[UPDATED 2024] Cisco 300-710 Questions Prepare with Free Demo of PDF
NEW 2024 Certification Sample Questions 300-710 Dumps & Practice Exam
Cisco 300-710 exam, also known as Securing Networks with Cisco Firepower, is designed for IT professionals who want to enhance their skills and knowledge in network security. 300-710 exam is part of the Cisco Certified Network Professional Security (CCNP Security) certification track, which validates the skills required to secure Cisco networks. The Cisco 300-710 exam focuses on Cisco Firepower Threat Defense, an advanced security solution that provides comprehensive threat protection for organizations of all sizes.
NEW QUESTION # 114
Which two deployment types support high availability? (Choose two.)
- A. transparent
- B. virtual appliance in public cloud
- C. intra-chassis multi-instance
- D. routed
- E. clustered
Answer: A,D
NEW QUESTION # 115
What is a characteristic of bridge groups on a Cisco FTD?
- A. In routed firewall mode, routing between bridge groups must pass through a routed interface.
- B. In transparent firewall mode, routing between bridge groups is supported
- C. Routing between bridge groups is achieved only with a router-on-a-stick configuration on a connected router
- D. In routed firewall mode, routing between bridge groups is supported.
Answer: D
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/asa/asa97/configuration/general/asa-97-general-config/intro-fw.pdf
NEW QUESTION # 116
An administrator is optimizing the Cisco FTD rules to improve network performance, and wants to bypass inspection for certain traffic types to reduce the load on the Cisco FTD. Which policy must be configured to accomplish this goal?
- A. prefilter
- B. intrusion
- C. URL filtering
- D. identity
Answer: A
NEW QUESTION # 117
Refer to the exhibit.
And engineer is analyzing the Attacks Risk Report and finds that there are over 300 instances of new operating systems being seen on the network How is the Firepower configuration updated to protect these new operating systems?
- A. Cisco Firepower automatically updates the policies.
- B. The administrator manually updates the policies.
- C. The administrator requests a Remediation Recommendation Report from Cisco Firepower
- D. Cisco Firepower gives recommendations to update the policies.
Answer: D
Explanation:
Ref: https://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide-v60/Tailoring_Intrusion_Protection_to_Your_Network_Assets.html
NEW QUESTION # 118
What is the maximum bit size that Cisco FMC supports for HTTPS certificates?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: C
Explanation:
Section: Management and Troubleshooting
Explanation/Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/610/configuration/guide/fpmc-config- guide-v61/system_configuration.html
NEW QUESTION # 119
An engineer is restoring a Cisco FTD configuration from a remote backup using the command restore remote-manager-backup location 1.1.1.1 admin /volume/home/admin BACKUP_Cisc394602314.zip on a Cisco FMG. After connecting to the repository, an error occurred that prevents the FTD device from accepting the backup file. What is the problem?
- A. The backup file extension was changed from tar to zip
- B. The backup file is too large for the Cisco FTD device
- C. The backup file is not in .cfg format.
- D. The backup file was not enabled prior to being applied
Answer: A
NEW QUESTION # 120
An engineer configures an access control rule that deploys file policy configurations to security zones or tunnel zones, and it causes the device to restart. What is the reason for the restart?
- A. The source tunnel zone in the rule does not match a tunnel zone that is assigned to a tunnel rule in the source policy.
- B. Source or destination security zones in the access control rule matches the security zones that are associated with interfaces on the target devices.
- C. The source tunnel zone in the rule does not match a tunnel zone that is assigned to a tunnel rule in the destination policy.
- D. Source or destination security zones in the source tunnel zone do not match the security zones that are associated with interfaces on the target devices.
Answer: B
NEW QUESTION # 121
Which Cisco Firepower feature is used to reduce the number of events received in a period of time?
- A. correlation
- B. suspending
- C. thresholding
- D. rate-limiting
Answer: C
Explanation:
Reference: https://www.cisco.com/c/en/us/td/docs/security/firesight/541/firepower-module-user-guide/asa-firepower-module-user-guide-v541/Intrusion-Global-Threshold.html
NEW QUESTION # 122
Which two packet captures does the FTD LINA engine support? (Choose two.)
- A. application ID
- B. source IP
- C. Layer 7 network ID
- D. protocol
- E. dynamic firewall importing
Answer: B,D
NEW QUESTION # 123
Drag and drop the steps to restore an automatic device registration failure on the standby Cisco FMC from the left into the correct order on the right. Not all options are used.
Answer:
Explanation:
NEW QUESTION # 124
An engineer has been tasked with providing disaster recovery for an organization's primary Cisco FMC. What must be done on the primary and secondary Cisco FMCs to ensure that a copy of the original corporate policy is available if the primary Cisco FMC fails?
- A. Connect the primary and secondary Cisco FMC devices with Category 6 cables of not more than 10 meters in length.
- B. Place the active Cisco FMC device on the same trusted management network as the standby device
- C. Configure high-availability in both the primary and secondary Cisco FMCs
- D. Restore the primary Cisco FMC backup configuration to the secondary Cisco FMC device when the primary device fails
Answer: D
NEW QUESTION # 125
A network engineer is logged into the Cisco AMP for Endpoints console and sees a malicious verdict for an identified SHA-256 hash. Which configuration is needed to mitigate this threat?
- A. Use regular expressions to block the malicious file.
- B. Enable a personal firewall in the infected endpoint.
- C. Add the hash to the simple custom detection list.
- D. Add the hash from the infected endpoint to the network block list.
Answer: C
NEW QUESTION # 126
A Cisco FMC administrator wants to configure fastpathing of trusted network traffic to increase performance. In which type of policy would the administrator configure this feature?
- A. Identity policy
- B. Prefilter policy
- C. Network Analysis policy
- D. Intrusion policy
Answer: B
NEW QUESTION # 127
A company is in the process of deploying intrusion prevention with Cisco FTDs managed by a Cisco FMC. An engineer must configure policies to detect potential intrusions but not block the suspicious traffic. Which action accomplishes this task?
- A. Configure IPS mode when creating or editing a policy rule under the Cisco FMC Intrusion tab in Access Policies section by checking the "Drop when inline" option.
- B. Configure IDS mode when creating or editing a policy rule under the Cisco FMC Intrusion tab in Access Policies section by checking the "Drop when inline" option.
- C. Configure IPS mode when creating or editing a policy rule under the Cisco FMC Intrusion tab in Access Policies section by unchecking the "Drop when inline" option.
- D. Configure IDS mode when creating or editing a policy rule under the Cisco FMC Intrusion tab in Access Policies section by unchecking the "Drop when inline" option.
Answer: D
NEW QUESTION # 128
Which command should be used on the Cisco FTD CLI to capture all the packets that hit an interface?
- A. capture
- B. configure coredump packet-engine enable
- C. capture-traffic
- D. capture WORD
Answer: A
Explanation:
Reason: the command "capture-traffic" is used for SNORT Engine Captures. To capture a LINA Engine Capture, you use the "capture" command. Since the Lina Engine represents the actual physical interface of the device, "capture" is the only reasonable choice Reference: https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/212474-working-with-firepower-threat-defense-f.html#anc10 The command is firepower# capture DMZ interface dmz trace detail match ip host 192.168.76.14 host 192.168.76.100 firepower# capture INSIDE interface inside trace detail match ip host 192.168.76.14 host 192.168.75.14
NEW QUESTION # 129
Which command must be run to generate troubleshooting files on an FTD?
- A. system generate-troubleshoot all
- B. system support view-files
- C. sudo sf_troubleshoot.pl
- D. show tech-support
Answer: C
Explanation:
Section: Management and Troubleshooting
Explanation/Reference: https://www.cisco.com/c/en/us/support/docs/security/sourcefire-defense-center/117663-technote- SourceFire-00.html
NEW QUESTION # 130
A company is deploying intrusion protection on multiple Cisco FTD appliances managed by Cisco FMC.
Which system-provided policy must be selected if speed and detection are priorities?
- A. Connectivity Over Security
- B. Balanced Security and Connectivity
- C. Maximum Detection
- D. Security Over Connectivity
Answer: B
NEW QUESTION # 131
What is a result of enabling Cisco FTD clustering?
- A. Site-to-site VPN functionality is limited to the master unit, and all VPN connections are dropped if the master unit fails.
- B. Integrated Routing and Bridging is supported on the master unit.
- C. For the dynamic routing feature, if the master unit fails, the newly elected master unit maintains all existing connections.
- D. All Firepower appliances can support Cisco FTD clustering.
Answer: A
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-config- guide-v64/clustering_for_the_firepower_threat_defense.html
NEW QUESTION # 132
When creating a report template, how can the results be limited to show only the activity of a specific subnet?
- A. Add a Table View section to the report with the Search field defined as the network in CIDR format.
- B. Select IP Address as the X-Axis in each section of the report.
- C. Create a custom search in Firepower Management Center and select it in each section of the report.
- D. Add an Input Parameter in the Advanced Settings of the report, and set the type to Network/IP.
Answer: D
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firesight/541/user-guide/FireSIGHT-System- UserGuide-v5401/Reports.html#87267
NEW QUESTION # 133
After deploying a network-monitoring tool to manage and monitor networking devices in your organization, you realize that you need to manually upload an MIB for the Cisco FMC. In which folder should you upload the MIB file?
- A. /etc/sf/DCEALERT.MIB
- B. /etc/sf/DCMIB.ALERT
- C. system/etc/DCEALERT.MIB
- D. /sf/etc/DCEALERT.MIB
Answer: A
NEW QUESTION # 134
......
300-710 Deluxe Study Guide with Online Test Engine: https://www.actual4dumps.com/300-710-study-material.html
300-710 Test Prep Training Practice Exam Questions Practice Tests: https://drive.google.com/open?id=1LNVH3xuvdbg_LrJhEqIQ_I-5wgebITSL