最新のCisco 300-710のPDFと問題集で(2026)無料試験問題解答 [Q149-Q169]

Share

最新のCisco 300-710のPDFと問題集で(2026)無料試験問題解答

あなたを合格させるCCNP Security 300-710試験問題集で2026年09月16日には423問あります


Cisco 300-710試験に合格することで、プロフェッショナルはネットワークセキュリティにおける専門知識を証明し、就職の見通しを改善することができます。この認定は、多くの組織によってセキュリティ専門家としての貴重な資格として認められており、キャリアアップや高い給与の新しい機会を提供することができます。


シスコ300-710試験は、シスコネットワークのセキュリティを強化したいITプロフェッショナルを対象に設計されており、シスコ認定ネットワークプロフェッショナルセキュリティ(CCNPセキュリティ)認定トラックの一部です。シスコ300-710試験は、すべての規模の組織に包括的な脅威保護を提供する高度なセキュリティソリューションであるCisco Firepower Threat Defenseに焦点を当てています。

 

質問 # 149
An engineer needs to configure remote storage on Cisco FMC. Configuration backups must be available from a secure location on the network for disaster recovery. Reports need to back up to a shared location that auditors can access with their Active Directory logins. Which strategy must the engineer use to meet these objectives?

  • A. Use NFS for both backups and reports.
  • B. Use SSH for backups and NFS for reports.
  • C. Use SMB for backups and NFS for reports.
  • D. Use SMB for both backups and reports.

正解:D

解説:
You cannot send backups to one remote system and reports to another, but you can choose to send either to a remote system and store the other on the Firepower Management Center.
https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-config- guide-v64/system_configuration.html#ID-2241-00000551


質問 # 150
What is a behavior of a Cisco FMC database purge?

  • A. The appropriate process is restarted.
  • B. User login and history data are removed from the database if the User Activity check box is selected.
  • C. Data can be recovered from the device.
  • D. The specified data is removed from Cisco FMC and kept for two weeks.

正解:A

解説:
Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/management_center_database_purge.pdf


質問 # 151
What is the role of the casebook feature in Cisco Threat Response?

  • A. pulling data via the browser extension
  • B. alert prioritization
  • C. sharing threat analysts
  • D. triage automaton with alerting

正解:C

解説:
The casebook and pivot menu are widgets available in Cisco Threat Response. Casebook - It is used to record, organize, and share sets of observables of interest primarily during an investigation and threat analysis. You can use a casebook to get the current verdicts or dispositions on the observables.
https://www.cisco.com/c/en/us/td/docs/security/ces/user_guide/esa_user_guide_13-5-1/b_ESA_Admin_Guide_ces_13-5-1/b_ESA_Admin_Guide_13-0_chapter_0110001.pdf


質問 # 152

Refer to the exhibit. Users attempt to connect to numerous external resources on various TCP ports. If the users mistype the port, their connection closes immediately, and it takes more than one minute before the connection is torn down. An engineer manages to capture both types of connections as shown in the exhibit.
What must the engineer configure to lower the timeout values for the second group of connections and resolve the user issues?

  • A. inbound access rule that allows TCP reset packets from outside
  • B. outbound access rule that allows the entire ICMP protocol suite
  • C. outbound access rule with the Block with reset action
  • D. inbound access rule that allows ICMP Type 3 from outside

正解:C


質問 # 153
A network engineer is configuring URL Filtering on Firepower Threat Defense. Which two port requirements on the Firepower Management Center must be validated to allow communication with the cloud service? (Choose two.)

  • A. outbound port TCP/80
  • B. inbound port TCP/443
  • C. outbound port TCP/443
  • D. inbound port TCP/80
  • E. outbound port TCP/8080

正解:A、C


質問 # 154
Which rule action is only available in Snort 3?

  • A. Rewrite
  • B. Pass
  • C. Generate
  • D. Alert

正解:D


質問 # 155
A Cisco FTD has two physical interfaces assigned to a BVI. Each interface is connected to a different VLAN on the same switch. Which firewall mode is the Cisco FTD set up to support?

  • A. transparent
  • B. high availability clustering
  • C. routed
  • D. active/active failover

正解:C


質問 # 156
An engineer plans to reconfigure an existing Cisco FTD from transparent mode to routed mode.
Which additional action must be taken to maintain communication between the two network segments?

  • A. Configure a NAT rule so that traffic between the segments is exempt from NAT.
  • B. Deploy inbound ACLs on each interface to allow traffic between the segments.
  • C. Update the IP addressing so that each segment is a unique IP subnet.
  • D. Assign a unique VLAN ID for the interface in each segment.

正解:C


質問 # 157

Refer to the exhibit. An engineer configures a NAT rule allowing clients to use the internet only if clients are located on the directly connected internal network. Dynamic auto PAT must be configured. Drag and drop the NAT rules from the left onto the corresponding targets on the right. Not all options are used.

正解:

解説:

Explanation:
A screenshot of a computer AI-generated content may be incorrect.


質問 # 158
An engineer is troubleshooting application failures through a FTD deployment. While using the FMC CLI. it has been determined that the traffic in question is not matching the desired policy. What should be done to correct this?

  • A. Use the system support firewall-engine-dump-user-f density-data command to change the policy and allow the application through the firewall.
  • B. Use the system support application-identification-debug command to determine which rules the traffic matching and modify the rule accordingly
  • C. Use the system support network-options command to fine tune the policy.
  • D. Use the system support firewall-engine-debug command to determine which rules the traffic matching and modify the rule accordingly

正解:B


質問 # 159
An administrator is configuring the interface of a Cisco Secure Firewall Threat Defense device in a passive IPS deployment. The device and interface have been identified. Which set of configuration steps of the administrator take next to complete the implementation?

  • A. Modify the interface to retransmit received traffic. Associate the interface with a security zone Enable the interface. Sat the MTU parameter.
  • B. Modify the interface to retransmit received traffic. Associate the interface with a security zone. Set the MTU parameter.
  • C. Set the interface mode to passive. Associate the interface with a security zone. Enable the interface. Set the MTU parameter.
  • D. Set the interface mode to passive. Associate the interface with a security zone. Set the MTU parameter.
    Reset the interface.

正解:C

解説:
In a passive IPS deployment for a Cisco Secure Firewall Threat Defense (FTD) device, the administrator must configure the interface to operate in passive mode. This involves setting the interface mode, associating it with a security zone, enabling the interface, and setting the MTU parameter.
Steps:
* Set the interface mode to passive:
* In FMC, navigate to Devices > Device Management.
* Select the FTD device and configure the relevant interface.
* Set the interface mode to "Passive."
* Associate the interface with a security zone:
* Create or select an appropriate security zone.
* Assign the passive interface to this security zone.
* Enable the interface:
* Ensure the interface is enabled to receive traffic.
* Set the MTU parameter:
* Configure the Maximum Transmission Unit (MTU) parameter as required.
This ensures that the FTD device can inspect traffic passively without impacting the network flow.
References: Cisco Secure Firewall Management Center Device Configuration Guide, Chapter on Interface Settings


質問 # 160
With Cisco FTD software, which interface mode must be configured to passively receive traffic that passes through the appliance?

  • A. firewall
  • B. IPS-only
  • C. tap
  • D. ERSPAN

正解:D

解説:
Reference:
v64/interface_overview_for_firepower_threat_defense.html


質問 # 161

Refer to the exhibit. An engineer analyzes a Network Risk Report from Cisco Secure Firewall Management Center. What should the engineer recommend implementing to mitigate the risk?

  • A. Network-based detection
  • B. IP address and URL blacklisting
  • C. Virtual protection
  • D. Trend analysis

正解:A


質問 # 162
Refer to the exhibit.

An engineer is modifying an access control policy to add a rule to Inspect all DNS traffic that passes it making the change and deploying the policy, they see that DNS traffic Is not being Inspected by the Snort engine. What is......

  • A. The rule Is configured with the wrong setting for the source port.
  • B. The action of the rule is set to trust instead of allow.
  • C. The rule must specify the security zone that originates the traffic.
  • D. The rule must define the source network for inspection as well as the port.

正解:B


質問 # 163
An engineer is configuring a Cisco Secure Firewall Threat Defense device to operate in transparent mode between two switch stacks. VLAN 10 is used for in-band management on both switch stacks. Which two actions are required on the device to inspect traffic between the switch stacks without interrupting network traffic? (Choose two.)

  • A. Set the MTU to 9198 on all interfaces to support jumbo frames.
  • B. Add separate routes for data and management traffic.
  • C. Exempt BPDUs from advanced inspection.
  • D. Configure at least one bridge group.
  • E. Configure a BVI interface for VLAN 10.

正解:C、D

解説:
Transparent firewall mode forwards traffic at Layer 2, so the participating physical interfaces must be assigned to at least one bridge group. This allows the device to inspect traffic while remaining logically transparent to the connected switch stacks. Bridge Protocol Data Units should also be exempted from advanced inspection. BPDUs are essential for spanning-tree operation, and delaying or blocking them during inspection restarts can produce topology instability or an interruption. A BVI provides Layer 3 addressing for device-originated traffic or management but is not inherently required merely to inspect transit traffic. Jumbo- frame configuration is unnecessary unless the network explicitly uses jumbo frames, and separate data and management routes do not establish transparent forwarding. Cisco specifically recommends using an EtherType ACL to trust BPDUs on each bridge-group member interface. Cisco transparent firewall configuration


質問 # 164
Refer to the exhibit.

An engineer is modifying an access control policy to add a rule to Inspect all DNS traffic that passes it making the change and deploying the policy, they see that DNS traffic Is not being Inspected by the Snort engine.
What is......

  • A. The rule Is configured with the wrong setting for the source port.
  • B. The action of the rule is set to trust instead of allow.
  • C. The rule must specify the security zone that originates the traffic.
  • D. The rule must define the source network for inspection as well as the port.

正解:B


質問 # 165
A VPN administrator converted an instance of Cisco Secure Firewall Threat Defense, which is managed by Cisco Secure Firewall Management Center, from using LDAP to LDAPS for remote access VPN authentication. Which certificate must be added to allow for remote users to authenticate over the VPN?

  • A. Secure Firewall Threat Defense certificate must be added to the LDAPS server.
  • B. Secure Firewall Management Center certificate must be added to the LDAPS server.
  • C. LDAPS server certificate must be added to Secure Firewall Threat Defense.
  • D. LDAPS server certificate must be added to Secure Firewall Management Center realms.

正解:C


質問 # 166
An engineer must investigate a connectivity issue from an endpoint behind a Cisco FTD device and a public DNS server. The endpoint cannot perform name resolution queries. Which action must the engineer perform to troubleshoot the issue by simulating real DNS traffic on the Cisco FTD while verifying the Snarl verdict?

  • A. Use the Capture w/Trace wizard in Cisco FMC.
  • B. Create a Custom Workflow in Cisco FMC.
  • C. Perform a Snort engine capture using tcpdump from the FTD CLI.
  • D. Run me system support firewall-engine-debug command from me FTD CLI.

正解:A

解説:
Explanation
The Capture w/Trace wizard in Cisco FMC allows you to capture packets on an FTD device and trace their path through the Snort engine. This can help you troubleshoot connectivity issues from an endpoint behind an FTD device and a public DNS server, as well as verify the Snort verdict for the DNS traffic. The Capture w/Trace wizard lets you specify the source and destination IP addresses, ports, and protocols for the packets you want to capture and trace, as well as the FTD device and interface where you want to perform the capture.
You can also apply filters to limit the capture size and duration. After you start the capture, you can ping the DNS server from the endpoint and then view the captured packets and their Snort verdicts in the FMC web interface2.
To use the Capture w/Trace wizard in Cisco FMC, you need to follow these steps2:
In the FMC web interface, navigate to Troubleshooting > Capture/Trace.
Click New Capture.
Choose an FTD device from the Device drop-down list.
Choose an interface from the Interface drop-down list.
Enter the source and destination IP addresses, ports, and protocols for the packets you want to capture and trace. For example, if you want to capture DNS queries from an endpoint with IP address 10.1.1.100 to a DNS server with IP address 8.8.8.8, you can enter these values:
Source IP: 10.1.1.100
Source Port: any
Destination IP: 8.8.8.8
Destination Port: 53
Protocol: UDP
Optionally, apply filters to limit the capture size and duration. For example, you can set the maximum number of packets to capture, the maximum capture file size, or the maximum capture time.
Click Start.
Ping the DNS server from the endpoint and wait for some packets to be captured.
Click Stop to stop the capture.
Click View Capture to see the captured packets and their Snort verdicts.
The other options are incorrect because:
Performing a Snort engine capture using tcpdump from the FTD CLI will not allow you to trace the path of the packets through the Snort engine or verify their Snort verdicts. Tcpdump is a command-line tool that can capture packets on an FTD device, but it does not provide any information about how Snort processes those packets or what actions Snort takes on them2.
Creating a Custom Workflow in Cisco FMC will not help you troubleshoot a connectivity issue from an endpoint behind an FTD device and a public DNS server. A Custom Workflow is a user-defined set of pages that display event data in different formats, such as tables, charts, maps, and so on. A Custom Workflow does not allow you to capture or trace packets on an FTD device3.
Running the system support firewall-engine-debug command from the FTD CLI will not allow you to simulate real DNS traffic on the FTD device or verify the Snort verdict for that traffic. The firewall-engine-debug command is a diagnostic tool that can generate synthetic packets and send them through the Snort engine on an FTD device. The synthetic packets are not real network traffic and do not affect any connections or policies on the FTD device4.


質問 # 167
An organization has implemented Cisco Firepower without IPS capabilities and now wants to enable inspection for their traffic. They need to be able to detect protocol anomalies and utilize the Snort rule sets to detect malicious behaviour. How is this accomplished?

  • A. Modify the network analysis policy to process the packets for inspection
  • B. Modify the intrusion policy to determine the minimum severity of an event to inspect.
  • C. Modify the access control policy to redirect interesting traffic to the engine
  • D. Modify the network discovery policy to detect new hosts to inspect

正解:B


質問 # 168
An engineer is configuring URL filtering for a Cisco FTD device in Cisco FMC. Users must receive a warning when they access http:/'www.Dac'additstte.corn with the option of continuing to the website if they choose to.
No other websites should be blacked. Which two actions must the engineer lake to meet these requirements?
(Choose two.)

  • A. On the HTTP Responses tab of the access control policy editor, sot the Interactive Block Response Page to system-provided.
  • B. Configure an access control rule that matches an URL object for http://www.badaduitslte.com; and set the action to interactive Block.
  • C. On the HTTP Responses tab of the access control policy editor, set the Block Response Page to Custom.
  • D. Configure the default action for the access control policy to Interactive Block.
  • E. Configure an access control rule that matches the Adult URL category and se: the action to interactive Block.

正解:A、B

解説:
To configure URL filtering for a Cisco FTD device in Cisco FMC, and to meet the requirements of the question, the engineer must do the following:
* On the HTTP Responses tab of the access control policy editor, set the Interactive Block Response Page to system-provided. This will enable the system to display a warning page to the users when they try to access a blocked URL, and give them the option to continue or cancel. The system-provided page is a default page that contains a generic message and a logo1.
* Configure
an access control rule that matches an URL object for http://www.badadultsite.com; and set the action to Interactive Block. This will apply the interactive block action to the specific URL that is defined in the URL object.
The interactive block action will trigger the interactive block response page that was configured in the previous step1.
The other options are incorrect because:
* On the HTTP Responses tab of the access control policy editor, setting the Block Response Page to Custom will not affect the interactive block action. The block response page is used when the action is set to Block, not Interactive Block1.
* Configuring the default action for the access control policy to Interactive Block will apply the interactive block action to all URLs that are not matched by any access control rule. This will not meet the requirement of blocking no other websites1.
* Configuring an access control rule that matches the Adult URL category and sets the action to Interactive Block will apply the interactive block action to all URLs that belong to the Adult category.
This
will not meet the requirement of blocking only http://www.badadultsite.com
1.


質問 # 169
......

300-710問題集はCCNP Security認証済み試験問題と解答:https://www.goshiken.com/Cisco/300-710-mondaishu.html

300-710無料試験学習ガイド!(更新された423問あります):https://drive.google.com/open?id=1muayH_pi_Q-aO_BH-F5aio0b4t5LZaMH