Cisco Securing Networks with Cisco Firepower - 300-710 Exam Practice Test

Which Cisco Advanced Malware Protection for Endpoints policy is used only for monitoring endpoint actively?
Correct Answer: D
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).

Refer to the exhibit. An engineer configures a NAT rule allowing clients to use the internet only if clients are located on the directly connected internal network. Dynamic auto PAT must be configured. Drag and drop the NAT rules from the left onto the corresponding targets on the right. Not all options are used.
Correct Answer:

Explanation:
A screenshot of a computer AI-generated content may be incorrect.
An engineer is troubleshooting HTTP traffic to a web server using the packet capture tool on Cisco FMC.
When reviewing the captures, the engineer notices that there are a lot of packets that are not sourced from or destined to the web server being captured. How can the engineer reduce the strain of capturing packets for irrelevant traffic on the Cisco FTD device?
Correct Answer: B
The administrator notices that there is malware present with an .exe extension and needs to verify if any of the systems on the network are running the executable file. What must be configured within Cisco AMP for Endpoints to show this data?
Correct Answer: D
Refer to the exhibit.

A Cisco Secure Firewall Threat Defense (FTD) device is deployed in inline mode with an inline set. The network engineer wants router R2 to remove the directly connected route M 68.1.0/24 from its routing table when the cable between routed R1 and the Secure FTD device Is disconnected. Which action must the engineer take?
1
Correct Answer: A
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
An organization has implemented Cisco Firepower without IPS capabilities and now wants to enable inspection for their traffic. They need to be able to detect protocol anomalies and utilize the Snort rule sets to detect malicious behaviour. How is this accomplished?
Correct Answer: D
A security administrator must configure Cisco Secure Firewall Management Center so that certain intrusion rules are active only during specified times. Which action must the administrator take?
Correct Answer: A
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
A network administrator configured a NAT policy that translates a public IP address to an internal web server IP address. An access policy has also been created that allows any source to reach the public IP address on port 80. The web server is still not reachable from the Internet on port 80. Which configuration change is needed?
Correct Answer: B
Which limitation applies to Cisco Firepower Management Center dashboards in a multidomain environment?
Correct Answer: D
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
Which interface type allows packets to be dropped?
Correct Answer: B
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).

Refer to the exhibit. An engineer is deploying a new instance of Cisco Secure Firewall Threat Defense. Which action must the engineer take next so that Client_A and Client_B receive an IP address via DHCP from Server_A?
Correct Answer: B
Which two routing options are valid with Cisco Firepower Threat Defense? (Choose two.)
Correct Answer: A,B
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
The CEO ask a network administrator to present to management a dashboard that shows custom analysis tables for the top DNS queries URL category statistics, and the URL reputation statistics.
Which action must the administrator take to quickly produce this information for management?
Correct Answer: A