Cisco · Free Practice Questions · Last reviewed May 2026
24real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
An administrator configures an Identity Policy on the FMC to authenticate users via Active Directory using captive portal. Where is the Identity Policy applied within the Firepower configuration hierarchy?
Directly under Devices > Device Management > Platform Settings
Within the Access Control Policy settings on the FMC
Identity policies are invoked and associated directly within the Access Control Policy.
Inside the SSL/TLS Decryption Policy
As a standalone rule inside a Prefilter Policy
A network engineer needs to configure Auto NAT on a Firepower Threat Defense device managed by FMC to translate internal subnet 10.10.10.0/24 to a single public IP address 203.0.113.50. Which translation type should be selected?
Static NAT
Dynamic PAT (Port Address Translation)
Dynamic PAT maps an entire subnet to a single IP address by translating source ports.
Static Identity NAT
Dynamic NAT
An administrator wants to create a Prefilter policy to fast-path (bypass Snort inspection for) a trusted backup stream between two data centers. Which action type should be selected in the Prefilter rule?
FastPath
FastPath instructs the FTD to bypass deep packet inspection (Snort) for the matched traffic flow.
Monitor
Block
Inspect
Trust
An administrator needs to configure manual NAT on an FTD device to translate both the source IP and source port of outbound packets originating from 192.168.2.50 to a specific public IP 198.51.100.10 and port 50000. Which manual NAT rule element achieves this?
Manual NAT rule with Translated Source set to an IP object and dynamic port translation enabled
Manual NAT allows granular control over source IP and source port translation parameters.
Static NAT with Bi-directional enabled
Auto NAT rule configured with Dynamic PAT
Identity NAT with Port Forwarding enabled
An administrator wants to decrypt inbound HTTPS traffic destined for a public web server behind a Firepower Threat Defense device. Which type of SSL/TLS decryption policy must be configured on the FMC?
SSL Decryption - Do Not Decrypt
Decrypt - Resign
Decrypt - Inbound
Decrypt - Inbound is specifically designed for decrypting incoming traffic to protected servers using the server's private key.
SSL Inspection Policy - Outbound
An administrator is configuring a new Access Control Policy on the Firepower Management Center and needs to add a rule that blocks peer-to-peer file sharing applications regardless of port. Which rule type should the administrator select?
NAT rule
Identity rule
Access control rule
Access control rules allow defining application filters to inspect and block traffic based on Layer 7 signatures.
Prefilter rule
Want more Configuration practice?
Practice this domainAn administrator is troubleshooting a Stateful High Availability (HA) pair of Cisco Secure Firewall 4100 series devices managed by FMC. The units are failing to form an HA state, and logs indicate a state mismatch on the control link. Which underlying cause is most likely preventing the HA synchronization?
The MTU on the data interfaces differs by 4 bytes.
The stateful HA control link is configured across a routed switch interface instead of a direct cross-over cable.
The management IP addresses on the active and standby units are identical.
One unit is running a slightly different maintenance patch release of FTD than its peer.
FMC enforces strict version matching; even a minor patch level mismatch between primary and secondary units will cause HA initialization to fail.
An engineer is configuring static route tracking on a Cisco Secure Firewall Threat Defense to ensure high availability for outbound internet connectivity. A backup static route is configured with a higher metric. What mechanism does the firewall use to dynamically switch from the primary route to the backup route when the primary next-hop fails?
Bidirectional Forwarding Detection (BFD) or ICMP ping SLA trackers that monitor the next-hop IP.
Static route tracking relies on IP SLA (ping/TCP monitors) or BFD to monitor availability and remove the primary route from the forwarding table upon failure.
STP topology change notifications received on the tracked interface.
FMC heartbeat loss detection between the firewall and the gateway.
Automatic generation of dynamic OSPF neighbor adjacencies over the static interface.
You are deploying a Cisco Secure Firewall Threat Defense in an existing core network as an out-of-band intrusion prevention system. Which NGIPS deployment mode should you configure to ensure the firewall performs deep packet inspection and generates alerts without dropping any production traffic in the event of a device failure or high load?
Transparent mode with inline bypass enabled
Inline deployment mode with fail-open enabled
Routed mode with asymmetric routing tolerance
Passive deployment mode using a SPAN or tap source
Passive mode receives mirrored traffic via SPAN/TAP and operates entirely out-of-band without interfering with the live traffic path.
You are configuring an active/standby High Availability pair for Cisco Secure Firewall Threat Defense using FMC. You need to configure port channels for the data interfaces to increase bandwidth and redundancy. Which guideline must be followed regarding port channels in an HA deployment?
LACP active mode is unsupported on HA secondary units; static port channels must be used instead.
Port channels are restricted to transparent mode HA configurations only.
The port channel interfaces on both the primary and secondary units must have identical interface IDs and member port compositions.
HA units require symmetrical configurations, meaning port channels and their physical members must match precisely on both devices.
Port channels can only be configured on the active unit; the standby unit automatically inherits them via stateful sync.
An engineer has deployed a Cisco Secure Firewall Threat Defense in transparent firewall mode. Users on the inside segment report they cannot reach a server on the outside segment. The engineer verifies that the BVI (Bridge Virtual Interface) has an IP address in the same subnet as the internal hosts and default gateway. What is a likely reason for traffic being dropped?
An EtherType access list is blocking the encapsulated traffic or ARP requests between the bridge groups.
Transparent firewalls pass IP traffic by default, but non-IP traffic or specific Layer 2 control protocols require EtherType rules, and proper ARP inspection/learning is necessary.
An explicit Access Control Policy rule is blocking the traffic, because transparent mode inspections still require standard ACP rules.
The security zones for the inside and outside interfaces are identical, causing an implicit intra-zone drop.
Dynamic routing protocols must be enabled on the BVI to advertise the transparent subnet upstream.
An enterprise network design incorporates Equal-Cost Multi-Path (ECMP) routing across two Cisco Secure Firewall Threat Defense units functioning independently in routed mode. What is the primary benefit of enabling ECMP on the firewalls?
It allows passive NGIPS interfaces to share inspection load without SPAN replication.
It pools the CPU and memory resources of both firewalls into a single logical cluster.
It enables the firewall to balance outbound traffic across multiple next-hop gateways using multiple equal-cost routes.
ECMP provides traffic load balancing across multiple equal-cost paths.
It synchronizes connection state tables across both independent firewalls for zero-loss failover.
Want more Deployment practice?
Practice this domainAn administrator successfully restores an FMC backup onto a freshly deployed FMC virtual appliance of the exact same software version. However, after the restore completes, all managed FTD devices show a status of 'Offline' or 'Config Apply Failed'. What is the most likely root cause and correct resolution?
The FTD management interface IP addresses must be manually changed to match the old FMC management subnet.
The administrator must run 'configure manager add' on the FMC CLI to force an SNMP trap listener.
The new FMC has a different system UUID and Internal Certificate Authority keys; the administrator must re-establish trust by re-registering the FTD devices using new registration keys.
Restoring to a new appliance generates a new appliance ID/CA, breaking the secure registration channel until re-established.
The FTD devices automatically wipe their configurations when an FMC backup is restored; the administrator must factory reset every FTD.
An administrator needs to troubleshoot a routing issue on an FTD device managed by FMC. Where in the FMC GUI should the administrator navigate to view and modify static and dynamic routing configurations for the device?
Objects > Object Management > Network > Routes
Devices > Device Management > Edit Device > Routing tab
Device-specific settings like static routes, OSPF, and BGP are configured under the Routing tab of the device settings.
System > Configuration > Network Settings
Policies > Access Control > Routing
An FTD device is dropping packets unexpectedly. An engineer runs a packet tracer via the FTD diagnostic CLI using 'system support diagnostic-cli' and enters the command: 'packet-tracer input inside tcp 192.168.1.50 12345 10.0.0.5 80'. The output shows a drop at the 'Access-Rule' phase with the action 'DROP'. What does this indicate?
The NAT translation table lacks a dynamic PAT port allocation for the source IP.
An Access Control Policy rule matched the connection parameters and was configured with an action of Block or Block with reset.
The Access-Rule phase evaluates ACP rules; a drop here means an explicit blocking rule matched.
The FTD routing table does not have a valid route back to the source IP 192.168.1.50.
The SSL decryption policy failed to validate the server certificate for 10.0.0.5.
An administrator notices that the Firepower Management Center (FMC) health monitor shows a critical warning regarding high disk utilization on the /var partition. Which built-in utility or action should the administrator perform first to safely free up disk space without disrupting critical database integrity?
Reboot the FMC appliance into single-user mode and execute a complete filesystem format on the /var partition.
Use the FMC GUI to delete unneeded packet captures and older correlation event logs or prune event data via System > Health > Monitor.
Pruning old event data or removing stale packet captures directly reduces the /var disk utilization safely.
Navigate to System > Integration > Snort and delete all historical rule inspection data.
Run the 'rm -rf /var/sf/imagedb/*' command directly from the expert mode CLI to purge immediate image databases.
During a routine backup of the FMC, the administrator wants to ensure that the generated backup file contains critical historical events, configurations, and intrusion event data so that it can be fully restored to a replacement appliance if necessary. Which backup type should be selected in the FMC?
Manual Backup with both System Settings and Historical Event Data checkboxes enabled
Selecting both settings ensures configuration and event tables are preserved in the backup tarball.
RAID Controller Configuration Export
System Configuration Backup only
Snort Rule Update (SRU) Snapshot Backup
An FTD device managed by FMC is experiencing high CPU utilization attributed to the Snort inspection engine. The administrator wants to identify which specific intrusion rules or access control rules are consuming the most resources. Which tool or report should the administrator use?
Run a packet capture on the management interface (eth0) with a BPF filter for CPU interrupts.
Access the FTD CLI and run 'system support diagnostic-cli' followed by 'show perfstats' or review the Intrusion Performance dashboard in FMC.
FMC Intrusion Performance dashboards and CLI perfstats provide granular details on rule processing overhead.
Navigate to Analysis > Datastores > Packet Trace and export the raw CPU register dump.
Check the Interfaces > Counters page in the Cisco Integrated Management Controller (CIMC).
Want more Management And Troubleshooting practice?
Practice this domainAn organization integrates Cisco Secure Firewall Threat Defense with Cisco SecureX (now Cisco Security Cloud Control / Cisco XDR) for threat intelligence and incident response. When investigating an indicator of compromise (IoC) on SecureX, an administrator triggers a block action for a malicious file hash. How is this block action enforced across the managed Secure Firewall Threat Defense devices?
SecureX uses NETCONF to directly modify the running configuration of the FTD data plane, bypassing the FMC.
The FTD devices poll Cisco SecureX directly every 60 seconds via secure syslog to retrieve updated file hashes.
The action requires the administrator to manually export a Snort rule from SecureX and import it into the FMC Advanced Malware Protection (AMP) policy.
The FMC receives the SecureX API notification and automatically pushes an update to the Security Intelligence Blacklist and File Control policies on the FTD.
SecureX communicates via the FMC API to dynamically update blocklists and intelligence feeds on the managed firewalls.
An administrator configures Cisco Secure Firewall Threat Defense to send connection logs to a syslog server. However, the syslog server receives logs with source IP addresses belonging to the FMC management interface rather than the FTD data interface IP address. What is the correct way to ensure syslog messages are sent directly from the FTD data or management interface as intended?
Configure a NAT exemption rule on the FTD to prevent translation of syslog traffic destined for the SIEM.
Modify the Snort engine configuration file via Expert Mode to rewrite the source IP of exported syslog packets.
Enable 'Reliable Syslog' under System > Preferences on the FMC.
Configure the specific syslog server settings under Platform Settings > Syslog on the FMC and designate the desired egress interface for alert generation.
Platform Settings allow specifying the source interface and routing parameters for syslog export from FTD.
An administrator wants to stream security events, connection events, and intrusion events from Cisco Secure Firewall Management Center (FMC) to a third-party SIEM platform. Which built-in protocol and feature on the FMC should be configured to export these events in real-time?
pxGrid
NETCONF
eStreamer
eStreamer is the native FMC feature used to stream event data to third-party SIEM and management platforms.
RADIUS Accounting
An administrator is integrating Cisco Secure Firewall Threat Defense with Cisco Identity Services Engine (ISE) using Platform Exchange Services (pxGrid). Which service must be enabled and running on the ISE nodes for pxGrid communication to succeed?
IPAM Synchronization Service
RADIUS Accounting Service
Cisco pxGrid Service
The pxGrid service is explicitly required on ISE for sharing context with external systems like Secure Firewall.
TACACS+ Authentication Service
A network security engineer configures Cisco Secure Firewall Threat Defense to ingest Security Group Tags (SGTs) from Cisco ISE via pxGrid. The integration is active, and SGTs are successfully mapped to IP addresses. However, access control rules referencing Security Group Tags fail to match traffic originating from authenticated endpoints. What is the most likely cause of this behavior on FTD?
Cisco Secure Firewall Threat Defense does not support enforcement of SGTs learned via pxGrid; it only supports SXP.
The TrustSec SXP peering is not configured between the FTD and the authenticator switch, causing the firewall data plane to drop or ignore inline SGT headers.
If SXP or inline TrustSec is missing along the data path, the firewall does not receive the SGT metadata embedded or mapped in the packets.
The Identity Source Sequence on ISE must include Active Directory LDAP bindings specifically for FTD rule evaluation.
The FMC requires a manual restart of the Snort detection engine every time a new SGT is learned via pxGrid.
An administrator is integrating Cisco Secure Firewall Threat Defense with Cisco Identity Services Engine (ISE) using pxGrid. During the initial connection phase, the Secure Firewall is stuck in a 'Connecting' state and fails to download user-to-IP mapping. Where should the administrator check the pxGrid client status and troubleshoot the registration certificate handshake on the Secure Firewall CLI?
Run the command 'show pxgrid status' and 'show crypto ca certificates' in the FTD expert mode or CLI.
These commands verify the operational status of the pxGrid agent and the validity of the certificates exchanged between the firewall and ISE.
Inspect the 'estreamer.log' file on the FMC to view ISE pxGrid heartbeat failures.
Run 'show ise identity source' on the FMC CLI to confirm active pxGrid threads.
Check the Platform Settings policy under 'Cisco Identity Services Engine' and review the 'show sgt-mapping' command.
Want more Integration practice?
Practice this domainThe 300-710 SNCF exam has 200 questions and must be completed in 120 minutes. Cisco passing scores vary by exam version and are not always publicly listed. Check the official Cisco exam page before booking.
CLI output interpretation, network topology analysis, routing behaviour, switching concepts, troubleshooting, and configuration questions.
The exam covers 4 domains: Configuration, Deployment, Management And Troubleshooting, Integration. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official Cisco 300-710 SNCF exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.