Pre-Winter Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Cisco 300-710 Based on Real Exam Environment

Page: 23 / 33
Total 444 questions

Securing Networks with Cisco Firepower (300-710 SNCF) v1.2 Questions and Answers

Question 89

A network administrator cannot select the link to be used for failover when configuring an active/passive HA Cisco FTD pair.

Which configuration must be changed before setting up the high availability pair?

Options:

A.

An IP address in the same subnet must be added to each Cisco FTD on the interface.

B.

The interface name must be removed from the interface on each Cisco FTD.

C.

The name Failover must be configured manually on the interface on each cisco FTD.

D.

The interface must be configured as part of a LACP Active/Active EtherChannel.

Question 90

Refer to the exhibit. Authenticated VPN users at a financial institution can reach trading servers in the 10.200.0.0/16 range, but one user, vpn-useM is not able to access the trading application at 10.200.5.50 on TCP 8443. An engineer enables system support trace on the Cisco Secure Firewall Threat Defense. Which action must be performed to resolve the issue?

Options:

A.

Modify the group policy to assign a higher-privilege VPN filter ACL to all users in vpn-user1 ' s group, overriding the ACL applied by DAP.

B.

Edit the group policy for the VPN tunnel group and permit 10.200.5.50/8443 in the split-tunnel ACL.

C.

Update the DAP RESTRICT_TRADING ACL to permit TCP to 10.200.5.50 on port 8443.

D.

Add a static route for 10.200.5.0/24 pointing to the inside interface, and a static route for the vpn-user1 host 172.16.100.10 to the outside interface.

Question 91

A network administrator is configuring a Cisco AMP public cloud instance and wants to capture infections and polymorphic variants of a threat to help detect families of malware. Which detection engine meets this requirement?

Options:

A.

RBAC

B.

Tetra

C.

Ethos

D.

Spero

Question 92

An administrator must use Cisco FMC to install a backup route within the Cisco FTD to route traffic in case of a routing failure with the primary route. Which action accomplishes this task?

Options:

A.

Install the static backup route and modify the metric to be less than the primary route.

B.

Configure EIGRP routing on the FMC to ensure that dynamic routes are always updated.

C.

Use a default route on the FMC instead of having multiple routes contending for priority.

D.

Create the backup route and use route tracking on both routes to a destination IP address in the network.

Page: 23 / 33
Total 444 questions