結果を保証するには最新2024年10月無料Cisco 300-710で練習しよう [Q156-Q174]

Share

結果を保証するには最新2024年10月無料Cisco 300-710で練習しよう

有効な問題最新版を無料で試そう300-710試験問題集解答

質問 # 156
An engineer is configuring Cisco FMC and wants to allow multiple physical interfaces to be part of the same VLAN. The managed devices must be able to perform Layer 2 switching between interfaces, including sub-interfaces. What must be configured to meet these requirements?

  • A. integrated routing and bridging
  • B. interface-based VLAN switching
  • C. inter-chassis clustering VLAN
  • D. Cisco ISE Security Group Tag

正解:A


質問 # 157
Refer to the exhibit.

An organization has an access control rule with the intention of sending all social media traffic for inspection After using the rule for some time, the administrator notices that the traffic is not being inspected, but is being automatically allowed What must be done to address this issue?

  • A. Modify the selected application within the rule
  • B. Modify the rule action from trust to allow
  • C. Add the social network URLs to the block list
  • D. Change the intrusion policy to connectivity over security.

正解:A


質問 # 158
Drag and drop the steps to restore an automatic device registration failure on the standby Cisco FMC from the left into the correct order on the right. Not all options are used.

正解:

解説:

Explanation

Explanation
Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/firepower_management_center_high_availability.html#id_32288


質問 # 159
IT management is asking the network engineer to provide high-level summary statistics of the Cisco FTD appliance in the network. The business is approaching a peak season so the need to maintain business uptime is high. Which report type should be used to gather this information?

  • A. SNMP Report
  • B. Risk Report
  • C. Malware Report
  • D. Standard Report

正解:B


質問 # 160
Which Cisco Firepower feature is used to reduce the number of events received in a period of time?

  • A. correlation
  • B. rate-limiting
  • C. suspending
  • D. thresholding

正解:D

解説:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firesight/541/firepower-module-user-guide/asa- firepower-module-user-guide-v541/Intrusion-Global-Threshold.html


質問 # 161
What is the maximum SHA level of filtering that Threat Intelligence Director supports?

  • A. SHA-256
  • B. SHA-4096
  • C. SHA-1024
  • D. SHA-512

正解:A

解説:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/623/configuration/guide/fpmc-config-guide-v623/cisco


質問 # 162
Which command must be run to generate troubleshooting files on an FTD?

  • A. system generate-troubleshoot all
  • B. sudo sf_troubleshoot.pl
  • C. show tech-support
  • D. system support view-files

正解:B

解説:
Reference: https://www.cisco.com/c/en/us/support/docs/security/sourcefire-defense-center/117663-technote-SourceFire-00.html


質問 # 163
Which two statements about bridge-group interfaces in Cisco FTD are true? (Choose two.)

  • A. Bidirectional Forwarding Detection echo packets are allowed through the FTD when using bridge-group members.
  • B. Bridge groups are supported only in transparent firewall mode.
  • C. The BVI IP address must be in a separate subnet from the connected network.
  • D. Each directly connected network must be on the same subnet.
  • E. Bridge groups are supported in both transparent and routed firewall modes.

正解:D、E


質問 # 164
A network administrator notices that remote access VPN users are not reachable from inside the network. It is determined that routing is configured correctly, however return traffic is entering the firewall but not leaving it What is the reason for this issue?

  • A. An object NAT exemption rule does not exist at the top of the NAT table.
  • B. An external NAT IP address is not configured.
  • C. An external NAT IP address is configured to match the wrong interface.
  • D. A manual NAT exemption rule does not exist at the top of the NAT table.

正解:D

解説:
https://www.cisco.com/c/en/us/support/docs/security/firepower-management-center/212702-configure-and-verify


質問 # 165
An engineer must deploy a Cisco FTD device. Management wants to examine traffic without requiring network changes that will disrupt end users. Corporate security policy requires the separation of management traffic from data traffic and the use of SSH over Telnet for remote administration. How must the device be deployed to meet these requirements?

  • A. in transparent mode with a management Interface
  • B. in routed mode with a bridge virtual interface
  • C. in transparent made with a data interface
  • D. in routed mode with a diagnostic interface

正解:A

解説:
To deploy a Cisco FTD device that meets the requirements of the question, the engineer must use transparent mode with a management interface. Transparent mode is a firewall configuration in which the FTD device acts as a "bump in the wire" or a "stealth firewall" and is not seen as a router hop to connected devices. In transparent mode, the FTD device can examine traffic without requiring network changes that will disrupt end users, such as changing IP addresses or routing configurations1. A management interface is a dedicated interface that is used for managing the FTD device and separating management traffic from data traffic. A management interface can be configured to allow SSH access for remote administration, which is more secure than Telnet2.
The other options are incorrect because:
* Routed mode is a firewall configuration in which the FTD device acts as a router and performs address translation and routing for connected networks. Routed mode requires network changes that may disrupt end users, such as changing IP addresses or routing configurations1. A diagnostic interface is a special interface that is used for troubleshooting and capturing traffic on the FTD device. A diagnostic interface does not separate management traffic from data traffic or allow SSH access for remote administration.
* Transparent mode with a data interface does not meet the requirement of separating management traffic from data traffic. A data interface is a regular interface that is used for passing and inspecting traffic on the FTD device. A data interface does not allow SSH access for remote administration2.
* Routed mode with a bridge virtual interface (BVI) does not meet the requirement of examining traffic without requiring network changes that will disrupt end users. A BVI is a logical interface that acts as a container for one or more physical or logical interfaces that belong to the same layer 2 broadcast domain. A BVI allows the FTD device to route between different bridge groups on the same security module/engine. However, routed mode still requires network changes that may disrupt end users, such as changing IP addresses or routing configurations.


質問 # 166
An administrator is setting up Cisco Firepower to send data to the Cisco Stealthwatch appliances. The NetFlow_Set_Parameters object is already created, but NetFlow is not being sent to the flow collector. What must be done to prevent this from occurring?

  • A. Add the NetFlow_Add_Destination object to the configuration
  • B. Create a Security Intelligence object to send the data to Cisco Stealthwatch
  • C. Add the NetFlow_Send_Destination object to the configuration
  • D. Create a service identifier to enable the NetFlow service

正解:B


質問 # 167
A network engineer is extending a user segment through an FTD device for traffic inspection without creating another IP subnet How is this accomplished on an FTD device in routed mode?

  • A. by leveraging the ARP to direct traffic through the firewall
  • B. by assigning an inline set interface
  • C. by bypassing protocol inspection by leveraging pre-filter rules
    https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-config-guide-v64/transparent_or_routed_firewall_mode_for_firepower_threat_defense.html
  • D. by using a BVI and create a BVI IP address in the same subnet as the user segment

正解:D


質問 # 168
A security engineer is configuring a remote Cisco FTD that has limited resources and internet bandwidth. Which malware action and protection option should be configured to reduce the requirement for cloud lookups?

  • A. Block Malware action and dynamic analysis
  • B. Block Malware action and local malware analysis
  • C. Malware Cloud Lookup and dynamic analysis
  • D. Block File action and local malware analysis

正解:C


質問 # 169
After deploying a network-monitoring tool to manage and monitor networking devices in your organization, you realize that you need to manually upload an MIB for the Cisco FMC. In which folder should you upload the MIB file?

  • A. /etc/sf/DCEALERT.MIB
  • B. /etc/sf/DCMIB.ALERT
  • C. /sf/etc/DCEALERT.MIB
  • D. system/etc/DCEALERT.MIB

正解:A

解説:
Section: Management and Troubleshooting
Explanation
Explanation/Reference: https://www.cisco.com/c/en/us/td/docs/security/firesight/541/firepower-module-user-guide/asa- firepower-module-user-guide-v541/Intrusion-External-Responses.pdf


質問 # 170
Which two types of objects are reusable and supported by Cisco FMC? (Choose two.)

  • A. reputation-based objects that represent Security Intelligence feeds and lists, application filters based on category and reputation, and file lists
  • B. network-based objects that represent IP address and networks, port/protocols pairs, VLAN tags, security zones, and origin/destination country
  • C. reputation-based objects, such as URL categories
  • D. dynamic key mapping objects that help link HTTP and HTTPS GET requests to Layer 7 application protocols.
  • E. network-based objects that represent FQDN mappings and networks, port/protocol pairs, VXLAN tags, security zones and origin/destination country

正解:A、B

解説:
Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/reusable_objects.html#ID-2243-00000414


質問 # 171
An engineer is monitoring network traffic from their sales and product development departments, which are on two separate networks What must be configured in order to maintain data privacy for both departments?

  • A. Use passive IDS ports for both departments
  • B. Use 802 1Q mime set Trunk interfaces with VLANs to maintain logical traffic separation
  • C. Use a dedicated IPS inline set for each department to maintain traffic separation
  • D. Use one pair of inline set in TAP mode for both departments

正解:D

解説:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-config-guide-v64/ inline_sets_and_passive_interfaces_for_firepower_threat_defense.html


質問 # 172
An engineer is troubleshooting connectivity to the DNS servers from hosts behind a new Cisco FTD device. The hosts cannot send DNS queries to servers in the DMZ. Which action should the engineer take to troubleshoot this issue using the real DNS packets?

  • A. Use the show blocks command in the Threat Defense CLI tool and create a policy to allow the blocked traffic.
  • B. Use the Connection Events dashboard to check the block reason and adjust the inspection policy as needed.
  • C. Use the packet capture tool to check where the traffic is being blocked and adjust the access control or intrusion policy as needed.
  • D. Use the packet tracer tool to determine at which hop the packet is being dropped.

正解:B


質問 # 173
Which CLI command is used to control special handling of clientHello messages?

  • A. system support ssl-client-hello-display
  • B. system support ssl-client-hello-force-reset
  • C. system support ssl-client-hello-tuning
  • D. system support ssl-client-hello-reset

正解:D


質問 # 174
......


Cisco 300-710認定試験は、ITプロフェッショナルがCisco Firepowerテクノロジーを使用してネットワークインフラストラクチャを保護する専門知識を実証する優れた方法です。 Cisco Firpower NGFWとFMCの実装、構成、管理のスキルと知識、およびセキュリティの脅威をリアルタイムで検出および対応する能力を検証します。この試験に合格すると、キャリアの見通しを高め、ネットワークセキュリティの分野で新しい機会を開くことができます。


Ciscoの300-710試験に備えるために、オンラインコースを受講したり、トレーニングセッションに参加したり、学習教材を読んだり、実験室で練習したりすることができます。Ciscoは、書籍、ビデオ、模擬試験などの公式の学習リソースも提供しており、試験に備えるのに役立ちます。この試験を受ける前に、ネットワークセキュリティにおいて3〜5年の経験を持っていることが推奨されています。


Cisco 300-710認定試験は、Cisco Firepowerでネットワークを保護するために必要な知識とスキルをテストするように設計されています。この試験は、Cisco Firepowerを使用してネットワークセキュリティポリシーとテクノロジーの実装と管理に関する専門知識を実証したいIT専門家に最適です。この試験では、ネットワークセキュリティの概念、脅威防衛技術、火力管理と構成など、幅広いトピックをカバーしています。

 

300-710ブレーン問題集PDF、Cisco 300-710試験問題詰合せ:https://www.goshiken.com/Cisco/300-710-mondaishu.html

2024年最新の300-710サンプル問題は信頼され続ける300-710テストエンジン:https://drive.google.com/open?id=1wz9CQKzWWNBfHRGLlz4LAHiCZUeSKX6x