Practice 300-710 SNCF Configuration questions with full explanations on every answer.
Start practicing
Configuration — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
An administrator configures an Identity Policy on the FMC to authenticate users via Active Directory using captive portal. Where is the Identity Policy applied within the Firepower configuration hierarchy?
2A network engineer needs to configure Auto NAT on a Firepower Threat Defense device managed by FMC to translate internal subnet 10.10.10.0/24 to a single public IP address 203.0.113.50. Which translation type should be selected?
3An administrator wants to create a Prefilter policy to fast-path (bypass Snort inspection for) a trusted backup stream between two data centers. Which action type should be selected in the Prefilter rule?
4An administrator needs to configure manual NAT on an FTD device to translate both the source IP and source port of outbound packets originating from 192.168.2.50 to a specific public IP 198.51.100.10 and port 50000. Which manual NAT rule element achieves this?
5An administrator wants to decrypt inbound HTTPS traffic destined for a public web server behind a Firepower Threat Defense device. Which type of SSL/TLS decryption policy must be configured on the FMC?
6An administrator is configuring a new Access Control Policy on the Firepower Management Center and needs to add a rule that blocks peer-to-peer file sharing applications regardless of port. Which rule type should the administrator select?
7An administrator wants to create a Port object group containing TCP ports 80, 443, and 8080 on the FMC. Where is this object configured?
8An enterprise requires FTD to decrypt outbound SSL/TLS traffic so internal users visiting external websites can be inspected by Snort for malware. Which policy and action combination must be configured?
9An FMC administrator is configuring a URL Filtering policy. They want to block URLs categorized as 'Hacking' while logging the event. Where is this configured within the Access Control Policy?
10An administrator configures a security intelligence feed in the FMC to block known malicious IP addresses. Where are Security Intelligence feeds and lists applied in the FMC configuration?
11When configuring an Access Control Policy on the FMC, what is the purpose of the Default Action set at the bottom of the rules table?
12An administrator needs to configure an identity policy to authenticate users using an external RADIUS server via Passive Authentication. Which mechanism accomplishes passive user identification?
13An FTD device is deployed in routed mode with multiple security zones. An administrator needs to configure an Access Control rule that evaluates traffic flowing between two different security zones. How are security zones utilized in the rule?
14An engineer is configuring a QoS policy on an FMC-managed FTD and needs to police traffic to a maximum bandwidth limit on an interface. Which shaping/policing parameter must be configured?
15An administrator needs to create a Geolocation object in the FMC to block traffic originating from a specific country. Where is this object used?
16An administrator configures DNS injection and rewriting in a manual NAT rule on an FTD device. What is the primary purpose of enabling DNS translation in a NAT rule?
17An engineer wants to group several FTD interfaces into a single logical zone to simplify Access Control rule creation. Where are security zones created in the FMC?
18An administrator is configuring a Prefilter policy to handle GRE-encapsulated traffic. Which Prefilter rule option allows handling or accelerating tunneled traffic?
19An administrator wants to configure an Access Control rule that triggers an Intrusion Policy only when specific vulnerability signatures match. Where is the Intrusion Policy assigned?
20An administrator needs to create a custom Application filter object in the FMC to easily select cloud storage applications in Access Control rules. Where are application filters created?
21An administrator configures an SSL Decryption Policy with a rule to 'Do Not Decrypt' financial traffic. However, the administrator also wants to ensure that the encrypted session still undergoes basic certificate validation and categorization. How does FTD handle 'Do Not Decrypt' traffic?
22An administrator needs to create a variable set to define specific port or network variables used within Intrusion Rules. Where are variable sets managed in the FMC?
23An administrator is configuring manual NAT and needs to specify an interface pair (Source Interface and Destination Interface). Why is defining interface objects important in manual NAT rules?
24An administrator is configuring manual NAT on an FTD device managed by FMC. Which TWO parameters must be defined when creating a manual NAT rule? (Choose two)
25An administrator is troubleshooting an Access Control Policy where multiple rules could potentially match a specific packet. In what order does the FMC evaluate rules within an Access Control Policy?
26An administrator needs to configure Active Authentication using a captive portal on an FTD device. Which firewall feature must be properly configured and running to present the authentication prompt to users?
27Which THREE actions can be assigned to an individual rule within an Access Control Policy on the FMC? (Choose three)
28Which THREE criteria can be used to match traffic within an Access Control rule on the FMC? (Choose three)
29Which THREE settings can be configured within a Prefilter Policy on the FMC? (Choose three)
30An administrator is configuring Identity Policies on the FMC. Which TWO identity sources are supported for user mapping and authentication? (Choose two)
31When configuring manual NAT on an FTD device, which THREE options are available for configuring the Translated Source? (Choose three)
32An administrator is managing object configurations on the FMC. Which TWO of the following are valid object types that can be created under Object Management? (Choose two)
33Which THREE methods can be used to populate IP address objects or groups in the FMC Object Management? (Choose three)
34An administrator is configuring Security Intelligence in FMC. Which TWO types of objects can be added to Security Intelligence blacklists or whitelists? (Choose two)
35A network engineer is deploying a Firepower Threat Defense (FTD) device and must configure NAT to translate an internal server IP of 10.10.10.50 to a public IP of 203.0.113.50 while preserving the original source port for inbound traffic. Which NAT type accomplishes this?
36An administrator configures an SSL Decryption Policy on the FMC to decrypt inbound HTTPS traffic destined for an internal web server. The administrator imports the private key and server certificate into the FMC. Which decryption action must be selected to allow the FTD to decrypt this traffic using the server's private key?
37An Identity Policy is configured on the FMC to authenticate users connecting through the FTD. The administrator wants to use Active Directory as the identity source. Which mechanism must be configured to map user IP addresses to usernames without requiring explicit web authentication?
38An administrator wants to group multiple existing port objects (e.g., TCP 80, TCP 443, TCP 8080) into a single object for use in Access Control Policy rules. Which object container should be created?
39An administrator needs to configure NAT on an FTD device so that internal traffic destined for a partner network uses the original source IP, but the destination IP is translated from 192.168.10.50 to 172.16.50.10. What type of NAT rule is required?
40An administrator is configuring SSL Decryption to inspect internal clients browsing external websites. The organization wants to ensure that traffic to financial and health-related websites is bypassed to maintain privacy and regulatory compliance. How should this be configured in the SSL Policy?
41An administrator is configuring Access Control Policy rules on the FMC. The default action for unmatched traffic is currently set to Block. The requirement is changed so that unmatched traffic should pass through the FTD without inspection. Where is this setting modified?
42An FTD device is deployed behind a service provider router that performs NAT, meaning the external IP address assigned to the FTD's outside interface changes dynamically via DHCP. How should a Manual NAT rule be configured to handle outbound traffic referencing this dynamic outside IP?
43An administrator configures QoS on an FTD interface to prioritize VoIP traffic. Which traffic matching mechanism within the QoS policy allows the FTD to identify VoIP traffic (such as SIP or RTP) based on Layer 7 application inspection?
44An administrator is configuring an Identity Policy with Active Directory integration. The requirement is to ensure that users who fail primary AD authentication are assigned to a restricted guest VLAN using ISE integration. Which component in the FMC architecture handles this user-to-group association?
45An administrator needs to create a custom URL object to block a specific malicious domain name 'example.malicious.com' in an Access Control Policy. Which object type should be created?
46An administrator wants to ensure that specific internal subnets are never subjected to NAT translation when communicating with a partner VPN tunnel. Which NAT feature achieves this?
47An administrator is troubleshooting an SSL Decryption policy where encrypted connections are failing. The FMC logs indicate that clients are rejecting the FTD's re-signed certificate because it is not trusted. What configuration step is missing?
48An administrator is configuring Security Intelligence on the FMC to drop traffic from known malicious IP addresses. Where in the Access Control Policy is Security Intelligence evaluated relative to standard access rules?
49An administrator is creating an Access Control Policy rule on the FMC. Which TWO elements are required to create a basic rule? (Choose two)
50An administrator is configuring Manual NAT on an FTD device. Which THREE parameters must be defined when creating a Manual Static NAT rule for inbound traffic? (Choose three)
51An administrator needs to define network objects in the FMC Object Management menu. Which THREE object types are natively supported for network definition? (Choose three)
52An administrator is configuring an Identity Policy to enforce user-based access control. Which THREE identity sources are supported by the FMC for user awareness? (Choose three)
53An administrator is configuring an SSL Decryption Policy on the FMC. Which TWO conditions or actions can be configured within an SSL rule? (Choose two)
54An administrator is troubleshooting a Prefilter Policy configured on an FMC. Which THREE actions are available when creating a rule in a Prefilter Policy? (Choose three)
55An administrator is configuring Security Intelligence feeds on the FMC. Which TWO types of objects or feeds can be used to populate Security Intelligence blacklists? (Choose two)
56An administrator is configuring interface-level QoS on an FTD device. Which THREE parameters or features can be configured within an FTD QoS policy? (Choose three)
57An administrator is configuring a Network Address Translation (NAT) rule on a Cisco FMC managed Threat Defense device. The requirement is to translate the source IP address of traffic coming from the inside zone going to the outside zone, but only for a specific internal subnet. Which NAT type must the administrator select in the FMC NAT rule configuration?
58A security engineer is creating an Access Control Policy (ACP) in FMC. The policy must block all traffic matching specific URL categories while allowing standard web browsing. However, the administrator wants users to receive a warning page before continuing to pages categorized as "Potentially Damaging Content" rather than a hard block. Which action should the engineer assign to the URL category in the ACP Rules tab?
59An administrator is implementing an SSL Decryption Policy on a Cisco Firepower Threat Defense device managed by FMC. The policy must decrypt outbound HTTPS traffic to inspect for malware, but certain financial domains must be excluded from decryption to comply with privacy regulations. Which rule action should be configured for these specific financial domains in the SSL Decryption Policy?
60An administrator needs to configure Quality of Service (QoS) on a Cisco Firepower Threat Defense device via FMC to limit peer-to-peer traffic bandwidth. Where must the QoS policy be applied for it to take effect on traffic traversing the firewall?
61An engineer is configuring an Identity Policy in FMC to enforce user-based access control. Active Directory integration has been established via User Agent, but the engineer notices that some users authenticated via remote access VPN are not being resolved to their IP addresses. Which feature must be integrated into the identity configuration to capture IP-to-user mappings for remote access VPN users?
62An administrator is configuring a Prefilter Policy in FMC to optimize performance on a Cisco Firepower Threat Defense device. The requirement is to completely bypass inspection for a trusted high-speed data backup tunnel between two datacenters using GRE encapsulation. Which prefilter rule action should be selected?
63An administrator is configuring a Manual NAT rule in the FMC for an internal server that needs to be accessed from the outside zone. The internal IP is 192.168.1.50, and it must be translated to a public IP 203.0.113.10. Which TWO configuration parameters must be specified when defining this Manual NAT rule? (Choose two)
64An administrator needs to ensure that internal users can access the internet using a public IP while hiding their private address. Which NAT rule type should be configured on the FMC?
65An administrator is setting up a new Cisco Firepower Threat Defense device and needs to configure platform-level parameters using FMC Platform Settings. Which TWO features can be configured via Platform Settings? (Choose two)
66You are configuring an SSL Decryption policy. Which action is required to ensure that traffic to a specific financial website is excluded from inspection due to compliance reasons?
67Which THREE components are necessary to implement passive identity monitoring in an FMC-managed Firepower system?
68You are configuring a NAT rule on an FTD device managed by FMC. You need to translate the source IP of internal hosts to a specific public IP address when they access the internet. Which NAT type must be selected in the FMC NAT Rule editor?
69You are defining an Access Control Policy rule to allow traffic. If you want to log the connection at the end of the flow only if it matches the rule, which Logging setting is appropriate?
70You are configuring SSL decryption. To ensure that traffic to a specific financial domain is NOT decrypted due to privacy regulations, what must you configure in the SSL Decryption Policy?
71When creating a network object in FMC, which field allows you to define a group of IP addresses using CIDR notation?
72A security requirement mandates that QoS be applied to limit bandwidth for guest users. Where is QoS configured on an FMC-managed FTD?
73You are troubleshooting a connectivity issue. The traffic is being dropped by a Prefilter rule. What is the characteristic of traffic handled by a Prefilter policy?
74You need to map internal users to specific security policies based on their AD group membership. What must be configured in FMC to support this?
75You are configuring a NAT rule for a web server located in a DMZ. You want to translate the destination IP from a public address to the private DMZ address. Which NAT type is used?
76Which option in the Access Control Policy rule allows you to define a specific application, such as 'Facebook', to be blocked?
77Which TWO components must be configured in FMC to enable User Identity mapping for Access Control Rules?
78When editing an Access Control Rule, which action allows you to drop traffic while simultaneously sending a TCP RST to the client?
79Which THREE criteria can be used to match traffic in an Access Control Policy rule?
80Which TWO settings are available when configuring the 'Logging' tab in an Access Control Rule?
81When configuring a NAT rule, which THREE options are valid 'Type' selections within the NAT Rule editor?
82Which TWO items must be defined to create a fully functional Network Object group in FMC?
83Which THREE actions can be performed by an SSL Decryption Policy?
84Which TWO types of objects can be created in the FMC Object Manager?
85Which TWO protocols are commonly managed via Port objects in FMC?
86Which TWO methods can be used to identify users in an Identity Policy?
87Where in the FMC UI do you go to create a new Access Control Policy?
88What is the result of assigning a 'Trust' action to a rule in an Access Control Policy?
89You are configuring a NAT rule and need to hide the internal network behind a single interface IP. Which NAT translation setting is required?
90Which feature in FMC allows you to group multiple physical interfaces into a single logical zone for policy assignment?
91When deploying a configuration change from FMC to FTD, what is the 'Deployment' process actually doing?
92You are creating a custom URL category. How do you add specific domains to this category in FMC?
93In the context of FTD, what does 'FMC' stand for?
94Which type of object is best suited for defining a web server's public-to-private NAT mapping?
95You are setting up an FTD interface. What is the difference between a 'Routed' and 'Transparent' interface mode?
96What is the primary function of a 'Security Zone' in FMC?
97Where do you define the 'Search' criteria for finding objects in FMC?
98When defining a NAT rule for an internal server, what happens if the 'DNS Rewrite' option is enabled?
99You have a large number of NAT rules. How does the FTD process them?
100What is the purpose of 'Network Discovery' in FMC?
101Which tab in the Access Control Policy rule editor allows you to specify the source and destination zones?
102How do you enable 'High Availability' (HA) for an FTD pair managed by FMC?
103When configuring a QoS policy, what happens if you exceed the 'Rate Limit' set for a traffic class?
104What must be configured before an Access Control Rule can use a URL category?
105What action should you take if you want to test a new Access Control Rule without impacting production traffic?
106When using the 'Search' feature in the Access Control Policy, which filter allows you to find all rules containing a specific network object?
107What is the result of using a 'Security Group' object in an Access Control rule?
108What is the purpose of an 'FQDN' object in FMC?
109How do you identify which Access Control Rule triggered a specific connection log?
110Which tab in the FMC Object Manager allows you to manage pre-defined objects?
111If you need to block a specific file type (e.g., .exe) from being downloaded, which feature must you enable in the Access Control Rule?
112When configuring an FQDN object, which THREE options are valid for the FQDN field?
113Which TWO items can be used to filter traffic in a QoS policy?
114Which TWO tasks are required to delete a NAT rule safely?
115Which TWO fields are commonly used in the 'NAT Rule' editor to define the source address?
116Which THREE components of an Access Control rule can be used to identify traffic as 'Application' based?
117What must be done to apply a change made in the Access Control Policy?
118What is the result of applying an 'IPS Policy' to an Access Control Rule?
119How do you ensure that a specific host object is only used in a specific interface?
120In the FMC, what is the purpose of the 'Network Discovery Policy'?
121Which tab in the Access Control Policy rule allows you to choose the 'Logging' action?
122When you have multiple overlapping NAT rules, which rule is applied?
123Which menu in the FMC allows you to view the list of managed FTD devices?
124When configuring an FTD in Transparent Mode, how is the 'Bridge Group' created?
125What is the effect of changing the order of rules in an Access Control Policy?
126What occurs when an 'Interactive Block' action is used in an Access Control rule?
127What is the primary function of the 'Object Management' section in FMC?
128Which object type should be used to represent a group of network subnets?
The Configuration domain covers the key concepts tested in this area of the 300-710 SNCF exam blueprint published by Cisco. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all 300-710 SNCF domains — no account required.
The Courseiva 300-710 SNCF question bank contains 128 questions in the Configuration domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Configuration domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included