Courseiva

Cisco Securing Networks with Cisco Firewalls (300-710 SNCF, CCNP Security) (300-710 SNCF) (300-710 SNCF) — Questions 151225

478 questions total · 7pages · All types, answers revealed

Page 2

Page 3 of 7

Page 4
151
Multi-Selecthard

An administrator is troubleshooting an eStreamer client script failure where the connection is refused on port 8302. Which TWO potential causes should the administrator investigate? (Choose two)

Select 2 answers
A.An intermediate firewall or the FMC internal iptables firewall is blocking TCP port 8302 traffic.
B.The FTD Snort engine is out of memory.
C.The DHCP lease on the FTD data interface has expired.
D.The pxGrid certificate on ISE has expired.
E.The eStreamer service/daemon is not running or enabled on the FMC management plane.
AnswersA, E

Firewalls blocking port 8302 will prevent client connections from reaching the FMC eStreamer daemon.

Why this answer

Connection refused errors on port 8302 indicate that the eStreamer service is not running on the FMC or that network filtering/firewalls are blocking access to port 8302.

152
Multi-Selecthard

An administrator wants to configure Access Control rules on Cisco Secure Firewall Threat Defense using identity context received from Cisco ISE via pxGrid. Which TWO criteria can be utilized in the Access Control policy rule configuration once pxGrid is fully integrated? (Choose two)

Select 2 answers
A.User names and User Groups
B.Security Group Tags (SGTs)
C.DHCP lease pool exhaustion percentages
D.OSPF neighbor adjacency states
E.MACsec encryption key lifetimes
AnswersA, B

User identities and group memberships passed from ISE via pxGrid can be used in Access Control rules.

Why this answer

Once pxGrid is integrated, Access Control rules can filter traffic based on user identities, user groups, and Security Group Tags (SGTs).

153
Multi-Selecthard

An administrator is analyzing a troubleshooting scenario involving Snort inspection crashes on an FTD device. Which THREE locations or tools should the administrator check to diagnose why the Snort process restarted or crashed? (Choose three)

Select 3 answers
A.Check the Cisco Smart Software Manager portal for license expiration alerts.
B.Inspect the DHCP lease logs in /var/log/dhcpd.log.
C.Examine /var/log/messages and system log files for Out-Of-Memory (OOM) killer events targeting Snort.
D.Review Snort runtime error logs located in /var/log/snort/ or via FMC health alerts.
E.Check for core dump files generated in the crash directories using 'system support clean-core' or expert mode listing.
AnswersC, D, E

OOM killer logs in /var/log/messages indicate if the kernel terminated Snort due to high memory consumption.

Why this answer

Snort crashes leave traces in /var/log/messages, core dump directories (/var/crash or specific core locations), and Snort specific log files in /var/log/snort/.

154
MCQhard

An organization integrates Cisco Secure Firewall Threat Defense with Cisco ISE via pxGrid. The security team notices that identity rules are matching incorrect users for traffic originating from shared Citrix terminal servers or Virtual Desktop Infrastructure (VDI) multi-user hosts. What mechanism must be enabled and configured to properly handle multi-user IP identity attribution on Secure Firewall?

A.Configuring SXP peers between the VDI hypervisor and the FMC.
B.Configuring static NAT overloading on the FTD egress interface.
C.Enabling SNMP polling on the VDI host so FMC can query active user sessions every 10 seconds.
D.Port-Based Identity mapping (or Terminal Services Agent integration) to correlate user sessions by source port in addition to IP address.
AnswerD

Standard IP-to-user mapping fails on shared IP hosts; port-based identity attribution uses source ports to distinguish between multiple concurrent users on the same IP.

Why this answer

For multi-user environments such as Citrix or VDI where multiple users share a single IP address, FTD and ISE must utilize Port-Based Allocation (or Terminal Services Agent / pxGrid multi-user session mapping with port multiplexing) to track user identity based on source ports.

155
Multi-Selecthard

An administrator is troubleshooting an eStreamer client connection between a Python script and the Cisco FMC. The script fails to authenticate. Which TWO items must be verified regarding the eStreamer client credentials? (Choose two)

Select 2 answers
A.Verify that the PKCS#12 certificate file and password/keys used by the client script match the credentials generated on the FMC.
B.Verify that the IP address of the client host matches the authorized IP address configured during eStreamer certificate generation on the FMC.
C.Verify the FTD Active Directory domain password.
D.Check the pxGrid client approval status on the Cisco ISE server.
E.Check the SNMPv3 community string on the FTD management interface.
AnswersA, B

Mutual TLS requires matching client certificates and private keys generated by the FMC.

Why this answer

eStreamer client authentication relies on the generated PKCS#12 certificate bundle and ensuring the client IP address is explicitly authorized in the FMC eStreamer configuration.

156
MCQhard

An administrator successfully restores an FMC backup onto a freshly deployed FMC virtual appliance of the exact same software version. However, after the restore completes, all managed FTD devices show a status of 'Offline' or 'Config Apply Failed'. What is the most likely root cause and correct resolution?

A.The FTD management interface IP addresses must be manually changed to match the old FMC management subnet.
B.The administrator must run 'configure manager add' on the FMC CLI to force an SNMP trap listener.
C.The new FMC has a different system UUID and Internal Certificate Authority keys; the administrator must re-establish trust by re-registering the FTD devices using new registration keys.
D.The FTD devices automatically wipe their configurations when an FMC backup is restored; the administrator must factory reset every FTD.
AnswerC

Restoring to a new appliance generates a new appliance ID/CA, breaking the secure registration channel until re-established.

Why this answer

When restoring an FMC backup to a new appliance, the Internal CA (Public/Private keys) changes unless it is a bare-metal restore using the exact same hardware UUID or proper registration re-establishment. Often, registration keys must be re-configured or mutual TLS certificates synchronized because the new FMC instance has a different registration identity.

157
MCQhard

An organization integrates Cisco Secure Firewall Threat Defense with Cisco SecureX (now Cisco Security Cloud Control / Cisco XDR) for threat intelligence and incident response. When investigating an indicator of compromise (IoC) on SecureX, an administrator triggers a block action for a malicious file hash. How is this block action enforced across the managed Secure Firewall Threat Defense devices?

A.SecureX uses NETCONF to directly modify the running configuration of the FTD data plane, bypassing the FMC.
B.The FTD devices poll Cisco SecureX directly every 60 seconds via secure syslog to retrieve updated file hashes.
C.The action requires the administrator to manually export a Snort rule from SecureX and import it into the FMC Advanced Malware Protection (AMP) policy.
D.The FMC receives the SecureX API notification and automatically pushes an update to the Security Intelligence Blacklist and File Control policies on the FTD.
AnswerD

SecureX communicates via the FMC API to dynamically update blocklists and intelligence feeds on the managed firewalls.

Why this answer

When an observable (such as a file hash or IP) is blocked via Cisco SecureX threat intelligence/threat response integration, the FMC receives the pivot or API call and automatically updates the Security Intelligence Blacklist or File Control policy objects on the managed FTD devices.

158
Multi-Selecthard

An administrator is planning a third-party SIEM integration with Cisco Secure Firewall Management Center. Which TWO methods or protocols are officially supported for exporting event data from the FMC to the SIEM? (Choose two)

Select 2 answers
A.eStreamer API / protocol over TCP port 8302
B.Exporting raw packet captures (PCAP) via FTP every 5 minutes
C.Syslog export (UDP or TCP/TLS) configured via FTD Platform Settings
D.Direct SQL database replication from the FMC internal PostgreSQL database over SSH
E.NetFlow v5 export from the FMC management interface
AnswersA, C

eStreamer is a primary supported method for streaming events to SIEMs.

Why this answer

FMC officially supports eStreamer for streaming structured security events and Platform Settings syslog for exporting syslog-formatted logs to third-party SIEMs.

159
Multi-Selecthard

Which THREE items are synchronized across an FTD high availability pair?

Select 3 answers
A.NAT tables.
B.Management interface IP.
C.Connection/Session states.
D.Physical interface counters.
E.Configuration policies.
AnswersA, C, E

Required to maintain existing sessions.

Why this answer

HA synchronization includes NAT tables, connection/session states, and the system configuration policies.

160
Multi-Selecthard

An engineer is troubleshooting a scenario where Security Group Tags (SGTs) are not being enforced by FTD access control rules despite an active pxGrid connection between ISE and FMC. Which TWO potential causes should the engineer investigate? (Choose two)

Select 2 answers
A.The FTD management interface IP address is not registered in Active Directory.
B.The FMC eStreamer service is disabled, blocking SGT updates.
C.SXP peering or inline TrustSec header propagation is missing along the data path between the endpoint and the FTD interface.
D.Syslog facility local0 is not configured on the switch.
E.The Access Control policy rules do not have the corresponding Security Group Tags selected under the Users/SGT tab.
AnswersC, E

Without SXP or inline TrustSec headers, the firewall data plane does not receive SGT metadata in the packets.

Why this answer

SGT enforcement requires proper SXP/inline propagation across data paths and correct Access Control rule configuration matching the tags.

161
MCQeasy

An administrator is deploying a new Cisco Secure Firewall Threat Defense device and needs to ensure that the firewall performs layer 3 routing while keeping the existing subnet architecture completely transparent to the upstream router. Which firewall mode must be selected during initial configuration?

A.Inline mode
B.Routed mode
C.Transparent mode
D.Passive mode
AnswerC

Transparent mode operates at Layer 2 and bridges traffic without changing subnet schemes.

Why this answer

In transparent mode, the firewall acts like a Layer 2 bridge. The upstream and downstream networks remain in the same subnet, making the firewall transparent to layer 3 routing.

162
MCQeasy

An FMC administrator needs to back up configuration data and event data for disaster recovery. Which backup type includes both system configurations and historical event data stored in the database?

A.Manual Backup with Event Data option selected
B.Health Monitor Export
C.Datastore Archive
D.System Backup
AnswerA

FMC allows administrators to include event data in manual system backups, though it is excluded by default due to size.

Why this answer

A manual or scheduled backup in FMC can be configured to include event data, but standard system backups typically separate configuration and events because event databases are extremely large. However, the system allows full backups that include event data when explicitly selected.

163
Multi-Selectmedium

An administrator is planning the deployment of Cisco Secure Firewall Virtual in a public cloud environment (AWS or Azure). Which TWO deployment practices are recommended for ensuring high availability and performance? (Choose two)

Select 2 answers
A.Deploy multiple virtual network interfaces (NICs) to separate management, internal, and external traffic paths.
B.Disable Smart Licensing to avoid cloud internet egress fees.
C.Use physical serial console cables attached to the hypervisor for initial configuration.
D.Rely solely on single-NIC deployments with VLAN subinterfaces trunking all cloud traffic.
E.Select an instance type and throughput license tier that aligns with expected cloud throughput demands.
AnswersA, E

Using multiple NICs isolates management and data traffic planes.

Why this answer

Cloud deployments require proper instance sizing, multiple NIC configurations for separating management and data planes, and cloud-native HA mechanisms.

164
MCQeasy

An administrator needs to schedule automated weekly backups of the FMC configuration and store them securely on a remote SCP server. Where is remote backup storage configured in the FMC GUI?

A.Devices > Device Management > Backup
B.System > Integration > SCP Servers
C.System > Tools > Backup / Restore > Remote Storage
D.Objects > Object Management > Servers > Backup
AnswerC

Remote storage destinations for backups are configured under the Backup / Restore menu.

Why this answer

Remote storage locations for backups (such as FTP, SFTP, SCP) are configured under System > Tools > Backup / Restore > Remote Storage Settings.

165
MCQmedium

An engineer is configuring Cisco eStreamer to stream events from FMC to a third-party SIEM. The firewall security policy blocks incoming connections on port 8302 from the SIEM server to the FMC. Which device and interface are involved in listening for the eStreamer client connection?

A.The FTD data interface listening on TCP port 8302.
B.The FTD management interface listening on UDP port 514.
C.The ISE pxGrid node listening on TCP port 8910.
D.The FMC management interface listening on TCP port 8302.
AnswerD

eStreamer runs on the FMC and listens on TCP port 8302 on the management interface.

Why this answer

The eStreamer server process runs on the Cisco Secure Firewall Management Center (FMC), listening on TCP port 8302 on its management interface.

166
Multi-Selecthard

An administrator is designing a logging architecture where Cisco Secure Firewall Threat Defense exports connection and intrusion events to a third-party SIEM. Which TWO design principles should be followed to ensure security and scalability? (Choose two)

Select 2 answers
A.Disable all Access Control rule logging and enable eStreamer over unencrypted TCP port 8302.
B.Rely exclusively on FMC database storage without exporting events to any SIEM.
C.Implement Reliable Syslog (TCP/TLS) to ensure encrypted transmission and prevent packet loss during network congestion.
D.Configure all logs to be exported unencrypted via UDP port 514 across the internet.
E.Configure appropriate severity filters to prevent low-priority debug events from overwhelming SIEM storage and ingestion licenses.
AnswersC, E

TCP with TLS guarantees delivery and protects log data in transit.

Why this answer

SIEM logging design requires leveraging reliable transport (TCP/TLS) to prevent packet loss and implementing event filtering to manage log volume effectively.

167
MCQeasy

During a routine backup of the FMC, the administrator wants to ensure that the generated backup file contains critical historical events, configurations, and intrusion event data so that it can be fully restored to a replacement appliance if necessary. Which backup type should be selected in the FMC?

A.Manual Backup with both System Settings and Historical Event Data checkboxes enabled
B.RAID Controller Configuration Export
C.System Configuration Backup only
D.Snort Rule Update (SRU) Snapshot Backup
AnswerA

Selecting both settings ensures configuration and event tables are preserved in the backup tarball.

Why this answer

FMC provides 'Manual Backup' configurations where administrators can select components. To include configuration and event data, a manual backup profile must be created with both System Configuration and Event data selected.

168
Multi-Selectmedium

Which TWO of the following are valid high availability modes for FTD?

Select 2 answers
A.Active/Active (non-clustered).
B.Failover-on-demand.
C.Active/Standby.
D.Clustering.
E.Load-Balanced Passive.
AnswersC, D

Standard failover mode.

Why this answer

FTD supports active/standby and clustering for high availability.

169
MCQmedium

A network engineer is deploying a Firepower Threat Defense (FTD) device and must configure NAT to translate an internal server IP of 10.10.10.50 to a public IP of 203.0.113.50 while preserving the original source port for inbound traffic. Which NAT type accomplishes this?

A.Manual Static NAT
B.Auto NAT (Dynamic PAT)
C.Manual Identity NAT
D.Auto NAT (Static Patched)
AnswerA

Manual NAT provides granular control, allowing static IP translation with port preservation options for inbound traffic.

Why this answer

Manual Static NAT allows the translation of a specific internal IP to a specific external public IP while supporting port translation and preservation options.

170
MCQeasy

In which mode does the FTD firewall act as a Layer 3 hop and perform NAT?

A.Passive mode
B.Inline mode
C.Routed mode
D.Transparent mode
AnswerC

Routed mode supports Layer 3 functions including NAT.

Why this answer

Routed mode is the standard deployment mode where the FTD operates as a Layer 3 device and supports NAT and routing protocols.

171
MCQmedium

An administrator is troubleshooting a policy deployment failure from the Firepower Management Center (FMC) to a managed Firepower Threat Defense (FTD) device. The deployment hangs at 33 percent with an error related to snort synchronization. Which tool should the administrator use on the FTD CLI to examine the real-time Snort rule compilation and policy application process?

A.Expert mode and check /var/log/pm/pm.log and Snort startup logs
B.System Support Diagnostic (system support diagnostic)
C.show deploy-status
D.system support firewall-engine-debug
AnswerA

The process manager (pm) and Snort logs on the FTD CLI show exact synchronization and compilation errors during deployment.

Why this answer

The system support ftw command or tailing the /var/log/messages and /var/log/pm/pm.log files along with examining snort compilation logs provides deep insight into deployment failures. Specifically, monitoring the deployment task manager and pm logs reveals why snort synchronization hangs.

172
MCQhard

An administrator is configuring static route tracking on a Cisco Secure Firewall Threat Defense deployment to handle link failure. If the tracked object goes down, the static route should be removed from the routing table. Where is this configuration managed when using Cisco FMC?

A.Under Devices > Device Management > Routing > Static Route, by editing the route and selecting a Monitor Track object.
B.Under Policies > Access Control > Routing Policies, by enabling SLA tracking hooks.
C.Under System > Configuration > High Availability > Route Tracking.
D.Under Objects > Object Management > SIEM > Route Track.
AnswerA

FMC allows administrators to link a static route directly to a tracked object (such as an ICMP or TCP ICMP Echo SLA) inside the Static Route configuration dialog.

Why this answer

Static route tracking in FMC is managed under Devices > Device Management > Routing > Static Route, where you associate an IP SLA Monitor object or Track object to a specific static route entry.

173
Multi-Selecthard

An administrator is preparing an upgrade plan for an FMC and its managed FTD devices. Which THREE best practices should be followed during the upgrade process to minimize downtime and avoid failure? (Choose three)

Select 3 answers
A.Take a complete backup of the FMC and export device configurations prior to starting the upgrade.
B.Always upgrade the FMC to the target version before upgrading any managed FTD devices.
C.Run the pre-upgrade checker script/package on the devices to identify potential blockers.
D.Factory reset all FTD devices immediately after pushing the upgrade package.
E.Disable the sftunnel service permanently during the upgrade to prevent packet inspection.
AnswersA, B, C

Backups ensure recovery capability if an upgrade fails.

Why this answer

Best practices include reading release notes for upgrade paths, taking backups before upgrading, running pre-upgrade checkers, and upgrading FMC before FTD devices.

174
MCQeasy

Which interface configuration mode allows the FTD to handle traffic across multiple physical links as a single logical interface?

A.Redundant Interface
B.Bridge Group
C.Sub-interface
D.Port Channel
AnswerD

Port channel aggregates links.

Why this answer

A Port Channel (or EtherChannel) aggregates multiple physical interfaces into one logical bundle.

175
Multi-Selecthard

You are configuring High Availability for two FTD devices. Which TWO conditions must be met for a successful failover state? (Choose two)

Select 2 answers
A.The failover link must be connected to a public-facing switch.
B.The devices must use different management IP addresses.
C.The standby unit must have a higher priority value than the active unit.
D.The devices must be running the exact same version of FTD software.
E.The devices must use different serial numbers.
AnswersB, D

Each unit in an HA pair requires its own management IP address.

Why this answer

FTD failover requires identical hardware/software and specific link configuration for state synchronization.

176
Multi-Selecthard

An administrator is configuring Cisco ISE pxGrid integration with Cisco Secure Firewall Management Center. Which TWO identity sources or methods supported by ISE can provide context that is subsequently consumed by FTD via pxGrid? (Choose two)

Select 2 answers
A.Raw NetFlow v5 packet streams exported directly from core routers to the FMC
B.Guest WebAuth portal authentications
C.Active Directory / LDAP authentications via 802.1X or RADIUS
D.Local FTD administrator CLI login sessions
E.DHCP server static lease table text files imported manually into FMC
AnswersB, C

Guest users authenticated through ISE portals have their identity context published via pxGrid.

Why this answer

ISE gathers identity context from 802.1X/RADIUS authentications, passive identity collectors, and web authentication portals, publishing them via pxGrid.

177
MCQhard

During an upgrade of an FTD device managed by FMC, the pre-checks fail because of insufficient disk space in the target upgrade partition. Which CLI command sequence should the administrator use to safely clean up previous upgrade installation files and temporary packages?

A.system support upgrade-purge
B.expert mode followed by apt-get clean
C.rm -rf /var/sf/upgrade/*
D.system support installer cleanup
AnswerD

This command safely purges old upgrade installers and temporary files to reclaim space for new upgrades.

Why this answer

FTD upgrade installation packages are stored in specific directories. The command 'system support installer cleanup' is the built-in utility designed to safely remove leftover upgrade files and temporary install artifacts.

178
MCQmedium

Which object type should be used to represent a group of network subnets?

A.Host
B.Range
C.Port Group
D.Network Group
AnswerD

Best for grouping subnets.

Why this answer

A Network Group object allows you to aggregate multiple network subnets into a single object for policy efficiency.

179
Multi-Selecteasy

Which THREE items are required to create a port channel on an FTD device?

Select 3 answers
A.A static route to the port channel
B.LACP configuration
C.Two or more physical interfaces
D.A physical bypass module
E.A logical Port-Channel interface
AnswersB, C, E

LACP negotiates the aggregation between devices.

Why this answer

A port channel requires multiple physical interfaces, a logical port-channel interface ID, and the LACP protocol settings.

180
Multi-Selectmedium

Which TWO of the following are valid reasons to use Transparent Mode?

Select 2 answers
A.To increase throughput by ignoring L3 headers.
B.To act as a Layer 3 gateway.
C.To enable dynamic routing.
D.Simplified L2 insertion.
E.Network address transparency.
AnswersD, E

It acts as a bump-in-the-wire.

Why this answer

Transparent mode is used when you cannot change the IP addressing scheme of the network and when you need to insert security without routing changes.

181
Multi-Selecthard

When considering virtual FTD deployments, which THREE factors significantly impact the performance of the instance?

Select 3 answers
A.The number of configured Access Control Rules
B.The amount of provisioned RAM
C.The number of active management sessions
D.The type of virtual network adapter
E.Number of allocated CPU cores
AnswersB, D, E

RAM is critical for the FTD state table and packet buffer.

Why this answer

Performance in virtual FTD is constrained by hardware resources like CPU cores, RAM, and the efficiency of the virtual network adapter.

182
MCQeasy

Which type of FTD interface should be configured to connect to a trunk port on a switch?

A.Physical interface without a VLAN ID.
B.Management interface.
C.Port channel interface.
D.Sub-interface with a VLAN tag.
AnswerD

VLAN tagging is defined via sub-interfaces.

Why this answer

A sub-interface, when assigned a specific VLAN ID, is used to process traffic on a trunked link.

183
Multi-Selecteasy

Which TWO interface modes are available when configuring an intrusion prevention (NGIPS) security policy on a Cisco Secure Firewall Threat Defense device? (Choose two)

Select 2 answers
A.Bridged Layer 4 mode
B.NAT-patrolled mode
C.Inline mode
D.Promiscuous trunk mode
E.Passive mode
AnswersC, E

Inline mode allows the NGIPS engine to inspect traffic and drop malicious packets in real-time.

Why this answer

NGIPS policies on FTD can be deployed using inline mode (to inspect and drop traffic) or passive mode (to monitor and log traffic without dropping).

184
MCQhard

When using clustering with FTD, what is the 'Flow Owner' in the context of traffic distribution?

A.The master unit that manages the configuration.
B.The unit that maintains the connection state for a specific flow.
C.Any unit that has the highest CPU availability.
D.The unit that performs the SSL decryption for the flow.
AnswerB

Ownership ensures stateful inspection consistency across the cluster.

Why this answer

In a cluster, the Flow Owner is the specific unit that has received the initial TCP SYN for a connection and is responsible for all subsequent packets in that flow to ensure consistency.

185
Multi-Selecthard

An administrator is configuring Cisco Secure Firewall Threat Defense to send syslog messages to a SIEM. Which TWO settings in Platform Settings determine how syslog messages are formatted and transmitted? (Choose two)

Select 2 answers
A.Syslog server transport protocol (UDP or TCP/Reliable Syslog)
B.The SecureX API integration client ID
C.Syslog severity levels and event category logging filters
D.The eStreamer client certificate bundle password
E.The ISE pxGrid node IP address
AnswersA, C

Transport protocol selection is configured within Platform Settings.

Why this answer

Platform Settings allow configuring message severity filters, transport protocol (UDP/TCP), and header formatting options.

186
MCQeasy

An administrator wants to create a Port object group containing TCP ports 80, 443, and 8080 on the FMC. Where is this object configured?

A.Policies > Access Control > Ports
B.Devices > Device Management > Object Explorer
C.Objects > Object Management > Ports
D.System > Configuration > Port Groups
AnswerC

Port objects and port object groups are managed under Objects > Object Management > Ports.

Why this answer

Port object groups and individual ports are created under Objects > Object Management > Ports.

187
MCQhard

An enterprise integrates Cisco Secure Firewall Management Center with Cisco ISE via pxGrid. The security team wants to ensure that when an administrator quarantines a host in Cisco SecureX, the firewall immediately drops active connections from that host without waiting for the FMC policy deployment cycle. How does SecureX achieve immediate enforcement on FTD?

A.SecureX sends an SNMP set command directly to the FTD data interface kernel.
B.ISE forces the FTD to reboot into maintenance mode to clear active states.
C.The FTD polls the SecureX cloud API every 1 second, causing high CPU usage.
D.SecureX uses the FMC REST API to dynamically push runtime block instructions that take effect immediately without requiring a full policy deployment.
AnswerD

SecureX leverages FMC APIs for rapid threat containment, applying runtime blocks directly to FTD without a full deployment.

Why this answer

When an immediate mitigation action (such as blocking an IP or domain) is triggered from SecureX, SecureX utilizes the FMC REST API to dynamically inject a transient block or update Security Intelligence runtime blacklists on the FTD data plane instantly, bypassing the lengthy full policy deployment cycle.

188
Multi-Selecthard

Which THREE considerations must be addressed when deploying FTDv in a public cloud?

Select 3 answers
A.Integration with cloud route tables for failover.
B.VPC security group constraints.
C.Cloud-specific instance sizing.
D.Hardware bypass capabilities.
E.Clustering using local control links.
AnswersA, B, C

Required for traffic redirection.

Why this answer

Cloud deployments require API-based routing, specific instance sizing, and VPC-level security group awareness.

189
Multi-Selectmedium

When deploying Cisco Secure Firewall Threat Defense in transparent mode, which TWO operational characteristics or restrictions apply to the deployment? (Choose two)

Select 2 answers
A.Every physical interface must be configured with a unique public routable IP address.
B.The firewall must act as the primary DHCP server for all downstream VLANs.
C.The firewall bridges traffic at Layer 2 between interfaces belonging to the same BVI bridge group.
D.Network Address Translation (NAT) is fully supported for changing IP addresses across interfaces.
E.Dynamic routing protocols like OSPF and RIP cannot run across transparent firewall interfaces.
AnswersC, E

Transparent mode bridges Layer 2 traffic across BVI members.

Why this answer

Transparent firewalls operate at Layer 2, bridge traffic using BVIs, do not support dynamic routing protocols, and require management IP addresses for the bridge group.

190
MCQeasy

Which protocol is utilized by Cisco Secure Firewall Management Center and FTD devices to communicate with Cisco SecureX for cloud-delivered threat intelligence?

A.SNMPv2c
B.HTTPS (REST API over port 443)
C.TFTP
D.Syslog over UDP 514
AnswerB

Cloud integrations and SecureX communication rely on secure HTTPS REST APIs.

Why this answer

Cisco SecureX and cloud services communicate with Cisco Secure Firewall Management Center using REST APIs over HTTPS (port 443).

191
MCQeasy

A security engineer is deploying a Cisco Secure Firewall Threat Defense device inline in front of a critical server farm. The goal is to inspect all incoming and outgoing traffic for intrusions without modifying the IP addressing schema of the servers. Which interface mode should be configured on the FTD device?

A.Passive mode
B.Inline mode with a bypass capability
C.SPAN mode
D.Promiscuous mode
AnswerB

Inline mode evaluates traffic passing directly through the interface pair and can drop malicious payloads.

Why this answer

Inline mode places the firewall directly in the path of traffic, allowing it to inspect, drop, or modify packets while operating transparently or via routed configurations.

192
Multi-Selectmedium

When troubleshooting FTD policy deployment, which THREE of the following are common reasons for a deployment to fail?

Select 3 answers
A.Insufficient memory on the FTD
B.Invalid license keys for third-party integrations
C.Configuration conflicts in the policy
D.Incorrect browser version on the client
E.Loss of connectivity between FMC and FTD
AnswersA, C, E

Heavy policies may exceed available memory during compilation.

Why this answer

Resource constraints, connectivity issues, and configuration conflicts are the most frequent causes of failed deployments.

193
MCQeasy

You are configuring static route tracking on an FTD device. What is the primary purpose of this configuration?

A.To load-balance traffic across ISPs.
B.To increase the throughput of the interface.
C.To dynamically adjust the MTU of the link.
D.To ensure traffic is only routed through a verified path.
AnswerD

Tracking ensures the gateway is alive before using the route.

Why this answer

Static route tracking allows the firewall to monitor the availability of a path using ICMP or other probes and remove the route from the routing table if the probe fails.

194
Multi-Selectmedium

Which TWO fields are commonly used in the 'NAT Rule' editor to define the source address?

Select 2 answers
A.Destination Port
B.Translated Source
C.Original Source
D.Access List
E.Interface Group
AnswersB, C

The address after translation.

Why this answer

NAT rules use 'Original Source' and 'Translated Source' fields to define the address translation logic.

195
MCQeasy

When deploying a Cisco Secure Firewall Threat Defense in transparent mode, how are the firewall interfaces configured to pass traffic between segments without routing?

A.Interfaces are grouped into a Bridge Virtual Interface (BVI) bridge group that acts as a Layer 2 bridge.
B.Interfaces are configured with dynamic NAT overload to translate Layer 2 MAC addresses into Layer 3 IPs.
C.The firewall acts as an 802.1Q trunk port where all VLANs are terminated on a single subinterface.
D.Each physical interface is assigned a distinct IP address in the same subnet.
AnswerA

Transparent firewalls use BVIs to bridge traffic at Layer 2 across interfaces.

Why this answer

In transparent mode, the firewall bridges traffic between interfaces using a Bridge Virtual Interface (BVI). The BVI is assigned an IP address for management and Layer 3 functions, while the physical interfaces belong to the bridge group.

196
MCQhard

An FTD device is deployed in routed mode with multiple security zones. An administrator needs to configure an Access Control rule that evaluates traffic flowing between two different security zones. How are security zones utilized in the rule?

A.Security zones replace IP address objects entirely in all rule configurations.
B.Security zones are used exclusively in NAT translation rules.
C.Security zones are selected under the Zones tab of an Access Control rule as Source and Destination.
D.Security zones are assigned globally in device platform settings, not in access rules.
AnswerC

Rules use Source and Destination Zones to match traffic traversing between specific interface groups.

Why this answer

Security zones are groupings of interfaces referenced as source and destination zones within Access Control rules.

197
MCQmedium

An administrator configures Cisco Secure Firewall Threat Defense to send connection logs to a syslog server. However, the syslog server receives logs with source IP addresses belonging to the FMC management interface rather than the FTD data interface IP address. What is the correct way to ensure syslog messages are sent directly from the FTD data or management interface as intended?

A.Configure a NAT exemption rule on the FTD to prevent translation of syslog traffic destined for the SIEM.
B.Modify the Snort engine configuration file via Expert Mode to rewrite the source IP of exported syslog packets.
C.Enable 'Reliable Syslog' under System > Preferences on the FMC.
D.Configure the specific syslog server settings under Platform Settings > Syslog on the FMC and designate the desired egress interface for alert generation.
AnswerD

Platform Settings allow specifying the source interface and routing parameters for syslog export from FTD.

Why this answer

In Platform Settings > Syslog, administrators can define the syslog server configuration and explicitly select whether the syslog packets originate from the management interface or a specific data interface (Security Intelligence/Routing configuration).

198
Multi-Selecthard

Which THREE settings can be configured within a Prefilter Policy on the FMC? (Choose three)

Select 3 answers
A.Intrusion Policy signature tuning
B.FastPath action to bypass Snort inspection
C.Default Action for unmatched traffic (Analyze or FastPath)
D.Security Intelligence block lists
E.Tunnel rule handling (e.g., GRE, IPsec)
AnswersB, C, E

FastPath is a core prefilter action.

Why this answer

Prefilter policies support FastPath, Tunnel rules, and Default Actions (Analyze or FastPath).

199
MCQmedium

You are troubleshooting a port channel failure on an FTD device. The port channel is 'Up/Down'. What is the most likely cause?

A.Insufficient license.
B.The FTD is in transparent mode.
C.Mismatched LACP configuration.
D.Physical cable damage.
AnswerC

LACP mismatches prevent the logical bundle from becoming fully operational.

Why this answer

An 'Up/Down' status for a port channel usually indicates that LACP negotiation is failing between the FTD and the connected switch.

200
Multi-Selecthard

When deploying a Cisco Secure Firewall Threat Defense virtual appliance (FPRv) in a public cloud environment such as Microsoft Azure, which TWO architectural considerations or limitations must be accounted for? (Choose two)

Select 2 answers
A.User-Defined Routes (UDRs) in Azure must be configured to point traffic destined for other subnets to the FTDv internal interface IP.
B.A minimum of three distinct network interfaces (Management, Inside, and Outside) must be configured in Azure.
C.The FTDv management interface can be shared with the data plane traffic if bandwidth optimization is enabled.
D.Physical clustering using dedicated control interfaces is natively supported in Azure just like on-prem hardware.
E.Dynamic routing protocols (BGP/OSPF) are entirely unsupported on virtual appliances deployed in public clouds.
AnswersA, B

Azure virtual networks rely on User-Defined Routes to steer traffic through the virtual firewall appliance.

Why this answer

Azure deployments have specific constraints regarding throughput licensing models, interface requirements (Management, Inside, Outside), and lack of native support for certain on-prem features like traditional physical clustering.

201
Multi-Selecthard

An enterprise security architect is designing an architecture where Cisco Secure Firewall Threat Defense integrates with a third-party SIEM. Which THREE methods or protocols are officially supported for exporting security events and logs from the FMC/Firewall to the third-party SIEM? (Choose three)

Select 3 answers
A.Direct SQL database replication from the FMC internal PostgreSQL database to the SIEM
B.Cisco SecureX / REST APIs for programmatic event retrieval
C.Syslog (UDP/TCP/TLS) forwarding from Platform Settings
D.SNMPv1 trap forwarding of full packet payloads
E.eStreamer API for custom client integrations
AnswersB, C, E

REST APIs and SecureX integrations allow programmatic polling and event ingestion.

Why this answer

Supported methods for exporting events to third-party SIEMs include syslog, the eStreamer API, and Cisco SecureX/REST APIs.

202
MCQeasy

An administrator wants to export a packet capture (.pcap file) taken on an FTD interface directly from the FMC GUI for offline analysis in Wireshark. Where should the administrator navigate?

A.System > Tools > Packet Export
B.Policies > Access Control > Advanced > Packet Capture
C.Analysis > Captures or Devices > Device Management > Packet Capture
D.Objects > Object Management > Captures
AnswerC

FMC allows configuring, running, and downloading packet captures via the Device Management or Analysis capture menus.

Why this answer

Packet captures taken on FTD devices can be managed and downloaded directly from the FMC GUI under Analysis > Captures or Devices > Device Management > Packet Capture.

203
MCQmedium

An administrator is configuring Cisco Secure Firewall Threat Defense to send syslogs to a third-party SIEM. To ensure confidentiality of sensitive log data traversing untrusted network segments, how should the syslog export be configured?

A.Configure Reliable Syslog utilizing TCP with TLS encryption under Platform Settings > Syslog.
B.Configure HTTPS POST requests in the eStreamer client configuration.
C.Enable Secure Shell (SSH) port forwarding for UDP port 514.
D.Tunnel all UDP syslog packets inside an IPsec VPN tunnel terminated on the FMC management interface.
AnswerA

Reliable Syslog enables TCP transport with TLS encryption to protect syslog data in transit.

Why this answer

To secure syslog transmission, administrators configure Reliable Syslog, which uses TLS encryption over TCP (typically on TCP port 6514) between the FTD and the SIEM syslog collector.

204
MCQmedium

An FTD device is dropping packets unexpectedly. An engineer runs a packet tracer via the FTD diagnostic CLI using 'system support diagnostic-cli' and enters the command: 'packet-tracer input inside tcp 192.168.1.50 12345 10.0.0.5 80'. The output shows a drop at the 'Access-Rule' phase with the action 'DROP'. What does this indicate?

A.The NAT translation table lacks a dynamic PAT port allocation for the source IP.
B.An Access Control Policy rule matched the connection parameters and was configured with an action of Block or Block with reset.
C.The FTD routing table does not have a valid route back to the source IP 192.168.1.50.
D.The SSL decryption policy failed to validate the server certificate for 10.0.0.5.
AnswerB

The Access-Rule phase evaluates ACP rules; a drop here means an explicit blocking rule matched.

Why this answer

A packet tracer drop at the Access-Rule phase with a drop action indicates that an Access Control Policy rule matched the traffic and explicitly dropped or rejected it.

205
MCQeasy

An administrator is configuring Cisco Identity Services Engine (ISE) integration with Cisco Secure Firewall Threat Defense using TrustSec. Which protocol is primarily utilized to exchange Security Group Tags (SGTs) and SGs to IP mappings directly between the ISE policy service node and the firewall?

A.RADIUS
B.pxGrid
C.SXP
D.TACACS+ dACLs
AnswerC

SXP is the protocol used to propagate SGTs to devices that do not natively understand inline SGT tagging.

Why this answer

TrustSec SGTs and IP-to-SGT mappings are exchanged between ISE and the firewall utilizing the SGT Exchange Protocol (SXP).

206
MCQeasy

An administrator is configuring Cisco Secure Firewall Threat Defense to send connection and intrusion events to a third-party SIEM. Which protocol and port are natively supported by the eStreamer client integration for streaming events from the firewall?

A.TCP port 514 using standard Syslog
B.TCP port 9997 using Splunk Forwarder protocol
C.UDP port 443 using HTTPS
D.TCP port 8302 using the eStreamer API
AnswerD

eStreamer natively communicates over TCP port 8302 with authenticated and authorized clients.

Why this answer

The Cisco eStreamer (Event Streamer) daemon on Secure Firewall Threat Defense communicates with external clients over TCP port 8302, using a securely negotiated SSL/TLS connection.

207
Multi-Selecthard

An engineer is troubleshooting a packet capture configuration on an FTD device managed by FMC. Which THREE statements regarding FTD packet capture behavior and limitations are correct? (Choose three)

Select 3 answers
A.Packet captures can record up to 10 gigabytes of data directly into NVRAM.
B.Packet captures require a mandatory Access Control Rule permit entry for the captured traffic to be processed.
C.Packet captures on FTD capture decrypted payload content for IPsec traffic terminated on the firewall if specified with crypto options.
D.Packet captures can be configured to capture traffic on multiple interfaces simultaneously.
E.Packet capture buffers have a maximum size limit, and older packets are overwritten when the buffer fills up unless exported.
AnswersC, D, E

Capturing decrypted traffic or using specific filters allows viewing decrypted payloads on the terminating device.

Why this answer

FTD packet captures can capture ingress/egress, have buffer size limits, and can utilize access control lists or filters, but they cannot capture encrypted payload content post-decryption unless terminated on the box.

208
Multi-Selectmedium

Which THREE configuration settings must be verified on the FMC when troubleshooting syslog export issues to a third-party SIEM receiver? (Choose three)

Select 3 answers
A.Syslog server IP address and port configuration in Platform Settings
B.pxGrid client approval status in Cisco ISE
C.Protocol selection (UDP, TCP, or TLS) matching the SIEM collector capability
D.eStreamer client certificate validity
E.Access Control rule logging options enabled to log at beginning or end of connection
AnswersA, C, E

The destination IP and port must be correctly defined in Platform Settings.

Why this answer

Syslog troubleshooting involves verifying the destination server IP/port, the protocol (UDP/TCP), and ensuring that the appropriate Access Control rules or Platform Settings are configured to actually generate and send the logs.

209
MCQmedium

What is the purpose of 'Network Discovery' in FMC?

A.To push firmware updates
B.To configure routing protocols
C.To identify hosts and user activity
D.To perform active IPS scanning
AnswerC

It builds a map of network assets.

Why this answer

Network Discovery identifies hosts, applications, and operating systems on the network.

210
MCQhard

An FMC administrator is configuring a URL Filtering policy. They want to block URLs categorized as 'Hacking' while logging the event. Where is this configured within the Access Control Policy?

A.Objects > Object Management > URL Objects
B.Policies > SSL Decryption > URL Match criteria
C.Policies > Access Control > Access Control Policy > Rules > URLs tab
D.Devices > Device Management > URL Filtering Settings
AnswerC

URL category matching is configured directly in the URLs tab of an Access Control rule.

Why this answer

URL filtering configuration is embedded directly within Access Control rules under the URLs tab.

211
MCQhard

When configuring an NGIPS appliance in passive mode, how does the system handle traffic flow to ensure monitoring without impacting the production network?

A.It uses an inline set with a bypass feature enabled.
B.It drops malicious packets by sending TCP resets to the source.
C.It receives a copy of traffic via a SPAN or TAP port and performs out-of-band analysis.
D.It requires an EtherChannel configuration to load balance traffic.
AnswerC

Passive deployment relies on traffic mirroring.

Why this answer

Passive mode utilizes a TAP or SPAN port to ingest a copy of the traffic. It does not sit in the traffic path, meaning it cannot block traffic directly.

212
Multi-Selecthard

An administrator wants to ensure that all security event logs from Cisco Secure Firewall Threat Defense are exported reliably and in real time to external security analytics tools. Which TWO deployment and configuration practices should be implemented? (Choose two)

Select 2 answers
A.Rely solely on local FTD disk storage and export logs via manual SCP once a week.
B.Configure Reliable Syslog (TCP with TLS) in FTD Platform Settings to ensure encrypted and guaranteed log delivery.
C.Disable the Snort engine to prevent log buffer congestion.
D.Configure eStreamer on the FMC to stream intrusion, connection, and malware events to a SIEM collector.
E.Configure SNMPv1 traps to poll event counters every 60 seconds.
AnswersB, D

Reliable syslog prevents packet loss and encrypts logs in transit.

Why this answer

Reliable and real-time log export requires configuring both eStreamer for FMC-level event streaming and Reliable Syslog (TCP/TLS) for platform syslog export.

213
MCQhard

An administrator is troubleshooting an eStreamer integration where custom Python client scripts fail to receive events from the FMC. The administrator verifies that network connectivity, certificates, and user permissions are correct. Upon running the client script in verbose mode, the error indicates an 'Incompatible Protocol Version' between the client SDK and the FMC. How is this resolved?

A.Downgrade the FMC software to match the legacy eStreamer client library.
B.Update the eStreamer client SDK on the third-party SIEM to a version compatible with the current FMC software release.
C.Switch from eStreamer to legacy SNMP traps.
D.Modify the eStreamer version registry key in the FMC expert shell configuration file.
AnswerB

Client SDKs must be compatible with the FMC eStreamer server version to negotiate the protocol successfully.

Why this answer

Cisco FMC updates frequently include eStreamer protocol version upgrades. If an older third-party SIEM client SDK is used with a newly upgraded FMC, the client SDK must be updated to match or support the eStreamer protocol version running on the FMC.

214
MCQhard

You are configuring a NAT rule for a web server located in a DMZ. You want to translate the destination IP from a public address to the private DMZ address. Which NAT type is used?

A.Static NAT
B.Identity NAT
C.Manual NAT
D.Dynamic NAT
AnswerA

Static NAT handles the inbound one-to-one mapping.

Why this answer

Static NAT is used for inbound traffic translation where a public IP maps to a private internal server IP.

215
MCQhard

An administrator is deploying a Cisco Secure Firewall Threat Defense Virtual (FTDv) in Microsoft Azure. The architecture calls for a 3-NIC deployment (Management, Inside, and Outside). After deployment, asymmetric routing issues are observed because Azure Load Balancer is forwarding return traffic directly back to a different backend instance. What configuration must be applied to prevent asymmetric drops?

A.Enable Strict Asymmetric Routing Bypass mode in the FTDv Advanced Firewall Settings.
B.Disable the Azure UDR (User Defined Route) on the inside subnet.
C.Convert the FTDv deployment from routed mode to transparent mode.
D.Configure Source NAT (SNAT) on the FTDv so that traffic appears to originate from the firewall interface IP, ensuring symmetrical return paths.
AnswerD

Using SNAT ensures that return traffic from servers comes back to the firewall instance's IP address rather than directly to the client, preventing asymmetric routing drops.

Why this answer

Cloud deployments utilizing load balancers often require enabling SNAT (Source NAT) on the firewall so that return traffic flows back through the exact same firewall instance, preventing asymmetric drop behavior.

216
Multi-Selectmedium

An administrator is preparing to deploy Cisco Secure Firewall Threat Defense in passive NGIPS mode connected to a Catalyst switch. Which TWO configuration steps on the switch and firewall are necessary for successful packet inspection? (Choose two)

Select 2 answers
A.Configure the firewall data interfaces to operate in passive mode so they do not attempt to forward or drop traffic.
B.Enable dynamic OSPF routing between the switch and the firewall's passive interface.
C.Configure a SPAN (Switched Port Analyzer) or RSPAN session on the upstream switch to mirror traffic toward the firewall's passive interface.
D.Assign a default gateway IP address to the passive interface to route return packets back to clients.
E.Configure an inline set pairing the passive interfaces with a hardware bypass module.
AnswersA, C

Passive interfaces analyze traffic without forwarding or dropping.

Why this answer

Passive mode requires configuring a SPAN session (or TAP) on the switch to mirror traffic and configuring passive interfaces on the FTD to ingest and inspect that mirrored stream.

217
Multi-Selecteasy

An administrator wants to ensure that packet captures taken on an FTD can be analyzed easily. Which TWO ways can packet capture files (.pcap) be retrieved from the FMC? (Choose two)

Select 2 answers
A.Stream pcap files via SNMP traps to an NMS.
B.Download the .pcap file directly through the FMC GUI under Device Management > Packet Capture.
C.Email the raw binary capture automatically to Cisco Smart Licensing servers.
D.Automatically print the .pcap hex output to the connected serial console port line-by-line.
E.View captured packets in real-time or analyze summary statistics within the FMC web interface.
AnswersB, E

FMC provides a direct download link for completed packet capture files.

Why this answer

FMC allows administrators to download packet capture files directly through the GUI via Devices > Device Management > Packet Capture or view them in real-time.

218
MCQmedium

An administrator is configuring manual NAT and needs to specify an interface pair (Source Interface and Destination Interface). Why is defining interface objects important in manual NAT rules?

A.It replaces the need for security zones in Access Control policies.
B.It forces the FTD to convert the packet from Layer 2 to Layer 3.
C.It scopes the translation rule to specific ingress and egress interfaces, preventing unintended translations across other subnets.
D.It enables automatic routing table updates for the translated IP address.
AnswerC

Explicit interface specification ensures NAT only applies to traffic traversing those exact interfaces.

Why this answer

Interface specifications in manual NAT help define the directionality and scope of the translation (e.g., inside to outside).

219
MCQmedium

How do you enable 'High Availability' (HA) for an FTD pair managed by FMC?

A.Under Devices > Device Management
B.Under Policies > HA
C.Via the System > Configuration menu
D.In the Access Control Policy
AnswerA

HA is a device-level configuration.

Why this answer

HA is configured in the Device Management section by selecting two devices to pair.

220
MCQeasy

An administrator is configuring Access Control Policy rules on the FMC. The default action for unmatched traffic is currently set to Block. The requirement is changed so that unmatched traffic should pass through the FTD without inspection. Where is this setting modified?

A.In the platform settings policy assigned to the device
B.Under Objects > Object Management > Default Action
C.Inside the Prefilter policy configuration
D.At the bottom of the Access Control Policy rules page (Default Action setting)
AnswerD

The default action for traffic that matches no rules is set at the bottom of the ACP rules tab.

Why this answer

The default action of an Access Control Policy is configured at the bottom of the Access Control Policy rules table.

221
MCQmedium

An engineer is troubleshooting a stateful failover issue in a Cisco Secure Firewall Threat Defense Active/Standby high availability pair. The firewall units are passing data traffic, but failover state synchronization fails. Which dedicated interface must be verified for correct physical connectivity and configuration?

A.The Cluster Control Link (CCL)
B.The Management Interface (eth0)
C.The Failover and State Link
D.The Diagnostic Interface
AnswerC

The failover link and state link carry health checks and stateful session synchronization data between the units.

Why this answer

Stateful failover relies on the Failover Link (and optionally a Stateful Failover Link) to replicate connection tables, translation tables, and other stateful data between primary and standby units.

222
Multi-Selecthard

An engineer is troubleshooting a Cisco Secure Firewall Threat Defense clustering deployment where configuration synchronization between the control node and a data node has failed. Which THREE diagnostic steps or log sources should the engineer check? (Choose three)

Select 3 answers
A.Execute the 'show cluster info' and 'show cluster state' commands on the firewall CLI to verify node membership and sync status.
B.Verify physical connectivity, MTU settings, and packet loss on the Cluster Control Link (CCL) interface.
C.Check the BGP routing table on the core switch for missing Autonomous System path attributes.
D.Examine the FMC deployment task history and error logs to identify specific configuration push failures to the cluster nodes.
E.Review the VMware vCenter datastore utilization for disk space errors.
AnswersA, B, D

CLI cluster show commands provide real-time cluster health and membership details.

Why this answer

Troubleshooting cluster sync issues involves examining cluster health status via CLI commands (e.g., 'show cluster info'), reviewing FMC deployment history logs, and verifying Cluster Control Link connectivity.

223
MCQeasy

Which component in Cisco Secure Firewall architecture is responsible for generating Security Intelligence feeds and synchronizing them with Cisco SecureX threat intelligence?

A.The local DHCP server on the FTD
B.Cisco Identity Services Engine (ISE)
C.Cisco Secure Firewall Management Center (FMC)
D.Cisco DNA Center
AnswerC

FMC downloads and manages global threat intelligence feeds and distributes blacklists to FTD.

Why this answer

The Cisco Secure Firewall Management Center (FMC) downloads Security Intelligence feeds and cloud threat intelligence from Cisco SecureX and distributes them to the managed FTD devices.

224
Multi-Selecthard

When configuring manual NAT on an FTD device, which THREE options are available for configuring the Translated Source? (Choose three)

Select 3 answers
A.Specific IP Address or Network Object
B.Prefilter FastPath target
C.Security Intelligence blacklist feed
D.Dynamic IP Address Pool
E.Interface (Dynamic PAT)
AnswersA, D, E

Translating source to a static object or pool is supported.

Why this answer

Translated source options in manual NAT include Interface (PAT), Network/Host Object, and Dynamic Pool.

225
Multi-Selecteasy

Which TWO details are typically required when establishing a pxGrid connection between Cisco ISE and the Firepower Management Center? (Choose two)

Select 2 answers
A.Cisco ISE node IP address or hostname
B.RADIUS client shared secret for firewall authentication
C.pxGrid client certificate and password / shared secret setup
D.Active Directory Global Catalog server port (3268)
E.SNMP community string for the ISE Policy Service Node
AnswersA, C

The FMC needs to know the IP address or FQDN of the ISE pxGrid node to connect.

Why this answer

Setting up pxGrid requires the ISE server IP address/hostname and the shared secret or certificate configuration used during client registration.

Page 2

Page 3 of 7

Page 4

All pages

Practice 300-710 SNCF by domain

Target a specific domain to shore up weak areas.

See all domains with question counts →