Latest 300-710 Actual Free Exam Updated 279 Questions [Q24-Q41]

Share

Latest 300-710 Actual Free Exam Updated 279 Questions

Online Questions - Valid Practice 300-710 Exam Dumps Test Questions

NEW QUESTION # 24
Which CLI command is used to control special handling of ClientHello messages?

  • A. system support ssl-client-hello-enabled
  • B. system support ssl-client-hello-display
  • C. system support ssl-client-hello-force-reset
  • D. system support ssl-client-hello-tuning

Answer: A

Explanation:
Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/610/configuration/guide/fpmc-config-guide-v61/firepower_command_line_reference.html


NEW QUESTION # 25
Which command is run at the CLI when logged in to an FTD unit, to determine whether the unit is managed locally or by a remote FMC server?

  • A. show running-config | include manager
  • B. system generate-troubleshoot
  • C. show managers
  • D. show configuration session

Answer: C


NEW QUESTION # 26
An administrator needs to configure Cisco FMC to send a notification email when a data transfer larger than
10 MB is initiated from an internal host outside of standard business hours. Which Cisco FMC feature must be configured to accomplish this task?

  • A. intrusion policy
  • B. file and malware policy
  • C. correlation policy
  • D. application detector

Answer: B


NEW QUESTION # 27
An engineer currently has a Cisco FTD device registered to the Cisco FMC and is assigned the address of 10
10.50.12. The organization is upgrading the addressing schemes and there is a requirement to convert the addresses to a format that provides an adequate amount of addresses on the network What should the engineer do to ensure that the new addressing takes effect and can be used for the Cisco FTD to Cisco FMC connection?

  • A. Delete and reregister the device to Cisco FMC
  • B. Update the IP addresses from IFV4 to IPv6 without deleting the device from Cisco FMC
  • C. Format and reregister the device to Cisco FMC.
  • D. Cisco FMC does not support devices that use IPv4 IP addresses.

Answer: B


NEW QUESTION # 28
An engineer is configuring a second Cisco FMC as a standby device but is unable to register with the active unit. What is causing this issue?

  • A. The licensing purchased does not include high availability.
  • B. The primary FMC currently has devices connected to it.
  • C. The code versions running on the Cisco FMC devices are different.
  • D. There is only 10 Mbps of bandwidth between the two devices.

Answer: C

Explanation:
Section: Deployment


NEW QUESTION # 29
Which two types of objects are reusable and supported by Cisco FMC? (Choose two.)

  • A. reputation-based objects that represent Security Intelligence feeds and lists, application filters based on category and reputation, and file lists
  • B. dynamic key mapping objects that help link HTTP and HTTPS GET requests to Layer 7 application protocols.
  • C. network-based objects that represent IP address and networks, port/protocols pairs, VLAN tags, security zones, and origin/destination country
  • D. network-based objects that represent FQDN mappings and networks, port/protocol pairs, VXLAN tags, security zones and origin/destination country
  • E. reputation-based objects, such as URL categories

Answer: A,C

Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config- guide-v62/reusable_objects.html#ID-2243-00000414


NEW QUESTION # 30
An organization is configuring a new Cisco Firepower High Availability deployment. Which action must be taken to ensure that failover is as seamless as possible to end users?

  • A. Set up a virtual failover MAC address between chassis.
  • B. Load the same software version on both chassis.
  • C. Set the same FQDN for both chassis.
  • D. Use a dedicated stateful link between chassis.

Answer: D


NEW QUESTION # 31
A network security engineer must export packet captures from the Cisco FMC web browser while troubleshooting an issue. When navigating to the address https://<FMC IP>/capture/CAPI/pcap/test.pcap. an error 403: Forbidden is given instead of the PCAP file. Which action must the engineer take to resolve this issue?

  • A. Disable the HTTPS server and use HTTP instead.
  • B. Use the Cisco FTD IP address as the proxy server setting on the browser.
  • C. Enable the HTTPS server for the device platform policy.
  • D. Disable the proxy setting on the browser.

Answer: C


NEW QUESTION # 32
An engineer runs the command restore remote-manager-backup location 2.2.2.2 admin /Volume/home/admin FTD408566513.zip on a Cisco FMC. After connecting to the repository, the Cisco FTD device is unable to accept the backup file. What is the reason for this failure?

  • A. The backup file extension was changed from .tar to .zip.
  • B. The backup file is not in .cfg format.
  • C. The directory location is incorrect.
  • D. The wrong IP address is used.

Answer: A


NEW QUESTION # 33
An administrator is adding a new URL-based category feed to the Cisco FMC for use within the policies. The intelligence source does not use STIX. but instead uses a .txt file format. Which action ensures that regular updates are provided?

  • A. Convert the .txt file to STIX and upload it to the Cisco FMC.
  • B. Add a TAXII feed source and input the URL for the feed.
  • C. Upload the .txt file and configure automatic updates using the embedded URL.
  • D. Add a URL source and select the flat file type within Cisco FMC.

Answer: D


NEW QUESTION # 34
A network administrator notices that SI events are not being updated The Cisco FTD device is unable to load all of the SI event entries and traffic is not being blocked as expected. What must be done to correct this issue?

  • A. Replace the affected devices with devices that provide more memory
  • B. Manually update the SI event entries to that the appropriate traffic is blocked
  • C. Redeploy configurations to affected devices so that additional memory is allocated to the SI module
  • D. Restart the affected devices in order to reset the configurations

Answer: C


NEW QUESTION # 35
Which CLI command is used to control special handling of ClientHello messages?

  • A. system support ssl-client-hello-reset
  • B. system support ssl-client-hello-tuning
  • C. system support ssl-client-hello-display
  • D. system support ssl-client-hello-force-reset

Answer: B

Explanation:
Section: Management and Troubleshooting
Explanation/Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/610/configuration/guide/fpmc-config- guide-v61/firepower_command_line_reference.html


NEW QUESTION # 36
A network administrator cannot select the link to be used for failover when configuring an active/passive HA Cisco FTD pair.
Which configuration must be changed before setting up the high availability pair?

  • A. The interface name must be removed from the interface on each Cisco FTD.
  • B. The interface must be configured as part of a LACP Active/Active EtherChannel.
  • C. An IP address in the same subnet must be added to each Cisco FTD on the interface.
  • D. The name Failover must be configured manually on the interface on each cisco FTD.

Answer: C


NEW QUESTION # 37
A security engineer is configuring a remote Cisco FTD that has limited resources and internet bandwidth. Which malware action and protection option should be configured to reduce the requirement for cloud lookups?

  • A. Block File action and local malware analysis
  • B. Block Malware action and dynamic analysis
  • C. Malware Cloud Lookup and dynamic analysis
  • D. Block Malware action and local malware analysis

Answer: C


NEW QUESTION # 38
An engineer is configuring a cisco FTD appliance in IPS-only mode and needs to utilize fail-to-wire interfaces. Which interface mode should be used to meet these requirements?

  • A. inline set
  • B. routed
  • C. passive
  • D. transparent

Answer: A


NEW QUESTION # 39
An engineer is troubleshooting a device that cannot connect to a web server. The connection is initiated from the Cisco FTD inside interface and attempting to reach 10.0.1.100 over the non-standard port of 9443 The host the engineer is attempting the connection from is at the IP address of 10.20.10.20. In order to determine what is happening to the packets on the network, the engineer decides to use the FTD packet capture tool Which capture configuration should be used to gather the information needed to troubleshoot this issue?
A)

B)

C)

D)

  • A. Option D
  • B. Option B
  • C. Option C
  • D. Option A

Answer: B


NEW QUESTION # 40
Which command is run at the CLI when logged in to an FTD unit, to determine whether the unit is managed locally or by a remote FMC server?

  • A. show running-config | include manager
  • B. system generate-troubleshoot
  • C. show managers
  • D. show configuration session

Answer: C

Explanation:
Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/command_ref/b_Command_Reference_for_Firepower_Threat_Defense/c_3.html


NEW QUESTION # 41
......

300-710 Exam PDF [2023] Tests Free Updated Today with Correct 279 Questions: https://www.vceprep.com/300-710-latest-vce-prep.html

100% Real 300-710 dumps  - Brilliant 300-710 Exam Questions PDF: https://drive.google.com/open?id=11TSWnxIzzDd-Txd9jaYA94fmlC4bFlNN