SNCF 300-710 F
|
|
Title of test:
![]() SNCF 300-710 F Description: Securing Networks with Cisco Firewalls |



| New Comment |
|---|
NO RECORDS |
|
An administrator is configuring a new report template off of a saved search within Cisco Secure Firewall Management Center. The goal is to use the malware analysis report template, but use a different type of saved search as the basis. The report is not working. What must be considered when configuring this report template?. Saved searches from a different report template must be used. Saved searches must be renamed before using for different report template. Saved searches are available freely for all report templates within the same domain. Saved searches can be used for the same report template only. An engineer is deploying a Cisco ASA Secure Firewall module. The engineer must be able to examine traffic without impacting the network, and the ASA has been deployed with a single context. Which ASA Secure Firewall module deployment mode must be implemented to meet the requirements?. routed mode with inline tap monitor-only mode. transparent mode with passive monitor-only mode. transparent mode with inline tap monitor-only mode. routed mode with passive monitor-only mode. An engineer is setting up a new Cisco Secure Firewall Threat Defense appliance to replace the current firewall. The company requests that inline sets be used and that when one interface in an inline set goes down, the second interface in the inline set goes down. What must the engineer configure to meet the deployment requirements?. propagate link state. Snort fail open. inline tap mode. strict TCP enforcement. Refer to the exhibit. An engineer is configuring a high-availability solution that has the hardware devices and software versions: • two Cisco Secure Firewall 9300 Security Appliances with FXOS SW 2.0(1.23) • one Cisco Secure Firewall Threat Defense with 6.0 1 1 (build 1023) • one Cisco Secure Firewall Management Center with SW 6 0.1.1 (build 1023) Which condition must be met to complete the high-availability configuration?. Both firewalls must be in transparent mode. The version numbers must have the same patch number. DHCP must be configured on at least one firewall interface. Both firewalls must have the same number of interfaces. An engineer is deploying a Cisco Secure Firewall Management Center appliance. The company must send data to Cisco Secure Network Analytics appliances. Which two actions must the engineer take? (Choose two.). Create a service identifier to enable the NetFlow service. Add the Netflow_Send_Destination object to the configuration. Add the Netflow_Set_Parameters object to the configuration. Add the Netflow_Add_Destination object to the configuration. Security Intelligence object to send data to Cisco Secure Network Analytics. A network administrator is trying to configure a previously created file policy on a new access policy. Which action must the administrator take before applying the file policy?. Create a new access control rule. Apply an application to an access control rule. Set up an inspection policy. Assign the file policy to the default action. A security engineer must add a new policy to block UDP traffic to one server. The engineer adds a new object. Which action must the engineer take next to identify all the UDP ports?. Specify the transport protocol and leave the port number empty. Define the transport protocol and the mandatory port range. Add the transport number and specify the type and code. Add the corresponding IP protocol number for UDP and TCP. Refer to the exhibit. An engineer is configuring access control rules on a Cisco Secure Firewall Threat Defense device. The access control rules must include a file policy with rules that will trigger when MSEXE files are accessed. Which two actions must be configured in the access rule? (Choose two.). block files with reset. interactive block. monitor. allow. trust. An engineer must deny ICMP traffic to the networks of separate departments that use Cisco Secure Firewall Management Center. The engineer must use the same object on the relevant device for each network. What must be configured in Secure Firewall Management Center?. Allow Overrides check box. IP address. Deny ICMP check box. IP range. A VPN administrator converted an instance of Cisco Secure Firewall Threat Defense, which is managed by Cisco Secure Firewall Management Center, from using LDAP to LDAPS for remote access VPN authentication. Which certificate must be added to allow for remote users to authenticate over the VPN?. Secure Firewall Threat Defense certificate must be added to the LDAPS server. LDAPS server certificate must be added to Secure Firewall Management Center realms. Secure Firewall Management Center certificate must be added to the LDAPS server. LDAPS server certificate must be added to Secure Firewall Threat Defense. A network administrator is configuring a transparent Cisco Secure Firewall Threat Defense registered to a Cisco Secure Firewall Management Center. The administrator wants to configure the Secure Firewall Threat Defense to allow ARP traffic to pass between two interfaces of a bridge group. What must be configured?. Use the default configuration on the devices. An access policy must allow MAC address 0100.0CCC.CCCD. ARP inspection must be disabled. An access policy must allow MAC address FFFF.FFFF.FFFF. A network administrator manages a network with multiple firewalls in a data center. The administrator must change a next-generation firewall from routed to transparent mode. Which action must the administrator take to meet the requirement?. Deregister the firewall in Cisco Secure Firewall Management Center. Enter the configure firewall transparent command from the CLI. Manually delete the interface configuration from the CLI. Create one or more bridge groups from the CLI. A security engineer sees an alert on Cisco Secure Endpoint console showing a malicious verdict for a file with the SHA-256 hash 0488537078abcdef048853abcdef048853abcdef048853abcdef048853abcdef048853. Which step will mitigate this threat?. Add the hash to network block list. Quarantine the file on endpoint. Add the hash to custom detection list. Enable firewall on infected endpoint. An engineer must investigate a connectivity issue by using Cisco Secure Firewall Management Center to access the Packet Capture feature on a Cisco Secure Firewall Threat Defense device. The engineer must see a real packet going through the Secure Firewall Threat Defense device and the Snort detection actions. While reviewing the packet capture, the engineer discovers that the Snort detection actions are missing. Which action must the engineer take to resolve the issue?. Enable the Continuous Capture option. Enable the Trace option. Specify the packet size. Specify the buffer size. An engineer is deploying failover capabilities for a pair of Cisco Secure Firewall devices. The core switch keeps the MAC address of the previously active unit in the ARP table. Which action must the engineer take to minimize downtime and ensure that network users keep access to the internet after a Cisco Secure Firewall failover?. Use a virtual MAC address on both units. Add the MAC address to the switch ARP table. Set the same MAC address on both units. Run a script to send gratuitous ARP after a failover. An engineer must deploy a Cisco Secure Firewall Threat Defense instance. The company wants the Secure Firewall Threat Defense deployment to allow business traffic in the event of any type of failure, and there must be no connectivity issues caused by the IPS in the perimeter of its data center. Which implementation mode must the engineer use?. hardware bypass. Snort fail open. inline set. passive. Refer to the exhibit. An engineer observes that users sometimes find their device after the device is declared stolen and block listed in Cisco ISE. What must be selected from the My Devices portal in Cisco ISE to allow the users to reconnect their devices to the network?. Register. Reinstate. Lost. Stolen. A network administrator wants to configure a default policy to block malicious sites based on the requested URL lookup. Which feature meets the requirement?. file policies. malware policies. DNS policies. URL filtering policies. An engineer must implement static route tracking on Cisco Secure Firewall Threat Defense and reroute traffic by using a backup path if the primary path fails. The engineer already defined the primary static route, and the primary path is already monitored. Which action must the engineer take to meet the requirement?. Establish an IP SLA ICMP echo request. Configure a tracking object for the static route. Assign a unique tracking ID to the static route. Configure a secondary static route that has higher precedence. A network engineer wants to disable the HTTP response page and interactive blocking of the entire access control policy in Cisco Secure Firewall Management Center. What must be selected in Block Response Page and Interactive Block Response Page?. View. Custom. System. None. A network administrator is configuring an instance of Cisco Secure Firewall Threat Defense, which is registered to Cisco Secure Firewall Management Center, to prevent internal users from downloading executable files from the internet. What must be created and configured by the administrator to meet the requirement?. file policy that blocks downloads of all executable files and applies the file policy to the default action in the access policy. access policy rule that allows users to reach the internet with a second rule that blocks application executables. file policy rule that allows users to reach the internet with a second rule applied that blocks application use of FTP. access policy rule that allows users to reach the internet and assigns a file policy that blocks executable downloads to the rule. Refer to the exhibit. An engineer configures a NAT rule allowing clients to use the internet only if clients are located on the directly connected internal network. Dynamic auto PAT must be configured. Drag and drop the NAT rules from the left onto the corresponding targets on the right. Not all options are used. auto NAT. outside_zone. obj_192.168.2.0_24. obj_192.168.1.0_24. inside_zone. dynamic. destination interface IP. An engineer must export a packet capture from Cisco Secure Firewall Management Center to assist in troubleshooting an issue on a Secure Firewall Threat Defense device. When the engineer navigates to the URL for Secure Firewall Management Center at: https:///capture/CAPI/pcap/sample.pcap The engineer receives a 403: Forbidden error instead of being provided with the PCAP file. Which action resolves the issue?. Disable the proxy setting on the client browser. Disable the HTTPS server and use HTTP. Enable HTTPS in the device platform policy. Enable the proxy setting in the device platform policy. An engineer configures an access control rule that deploys file policy configurations to security zone or tunnel zones, and it causes the device to restart. What is the reason for the restart?. Source or destination security zones in the access control rule matches the security zones that are associated with interfaces on the target devices. The source tunnel zone in the rule does not match a tunnel zone that is assigned to a tunnel rule in the destination policy. Source or destination security zones in the source tunnel zone do not match the security zones that are associated with interfaces on the target devices. The source tunnel zone in the rule does not match a tunnel zone that is assigned to a tunnel rule in the source policy. Refer to the exhibit. An engineer is troubleshooting connectivity issues over a VPN tunnel. Users from the 192.168.68.0/24 network report that they cannot connect to a remote web server that has an IP address of 192.168.67.100. The engineer confirms that NAT and access control rules on the local Cisco Secure Firewall Threat Defense Virtual will allow the connection. Which two configuration changes must the engineer make to resolve the connectivity issues? (Choose two.). Unblock the remote firewall connection. Set the VPN to support two-way traffic. Bring the VPN tunnel up. Match the crypto access control list. Reconfigure the web server. Refer to the exhibit. An engineer analyzes a Network Risk Report from Cisco Secure Firewall Management Center. What should the engineer recommend implementing to mitigate the risk?. trend analysis. network-based detection. virtual protection. IP address and URL blacklisting. A security engineer is reviewing a Cisco Secure Endpoint public cloud instance. The engineer discovers a malicious verdict for a SHA-256 hash of 689efc1ecdc23ec0b0885a80663e30ea013d493f8e88224b570a1234567890. Which configuration action must be done in Secure Endpoint console to mitigate the threat?. Add the hash to the custom detection list. Set access control policy and deny files with the hash. Configure correlation policy to block the hash. Apply regular expression to block the malicious file. Refer to the exhibit. A network engineer is analyzing a Network Risk Report generated in Cisco Secure Firewall Management Center that focuses on network security and efficient bandwidth utilization. Which application should be restricted?. SFTP. BitTorrent. Tivoli. SSH. Which three items represent features of Cisco Virtual Switching System? (Choose three.). Single control plane. Dual control planes. VSS appears as one switch to downstream switches. VSS appears as two switches to downstream switch. Etherchannel protocols include Static, LACP. channel protocols include Static, PAgP, PAgP+, LACP. |





