Cisco® 300-710 Exam Practice Questions (P. 4)
- Full Access (360 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #31
A hospital network needs to upgrade their Cisco FMC managed devices and needs to ensure that a disaster recovery process is in place. What must be done in order to minimize downtime on the network?
- AConfigure a second circuit to an ISP for added redundancy.
- BKeep a copy of the current configuration to use as backup.Most Voted
- CConfigure the Cisco FMCs for failover.
- DConfigure the Cisco FMC managed devices for clustering.
Correct Answer:
C
C

Good job spotting the importance of minimizing network downtime during upgrades by employing Cisco FMC managed devices for failover. Failover configuration allows the network to continue functioning without interruption by automatically switching to a backup system upon detecting a failure of the main system. This capability is crucial in ensuring that network operations do not halt during critical updates or unexpected outages, particularly in a sensitive environment like a hospital. This approach maintains operational consistency and protects against potential data loss or service disruption during system upgrades.
send
light_mode
delete
Question #32
An organization has implemented Cisco Firepower without IPS capabilities and now wants to enable inspection for their traffic. They need to be able to detect protocol anomalies and utilize the Snort rule sets to detect malicious behavior. How is this accomplished?
- AModify the network discovery policy to detect new hosts to inspect.
- BModify the access control policy to redirect interesting traffic to the engine.Most Voted
- CModify the intrusion policy to determine the minimum severity of an event to inspect.
- DModify the network analysis policy to process the packets for inspection.
Correct Answer:
D
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/670/fdm/fptd-fdm-config-guide-670/fptd-fdm-intrusion.html
D
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/670/fdm/fptd-fdm-config-guide-670/fptd-fdm-intrusion.html
send
light_mode
delete
Question #33
An engineer is tasked with deploying an internal perimeter firewall that will support multiple DMZs. Each DMZ has a unique private IP subnet range. How is this requirement satisfied?
- ADeploy the firewall in transparent mode with access control policies
- BDeploy the firewall in routed mode with access control policiesMost Voted
- CDeploy the firewall in routed mode with NAT configured
- DDeploy the firewall in transparent mode with NAT configured
Correct Answer:
C
Reference:
https://www.cisco.com/c/en/us/td/docs/security/asa/asa96/configuration/general/asa-96-general-config/intro-fw.html
C
Reference:
https://www.cisco.com/c/en/us/td/docs/security/asa/asa96/configuration/general/asa-96-general-config/intro-fw.html
send
light_mode
delete
Question #34
An engineer must configure high availability for the Cisco Firepower devices. The current network topology does not allow for two devices to pass traffic concurrently. How must the devices be implemented in this environment?
- Ain active/active mode
- Bin a cluster span EtherChannel
- Cin active/passive mode
- Din cluster interface mode
Correct Answer:
C
C

For configuring high availability in Cisco Firepower, when you cannot use two devices to pass traffic concurrently, the correct setup is the active/passive mode. In this configuration, one device actively manages traffic, while the other remains in a standby mode, ready to take over if the primary device fails. This approach ensures continuous traffic flow without requiring simultaneous traffic handling by both devices, aligning with network topologies that do not support concurrent device traffic.
send
light_mode
delete
Question #35
When deploying a Cisco ASA Firepower module, an organization wants to evaluate the contents of the traffic without affecting the network. It is currently configured to have more than one instance of the same device on the physical appliance. Which deployment mode meets the needs of the organization?
- Ainline tap monitor-only modeMost Voted
- Bpassive monitor-only mode
- Cpassive tap monitor-only mode
- Dinline mode
Correct Answer:
B
B

The passive monitor-only mode is indeed the best fit when the focus is on monitoring traffic without direct interaction with the flow itself, making it non-intrusive and ideal for the specified context of not affecting the network. However, some points were raised about the possible limitation in passive monitor-only mode when multiple instances are involved. This should be fact-checked against the most current Cisco documentation, as configurations and capabilities may evolve over software versions or through specific deployment details not covered fully here.
send
light_mode
delete
Question #36
An organization has a Cisco FTD that uses bridge groups to pass traffic from the inside interfaces to the outside interfaces. They are unable to gather information about neighboring Cisco devices or use multicast in their environment. What must be done to resolve this issue?
- ACreate a firewall rule to allow CDP trafficMost Voted
- BCreate a bridge group with the firewall interfaces
- CChange the firewall mode to transparent
- DChange the firewall mode to routed
Correct Answer:
D
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/623/configuration/guide/fpmc-config-guide-v623/ transparent_or_routed_firewall_mode_for_firepower_threat_defense.html
D
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/623/configuration/guide/fpmc-config-guide-v623/ transparent_or_routed_firewall_mode_for_firepower_threat_defense.html
send
light_mode
delete
Question #37
A network engineer implements a new Cisco Firepower device on the network to take advantage of its intrusion detection functionality. There is a requirement to analyze the traffic going across the device, alert on any malicious traffic, and appear as a bump in the wire. How should this be implemented?
- ASpecify the BVI IP address as the default gateway for connected devices
- BEnable routing on the Cisco Firepower
- CAdd an IP address to the physical Cisco Firepower interfaces
- DConfigure a bridge group in transparent mode
Correct Answer:
D
D

The proper deployment of Cisco Firepower in transparent mode, acting as "a bump in the wire," is through configuring a bridge group in transparent mode. This setup allows the unit to monitor and control the data passing through without being detected by connected devices, hence not affecting the network topology. The bridge group manages the traffic between internal and external interfaces using bridging techniques while maintaining all standard firewall functionalities, elevating network security without disruption. This method is crucial for environments needing seamless and non-disruptive security measures.
send
light_mode
delete
Question #38
Which two conditions must be met to enable high availability between two Cisco FTD devices? (Choose two.)
- Asame flash memory size
- Bsame NTP configuration
- Csame DHCP/PPoE configuration
- Dsame host name
- Esame number of interfaces
Correct Answer:
BE
BE
send
light_mode
delete
Question #39
An engineer is building a new access control policy using Cisco FMC. The policy must inspect a unique IPS policy as well as log rule matching. Which action must be taken to meet these requirements?
- AConfigure an IPS policy and enable per-rule loggingMost Voted
- BDisable the default IPS policy and enable global logging
- CConfigure an IPS policy and enable global logging
- DDisable the default IPS policy and enable per-rule logging
Correct Answer:
A
A
send
light_mode
delete
Question #40
Which two OSPF routing features are configured in Cisco FMC and propagated to Cisco FTD? (Choose two.)
- AOSPFv2 with IPv6 capabilities
- Bvirtual linksMost Voted
- CSHA authentication to OSPF packets
- Darea boundary router type 1 LSA filtering
- EMD5 authentication to OSPF packetsMost Voted
Correct Answer:
BE
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/ospf_for_firepower_threat_defense.html
BE
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/ospf_for_firepower_threat_defense.html
send
light_mode
delete
All Pages