Cisco

300-710 practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 259-question bank.

Provider
Cisco
Question bank
259
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for 300-710, a certification listed under Cisco. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Cisco. The certification credential is issued by Cisco, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    What is a result of enabling Cisco FTD clustering?

    Choose one answer.

    • For the dynamic routing feature, if the master unit fails, the newly elected master unit maintains all existing connections.
    • Integrated Routing and Bridging is supported on the master unit.
    • Site-to-site VPN functionality is limited to the master unit, and all VPN connections are dropped if the master unit fails.
    • All Firepower appliances support Cisco FTD clustering.
  2. Question 2 · 1

    An engineer has been asked to show application usages automatically on a monthly basis and send the information to management. What mechanism should be used to accomplish this task?

    Choose one answer.

    • reports
    • context explorer
    • dashboards
    • event viewer
  3. Question 3 · 1

    A network administrator is configuring SNORT inspection policies and is seeing failed deployment messages in Cisco FMC. What information should the administrator generate for Cisco TAC to help troubleshoot?

    Choose one answer.

    • A ג€troubleshootג€ file for the device in question.
    • A ג€show techג€ file for the device in question.
    • A ג€troubleshootג€ file for the Cisco FMC.
    • A ג€show techג€ for the Cisco FMC.
  4. Question 4 · 1

    An administrator is attempting to remotely log into a switch in the data center using SSH and is unable to connect. How does the administrator confirm that traffic is reaching the firewall?

    Choose one answer.

    • by performing a packet capture on the firewall
    • by attempting to access it from a different workstation
    • by running Wireshark on the administrator's PC
    • by running a packet tracer on the firewall
  5. Question 5 · 1

    IT management is asking the network engineer to provide high-level summary statistics of the Cisco FTD appliance in the network. The business is approaching a peak season so the need to maintain business uptime is high. Which report type should be used to gather this information?

    Choose one answer.

    • Risk Report
    • SNMP Report
    • Standard Report
    • Malware Report
  6. Question 6 · 1

    An administrator is setting up Cisco FirePower to send data to the Cisco Stealthwatch appliances. The NetFlow_Set_Parameters objet is already created, but NetFlow is not being sent to the flow collector. What must be done to prevent this from occurring?

    Choose one answer.

    • Create a service identifier to enable the NetFlow service.
    • Add the NetFlow_Send_Destination object to the configuration.
    • Create a Security Intelligence object to send the data to Cisco Stealthwatch.
    • Add the NetFlow_Add_Destination object to the configuration.
  7. Question 7 · 1

    With a recent summer time change, system logs are showing activity that occurred to be an hour behind real time. Which action should be taken to resolve this issue?

    Choose one answer.

    • Manually adjust the time to the correct hour on all managed devices.
    • Configure the system clock settings to use NTP with Daylight Savings checked.
    • Configure the system clock settings to use NTP.
    • Manually adjust the time to the correct hour on the Cisco FMC.
  8. Question 8 · 1

    A network administrator notices that SI events are not being updated. The Cisco FTD device is unable to load all of the SI event entries and traffic is not being blocked as expected. What must be done to correct this issue?

    Choose one answer.

    • Restart the affected devices in order to reset the configurations.
    • Redeploy configurations to affected devices so that additional memory is allocated to the SI module.
    • Replace the affected devices with devices that provide more memory.
    • Manually update the SI event entries to that the appropriate traffic is blocked.
  9. Question 9 · 1

    Which two dynamic routing protocols are supported in Cisco FTD without using FlexConfig? (Choose two.)

    Choose all answers that apply.

    • EIGRP
    • OSPF
    • static routing
    • IS-IS
    • BGP
  10. Question 10 · 1

    Refer to the exhibit. What must be done to fix access to this website while preventing the same communication to all other websites?

    Choose one answer.

    Question illustration 1
    • Create an intrusion policy rule to have Snort allow port 80 to only 172.1.1.50.
    • Create an intrusion policy rule to have Snort allow port 443 to only 172.1.1.50.
    • Create an access control policy rule to allow port 443 to only 172.1.1.50.
    • Create an access control policy rule to allow port 80 to only 172.1.1.50.
  11. Question 11 · 1

    A connectivity issue is occurring between a client and a server which are communicating through a Cisco Firepower device. While troubleshooting, a network administrator sees that traffic is reaching the server, but the client is not getting a response. Which step must be taken to resolve this issue without initiating traffic from the client?

    Choose one answer.

    • Use packet-tracer to ensure that traffic is not being blocked by an access list
    • Use packet capture to ensure that traffic is not being blocked by an access list
    • Use packet capture to validate that the packet passes through the firewall and is NATed to the corrected IP address
    • Use packet-tracer to validate that the packet passes through the firewall and is NATed to the corrected IP address
  12. Question 12 · 1

    A VPN user is unable to connect to web resources behind the Cisco FTD device terminating the connection. While troubleshooting, the network administrator determines that the DNS response are not getting through the Cisco FTD. What must be done to address this issue while still utilizing Snort IPS rules?

    Choose one answer.

    • Uncheck the ג€Drop when Inlineג€ box in the intrusion policy to allow the traffic
    • Modify the Snort rules to allow legitimate DNS traffic to the VPN users
    • Disable the intrusion rule thresholds to optimize the Snort processing
    • Decrypt the packet after the VPN flow so the DNS queries are not inspected
  13. Question 13 · 1

    An organization has a Cisco IPS running in inline mode and is inspecting traffic for malicious activity. When traffic is received by the Cisco IPS, if it is not dropped, how does the traffic get to its destination?

    Choose one answer.

    • It is retransmitted from the Cisco IPS inline set
    • The packets are duplicated and a copy is sent to the destination
    • It is transmitted out of the Cisco IPS outside interface
    • It is routed back to the Cisco ASA interfaces for transmission
  14. Question 14 · 1

    An engineer is investigating connectivity problems on Cisco Firepower that is using service group tags. Specific devices are not being tagged correctly, which is preventing clients from using the proper policies when going through the firewall. How is this issue resolved?

    Choose one answer.

    • Use traceroute with advanced options
    • Use Wireshark with an IP subnet filter
    • Use a packet capture with match criteria
    • Use a packet sniffer with correct filtering
  15. Question 15 · 1

    An organization must be able to ingest NetFlow traffic from their Cisco FTD device to Cisco Stealthwatch for behavioral analysis. What must be configured on the Cisco FTD to meet this requirement?

    Choose one answer.

    • flexconfig object for NetFlow
    • interface object to export NetFlow
    • security intelligence object for NetFlow
    • variable set object for NetFlow

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free