最新のCisco 300-710試験問題解答がズラリ
300-710試験練習テスト問題(更新された423問あります)
質問 # 212
A security engineer is configuring a remote Cisco FTD that has limited resources and internet bandwidth. Which malware action and protection option should be configured to reduce the requirement for cloud lookups?
- A. Block File action and local malware analysis
- B. Block Malware action and dynamic analysis
- C. Block Malware action and local malware analysis
- D. Malware Cloud Lookup and dynamic analysis
正解:D
質問 # 213
An engineer must configure a SPAN session to monitor traffic by using a Cisco Secure IPS device in passive mode. Cisco Secure IPS interface Gi0/1 is connected to Cisco Catalyst switch interface Gi0/3. Which SPAN configuration meets the requirement?
- A. Switch(config)# monitor source interface Gi0/1Switch(config)# monitor destination interface Gi0/3
- B. Switch(config)# monitor session 1 source interface Gi0/1Switch(config)# monitor session 1 destination interface Gi0/3
- C. Switch(config)# monitor session 1 source interface Gi0/3Switch(config)# monitor session 1 destination interface Gi0/3
- D. Switch(config)# monitor source interface Gi0/1Switch(config)# monitor destination interface Gi0/3
正解:B
解説:
A local SPAN configuration requires a numbered monitoring session with a source interface and a different destination interface. Gi0/1 is the switch interface whose traffic must be copied, while Gi0/3 is connected to the passive Cisco Secure IPS sensor and must therefore be the SPAN destination. Option C correctly associates both commands with session 1 and maps the monitored traffic from Gi0/1 to Gi0/3. Option B incorrectly makes Gi0/3 both the source and destination, which cannot provide the required monitoring path.
Options A and D omit the mandatory session 1 portion of the Catalyst SPAN syntax. Because the IPS operates passively, it receives copies of packets on its monitoring interface without becoming an inline forwarding device and without being able to disrupt the production traffic.
質問 # 214
The event dashboard within the Cisco FMC has been inundated with low priority intrusion drop events, which are overshadowing high priority events. An engineer has been tasked with reviewing the policies and reducing the low priority events. Which action should be configured to accomplish this task?
- A. drop connection
- B. generate events
- C. drop and generate
- D. drop packet
正解:B
解説:
Section: Deployment
Explanation/Reference:
Reference" https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config- guide-v62/working_with_intrusion_events.html
質問 # 215
A network administrator reviews the file report for the last month and notices that all file types, except exe.
show a disposition of unknown. What is the cause of this issue?
- A. Only Spero file analysis is enabled.
- B. The Cisco FMC cannot reach the Internet to analyze files.
- C. The malware license has not been applied to the Cisco FTD.
- D. A file policy has not been applied to the access policy.
正解:D
解説:
A file policy defines the actions that the Cisco Firepower Threat Defense (FTD) device should take when it encounters different types of files. The file policy is applied as part of an access control policy. If an access control policy does not include a file policy, the FTD device will not take any action on the files it encounters, resulting in a disposition of "unknown" for all file types except exe.
Reference:
https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/219759-configure-bypass-policies-on-the-c
質問 # 216
Network users are experiencing Intermittent issues with internet access. An engineer ident med mat the issue Is being caused by NAT exhaustion. How must the engineer change the dynamic NAT configuration to provide internet access for more users without running out of resources?
- A. Define an additional static NAT for the network object in use.
- B. Configure fallthrough to interface PAT on 'he Advanced tab.
- C. Add an identity NAT rule to handle the overflow of users.
- D. Convert the dynamic auto NAT rule to dynamic manual NAT.
正解:B
解説:
Explanation
Fallthrough to interface PAT is a feature that allows the dynamic NAT configuration to use the interface IP address as a last resort when the NAT pool is exhausted. This way, more users can access the internet without running out of resources. To enable this feature, the engineer must check the Enable PAT Fallback check box on the Advanced tab of the NAT rule editor1
質問 # 217
A security engineer must integrate an external feed containing STIX/TAXII data with Cisco FMC. Which feature must be enabled on the Cisco FMC to support this connection?
- A. Cisco Success Network
- B. Cisco Secure Endpoint Integration
- C. Threat Intelligence Director
- D. Security Intelligence Feeds
正解:C
質問 # 218
A network administrator is configuring a site-to-site IPsec VPN to a router sitting behind a Cisco FTD. The administrator has configured an access policy to allow traffic to this device on UDP
500, 4500, and ESP VPN traffic is not working. Which action resolves this issue?
- A. Set the allow action in the access policy to trust.
- B. Enable IPsec inspection on the access policy.
- C. Change the access policy to allow all ports.
- D. Modify the NAT policy to use the interface PAT.
正解:D
解説:
In a site-to-site IPsec VPN configuration where one router is behind a Cisco FTD (Firepower Threat Defense) firewall, proper NAT traversal is critical.
Even if you've allowed UDP 500 (ISAKMP), UDP 4500 (NAT-T), and ESP (IP protocol 50) in the access policy, NAT can still break the VPN unless handled properly.
質問 # 219
An engineer wants to convert a Cisco Secure Firewall Threat Defense device that is currently managed by Cisco Secure Firewall Management Center from routed mode to transparent mode. Which CLI command must the engineer execute first to perform this conversion?
- A. no configure manager
- B. no configure firewall routed
- C. configure manager delete
- D. configure firewall transparent
正解:C
解説:
The Threat Defense device cannot change its firewall mode while it has an active manager configuration.
After unregistering the device from Management Center, the engineer must execute configure manager delete to remove the manager association and place the device in No Manager Mode. The engineer can then execute configure firewall transparent to change the operating mode. Changing firewall modes clears the device configuration because routed-mode and transparent-mode interface configurations are incompatible. After completing the conversion, the engineer must configure the Management Center association again with configure manager add and register the device. Options A and B are not valid Threat Defense CLI commands.
Option D performs the actual mode conversion, but it is not the first required CLI command while the manager association remains configured. Cisco Threat Defense command reference
質問 # 220
A VPN user is unable to conned lo web resources behind the Cisco FTD device terminating the connection. While troubleshooting, the network administrator determines that the DNS responses are not getting through the Cisco FTD What must be done to address this issue while still utilizing Snort IPS rules?
- A. Uncheck the "Drop when Inline" box in the intrusion policy to allow the traffic.
- B. Modify the Snort rules to allow legitimate DNS traffic to the VPN users.
- C. Disable the intrusion rule threshes to optimize the Snort processing.
- D. Decrypt the packet after the VPN flow so the DNS queries are not inspected
正解:B
質問 # 221 
Refertothe exhibit. An engineer is analyzing a Network Risk Report from Cisco FMC. Which application must the engineer take immediate action against to prevent unauthorized network use?
- A. YouTube
- B. TOR
- C. Kerberos
- D. Chrome
正解:B
質問 # 222
Which two remediation options are available when Cisco FMC is integrated with Cisco ISE? (Choose two.)
- A. quarantine
- B. DHCP pool disablement
- C. dynamic null route configured
- D. port shutdown
- E. host shutdown
正解:A、D
解説:
Section: Integration
Explanation/Reference: https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/210524-configure- firepower-6-1-pxgrid-remediati.html
質問 # 223
There is an increased amount of traffic on the network and for compliance reasons, management needs visibility into the encrypted traffic What is a result of enabling TLS'SSL decryption to allow this visibility?
- A. It prompts the need for a corporate managed certificate
- B. It has minimal performance impact
- C. It is not subject to any Privacy regulations
- D. It will fail if certificate pinning is not enforced
正解:A
質問 # 224
A company is deploying AMP private cloud. The AMP private cloud instance has already been deployed by the server administrator. The server administrator provided the hostname of the private cloud instance to the network engineer via email. What additional information does the network engineer require from the server administrator to be able to make the connection to the AMP private cloud in Cisco FMC?
- A. SSL certificate for the AMP private cloud instance
- B. Internet access for the AMP private cloud to reach the AMP public cloud
- C. IP address and port number for the connection proxy
- D. Username and password to the AMP private cloud instance
正解:A
解説:
Step 6: Click Browse next to the Certificate Upload Path field to browse to the location of a valid TLS or SSL encryption certificate for the private cloud. For more information, see the AMP private cloud documentation.
https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config- guide-v62/file_policies_and_amp_for_firepower.html
質問 # 225
Which communication is blocked from the bridge groups when multiple are configured in transparent mode on a Cisco Secure Firewall Threat Defense appliance?
- A. With client devices
- B. With each other
- C. With the internet
- D. With other routers
正解:B
質問 # 226
Which two actions can be used in an access control policy rule? (Choose two.)
- A. Block with Reset
- B. Monitor
- C. Block ALL
- D. Discover
- E. Analyze
正解:A、B
解説:
https://www.cisco.com/c/en/us/td/docs/security/firesight/541/firepower-module-user-guide/asa- firepower-module-user-guide-v541/AC-Rules-Tuning-Overview.html#71854
質問 # 227
An organization wants to secure traffic from their branch office to the headquarter building using Cisco Firepower devices, They want to ensure that their Cisco Firepower devices are not wasting resources on inspecting the VPN traffic. What must be done to meet these requirements?
- A. Enable a flexconfig policy to re-classify VPN traffic so that it no longer appears as interesting traffic
- B. Configure the Cisco Firepower devices to bypass the access control policies for VPN traffic.
- C. Configure the Cisco Firepower devices to ignore the VPN traffic using prefilter policies
- D. Tune the intrusion policies in order to allow the VPN traffic through without inspection
正解:B
解説:
When you configure the Cisco Firepower devices to bypass the access control policies for VPN traffic, the devices will not inspect the VPN traffic and thus will not waste resources on it. This is the best option to ensure that the VPN traffic is not wasting resources on the Cisco Firepower devices.
Reference:https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/219759-configure-bypass- policies-on-the-cisco-firepow.html
質問 # 228
IT management is asking the network engineer to provide high-level summary statistics of the Cisco FTD appliance in the network. The business is approaching a peak season so the need to maintain business uptime is high. Which report type should be used to gather this information?
- A. Standard Report
- B. Risk Report
- C. SNMP Report
- D. Malware Report
正解:A
質問 # 229
Drag and Drop Question
An engineer must configure high availability on two Cisco Secure Firewall Threat Defense appliances. Drag and drop the configuration steps from the left into the sequence on the right.
正解:
解説:
質問 # 230 
Refer to the exhibit. An engineer analyzes a Network Risk Report from Cisco Secure Firewall Management Center. What should the engineer recommend implementing to mitigate the risk?
- A. IP address and URL blacklisting
- B. Trend analysis
- C. Network-based detection
- D. Virtual protection
正解:C
質問 # 231
......
Cisco 300-710試験では、高度なファイアウォールとVPN構成、アクセス制御ポリシー、セキュリティインテリジェンス、ネットワーク分析、トラブルシューティングなど、Cisco Firpower NGFWに関連する幅広いトピックをカバーしています。また、候補者は、脅威の検出と緩和技術、およびネットワークセキュリティポリシーと手順を実装するためのベストプラクティスを深く理解することも期待されています。試験に合格するには、強固な理論的基盤だけでなく、実際の環境でCisco Firpower NGFWアプライアンスの構成と管理における実践的な経験も必要です。
あなたを合格させるCisco試験には300-710試験問題集:https://www.goshiken.com/Cisco/300-710-mondaishu.html
合格させる300-710試験情報と無料練習テスト:https://drive.google.com/open?id=1el8f-j9tKUFN_sjvU_t0ctStfdYmuORe