Month End Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Cisco CCNP Security 300-710 Questions and answers with CertsForce

Viewing page 4 out of 12 pages
Viewing questions 31-40 out of questions
Questions # 31:

An engineer must replace a Cisco Secure Firewall high-availability device due to a failure. When the replacement device arrives, the engineer must separate the high-availability pair from Cisco Secure Firewall Management Center Which action must the engineer take first to restore high availability?

Options:

A.

Register the secondary device


B.

Force a break between the devices.


C.

Unregister the secondary device.


D.

Configure NTP time synchronization.


Expert Solution
Questions # 32:

When deploying a Cisco ASA Firepower module, an organization wants to evaluate the contents of the traffic without affecting the network. It is currently configured to have more than one instance of the same device on the physical appliance Which deployment mode meets the needs of the organization?

Options:

A.

inline tap monitor-only mode


B.

passive monitor-only mode


C.

passive tap monitor-only mode


D.

inline mode


Expert Solution
Questions # 33:

An organization recently implemented a transparent Cisco FTD in their network.

They must ensure that the device does not respond to insecure SSL/TLS protocols.

Which action accomplishes the task?

Options:

A.

Modify the device's settings using the device management feature within Cisco FMC to force onlysecure protocols.


B.

Use the Cisco FTD platform policy to change the minimum SSL version on the device to TLS 1.2.


C.

Enable the UCAPL/CC compliance on the device to support only the most secure protocols available.


D.

Configure a FlexConfig object to disable any insecure TLS protocols on the Cisco FTD device.


Expert Solution
Questions # 34:

A network administrator is trying to configure an access rule to allow access to a specific banking site over HTTPS. Which method must the administrator use to meet the requirement?

Options:

A.

Enable SSL decryption and specify the URL.


B.

Define the URL to be blocked and set the application to HTTP.


C.

Define the URL to be blocked and disable SSL inspection.


D.

Block the category of banking and define the application of WWW.


Expert Solution
Questions # 35:

A Cisco FTD has two physical interfaces assigned to a BVI. Each interface is connected to a different VLAN on the same switch. Which firewall mode is the Cisco FTD set up to support?

Options:

A.

active/active failover


B.

transparent


C.

routed


D.

high availability clustering


Expert Solution
Questions # 36:

An administrator is optimizing the Cisco FTD rules to improve network performance, and wants to bypass inspection for certain traffic types to reduce the load on the Cisco FTD. Which policy must be configured to accomplish this goal?

Options:

A.

prefilter


B.

intrusion


C.

identity


D.

URL filtering


Expert Solution
Questions # 37:

Question # 37

Refer to the exhibit. Users attempt to connect to numerous external resources on various TCP ports. If the users mistype the port, their connection closes immediately, and it takes more than one minute before the connection is torn down. An engineer manages to capture both types of connections as shown in the exhibit. What must the engineer configure to lower the timeout values for the second group of connections and resolve the user issues?

Options:

A.

Outbound access rule with the Block with reset action


B.

Outbound access rule that allows the entire ICMP protocol suite


C.

Inbound access rule that allows TCP reset packets from outside


Expert Solution
Questions # 38:

An engineer is troubleshooting an intermittent connectivity issue on a Cisco Secure Firewall Threat Defense appliance and must collect 24 hours' worth of data. The engineer started a packet capture. Whenever it stopsprematurely during this time period. The engineer notices that the packet capture butter size is set to the default of 32 MB Which butter S170 is the maximum that the engineer must sot to able the packet capture to run successfully?

Options:

A.

64 MB


B.

1 GB


C.

10 GB


D.

100 GB


Expert Solution
Questions # 39:

What is a valid Cisco AMP file disposition?

Options:

A.

non-malicious


B.

malware


C.

known-good


D.

pristine


Expert Solution
Questions # 40:

Drag and drop the configuration steps from the left into the sequence on the right to enable external authentication on Cisco FMC to a RADIUS server.

Question # 40


Expert Solution
Viewing page 4 out of 12 pages
Viewing questions 31-40 out of questions