Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Cisco CCNP Security 300-710 Questions and answers with CertsForce

Viewing page 1 out of 13 pages
Viewing questions 1-10 out of questions
Questions # 1:

A company is in the process of deploying intrusion prevention with Cisco FTDs managed by a Cisco FMC. An engineer must configure policies to detect potential intrusions but not block the suspicious traffic. Which action accomplishes this task?

Options:

A.

Configure IDS mode when creating or editing a policy rule under the Cisco FMC Intrusion tab in Access Policies section by unchecking the " Drop when inline " option.


B.

Configure IPS mode when creating or editing a policy rule under the Cisco FMC Intrusion tab in Access Policies section by checking the " Drop when inline " option.


C.

Configure IPS mode when creating or editing a policy rule under the Cisco FMC Intrusion tab in Access Policies section by unchecking the " Drop when inline " option.


D.

Configure IDS mode when creating or editing a policy rule under the Cisco FMC Intrusion tab in Access Policies section by checking the " Drop when inline " option.


Expert Solution
Questions # 2:

Which communication is blocked from the bridge groups when multiple are configured in transparent mode on a Cisco Secure Firewall Threat Defense appliance?

Options:

A.

With client devices


B.

With other routers


C.

With each other


D.

With the internet


Expert Solution
Questions # 3:

Question # 3

Refer to the exhibit. Users attempt to connect to numerous external resources on various TCP ports. If the users mistype the port, their connection closes immediately, and it takes more than one minute before the connection is torn down. An engineer manages to capture both types of connections as shown in the exhibit. What must the engineer configure to lower the timeout values for the second group of connections and resolve the user issues?

Options:

A.

outbound access rule that allows the entire ICMP protocol suite


B.

inbound access rule that allows ICMP Type 3 from outside


C.

inbound access rule that allows TCP reset packets from outside


D.

outbound access rule with the Block with reset action


Expert Solution
Questions # 4:

Question # 4

Refer to the exhibit. An engineer must configure a connection on a Cisco ASA Firewall with a Cisco Secure Firewall Services Module to ensure that the secondary interface takes over all the functions of the primary interface if the primary interface fails. Drag and drop the code snippets from the bottom onto the boxes in the CLI commands to configure the failover. Not all options are used.

Question # 4


Expert Solution
Questions # 5:

An administrator is attempting to remotely log into a switch in the data centre using SSH and is unable to connect. How does the administrator confirm that traffic is reaching the firewall?

Options:

A.

by running Wireshark on the administrator ' s PC


B.

by performing a packet capture on the firewall.


C.

by running a packet tracer on the firewall.


D.

by attempting to access it from a different workstation.


Expert Solution
Questions # 6:

An administrator is setting up Cisco Firepower to send data to the Cisco Stealthwatch appliances. The NetFlow_Set_Parameters object is already created, but NetFlow is not being sent to the flow collector. What must be done to prevent this from occurring?

Options:

A.

Add the NetFlow_Send_Destination object to the configuration


B.

Create a Security Intelligence object to send the data to Cisco Stealthwatch


C.

Create a service identifier to enable the NetFlow service


D.

Add the NetFlow_Add_Destination object to the configuration


Expert Solution
Questions # 7:

Which two conditions are necessary for high availability to function between two Cisco FTD devices? (Choose two.)

Options:

A.

The units must be the same version


B.

Both devices can be part of a different group that must be in the same domain when configured within the FMC.


C.

The units must be different models if they are part of the same series.


D.

The units must be configured only for firewall routed mode.


E.

The units must be the same model.


Expert Solution
Questions # 8:

What is the role of realms in the Cisco ISE and Cisco Secure Firewall Management Center integration?

Options:

A.

TACACS+ database


B.

AD definition


C.

Cisco Secure Firewall VDC


D.

Cisco ISE context


E.

(Option not provided – please confirm or provide)


Expert Solution
Questions # 9:

A network administrator observes an attempted attack from a specific IP address in Cisco Secure Firewall Management Center. Which Cisco security tool can be used directly from the Secure Firewall Management Center web interface to obtain additional information about the IP address?

Options:

A.

Cisco Threat Response browser plugin


B.

Cisco Secure Network Analytics


C.

Cisco Identity Services Engine


D.

Cisco Secure Endpoint


Expert Solution
Questions # 10:

An engineer is working on a LAN switch and has noticed that its network connection to the mime Cisco IPS has gone down Upon troubleshooting it is determined that the switch is working as expected What must have been implemented for this failure to occur?

Options:

A.

The upstream router has a misconfigured routing protocol


B.

Link-state propagation is enabled


C.

The Cisco IPS has been configured to be in fail-open mode


D.

The Cisco IPS is configured in detection mode


Expert Solution
Viewing page 1 out of 13 pages
Viewing questions 1-10 out of questions