300-710 SNCF · domain
scenario questions
Practise Cisco Securing Networks with Cisco Firewalls (300-710 SNCF, CCNP Security) (300-710 SNCF) scenario questions practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice scenario questions questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about scenario questions
scenario questions questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common scenario questions exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All scenario questions questions (478)
Click any question to see the full explanation, or start a practice session above.
An administrator configures DNS injection and rewriting in a manual NAT rule on an FTD device. What is the primary purpose of enabling DNS translation in a NAT rule?
Hard2An administrator needs to determine if the FMC has enough disk space to hold a new software upgrade image. Which menu should they check?
Medium3An engineer has modified several access control rules and object groups on the FMC. Before deploying these changes to the FTD, the engineer wants to review all pending changes to ensure no unauthorized modifications are included. Where in the FMC GUI should the engineer go to view pending deployment changes?
Medium4An administrator is configuring Manual NAT on an FTD device. Which THREE parameters must be defined when creating a Manual Static NAT rule for inbound traffic? (Choose three)
Medium5When using the 'Search' feature in the Access Control Policy, which filter allows you to find all rules containing a specific network object?
Hard6An administrator is troubleshooting a syslog integration where Secure Firewall Threat Defense is sending logs to a SIEM, but the receiving SIEM cannot parse the message headers properly because the timestamp format is in local time rather than UTC. Where can the timestamp format for syslog messages be adjusted on the FMC?
Medium7When configuring an Access Control Policy on the FMC, what is the purpose of the Default Action set at the bottom of the rules table?
Easy8An administrator is troubleshooting a memory leak on an FTD virtual appliance. The administrator wants to inspect real-time memory usage of individual system processes and identify top memory-consuming tasks. Which command should be run in the FTD expert mode shell?
Hard9You are deploying a Cisco Secure Firewall Threat Defense in transparent mode. How are frames forwarded between the internal and external interfaces of the firewall?
Easy10Which TWO statements are true regarding NGIPS passive mode deployment?
Medium11An engineer is deploying a Cisco Secure Firewall Threat Defense in routed mode and must configure an internal interface connected to a data center segment. The requirement is to route traffic at Layer 3 while keeping the firewall transparent to the MAC addresses of the hosts. Which action should the engineer perform on the interface setting in Cisco FMC?
Medium12An administrator is configuring Security Intelligence feeds on the FMC. Which TWO types of objects or feeds can be used to populate Security Intelligence blacklists? (Choose two)
Easy13You need to map internal users to specific security policies based on their AD group membership. What must be configured in FMC to support this?
Medium14An administrator is troubleshooting a packet drop issue on a Firepower Threat Defense (FTD) device managed by Firepower Management Center (FMC). The administrator wants to inspect real-time packets entering and leaving specific interfaces including layer 2/3 headers and ASP drop details. Which built-in FMC feature should the administrator use?
Medium15An engineer is preparing to deploy a Cisco Secure Firewall Threat Defense cluster in an enterprise data center. Which THREE requirements must be verified and configured prior to cluster initialization? (Choose three)
Hard16When deploying an FTD virtual appliance on-prem using VMware ESXi, which virtual network adapter type is recommended for optimal performance?
Easy17An engineer is configuring a Cisco Secure Firewall Threat Defense cluster in a data center. To ensure high availability and prevent split-brain scenarios, what is the specific function of the cluster control link (CCL)?
Hard18An administrator is planning the deployment of a Cisco Secure Firewall Threat Defense device and needs to choose between routed mode and transparent mode. Which factor strongly favors choosing transparent mode?
Easy19Which THREE interface types are supported on FTD appliances?
Hard20What action should you take if you want to test a new Access Control Rule without impacting production traffic?
Medium21An engineer is configuring an Identity Policy in FMC to enforce user-based access control. Active Directory integration has been established via User Agent, but the engineer notices that some users authenticated via remote access VPN are not being resolved to their IP addresses. Which feature must be integrated into the identity configuration to capture IP-to-user mappings for remote access VPN users?
Medium22An FTD device is configured in routed mode. What must be configured to allow traffic to exit the network through the firewall?
Medium23You are configuring a high availability pair of FTDs. Which interface type is strictly reserved for state synchronization?
Medium24Which tab in the Access Control Policy rule editor allows you to specify the source and destination zones?
Easy25An organization configures third-party SIEM integration where Secure Firewall Threat Defense sends syslog messages over UDP. During high-traffic events, the SIEM administrator notices significant log dropping and packet loss across the network. What is the best practice solution to ensure reliable syslog delivery without packet loss due to UDP buffer overflows?
Hard26You are deploying a Cisco Secure Firewall in transparent mode. Which requirement must be met to ensure the appliance can successfully pass traffic between two directly connected subnets?
Medium27You need to configure link redundancy on a Cisco Secure Firewall Threat Defense pair using EtherChannel (Port Channel) across multiple physical interfaces. When configuring LACP (IEEE 802.3ad) for the port channel interface via the Firepower Management Center (FMC), which requirement must be met for successful negotiation?
Medium28An engineer is designing a high-availability architecture utilizing Equal-Cost Multi-Path (ECMP) routing with Cisco Secure Firewall Threat Defense units. Which THREE characteristics or limitations apply to ECMP on FTD? (Choose three)
Hard29You are configuring an SSL Decryption policy. Which action is required to ensure that traffic to a specific financial website is excluded from inspection due to compliance reasons?
Hard30An administrator needs to restore an FMC configuration backup onto a replacement hardware appliance. Which of the following conditions must be met for the backup restoration to succeed successfully?
Medium31Which interface configuration is required to allow traffic to pass between two interfaces that belong to the same bridge group?
Easy32An administrator is troubleshooting a high availability (HA) failover link failure between two FTD physical appliances. Which THREE checks should be performed to diagnose physical and logical connectivity between the failover interfaces? (Choose three)
Medium33When troubleshooting a connectivity issue where traffic is being dropped, which TWO of the following logs or tools should be reviewed first to determine the cause?
Medium34An administrator notices that the FMC Health Monitor shows a 'Critical' alert for the Snort process utilization on an FTD device. What is the most appropriate first-line troubleshooting step from the FMC GUI or FTD CLI to investigate the cause of high Snort CPU usage?
Hard35Which component is responsible for processing traffic in an FTD cluster when 'Distributed' mode is used?
Medium36An administrator configures Cisco Secure Firewall Threat Defense to send syslog messages to a SIEM. The administrator wants to ensure that syslog messages include the unique firewall ID (device name) and structured metadata so the SIEM can distinguish logs coming from multiple firewalls in a cluster. Where is this configured?
Medium37An administrator is configuring Security Intelligence in FMC. Which TWO types of objects can be added to Security Intelligence blacklists or whitelists? (Choose two)
Medium38An administrator is troubleshooting an active/standby Cisco Secure Firewall High Availability pair. Stateful failover is enabled, but active long-lived TCP connections are dropping when a failover occurs. Upon checking the stateful inspection settings, what is the most likely cause of this behavior?
Hard39When configuring an FTD cluster, what is the purpose of the Control Plane IP address?
Hard40Which THREE methods can be used to populate IP address objects or groups in the FMC Object Management? (Choose three)
Hard41When configuring a NAT rule, which THREE options are valid 'Type' selections within the NAT Rule editor?
Hard42Where do you define the 'Search' criteria for finding objects in FMC?
Easy43An administrator is troubleshooting a Cisco Secure Firewall Threat Defense deployment integrated with Cisco ISE using pxGrid for TrustSec. The firewall is failing to enforce Security Group Tag (SGT) filtering on incoming traffic. What is the most likely cause of this issue?
Hard44When you have multiple overlapping NAT rules, which rule is applied?
Hard45A security requirement mandates that QoS be applied to limit bandwidth for guest users. Where is QoS configured on an FMC-managed FTD?
Medium46Where in the FMC UI do you go to create a new Access Control Policy?
Easy47An administrator is configuring third-party SIEM integration using eStreamer on the FMC. A custom client application is written to connect to the FMC eStreamer server, but the connection is immediately reset. What is the most likely cause of this issue?
Medium48An engineer is troubleshooting a high availability failover issue in a Cisco Secure Firewall Threat Defense pair. Which THREE conditions will trigger an automatic failover event in an Active/Standby deployment? (Choose three)
Hard49An administrator is configuring a secure firewall deployment in an environment where dynamic routing via OSPF is required across multiple security zones. Which configuration requirement must be met on the Cisco Secure Firewall Threat Defense?
Medium50Which protocol does Cisco Secure Firewall Threat Defense use to exchange SGT (Security Group Tag) metadata across intermediate routers that do not support inline tagging?
Easy51When deploying an FTD in a virtual environment, what is the primary role of the 'GigabitEthernet0/0' interface by default?
Medium52What must be configured before an Access Control Rule can use a URL category?
Medium53Which component is mandatory for managing multiple FTD devices in a distributed enterprise deployment?
Easy54An administrator is configuring high availability for Cisco Secure Firewall Threat Defense using Cisco FMC. Which TWO configuration steps are required during the initial setup of an Active/Standby HA pair? (Choose two)
Medium55An administrator is configuring inline interface pairs on a Cisco Secure Firewall Threat Defense device. Which THREE characteristics apply to inline deployment mode? (Choose three)
Hard56An administrator wants to view system status and resource metrics directly on an FTD CLI without logging into the FMC. Which TWO commands are commonly used in the FTD diagnostic CLI or expert shell for this purpose? (Choose two)
Easy57What is the effect of changing the order of rules in an Access Control Policy?
Medium58You are deploying an FTD unit in transparent mode. Which requirement must be met for the management interface and data interfaces during the initial configuration?
Medium59What is the result of applying an 'IPS Policy' to an Access Control Rule?
Medium60An administrator needs to configure an identity policy to authenticate users using an external RADIUS server via Passive Authentication. Which mechanism accomplishes passive user identification?
Medium61Which TWO of the following are valid methods for deploying an FTD appliance?
Medium62An administrator configures Cisco Secure Firewall Threat Defense to send syslog messages to a remote SIEM. Which TWO features help ensure that syslog messages are transmitted securely and reliably across untrusted networks? (Choose two)
Hard63An administrator is preparing to upgrade an FTD managed device using the FMC. Before initiating the upgrade, which FMC utility should be run to check for compatibility, disk space, and potential configuration blocks?
Easy64An administrator is troubleshooting an issue where an FMC cannot communicate with a managed FTD device. The health monitor shows registration is down. The administrator checks the FTD CLI and verifies the registration key and NAT ID. Which log file on the FTD should the administrator examine to troubleshoot registration and communication daemon errors (such as sftunnel)?
Hard65What must be done to apply a change made in the Access Control Policy?
Easy66An engineer is configuring a QoS policy on an FMC-managed FTD and needs to police traffic to a maximum bandwidth limit on an interface. Which shaping/policing parameter must be configured?
Hard67An administrator is troubleshooting an eStreamer connection between the FMC and a custom Python SIEM script. The connection is established, but no intrusion events appear in the SIEM. Which TWO potential reasons could explain why intrusion events are missing from the stream? (Choose two)
Hard68An engineer needs to troubleshoot connectivity through an FTD firewall and wants to use the FTD packet tracer utility. Which THREE parameters are required when executing a basic packet tracer command from the diagnostic CLI? (Choose three)
Medium69You are integrating Cisco Secure Firewall Management Center (FMC) with Cisco Identity Services Engine (ISE) via pxGrid. After successfully establishing the pxGrid connection, user identity data is not populating on the FMC. Where in the FMC GUI should you verify that the SGTs and user-to-IP mappings are being received?
Medium70An enterprise network architect is designing high availability for Cisco Secure Firewall Threat Defense using static route tracking and IP SLA. Which THREE components are essential for implementing robust static route tracking? (Choose three)
Hard71An administrator is troubleshooting connectivity issues to the FMC web interface (HTTPS). Which TWO commands or diagnostic checks can be performed on the FMC CLI to verify web server responsiveness and port status? (Choose two)
Medium72An FMC managed deployment is experiencing slow GUI performance and delayed event reporting. The administrator suspects database table bloat in the FMC PostgreSQL database. Which utility or command can the administrator run from the FMC expert shell to analyze and vacuum/optimize the database safely?
Hard73What is the result of using a 'Security Group' object in an Access Control rule?
Hard74In an FTD clustering deployment, how does the control plane communicate state information between the master and slave units?
Hard75What is the primary function of the 'Object Management' section in FMC?
Easy76When creating a network object in FMC, which field allows you to define a group of IP addresses using CIDR notation?
Easy77An administrator needs to deploy an FTD in inline mode for IPS functionality but must ensure that the traffic remains uninterrupted if the software process fails. Which feature should be enabled?
Hard78Which FTD deployment mode is best suited for an environment where the device should monitor traffic without performing any blocking or dropping actions?
Easy79An administrator is deploying Cisco Secure Firewall Virtual in a Microsoft Azure environment using automated templates. The deployment requires multiple network interfaces for management, internal, and external zones. How does Azure assign IP configurations to these virtual network interfaces (NICs)?
Hard80An FTD high-availability pair is experiencing split-brain behavior due to a unidirectional failure of the state and heartbeat links. As a result, both units are claiming to be Active. Which CLI command on the FTD should an administrator use to troubleshoot interface failover status and verify interface health across the failover link?
Hard81An engineer deploys an Access Control Policy change from the FMC to a managed FTD device. The task hangs in the Deployment History with a status of 'Applying' for an extended period. Upon checking the FTD CLI, the engineer notices a locked deployment file or stuck process. What action should be taken to clear or restart the deployment process safely?
Medium82An administrator is configuring security zones on a Cisco Secure Firewall Threat Defense. Which TWO rules regarding security zones and interface assignments are correct? (Choose two)
Medium83An administrator notices that health alerts from managed FTD devices are not appearing in the FMC health monitor, although traffic logs are updating normally. Which service or daemon on the FMC is primarily responsible for collecting and processing health and performance metrics from managed devices?
Medium84Which tab in the FMC Object Manager allows you to manage pre-defined objects?
Medium85An administrator needs to troubleshoot an issue where legitimate traffic is being silently dropped by the FTD device. The standard packet trace does not reveal the exact reason. Which command executed on the FTD CLI is best suited to diagnose accelerated security path (ASP) drops in real time?
Hard86When configuring the integration between Cisco Secure Firewall and Cisco ISE via pxGrid, what is the primary role of Cisco ISE in this architecture?
Easy87An organization is planning to deploy a Cisco Secure Firewall Threat Defense Cluster using three Secure Firewall 9300 security modules to handle a massive aggregate throughput requirement. Which consideration is critical when designing this cluster?
Medium88You are configuring a NAT rule on an FTD device managed by FMC. You need to translate the source IP of internal hosts to a specific public IP address when they access the internet. Which NAT type must be selected in the FMC NAT Rule editor?
Medium89When configuring a QoS policy, what happens if you exceed the 'Rate Limit' set for a traffic class?
Hard90Which TWO FTD interface types are commonly used for connectivity to an ISP?
Easy91An administrator needs to forward Cisco Secure Firewall Threat Defense intrusion events to a third-party SIEM in real-time. Which menu path in the Firepower Management Center is used to configure syslog alerts for intrusion rules?
Easy92Which Cisco SecureX component acts as the central pivot point for threat investigations across Cisco Secure Firewall, Cisco Secure Endpoint, and third-party security tools?
Easy93Which TWO methods can be used to identify users in an Identity Policy?
Medium94An administrator wants to configure an Access Control rule that triggers an Intrusion Policy only when specific vulnerability signatures match. Where is the Intrusion Policy assigned?
Medium95An administrator wants to configure automated backup generation on the FMC and ensure that backup archives are securely offloaded to a remote server. Where is this configured in the FMC GUI?
Easy96An administrator is deploying a Cisco Secure Firewall Virtual (Fv) appliance in an Amazon Web Services (AWS) environment. Which licensing model is typically supported for traffic throughput and feature activation during this cloud deployment?
Easy97An administrator is reviewing the health of the Cisco Secure Firewall Management Center integration with Cisco SecureX. Which TWO methods can be used to verify that the integration is functioning properly? (Choose two)
Hard98An administrator is configuring Cisco Secure Firewall Threat Defense to forward syslog messages. The security team requires that only critical intrusion events and high-severity security alerts are sent via syslog, filtering out routine connection permits. Where should the administrator configure severity filtering for syslog export?
Medium99An administrator wishes to configure third-party SIEM integration with Cisco Secure Firewall Threat Defense by forwarding security events in a standard format. While eStreamer is available, the SIEM only accepts standard syslog. Which configuration options must be selected in FMC to ensure the SIEM receives parseable CEF (Common Event Format) or LEEF logs?
Medium100An administrator notices that health monitors on the FMC show a critical warning for high disk utilization on the /var partition of an FTD device. What is the safest and most standard method to resolve disk space exhaustion caused by accumulated core files and rotated logs on FTD?
Medium101When configuring Cisco Secure Firewall Threat Defense to forward syslog messages to a remote SIEM receiver, which transport layer protocols are natively supported for syslog export?
Easy102Which TWO protocols are commonly managed via Port objects in FMC?
Easy103When configuring Cisco ISE pxGrid integration within the Firepower Management Center, which TCP port must be open across the intermediate firewall for secure pxGrid communication?
Easy104An administrator needs to restore an FMC configuration from a previously saved backup file. Where in the FMC GUI is the Backup/Restore utility located?
Easy105An administrator is deploying a Cisco Secure Firewall Threat Defense Virtual (FTDv) on-premises using a KVM hypervisor. During the initial deployment, the virtual machine fails to boot and console logs indicate an issue with interface mapping. What is a key requirement for physical interface mapping on KVM-based FTDv deployments?
Medium106An administrator needs to create a custom URL object to block a specific malicious domain name 'example.malicious.com' in an Access Control Policy. Which object type should be created?
Easy107An engineer needs to analyze the connection history and security events from an FTD device that occurred three weeks ago. However, when querying the FMC event viewer, the events are missing. What is the most likely cause of this behavior?
Medium108An administrator is configuring Security Intelligence on the FMC to drop traffic from known malicious IP addresses. Where in the Access Control Policy is Security Intelligence evaluated relative to standard access rules?
Medium109An administrator configures an eStreamer client script on a remote server to receive events from FMC. The script connects successfully and starts receiving events, but after a few hours, the connection drops and throws a timeout error. What is the most likely cause of this behavior?
Medium110An engineer configures Cisco Secure Firewall Threat Defense to ingest SGTs from Cisco ISE via pxGrid and wants to enforce access control based on these tags. Which TWO requirements must be met for the firewall to successfully enforce SGT-based policies? (Choose two)
Hard111What is the purpose of an 'FQDN' object in FMC?
Easy112When defining a NAT rule for an internal server, what happens if the 'DNS Rewrite' option is enabled?
Hard113A network security engineer is setting up a high availability (HA) pair for two Cisco Secure Firewall Threat Defense devices managed by Cisco FMC. Which prerequisite condition must be met between the primary and secondary units before configuring the HA pair?
Easy114In routed mode, what is the purpose of the 'Name' assigned to an interface?
Easy115An engineer is troubleshooting Cisco Secure Firewall integration with Cisco SecureX. The integration is active, but a custom threat indicator block action initiated in SecureX fails to reach the managed FTD devices. Which TWO troubleshooting steps should the engineer perform? (Choose two)
Hard116An administrator is deploying static route tracking combined with IP SLA on a Cisco Secure Firewall Threat Defense device managed by Cisco FMC. Which TWO components must be configured to implement this feature successfully? (Choose two)
Medium117An engineer has deployed an active/standby High Availability pair of Cisco Secure Firewall Threat Defense devices. A failure occurs on the active unit, and a failover successfully takes place. However, upon recovery of the original active unit, it immediately resumes its role as the active unit, causing a brief secondary interruption. Which failover setting governs this behavior?
Hard118An administrator needs to monitor the real-time health and status of managed devices from the FMC dashboard. Which TWO dashboard widgets or features are available in FMC to assist with device monitoring? (Choose two)
Medium119If you need to block a specific file type (e.g., .exe) from being downloaded, which feature must you enable in the Access Control Rule?
Hard120An administrator is preparing to perform a system backup on the FMC. Which TWO data categories can be optionally included or excluded when generating the backup? (Choose two)
Medium121An engineer is configuring NGIPS inline sets on a Cisco Secure Firewall Threat Defense deployment. Which THREE configuration options or behaviors are associated with inline sets? (Choose three)
Hard122An administrator is configuring Cisco Secure Firewall Threat Defense to export syslog messages to a remote SIEM. Which TWO parameters can be customized under the FTD Platform Settings syslog configuration? (Choose two)
Hard123An administrator is troubleshooting an eStreamer integration where the client script disconnects immediately after authentication. Upon inspecting the logs, the administrator notes an SSL certificate verification error. Which TWO areas should be checked to resolve this certificate error? (Choose two)
Hard124Which action must be taken on the FTD CLI after a manual configuration change is made, if you want to ensure the FMC does not overwrite it?
Easy125An administrator is deploying an FTD in a virtual environment. What is the minimum recommended vCPU and RAM configuration for an FTDv instance?
Medium126An engineer needs to deploy a Cisco Secure Firewall Threat Defense in transparent firewall mode. Which TWO statements describe characteristics of transparent mode? (Choose two)
Medium127Which license state must an FTD device reach to allow the FMC to push policy configurations to it?
Easy128An enterprise is deploying a Cisco Secure Firewall Threat Defense cluster. During the setup of the Cluster Control Link (CCL), the administrator must ensure specific networking criteria are met. What is a primary design requirement for the CCL interface?
Hard129An administrator is troubleshooting Cisco ISE pxGrid integration with Secure Firewall Management Center. Which TWO issues commonly prevent successful pxGrid registration and trust establishment? (Choose two)
Hard130An administrator is configuring manual NAT on an FTD device managed by FMC. Which TWO parameters must be defined when creating a manual NAT rule? (Choose two)
Medium131An administrator is integrating Cisco Secure Firewall Management Center with Cisco ISE via pxGrid. The connection fails during the certificate validation phase because the FMC rejects the ISE pxGrid certificate. Upon inspection, the FMC certificate store lacks the intermediate CA certificate of the PKI hierarchy used by ISE. How should the administrator resolve this?
Hard132An engineer is configuring Cisco eStreamer to stream security events from FMC to a third-party SIEM. Which THREE components or prerequisites must be properly established for the eStreamer client to successfully connect and receive events? (Choose three)
Hard133An administrator is configuring an NGIPS deployment using a Cisco Secure Firewall Threat Defense inline set. Traffic needs to be analyzed, but certain trusted bulk data transfers should bypass the Snort inspection engine without breaking the inline flow. Which feature should the administrator configure?
Hard134You are configuring SSL decryption. To ensure that traffic to a specific financial domain is NOT decrypted due to privacy regulations, what must you configure in the SSL Decryption Policy?
Hard135An administrator needs to perform a full system backup of the FMC. Where is the most appropriate place to store this backup for long-term disaster recovery?
Medium136An administrator needs to verify if an FTD is correctly receiving updates from the Cisco Support Cloud. Which menu path shows the status of rule updates and threat intelligence feeds?
Medium137An enterprise environment requires streaming connection events, intrusion events, and file events from Cisco Secure Firewall Threat Defense to a third-party SIEM. Which native protocol and feature on the firewall is designed to stream these events in real time?
Easy138An administrator is troubleshooting a scenario where Snort inspection threads on an FTD are crashing intermittently, producing core dumps. To assist Cisco TAC in root cause analysis, what is the correct sequence of tools or CLI commands to collect the necessary diagnostic data?
Hard139Which THREE features are critical for maintaining a stable FTD cluster?
Hard140Which THREE actions can be assigned to an individual rule within an Access Control Policy on the FMC? (Choose three)
Hard141An administrator is deploying a Cisco Secure Firewall Threat Defense High Availability pair. During the initial configuration in Cisco FMC, the administrator assigns specific priority values. How does the failover process use the primary and secondary unit designations and priorities?
Medium142An administrator configures an SSL Decryption Policy with a rule to 'Do Not Decrypt' financial traffic. However, the administrator also wants to ensure that the encrypted session still undergoes basic certificate validation and categorization. How does FTD handle 'Do Not Decrypt' traffic?
Hard143In an FTD cluster, which unit is responsible for assigning flow ownership to other units in the cluster?
Easy144Which command is used on the Cisco Secure Firewall Threat Defense CLI to verify that the device is successfully communicating with the Cisco Secure Firewall Management Center?
Easy145An administrator wants to check the status of all software processes running on an FMC appliance (such as the web server, database, and event handlers) to ensure everything is running smoothly. Which command should be run in the FMC CLI?
Easy146An enterprise integrates Cisco Secure Firewall Management Center with Cisco ISE via pxGrid. Which TWO conditions or events can cause an active user-to-IP mapping to be purged from the FTD identity table? (Choose two)
Hard147When registering a new Cisco Secure Firewall Threat Defense device to Cisco Defense Orchestrator (CDO) or Cisco FMC, what is the primary prerequisite protocol or connectivity requirement that must be established from the managed device toward the management platform?
Easy148An administrator is configuring port channels (EtherChannels) on Cisco Secure Firewall Threat Defense interfaces. Which TWO requirements or guidelines must be followed? (Choose two)
Medium149An administrator needs to configure manual NAT on an FTD device to translate both the source IP and source port of outbound packets originating from 192.168.2.50 to a specific public IP 198.51.100.10 and port 50000. Which manual NAT rule element achieves this?
Medium150A network engineer is troubleshooting a Cisco ISE and Cisco Secure Firewall integration where users are failing to get assigned identity-based access control policies. The engineer notices that user-to-IP mappings are successfully retrieved via pxGrid, but Security Group Tags are missing. Where in Cisco FMC should the engineer verify the SXP connection settings?
Medium151An administrator is troubleshooting an eStreamer client script failure where the connection is refused on port 8302. Which TWO potential causes should the administrator investigate? (Choose two)
Hard152An administrator wants to configure Access Control rules on Cisco Secure Firewall Threat Defense using identity context received from Cisco ISE via pxGrid. Which TWO criteria can be utilized in the Access Control policy rule configuration once pxGrid is fully integrated? (Choose two)
Hard153An administrator is analyzing a troubleshooting scenario involving Snort inspection crashes on an FTD device. Which THREE locations or tools should the administrator check to diagnose why the Snort process restarted or crashed? (Choose three)
Hard154An organization integrates Cisco Secure Firewall Threat Defense with Cisco ISE via pxGrid. The security team notices that identity rules are matching incorrect users for traffic originating from shared Citrix terminal servers or Virtual Desktop Infrastructure (VDI) multi-user hosts. What mechanism must be enabled and configured to properly handle multi-user IP identity attribution on Secure Firewall?
Hard155An administrator is troubleshooting an eStreamer client connection between a Python script and the Cisco FMC. The script fails to authenticate. Which TWO items must be verified regarding the eStreamer client credentials? (Choose two)
Hard156An administrator successfully restores an FMC backup onto a freshly deployed FMC virtual appliance of the exact same software version. However, after the restore completes, all managed FTD devices show a status of 'Offline' or 'Config Apply Failed'. What is the most likely root cause and correct resolution?
Hard157An organization integrates Cisco Secure Firewall Threat Defense with Cisco SecureX (now Cisco Security Cloud Control / Cisco XDR) for threat intelligence and incident response. When investigating an indicator of compromise (IoC) on SecureX, an administrator triggers a block action for a malicious file hash. How is this block action enforced across the managed Secure Firewall Threat Defense devices?
Hard158An administrator is planning a third-party SIEM integration with Cisco Secure Firewall Management Center. Which TWO methods or protocols are officially supported for exporting event data from the FMC to the SIEM? (Choose two)
Hard159Which THREE items are synchronized across an FTD high availability pair?
Hard160An engineer is troubleshooting a scenario where Security Group Tags (SGTs) are not being enforced by FTD access control rules despite an active pxGrid connection between ISE and FMC. Which TWO potential causes should the engineer investigate? (Choose two)
Hard161An administrator is deploying a new Cisco Secure Firewall Threat Defense device and needs to ensure that the firewall performs layer 3 routing while keeping the existing subnet architecture completely transparent to the upstream router. Which firewall mode must be selected during initial configuration?
Easy162An FMC administrator needs to back up configuration data and event data for disaster recovery. Which backup type includes both system configurations and historical event data stored in the database?
Easy163An administrator is planning the deployment of Cisco Secure Firewall Virtual in a public cloud environment (AWS or Azure). Which TWO deployment practices are recommended for ensuring high availability and performance? (Choose two)
Medium164An administrator needs to schedule automated weekly backups of the FMC configuration and store them securely on a remote SCP server. Where is remote backup storage configured in the FMC GUI?
Easy165An engineer is configuring Cisco eStreamer to stream events from FMC to a third-party SIEM. The firewall security policy blocks incoming connections on port 8302 from the SIEM server to the FMC. Which device and interface are involved in listening for the eStreamer client connection?
Medium166An administrator is designing a logging architecture where Cisco Secure Firewall Threat Defense exports connection and intrusion events to a third-party SIEM. Which TWO design principles should be followed to ensure security and scalability? (Choose two)
Hard167During a routine backup of the FMC, the administrator wants to ensure that the generated backup file contains critical historical events, configurations, and intrusion event data so that it can be fully restored to a replacement appliance if necessary. Which backup type should be selected in the FMC?
Easy168Which TWO of the following are valid high availability modes for FTD?
Medium169A network engineer is deploying a Firepower Threat Defense (FTD) device and must configure NAT to translate an internal server IP of 10.10.10.50 to a public IP of 203.0.113.50 while preserving the original source port for inbound traffic. Which NAT type accomplishes this?
Medium170In which mode does the FTD firewall act as a Layer 3 hop and perform NAT?
Easy171An administrator is troubleshooting a policy deployment failure from the Firepower Management Center (FMC) to a managed Firepower Threat Defense (FTD) device. The deployment hangs at 33 percent with an error related to snort synchronization. Which tool should the administrator use on the FTD CLI to examine the real-time Snort rule compilation and policy application process?
Medium172An administrator is configuring static route tracking on a Cisco Secure Firewall Threat Defense deployment to handle link failure. If the tracked object goes down, the static route should be removed from the routing table. Where is this configuration managed when using Cisco FMC?
Hard173An administrator is preparing an upgrade plan for an FMC and its managed FTD devices. Which THREE best practices should be followed during the upgrade process to minimize downtime and avoid failure? (Choose three)
Hard174Which interface configuration mode allows the FTD to handle traffic across multiple physical links as a single logical interface?
Easy175You are configuring High Availability for two FTD devices. Which TWO conditions must be met for a successful failover state? (Choose two)
Hard176An administrator is configuring Cisco ISE pxGrid integration with Cisco Secure Firewall Management Center. Which TWO identity sources or methods supported by ISE can provide context that is subsequently consumed by FTD via pxGrid? (Choose two)
Hard177During an upgrade of an FTD device managed by FMC, the pre-checks fail because of insufficient disk space in the target upgrade partition. Which CLI command sequence should the administrator use to safely clean up previous upgrade installation files and temporary packages?
Hard178Which object type should be used to represent a group of network subnets?
Medium179Which THREE items are required to create a port channel on an FTD device?
Easy180Which TWO of the following are valid reasons to use Transparent Mode?
Medium181When considering virtual FTD deployments, which THREE factors significantly impact the performance of the instance?
Hard182Which type of FTD interface should be configured to connect to a trunk port on a switch?
Easy183Which TWO interface modes are available when configuring an intrusion prevention (NGIPS) security policy on a Cisco Secure Firewall Threat Defense device? (Choose two)
Easy184When using clustering with FTD, what is the 'Flow Owner' in the context of traffic distribution?
Hard185An administrator is configuring Cisco Secure Firewall Threat Defense to send syslog messages to a SIEM. Which TWO settings in Platform Settings determine how syslog messages are formatted and transmitted? (Choose two)
Hard186An administrator wants to create a Port object group containing TCP ports 80, 443, and 8080 on the FMC. Where is this object configured?
Easy187An enterprise integrates Cisco Secure Firewall Management Center with Cisco ISE via pxGrid. The security team wants to ensure that when an administrator quarantines a host in Cisco SecureX, the firewall immediately drops active connections from that host without waiting for the FMC policy deployment cycle. How does SecureX achieve immediate enforcement on FTD?
Hard188Which THREE considerations must be addressed when deploying FTDv in a public cloud?
Hard189When deploying Cisco Secure Firewall Threat Defense in transparent mode, which TWO operational characteristics or restrictions apply to the deployment? (Choose two)
Medium190Which protocol is utilized by Cisco Secure Firewall Management Center and FTD devices to communicate with Cisco SecureX for cloud-delivered threat intelligence?
Easy191A security engineer is deploying a Cisco Secure Firewall Threat Defense device inline in front of a critical server farm. The goal is to inspect all incoming and outgoing traffic for intrusions without modifying the IP addressing schema of the servers. Which interface mode should be configured on the FTD device?
Easy192When troubleshooting FTD policy deployment, which THREE of the following are common reasons for a deployment to fail?
Medium193You are configuring static route tracking on an FTD device. What is the primary purpose of this configuration?
Easy194Which TWO fields are commonly used in the 'NAT Rule' editor to define the source address?
Medium195When deploying a Cisco Secure Firewall Threat Defense in transparent mode, how are the firewall interfaces configured to pass traffic between segments without routing?
Easy196An FTD device is deployed in routed mode with multiple security zones. An administrator needs to configure an Access Control rule that evaluates traffic flowing between two different security zones. How are security zones utilized in the rule?
Hard197An administrator configures Cisco Secure Firewall Threat Defense to send connection logs to a syslog server. However, the syslog server receives logs with source IP addresses belonging to the FMC management interface rather than the FTD data interface IP address. What is the correct way to ensure syslog messages are sent directly from the FTD data or management interface as intended?
Medium198Which THREE settings can be configured within a Prefilter Policy on the FMC? (Choose three)
Hard199You are troubleshooting a port channel failure on an FTD device. The port channel is 'Up/Down'. What is the most likely cause?
Medium200When deploying a Cisco Secure Firewall Threat Defense virtual appliance (FPRv) in a public cloud environment such as Microsoft Azure, which TWO architectural considerations or limitations must be accounted for? (Choose two)
Hard201An enterprise security architect is designing an architecture where Cisco Secure Firewall Threat Defense integrates with a third-party SIEM. Which THREE methods or protocols are officially supported for exporting security events and logs from the FMC/Firewall to the third-party SIEM? (Choose three)
Hard202An administrator wants to export a packet capture (.pcap file) taken on an FTD interface directly from the FMC GUI for offline analysis in Wireshark. Where should the administrator navigate?
Easy203An administrator is configuring Cisco Secure Firewall Threat Defense to send syslogs to a third-party SIEM. To ensure confidentiality of sensitive log data traversing untrusted network segments, how should the syslog export be configured?
Medium204An FTD device is dropping packets unexpectedly. An engineer runs a packet tracer via the FTD diagnostic CLI using 'system support diagnostic-cli' and enters the command: 'packet-tracer input inside tcp 192.168.1.50 12345 10.0.0.5 80'. The output shows a drop at the 'Access-Rule' phase with the action 'DROP'. What does this indicate?
Medium205An administrator is configuring Cisco Identity Services Engine (ISE) integration with Cisco Secure Firewall Threat Defense using TrustSec. Which protocol is primarily utilized to exchange Security Group Tags (SGTs) and SGs to IP mappings directly between the ISE policy service node and the firewall?
Easy206An administrator is configuring Cisco Secure Firewall Threat Defense to send connection and intrusion events to a third-party SIEM. Which protocol and port are natively supported by the eStreamer client integration for streaming events from the firewall?
Easy207An engineer is troubleshooting a packet capture configuration on an FTD device managed by FMC. Which THREE statements regarding FTD packet capture behavior and limitations are correct? (Choose three)
Hard208Which THREE configuration settings must be verified on the FMC when troubleshooting syslog export issues to a third-party SIEM receiver? (Choose three)
Medium209What is the purpose of 'Network Discovery' in FMC?
Medium210An FMC administrator is configuring a URL Filtering policy. They want to block URLs categorized as 'Hacking' while logging the event. Where is this configured within the Access Control Policy?
Hard211When configuring an NGIPS appliance in passive mode, how does the system handle traffic flow to ensure monitoring without impacting the production network?
Hard212An administrator wants to ensure that all security event logs from Cisco Secure Firewall Threat Defense are exported reliably and in real time to external security analytics tools. Which TWO deployment and configuration practices should be implemented? (Choose two)
Hard213An administrator is troubleshooting an eStreamer integration where custom Python client scripts fail to receive events from the FMC. The administrator verifies that network connectivity, certificates, and user permissions are correct. Upon running the client script in verbose mode, the error indicates an 'Incompatible Protocol Version' between the client SDK and the FMC. How is this resolved?
Hard214You are configuring a NAT rule for a web server located in a DMZ. You want to translate the destination IP from a public address to the private DMZ address. Which NAT type is used?
Hard215An administrator is deploying a Cisco Secure Firewall Threat Defense Virtual (FTDv) in Microsoft Azure. The architecture calls for a 3-NIC deployment (Management, Inside, and Outside). After deployment, asymmetric routing issues are observed because Azure Load Balancer is forwarding return traffic directly back to a different backend instance. What configuration must be applied to prevent asymmetric drops?
Hard216An administrator is preparing to deploy Cisco Secure Firewall Threat Defense in passive NGIPS mode connected to a Catalyst switch. Which TWO configuration steps on the switch and firewall are necessary for successful packet inspection? (Choose two)
Medium217An administrator wants to ensure that packet captures taken on an FTD can be analyzed easily. Which TWO ways can packet capture files (.pcap) be retrieved from the FMC? (Choose two)
Easy218An administrator is configuring manual NAT and needs to specify an interface pair (Source Interface and Destination Interface). Why is defining interface objects important in manual NAT rules?
Medium219How do you enable 'High Availability' (HA) for an FTD pair managed by FMC?
Medium220An administrator is configuring Access Control Policy rules on the FMC. The default action for unmatched traffic is currently set to Block. The requirement is changed so that unmatched traffic should pass through the FTD without inspection. Where is this setting modified?
Easy221An engineer is troubleshooting a stateful failover issue in a Cisco Secure Firewall Threat Defense Active/Standby high availability pair. The firewall units are passing data traffic, but failover state synchronization fails. Which dedicated interface must be verified for correct physical connectivity and configuration?
Medium222An engineer is troubleshooting a Cisco Secure Firewall Threat Defense clustering deployment where configuration synchronization between the control node and a data node has failed. Which THREE diagnostic steps or log sources should the engineer check? (Choose three)
Hard223Which component in Cisco Secure Firewall architecture is responsible for generating Security Intelligence feeds and synchronizing them with Cisco SecureX threat intelligence?
Easy224When configuring manual NAT on an FTD device, which THREE options are available for configuring the Translated Source? (Choose three)
Hard225Which TWO details are typically required when establishing a pxGrid connection between Cisco ISE and the Firepower Management Center? (Choose two)
Easy226Which THREE types of events can be streamed natively from Cisco Secure Firewall using the eStreamer API to a third-party SIEM or custom application? (Choose three)
Medium227An administrator configures pxGrid integration between Cisco ISE and Cisco Secure Firewall Threat Defense. During the certificate enrollment process, the firewall fails to trust the ISE pxGrid node. What is the most likely root cause of this failure in a standalone FMC deployment?
Hard228Which component in an FTD cluster handles the 'Health Check' process to determine if a node is still active?
Medium229An FTD device managed by FMC is experiencing high CPU utilization attributed to the Snort inspection engine. The administrator wants to identify which specific intrusion rules or access control rules are consuming the most resources. Which tool or report should the administrator use?
Medium230Which of the following must be identical on both units of an FTD high availability pair to ensure successful synchronization?
Medium231An administrator is troubleshooting a Cisco Secure Firewall Threat Defense high availability deployment where MAC address persistence is causing intermittent packet drops after a failover event. What is the role of MAC address persistence in an HA setup?
Hard232Which THREE criteria can be used to match traffic in an Access Control Policy rule?
Hard233A security engineer is creating an Access Control Policy (ACP) in FMC. The policy must block all traffic matching specific URL categories while allowing standard web browsing. However, the administrator wants users to receive a warning page before continuing to pages categorized as "Potentially Damaging Content" rather than a hard block. Which action should the engineer assign to the URL category in the ACP Rules tab?
Medium234In an FTD high availability pair, what happens to the standby unit if it loses the heartbeat signal on the failover link?
Medium235An engineer needs to troubleshoot intermittent packet loss between an FTD inside interface and a destination server. The engineer runs the 'packet-tracer' command on the FTD CLI. What limitation must the engineer keep in mind regarding packet-tracer?
Medium236An administrator sets up Cisco ISE and Secure Firewall integration. The firewall successfully learns user identities from ISE pxGrid, but when users roam to a new IP address, the firewall continues to apply the old IP-to-user mapping for several minutes. What is the best way to resolve this synchronization lag?
Medium237An administrator is troubleshooting a scenario where configuration deployment from FMC to an FTD device fails with a 'Deployment Validation Error'. Where can the administrator view the detailed validation messages and deployment task history?
Medium238An enterprise is deploying a high-availability cluster of Cisco Secure Firewall Threat Defense devices to scale performance. Which requirement must be met regarding the physical switch infrastructure connecting the cluster nodes?
Medium239An administrator configures pxGrid integration between Cisco ISE and Secure Firewall Management Center. During the pxGrid certificate generation on ISE, the administrator must export the client certificate and keystore. What format must the client keystore be in when importing it into the FMC to establish the pxGrid trust relationship?
Hard240An enterprise environment uses Cisco SecureX (now Cisco Security Cloud Control / Cisco XDR) integrated with Cisco Secure Firewall. An incident responder wants to use SecureX threat intelligence to automatically quarantine a compromised host whose IP address was identified by the firewall. Which component acts as the secure relay for API requests between SecureX and an on-premises FMC?
Medium241What is the consequence of configuring an FTD interface with 'Non-Promiscuous' mode in a virtualized deployment?
Hard242Which TWO items must be defined to create a fully functional Network Object group in FMC?
Medium243When troubleshooting FTD high memory or CPU usage, an administrator can gather diagnostic data directly from the appliance. Which THREE commands can be executed on the FTD CLI to analyze resource utilization? (Choose three.)
Medium244An engineer has deployed a Cisco Secure Firewall Threat Defense in transparent firewall mode. Users on the inside segment report they cannot reach a server on the outside segment. The engineer verifies that the BVI (Bridge Virtual Interface) has an IP address in the same subnet as the internal hosts and default gateway. What is a likely reason for traffic being dropped?
Hard245An administrator needs to verify the license status and active feature subscriptions (such as URL Filtering, Malware, and IPS) on an FMC. Where should the administrator check this information in the FMC GUI?
Easy246When deploying a Cisco Secure Firewall Threat Defense device, what is the purpose of configuring Security Zones?
Easy247An administrator is preparing to troubleshoot a complex routing and NAT issue on an FTD device using packet tracer. Which TWO statements regarding the FTD packet tracer tool are correct? (Choose two.)
Hard248You are analyzing connection events and notice a block action. Which field in the connection event details best explains why the connection was dropped by the policy?
Medium249An enterprise is deploying Cisco Secure Firewall Threat Defense virtual appliances on-premises using VMware ESXi. Which THREE prerequisites or hypervisor configurations are required for proper operation? (Choose three)
Hard250An administrator is configuring Cisco Secure Firewall Threat Defense to send syslog messages to a remote SIEM. Which TWO fields or parameters can be included in the syslog output to facilitate incident investigation and event parsing by the SIEM? (Choose two)
Hard251An engineer configures Cisco Secure Firewall Threat Defense to ingest context from Cisco ISE using pxGrid. The integration status on the FMC shows 'Connected', but when inspecting user identities via the FTD CLI using 'show user-identity user', no active users appear. Which CLI command should the engineer use to troubleshoot the pxGrid session feed specifically at the FTD process level?
Hard252When planning an FTD high availability deployment, which TWO requirements are critical for the link between the two firewalls?
Medium253An administrator is setting up Cisco SecureX threat intelligence integration with Cisco Secure Firewall Management Center. The test connection fails with a 'Token Expired or Invalid' error. What is the correct procedure to re-establish trust and authentication between the FMC and SecureX?
Medium254An administrator is configuring a Network Address Translation (NAT) rule on a Cisco FMC managed Threat Defense device. The requirement is to translate the source IP address of traffic coming from the inside zone going to the outside zone, but only for a specific internal subnet. Which NAT type must the administrator select in the FMC NAT rule configuration?
Easy255An engineer is setting up a Cisco Secure Firewall Threat Defense cluster. Which TWO statements accurately describe the architecture and behavior of FTD clustering? (Choose two)
Medium256An administrator needs to troubleshoot a routing issue on an FTD device managed by FMC. Where in the FMC GUI should the administrator navigate to view and modify static and dynamic routing configurations for the device?
Easy257An administrator wants to create a Prefilter policy to fast-path (bypass Snort inspection for) a trusted backup stream between two data centers. Which action type should be selected in the Prefilter rule?
Easy258When configuring an FTD cluster, what is the maximum number of nodes supported in a single cluster?
Hard259An administrator integrates Cisco Secure Firewall Management Center with Cisco ISE via pxGrid. After successful registration, the administrator wants to create an Access Control policy rule that blocks traffic from users in the 'Contractors' Security Group Tag. Where in the FMC rule creation wizard should the administrator configure this condition?
Hard260You are deploying a Cisco Secure Firewall Threat Defense cluster in a data center environment. Which deployment requirement must be strictly followed regarding the control link and data interfaces?
Medium261Which TWO benefits are gained by integrating Cisco Secure Firewall with Cisco Identity Services Engine (ISE) using TrustSec SGTs? (Choose two)
Medium262An engineer is troubleshooting a Cisco Secure Firewall Threat Defense virtual appliance deployed in Microsoft Azure. Connectivity tests show intermittent packet drops. Which THREE troubleshooting steps or configurations should be verified in Azure and FTDv? (Choose three)
Hard263When utilizing static route tracking, what value represents the frequency of the tracking probe?
Medium264Which protocol is used by the FTD to communicate with the FMC for management traffic?
Hard265An administrator is deploying Cisco Secure Firewall Threat Defense Virtual (FTDv) in an enterprise cloud environment (such as AWS or Azure). Which THREE considerations are unique to cloud-based firewall deployments compared to physical hardware deployments? (Choose three)
Hard266An administrator is configuring Equal-Cost Multi-Path (ECMP) routing on a Cisco Secure Firewall Threat Defense deployment to balance traffic across two upstream next-hop routers. How does the firewall select the specific path for a given TCP flow?
Hard267You are deploying a Cisco Firepower Threat Defense (FTD) device in transparent mode. Which requirement must be met to allow traffic flow through the firewall?
Medium268Which THREE of the following are supported methods for FTD failover mechanism?
Hard269When deploying FTD in a virtual environment on AWS, which feature allows the firewall to handle high-bandwidth traffic by distributing it across multiple interfaces using ECMP?
Medium270An administrator needs to define network objects in the FMC Object Management menu. Which THREE object types are natively supported for network definition? (Choose three)
Easy271An administrator configures an SSL Decryption Policy on the FMC to decrypt inbound HTTPS traffic destined for an internal web server. The administrator imports the private key and server certificate into the FMC. Which decryption action must be selected to allow the FTD to decrypt this traffic using the server's private key?
Hard272You are deploying FTD in a cloud environment. What is the primary purpose of the 'Management Interface' when launching the virtual instance?
Medium273An administrator wants to configure automated email notifications from the FMC whenever a critical health monitor alert occurs on any managed device. Where should this be configured in the FMC GUI?
Easy274An administrator is configuring a Manual NAT rule in the FMC for an internal server that needs to be accessed from the outside zone. The internal IP is 192.168.1.50, and it must be translated to a public IP 203.0.113.10. Which TWO configuration parameters must be specified when defining this Manual NAT rule? (Choose two)
Hard275You are deploying a Cisco FTD High Availability pair. During the synchronization process, what occurs when the standby unit fails to receive three consecutive heartbeat hellos from the primary?
Hard276An organization integrates Cisco Secure Firewall with Cisco SecureX. Which THREE actions or capabilities can be executed as part of this integration? (Choose three)
Hard277An administrator needs to send Cisco Secure Firewall Threat Defense audit logs and security logs to an external syslog server. Which configuration object in the FMC Platform Settings must be modified to define the destination IP address, transport protocol, and port?
Medium278You are deploying an FTD in AWS. What is the correct way to handle the internal IP addresses of the FTD instances in an HA pair?
Medium279An administrator is configuring a Prefilter Policy in FMC to optimize performance on a Cisco Firepower Threat Defense device. The requirement is to completely bypass inspection for a trusted high-speed data backup tunnel between two datacenters using GRE encapsulation. Which prefilter rule action should be selected?
Hard280When configuring a Port Channel on an FTD, what is the primary benefit of using LACP (Link Aggregation Control Protocol)?
Medium281A security analyst configures syslog integration on Cisco Secure Firewall Threat Defense to forward critical security events to a Splunk SIEM. Which configuration step must be performed within the Firepower Management Center (FMC) to ensure these logs include the user identity and SGT mapping?
Medium282An FTD device is failing to register with the FMC. The administrator confirms connectivity via ping. Which CLI command should the administrator run on the FTD to verify the registration status and the shared secret handshake?
Medium283An administrator needs to configure Active Authentication using a captive portal on an FTD device. Which firewall feature must be properly configured and running to present the authentication prompt to users?
Medium284You need to implement static route tracking on an FTD to ensure traffic fails over to a secondary ISP. Which object is used to define the reachability check?
Medium285You are configuring a Cisco Secure Firewall Threat Defense deployment in an AWS environment. Which specific component is required to handle automated failover and route table updates when deploying a clustered or high-availability pair across multiple Availability Zones?
Medium286An administrator wants to decrypt inbound HTTPS traffic destined for a public web server behind a Firepower Threat Defense device. Which type of SSL/TLS decryption policy must be configured on the FMC?
Hard287An administrator is integrating Cisco Secure Firewall Threat Defense with Cisco Identity Services Engine (ISE) using pxGrid. During the initial connection phase, the Secure Firewall is stuck in a 'Connecting' state and fails to download user-to-IP mapping. Where should the administrator check the pxGrid client status and troubleshoot the registration certificate handshake on the Secure Firewall CLI?
Medium288Which tool in the FMC allows you to view the real-time flow of packets being processed by the Snort engine for troubleshooting purposes?
Easy289An administrator configures an Identity Policy on the FMC to authenticate users via Active Directory using captive portal. Where is the Identity Policy applied within the Firepower configuration hierarchy?
Medium290An administrator is configuring an inline interface pair on a Cisco Secure Firewall Threat Defense device using Cisco FMC. The business requires that if the firewall experiences a power failure or kernel panic, traffic must continue to flow uninterrupted through the network segment. Which action should the administrator take?
Medium291An administrator integrates Cisco Secure Firewall with Cisco SecureX. Which TWO components or settings are required on the FMC to establish and maintain this cloud integration? (Choose two)
Hard292An administrator is configuring third-party SIEM integration using eStreamer. Which TWO actions must be completed on the FMC to generate the necessary client integration files? (Choose two)
Hard293Which feature in FMC allows you to group multiple physical interfaces into a single logical zone for policy assignment?
Medium294An enterprise integrates Cisco Secure Firewall with Cisco SecureX. The security team wants to leverage SecureX Threat Intelligence to automatically quarantine endpoints that exhibit malicious behavior. How does the integration coordinate this mitigation action across SecureX, FMC, and ISE?
Hard295When configuring an FQDN object, which THREE options are valid for the FQDN field?
Hard296Which TWO components must be configured to manage an FTD via the FMC?
Medium297An administrator is setting up health monitoring alerts on the FMC. Which TWO notification methods can be configured when a health alert is triggered? (Choose two)
Easy298An administrator is performing a backup and restore operation on an FMC appliance. Which THREE statements are correct regarding the FMC restore process? (Choose three)
Hard299An administrator is troubleshooting a Stateful High Availability (HA) pair of Cisco Secure Firewall 4100 series devices managed by FMC. The units are failing to form an HA state, and logs indicate a state mismatch on the control link. Which underlying cause is most likely preventing the HA synchronization?
Hard300An engineer is deploying Cisco Secure Firewall Threat Defense in a complex multi-zone routed environment. Which THREE design considerations apply when implementing routed mode interfaces? (Choose three)
Hard301A network engineer needs to configure Auto NAT on a Firepower Threat Defense device managed by FMC to translate internal subnet 10.10.10.0/24 to a single public IP address 203.0.113.50. Which translation type should be selected?
Medium302Which Cisco security product integrates with Secure Firewall to provide threat intelligence sharing, automated response actions, and cross-product pivot investigations across email, endpoint, network, and cloud workloads?
Easy303An administrator is troubleshooting an issue where Snort inspection engine crashes repeatedly on an FTD device. Which THREE diagnostic artifacts or steps should the administrator collect and perform to assist Cisco TAC in resolving the core dump issue? (Choose three)
Hard304You are configuring a static route on a Cisco Secure Firewall Threat Defense using FDM. Which parameters are strictly required to create a valid IPv4 static route?
Easy305An engineer is troubleshooting a passive NGIPS deployment where the Cisco Secure Firewall is connected to a switch SPAN port. Security analysts report that certain VLAN-tagged packets are not appearing in the event logs. What is the most likely cause?
Medium306An administrator is troubleshooting a Cisco ISE and Secure Firewall pxGrid integration where identity policies are failing to match traffic. Which TWO tools or diagnostic methods should the administrator use to verify that IP-to-user mappings are present on the FTD? (Choose two)
Hard307An administrator configures Cisco Secure Firewall Threat Defense to integrate with Cisco ISE via pxGrid. Which TWO operational benefits are provided by this integration for firewall policy enforcement? (Choose two)
Hard308An engineer is deploying a Cisco Secure Firewall Threat Defense Virtual (FTDv) instance in an Amazon Web Services (AWS) VPC. The deployment requires the FTDv to inspect traffic crossing between public and private subnets. Which AWS architectural construct is mandatory for routing traffic through the FTDv instance?
Medium309An administrator needs to create a variable set to define specific port or network variables used within Intrusion Rules. Where are variable sets managed in the FMC?
Easy310An administrator is configuring automated backup tasks on the FMC. Which TWO destinations or protocols are natively supported by the FMC for storing backup archives? (Choose two)
Easy311An enterprise requires FTD to decrypt outbound SSL/TLS traffic so internal users visiting external websites can be inspected by Snort for malware. Which policy and action combination must be configured?
Hard312In the context of FTD, what does 'FMC' stand for?
Easy313Which TWO tasks are required to delete a NAT rule safely?
Medium314An administrator needs to ensure that internal users can access the internet using a public IP while hiding their private address. Which NAT rule type should be configured on the FMC?
Medium315An administrator is configuring Cisco Secure Firewall Threat Defense to send syslog messages. Which TWO options can be included in the syslog message header or content to assist SIEM correlation and analysis? (Choose two)
Hard316An administrator needs to create a Geolocation object in the FMC to block traffic originating from a specific country. Where is this object used?
Medium317An administrator is troubleshooting an Access Control Policy where multiple rules could potentially match a specific packet. In what order does the FMC evaluate rules within an Access Control Policy?
Hard318An administrator is configuring interface-level QoS on an FTD device. Which THREE parameters or features can be configured within an FTD QoS policy? (Choose three)
Medium319An engineer is configuring static route tracking on a Cisco Secure Firewall Threat Defense to ensure high availability for outbound internet connectivity. A backup static route is configured with a higher metric. What mechanism does the firewall use to dynamically switch from the primary route to the backup route when the primary next-hop fails?
Hard320An administrator is troubleshooting high memory utilization on an FMC appliance. Which TWO actions or tools can be used to identify resource-heavy processes or clean up storage? (Choose two)
Medium321Which TWO of the following are valid requirements for setting up an FTD high availability pair?
Medium322Which THREE factors affect the choice between deploying FTD in Routed vs Transparent mode?
Hard323When configuring an FTD in Transparent Mode, how is the 'Bridge Group' created?
Hard324When configuring FMC backup schedules, which TWO storage options are natively supported for the backup files?
Hard325An organization uses Cisco Secure Firewall Threat Defense and integrates with Cisco ISE for identity policies. The security team notices that identity rules are intermittently failing because the FTD cache of IP-to-user mappings is being flushed unexpectedly. Upon investigation, what condition on FTD or ISE typically causes the purging of active user identity maps?
Hard326An administrator is creating an Access Control Policy rule on the FMC. Which TWO elements are required to create a basic rule? (Choose two)
Easy327When deploying a configuration change from FMC to FTD, what is the 'Deployment' process actually doing?
Hard328You are setting up an FTD interface. What is the difference between a 'Routed' and 'Transparent' interface mode?
Medium329An administrator is configuring an Identity Policy to enforce user-based access control. Which THREE identity sources are supported by the FMC for user awareness? (Choose three)
Medium330An administrator is setting up a new Cisco Firepower Threat Defense device and needs to configure platform-level parameters using FMC Platform Settings. Which TWO features can be configured via Platform Settings? (Choose two)
Medium331Which type of object is best suited for defining a web server's public-to-private NAT mapping?
Medium332An engineer is deploying an NGIPS inline set across two physical interfaces. To prevent network disruption during maintenance, the engineer needs to ensure that if the firewall loses power or experiences a kernel panic, traffic can still traverse the physical link. Which hardware feature must the interfaces support?
Medium333Which TWO actions must be performed on Cisco ISE when setting up pxGrid integration with Cisco Secure Firewall Management Center (FMC)? (Choose two.)
Medium334An engineer is troubleshooting Cisco SecureX threat intelligence integration with Cisco Secure Firewall Management Center. The firewall is failing to receive updated indicators of compromise. Which TWO troubleshooting steps should the engineer perform? (Choose two)
Hard335An administrator is implementing an SSL Decryption Policy on a Cisco Firepower Threat Defense device managed by FMC. The policy must decrypt outbound HTTPS traffic to inspect for malware, but certain financial domains must be excluded from decryption to comply with privacy regulations. Which rule action should be configured for these specific financial domains in the SSL Decryption Policy?
Hard336An administrator is configuring an SSL Decryption Policy on the FMC. Which TWO conditions or actions can be configured within an SSL rule? (Choose two)
Hard337An Identity Policy is configured on the FMC to authenticate users connecting through the FTD. The administrator wants to use Active Directory as the identity source. Which mechanism must be configured to map user IP addresses to usernames without requiring explicit web authentication?
Medium338Which TWO of the following are required for FTD transparent mode deployment?
Medium339An engineer deploys an NGIPS in passive mode using a SPAN (Switched Port Analyzer) port on a core switch. During traffic analysis, the engineer notices that the firewall is not seeing TCP reset packets generated by internal servers. What is the primary operational limitation of deploying an NGIPS in passive mode that explains this behavior?
Medium340An organization mandates that all integration traffic between Cisco Firepower Management Center and Cisco SecureX must be inspected. Which cloud connection mechanism does FMC use to communicate with SecureX threat intelligence and telemetry?
Hard341When troubleshooting policy deployment failures, which log file on the FMC should be examined to see the specific error returned by the device during the commit process?
Medium342An administrator needs to configure NAT on an FTD device so that internal traffic destined for a partner network uses the original source IP, but the destination IP is translated from 192.168.10.50 to 172.16.50.10. What type of NAT rule is required?
Medium343A network security engineer configures Cisco Secure Firewall Threat Defense to ingest Security Group Tags (SGTs) from Cisco ISE via pxGrid. The integration is active, and SGTs are successfully mapped to IP addresses. However, access control rules referencing Security Group Tags fail to match traffic originating from authenticated endpoints. What is the most likely cause of this behavior on FTD?
Hard344An administrator is setting up a high availability pair of Cisco Secure Firewall devices. During the HA configuration wizard in FMC, the administrator is asked to provide a registration key. What is the purpose of this key?
Medium345An administrator is configuring Identity Policies on the FMC. Which TWO identity sources are supported for user mapping and authentication? (Choose two)
Medium346When troubleshooting an issue where an FTD interface is in a 'down' state, which command helps verify if there is a physical layer issue or an administrative shutdown?
Hard347An administrator is preparing to upgrade an FMC and its managed FTD devices from version 6.6.x to 7.2.x. What is the mandatory prerequisite regarding upgrade paths and compatibility checks?
Hard348Which TWO items can be used to filter traffic in a QoS policy?
Medium349An FTD device is deployed behind a service provider router that performs NAT, meaning the external IP address assigned to the FTD's outside interface changes dynamically via DHCP. How should a Manual NAT rule be configured to handle outbound traffic referencing this dynamic outside IP?
Medium350An engineer is deploying a Cisco Secure Firewall Threat Defense Virtual (FTDv) in Google Cloud Platform (GCP). The architecture requires multiple network interfaces. How does GCP map these interfaces during deployment?
Medium351An administrator configures Cisco Secure Firewall Threat Defense to send connection logs to a syslog server. The SIEM administrator reports that connection teardown logs are missing, while connection creation logs are successfully received. What setting in the FTD Platform Settings syslog configuration needs to be adjusted?
Medium352An FTD high availability pair experiences a failover due to a hardware failure on the active unit. After the standby unit takes over, the administrator notices that existing TCP connections were dropped and did not state-fully fail over. What configuration setting should the administrator verify?
Hard353When configuring ECMP (Equal-Cost Multi-Path) on FTD, what happens if one of the next-hop paths fails?
Hard354An administrator integrates Cisco Secure Firewall Management Center with Cisco SecureX. Which TWO benefits and features are unlocked by this cloud integration? (Choose two)
Hard355Which THREE commands are valid for gathering information about the FTD's current status and health from the CLI?
Hard356When deploying an FTD appliance, which interface role is used for receiving traffic from a SPAN port?
Medium357An administrator is managing high availability failover events for Cisco Secure Firewall Threat Defense devices using Cisco FMC. Which TWO actions or events will trigger a failover from the active unit to the standby unit? (Choose two)
Medium358When deploying an FTD virtual appliance in AWS, which feature allows the FTD to scale horizontally to handle varying traffic loads?
Hard359An administrator is configuring third-party SIEM integration using syslog on Cisco Secure Firewall Threat Defense. Which TWO configuration practices are recommended to ensure optimal log management and troubleshooting? (Choose two)
Hard360An administrator is configuring static route tracking on a Cisco Secure Firewall Threat Defense device managed by FMC. A tracked IP address becomes unreachable, and the primary static route is removed from the routing table. What mechanism does FTD use to verify the reachability of the tracked destination?
Hard361An administrator is troubleshooting a Prefilter Policy configured on an FMC. Which THREE actions are available when creating a rule in a Prefilter Policy? (Choose three)
Hard362An administrator is configuring a new Access Control Policy on the Firepower Management Center and needs to add a rule that blocks peer-to-peer file sharing applications regardless of port. Which rule type should the administrator select?
Easy363How do you ensure that a specific host object is only used in a specific interface?
Hard364Which TWO settings are available when configuring the 'Logging' tab in an Access Control Rule?
Medium365Which THREE of the following are necessary to configure an FTD in passive mode?
Hard366Which THREE of the following are valid requirements or characteristics when deploying Cisco Secure Firewall Threat Defense in a high availability (HA) configuration? (Choose three)
Medium367Which deployment scenario represents the correct use case for deploying a Cisco Secure Firewall Threat Defense in passive NGIPS mode?
Easy368An administrator is troubleshooting eStreamer event export from a Firepower Management Center to a third-party SIEM tool. Which TWO factors can cause eStreamer communication to fail? (Choose two.)
Medium369Which TWO types of objects can be created in the FMC Object Manager?
Medium370An administrator is configuring third-party SIEM integration using eStreamer. The external client application encounters a TLS handshake failure when attempting to connect to the FMC eStreamer port. What is the standard troubleshooting step to resolve certificate validation issues between an external eStreamer client and the FMC?
Medium371An administrator is configuring a Prefilter policy to handle GRE-encapsulated traffic. Which Prefilter rule option allows handling or accelerating tunneled traffic?
Medium372An FMC high availability (HA) pair has split-brain symptoms due to a management network failure. After restoring network connectivity, the standby unit remains in a 'Failed' state and does not automatically re-synchronize. What is the correct procedure to recover the HA sync?
Hard373An enterprise integrates Cisco Secure Firewall Threat Defense with Cisco ISE via pxGrid. The security team notices that user identity mapping is intermittent for wireless clients roaming across different access points. Which TWO factors should be verified to ensure robust identity continuity during wireless roaming? (Choose two)
Hard374Which FTD deployment mode must be selected to use the device as a transparent bump-in-the-wire for security inspection?
Easy375Which tab in the Access Control Policy rule allows you to choose the 'Logging' action?
Easy376You are troubleshooting high CPU utilization on an FTD device. Which tool should you use to identify which specific process (e.g., snort) is consuming the most resources?
Hard377An administrator is troubleshooting asymmetric routing issues across an FTD firewall using the FMC connection events and FTD CLI. The administrator wants to disable TCP state bypass or adjust TCP normalization settings to allow non-synchronized SYN packets through for a specific application. Where are TCP normalization and stateful inspection parameters configured for FTD?
Hard378An administrator is managing object configurations on the FMC. Which TWO of the following are valid object types that can be created under Object Management? (Choose two)
Medium379You are configuring an active/standby High Availability pair for Cisco Secure Firewall Threat Defense using FMC. You need to configure port channels for the data interfaces to increase bandwidth and redundancy. Which guideline must be followed regarding port channels in an HA deployment?
Medium380Which menu in the FMC allows you to view the list of managed FTD devices?
Easy381Which option in the Access Control Policy rule allows you to define a specific application, such as 'Facebook', to be blocked?
Easy382An administrator is preparing to upgrade a high-availability (HA) pair of Firepower Threat Defense devices managed by an FMC. Before initiating the upgrade task via the FMC upgrade tool, which preliminary action is mandatory to ensure a seamless process and prevent split-brain conditions?
Hard383An administrator configures a security intelligence feed in the FMC to block known malicious IP addresses. Where are Security Intelligence feeds and lists applied in the FMC configuration?
Medium384An administrator is investigating an issue where connection events are failing to reach the FMC from a managed FTD. Which THREE daemons or logs on the FTD and FMC should be checked to troubleshoot event transport and communication issues? (Choose three)
Hard385An engineer is troubleshooting a newly deployed FTD device where syslog messages are not reaching the external syslog server. Which tool on the FTD CLI can the engineer use to verify if the syslog generation and transmission process is attempting to send packets out the management or data interface?
Medium386An administrator notices that the Firepower Management Center (FMC) health monitor shows a critical warning regarding high disk utilization on the /var partition. Which built-in utility or action should the administrator perform first to safely free up disk space without disrupting critical database integrity?
Easy387An engineer suspects that asymmetric routing is causing packets to be dropped by the FTD firewall. Which command should the engineer run on the FTD CLI to check for dropped packets and view drop reasons in real time?
Medium388When configuring Cisco Secure Firewall Threat Defense integration with Cisco Threat Response (SecureX Threat Response) for automated threat hunting and mitigation, which THREE components or steps are required? (Choose three.)
Hard389An administrator is troubleshooting an SSL Decryption policy where encrypted connections are failing. The FMC logs indicate that clients are rejecting the FTD's re-signed certificate because it is not trusted. What configuration step is missing?
Hard390You are deploying a Cisco Secure Firewall Threat Defense in an existing core network as an out-of-band intrusion prevention system. Which NGIPS deployment mode should you configure to ensure the firewall performs deep packet inspection and generates alerts without dropping any production traffic in the event of a device failure or high load?
Easy391Which THREE items are included in an FMC backup archive?
Hard392In the FMC, what is the purpose of the 'Network Discovery Policy'?
Medium393Which TWO protocols or mechanisms are used to integrate Cisco Identity Services Engine (ISE) with Cisco Secure Firewall Threat Defense? (Choose two)
Easy394When integrating Cisco Secure Firewall with Cisco SecureX, which component acts as the local orchestrator and liaison that relays threat intelligence and response actions between the managed FTD devices and the SecureX cloud?
Easy395An administrator is integrating Cisco Secure Firewall Threat Defense with Cisco Identity Services Engine (ISE) using Platform Exchange Services (pxGrid). Which service must be enabled and running on the ISE nodes for pxGrid communication to succeed?
Easy396An administrator wants to verify the NTP synchronization status and time offset on a managed FTD device from the FMC GUI. Where can this health and system information be viewed?
Easy397An administrator is configuring the Cisco eStreamer client on a Linux-based SIEM collector to connect to the FMC. After copying the generated certificate files to the client, the connection attempt fails with an error indicating that the client certificate is untrusted. What is the most likely reason for this failure?
Medium398An administrator configures pxGrid integration between Cisco ISE and Cisco Secure Firewall Management Center. The administrator wants to verify that the pxGrid service on ISE is actively responding and publishing topics. Which tool or interface on ISE should be used to check pxGrid node status?
Medium399Which THREE actions can be performed by an SSL Decryption Policy?
Hard400An administrator wants to generate a health report on the FMC to present hardware utilization trends over the past 30 days. Which section of the FMC GUI provides pre-built health reports and metric tracking?
Easy401An administrator is configuring an Identity Policy with Active Directory integration. The requirement is to ensure that users who fail primary AD authentication are assigned to a restricted guest VLAN using ISE integration. Which component in the FMC architecture handles this user-to-group association?
Hard402Which THREE components are necessary to implement passive identity monitoring in an FMC-managed Firepower system?
Hard403An administrator is planning an upgrade of an FMC managing multiple FTD devices across various software versions. Which THREE factors must be validated according to Cisco compatibility guidelines before proceeding? (Choose three)
Hard404An administrator is configuring Cisco SecureX threat intelligence integration with Cisco Secure Firewall Threat Defense via the FMC. Which TWO actions can be performed directly through the SecureX integration? (Choose two)
Hard405Which THREE criteria can be used to match traffic within an Access Control rule on the FMC? (Choose three)
Hard406An engineer needs to troubleshoot an intermittent connectivity issue between a secured zone and the internet through a Firepower Threat Defense (FTD) managed by FMC. The engineer wants to capture traffic hitting a specific Access Control rule without overwhelming the system. Which packet capture configuration is most appropriate?
Medium407When analyzing performance issues, which THREE metrics should an administrator monitor in the FMC Health Monitor?
Medium408An engineer needs to troubleshoot high CPU usage on an FTD device caused by Snort. Which THREE actions or features can be adjusted or implemented to mitigate Snort CPU load? (Choose three)
Medium409You are deploying a high-availability pair of Firepower Threat Defense (FTD) units. Which TWO requirements must be met to ensure stateful failover functions correctly?
Medium410You are troubleshooting high availability. The units are connected, but the failover link shows as 'Down'. What is the most likely cause?
Medium411An enterprise network design incorporates Equal-Cost Multi-Path (ECMP) routing across two Cisco Secure Firewall Threat Defense units functioning independently in routed mode. What is the primary benefit of enabling ECMP on the firewalls?
Easy412When deploying an FTD cluster, which component is responsible for distributing traffic across the members of the cluster?
Hard413Which protocol is natively used by Cisco Secure Firewall Management Center to stream connection and intrusion events to external SIEM systems in real time?
Easy414An administrator is planning an Active/Standby High Availability deployment for two Cisco Secure Firewall Threat Defense devices managed by FMC. Which THREE prerequisites must be satisfied before configuring the HA pair? (Choose three)
Hard415An engineer is configuring dynamic routing using OSPF on a Cisco Secure Firewall Threat Defense device managed by FMC. Which TWO configuration steps are required to establish an OSPF adjacency? (Choose two)
Medium416Which FTD command-line tool is primarily used to check interface status and physical link state?
Easy417You are deploying a Cisco Firepower Threat Defense (FTD) unit in transparent mode. Which requirement must be met for the device to process traffic correctly in this mode?
Medium418You have a large number of NAT rules. How does the FTD process them?
Hard419An administrator wants to group multiple existing port objects (e.g., TCP 80, TCP 443, TCP 8080) into a single object for use in Access Control Policy rules. Which object container should be created?
Easy420Which type of events can be exported from Cisco Secure Firewall Management Center to a SIEM using the eStreamer protocol?
Easy421You are defining an Access Control Policy rule to allow traffic. If you want to log the connection at the end of the flow only if it matches the rule, which Logging setting is appropriate?
Medium422A security engineer is integrating Cisco Secure Firewall with a third-party SIEM using eStreamer. The SIEM vendor's connector documentation requires the eStreamer event types to be parsed correctly. Which file format or protocol encoding does eStreamer use to transmit event records over TCP port 8305?
Hard423An administrator notices that the FMC dashboard indicates a yellow health status for an FTD device. Where should the administrator navigate to identify the specific process or service that is failing?
Medium424How do you identify which Access Control Rule triggered a specific connection log?
Medium425You are troubleshooting a connectivity issue. The traffic is being dropped by a Prefilter rule. What is the characteristic of traffic handled by a Prefilter policy?
Hard426In an FTD cluster, what happens if the cluster control link fails?
Hard427An administrator configures Cisco Secure Firewall Management Center to integrate with Cisco Threat Response / SecureX. After completing the configuration, threat intelligence indicators are not updating on the firewall. Where can the administrator check the synchronization status and API communication logs between FMC and SecureX on the FMC CLI?
Medium428When editing an Access Control Rule, which action allows you to drop traffic while simultaneously sending a TCP RST to the client?
Medium429When a packet capture is running on the FTD, where can you download the resulting .pcap file for analysis in Wireshark?
Hard430An engineer is troubleshooting a Cisco ISE and Secure Firewall pxGrid integration. The administrator notices that user group memberships are not populating correctly on the FTD, even though IP-to-user mappings are visible. What is the most likely reason user group information is missing?
Hard431An administrator configures a Cisco Secure Firewall Threat Defense cluster. During normal operations, a data node experiences a critical hardware failure. What happens to the active connections currently processed by that specific failed data node?
Hard432You are restoring an FMC backup to a new appliance. Which of the following conditions must be met for a successful restore?
Hard433An administrator is integrating Cisco Secure Firewall Threat Defense with Cisco Threat Response (now Cisco SecureX threat intelligence). Which mechanism does the firewall use to automatically receive dynamic indicators of compromise (IoCs) and perform retrospective security analysis?
Hard434You are deploying an FTD in a cloud environment and need to ensure high availability. Which technology is typically used to manage the virtual IP failover?
Hard435What is the result of assigning a 'Trust' action to a rule in an Access Control Policy?
Medium436Which of the following is a limitation when deploying an FTD in transparent mode?
Hard437Which TWO of the following are required when configuring a static route with tracking?
Medium438An administrator is setting up FTD HA. Which of the following is true regarding the configuration synchronization between the primary and secondary units?
Medium439You are configuring an NGIPS mode deployment on an FTD device. You need to ensure that the FTD can drop malicious traffic in real-time. Which mode must you select?
Medium440An administrator is performing health monitoring on an FMC appliance. Which TWO health monitors are available out-of-the-box in the FMC Health Monitor dashboard to track system resource utilization? (Choose two)
Easy441An administrator needs to create a custom Application filter object in the FMC to easily select cloud storage applications in Access Control rules. Where are application filters created?
Easy442You are configuring identity-based access control rules on Cisco Secure Firewall Threat Defense using user groups imported from Cisco ISE via pxGrid. Users report that they are not matching the identity rule, although their IP address is correctly mapped to their username in the FMC Active Sessions table. What is the root cause?
Hard443An administrator is troubleshooting a Cisco Secure Firewall Threat Defense and Cisco ISE pxGrid integration where user-to-IP mappings are not being received by the FTD. Which TWO troubleshooting steps should the administrator perform on the FTD or FMC CLI to diagnose the issue? (Choose two)
Hard444What occurs when an 'Interactive Block' action is used in an Access Control rule?
Hard445Which menu path in the Cisco Secure Firewall Management Center (FMC) is used to configure the connection to Cisco Threat Response or Cisco SecureX?
Easy446An administrator is troubleshooting a policy deployment failure between an FMC and an FTD. Which THREE log files on the FTD contain relevant information regarding policy application and deployment tasks? (Choose three)
Medium447Which TWO methods can be used to gather diagnostic information for a Cisco TAC case from an FTD device?
Medium448Which TWO of the following are benefits of using a Port Channel on an FTD?
Medium449An administrator needs to configure Quality of Service (QoS) on a Cisco Firepower Threat Defense device via FMC to limit peer-to-peer traffic bandwidth. Where must the QoS policy be applied for it to take effect on traffic traversing the firewall?
Easy450An administrator is troubleshooting a VPN tunnel termination issue on an FTD device. To check IPsec Phase 1 and Phase 2 security associations (SAs) and real-time crypto debugging messages, which command should be executed on the FTD diagnostic CLI?
Medium451When using a Redundant Interface, what is the primary behavior during a link failure?
Medium452An administrator configures QoS on an FTD interface to prioritize VoIP traffic. Which traffic matching mechanism within the QoS policy allows the FTD to identify VoIP traffic (such as SIP or RTP) based on Layer 7 application inspection?
Medium453You have an FTD device and need to perform deep packet inspection without changing the network topology or IP addressing. Which deployment mode should you choose?
Hard454An administrator wants to stream security events, connection events, and intrusion events from Cisco Secure Firewall Management Center (FMC) to a third-party SIEM platform. Which built-in protocol and feature on the FMC should be configured to export these events in real-time?
Easy455An administrator is configuring SSL Decryption to inspect internal clients browsing external websites. The organization wants to ensure that traffic to financial and health-related websites is bypassed to maintain privacy and regulatory compliance. How should this be configured in the SSL Policy?
Hard456An enterprise integrates Cisco Secure Firewall Management Center with Cisco ISE using pxGrid for identity-based access control. The security team notices that user identity mapping works for domain users authenticating via 802.1X, but guest users connecting through a WebAuth portal do not have their user-to-IP mappings populated on the FTD. What is the root cause of this issue?
Hard457An administrator is configuring a static route tracking mechanism on a Cisco Secure Firewall Threat Defense device using an ICMP Echo IP SLA object. What happens to the tracked static route if the SLA probe fails to receive a response?
Medium458An administrator wants to ensure that specific internal subnets are never subjected to NAT translation when communicating with a partner VPN tunnel. Which NAT feature achieves this?
Easy459An administrator is setting up Cisco ISE pxGrid integration with Cisco Secure Firewall Management Center. Which TWO configuration steps must be performed on the Cisco ISE side to ensure successful integration? (Choose two)
Hard460Which THREE components of an Access Control rule can be used to identify traffic as 'Application' based?
Hard461An administrator is troubleshooting intermittent connectivity loss between an FTD managed device and the FMC. Which TWO methods or tools can be used to verify registration and communication status between the managed device and the FMC? (Choose two.)
Hard462An administrator is managing Cisco Secure Firewall Threat Defense devices using Cisco Defense Orchestrator (CDO). Which TWO capabilities does CDO provide for firewall deployment and management? (Choose two)
Medium463An administrator is configuring a new Cisco Secure Firewall Threat Defense in routed mode on Firepower Device Manager (FDM). During the initial setup, the administrator needs to define the routing behavior for a multi-zone deployment. Which configuration step is mandatory when setting up routed mode?
Medium464You are creating a custom URL category. How do you add specific domains to this category in FMC?
Hard465An engineer wants to group several FTD interfaces into a single logical zone to simplify Access Control rule creation. Where are security zones created in the FMC?
Easy466You are configuring a NAT rule and need to hide the internal network behind a single interface IP. Which NAT translation setting is required?
Hard467An engineer is troubleshooting a scenario where Cisco Secure Firewall is receiving SGT information from Cisco ISE via SXP, but access control rules referencing Security Group Tags are not matching traffic. What is the most effective command to run on the Threat Defense CLI to verify that the firewall has learned the IP-to-SGT mappings?
Hard468What is the primary function of a 'Security Zone' in FMC?
Medium469What is the recommended procedure for performing a major software upgrade on an FTD HA pair managed by an FMC to ensure zero downtime?
Easy470An engineer is troubleshooting a scenario where an FTD device fails its pre-upgrade health check during an upgrade initiated from the FMC. Which THREE common pre-check failures must be resolved before proceeding? (Choose three)
Hard471An FTD device managed by FMC is failing to download latest Snort Rule Updates (SRUs) and GeoDB updates automatically. The FMC has internet access via an HTTPS proxy. Where must the HTTPS proxy settings be configured on the FMC so that it can successfully reach Cisco update servers?
Medium472An engineer is troubleshooting a mutual TLS connection failure between Cisco ISE pxGrid and the FMC. The openssl command on the FMC reveals a 'certificate verify failed' error. What is the underlying reason for this error?
Hard473When configuring syslog export from Cisco Secure Firewall Threat Defense using Firepower Management Center, which alert format should you choose to ensure standard SIEM ingestion parsers can easily read the event headers?
Easy474Which TWO components must be configured in FMC to enable User Identity mapping for Access Control Rules?
Medium475Which THREE features must be configured to successfully implement static route tracking on an FTD device?
Hard476Which THREE steps are part of a standard FTD upgrade workflow managed via the FMC?
Hard477When performing a packet capture on an FTD device, how can you filter the traffic to only capture traffic from a specific source IP address?
Medium478An FMC administrator is troubleshooting a scenario where device registration between an FTD and FMC fails immediately with a registration key mismatch error. The administrator verified the NAT ID and registration key. What underlying protocol handshake fails during this registration process, and how can it be debugged?
HardOther domains
All 300-710 SNCF exam domains
Frequently asked questions
- What does the scenario questions domain cover on the 300-710 SNCF exam?
- scenario questions questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 478 scenario questions questions in the 300-710 SNCF question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only scenario questions questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.