Pre-Winter Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

Cisco 300-710 - Securing Networks with Cisco Firewalls

Page: 9 / 13
Total 420 questions

Which Cisco Secure Firewall Threat Defense interface mode must be deployed when implementing an IPS that must receive and retransmit all traffic unless the traffic is explicitly dropped?

A.

Routed

B.

Inline

C.

Passive

D.

Transparent

IT management is asking the network engineer to provide high-level summary statistics of the Cisco FTD appliance in the network. The business is approaching a peak season so the need to maintain business uptime is high. Which report type should be used to gather this information?

A.

Malware Report

B.

Standard Report

C.

SNMP Report

D.

Risk Report

What is the purpose of the IRB feature in next-generation firewall?

A.

To allow multiple physical interfaces to be part of the same VLAN

B.

To enable transparent bridging between two Layer 2 interfaces

C.

To block routing between two Layer 3 interfaces

D.

To configure NAT in transparent mode

A Cisco FMC administrator wants to configure fastpathing of trusted network traffic to increase performance. In which type of policy would the administrator configure this feature?

A.

Identity policy

B.

Prefilter policy

C.

Network Analysis policy

D.

Intrusion policy

An engineer is analyzing a risk report generated by Cisco Secure Firewall Management Center. The report contains the following fields:

Total Attacks

Events Requiring Attention

Hosts Targeted

Hosts Connected to CnC Servers

Which type of risk report is the engineer analyzing?

A.

Network Risk Report

B.

Attacks Risk Report

C.

Events Risk Report

D.

Hosts Risk Report

A network administrator is reviewing a weekly scheduled attacks risk report and notices a host that is flagged for an impact 2 attack. Where should the administrator look within Cisco FMC to find out more relevant information about this host and attack?

A.

Analysis > Lookup > Whols

B.

Analysis > Correlation > Correlation Events

C.

Analysis > Hosts > Vulnerabilities

D.

Analysis > Hosts > Host Attributes

Which object type supports object overrides?

A.

time range

B.

security group tag

C.

network object

D.

DNS server group

An engineer is implementing clustering in Cisco Secure Firewall Management Center. The configuration must ensure that the cluster has a designated control node with more resources than the other nodes. What must the engineer set for the priority value of that node?

A.

0

B.

A value lower than the values assigned to the other nodes in the cluster

C.

A value higher than the values assigned to the other nodes in the cluster

D.

255

A network administrator must send a daily email report to management detailing changes made during the previous 24 hours in Cisco Secure Firewall Management Center. Which system setting must be enabled to meet this requirement?

A.

Change Reconciliation

B.

Send Audit Log to HTTP Server

C.

Send Audit Log to Syslog

D.

STIG Compliance

A security engineer found a suspicious file from an employee email address and is trying to upload it for analysis, however the upload is failing. The last registration status is still active. What is the cause for this issue?

A.

Cisco AMP for Networks is unable to contact Cisco Threat Grid on premise.

B.

Cisco AMP for Networks is unable to contact Cisco Threat Grid Cloud.

C.

There is a host limit set.

D.

The user agent status is set to monitor.