
[2023年05月05日] 最速準備で試験合格!300-710問題の事前予備
300-710のPDF問題集リアル2023最近更新された問題
Cisco 300-710認定を取得することは、Cisco Firepowerを使用して企業ネットワークをセキュリティーできる技術を持つ候補者の能力を証明するためのものであり、現代のサイバーセキュリティーの景気において、貴重なスキルセットです。この認定は、キャリアアップの機会やネットワークセキュリティーの分野での収益性の向上につながることもあります。
質問 # 14
What is a functionality of port objects in Cisco FMC?
- A. to mix transport protocols when setting both source and destination port conditions in a rule
- B. to represent protocols other than TCP, UDP, and ICMP
- C. to add any protocol other than TCP or UDP for source port conditions in access control rules.
- D. to represent all protocols in the same way
正解:B
解説:
Section: Management and Troubleshooting
Explanation/Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config- guide-v62/reusable_objects.html
質問 # 15
What is the result of specifying of QoS rule that has a rate limit that is greater than the maximum throughput of an interface?
- A. The system rate-limits all traffic.
- B. The system repeatedly generates warnings.
- C. The rate-limiting rule is disabled.
- D. Matching traffic is not rate limited.
正解:D
質問 # 16
When a Cisco FTD device is configured in transparent firewall mode, on which two interface types can an IP address be configured? (Choose two.)
- A. Diagnostic
- B. BVI
- C. EtherChannel
- D. Subinterface
- E. Physical
正解:A、B
質問 # 17
While configuring FTD, a network engineer wants to ensure that traffic passing through the appliance does not require routing or Vlan rewriting. Which interface mode should the engineer implement to accomplish this task?
- A. Inline tap
- B. Inline set
- C. transparent
- D. passive
正解:C
質問 # 18
Which two conditions are necessary for high availability to function between two Cisco FTD devices? (Choose two.)
- A. Both devices can be part of a different group that must be in the same domain when configured within the FMC.
- B. The units must be different models if they are part of the same series.
- C. The units must be the same model.
- D. The units must be configured only for firewall routed mode.
- E. The units must be the same version
正解:C、E
解説:
Section: Deployment
Explanation/Reference: https://www.cisco.com/c/en/us/support/docs/security/firepower-management-center/212699- configure-ftd-high-availability-on-firep.html
質問 # 19
Which Firepower feature allows users to configure bridges in routed mode and enables devices to perform Layer 2 switching between interfaces?
- A. BDI
- B. IRB
- C. FlexConfig
- D. SGT
正解:B
解説:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/620/relnotes/ Firepower_System_Release_Notes_Version_620/new_features_and_functionality.html
質問 # 20
An engineer is troubleshooting application failures through an FTD deployment. While using the FMC CLI, it has been determined that the traffic in question is not matching the desired policy. What should be done to correct this?
- A. Use the system support network-options command to fine tune the policy.
- B. Use the system support firewall-engine-debug command to determine which rules the traffic matching and modify the rule accordingly.
- C. Use the system support firewall-engine-dump-user-identity-data command to change the policy and allow the application though the firewall.
- D. Use the system support application-identification-debug command to determine which rules the traffic matching and modify the rule accordingly.
正解:B
解説:
Section: Management and Troubleshooting
質問 # 21
A network administrator is implementing an active/passive high availability Cisco FTD pair.
When adding the high availability pair, the administrator cannot select the secondary peer.
What is the cause?
- A. The second Cisco FTD is not the same model as the primary Cisco FTD.
- B. Both Cisco FTD devices are not at the same software Version
- C. The failover link must be defined on each Cisco FTD before adding the high availability pair.
- D. An high availability license must be added to the Cisco FMC before adding the high availability pair.
正解:A
質問 # 22
An engineer is monitoring network traffic from their sales and product development departments, which are on two separate networks What must be configured in order to maintain data privacy for both departments?
- A. Use 802 1Q mime set Trunk interfaces with VLANs to maintain logical traffic separation
- B. Use one pair of inline set in TAP mode for both departments
- C. Use passive IDS ports for both departments
- D. Use a dedicated IPS inline set for each department to maintain traffic separation
正解:A
質問 # 23
An engineer is vorlang on a LAN switch and has noticed that its network connection to the mime Cisco IPS has gone down Upon troubleshooting it is determined that the switch is working as expected What must have been implemented for this failure to occur?
- A. Link-state propagation is enabled
- B. The Cisco IPS has been configured to be in fail-open mode
- C. The upstream router has a misconfigured routing protocol
- D. The Cisco IPS is configured in detection mode
正解:D
質問 # 24
A user within an organization opened a malicious file on a workstation which in turn caused a ransomware attack on the network. What should be configured within the Cisco FMC to ensure the file is tested for viruses on a sandbox system?
- A. Dynamic analysis
- B. Capacity handling
- C. Spere analysis
- D. Local malware analysis
正解:A
質問 # 25
An administrator must use Cisco FMC to install a backup route within the Cisco FTD to route traffic in case of a routing failure with the primary route. Which action accomplishes this task?
- A. Install the static backup route and modify the metric to be less than the primary route.
- B. Use a default route on the FMC instead of having multiple routes contending for priority.
- C. Create the backup route and use route tracking on both routes to a destination IP address in the network.
- D. Configure EIGRP routing on the FMC to ensure that dynamic routes are always updated.
正解:A
質問 # 26
A network engineer wants to add a third-party threat feed into the Cisco FMC for enhanced threat detection Which action should be taken to accomplish this goal?
- A. Enable Rapid Threat Containment using REST APIs
- B. Enable Rapid Threat Containment using STIX and TAXII
- C. Enable Threat Intelligence Director using REST APIs
- D. Enable Threat Intelligence Director using STIX and TAXII
正解:D
解説:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/623/configuration/guide/fpmc-config-guide-v623/cisco_threat_intelligence_director__tid_.html
質問 # 27
An engineer is configuring a second Cisco FMC as a standby device but is unable to register with the active unit. What is causing this issue?
- A. The licensing purchased does not include high availability
- B. There is only 10 Mbps of bandwidth between the two devices.
- C. The primary FMC currently has devices connected to it.
- D. The code versions running on the Cisco FMC devices are different
正解:A
解説:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/firepower_management_center_high_availability.html
質問 # 28
An analyst using the security analyst account permissions is trying to view the Correlations Events Widget but is not able to access it. However, other dashboards are accessible. Why is this occurring?
- A. The widget is configured to display only when active events are present.
- B. The widget is not configured within the Cisco FMC.
- C. An API restriction within the Cisco FMC is preventing the widget from displaying.
- D. The security analyst role does not have permission to view this widget.
正解:D
質問 # 29
Which CLI command is used to generate firewall debug messages on a Cisco Firepower?
- A. system support ssl-debug
- B. system support firewall-engine-debug
- C. system support platform
- D. system support dump-table
正解:B
解説:
Reference:
https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/212330-firepower- management-center-display-acc.html
質問 # 30
An administrator is adding a QoS policy to a Cisco FTD deployment. When a new rule is added to the policy and QoS is applied on 'Interfaces in Destination Interface Objects", no interface objects are available What is the problem?
- A. A conflict exists between the destination interface types that is preventing QoS from being added
- B. QoS is available only on routed interfaces, and this device is in transparent mode.
- C. The network segments that the interfaces are on do not have contiguous IP space
- D. The FTD is out of available resources lor use. so QoS cannot be added
正解:B
質問 # 31
An engineer currently has a Cisco FTD device registered to the Cisco FMC and is assigned the address of 10 10.50.12. The organization is upgrading the addressing schemes and there is a requirement to convert the addresses to a format that provides an adequate amount of addresses on the network What should the engineer do to ensure that the new addressing takes effect and can be used for the Cisco FTD to Cisco FMC connection?
- A. Update the IP addresses from IFV4 to IPv6 without deleting the device from Cisco FMC
- B. Delete and reregister the device to Cisco FMC
- C. Format and reregister the device to Cisco FMC.
- D. Cisco FMC does not support devices that use IPv4 IP addresses.
正解:B
質問 # 32
A network administrator is configuring Snort inspection policies and is seeing failed deployment messages in Cisco FMC. What information should the administrator generate for Cisco TAC to help troubleshoot?
- A. A "troubleshoot" file for the Cisco FMC.
- B. A "troubleshoot" file for the device in question.
- C. A "show tech" for the Cisco FMC.
- D. A "show tech" file for the device in question.
正解:B
質問 # 33
A network administrator is configuring a Cisco AMP public cloud instance and wants to capture infections and polymorphic variants of a threat to help detect families of malware. Which detection engine meets this requirement?
- A. Spero
- B. Ethos
- C. Tetra
- D. RBAC
正解:B
質問 # 34
......
Cisco 300-710 認定試験の出題範囲:
| トピック | 出題範囲 |
|---|---|
| トピック 1 |
|
| トピック 2 |
|
| トピック 3 |
|
| トピック 4 |
|
| トピック 5 |
|
| トピック 6 |
|
| トピック 7 |
|
| トピック 8 |
|
| トピック 9 |
|
| トピック 10 |
|
300-710問題集と練習テスト(261試験問題):https://www.goshiken.com/Cisco/300-710-mondaishu.html
リリースCisco 300-710更新された問題PDF:https://drive.google.com/open?id=15XI7BcpW__tKxq0MMnukZVbXlsSVZ7MY