Cisco devices or use multicast in their environment.What must be done to resolve this issue?
A. Create a firewall rule to allow CDP traffic
B. Create a bridge group with the firewall interfaces
C. Change the firewall mode to transparent
D. Change the firewall mode to routed
عرض الإجابة
اجابة صحيحة: C
السؤال #17
What are two features of bridge-group interfaces in Cisco FTD? (Choose two.)
A. he BVI IP address must be in a separate subnet from the connected network
B. ridge groups are supported in both transparent and routed firewall modes
C. ridge groups are supported only in transparent firewall mode
D. idirectional Forwarding Detection echo packets are allowed through the FTD when using bridge-group members
E. ach directly connected network must be on the same subnet
عرض الإجابة
اجابة صحيحة: BE
السؤال #18
An administrator is attempting to add a Cisco Secure Firewall Threat Defence device to Cisco Secure Firewall Management Center with a password of Cisco0480846211 480846211. The private IP address of the FMC server is 192.168.75.201. Which command must be used in order to accomplish this task?
A. configure manager add 192
B. configure manager add 192
C. configure manager add 192
D. configure manager add 192
E. Reveal Answer
عرض الإجابة
اجابة صحيحة: B
السؤال #19
An engineer is monitoring network traffic from their sales and product development departments, which are on two separate networks.What must be configured in order to maintain data privacy for both departments?
A. Use passive IDS ports for both departments
B. Use a dedicated IPS inline set for each department to maintain traffic separation
C. Use 802
D. Use one pair of inline set in TAP mode for both departments
عرض الإجابة
اجابة صحيحة: C
السؤال #20
An organization has implemented Cisco Firepower without IPS capabilities and now wants to enable inspection for their traffic. They need to be able to detect protocol anomalies and utilize the Snort rule sets to detect malicious behavior. How is this accomplished?
A. Modify the network discovery policy to detect new hosts to inspect
B. Modify the access control policy to redirect interesting traffic to the engine
C. Modify the intrusion policy to determine the minimum severity of an event to inspect
D. Modify the network analysis policy to process the packets for inspection
عرض الإجابة
اجابة صحيحة: B
السؤال #21
What is a characteristic of bridge groups on a Cisco FTD?
A. In routed firewall mode, routing between bridge groups must pass through a routed interface
B. In routed firewall mode, routing between bridge groups is supported
C. In transparent firewall mode, routing between bridge groups is supported
D. Routing between bridge groups is achieved only with a router-on-a-stick configuration on a connected router
E. Reveal Answer
عرض الإجابة
اجابة صحيحة: B
السؤال #22
An engineer is configuring a Cisco FTD appliance in IPS-only mode and needs to utilize fail-to-wire interfaces.Which interface mode should be used to meet these requirements?
A. passive
B. routed
C. transparent
D. inline set
عرض الإجابة
اجابة صحيحة: D
السؤال #23
A network administrator is setting up a new highly available Cisco Secure Firewall Threat Defense (FTD) pair. The administrator wants to monitor that the interfaces on the secondary Secure FTD are reachable not just up.What must the administrator configure?
A. This happens by default when high availability is enabled
B. secondary IP address
C. EUI 64 address on a high-availability link
D. separate high-availability and failover links
عرض الإجابة
اجابة صحيحة: B
السؤال #24
An engineer is tasked with deploying an internal perimeter firewall that will support multiple DMZs. Each DMZ has a unique private IP subnet range. How is this requirement satisfied?
A. eploy the firewall in transparent mode with access control policies
B. eploy the firewall in routed mode with access control policies
C. eploy the firewall in routed mode with NAT configured
D. eploy the firewall in transparent mode with NAT configured
عرض الإجابة
اجابة صحيحة: B
السؤال #25
Which two dynamic routing protocols are supported in Firepower Threat Defense without usingFlexConfig? (Choose two.)
A. IGRP
B. SPF
C. tatic routing
D. S-IS
E. GP
عرض الإجابة
اجابة صحيحة: BE
السؤال #26
A network engineer is planning on replacing an Active/Standby pair of physical Cisco Secure Firewall ASAs with a pair of Cisco Secure Firewall Threat Defense Virtual appliances.Which two virtual environments support the current High Availability configuration? (Choose two.)
A. ESXi
B. Azure
C. Openstack
D. KVM
E. AWS
عرض الإجابة
اجابة صحيحة: AD
السؤال #27
With Cisco FTD software, which interface mode must be configured to passively receive traffic that passes through the appliance?
A. inline set
B. passive
C. routed
D. inline tap
عرض الإجابة
اجابة صحيحة: D
السؤال #28
A network engineer implements a new Cisco Firepower device on the network to take advantage of its intrusion detection functionality. There is a requirement to analyze the traffic going across the device, alert on any malicious traffic, and appear as a bump in the wire. How should this be implemented?
A. Specify the BVI IP address as the default gateway for connected devices
B. Enable routing on the Cisco Firepower
C. Add an IP address to the physical Cisco Firepower interfaces
D. Configure a bridge group in transparent mode
عرض الإجابة
اجابة صحيحة: D
السؤال #29
Which interface type allows packets to be dropped?
A. passive
B. inline
C. ERSPAN
D. TAP
عرض الإجابة
اجابة صحيحة: B
السؤال #30
While integrating Cisco Umbrella with Cisco Threat Response, a network security engineer wants to automatically push blocking of domains from the Cisco Threat Response interface to Cisco Umbrella. Which API meets this requirement?
A. investigate
B. reporting
C. enforcement
D. REST
E. Reveal Answer
عرض الإجابة
اجابة صحيحة: D
السؤال #31
An engineer is building a new access control policy using Cisco FMC. The policy must inspect aunique IPS policy as well as log rule matching. Which action must be taken to meet theserequirements?
A. onfigure an IPS policy and enable per-rule logging
B. isable the default IPS policy and enable global logging
C. onfigure an IPS policy and enable global logging
D. isable the default IPS policy and enable per-rule logging
عرض الإجابة
اجابة صحيحة: C
السؤال #32
A network engineer is extending a user segment through an FTD device for traffic inspection without creating another IP subnet. How is this accomplished on an FTD device in routed mode?
A. by assigning an inline set interface
B. by using a BVI and creating a BVI IP address in the same subnet as the user segment
C. by leveraging the ARP to direct traffic through the firewall
D. by bypassing protocol inspection by leveraging pre-filter rules
عرض الإجابة
اجابة صحيحة: B
السؤال #33
Which two conditions must be met to enable high availability between two Cisco FTD devices? (Choose two.)
A. same flash memory size
B. same NTP configuration
C. same DHCP/PPoE configuration
D. same host name
E. same number of interfaces
عرض الإجابة
اجابة صحيحة: BE
السؤال #34
Which group within Cisco does the Threat Response team use for threat analysis and research?
A. Cisco Deep Analytics
B. OpenDNS Group
C. Cisco Network Response
D. Cisco Talos
عرض الإجابة
اجابة صحيحة: D
السؤال #35
An engineer is implementing a new Cisco Secure Firewall. The firewall must filter traffic between the three subnets:· LAN 192.168.101.0/24· DMZ 192.168.200.0/24· WAN 10.0.0.0/30Which firewall mode must the engineer implement?
A. network
B. routed
C. gateway
D. transparent
عرض الإجابة
اجابة صحيحة: B
السؤال #36
Which action must be taken to permit communication between a bridge group and routed interface on Cisco Secure Firewall?
A. nable split tunneling
B. efine a source NAT address
C. reate an access rule to allow the traffic
D. reate an ACL for the bridge group
عرض الإجابة
اجابة صحيحة: C
السؤال #37
A company is deploying a Cisco Secure IPS device configured in inline mode with a single Interface set that contains four interface pairs.Which two configurations must be implemented to allow the IPS device to uniquely identify packet flows and prevent the reporting of duplicate traffic and false positives? (Choose two.)
A. Set the source SPAN ports to tx only on the switches connected to the IPS interfaces
B. Modify the security zones used by the Cisco Secure IPS device
C. Change the MTU for the inline set to at least 1518
D. Reconfigure access rules to drop all but the first occurrence of the packet
E. Reassign the interface pairs to separate inline sets
عرض الإجابة
اجابة صحيحة: BE
السؤال #38
A network administrator is setting up a new highly available Cisco Secure Firewall Threat Defense (FTD) pair. The administrator wants to monitor that the interfaces on the secondary Secure FTD are reachable not just up.What must the administrator configure?
A. This happens by default when high availability is enabled
B. secondary IP address
C. EUI 64 address on a high-availability link
D. separate high-availability and failover links
عرض الإجابة
اجابة صحيحة: B
السؤال #39
While configuring FTD, a network engineer wants to ensure that traffic passing though the appliance does not require routing or VLAN rewriting.Which interface mode should the engineer implement to accomplish this task?
A. inline set
B. passive
C. transparent
D. inline tap
عرض الإجابة
اجابة صحيحة: A
السؤال #40
Which two actions can be used in an access control policy rule? (Choose two.)
A. lock with Reset
B. onitor
C. nalyze
D. iscover
E. lock ALL
عرض الإجابة
اجابة صحيحة: AB
السؤال #41
Which policy rule is included in the deployment of a local DMZ during the initial deployment of aCisco NGFW through the Cisco FMC GUI?
A. default DMZ policy for which only a user can change the IP addresses
B. eny ip any
C. o policy rule is included
D. ermit ip any
عرض الإجابة
اجابة صحيحة: C
السؤال #42
A network engineer implements a new Cisco Firepower device on the network to take advantage of its intrusion detection functionality. There is a requirement to analyze the traffic going across the device, alert on any malicious traffic, and appear as a bump in the wire. How should this be implemented?
A. pecify the BVI IP address as the default gateway for connected devices
B. nable routing on the Cisco Firepower
C. dd an IP address to the physical Cisco Firepower interfaces
D. onfigure a bridge group in transparent mode
عرض الإجابة
اجابة صحيحة: D
السؤال #43
What is a result of enabling Cisco FTD clustering?
A. For the dynamic routing feature, if the master unit fails, the newly elected master unit maintains all existing connections
B. Integrated Routing and Bridging is supported on the master unit
C. Site-to-site VPN functionality is limited to the master unit, and all VPN connections are dropped if the master unit fails
D. All Firepower appliances support Cisco FTD clustering
عرض الإجابة
اجابة صحيحة: C
السؤال #44
When creating a report template, how are the results limited to show only the activity of a specific subnet?
A. reate a custom search in Cisco FMC and select it in each section of the report
B. dd an Input Parameter in the Advanced Settings of the report, and set the type to Network/IP
C. dd a Table View section to the report with the Search field defined as the network in CIDR format
D. elect IP Address as the X-Axis in each section of the report
عرض الإجابة
اجابة صحيحة: B
السؤال #45
An engineer installs a Cisco FTD device and wants to inspect traffic within the same subnet passing through a firewall and inspect traffic destined to the Internet.Which configuration will meet this requirement?
A. transparent firewall mode with IRB only
B. routed firewall mode with BVI and routed interfaces
C. transparent firewall mode with multiple BVIs
D. routed firewall mode with routed interfaces only
عرض الإجابة
اجابة صحيحة: C
السؤال #46
An engineer is implementing a new Cisco Secure Firewall. The firewall must filler traffic between the three subnets:- LAN 192.168.101.0/24- DMZ 192.168.200.0/24- WAN 10.0.0.0/30Which firewall mode must the engineer implement?
A. etwork
B. ransparent
C. ateway
D. outed
عرض الإجابة
اجابة صحيحة: D
السؤال #47
An engineer is tasked with deploying an internal perimeter firewall that will support multiple DMZsEach DMZ has a unique private IP subnet range. How is this requirement satisfied?
A. eploy the firewall in transparent mode with access control policies
B. eploy the firewall in routed mode with access control policies
C. eploy the firewall in routed mode with NAT configured
D. eploy the firewall in transparent mode with NAT configured
عرض الإجابة
اجابة صحيحة: C
السؤال #48
An administrator configures the interfaces of a Cisco Secure Firewall Threat Defense device in an inline IPS deployment. The administrator completes these actions:· identifies the device and the interfaces· sets the interface mode to inline· enables the interfacesWhich configuration step must the administrator take next to complete the implementation?
A. Set the interface to routed mode
B. Enable spanning-tree PortFast on the interfaces
C. Configure an inline set
D. Set the interface to transparent mode
عرض الإجابة
اجابة صحيحة: C
السؤال #49
What is a limitation to consider when running a dynamic routing protocol on a Cisco Secure Firewall Threat Defense device in IRB mode?
A. Only link-state routing protocols are supported
B. Only nonbridge interfaces are supported
C. Only EtherChannel interfaces are supported
D. Only distance vector routing protocols are supported
عرض الإجابة
اجابة صحيحة: B
السؤال #50
What are two application layer preprocessors? (Choose two.)
A. IFS
B. MAP
C. SL
D. NP3
E. CMP
عرض الإجابة
اجابة صحيحة: BC
السؤال #51
A Cisco FTD device is running in transparent firewall mode with a VTEP bridge group member ingress interface.What must be considered by an engineer tasked with specifying a destination MAC address for a packet trace?
A. The output format option for the packet logs is unavailable
B. Only the UDP packet type is supported
C. The destination MAC address is optional if a VLAN ID value is entered
D. The VLAN ID and destination MAC address are optional
عرض الإجابة
اجابة صحيحة: C
السؤال #52
What is the difference between inline and inline tap on Cisco Firepower?
A. Inline tap mode can send a copy of the traffic to another device
B. Inline tap mode does full packet capture
C. Inline mode cannot do SSL decryption
D. Inline mode can drop malicious traffic
عرض الإجابة
اجابة صحيحة: A
السؤال #53
An administrator configures the interfaces of a Cisco Secure Firewall Threat Defense device in an inline IPS deployment. The administrator completes these actions:· identifies the device and the interfaces· sets the interface mode to inline· enables the interfacesWhich configuration step must the administrator take next to complete the implementation?
A. Set the interface to routed mode
B. Enable spanning-tree PortFast on the interfaces
C. Configure an inline set
D. Set the interface to transparent mode
عرض الإجابة
اجابة صحيحة: C
السؤال #54
A network administrator is trying to configure a previously created file policy on a new access policy. Which action must the administrator take before applying the file policy?
A. Set up an inspection policy
B. Create a new access control rule
C. Assign the file policy to the default action
D. Apply an application to an access control rule
عرض الإجابة
اجابة صحيحة: B
السؤال #55
An organization is migrating their Cisco ASA devices running in multicontext mode to Cisco FTD devices.Which action must be taken to ensure that each context on the Cisco ASA is logically separated in the Cisco FTD devices?
A. Configure a container instance in the Cisco FTD for each context in the Cisco AS
B. Add the Cisco FTD device to the Cisco ASA port channels
C. Configure the Cisco FTD to use port channels spanning multiple networks
D. Add a native instance to distribute traffic to each Cisco FTD context
عرض الإجابة
اجابة صحيحة: A
السؤال #56
Which interface type allows packets to be dropped?
A. passive
B. inline
C. ERSPAN
D. TAP
عرض الإجابة
اجابة صحيحة: B
السؤال #57
Which two deployment types support high availability? (Choose two.)
A. ransparent
B. outed
C. lustered
D. ntra-chassis multi-instance
E. irtual appliance in public cloud
عرض الإجابة
اجابة صحيحة: AB
السؤال #58
What is the difference between inline and inline tap on Cisco Firepower?
A. Inline tap mode can send a copy of the traffic to another device
B. Inline tap mode does full packet capture
C. Inline mode cannot do SSL decryption
D. Inline mode can drop malicious traffic
عرض الإجابة
اجابة صحيحة: D
السؤال #59
An administrator is configuring the interface of a Cisco Secure Firewall Threat Defense firewall device in a passive IPS deployment. The device and interface have been identified.Which set of configuration steps must the administrator perform next to complete the implementation?
A. Set the interface mode to passive
B. Modify the interface to retransmit received traffic
C. Set the interface mode to passive
D. Modify the interface to retransmit received traffic
عرض الإجابة
اجابة صحيحة: A

عرض الإجابات بعد التقديم

يرجى إرسال البريد الإلكتروني الخاص بك والواتس اب للحصول على إجابات الأسئلة.

ملحوظة: يرجى التأكد من صلاحية معرف البريد الإلكتروني وWhatsApp حتى تتمكن من الحصول على نتائج الاختبار الصحيحة.

بريد إلكتروني:
رقم الواتس اب/الهاتف:
Contact Us