[2026年03月]更新のCisco 300-710問題集合格率を上げるなら300-710試験問題集
あなたのゴールを成し遂げるための問題集!あなたのSecuring Networks with Cisco Firepowerの試験準備を合格するために実際のCisco 300-710問題集をおすすめします
質問 # 148
Which Cisco Secure Firewall Management Center widget is authorized only for users with administrator access?
- A. appliance information
- B. product licensing
- C. system load
- D. current sessions
正解:B
質問 # 149
Which component is needed to perform rapid threat containment with Cisco FMC?
- A. ISE
- B. SIEM
- C. RESTful API
- D. DDI
正解:A
解説:
To perform rapid threat containment with Cisco FMC, the necessary component is Cisco Identity Services Engine (ISE). ISE integrates with FMC to provide dynamic network access control and enforcement, allowing for quick isolation of compromised endpoints based on security events detected by FMC.
Steps:
* Integrate FMC with ISE by configuring the necessary settings in both platforms.
* Define security policies in FMC that trigger rapid threat containment actions via ISE.
* When a threat is detected, FMC can instruct ISE to isolate the affected endpoint, limiting its access to the network.
This integration enables automated and efficient threat containment, reducing the response time and mitigating the impact of security incidents.
References:Cisco Secure Firewall Management Center Integration Guide, Chapter on ISE Integration for Rapid Threat Containment.
質問 # 150
Which default action setting in a Cisco FTD Access Control Policy allows all traffic from an undefined application to pass without Snort Inspection?
- A. Trust All Traffic
- B. Intrusion Prevention
- C. Inherit from Base Policy
- D. Network Discovery Only
正解:A
解説:
The default action setting in a Cisco FTD Access Control Policy determines how the system handles and logs traffic that is not handled by any other access control configuration. The default action can block or trust all traffic without further inspection, or inspect traffic for intrusions and discovery data3.
The Trust All Traffic option allows all traffic from an undefined application to pass without Snort inspection.
This option also disables Security Intelligence filtering, file and malware inspection, and URL filtering for all traffic handled by the default action. This option is useful when you want to minimize the performance impact of access control on your network3.
The other options are incorrect because:
* The Inherit from Base Policy option inherits the default action setting from the base policy. The base policy is the predefined access control policy that you use as a starting point for creating your own policies. Depending on which base policy you choose, the inherited default action setting can be different3.
* The Network Discovery Only option inspects all traffic for discovery data only. This option enables Security Intelligence filtering for all traffic handled by the default action, but disables file and malware inspection, URL filtering, and intrusion inspection. This option is useful when you want to collect information about your network before you configure access control rules3.
* The Intrusion Prevention option inspects all traffic for intrusions and discovery data. This option enables Security Intelligence filtering, file and malware inspection, URL filtering, and intrusion inspection for all traffic handled by the default action. This option provides the most comprehensive protection for your network, but also has the most performance impact3.
質問 # 151
A network engineer is logged into the Cisco AMP for Endpoints console and sees a malicious verdict for an identified SHA-256 hash. Which configuration is needed to mitigate this threat?
- A. Add the hash from the infected endpoint to the network block list.
- B. Add the hash to the simple custom deletion list.
- C. Use regular expressions to block the malicious file.
- D. Enable a personal firewall in the infected endpoint.
正解:B
質問 # 152
A user within an organization opened a malicious file on a workstation which in turn caused a ransomware attack on the network. What should be configured within the Cisco FMC to ensure the file is tested for viruses on a sandbox system?
- A. Dynamic analysis
- B. Local malware analysis
- C. Capacity handling
- D. Spere analysis
正解:A
解説:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/623/configuration/guide/fpmc-config-guide-v623/file_policies_and_advanced_malware_protection.html#ID-2199-000005d8
質問 # 153
What is a result of enabling Cisco FTD clustering?
- A. All Firepower appliances can support Cisco FTD clustering.
- B. Site-to-site VPN functionality is limited to the master unit, and all VPN connections are dropped if the master unit fails.
- C. Integrated Routing and Bridging is supported on the master unit.
- D. For the dynamic routing feature, if the master unit fails, the newly elected master unit maintains all existing connections.
正解:B
解説:
Remote access VPN is not supported with clustering. VPN functionality is limited to the control unit and does not take advantage of the cluster high availability capabilities.
If the control unit fails, all existing VPN connections are lost, and VPN users will see a disruption in service. When a new control unit is elected, you must re-establish the VPN connections.
https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-config- guide-v64/clustering_for_the_firepower_threat_defense.html
質問 # 154
Which action should be taken after editing an object that is used inside an access control policy?
- A. Create another rule using a different object name.
- B. Delete the existing object in use.
- C. Refresh the Cisco FMC GUI for the access control policy.
- D. Redeploy the updated configuration.
正解:D
解説:
Section: Management and Troubleshooting
Explanation/Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/630/configuration/guide/fpmc-config- guide-v63/reusable_objects.html
質問 # 155
Drag and Drop Question
Refer to the exhibit. An engineer configures a NAT rule allowing clients to use the internet only if clients are located on the directly connected internal network. Dynamic auto PAT must be configured. Drag and drop the NAT rules from the left onto the corresponding targets on the right.
Not all options are used.

正解:
解説:
質問 # 156
An engineer is configuring a Cisco Secure Firewall Threat Defense device managed by Cisco Secure Firewall Management Center. The device must have SSH enabled and be accessible from the inside interface for remote administration. Which type of policy must the engineer configure to accomplish this?
- A. access control
- B. platform settings
- C. identity
- D. prefilter
正解:B
解説:
To enable SSH access to a Cisco Secure Firewall Threat Defense (FTD) device from the inside interface for remote administration, the engineer needs to configure a Platform Settings policy in Cisco Secure Firewall Management Center (FMC). The Platform Settings policy allows the configuration of various system-related settings, including enabling SSH, specifying the allowed interfaces, and defining the SSH access parameters.
Steps:
In FMC, navigate to Policies > Access Control > Platform Settings. Create a new Platform Settings policy or edit an existing one.
In the policy settings, go to the SSH section.
Enable SSH and specify the inside interface as the allowed interface for SSH access. Define the SSH parameters such as allowed IP addresses, user credentials, and other security settings.
Save and deploy the policy to the FTD device.
This configuration ensures that SSH access is enabled on the specified interface, allowing secure remote administration.
質問 # 157
An analyst using the security analyst account permissions is trying to view the Correlations Events Widget but is not able to access it. However, other dashboards are accessible. Why is this occurring?
- A. The widget is not configured within the Cisco FMC.
- B. An API restriction within the Cisco FMC is preventing the widget from displaying.
- C. The security analyst role does not have permission to view this widget.
- D. The widget is configured to display only when active events are present.
正解:C
質問 # 158
Refer to the exhibit. An engineer is configuring access control rules on a Cisco Secure Firewall Threat Defense device. The access control rules must include a file policy with rules that will trigger when MSEXE files are accessed. Which two actions must be configured in the access rule? (Choose two.)
- A. interactive block
- B. allow
- C. block files with reset
- D. monitor
- E. trust
正解:A、B
質問 # 159
A network engineer detects a connectivity issue between Cisco Secure Firewall Management Centre and Cisco Secure Firewall Threat Defense Initial troubleshooting indicates that heartbeats and events not being received. The engineer re-establishes the secure channels between both peers Which two commands must the engineer run to resolve the issue? (Choose two.)
- A. sudo stats_unified.pl
- B. show history
- C. manage_procs.pl
- D. sudo perfstats -Cq < /var/sf/rna/correlator-stats/now
- E. show disk-manager
正解:A、C
解説:
When connectivity issues are detected between Cisco Secure Firewall Management Center (FMC) and Cisco Secure Firewall Threat Defense (FTD) devices, and initial troubleshooting indicates that heartbeats and events are not being received, the engineer can run the following commands to resolve the issue by re-establishing secure channels and checking process statuses:
* manage_procs.pl:This script is used to manage and restart processes on the FTD device. Running this script can help restart any malfunctioning processes and re-establish connectivity between the FMC and FTD.
* sudo stats_unified.pl:This command provides detailed statistics and status of the unified system processes. It helps in diagnosing and resolving issues related to the secure channel and event reporting.
Steps:
* Access the FTD CLI.
* Run the commandmanage_procs.plto restart processes.
* Run the commandsudo stats_unified.plto gather detailed process statistics and verify the status.
These commands help resolve connectivity issues by ensuring that all necessary processes are running correctly and secure channels are re-established.
References:Cisco Secure Firewall Threat Defense Configuration Guide, Chapter on Troubleshooting and CLI Commands.
質問 # 160
An engineer wants to connect a single IP subnet through a Cisco FTD firewall and enforce policy. There is a requirement to present the internal IP subnet to the outside as a different IP address. What must be configured to meet these requirements?
- A. Configure the downstream router to perform NAT.
- B. Configure the upstream router to perform NAT.
- C. Configure the Cisco FTD firewall in transparent mode with NAT enabled.
- D. Configure the Cisco FTD firewall in routed mode with NAT enabled.
正解:D
質問 # 161
An administrator is setting up Cisco Firepower to send data to the Cisco Stealthwatch appliances. The NetFlow_Set_Parameters object is already created, but NetFlow is not being sent to the flow collector. What must be done to prevent this from occurring?
- A. Add the NetFlow_Send_Destination object to the configuration
- B. Create a service identifier to enable the NetFlow service
- C. Add the NetFlow_Add_Destination object to the configuration
- D. Create a Security Intelligence object to send the data to Cisco Stealthwatch
正解:C
質問 # 162
What is a method used by Cisco Rapid Threat Containment to contain the threat in the network?
- A. share context data
- B. trustsec segmentation
- C. change of authentication
- D. TACACS+
正解:B
質問 # 163
A network administrator is configuring Snort inspection policies and is seeing failed deployment messages in Cisco FMC. What information should the administrator generate for Cisco TAC to help troubleshoot?
- A. A "troubleshoot" file for the device in question.
- B. A "show tech" for the Cisco FMC.
- C. A "show tech" file for the device in question.
- D. A "troubleshoot" file for the Cisco FMC.
正解:A
質問 # 164
An engineer must replace a Cisco Secure Firewall high-availability device due to a failure. When the replacement device arrives, the engineer must separate the high-availability pair from Cisco Secure Firewall Management Center. Which action must the engineer take first to restore high availability?
- A. Unregister the secondary device.
- B. Configure NTP time synchronization.
- C. Register the secondary device
- D. Force a break between the devices.
正解:A
解説:
When replacing a Cisco Secure Firewall high-availability (HA) device due to a failure, the first step the engineer must take is to unregister the secondary (failed) device from the Cisco Secure Firewall Management Center (FMC). This action separates the HA pair and ensures that the new replacement device can be registered and configured correctly.
Steps:
Access the FMC and navigate to the device management section.
Unregister the failed secondary device to remove it from the HA pair.
Register the replacement device to the FMC.
Reconfigure the HA settings to restore the high-availability configuration.
By unregistering the failed device first, the engineer ensures a clean setup for the replacement device, avoiding potential conflicts or issues in the HA configuration.
質問 # 165
An administrator is adding a new URL-based category feed to the Cisco FMC for use within the policies. The intelligence source does not use STIX. but instead uses a .txt file format. Which action ensures that regular updates are provided?
- A. Add a TAXII feed source and input the URL for the feed.
- B. Add a URL source and select the flat file type within Cisco FMC.
- C. Upload the .txt file and configure automatic updates using the embedded URL.
- D. Convert the .txt file to STIX and upload it to the Cisco FMC.
正解:A
質問 # 166
......
100% 無料300-710デモ-試し読み [PDF]、今すぐゲットせよ:https://drive.google.com/open?id=1wz9CQKzWWNBfHRGLlz4LAHiCZUeSKX6x
正確でかつ完璧 アンサーはまるでリアル試験問題:https://www.goshiken.com/Cisco/300-710-mondaishu.html