Sample questions
Cisco Securing Networks with Cisco Firewalls (300-710 SNCF, CCNP Security) (300-710 SNCF) practice questions
You are configuring SSL decryption. To ensure that traffic to a specific financial domain is NOT decrypted due to privacy regulations, what must you configure in the SSL Decryption…
An administrator is configuring a Manual NAT rule in the FMC for an internal server that needs to be accessed from the outside zone. The internal IP is 192.168.1.50, and it must be…
Which type of object is best suited for defining a web server's public-to-private NAT mapping?
How do you ensure that a specific host object is only used in a specific interface?
An administrator is configuring a new Access Control Policy on the Firepower Management Center and needs to add a rule that blocks peer-to-peer file sharing applications regardless…
An administrator is setting up a new Cisco Firepower Threat Defense device and needs to configure platform-level parameters using FMC Platform Settings. Which TWO features can be c…
Which THREE settings can be configured within a Prefilter Policy on the FMC? (Choose three)
Which THREE components of an Access Control rule can be used to identify traffic as 'Application' based?
An enterprise requires FTD to decrypt outbound SSL/TLS traffic so internal users visiting external websites can be inspected by Snort for malware. Which policy and action combinati…
An administrator needs to create a variable set to define specific port or network variables used within Intrusion Rules. Where are variable sets managed in the FMC?
An administrator wants to create a Prefilter policy to fast-path (bypass Snort inspection for) a trusted backup stream between two data centers. Which action type should be selecte…
An administrator wants to decrypt inbound HTTPS traffic destined for a public web server behind a Firepower Threat Defense device. Which type of SSL/TLS decryption policy must be c…
An engineer is configuring a QoS policy on an FMC-managed FTD and needs to police traffic to a maximum bandwidth limit on an interface. Which shaping/policing parameter must be con…
An administrator configures an Identity Policy on the FMC to authenticate users via Active Directory using captive portal. Where is the Identity Policy applied within the Firepower…
An administrator configures a security intelligence feed in the FMC to block known malicious IP addresses. Where are Security Intelligence feeds and lists applied in the FMC config…
An administrator needs to configure manual NAT on an FTD device to translate both the source IP and source port of outbound packets originating from 192.168.2.50 to a specific publ…
An administrator configures an SSL Decryption Policy with a rule to 'Do Not Decrypt' financial traffic. However, the administrator also wants to ensure that the encrypted session s…
An administrator is configuring Security Intelligence in FMC. Which TWO types of objects can be added to Security Intelligence blacklists or whitelists? (Choose two)
An administrator wants to group multiple existing port objects (e.g., TCP 80, TCP 443, TCP 8080) into a single object for use in Access Control Policy rules. Which object container…
An administrator needs to configure an identity policy to authenticate users using an external RADIUS server via Passive Authentication. Which mechanism accomplishes passive user i…
Which THREE criteria can be used to match traffic within an Access Control rule on the FMC? (Choose three)
An administrator wants to create a Port object group containing TCP ports 80, 443, and 8080 on the FMC. Where is this object configured?
An administrator needs to create a Geolocation object in the FMC to block traffic originating from a specific country. Where is this object used?
An engineer wants to group several FTD interfaces into a single logical zone to simplify Access Control rule creation. Where are security zones created in the FMC?