Pre-Winter Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

300-710 Premium Exam Questions

Page: 30 / 33
Total 444 questions

Securing Networks with Cisco Firepower (300-710 SNCF) v1.2 Questions and Answers

Question 117

A network administrator is trying to configure a previously created file policy on a new access policy. Which action must the administrator take before applying the file policy?

Options:

A.

Set up an inspection policy.

B.

Create a new access control rule.

C.

Assign the file policy to the default action.

D.

Apply an application to an access control rule.

Question 118

A security engineer must add a new policy to block UDP traffic to one server. The engineer adds a new object. Which action must the engineer take next to identify all the UDP ports?

Options:

A.

Define the transport protocol and the mandatory port range.

B.

Add the transport number and specify the type and code.

C.

Add the corresponding IP protocol number for UDP and TCP.

D.

Specify the transport protocol and leave the port number empty.

Question 119

An engineer is reviewing a ticket that requests to allow traffic for some devices that must connect to a server over 8699/udp. The request mentions only one IP address, 172.16.18.15, but the requestor asked for the engineer to open the port for all machines that have been trying to connect to it over the last week. Which action must the engineer take to troubleshoot this issue?

Options:

A.

Use the context explorer to see the application blocks by protocol.

B.

Use the context explorer to see the destination port blocks

C.

Filter the connection events by the source port 8699/udp.

D.

Filter the connection events by the destination port 8699/udp.

Question 120

A financial services firm is configuring split-tunnel remote access VPN on a Cisco Secure Firewall Threat Defence managed by Cisco Secure Firewall Management Center. Only traffic to 10.0 0.0/8 and 172 16 0 0/12 must traverse the VPN tunnel Internet traffic must exit locally on the client. Internal DNS queries must traverse the VPN tunnel to the corporate DNS server at 10.1.1.53 for the domain corp.finserv.local. Cisco Secure Client is deployed on all endpoints. Which configuration must be done to accomplish the task?

Options:

A.

Implement a split-tunnel exclude list for all public address space, assign 10.1 1 53 as the primary DNS server in the group policy, and enable the Umbrella Roaming Security module to handle DNS queries for non-tunneled traffic.

B.

Configure a split-tunnel include policy scoped to 10.0.0.0/8 and 172.16.0.0/12 in the group policy, and define a split-DNS entry for corp.finserv.local so Secure Client routes matching DNS queries through the tunnel to 10.1.1.53.

C.

Enable full-tunnel mode in the group policy and apply an ACL permitting only RFC-1918 traffic into the tunnel, then assign 10.1.1.53 as the primary DNS server and rely on the Windows DNS suffix search list to handle internal resolution.

D.

Use a network object group containing 10.0.0.0/8 and 172.16.0.0/12 as the split-tunnel include list, assign 8.8.8.8 as the primary DNS server in the group policy, and configure a conditional DNS forwarder on the client for corp finserv.local

Page: 30 / 33
Total 444 questions