Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Cisco CCNP Security 300-710 Questions and answers with CertsForce

Viewing page 2 out of 13 pages
Viewing questions 11-20 out of questions
Questions # 11:

An engineer must investigate a connectivity issue from an endpoint behind a Cisco FTD device and a public DNS server. The endpoint cannot perform name resolution queries. Which action must the engineer perform to troubleshoot the issue by simulating real DNS traffic on the Cisco FTD while verifying the Snarl verdict?

Options:

A.

Perform a Snort engine capture using tcpdump from the FTD CLI.


B.

Use the Capture w/Trace wizard in Cisco FMC.


C.

Create a Custom Workflow in Cisco FMC.


D.

Run me system support firewall-engine-debug command from me FTD CLI.


Expert Solution
Questions # 12:

An engineer must deny ICMP traffic to the networks of separate departments that use Cisco Secure Firewall Management Center. The engineer must use the same object on the relevant device for each network. What must be configured in Secure Firewall Management Center?

Options:

A.

IP address


B.

IP range


C.

Deny ICMP check box


D.

Allow Overrides check box


Expert Solution
Questions # 13:

Refer to the exhibit.

Question # 13

A Cisco Secure Firewall Threat Defense (FTD) device is deployed in inline mode with an inline set. The network engineer wants router R2 to remove the directly connected route M 68.1.0/24 from its routing table when the cable between routed R1 and the Secure FTD device Is disconnected. Which action must the engineer take?

1

Options:

A.

Implement the Propagate Link Stale option on the Secure FTD device


B.

Establish a routing protocol between R1 and R2.


C.

Disable hardware bypass on the Secure FTD device.


D.

Implement autostate functionality on the Gi0/2 interface of R2


Expert Solution
Questions # 14:

What is the RTC workflow when the infected endpoint is identified?

Options:

A.

Cisco ISE instructs Cisco AMP to contain the infected endpoint.


B.

Cisco ISE instructs Cisco FMC to contain the infected endpoint.


C.

Cisco AMP instructs Cisco FMC to contain the infected endpoint.


D.

Cisco FMC instructs Cisco ISE to contain the infected endpoint.


Expert Solution
Questions # 15:

An engineer Is configuring a Cisco FTD device to place on the Finance VLAN to provide additional protection tor company financial data. The device must be deployed without requiring any changes on the end user workstations, which currently use DHCP lo obtain an IP address. How must the engineer deploy the device to meet this requirement?

Options:

A.

Deploy the device in routed mode and allow DHCP traffic in the access control policies.


B.

Deploy the device in routed made aid enable the DHCP Relay feature.


C.

Deploy the device in transparent mode and allow DHCP traffic in the access control policies


D.

Deploy the device in transparent mode and enable the DHCP Server feature.


Expert Solution
Questions # 16:

Refer to the exhibit.

Question # 16

An engineer must create a QoS policy in Cisco Secure Firewall Management Center to limit HTTP and HTTPS traffic originating from users in the HR department. The download and upload limits for HTTP and HTTPS traffic must both be set to 5 Mb/s. Drag and drop the values onto the corresponding QoS rule settings.

Question # 16


Expert Solution
Questions # 17:

An engineer is configuring multiple Cisco FTD appliances (or use in the network. Which rule must the engineer follow while defining interface objects in Cisco FMC for use with interfaces across multiple devices?

Options:

A.

An interface cannot belong to a security zone and an interface group


B.

Interface groups can contain multiple interface types


C.

Interface groups can contain interfaces from many devices.


D.

Two security zones can contain the same interface


Expert Solution
Questions # 18:

A network administrator configured an access control rule named WEB05405_SRV06798_ALLOW that allows any source on the Internet to reach the public IP address of a web server on port 8080. The administrator also configured a NAT policy that translates the public IP address to the internal web server IP address. During testing, the web server is not reachable from the Internet on port 8080. Which configuration must the administrator apply to resolve the issue?

Options:

A.

Configure the access control rule with the Trust action.


B.

Disable intrusion inspection for port 8080.


C.

Modify the NAT policy to translate the source IP address as well as the destination IP address.


D.

Replace the web server’s public IP address with its internal IP address in the access control rule.


Expert Solution
Questions # 19:

Question # 19

Refertothe exhibit. An engineer is analyzing a Network Risk Report from Cisco FMC. Which application must the engineer take immediate action against to prevent unauthorized network use?

Options:

A.

Kerberos


B.

YouTube


C.

Chrome


D.

TOR


Expert Solution
Questions # 20:

A network administrator is reviewing a weekly scheduled attacks risk report and notices a host that is flagged for an impact 2 attack. Where should the administrator look within Cisco FMC to find out more relevant information about this host and attack?

Options:

A.

Analysis > Lookup > Whols


B.

Analysis > Correlation > Correlation Events


C.

Analysis > Hosts > Vulnerabilities


D.

Analysis > Hosts > Host Attributes


Expert Solution
Viewing page 2 out of 13 pages
Viewing questions 11-20 out of questions