Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Cisco CCNP Security 300-710 Questions and answers with CertsForce

Viewing page 6 out of 13 pages
Viewing questions 51-60 out of questions
Questions # 51:

A network administrator has converted a Cisco FTD from using LDAP to LDAPS for VPN authentication. The Cisco FMC can connect to the LDAPS server, but the Cisco FTD is not connecting. Which configuration must be enabled on the Cisco FTD?

Options:

A.

SSL must be set to a use TLSv1.2 or lower.


B.

The LDAPS must be allowed through the access control policy.


C.

DNS servers must be defined for name resolution.


D.

The RADIUS server must be defined.


Expert Solution
Questions # 52:

An engineer is troubleshooting application failures through a FTD deployment. While using the FMC CLI. it has been determined that the traffic in question is not matching the desired policy. What should be done to correct this?

Options:

A.

Use the system support firewall-engine-debug command to determine which rules the traffic matchingand modify the rule accordingly


B.

Use the system support application-identification-debug command to determine which rules the traffic matching and modify the rule accordingly


C.

Use the system support firewall-engine-dump-user-f density-data command to change the policy and allow the application through the firewall.


D.

Use the system support network-options command to fine tune the policy.


Expert Solution
Questions # 53:

A company is in the process of deploying intrusion protection with Cisco FTDs managed by a Cisco FMC. Which action must be selected to enable fewer rules detect only critical conditions and avoid false positives?

Options:

A.

Connectivity Over Security


B.

Balanced Security and Connectivity


C.

Maximum Detection


D.

No Rules Active


Expert Solution
Questions # 54:

An engineer is creating an URL object on Cisco FMC How must it be configured so that the object will match for HTTPS traffic in an access control policy?

Options:

A.

Specify the protocol to match (HTTP or HTTPS).


B.

Use the FQDN including the subdomain for the website


C.

Define the path to the individual webpage that uses HTTPS.


D.

Use the subject common name from the website certificate


Expert Solution
Questions # 55:

A security engineer must deploy a Cisco FTD appliance as a bump in the wire to detect intrusion events without disrupting the flow of network traffic. Which two features must be configured to accomplish the task? (Choose two.)

Options:

A.

inline set pair


B.

transparent mode


C.

tapemode


D.

passive interfaces


E.

bridged mode


Expert Solution
Questions # 56:

An engineer must configure email notifications on Cisco Secure Firewall Management Center. TLS encryption must be used to protect the messages from unauthorized access. The engineer adds the IP address of the mail relay host and must set the port number. Which TCP port must the engineer use?

Options:

A.

25


B.

389


C.

465


D.

587


Expert Solution
Questions # 57:

An engineer must permit SSH on the inside interface of a Cisco Secure Firewall Threat Defense device. SSH is currently permitted only on the management interface. Which type of policy

must the engineer configure?

Options:

A.

platform policy


B.

access control policy


C.

NAT policy


D.

intrusion policy


Expert Solution
Questions # 58:

An engineer configures an access control rule that deploys file policy configurations to security zones or tunnel zones, and it causes the device to restart. What is the reason for the restart?

Options:

A.

Source or destination security zones in the access control rule matches the security zones that are associated with interfaces on the target devices.


B.

The source tunnel zone in the rule does not match a tunnel zone that is assigned to a tunnel rule in the destination policy.


C.

Source or destination security zones in the source tunnel zone do not match the security zones that are associated with interfaces on the target devices.


D.

The source tunnel zone in the rule does not match a tunnel zone that is assigned to a tunnel rule in the source policy.


Expert Solution
Questions # 59:

Which policy rule is included in the deployment of a local DMZ during the initial deployment of a Cisco NGFW through the Cisco FMC GUI?

Options:

A.

a default DMZ policy for which only a user can change the IP addresses.


B.

deny ip any


C.

no policy rule is included


D.

permit ip any


Expert Solution
Questions # 60:

A network administrator notices that inspection has been interrupted on all non-managed interfaces of a device. What is the cause of this?

Options:

A.

The value of the highest MTU assigned to any non-management interface was changed.


B.

The value of the highest MSS assigned to any non-management interface was changed.


C.

A passive interface was associated with a security zone.


D.

Multiple inline interface pairs were added to the same inline interface.


Expert Solution
Viewing page 6 out of 13 pages
Viewing questions 51-60 out of questions