Pre-Winter Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: buysanta

Exact2Pass Menu

Securing Networks with Cisco Firepower (300-710 SNCF) v1.2

Last Update 14 hours ago Total Questions : 444

The Securing Networks with Cisco Firepower (300-710 SNCF) v1.2 content is now fully updated, with all current exam questions added 14 hours ago. Deciding to include 300-710 practice exam questions in your study plan goes far beyond basic test preparation.

You'll find that our 300-710 exam questions frequently feature detailed scenarios and practical problem-solving exercises that directly mirror industry challenges. Engaging with these 300-710 sample sets allows you to effectively manage your time and pace yourself, giving you the ability to finish any Securing Networks with Cisco Firepower (300-710 SNCF) v1.2 practice test comfortably within the allotted time.

Question # 41

Which object type supports object overrides?

A.

time range

B.

security group tag

C.

network object

D.

DNS server group

Question # 42

A network engineer is logged into the Cisco AMP for Endpoints console and sees a malicious verdict for an identified SHA-256 hash. Which configuration is needed to mitigate this threat?

A.

Use regular expressions to block the malicious file.

B.

Add the hash from the infected endpoint to the network block list.

C.

Add the hash to the simple custom detection list.

D.

Enable a personal firewall in the infected endpoint.

Question # 43

Which Cisco Secure Firewall Threat Defense interface mode must be deployed when implementing an IPS that must receive and retransmit all traffic unless the traffic is explicitly dropped?

A.

Routed

B.

Inline

C.

Passive

D.

Transparent

Question # 44

An engineer must deploy a Cisco FTD appliance via Cisco FMC to span a network segment to detect malware and threats. When setting the Cisco FTD interface mode, which sequence of actions meets this requirement?

A.

Set to passive, and configure an access control policy with an intrusion policy and a file policy defined

B.

Set to passive, and configure an access control policy with a prefilter policy defined

C.

Set to none, and configure an access control policy with a prefilter policy defined

D.

Set to none, and configure an access control policy with an intrusion policy and a file policy defined

Question # 45

What is the disadvantage of setting up a site-to-site VPN in a clustered-units environment?

A.

VPN connections can be re-established only if the failed master unit recovers.

B.

Smart License is required to maintain VPN connections simultaneously across all cluster units.

C.

VPN connections must be re-established when a new master unit is elected.

D.

Only established VPN connections are maintained when a new master unit is elected.

Question # 46

An engineer is setting up a new Cisco Secure Firewall Threat Defense appliance to replace the current firewall. The company requests that inline sets be used and that when one interface in

an inline set goes down, the second interface in the inline set goes down. What must the engineer configure to meet the deployment requirements?

A.

strict TCP enforcement

B.

propagate link state

C.

Snort fail open

D.

inline tap mode

Question # 47

A security engineer must configure a Cisco FTD appliance to inspect traffic coming from the internet. The Internet traffic will be mirrored from the Cisco Catalyst 9300 Switch. Which configuration accomplishes the task?

A.

Set interface configuration mode to none.

B.

Set the firewall mode to transparent.

C.

Set the firewall mode to routed.

D.

Set interface configuration mode to passive.

Question # 48

A security engineer must add a new policy to block UDP traffic to one server. The engineer adds a new object. Which action must the engineer take next to identify all the UDP ports?

A.

Define the transport protocol and the mandatory port range.

B.

Add the transport number and specify the type and code.

C.

Add the corresponding IP protocol number for UDP and TCP.

D.

Specify the transport protocol and leave the port number empty.

Question # 49

An administrator is attempting to remotely log into a switch in the data centre using SSH and is unable to connect. How does the administrator confirm that traffic is reaching the firewall?

A.

by running Wireshark on the administrator ' s PC

B.

by performing a packet capture on the firewall.

C.

by running a packet tracer on the firewall.

D.

by attempting to access it from a different workstation.

Question # 50

An engineer is configuring two new Cisco Secure Firewall Threat Defense devices to replace the existing firewalls. Network traffic must be analyzed for intrusion events without impacting the traffic. What must the engineer implement next to accomplish the goal?

A.

Passive mode

B.

Inline Pair in Tap mode

C.

ERSPAN Passive mode

D.

Inline Pair mode

Go to page: