Verified 300-710 Exam Dumps Q&As - Provide 300-710 with Correct Answers
Pass Your 300-710 Dumps Free Latest Cisco Practice Tests
NEW QUESTION # 93
Which group within Cisco does the Threat Response team use for threat analysis and research?
- A. Cisco Deep Analytics
- B. Cisco Talos
- C. OpenDNS Group
- D. Cisco Network Response
Answer: B
Explanation:
Reference:
https://www.cisco.com/c/en/us/products/security/threat-response.html#~benefits
NEW QUESTION # 94
Which command is run at the CLI when logged in to an FTD unit, to determine whether the unit is managed locally or by a remote FMC server?
- A. show configuration session
- B. show managers
- C. system generate-troubleshoot
- D. show running-config | include manager
Answer: B
Explanation:
Section: Management and Troubleshooting
Explanation/Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/command_ref/ b_Command_Reference_for_Firepower_Threat_Defense/c_3.html
NEW QUESTION # 95
An administrator is creating interface objects to better segment their network but is having trouble adding interfaces to the objects. What is the reason for this failure?
- A. The interfaces belong to multiple interface groups.
- B. The administrator is adding an interface that is in multiple zones.
- C. The interfaces are being used for NAT for multiple networks.
- D. The administrator is adding interfaces of multiple types.
Answer: A
Explanation:
Explanation
https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/reusa
"All interfaces in an interface object must be of the same type: all inline, passive, switched, routed, or ASA FirePOWER. After you create an interface object, you cannot change the type of interfaces it contains."
NEW QUESTION # 96
A security engineer is deploying a pair of primary and secondary Cisco FMC devices. The secondary must also receive updates from Cisco Talos. Which action achieves this goal?
- A. Configure the secondary Cisco FMC so that it receives updates from Cisco Talos.
- B. Configure the primary Cisco FMC so that the rules are updated.
- C. Manually import rule updates onto the secondary Cisco FMC device.
- D. Force failover for the secondary Cisco FMC to synchronize the rule updates from the primary.
Answer: B
NEW QUESTION # 97
A network administrator is troubleshooting access to a website hosted behind a Cisco FTD device External clients cannot access the web server via HTTPS The IP address configured on the web server is 192 168 7.46 The administrator is running the command capture CAP interface outside match ip any 192.168.7.46
255.255.255.255 but cannot see any traffic in the capture Why is this occurring?
- A. The FTD has no route to the web server.
- B. The packet capture shows only blocked traffic
- C. The access policy is blocking the traffic.
- D. The capture must use the public IP address of the web server.
Answer: D
NEW QUESTION # 98
Which command should be used on the Cisco FTD CLI to capture all the packets that hit an interface?
- A. capture WORD
- B. configure coredump packet-engine enable
- C. capture
- D. capture-traffic
Answer: D
Explanation:
Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/command_ref/b_Command_Reference_for_Firepower_Threat_Defense/ac_1.html
NEW QUESTION # 99
An engineer Is configuring a Cisco FTD device to place on the Finance VLAN to provide additional protection tor company financial data. The device must be deployed without requiring any changes on the end user workstations, which currently use DHCP lo obtain an IP address. How must the engineer deploy the device to meet this requirement?
- A. Deploy the device in routed mode and allow DHCP traffic in the access control policies.
- B. Deploy the device in routed made aid enable the DHCP Relay feature.
- C. Deploy the device in transparent mode and enable the DHCP Server feature.
- D. Deploy the device in transparent mode and allow DHCP traffic in the access control policies
Answer: D
Explanation:
Explanation
Transparent mode allows the FTD device to act as a "bump in the wire" that does not affect the IP addressing of the network. The end user workstations will not need any changes to their configuration, as they will still receive an IP address from the same DHCP server. However, the FTD device must allow DHCP traffic in the access control policies, otherwise it will block the DHCP requests and replies1
NEW QUESTION # 100
An engineer is troubleshooting a device that cannot connect to a web server. The connection is initiated from the Cisco FTD inside interface and attempting to reach 10.0.1.100 over the non-standard port of 9443 The host the engineer is attempting the connection from is at the IP address of 10.20.10.20. In order to determine what is happening to the packets on the network, the engineer decides to use the FTD packet capture tool Which capture configuration should be used to gather the information needed to troubleshoot this issue?
A)
B)
C)
D)
- A. Option D
- B. Option A
- C. Option C
- D. Option B
Answer: D
NEW QUESTION # 101
Refer to the exhibit.
What is the effect of the existing Cisco FMC configuration?
- A. The management connection between the Cisco FMC and the Cisco FTD is disabled.
- B. The SSL-encrypted communication channel between the Cisco FMC and the managed device becomes plain-text communication channel.
- C. The remote management port for communication between the Cisco FMC and the managed device changes to port 8443.
- D. The managed device is deleted from the Cisco FMC.
Answer: A
NEW QUESTION # 102
What is the advantage of having Cisco Firepower devices send events to Cisco Threat response via the security services exchange portal directly as opposed to using syslog?
- A. All types of Firepower devices are supported.
- B. An on-premises proxy server does not need to set up and maintained
- C. Supports all devices that are running supported versions of Firepower
- D. Firepower devices do not need to be connected to the internet.
Answer: A
NEW QUESTION # 103
Drag and drop the steps to restore an automatic device registration failure on the standby Cisco FMC from the left into the correct order on the right. Not all options are used.
Answer:
Explanation:
Explanation
Explanation
Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config- guide-v62/firepower_management_center_high_availability.html#id_32288
NEW QUESTION # 104
A network engineer is deploying a Cisco Firepower 4100 appliance and must configure a multi-instance environment for high availability. Drag and drop me actions from the left into sequence on the right far this configuration.
Answer:
Explanation:
Explanation
The correct sequence of actions for configuring a multi-instance environment for high availability on a Cisco Firepower 4100 appliance is as follows:
Add a resource profile for container instances. A resource profile defines the CPU, RAM, and disk space allocation for each container instance. You can create multiple resource profiles with different resource settings and assign them to different container instances1.
Add a MAC pool prefix and view the MAC address for the container instance interfaces. A MAC pool prefix is a 24-bit prefix that is used to generate MAC addresses for the container instance interfaces.
You can specify a custom MAC pool prefix or use the default one. You can also view the MAC addresses that are assigned to each container instance interface1.
Configure interfaces. You need to configure the physical interfaces, EtherChannels, and VLAN subinterfaces that will be used by the container instances. You can also configure shared interfaces that can be used by multiple container instances on the same security module/engine1.
Add a Standalone Firepower Threat Defense for Cisco Secure Firewall Management Center. You need to add a logical device that runs a standalone Firepower Threat Defense (FTD) application instance and register it with the Cisco Secure Firewall Management Center (FMC). This logical device will act as the management interface for the container instances1.
Add a high-availability pair. You need to add another logical device that runs a standalone FTD application instance and register it with the FMC as well. Then, you need to configure high availability (HA) between the two standalone FTD logical devices. This will enable HA for the container instances that are associated with them1.
NEW QUESTION # 105
Which CLI command is used to control special handling of ClientHello messages?
- A. system support ssl-client-hello-tuning
- B. system support ssl-client-hello-force-reset
- C. system support ssl-client-hello-enabled
- D. system support ssl-client-hello-display
Answer: C
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/610/configuration/guide/fpmc-config- guide-v61/firepower_command_line_reference.html
NEW QUESTION # 106
A network engineer is extending a user segment through an FTD device for traffic inspection without creating another IP subnet How is this accomplished on an FTD device in routed mode?
- A. by bypassing protocol inspection by leveraging pre-filter rules
- B. by leveraging the ARP to direct traffic through the firewall
- C. by using a BVI and create a BVI IP address in the same subnet as the user segment
- D. by assigning an inline set interface
Answer: D
Explanation:
https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-config-guide-v64/transparent_or_routed_firewall_mode_for_firepower_threat_defense.html
NEW QUESTION # 107
An engineer is monitoring network traffic from their sales and product development departments, which are on two separate networks What must be configured in order to maintain data privacy for both departments?
- A. Use 802 1Q mime set Trunk interfaces with VLANs to maintain logical traffic separation
- B. Use a dedicated IPS inline set for each department to maintain traffic separation
- C. Use one pair of inline set in TAP mode for both departments
- D. Use passive IDS ports for both departments
Answer: A
NEW QUESTION # 108
An engineer plans to reconfigure an existing Cisco FTD from transparent mode to routed mode. Which additional action must be taken to maintain communication Between me two network segments?
- A. Deploy inbound ACLs on each interface to allow traffic between the segments.
- B. Update the IP addressing so that each segment is a unique IP subnet.
- C. Assign a unique VLAN ID for the interface in each segment.
- D. Configure a NAT rule so mat traffic between the segments is exempt from NAT.
Answer: B
Explanation:
Explanation
When reconfiguring an existing Cisco FTD from transparent mode to routed mode, an additional action that must be taken to maintain communication between the two network segments is to update the IP addressing so that each segment is a unique IP subnet. This is because in routed mode, the FTD device acts as a router hop in the network and requires each interface to be on a different subnet. In transparent mode, the FTD device acts as a layer 2 firewall and does not require different subnets for each interface1.
The other options are incorrect because:
Configuring a NAT rule so that traffic between the segments is exempt from NAT is not necessary to maintain communication between the two network segments. NAT is used to translate IP addresses between different networks, but it does not affect the routing of packets. Moreover, NAT is optional in routed mode and can be disabled if not needed2.
Deploying inbound ACLs on each interface to allow traffic between the segments is not required to maintain communication between the two network segments. ACLs are used to control access to network resources based on source and destination addresses, protocols, and ports. They do not affect the routing of packets. Furthermore, ACLs are optional in routed mode and can be configured as needed3.
Assigning a unique VLAN ID for the interface in each segment is not relevant to maintain communication between the two network segments. VLANs are used to create logical groups of hosts that share the same broadcast domain, regardless of their physical location or connection. They do not affect the routing of packets. Besides, VLANs are not supported in routed mode and can only be used in transparent mode4.
NEW QUESTION # 109
Which command must be run to generate troubleshooting files on an FTD?
- A. show tech-support
- B. system support view-files
- C. sudo sf_troubleshoot.pl
- D. system generate-troubleshoot all
Answer: D
Explanation:
Reference: https://www.cisco.com/c/en/us/support/docs/security/sourcefire-defense-center/117663-technote- SourceFire-00.html
NEW QUESTION # 110
Which command is entered in the Cisco FMC CLI to generate a troubleshooting file?
- A. show tech-support chassis
- B. sudo sf_troubleshoot.pl
- C. system support diagnostic-cli
- D. show running-config
Answer: B
Explanation:
Section: Management and Troubleshooting
Explanation/Reference: https://www.cisco.com/c/en/us/support/docs/security/sourcefire-defense-center/117663-technote- SourceFire-00.html
NEW QUESTION # 111
Which two OSPF routing features are configured in Cisco FMC and propagated to Cisco FTD? (Choose two.)
- A. MD5 authentication to OSPF packets
- B. OSPFv2 with IPv6 capabilities
- C. area boundary router type 1 LSA filtering
- D. SHA authentication to OSPF packets
- E. virtual links
Answer: C,E
Explanation:
Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/ospf_for_firepower_threat_defense.html
NEW QUESTION # 112
......
Get Top-Rated Cisco 300-710 Exam Dumps Now: https://testking.prep4sureexam.com/300-710-dumps-torrent.html