Courseiva

CCNA Configuration Questions

75 of 128 questions · Page 1/2 · Configuration · Answers revealed

1
MCQhard

An administrator configures DNS injection and rewriting in a manual NAT rule on an FTD device. What is the primary purpose of enabling DNS translation in a NAT rule?

A.To cache DNS responses locally on the FTD control plane
B.To encrypt DNS queries over TLS (DoT)
C.To block malicious DNS tunneling attempts via Snort inspection
D.To rewrite DNS A-records returning internal server IPs so external clients receive the correct public NAT IP
AnswerD

DNS translation rewrites IP addresses inside DNS response payloads so clients connecting through NAT reach the right address.

Why this answer

DNS translation ensures that when an internal client queries a local DNS server for an external name that resolves to a private IP (due to NAT), the FTD rewrites the DNS A-record response to the public IP.

2
Multi-Selectmedium

An administrator is configuring Manual NAT on an FTD device. Which THREE parameters must be defined when creating a Manual Static NAT rule for inbound traffic? (Choose three)

Select 3 answers
A.Dynamic Port Allocation pool
B.Translated Source IP address or object
C.Original Source IP address or object
D.Original Destination IP address or object
E.Routing metric preference
AnswersB, C, D

Translated source is required to specify the internal mapped IP.

Why this answer

Manual NAT rules require a Source Interface (or original source/destination criteria), Original Source, Translated Source, and appropriate interface specifications. Specifically, original destination, translated destination, and interface settings are core components.

3
MCQhard

When using the 'Search' feature in the Access Control Policy, which filter allows you to find all rules containing a specific network object?

A.Filter by Action
B.Filter by Name
C.Filter by Zone
D.Filter by Network
AnswerD

This filter finds rules using specific network objects.

Why this answer

The rule editor allows filtering rules based on their contents like networks, zones, or applications.

4
MCQeasy

When configuring an Access Control Policy on the FMC, what is the purpose of the Default Action set at the bottom of the rules table?

A.It sets the global timeout values for all TCP connections.
B.It defines the action taken for traffic that matches no explicit rules in the policy.
C.It acts as a prefilter rule for dropped packets.
D.It forces all unmatched traffic to be sent to the Cisco Cloud for telemetry.
AnswerB

The default action acts as the catch-all rule for any traffic not matching preceding access control rules.

Why this answer

The Default Action determines how traffic that fails to match any explicit access control rule is handled (typically Block or Pass with logging).

5
Multi-Selecteasy

An administrator is configuring Security Intelligence feeds on the FMC. Which TWO types of objects or feeds can be used to populate Security Intelligence blacklists? (Choose two)

Select 2 answers
A.Local user identity realm database
B.Prefilter fast-path exclusion rules
C.Custom Network/IP Lists (Objects)
D.QoS class map profile objects
E.Cisco provided dynamic feeds (e.g., IP or URL reputation feeds)
AnswersC, E

Administrators can upload or define custom IP lists to block.

Why this answer

Security Intelligence supports custom network/IP lists and Cisco provided dynamic feeds (like reputation feeds for URLs and IPs).

6
MCQmedium

You need to map internal users to specific security policies based on their AD group membership. What must be configured in FMC to support this?

A.Access Control Policy
B.Network Discovery Policy
C.Identity Policy
D.SSL Decryption Policy
AnswerC

The Identity Policy defines how the system identifies users via realms.

Why this answer

Identity policies require an Identity Realm and agent integration to map user IPs to group memberships.

7
MCQmedium

What action should you take if you want to test a new Access Control Rule without impacting production traffic?

A.Delete the rule
B.Use the 'Block' action
C.Use the 'Trust' action
D.Use the 'Monitor' action
AnswerD

Monitor logs matches without enforcing drops.

Why this answer

Use the 'Monitor' action first to see what traffic matches the rule without blocking it.

8
MCQmedium

An engineer is configuring an Identity Policy in FMC to enforce user-based access control. Active Directory integration has been established via User Agent, but the engineer notices that some users authenticated via remote access VPN are not being resolved to their IP addresses. Which feature must be integrated into the identity configuration to capture IP-to-user mappings for remote access VPN users?

A.FMC Captive Portal
B.Terminal Services Agent (TS Agent)
C.SNMP polling of the DHCP server
D.Cisco Identity Services Engine (ISE) via pxGrid or RADIUS Accounting
AnswerD

ISE integration via pxGrid or RADIUS accounting provides user-to-IP mappings for Remote Access VPN sessions.

Why this answer

Remote Access VPN users authenticate directly to the VPN gateway. To map their dynamic IP addresses to their usernames in FMC, Cisco Adaptive Security Device Manager (ASDM) or FMC must leverage Remote Access connection profiles and ISE/RADIUS accounting or FTD local database integration. Specifically, RADIX/ISE accounting or FTD identity sources handle VPN session user mapping.

Within FMC identity policies, captive portal or TS Agent does not track remote VPN pools as effectively as configuring RADIUS/ISE or leveraging the FTD RA VPN user mapping integration.

9
MCQeasy

Which tab in the Access Control Policy rule editor allows you to specify the source and destination zones?

A.Ports
B.Zones
C.Networks
D.Applications
AnswerB

This is the correct tab for zone selection.

Why this answer

The 'Zones' tab is where you define ingress and egress zones for the rule.

10
MCQhard

You are configuring an SSL Decryption policy. Which action is required to ensure that traffic to a specific financial website is excluded from inspection due to compliance reasons?

A.Do Not Decrypt
B.Decrypt - Resign
C.Bypass
D.Block
AnswerA

This allows the traffic to pass through the firewall without SSL inspection.

Why this answer

The 'Do Not Decrypt' action is used in the SSL policy to bypass decryption for specific traffic based on URL or category.

11
Multi-Selectmedium

An administrator is configuring Security Intelligence in FMC. Which TWO types of objects can be added to Security Intelligence blacklists or whitelists? (Choose two)

Select 2 answers
A.URL objects
B.Intrusion policy objects
C.Network / IP objects
D.Security Zone objects
E.Application filter objects
AnswersA, C

URL objects and feeds are supported in Security Intelligence lists.

Why this answer

Security Intelligence supports IP address objects/networks and URL objects/feeds.

12
Multi-Selecthard

Which THREE methods can be used to populate IP address objects or groups in the FMC Object Management? (Choose three)

Select 3 answers
A.Intrusion Signature ID number
B.CIDR Network subnet
C.Individual Host IP address
D.IP Address Range (start to end)
E.Mac Address OUI prefix
AnswersB, C, D

Network objects use CIDR notation.

Why this answer

IP objects can be populated using individual IP addresses, CIDR network subnets, IP ranges, or FQDNs.

13
Multi-Selecthard

When configuring a NAT rule, which THREE options are valid 'Type' selections within the NAT Rule editor?

Select 3 answers
A.Static
B.Identity
C.Virtual
D.Dynamic
E.Transparent
AnswersA, B, D

Valid NAT type.

Why this answer

Static, Dynamic, and Identity are valid NAT types in FTD/FMC.

14
MCQeasy

Where do you define the 'Search' criteria for finding objects in FMC?

A.Devices > Device Management
B.Policies > Access Control
C.Objects > Object Management
D.Analysis > Reports
AnswerC

Correct, this page has the search functionality.

Why this answer

The Object Management page provides a search bar for filtering existing objects.

15
MCQhard

When you have multiple overlapping NAT rules, which rule is applied?

A.The rule that matches the interface
B.The rule with the lowest priority
C.The most specific rule
D.The first matching rule
AnswerD

Top-down, first match wins.

Why this answer

The FTD matches NAT rules using a top-down approach, similar to Access Control rules.

16
MCQmedium

A security requirement mandates that QoS be applied to limit bandwidth for guest users. Where is QoS configured on an FMC-managed FTD?

A.Within the Access Control Policy rules
B.In a separate QoS Policy
C.Under the Platform Settings
D.In the Prefilter Policy
AnswerB

QoS policies are managed independently and applied to interfaces.

Why this answer

QoS policies are defined as a separate policy type in the FMC and then applied to the Access Control Policy.

17
MCQeasy

Where in the FMC UI do you go to create a new Access Control Policy?

A.Devices > Device Management
B.Policies > Access Control
C.Objects > Object Management
D.Analysis > Connection
AnswerB

Correct navigation path.

Why this answer

Access Control Policies are found under the Policies menu.

18
MCQmedium

What must be configured before an Access Control Rule can use a URL category?

A.URL Filtering License
B.Identity Policy
C.Prefilter Policy
D.QoS Policy
AnswerA

Required for dynamic URL category updates.

Why this answer

The URL filtering license must be enabled/configured for the category database to be available.

19
MCQmedium

What is the effect of changing the order of rules in an Access Control Policy?

A.No effect
B.Resets the device
C.Changes the evaluation sequence
D.Updates the device firmware
AnswerC

Correct, order defines priority.

Why this answer

Rules are evaluated top-down; changing the order can cause a rule to be shadowed or never matched.

20
MCQmedium

What is the result of applying an 'IPS Policy' to an Access Control Rule?

A.It enables deep packet inspection
B.It bypasses decryption
C.It blocks traffic based on IP
D.It disables the rule
AnswerA

IPS policy adds the inspection layer.

Why this answer

The IPS policy enables deep packet inspection for the traffic matched by the rule.

21
MCQmedium

An administrator needs to configure an identity policy to authenticate users using an external RADIUS server via Passive Authentication. Which mechanism accomplishes passive user identification?

A.Cisco ISE pxGrid / Firepower User Agent
B.Captive Portal
C.RADIUS Challenge-Response prompt
D.HTTP Basic Authentication challenge
AnswerA

Passive authentication relies on identity services like ISE pxGrid or Active Directory event logs via User Agent.

Why this answer

Passive authentication maps users without prompting them for credentials, typically achieved using Cisco Firepower User Agent or ISE pxGrid integration.

22
MCQeasy

What must be done to apply a change made in the Access Control Policy?

A.Click 'Deploy'
B.Wait 24 hours
C.Click 'Save'
D.Restart the device
AnswerA

Deploy pushes the config to the sensor.

Why this answer

You must click 'Deploy' in the FMC to push the changes to the FTD.

23
MCQhard

An engineer is configuring a QoS policy on an FMC-managed FTD and needs to police traffic to a maximum bandwidth limit on an interface. Which shaping/policing parameter must be configured?

A.Traffic Policing with specified Committed Information Rate (CIR)
B.Prefilter FastPath Rate Cap
C.Access Control Rate Limiting action
D.Random Early Detection (RED) drop threshold
AnswerA

Traffic policing uses CIR and burst parameters to strictly limit bandwidth consumption.

Why this answer

Interface-based QoS rate limiting uses police parameters to cap bandwidth for traffic matching the QoS policy.

24
MCQhard

What is the result of using a 'Security Group' object in an Access Control rule?

A.Matches based on IP address
B.Matches based on VLAN
C.Matches based on SGT
D.Matches based on Interface
AnswerC

SGTs (Security Group Tags) are the basis for this object type.

Why this answer

Security Group objects allow policy matching based on Cisco TrustSec tags.

25
MCQeasy

What is the primary function of the 'Object Management' section in FMC?

A.To create reusable objects
B.To analyze traffic
C.To create policies
D.To manage firmware
AnswerA

This is the central location for objects.

Why this answer

Object Management is where you create reusable objects for policies.

26
MCQeasy

When creating a network object in FMC, which field allows you to define a group of IP addresses using CIDR notation?

A.Network
B.Host
C.Range
D.FQDN
AnswerA

Network allows defining an IP block using CIDR.

Why this answer

The Network object type allows single hosts, ranges, or subnets using CIDR notation.

27
MCQmedium

Which tab in the FMC Object Manager allows you to manage pre-defined objects?

A.User Objects
B.System Objects
C.Global Objects
D.Custom Objects
AnswerB

Shows system-provided objects.

Why this answer

FMC provides a list of pre-defined objects under the 'Network' or 'Port' categories; you can filter for 'System' objects.

28
MCQmedium

You are configuring a NAT rule on an FTD device managed by FMC. You need to translate the source IP of internal hosts to a specific public IP address when they access the internet. Which NAT type must be selected in the FMC NAT Rule editor?

A.Identity NAT
B.Static NAT
C.Policy NAT
D.Dynamic NAT
AnswerD

Dynamic NAT is the correct selection for source translation from a group of internal hosts.

Why this answer

Dynamic NAT allows mapping a range of internal addresses to a single or range of public addresses, typically used for internet access.

29
MCQhard

When configuring a QoS policy, what happens if you exceed the 'Rate Limit' set for a traffic class?

A.The traffic is redirected to another interface
B.The traffic is logged as critical
C.The connection is reset
D.The excess traffic is policed
AnswerD

Policing discards traffic exceeding the threshold.

Why this answer

Traffic exceeding the rate limit is policed (dropped or shaped).

30
Multi-Selectmedium

Which TWO methods can be used to identify users in an Identity Policy?

Select 2 answers
A.Captive Portal
B.DHCP Snooping
C.RADIUS Proxy
D.SNMP Polling
E.Passive Authentication
AnswersA, E

Active auth via browser.

Why this answer

Passive (ISE/AD) and Active (Captive Portal) are the main identification methods.

31
MCQmedium

An administrator wants to configure an Access Control rule that triggers an Intrusion Policy only when specific vulnerability signatures match. Where is the Intrusion Policy assigned?

A.Under the Advanced tab of the Access Control Policy globally
B.Under the Inspection tab of an individual Access Control rule
C.Within the Platform Settings object
D.In the Security Intelligence policy settings
AnswerB

An individual Access Control rule allows assigning a specific Intrusion Policy under its Inspection tab.

Why this answer

Intrusion policies are assigned to Access Control rules under the Inspection tab or as the default intrusion policy for the access control policy.

32
Multi-Selecteasy

Which TWO protocols are commonly managed via Port objects in FMC?

Select 2 answers
A.UDP
B.ARP
C.TCP
D.IGMP
E.ICMP
AnswersA, C

Primary L4 protocol.

Why this answer

TCP and UDP are the primary protocols managed via port objects.

33
MCQeasy

An administrator needs to create a custom URL object to block a specific malicious domain name 'example.malicious.com' in an Access Control Policy. Which object type should be created?

A.Security Intelligence Object
B.FQDN Object
C.Network Object
D.URL Object
AnswerD

URL objects allow specifying exact web domains or paths for layer 7 URL filtering rules.

Why this answer

URL objects are created under Object Management to define specific web domains or URLs for use in access control rules.

34
MCQmedium

An administrator is configuring Security Intelligence on the FMC to drop traffic from known malicious IP addresses. Where in the Access Control Policy is Security Intelligence evaluated relative to standard access rules?

A.Inside the Prefilter policy configuration menu
B.Before Access Control rules are evaluated
C.After all Access Control rules are evaluated as a fallback action
D.Concurrently with Intrusion Policy inspection
AnswerB

Security Intelligence acts as a pre-filter step within the Access Control Policy, dropping bad IPs before rule matching begins.

Why this answer

Security Intelligence is evaluated before Access Control Policy rules are processed, providing an efficient early drop mechanism.

35
MCQeasy

What is the purpose of an 'FQDN' object in FMC?

A.To define a protocol port
B.To define a zone
C.To define a domain name
D.To define a static IP
AnswerC

FQDN stands for Fully Qualified Domain Name.

Why this answer

FQDN objects are used to define network resources by domain name, which the FTD resolves.

36
MCQhard

When defining a NAT rule for an internal server, what happens if the 'DNS Rewrite' option is enabled?

A.The FTD forces a DNS query to an external server
B.The FTD creates a new NAT object
C.The FTD blocks all DNS traffic
D.The FTD modifies DNS responses
AnswerD

Correct, it rewrites the A-record to the internal IP.

Why this answer

DNS Rewrite modifies the payload of DNS responses to ensure clients reach the correct internal server IP instead of the NAT public IP.

37
MCQhard

If you need to block a specific file type (e.g., .exe) from being downloaded, which feature must you enable in the Access Control Rule?

A.SSL Policy
B.IPS Policy
C.File Policy
D.QoS Policy
AnswerC

File policies handle file inspection and blocking.

Why this answer

File policies are associated with Access Control rules to inspect and block files.

38
Multi-Selectmedium

An administrator is configuring manual NAT on an FTD device managed by FMC. Which TWO parameters must be defined when creating a manual NAT rule? (Choose two)

Select 2 answers
A.Prefilter FastPath action
B.Security Intelligence Whitelist
C.Snort Inspection Engine Mode
D.Original Source
E.NAT Type (Static or Dynamic)
AnswersD, E

Every manual NAT rule must define the Original Source network/IP object being translated.

Why this answer

Manual NAT rules require defining the NAT type (Static or Dynamic) and the Original Source (along with other matching parameters like interfaces or destination).

39
MCQhard

You are configuring SSL decryption. To ensure that traffic to a specific financial domain is NOT decrypted due to privacy regulations, what must you configure in the SSL Decryption Policy?

A.Use a 'Monitor' action in the SSL policy
B.Configure an SSL rule with the 'Do Not Decrypt' action
C.Create an Access Control Rule with a 'Decrypt' action
D.Add the domain to the Prefilter Policy
AnswerB

The Do Not Decrypt action explicitly tells the FTD to pass the traffic as-is.

Why this answer

The 'Do Not Decrypt' action is used in SSL policies to bypass inspection for specific URLs or categories.

40
Multi-Selecthard

Which THREE actions can be assigned to an individual rule within an Access Control Policy on the FMC? (Choose three)

Select 3 answers
A.Decrypt
B.FastPath
C.Allow
D.Block
E.Monitor
AnswersC, D, E

Allow passes traffic for inspection and forwarding.

Why this answer

Access Control rules support actions such as Allow, Block, Interactive Block, Trust, and Monitor.

41
MCQhard

An administrator configures an SSL Decryption Policy with a rule to 'Do Not Decrypt' financial traffic. However, the administrator also wants to ensure that the encrypted session still undergoes basic certificate validation and categorization. How does FTD handle 'Do Not Decrypt' traffic?

A.All inspection, including URL categorization and SNI extraction, is completely bypassed.
B.The FTD extracts SNI and performs URL categorization using the unencrypted Client Hello handshake.
C.The FTD converts the traffic to plaintext using a self-signed proxy certificate.
D.The FTD drops the connection because decryption is mandatory for any inspection.
AnswerB

Client Hello inspection allows URL categorization and SNI matching even when full decryption is disabled.

Why this answer

Even when traffic is set to Do Not Decrypt, FTD can inspect the TLS handshake (Client Hello) to extract SNI, categorize the URL, and validate basic certificate attributes without decrypting the payload.

42
MCQmedium

An administrator needs to configure manual NAT on an FTD device to translate both the source IP and source port of outbound packets originating from 192.168.2.50 to a specific public IP 198.51.100.10 and port 50000. Which manual NAT rule element achieves this?

A.Manual NAT rule with Translated Source set to an IP object and dynamic port translation enabled
B.Static NAT with Bi-directional enabled
C.Auto NAT rule configured with Dynamic PAT
D.Identity NAT with Port Forwarding enabled
AnswerA

Manual NAT allows granular control over source IP and source port translation parameters.

Why this answer

Manual NAT rules allow specifying Original Source, Translated Source (IP), and Port translation options to achieve Port Address Translation.

43
MCQmedium

A network engineer is deploying a Firepower Threat Defense (FTD) device and must configure NAT to translate an internal server IP of 10.10.10.50 to a public IP of 203.0.113.50 while preserving the original source port for inbound traffic. Which NAT type accomplishes this?

A.Manual Static NAT
B.Auto NAT (Dynamic PAT)
C.Manual Identity NAT
D.Auto NAT (Static Patched)
AnswerA

Manual NAT provides granular control, allowing static IP translation with port preservation options for inbound traffic.

Why this answer

Manual Static NAT allows the translation of a specific internal IP to a specific external public IP while supporting port translation and preservation options.

44
MCQmedium

Which object type should be used to represent a group of network subnets?

A.Host
B.Range
C.Port Group
D.Network Group
AnswerD

Best for grouping subnets.

Why this answer

A Network Group object allows you to aggregate multiple network subnets into a single object for policy efficiency.

45
MCQeasy

An administrator wants to create a Port object group containing TCP ports 80, 443, and 8080 on the FMC. Where is this object configured?

A.Policies > Access Control > Ports
B.Devices > Device Management > Object Explorer
C.Objects > Object Management > Ports
D.System > Configuration > Port Groups
AnswerC

Port objects and port object groups are managed under Objects > Object Management > Ports.

Why this answer

Port object groups and individual ports are created under Objects > Object Management > Ports.

46
Multi-Selectmedium

Which TWO fields are commonly used in the 'NAT Rule' editor to define the source address?

Select 2 answers
A.Destination Port
B.Translated Source
C.Original Source
D.Access List
E.Interface Group
AnswersB, C

The address after translation.

Why this answer

NAT rules use 'Original Source' and 'Translated Source' fields to define the address translation logic.

47
MCQhard

An FTD device is deployed in routed mode with multiple security zones. An administrator needs to configure an Access Control rule that evaluates traffic flowing between two different security zones. How are security zones utilized in the rule?

A.Security zones replace IP address objects entirely in all rule configurations.
B.Security zones are used exclusively in NAT translation rules.
C.Security zones are selected under the Zones tab of an Access Control rule as Source and Destination.
D.Security zones are assigned globally in device platform settings, not in access rules.
AnswerC

Rules use Source and Destination Zones to match traffic traversing between specific interface groups.

Why this answer

Security zones are groupings of interfaces referenced as source and destination zones within Access Control rules.

48
Multi-Selecthard

Which THREE settings can be configured within a Prefilter Policy on the FMC? (Choose three)

Select 3 answers
A.Intrusion Policy signature tuning
B.FastPath action to bypass Snort inspection
C.Default Action for unmatched traffic (Analyze or FastPath)
D.Security Intelligence block lists
E.Tunnel rule handling (e.g., GRE, IPsec)
AnswersB, C, E

FastPath is a core prefilter action.

Why this answer

Prefilter policies support FastPath, Tunnel rules, and Default Actions (Analyze or FastPath).

49
MCQmedium

What is the purpose of 'Network Discovery' in FMC?

A.To push firmware updates
B.To configure routing protocols
C.To identify hosts and user activity
D.To perform active IPS scanning
AnswerC

It builds a map of network assets.

Why this answer

Network Discovery identifies hosts, applications, and operating systems on the network.

50
MCQhard

An FMC administrator is configuring a URL Filtering policy. They want to block URLs categorized as 'Hacking' while logging the event. Where is this configured within the Access Control Policy?

A.Objects > Object Management > URL Objects
B.Policies > SSL Decryption > URL Match criteria
C.Policies > Access Control > Access Control Policy > Rules > URLs tab
D.Devices > Device Management > URL Filtering Settings
AnswerC

URL category matching is configured directly in the URLs tab of an Access Control rule.

Why this answer

URL filtering configuration is embedded directly within Access Control rules under the URLs tab.

51
MCQhard

You are configuring a NAT rule for a web server located in a DMZ. You want to translate the destination IP from a public address to the private DMZ address. Which NAT type is used?

A.Static NAT
B.Identity NAT
C.Manual NAT
D.Dynamic NAT
AnswerA

Static NAT handles the inbound one-to-one mapping.

Why this answer

Static NAT is used for inbound traffic translation where a public IP maps to a private internal server IP.

52
MCQmedium

An administrator is configuring manual NAT and needs to specify an interface pair (Source Interface and Destination Interface). Why is defining interface objects important in manual NAT rules?

A.It replaces the need for security zones in Access Control policies.
B.It forces the FTD to convert the packet from Layer 2 to Layer 3.
C.It scopes the translation rule to specific ingress and egress interfaces, preventing unintended translations across other subnets.
D.It enables automatic routing table updates for the translated IP address.
AnswerC

Explicit interface specification ensures NAT only applies to traffic traversing those exact interfaces.

Why this answer

Interface specifications in manual NAT help define the directionality and scope of the translation (e.g., inside to outside).

53
MCQmedium

How do you enable 'High Availability' (HA) for an FTD pair managed by FMC?

A.Under Devices > Device Management
B.Under Policies > HA
C.Via the System > Configuration menu
D.In the Access Control Policy
AnswerA

HA is a device-level configuration.

Why this answer

HA is configured in the Device Management section by selecting two devices to pair.

54
MCQeasy

An administrator is configuring Access Control Policy rules on the FMC. The default action for unmatched traffic is currently set to Block. The requirement is changed so that unmatched traffic should pass through the FTD without inspection. Where is this setting modified?

A.In the platform settings policy assigned to the device
B.Under Objects > Object Management > Default Action
C.Inside the Prefilter policy configuration
D.At the bottom of the Access Control Policy rules page (Default Action setting)
AnswerD

The default action for traffic that matches no rules is set at the bottom of the ACP rules tab.

Why this answer

The default action of an Access Control Policy is configured at the bottom of the Access Control Policy rules table.

55
Multi-Selecthard

When configuring manual NAT on an FTD device, which THREE options are available for configuring the Translated Source? (Choose three)

Select 3 answers
A.Specific IP Address or Network Object
B.Prefilter FastPath target
C.Security Intelligence blacklist feed
D.Dynamic IP Address Pool
E.Interface (Dynamic PAT)
AnswersA, D, E

Translating source to a static object or pool is supported.

Why this answer

Translated source options in manual NAT include Interface (PAT), Network/Host Object, and Dynamic Pool.

56
Multi-Selecthard

Which THREE criteria can be used to match traffic in an Access Control Policy rule?

Select 3 answers
A.Application
B.SSL Certificate Name
C.QoS Priority
D.Source/Destination Network
E.URL Category
AnswersA, D, E

L7 matching for specific apps.

Why this answer

Access control rules can match based on Source/Destination Network, Applications, and URL categories.

57
MCQmedium

A security engineer is creating an Access Control Policy (ACP) in FMC. The policy must block all traffic matching specific URL categories while allowing standard web browsing. However, the administrator wants users to receive a warning page before continuing to pages categorized as "Potentially Damaging Content" rather than a hard block. Which action should the engineer assign to the URL category in the ACP Rules tab?

A.Block
B.Allow
C.Monitor
D.Interactive Block
AnswerD

Interactive Block displays a warning page allowing the user to click through to the destination.

Why this answer

The Interactive Block action presents the user with a warning page and an option to bypass the warning and proceed to the site, whereas Block simply drops the connection or presents a block page with no bypass option.

58
Multi-Selectmedium

Which TWO items must be defined to create a fully functional Network Object group in FMC?

Select 2 answers
A.Member Objects
B.Object Description
C.SNMP Traps
D.Routing Table
E.Object Name
AnswersA, E

The group must contain items to be useful.

Why this answer

A group needs a name and at least one member (object) assigned to it.

59
MCQeasy

An administrator is configuring a Network Address Translation (NAT) rule on a Cisco FMC managed Threat Defense device. The requirement is to translate the source IP address of traffic coming from the inside zone going to the outside zone, but only for a specific internal subnet. Which NAT type must the administrator select in the FMC NAT rule configuration?

A.Twice NAT (Destination NAT)
B.Prefilter NAT
C.Auto NAT (Object NAT)
D.Manual NAT (Identity NAT)
AnswerC

Auto NAT is tied directly to a network or host object and is commonly used to translate a specific internal subnet to an outside interface address.

Why this answer

Manual NAT or Auto NAT can be used, but for granular control over source and destination zones and interfaces, an Auto NAT rule or a Manual NAT rule configured as Source NAT (Dynamic NAT or PAT) from inside to outside is required. Specifically, for translating source IP addresses of an internal subnet going out, Auto NAT (Network Object NAT) using a network object for the source is the most direct method.

60
MCQeasy

An administrator wants to create a Prefilter policy to fast-path (bypass Snort inspection for) a trusted backup stream between two data centers. Which action type should be selected in the Prefilter rule?

A.FastPath
B.Monitor
C.Block
D.Inspect
E.Trust
AnswerA

FastPath instructs the FTD to bypass deep packet inspection (Snort) for the matched traffic flow.

Why this answer

The FastPath action in a Prefilter policy allows matching traffic to bypass Snort inspection for performance optimization.

61
Multi-Selecteasy

An administrator needs to define network objects in the FMC Object Management menu. Which THREE object types are natively supported for network definition? (Choose three)

Select 3 answers
A.Port Object
B.Host Object
C.Network Object (Subnet)
D.Application Filter Object
E.Range Object
AnswersB, C, E

Host objects represent single IP addresses.

Why this answer

FMC supports Host, Range, Network (subnet), FQDN, and Network Group objects for network definitions.

62
MCQhard

An administrator configures an SSL Decryption Policy on the FMC to decrypt inbound HTTPS traffic destined for an internal web server. The administrator imports the private key and server certificate into the FMC. Which decryption action must be selected to allow the FTD to decrypt this traffic using the server's private key?

A.Do Not Decrypt
B.Decrypt - Resign
C.Block
D.Decrypt - Known Key
AnswerD

Decrypt - Known Key requires the private key of the server to be imported, allowing the FTD to passively decrypt inbound TLS sessions destined for that server.

Why this answer

Decrypt - Resign is used for outbound, while Decrypt - Known Key is used when you own the server and supply its private key to decrypt inbound traffic.

63
Multi-Selecthard

An administrator is configuring a Manual NAT rule in the FMC for an internal server that needs to be accessed from the outside zone. The internal IP is 192.168.1.50, and it must be translated to a public IP 203.0.113.10. Which TWO configuration parameters must be specified when defining this Manual NAT rule? (Choose two)

Select 2 answers
A.Interface PAT (PAT Pool)
B.Original Source
C.ARP Inspection Profile
D.Translated Source
E.DNS Resolution Option
AnswersB, D

The Original Source must be defined as the internal server object (192.168.1.50).

Why this answer

Manual NAT rules require defining the Source Interface (original source zone/interface), Destination Interface (translated destination zone/interface), Original Source IP, and Translated Source IP.

64
MCQhard

An administrator is configuring a Prefilter Policy in FMC to optimize performance on a Cisco Firepower Threat Defense device. The requirement is to completely bypass inspection for a trusted high-speed data backup tunnel between two datacenters using GRE encapsulation. Which prefilter rule action should be selected?

A.Monitor
B.Block
C.Analyze
D.Fast Path
AnswerD

Fast Path skips the Snort inspection engine entirely, accelerating packet processing for trusted traffic.

Why this answer

To completely bypass Snort inspection and fast-path the traffic at the hardware/driver level for performance, the Fast Path action is used within a Prefilter policy.

65
MCQmedium

An administrator needs to configure Active Authentication using a captive portal on an FTD device. Which firewall feature must be properly configured and running to present the authentication prompt to users?

A.Prefilter Bypass rule with SSL Resign
B.HTTP/HTTPS Response Page and Authentication Certificate configuration
C.SNMPv3 trap notification server
D.Platform Settings AAA server group for SSH/Telnet
AnswerB

Captive portal relies on an HTTP response server certificate and settings to present the login page.

Why this answer

Captive portal active authentication requires an HTTP/HTTPS response server configuration on the FTD to intercept unauthenticated HTTP sessions and prompt for credentials.

66
MCQhard

An administrator wants to decrypt inbound HTTPS traffic destined for a public web server behind a Firepower Threat Defense device. Which type of SSL/TLS decryption policy must be configured on the FMC?

A.SSL Decryption - Do Not Decrypt
B.Decrypt - Resign
C.Decrypt - Inbound
D.SSL Inspection Policy - Outbound
AnswerC

Decrypt - Inbound is specifically designed for decrypting incoming traffic to protected servers using the server's private key.

Why this answer

Decrypt - Inbound is used when the FTD device holds the private key of the server to decrypt inbound traffic destined for internal protected servers.

67
MCQmedium

An administrator configures an Identity Policy on the FMC to authenticate users via Active Directory using captive portal. Where is the Identity Policy applied within the Firepower configuration hierarchy?

A.Directly under Devices > Device Management > Platform Settings
B.Within the Access Control Policy settings on the FMC
C.Inside the SSL/TLS Decryption Policy
D.As a standalone rule inside a Prefilter Policy
AnswerB

Identity policies are invoked and associated directly within the Access Control Policy.

Why this answer

Identity policies are associated directly with an Access Control Policy under the Advanced tab or specific settings, which links the user mapping to traffic inspection.

68
MCQmedium

Which feature in FMC allows you to group multiple physical interfaces into a single logical zone for policy assignment?

A.Security Zone
B.VLAN Group
C.Port Channel
D.Bridge Group
AnswerA

Security Zones are the FMC construct for this purpose.

Why this answer

Security Zones allow logical grouping of interfaces for easier policy management.

69
Multi-Selecthard

When configuring an FQDN object, which THREE options are valid for the FQDN field?

Select 3 answers
A.IP address
B.Subdomain
C.Wildcard domain
D.Protocol name
E.Single domain name
AnswersB, C, E

Matches specific subdomains.

Why this answer

FQDN objects can be a single domain, a wildcard domain, or a domain with specific subdomains.

70
MCQmedium

A network engineer needs to configure Auto NAT on a Firepower Threat Defense device managed by FMC to translate internal subnet 10.10.10.0/24 to a single public IP address 203.0.113.50. Which translation type should be selected?

A.Static NAT
B.Dynamic PAT (Port Address Translation)
C.Static Identity NAT
D.Dynamic NAT
AnswerB

Dynamic PAT maps an entire subnet to a single IP address by translating source ports.

Why this answer

Dynamic PAT translates a pool of inside IP addresses to a single outside IP address using unique port numbers, which matches mapping a subnet to a single public IP.

71
MCQeasy

An administrator needs to create a variable set to define specific port or network variables used within Intrusion Rules. Where are variable sets managed in the FMC?

A.Devices > Device Management > Variables
B.Objects > Object Management > Variable Sets
C.System > Localized Variables
D.Policies > Access Control > Variables
AnswerB

Intrusion rule variable sets are managed under Objects > Object Management > Variable Sets.

Why this answer

Variable sets are managed under Objects > Object Management > Variable Sets.

72
MCQhard

An enterprise requires FTD to decrypt outbound SSL/TLS traffic so internal users visiting external websites can be inspected by Snort for malware. Which policy and action combination must be configured?

A.SSL/TLS Decryption Policy with Decrypt - Resign action
B.Prefilter Policy configured with SSL Bypass
C.SSL/TLS Decryption Policy with Decrypt - Inbound action
D.Access Control Policy with Malware Inspection enabled and no SSL policy
AnswerA

Decrypt - Resign re-signs outbound traffic with a trusted local CA certificate to allow inspection.

Why this answer

Outbound SSL decryption requires an SSL/TLS Decryption Policy with a 'Decrypt - Resign' action using an internal subordinate CA certificate.

73
MCQeasy

In the context of FTD, what does 'FMC' stand for?

A.Firewall Management Console
B.Firewall Monitoring Center
C.Firepower Managed Cloud
D.Firepower Management Center
AnswerD

Correct product name.

Why this answer

FMC is the central management platform for FTD devices.

74
Multi-Selectmedium

Which TWO tasks are required to delete a NAT rule safely?

Select 2 answers
A.Deploy changes
B.Identify dependencies
C.Backup the FMC
D.Disable the rule
E.Rename the rule
AnswersA, B

Required to effect the deletion on the device.

Why this answer

Before deleting, ensure no other policies reference it and save/deploy the changes.

75
MCQmedium

An administrator needs to ensure that internal users can access the internet using a public IP while hiding their private address. Which NAT rule type should be configured on the FMC?

A.Policy NAT
B.Identity NAT
C.Static NAT
D.Dynamic NAT
AnswerD

Dynamic NAT provides a pool of addresses or PAT to translate internal hosts to a public IP.

Why this answer

Dynamic NAT or PAT is used to map internal private addresses to public addresses for outbound internet traffic.

Page 1 of 2 · 128 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Configuration questions.