Get Latest Oct-2021 Conduct effective penetration tests using Prep4away 300-710 [Q34-Q56]

Share

Get Latest [Oct-2021] Conduct effective penetration tests using  Prep4away 300-710

Penetration testers simulate 300-710 exam PDF

NEW QUESTION 34
An engineer configures a network discovery policy on Cisco FMC. Upon configuration, it is noticed that excessive and misleading events filing the database and overloading the Cisco FMC. A monitored NAT device is executing multiple updates of its operating system in a short period of time. What configuration change must be made to alleviate this issue?

  • A. Leave default networks.
  • B. Change the method to TCP/SYN.
  • C. Exclude load balancers and NAT devices.
  • D. Increase the number of entries on the NAT device.

Answer: C

Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide-v60/Network_Discovery_Policies.html

 

NEW QUESTION 35
Which command is typed at the CLI on the primary Cisco FTD unit to temporarily stop running high- availability?

  • A. configure high-availability resume
  • B. system support network-options
  • C. configure high-availability disable
  • D. configure high-availability suspend

Answer: C

 

NEW QUESTION 36
An organization has seen a lot of traffic congestion on their links going out to the internet There is a Cisco Firepower device that processes all of the traffic going to the internet prior to leaving the enterprise. How is the congestion alleviated so that legitimate business traffic reaches the destination?

  • A. Create a QoS policy rate-limiting high bandwidth applications
  • B. Create a VPN policy so that direct tunnels are established to the business applications
  • C. Create a flexconfig policy to use WCCP for application aware bandwidth limiting
  • D. Create a NAT policy so that the Cisco Firepower device does not have to translate as many addresses

Answer: A

 

NEW QUESTION 37
Which command is typed at the CLI on the primary Cisco FTD unit to temporarily stop running high- availability?

  • A. configure high-availability resume
  • B. system support network-options
  • C. configure high-availability disable
  • D. configure high-availability suspend

Answer: C

Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/610/configuration/guide/fpmc-config- guide-v61/firepower_threat_defense_high_availability.html

 

NEW QUESTION 38
In a Cisco AMP for Networks deployment, which disposition is returned if the cloud cannot be reached?

  • A. unknown
  • B. disconnected
  • C. clean
  • D. unavailable

Answer: D

Explanation:
Section: Integration
Explanation/Reference:

 

NEW QUESTION 39
The event dashboard within the Cisco FMC has been inundated with low priority intrusion drop events, which are overshadowing high priority events. An engineer has been tasked with reviewing the policies and reducing the low priority events. Which action should be configured to accomplish this task?

  • A. drop packet
  • B. generate events
  • C. drop connection
  • D. drop and generate

Answer: D

 

NEW QUESTION 40
What is a result of enabling Cisco FTD clustering?

  • A. All Firepower appliances can support Cisco FTD clustering.
  • B. Site-to-site VPN functionality is limited to the master unit, and all VPN connections are dropped if the master unit fails.
  • C. Integrated Routing and Bridging is supported on the master unit.
  • D. For the dynamic routing feature, if the master unit fails, the newly elected master unit maintains all existing connections.

Answer: B

Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-config- guide-v64/clustering_for_the_firepower_threat_defense.html

 

NEW QUESTION 41
A network engineer wants to add a third-party threat feed into the Cisco FMC for enhanced threat detection Which action should be taken to accomplish this goal?

  • A. Enable Threat Intelligence Director using REST APIs
  • B. Enable Rapid Threat Containment using STIX and TAXII
  • C. Enable Threat Intelligence Director using STIX and TAXII
  • D. Enable Rapid Threat Containment using REST APIs

Answer: C

Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/623/configuration/guide/fpmc-config-guide-v623/cisco_threat_intelligence_director__tid_.html

 

NEW QUESTION 42
In which two places can thresholding settings be configured? (Choose two.)

  • A. globally, per intrusion policy
  • B. per preprocessor, within the network analysis policy
  • C. globally, within the network analysis policy
  • D. on each IPS rule
  • E. on each access control rule

Answer: A,D

Explanation:
Reference: https://www.cisco.com/c/en/us/td/docs/security/firesight/541/firepower-module-user-guide/asa-firepower-module-user-guide-v541/Intrusion-Global-Threshold.pdf

 

NEW QUESTION 43
Which protocol establishes network redundancy in a switched Firepower device deployment?

  • A. HSRP
  • B. STP
  • C. VRRP
  • D. GLBP

Answer: B

Explanation:
Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/firepower_threat_defense_high_availability.html

 

NEW QUESTION 44
Which command is run on an FTD unit to associate the unit to an FMC manager that is at IP address 10.0.0.10, and that has the registration key Cisco123?

  • A. configure manager add Cisco123 10.0.0.10
  • B. configure manager local Cisco123 10.0.0.10
  • C. configure manager local 10.0.0.10 Cisco123
  • D. configure manager add 10.0.0.10 Cisco123

Answer: D

Explanation:
Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/misc/fmc-ftd-mgmt-nw/fmc-ftd-mgmt-nw.html#id_106101

 

NEW QUESTION 45
What is the maximum SHA level of filtering that Threat Intelligence Director supports?

  • A. SHA-512
  • B. SHA-4096
  • C. SHA-256
  • D. SHA-1024

Answer: C

 

NEW QUESTION 46
What is the disadvantage of setting up a site-to-site VPN in a clustered-units environment?

  • A. VPN connections must be re-established when a new master unit is elected.
  • B. Smart License is required to maintain VPN connections simultaneously across all cluster units.
  • C. Only established VPN connections are maintained when a new master unit is elected.
  • D. VPN connections can be re-established only if the failed master unit recovers.

Answer: A

Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/fxos/clustering/ftd-cluster- solution.html#concept_g32_yml_y2b

 

NEW QUESTION 47
Refer to the exhibit.

What must be done to fix access to this website while preventing the same communication to all other websites?

  • A. Create an access control policy rule to allow port 443 to only 172.1.1 50
  • B. Create an access control policy rule to allow port 80 to only 172.1.1 50.
  • C. Create an intrusion policy rule to have Snort allow port 80 to only 172.1.1 50.
  • D. Create an intrusion policy rule to have Snort allow port 443 to only 172.1.1.50

Answer: B

 

NEW QUESTION 48
An engineer configures a network discovery policy on Cisco FMC. Upon configuration, it is noticed that excessive and misleading events filing the database and overloading the Cisco FMC. A monitored NAT device is executing multiple updates of its operating system in a short period of time. What configuration change must be made to alleviate this issue?

  • A. Leave default networks.
  • B. Change the method to TCP/SYN.
  • C. Exclude load balancers and NAT devices.
  • D. Increase the number of entries on the NAT device.

Answer: C

 

NEW QUESTION 49
An administrator is setting up Cisco Firepower to send data to the Cisco Stealthwatch appliances. The NetFlow_Set_Parameters object is already created, but NetFlow is not being sent to the flow collector. What must be done to prevent this from occurring?

  • A. Add the NetFlow_Add_Destination object to the configuration
  • B. Create a service identifier to enable the NetFlow service
  • C. Add the NetFlow_Send_Destination object to the configuration
  • D. Create a Security Intelligence object to send the data to Cisco Stealthwatch

Answer: D

 

NEW QUESTION 50
Which action should you take when Cisco Threat Response notifies you that AMP has identified a file as malware?

  • A. Add the malicious file to the block list.
  • B. Wait for Cisco Threat Response to automatically block the malware.
  • C. Forward the result of the investigation to an external threat-analysis engine.
  • D. Send a snapshot to Cisco for technical support.

Answer: A

Explanation:
Section: Integration

 

NEW QUESTION 51
What are the minimum requirements to deploy a managed device inline?

  • A. passive interface, MTU, and mode
  • B. inline interfaces, MTU, and mode
  • C. inline interfaces, security zones, MTU, and mode
  • D. passive interface, security zone, MTU, and mode

Answer: B

Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/650/configuration/guide/fpmc-config- guide-v65/ips_device_deployments_and_configuration.html

 

NEW QUESTION 52
After deploying a network-monitoring tool to manage and monitor networking devices in your organization, you realize that you need to manually upload an MIB for the Cisco FMC. In which folder should you upload the MIB file?

  • A. /etc/sf/DCEALERT.MIB
  • B. /sf/etc/DCEALERT.MIB
  • C. /etc/sf/DCMIB.ALERT
  • D. system/etc/DCEALERT.MIB

Answer: A

 

NEW QUESTION 53
A user within an organization opened a malicious file on a workstation which in turn caused a ransomware attack on the network. What should be configured within the Cisco FMC to ensure the file is tested for viruses on a sandbox system?

  • A. Capacity handling
  • B. Local malware analysis
  • C. Spere analysis
  • D. Dynamic analysis

Answer: D

Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/623/configuration/guide/fpmc-config-guide-v623/file_policies_and_advanced_malware_protection.html#ID-2199-000005d8

 

NEW QUESTION 54
A security engineer is configuring an Access Control Policy for multiple branch locations These locations share a common rule set and utilize a network object called INSIDE_NET which contains the locally significant internal network subnets at each location What technique will retain the policy consistency at each location but allow only the locally significant network subnet within the applicable rules?

  • A. utilizing a dynamic ACP that updates from Cisco Talos
  • B. creating an ACP with an INSIDE_NET network object and object overrides
  • C. utilizing policy inheritance
  • D. creating a unique ACP per device

Answer: C

 

NEW QUESTION 55
An administrator is setting up Cisco Firepower to send data to the Cisco Stealthwatch appliances. The NetFlow_Set_Parameters object is already created, but NetFlow is not being sent to the flow collector. What must be done to prevent this from occurring?

  • A. Create a service identifier to enable the NetFlow service
  • B. Add the NetFlow_Send_Destination object to the configuration
  • C. Create a Security Intelligence object to send the data to Cisco Stealthwatch
  • D. Add the NetFlow_Add_Destination object to the configuration

Answer: D

 

NEW QUESTION 56
......


Asked Prerequisites

Officially, there are no mandatory requirements to fulfill before taking up the Cisco 300-710 exam. Anyone can go for it and excel at the career front. But, the preparation process is not as easy as it may sound. So, it is wise to gain adequate industry exposure, saying about three to five years, before appearing for this test. Such a prior understanding will make the exam journey more simplified and effortless.

 

Tested Material Used To 300-710 Test Engine: https://www.prep4away.com/Cisco-certification/braindumps.300-710.ete.file.html

Steps Necessary To Pass The 300-710 Exam: https://drive.google.com/open?id=1vj5PvcLk1b6MviCs14gemhygwu6JYLpf