option
Questions
ayuda
daypo
search.php

SNCF 300-710 D

COMMENTS STATISTICS RECORDS
TAKE THE TEST
Title of test:
SNCF 300-710 D

Description:
Securing Networks with Cisco Firewalls

Creation Date: 2026/09/05

Category: Others

Number of questions: 60

Rating:(0)
Share the Test:
Nuevo ComentarioNuevo Comentario
New Comment
NO RECORDS
Content:

An engineer must deploy a Cisco FTD appliance via Cisco FMC to span a network segment to detect malware and threats. When setting the Cisco FTD interface mode, which sequence of actions meets this requirement?. Set to passive, and configure an access control policy with an intrusion policy and a file policy defined. Set to passive, and configure an access control policy with a prefilter policy defined. Set to none, and configure an access control policy with an intrusion policy and a file policy defined. Set to none, and configure an access control policy with a prefilter policy defined.

An engineer wants to perform a packet capture on the Cisco FTD to confirm that the host using IP address 192.168.100.100 has the MAC address of 1234.5678.901 to help troubleshoot a connectivity issue. What is the correct tcpdump command syntax to ensure that the MAC address appears in the packet capture output?. -w capture.pcap -s 1518 host 192.168.100.100 ether. -w capture.pcap -s 1518 host 192.168.100.100 mac. -nm src 192.168.100.100. -ne src 192.168.100.100.

What must be implemented on Cisco Firepower to allow multiple logical devices on a single physical device to have access to external hosts?. Add at least two container instances from the same module. Set up a cluster control link between all logical devices. Define VLAN subinterfaces for each logical device. Add one shared management interface on all logical devices.

An engineer must configure a Cisco FMC dashboard in a multidomain deployment. Which action must the engineer take to edit a report template from an ancestor domain?. Copy it to the current domain. Add it as a separate widget. Change the document attributes. Assign themselves ownership of it.

A company is deploying intrusion protection on multiple Cisco FTD appliances managed by Cisco FMC. Which system-provided policy must be selected if speed and detection are priorities?. Maximum Detection. Connectivity Over Security. Security Over Connectivity. Balanced Security and Connectivity.

An engineer integrates Cisco FMC and Cisco ISE using pxGrid. Which role is assigned for Cisco FMC?. server. controller. publisher. client.

A company wants a solution to aggregate the capacity of two Cisco FTD devices to make the best use of resources such as bandwidth and connections per second. Which order of steps must be taken across the Cisco FTDs with Cisco FMC to meet this requirement?. Add members to the Cisco FMC, configure Cisco FTD interfaces, create the cluster in Cisco FMC, and configure cluster members in Cisco FMC. Add members to Cisco FMC, configure Cisco FTD interfaces in Cisco FMC, configure cluster members in Cisco FMC, create cluster in Cisco FMC, and configure cluster members in Cisco FMC. Configure the Cisco FTD interfaces, add members to FMC, configure cluster members in FMC, and create cluster in Cisco FMC. Configure the Cisco FTD interfaces and cluster members, add members to Cisco FMC, and create the cluster in Cisco FMC.

The administrator notices that there is malware present with an .exe extension and needs to verify if any of the systems on the network are running the executable file. What must be configured within Cisco AMP for Endpoints to show this data?. vulnerable software. file analysis. threat root cause. prevalence.

Upon detecting a flagrant threat on an endpoint, which two technologies instruct Cisco Identity Services Engine to contain the infected endpoint either manually or automatically? (Choose two.). Cisco Stealthwatch. Cisco ASA 5500 Series. Cisco FMC. Cisco ASR 7200 Series. Cisco AMP.

A security engineer found a suspicious file from an employee email address and is trying to upload it for analysis, however the upload is failing. The last registration status is still active. What is the cause for this issue?. Cisco AMP for Networks is unable to contact Cisco Threat Grid on premise. There is a host limit set. The user agent status is set to monitor. Cisco AMP for Networks is unable to contact Cisco Threat Grid Cloud.

What is the role of the casebook feature in Cisco Threat Response?. pulling data via the browser extension. alert prioritization. sharing threat analysis. triage automation with alerting.

An engineer is troubleshooting a file that is being blocked by a Cisco FTD device on the network. The user is reporting that the file is not malicious. Which action does the engineer take to identify the file and validate whether or not it is malicious?. Identify the file in the intrusion events and submit it to Threat Grid for analysis. Use FMC file analysis to look for the file and select Analyze to determine its disposition. Use the context explorer to find the file and download it to the local machine for investigation. Right click the connection event and send the file to AMP for Endpoints to see if the hash is malicious.

Which protocol is needed to exchange threat details in rapid threat containment on Cisco FMC?. SGT. SNMP v3. BFD. pxGrid.

The network administrator wants to enhance the network security posture by enabling machine learning for malware detection due to a concern with suspicious Microsoft executable file types that were seen while creating monthly security reports for the CIO. Which feature must be enabled to accomplish this goal?. Ethos. static analysis. Spero. dynamic analysis.

What is the RTC workflow when the infected endpoint is identified?. Cisco ISE instructs Cisco AMP to contain the infected endpoint. Cisco ISE instructs Cisco FMC to contain the infected endpoint. Cisco FMC instructs Cisco ISE to contain the infected endpoint. Cisco AMP instructs Cisco FMC to contain the infected endpoint.

A network administrator is configuring a Cisco AMP public cloud instance and wants to capture infections and polymorphic variants of a threat to help detect families of malware. Which detection engine meets this requirement?. Ethos. Tetra. RBAC. Spero.

Due to an increase in malicious events, a security engineer must generate a threat report to include intrusion events, malware events, and security intelligence events. How is this information collected in a single report?. Run the default Firepower report. Create a Custom report. Generate a malware report. Export the Attacks Risk report.

A network administrator is trying to convert from LDAP to LDAPS for VPN user authentication on a Cisco FTD. Which action must be taken on the Cisco FTD objects to accomplish this task?. Identify the LDAPS cipher suite and use a Cipher Suite List object to define the Cisco FTD connection requirements. Modify the Policy List object to define the session requirements for LDAPS. Add a Key Chain object to acquire the LDAPS certificate. Create a Certificate Enrollment object to get the LDAPS certificate needed.

A network administrator is configuring an FTD in transparent mode. A bridge group is set up and an access policy has been set up to allow all IP traffic. Traffic is not passing through the FTD. What additional configuration is needed?. An IP address must be assigned to the BVI. The security levels of the interfaces must be set. A default route must be added to the FTD. A mac-access control list must be added to allow all MAC addresses.

Which feature is supported by IRB on Cisco FTD devices?. redundant interface. high-availability cluster. dynamic routing protocol. EtherChannel interface.

A security analyst must create a new report within Cisco FMC to show an overview of the daily attacks, vulnerabilities, and connections. The analyst wants to reuse specific dashboards from other reports to create this consolidated one. Which action accomplishes this task?. Copy the Malware Report and modify the sections to pull components from other reports. Create a new dashboard object via Object Management to represent the desired views. Use the import feature in the newly created report to select which dashboards to add. Modify the Custom Workflows within the Cisco FMC to feed the desired data into the new report.

Refer to the exhibit. A systems administrator conducts a connectivity test to their SCCM server from a host machine and gets no response from the server. Which action ensures that the ping packets reach the destination and that the host receives replies?. Configure a custom Snort signature to allow ICMP traffic after inspection. Modify the Snort rules to allow ICMP traffic. Create an access control policy rule that allows ICMP traffic. Create an ICMP allow list and add the ICMP destination to remove it from the implicit deny list.

An administrator is setting up a Cisco FMC and must provide expert mode access for a security engineer. The engineer is permitted to use only a secured out-of-band network workstation with a static IP address to access the Cisco FMC. What must be configured to enable this access?. Enable SSH and define an access list. Enable HTTPS and SNMP under the Access List section. Enable SCP under the Access List section. Enable HTTP and define an access list.

A network administrator registered a new FTD to an existing FMC. The administrator cannot place the FTD in transparent mode. Which action enables transparent mode?. Deregister the FTD device from FMC and configure transparent mode via the CLI. Obtain an FTD model that supports transparent mode. Add a Bridge Group Interface to the FTD before transparent mode is configured. Assign an IP address to two physical interfaces.

A network engineer must provide redundancy between two Cisco FTD devices. The redundancy configuration must include automatic configuration, translation, and connection updates. After the initial configuration of the two appliances, which two steps must be taken to proceed with the redundancy configuration? (Choose two.). Configure the virtual MAC address on the failover link. Configure the failover link with stateful properties. Disable hellos on the inside interface. Ensure the high availability license is enabled. Configure the standby IP addresses.

An administrator is attempting to add a new FTD device to their FMC behind a NAT device with a NAT ID of NAT001 and a password of Cisco0123456789. The private IP address of the FMC server is 192.168.45.45, which is being translated to the public IP address of 209.165.200.225/27. Which command set must be used in order to accomplish this task?. configure manager add 209.165.200.225 255.255.255.224. configure manager add 209.165.200.225. configure manager add 209.165.200.225/27. configure manager add 192.168.45.45.

An engineer attempts to pull the configuration for a Cisco FTD sensor to review with Cisco TAC but does not have direct access to the CLI for the device. The CLI for the device is managed by Cisco FMC to which the engineer has access. Which action in Cisco FMC grants access to the CLI for the device?. Create a backup of the configuration within the Cisco FMC. Download the configuration file within the File Download section of Cisco FMC. Export the configuration using the Import/Export tool within Cisco FMC. Use the show run all command in the Cisco FTD CLI feature within Cisco FMC.

An engineer must add DNS-specific rules to the Cisco FTD intrusion policy. The engineer wants to use the rules currently in the Cisco FTD Snort database that are not already enabled but does not want to enable more than are needed. Which action meets these requirements?. Change the rules using the Generate and Use Recommendations feature. Change the rule state within the policy being used. Change the dynamic state of the rule within the policy. Change the base policy to Security over Connectivity.

A security engineer must deploy a Cisco FTD appliance as a bump in the wire to detect intrusion events without disrupting the flow of network traffic. Which two features must be configured to accomplish the task? (Choose two.). transparent mode. tap mode. bridged mode. inline set pair. passive interfaces.

A network administrator has converted a Cisco FTD from using LDAP to LDAPS for VPN authentication. The Cisco FMC can connect to the LDAPS server, but the Cisco FTD is not connecting. Which configuration must be enabled on the Cisco FTD?. The LDAPS must be allowed through the access control policy. The RADIUS server must be defined. SSL must be set to a use TLSv1.2 or lower. DNS servers must be defined for name resolution.

A security engineer is deploying a pair of primary and secondary Cisco FMC devices. The secondary must also receive updates from Cisco Talos. Which action achieves this goal?. Manually import rule updates onto the secondary Cisco FMC device. Force failover for the secondary Cisco FMC to synchronize the rule updates from the primary. Configure the primary Cisco FMC so that the rules are updated. Configure the secondary Cisco FMC so that it receives updates from Cisco Talos.

A security engineer must configure a Cisco FTD appliance to inspect traffic coming from the internet. The internet traffic will be mirrored from the Cisco Catalyst 9300 Switch. Which configuration accomplishes the task?. Set the firewall mode to routed. Set interface configuration mode to passive. Set the firewall mode to transparent. Set interface configuration mode to none.

Refer to the exhibit. An engineer is analyzing a Network Risk Report from Cisco FMC. Which application must the engineer take immediate action against to prevent unauthorized network use?. YouTube. TOR. Chrome. Kerberos.

An organization is implementing Cisco FTD using transparent mode in the network. Which rule in the default Access Control Policy ensures that this deployment does not create a loop in the network?. Multicast and broadcast packets are denied by default. STP BPDU packets are allowed by default. ARP inspection is enabled by default. ARP packets are allowed by default.

When a Cisco FTD device is configured in transparent firewall mode, on which two interface types can an IP address be configured? (Choose two.). Physical. EtherChannel. Subinterface. BVI. Diagnostic.

A security engineer needs to configure a network discovery policy on a Cisco FMC appliance and prevent excessive network discovery events from overloading the FMC database? Which action must be taken to accomplish this task?. Monitor only the default IPv4 and IPv6 network ranges. Configure NetFlow exporters for monitored networks. Change the network discovery method to TCP/SYN. Exclude load balancers and NAT devices in the policy.

An organization is installing a new Cisco FTD appliance in the network. An engineer is tasked with configuring access between two network segments within the same IP subnet. Which step is needed to accomplish this task?. Specify a name for the bridge group. Assign an IP address to the Bridge Virtual Interface. Permit BPDU packets to prevent loops. Add a separate bridge group for each segment.

An engineer defines a new rule while configuring an Access Control Policy. After deploying the policy, the rule is not working as expected and the hit counters associated with the rule are showing zero. What is causing this error?. An incorrect application signature was used in the rule. The wrong source interface for Snort was selected in the rule. The rule was not enabled after being created. Logging is not enabled for the rule.

An administrator needs to configure Cisco FMC to send a notification email when a data transfer larger than 10 MB is initiated from an internal host outside of standard business hours. Which Cisco FMC feature must be configured to accomplish this task?. file and malware policy. application detector. correlation policy. intrusion policy.

Which process should be checked when troubleshooting registration issues between Cisco FMC and managed devices to verify that secure communication is occurring?. fpcollect. dhclient. sfrmgr. sftunnel.

A security engineer must integrate an external feed containing STIX/TAXII data with Cisco FMC. Which feature must be enabled on the Cisco FMC to support this connection?. Threat Intelligence Director. Cisco Success Network. Security Intelligence Feeds. Cisco Secure Endpoint Integration.

A network administrator is configuring a site-to-site IPsec VPN to a router sitting behind a Cisco FTD. The administrator has configured an access policy to allow traffic to this device on UDP 500, 4500, and ESP. VPN traffic is not working. Which action resolves this issue?. Change the access policy to allow all ports. Enable IPsec Inspection on the access policy. Set the allow action in the access policy to trust. Modify the NAT policy to use the interface PAT.

When using Cisco Threat Response, which phase of the Intelligence Cycle publishes the results of the investigation?. processing. direction. dissemination. analysis.

A security engineer is adding three Cisco FTD devices to a Cisco FMC. Two of the devices have successfully registered to the Cisco FMC. The device that is unable to register is located behind a router that translates all outbound traffic to the router’s WAN IP address. Which two steps are required for this device to register to the Cisco FMC? (Choose two.). Reconfigure the Cisco FMC to use the device’s private IP address instead of the WAN address. Configure a NAT ID on both the Cisco FMC and the device. Reconfigure the Cisco FMC to use the device’s hostname instead of IP address. Remove the IP address defined for the device in the Cisco FMC. Add the port number being used for PAT on the router to the device’s IP address in the Cisco FMC.

An engineer is setting up a remote access VPN on a Cisco FTD device and wants to define which traffic gets sent over the VPN tunnel. Which named object type in Cisco FMC must be used to accomplish this task?. crypto map. split tunnel. access list. route map.

An engineer needs to configure remote storage on Cisco FMC. Configuration backups must be available from a secure location on the network for disaster recovery. Reports need to back up to a shared location that auditors can access with their Active Directory logins. Which strategy must the engineer use to meet these objectives?. Use NFS for both backups and reports. Use SSH for backups and NFS for reports. Use SMB for backups and NFS for reports. Use SMB for both backups and reports.

An engineer is configuring two new Cisco FTD devices to replace the existing high availability firewall pair in a highly secure environment. The information exchanged between the FTD devices over the failover link must be encrypted. Which protocol supports this on the Cisco FTD?. MACsec. IPsec. SSH. SSL.

A network engineer is deploying a Cisco Firepower 4100 appliance and must configure a multi-instance environment for high availability. Drag and drop the actions from the left into sequence on the right for this configuration. Add a MAC pool prefix and view the MAC addresses for the container instance interfaces. Configure interfaces. Add a high-availability pair. Add a resource profile for container instances. Add a Standalone Firepower Threat Defense for Cisco Secure Firewall Management Center.

A security engineer must configure policies for a recently deployed Cisco FTD. The security policy for the company dictates that when five or more connections from external sources are initiated within 2 minutes, there is cause for concern. Which type of policy must be configured in Cisco FMC to generate an alert when this condition is triggered?. application detector. access control. correlation. intrusion.

A network administrator is reviewing a weekly scheduled attacks risk report and notices a host that is flagged for an Impact 2 attack. Where should the administrator look within Cisco FMC to find out more relevant information about this host and attack?. Analysis > Lookup > Whois. Analysis > Correlation > Correlation Events. Analysis > Hosts > Vulnerabilities. Analysis > Hosts > Host Attributes.

A consultant is working on a project where the customer is upgrading from a single Cisco Firepower 2130 managed by FDM to a pair of Cisco Firepower 2130s managed by FMC for high availability. The customer wants the configuration of the existing device being managed by FDM to be carried over to FMC and then replicated to the additional device being added to create the high availability pair. Which action must the consultant take to meet this requirement?. The current FDM configuration must be configured by hand into FMC before the devices are registered. The current FDM configuration must be migrated to FMC using the Secure Firewall Migration Tool. The FTD configuration must be converted to ASA command format, which can then be migrated to FMC. The current FDM configuration will be converted automatically into FMC when the device registers.

A network administrator must create an EtherChannel interface on a new Cisco Firepower 9300 appliance registered with an FMC for high availability. Where must the administrator create the EtherChannel interface?. FMC GUI. FMC CLI. FTD CLI. FXOS CLI.

A network administrator is reviewing a monthly advanced malware risk report and notices a host that is listed as CnC Connected. Where must the administrator look within Cisco FMC to further determine if this host is infected with malware?. Analysis > Hosts > Indications of Compromise. Analysis > Hosts > Host Attributes. Analysis > Files > Malware Events. Analysis > Files > Network File Trajectory.

An engineer is configuring a Cisco FTD device to place on the Finance VLAN to provide additional protection for company financial data. The device must be deployed without requiring any changes on the end user workstations, which currently use DHCP to obtain an IP address. How must the engineer deploy the device to meet this requirement?. Deploy the device in transparent mode and enable the DHCP Server feature. Deploy the device in routed mode and enable the DHCP Relay feature. Deploy the device in transparent mode and allow DHCP traffic in the access control policies. Deploy the device in routed mode and allow DHCP traffic in the access control policies.

Which default action setting in a Cisco FTD Access Control Policy allows all traffic from an undefined application to pass without Snort inspection?. Network Discovery Only. Inherit from Base Policy. Intrusion Prevention. Trust All Traffic.

An engineer plans to reconfigure an existing Cisco FTD from transparent mode to routed mode. Which additional action must be taken to maintain communication between the two network segments?. Assign a unique VLAN ID for the interface in each segment. Update the IP addressing so that each segment is a unique IP subnet. Configure a NAT rule so that traffic between the segments is exempt from NAT. Deploy inbound ACLs on each interface to allow traffic between the segments.

Network users are experiencing intermittent issues with internet access. An engineer identified that the issue is being caused by NAT exhaustion. How must the engineer change the dynamic NAT configuration to provide internet access for more users without running out of resources?. Convert the dynamic auto NAT rule to dynamic manual NAT. Add an identity NAT rule to handle the overflow of users. Configure fallthrough to interface PAT on the Advanced tab. Define an additional static NAT for the network object in use.

An engineer is configuring a custom intrusion rule on Cisco FMC. The engineer needs the rule to search the payload or stream for the string "|44 78 97 13 2 0A|". Which keyword must the engineer use with this string to create an argument for packet inspection?. protected_content. content. data. metadata.

An engineer must investigate a connectivity issue from an endpoint behind a Cisco FTD device and a public DNS server. The endpoint cannot perform name resolution queries. Which action must the engineer perform to troubleshoot the issue by simulating real DNS traffic on the Cisco FTD while verifying the Snort verdict?. Use the Capture w/Trace wizard in Cisco FMC. Run the system support firewall-engine-debug command from the FTD CLI. Create a Custom Workflow in Cisco FMC. Perform a Snort engine capture using tcpdump from the FTD CLI.

When an engineer captures traffic on a Cisco Secure Firewall Threat Defense device to troubleshoot a connectivity problem, they receive a large amount of output data in the GUI tool. The engineer found that viewing the captures this way is time-consuming and difficult to sort and filter. Which file type must the engineer export the data in so that it can be reviewed using a tool built for this type of analysis?. NetFlow v9. PCAP. IPFIX. NetFlow v5.

Report abuse