300-710 PDF Pass Leader, 300-710 Latest Real Test
Valid 300-710 Test Answers & 300-710 Exam PDF
NEW QUESTION 39
Which two features of Cisco AMP for Endpoints allow for an uploaded file to be blocked? (Choose two.)
- A. application whitelisting
- B. file repository
- C. exclusions
- D. simple custom detection
- E. application blocking
Answer: D,E
NEW QUESTION 40
Which Cisco Firepower feature is used to reduce the number of events received in a period of time?
- A. suspending
- B. thresholding
- C. rate-limiting
- D. correlation
Answer: B
Explanation:
Reference: https://www.cisco.com/c/en/us/td/docs/security/firesight/541/firepower-module-user-guide/asa-firepower-module-user-guide-v541/Intrusion-Global-Threshold.html
NEW QUESTION 41
After deploying a network-monitoring tool to manage and monitor networking devices in your organization, you realize that you need to manually upload an MIB for the Cisco FMC. In which folder should you upload the MIB file?
- A. /etc/sf/DCEALERT.MIB
- B. system/etc/DCEALERT.MIB
- C. /etc/sf/DCMIB.ALERT
- D. /sf/etc/DCEALERT.MIB
Answer: A
NEW QUESTION 42
Drag and drop the steps to restore an automatic device registration failure on the standby Cisco FMC from the left into the correct order on the right. Not all options are used.
Answer:
Explanation:
Explanation
Explanation
Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config- guide-v62/firepower_management_center_high_availability.html#id_32288
NEW QUESTION 43
Which Cisco Advanced Malware Protection for Endpoints policy is used only for monitoring endpoint actively?
- A. audit
- B. Windows domain controller
- C. triage
- D. protection
Answer: A
Explanation:
Reference: https://www.cisco.com/c/en/us/support/docs/security/amp-endpoints/214933-amp-for-endpoints-deployment-methodology.html
NEW QUESTION 44
An organization must be able to ingest NetFlow traffic from their Cisco FTD device to Cisco Stealthwatch for behavioral analysis. What must be configured on the Cisco FTD to meet this requirement?
- A. variable set object for NetFlow
- B. flexconfig object for NetFlow
- C. security intelligence object for NetFlow
- D. interface object to export NetFlow
Answer: B
NEW QUESTION 45
The event dashboard within the Cisco FMC has been inundated with low priority intrusion drop events, which are overshadowing high priority events. An engineer has been tasked with reviewing the policies and reducing the low priority events. Which action should be configured to accomplish this task?
- A. drop and generate
- B. generate events
- C. drop connection
- D. drop packet
Answer: A
NEW QUESTION 46
Which CLI command is used to generate firewall debug messages on a Cisco Firepower?
- A. system support platform
- B. system support dump-table
- C. system support ssl-debug
- D. system support firewall-engine-debug
Answer: D
Explanation:
Section: Management and Troubleshooting
Explanation/Reference: https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/212330-firepower- management-center-display-acc.html
NEW QUESTION 47
An engineer configures an access control rule that deploys file policy configurations to security zones or tunnel zones, and it causes the device to restart. What is the reason for the restart?
- A. Source or destination security zones in the access control rule matches the security zones that are associated with interfaces on the target devices.
- B. The source tunnel zone in the rule does not match a tunnel zone that is assigned to a tunnel rule in the destination policy.
- C. Source or destination security zones in the source tunnel zone do not match the security zones that are associated with interfaces on the target devices.
- D. The source tunnel zone in the rule does not match a tunnel zone that is assigned to a tunnel rule in the source policy.
Answer: A
NEW QUESTION 48
Which command should be used on the Cisco FTD CLI to capture all the packets that hit an interface?
- A. capture WORD
- B. configure coredump packet-engine enable
- C. capture-traffic
- D. capture
Answer: C
Explanation:
Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/command_ref/b_Command_Reference_for_Firepower_Threat_Defense/ac_1.html
NEW QUESTION 49
Which two routing options are valid with Cisco FTD? (Choose Two)
- A. BGPv4 in transparent firewall mode
- B. BGPv4 with nonstop forwarding
- C. ECMP with up to three equal cost paths across multiple interfaces
- D. ECMP with up to three equal cost paths across a single interface
- E. BGPv6
Answer: D,E
NEW QUESTION 50
Which two packet captures does the FTD LINA engine support? (Choose two.)
- A. Layer 7 network ID
- B. dynamic firewall importing
- C. application ID
- D. protocol
- E. source IP
Answer: D,E
Explanation:
Section: Management and Troubleshooting
Explanation/Reference: https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/212474-working-with- firepower-threat-defense-f.html
NEW QUESTION 51
Refer to the exhibit.
And engineer is analyzing the Attacks Risk Report and finds that there are over 300 instances of new operating systems being seen on the network How is the Firepower configuration updated to protect these new operating systems?
- A. The administrator requests a Remediation Recommendation Report from Cisco Firepower
- B. The administrator manually updates the policies.
- C. Cisco Firepower automatically updates the policies.
- D. Cisco Firepower gives recommendations to update the policies.
Answer: D
Explanation:
Explanation
Ref:
https://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide-v60/Tailori
NEW QUESTION 52
With a recent summer time change, system logs are showing activity that occurred to be an hour behind real time Which action should be taken to resolve this issue?
- A. Configure the system clock settings to use NTP with Daylight Savings checked
- B. Configure the system clock settings to use NTP
- C. Manually adjust the time to the correct hour on the Cisco FMC.
- D. Manually adjust the time to the correct hour on all managed devices
Answer: A
NEW QUESTION 53
Which CLI command is used to generate firewall debug messages on a Cisco Firepower?
- A. system support platform
- B. system support dump-table
- C. system support ssl-debug
- D. system support firewall-engine-debug
Answer: D
Explanation:
Reference: https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/212330-firepower-management-center-display-acc.html
NEW QUESTION 54
An engineer currently has a Cisco FTD device registered to the Cisco FMC and is assigned the address of 10 10.50.12. The organization is upgrading the addressing schemes and there is a requirement to convert the addresses to a format that provides an adequate amount of addresses on the network What should the engineer do to ensure that the new addressing takes effect and can be used for the Cisco FTD to Cisco FMC connection?
- A. Cisco FMC does not support devices that use IPv4 IP addresses.
- B. Update the IP addresses from IFV4 to IPv6 without deleting the device from Cisco FMC
- C. Delete and reregister the device to Cisco FMC
- D. Format and reregister the device to Cisco FMC.
Answer: B
NEW QUESTION 55
When deploying a Cisco ASA Firepower module, an organization wants to evaluate the contents of the traffic without affecting the network. It is currently configured to have more than one instance of the same device on the physical appliance Which deployment mode meets the needs of the organization?
- A. inline tap monitor-only mode
- B. passive tap monitor-only mode
- C. inline mode
- D. passive monitor-only mode
Answer: D
NEW QUESTION 56
Which firewall design allows a firewall to forward traffic at layer 2 and layer 3 for the same subnet?
- A. transparent mode
- B. Cisco Firepower Threat Defense mode
- C. routed mode
- D. integrated routing and bridging
Answer: B
NEW QUESTION 57
What is a feature of Cisco AMP private cloud?
- A. It supports anonymized retrieval of threat intelligence
- B. It performs dynamic analysis
- C. It supports security intelligence filtering.
- D. It disables direct connections to the public cloud.
Answer: D
NEW QUESTION 58
A VPN user is unable to conned lo web resources behind the Cisco FTD device terminating the connection. While troubleshooting, the network administrator determines that the DNS responses are not getting through the Cisco FTD What must be done to address this issue while still utilizing Snort IPS rules?
- A. Uncheck the "Drop when Inline" box in the intrusion policy to allow the traffic.
- B. Modify the Snort rules to allow legitimate DNS traffic to the VPN users.
- C. Decrypt the packet after the VPN flow so the DNS queries are not inspected
- D. Disable the intrusion rule threshes to optimize the Snort processing.
Answer: B
NEW QUESTION 59
Which two actions can be used in an access control policy rule? (Choose two.)
- A. Block ALL
- B. Analyze
- C. Discover
- D. Monitor
- E. Block with Reset
Answer: D,E
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firesight/541/firepower-module-user-guide/asa- firepower-module-user-guide-v541/AC-Rules-Tuning-Overview.html#71854
NEW QUESTION 60
A network engineer is extending a user segment through an FTD device for traffic inspection without creating another IP subnet How is this accomplished on an FTD device in routed mode?
- A. by assigning an inline set interface
- B. by leveraging the ARP to direct traffic through the firewall
- C. by bypassing protocol inspection by leveraging pre-filter rules
- D. by using a BVI and create a BVI IP address in the same subnet as the user segment
Answer: D
Explanation:
https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-config-guide-v64/transparent_or_routed_firewall_mode_for_firepower_threat_defense.html
NEW QUESTION 61
......
IT enthusiasts who are willing to earn name and fame in the world of cybersecurity must think of taking the Cisco 300-710 exam. Packed with pivotal cognizance and expertise, it has everything that any security professional will need to stand out from the crowd and embark on a successful career journey.
300-710 Dumps Ensure Your Passing: https://www.newpassleader.com/Cisco/300-710-exam-preparation-materials.html
300-710 exam dumps and online Test Engine: https://drive.google.com/open?id=1mMWl-OD7b7FbSWVQMGdIc54wQ9g2krOK