Pre-Winter Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Free 300-710 Questions Attempt

Page: 17 / 33
Total 444 questions

Securing Networks with Cisco Firepower (300-710 SNCF) v1.2 Questions and Answers

Question 65

Refer to the exhibit.

A client with IP address 10.254.51.117 connects through a Cisco Secure Firewall Threat Defense device toward a website at 10.10.1.1. The packet capture shows repeated TCP SYN packets from the client without completion of the three-way handshake. Which action must the engineer take to resolve the issue?

Options:

A.

Configure the inside interface to send ACK messages.

B.

Add a firewall rule that allows the web server to communicate with the DMZ.

C.

Add a firewall rule that allows ACK responses from the inside to the outside.

D.

Configure the outside interface to receive SYN-ACK messages.

Question 66

Which two actions can be used in an access control policy rule? (Choose two.)

Options:

A.

Block with Reset

B.

Monitor

C.

Analyze

D.

Discover

E.

Block ALL

Question 67

A security engineer must configure a Cisco Secure Firewall Threat Defense device to inspect only executable files. A lightweight method of detecting whether a file is an executable must be used. Which configuration for Malware Cloud Lookup must be selected in Cisco Secure Firewall Management Center?

Options:

A.

capacity handling

B.

Local Malware Analysis

C.

dynamic analysis

D.

Spero analysis for MSEXE

Question 68

Which command is run at the CLI when logged in to an FTD unit, to determine whether the unit is managed locally or by a remote FMC server?

Options:

A.

system generate-troubleshoot

B.

show configuration session

C.

show managers

D.

show running-config | include manager

Page: 17 / 33
Total 444 questions