لا تريد أن تفوت شيئا؟

نصائح اجتياز امتحان الشهادة

آخر أخبار الامتحانات ومعلومات الخصم

برعاية وحديثة من قبل خبرائنا

نعم، أرسل لي النشرة الإخبارية

خذ اختبارات أخرى عبر الإنترنت

السؤال #1
Topic 1Which interface type allows packets to be dropped?
A. passive
B. inline
C. ERSPAN
D. TAP
عرض الإجابة
اجابة صحيحة: B
السؤال #2
Topic 1Which policy rule is included in the deployment of a local DMZ during the initial deployment of a Cisco NGFW through theCisco FMC GUI?
A. a default DMZ policy for which only a user can change the IP addresses
B. deny ip any
C. no policy rule is included
D. permit ip any
عرض الإجابة
اجابة صحيحة: C
السؤال #3
An engineer defines a new rule while configuring an Access Control Policy. After deploying the policy, the rule is not working as expected and the hit counters associated with the rule are showing zero. What is causing this error?
A. ogging is not enabled for the rule
B. he rule was not enabled after being created
C. he wrong source interface for Snort was selected in the rule
D. n incorrect application signature was used in the rule
عرض الإجابة
اجابة صحيحة: B
السؤال #4
Topic 1Which Cisco Firepower Threat Defense, which two interface settings are required when configuring a routed interface?(Choose two.)
A. Redundant Interface
B. EtherChannel
C. Speed
D. Media Type
E. Duplex
عرض الإجابة
اجابة صحيحة: CE
السؤال #5
Topic 1What are two application layer preprocessors? (Choose two.)
A. CIFS
B. IMAP
C. SSL
D. DNP3
E. ICMP
عرض الإجابة
اجابة صحيحة: BC
السؤال #6
Topic 1Which two dynamic routing protocols are supported in Cisco FTD without using FlexConfig? (Choose two.)
A. EIGRP
B. OSPF
C. static routing
D. IS-IS
E. BGP
عرض الإجابة
اجابة صحيحة: CE
السؤال #7
Topic 1A network engineer is extending a user segment through an FTD device for traffic inspection without creating another IPsubnet. How is this accomplished on an FTD device in routed mode?
A. by assigning an inline set interface
B. by using a BVI and creating a BVI IP address in the same subnet as the user segment
C. by leveraging the ARP to direct traffic through the firewall
D. by bypassing protocol inspection by leveraging pre-filter rules
عرض الإجابة
اجابة صحيحة: A
السؤال #8
Which limitation applies to Cisco Firepower Management Center dashboards in a multidomain environment?
A. Child domains can view but not edit dashboards that originate from an ancestor domain
B. Child domains have access to only a limited set of widgets from ancestor domains
C. Only the administrator of the top ancestor domain can view dashboards
D. Child domains cannot view dashboards that originate from an ancestor domain
عرض الإجابة
اجابة صحيحة: CE
السؤال #9
Topic 1An engineer is implementing Cisco FTD in the network and is determining which Firepower mode to use. The organizationneeds to have multiple virtual Firepower devices working separately inside of the FTD appliance to provide trafficsegmentation. Which deployment mode should be configured in the Cisco Firepower Management Console to support theserequirements?
A. multi-instance
B. multiple deployment
C. single deployment
D. single-context
عرض الإجابة
اجابة صحيحة: A
السؤال #10
A network administrator is reviewing a weekly scheduled attacks risk report and notices a host that is flagged for an impact 2 attack. Where should the administrator look within Cisco FMC to find out more relevant information about this host and attack? The Analysis > Hosts > Vulnerabilities page in Cisco FMC displays information about the hosts on the network and their associated vulnerabilities. The administrator can filter the hosts by impact level, which indicates how likely an attack is to succeed agai
A. nalysis > Lookup > Whols
B. nalysis > Correlation > Correlation Events
C. nalysis > Hosts > Vulnerabilities
D. nalysis > Hosts > Host Attributes
عرض الإجابة
اجابة صحيحة: C
السؤال #11
A network administrator reviews me attack risk report and notices several Low-Impact attacks. What does this type of attack indicate? A low-impact attack indicates that the host is not vulnerable to those attacks.A low-impact attack is an attack that does not exploit any known vulnerability on the target host or does not match any signature or anomaly rule on the FTD device5. A low-impact attack does not mean that the attack is not dangerous to the network or that the host is not within the administrator's
A. ll attacks are listed as low until manually categorized
B. he host is not vulnerable to those attacks
C. he attacks are not dangerous to the network
D. he host is not within the administrator's environment
عرض الإجابة
اجابة صحيحة: B
السؤال #12
Which command is run at the CLI when logged in to an FTD unit, to determine whether the unit is managed locally or by a remote FMC server?
A. system generate-troubleshoot
B. show configuration session
C. show managers
D. show running-config | include manager
عرض الإجابة
اجابة صحيحة: A
السؤال #13
What is the result of specifying of QoS rule that has a rate limit that is greater than the maximum throughput of an interface?
A. The rate-limiting rule is disabled
B. Matching traffic is not rate limited
C. The system rate-limits all traffic
D. The system repeatedly generates warnings
عرض الإجابة
اجابة صحيحة: D
السؤال #14
What is a result of enabling Cisco FTD clustering?
A. For the dynamic routing feature, if the master unit fails, the newly elected master unit maintains all existing connections
B. Integrated Routing and Bridging is supported on the master unit
C. Site-to-site VPN functionality is limited to the master unit, and all VPN connections are dropped if the master unit fails
D. All Firepower appliances can support Cisco FTD clustering
عرض الإجابة
اجابة صحيحة: C
السؤال #15
An engineer plans to reconfigure an existing Cisco FTD from transparent mode to routed mode. Which additional action must be taken to maintain communication Between me two network segments? When reconfiguring an existing Cisco FTD from transparent mode to routed mode, an additional action that must be taken to maintain communication between the two network segments is to update the IP addressing so that each segment is a unique IP subnet. This is because in routed mode, the FTD device acts as a router hop i
A. onfigure a NAT rule so mat traffic between the segments is exempt from NAT
B. pdate the IP addressing so that each segment is a unique IP subnet
C. eploy inbound ACLs on each interface to allow traffic between the segments
D. ssign a unique VLAN ID for the interface in each segment
عرض الإجابة
اجابة صحيحة: B

عرض الإجابات بعد التقديم

يرجى إرسال البريد الإلكتروني الخاص بك والواتس اب للحصول على إجابات الأسئلة.

ملحوظة: يرجى التأكد من صلاحية معرف البريد الإلكتروني وWhatsApp حتى تتمكن من الحصول على نتائج الاختبار الصحيحة.

بريد إلكتروني:
رقم الواتس اب/الهاتف: