Courseiva

CCNA Integration Questions

75 of 106 questions · Page 1/2 · Integration · Answers revealed

1
MCQmedium

An administrator is troubleshooting a syslog integration where Secure Firewall Threat Defense is sending logs to a SIEM, but the receiving SIEM cannot parse the message headers properly because the timestamp format is in local time rather than UTC. Where can the timestamp format for syslog messages be adjusted on the FMC?

A.In Platform Settings > Syslog settings, under the advanced options for syslog message formatting.
B.In Objects > Object Management > Syslog Formats.
C.In the Access Control Policy advanced logging tab.
D.In System > Preferences > Timezone on the FMC.
AnswerA

Syslog formatting options, including timestamps (UTC vs local), are configured within the Platform Settings policy applied to the FTD.

Why this answer

Syslog timestamp formats (such as UTC vs local time, and inclusion of year) are configured in the FTD Platform Settings under the Syslog or Time synchronization settings.

2
MCQhard

An organization configures third-party SIEM integration where Secure Firewall Threat Defense sends syslog messages over UDP. During high-traffic events, the SIEM administrator notices significant log dropping and packet loss across the network. What is the best practice solution to ensure reliable syslog delivery without packet loss due to UDP buffer overflows?

A.Configure Reliable Syslog utilizing TCP transport to ensure flow control and guaranteed packet delivery.
B.Increase the UDP socket buffer size on the FTD expert shell using sysctl kernel tuning.
C.Disable connection logging and rely solely on eStreamer.
D.Configure NAT overload on the syslog export interface.
AnswerA

TCP provides retransmission and flow control, eliminating the packet loss issues inherent to UDP syslog in high-traffic environments.

Why this answer

UDP is a best-effort transport protocol prone to packet loss during network congestion. Switching to Reliable Syslog (TCP with TLS encryption) ensures flow control, retransmissions, and guaranteed delivery of syslog messages to the SIEM.

3
MCQmedium

An administrator configures Cisco Secure Firewall Threat Defense to send syslog messages to a SIEM. The administrator wants to ensure that syslog messages include the unique firewall ID (device name) and structured metadata so the SIEM can distinguish logs coming from multiple firewalls in a cluster. Where is this configured?

A.In Platform Settings > Syslog > Syslog Settings, configure the device identifier option (device name or IP).
B.Via the FTD CLI command 'syslog device-name override'.
C.In Objects > Object Management > Syslog Headers.
D.In System > Configuration > Identification.
AnswerA

Syslog headers can be customized in Platform Settings to include the firewall device name or identifier.

Why this answer

FTD Platform Settings allow configuring syslog header formats, including device identifiers, serial numbers, or custom message prefixes to distinguish devices in multi-firewall deployments.

4
MCQhard

An administrator is troubleshooting a Cisco Secure Firewall Threat Defense deployment integrated with Cisco ISE using pxGrid for TrustSec. The firewall is failing to enforce Security Group Tag (SGT) filtering on incoming traffic. What is the most likely cause of this issue?

A.Inline tagging is disabled in the access control policy Advanced settings.
B.Syslog event generation for identity events is disabled in the platform settings.
C.The pxGrid certificate on ISE has expired, but the node trust is still active.
D.The eStreamer service on the FMC is stopped.
AnswerA

SGT enforcement requires inline tagging to be enabled so the firewall can read the SGT header encapsulated in the packet.

Why this answer

For SGT enforcement to work properly on Secure Firewall Threat Defense, inline tagging must be enabled on the access control policy or the SGT/ISE integration must be explicitly mapped and enabled in the platform settings and access control rules, ensuring SGT metadata is preserved across security zones.

5
MCQmedium

An administrator is configuring third-party SIEM integration using eStreamer on the FMC. A custom client application is written to connect to the FMC eStreamer server, but the connection is immediately reset. What is the most likely cause of this issue?

A.The SIEM is using TCP port 443 instead of eStreamer default port 8305.
B.The eStreamer client certificate and pkcs12 password have not been generated and configured on the FMC.
C.Syslog facility levels are set to local0 instead of daemon.
D.pxGrid service is disabled on the FMC.
AnswerB

eStreamer requires mutual authentication via a generated client certificate and unique password.

Why this answer

Before an eStreamer client can connect to FMC, an eStreamer certificate and password must be generated on the FMC and imported into the client application.

6
MCQeasy

Which protocol does Cisco Secure Firewall Threat Defense use to exchange SGT (Security Group Tag) metadata across intermediate routers that do not support inline tagging?

A.RADIUS
B.TACACS+
C.SNMPv3
D.SXP (Scalable Group Tag Exchange Protocol)
AnswerD

SXP is the control plane protocol used to distribute SGT mappings to devices like FTD across non-TrustSec networks.

Why this answer

SXP (Scalable Group Tag Exchange Protocol) is a protocol used to propagate SGT-to-IP mappings across network devices and firewalls that do not support inline MACsec or IPsec SGT propagation.

7
Multi-Selecthard

An administrator configures Cisco Secure Firewall Threat Defense to send syslog messages to a remote SIEM. Which TWO features help ensure that syslog messages are transmitted securely and reliably across untrusted networks? (Choose two)

Select 2 answers
A.Configuring SNMPv3 privacy and authentication parameters on the syslog server.
B.Enabling TLS encryption for syslog transmission to protect sensitive log contents in transit.
C.Configuring Reliable Syslog over TCP to enable packet retransmissions and flow control.
D.Configuring the syslog server IP as a secondary management gateway.
E.Enabling SSH tunneling on UDP port 514.
AnswersB, C

TLS encryption secures syslog data against eavesdropping across untrusted networks.

Why this answer

Reliable syslog uses TCP and TLS encryption to secure and guarantee delivery of syslog messages.

8
Multi-Selecthard

An administrator is troubleshooting an eStreamer connection between the FMC and a custom Python SIEM script. The connection is established, but no intrusion events appear in the SIEM. Which TWO potential reasons could explain why intrusion events are missing from the stream? (Choose two)

Select 2 answers
A.The SIEM script is using UDP instead of TCP for eStreamer communication.
B.The FMC eStreamer listening port was changed from 8302 to 443.
C.The Access Control policy applied to the FTD devices does not have an Intrusion Policy assigned to inspect and generate events.
D.The eStreamer client script failed to subscribe to intrusion event record types during the initial handshake request.
E.The FTD management interface IP address is blocked by an Access Control rule.
AnswersC, D

If intrusion inspection is set to 'None' or 'Access Control with no IPS', no intrusion events are generated for eStreamer to stream.

Why this answer

Missing intrusion events in eStreamer can result from the client script not subscribing to intrusion event types during initialization or from Access Control rules not having intrusion policies enabled.

9
MCQmedium

You are integrating Cisco Secure Firewall Management Center (FMC) with Cisco Identity Services Engine (ISE) via pxGrid. After successfully establishing the pxGrid connection, user identity data is not populating on the FMC. Where in the FMC GUI should you verify that the SGTs and user-to-IP mappings are being received?

A.Devices > Device Management > Advanced > pxGrid
B.Objects > Object Management > Access Control List
C.Analysis > Users > Active Sessions
D.System > Integration > Cisco ISE > Runtime Status
AnswerC

Analysis > Users > Active Sessions displays the current user-to-IP mappings and identity data learned from ISE via pxGrid.

Why this answer

User-to-IP mappings and Security Group Tags (SGTs) received via pxGrid can be verified under Analysis > Users > User Activity or by checking the Connection Status within the ISE configuration pane under System > Integration > ISE.

10
MCQeasy

When configuring the integration between Cisco Secure Firewall and Cisco ISE via pxGrid, what is the primary role of Cisco ISE in this architecture?

A.To act as the primary syslog collector for firewall intrusion alerts.
B.To act as an inline packet inspection engine for Layer 7 threats.
C.To provide user identity, IP address mapping, and group context to the firewall.
D.To store and analyze raw eStreamer event streams from the firewall.
AnswerC

ISE provides rich identity and context via pxGrid to enrich firewall policies.

Why this answer

Cisco ISE acts as the source of truth for user identity, endpoint posture, and contextual metadata, sharing it with the firewall via pxGrid.

11
MCQeasy

An administrator needs to forward Cisco Secure Firewall Threat Defense intrusion events to a third-party SIEM in real-time. Which menu path in the Firepower Management Center is used to configure syslog alerts for intrusion rules?

A.Analysis > Intrusion > Events > Configuration
B.Devices > Device Management > Syslog
C.Policies > Access Control > Intrusion
D.System > Integration > Syslog
AnswerC

Intrusion policies contain the rule states and alert actions, including syslog notification configuration.

Why this answer

Intrusion event alerting via syslog in FMC is configured by navigating to Policies > Access Control > Intrusion, editing the intrusion policy, and configuring the alert destination settings or global alert responses.

12
MCQeasy

Which Cisco SecureX component acts as the central pivot point for threat investigations across Cisco Secure Firewall, Cisco Secure Endpoint, and third-party security tools?

A.Cisco Threat Response
B.Cisco eStreamer Client
C.Cisco ISE pxGrid Server
D.Firepower Device Manager (FDM)
AnswerA

Cisco Threat Response (integrated into SecureX) provides the pivoting and threat investigation engine across products.

Why this answer

Cisco SecureX (or Cisco XDR) provides a cloud-native platform that unifies visibility and enables pivoting across security products.

13
Multi-Selecthard

An administrator is reviewing the health of the Cisco Secure Firewall Management Center integration with Cisco SecureX. Which TWO methods can be used to verify that the integration is functioning properly? (Choose two)

Select 2 answers
A.Run 'show securex status' on the FTD CLI.
B.Inspect the 'pxgrid.log' file on the FMC.
C.Run 'show estreamer status' on the FTD CLI.
D.Examine cloud services and API log files in the FMC expert shell under /var/log/cisco/.
E.Check the connection and registration status indicator under System > Integration > SecureX on the FMC GUI.
AnswersD, E

FMC expert shell logs detail API calls and cloud synchronization events.

Why this answer

Integration status can be verified through the FMC System > Integration > SecureX health status and by checking cloud services API logs on the FMC expert shell.

14
MCQmedium

An administrator is configuring Cisco Secure Firewall Threat Defense to forward syslog messages. The security team requires that only critical intrusion events and high-severity security alerts are sent via syslog, filtering out routine connection permits. Where should the administrator configure severity filtering for syslog export?

A.In FTD Platform Settings > Syslog > Event Logging, configure severity thresholds for specific event categories.
B.Via the FTD CLI command 'logging severity-filter critical'.
C.In the Access Control Policy advanced tab by disabling connection logging.
D.In Objects > Object Management > Syslog Severity.
AnswerA

Platform Settings allow fine-tuning which event categories and severity levels are exported to syslog.

Why this answer

In FTD Platform Settings > Syslog, administrators can select specific event classes (such as Intrusion, Security Intelligence, or Access Control) and assign severity filters so that only desired severity levels are exported.

15
MCQmedium

An administrator wishes to configure third-party SIEM integration with Cisco Secure Firewall Threat Defense by forwarding security events in a standard format. While eStreamer is available, the SIEM only accepts standard syslog. Which configuration options must be selected in FMC to ensure the SIEM receives parseable CEF (Common Event Format) or LEEF logs?

A.Configure syslog output format to include unified syslog or standard text formats compatible with SIEM parsers in Platform Settings.
B.Enable the eStreamer-to-Syslog translator daemon inside Access Control policies.
C.Configure NetFlow v9 templates with custom CEF field type definitions.
D.Install a CEF/LEEF plugin on the managed Threat Defense device via FlexConfig.
AnswerA

FMC allows configuring syslog message formats and severity levels in Platform Settings to match SIEM parsing expectations.

Why this answer

FMC Platform Settings or Alert configurations allow formatting syslog output into industry-standard formats such as Cisco standard, or leveraging advanced logging integrations. Wait, FMC syslog settings support Cisco legacy format or standard syslog, but third-party SIEM parsing often relies on specific header mappings or third-party connectors. Let's look at standard FMC syslog capabilities: FMC allows configuring syslog alert formats under Platform Settings.

16
MCQeasy

When configuring Cisco Secure Firewall Threat Defense to forward syslog messages to a remote SIEM receiver, which transport layer protocols are natively supported for syslog export?

A.HTTP and HTTPS only
B.UDP only
C.UDP and TCP
D.TCP and SCTP
AnswerC

FTD supports both UDP and TCP transport protocols for syslog transmission.

Why this answer

Cisco Secure Firewall Threat Defense supports both UDP and TCP (including reliable syslog over TCP) for transmitting syslog messages to external SIEMs.

17
MCQeasy

When configuring Cisco ISE pxGrid integration within the Firepower Management Center, which TCP port must be open across the intermediate firewall for secure pxGrid communication?

A.TCP 389
B.TCP 8910
C.TCP 80
D.UDP 514
AnswerB

TCP 8910 is the standard designated port for Cisco pxGrid services.

Why this answer

Cisco ISE pxGrid typically operates over TCP port 8910 for client-server communications.

18
MCQmedium

An administrator configures an eStreamer client script on a remote server to receive events from FMC. The script connects successfully and starts receiving events, but after a few hours, the connection drops and throws a timeout error. What is the most likely cause of this behavior?

A.The eStreamer service on the FMC has a hard-coded 2-hour session limit for security reasons.
B.The FMC automatically rotates the eStreamer client certificate every 4 hours.
C.The Snort inspection engine on the FTD restarts hourly to clear cache.
D.An intermediate firewall or stateful device closed the TCP port 8302 session due to inactivity timeout.
AnswerD

Stateful firewalls drop idle TCP connections if no keepalives or data are exchanged within the configured timeout window.

Why this answer

Firewalls or intermediate network devices along the path between the external eStreamer client and the FMC often have idle session timeouts (e.g., 30 minutes or 1 hour). If eStreamer traffic is quiet, the session times out. eStreamer keepalive configurations or firewall idle timeouts must be adjusted.

19
Multi-Selecthard

An engineer configures Cisco Secure Firewall Threat Defense to ingest SGTs from Cisco ISE via pxGrid and wants to enforce access control based on these tags. Which TWO requirements must be met for the firewall to successfully enforce SGT-based policies? (Choose two)

Select 2 answers
A.An active eStreamer subscription for intrusion event streaming.
B.Syslog server configuration with local4 facility enabled.
C.Active Directory domain controller LDAP integration directly configured on the FTD CLI.
D.An active and healthy pxGrid connection between ISE and FMC to synchronize IP-to-SGT mappings.
E.Proper SXP peering or inline TrustSec configuration so data plane packets retain SGT metadata across the network.
AnswersD, E

pxGrid provides the runtime IP-to-SGT mapping table consumed by the firewall.

Why this answer

Enforcing SGT-based policies requires an active pxGrid connection for mapping retrieval and SXP/inline propagation so data plane packets carry the tag metadata.

20
Multi-Selecthard

An engineer is troubleshooting Cisco Secure Firewall integration with Cisco SecureX. The integration is active, but a custom threat indicator block action initiated in SecureX fails to reach the managed FTD devices. Which TWO troubleshooting steps should the engineer perform? (Choose two)

Select 2 answers
A.Run 'show pxgrid status' on the FTD CLI.
B.Inspect the 'estreamer.log' on the FTD CLI.
C.Check FMC cloud services log files to verify that API requests from SecureX completed successfully without authorization errors.
D.Verify that FMC successfully received the SecureX API webhook/call and generated a pending policy deployment for the FTD.
E.Restart the physical FTD appliance to force cloud synchronization.
AnswersC, D

FMC logs API transactions and will show authentication or parsing errors if SecureX requests fail.

Why this answer

Troubleshooting SecureX action delivery involves checking API communication between SecureX and FMC, and verifying that FMC successfully deploys policy updates to the FTD sensors.

21
Multi-Selecthard

An administrator is configuring Cisco Secure Firewall Threat Defense to export syslog messages to a remote SIEM. Which TWO parameters can be customized under the FTD Platform Settings syslog configuration? (Choose two)

Select 2 answers
A.The encryption algorithm used for IPsec VPN tunnels terminating on the FTD
B.The OSPF routing protocol router ID
C.The Snort inspection engine memory allocation size
D.Syslog facility levels (e.g., local0 through local7) and severity filters
E.Syslog transport protocol (UDP or TCP/Reliable Syslog with TLS encryption)
AnswersD, E

Administrators can configure the syslog facility and severity filtering per event category.

Why this answer

Platform Settings for syslog allow configuring transport protocols (UDP/TCP/Reliable Syslog), log facilities, message formatting, and severity filters.

22
Multi-Selecthard

An administrator is troubleshooting an eStreamer integration where the client script disconnects immediately after authentication. Upon inspecting the logs, the administrator notes an SSL certificate verification error. Which TWO areas should be checked to resolve this certificate error? (Choose two)

Select 2 answers
A.Verify the pxGrid client approval status on the Cisco ISE dashboard.
B.Verify that the FMC CA root certificate has been correctly imported into the client application's trust store.
C.Ensure that the client certificate and private key bundle generated from the FMC were correctly copied and referenced by the client script.
D.Check the FTD Platform Settings syslog server IP configuration.
E.Restart the Snort engine on the FTD device.
AnswersB, C

The client must trust the FMC CA to validate the server certificate.

Why this answer

eStreamer TLS verification errors occur when the client lacks the FMC CA certificate or when the client certificate bundle generated from the FMC is invalid or expired.

23
Multi-Selecthard

An administrator is troubleshooting Cisco ISE pxGrid integration with Secure Firewall Management Center. Which TWO issues commonly prevent successful pxGrid registration and trust establishment? (Choose two)

Select 2 answers
A.The FMC client certificate is pending manual approval in the Cisco ISE pxGrid Services client management console.
B.The FTD device is missing an Active Directory domain join account.
C.The FMC lacks the Root or Intermediate CA certificate of the ISE PKI in its trusted certificate store.
D.The eStreamer service port 8302 is blocked on the ISE server.
E.The Snort engine on the FTD is disabled.
AnswersA, C

New pxGrid client registrations on ISE often require manual approval unless automatic approval is configured.

Why this answer

pxGrid integration issues frequently stem from certificate validation errors (missing CA chains) or unapproved client registrations on the ISE pxGrid dashboard.

24
MCQhard

An administrator is integrating Cisco Secure Firewall Management Center with Cisco ISE via pxGrid. The connection fails during the certificate validation phase because the FMC rejects the ISE pxGrid certificate. Upon inspection, the FMC certificate store lacks the intermediate CA certificate of the PKI hierarchy used by ISE. How should the administrator resolve this?

A.Configure an SNMPv3 community string to bridge the certificate trust gap.
B.Upload the complete certificate authority chain (Root and Intermediate CA certificates) into the FMC Trusted CAs object repository.
C.Generate a self-signed certificate on the FTD CLI and assign it as the pxGrid trust anchor.
D.Disable certificate validation in the FMC pxGrid advanced configuration menu.
AnswerB

The FMC must have the entire CA chain trusted to validate the ISE pxGrid server certificate successfully.

Why this answer

Mutual TLS for pxGrid requires the FMC to trust the entire certificate chain presented by ISE. The administrator must upload both the Root CA and Intermediate CA certificates of the ISE PKI to the FMC's trusted certificate store under Object Management > PKI > Trusted CAs.

25
Multi-Selecthard

An engineer is configuring Cisco eStreamer to stream security events from FMC to a third-party SIEM. Which THREE components or prerequisites must be properly established for the eStreamer client to successfully connect and receive events? (Choose three)

Select 3 answers
A.Enable SNMPv2c traps on all managed FTD devices.
B.Generate a valid eStreamer client certificate bundle (PKCS#12) and configure the client IP address on the FMC.
C.Ensure TCP port 8302 is allowed through any intermediate firewalls between the SIEM client and the FMC management interface.
D.Configure UDP port 514 forwarding on the FTD data interfaces.
E.Install the FMC CA certificate on the SIEM client host so it trusts the FMC server certificate.
AnswersB, C, E

The FMC must authorize the client IP and issue a client certificate bundle for mutual TLS authentication.

Why this answer

eStreamer integration requires generating client certificate bundles, ensuring network access on port 8302, and enabling the eStreamer service/client rights on the FMC.

26
MCQeasy

An enterprise environment requires streaming connection events, intrusion events, and file events from Cisco Secure Firewall Threat Defense to a third-party SIEM. Which native protocol and feature on the firewall is designed to stream these events in real time?

A.NetFlow v9
B.Syslog over UDP
C.eStreamer
D.SNMPv3 Traps
AnswerC

eStreamer is Cisco's proprietary protocol designed to securely stream intrusion, connection, and file events to third-party SIEMs.

Why this answer

The eStreamer (Event Streamer) API allows external applications and SIEM systems to stream real-time connection, intrusion, and file events from the FMC.

27
MCQeasy

Which command is used on the Cisco Secure Firewall Threat Defense CLI to verify that the device is successfully communicating with the Cisco Secure Firewall Management Center?

A.show fmc status
B.show managers
C.show isc status
D.show controller connection
AnswerB

'show managers' displays the FMC IP address, connection status, and registration key details on the FTD CLI.

Why this answer

To check the registration and management connection status between FTD and FMC, the administrator uses the CLI command 'show managers'.

28
Multi-Selecthard

An enterprise integrates Cisco Secure Firewall Management Center with Cisco ISE via pxGrid. Which TWO conditions or events can cause an active user-to-IP mapping to be purged from the FTD identity table? (Choose two)

Select 2 answers
A.Receipt of a RADIUS accounting stop message or session timeout expiration.
B.A scheduled weekly restart of the eStreamer service on the FMC.
C.Automatic daily rotation of the FMC administrator password.
D.Receipt of an explicit user logoff or session termination event notification from ISE pxGrid.
E.An update to the Snort intrusion signature package.
AnswersA, D

Accounting stop messages or session timeouts signal the end of a user session, clearing the identity map.

Why this answer

Active identity mappings are purged when ISE sends session termination notices (logoff) or when accounting stop messages are received from the network access device.

29
MCQmedium

A network engineer is troubleshooting a Cisco ISE and Cisco Secure Firewall integration where users are failing to get assigned identity-based access control policies. The engineer notices that user-to-IP mappings are successfully retrieved via pxGrid, but Security Group Tags are missing. Where in Cisco FMC should the engineer verify the SXP connection settings?

A.System > Integration > Threat Defense
B.Policies > Access Control > Identity
C.Devices > Device Management > Advanced > SXP
D.Integration > Cisco ISE > SXP
AnswerD

In modern FMC versions, the Cisco ISE integration settings including SXP peer connections are managed under the Integration menu.

Why this answer

SXP configuration on the Secure Firewall managed by FMC is located under Devices > Device Management > Platform Settings, or directly under the specific device configuration depending on the deployment, but specifically under Access Control and Identity Policies for identity sources. Wait, SXP configuration specifically resides under Integration > Cisco ISE > SXP on FMC versions 6.7 and later.

30
Multi-Selecthard

An administrator is troubleshooting an eStreamer client script failure where the connection is refused on port 8302. Which TWO potential causes should the administrator investigate? (Choose two)

Select 2 answers
A.An intermediate firewall or the FMC internal iptables firewall is blocking TCP port 8302 traffic.
B.The FTD Snort engine is out of memory.
C.The DHCP lease on the FTD data interface has expired.
D.The pxGrid certificate on ISE has expired.
E.The eStreamer service/daemon is not running or enabled on the FMC management plane.
AnswersA, E

Firewalls blocking port 8302 will prevent client connections from reaching the FMC eStreamer daemon.

Why this answer

Connection refused errors on port 8302 indicate that the eStreamer service is not running on the FMC or that network filtering/firewalls are blocking access to port 8302.

31
Multi-Selecthard

An administrator wants to configure Access Control rules on Cisco Secure Firewall Threat Defense using identity context received from Cisco ISE via pxGrid. Which TWO criteria can be utilized in the Access Control policy rule configuration once pxGrid is fully integrated? (Choose two)

Select 2 answers
A.User names and User Groups
B.Security Group Tags (SGTs)
C.DHCP lease pool exhaustion percentages
D.OSPF neighbor adjacency states
E.MACsec encryption key lifetimes
AnswersA, B

User identities and group memberships passed from ISE via pxGrid can be used in Access Control rules.

Why this answer

Once pxGrid is integrated, Access Control rules can filter traffic based on user identities, user groups, and Security Group Tags (SGTs).

32
MCQhard

An organization integrates Cisco Secure Firewall Threat Defense with Cisco ISE via pxGrid. The security team notices that identity rules are matching incorrect users for traffic originating from shared Citrix terminal servers or Virtual Desktop Infrastructure (VDI) multi-user hosts. What mechanism must be enabled and configured to properly handle multi-user IP identity attribution on Secure Firewall?

A.Configuring SXP peers between the VDI hypervisor and the FMC.
B.Configuring static NAT overloading on the FTD egress interface.
C.Enabling SNMP polling on the VDI host so FMC can query active user sessions every 10 seconds.
D.Port-Based Identity mapping (or Terminal Services Agent integration) to correlate user sessions by source port in addition to IP address.
AnswerD

Standard IP-to-user mapping fails on shared IP hosts; port-based identity attribution uses source ports to distinguish between multiple concurrent users on the same IP.

Why this answer

For multi-user environments such as Citrix or VDI where multiple users share a single IP address, FTD and ISE must utilize Port-Based Allocation (or Terminal Services Agent / pxGrid multi-user session mapping with port multiplexing) to track user identity based on source ports.

33
Multi-Selecthard

An administrator is troubleshooting an eStreamer client connection between a Python script and the Cisco FMC. The script fails to authenticate. Which TWO items must be verified regarding the eStreamer client credentials? (Choose two)

Select 2 answers
A.Verify that the PKCS#12 certificate file and password/keys used by the client script match the credentials generated on the FMC.
B.Verify that the IP address of the client host matches the authorized IP address configured during eStreamer certificate generation on the FMC.
C.Verify the FTD Active Directory domain password.
D.Check the pxGrid client approval status on the Cisco ISE server.
E.Check the SNMPv3 community string on the FTD management interface.
AnswersA, B

Mutual TLS requires matching client certificates and private keys generated by the FMC.

Why this answer

eStreamer client authentication relies on the generated PKCS#12 certificate bundle and ensuring the client IP address is explicitly authorized in the FMC eStreamer configuration.

34
MCQhard

An organization integrates Cisco Secure Firewall Threat Defense with Cisco SecureX (now Cisco Security Cloud Control / Cisco XDR) for threat intelligence and incident response. When investigating an indicator of compromise (IoC) on SecureX, an administrator triggers a block action for a malicious file hash. How is this block action enforced across the managed Secure Firewall Threat Defense devices?

A.SecureX uses NETCONF to directly modify the running configuration of the FTD data plane, bypassing the FMC.
B.The FTD devices poll Cisco SecureX directly every 60 seconds via secure syslog to retrieve updated file hashes.
C.The action requires the administrator to manually export a Snort rule from SecureX and import it into the FMC Advanced Malware Protection (AMP) policy.
D.The FMC receives the SecureX API notification and automatically pushes an update to the Security Intelligence Blacklist and File Control policies on the FTD.
AnswerD

SecureX communicates via the FMC API to dynamically update blocklists and intelligence feeds on the managed firewalls.

Why this answer

When an observable (such as a file hash or IP) is blocked via Cisco SecureX threat intelligence/threat response integration, the FMC receives the pivot or API call and automatically updates the Security Intelligence Blacklist or File Control policy objects on the managed FTD devices.

35
Multi-Selecthard

An administrator is planning a third-party SIEM integration with Cisco Secure Firewall Management Center. Which TWO methods or protocols are officially supported for exporting event data from the FMC to the SIEM? (Choose two)

Select 2 answers
A.eStreamer API / protocol over TCP port 8302
B.Exporting raw packet captures (PCAP) via FTP every 5 minutes
C.Syslog export (UDP or TCP/TLS) configured via FTD Platform Settings
D.Direct SQL database replication from the FMC internal PostgreSQL database over SSH
E.NetFlow v5 export from the FMC management interface
AnswersA, C

eStreamer is a primary supported method for streaming events to SIEMs.

Why this answer

FMC officially supports eStreamer for streaming structured security events and Platform Settings syslog for exporting syslog-formatted logs to third-party SIEMs.

36
Multi-Selecthard

An engineer is troubleshooting a scenario where Security Group Tags (SGTs) are not being enforced by FTD access control rules despite an active pxGrid connection between ISE and FMC. Which TWO potential causes should the engineer investigate? (Choose two)

Select 2 answers
A.The FTD management interface IP address is not registered in Active Directory.
B.The FMC eStreamer service is disabled, blocking SGT updates.
C.SXP peering or inline TrustSec header propagation is missing along the data path between the endpoint and the FTD interface.
D.Syslog facility local0 is not configured on the switch.
E.The Access Control policy rules do not have the corresponding Security Group Tags selected under the Users/SGT tab.
AnswersC, E

Without SXP or inline TrustSec headers, the firewall data plane does not receive SGT metadata in the packets.

Why this answer

SGT enforcement requires proper SXP/inline propagation across data paths and correct Access Control rule configuration matching the tags.

37
MCQmedium

An engineer is configuring Cisco eStreamer to stream events from FMC to a third-party SIEM. The firewall security policy blocks incoming connections on port 8302 from the SIEM server to the FMC. Which device and interface are involved in listening for the eStreamer client connection?

A.The FTD data interface listening on TCP port 8302.
B.The FTD management interface listening on UDP port 514.
C.The ISE pxGrid node listening on TCP port 8910.
D.The FMC management interface listening on TCP port 8302.
AnswerD

eStreamer runs on the FMC and listens on TCP port 8302 on the management interface.

Why this answer

The eStreamer server process runs on the Cisco Secure Firewall Management Center (FMC), listening on TCP port 8302 on its management interface.

38
Multi-Selecthard

An administrator is designing a logging architecture where Cisco Secure Firewall Threat Defense exports connection and intrusion events to a third-party SIEM. Which TWO design principles should be followed to ensure security and scalability? (Choose two)

Select 2 answers
A.Disable all Access Control rule logging and enable eStreamer over unencrypted TCP port 8302.
B.Rely exclusively on FMC database storage without exporting events to any SIEM.
C.Implement Reliable Syslog (TCP/TLS) to ensure encrypted transmission and prevent packet loss during network congestion.
D.Configure all logs to be exported unencrypted via UDP port 514 across the internet.
E.Configure appropriate severity filters to prevent low-priority debug events from overwhelming SIEM storage and ingestion licenses.
AnswersC, E

TCP with TLS guarantees delivery and protects log data in transit.

Why this answer

SIEM logging design requires leveraging reliable transport (TCP/TLS) to prevent packet loss and implementing event filtering to manage log volume effectively.

39
Multi-Selecthard

An administrator is configuring Cisco ISE pxGrid integration with Cisco Secure Firewall Management Center. Which TWO identity sources or methods supported by ISE can provide context that is subsequently consumed by FTD via pxGrid? (Choose two)

Select 2 answers
A.Raw NetFlow v5 packet streams exported directly from core routers to the FMC
B.Guest WebAuth portal authentications
C.Active Directory / LDAP authentications via 802.1X or RADIUS
D.Local FTD administrator CLI login sessions
E.DHCP server static lease table text files imported manually into FMC
AnswersB, C

Guest users authenticated through ISE portals have their identity context published via pxGrid.

Why this answer

ISE gathers identity context from 802.1X/RADIUS authentications, passive identity collectors, and web authentication portals, publishing them via pxGrid.

40
Multi-Selecthard

An administrator is configuring Cisco Secure Firewall Threat Defense to send syslog messages to a SIEM. Which TWO settings in Platform Settings determine how syslog messages are formatted and transmitted? (Choose two)

Select 2 answers
A.Syslog server transport protocol (UDP or TCP/Reliable Syslog)
B.The SecureX API integration client ID
C.Syslog severity levels and event category logging filters
D.The eStreamer client certificate bundle password
E.The ISE pxGrid node IP address
AnswersA, C

Transport protocol selection is configured within Platform Settings.

Why this answer

Platform Settings allow configuring message severity filters, transport protocol (UDP/TCP), and header formatting options.

41
MCQhard

An enterprise integrates Cisco Secure Firewall Management Center with Cisco ISE via pxGrid. The security team wants to ensure that when an administrator quarantines a host in Cisco SecureX, the firewall immediately drops active connections from that host without waiting for the FMC policy deployment cycle. How does SecureX achieve immediate enforcement on FTD?

A.SecureX sends an SNMP set command directly to the FTD data interface kernel.
B.ISE forces the FTD to reboot into maintenance mode to clear active states.
C.The FTD polls the SecureX cloud API every 1 second, causing high CPU usage.
D.SecureX uses the FMC REST API to dynamically push runtime block instructions that take effect immediately without requiring a full policy deployment.
AnswerD

SecureX leverages FMC APIs for rapid threat containment, applying runtime blocks directly to FTD without a full deployment.

Why this answer

When an immediate mitigation action (such as blocking an IP or domain) is triggered from SecureX, SecureX utilizes the FMC REST API to dynamically inject a transient block or update Security Intelligence runtime blacklists on the FTD data plane instantly, bypassing the lengthy full policy deployment cycle.

42
MCQeasy

Which protocol is utilized by Cisco Secure Firewall Management Center and FTD devices to communicate with Cisco SecureX for cloud-delivered threat intelligence?

A.SNMPv2c
B.HTTPS (REST API over port 443)
C.TFTP
D.Syslog over UDP 514
AnswerB

Cloud integrations and SecureX communication rely on secure HTTPS REST APIs.

Why this answer

Cisco SecureX and cloud services communicate with Cisco Secure Firewall Management Center using REST APIs over HTTPS (port 443).

43
MCQmedium

An administrator configures Cisco Secure Firewall Threat Defense to send connection logs to a syslog server. However, the syslog server receives logs with source IP addresses belonging to the FMC management interface rather than the FTD data interface IP address. What is the correct way to ensure syslog messages are sent directly from the FTD data or management interface as intended?

A.Configure a NAT exemption rule on the FTD to prevent translation of syslog traffic destined for the SIEM.
B.Modify the Snort engine configuration file via Expert Mode to rewrite the source IP of exported syslog packets.
C.Enable 'Reliable Syslog' under System > Preferences on the FMC.
D.Configure the specific syslog server settings under Platform Settings > Syslog on the FMC and designate the desired egress interface for alert generation.
AnswerD

Platform Settings allow specifying the source interface and routing parameters for syslog export from FTD.

Why this answer

In Platform Settings > Syslog, administrators can define the syslog server configuration and explicitly select whether the syslog packets originate from the management interface or a specific data interface (Security Intelligence/Routing configuration).

44
Multi-Selecthard

An enterprise security architect is designing an architecture where Cisco Secure Firewall Threat Defense integrates with a third-party SIEM. Which THREE methods or protocols are officially supported for exporting security events and logs from the FMC/Firewall to the third-party SIEM? (Choose three)

Select 3 answers
A.Direct SQL database replication from the FMC internal PostgreSQL database to the SIEM
B.Cisco SecureX / REST APIs for programmatic event retrieval
C.Syslog (UDP/TCP/TLS) forwarding from Platform Settings
D.SNMPv1 trap forwarding of full packet payloads
E.eStreamer API for custom client integrations
AnswersB, C, E

REST APIs and SecureX integrations allow programmatic polling and event ingestion.

Why this answer

Supported methods for exporting events to third-party SIEMs include syslog, the eStreamer API, and Cisco SecureX/REST APIs.

45
MCQmedium

An administrator is configuring Cisco Secure Firewall Threat Defense to send syslogs to a third-party SIEM. To ensure confidentiality of sensitive log data traversing untrusted network segments, how should the syslog export be configured?

A.Configure Reliable Syslog utilizing TCP with TLS encryption under Platform Settings > Syslog.
B.Configure HTTPS POST requests in the eStreamer client configuration.
C.Enable Secure Shell (SSH) port forwarding for UDP port 514.
D.Tunnel all UDP syslog packets inside an IPsec VPN tunnel terminated on the FMC management interface.
AnswerA

Reliable Syslog enables TCP transport with TLS encryption to protect syslog data in transit.

Why this answer

To secure syslog transmission, administrators configure Reliable Syslog, which uses TLS encryption over TCP (typically on TCP port 6514) between the FTD and the SIEM syslog collector.

46
MCQeasy

An administrator is configuring Cisco Identity Services Engine (ISE) integration with Cisco Secure Firewall Threat Defense using TrustSec. Which protocol is primarily utilized to exchange Security Group Tags (SGTs) and SGs to IP mappings directly between the ISE policy service node and the firewall?

A.RADIUS
B.pxGrid
C.SXP
D.TACACS+ dACLs
AnswerC

SXP is the protocol used to propagate SGTs to devices that do not natively understand inline SGT tagging.

Why this answer

TrustSec SGTs and IP-to-SGT mappings are exchanged between ISE and the firewall utilizing the SGT Exchange Protocol (SXP).

47
MCQeasy

An administrator is configuring Cisco Secure Firewall Threat Defense to send connection and intrusion events to a third-party SIEM. Which protocol and port are natively supported by the eStreamer client integration for streaming events from the firewall?

A.TCP port 514 using standard Syslog
B.TCP port 9997 using Splunk Forwarder protocol
C.UDP port 443 using HTTPS
D.TCP port 8302 using the eStreamer API
AnswerD

eStreamer natively communicates over TCP port 8302 with authenticated and authorized clients.

Why this answer

The Cisco eStreamer (Event Streamer) daemon on Secure Firewall Threat Defense communicates with external clients over TCP port 8302, using a securely negotiated SSL/TLS connection.

48
Multi-Selectmedium

Which THREE configuration settings must be verified on the FMC when troubleshooting syslog export issues to a third-party SIEM receiver? (Choose three)

Select 3 answers
A.Syslog server IP address and port configuration in Platform Settings
B.pxGrid client approval status in Cisco ISE
C.Protocol selection (UDP, TCP, or TLS) matching the SIEM collector capability
D.eStreamer client certificate validity
E.Access Control rule logging options enabled to log at beginning or end of connection
AnswersA, C, E

The destination IP and port must be correctly defined in Platform Settings.

Why this answer

Syslog troubleshooting involves verifying the destination server IP/port, the protocol (UDP/TCP), and ensuring that the appropriate Access Control rules or Platform Settings are configured to actually generate and send the logs.

49
Multi-Selecthard

An administrator wants to ensure that all security event logs from Cisco Secure Firewall Threat Defense are exported reliably and in real time to external security analytics tools. Which TWO deployment and configuration practices should be implemented? (Choose two)

Select 2 answers
A.Rely solely on local FTD disk storage and export logs via manual SCP once a week.
B.Configure Reliable Syslog (TCP with TLS) in FTD Platform Settings to ensure encrypted and guaranteed log delivery.
C.Disable the Snort engine to prevent log buffer congestion.
D.Configure eStreamer on the FMC to stream intrusion, connection, and malware events to a SIEM collector.
E.Configure SNMPv1 traps to poll event counters every 60 seconds.
AnswersB, D

Reliable syslog prevents packet loss and encrypts logs in transit.

Why this answer

Reliable and real-time log export requires configuring both eStreamer for FMC-level event streaming and Reliable Syslog (TCP/TLS) for platform syslog export.

50
MCQhard

An administrator is troubleshooting an eStreamer integration where custom Python client scripts fail to receive events from the FMC. The administrator verifies that network connectivity, certificates, and user permissions are correct. Upon running the client script in verbose mode, the error indicates an 'Incompatible Protocol Version' between the client SDK and the FMC. How is this resolved?

A.Downgrade the FMC software to match the legacy eStreamer client library.
B.Update the eStreamer client SDK on the third-party SIEM to a version compatible with the current FMC software release.
C.Switch from eStreamer to legacy SNMP traps.
D.Modify the eStreamer version registry key in the FMC expert shell configuration file.
AnswerB

Client SDKs must be compatible with the FMC eStreamer server version to negotiate the protocol successfully.

Why this answer

Cisco FMC updates frequently include eStreamer protocol version upgrades. If an older third-party SIEM client SDK is used with a newly upgraded FMC, the client SDK must be updated to match or support the eStreamer protocol version running on the FMC.

51
MCQeasy

Which component in Cisco Secure Firewall architecture is responsible for generating Security Intelligence feeds and synchronizing them with Cisco SecureX threat intelligence?

A.The local DHCP server on the FTD
B.Cisco Identity Services Engine (ISE)
C.Cisco Secure Firewall Management Center (FMC)
D.Cisco DNA Center
AnswerC

FMC downloads and manages global threat intelligence feeds and distributes blacklists to FTD.

Why this answer

The Cisco Secure Firewall Management Center (FMC) downloads Security Intelligence feeds and cloud threat intelligence from Cisco SecureX and distributes them to the managed FTD devices.

52
Multi-Selecteasy

Which TWO details are typically required when establishing a pxGrid connection between Cisco ISE and the Firepower Management Center? (Choose two)

Select 2 answers
A.Cisco ISE node IP address or hostname
B.RADIUS client shared secret for firewall authentication
C.pxGrid client certificate and password / shared secret setup
D.Active Directory Global Catalog server port (3268)
E.SNMP community string for the ISE Policy Service Node
AnswersA, C

The FMC needs to know the IP address or FQDN of the ISE pxGrid node to connect.

Why this answer

Setting up pxGrid requires the ISE server IP address/hostname and the shared secret or certificate configuration used during client registration.

53
Multi-Selectmedium

Which THREE types of events can be streamed natively from Cisco Secure Firewall using the eStreamer API to a third-party SIEM or custom application? (Choose three)

Select 3 answers
A.Connection events
B.FMC hardware temperature sensor telemetry logs
C.File events
D.CLI administrator command audit logs
E.Intrusion events
AnswersA, C, E

Connection events detailing traffic flows can be streamed via eStreamer.

Why this answer

eStreamer supports streaming connection events, intrusion events, and file events (along with malware events).

54
MCQhard

An administrator configures pxGrid integration between Cisco ISE and Cisco Secure Firewall Threat Defense. During the certificate enrollment process, the firewall fails to trust the ISE pxGrid node. What is the most likely root cause of this failure in a standalone FMC deployment?

A.The SXP secret password does not match between ISE and the firewall.
B.The pxGrid subscriber profile on ISE was not approved within 24 hours.
C.The ISE pxGrid root CA certificate is not imported into the FMC trusted certificates store.
D.RADIUS shared secrets are mismatched on the Policy Service Nodes.
AnswerC

Mutual TLS authentication requires the root CA of the peer to be present in the trusted certificate store of the validating device.

Why this answer

For pxGrid communication to establish successfully, the ISE pxGrid node certificate and FMC/Firewall pxGrid certificate must be signed by a mutually trusted Certificate Authority (CA), and the CA root certificate must be imported into the FMC trusted certificates store.

55
MCQmedium

An administrator sets up Cisco ISE and Secure Firewall integration. The firewall successfully learns user identities from ISE pxGrid, but when users roam to a new IP address, the firewall continues to apply the old IP-to-user mapping for several minutes. What is the best way to resolve this synchronization lag?

A.Ensure real-time pxGrid session notifications are enabled and check the Active Directory agent timeouts if applicable.
B.Reboot the FMC daily via a cron job.
C.Increase the NetFlow export interval to 1 minute.
D.Change the syslog facility to emergency.
AnswerA

pxGrid relies on real-time event notifications; verifying pxGrid subscription ensures immediate notification of session attribute changes or roaming.

Why this answer

Tuning the pxGrid session refresh and timeout settings or verifying the pxGrid subscription status ensures prompt updates of session changes.

56
MCQhard

An administrator configures pxGrid integration between Cisco ISE and Secure Firewall Management Center. During the pxGrid certificate generation on ISE, the administrator must export the client certificate and keystore. What format must the client keystore be in when importing it into the FMC to establish the pxGrid trust relationship?

A.Plaintext DER binary format without private keys.
B.PKCS#12 (.pfx/.p12) bundle containing the client certificate, private key, and CA certificate.
C.Microsoft Exchange Web Services (EWS) XML format.
D.Java KeyStore (.jks) format exclusively.
AnswerB

The PKCS#12 format securely bundles the private key, public certificate, and certificate authority chain required for mutual TLS authentication in pxGrid.

Why this answer

When establishing pxGrid integration between FMC and ISE, the administrator imports the ISE root CA certificate and the client certificate/key bundle (typically in PKCS#12 or PEM format depending on the FMC version requirements) into the FMC Identity Services configuration.

57
MCQmedium

An enterprise environment uses Cisco SecureX (now Cisco Security Cloud Control / Cisco XDR) integrated with Cisco Secure Firewall. An incident responder wants to use SecureX threat intelligence to automatically quarantine a compromised host whose IP address was identified by the firewall. Which component acts as the secure relay for API requests between SecureX and an on-premises FMC?

A.Cisco ISE pxGrid Node
B.Cisco Secure Network Analytics Manager
C.eStreamer Event Relay Service
D.SecureX Device Connector
AnswerD

The SecureX Device Connector establishes an outbound-only connection to the cloud, allowing orchestration and pivoting to on-premises FMC APIs.

Why this answer

The SecureX Threat Response (or Cisco XDR) on-premises deployment relies on the SecureX Device Connector (or Secure Client/Cloud Connector framework embedded in FMC) to proxy API requests securely without requiring inbound firewall holes.

58
Multi-Selecthard

An administrator is configuring Cisco Secure Firewall Threat Defense to send syslog messages to a remote SIEM. Which TWO fields or parameters can be included in the syslog output to facilitate incident investigation and event parsing by the SIEM? (Choose two)

Select 2 answers
A.Full memory core dump binary attachments
B.Precise timestamp formatting (UTC or local time) configured in Platform Settings
C.FMC administrator SSH private keys
D.Firewall device name or identifier in the syslog header
E.Raw packet captures (PCAP) of dropped connections embedded in syslog text
AnswersB, D

Timestamps allow SIEMs to accurately order events chronologically.

Why this answer

Syslog messages can include device identifiers and explicit timestamps to aid SIEM log parsing and correlation.

59
MCQhard

An engineer configures Cisco Secure Firewall Threat Defense to ingest context from Cisco ISE using pxGrid. The integration status on the FMC shows 'Connected', but when inspecting user identities via the FTD CLI using 'show user-identity user', no active users appear. Which CLI command should the engineer use to troubleshoot the pxGrid session feed specifically at the FTD process level?

A.Run 'clear pxgrid cache' from the FTD privileged EXEC mode.
B.Access the expert mode shell and check the identity daemon logs or execute 'show idedb statistics'.
C.Run 'debug crypto pxgrid' from the FMC CLI.
D.Execute 'show threat-response status' on the FTD.
AnswerB

The 'idedb' commands and identity daemon logs on the FTD expert shell provide deep visibility into whether user mappings are being received and stored in the database.

Why this answer

To troubleshoot low-level pxGrid and identity agent behavior on Secure Firewall Threat Defense, engineers use diagnostic shell commands such as 'pmtool' or checking the identity daemon logs located in /var/log/Cisco/identity or running 'show idedb' commands.

60
MCQmedium

An administrator is setting up Cisco SecureX threat intelligence integration with Cisco Secure Firewall Management Center. The test connection fails with a 'Token Expired or Invalid' error. What is the correct procedure to re-establish trust and authentication between the FMC and SecureX?

A.Log into the FTD CLI and execute the 'clear securex-token' command.
B.Generate a new client ID and API key from the Cisco SecureX (Security Cloud Control) console and update the integration credentials in FMC System > Integration > SecureX.
C.Reinstall the Snort rule updates package on the FMC.
D.Reboot the FMC appliance to regenerate the internal device certificate.
AnswerB

Cloud integration tokens expire or become invalid if revoked, requiring new credentials to be generated and entered into the FMC.

Why this answer

To resolve API token or cloud registration expirations for SecureX, the administrator must re-register the FMC with SecureX by generating a new API key / integration credential from the SecureX/Security Cloud Control portal and pasting it into the FMC System > Integration > SecureX settings.

61
MCQhard

An administrator integrates Cisco Secure Firewall Management Center with Cisco ISE via pxGrid. After successful registration, the administrator wants to create an Access Control policy rule that blocks traffic from users in the 'Contractors' Security Group Tag. Where in the FMC rule creation wizard should the administrator configure this condition?

A.In the Access Control Rule, navigate to the Users tab and select the desired Security Group Tag.
B.In Objects > Object Management > Access Control > SGT Objects.
C.In the Platform Settings policy under Identity Sources.
D.In the Access Control Rule, navigate to the Networks tab and select Security Groups.
AnswerA

The Users tab in FMC Access Control rules allows administrators to filter traffic based on users, user groups, and Security Group Tags (SGTs).

Why this answer

In FMC Access Control policies, user and tag-based criteria are added under the 'Users' tab of the rule configuration, where Security Group Tags learned via pxGrid can be selected.

62
Multi-Selectmedium

Which TWO benefits are gained by integrating Cisco Secure Firewall with Cisco Identity Services Engine (ISE) using TrustSec SGTs? (Choose two)

Select 2 answers
A.Propagation of security tags across network boundaries via SXP for consistent enforcement
B.Policy creation based on user roles and group membership rather than dynamic IP addresses
C.Automatic remediation of endpoint malware infections via direct quarantine commands sent from the firewall to Active Directory
D.Replacement of traditional routing protocols with TrustSec matrix routing
E.Elimination of the need for access control rules on the firewall
AnswersA, B

SXP propagates tags to devices that do not support inline tagging, maintaining consistent policy.

Why this answer

TrustSec SGT integration allows creating scalable firewall access control policies based on security groups rather than changing IP addresses, and enforcing segmentation across the network.

63
Multi-Selecthard

An organization integrates Cisco Secure Firewall with Cisco SecureX. Which THREE actions or capabilities can be executed as part of this integration? (Choose three)

Select 3 answers
A.Automated blocking of malicious file hashes or IP indicators across managed FTD devices via FMC API orchestration.
B.Configuring Layer 2 switchport access VLAN assignments via SecureX cloud agents.
C.Visualizing threat incidence and pivoting from SecureX ribbon investigations directly to FMC event logs.
D.Replacing the FMC as the primary device management and policy deployment GUI for FTD.
E.Synchronizing global threat intelligence feeds and security intelligence blacklists with the FMC.
AnswersA, C, E

SecureX can orchestrate block actions across firewalls via FMC APIs.

Why this answer

SecureX integration allows threat intelligence synchronization, pivoting for incident investigation, and automated threat response actions like blocking indicators across devices.

64
MCQmedium

An administrator needs to send Cisco Secure Firewall Threat Defense audit logs and security logs to an external syslog server. Which configuration object in the FMC Platform Settings must be modified to define the destination IP address, transport protocol, and port?

A.System > Integration > Syslog
B.Devices > Platform Settings > Syslog > Syslog Servers
C.Access Control Policy > Logging
D.Objects > Object Management > Syslog Destination
AnswerB

Syslog server IP addresses, ports, and protocols are configured under Platform Settings -> Syslog.

Why this answer

Syslog server destinations are configured under Platform Settings via the Syslog server object configuration within the FMC.

65
MCQmedium

A security analyst configures syslog integration on Cisco Secure Firewall Threat Defense to forward critical security events to a Splunk SIEM. Which configuration step must be performed within the Firepower Management Center (FMC) to ensure these logs include the user identity and SGT mapping?

A.Enable SNMP polling on the FMC for user IP mappings.
B.Deploy an eStreamer client directly on the Splunk indexer.
C.Configure NetFlow export templates to include SGT fields.
D.Configure syslog alerts within the Access Control Policy rules and ensure user identity inclusion is enabled.
AnswerD

Access Control rules dictate event logging behavior, and syslog settings must be configured to append user data.

Why this answer

To include identity and user metadata in syslog messages generated by Threat Defense, the administrator must ensure that Extended Syslog formats or appropriate logging destinations containing user activity are enabled within the Platform Settings or Access Control Policy syslog settings.

66
MCQmedium

An administrator is integrating Cisco Secure Firewall Threat Defense with Cisco Identity Services Engine (ISE) using pxGrid. During the initial connection phase, the Secure Firewall is stuck in a 'Connecting' state and fails to download user-to-IP mapping. Where should the administrator check the pxGrid client status and troubleshoot the registration certificate handshake on the Secure Firewall CLI?

A.Run the command 'show pxgrid status' and 'show crypto ca certificates' in the FTD expert mode or CLI.
B.Inspect the 'estreamer.log' file on the FMC to view ISE pxGrid heartbeat failures.
C.Run 'show ise identity source' on the FMC CLI to confirm active pxGrid threads.
D.Check the Platform Settings policy under 'Cisco Identity Services Engine' and review the 'show sgt-mapping' command.
AnswerA

These commands verify the operational status of the pxGrid agent and the validity of the certificates exchanged between the firewall and ISE.

Why this answer

On Secure Firewall Threat Defense (managed via FMC), the pxGrid client runs as part of the FTD platform services. Troubleshooting pxGrid connection issues requires checking the fxos/platform or system logs, specifically using the command 'show pxgrid status' and verifying the PKI certificates issued by ISE under the security-client framework.

67
Multi-Selecthard

An administrator integrates Cisco Secure Firewall with Cisco SecureX. Which TWO components or settings are required on the FMC to establish and maintain this cloud integration? (Choose two)

Select 2 answers
A.Valid API integration keys / credentials generated from the Cisco SecureX cloud management console and pasted into the FMC.
B.An active eStreamer daemon listening on TCP port 8302 for SecureX incoming connection polls.
C.A direct SSH tunnel between the FTD data plane and the SecureX cloud.
D.An active pxGrid session client on every managed FTD device.
E.Outbound HTTPS (TCP port 443) connectivity from the FMC management interface to the SecureX cloud endpoints.
AnswersA, E

API credentials authenticate the FMC to the SecureX cloud services.

Why this answer

SecureX integration on FMC requires outbound internet connectivity over HTTPS (port 443) and valid API integration credentials generated from the SecureX/Security Cloud Control portal.

68
Multi-Selecthard

An administrator is configuring third-party SIEM integration using eStreamer. Which TWO actions must be completed on the FMC to generate the necessary client integration files? (Choose two)

Select 2 answers
A.Enable the pxGrid service persona on the FMC management interface.
B.Generate a SecureX API token from FMC System Preferences.
C.Generate the PKCS#12 certificate bundle and download the CA certificate for the client.
D.Specify the IP address of the external eStreamer client host in the FMC eStreamer configuration menu.
E.Configure a syslog server IP address under FTD Platform Settings.
AnswersC, D

The PKCS#12 bundle and CA certificate are required for mutual TLS authentication.

Why this answer

Generating eStreamer client integration files on FMC requires specifying the client IP address and creating the client certificate bundle.

69
MCQhard

An enterprise integrates Cisco Secure Firewall with Cisco SecureX. The security team wants to leverage SecureX Threat Intelligence to automatically quarantine endpoints that exhibit malicious behavior. How does the integration coordinate this mitigation action across SecureX, FMC, and ISE?

A.SecureX directly accesses the FTD data plane via SSH to shut down the physical switchport.
B.SecureX instructs Cisco ISE via API/pxGrid to apply an Adaptive Network Control (ANC) quarantine policy to the endpoint, while FMC blocks associated traffic flows.
C.The FTD continuously polls SecureX and reconfigures its VLAN database using VTP.
D.ISE sends a DHCP release packet to the endpoint through the FTD inspection engine.
AnswerB

SecureX coordinates across security products, leveraging ISE's ANC to quarantine endpoints at the network access layer and FMC/FTD for traffic blocking.

Why this answer

SecureX orchestrates threat response by triggering an API call to ISE (via pxGrid/ANC) to dynamically apply an Adaptive Network Control (ANC) quarantine policy or to FMC to block the IP, isolating the compromised endpoint.

70
MCQeasy

Which Cisco security product integrates with Secure Firewall to provide threat intelligence sharing, automated response actions, and cross-product pivot investigations across email, endpoint, network, and cloud workloads?

A.Cisco Email Security Appliance (ESA)
B.Cisco SecureX
C.Cisco Prime Infrastructure
D.Cisco AnyConnect Secure Mobility Client
AnswerB

SecureX unifies visibility and enables threat response and automation across email, endpoint, network, and cloud.

Why this answer

Cisco SecureX (evolving into Cisco Security Cloud Control / Cisco XDR) is Cisco's integrated security platform providing unified threat response and visibility across security vectors.

71
Multi-Selecthard

An administrator is troubleshooting a Cisco ISE and Secure Firewall pxGrid integration where identity policies are failing to match traffic. Which TWO tools or diagnostic methods should the administrator use to verify that IP-to-user mappings are present on the FTD? (Choose two)

Select 2 answers
A.Inspect the 'estreamer.log' file on the FTD CLI.
B.Run 'show user-identity user' on the FTD CLI to verify active user mappings.
C.Access the FTD expert mode shell and check identity database statistics using 'show idedb statistics'.
D.Run 'show ise-server status' on the FMC CLI.
E.Run 'debug pxgrid packet' on the FTD privileged EXEC mode.
AnswersB, C

This command displays active user-to-IP mappings currently stored in the FTD memory.

Why this answer

Identity mappings on FTD can be verified using FTD CLI commands such as 'show user-identity user' and inspecting the identity database statistics ('show idedb').

72
Multi-Selecthard

An administrator configures Cisco Secure Firewall Threat Defense to integrate with Cisco ISE via pxGrid. Which TWO operational benefits are provided by this integration for firewall policy enforcement? (Choose two)

Select 2 answers
A.Automatic generation of FTD intrusion detection signatures.
B.Real-time streaming of raw PCAP files to third-party SIEM platforms.
C.Direct management of FMC appliance administrator passwords.
D.Consumption of Security Group Tags (SGTs) for tag-based microsegmentation and access filtering.
E.Enforcement of Access Control policies based on user identity, username, and user group membership.
AnswersD, E

ISE shares SGT mapping via pxGrid for firewall policy enforcement.

Why this answer

pxGrid integration allows identity-based access control rules and dynamic threat mitigation (such as quarantine or tagging) based on ISE context.

73
Multi-Selecthard

An administrator is configuring Cisco Secure Firewall Threat Defense to send syslog messages. Which TWO options can be included in the syslog message header or content to assist SIEM correlation and analysis? (Choose two)

Select 2 answers
A.Device name or firewall identifier in the syslog header
B.FMC administrator password hash for auditing
C.Full Active Directory database file attachments
D.Precise timestamp formatting (UTC or local time) configured in Platform Settings
E.Raw PCAP binary dumps appended to every syslog packet
AnswersA, D

Including the device name in syslog headers helps distinguish logs from multiple firewalls.

Why this answer

Syslog messages can include device identifiers and timestamps to aid SIEM correlation.

74
MCQhard

An organization uses Cisco Secure Firewall Threat Defense and integrates with Cisco ISE for identity policies. The security team notices that identity rules are intermittently failing because the FTD cache of IP-to-user mappings is being flushed unexpectedly. Upon investigation, what condition on FTD or ISE typically causes the purging of active user identity maps?

A.A mismatch in the NTP time synchronization greater than 5 minutes between the FTD and the FMC.
B.Exceeding the FMC database storage limit for event logging.
C.Receipt of an accounting stop message from the authenticator or an explicit session termination event from ISE pxGrid.
D.Automatic daily rotation of the FMC administrator password.
AnswerC

ISE sends session termination or accounting stop events via pxGrid, prompting the FTD to remove the IP-to-user mapping from its active identity table.

Why this answer

User identity mappings on FTD can be purged or invalidated due to RADIUS accounting stop messages, explicit pxGrid session termination notices from ISE (such as logoff or re-authentication timeouts), or when the maximum session idle timer expires on the firewall identity policy configuration.

75
Multi-Selectmedium

Which TWO actions must be performed on Cisco ISE when setting up pxGrid integration with Cisco Secure Firewall Management Center (FMC)? (Choose two.)

Select 2 answers
A.Enable TrustSec SGT propagation via NetFlow v9 on all ISE interfaces.
B.Approve the certificate for the FMC client within the Cisco ISE pxGrid services administration interface.
C.Configure SNMPv3 traps on ISE to forward user IP mappings to the FMC.
D.Configure a RADIUS shared secret on the FMC platform settings page.
E.Enable the pxGrid service on the appropriate Cisco ISE Policy Service Nodes or Administration nodes.
AnswersB, E

ISE requires manual or automatic approval of client certificates attempting to join the pxGrid ecosystem.

Why this answer

When integrating ISE with FMC via pxGrid, you must enable the pxGrid service on the designated ISE nodes and approve the certificate/node registration from the FMC or ISE side depending on auto-approval settings.

Page 1 of 2 · 106 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Integration questions.