Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Cisco CCNP Security 300-710 Questions and answers with CertsForce

Viewing page 7 out of 13 pages
Viewing questions 61-70 out of questions
Questions # 61:

How many report templates does the Cisco Firepower Management Center support?

Options:

A.

20


B.

10


C.

5


D.

unlimited


Expert Solution
Questions # 62:

Refer to the exhibit.

Question # 62

A user on a computer named Client1 is performing a traceroute to IP address 209.165.202.2. Drag and drop the appropriate values onto the fields in the Capture w/Trace configuration and captured-packet output. Not all options are used.

Question # 62


Expert Solution
Questions # 63:

Refer to the exhibit.

A systems administrator conducts a connectivity test to their SCCM server from a host machine and gets no response from the server. Which action ensures that the ping packets reach the destination and that the host receives replies?

Options:

A.

Create an access control policy rule that allows ICMP traffic.


B.

Configure a custom Snort signature to allow ICMP traffic after Inspection.


C.

Modify the Snort rules to allow ICMP traffic.


D.

Create an ICMP allow list and add the ICMP destination to remove it from the implicit deny list.


Expert Solution
Questions # 64:

Which two types of objects are reusable and supported by Cisco FMC? (Choose two.)

Options:

A.

dynamic key mapping objects that help link HTTP and HTTPS GET requests to Layer 7 application protocols.


B.

reputation-based objects that represent Security Intelligence feeds and lists, application filters based on category and reputation, and file lists


C.

network-based objects that represent IP address and networks, port/protocols pairs, VLAN tags, security zones, and origin/destination country


D.

network-based objects that represent FQDN mappings and networks, port/protocol pairs, VXLAN tags, security zones and origin/destination country


E.

reputation-based objects, such as URL categories


Expert Solution
Questions # 65:

An administrator must fix a network problem whereby traffic from the inside network to a webserver is not getting through an instance of Cisco Secure Firewall Threat Defense. Which command must the administrator use to capture packets to the webserver that are dropped by Secure Firewall Throat Defense and resold the issue?

Options:

A.

capture CAP int OUTSIDE match ip any host WEBSERVERIP


B.

capture CAP type asp-drop all headers-only


C.

capture CAP int INSIDE match ip any host WEBSERVERIP


D.

capture CAP int INSIDE match tcp any 80 host WEBSERVERlP 80


Expert Solution
Questions # 66:

An engineer must build redundancy into the network and traffic must continuously flow if a redundant switch in front of the firewall goes down. What must be configured to accomplish this task?

Options:

A.

redundant interfaces on the firewall cluster mode and switches


B.

redundant interfaces on the firewall noncluster mode and switches


C.

vPC on the switches to the interface mode on the firewall duster


D.

vPC on the switches to the span EtherChannel on the firewall cluster


Expert Solution
Questions # 67:

A network administrator configured a NAT policy that translates a public IP address to an internal web server IP address. An access policy has also been created that allows any source to reach the public IP address on port 80. The web server is still not reachable from the Internet on port 80. Which configuration change is needed?

Options:

A.

The intrusion policy must be disabled for port 80.


B.

The access policy rule must be configured for the action trust.


C.

The NAT policy must be modified to translate the source IP address as well as destination IP address.


D.

The access policy must allow traffic to the internal web server IP address.


Expert Solution
Questions # 68:

Refer to the exhibit.

Question # 68

And engineer is analyzing the Attacks Risk Report and finds that there are over 300 instances of new operating systems being seen on the network How is the Firepower configuration updated to protect these new operating systems?

Options:

A.

Cisco Firepower automatically updates the policies.


B.

The administrator requests a Remediation Recommendation Report from Cisco Firepower


C.

Cisco Firepower gives recommendations to update the policies.


D.

The administrator manually updates the policies.


Expert Solution
Questions # 69:

An engineer defines a new rule while configuring an Access Control Policy. After deploying the policy, the rule is not working as expected and the hit counters associated with the rule are showing zero. What is causing this error?

Options:

A.

Logging is not enabled for the rule.


B.

The rule was not enabled after being created.


C.

The wrong source interface for Snort was selected in the rule.


D.

An incorrect application signature was used in the rule.


Expert Solution
Questions # 70:

When an engineer captures traffic on a Cisco FTD to troubleshoot a connectivity problem, they receive a large amount of output data in the GUI tool. The engineer found that viewing the Captures this way is time-consuming and difficult lo son and filter. Which file type must the engineer export the data in so that it can be reviewed using a tool built for this type of analysis?

Options:

A.

NetFlow v9


B.

PCAP


C.

NetFlow v5


D.

IPFIX


Expert Solution
Viewing page 7 out of 13 pages
Viewing questions 61-70 out of questions