
Verified 300-710 dumps Q&As - 100% Pass from ITPassLeader
Pass 300-710 Exam in First Attempt Guaranteed 2023 Dumps!
NEW QUESTION # 123
Which command-line mode is supported from the Cisco FMC CLI?
- A. admin
- B. user
- C. configuration
- D. privileged
Answer: C
Explanation:
Section: Management and Troubleshooting
Explanation/Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/660/configuration/guide/fpmc-config- guide-v66/command_line_reference.pdf
NEW QUESTION # 124
Which Cisco Firepower Threat Defense, which two interface settings are required when configuring a routed interface? (Choose two.)
- A. Speed
- B. Duplex
- C. EtherChannel
- D. Redundant Interface
- E. Media Type
Answer: A,B
Explanation:
Explanation
https://www.cisco.com/c/en/us/td/docs/security/firepower/610/fdm/fptd-fdm-config-guide-610/fptd-fdm-interfaces.html
NEW QUESTION # 125
An organization is migrating their Cisco ASA devices running in multicontext mode to Cisco FTD devices. Which action must be taken to ensure that each context on the Cisco ASA is logically separated in the Cisco FTD devices?
- A. Configure the Cisco FTD to use port channels spanning multiple networks.
- B. Add a native instance to distribute traffic to each Cisco FTD context.
- C. Configure a container instance in the Cisco FTD for each context in the Cisco ASA.
- D. Add the Cisco FTD device to the Cisco ASA port channels.
Answer: C
NEW QUESTION # 126
Which firewall design will allow It to forward traffic at layers 2 and 3 for the same subnet?
- A. Cisco Firepower Threat Defense mode
- B. transparent mode
- C. Integrated routing and bridging
- D. routed mode
Answer: C
Explanation:
Integrated routing and bridging (IRB) is a feature of Cisco Firepower Threat Defense (FTD) that allows the firewall to forward traffic at both layers 2 and 3 for the same subnet. In this mode, the firewall can act as a switch or a bridge to forward traffic at layer 2 and as a router to forward traffic at layer 3. This allows the firewall to maintain full control over the traffic, while still allowing it to forward traffic at both layers.
https://www.cisco.com/c/en/us/td/docs/security/firepower/ftd-config-guide/FTD-Config-Guide-v6/Integrated-Routing-and-Bridging.html
NEW QUESTION # 127
Within Cisco Firepower Management Center, where does a user add or modify widgets?
- A. reporting
- B. dashboard
- C. context explorer
- D. summary tool
Answer: B
NEW QUESTION # 128
An engineer is setting up a new Firepower deployment and is looking at the default FMC policies to start the implementation During the initial trial phase, the organization wants to test some common Snort rules while still allowing the majority of network traffic to pass Which default policy should be used?
- A. Connectivity Over Security
- B. Maximum Detection
- C. Security Over Connectivity
- D. Balanced Security and Connectivity
Answer: D
Explanation:
Explanation
https://www.cisco.com/c/en/us/td/docs/security/firepower/623/fdm/fptd-fdm-config-guide-623/fptd-fdm-intrusio
NEW QUESTION # 129
An engineer must define a URL object on Cisco FMC. What is the correct method to specify the URL without performing SSL inspection?
- A. Specify all subdomains in the object group.
- B. Use Subject Common Name value.
- C. Specify the protocol in the object.
- D. Include all URLs from CRL Distribution Points.
Answer: A
NEW QUESTION # 130
Which command is typed at the CLI on the primary Cisco FTD unit to temporarily stop running high-availability?
- A. system support network-options
- B. configure high-availability resume
- C. configure high-availability suspend
- D. configure high-availability disable
Answer: D
Explanation:
Section: Management and Troubleshooting
Explanation/Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/610/configuration/guide/fpmc-config- guide-v61/firepower_threat_defense_high_availability.html
NEW QUESTION # 131
Which two types of objects are reusable and supported by Cisco FMC? (Choose two.)
- A. network-based objects that represent FQDN mappings and networks, port/protocol pairs, VXLAN tags, security zones and origin/destination country
- B. reputation-based objects, such as URL categories
- C. dynamic key mapping objects that help link HTTP and HTTPS GET requests to Layer 7 application protocols.
- D. reputation-based objects that represent Security Intelligence feeds and lists, application filters based on category and reputation, and file lists
- E. network-based objects that represent IP address and networks, port/protocols pairs, VLAN tags, security zones, and origin/destination country
Answer: D,E
Explanation:
Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/reusable_objects.html#ID-2243-00000414
NEW QUESTION # 132
While configuring FTD, a network engineer wants to ensure that traffic passing through the appliance does not require routing or Vlan rewriting. Which interface mode should the engineer implement to accomplish this task?
- A. passive
- B. Inline set
- C. Inline tap
- D. transparent
Answer: D
NEW QUESTION # 133
An engineer must configure the firewall to monitor traffic within a single subnet without increasing the hop count of that traffic. How would the engineer achieve this?
- A. Configure Cisco Firepower in FXOS monitor only mode.
- B. Set up Cisco Firepower in intrusion prevention mode
- C. Set up Cisco Firepower as managed by Cisco FDM
- D. Configure Cisco Firepower as a transparent firewall
Answer: D
NEW QUESTION # 134
Which Firepower feature allows users to configure bridges in routed mode and enables devices to perform Layer 2 switching between interfaces?
- A. FlexConfig
- B. BDI
- C. SGT
- D. IRB
Answer: D
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/620/relnotes/ Firepower_System_Release_Notes_Version_620/new_features_and_functionality.html
NEW QUESTION # 135
Which action should you take when Cisco Threat Response notifies you that AMP has identified a file as malware?
- A. Send a snapshot to Cisco for technical support.
- B. Forward the result of the investigation to an external threat-analysis engine.
- C. Wait for Cisco Threat Response to automatically block the malware.
- D. Add the malicious file to the block list.
Answer: D
Explanation:
Section: Integration
NEW QUESTION # 136
Which CLI command is used to control special handling of ClientHello messages?
- A. system support ssl-client-hello-enabled
- B. system support ssl-client-hello-display
- C. system support ssl-client-hello-tuning
- D. system support ssl-client-hello-force-reset
Answer: A
NEW QUESTION # 137
A network engineer is extending a user segment through an FTD device for traffic inspection without creating another IP subnet How is this accomplished on an FTD device in routed mode?
- A. by assigning an inline set interface
- B. by using a BVI and create a BVI IP address in the same subnet as the user segment
- C. by bypassing protocol inspection by leveraging pre-filter rules
- D. by leveraging the ARP to direct traffic through the firewall
Answer: B
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-config-guide-v64/transparent_or_routed_firewall_mode_for_firepower_threat_defense.html
NEW QUESTION # 138
An engineer has been tasked with providing disaster recovery for an organization's primary Cisco FMC. What must be done on the primary and secondary Cisco FMCs to ensure that a copy of the original corporate policy is available if the primary Cisco FMC fails?
- A. Restore the primary Cisco FMC backup configuration to the secondary Cisco FMC device when the primary device fails
- B. Connect the primary and secondary Cisco FMC devices with Category 6 cables of not more than 10 meters in length.
- C. Configure high-availability in both the primary and secondary Cisco FMCs
- D. Place the active Cisco FMC device on the same trusted management network as the standby device
Answer: C
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/firepower_management_center_high_availability.html
NEW QUESTION # 139
A network engineer implements a new Cisco Firepower device on the network to take advantage of its intrusion detection functionality. There is a requirement to analyze the traffic going across the device, alert on any malicious traffic, and appear as a bump in the wire How should this be implemented?
- A. Configure a bridge group in transparent mode.
- B. Enable routing on the Cisco Firepower
- C. Add an IP address to the physical Cisco Firepower interfaces.
- D. Specify the BVl IP address as the default gateway for connected devices.
Answer: A
Explanation:
Traditionally, a firewall is a routed hop and acts as a default gateway for hosts that connect to one of its screened subnets. A transparent firewall, on the other hand, is a Layer 2 firewall that acts like a "bump in the wire," or a "stealth firewall," and is not seen as a router hop to connected devices. However, like any other firewall, access control between interfaces is controlled, and all of the usual firewall checks are in place. Layer 2 connectivity is achieved by using a "bridge group" where you group together the inside and outside interfaces for a network, and the ASA uses bridging techniques to pass traffic between the interfaces. Each bridge group includes a Bridge Virtual Interface (BVI) to which you assign an IP address on the network. You can have multiple bridge groups for multiple networks. In transparent mode, these bridge groups cannot communicate with each other. https://www.cisco.com/c/en/us/td/docs/security/asa/asa97/configuration/general/asa-97-general-config/intro-fw.html
NEW QUESTION # 140
Which action should be taken after editing an object that is used inside an access control policy?
- A. Delete the existing object in use.
- B. Create another rule using a different object name.
- C. Refresh the Cisco FMC GUI for the access control policy.
- D. Redeploy the updated configuration.
Answer: D
Explanation:
Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/630/configuration/guide/fpmc-config-guide-v63/reusable_objects.html
NEW QUESTION # 141
......
300-710 Dumps Full Questions - Exam Study Guide: https://www.itpassleader.com/Cisco/300-710-dumps-pass-exam.html
Use Real 300-710 - 100% Cover Real Exam Questions: https://drive.google.com/open?id=12Omz5jVAk99qRmmEwFGnO3NuSBDRRsFb