option
Questions
ayuda
daypo
search.php

SNCF 300-710 F

COMMENTS STATISTICS RECORDS
TAKE THE TEST
Title of test:
SNCF 300-710 F

Description:
Securing Networks with Cisco Firewalls

Creation Date: 2026/09/29

Category: Others

Number of questions: 60

Rating:(0)
Share the Test:
Nuevo ComentarioNuevo Comentario
New Comment
NO RECORDS
Content:

An administrator is configuring a new report template off of a saved search within Cisco Secure Firewall Management Center. The goal is to use the malware analysis report template, but use a different type of saved search as the basis. The report is not working. What must be considered when configuring this report template?. Saved searches from a different report template must be used. Saved searches must be renamed before using for different report template. Saved searches are available freely for all report templates within the same domain. Saved searches can be used for the same report template only.

An engineer is deploying a Cisco ASA Secure Firewall module. The engineer must be able to examine traffic without impacting the network, and the ASA has been deployed with a single context. Which ASA Secure Firewall module deployment mode must be implemented to meet the requirements?. routed mode with inline tap monitor-only mode. transparent mode with passive monitor-only mode. transparent mode with inline tap monitor-only mode. routed mode with passive monitor-only mode.

An engineer is setting up a new Cisco Secure Firewall Threat Defense appliance to replace the current firewall. The company requests that inline sets be used and that when one interface in an inline set goes down, the second interface in the inline set goes down. What must the engineer configure to meet the deployment requirements?. propagate link state. Snort fail open. inline tap mode. strict TCP enforcement.

Refer to the exhibit. An engineer is configuring a high-availability solution that has the hardware devices and software versions: • two Cisco Secure Firewall 9300 Security Appliances with FXOS SW 2.0(1.23) • one Cisco Secure Firewall Threat Defense with 6.0 1 1 (build 1023) • one Cisco Secure Firewall Management Center with SW 6 0.1.1 (build 1023) Which condition must be met to complete the high-availability configuration?. Both firewalls must be in transparent mode. The version numbers must have the same patch number. DHCP must be configured on at least one firewall interface. Both firewalls must have the same number of interfaces.

An engineer is deploying a Cisco Secure Firewall Management Center appliance. The company must send data to Cisco Secure Network Analytics appliances. Which two actions must the engineer take? (Choose two.). Create a service identifier to enable the NetFlow service. Add the Netflow_Send_Destination object to the configuration. Add the Netflow_Set_Parameters object to the configuration. Add the Netflow_Add_Destination object to the configuration. Security Intelligence object to send data to Cisco Secure Network Analytics.

A network administrator is trying to configure a previously created file policy on a new access policy. Which action must the administrator take before applying the file policy?. Create a new access control rule. Apply an application to an access control rule. Set up an inspection policy. Assign the file policy to the default action.

A security engineer must add a new policy to block UDP traffic to one server. The engineer adds a new object. Which action must the engineer take next to identify all the UDP ports?. Specify the transport protocol and leave the port number empty. Define the transport protocol and the mandatory port range. Add the transport number and specify the type and code. Add the corresponding IP protocol number for UDP and TCP.

Refer to the exhibit. An engineer is configuring access control rules on a Cisco Secure Firewall Threat Defense device. The access control rules must include a file policy with rules that will trigger when MSEXE files are accessed. Which two actions must be configured in the access rule? (Choose two.). block files with reset. interactive block. monitor. allow. trust.

An engineer must deny ICMP traffic to the networks of separate departments that use Cisco Secure Firewall Management Center. The engineer must use the same object on the relevant device for each network. What must be configured in Secure Firewall Management Center?. Allow Overrides check box. IP address. Deny ICMP check box. IP range.

A VPN administrator converted an instance of Cisco Secure Firewall Threat Defense, which is managed by Cisco Secure Firewall Management Center, from using LDAP to LDAPS for remote access VPN authentication. Which certificate must be added to allow for remote users to authenticate over the VPN?. Secure Firewall Threat Defense certificate must be added to the LDAPS server. LDAPS server certificate must be added to Secure Firewall Management Center realms. Secure Firewall Management Center certificate must be added to the LDAPS server. LDAPS server certificate must be added to Secure Firewall Threat Defense.

A network administrator is configuring a transparent Cisco Secure Firewall Threat Defense registered to a Cisco Secure Firewall Management Center. The administrator wants to configure the Secure Firewall Threat Defense to allow ARP traffic to pass between two interfaces of a bridge group. What must be configured?. Use the default configuration on the devices. An access policy must allow MAC address 0100.0CCC.CCCD. ARP inspection must be disabled. An access policy must allow MAC address FFFF.FFFF.FFFF.

A network administrator manages a network with multiple firewalls in a data center. The administrator must change a next-generation firewall from routed to transparent mode. Which action must the administrator take to meet the requirement?. Deregister the firewall in Cisco Secure Firewall Management Center. Enter the configure firewall transparent command from the CLI. Manually delete the interface configuration from the CLI. Create one or more bridge groups from the CLI.

A security engineer sees an alert on Cisco Secure Endpoint console showing a malicious verdict for a file with the SHA-256 hash 0488537078abcdef048853abcdef048853abcdef048853abcdef048853abcdef048853. Which step will mitigate this threat?. Add the hash to network block list. Quarantine the file on endpoint. Add the hash to custom detection list. Enable firewall on infected endpoint.

An engineer must investigate a connectivity issue by using Cisco Secure Firewall Management Center to access the Packet Capture feature on a Cisco Secure Firewall Threat Defense device. The engineer must see a real packet going through the Secure Firewall Threat Defense device and the Snort detection actions. While reviewing the packet capture, the engineer discovers that the Snort detection actions are missing. Which action must the engineer take to resolve the issue?. Enable the Continuous Capture option. Enable the Trace option. Specify the packet size. Specify the buffer size.

An engineer is deploying failover capabilities for a pair of Cisco Secure Firewall devices. The core switch keeps the MAC address of the previously active unit in the ARP table. Which action must the engineer take to minimize downtime and ensure that network users keep access to the internet after a Cisco Secure Firewall failover?. Use a virtual MAC address on both units. Add the MAC address to the switch ARP table. Set the same MAC address on both units. Run a script to send gratuitous ARP after a failover.

An engineer must deploy a Cisco Secure Firewall Threat Defense instance. The company wants the Secure Firewall Threat Defense deployment to allow business traffic in the event of any type of failure, and there must be no connectivity issues caused by the IPS in the perimeter of its data center. Which implementation mode must the engineer use?. hardware bypass. Snort fail open. inline set. passive.

Refer to the exhibit. An engineer observes that users sometimes find their device after the device is declared stolen and block listed in Cisco ISE. What must be selected from the My Devices portal in Cisco ISE to allow the users to reconnect their devices to the network?. Register. Reinstate. Lost. Stolen.

A network administrator wants to configure a default policy to block malicious sites based on the requested URL lookup. Which feature meets the requirement?. file policies. malware policies. DNS policies. URL filtering policies.

An engineer must implement static route tracking on Cisco Secure Firewall Threat Defense and reroute traffic by using a backup path if the primary path fails. The engineer already defined the primary static route, and the primary path is already monitored. Which action must the engineer take to meet the requirement?. Establish an IP SLA ICMP echo request. Configure a tracking object for the static route. Assign a unique tracking ID to the static route. Configure a secondary static route that has higher precedence.

A network engineer wants to disable the HTTP response page and interactive blocking of the entire access control policy in Cisco Secure Firewall Management Center. What must be selected in Block Response Page and Interactive Block Response Page?. View. Custom. System. None.

A network administrator is configuring an instance of Cisco Secure Firewall Threat Defense, which is registered to Cisco Secure Firewall Management Center, to prevent internal users from downloading executable files from the internet. What must be created and configured by the administrator to meet the requirement?. file policy that blocks downloads of all executable files and applies the file policy to the default action in the access policy. access policy rule that allows users to reach the internet with a second rule that blocks application executables. file policy rule that allows users to reach the internet with a second rule applied that blocks application use of FTP. access policy rule that allows users to reach the internet and assigns a file policy that blocks executable downloads to the rule.

Refer to the exhibit. An engineer configures a NAT rule allowing clients to use the internet only if clients are located on the directly connected internal network. Dynamic auto PAT must be configured. Drag and drop the NAT rules from the left onto the corresponding targets on the right. Not all options are used. auto NAT. outside_zone. obj_192.168.2.0_24. obj_192.168.1.0_24. inside_zone. dynamic. destination interface IP.

An engineer must export a packet capture from Cisco Secure Firewall Management Center to assist in troubleshooting an issue on a Secure Firewall Threat Defense device. When the engineer navigates to the URL for Secure Firewall Management Center at: https:///capture/CAPI/pcap/sample.pcap The engineer receives a 403: Forbidden error instead of being provided with the PCAP file. Which action resolves the issue?. Disable the proxy setting on the client browser. Disable the HTTPS server and use HTTP. Enable HTTPS in the device platform policy. Enable the proxy setting in the device platform policy.

An engineer configures an access control rule that deploys file policy configurations to security zone or tunnel zones, and it causes the device to restart. What is the reason for the restart?. Source or destination security zones in the access control rule matches the security zones that are associated with interfaces on the target devices. The source tunnel zone in the rule does not match a tunnel zone that is assigned to a tunnel rule in the destination policy. Source or destination security zones in the source tunnel zone do not match the security zones that are associated with interfaces on the target devices. The source tunnel zone in the rule does not match a tunnel zone that is assigned to a tunnel rule in the source policy.

Refer to the exhibit. An engineer is troubleshooting connectivity issues over a VPN tunnel. Users from the 192.168.68.0/24 network report that they cannot connect to a remote web server that has an IP address of 192.168.67.100. The engineer confirms that NAT and access control rules on the local Cisco Secure Firewall Threat Defense Virtual will allow the connection. Which two configuration changes must the engineer make to resolve the connectivity issues? (Choose two.). Unblock the remote firewall connection. Set the VPN to support two-way traffic. Bring the VPN tunnel up. Match the crypto access control list. Reconfigure the web server.

Refer to the exhibit. An engineer analyzes a Network Risk Report from Cisco Secure Firewall Management Center. What should the engineer recommend implementing to mitigate the risk?. trend analysis. network-based detection. virtual protection. IP address and URL blacklisting.

A security engineer is reviewing a Cisco Secure Endpoint public cloud instance. The engineer discovers a malicious verdict for a SHA-256 hash of 689efc1ecdc23ec0b0885a80663e30ea013d493f8e88224b570a1234567890. Which configuration action must be done in Secure Endpoint console to mitigate the threat?. Add the hash to the custom detection list. Set access control policy and deny files with the hash. Configure correlation policy to block the hash. Apply regular expression to block the malicious file.

Refer to the exhibit. A network engineer is analyzing a Network Risk Report generated in Cisco Secure Firewall Management Center that focuses on network security and efficient bandwidth utilization. Which application should be restricted?. SFTP. BitTorrent. Tivoli. SSH.

Which three items represent features of Cisco Virtual Switching System? (Choose three.). Single control plane. Dual control planes. VSS appears as one switch to downstream switches. VSS appears as two switches to downstream switch. Etherchannel protocols include Static, LACP. channel protocols include Static, PAgP, PAgP+, LACP.

An engineer configures a network discovery policy on Cisco FMC. Upon configuration, it is noticed that excessive and misleading events are filling the database and overloading the Cisco FMC. A monitored NAT device is executing multiple updates of its operating system in a short period of time. What configuration change must be made to alleviate this issue?. Exclude load balancers and NAT devices. Leave default networks. Increase the number of entries on the NAT device. Change the method to TCP/SYN.

Configuring Cisco Secure Firewall Threat Defense (FTD) with an interface in IPS Inline Pair mode. inline set MTU set to 1500. propagate link state disabled. security zone set to OUTSIDE_ZONE. FailSafe disabled.

Refer to the exhibit. A client that has IP address 192.168.67.102 reports issues when connecting to a remote server. Based on the topology and output of packet tracer tool, which action resolves the connectivity issue?. Restart the client-side application. Add the route to the destination. Unblock the access rule on FTDv. Reconfigure NAT on FTDv.

After a network security breach, an engineer must strengthen the security of the corporate network. Upper management must be regularly updated with a high-level overview of any occurring network threats. Which access must the engineer provide upper management to view the required data from Cisco Secure Firewall Management Center?. Analysis > Status with a sliding time window of one day. Events by priority and classification and set a sliding time window of one day. Reports with a daily recurring task that generates based on the network risk report template. Security Intelligence Statistics dashboard set to Show the Last option to one day.

What is the purpose of the IRB feature in next-generation firewall?. to enable transparent bridging between two Layer 2 interfaces. to block routing between two Layer 3 interfaces. to allow multiple physical interfaces to be part of the same VLAN. to configure NAT in transparent mode.

A network engineer must deploy a Cisco ASA to an existing network without changing any IP addresses or networking settings. The external devices connected to the firewall will be on the same subnet as the internal devices. Which command must the engineer use to meet the requirements?. firewall transparent. firewall routed. mode multiple. no firewall transparent.

Which communication is blocked from the bridge groups when multiple are configured in transparent mode on a Cisco Secure Firewall Threat Defense appliance?. with other routers. with client devices. with each other. with the internet.

How should a high-availability pair of Cisco Secure Firewall Threat Defense Virtual appliances be deployed to Cisco Secure Firewall Management Center?. Add the primary appliance to Cisco Secure Firewall Management Center first, then configure high availability. Configure high availability first, then add only the primary Cisco Secure Firewall Threat Defense Virtual appliance to Cisco Secure Firewall Management Center. Add the primary and secondary Cisco Secure Firewall Threat Defense Virtual appliances to Cisco Secure Firewall Management Center first, then configure high availability. Configure high availability first, then add the primary and secondary appliances to Cisco Secure Firewall Management Center.

An engineer is implementing clustering in Cisco Secure Firewall Management Center. The configuration must ensure that the cluster has a designated control unit node with more resources than the other nodes. What must the engineer set for the priority value of the node?. value lower than the other units in the cluster. value higher than the other units in the cluster. 0. 255.

An engineer is configuring a Cisco Secure Firewall Threat Defense device to operate in transparent mode between two switch stacks. VLAN 10 is used for in-band management on both switch stacks. Which two actions are required on the device to inspect traffic between the two switch stacks without causing any interruption to network traffic? (Choose two.). Set the MTU to 9198 on all interfaces to support jumbo frames. Add separate routes for data and management traffic. Exempt BPDUs from advanced inspection. Configure a BVI interface for VLAN 10. Configure at least one bridge group.

An engineer must configure a new identity policy in Cisco Firepower Management Center. Active authentication must be configured by using a Kerberos connection. Which two realms must be configured? (Choose two.). directory username. active directory join username. directory password. active directory primary domain. active directory join password.

Refer to the exhibit. An engineer must create a QoS policy in Cisco Firepower Management Center to limit HTTP and HTTPS traffic from users in the HR department. The upload and download limit of the HTTP and HTTPS traffic must be set to 5 Mb/s. Drag and drop the values from the left onto the corresponding settings on the right. 192.168.1.0/24. 192.168.2.0/24. HTTP-HTTPS. HTTP-HTTPS-QoS. 5 Mb/5. Interfaces in Destination Interface Objects.

An engineer must configure an ERSPAN passive interface on a Cisco Secure IPS by using the Cisco Secure Firewall Management Center. These configurations have been performed already: • Configure the passive interface. • Configure the ERSPAN IP address. Which two additional settings must be configured to complete the configuration? (Choose two.). Destination MAC. TCP Intercept. Bypass Mode. Flow Id. Source IP.

An engineer must create a basic access control policy in the Cisco Secure Firewall Management Center to block all traffic by default. Drag and drop the configuration actions from the left into sequence on the right. Choose the Default Action, and select Block all traffic. Select the device, select Add to Policy, and then select Save. Select Policies and Access Control. Select New Policy and enter a unique name.

An engineer must configure the encrypted visibility engine for a Cisco Secure Firewall Threat Defense device in Cisco Secure Firewall Management Center. The engineer already configured an access control policy, Cisco vulnerability database updates, and the Cisco Success Network. Which two actions must be taken to complete the Secure Firewall Threat Defense device configuration? (Choose two.). Configure an SSL/TLS policy. Enable encrypted traffic inspection. Enable Snort 3. Install a Threat license. Configure an identity policy.

Refer to the exhibit. A security engineer views the health alerts in Cisco Secure Firewall Management Center by using the Health Monitor in the web interface. One of the alerts shows an appliance as critical because the Time Synchronization module status is out of sync. To troubleshoot the issue, the engineer runs the ntpq command in Secure Firewall Management Center. The output is shown in the exhibit. Which action must the security engineer take next to resolve the issue?. Configure the appliance to receive the time from an NTP server. Reestablish the connection to the timeserver. Reset the appliance with a hard reboot. Configure the appliance to sync with its own internal clock.

An engineer is analyzing a risk report generated by using Cisco Secure Firewall Management Center. The report contains these fields: • Total Attacks • Events Requiring Attention • Hosts Targeted • Hosts Connected to CnC Servers Which type of risk report is the engineer analyzing?. attacks. network. events. hosts.

An engineer is reviewing an existing custom server fingerprint on a Cisco Secure Firewall because the current information is inaccurate. Which action must the engineer take to improve the accuracy of the network discovery rules?. Add NetFlow monitoring for the network segment. Exclude the ports that must be skipped. Set one common rule to override the reports in the multidomain environment. Exclude the IP address that is used to communicate with the monitored host.

An engineer is configuring Cisco Security Devices by using Cisco Secure Firewall Management Center. Which configuration command must be run to compare the CA certificate bundle on the local system to the latest CA bundle from the Cisco server?. configure cert-update run-now. configure cert-update test. configure cert-update compare. configure cert-update auto-update enable.

Which Cisco Rapid Threat Containment mitigation action is enabled by integrating pxGrid Adaptive Network Control with Cisco ISE and Cisco Secure Firewall Management Center?. reject. suspend. terminate. block.

How does Cisco Secure Cloud Analytics handle information about network traffic?. It stores the information in a database without any analysis. It performs a heuristic analysis on events and network flow data. It forwards the information to other devices without storing it. It performs a behavioral analysis on events and network flow data.

Which action occurs in the Rapid Threat Containment workflow when an infected endpoint with the MAC address 05:19:75:64.65:EA is detected to isolate the infected endpoint?. Cisco Secure Endpoint instructs Cisco ISE. Cisco ISE instructs Cisco Secure Firewall Management Centre. Cisco ISE instructs Cisco Secure Endpoint. Cisco Secure Firewall Management Centre instructs Cisco ISE.

The network administrator must send a daily email report to management about changes made during the last 24 hours in Cisco Secure Firewall Management Center. Which system setting must be enabled to meet the requirement?. STIG Compliance. Change Reconciliation. Send Audit Log to HTTP Server. Send Audit Log to Syslog.

A security engineer wants to add the Interface Traffic widget to the Summary Dashboard in Cisco Secure Firewall Management Center. The engineer clicks Add Widgets and is in edit mode. Which set of actions must the security engineer take to complete the configuration?. Click All Categories, open the Miscellaneous tab, and click the Add widget button. Click All Categories, open the New tab, and click the Add widget button. Click All Categories, open the Operations tab, and click the Add widget button. Click All Categories, open the Analysis & Reporting tab, and then click Add widget button.

The network engineer at an organization must provide a high-level statistics summary about the Cisco Secure Firewall Threat Defense device. The organization is approaching its peak season, so network downtime must be minimized. Which type of report must the network engineer use?. risk. host. SNMP. malware.

An engineer is configuring a Cisco Secure Firewall Management Center appliance. Secure Firewall Management Center must respond in real time to threats on the network and use a host profile qualification to trigger a response. Which type of policy must be configured in Secure Firewall Management Center?. application detector. network discovery. correlation. intrusion.

An engineer is configuring a Cisco Secure Firewall Management Center appliance. The company requires the use of a TAXII server in Threat Intelligence Director. The company requires that in Threat Intelligence Director, Action must be set to Block. On which two items must the engineer configure a block? (Choose two.). elements. observable. complex indicator. source. indicators.

Refer to the exhibit. After a critical incident, an engineer must determine why a server in the DMZ is sending TCP RST responses. Users access an application from the internet, but the users cannot see the main webpage of the application. Where must the engineer capture the traffic to enable the issue to be identified and resolved?. inside interface of a perimeter router. router of the ISP. internet-facing interface of the perimeter firewall. DMZ interface of the perimeter firewall.

An engineer wants to convert a Cisco Secure Firewall Threat Defense device that is currently being managed by Cisco Secure Firewall Management Center from routed mode to transparent mode. Which CLI command must the engineer execute first to perform this conversion?. no configure manager. configure manager delete. configure firewall transparent. no configure firewall routed.

An engineer must deploy a high-availability that includes two Cisco Secure Firewall Threat Defense devices. The deployment must have a mechanism that protects synchronization between cluster members. Which action must the engineer take to meet the requirements?. Configure an SSL VPN tunnel between units. Clear the commit queue at the time of a sync. Select the Key Generation method for IPsec. Encrypt the synchronization traffic with SSL.

A security engineer must create an access list object in Cisco Secure Firewall Management Center to allow traffic to IP address 10.236.131.1 but block traffic to IP address 10.236.131.0/24. Which access control entries must the engineer create?. A. B. C. D.

Report abuse