[2022] Verified 300-710 Dumps Q&As - 1 Year Free & Quickly Updates [Q63-Q78]

Share

[2022] Verified 300-710 Dumps Q&As - 1 Year Free & Quickly Updates

Latest 2022 Realistic Verified 300-710 Dumps - 100% Free 300-710 Exam Dumps

NEW QUESTION 63
With Cisco FTD software, which interface mode must be configured to passively receive traffic that passes through the appliance?

  • A. ERSPAN
  • B. IPS-only
  • C. firewall
  • D. tap

Answer: A

Explanation:
Reference:
v64/interface_overview_for_firepower_threat_defense.html

 

NEW QUESTION 64
Which connector is used to integrate Cisco ISE with Cisco FMC for Rapid Threat Containment?

  • A. FMC RTC
  • B. pxGrid
  • C. ISEGrid
  • D. FTD RTC

Answer: B

Explanation:
Section: Integration

 

NEW QUESTION 65
With Cisco FTD integrated routing and bridging, which interface does the bridge group use to communicate with a routed interface?

  • A. switch virtual
  • B. bridge group member
  • C. bridge virtual
  • D. subinterface

Answer: B

 

NEW QUESTION 66
A network engineer is receiving reports of users randomly getting disconnected from their corporate applications which traverses the data center FTD appliance Network monitoring tools show that the FTD appliance utilization is peaking above 90% of total capacity. What must be done in order to further analyze this issue?

  • A. Use the Packet Export feature to save data onto external drives
  • B. Use the Packet Analysis feature for capturing network data
  • C. Use the Packet Capture feature to collect real-time network traffic
  • D. Use the Packet Tracer feature for traffic policy analysis

Answer: C

Explanation:
Reference:
https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/212474-working-with-firepower-threat-defense-f.html

 

NEW QUESTION 67
A security engineer must deploy a Cisco FTD appliance as a bump in the wire to detect intrusion events without disrupting the flow of network traffic. Which two features must be configured to accomplish the task? (Choose two.)

  • A. tapemode
  • B. bridged mode
  • C. passive interfaces
  • D. inline set pair
  • E. transparent mode

Answer: A,E

 

NEW QUESTION 68
An engineer has been asked to show application usages automatically on a monthly basis and send the information to management What mechanism should be used to accomplish this task?

  • A. dashboards
  • B. event viewer
  • C. context explorer
  • D. reports

Answer: B

 

NEW QUESTION 69
A Cisco FTD has two physical interfaces assigned to a BVI. Each interface is connected to a different VLAN on the same switch. Which firewall mode is the Cisco FTD set up to support?

  • A. routed
  • B. high availability clustering
  • C. transparent
  • D. active/active failover

Answer: C

 

NEW QUESTION 70
An engineer is configuring a second Cisco FMC as a standby device but is unable to register with the active unit. What is causing this issue?

  • A. The primary FMC currently has devices connected to it.
  • B. The code versions running on the Cisco FMC devices are different
  • C. There is only 10 Mbps of bandwidth between the two devices.
    https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/firepower_management_center_high_availability.html
  • D. The licensing purchased does not include high availability

Answer: B

 

NEW QUESTION 71
Which protocol establishes network redundancy in a switched Firepower device deployment?

  • A. GLBP
  • B. VRRP
  • C. HSRP
  • D. STP

Answer: D

Explanation:
Section: Deployment
Explanation/Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config- guide-v62/firepower_threat_defense_high_availability.html

 

NEW QUESTION 72
With Cisco Firepower Threat Defense software, which interface mode must be configured to passively receive traffic that passes through the appliance?

  • A. inline tap
  • B. routed
  • C. passive
  • D. inline set

Answer: C

Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-config- guide-v64/interface_overview_for_firepower_threat_defense.html

 

NEW QUESTION 73
An organization wants to secure traffic from their branch office to the headquarter building using Cisco Firepower devices, They want to ensure that their Cisco Firepower devices are not wasting resources on inspecting the VPN traffic. What must be done to meet these requirements?

  • A. Configure the Cisco Firepower devices to ignore the VPN traffic using prefilter policies
  • B. Tune the intrusion policies in order to allow the VPN traffic through without inspection
  • C. Configure the Cisco Firepower devices to bypass the access control policies for VPN traffic.
  • D. Enable a flexconfig policy to re-classify VPN traffic so that it no longer appears as interesting traffic

Answer: C

Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/640/fdm/fptd-fdm-config-guide-640/fptd-fdm-ravpn.html

 

NEW QUESTION 74
Which command is typed at the CLI on the primary Cisco FTD unit to temporarily stop running high- availability?

  • A. configure high-availability suspend
  • B. configure high-availability disable
  • C. system support network-options
  • D. configure high-availability resume

Answer: B

Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/610/configuration/guide/fpmc-config- guide-v61/firepower_threat_defense_high_availability.html

 

NEW QUESTION 75
Refer to the exhibit. What must be done to fix access to this website while preventing the same communication to all other websites?

  • A. Create an access control policy rule to allow port 80 to only 172.1.1.50.
  • B. Create an intrusion policy rule to have Snort allow port 443 to only 172.1.1.50.
  • C. Create an access control policy rule to allow port 443 to only 172.1.1.50.
  • D. Create an intrusion policy rule to have Snort allow port 80 to only 172.1.1.50.

Answer: A

 

NEW QUESTION 76
Which two remediation options are available when Cisco FMC is integrated with Cisco ISE? (Choose two.)

  • A. quarantine
  • B. dynamic null route configured
  • C. port shutdown
  • D. DHCP pool disablement
  • E. host shutdown

Answer: A,C

Explanation:
Section: Integration
Explanation/Reference: https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/210524-configure- firepower-6-1-pxgrid-remediati.html

 

NEW QUESTION 77
Which command should be used on the Cisco FTD CLI to capture all the packets that hit an interface?

  • A. capture-traffic
  • B. capture WORD
  • C. capture
  • D. configure coredump packet-engine enable

Answer: A

Explanation:
Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/command_ref/b_Command_Reference_for_Firepower_Threat_Defense/ac_1.html

 

NEW QUESTION 78
......

300-710 Dumps PDF and Test Engine Exam Questions: https://pass4sure.actual4cert.com/300-710-pass4sure-vce.html