Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Cisco CCNP Security 300-710 Questions and answers with CertsForce

Viewing page 9 out of 13 pages
Viewing questions 81-90 out of questions
Questions # 81:

Question # 81

Refer to the exhibit. An engineer is deploying a new instance of Cisco Secure Firewall Threat Defense. Which action must the engineer take next so that Client_A and Client_B receive an IP address via DHCP from Server_A?

Options:

A.

Disable Option 82 in the DHCP relay configuration properties using Secure Firewall Management Center.


B.

Add access rules that allow DHCP traffic by using Cisco Secure Firewall Management Center.


C.

Add another DHCP pool on Server_A with DHCP relay on Secure Firewall Threat Defense.


D.

Disable all the DHCP Snort rules by using Secure Firewall Device Manager.


Expert Solution
Questions # 82:

A network administrator is configuring a transparent Cisco Secure Firewall Threat Defense registered to a Cisco Secure Firewall Management Center. The administrator wants to configure the Secure Firewall Threat Defense to allow ARP traffic to pass between two interfaces of a bridge group. What must be configured?

Options:

A.

Use the default configuration on the devices.


B.

An access policy must allow MAC address FFFF.FFFF.FFFF.


C.

ARP inspection must be disabled.


D.

An access policy must allow MAC address 0100.0CCC.CCCD.


Expert Solution
Questions # 83:

Question # 83

Refer to the exhibit. An engineer is configuring an instance of Cisco Secure Firewall Threat Defense with interfaces in IPS Inline Pair mode. What must be configured on interface e1/6 to accomplish the requirement?

Options:

A.

propagate link state disabled


B.

inline set MTU set to 1500


C.

FailSafe disabled


D.

security zone set to OUTSIDE_ZONE


Expert Solution
Questions # 84:

An engineer must configure an ERSPAN passive interface on a Cisco Secure IPS by using the Cisco Secure Firewall Management Center. These configurations have been performed already:

Configure the passive interface.

Configure the ERSPAN IP address.

Which two additional settings must be configured to complete the configuration? (Choose two.)

Options:

A.

Source IP


B.

Bypass Mode


C.

TCP Intercept


D.

Flow ID


E.

Destination MAC


Expert Solution
Questions # 85:

An engineer must configure a new identity policy in Cisco Firepower Management Center. Active authentication must be configured by using a Kerberos connection. Which two realms must be configured? (Choose two.)

Options:

A.

Directory password


B.

Active directory join password


C.

Active directory primary domain


D.

Active directory join username


E.

Directory username


Expert Solution
Questions # 86:

An engineer must integrate a thud-party security Intelligence teed with Cisco Secure Firewall Management Center. Secure Firewall Management Center is running Version 6.2 3 and has 8 GB of memory. Which two actions must be taken to implement Throat Intelligence Director? (Choose two.)

Options:

A.

Upgrade to version 6.6.


B.

Enable REST API access.


C.

Add the URL of the TAXII server.


D.

Add 7 GB of memory.


E.

Add a TAXII server


Expert Solution
Questions # 87:

An engineer has been tasked with providing disaster recovery for an organization ' s primary Cisco FMC. What must be done on the primary and secondary Cisco FMCs to ensure that a copy of the original corporate policy is available if the primary Cisco FMC fails?

Options:

A.

Configure high-availability in both the primary and secondary Cisco FMCs


B.

Connect the primary and secondary Cisco FMC devices with Category 6 cables of not more than 10 meters in length.


C.

Place the active Cisco FMC device on the same trusted management network as the standby device


D.

Restore the primary Cisco FMC backup configuration to the secondary Cisco FMC device when the primary device fails


Expert Solution
Questions # 88:

Drag and drop the configuration steps from the left into the sequence on the right to enable external authentication on Cisco FMC to a RADIUS server.

Question # 88


Expert Solution
Questions # 89:

An engineer is configuring a file policy on a Cisco Secure Firewall Management Center appliance. Files with an Unknown disposition must be analyzed by Cisco Secure Malware Analytics. What must be configured on the Secure Firewall Management Center appliance?

Options:

A.

Sandbox Analysis


B.

Spero Analysis


C.

Malware Analysis


D.

Dynamic Analysis


Expert Solution
Questions # 90:

Which component is needed to perform rapid threat containment with Cisco FMC?

Options:

A.

ISE


B.

RESTful API


C.

SIEM


D.

DDI


Expert Solution
Viewing page 9 out of 13 pages
Viewing questions 81-90 out of questions