Month End Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Cisco CCNP Security 300-710 Questions and answers with CertsForce

Viewing page 9 out of 12 pages
Viewing questions 81-90 out of questions
Questions # 81:

An engineer must investigate a connectivity issue from an endpoint behind a Cisco FTD device and a public DNS server. The endpoint cannot perform name resolution queries. Which action must the engineer perform to troubleshoot the issue by simulating real DNS traffic on the Cisco FTD while verifying the Snarl verdict?

Options:

A.

Perform a Snort engine capture using tcpdump from the FTD CLI.


B.

Use the Capture w/Trace wizard in Cisco FMC.


C.

Create a Custom Workflow in Cisco FMC.


D.

Run me system support firewall-engine-debug command from me FTD CLI.


Expert Solution
Questions # 82:

Which limitation applies to Cisco Firepower Management Center dashboards in a multidomain environment?

Options:

A.

Child domains can view but not edit dashboards that originate from an ancestor domain.


B.

Child domains have access to only a limited set of widgets from ancestor domains.


C.

Only the administrator of the top ancestor domain can view dashboards.


D.

Child domains cannot view dashboards that originate from an ancestor domain.


Expert Solution
Questions # 83:

A network security engineer must export packet captures from the Cisco FMC web browser while troubleshooting an issue. When navigating to the address https:// /capture/CAPI/pcap/test.pcap. an error 403: Forbidden is given instead of the PCAP file. Which action must the engineer take to resolve this issue?

Options:

A.

Disable the HTTPS server and use HTTP instead.


B.

Enable the HTTPS server for the device platform policy.


C.

Disable the proxy setting on the browser.


D.

Use the Cisco FTD IP address as the proxy server setting on the browser.


Expert Solution
Questions # 84:

A security engineer is configuring an Access Control Policy for multiple branch locations These locations share a common rule set and utilize a network object called INSIDE_NET which contains the locally significant internal network subnets at each location What technique will retain the policy consistency at each location but allow only the locally significant network subnet within the applicable rules?

Options:

A.

utilizing policy inheritance


B.

utilizing a dynamic ACP that updates from Cisco Talos


C.

creating a unique ACP per device


D.

creating an ACP with an INSIDE_NET network object and object overrides


Expert Solution
Questions # 85:

What is an advantage of adding multiple inline interface pairs to the same inline interface set when deploying an asynchronous routing configuration?

Options:

A.

Allows the IPS to identify inbound and outbound traffic as part of the same traffic flow.


B.

The interfaces disable autonegotiation and interface speed is hard coded set to 1000 Mbps.


C.

Allows traffic inspection to continue without interruption during the Snort process restart.


D.

The interfaces are automatically configured as a media-independent interface crossover.


Expert Solution
Questions # 86:

A network engineer sets up a secondary CiscoFMC that is integrated with Cisco Security Packet Analyzer What occurs when the secondary CiscoFMC synchronizes with the primary Cisco FMC?

Options:

A.

The existing integration configuration is replicated to the primary Cisco FMC


B.

The existing configuration for integration of the secondary Cisco FMC the Cisco Security Packet Analyzer is overwritten.


C.

The synchronization between the primary and secondary Cisco FMC fails


D.

The secondary Cisco FMC must be reintegrated with the Cisco Security Packet Analyzer after the synchronization


Expert Solution
Questions # 87:

An engineer has been asked to show application usages automatically on a monthly basis and send the information to management What mechanism should be used to accomplish this task?

Options:

A.

event viewer


B.

reports


C.

dashboards


D.

context explorer


Expert Solution
Questions # 88:

Which Cisco Advanced Malware Protection for Endpoints policy is used only for monitoring endpoint actively?

Options:

A.

Windows domain controller


B.

audit


C.

triage


D.

protection


Expert Solution
Questions # 89:

Which two routing options are valid with Cisco Firepower Threat Defense? (Choose two.)

Options:

A.

BGPv6


B.

ECMP with up to three equal cost paths across multiple interfaces


C.

ECMP with up to three equal cost paths across a single interface


D.

BGPv4 in transparent firewall mode


E.

BGPv4 with nonstop forwarding


Expert Solution
Questions # 90:

Which action should be taken after editing an object that is used inside an access control policy?

Options:

A.

Delete the existing object in use.


B.

Refresh the Cisco FMC GUI for the access control policy.


C.

Redeploy the updated configuration.


D.

Create another rule using a different object name.


Expert Solution
Viewing page 9 out of 12 pages
Viewing questions 81-90 out of questions