Courseiva

300-710 SNCF · domain

Configuration

Practise Cisco Securing Networks with Cisco Firewalls (300-710 SNCF, CCNP Security) (300-710 SNCF) Configuration practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

128 questions28 easy55 medium45 hard

Focused practice

Practice Configuration questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Configuration

Configuration questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Configuration exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Configuration questions (128)

Click any question to see the full explanation, or start a practice session above.

1

An administrator configures DNS injection and rewriting in a manual NAT rule on an FTD device. What is the primary purpose of enabling DNS translation in a NAT rule?

Hard
2

An administrator is configuring Manual NAT on an FTD device. Which THREE parameters must be defined when creating a Manual Static NAT rule for inbound traffic? (Choose three)

Medium
3

When using the 'Search' feature in the Access Control Policy, which filter allows you to find all rules containing a specific network object?

Hard
4

When configuring an Access Control Policy on the FMC, what is the purpose of the Default Action set at the bottom of the rules table?

Easy
5

An administrator is configuring Security Intelligence feeds on the FMC. Which TWO types of objects or feeds can be used to populate Security Intelligence blacklists? (Choose two)

Easy
6

You need to map internal users to specific security policies based on their AD group membership. What must be configured in FMC to support this?

Medium
7

What action should you take if you want to test a new Access Control Rule without impacting production traffic?

Medium
8

An engineer is configuring an Identity Policy in FMC to enforce user-based access control. Active Directory integration has been established via User Agent, but the engineer notices that some users authenticated via remote access VPN are not being resolved to their IP addresses. Which feature must be integrated into the identity configuration to capture IP-to-user mappings for remote access VPN users?

Medium
9

Which tab in the Access Control Policy rule editor allows you to specify the source and destination zones?

Easy
10

You are configuring an SSL Decryption policy. Which action is required to ensure that traffic to a specific financial website is excluded from inspection due to compliance reasons?

Hard
11

An administrator is configuring Security Intelligence in FMC. Which TWO types of objects can be added to Security Intelligence blacklists or whitelists? (Choose two)

Medium
12

Which THREE methods can be used to populate IP address objects or groups in the FMC Object Management? (Choose three)

Hard
13

When configuring a NAT rule, which THREE options are valid 'Type' selections within the NAT Rule editor?

Hard
14

Where do you define the 'Search' criteria for finding objects in FMC?

Easy
15

When you have multiple overlapping NAT rules, which rule is applied?

Hard
16

A security requirement mandates that QoS be applied to limit bandwidth for guest users. Where is QoS configured on an FMC-managed FTD?

Medium
17

Where in the FMC UI do you go to create a new Access Control Policy?

Easy
18

What must be configured before an Access Control Rule can use a URL category?

Medium
19

What is the effect of changing the order of rules in an Access Control Policy?

Medium
20

What is the result of applying an 'IPS Policy' to an Access Control Rule?

Medium
21

An administrator needs to configure an identity policy to authenticate users using an external RADIUS server via Passive Authentication. Which mechanism accomplishes passive user identification?

Medium
22

What must be done to apply a change made in the Access Control Policy?

Easy
23

An engineer is configuring a QoS policy on an FMC-managed FTD and needs to police traffic to a maximum bandwidth limit on an interface. Which shaping/policing parameter must be configured?

Hard
24

What is the result of using a 'Security Group' object in an Access Control rule?

Hard
25

What is the primary function of the 'Object Management' section in FMC?

Easy
26

When creating a network object in FMC, which field allows you to define a group of IP addresses using CIDR notation?

Easy
27

Which tab in the FMC Object Manager allows you to manage pre-defined objects?

Medium
28

You are configuring a NAT rule on an FTD device managed by FMC. You need to translate the source IP of internal hosts to a specific public IP address when they access the internet. Which NAT type must be selected in the FMC NAT Rule editor?

Medium
29

When configuring a QoS policy, what happens if you exceed the 'Rate Limit' set for a traffic class?

Hard
30

Which TWO methods can be used to identify users in an Identity Policy?

Medium
31

An administrator wants to configure an Access Control rule that triggers an Intrusion Policy only when specific vulnerability signatures match. Where is the Intrusion Policy assigned?

Medium
32

Which TWO protocols are commonly managed via Port objects in FMC?

Easy
33

An administrator needs to create a custom URL object to block a specific malicious domain name 'example.malicious.com' in an Access Control Policy. Which object type should be created?

Easy
34

An administrator is configuring Security Intelligence on the FMC to drop traffic from known malicious IP addresses. Where in the Access Control Policy is Security Intelligence evaluated relative to standard access rules?

Medium
35

What is the purpose of an 'FQDN' object in FMC?

Easy
36

When defining a NAT rule for an internal server, what happens if the 'DNS Rewrite' option is enabled?

Hard
37

If you need to block a specific file type (e.g., .exe) from being downloaded, which feature must you enable in the Access Control Rule?

Hard
38

An administrator is configuring manual NAT on an FTD device managed by FMC. Which TWO parameters must be defined when creating a manual NAT rule? (Choose two)

Medium
39

You are configuring SSL decryption. To ensure that traffic to a specific financial domain is NOT decrypted due to privacy regulations, what must you configure in the SSL Decryption Policy?

Hard
40

Which THREE actions can be assigned to an individual rule within an Access Control Policy on the FMC? (Choose three)

Hard
41

An administrator configures an SSL Decryption Policy with a rule to 'Do Not Decrypt' financial traffic. However, the administrator also wants to ensure that the encrypted session still undergoes basic certificate validation and categorization. How does FTD handle 'Do Not Decrypt' traffic?

Hard
42

An administrator needs to configure manual NAT on an FTD device to translate both the source IP and source port of outbound packets originating from 192.168.2.50 to a specific public IP 198.51.100.10 and port 50000. Which manual NAT rule element achieves this?

Medium
43

A network engineer is deploying a Firepower Threat Defense (FTD) device and must configure NAT to translate an internal server IP of 10.10.10.50 to a public IP of 203.0.113.50 while preserving the original source port for inbound traffic. Which NAT type accomplishes this?

Medium
44

Which object type should be used to represent a group of network subnets?

Medium
45

An administrator wants to create a Port object group containing TCP ports 80, 443, and 8080 on the FMC. Where is this object configured?

Easy
46

Which TWO fields are commonly used in the 'NAT Rule' editor to define the source address?

Medium
47

An FTD device is deployed in routed mode with multiple security zones. An administrator needs to configure an Access Control rule that evaluates traffic flowing between two different security zones. How are security zones utilized in the rule?

Hard
48

Which THREE settings can be configured within a Prefilter Policy on the FMC? (Choose three)

Hard
49

What is the purpose of 'Network Discovery' in FMC?

Medium
50

An FMC administrator is configuring a URL Filtering policy. They want to block URLs categorized as 'Hacking' while logging the event. Where is this configured within the Access Control Policy?

Hard
51

You are configuring a NAT rule for a web server located in a DMZ. You want to translate the destination IP from a public address to the private DMZ address. Which NAT type is used?

Hard
52

An administrator is configuring manual NAT and needs to specify an interface pair (Source Interface and Destination Interface). Why is defining interface objects important in manual NAT rules?

Medium
53

How do you enable 'High Availability' (HA) for an FTD pair managed by FMC?

Medium
54

An administrator is configuring Access Control Policy rules on the FMC. The default action for unmatched traffic is currently set to Block. The requirement is changed so that unmatched traffic should pass through the FTD without inspection. Where is this setting modified?

Easy
55

When configuring manual NAT on an FTD device, which THREE options are available for configuring the Translated Source? (Choose three)

Hard
56

Which THREE criteria can be used to match traffic in an Access Control Policy rule?

Hard
57

A security engineer is creating an Access Control Policy (ACP) in FMC. The policy must block all traffic matching specific URL categories while allowing standard web browsing. However, the administrator wants users to receive a warning page before continuing to pages categorized as "Potentially Damaging Content" rather than a hard block. Which action should the engineer assign to the URL category in the ACP Rules tab?

Medium
58

Which TWO items must be defined to create a fully functional Network Object group in FMC?

Medium
59

An administrator is configuring a Network Address Translation (NAT) rule on a Cisco FMC managed Threat Defense device. The requirement is to translate the source IP address of traffic coming from the inside zone going to the outside zone, but only for a specific internal subnet. Which NAT type must the administrator select in the FMC NAT rule configuration?

Easy
60

An administrator wants to create a Prefilter policy to fast-path (bypass Snort inspection for) a trusted backup stream between two data centers. Which action type should be selected in the Prefilter rule?

Easy
61

An administrator needs to define network objects in the FMC Object Management menu. Which THREE object types are natively supported for network definition? (Choose three)

Easy
62

An administrator configures an SSL Decryption Policy on the FMC to decrypt inbound HTTPS traffic destined for an internal web server. The administrator imports the private key and server certificate into the FMC. Which decryption action must be selected to allow the FTD to decrypt this traffic using the server's private key?

Hard
63

An administrator is configuring a Manual NAT rule in the FMC for an internal server that needs to be accessed from the outside zone. The internal IP is 192.168.1.50, and it must be translated to a public IP 203.0.113.10. Which TWO configuration parameters must be specified when defining this Manual NAT rule? (Choose two)

Hard
64

An administrator is configuring a Prefilter Policy in FMC to optimize performance on a Cisco Firepower Threat Defense device. The requirement is to completely bypass inspection for a trusted high-speed data backup tunnel between two datacenters using GRE encapsulation. Which prefilter rule action should be selected?

Hard
65

An administrator needs to configure Active Authentication using a captive portal on an FTD device. Which firewall feature must be properly configured and running to present the authentication prompt to users?

Medium
66

An administrator wants to decrypt inbound HTTPS traffic destined for a public web server behind a Firepower Threat Defense device. Which type of SSL/TLS decryption policy must be configured on the FMC?

Hard
67

An administrator configures an Identity Policy on the FMC to authenticate users via Active Directory using captive portal. Where is the Identity Policy applied within the Firepower configuration hierarchy?

Medium
68

Which feature in FMC allows you to group multiple physical interfaces into a single logical zone for policy assignment?

Medium
69

When configuring an FQDN object, which THREE options are valid for the FQDN field?

Hard
70

A network engineer needs to configure Auto NAT on a Firepower Threat Defense device managed by FMC to translate internal subnet 10.10.10.0/24 to a single public IP address 203.0.113.50. Which translation type should be selected?

Medium
71

An administrator needs to create a variable set to define specific port or network variables used within Intrusion Rules. Where are variable sets managed in the FMC?

Easy
72

An enterprise requires FTD to decrypt outbound SSL/TLS traffic so internal users visiting external websites can be inspected by Snort for malware. Which policy and action combination must be configured?

Hard
73

In the context of FTD, what does 'FMC' stand for?

Easy
74

Which TWO tasks are required to delete a NAT rule safely?

Medium
75

An administrator needs to ensure that internal users can access the internet using a public IP while hiding their private address. Which NAT rule type should be configured on the FMC?

Medium
76

An administrator needs to create a Geolocation object in the FMC to block traffic originating from a specific country. Where is this object used?

Medium
77

An administrator is troubleshooting an Access Control Policy where multiple rules could potentially match a specific packet. In what order does the FMC evaluate rules within an Access Control Policy?

Hard
78

An administrator is configuring interface-level QoS on an FTD device. Which THREE parameters or features can be configured within an FTD QoS policy? (Choose three)

Medium
79

When configuring an FTD in Transparent Mode, how is the 'Bridge Group' created?

Hard
80

An administrator is creating an Access Control Policy rule on the FMC. Which TWO elements are required to create a basic rule? (Choose two)

Easy
81

When deploying a configuration change from FMC to FTD, what is the 'Deployment' process actually doing?

Hard
82

You are setting up an FTD interface. What is the difference between a 'Routed' and 'Transparent' interface mode?

Medium
83

An administrator is configuring an Identity Policy to enforce user-based access control. Which THREE identity sources are supported by the FMC for user awareness? (Choose three)

Medium
84

An administrator is setting up a new Cisco Firepower Threat Defense device and needs to configure platform-level parameters using FMC Platform Settings. Which TWO features can be configured via Platform Settings? (Choose two)

Medium
85

Which type of object is best suited for defining a web server's public-to-private NAT mapping?

Medium
86

An administrator is implementing an SSL Decryption Policy on a Cisco Firepower Threat Defense device managed by FMC. The policy must decrypt outbound HTTPS traffic to inspect for malware, but certain financial domains must be excluded from decryption to comply with privacy regulations. Which rule action should be configured for these specific financial domains in the SSL Decryption Policy?

Hard
87

An administrator is configuring an SSL Decryption Policy on the FMC. Which TWO conditions or actions can be configured within an SSL rule? (Choose two)

Hard
88

An Identity Policy is configured on the FMC to authenticate users connecting through the FTD. The administrator wants to use Active Directory as the identity source. Which mechanism must be configured to map user IP addresses to usernames without requiring explicit web authentication?

Medium
89

An administrator needs to configure NAT on an FTD device so that internal traffic destined for a partner network uses the original source IP, but the destination IP is translated from 192.168.10.50 to 172.16.50.10. What type of NAT rule is required?

Medium
90

An administrator is configuring Identity Policies on the FMC. Which TWO identity sources are supported for user mapping and authentication? (Choose two)

Medium
91

Which TWO items can be used to filter traffic in a QoS policy?

Medium
92

An FTD device is deployed behind a service provider router that performs NAT, meaning the external IP address assigned to the FTD's outside interface changes dynamically via DHCP. How should a Manual NAT rule be configured to handle outbound traffic referencing this dynamic outside IP?

Medium
93

An administrator is troubleshooting a Prefilter Policy configured on an FMC. Which THREE actions are available when creating a rule in a Prefilter Policy? (Choose three)

Hard
94

An administrator is configuring a new Access Control Policy on the Firepower Management Center and needs to add a rule that blocks peer-to-peer file sharing applications regardless of port. Which rule type should the administrator select?

Easy
95

How do you ensure that a specific host object is only used in a specific interface?

Hard
96

Which TWO settings are available when configuring the 'Logging' tab in an Access Control Rule?

Medium
97

Which TWO types of objects can be created in the FMC Object Manager?

Medium
98

An administrator is configuring a Prefilter policy to handle GRE-encapsulated traffic. Which Prefilter rule option allows handling or accelerating tunneled traffic?

Medium
99

Which tab in the Access Control Policy rule allows you to choose the 'Logging' action?

Easy
100

An administrator is managing object configurations on the FMC. Which TWO of the following are valid object types that can be created under Object Management? (Choose two)

Medium
101

Which menu in the FMC allows you to view the list of managed FTD devices?

Easy
102

Which option in the Access Control Policy rule allows you to define a specific application, such as 'Facebook', to be blocked?

Easy
103

An administrator configures a security intelligence feed in the FMC to block known malicious IP addresses. Where are Security Intelligence feeds and lists applied in the FMC configuration?

Medium
104

An administrator is troubleshooting an SSL Decryption policy where encrypted connections are failing. The FMC logs indicate that clients are rejecting the FTD's re-signed certificate because it is not trusted. What configuration step is missing?

Hard
105

In the FMC, what is the purpose of the 'Network Discovery Policy'?

Medium
106

Which THREE actions can be performed by an SSL Decryption Policy?

Hard
107

An administrator is configuring an Identity Policy with Active Directory integration. The requirement is to ensure that users who fail primary AD authentication are assigned to a restricted guest VLAN using ISE integration. Which component in the FMC architecture handles this user-to-group association?

Hard
108

Which THREE components are necessary to implement passive identity monitoring in an FMC-managed Firepower system?

Hard
109

Which THREE criteria can be used to match traffic within an Access Control rule on the FMC? (Choose three)

Hard
110

You have a large number of NAT rules. How does the FTD process them?

Hard
111

An administrator wants to group multiple existing port objects (e.g., TCP 80, TCP 443, TCP 8080) into a single object for use in Access Control Policy rules. Which object container should be created?

Easy
112

You are defining an Access Control Policy rule to allow traffic. If you want to log the connection at the end of the flow only if it matches the rule, which Logging setting is appropriate?

Medium
113

How do you identify which Access Control Rule triggered a specific connection log?

Medium
114

You are troubleshooting a connectivity issue. The traffic is being dropped by a Prefilter rule. What is the characteristic of traffic handled by a Prefilter policy?

Hard
115

When editing an Access Control Rule, which action allows you to drop traffic while simultaneously sending a TCP RST to the client?

Medium
116

What is the result of assigning a 'Trust' action to a rule in an Access Control Policy?

Medium
117

An administrator needs to create a custom Application filter object in the FMC to easily select cloud storage applications in Access Control rules. Where are application filters created?

Easy
118

What occurs when an 'Interactive Block' action is used in an Access Control rule?

Hard
119

An administrator needs to configure Quality of Service (QoS) on a Cisco Firepower Threat Defense device via FMC to limit peer-to-peer traffic bandwidth. Where must the QoS policy be applied for it to take effect on traffic traversing the firewall?

Easy
120

An administrator configures QoS on an FTD interface to prioritize VoIP traffic. Which traffic matching mechanism within the QoS policy allows the FTD to identify VoIP traffic (such as SIP or RTP) based on Layer 7 application inspection?

Medium
121

An administrator is configuring SSL Decryption to inspect internal clients browsing external websites. The organization wants to ensure that traffic to financial and health-related websites is bypassed to maintain privacy and regulatory compliance. How should this be configured in the SSL Policy?

Hard
122

An administrator wants to ensure that specific internal subnets are never subjected to NAT translation when communicating with a partner VPN tunnel. Which NAT feature achieves this?

Easy
123

Which THREE components of an Access Control rule can be used to identify traffic as 'Application' based?

Hard
124

You are creating a custom URL category. How do you add specific domains to this category in FMC?

Hard
125

An engineer wants to group several FTD interfaces into a single logical zone to simplify Access Control rule creation. Where are security zones created in the FMC?

Easy
126

You are configuring a NAT rule and need to hide the internal network behind a single interface IP. Which NAT translation setting is required?

Hard
127

What is the primary function of a 'Security Zone' in FMC?

Medium
128

Which TWO components must be configured in FMC to enable User Identity mapping for Access Control Rules?

Medium

Frequently asked questions

What does the Configuration domain cover on the 300-710 SNCF exam?
Configuration questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 128 Configuration questions in the 300-710 SNCF question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Configuration questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
cisco-sncf CISCO-SNCF configuration Practice Questions