[Nov-2023 Newly Released] 300-710 Dumps for CCNP Security Certified [Q74-Q94]

Share

[Nov-2023 Newly Released] 300-710 Dumps for CCNP Security Certified

Updated Verified 300-710 dumps Q&As - 100% Pass

NEW QUESTION # 74
What is a feature of Cisco AMP private cloud?

  • A. It performs dynamic analysis
  • B. It supports security intelligence filtering.
  • C. It disables direct connections to the public cloud.
  • D. It supports anonymized retrieval of threat intelligence

Answer: C


NEW QUESTION # 75
An administrator is attempting to remotely log into a switch in the data centre using SSH and is unable to connect. How does the administrator confirm that traffic is reaching the firewall?

  • A. by performing a packet capture on the firewall.
  • B. by running a packet tracer on the firewall.
  • C. by attempting to access it from a different workstation.
  • D. by running Wireshark on the administrator's PC

Answer: B

Explanation:
Reference:
https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/212474-working-with-firepower-threat-defense-f.html#anc16


NEW QUESTION # 76
Which command should be used on the Cisco FTD CLI to capture all the packets that hit an interface?

  • A. capture-traffic
  • B. capture
  • C. capture WORD
  • D. configure coredump packet-engine enable

Answer: A


NEW QUESTION # 77
A security engineer must integrate an external feed containing STIX/TAXII data with Cisco FMC. Which feature must be enabled on the Cisco FMC to support this connection?

  • A. Threat Intelligence Director
  • B. Cisco Success Network
  • C. Cisco Secure Endpoint Integration
  • D. Security Intelligence Feeds

Answer: A


NEW QUESTION # 78
An analyst using the security analyst account permissions is trying to view the Correlations Events Widget but is not able to access it. However, other dashboards are accessible. Why is this occurring?

  • A. The widget is configured to display only when active events are present.
  • B. An API restriction within the Cisco FMC is preventing the widget from displaying.
  • C. The widget is not configured within the Cisco FMC.
  • D. The security analyst role does not have permission to view this widget.

Answer: C


NEW QUESTION # 79
Which protocol establishes network redundancy in a switched Firepower device deployment?

  • A. STP
  • B. HSRP
  • C. VRRP
  • D. GLBP

Answer: A

Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config- guide-v62/firepower_threat_defense_high_availability.html


NEW QUESTION # 80
An engineer wants to perform a packet capture on the Cisco FTD to confirm that the host using IP address 192
168.100.100 has the MAC address of 0042 7734.103 to help troubleshoot a connectivity issue What is the correct tcpdump command syntax to ensure that the MAC address appears in the packet capture output?

  • A. -w capture.pcap -s 1518 host 192.168.100.100 mac
  • B. -w capture.pcap -s 1518 host 192.168.100.100 ether
  • C. -ne src 192.168.100.100
  • D. -nm src 192.168.100.100

Answer: C

Explanation:
Reference:
https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/212474-working-with-firepower-threat-def


NEW QUESTION # 81
A user within an organization opened a malicious file on a workstation which in turn caused a ransomware attack on the network. What should be configured within the Cisco FMC to ensure the file is tested for viruses on a sandbox system?

  • A. Spere analysis
  • B. Dynamic analysis
  • C. Capacity handling
  • D. Local malware analysis

Answer: B


NEW QUESTION # 82
An engineer currently has a Cisco FTD device registered to the Cisco FMC and is assigned the address of
10.10.50.12. The organization is upgrading the addressing schemes and there is a requirement to convert the addresses to a format that provides an adequate amount of addresses on the network. What should the engineer do to ensure that the new addressing takes effect and can be used for the Cisco FTD to Cisco FMC connection?

  • A. Update the IP addresses from IPv4 to IPv6 without deleting from Cisco FMC.
  • B. Format and reregister the device to Cisco FMC.
  • C. Delete and reregister the device to Cisco FMC.
  • D. Cisco FMC does not support devices that use IPv4 IP addresses.

Answer: A

Explanation:
Section: Management and Troubleshooting


NEW QUESTION # 83
An engineer must investigate a connectivity issue and decides to use the packet capture feature on Cisco FTD.
The goal is to see the real packet going through the Cisco FTD device and see the Snort detection actions as a part of the output. After the capture-traffic command is issued, only the packets are displayed. Which action resolves this issue?

  • A. Specify the trace using the -T option after the capture-traffic command.
  • B. Perform the trace within the Cisco FMC GUI instead of the Cisco FTD CLI.
  • C. Use the verbose option as a part of the capture-traffic command
  • D. Use the capture command and specify the trace option to get the required information.

Answer: D


NEW QUESTION # 84
While configuring FTD, a network engineer wants to ensure that traffic passing through the appliance does not require routing or Vlan rewriting. Which interface mode should the engineer implement to accomplish this task?

  • A. passive
  • B. transparent
  • C. Inline set
  • D. Inline tap

Answer: B


NEW QUESTION # 85
A network engineer is logged into the Cisco AMP for Endpoints console and sees a malicious verdict for an identified SHA-256 hash. Which configuration is needed to mitigate this threat?

  • A. Add the hash from the infected endpoint to the network block list.
  • B. Use regular expressions to block the malicious file.
  • C. Enable a personal firewall in the infected endpoint.
  • D. Add the hash to the simple custom detection list.

Answer: D


NEW QUESTION # 86
Refer to the exhibit.

And engineer is analyzing the Attacks Risk Report and finds that there are over 300 instances of new operating systems being seen on the network How is the Firepower configuration updated to protect these new operating systems?

  • A. The administrator requests a Remediation Recommendation Report from Cisco Firepower
  • B. The administrator manually updates the policies.
    Ref: https://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide-v60/Tailoring_Intrusion_Protection_to_Your_Network_Assets.html
  • C. Cisco Firepower automatically updates the policies.
  • D. Cisco Firepower gives recommendations to update the policies.

Answer: D


NEW QUESTION # 87
Which group within Cisco does the Threat Response team use for threat analysis and research?

  • A. Cisco Talos
  • B. Cisco Network Response
  • C. OpenDNS Group
  • D. Cisco Deep Analytics

Answer: A

Explanation:
Reference: https://www.cisco.com/c/en/us/products/security/threat-response.html#~benefits


NEW QUESTION # 88
An engineer is troubleshooting HTTP traffic to a web server using the packet capture tool on Cisco FMC.
When reviewing the captures, the engineer notices that there are a lot of packets that are not sourced from or destined to the web server being captured. How can the engineer reduce the strain of capturing packets for irrelevant traffic on the Cisco FTD device?

  • A. Use an access-list within the packet capture to permit only HTTP traffic to and from the web server.
  • B. Use the -c option to restrict the packet capture to only the first 100 packets.
  • C. Use the host filter in the packet capture to capture traffic to or from a specific host.
  • D. Redirect the packet capture output to a. pcap file that can be opened with Wireshark.

Answer: C


NEW QUESTION # 89
A network security engineer must export packet captures from the Cisco FMC web browser while troubleshooting an issue. When navigating to the address Error! Hyperlink reference not valid. IP>/capture/CAPI/pcap/test.pcap. an error 403: Forbidden is given instead of the PCAP file. Which action must the engineer take to resolve this issue?

  • A. Use the Cisco FTD IP address as the proxy server setting on the browser.
  • B. Enable the HTTPS server for the device platform policy.
  • C. Disable the proxy setting on the browser.
  • D. Disable the HTTPS server and use HTTP instead.

Answer: B


NEW QUESTION # 90
Which action should you take when Cisco Threat Response notifies you that AMP has identified a file as malware?

  • A. Wait for Cisco Threat Response to automatically block the malware.
  • B. Forward the result of the investigation to an external threat-analysis engine.
  • C. Add the malicious file to the block list.
  • D. Send a snapshot to Cisco for technical support.

Answer: C

Explanation:
Section: Integration


NEW QUESTION # 91
An organization wants to secure traffic from their branch office to the headquarter building using Cisco Firepower devices, They want to ensure that their Cisco Firepower devices are not wasting resources on inspecting the VPN traffic. What must be done to meet these requirements?

  • A. Enable a flexconfig policy to re-classify VPN traffic so that it no longer appears as interesting traffic
  • B. Configure the Cisco Firepower devices to bypass the access control policies for VPN traffic.
  • C. Tune the intrusion policies in order to allow the VPN traffic through without inspection
  • D. Configure the Cisco Firepower devices to ignore the VPN traffic using prefilter policies

Answer: B

Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/640/fdm/fptd-fdm-config-guide-640/fptd-fdm-ravpn.html


NEW QUESTION # 92
Which policy rule is included in the deployment of a local DMZ during the initial deployment of a Cisco NGFW through the Cisco FMC GUI?

  • A. permit ip any
  • B. deny ip any
  • C. no policy rule is included
  • D. a default DMZ policy for which only a user can change the IP addresses.

Answer: C


NEW QUESTION # 93
A VPN user is unable to conned lo web resources behind the Cisco FTD device terminating the connection. While troubleshooting, the network administrator determines that the DNS responses are not getting through the Cisco FTD What must be done to address this issue while still utilizing Snort IPS rules?

  • A. Disable the intrusion rule threshes to optimize the Snort processing.
  • B. Uncheck the "Drop when Inline" box in the intrusion policy to allow the traffic.
  • C. Decrypt the packet after the VPN flow so the DNS queries are not inspected
  • D. Modify the Snort rules to allow legitimate DNS traffic to the VPN users.

Answer: D


NEW QUESTION # 94
......

Latest 300-710 Exam Dumps Cisco Exam from Training: https://torrentpdf.validvce.com/300-710-exam-collection.html