Verified 300-710 Dumps Q&As - 300-710 Test Engine with Correct Answers
Pass Your 300-710 Dumps as PDF Updated on 2024 With 279 Questions
NEW QUESTION # 139
Which two routing options are valid with Cisco Firepower Threat Defense? (Choose two.)
- A. BGPv4 in transparent firewall mode
- B. BGPv6
- C. ECMP with up to three equal cost paths across a single interface
- D. BGPv4 with nonstop forwarding
- E. ECMP with up to three equal cost paths across multiple interfaces
Answer: B,C
Explanation:
Section: Configuration
Explanation/Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/601/configuration/guide/fpmc-config- guide-v601/fpmc-config-guide-v60_chapter_01100011.html#ID-2101-0000000e
NEW QUESTION # 140
A network engineer implements a new Cisco Firepower device on the network to take advantage of its intrusion detection functionality. There is a requirement to analyze the traffic going across the device, alert on any malicious traffic, and appear as a bump in the wire How should this be implemented?
- A. Enable routing on the Cisco Firepower
- B. Add an IP address to the physical Cisco Firepower interfaces.
- C. Configure a bridge group in transparent mode.
- D. Specify the BVl IP address as the default gateway for connected devices.
Answer: C
Explanation:
Traditionally, a firewall is a routed hop and acts as a default gateway for hosts that connect to one of its screened subnets. A transparent firewall, on the other hand, is a Layer 2 firewall that acts like a "bump in the wire," or a "stealth firewall," and is not seen as a router hop to connected devices. However, like any other firewall, access control between interfaces is controlled, and all of the usual firewall checks are in place. Layer 2 connectivity is achieved by using a "bridge group" where you group together the inside and outside interfaces for a network, and the ASA uses bridging techniques to pass traffic between the interfaces. Each bridge group includes a Bridge Virtual Interface (BVI) to which you assign an IP address on the network. You can have multiple bridge groups for multiple networks. In transparent mode, these bridge groups cannot communicate with each other. https://www.cisco.com/c/en/us/td/docs/security/asa/asa97/configuration/general/asa-97-general-config/intro-fw.html
NEW QUESTION # 141
An organization has implemented Cisco Firepower without IPS capabilities and now wants to enable inspection for their traffic. They need to be able to detect protocol anomalies and utilize the Snort rule sets to detect malicious behavior. How is this accomplished?
- A. Modify the network discovery policy to detect new hosts to inspect.
- B. Modify the network analysis policy to process the packets for inspection.
- C. Modify the access control policy to redirect interesting traffic to the engine.
- D. Modify the intrusion policy to determine the minimum severity of an event to inspect.
Answer: B
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/670/fdm/fptd-fdm-config-guide-670/fptd-fdmintrusion.
Html
NEW QUESTION # 142
Which group within Cisco does the Threat Response team use for threat analysis and research?
- A. Cisco Talos
- B. OpenDNS Group
- C. Cisco Network Response
- D. Cisco Deep Analytics
Answer: A
Explanation:
Reference: https://www.cisco.com/c/en/us/products/security/threat-response.html#~benefits
NEW QUESTION # 143
An engineer is building a new access control policy using Cisco FMC. The policy must inspect a unique IPS policy as well as log rule matching. Which action must be taken to meet these requirements?
- A. Disable the default IPS policy and enable global logging.
- B. Configure an IPS policy and enable global logging.
- C. Configure an IPS policy and enable per-rule logging.
- D. Disable the default IPS policy and enable per-rule logging.
Answer: C
NEW QUESTION # 144
Which two deployment types support high availability? (Choose two.)
- A. transparent
- B. intra-chassis multi-instance
- C. routed
- D. virtual appliance in public cloud
- E. clustered
Answer: A,C
NEW QUESTION # 145
Drag and drop the steps to restore an automatic device registration failure on the standby Cisco FMC from the left into the correct order on the right. Not all options are used.
Answer:
Explanation:
NEW QUESTION # 146
An engineer has been tasked with providing disaster recovery for an organization's primary Cisco FMC.
What must be done on the primary and secondary Cisco FMCs to ensure that a copy of the original corporate policy is available if the primary Cisco FMC fails?
- A. Connect the primary and secondary Cisco FMC devices with Category 6 cables of not more than 10 meters in length.
- B. Place the active Cisco FMC device on the same trusted management network as the standby device
- C. Configure high-availability in both the primary and secondary Cisco FMCs
- D. Restore the primary Cisco FMC backup configuration to the secondary Cisco FMC device when the primary device fails
Answer: D
NEW QUESTION # 147
A security engineer is configuring a remote Cisco FTD that has limited resources and internet bandwidth. Which malware action and protection option should be configured to reduce the requirement for cloud lookups?
- A. Block Malware action and local malware analysis
- B. Block Malware action and dynamic analysis
- C. Block File action and local malware analysis
- D. Malware Cloud Lookup and dynamic analysis
Answer: D
NEW QUESTION # 148
What is the advantage of having Cisco Firepower devices send events to Cisco Threat response via the security services exchange portal directly as opposed to using syslog?
- A. All types of Firepower devices are supported.
- B. Supports all devices that are running supported versions of Firepower
- C. Firepower devices do not need to be connected to the internet.
- D. An on-premises proxy server does not need to set up and maintained
Answer: A
NEW QUESTION # 149
After deploying a network-monitoring tool to manage and monitor networking devices in your organization, you realize that you need to manually upload an MIB for the Cisco FMC. In which folder should you upload the MIB file?
- A. /etc/sf/DCEALERT.MIB
- B. system/etc/DCEALERT.MIB
- C. /etc/sf/DCMIB.ALERT
- D. /sf/etc/DCEALERT.MIB
Answer: A
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firesight/541/firepower-module-user-guide/asa- firepower-module-user-guide-v541/Intrusion-External-Responses.pdf
NEW QUESTION # 150
A network administrator is migrating from a Cisco ASA to a Cisco FTD.
EIGRP is configured on the Cisco ASA but it is not available in the Cisco FMC.
Which action must the administrator take to enable this feature on the Cisco FTD?
- A. Create a custom variable set and enable the feature in the variable set.
- B. Add the command feature eigrp via the FTD CLI.
- C. Enable advanced configuration options in the FMC.
- D. Configure EIGRP parameters using FlexConfig objects.
Answer: D
NEW QUESTION # 151
A network engineer is logged into the Cisco AMP for Endpoints console and sees a malicious verdict for an identified SHA-256 hash. Which configuration is needed to mitigate this threat?
- A. Add the hash from the infected endpoint to the network block list.
- B. Add the hash to the simple custom detection list.
- C. Use regular expressions to block the malicious file.
- D. Enable a personal firewall in the infected endpoint.
Answer: B
NEW QUESTION # 152
Refer to the exhibit.
What must be done to fix access to this website while preventing the same communication to all other websites?
- A. Create an intrusion policy rule to have Snort allow port 443 to only 172.1.1.50
- B. Create an access control policy rule to allow port 443 to only 172.1.1 50
- C. Create an intrusion policy rule to have Snort allow port 80 to only 172.1.1 50.
- D. Create an access control policy rule to allow port 80 to only 172.1.1 50.
Answer: D
NEW QUESTION # 153
Drag and drop the steps to restore an automatic device registration failure on the standby Cisco FMC from the left into the correct order on the right. Not all options are used.
Answer:
Explanation:
NEW QUESTION # 154
What is an advantage of adding multiple inline interface pairs to the same inline interface set when deploying an asynchronous routing configuration?
- A. The interfaces disable autonegotiation and interface speed is hard coded set to 1000 Mbps.
- B. The interfaces are automatically configured as a media-independent interface crossover.
- C. Allows the IPS to identify inbound and outbound traffic as part of the same traffic flow.
- D. Allows traffic inspection to continue without interruption during the Snort process restart.
Answer: C
Explanation:
Explanation
https://www.cisco.com/c/en/us/td/docs/security/firepower/601/configuration/guide/fpmc-config-guide-v601/fpm
NEW QUESTION # 155
A Cisco FTD device is running in transparent firewall mode with a VTEP bridge group member ingress interface What must be considered by an engineer tasked with specifying a destination MAC address for a packet trace?
- A. The output format option for the packet logs unavailable
- B. The destination MAC address is optional if a VLAN ID value is entered
- C. The VLAN ID and destination MAC address are optional
- D. Only the UDP packet type is supported
Answer: B
NEW QUESTION # 156
Refer to the exhibit.
An organization has an access control rule with the intention of sending all social media traffic for inspection After using the rule for some time, the administrator notices that the traffic is not being inspected, but is being automatically allowed What must be done to address this issue?
- A. Change the intrusion policy to connectivity over security.
- B. Add the social network URLs to the block list
- C. Modify the rule action from trust to allow
- D. Modify the selected application within the rule
Answer: D
NEW QUESTION # 157
Which two conditions are necessary for high availability to function between two Cisco FTD devices?
(Choose two.)
- A. The units must be different models if they are part of the same series.
- B. The units must be configured only for firewall routed mode.
- C. Both devices can be part of a different group that must be in the same domain when configured within the FMC.
- D. The units must be the same version
- E. The units must be the same model.
Answer: D,E
Explanation:
Reference: https://www.cisco.com/c/en/us/support/docs/security/firepower-management-center/212699-configure-ftd-high-availability-on-firep.html
NEW QUESTION # 158
Which Firepower feature allows users to configure bridges in routed mode and enables devices to perform Layer 2 switching between interfaces?
- A. SGT
- B. BDI
- C. FlexConfig
- D. IRB
Answer: D
Explanation:
Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/620/relnotes/Firepower_System_Release_Notes_Version_620/new_features_and_functionality.html
NEW QUESTION # 159
There is an increased amount of traffic on the network and for compliance reasons, management needs visibility into the encrypted traffic What is a result of enabling TLS'SSL decryption to allow this visibility?
- A. It prompts the need for a corporate managed certificate
- B. It will fail if certificate pinning is not enforced
- C. It has minimal performance impact
- D. It is not subject to any Privacy regulations
Answer: A
NEW QUESTION # 160
A company is deploying intrusion protection on multiple Cisco FTD appliances managed by Cisco FMC. Which system-provided policy must be selected if speed and detection are priorities?
- A. Security Over Connectivity
- B. Connectivity Over Security
- C. Maximum Detection
- D. Balanced Security and Connectivity
Answer: D
NEW QUESTION # 161
administrator is configuring SNORT inspection policies and is seeing failed deployment messages in Cisco FMC . What information should the administrator generate for Cisco TAC to help troubleshoot?
- A. A "troubleshoot" file for the Cisco FMC
- B. A Troubleshoot" file for the device in question.
- C. A "show tech" for the Cisco FMC.
- D. A "show tech" file for the device in question
Answer: A
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/troubleshooting_the_system.html
NEW QUESTION # 162
......
Pass Cisco 300-710 Exam Info and Free Practice Test: https://examcertify.passleader.top/Cisco/300-710-exam-braindumps.html