SNCF 300-710 B
|
|
Title of test:
![]() SNCF 300-710 B Description: Securing Networks with Cisco Firewalls |



| New Comment |
|---|
NO RECORDS |
|
A user within an organization opened a malicious file on a workstation which in turn caused a ransomware attack on the network. What should be configured within the Cisco FMC to ensure the file is tested for viruses on a sandbox system?. Spero analysis. capacity handling. local malware analysis. dynamic analysis. An engineer configures a network discovery policy on Cisco FMC. Upon configuration, it is noticed that excessive and misleading events are filling the database and overloading the Cisco FMC. A monitored NAT device is executing multiple updates of its operating system in a short period of time. What configuration change must be made to alleviate this issue?. Exclude load balancers and NAT devices. Leave default networks. Increase the number of entries on the NAT device. Change the method to TCP/SYN. A network administrator notices that remote access VPN users are not reachable from inside the network. It is determined that routing is configured correctly; however, return traffic is entering the firewall but not leaving it. What is the reason for this issue?. A manual NAT exemption rule does not exist at the top of the NAT table. An external NAT IP address is not configured. An external NAT IP address is configured to match the wrong interface. An object NAT exemption rule does not exist at the top of the NAT table. An administrator is creating interface objects to better segment their network but is having trouble adding interfaces to the objects. What is the reason for this failure?. The interfaces are being used for NAT for multiple networks. The administrator is adding interfaces of multiple types. The administrator is adding an interface that is in multiple zones. The interfaces belong to multiple interface groups. An organization is using a Cisco FTD and Cisco ISE to perform identity-based access controls. A network administrator is analyzing the Cisco FTD events and notices that unknown user traffic is being allowed through the firewall. How should this be addressed to block the traffic while allowing legitimate user traffic?. Modify the Cisco ISE authorization policy to deny this access to the user. Modify Cisco ISE to send only legitimate usernames to the Cisco FTD. Add the unknown user in the Access Control Policy in Cisco FTD. Add the unknown user in the Malware & File Policy in Cisco FTD. What is the benefit of selecting the trace option for packet capture?. The option indicates whether the packet was dropped or successful. The option indicates whether the destination host responds through a different path. The option limits the number of packets that are captured. The option captures details of each packet. After deploying a network-monitoring tool to manage and monitor networking devices in your organization, you realize that you need to manually upload an MIB for the Cisco FMC. In which folder should you upload the MIB file?. /etc/sf/DCMIB.ALERT. /sf/etc/DCEALERT.MIB. /etc/sf/DCEALERT.MIB. system/etc/DCEALERT.MIB. Which command is run at the CLI when logged in to an FTD unit, to determine whether the unit is managed locally or by a remote FMC server?. system generate-troubleshoot. show configuration session. show managers. show running-config | include manager. Which command should be used on the Cisco FTD CLI to capture all the packets that hit an interface?. configure coredump packet-engine enable. capture-traffic. capture. capture WORD. How many report templates does the Cisco Firepower Management Center support?. 20. 10. 5. unlimited. Which action should be taken after editing an object that is used inside an access control policy?. Delete the existing object in use. Refresh the Cisco FMC GUI for the access control policy. Redeploy the updated configuration. Create another rule using a different object name. Which Cisco Firepower feature is used to reduce the number of events received in a period of time?. rate-limiting. suspending. correlation. thresholding. Which report template field format is available in Cisco FMC?. box lever chart. arrow chart. bar chart. benchmark chart. Which group within Cisco does the Threat Response team use for threat analysis and research?. Cisco Deep Analytics. OpenDNS Group. Cisco Network Response. Cisco Talos. Drag and drop the steps to restore an automatic device registration failure on the standby Cisco FMC from the left into the correct order on the right. Not all options are used. Select and Place: Enter the "configure manager add" command at the CLI of the affected device. Unregister the device from the standby Cisco FMC. Register the affected device on the active Cisco FMC. Enter the "configure manager delete" command at the CLI of the affected device. Register the affected device on the standby Cisco FMC. Unregister the device from the active Cisco FMC. Which CLI command is used to generate firewall debug messages on a Cisco Firepower?. system support firewall-engine-debug. system support ssl-debug. system support platform. system support dump-table. Which command-line mode is supported from the Cisco FMC CLI?. privileged. user. configuration. admin. Which command is entered in the Cisco FMC CLI to generate a troubleshooting file?. show running-config. show tech-support chassis. system support diagnostic-cli. sudo sf_troubleshoot.pl. Which CLI command is used to control special handling of ClientHello messages?. system support ssl-client-hello-tuning. system support ssl-client-hello-display. system support ssl-client-hello-force-reset. system support ssl-client-hello-reset. Which command is typed at the CLI on the primary Cisco FTD unit to temporarily stop running high-availability?. configure high-availability resume. configure high-availability disable. system support network-options. configure high-availability suspend. Which command must be run to generate troubleshooting files on an FTD?. system support view-files. sudo sf_troubleshoot.pl. system generate-troubleshoot all. show tech-support. Which two products are available as multipoint conferencing options in the CMR Premise platform? (Choose two.). Cisco Meeting Server. Cisco Expressway. Cisco Telepresence Multipoint Switch. Telepresence Server. Cisco VCS. What is a functionality of port objects in Cisco FMC?. to mix transport protocols when setting both source and destination port conditions in a rule. to represent protocols other than TCP, UDP, and ICMP. to represent all protocols in the same way. to add any protocol other than TCP or UDP for source port conditions in access control rules. What is the role of realms in the Cisco ISE and Cisco FMC integration?. AD definition. Cisco ISE context. TACACS+ database. Cisco Secure Firewall VDC. A network engineer is configuring URL Filtering on Cisco FTD. Which two port requirements on the FMC must be validated to allow communication with the cloud service? (Choose two.). outbound port TCP/443. inbound port TCP/80. outbound port TCP/8080. inbound port TCP/443. outbound port TCP/80. What is the maximum bit size that Cisco FMC supports for HTTPS certificates?. 1024. 8192. 4096. 2048. Which limitation applies to Cisco Firepower Management Center (FMC) dashboards in a multi-domain environment?. Child domains are not able to view dashboards that originate from an ancestor domain. Child domains have access to only a limited set of widgets from ancestor domains. Only the administrator of the top ancestor domain can view dashboards. Child domains cannot view dashboards that originate from an ancestor domain. Which two considerations must be made when deleting and re-adding devices while managing them via Cisco FMC? (Choose two.) A. B. C. D. E. An option to re-apply NAT and VPN policies during registration is available, so users do not need to re-apply the policies after registration is completed. Before re-adding the device in Cisco FMC, the manager must be added back. Once a device has been deleted, it must be reconfigured before it is re-added to the Cisco FMC. The Cisco FMC web interface prompts users to re-apply access control policies. There is no option to re-apply NAT and VPN policies during registration available, so users need to re-apply the policies after registration is completed. What is a behavior of a Cisco FMC database purge?. User login and history data are removed from the database if the User Activity check box is selected. Data is recovered from the device. The appropriate process is restarted. The specified data is removed from Cisco FMC and kept for two weeks. What is a result of enabling Cisco FTD clustering?. Existing connections are not universally maintained across a master failure for dynamic routing; failover causes disruption. Integrated Routing and Bridging (IRB) limitations/support do not behave this way on the master unit. Site-to-site VPN functionality is limited to the master unit, and all VPN connections are dropped if the master unit fails. Not all Firepower hardware appliances support clustering. An engineer currently has a Cisco FTD device registered to the Cisco FMC and is assigned the address of 10.10.50.12. The organization is upgrading the addressing schemes and there is a requirement to convert the addresses to a format that provides an adequate amount of addresses on the network. What should the engineer do to ensure that the new addressing takes effect and can be used for the Cisco FTD to Cisco FMC connection?. Update the IP addresses from IPv4 to IPv6 without deleting from Cisco FMC. Format and reregister the device to Cisco FMC. Cisco FMC does not support devices that use IPv4 IP addresses. Delete and reregister the device to Cisco FMC. Refer to the exhibit. An engineer is analyzing the Attacks Risk Report and finds that there are over 300 instances of new operating systems being seen on the network. How is the Firepower configuration updated to protect these new operating systems?. The administrator manually updates the policies. The administrator requests a Remediation Recommendation Report from Cisco Firepower. Cisco Firepower gives recommendations to update the policies. Cisco Firepower automatically updates the policies. After using Firepower for some time and learning about how it interacts with the network, an administrator is trying to correlate malicious activity with a user. Which widget should be configured to provide this visibility on the Cisco Firepower dashboards?. Current Sessions. Correlation Events. Current Status. Custom Analysis. An engineer is troubleshooting application failures through an FTD deployment. While using the FMC CLI, it has been determined that the traffic in question is not matching the desired policy. What should be done to correct this?. Use the system support firewall-engine-debug command to determine which rules the traffic matching and modify the rule accordingly. Use the system support firewall-engine-dump-user-identity-data command to change the policy and allow the application though the firewall. Use the system support application-identification-debug command to determine which rules the traffic matching and modify the rule accordingly. Use the system support network-options command to fine tune the policy. An engineer has been asked to show application usages automatically on a monthly basis and send the information to management. What mechanism should be used to accomplish this task?. reports. context explorer. dashboards. event viewer. A network administrator is configuring SNORT inspection policies and is seeing failed deployment messages in Cisco FMC. What information should the administrator generate for Cisco TAC to help troubleshoot?. A "troubleshoot" file for the device in question. A "show tech" file for the device in question. A "troubleshoot" file for the Cisco FMC. A "show tech" for the Cisco FMC. An engineer is troubleshooting a device that cannot connect to a web server. The connection is initiated from the Cisco FTD inside interface and attempting to reach 10.0.1.100 over the non-standard port of 9443. The host the engineer is attempting the connection from is at the IP address of 10.20.10.20. In order to determine what is happening to the packets on the network, the engineer decides to use the FTD packet capture tool. Which capture configuration should be used to gather the information needed to troubleshoot the issue?. A. B. C. D. A network engineer is receiving reports of users randomly getting disconnected from their corporate applications which traverse the data center FTD appliance. Network monitoring tools show that the FTD appliance utilization is peaking above 90% of total capacity. What must be done in order to further analyze this issue?. Use the Packet Export feature to save data onto external drives. Use the Packet Capture feature to collect real-time network traffic. Use the Packet Tracer feature for traffic policy analysis. Use the Packet Analysis feature for capturing network data. An administrator is attempting to remotely log into a switch in the data center using SSH and is unable to connect. How does the administrator confirm that traffic is reaching the firewall?. by performing a packet capture on the firewall. by attempting to access it from a different workstation. by running Wireshark on the administrator's PC. by running a packet tracer on the firewall. IT management is asking the network engineer to provide high-level summary statistics of the Cisco FTD appliance in the network. The business is approaching a peak season so the need to maintain business uptime is high. Which report type should be used to gather this information?. Risk Report. SNMP Report. Standard Report. Malware Report. There are several devices on a network that are considered critical and need to be placed into the ISE database and a policy used for them. The organization does not want to use profiling. What must be done to accomplish this goal?. Enter the MAC address in the correct Endpoint Identity Group. Enter the IP address in the correct Endpoint Identity Group. Enter the IP address in the correct Logical Profile. Enter the MAC address in the correct Logical Profile. An administrator is setting up Cisco FirePower to send data to the Cisco Stealthwatch appliances. The NetFlow_Set_Parameters objet is already created, but NetFlow is not being sent to the flow collector. What must be done to prevent this from occurring?. Create a service identifier to enable the NetFlow service. Add the NetFlow_Send_Destination object to the configuration. Create a Security Intelligence object to send the data to Cisco Stealthwatch. Add the NetFlow_Add_Destination object to the configuration. With a recent summer time change, system logs are showing activity that occurred to be an hour behind real time. Which action should be taken to resolve this issue?. Manually adjust the time to the correct hour on all managed devices. Configure the system clock settings to use NTP with Daylight Savings checked. Configure the system clock settings to use NTP. Manually adjust the time to the correct hour on the Cisco FMC. A network administrator notices that SI events are not being updated. The Cisco FTD device is unable to load all of the SI event entries and traffic is not being blocked as expected. What must be done to correct this issue?. Restart the affected devices in order to reset the configurations. Redeploy configurations to affected devices so that additional memory is allocated to the SI module. Replace the affected devices with devices that provide more memory. Manually update the SI event entries to that the appropriate traffic is blocked. Refer to the exhibit. What must be done to fix access to this website while preventing the same communication to all other websites?. Create an intrusion policy rule to have Snort allow port 80 to only 172.1.1.50. Create an intrusion policy rule to have Snort allow port 443 to only 172.1.1.50. Create an access control policy rule to allow port 443 to only 172.1.1.50. Create an access control policy rule to allow port 80 to only 172.1.1.50. A connectivity issue is occurring between a client and a server which are communicating through a Cisco Firepower device. While troubleshooting, a network administrator sees that traffic is reaching the server, but the client is not getting a response. Which step must be taken to resolve this issue without initiating traffic from the client?. Use packet-tracer to ensure that traffic is not being blocked by an access list. Use packet capture to ensure that traffic is not being blocked by an access list. Use packet capture to validate that the packet passes through the firewall and is NATed to the corrected IP address. Use packet-tracer to validate that the packet passes through the firewall and is NATed to the corrected IP address. A VPN user is unable to connect to web resources behind the Cisco FTD device terminating the connection. While troubleshooting, the network administrator determines that the DNS response are not getting through the Cisco FTD. What must be done to address this issue while still utilizing Snort IPS rules?. Uncheck the "Drop when Inline" box in the intrusion policy to allow the traffic. Modify the Snort rules to allow legitimate DNS traffic to the VPN users. Disable the intrusion rule thresholds to optimize the Snort processing. Decrypt the packet after the VPN flow so the DNS queries are not inspected. A Cisco FirePower administrator needs to configure a rule to allow a new application that has never been seen on the network. Which two actions should be selected to allow the traffic to pass without inspection? (Choose two.). permit. allow. reset. trust. monitor. An organization has a Cisco IPS running in inline mode and is inspecting traffic for malicious activity. When traffic is received by the Cisco IPS, if it is not dropped, how does the traffic get to its destination?. It is retransmitted from the Cisco IPS inline set. The packets are duplicated and a copy is sent to the destination. It is transmitted out of the Cisco IPS outside interface. It is routed back to the Cisco ASA interfaces for transmission. An engineer is investigating connectivity problems on Cisco Firepower that is using service group tags. Specific devices are not being tagged correctly, which is preventing clients from using the proper policies when going through the firewall. How is this issue resolved?. Use traceroute with advanced options. Use Wireshark with an IP subnet filter. Use a packet capture with match criteria. Use a packet sniffer with correct filtering. An organization must be able to ingest NetFlow traffic from their Cisco FTD device to Cisco Stealthwatch for behavioral analysis. What must be configured on the Cisco FTD to meet this requirement?. flexconfig object for NetFlow. interface object to export NetFlow. security intelligence object for NetFlow. variable set object for NetFlow. An engineer must build redundancy into the network and traffic must continuously flow if a redundant switch in front of the firewall goes down. What must be configured to accomplish this task?. redundant interfaces on the firewall cluster mode and switches. redundant interfaces on the firewall noncluster mode and switches. vPC on the switches to the interface mode on the firewall cluster. vPC on the switches to the span EtherChannel on the firewall cluster. A network administrator notices that inspection has been interrupted on all non-managed interfaces of a device. What is the cause of this?. The value of the highest MTU assigned to any non-management interface was changed. The value of the highest MSS assigned to any non-management interface was changed. A passive interface was associated with a security zone. Multiple inline interface pairs were added to the same inline interface. A network administrator needs to create a policy on Cisco Firepower to fast-path traffic to avoid Layer 7 inspection. The rate at which traffic is inspected must be optimized. What must be done to achieve this goal?. Enable the FXOS for multi-instance. Configure a prefilter policy. Configure modular policy framework. Disable TCP inspection. A network engineer is tasked with minimizing traffic interruption during peak traffic times. When the SNORT inspection engine is overwhelmed, what must be configured to alleviate this issue?. Enable IPS inline link state propagation. Enable Pre-filter policies before the SNORT engine failure. Set a Trust ALL access control policy. Enable Automatic Application Bypass. Which two features of Cisco AMP for Endpoints allow for an uploaded file to be blocked? (Choose two.). application blocking. simple custom detection. file repository. exclusions. application allow listing. Action required upon receiving a malware identification notification from AMP via Cisco Threat Response. Add the malicious file to the block list. Create a custom detection list to flag the file as low risk. Delete the notification and take no further action. Ignore the notification until multiple instances are reported. Which Cisco AMP for Endpoints policy is used only for monitoring endpoint activity?. Windows domain controller. audit. triage. protection. What is a valid Cisco AMP file disposition?. non-malicious. malware. known-good. pristine. In a Cisco AMP for Networks deployment, which disposition is returned if the cloud cannot be reached?. unavailable. unknown. clean. disconnected. Which two remediation options are available when Cisco FMC is integrated with Cisco ISE? (Choose two.). dynamic null route configured. DHCP pool disablement. quarantine. port shutdown. host shutdown. Which connector is used to integrate Cisco ISE with Cisco FMC for Rapid Threat Containment?. pxGrid. FTD RTC. FMC RTC. ISEGrid. What is the maximum SHA level of filtering that Threat Intelligence Director supports?. SHA-1024. SHA-4096. SHA-512. SHA-256. What is the advantage of having Cisco Firepower devices send events to Cisco Threat Response via the security services exchange portal directly as opposed to using syslog?. Firepower devices do not need to be connected to the Internet. An on-premises proxy server does not need to set up and maintained. All types of Firepower devices are supported. Supports all devices that are running supported versions. Which license type is required on Cisco ISE to integrate with Cisco FMC pxGrid?. apex. plus. base. mobility. |





