SNCF 300-710 C
|
|
Title of test:
![]() SNCF 300-710 C Description: Securing Networks with Cisco Firewalls |



| New Comment |
|---|
NO RECORDS |
|
What is a feature of Cisco AMP private cloud?. It disables direct connections to the public cloud. It supports security intelligence filtering. It support anonymized retrieval of threat intelligence. It performs dynamic analysis. Which feature within the Cisco FMC web interface allows for detecting, analyzing, and blocking malware in network traffic?. intrusion and file events. Cisco AMP for Networks. file policies. Cisco AMP for Endpoints. A network administrator discovers that a user connected to a file server and downloaded a malware file. The Cisco FMC generated an alert for the malware event, however the user still remained connected. Which Cisco AMP file rule action within the Cisco FMC must be set to resolve this issue?. Malware Cloud Lookup. Reset Connection. Detect Files. Local Malware Analysis. An engineer has been tasked with using Cisco FMC to determine if files being sent through the network are malware. Which two configuration tasks must be performed to achieve this file lookup? (Choose two.). The Cisco FMC needs to include a SSL decryption policy. The Cisco FMC needs to connect to the Cisco AMP for Endpoints service. The Cisco FMC needs to connect to the Cisco ThreatGrid service directly for sandboxing. The Cisco FMC needs to connect with the FireAMP Cloud. The Cisco FMC needs to include a file inspection policy for malware lookup. A network engineer wants to add a third-party threat feed into the Cisco FMC for enhanced threat detection. Which action should be taken to accomplish this goal?. Enable Rapid Threat Containment using REST APIs. Enable Rapid Threat Containment using STIX and TAXII. Enable Threat Intelligence Director using REST APIs. Enable Threat Intelligence Director using STIX and TAXII. A network engineer is logged into the Cisco AMP for Endpoints console and sees a malicious verdict for an identified SHA-256 hash. Which configuration is needed to mitigate this threat?. Add the hash to the simple custom detection list. Use regular expressions to block the malicious file. Enable a personal firewall in the infected endpoint. Add the hash from the infected endpoint to the network block list. A network administrator is concerned about the high number of malware files affecting users' machines. What must be done within the access control policy in Cisco FMC to address this concern?. Create an intrusion policy and set the access control policy to block. Create an intrusion policy and set the access control policy to allow. Create a file policy and set the access control policy to allow. Create a file policy and set the access control policy to block. Within an organization’s high availability environment where both firewalls are passing traffic, traffic must be segmented based on which department it is destined for. Each department is situated on a different LAN. What must be configured to meet these requirements?. redundant interfaces. span EtherChannel clustering. high availability active/standby firewalls. multi-instance firewalls. What is a result of enabling Cisco FTD clustering?. For the dynamic routing feature, if the master unit fails, the newly elected master unit maintains all existing connections. Integrated Routing and Bridging is supported on the master unit. Site-to-site VPN functionality is limited to the master unit, and all VPN connections are dropped if the master unit fails. All Firepower appliances can support Cisco FTD clustering. A network security engineer must replace a faulty Cisco FTD device in a high availability pair. Which action must be taken while replacing the faulty unit?. Ensure that the faulty Cisco FTD device remains registered to the Cisco FMC. Shut down the active Cisco FTD device before powering up the replacement unit. Shut down the Cisco FMC before powering up the replacement unit. Unregister the faulty Cisco FTD device from the Cisco FMC. An administrator is optimizing the Cisco FTD rules to improve network performance, and wants to bypass inspection for certain traffic types to reduce the load on the Cisco FTD. Which policy must be configured to accomplish this goal?. intrusion. prefilter. URL filtering. identity. A Cisco FTD has two physical interfaces assigned to a BVI. Each interface is connected to a different VLAN on the same switch. Which firewall mode is the Cisco FTD set up to support?. high availability clustering. active/active failover. transparent. routed. An organization is migrating their Cisco ASA devices running in multicontext mode to Cisco FTD devices. Which action must be taken to ensure that each context on the Cisco ASA is logically separated in the Cisco FTD devices?. Configure a container instance in the Cisco FTD for each context in the Cisco ASA. Add the Cisco FTD device to the Cisco ASA port channels. Configure the Cisco FTD to use port channels spanning multiple networks. Add a native instance to distribute traffic to each Cisco FTD context. An engineer wants to change an existing transparent Cisco FTD to routed mode. The device controls traffic between two network segments. Which action is mandatory to allow hosts to reestablish communication between these two segments after the change?. Remove the existing dynamic routing protocol settings. Configure multiple BVIs to route between segments. Assign unique VLAN IDs to each firewall interface. Implement non-overlapping IP subnets on each segment. An engineer installs a Cisco FTD device and wants to inspect traffic within the same subnet passing through a firewall and inspect traffic destined to the Internet. Which configuration will meet this requirement?. transparent firewall mode with IRB only. routed firewall mode with BVI and routed interfaces. transparent firewall mode with multiple BVIs. routed firewall mode with routed interfaces only. A network administrator is deploying a Cisco IPS appliance and needs it to operate initially without affecting traffic flows. It must also collect data to provide a baseline of unwanted traffic before being reconfigured to drop it. Which Cisco IPS mode meets these requirements?. failsafe. inline tap. promiscuous. bypass. A network administrator is implementing an active/passive high availability Cisco FTD pair. When adding the high availability pair, the administrator cannot select the secondary peer. What is the cause?. The second Cisco FTD is not the same model as the primary Cisco FTD. An high availability license must be added to the Cisco FMC before adding the high availability pair. The failover link must be defined on each Cisco FTD before adding the high availability pair. Both Cisco FTD devices are not at the same software version. An administrator is configuring their transparent Cisco FTD device to receive ERSPAN traffic from multiple switches on a passive port, but the Cisco FTD is not processing the traffic. What is the problem?. The switches do not have Layer 3 connectivity to the FTD device for GRE traffic transmission. The switches were not set up with a monitor session ID that matches the flow ID defined on the Cisco FTD. The Cisco FTD must be in routed mode to process ERSPAN traffic. The Cisco FTD must be configured with an ERSPAN port not a passive port. What is an advantage of adding multiple inline interface pairs to the same inline interface set when deploying an asynchronous routing configuration?. Allows the IPS to identify inbound and outbound traffic as part of the same traffic flow. The interfaces disable autonegotiation and interface speed is hard coded set to 1000 Mbps. Allows traffic inspection to continue without interruption during the Snort process restart. The interfaces are automatically configured as a media-independent interface crossover. A network administrator cannot select the link to be used for failover when configuring an active/passive HA Cisco FTD pair. Which configuration must be changed before setting up the high availability pair?. An IP address in the same subnet must be added to each Cisco FTD on the interface. The interface name must be removed from the interface on each Cisco FTD. The name Failover must be configured manually on the interface on each Cisco FTD. The interface must be configured as part of a LACP Active/Active EtherChannel. Refer to the exhibit. Which action resolves intermittent connectivity observed with the SNMP trap rackets?. Decrease the committed burst size of the mgmt class map. Increase the CIR of the mgmt class map. Add one new entry in the ACL 120 to permit the UDP port 161. Add a new class map to match TCP traffic. Which firewall design will allow it to forward traffic at layers 2 and 3 for the same subnet?. routed mode. Cisco Firepower Threat Defense mode. transparent mode. integrated routing and bridging. An organization is configuring a new Cisco Firepower High Availability deployment. Which action must be taken to ensure that failover is as seamless as possible to end users?. Set the same FQDN for both chassis. Set up a virtual failover MAC address between chassis. Load the same software version on both chassis. Use a dedicated stateful link between chassis. A company is in the process of deploying intrusion prevention with Cisco FTDs managed by a Cisco FMC. An engineer must configure policies to detect potential intrusions but not block the suspicious traffic. Which action accomplishes this task?. Configure IPS mode when creating or editing a policy rule under the Cisco FMC Intrusion tab in Access Policies section by checking the “Drop when inline” option. Configure IPS mode when creating or editing a policy rule under the Cisco FMC Intrusion tab in Access Policies section by unchecking the “Drop when inline” option. Configure IDS mode when creating or editing a policy rule under the Cisco FMC Intrusion tab in Access Policies section by checking the “Drop when inline” option. Configure IDS mode when creating or editing a policy rule under the Cisco FMC Intrusion tab in Access Policies section by unchecking the “Drop when inline” option. An engineer is using the configure manager add Cisc404225383 command to add a new Cisco FTD device to the Cisco FMC; however, the device is not being added. Why is this occurring?. DONOTRESOLVE must be added to the command. The IP address used should be that of the Cisco FTD, not the Cisco FMC. The registration key is missing from the command. The NAT ID is required since the Cisco FMC is behind a NAT device. An organization does not want to use the default Cisco Firepower block page when blocking HTTP traffic. The organization wants to include information about its policies and procedures to help educate the users whenever a block occurs. Which two steps must be taken to meet these requirements? (Choose two.). Edit the HTTP request handling in the access control policy to customized block. Modify the system-provided block page result using Python. Create HTML code with the information for the policies and procedures. Change the HTTP response in the access control policy to custom. Write CSS code with the information for the policies and procedures. A company has many Cisco FTD devices managed by a Cisco FMC. The security model requires that access control rule logs be collected for analysis. The security engineer is concerned that the Cisco FMC will not be able to process the volume of logging that will be generated. Which configuration addresses concern this?. Send Cisco FTD connection events directly to a SIEM system and forward security events from Cisco FMC to the SIEM system for storage and analysis. Send Cisco FTD connection events and security events directly to SIEM system for storage and analysis. Send Cisco FTD connection events and security events to a cluster of Cisco FMC devices for storage and analysis. Send Cisco FTD connection events and security events to Cisco FMC and configure it to forward logs to SIEM for storage and analysis. A network administrator reviews the file report for the last month and notices that all file types, except exe, show a disposition of unknown. What is the cause of this issue?. Only Spero file analysis is enabled. The Cisco FMC cannot reach the Internet to analyze files. A file policy has not been applied to the access policy. The malware license has not been applied to the Cisco FTD. An engineer wants to connect a single IP subnet through a Cisco FTD firewall and enforce policy. There is a requirement to present the internal IP subnet to the outside as a different IP address. What must be configured to meet these requirements?. Configure the Cisco FTD firewall in routed mode with NAT enabled. Configure the upstream router to perform NAT. Configure the Cisco FTD firewall in transparent mode with NAT enabled. Configure the downstream router to perform NAT. A security engineer is configuring a remote Cisco FTD that has limited resources and internet bandwidth. Which malware action and protection option should be configured to reduce the requirement for cloud lookups?. Block File action and local malware analysis. Malware Cloud Lookup and dynamic analysis. Block Malware action and dynamic analysis. Block Malware action and local malware analysis. An administrator must use Cisco FMC to install a backup route within the Cisco FTD to route traffic in case of a routing failure with primary route. Which action accomplish this task?. Install the static backup route and modify the metric to be less than the primary route. Use a default route in the FMC instead of having multiple routes contending for priority. Configure EIGRP routing on the FMC to ensure that dynamic routes are always updated. Create the backup route and use route tracking on both routes to a destination IP address in the network. An engineer is modifying an access control policy to add a rule to inspect all DNS traffic that passes through the firewall. After making the change and deploying the policy, they see that DNS traffic is not being inspected by the Snort engine. What is the problem?. The action of the rule is set to trust instead of allow. The rule is configured with the wrong setting for the source port. The rule must define the source network for inspection as well as the port. The rule must specify the security zone that originates the traffic. A network administrator configured a NAT policy that translates a public IP address to an internal web server IP address. An access policy has also been created that allows any source to reach the public IP address on port 80. The web server is still not reachable from the Internet on port 80. Which configuration change is needed?. The NAT policy must be modified to translate the source IP address as well as destination IP address. The access policy must allow traffic to the internal web server IP address. The intrusion policy must be disabled for port 80. The access policy rule must be configured for the action trust. An administrator is adding a new URL-based category feed to the Cisco FMC for use within the policies. The intelligence source does not use STIX, but instead uses a .txt file format. Which action ensures that regular updates are provided?. Add a URL source and select the flat file type within Cisco FMC. Add a TAXII feed source and input the URL for the feed. Upload the .txt file and configure automatic updates using the embedded URL. Convert the .txt file to STIX and upload it to the Cisco FMC. An engineer is configuring Cisco FMC and wants to limit the time allowed for processing packets through the interface. However, if the time is exceeded, the configuration must allow packets to bypass detection. What must be configured on the Cisco FMC to accomplish this task?. Cisco ISE Security Group Tag. Automatic Application Bypass. Inspect Local Traffic Bypass. Fast-Path Rules Bypass. An engineer must define a URL object on Cisco FMC. What is the correct method to specify the URL without performing SSL inspection?. Include all URLs from CRL Distribution Points. Use Subject Common Name value. Specify all subdomains in the object group. Specify the protocol in the object. An organization recently implemented a transparent Cisco FTD in their network. They must ensure that the device does not respond to insecure SSL/TLS protocols. Which action accomplishes this task?. Modify the device’s settings using the device management feature within Cisco FMC to force only secure protocols. Use the Cisco FTD platform policy to change the minimum SSL version on the device to TLS 1.2. Enable the UCAPL/CC compliance on the device to support only the most secure protocols available. Configure a FlexConfig object to disable any insecure TLS protocols on the Cisco FTD device. A network administrator is migrating from a Cisco ASA to a Cisco FTD. EIGRP is configured on the Cisco ASA but it is not available in the Cisco FMC. Which action must the administrator take to enable this feature on the Cisco FTD?. Configure EIGRP parameters using FlexConfig objects. Add the command feature eigrp via the FTD CLI. Create a custom variable set and enable the feature in the variable set. Enable advanced configuration options in the FMC. A Cisco FMC administrator wants to configure fastpathing of trusted network traffic to increase performance. In which type of policy would the administrator configure this feature?. Network Analysis policy. Identity policy. Prefilter policy. Intrusion policy. Drag and drop the configuration steps from the left into the sequence on the right to enable external authentication on Cisco FMC to a RADIUS server. Select Authentication Method and RADIUS. Configure the primary and secondary servers and user roles. Select Users and External Authentication. Add External Authentication Object. An engineer is creating an URL object on Cisco FMC. How must it be configured so that the object will match for HTTPS traffic in an access control policy?. Specify the protocol to match (HTTP or HTTPS). Use the FQDN including the subdomain for the website. Use the subject common name from the website certificate. Define the path to the individual webpage that uses HTTPS. Which action must be taken on the Cisco FMC when a packet bypass is configured in case the Snort engine is down or a packet takes too long to process?. Enable Automatic Application Bypass. Add a Bypass Threshold policy for failures. Configure Fastpath rules to bypass inspection. Enable Inspect Local Router Traffic. An engineer is configuring multiple Cisco FTD appliances for use in the network. Which rule must the engineer follow while defining interface objects in Cisco FMC for use with interfaces across multiple devices?. Two security zones can contain the same interface. Interface groups can contain interfaces from many devices. An interface cannot belong to a security zone and an interface group. Interface groups can contain multiple interface types. An administrator is adding a QoS policy to a Cisco FTD deployment. When a new rule is added to the policy and QoS is applied on “Interfaces in Destination Interface Objects”, no interface objects are available. What is the problem?. The FTD is out of available resources for use, so QoS cannot be added. The network segments that the interfaces are on do not have contiguous IP space. A conflict exists between the destination interface types that is preventing QoS from being added. QoS is available only on routed interfaces, and this device is in transparent mode. A network administrator wants to block traffic to a known malware site at https:/www.badsite.com and all subdomains while ensuring no packets from any internal client are sent to that site. Which type of policy must the network administrator use to accomplish this goal?. Access Control policy with URL filtering. Prefilter policy. DNS policy. SSL policy. A network security engineer must export packet captures from the Cisco FMC web browser while troubleshooting an issue. When navigating to the address https:///capture/CAPI/pcap/test.pcap, an error 403: Forbidden is given instead of the PCAP file. Which action must the engineer take to resolve this issue?. Disable the proxy setting on the browser. Disable the HTTPS server and use HTTP instead. Use the Cisco FTD IP address as the proxy server setting on the browser. Enable the HTTPS server for the device platform policy. An analyst is investigating a potentially compromised endpoint within the network and pulls a host report for the endpoint in question to collect metrics and documentation. What information should be taken from this report for the investigation?. client applications by user, web applications, and user connections. number of attacked machines, sources of the attack, and traffic patterns. threat detections over time and application protocols transferring malware. intrusion events, host connections, and user sessions. An engineer must investigate a connectivity issue and decides to use the packet capture feature on Cisco FTD. The goal is to see the real packet going through the Cisco FTD device and see Snort detection actions as a part of the output. After the capture-traffic command is issued, only the packets are displayed. Which action resolves this issue?. Specify the trace using the -T option after the capture-traffic command. Perform the trace within the Cisco FMC GUI instead of the Cisco FMC CLI. Use the verbose option as a part of the capture-traffic command. Use the capture command and specify the trace option to get the required information. An analyst using the security analyst account permissions is trying to view the Correlations Events Widget but is not able to access it. However, other dashboards are accessible. Why is this occurring?. The widget is configured to display only when active events are present. The security analyst role does not have permission to view this widget. An API restriction within the Cisco FMC is preventing the widget from displaying. The widget is not configured within the Cisco FMC. An engineer is troubleshooting connectivity to the DNS servers from hosts behind a new Cisco FTD device. The hosts cannot send DNS queries to servers in the DMZ. Which action should the engineer take to troubleshoot this issue using the real DNS packets?. Use the packet capture tool to check where the traffic is being blocked and adjust the access control or intrusion policy as needed. Use the Connection Events dashboard to check the block reason and adjust the inspection policy as needed. Use the packet tracer tool to determine at which hop the packet is being dropped. Use the show blocks command in the Threat Defense CLI tool and create a policy to allow the blocked traffic. An engineer must configure a Cisco FMC dashboard in a child domain. Which action must be taken so that the dashboard is visible to the parent domain?. Adjust policy inheritance settings. Add a separate widget. Create a copy of the dashboard. Add a separate tab. A network engineer sets up a secondary Cisco FMC that is integrated with Cisco Security Packet Analyzer. What occurs when the secondary Cisco FMC synchronizes with the primary Cisco FMC?. The existing configuration for integration of the secondary Cisco FMC the Cisco Security Packet Analyzer is overwritten. The synchronization between the primary and secondary Cisco FMC fails. The existing integration configuration is replicated to the primary Cisco FMC. The secondary Cisco FMC must be reintegrated with the Cisco Security Packet Analyzer after the synchronization. An analyst is reviewing the Cisco FMC reports for the week. They notice that some peer-to-peer applications are being used on the network and they must identify which poses the greatest risk to the environment. Which report gives the analyst this information?. User Risk Report. Advanced Malware Risk Report. Attacks Risk Report. Network Risk Report. An administrator receives reports that users cannot access a cloud-hosted web server. The access control policy was recently updated with several new policy additions and URL filtering. What must be done to troubleshoot the issue and restore access without sacrificing the organization's security posture?. Download a PCAP of the traffic attempts to verify the blocks and use the flexconfig objects to create a rule that allows only the required traffic to the destination server. Identify the blocked traffic in the Cisco FMC connection events to validate the block, and modify the policy to allow the traffic to the web server. Create a new access control policy rule to allow ports 80 and 443 to the FQDN of the web server. Verify the blocks using the packet capture tool and create a rule with the action monitor for the traffic. An engineer is reviewing a ticket that requests to allow traffic for some devices that must connect to a server over 8699/udp. The request mentions only one IP address, 172.16.18.15, but the requestor asked for the engineer to open the port for all machines that have been trying to connect to it over the last week. Which action must the engineer take to troubleshoot this issue?. Use the context explorer to see the application blocks by protocol. Filter the connection events by the source port 8699/udp. Filter the connection events by the destination port 8699/udp. Use the context explorer to see the destination port blocks. While integrating Cisco Umbrella with Cisco Threat Response, a network security engineer wants to automatically push blocking of domains from the Cisco Threat Response interface to Cisco Umbrella. Which API meets this requirement?. investigate. REST. reporting. enforcement. An engineer is working on a LAN switch and has noticed that its network connection to the inline Cisco IPS has gone down. Upon troubleshooting, it is determined that the switch is working as expected. What must have been implemented for this failure to occur?. The upstream router has a misconfigured routing protocol. Link-state propagation is enabled. The Cisco IPS has been configured to be in fail-open mode. The Cisco IPS is configured in detection mode. The CIO asks a network administrator to present to management a dashboard that shows custom analysis tables for the top DNS queries URL category statistics, and the URL reputation statistics. Which action must the administrator take to quickly produce this information for management?. Run the Attack report and filter on DNS to show this information. Create a new dashboard and add three custom analysis widgets that specify the tables needed. Modify the Connection Events dashboard to display the information in a view for management. Copy the intrusion events dashboard tab and modify each widget to show the correct charts. Which Cisco FMC report gives the analyst information about the ports and protocols that are related to the configured sensitive network for analysis?. Malware Report. Host Report. Firepower Report. Network Report. An engineer is investigating connectivity problems on Cisco Firepower for a specific SGT. Which command allows the engineer to capture real packets that pass through the firewall using an SGT of 64?. capture CAP type inline-tag 64 match ip any any. capture CAP match 64 type inline-tag ip any any. capture CAP headers-only type inline-tag 64 match ip any any. capture CAP buffer 64 match ip any any. A company is in the process of deploying intrusion protection with Cisco FTDs managed by a Cisco FMC. Which action must be selected to enable fewer rules detect only critical conditions and avoid false positives?. Connectivity Over Security. Balanced Security and Connectivity. Maximum Detection. No Rules Active. An engineer wants to add an additional Cisco FTD Version 6.2.3 device to their current 6.2.3 deployment to create a high availability pair. The currently deployed Cisco FTD device is using local management and identical hardware including the available port density to enable the failover and stateful links required in a proper high availability deployment. Which action ensures that the environment is ready to pair the new Cisco FTD with the old one?. Change from Cisco FDM management to Cisco FMC management on both devices and register them to FMC. Ensure that the two devices are assigned IP addresses from the 169.254.0.0/16 range for failover interfaces. Factory reset the current Cisco FTD so that it can synchronize configurations with the new Cisco FTD device. Ensure that the configured DNS servers match on the two devices for name resolution. Refer to the exhibit. What is the effect of the existing Cisco FMC configuration?. The remote management port for communication between the Cisco FMC and the managed device changes to port 8443. The managed device is deleted from the Cisco FMC. The SSL-encrypted communication channel between the Cisco FMC and the managed device becomes plain-text communication channel. The management connection between the Cisco FMC and the Cisco FTD is disabled. Remote users who connect via Cisco AnyConnect to the corporate network behind a Cisco FTD device report that they get no audio when calling between remote users using their softphones. These same users can call internal users on the corporate network without any issues. What is the cause of this issue?. FTD has no NAT policy that allows outside to outside communication. Split tunneling is enabled for the Remote Access VPN on FTD. The hairpinning feature is not available on FTD. The Enable Spoke to Spoke Connectivity through Hub option is not selected on FTD. A network administrator is troubleshooting access to a website hosted behind a Cisco FTD device. External clients cannot access the web server via HTTPS. The IP address configured on the web server is 192.168.7.46. The administrator is running the command capture CAP interface outside match ip any 192.168.7.46 255.255.255.255 but cannot see any traffic in the capture. Why is this occurring?. The capture must use the public IP address of the web server. The packet capture shows only blocked traffic. The FTD has no route to the web server. The access policy is blocking the traffic. |





