[2024年03月15日] 最新更新されたのは300-710試験問題2024年更新
無料更新されたCisco 300-710テストエンジン問題には279問題と解答
Cisco 300-710:Cisco Firepower試験でネットワークを保護することは、ネットワークセキュリティのスキルと知識を強化したい専門家にとって優れた認証です。この認定は、Cisco Firpower NGIPSおよびNGFWソリューションの構成、展開、および管理における個人の専門知識を検証します。この認定は業界で高く評価されており、専門家がネットワークセキュリティの分野でキャリアを促進するのに役立ちます。
Cisco Firepower NGFWは、ネットワークからエンドポイントまでの攻撃の全体的な脅威保護と可視性を提供します。この試験では、NGFWアクセス制御ポリシー、SSL復号化、およびVPNの設定などのトピックがカバーされます。候補者は、カスタムシグネチャやイベントアクションを含むIPSポリシーの設定と管理能力もテストされます。
質問 # 24
An engineer must configure the firewall to monitor traffic within a single subnet without increasing the hop count of that traffic. How would the engineer achieve this?
- A. Set up Cisco Firepower in intrusion prevention mode
- B. Configure Cisco Firepower as a transparent firewall
- C. Set up Cisco Firepower as managed by Cisco FDM
- D. Configure Cisco Firepower in FXOS monitor only mode.
正解:B
質問 # 25
A security engineer is configuring an Access Control Policy for multiple branch locations. These locations share a common rule set and utilize a network object called INSIDE_NET which contains the locally significant internal network subnets at each location. Which technique will retain the policy consistency at each location but allow only the locally significant network subnet within the applicable rules?
- A. creating a unique Access Control Policy per device
- B. utilizing policy inheritance
- C. utilizing a dynamic Access Control Policy that updates from Cisco Talos
- D. creating an Access Control Policy with an INSIDE_NET network object and object overrides
正解:D
質問 # 26
Which command is run on an FTD unit to associate the unit to an FMC manager that is at IP address 10.0.0.10, and that has the registration key Cisco123?
- A. configure manager local Cisco123 10.0.0.10
- B. configure manager add 10.0.0.10 Cisco123
- C. configure manager local 10.0.0.10 Cisco123
- D. configure manager add Cisco123 10.0.0.10
正解:B
解説:
Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/misc/fmc-ftd-mgmt-nw/fmc-ftd-mgmt-nw.html#id_106101
質問 # 27
A company wants a solution to aggregate the capacity of two Cisco FTD devices to make the best use of resources such as bandwidth and connections per second. Which order of steps must be taken across the Cisco FTDs with Cisco FMC to meet this requirement?
- A. Add members to Cisco FMC, configure Cisco FTD interfaces in Cisco FMC. configure cluster members in Cisco FMC, create cluster in Cisco FMC. and configure cluster members in Cisco FMC.
- B. Configure the Cisco FTD interfaces, add members to FMC, configure cluster members in FMC, and create cluster in Cisco FMC.
- C. Add members to the Cisco FMC, configure Cisco FTD interfaces, create the cluster in Cisco FMC, and configure cluster members in Cisco FMC.
- D. Configure the Cisco FTD interfaces and cluster members, add members to Cisco FMC. and create the cluster in Cisco FMC.
正解:D
質問 # 28
Refer to the exhibit.
And engineer is analyzing the Attacks Risk Report and finds that there are over 300 instances of new operating systems being seen on the network How is the Firepower configuration updated to protect these new operating systems?
- A. The administrator manually updates the policies.
- B. Cisco Firepower gives recommendations to update the policies.
- C. Cisco Firepower automatically updates the policies.
- D. The administrator requests a Remediation Recommendation Report from Cisco Firepower
正解:B
解説:
Explanation
Ref:
https://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide-v60/Tailori
質問 # 29
A network engineer implements a new Cisco Firepower device on the network to take advantage of its intrusion detection functionality. There is a requirement to analyze the traffic going across the device, alert on any malicious traffic, and appear as a bump in the wire How should this be implemented?
- A. Specify the BVl IP address as the default gateway for connected devices.
- B. Configure a bridge group in transparent mode.
- C. Enable routing on the Cisco Firepower
- D. Add an IP address to the physical Cisco Firepower interfaces.
正解:D
質問 # 30
What is the result a specifying of QoS rule that has a rate limit that is greater than the maximum throughput of an interface?
- A. Matching traffic is not rate limited.
- B. The rate-limiting rule is disabled.
- C. The system rate-limits all traffic.
- D. The system repeatedly generates warnings.
正解:A
解説:
Section: Configuration
Explanation/Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config- guide-v62/quality_of_service_qos.pdf
質問 # 31
In which two places can thresholding settings be configured? (Choose two.)
- A. globally, per intrusion policy
- B. per preprocessor, within the network analysis policy
- C. on each access control rule
- D. on each IPS rule
- E. globally, within the network analysis policy
正解:A、D
解説:
Section: Configuration
Explanation/Reference: https://www.cisco.com/c/en/us/td/docs/security/firesight/541/firepower-module-user-guide/asa- firepower-module-user-guide-v541/Intrusion-Global-Threshold.pdf
質問 # 32
Which CLI command is used to control special handling of ClientHello messages?
- A. system support ssl-client-hello-force-reset
- B. system support ssl-client-hello-tuning
- C. system support ssl-client-hello-enabled
- D. system support ssl-client-hello-display
正解:C
質問 # 33
With Cisco FTD integrated routing and bridging, which interface does the bridge group use to communicate with a routed interface?
- A. bridge virtual
- B. bridge group member
- C. subinterface
- D. switch virtual
正解:A
解説:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-config-guide-v64/transp
質問 # 34
A network engineer implements a new Cisco Firepower device on the network to take advantage of its intrusion detection functionality. There is a requirement to analyze the traffic going across the device, alert on any malicious traffic, and appear as a bump in the wire How should this be implemented?
- A. Specify the BVl IP address as the default gateway for connected devices.
- B. Add an IP address to the physical Cisco Firepower interfaces.
- C. Enable routing on the Cisco Firepower
- D. Configure a bridge group in transparent mode.
正解:D
解説:
Traditionally, a firewall is a routed hop and acts as a default gateway for hosts that connect to one of its screened subnets. A transparent firewall, on the other hand, is a Layer 2 firewall that acts like a "bump in the wire," or a "stealth firewall," and is not seen as a router hop to connected devices. However, like any other firewall, access control between interfaces is controlled, and all of the usual firewall checks are in place. Layer 2 connectivity is achieved by using a "bridge group" where you group together the inside and outside interfaces for a network, and the ASA uses bridging techniques to pass traffic between the interfaces. Each bridge group includes a Bridge Virtual Interface (BVI) to which you assign an IP address on the network. You can have multiple bridge groups for multiple networks. In transparent mode, these bridge groups cannot communicate with each other. https://www.cisco.com/c/en/us/td/docs/security/asa/asa97/configuration/general/asa-97-general-config/intro-fw.html
質問 # 35
Within Cisco Firepower Management Center, where does a user add or modify widgets?
- A. dashboard
- B. summary tool
- C. context explorer
- D. reporting
正解:A
解説:
Section: Management and Troubleshooting
Explanation/Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide- v60/Using_Dashboards.html
質問 # 36
Which two types of objects are reusable and supported by Cisco FMC? (Choose two.)
- A. reputation-based objects that represent Security Intelligence feeds and lists, application filters based on category and reputation, and file lists
- B. network-based objects that represent IP address and networks, port/protocols pairs, VLAN tags, security zones, and origin/destination country
- C. dynamic key mapping objects that help link HTTP and HTTPS GET requests to Layer 7 application protocols.
- D. reputation-based objects, such as URL categories
- E. network-based objects that represent FQDN mappings and networks, port/protocol pairs, VXLAN tags, security zones and origin/destination country
正解:A、B
質問 # 37
A network administrator is configuring a site-to-site IPsec VPN to a router sitting behind a Cisco FTD. The administrator has configured an access policy to allow traffic to this device on UDP 500, 4500, and ESP VPN traffic is not working. Which action resolves this issue?
- A. Enable IPsec inspection on the access policy.
- B. Set the allow action in the access policy to trust.
- C. Change the access policy to allow all ports.
- D. Modify the NAT policy to use the interface PAT.
正解:A
質問 # 38
An engineer must configure high availability for the Cisco Firepower devices. The current network topology does not allow for two devices to pass traffic concurrently. How must the devices be implemented in this environment?
- A. in active/passive mode
- B. in active/active mode
- C. in cluster interface mode
- D. in a cluster span EtherChannel
正解:A
質問 # 39
Drag and drop the steps to restore an automatic device registration failure on the standby Cisco FMC from the left into the correct order on the right. Not all options are used.
正解:
解説:
質問 # 40
What is the role of the casebook feature in Cisco Threat Response?
- A. pulling data via the browser extension
- B. sharing threat analysts
- C. triage automaton with alerting
- D. alert prioritization
正解:B
解説:
Explanation
The casebook and pivot menu are widgets available in Cisco Threat Response. Casebook - It is used to record, organize, and share sets of observables of interest primarily during an investigation and threat analysis. You can use a casebook to get the current verdicts or dispositions on the observables.
https://www.cisco.com/c/en/us/td/docs/se
curity/ces/user_guide/esa_user_guide_13-5-1/b_ESA_Admin_Guide_ces
_13-5-1/b_ESA_Admin_Guide_13-0_chapter_0110001.pdf
質問 # 41
Drag and drop the steps to restore an automatic device registration failure on the standby Cisco FMC from the left into the correct order on the right. Not all options are used.
正解:
解説:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config- guide-v62/firepower_management_center_high_availability.html#id_32288
質問 # 42
Which object type supports object overrides?
- A. DNS server group
- B. security group tag
- C. time range
- D. network object
正解:D
解説:
Section: Configuration
Explanation/Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide- v60/Reusable_Objects.html#concept_8BFE8B9A83D742D9B647A74F7AD50053
質問 # 43
What is a behavior of a Cisco FMC database purge?
- A. The appropriate process is restarted.
- B. User login and history data are removed from the database if the User Activity check box is selected.
- C. Data can be recovered from the device.
- D. The specified data is removed from Cisco FMC and kept for two weeks.
正解:A
解説:
Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/management_center_database_purge.pdf
質問 # 44
Which action must be taken on the Cisco FMC when a packet bypass is configured in case the Snort engine is down or a packet takes too long to process?
- A. Enable Inspect Local Router Traffic
- B. Enable Automatic Application Bypass
- C. Add a Bypass Threshold policy for failures
- D. Configure Fastpath rules to bypass inspection
正解:B
質問 # 45
An administrator must use Cisco FMC to install a backup route within the Cisco FTD to route traffic in case of a routing failure with the primary route. Which action accomplishes this task?
- A. Create the backup route and use route tracking on both routes to a destination IP address in the network.
- B. Configure EIGRP routing on the FMC to ensure that dynamic routes are always updated.
- C. Install the static backup route and modify the metric to be less than the primary route.
- D. Use a default route on the FMC instead of having multiple routes contending for priority.
正解:A
質問 # 46
An engineer must define a URL object on Cisco FMC. What is the correct method to specify the URL without performing SSL inspection?
- A. Specify the protocol in the object.
- B. Specify all subdomains in the object group.
- C. Use Subject Common Name value.
- D. Include all URLs from CRL Distribution Points.
正解:C
質問 # 47
Refer to the exhibit.
An organization has an access control rule with the intention of sending all social media traffic for inspection After using the rule for some time, the administrator notices that the traffic is not being inspected, but is being automatically allowed What must be done to address this issue?
- A. Add the social network URLs to the block list
- B. Change the intrusion policy to connectivity over security.
- C. Modify the selected application within the rule
- D. Modify the rule action from trust to allow
正解:C
質問 # 48
......
Cisco Firepower Technologyは、高度な脅威の検出と保護機能を提供する包括的なセキュリティソリューションです。セキュリティの専門家は、ネットワークトラフィックを監視し、セキュリティの脅威を検出および防止し、セキュリティインシデントにリアルタイムで対応できます。 Cisco Firepower NGFWとFMCは、このソリューションの重要なコンポーネントであり、ネットワークセキュリティ管理のための統一されたプラットフォームを提供します。
100%の合格率を試そう!更新されたのは300-710試験問題 [2024年更新]:https://www.goshiken.com/Cisco/300-710-mondaishu.html
ベストな問題集を使おうCCNP Security 300-710専門試験問題:https://drive.google.com/open?id=1muayH_pi_Q-aO_BH-F5aio0b4t5LZaMH