New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Cisco CCNP Security 300-710 Questions and answers with CertsForce

Viewing page 1 out of 12 pages
Viewing questions 1-10 out of questions
Questions # 1:

The CEO ask a network administrator to present to management a dashboard that shows custom analysis tables for the top DNS queries URL category statistics, and the URL reputation statistics.

Which action must the administrator take to quickly produce this information for management?

Options:

A.

Run the Attack report and filter on DNS to show this information.


B.

Create a new dashboard and add three custom analysis widgets that specify the tables needed.


C.

Modify the Connection Events dashboard to display the information in a view for management.


D.

Copy the intrusion events dashboard tab and modify each widget to show the correct charts.


Expert Solution
Questions # 2:

Which Cisco FMC report gives the analyst information about the ports and protocols that are related to the configured sensitive network for analysis?

Options:

A.

Malware Report


B.

Host Report


C.

Firepower Report


D.

Network Report


Expert Solution
Questions # 3:

An engineer must permit SSH on the inside interface of a Cisco Secure Firewall Threat Defense device. SSH is currently permitted only on the management interface. Which type of policy

must the engineer configure?

Options:

A.

platform policy


B.

access control policy


C.

NAT policy


D.

intrusion policy


Expert Solution
Questions # 4:

A security engineer needs to configure a network discovery policy on a Cisco FMC appliance and prevent excessive network discovery events from overloading the FMC database? Which action must be taken to accomplish this task?

Options:

A.

Change the network discovery method to TCP/SYN.


B.

Configure NetFlow exporters for monitored networks.


C.

Monitor only the default IPv4 and IPv6 network ranges.


D.

Exclude load balancers and NAT devices in the policy.


Expert Solution
Questions # 5:

An administrator is attempting to add a new FTD device to their FMC behind a NAT device with a NAT ID of NAT001 and a password of Cisco0420l06525. The private IP address of the FMC server is 192.168.45.45. which is being translated to the public IP address of 209.165.200.225/27. Which command set must be used in order to accomplish this task?

Options:

A.

configure manager add 209.165.200.225


B.

configure manager add 192.168.45,45


C.

configure manager add 209.165.200.225 255.255.255.224


D.

configure manager add 209.165.200.225/27


Expert Solution
Questions # 6:

An organization is setting up two new Cisco FTD devices to replace their current firewalls and cannot have any network downtime During the setup process, the synchronization between the two devices is failing What action is needed to resolve this issue?

Options:

A.

Confirm that both devices have the same port-channel numbering


B.

Confirm that both devices are running the same software version


C.

Confirm that both devices are configured with the same types of interfaces


D.

Confirm that both devices have the same flash memory sizes


Expert Solution
Questions # 7:

An engineer is deploying Cisco Secure Endpoint for the first time and on endpoint with MAC address 50:54:15:04:0:AB. The engineer must make sure that during the testing phase no files are isolated and network connections must not be blocked. Which policy type must be configured to accomplish the task?

Options:

A.

Triage


B.

Quarantine


C.

Protect


D.

Audit


Expert Solution
Questions # 8:

An engineer must configure email notifications on Cisco Secure Firewall Management Center. TLS encryption must be used to protect the messages from unauthorized access. The engineer adds the IP address of the mail relay host and must set the port number. Which TCP port must the engineer use?

Options:

A.

25


B.

389


C.

465


D.

587


Expert Solution
Questions # 9:

A network administrator discovers that a user connected to a file server and downloaded a malware file. The Cisc FMC generated an alert for the malware event, however the user still remained connected. Which Cisco APM file rule action within the Cisco FMC must be set to resolve this issue?

Options:

A.

Detect Files


B.

Malware Cloud Lookup


C.

Local Malware Analysis


D.

Reset Connection


Expert Solution
Questions # 10:

What is the role of realms in the Cisco ISE and Cisco FMC integration?

Options:

A.

AD definition


B.

TACACS+ database


C.

Cisco ISE context


D.

Cisco Secure Firewall VDC


Expert Solution
Viewing page 1 out of 12 pages
Viewing questions 1-10 out of questions