Pass the Cisco CCNP Security 300-710 Questions and answers with CertsForce

Viewing page 9 out of 10 pages
Viewing questions 81-90 out of questions
Questions # 81:

Which policy rule is included in the deployment of a local DMZ during the initial deployment of a Cisco NGFW through the Cisco FMC GUI?

Options:

A.

a default DMZ policy for which only a user can change the IP addresses.


B.

deny ip any


C.

no policy rule is included


D.

permit ip any


Expert Solution
Questions # 82:

Which protocol establishes network redundancy in a switched Firepower device deployment?

Options:

A.

STP


B.

HSRP


C.

GLBP


D.

VRRP


Expert Solution
Questions # 83:

On the advanced tab under inline set properties, which allows interfaces to emulate a passive interface?

Options:

A.

transparent inline mode


B.

TAP mode


C.

strict TCP enforcement


D.

propagate link state


Expert Solution
Questions # 84:

Within an organization's high availability environment where both firewalls are passing traffic, traffic must be segmented based on which department it is destined for. Each department is situated on a different LAN. What must be configured to meet these requirements?

Options:

A.

span EtherChannel clustering


B.

redundant interfaces


C.

high availability active/standby firewalls


D.

multi-instance firewalls


Expert Solution
Questions # 85:

A Cisco FTD has two physical interfaces assigned to a BVI. Each interface is connected to a different VLAN on the same switch. Which firewall mode is the Cisco FTD set up to support?

Options:

A.

active/active failover


B.

transparent


C.

routed


D.

high availability clustering


Expert Solution
Questions # 86:

What is the difference between inline and inline tap on Cisco Firepower?

Options:

A.

Inline tap mode can send a copy of the traffic to another device.


B.

Inline tap mode does full packet capture.


C.

Inline mode cannot do SSL decryption.


D.

Inline mode can drop malicious traffic.


Expert Solution
Questions # 87:

What are the minimum requirements to deploy a managed device inline?

Options:

A.

inline interfaces, security zones, MTU, and mode


B.

passive interface, MTU, and mode


C.

inline interfaces, MTU, and mode


D.

passive interface, security zone, MTU, and mode


Expert Solution
Questions # 88:

When deploying a Cisco ASA Firepower module, an organization wants to evaluate the contents of the traffic without affecting the network. It is currently configured to have more than one instance of the same device on the physical appliance Which deployment mode meets the needs of the organization?

Options:

A.

inline tap monitor-only mode


B.

passive monitor-only mode


C.

passive tap monitor-only mode


D.

inline mode


Expert Solution
Questions # 89:

A network security engineer must replace a faulty Cisco FTD device in a high availability pair. Which action must be taken while replacing the faulty unit?

Options:

A.

Shut down the Cisco FMC before powering up the replacement unit.


B.

Ensure that the faulty Cisco FTD device remains registered to the Cisco FMC.


C.

Unregister the faulty Cisco FTD device from the Cisco FMC


D.

Shut down the active Cisco FTD device before powering up the replacement unit.


Expert Solution
Questions # 90:

A network engineer implements a new Cisco Firepower device on the network to take advantage of its intrusion detection functionality. There is a requirement to analyze the traffic going across the device, alert on any malicious traffic, and appear as a bump in the wire How should this be implemented?

Options:

A.

Specify the BVl IP address as the default gateway for connected devices.


B.

Enable routing on the Cisco Firepower


C.

Add an IP address to the physical Cisco Firepower interfaces.


D.

Configure a bridge group in transparent mode.


Expert Solution
Viewing page 9 out of 10 pages
Viewing questions 81-90 out of questions