300-710 SNCF Management And Troubleshooting Practice Question
An engineer suspects that asymmetric routing is causing packets to be dropped by the FTD firewall. Which command should the engineer run on the FTD CLI to check for dropped packets and view drop reasons in real time?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
system support firewall-engine-debug with tracing enabled
The command 'system support firewall-engine-debug' allows capturing packet flow and seeing exact drop reasons, but for real-time drop statistics, 'show asp drop' (inherited from ASA lineage) or examining packet tracer output is used. On FTD, packet tracing and drop debugs are standard.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
system support firewall-engine-debug with tracing enabled
Why this is correct
This utility allows tracing the packet through the inspection engine to identify exact drop points and reasons such as asymmetric routing.
- ✗
show snort statistics drops
Why it's wrong here
Snort statistics show inspection queue drops, not firewall engine security state drops.
- ✗
debug crypto ipsec
Why it's wrong here
This is strictly for VPN tunnel debugging, not general firewall packet drops.
- ✗
show interface counters drops
Why it's wrong here
This only shows interface-level hardware drops, not firewall engine security drops.
Quick reference
Asymmetric Encryption Algorithm Comparison
| Algorithm | Key Exchange | Signatures | Equivalent Security Key | Notes |
|---|---|---|---|---|
| RSA-3072 | Yes | Yes | 128-bit | Widely deployed; slow for bulk data |
| ECDSA P-256 | No | Yes | 128-bit | Fast signatures; standard TLS certs |
| ECDH / ECDHE | Yes | No | 128-bit | Perfect forward secrecy in TLS 1.3 |
| DH / DHE | Yes | No | 128-bit (3072-bit key) | Replaced by ECDHE in modern TLS |
| Ed25519 | No | Yes | ~128-bit | SSH keys, modern PKI |
About these practice questions
One of 478 original 300-710 SNCF practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official Cisco exam blueprint
This 300-710 SNCF practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-710 SNCF exam.