Pre-Winter Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

300-710 Leak Questions

Page: 27 / 33
Total 444 questions

Securing Networks with Cisco Firepower (300-710 SNCF) v1.2 Questions and Answers

Question 105

Users report that Cisco Duo 2FA fails when they attempt to connect to the VPN on a Cisco Secure Firewall Threat Defense (FTD) device IT staff have VPN profiles that do not require multifactor authentication and they can connect to the VPN without any issues When viewing the VPN troubleshooting log in Cisco Secure Firewall Management Centre (FMC), the network administrator sees an error in the Cisco Duo AAA server has been marked as tailed. What is the root cause of the Issue?

Options:

A.

Multifactor authentication Is not supported on Secure FMC managed devices.

B.

Duo trust certificates are missing from the Secure FTD device.

C.

The internal AD server is unreachable from the Secure FTD device.

D.

AD Trust certificates are missing from the Secure FTD device.

Question 106

Which CLI command is used to control special handling of clientHello messages?

Options:

A.

system support ssl-client-hello-tuning

B.

system support ssl-client-hello-display

C.

system support ssl-client-hello-force-reset

D.

system support ssl-client-hello-reset

Question 107

An engineer is troubleshooting connectivity to the DNS servers from hosts behind a new Cisco FTD device. The hosts cannot send DNS queries to servers in the DMZ. Which action should the engineer take to troubleshoot this issue using the real DNS packets?

Options:

A.

Use the Connection Events dashboard to check the block reason and adjust the inspection policy as needed.

B.

Use the packet capture tool to check where the traffic is being blocked and adjust the access control or intrusion policy as needed.

C.

Use the packet tracer tool to determine at which hop the packet is being dropped.

D.

Use the show blocks command in the Threat Defense CLI tool and create a policy to allow the blocked traffic.

Question 108

An engineer must determine the root cause of an incident. The engineer plans to run a packet capture on a Cisco Secure Firewall device but remembers that the device experienced performance problems when the packet-capture command was previously executed. Which packet-capture options must the engineer use to minimize the performance impact?

Options:

A.

-c 10000 host 10.10.10.10

B.

-s 1500 -c 1000 host 10.10.10.10

C.

-c 1000 host 10.10.10.10

D.

-w test -s 1518 -c 1000 host 10.10.10.10

Page: 27 / 33
Total 444 questions