Use Real 300-710 - 100% Cover Real Exam Questions [Aug-2021]
Dumps Brief Outline Of The 300-710 Exam - Exam4Labs
NEW QUESTION 52
What is a result of enabling Cisco FTD clustering?
- A. All Firepower appliances can support Cisco FTD clustering.
- B. Integrated Routing and Bridging is supported on the master unit.
- C. For the dynamic routing feature, if the master unit fails, the newly elected master unit maintains all existing connections.
- D. Site-to-site VPN functionality is limited to the master unit, and all VPN connections are dropped if the master unit fails.
Answer: D
NEW QUESTION 53
On the advanced tab under inline set properties, which allows interfaces to emulate a passive interface?
- A. TAP mode
- B. strict TCP enforcement
- C. transparent inline mode
- D. propagate link state
Answer: D
Explanation:
Section: Deployment
Explanation/Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-config- guide-v64/inline_sets_and_passive_interfaces_for_firepower_threat_defense.html
NEW QUESTION 54
Which connector is used to integrate Cisco ISE with Cisco FMC for Rapid Threat Containment?
- A. FMC RTC
- B. ISEGrid
- C. pxGrid
- D. FTD RTC
Answer: C
NEW QUESTION 55
Refer to the exhibit.
An organization has an access control rule with the intention of sending all social media traffic for inspection After using the rule for some time, the administrator notices that the traffic is not being inspected, but is being automatically allowed What must be done to address this issue?
- A. Modify the rule action from trust to allow
- B. Change the intrusion policy to connectivity over security.
- C. Add the social network URLs to the block list
- D. Modify the selected application within the rule
Answer: D
NEW QUESTION 56
An administrator is attempting to remotely log into a switch in the data centre using SSH and is unable to connect. How does the administrator confirm that traffic is reaching the firewall?
- A. by performing a packet capture on the firewall.
- B. by running Wireshark on the administrator's PC
- C. by running a packet tracer on the firewall.
- D. by attempting to access it from a different workstation.
Answer: C
Explanation:
Reference:
https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/212474-working-with-firepower-threat-defense-f.html#anc16
NEW QUESTION 57
With Cisco Firepower Threat Defense software, which interface mode must be configured to passively receive traffic that passes through the appliance?
- A. inline tap
- B. passive
- C. inline set
- D. routed
Answer: B
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-config- guide-v64/interface_overview_for_firepower_threat_defense.html
NEW QUESTION 58
An engineer is investigating connectivity problems on Cisco Firepower that is using service group tags.
Specific devices are not being tagged correctly, which is preventing clients from using the proper policies when going through the firewall How is this issue resolved?
- A. Use a packet capture with match criteria.
- B. Use Wireshark with an IP subnet filter.
- C. Use a packet sniffer with correct filtering
- D. Use traceroute with advanced options.
Answer: D
NEW QUESTION 59
Which two features of Cisco AMP for Endpoints allow for an uploaded file to be blocked? (Choose two.)
- A. file repository
- B. application blocking
- C. simple custom detection
- D. exclusions
- E. application whitelisting
Answer: B,C
NEW QUESTION 60
An engineer currently has a Cisco FTD device registered to the Cisco FMC and is assigned the address of 10
10.50.12. The organization is upgrading the addressing schemes and there is a requirement to convert the addresses to a format that provides an adequate amount of addresses on the network What should the engineer do to ensure that the new addressing takes effect and can be used for the Cisco FTD to Cisco FMC connection?
- A. Delete and reregister the device to Cisco FMC
- B. Update the IP addresses from IFV4 to IPv6 without deleting the device from Cisco FMC
- C. Format and reregister the device to Cisco FMC.
- D. Cisco FMC does not support devices that use IPv4 IP addresses.
Answer: A
NEW QUESTION 61
An engineer has been tasked with using Cisco FMC to determine if files being sent through the network are malware. Which two configuration takes must be performed to achieve this file lookup? (Choose two.)
- A. The Cisco FMC needs to include a file inspection policy for malware lookup.
- B. The Cisco FMC needs to include a SSL decryption policy.
- C. The Cisco FMC needs to connect to the Cisco ThreatGrid service directly for sandboxing.
- D. The Cisco FMC needs to connect to the Cisco AMP for Endpoints service.
- E. The Cisco FMC needs to connect with the FireAMP Cloud.
Answer: A,D
NEW QUESTION 62
Which CLI command is used to generate firewall debug messages on a Cisco Firepower?
- A. system support firewall-engine-debug
- B. system support dump-table
- C. system support ssl-debug
- D. system support platform
Answer: A
NEW QUESTION 63
Which license type is required on Cisco ISE to integrate with Cisco FMC pxGrid?
- A. mobility
- B. plus
- C. apex
- D. base
Answer: B
Explanation:
https://www.cisco.com/c/en/us/td/docs/security/ise/1-3/admin_guide/b_ise_admin_guide_13/ b_ise_admin_guide_sample_chapter_0111.html#concept_DE1C38E055794B198ED352D1528B5182
NEW QUESTION 64
An organization has noticed that malware was downloaded from a website that does not currently have a known bad reputation. How will this issue be addresses globally in the quickest way possible and with the least amount of impact?
- A. Cisco Talos will automatically update the policies.
- B. by creating a URL object in the policy to block the website
- C. by Isolating the endpoint
- D. by denying outbound web access
Answer: B
NEW QUESTION 65
Which protocol establishes network redundancy in a switched Firepower device deployment?
- A. STP
- B. HSRP
- C. GLBP
- D. VRRP
Answer: A
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config- guide-v62/firepower_threat_defense_high_availability.html
NEW QUESTION 66
Which report template field format is available in Cisco FMC?
- A. arrow chart
- B. box lever chart
- C. benchmark chart
- D. bar chart
Answer: D
Explanation:
Section: Management and Troubleshooting
Explanation/Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide- v60/Working_with_Reports.html
NEW QUESTION 67
administrator is configuring SNORT inspection policies and is seeing failed deployment messages in Cisco FMC . What information should the administrator generate for Cisco TAC to help troubleshoot?
- A. A "troubleshoot" file for the Cisco FMC
- B. A "show tech" for the Cisco FMC.
- C. A Troubleshoot" file for the device in question.
- D. A "show tech" file for the device in question
Answer: A
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/troubleshooting_the_system.html
NEW QUESTION 68
Which command-line mode is supported from the Cisco Firepower Management Center CLI?
- A. privileged
- B. configuration
- C. user
- D. admin
Answer: B
Explanation:
Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/660/configuration/guide/fpmc-config-guide-v66/command_line_reference.pdf
NEW QUESTION 69
What are the minimum requirements to deploy a managed device inline?
- A. passive interface, MTU, and mode
- B. inline interfaces, MTU, and mode
- C. passive interface, security zone, MTU, and mode
- D. inline interfaces, security zones, MTU, and mode
Answer: B
Explanation:
Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/650/configuration/guide/fpmc-config-guide-v65/ips_device_deployments_and_configuration.html
NEW QUESTION 70
Which two dynamic routing protocols are supported in Firepower Threat Defense without using FlexConfig?
(Choose two.)
- A. OSPF
- B. EIGRP
- C. BGP
- D. static routing
- E. IS-IS
Answer: A,C
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/660/fdm/fptd-fdm-config-guide-660/fptd- fdm-routing.html
NEW QUESTION 71
Which report template field format is available in Cisco FMC?
- A. arrow chart
- B. box lever chart
- C. benchmark chart
- D. bar chart
Answer: D
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide-v60/Working_with_Reports.html
NEW QUESTION 72
......
Certification Training for 300-710 Exam Dumps Test Engine: https://www.exam4labs.com/300-710-practice-torrent.html
300-710 Training & Certification Get Latest CCNP Security : https://drive.google.com/open?id=1FOzmKuv-EW8aj2ZxQAd2d7PkmcbkD39s