Pre-Winter Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: agile70

ExamsBrite Dumps

Securing Networks with Cisco Firewalls Question and Answers

Securing Networks with Cisco Firewalls

Last Update Sep 21, 2026
Total Questions : 420

We are offering FREE 300-710 Cisco exam questions. All you do is to just go and sign up. Give your details, prepare 300-710 free exam questions and then go for complete pool of Securing Networks with Cisco Firewalls test questions that will help you more.

300-710 pdf

300-710 PDF

$34.5  $114.99
300-710 Engine

300-710 Testing Engine

$40.5  $134.99
300-710 PDF + Engine

300-710 PDF + Testing Engine

$52.5  $174.99
Questions 1

What is the benefit of selecting the trace option for packet capture?

Options:

A.  

The option indicates whether the packet was dropped or successful.

B.  

The option indicated whether the destination host responds through a different path.

C.  

The option limits the number of packets that are captured.

D.  

The option captures details of each packet.

Discussion 0
Questions 2

A network administrator is configuring a site-to-site IPsec VPN to a router sitting behind a Cisco FTD. The administrator has configured an access policy to allow traffic to this device on UDP 500, 4500, and ESP VPN traffic is not working. Which action resolves this issue?

Options:

A.  

Set the allow action in the access policy to trust.

B.  

Enable IPsec inspection on the access policy.

C.  

Modify the NAT policy to use the interface PAT.

D.  

Change the access policy to allow all ports.

Discussion 0
Questions 3

An engineer is troubleshooting HTTP traffic to a web server using the packet capture tool on Cisco FMC. When reviewing the captures, the engineer notices that there are a lot of packets that are not sourced from or destined to the web server being captured. How can the engineer reduce the strain of capturing packets for irrelevant traffic on the Cisco FTD device?

Options:

A.  

Use the host filter in the packet capture to capture traffic to or from a specific host.

B.  

Redirect the packet capture output to a. pcap file that can be opened with Wireshark.

C.  

Use the -c option to restrict the packet capture to only the first 100 packets.

D.  

Use an access-list within the packet capture to permit only HTTP traffic to and from the web server.

Discussion 0
Questions 4

An engineer is configuring Cisco FMC and wants to limit the time allowed for processing packets through the interface However if the time is exceeded the configuration must allow packets to bypass detection What must be configured on the Cisco FMC to accomplish this task?

Options:

A.  

Fast-Path Rules Bypass

B.  

Cisco ISE Security Group Tag

C.  

Inspect Local Traffic Bypass

D.  

Automatic Application Bypass

Discussion 0
Questions 5

Which CLI command is used to generate firewall debug messages on a Cisco Firepower?

Options:

A.  

system support firewall-engine-debug

B.  

system support ssl-debug

C.  

system support platform

D.  

system support dump-table

Discussion 0
Questions 6

A network engineer sets up a secondary CiscoFMC that is integrated with Cisco Security Packet Analyzer What occurs when the secondary CiscoFMC synchronizes with the primary Cisco FMC?

Options:

A.  

The existing integration configuration is replicated to the primary Cisco FMC

B.  

The existing configuration for integration of the secondary Cisco FMC the Cisco Security Packet Analyzer is overwritten.

C.  

The synchronization between the primary and secondary Cisco FMC fails

D.  

The secondary Cisco FMC must be reintegrated with the Cisco Security Packet Analyzer after the synchronization

Discussion 0
Questions 7

In a Cisco AMP for Networks deployment, which disposition is returned if the cloud cannot be reached?

Options:

A.  

unavailable

B.  

unknown

C.  

clean

D.  

disconnected

Discussion 0
Questions 8

A security engineer manages a firewall console and an endpoint console and finds it challenging and the consuming to review events and modify blocking of specific files in both consoles. Which action must the engineer take to streamline this process?

Options:

A.  

From the Secure FMC. create a Cisco Secure Endpoint object and reference the object in the Cisco Secure Endpoint console.

B.  

From the Cisco Secure Endpoint console, Croats and copy an API key and paste into the Cisco Secure AMP tab

C.  

initiate the integration between Secure FMC and Cisco Secure Endpoint from the Secure FMC using the AMP tab

D.  

Within the Cisco Secure Endpoint console, copy the connector GUID and paste into the Cisco Secure Firewall Management Center (FMC) AMP tab.

Discussion 0
Questions 9

What is the maximum SHA level of filtering that Threat Intelligence Director supports?

Options:

A.  

SHA-1024

B.  

SHA-4096

C.  

SHA-512

D.  

SHA-256

Discussion 0
Questions 10

A software development company hosts the website http:dev.company.com for contractors to share code for projects they are working on with internal developers. The web server is on premises and is protected by a Cisco Secure Firewall Threat Defense appliance. The network administrator is worried about someone trying to transmit infected files to internal users via this site. Which type of policy must be able associated with an access control policy to enable Cisco Secure Firewall Malware Defense to detect and block malware?

Options:

A.  

SSL policy

B.  

Prefilter policy

C.  

File policy

D.  

Network discovery policy

Discussion 0
Questions 11

Which command is typed at the CLI on the primary Cisco FTD unit to temporarily stop running high- availability?

Options:

A.  

configure high-availability resume

B.  

configure high-availability disable

C.  

system support network-options

D.  

configure high-availability suspend

Discussion 0
Questions 12

An organization has a Cisco IPS running in inline mode and is inspecting traffic for malicious activity. When traffic is received by the Cisco IRS, if it is not dropped, how does the traffic get to its destination?

Options:

A.  

It is retransmitted from the Cisco IPS inline set.

B.  

The packets are duplicated and a copy is sent to the destination.

C.  

It is transmitted out of the Cisco IPS outside interface.

D.  

It is routed back to the Cisco ASA interfaces for transmission.

Discussion 0
Questions 13

An engineer is configuring two new Cisco Secure Firewall Threat Defense appliances as a high-availability pair. The high-availability pair must detect a failure on the failover link and trigger failover more quickly. Which two settings must the engineer decrease? (Choose two.)

Options:

A.  

Interface poll time

B.  

Peer hold time

C.  

Interface failure limit

D.  

Peer poll time

E.  

Interface hold time

Discussion 0
Questions 14

An engineer installs a Cisco FTD device and wants to inspect traffic within the same subnet passing through a firewall and inspect traffic destined to the internet.

Which configuration will meet this requirement?

Options:

A.  

transparent firewall mode with IRB only

B.  

routed firewall mode with BVI and routed interfaces

C.  

transparent firewall mode with multiple BVIs

D.  

routed firewall mode with routed interfaces only

Discussion 0
Questions 15

With Cisco FTD integrated routing and bridging, which interface does the bridge group use to communicate with a routed interface?

Options:

A.  

switch virtual

B.  

bridge group member

C.  

bridge virtual

D.  

subinterface

Discussion 0
Questions 16

Users report that Cisco Duo 2FA fails when they attempt to connect to the VPN on a Cisco Secure Firewall Threat Defense (FTD) device IT staff have VPN profiles that do not require multifactor authentication and they can connect to the VPN without any issues When viewing the VPN troubleshooting log in Cisco Secure Firewall Management Centre (FMC), the network administrator sees an error in the Cisco Duo AAA server has been marked as tailed. What is the root cause of the Issue?

Options:

A.  

Multifactor authentication Is not supported on Secure FMC managed devices.

B.  

Duo trust certificates are missing from the Secure FTD device.

C.  

The internal AD server is unreachable from the Secure FTD device.

D.  

AD Trust certificates are missing from the Secure FTD device.

Discussion 0
Questions 17

An engineer has been tasked with using Cisco FMC to determine if files being sent through the network are malware. Which two configuration takes must be performed to achieve this file lookup? (Choose two.)

Options:

A.  

The Cisco FMC needs to include a SSL decryption policy.

B.  

The Cisco FMC needs to connect to the Cisco AMP for Endpoints service.

C.  

The Cisco FMC needs to connect to the Cisco ThreatGrid service directly for sandboxing.

D.  

The Cisco FMC needs to connect with the FireAMP Cloud.

E.  

The Cisco FMC needs to include a file inspection policy for malware lookup.

Discussion 0
Questions 18

A security engineer must deploy a Cisco FTD appliance as a bump in the wire to detect intrusion events without disrupting the flow of network traffic. Which two features must be configured to accomplish the task? (Choose two.)

Options:

A.  

inline set pair

B.  

transparent mode

C.  

tapemode

D.  

passive interfaces

E.  

bridged mode

Discussion 0
Questions 19

A security engineer must improve security in an organization and is producing a risk mitigation strategy to present to management for approval. Which action must the security engineer take based on this Attacks Risk Report?

Options:

A.  

Inspect DNS traffic

B.  

Block NetBIOS.

C.  

Block Internal Explorer

D.  

Inspect TCP port 80 traffic

Discussion 0
Questions 20

An engainermust add DNS-specific rules to me Cisco FTD intrusion policy. The engineer wants to use the rules currently in the Cisco FTD Snort database that are not already enabled but does not want to enable more than are needed. Which action meets these requirements?

Options:

A.  

Change the dynamic state of the rule within the policy.

B.  

Change the base policy to Security over Connectivity.

C.  

Change the rule state within the policy being used.

D.  

Change the rules using the Generate and Use Recommendations feature.

Discussion 0
Questions 21

A network administrator notices that inspection has been interrupted on all non-managed interfaces of a device. What is the cause of this?

Options:

A.  

The value of the highest MTU assigned to any non-management interface was changed.

B.  

The value of the highest MSS assigned to any non-management interface was changed.

C.  

A passive interface was associated with a security zone.

D.  

Multiple inline interface pairs were added to the same inline interface.

Discussion 0
Questions 22

Refer to the exhibit. An engineer analyzes a Network Risk Report from Cisco Secure Firewall Management Center. What should the engineer recommend implementing to mitigate the risk?

Options:

A.  

IP address and URL blacklisting

B.  

Trend analysis

C.  

Network-based detection

D.  

Virtual protection

Discussion 0
Questions 23

Which command is entered in the Cisco FMC CLI to generate a troubleshooting file?

Options:

A.  

show running-config

B.  

show tech-support chassis

C.  

system support diagnostic-cli

D.  

sudo sf_troubleshoot.pl

Discussion 0
Questions 24

After using Firepower for some time and learning about how it interacts with the network, an administrator is trying to correlate malicious activity with a user Which widget should be configured to provide this visibility on the Cisco Firepower dashboards?

Options:

A.  

Custom Analysis

B.  

Current Status

C.  

Current Sessions

D.  

Correlation Events

Discussion 0
Questions 25

An engineer wants to convert a Cisco Secure Firewall Threat Defense device that is currently managed by Cisco Secure Firewall Management Center from routed mode to transparent mode. Which CLI command must the engineer execute first to perform this conversion?

Options:

A.  

no configure manager

B.  

no configure firewall routed

C.  

configure manager delete

D.  

configure firewall transparent

Discussion 0
Questions 26

An engineer is attempting to add a new FTD device to their FMC behind a NAT device with a NAT ID of ACME001 and a password of Cisco388267669. Which command set must be used in order to accomplish this?

Options:

A.  

configure manager add ACME001 < registration key > < FMC IP >

B.  

configure manager add < FMC IP > ACME0O1 < registration key >

C.  

configure manager add DONTRESOLVE < FMC IP > AMCE001 < registration key >

D.  

configure manager add < FMC IP > registration key > ACME001

Discussion 0
Questions 27

With a recent summer time change, system logs are showing activity that occurred to be an hour behind real time Which action should be taken to resolve this issue?

Options:

A.  

Manually adjust the time to the correct hour on all managed devices

B.  

Configure the system clock settings to use NTP with Daylight Savings checked

C.  

Manually adjust the time to the correct hour on the Cisco FM

C.  

D.  

Configure the system clock settings to use NTP

Discussion 0
Questions 28

With Cisco FTD software, which interface mode must be configured to passively receive traffic that passes through the appliance?

Options:

A.  

ERSPAN

B.  

IPS-only

C.  

firewall

D.  

tap

Discussion 0
Questions 29

A network administrator manages a network with multiple firewalls in a datacenter using Cisco Secure Firepower Management Center. The administrator must change a next-generation firewall from routed to transparent mode. Which action must the administrator take next to meet the requirement?

Options:

A.  

Deregister the firewall in Cisco Secure Firewall Management Center.

B.  

Enter the configure transparent firewall command from the CLI.

C.  

Create one or more bridge groups from the CLI.

D.  

Manually delete the interface configuration from the CLI.

Discussion 0
Questions 30

An engineer is building a new access control policy using Cisco FMC. The policy must inspect a unique IPS policy as well as log rule matching. Which action must be taken to meet these requirements?

Options:

A.  

Configure an IPS policy and enable per-rule logging.

B.  

Disable the default IPS policy and enable global logging.

C.  

Configure an IPS policy and enable global logging.

D.  

Disable the default IPS policy and enable per-rule logging.

Discussion 0
Questions 31

What is a method used by Cisco Rapid Threat Containment to contain the threat in the network?

Options:

A.  

change of authentication

B.  

share context data

C.  

TACACS+

D.  

trustsec segmentation

Discussion 0
Questions 32

Which feature within the Cisco FMC web interface allows for detecting, analyzing and blocking malware in network traffic?

Options:

A.  

intrusion and file events

B.  

Cisco AMP for Endpoints

C.  

Cisco AMP for Networks

D.  

file policies

Discussion 0
Questions 33

A network engineer detects a connectivity issue between Cisco Secure Firewall Management Center and Cisco Secure Firewall Threat Defense. Initial troubleshooting indicates that heartbeats and events are not being received. The engineer re-establishes the secure channels between both peers. Which two commands must the engineer run to resolve the issue? (Choose two.)

Options:

A.  

show disk-manager

B.  

show history

C.  

sudo stats_unified.pl

D.  

manage_procs.pl

E.  

sudo perfstats -Cq < /var/sf/rna/correlator-stats/now

Discussion 0
Questions 34

Refer to the exhibit. An engineer must import three network objects into the Cisco Secure Firewall Management Center by using a CSV file. Which header must be configured in the CSV file to accomplish the task?

Options:

A.  

NAME;DESCRIPTION;TYPE;VALUE;LOOKUP;

B.  

Name; Description; Type;Value;Lookup;

C.  

Name; Description; Type;Value;DN;

D.  

NAME;DESCRIPTION; TYPE;VALUE;DN;

Discussion 0
Questions 35

An engineer must implement static route tracking on a Cisco Secure Firewall Threat Defense appliance. Static route and IP SLA operation has already been configured. Static route must be removed from the routing table if the tracked object is unreachable. Which action must the engineer take next to meet the requirement?

Options:

A.  

Implement a secondary route that has a higher precedence.

B.  

Enable the IP SLA Responder on the backup path interface.

C.  

Assign a tracking object to the static route and the IP SLA operation.

D.  

Enable an ICMP redirect message on the interface connected to the backup path.

Discussion 0
Questions 36

A Cisco FTD device is running in transparent firewall mode with a VTEP bridge group member ingress interface What must be considered by an engineer tasked with specifying a destination MAC address for a packet trace?

Options:

A.  

The destination MAC address is optional if a VLAN ID value is entered

B.  

Only the UDP packet type is supported

C.  

The output format option for the packet logs unavailable

D.  

The VLAN ID and destination MAC address are optional

Discussion 0
Questions 37

Refer to the exhibit.

An organization has an access control rule with the intention of sending all social media traffic for inspection After using the rule for some time, the administrator notices that the traffic is not being inspected, but is being automatically allowed What must be done to address this issue?

Options:

A.  

Modify the selected application within the rule

B.  

Change the intrusion policy to connectivity over security.

C.  

Modify the rule action from trust to allow

D.  

Add the social network URLs to the block list

Discussion 0
Questions 38

Refer to the exhibit.

An engineer generates troubleshooting files in Cisco Secure Firewall Management Center (FMC). A successfully completed task Is removed before the files are downloaded. Which two actions must be taken to determine the filename and obtain the generated troubleshooting files without regenerating them? (Choose two.)

Options:

A.  

Use an FTP client Hi expert mode on Secure FMC lo upload the files to the FTP server.

B.  

Go to the same screen as shown in the exhibit, click Advanced Troubleshooting, enter the rile name, and then start the download

C.  

Connect to CU on the FTD67 and FTD66 devices and copy the tiles from flash to the PIP server.

D.  

Go to expert mode on Secure FMC. list the contents of/Var/common, and determine the correct filename from the output

E.  

Click System Monitoring, men Audit to determine the correct filename from the line containing the Generate Troubleshooting Files string.

Discussion 0
Questions 39

A network administrator notices that SI events are not being updated The Cisco FTD device is unable to load all of the SI event entries and traffic is not being blocked as expected. What must be done to correct this issue?

Options:

A.  

Restart the affected devices in order to reset the configurations

B.  

Manually update the SI event entries to that the appropriate traffic is blocked

C.  

Replace the affected devices with devices that provide more memory

D.  

Redeploy configurations to affected devices so that additional memory is allocated to the SI module

Discussion 0
Questions 40

An engineer is tasked with deploying an internal perimeter firewall that will support multiple DMZs Each DMZ has a unique private IP subnet range. How is this requirement satisfied?

Options:

A.  

Deploy the firewall in transparent mode with access control policies.

B.  

Deploy the firewall in routed mode with access control policies.

C.  

Deploy the firewall in routed mode with NAT configured.

D.  

Deploy the firewall in transparent mode with NAT configured.

Discussion 0
Questions 41

Which protocol is needed to exchange threat details in rapid threat containment on Cisco FMC?

Options:

A.  

SGT

B.  

SNMP v3

C.  

BFD

D.  

pxGrid

Discussion 0
Questions 42

An engineer must deny ICMP traffic to the networks of separate departments that use Cisco Secure Firewall Management Center. The engineer must use the same object on the relevant device for each network. What must be configured in Secure Firewall Management Center?

Options:

A.  

IP address

B.  

IP range

C.  

Deny ICMP check box

D.  

Allow Overrides check box

Discussion 0
Questions 43

A security engineer wants to add the Interface Traffic widget to the Summary Dashboard in Cisco Secure Firewall Management Center. The engineer clicks Add Widgets and enters edit mode. Which set of actions must the security engineer take to complete the configuration?

Options:

A.  

Click All Categories, open the Analysis & Reporting tab, and then click the Add widget button.

B.  

Click All Categories, open the New tab, and then click the Add widget button.

C.  

Click All Categories, open the Operations tab, and then click the Add widget button.

D.  

Click All Categories, open the Miscellaneous tab, and then click the Add widget button.

Discussion 0
Questions 44

What is the result of specifying of QoS rule that has a rate limit that is greater than the maximum throughput of an interface?

Options:

A.  

The rate-limiting rule is disabled.

B.  

Matching traffic is not rate limited.

C.  

The system rate-limits all traffic.

D.  

The system repeatedly generates warnings.

Discussion 0
Questions 45

Refer to the exhibit.

And engineer is analyzing the Attacks Risk Report and finds that there are over 300 instances of new operating systems being seen on the network How is the Firepower configuration updated to protect these new operating systems?

Options:

A.  

Cisco Firepower automatically updates the policies.

B.  

The administrator requests a Remediation Recommendation Report from Cisco Firepower

C.  

Cisco Firepower gives recommendations to update the policies.

D.  

The administrator manually updates the policies.

Discussion 0
Questions 46

An engineer must configure high availability for the Cisco Firepower devices. The current network topology does not allow for two devices to pass traffic concurrently. How must the devices be implemented in this environment?

Options:

A.  

in active/active mode

B.  

in a cluster span EtherChannel

C.  

in active/passive mode

D.  

in cluster interface mode

Discussion 0
Questions 47

A network engineer is receiving reports of users randomly getting disconnected from their corporate applications which traverses the data center FTD appliance Network monitoring tools show that the FTD appliance utilization is peaking above 90% of total capacity. What must be done in order to further analyze this issue?

Options:

A.  

Use the Packet Export feature to save data onto external drives

B.  

Use the Packet Capture feature to collect real-time network traffic

C.  

Use the Packet Tracer feature for traffic policy analysis

D.  

Use the Packet Analysis feature for capturing network data

Discussion 0
Questions 48

Refer to the exhibit. A client that has IP address 192.168.67.102 reports issues when connecting to a remote server. Based on the topology and output of packet tracer tool, which action resolves the connectivity issue?

Options:

A.  

Add the route to the destination.

B.  

Unblock the access rule on FTDv.

C.  

Restart the client-side application.

D.  

Reconfigure NAT on FTDv.

Discussion 0
Questions 49

A security engineer needs to configure a network discovery policy on a Cisco FMC appliance and prevent excessive network discovery events from overloading the FMC database? Which action must be taken to accomplish this task?

Options:

A.  

Change the network discovery method to TCP/SYN.

B.  

Configure NetFlow exporters for monitored networks.

C.  

Monitor only the default IPv4 and IPv6 network ranges.

D.  

Exclude load balancers and NAT devices in the policy.

Discussion 0
Questions 50

Which two solutions are used to access and view aggregated log data from the firewalls using Cisco Security Analytics and Logging? (Choose two.)

Options:

A.  

Cisco Secure Network Analytics

B.  

Cisco Defense Orchestrator

C.  

Cisco Catalyst Center

D.  

Secure Cloud Analytics

E.  

Cisco Prime Infrastructure

Discussion 0
Questions 51

Drag and drop the configuration steps from the left into the sequence on the right to enable external authentication on Cisco FMC to a RADIUS server.

Options:

Discussion 0
Questions 52

How should a high-availability pair of Cisco Secure Firewall Threat Defense Virtual appliances be deployed to Cisco Secure Firewall Management Center?

Options:

A.  

Configure high availability first, then add only the primary Cisco Secure Firewall Threat Defense Virtual appliance to Cisco Secure Firewall Management Center.

B.  

Add the primary and secondary Cisco Secure Firewall Threat Defense Virtual appliances to Cisco Secure Firewall Management Center first, then configure high availability.

C.  

Add the primary appliance to Cisco Secure Firewall Management Center first, then configure high availability.

D.  

Configure high availability first, then add the primary and secondary appliances to Cisco Secure Firewall Management Center.

Discussion 0
Questions 53

A network administrator is reviewing a monthly advanced malware risk report and notices a host that Is listed as CnC Connected. Where must the administrator look within Cisco FMC to further determine if this host is infected with malware?

Options:

A.  

Analysis > Hosts > indications of Compromise

B.  

Analysts > Files > Malware Events

C.  

Analysis > Hosts > Host Attributes

D.  

Analysis > Flies > Network File Trajectory

Discussion 0
Questions 54

A network administrator has converted a Cisco FTD from using LDAP to LDAPS for VPN authentication. The Cisco FMC can connect to the LDAPS server, but the Cisco FTD is not connecting. Which configuration must be enabled on the Cisco FTD?

Options:

A.  

SSL must be set to a use TLSv1.2 or lower.

B.  

The LDAPS must be allowed through the access control policy.

C.  

DNS servers must be defined for name resolution.

D.  

The RADIUS server must be defined.

Discussion 0
Questions 55

An engineer must deploy a Cisco FTD device. Management wants to examine traffic without requiring network changes that will disrupt end users. Corporate security policy requires the separation of management traffic from data traffic and the use of SSH over Telnet for remote administration. How must the device be deployed to meet these requirements?

Options:

A.  

in routed mode with a diagnostic interface

B.  

in transparent mode with a management Interface

C.  

in transparent made with a data interface

D.  

in routed mode with a bridge virtual interface

Discussion 0
Questions 56

An engineer is deploying failover capabilities for a pair of Cisco Secure Firewall devices. The core switch keeps the MAC address of the previously active unit in the ARP table. Which action must the engineer take to minimize downtime and ensure that network users keep access to the internet after a Cisco Secure Firewall failover?

Options:

A.  

Set the same MAC address on both units.

B.  

Add the MAC address to the switch ARP table.

C.  

Run a script to send gratuitous ARP after a failover.

D.  

Use a virtual MAC address on both units.

Discussion 0
Questions 57

An engineer is deploying a Cisco Secure Firewall Management Center appliance. The company must send data to Cisco Secure Network Analytics appliances. Which two actions must the engineer take? (Choose two.)

Options:

A.  

Configure Security Intelligence object to send data to Cisco Secure Network Analytics.

B.  

Add the Netflow_Send_Destination object to the configuration.

C.  

Add the Netflow_Add_Destination object to the configuration.

D.  

Add the Netflow_Set_Parameters object to the configuration.

E.  

Create a service identifier to enable the NetFlow service.

Discussion 0
Questions 58

What is the disadvantage of setting up a site-to-site VPN in a clustered-units environment?

Options:

A.  

VPN connections can be re-established only if the failed master unit recovers.

B.  

Smart License is required to maintain VPN connections simultaneously across all cluster units.

C.  

VPN connections must be re-established when a new master unit is elected.

D.  

Only established VPN connections are maintained when a new master unit is elected.

Discussion 0
Questions 59

An administrator is attempting to add a new FTD device to their FMC behind a NAT device with a NAT ID of NAT001 and a password of Cisco0420l06525. The private IP address of the FMC server is 192.168.45.45. which is being translated to the public IP address of 209.165.200.225/27. Which command set must be used in order to accomplish this task?

Options:

A.  

configure manager add 209.165.200.225 < reg_key > < nat_id >

B.  

configure manager add 192.168.45,45 < reg_key > < nat_id >

C.  

configure manager add 209.165.200.225 255.255.255.224 < reg_key > < nat_id >

D.  

configure manager add 209.165.200.225/27 < reg_key > < nat_id >

Discussion 0
Questions 60

Refer to the exhibit. Users attempt to connect to numerous external resources on various TCP ports. If the users mistype the port, their connection closes immediately, and it takes more than one minute before the connection is torn down. An engineer manages to capture both types of connections as shown in the exhibit. What must the engineer configure to lower the timeout values for the second group of connections and resolve the user issues?

Options:

A.  

Outbound access rule with the Block with reset action

B.  

Outbound access rule that allows the entire ICMP protocol suite

C.  

Inbound access rule that allows TCP reset packets from outside

Discussion 0
Questions 61

A security engineer is configuring an Access Control Policy for multiple branch locations. These locations share a common rule set and utilize a network object called INSIDE_NET which contains the locally significant internal network subnets at each location. Which technique will retain the policy consistency at each location but allow only the locally significant network subnet within the applicable rules?

Options:

A.  

utilizing a dynamic Access Control Policy that updates from Cisco Talos

B.  

utilizing policy inheritance

C.  

creating a unique Access Control Policy per device

D.  

creating an Access Control Policy with an INSIDE_NET network object and object overrides

Discussion 0
Questions 62

Which component is needed to perform rapid threat containment with Cisco FMC?

Options:

A.  

ISE

B.  

RESTful API

C.  

SIEM

D.  

DDI

Discussion 0
Questions 63

Refer to the exhibit.

An engineer must create a QoS policy in Cisco Secure Firewall Management Center to limit HTTP and HTTPS traffic originating from users in the HR department. The download and upload limits for HTTP and HTTPS traffic must both be set to 5 Mb/s. Drag and drop the values onto the corresponding QoS rule settings.

Options:

Discussion 0
Questions 64

An engineer is configuring two new Cisco Secure Firewall Threat Defense devices to replace the existing firewalls. Network traffic must be analyzed for intrusion events without impacting the traffic. What must the engineer implement next to accomplish the goal?

Options:

A.  

Passive mode

B.  

Inline Pair in Tap mode

C.  

ERSPAN Passive mode

D.  

Inline Pair mode

Discussion 0
Questions 65

An engineer is configuring a cisco FTD appliance in IPS-only mode and needs to utilize fail-to-wire interfaces. Which interface mode should be used to meet these requirements?

Options:

A.  

transparent

B.  

routed

C.  

passive

D.  

inline set

Discussion 0
Questions 66

A network administrator cannot select the link to be used for failover when configuring an active/passive HA Cisco FTD pair.

Which configuration must be changed before setting up the high availability pair?

Options:

A.  

An IP address in the same subnet must be added to each Cisco FTD on the interface.

B.  

The interface name must be removed from the interface on each Cisco FTD.

C.  

The name Failover must be configured manually on the interface on each cisco FTD.

D.  

The interface must be configured as part of a LACP Active/Active EtherChannel.

Discussion 0
Questions 67

An administrator configures a Cisco Secure Firewall Threat Defense device in transparent mode. To configure the BVI (Bridge Virtual Interface), the administrator must:

Add a bridge-group interface

Configure a bridge-group ID

Configure the bridge-group interface description

Add bridge-group member interfaces

How must the engineer perform these actions?

Options:

A.  

Configure a name for the bridge-group interface

B.  

Set a security zone for the bridge-group interface

C.  

Set the bridge-group interface mode to transparent

D.  

Configure an IP address for the bridge-group interface

Discussion 0
Questions 68

An engineer must deploy URL filtering in Cisco Secure Firewall Management Center Version 7.0. The engineer is configuring a URL condition for an access control rule to filter websites that display bad behavior or are malicious or undesirable. Which reputation level must be configured?

Options:

A.  

Questionable

B.  

Untrusted

C.  

Favorable

D.  

Neutral

Discussion 0
Questions 69

In which two ways do access control policies operate on a Cisco Firepower system? (Choose two.)

Options:

A.  

Traffic inspection can be interrupted temporarily when configuration changes are deployed.

B.  

The system performs intrusion inspection followed by file inspection.

C.  

They can block traffic based on Security Intelligence data.

D.  

File policies use an associated variable set to perform intrusion prevention.

E.  

The system performs a preliminary inspection on trusted traffic to validate that it matches the trusted parameters.

Discussion 0
Questions 70

A company is deploying intrusion protection on multiple Cisco FTD appliances managed by Cisco FMC. Which system-provided policy must be selected if speed and detection are priorities?

Options:

A.  

Connectivity Over Security

B.  

Security Over Connectivity

C.  

Maximum Detection

D.  

Balanced Security and Connectivity

Discussion 0
Questions 71

A network engineer is extending a user segment through an FTD device for traffic inspection without creating another IP subnet How is this accomplished on an FTD device in routed mode?

Options:

A.  

by leveraging the ARP to direct traffic through the firewall

B.  

by assigning an inline set interface

C.  

by using a BVI and create a BVI IP address in the same subnet as the user segment

D.  

by bypassing protocol inspection by leveraging pre-filter rules

Discussion 0
Questions 72

Refer to the exhibit.

A client with IP address 10.254.51.117 connects through a Cisco Secure Firewall Threat Defense device toward a website at 10.10.1.1. The packet capture shows repeated TCP SYN packets from the client without completion of the three-way handshake. Which action must the engineer take to resolve the issue?

Options:

A.  

Configure the inside interface to send ACK messages.

B.  

Add a firewall rule that allows the web server to communicate with the DMZ.

C.  

Add a firewall rule that allows ACK responses from the inside to the outside.

D.  

Configure the outside interface to receive SYN-ACK messages.

Discussion 0
Questions 73

A Cisco FTD device is running in transparent firewall mode with a VTEP bridge group member ingress interface. What must be considered by an engineer tasked with specifying a destination MAC address for a packet trace?

Options:

A.  

Only the UDP packet type is supported.

B.  

The output format option for the packet logs is unavailable.

C.  

The destination MAC address is optional if a VLAN ID value is entered.

D.  

The VLAN ID and destination MAC address are optional.

Discussion 0
Questions 74

A network administrator must create an EtherChannel Interface on a new Cisco Firepower 9300 appliance registered with an FMC tor high availability. Where must the administrator create the EtherChannel interface?

Options:

A.  

FMC CLI

B.  

FTD CLI

C.  

FXOS CLI

D.  

FMC GUI

Discussion 0
Questions 75

Which connector is used to integrate Cisco ISE with Cisco FMC for Rapid Threat Containment?

Options:

A.  

pxGrid

B.  

FTD RTC

C.  

FMC RTC

D.  

ISEGrid

Discussion 0
Questions 76

Network traffic coining from an organization ' s CEO must never be denied. Which access control policy configuration option should be used if the deployment engineer is not permitted to create a rule to allow all traffic?

Options:

A.  

Configure firewall bypass.

B.  

Change the intrusion policy from security to balance.

C.  

Configure a trust policy for the CEO.

D.  

Create a NAT policy just for the CEO.

Discussion 0
Questions 77

An organization wants to secure traffic from their branch office to the headquarter building using Cisco Firepower devices, They want to ensure that their Cisco Firepower devices are not wasting resources on inspecting the VPN traffic. What must be done to meet these requirements?

Options:

A.  

Configure the Cisco Firepower devices to ignore the VPN traffic using prefilter policies

B.  

Enable a flexconfig policy to re-classify VPN traffic so that it no longer appears as interesting traffic

C.  

Configure the Cisco Firepower devices to bypass the access control policies for VPN traffic.

D.  

Tune the intrusion policies in order to allow the VPN traffic through without inspection

Discussion 0
Questions 78

Refer to the exhibit.

A company is deploying a pair of Cisco Secure Firewall Threat defence devices named FTD1 and FTD2. FTD1 and FTD2 have been configured as an active/standby pair with a failover link but without a stateful link. What must be implemented next to ensure that users on the internal network still communicate with outside devices if FTD1 fails?

Options:

A.  

Disable port security on the switch interfaces connected to FTD1 and FTD2.

B.  

Set maximum secured addresses to two on the switch interfaces on FTD1 and FTD2.

C.  

Connect and configure a stateful link and thon deploy the changes.

D.  

Configure the spanning-tree PortFasI feature on SW1 and FTD2

Discussion 0
Questions 79

Which type of certificate must be exported from Cisco ISE to integrate Cisco Secure Firewall Management Center with pxGrid?

Options:

A.  

A self-signed SAML certificate from the domain controller

B.  

The certificate authority certificate of the pxGrid server node

C.  

A self-signed certificate authority certificate signed by a third party

D.  

The public-key certificate of the domain

Discussion 0
Questions 80

An engineermustconfigure a Cisco FMC dashboard in a multidomain deployment Which action must the engineer take to edit a report template from an ancestor domain?

Options:

A.  

Add it as a separate widget.

B.  

Copy it to the current domain

C.  

Assign themselves ownership of it

D.  

Change the document attributes.

Discussion 0
Questions 81

Which Cisco Firepower feature is used to reduce the number of events received in a period of time?

Options:

A.  

rate-limiting

B.  

suspending

C.  

correlation

D.  

thresholding

Discussion 0
Questions 82

Refer to the exhibit.

An engineer must configure a static route on the Cisco Catalyst switch to reach 192.168.10.0/24 through the 192.168.20.1 next hop. The route must use an administrative distance of 2. Which command meets the requirements?

Options:

A.  

ip route 192.168.10.0 255.255.255.0 192.168.20.1 1

B.  

ip route 192.168.20.0 255.255.255.0 192.168.10.1 1

C.  

ip route 192.168.10.0 255.255.255.0 192.168.20.1 2

D.  

ip route 192.168.20.0 255.255.255.0 192.168.10.1 2

Discussion 0
Questions 83

A network administrator is configuring Snort inspection policies and is seeing failed deployment messages in Cisco FMC. What information should the administrator generate for Cisco TAC to help troubleshoot?

Options:

A.  

A " show tech " file for the device in question.

B.  

A " troubleshoot " file for the device in question.

C.  

A " troubleshoot " file for the Cisco FM

C.  

D.  

A " show tech " for the Cisco FMC.

Discussion 0
Questions 84

An administrator is adding a new URL-based category feed to the Cisco FMC for use within the policies. The intelligence source does not use STIX. but instead uses a .txt file format. Which action ensures that regular updates are provided?

Options:

A.  

Add a URL source and select the flat file type within Cisco FMC.

B.  

Upload the .txt file and configure automatic updates using the embedded URL.

C.  

Add a TAXII feed source and input the URL for the feed.

D.  

Convert the .txt file to STIX and upload it to the Cisco FMC.

Discussion 0
Questions 85

A security engineer is configuring a remote Cisco FTD that has limited resources and internet bandwidth. Which malware action and protection option should be configured to reduce the requirement for cloud lookups?

Options:

A.  

Malware Cloud Lookup and dynamic analysis

B.  

Block Malware action and dynamic analysis

C.  

Block Malware action and local malware analysis

D.  

Block File action and local malware analysis

Discussion 0
Questions 86

Which command should be used on the Cisco FTD CLI to capture all the packets that hit an interface?

Options:

A.  

configure coredump packet-engine enable

B.  

capture-traffic

C.  

capture

D.  

capture WORD

Discussion 0
Questions 87

The event dashboard within the Cisco FMC has been inundated with low priority intrusion drop events, which are overshadowing high priority events. An engineer has been tasked with reviewing the policies and reducing the low priority events. Which action should be configured to accomplish this task?

Options:

A.  

generate events

B.  

drop packet

C.  

drop connection

D.  

drop and generate

Discussion 0
Questions 88

An engineer configures a network discovery policy on Cisco FMC. Upon configuration, it is noticed that excessive and misleading events filing the database and overloading the Cisco FMC. A monitored NAT device is executing multiple updates of its operating system in a short period of time. What configurationchange must be made to alleviate this issue?

Options:

A.  

Leave default networks.

B.  

Change the method to TCP/SYN.

C.  

Increase the number of entries on the NAT device.

D.  

Exclude load balancers and NAT devices.

Discussion 0
Questions 89

An engineer is restoring a Cisco FTD configuration from a remote backup using the command restore remote-manager-backup location 1.1.1.1 admin /volume/home/admin BACKUP_Cisc394602314.zip on a Cisco FMG. After connecting to the repository, an error occurred that prevents the FTD device from accepting the backup file. What is the problem?

Options:

A.  

The backup file is not in .cfg format.

B.  

The backup file is too large for the Cisco FTD device

C.  

The backup file extension was changed from tar to zip

D.  

The backup file was not enabled prior to being applied

Discussion 0
Questions 90

An engineer must integrate a third-party security intelligence feed with Cisco Secure Firewall Management Center. Secure Firewall Management Center is running Version 6.2.3 and has 8

GB of memory. Which two actions must be taken to implement Threat Intelligence Director? (Choose two.)

Options:

A.  

Enable REST API access.

B.  

Add a TAXII server.

C.  

Add the URL of the TAXII server.

D.  

Upgrade to version 6.6.

E.  

Add 7 GB of memory.

Discussion 0
Questions 91

A security engineer must add a new policy to block UDP traffic to one server. The engineer adds a new object. Which action must the engineer take next to identify all the UDP ports?

Options:

A.  

Define the transport protocol and the mandatory port range.

B.  

Add the transport number and specify the type and code.

C.  

Add the corresponding IP protocol number for UDP and TCP.

D.  

Specify the transport protocol and leave the port number empty.

Discussion 0
Questions 92

What is the RTC workflow when the infected endpoint is identified?

Options:

A.  

Cisco ISE instructs Cisco AMP to contain the infected endpoint.

B.  

Cisco ISE instructs Cisco FMC to contain the infected endpoint.

C.  

Cisco AMP instructs Cisco FMC to contain the infected endpoint.

D.  

Cisco FMC instructs Cisco ISE to contain the infected endpoint.

Discussion 0
Questions 93

An organization has a Cisco FTD that uses bridge groups to pass traffic from the inside interfaces to the outside interfaces. They are unable to gather information about neighbouring Cisco devices or use multicast in their environment. What must be done to resolve this issue?

Options:

A.  

Create a firewall rule to allow CDP traffic.

B.  

Create a bridge group with the firewall interfaces.

C.  

Change the firewall mode to transparent.

D.  

Change the firewall mode to routed.

Discussion 0
Questions 94

Refer to the exhibit.

A systems administrator conducts a connectivity test to their SCCM server from a host machine and gets no response from the server. Which action ensures that the ping packets reach the destination and that the host receives replies?

Options:

A.  

Create an access control policy rule that allows ICMP traffic.

B.  

Configure a custom Snort signature to allow ICMP traffic after Inspection.

C.  

Modify the Snort rules to allow ICMP traffic.

D.  

Create an ICMP allow list and add the ICMP destination to remove it from the implicit deny list.

Discussion 0
Questions 95

Refer to the exhibit. An engineer is deploying a new instance of Cisco Secure Firewall Threat Defense. Which action must the engineer take next so that Client_A and Client_B receive an IP address via DHCP from Server_A?

Options:

A.  

Disable Option 82 in the DHCP relay configuration properties using Secure Firewall Management Center.

B.  

Add access rules that allow DHCP traffic by using Cisco Secure Firewall Management Center.

C.  

Add another DHCP pool on Server_A with DHCP relay on Secure Firewall Threat Defense.

D.  

Disable all the DHCP Snort rules by using Secure Firewall Device Manager.

Discussion 0
Questions 96

A network engineer is logged into the Cisco AMP for Endpoints console and sees a malicious verdict for an identified SHA-256 hash. Which configuration is needed to mitigate this threat?

Options:

A.  

Use regular expressions to block the malicious file.

B.  

Add the hash from the infected endpoint to the network block list.

C.  

Add the hash to the simple custom detection list.

D.  

Enable a personal firewall in the infected endpoint.

Discussion 0
Questions 97

A network engineer is tasked with minimising traffic interruption during peak traffic limes. When the SNORT inspection engine is overwhelmed, what must be configured to alleviate this issue?

Options:

A.  

Enable IPS inline link state propagation

B.  

Enable Pre-filter policies before the SNORT engine failure.

C.  

Set a Trust ALL access control policy.

D.  

Enable Automatic Application Bypass.

Discussion 0
Questions 98

A network engineer is configuring URL Filtering on Firepower Threat Defense. Which two port requirements on the Firepower Management Center must be validated to allow communication with the cloud service? (Choose two.)

Options:

A.  

outbound port TCP/443

B.  

inbound port TCP/80

C.  

outbound port TCP/8080

D.  

inbound port TCP/443

E.  

outbound port TCP/80

Discussion 0
Questions 99

When deploying a Cisco ASA Firepower module, an organization wants to evaluate the contents of the traffic without affecting the network. It is currently configured to have more than one instance of the same device on the physical appliance Which deployment mode meets the needs of the organization?

Options:

A.  

inline tap monitor-only mode

B.  

passive monitor-only mode

C.  

passive tap monitor-only mode

D.  

inline mode

Discussion 0
Questions 100

A network administrator is trying to configure a previously created file policy on a new access policy. Which action must the administrator take before applying the file policy?

Options:

A.  

Set up an inspection policy.

B.  

Create a new access control rule.

C.  

Assign the file policy to the default action.

D.  

Apply an application to an access control rule.

Discussion 0
Questions 101

An engineer is configuring Cisco Secure Firewall Threat Defense managed by a Secure Firewall Management Center appliance. The company wants remote access VPN users to be reachable from the inside network. What must the engineer configure to meet the requirements?

Options:

A.  

manual NAT exemption rule at the top of the NAT policy

B.  

manual NAT exemption rule at the bottom of the NAT policy

C.  

auto NAT exemption rule at the top of the NAT policy

D.  

auto NAT exemption rule at the bottom of the NAT policy

Discussion 0
Questions 102

While configuring FTD, a network engineer wants to ensure that traffic passing through the appliance does not require routing or Vlan rewriting. Which interface mode should the engineer implement to accomplish this task?

Options:

A.  

passive

B.  

transparent

C.  

Inline tap

D.  

Inline set

Discussion 0
Questions 103

A network administrator is configuring an instance of Cisco Secure Firewall Threat Defense, which is registered to Cisco Secure Firewall Management Center, to prevent internal users from downloading executable files from the internet. What must be created and configured by the administrator to meet the requirement?

Options:

A.  

Access policy rule that allows users to reach the internet and assigns a file policy that blocks executable downloads to the rule.

B.  

File policy that blocks downloads of all executable files and applies the file policy to the default action in the access policy.

C.  

File policy rule that allows users to reach the internet with a second rule applied that blocks application use of FTP.

D.  

Access policy rule that allows users to reach the internet with a second rule that blocks application executables.

Discussion 0
Questions 104

An organization is implementing Cisco FTD using transparent mode in the network. Which rule in the default Access Control Policy ensures that this deployment does not create a loop in the network?

Options:

A.  

ARP inspection is enabled by default.

B.  

Multicast and broadcast packets are denied by default.

C.  

STP BPDU packets are allowed by default.

D.  

ARP packets are allowed by default.

Discussion 0
Questions 105

An engineer is configuring a custom application detector for HTTP traffic and wants to import a file that was provided by a third party. Which type of flies are advanced application detectors creates and uploaded as?

Options:

A.  

Perl script

B.  

NBAR protocol

C.  

LUA script

D.  

Python program

Discussion 0
Questions 106

What are two application layer preprocessors? (Choose two.)

Options:

A.  

CIFS

B.  

IMAP

C.  

SSL

D.  

DNP3

E.  

ICMP

Discussion 0
Questions 107

An administrator must use Cisco FMC to install a backup route within the Cisco FTD to route traffic in case of a routing failure with the primary route. Which action accomplishes this task?

Options:

A.  

Install the static backup route and modify the metric to be less than the primary route.

B.  

Configure EIGRP routing on the FMC to ensure that dynamic routes are always updated.

C.  

Use a default route on the FMC instead of having multiple routes contending for priority.

D.  

Create the backup route and use route tracking on both routes to a destination IP address in the network.

Discussion 0
Questions 108

The administrator notices that there is malware present with an .exe extension and needs to verify if any of the systems on the network are running the executable file. What must be configured within Cisco AMP for Endpoints to show this data?

Options:

A.  

prevalence

B.  

threat root cause

C.  

vulnerable software

D.  

file analysis

Discussion 0
Questions 109

An engineer is configuring a new dashboard within Cisco Secure Firewall Management Center and is having trouble implementing a custom widget. When a custom analysis widget is configured which option is mandatory for the system to display the information?

Options:

A.  

table

B.  

filter

C.  

title

D.  

results

Discussion 0
Questions 110

Which limitation applies to Cisco Firepower Management Center dashboards in a multidomain environment?

Options:

A.  

Child domains can view but not edit dashboards that originate from an ancestor domain.

B.  

Child domains have access to only a limited set of widgets from ancestor domains.

C.  

Only the administrator of the top ancestor domain can view dashboards.

D.  

Child domains cannot view dashboards that originate from an ancestor domain.

Discussion 0
Questions 111

An engineer is troubleshooting a file that is being blocked by a Cisco FTD device on the network.

The user is reporting that the file is not malicious.

Which action does the engineer take to identify the file and validate whether or not it is malicious?

Options:

A.  

identify the file in the intrusion events and submit it to Threat Grid for analysis.

B.  

Use FMC file analysis to look for the file and select Analyze to determine its disposition.

C.  

Use the context explorer to find the file and download it to the local machine for investigation.

D.  

Right click the connection event and send the file to AMP for Endpoints to see if the hash is malicious.

Discussion 0
Questions 112

Which two remediation options are available when Cisco FMC is integrated with Cisco ISE? (Choose two.)

Options:

A.  

dynamic null route configured

B.  

DHCP pool disablement

C.  

quarantine

D.  

port shutdown

E.  

host shutdown

Discussion 0
Questions 113

A VPN administrator converted an instance of Cisco Secure Firewall Threat Defense, which is managed by Cisco Secure Firewall Management Center, from using LDAP to LDAPS for

remote access VPN authentication. Which certificate must be added to allow for remote users to authenticate over the VPN?

Options:

A.  

LDAPS server certificate must be added to Secure Firewall Management Center realms.

B.  

Secure Firewall Management Center certificate must be added to the LDAPS server.

C.  

LDAPS server certificate must be added to Secure Firewall Threat Defense.

D.  

Secure Firewall Threat Defense certificate must be added to the LDAPS server.

Discussion 0
Questions 114

A network administrator is trying to configure Active Directory authentication for VPN authentication to a Cisco Secure Firewall Threat Defence instance that is registered with Cisco Secure Firewall Management Center. Which system settings must be configured first in Secure Firewall Management Center to accomplish the goal?

Options:

A.  

Device, Remote Access VPN

B.  

System, Realms

C.  

Policies, Authentication

D.  

Authentication, Device

Discussion 0
Questions 115

An administrator is working on a migration from Cisco ASA to the Cisco FTD appliance and needs to test the rules without disrupting the traffic. Which policy type should be used to configure the ASA rules during this phase of the migration?

Options:

A.  

identity

B.  

Intrusion

C.  

Access Control

D.  

Prefilter

Discussion 0
Questions 116

Which two routing options are valid with Cisco FTD? (Choose Two)

Options:

A.  

BGPv6

B.  

ECMP with up to three equal cost paths across multiple interfaces

C.  

ECMP with up to three equal cost paths across a single interface

D.  

BGPv4 in transparent firewall mode

E.  

BGPv4 with nonstop forwarding

Discussion 0
Questions 117

Which CLI command is used to control special handling of clientHello messages?

Options:

A.  

system support ssl-client-hello-tuning

B.  

system support ssl-client-hello-display

C.  

system support ssl-client-hello-force-reset

D.  

system support ssl-client-hello-reset

Discussion 0
Questions 118

What must be implemented on Cisco Firepower to allow multiple logical devices on a single physical device to have access to external hosts?

Options:

A.  

Add at least two container instances from the same module.

B.  

Set up a cluster control link between all logical devices

C.  

Add one shared management interface on all logical devices.

D.  

Define VLAN subinterfaces for each logical device.

Discussion 0
Questions 119

An engineer is configuring URL filtering tor a Cisco Secure Firewall Threat Defense device in Cisco Secure Firewall Management Centre. Use ' s must receive a warning when they access

..wwww badaduitsito com with the option of continuing to the website if they choose to No other websites should he blocked. Which two actions must the engineer take to moot these requirements?

Options:

A.  

Configure an access control rule that matches an URL object for http://www.Dadadullsile.com ' and set the action to Interactive Block.

B.  

On the HTTP Responses tab of the access control policy editor, set the Interactive Block Response Page to System-provided.

C.  

Configure the default action for the access control policy to Interactive Block.

D.  

On the HTTP Responses tab of the access control policy editor set the Block Response Page to Custom.

E.  

Configure an access control rule that matches the Adult URL category and sot the action to Interactive Block

Discussion 0
Questions 120

A security engineer must create a malware and file policy on a Cisco Secure Firewall Threat Defense device. The solution must ensure that PDF. DOCX, and XLSX files are not sent lo Cisco Secure Malware analytics. What must do configured to meet the requirements ' '

Options:

A.  

capacity handling

B.  

Spero analysis

C.  

dynamic analysis

D.  

local malware analysis

Discussion 0
Questions 121

A network engineer detects a connectivity issue between Cisco Secure Firewall Management Centre and Cisco Secure Firewall Threat Defense Initial troubleshooting indicates that heartbeats and events not being received. The engineer re-establishes the secure channels between both peers Which two commands must the engineer run to resolve the issue? (Choose two.)

Options:

A.  

manage_procs.pl

B.  

sudo stats_unified.pl

C.  

sudo perfstats -Cq < /var/sf/rna/correlator-stats/now

D.  

show history

E.  

show disk-manager

Discussion 0
Questions 122

An engineer has been tasked with providing disaster recovery for an organization ' s primary Cisco FMC. What must be done on the primary and secondary Cisco FMCs to ensure that a copy of the original corporate policy is available if the primary Cisco FMC fails?

Options:

A.  

Configure high-availability in both the primary and secondary Cisco FMCs

B.  

Connect the primary and secondary Cisco FMC devices with Category 6 cables of not more than 10 meters in length.

C.  

Place the active Cisco FMC device on the same trusted management network as the standby device

D.  

Restore the primary Cisco FMC backup configuration to the secondary Cisco FMC device when the primary device fails

Discussion 0
Questions 123

An administrator needs to configure Cisco FMC to send a notification email when a data transfer larger than 10 MB is initiated from an internal host outside of standard business hours. Which Cisco FMC feature must be configured to accomplish this task?

Options:

A.  

file and malware policy

B.  

application detector

C.  

intrusion policy

D.  

correlation policy

Discussion 0
Questions 124

An engineer wants to connect a single IP subnet through a Cisco FTD firewall and enforce policy. There is a requirement to present the internal IP subnet to the outside as a different IP address. What must be configured to meet these requirements?

Options:

A.  

Configure the downstream router to perform NAT.

B.  

Configure the upstream router to perform NAT.

C.  

Configure the Cisco FTD firewall in routed mode with NAT enabled.

D.  

Configure the Cisco FTD firewall in transparent mode with NAT enabled.

Discussion 0
Questions 125

An engineer must change the mode of a Cisco Secure Firewall Threat Defense (FTD) firewall in the Cisco Secure Firewall Management Center (FMC) inventory. The engineer must take these actions:

• Register Secure FTD with Secure FMC.

• Change the firewall mode.

• Deregister the Secure FTD device from Secure FMC.

How must the engineer take FTD take the actions?

Options:

A.  

Reload the Secure FTD device.

B.  

Configure the management IP address.

C.  

Access the Secure FTD CLI from the console port.

D.  

Erase the Secure FTD configuration

Discussion 0
Questions 126

An organization is migrating their Cisco ASA devices running in multicontext mode to Cisco FTD devices. Which action must be taken to ensure that each context on the Cisco ASA is logically separated in the Cisco FTD devices?

Options:

A.  

Add a native instance to distribute traffic to each Cisco FTD context.

B.  

Add the Cisco FTD device to the Cisco ASA port channels.

C.  

Configure a container instance in the Cisco FTD for each context in the Cisco ASA.

D.  

Configure the Cisco FTD to use port channels spanning multiple networks.

Discussion 0