option
Questions
ayuda
daypo
search.php

SNCF 300-710 E

COMMENTS STATISTICS RECORDS
TAKE THE TEST
Title of test:
SNCF 300-710 E

Description:
Securing Networks with Cisco Firewalls

Creation Date: 2026/09/06

Category: Others

Number of questions: 60

Rating:(0)
Share the Test:
Nuevo ComentarioNuevo Comentario
New Comment
NO RECORDS
Content:

An engineer is configuring a custom application detector for HTTP traffic and wants to import a file that was provided by a third party. Which type of files are advanced application detectors created and uploaded as?. Perl script. NBAR protocol. LUA script. Python program.

An engineer must deploy a Cisco Secure Firewall Threat Defense device. Management wants to examine traffic without requiring network changes that will disrupt end users. Corporate security policy requires the separation of management traffic from data traffic and the use of SSH over Telnet for remote administration. How must the device be deployed to meet these requirements?. in transparent mode with a management interface. in routed mode with a bridge virtual interface. in transparent mode with a data interface. in routed mode with a diagnostic interface.

A network administrator reviews the attack risk report and notices several low-impact attacks. What does this type of attack indicate?. All attacks are listed as low until manually recategorized. The host is not vulnerable to those attacks. The host is not within the administrator's environment. The attacks are not dangerous to the network.

What is a limitation to consider when running a dynamic routing protocol on a Cisco Secure Firewall Threat Defense device in IRB mode?. Only link-state routing protocols are supported. Only nonbridge interfaces are supported. Only EtherChannel interfaces are supported. Only distance vector routing protocols are supported.

An engineer is configuring URL filtering for a Cisco FTD device in Cisco FMC. Users must receive a warning when they access http://www.badadultsite.com with the option of continuing to the website if they choose to. No other websites should be blocked. Which two actions must the engineer take to meet these requirements? (Choose two.). On the HTTP Responses tab of the access control policy editor, set the Interactive Block Response Page to System-provided. Configure the default action for the access control policy to Interactive Block. Configure an access control rule that matches an URL object for http://www.badadultsite.com/ and set the action to Interactive Block. Configure an access control rule that matches the Adult URL category and set the action to Interactive Block. On the HTTP Responses tab of the access control policy editor, set the Block Response Page to Custom.

The security engineer reviews the syslog server events of an organization and sees many outbound connections to malicious sites initiated from hosts running Cisco Secure Endpoint. The hosts are on a separate network from the Cisco FTD device. Which action blocks the connections?. Modify the policy on Cisco Secure Endpoint to enable DFC. Modify the access control policy on the Cisco FMC to block malicious outbound connections. Add the IP addresses of the malicious sites to the access control policy on the Cisco FMC. Add a Cisco Secure Endpoint policy with the Tetra and Spero engines enabled.

An engineer has been tasked with performing an audit of network objects to determine which objects are duplicated across the various firewall models (Cisco Secure Firewall Threat Defense, Cisco Secure Firewall ASA, and Meraki MX Series) deployed throughout the company. Which tool will assist the engineer in performing that audit?. Cisco Firepower Device Manager. Cisco Defense Orchestrator. Cisco Secure Firewall Management Center. Cisco SecureX.

A network engineer is deploying a pair of Cisco Secure Firewall Threat Defense devices managed by Cisco Secure Firewall Management Center for High Availability. Internet access is a high priority for the business and therefore they have invested in internet circuits from two different ISPs. The requirement from the customer is that internet access must be available to their users even if one of the ISPs is down. Which two features must be deployed to achieve this requirement? (Choose two.). Route Tracking. Redundant interfaces. EtherChannel interfaces. SLA Monitor. BGP.

A network engineer is planning on replacing an Active/Standby pair of physical Cisco Secure Firewall ASAs with a pair of Cisco Secure Firewall Threat Defense Virtual appliances. Which two virtual environments support the current High Availability configuration? (Choose two.). ESXi. Azure. Openstack. KVM. AWS.

A company is deploying AMP private cloud. The AMP private cloud instance has already been deployed by the server administrator. The server administrator provided the hostname of the private cloud instance to the network engineer via email. What additional information does the network engineer require from the server administrator to be able to make the connection to the AMP private cloud in Cisco FMC?. SSL certificate for the AMP private cloud instance. Username and password to the AMP private cloud instance. IP address and port number for the connection proxy. Internet access for the AMP private cloud to reach the AMP public cloud.

A security engineer is deploying Cisco Secure Endpoint to detect a zero day malware attack with an SHA-256 hash of 47ea931f3e9dc23ec0b0885a80663e30ea013d493f8e88224b570a0464084628. What must be configured in Cisco Secure Endpoint to enable the application to take action based on this hash?. access control rule. correlation policy. transform set. custom detection list.

A security engineer must create a malware and file policy on a Cisco Secure Firewall Threat Defense device. The solution must ensure that PDF, DOCX, and XLSX files are not sent to Cisco Secure Malware Analytics. What must be configured to meet the requirements?. Spero analysis. local malware analysis. capacity handling. dynamic analysis.

Encrypted Visibility Engine (EVE) is enabled under which tab on an access control policy in Cisco Secure Firewall Management Center?. Network Analysis Policy. SSL. Advanced. Security Intelligence.

An engineer is configuring a Cisco Secure Firewall Threat Defense device managed by Cisco Secure Firewall Management Center. The device must have SSH enabled and be accessible from the inside interface for remote administration. Which type of policy must the engineer configure to accomplish this?. platform settings. access control. prefilter. identity.

What is the result when two users modify a VPN policy at the same time on a Cisco Secure Firewall Management Center managed device?. Both users can edit the policy and the last saved configuration persists. The changes from both users will be merged together into the policy. The first user locks the configuration when selecting edit on the policy. The system prevents modifications to the policy by multiple users.

A network administrator is configuring a BVI interface on a routed FTD. The administrator wants to isolate traffic on the interfaces connected to the bridge group and not have the FTD route this traffic using the routing table. What must be configured?. A new VRF must be created for the BVI interface. An IP address must be configured on the BVI. IP routing must be removed from the physical interfaces connected to the BVI. The BVI interface must be configured for transparent mode.

Which file format can standard reports from Cisco Secure Firewall Management Center be downloaded in?. doc. ppt. csv. xls.

Remote users who connect via Cisco Secure Client to the corporate network behind a Cisco Secure Firewall Threat Defense device are reporting no audio on calls when calling between remote users using their softphones. These same users can call internal users on the corporate network without any issues. What is the cause of this issue?. The hairpinning feature is not available on Cisco Secure Firewall Threat Defense. Cisco Secure Firewall Threat Defense needs a NAT policy that allows outside to outside communication. The Enable Spoke to Spoke Connectivity through Hub option is not selected on Cisco Secure Firewall Threat Defense. Split tunneling is enabled for the Remote Access VPN on Cisco Secure Firewall Threat Defense.

An administrator is configuring the interface of a Cisco Secure Firewall Threat Defense firewall device in a passive IPS deployment. The device and interface have been identified. Which set of configuration steps must the administrator perform next to complete the implementation?. Set the interface mode to passive. Associate the interface with a security zone. Enable the interface. Set the MTU parameter. Modify the interface to retransmit received traffic. Associate the interface with a security zone Set the MTU parameter. Set the interface mode to passive. Associate the interface with a security zone. Set the MTU parameter. Reset the interface. Modify the interface to retransmit received traffic. Associate the interface with a security zone. Enable the interface. Set the MTU parameter.

Which two statements are valid regarding the licensing model used on Cisco Secure Firewall Threat Defense Virtual appliances? (Choose two.). All licenses support a maximum of 250 VPN peers. All licenses support up to 16 vCPUs. All licenses require 500G of available storage for the VM. Licenses can be used on both physical and virtual appliances. Licenses can be used on any supported cloud platform.

A company is deploying Cisco Secure Firewall Threat Defense with IPS. What must be implemented in inline mode to pass the traffic without inspection during spikes and ensure that network traffic is kept?. Change the interface mode to Routed. Select Propagate Link State. Increase the MTU to 9000. Set the Snort Failsafe option.

A Cisco Secure Firewall Threat Defense device is configured in inline IPS mode to inspect all traffic that passes through the interfaces in the inline set. Which setting in the inline set configuration must be selected to allow traffic to pass through uninterrupted when VDB updates are being applied?. Tap Mode. Strict TCP Enforcement. Propagate Link State. Snort Fail Open.

Which two features can be used with Cisco Secure Firewall Threat Defense remote access VPN? (Choose two.). enable Duo two-factor authentication using LDAPS. support for Cisco Secure Firewall 4100 Series in cluster mode. SSL remote access VPN supports port sharing with other Cisco FTD features using SSL port 443. use of license utilization for zero-touch network deployment. support for Rapid Threat Containment using RADIUS dynamic authorization.

Which rule action is only available in Snort 3?. Pass. Generate. Alert. Rewrite.

A company is deploying a Cisco Secure IPS device configured in inline mode with a single Interface set that contains four interface pairs. Which two configurations must be implemented to allow the IPS device to uniquely identify packet flows and prevent the reporting of duplicate traffic and false positives? (Choose two.). Set the source SPAN ports to tx only on the switches connected to the IPS interfaces. Modify the security zones used by the Cisco Secure IPS device. Change the MTU for the inline set to at least 1518. Reconfigure access rules to drop all but the first occurrence of the packet. Reassign the interface pairs to separate inline sets.

An administrator configures new threat intelligence sources and must validate that the feeds are being downloaded and that the intelligence is being used within the Cisco Secure Firewall system. Which action accomplishes the task?. Look at the connection security intelligence events. Use the source status indicator to validate the usage. View the threat intelligence observables to see the downloaded data. Look at the access control policy to validate that the intelligence is being used.

Cisco Security Analytics and Logging SaaS licenses come with how many days of data retention by default?. 60. 90. 120. 365.

An external vendor is reporting that they are unable to access an ordering website hosted behind a Cisco Secure Firewall Threat Defense device. The administrator of the device wants to verify that the access policy and NAT policy are configured correctly to allow traffic from the public IP of the external vendor to TCP port 443 on the web server. Which two Cisco Secure Firewall Management Center tools must the administrator use to verify which rules the traffic from the external vendor is matching? (Choose two.). Packet Capture. Generate Troubleshooting File. Threat Defense CLI. File Download. Packet Tracer.

An organization created a custom application that is being flagged by Cisco Secure Endpoint. The application must be exempt from being flagged. What is the process to meet the requirement?. Configure the custom application to use the information-store paths. Add the custom application to the DFC list and update the policy. Precalculate the hash value of the custom application and add it to the allowed applications. Modify the custom detection list to exclude the custom application.

An engineer is configuring a new dashboard within Cisco Secure Firewall Management Center and is having trouble implementing a custom widget. When a custom analysis widget is configured, which option is mandatory for the system to display the information?. table. title. filter. results.

A network engineer is planning on deploying a Cisco Secure Firewall Threat Defense Virtual appliance in transparent mode. Which two virtual environments support this configuration? (Choose two.). OSI. AWS. GCP. KVM. ESXi.

An engineer is configuring a Cisco Secure Firewall Threat Defense device and wants to create a new intrusion rule based on the detection of a specific pattern in the data payload for a new zero-day exploit. Which keyword type must be used to add a line that identifies the author of the rule and the date it was created?. gtp_info. metadata. reference. content.

What is the role of realms in the Cisco ISE and Cisco FMC integration?. Cisco Secure Firewall VDC. Cisco ISE context. TACACS+ database. AD definition.

A network engineer must configure IPS mode on a Secure Firewall Threat Defense device to inspect traffic and act as an IDS. The engineer already configured the passive-interface on the Secure Firewall Threat Defense device and SPAN on the switch. What must be configured next by the engineer?. intrusion policy on the Secure Firewall Threat Defense device. active SPAN port on the switch. DHCP on the switch. active interface on the Secure Firewall Threat Defense device.

A software development company hosts the website https://dev.company.com for contractors to share code for projects they are working on with internal developers. The web server is on premises and is protected by a Cisco Secure Firewall Threat Defense appliance. The network administrator is worried about someone trying to transmit infected files to internal users via this site. Which type of policy must be associated with an access control policy to enable Cisco Secure Firewall Malware Defense to detect and block malware?. SSL policy. file policy. network discovery policy. prefilter policy.

A network engineer must configure an existing firewall to have a NAT configuration. The new configuration must support more than two interfaces per context. The firewall has previously been operating in transparent mode. The Cisco Secure Firewall Threat Defense (FTD) device has been deregistered from Cisco Secure Firewall Management Center (FMC). Which set of configuration actions must the network engineer take next to meet the requirements?. Run the configure firewall routed command from the Secure FTD device CLI, and reregister with Secure FMC. Run the configure manager add routed command from the Secure FMC CLI. and reregister with Secure FMC. Run the configure manager add routed command from the Secure FTD device CLI, and reregister with Secure FMC. Run the configure firewall routed command from the Secure FMC CLI. and reregister with Secure FMC.

A security engineer manages a firewall console and an endpoint console and finds it challenging and time consuming to review events and modify blocking of specific files in both consoles. Which action must the engineer take to streamline this process?. Within the Cisco Secure Endpoint console, copy the connector GUID and paste into the Cisco Secure Firewall Management Center (FMC) AMP tab. From the Cisco Secure Endpoint console, create and copy an API key and paste into the Cisco Secure AMP tab. From the Secure FMC, create a Cisco Secure Endpoint object and reference the object in the Cisco Secure Endpoint console. Initiate the integration between Secure FMC and Cisco Secure Endpoint from the Secure FMC using the AMP tab.

An engineer must create an access control policy on a Cisco Secure Firewall Threat Defense device. The company has a contact center that utilizes VoIP heavily, and it is critical that this traffic is not impacted by performance issues after deploying the access control policy. Which access control action rule must be configured to handle the VoIP traffic?. block. trust. monitor. allow.

An engineer must export a packet capture from Cisco Secure Firewall Management Center to assist in troubleshooting an issue on a Secure Firewall Threat Defense device. When the engineer navigates to the URL for Secure Firewall Management Center at: https:///capture/CAPI/pcap/sample.pcap The engineer receives a 403: Forbidden error instead of being provided with the PCAP file. Which action resolves the issue?. Disable the proxy setting on the client browser. Disable the HTTPS server and use HTTP. Enable HTTPS in the device platform policy. Enable the proxy setting in the device platform policy.

When packet capture is used on a Cisco Secure Firewall Threat Defense device and the packet flow is waiting on the malware query, which Snort verdict appears?. block. retry. replace. blockflow.

A network administrator wants to configure a Cisco Secure Firewall Threat Defense instance managed by Cisco Secure Firewall Management Center to block traffic to known cryptomining networks. Which system settings must the administrator configure in Secure Firewall Management Center to meet the requirement?. Intrusion Policy, Security Intelligence. Access Policy, Security Intelligence. Malware Policy, Rules. Access Policy, Rules.

A network engineer detects a connectivity issue between Cisco Secure Firewall Management Center and Cisco Secure Firewall Threat Defense. Initial troubleshooting indicates that heartbeats and events are not being received. The engineer re-establishes the secure channels between both peers. Which two commands must the engineer run to resolve the issue? (Choose two.). manage_procs.pl. show disk-manager. show history. sudo perfstats -Cq < /var/sf/rna/correlator-stats/now. sudo stats_unified.pl.

A network administrator is reviewing a packet capture. The packet capture from inside of Cisco Secure Firewall Threat Defense shows the inbound TCP traffic. However, the outbound TCP traffic is not seen in the packet capture from outside Secure Firewall Threat Defense. Which configuration change resolves the issue?. Packet capture must include UDP traffic. Inside interface must be assigned a higher security level. Route to the destination must be added. Inside interface must be assigned a lower security level.

An engineer is troubleshooting an intermittent connectivity issue on a Cisco Secure Firewall Threat Defense appliance and must collect 24 hours' worth of data. The engineer started a packet capture, however it stops prematurely during this time period. The engineer notices that the packet capture buffer size is set to the default of 32 MB. Which buffer size is the maximum that the engineer must set to enable the packet capture to run successfully?. 64 MB. 1 GB. 10 GB. 100 GB.

An administrator must fix a network problem whereby traffic from the inside network to a webserver is not getting through an instance of Cisco Secure Firewall Threat Defense. Which command must the administrator use to capture packets to the webserver that are dropped by Secure Firewall Threat Defense and resolve the issue?. capture CAP int INSIDE match ip any host WEBSERVERIP. capture CAP int OUTSIDE match ip any host WEBSERVERIP. capture CAP int INSIDE match tcp any 80 host WEBSERVERIP 80. capture CAP type asp-drop all headers-only.

Users report that Cisco Duo 2FA fails when they attempt to connect to the VPN on a Cisco Secure Firewall Threat Defense (FTD) device. IT staff have VPN profiles that do not require multifactor authentication and they can connect to the VPN without any issues. When viewing the VPN troubleshooting log in Cisco Secure Firewall Management Center (FMC), the network administrator sees an error that the Cisco Duo AAA server has been marked as failed. What is the root cause of the issue?. AD Trust certificates are missing from the Secure FTD device. Multifactor authentication is not supported on Secure FMC managed devices. The internal AD server is unreachable from the Secure FTD device. Duo trust certificates are missing from the Secure FTD device.

Refer to the exhibit. A security engineer must improve security in an organization and is producing a risk mitigation strategy to present to management for approval. Which action must the security engineer take based on this Attacks Risk Report?. Block NetBIOS. Inspect TCP port 80 traffic. Block Internet Explorer. Inspect DNS traffic.

An engineer is tasked with configuring a custom intrusion rule on Cisco Secure Firewall Management Center to detect and block the malicious traffic pattern with specific payload containing string "|04 68 72 80 87 ff ed cq fg he qm pn|". Which action must the Engineer configure on the IPS policy?. reset. drop. alert. disable. quarantine.

An engineer must integrate a third-party security intelligence feed with Cisco Secure Firewall Management Center. Secure Firewall Management Center is running Version 6.2.3 and has 8 GB of memory. Which two actions must be taken to implement Threat Intelligence Director? (Choose two.). Add a TAXI I server. Add the URL of the TAXII server. Upgrade to version 6.6. Enable REST API access. Add 7 GB of memory.

A network administrator is trying to configure Active Directory authentication for VPN authentication to a Cisco Secure Firewall Threat Defense instance that is registered with Cisco Secure Firewall Management Center. Which system settings must be configured first in Secure Firewall Management Center to accomplish the goal?. Authentication, Device. Policies, Authentication. System, Realms. Device, Remote Access VPN.

Which component is needed to perform rapid threat containment with Cisco FMC?. DDI. SIEM. ISE. RESTful API.

An administrator is attempting to add a new Cisco Secure Firewall Threat Defense device to Cisco Secure Firewall Management Center with a password of Cisco0481488187 481488187. The private IP address of the FMC server is 192.168.75.201. Which command must be used in order to accomplish this task?. configure manager add 192.168.75.201 255.255.255.0. configure manager add 192.168.75.201. configure manager add 192.168.45.45. configure manager add 192.168.75.201/24.

Which component simplifies incident investigation with Cisco Threat Response?. Cisco Secure Firewall appliance. Cisco AMP client. local CVE database. browser plug-in.

An engineer must change the mode of a Cisco Secure Firewall Threat Defense (FTD) firewall in the Cisco Secure Firewall Management Center (FMC) inventory. The engineer must take these actions: • Register Secure FTD with Secure FMC. • Change the firewall mode. • Deregister the Secure FTD device from Secure FMC. How must the engineer take the actions?. Access the Secure FTD CLI from the console port. Configure the management IP address. Reload the Secure FTD device. Erase the Secure FTD configuration.

An engineer is implementing a new Cisco Secure Firewall. The firewall must filter traffic between the three subnets: • LAN 192.168.101.0/24 • DMZ 192.168.200.0/24 • WAN 10.0.0.0/30 Which firewall mode must the engineer implement?. network. routed. gateway. transparent.

An administrator configures the interfaces of a Cisco Secure Firewall Threat Defense device in an inline IPS deployment. The administrator completes these actions: • identifies the device and the interfaces • sets the interface mode to inline • enables the interfaces Which configuration step must the administrator take next to complete the implementation?. Set the interface to routed mode. Enable spanning-tree PortFast on the interfaces. Configure an inline set. Set the interface to transparent mode.

Refer to the exhibit. A Cisco Secure Firewall Threat Defense (FTD) device is deployed in inline mode with an inline set. The network engineer wants router R2 to remove the directly connected route 192.168.1.0/24 from its routing table when the cable between router R1 and the Secure FTD device is disconnected. Which action must the engineer take?. Implement the Propagate Link State option on the Secure FTD device. Implement autostate functionality on the Gi0/2 interface of R2. Establish a routing protocol between R1 and R2. Disable hardware bypass on the Secure FTD device.

A network administrator is trying to configure an access rule to allow access to a specific banking site over HTTPS but not HTTP. Which method must the administrator use to meet the requirement?. Enable SSL decryption and specify the URL. Block the category of banking and define the application of WWW. Define the URL to be blocked and set the application to HTTP. Define the URL to be blocked and disable SSL inspection.

Refer to the exhibit. A company is deploying a pair of Cisco Secure Firewall Threat Defense devices named FTD1 and FTD2. FTD1 and FTD2 have been configured as an active/standby pair with a failover link but without a stateful link. What must be implemented next to ensure that users on the internal network still communicate with outside devices if FTD1 fails?. Disable port security on the switch interfaces connected to FTD1 and FTD2. Connect and configure a stateful link and then deploy the changes. Configure the spanning-tree PortFast feature on SW1 and FTD2. Set maximum secured addresses to two on the switch interfaces on FTD1 and FTD2.

Which action must be taken to configure an isolated bridge group for IRB mode on a Cisco Secure Firewall device?. Leave BVI interface name empty. Remove the route from the routing table. Add the restricted segment to the ACL. Define the NAT pool for the blocked traffic.

Report abuse