An engineer is configuring two new Cisco FTD devices to replace the existing high availability firewall pair in a highly secure environment. The information exchanged between the FTD devices over the failover link must be encrypted. Which protocol supports this on the Cisco FTD?
An engineer is configuring a custom intrusion rule on Cisco FMC. The engineer needs the rule to search the payload or stream for the string "|44 78 97 13 2 0A|". Which keyword must the engineer use with this string to create an argument for packet inspection?
Aprotected_content
Bcontent
Cdata
Dmetadata
An engineer must investigate a connectivity issue from an endpoint behind a Cisco FTD device and a public DNS server. The endpoint cannot perform name resolution queries. Which action must the engineer perform to troubleshoot the issue by simulating real DNS traffic on the Cisco FTD while verifying the Snort verdict?
AUse the Capture w/Trace wizard in Cisco FMC.
BRun the system support firewall-engine-debug command from the FTD CLI.
CCreate a Custom Workflow in Cisco FMC.
DPerform a Snort engine capture using tcpdump from the FTD CLI.
The network administrator wants to enhance the network security posture by enabling machine learning for malware detection due to a concern with suspicious Microsoft executable file types that were seen while creating monthly security reports for the CIO. Which feature must be enabled to accomplish this goal?
AEthos
Bstatic analysis
CSpero
Ddynamic analysis
DRAG DROP
A network engineer is deploying a Cisco Firepower 4100 appliance and must configure a multi-instance environment for high availability. Drag and drop the actions from the left into sequence on the right for this configuration.
Question 6
Deployment
0
Question 7
Integration
Question 8
Integration
Question 9
Management and Troubleshooting
Question 10
Configuration
Question 11
Configuration
Question 12
Deployment
Question 13
Configuration
Question 14
Configuration
Question 15
Configuration
Question 16
Configuration
Question 17
Configuration
Question 18
Management and Troubleshooting
Question 19
Management and Troubleshooting
Question 20
Management and Troubleshooting
Question 21
Deployment
Question 22
Configuration
Question 23
Configuration
Question 24
Configuration
Question 25
Configuration
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ad
Want a break from the ads?
Become a Supporter and enjoy a completely ad-free experience, plus unlock Learn Mode, Exam Mode, AstroTutor AI, and more.
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
What is an advantage of adding multiple inline interface pairs to the same inline interface set when deploying an asynchronous routing configuration?
AAllows the IPS to identify inbound and outbound traffic as part of the same traffic flow.
BThe interfaces disable autonegotiation and interface speed is hard coded set to 1000 Mbps.
CAllows traffic inspection to continue without interruption during the Snort process restart.
DThe interfaces are automatically configured as a media-independent interface crossover.
A network engineer wants to add a third-party threat feed into the Cisco FMC for enhanced threat detection. Which action should be taken to accomplish this goal?
AEnable Rapid Threat Containment using REST APIs.
BEnable Rapid Threat Containment using STIX and TAXII.
CEnable Threat Intelligence Director using REST APIs.
DEnable Threat Intelligence Director using STIX and TAXII.
An engineer integrates Cisco FMC and Cisco ISE using pxGrid. Which role is assigned for Cisco FMC?
Aserver
Bcontroller
Cpublisher
Dclient
An engineer has been asked to show application usages automatically on a monthly basis and send the information to management. What mechanism should be used to accomplish this task?
Areports
Bcontext explorer
Cdashboards
Devent viewer
An engineer needs to configure remote storage on Cisco FMC. Configuration backups must be available from a secure location on the network for disaster recovery. Reports need to back up to a shared location that auditors can access with their Active Directory logins. Which strategy must the engineer use to meet these objectives?
AUse NFS for both backups and reports.
BUse SSH for backups and NFS for reports.
CUse SMB for backups and NFS for reports.
DUse SMB for both backups and reports.
An engineer installs a Cisco FTD device and wants to inspect traffic within the same subnet passing through a firewall and inspect traffic destined to the Internet. Which configuration will meet this requirement?
Atransparent firewall mode with IRB only
Brouted firewall mode with BVI and routed interfaces
Ctransparent firewall mode with multiple BVIs
Drouted firewall mode with routed interfaces only
Which command is run on an FTD unit to associate the unit to an FMC manager that is at IP address 10.0.0.10, and that has the registration key Cisco123?
Aconfigure manager local 10.0.0.10 Cisco123
Bconfigure manager add Cisco123 10.0.0.10
Cconfigure manager local Cisco123 10.0.0.10
Dconfigure manager add 10.0.0.10 Cisco123
Which two actions can be used in an access control policy rule? (Choose two.)
ABlock with Reset
BMonitor
CAnalyze
DDiscover
EBlock ALL
On the advanced tab under inline set properties, which allows interfaces to emulate a passive interface?
Atransparent inline mode
BTAP mode
Cstrict TCP enforcement
Dpropagate link state
What are two application layer preprocessors? (Choose two.)
ACIFS
BIMAP
CSSL
DDNP3
EICMP
Which two OSPF routing features are configured in Cisco FMC and propagated to Cisco FTD? (Choose two.)
AOSPFv2 with IPv6 capabilities
Bvirtual links
CSHA authentication to OSPF packets
Darea boundary router type 1 LSA filtering
EMD5 authentication to OSPF packets
What is the result a specifying of QoS rule that has a rate limit that is greater than the maximum throughput of an interface?
AThe rate-limiting rule is disabled.
BMatching traffic is not rate limited.
CThe system rate-limits all traffic.
DThe system repeatedly generates warnings.
Which command is typed at the CLI on the primary Cisco FTD unit to temporarily stop running high-availability?
Aconfigure high-availability resume
Bconfigure high-availability disable
Csystem support network-options
Dconfigure high-availability suspend
What is the benefit of selecting the trace option for packet capture?
AThe option indicates whether the packet was dropped or successful.
BThe option indicates whether the destination host responds through a different path.
CThe option limits the number of packets that are captured.
DThe option captures details of each packet.
Which command should be used on the Cisco FTD CLI to capture all the packets that hit an interface?
Aconfigure coredump packet-engine enable
Bcapture-traffic
Ccapture
Dcapture WORD
What are the minimum requirements to deploy a managed device inline?
Ainline interfaces, security zones, MTU, and mode
Bpassive interface, MTU, and mode
Cinline interfaces, MTU, and mode
Dpassive interface, security zone, MTU, and mode
An engineer is configuring Cisco FMC and wants to limit the time allowed for processing packets through the interface. However, if the time is exceeded, the configuration must allow packets to bypass detection. What must be configured on the Cisco FMC to accomplish this task?
ACisco ISE Security Group Tag
BAutomatic Application Bypass
CInspect Local Traffic Bypass
DFast-Path Rules Bypass
The security engineer reviews the syslog server events of an organization and sees many outbound connections to malicious sites initiated from hosts running Cisco Secure Endpoint. The hosts are on a separate network from the Cisco FTD device. Which action blocks the connections?
AModify the policy on Cisco Secure Endpoint to enable DFC.
BModify the access control policy on the Cisco FMC to block malicious outbound connections
CAdd the IP addresses of the malicious sites to the access control policy on the Cisco FMC
DAdd a Cisco Secure Endpoint policy with the Tetra and Spero engines enabled
A company is deploying AMP private cloud. The AMP private cloud instance has already been deployed by the server administrator. The server administrator provided the hostname of the private cloud instance to the network engineer via email. What additional information does the network engineer require from the server administrator to be able to make the connection to the AMP private cloud in Cisco FMC?
ASSL certificate for the AMP private cloud instance
BUsername and password to the AMP private cloud instance
CIP address and port number for the connection proxy
DInternet access for the AMP private cloud to reach the AMP public cloud
A network administrator is trying to convert from LDAP to LDAPS for VPN user authentication on a Cisco FTD. Which action must be taken on the Cisco FTD objects to accomplish this task?
AIdentify the LDAPS cipher suite and use a Cipher Suite List object to define the Cisco FTD connection requirements.
BModify the Policy List object to define the session requirements for LDAPS.
CAdd a Key Chain object to acquire the LDAPS certificate.
DCreate a Certificate Enrollment object to get the LDAPS certificate needed.