Aug 23, 2022 Newest 300-710 Exam Dumps – Achieve Success in Actual 300-710 Exam
Updated Cisco 300-710 Dumps – Check Free 300-710 Exam Dumps (2022)
NEW QUESTION 83
Which firewall design allows a firewall to forward traffic at layer 2 and layer 3 for the same subnet?
- A. Cisco Firepower Threat Defense mode
- B. integrated routing and bridging
- C. routed mode
- D. transparent mode
Answer: A
NEW QUESTION 84
Which two actions can be used in an access control policy rule? (Choose two.)
- A. Block ALL
- B. Block with Reset
- C. Analyze
- D. Monitor
- E. Discover
Answer: B,D
NEW QUESTION 85
While integrating Cisco Umbrella with Cisco Threat Response, a network security engineer wants to automatically push blocking of domains from the Cisco Threat Response interface to Cisco Umbrell a. Which API meets this requirement?
- A. investigate
- B. enforcement
- C. REST
- D. reporting
Answer: B
NEW QUESTION 86
With Cisco FTD integrated routing and bridging, which interface does the bridge group use to communicate with a routed interface?
- A. subinterface
- B. switch virtual
- C. bridge group member
- D. bridge virtual
Answer: C
NEW QUESTION 87
An engineer is configuring a second Cisco FMC as a standby device but is unable to register with the active unit. What is causing this issue?
- A. The licensing purchased does not include high availability
- B. There is only 10 Mbps of bandwidth between the two devices.
- C. The primary FMC currently has devices connected to it.
- D. The code versions running on the Cisco FMC devices are different
Answer: D
Explanation:
https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/firepower_management_center_high_availability.html
NEW QUESTION 88
An engineer runs the command restore remote-manager-backup location 2.2.2.2 admin /Volume/home/admin FTD408566513.zip on a Cisco FMC. After connecting to the repository, the Cisco FTD device is unable to accept the backup file. What is the reason for this failure?
- A. The backup file extension was changed from .tar to .zip.
- B. The directory location is incorrect.
- C. The backup file is not in .cfg format.
- D. The wrong IP address is used.
Answer: A
NEW QUESTION 89
Which two dynamic routing protocols are supported in Firepower Threat Defense without using FlexConfig? (Choose two.)
- A. BGP
- B. OSPF
- C. static routing
- D. EIGRP
- E. IS-IS
Answer: A,B
NEW QUESTION 90
administrator is configuring SNORT inspection policies and is seeing failed deployment messages in Cisco FMC . What information should the administrator generate for Cisco TAC to help troubleshoot?
- A. A "show tech" for the Cisco FMC.
- B. A Troubleshoot" file for the device in question.
- C. A "troubleshoot" file for the Cisco FMC
- D. A "show tech" file for the device in question
Answer: C
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/troubleshooting_the_system.html
NEW QUESTION 91
An organization has a Cisco FTD that uses bridge groups to pass traffic from the inside interfaces to the outside interfaces. They are unable to gather information about neighbouring Cisco devices or use multicast in their environment. What must be done to resolve this issue?
- A. Create a firewall rule to allow CDP traffic.
- B. Change the firewall mode to transparent.
- C. Change the firewall mode to routed.
- D. Create a bridge group with the firewall interfaces.
Answer: C
NEW QUESTION 92
A network administrator notices that inspection has been interrupted on all non-managed interfaces of a device. What is the cause of this?
- A. A passive interface was associated with a security zone.
- B. The value of the highest MTU assigned to any non-management interface was changed.
- C. The value of the highest MSS assigned to any non-management interface was changed.
- D. Multiple inline interface pairs were added to the same inline interface.
Answer: B
NEW QUESTION 93
Which command is typed at the CLI on the primary Cisco FTD unit to temporarily stop running high-availability?
- A. system support network-options
- B. configure high-availability suspend
- C. configure high-availability resume
- D. configure high-availability disable
Answer: D
Explanation:
Section: Management and Troubleshooting
Explanation/Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/610/configuration/guide/fpmc-config- guide-v61/firepower_threat_defense_high_availability.html
NEW QUESTION 94
Refer to the exhibit.
An organization has an access control rule with the intention of sending all social media traffic for inspection After using the rule for some time, the administrator notices that the traffic is not being inspected, but is being automatically allowed What must be done to address this issue?
- A. Modify the selected application within the rule
- B. Modify the rule action from trust to allow
- C. Add the social network URLs to the block list
- D. Change the intrusion policy to connectivity over security.
Answer: A
NEW QUESTION 95
An engineer is troubleshooting a device that cannot connect to a web server. The connection is initiated from the Cisco FTD inside interface and attempting to reach 10.0.1.100 over the non-standard port of 9443 The host the engineer is attempting the connection from is at the IP address of 10.20.10.20. In order to determine what is happening to the packets on the network, the engineer decides to use the FTD packet capture tool Which capture configuration should be used to gather the information needed to troubleshoot this issue?
A)
B)
C)
D)
- A. Option D
- B. Option C
- C. Option A
- D. Option B
Answer: D
NEW QUESTION 96
A Cisco FTD has two physical interfaces assigned to a BVI. Each interface is connected to a different VLAN on the same switch. Which firewall mode is the Cisco FTD set up to support?
- A. high availability clustering
- B. transparent
- C. active/active failover
- D. routed
Answer: D
NEW QUESTION 97
Which CLI command is used to control special handling of ClientHello messages?
- A. system support ssl-client-hello-display
- B. system support ssl-client-hello-enabled
- C. system support ssl-client-hello-tuning
- D. system support ssl-client-hello-force-reset
Answer: B
NEW QUESTION 98
An engineer is implementing Cisco FTD in the network and is determining which Firepower mode to use. The organization needs to have multiple virtual Firepower devices working separately inside of the FTD appliance to provide traffic segmentation Which deployment mode should be configured in the Cisco Firepower Management Console to support these requirements?
- A. single deployment
- B. single-context
- C. multi-instance
- D. multiple deployment
Answer: C
NEW QUESTION 99
An engainer must add DNS-specific rules to me Cisco FTD intrusion policy. The engineer wants to use the rules currently in the Cisco FTD Snort database that are not already enabled but does not want to enable more than are needed. Which action meets these requirements?
- A. Change the dynamic state of the rule within the policy.
- B. Change the base policy to Security over Connectivity.
- C. Change the rule state within the policy being used.
- D. Change the rules using the Generate and Use Recommendations feature.
Answer: C
NEW QUESTION 100
A network engineer is logged into the Cisco AMP for Endpoints console and sees a malicious verdict for an identified SHA-256 hash. Which configuration is needed to mitigate this threat?
- A. Use regular expressions to block the malicious file.
- B. Enable a personal firewall in the infected endpoint.
- C. Add the hash to the simple custom detection list.
- D. Add the hash from the infected endpoint to the network block list.
Answer: C
NEW QUESTION 101
The event dashboard within the Cisco FMC has been inundated with low priority intrusion drop events, which are overshadowing high priority events. An engineer has been tasked with reviewing the policies and reducing the low priority events. Which action should be configured to accomplish this task?
- A. drop and generate
- B. generate events
- C. drop packet
- D. drop connection
Answer: A
NEW QUESTION 102
DRAG DROP
Drag and drop the steps to restore an automatic device registration failure on the standby Cisco FMC from the left into the correct order on the right. Not all options are used.
Select and Place:
Answer:
Explanation:
Section: Management and Troubleshooting
Explanation/Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config- guide-v62/firepower_management_center_high_availability.html#id_32288
NEW QUESTION 103
What is a behavior of a Cisco FMC database purge?
- A. User login and history data are removed from the database if the User Activity check box is selected.
- B. The specified data is removed from Cisco FMC and kept for two weeks.
- C. The appropriate process is restarted.
- D. Data can be recovered from the device.
Answer: C
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config- guide-v62/management_center_database_purge.pdf
NEW QUESTION 104
A network engineer is extending a user segment through an FTD device for traffic inspection without creating another IP subnet How is this accomplished on an FTD device in routed mode?
- A. by leveraging the ARP to direct traffic through the firewall
- B. by assigning an inline set interface
- C. by bypassing protocol inspection by leveraging pre-filter rules
- D. by using a BVI and create a BVI IP address in the same subnet as the user segment
Answer: D
Explanation:
Explanation
https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-config-guide-v64/transp
NEW QUESTION 105
A mid-sized company is experiencing higher network bandwidth utilization due to a recent acquisition The network operations team is asked to scale up their one Cisco FTD appliance deployment to higher capacities due to the increased network bandwidth. Which design option should be used to accomplish this goal?
- A. Deploy multiple Cisco FTD HA pairs to increase performance
- B. Deploy multiple Cisco FTD HA pairs in clustering mode to increase performance
- C. Deploy multiple Cisco FTD appliances using VPN load-balancing to scale performance.
- D. Deploy multiple Cisco FTD appliances in firewall clustering mode to increase performance.
Answer: D
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/fxos/clustering/ftd-cluster-solution.html#concept_C8502505F840451C9E600F1EED9BC18E
NEW QUESTION 106
With Cisco FTD integrated routing and bridging, which interface does the bridge group use to communicate with a routed interface?
- A. bridge group member
- B. subinterface
- C. switch virtual
- D. bridge virtual
Answer: D
NEW QUESTION 107
......
Actual 300-710 Exam Recently Updated Questions with Free Demo: https://skillsoft.braindumpquiz.com/300-710-exam-material.html