Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Cisco CCNP Security 300-710 Questions and answers with CertsForce

Viewing page 4 out of 13 pages
Viewing questions 31-40 out of questions
Questions # 31:

A network engineer is deploying a pair of Cisco Secure Firewall Threat Defense devices managed by Cisco Secure Firewall Management Center tor High Availability Internet access is a high priority for the business and therefore they have invested in internet circuits from two different ISPs. The requirement from the customer Is that Internet access must do available to their user’s oven if one of the ISPs is down. Which two features must be deployed to achieve this requirement? (Choose two.)

Options:

A.

EtherChannel interfaces


B.

Route Tracking


C.

SLA Monitor


D.

Redundant interfaces


E.

BGP


Expert Solution
Questions # 32:

A security engineer is configuring a remote Cisco FTD that has limited resources and internet bandwidth. Which malware action and protection option should be configured to reduce the requirement for cloud lookups?

Options:

A.

Malware Cloud Lookup and dynamic analysis


B.

Block Malware action and dynamic analysis


C.

Block Malware action and local malware analysis


D.

Block File action and local malware analysis


Expert Solution
Questions # 33:

When using Cisco Threat Response, which phase of the Intelligence Cycle publishes the results of the investigation?

Options:

A.

direction


B.

dissemination


C.

processing


D.

analysis


Expert Solution
Questions # 34:

A security engineer is configuring an Access Control Policy for multiple branch locations. These locations share a common rule set and utilize a network object called INSIDE_NET which contains the locally significant internal network subnets at each location. Which technique will retain the policy consistency at each location but allow only the locally significant network subnet within the applicable rules?

Options:

A.

utilizing a dynamic Access Control Policy that updates from Cisco Talos


B.

utilizing policy inheritance


C.

creating a unique Access Control Policy per device


D.

creating an Access Control Policy with an INSIDE_NET network object and object overrides


Expert Solution
Questions # 35:

A company wants a solution to aggregate the capacity of two Cisco FTD devices to make the best use of resources such as bandwidth and connections per second. Which order of steps must be taken across the Cisco FTDs with Cisco FMC to meet this requirement?

Options:

A.

Configure the Cisco FTD interfaces, add members to FMC, configure cluster members in FMC, and create cluster in Cisco FMC.


B.

Add members to Cisco FMC, configure Cisco FTD interfaces in Cisco FMC. configure cluster members in Cisco FMC, create cluster in Cisco FMC. and configure cluster members in Cisco FMC.


C.

Configure the Cisco FTD interfaces and cluster members, add members to Cisco FMC. and create the cluster in Cisco FMC.


D.

Add members to the Cisco FMC, configure Cisco FTD interfaces, create the cluster in Cisco FMC, and configure cluster members in Cisco FMC.


Expert Solution
Questions # 36:

A network administrator cannot select the link to be used for failover when configuring an active/passive HA Cisco FTD pair.

Which configuration must be changed before setting up the high availability pair?

Options:

A.

An IP address in the same subnet must be added to each Cisco FTD on the interface.


B.

The interface name must be removed from the interface on each Cisco FTD.


C.

The name Failover must be configured manually on the interface on each cisco FTD.


D.

The interface must be configured as part of a LACP Active/Active EtherChannel.


Expert Solution
Questions # 37:

An administrator receives reports that users cannot access a cloud-hosted web server. The access control policy was recently updated with several new policy additions and URL filtering. What must be done to troubleshoot the issue and restore access without sacrificing the organization ' s security posture?

Options:

A.

Create a new access control policy rule to allow ports 80 and 443 to the FQDN of the web server.


B.

Identify the blocked traffic in the Cisco FMC connection events to validate the block, and modify the policy to allow the traffic to the web server.


C.

Verify the blocks using the packet capture tool and create a rule with the action monitor for the traffic.


D.

Download a PCAP of the traffic attempts to verify the blocks and use the flexconfig objects to create a rule that allows only the required traffic to the destination server.


Expert Solution
Questions # 38:

A network administrator is configuring a site-to-site IPsec VPN to a router sitting behind a Cisco FTD. The administrator has configured an access policy to allow traffic to this device on UDP 500, 4500, and ESP VPN traffic is not working. Which action resolves this issue?

Options:

A.

Set the allow action in the access policy to trust.


B.

Enable IPsec inspection on the access policy.


C.

Modify the NAT policy to use the interface PAT.


D.

Change the access policy to allow all ports.


Expert Solution
Questions # 39:

A network administrator is deploying a Cisco IPS appliance and needs it to operate initially without affecting traffic flows.

It must also collect data to provide a baseline of unwanted traffic before being reconfigured to drop it. Which Cisco IPS mode meets these requirements?

Options:

A.

failsafe


B.

inline tap


C.

promiscuous


D.

bypass


Expert Solution
Questions # 40:

What is an attribute of the risk reporting capability in Cisco Secure Firewall Management Center?

Options:

A.

Includes all domains in a multidomain system


B.

Uses the same templates available to standard reports


C.

Includes the current domain in a multidomain system


D.

Uses the XML format to export all reporting


Expert Solution
Viewing page 4 out of 13 pages
Viewing questions 31-40 out of questions