Preview real exam questions, verified answers and available explanations before choosing a study plan.
Question 1
Single choice
An analyst is reviewing the Cisco FMC reports for the week. They notice that some peer-to-peer applications are being used on the network and they must identify which poses the greatest risk to the environment.
Which report gives the analyst this information?
A
Attacks Risk Report
B
User Risk Report
C
Network Risk Report
D
Advanced Malware Risk Report
Reveal answer detailsClose answer details
Correct answerC
Question 2
Single choice
A network administrator has converted a Cisco FTD from using LDAP to LDAPS for VPN authentication. The Cisco FMC can connect to the LDAPS server, but the Cisco FTD is not connecting.
Which configuration must be enabled on the Cisco FTD?
A
SSL must be set to a use TLSv1.2 or lower.
B
The LDAPS must be allowed through the access control policy.
C
DNS servers must be defined for name resolution.
D
The RADIUS server must be defined.
Reveal answer detailsClose answer details
Correct answerC
Question 3
Single choice
An organization recently implemented a transparent Cisco FTD in their network. They must ensure that the device does not respond to insecure SSL/TLS protocols.
Which action accomplishes this task?
A
Modify the device's settings using the device management feature within Cisco FMC to force only secure protocols.
B
Use the Cisco FTD platform policy to change the minimum SSL version on the device to TLS 1.2.
C
Enable the UCAPL/CC compliance on the device to support only the most secure protocols available.
D
Configure a FlexConfig object to disable any insecure TLS protocols on the Cisco FTD device.
Reveal answer detailsClose answer details
Correct answerB
Question 4
Single choice
Refer to the exhibit.
An engineer is analyzing the Attacks Risk Report and finds that there are over 300 instances of new operating systems being seen on the network.
How is the Firepower configuration updated to protect these new operating systems?
A
Cisco Firepower Automatically updates the policies.
B
The administrator requests a Remediation Recommendation Report from Cisco Firepower
C
Cisco Firepower gives recommendation to update the policies
An engineer attempts to pull the configuration for a Cisco FTD sensor to review with Cisco TAC but does not have direct access to the CLI for the device. The CLI for the device is managed by Cisco FMC to which the engineer has access.
Which action in Cisco FMC grants access to the CLI for the device?
A
Create a backup of the configuration within the Cisco FMC.
B
Download the configuration file within the File Download section of Cisco FMC.
C
Export the configuration using the Import/Export tool within Cisco FMC.
D
Use the show run all command in the Cisco FTD CLI feature within Cisco FMC.
Reveal answer detailsClose answer details
Correct answerC
Question 6
Single choice
A network administrator is configuring a BVI interface on a routed FTD. The administrator wants to isolate traffic on the interfaces connected to the bridge group and not have the FTD route this traffic using the routing table.
What must be configured?
A
A new VRF must be created for the BVI interface
B
An IP address must be configured on the BVI
C
IP routing must be removed from the physical interfaces connected to the BVI
D
The BVI interface must be configured for transparent mode
Reveal answer detailsClose answer details
Correct answerA
Question 7
Single choice
A network administrator registered a new FTD to an existing FMC. The administrator cannot place the FTD in transparent mode.
Which action enables transparent mode?
A
Deregister the FTD device from FMC and configure transparent mode via the CLI.
B
Obtain an FTD model that supports transparent mode.
C
Add a Bridge Group Interface to the FTD before transparent mode is configured.
D
Assign an IP address to two physical interfaces.
Reveal answer detailsClose answer details
Correct answerA
Question 8
Single choice
An engainer must add DNS-specific rules to me Cisco FTD intrusion policy. The engineer wants to use the rules currently in the Cisco FTD Snort database that are not already enabled but does not want to enable more than are needed.
Which action meets these requirements?
A
Change the dynamic state of the rule within the policy.
B
Change the base policy to Security over Connectivity.
C
Change the rule state within the policy being used.
D
Change the rules using the Generate and Use Recommendations feature.
A network security engineer must export packet captures from the Cisco FMC web browser while troubleshooting an issue.
When navigating to the address https://<FMC IP>/capture/CAPI/pcap/test.pcap.anerror403:ForbiddenisgiveninsteadofthePCAPfile.Whichactionmusttheengineertaketoresolvethisissue?
A
Disable the HTTPS server and use HTTP instead.
B
Enable the HTTPS server for the device platform policy.
C
Disable the proxy setting on the browser.
D
Use the Cisco FTD IP address as the proxy server setting on the browser.
Reveal answer detailsClose answer details
Correct answerB
Question 11
Single choice
What is the role of realms in the Cisco ISE and Cisco Secure Firewall Management Center integration?
A
TACACS+ database
B
AD definition
C
Cisco Secure Firewall VDC
D
Cisco ISE context
Reveal answer detailsClose answer details
Correct answerB
Question 12
Single choice
An engineer must export a packet capture from Cisco Secure Firewall Management Center to assist in troubleshooting an issue on a Secure Firewall Threat Defense device. When the engineer navigates to the URL for Secure Firewall Management Center at:
https:///capture/CAPI/pcap/sample.pcap The engineer receives a 403: Forbidden error instead of being provided with the PCAP file.
Which action resolves the issue?
A
Disable the proxy setting on the client browser.
B
Disable the HTTPS server and use HTTP.
C
Enable HTTPS in the device platform policy.
D
Enable the proxy setting in the device platform policy.
Reveal answer detailsClose answer details
Correct answerC
Explanation
If an engineer receives a 403: Forbidden error when attempting to download a packet capture file from Cisco Secure Firewall Management Center (FMC), the issue is likely due to HTTPS not being enabled in the device platform policy. To resolve this issue, the engineer must enable HTTPS in the platform policy. Steps: In FMC, navigate to Policies > Device Management > Platform Settings. Edit the relevant platform policy. Enable HTTPS for the device. Deploy the changes to the FTD device. This ensures that the FMC and FTD device can securely transfer the packet capture file over HTTPS, resolving the 403 error. References: Cisco Secure Firewall Management Center Administrator Guide, Chapter on Platform Settings and HTTPS Configuration.
Question 13
Single choice
An organization must be able to ingest NetFlow traffic from their Cisco FTD device to Cisco Stealthwatch for behavioral analysis.
What must be configured on the Cisco FTD to meet this requirement?
A
flexconfig object for NetFlow
B
interface object to export NetFlow
C
security intelligence object for NetFlow
D
variable set object for NetFlow
Reveal answer detailsClose answer details
Correct answerA
Question 14
Single choice
What is the maximum SHA level of filtering that Threat Intelligence Director supports?
An engineer must configure high availability for the Cisco Firepower devices. The current network topology does not allow for two devices to pass traffic concurrently.
How must the devices be implemented in this environment?
A
in active/active mode
B
in a cluster span EtherChannel
C
in active/passive mode
D
in cluster interface mode
Reveal answer detailsClose answer details
Correct answerC
Question 16
Single choice
Cisco Security Analytics and Logging SaaS licenses come with how many days of data retention by default?
A
60
B
90
C
120
D
365
Reveal answer detailsClose answer details
Correct answerB
Explanation
Cisco Security Analytics and Logging (SaaS) licenses come with a default data retention period of 90 days. This retention period allows organizations to store and analyze their security event data for up to 90 days, providing sufficient time for security monitoring and forensic investigations. References: Cisco Security Analytics and Logging Documentation, Chapter on License Information and Data Retention.
Question 17
Single choice
The event dashboard within the Cisco FMC has been inundated with low priority intrusion drop events, which are overshadowing high priority events. An engineer has been tasked with reviewing the policies and reducing the low priority events.
Which action should be configured to accomplish this task?
An engineer is deploying a new instance of Cisco Secure Firewall Threat Defense.
Which action must the engineer take next so that Client_A and Client_B receive an IP address via DHCP from Server_A?
A
Disable all the DHCP Snort rules by using Secure Firewall Device Manager.
B
Add access rules that allow DHCP traffic by using Cisco Secure Firewall Management Center.
C
Disable Option 82 in the DHCP relay configuration properties using Secure Firewall Management Center.
D
Add access rules that allow DHCP traffic by using Cisco Secure Firewall Management Center.
Reveal answer detailsClose answer details
Correct answerD
Explanation
In a transparent mode deployment, Cisco Secure Firewall Threat Defense (FTD) does not block traffic by default but may require explicit access rules for certain protocols, such as DHCP. DHCP requests and responses must be allowed through the firewall for the clients (Client_A and Client_B) to receive an IP address from the DHCP server (Server_A). By creating access rules that permit DHCP traffic in the Cisco Secure Firewall Management Center, the engineer enables the necessary communication for DHCP to function correctly between clients and the DHCP server.
Question 19
Single choice
A company is in the process of deploying intrusion protection with Cisco FTDs managed by a Cisco FMC.
Which action must be selected to enable fewer rules detect only critical conditions and avoid false positives?
A
Connectivity Over Security
B
Balanced Security and Connectivity
C
Maximum Detection
D
No Rules Active
Reveal answer detailsClose answer details
Correct answerA
Question 20
Single choice
Refer to the exhibit.
An engineer is configuring a high-availability solution that has the hardware devices and software versions:
1. two Cisco Secure Firewall 9300 Security Appliances with FXOS SW 2.0(1.23) 2. one Cisco Secure Firewall Threat Defense with 6.0 1 1 (build 1023) 3. one Cisco Secure Firewall Management Center with SW 6 0.1.1 (build 1023)
Which condition must be met to complete the high-availability configuration?
A
Both firewalls must be in transparent mode
B
The version numbers must have the same patch number
C
DHCP must be configured on at least one firewall interface.
D
Both firewalls must have the same number of interfaces
Reveal answer detailsClose answer details
Correct answerD
Explanation
In a high-availability (HA) setup for Cisco Secure Firewall devices, both firewalls in the HA pair must have identical configurations, which includes having the same number of interfaces with matching names, IP addresses, and settings. This requirement ensures that both devices can function seamlessly as primary and secondary units, allowing for smooth failover without configuration mismatches.
For HA to work properly, each firewall must have the same interface configuration to ensure that both units can handle traffic in the same way when a failover event occurs. If the primary device fails, the secondary device needs to have identical interface configurations to take over immediately.
Question 21
Single choice
A security engineer is deploying a pair of primary and secondary Cisco FMC devices. The secondary must also receive updates from Cisco Talos.
Which action achieves this goal?
A
Manually import rule updates onto the secondary Cisco FMC device.
B
Force failover for the secondary Cisco FMC to synchronize the rule updates from the primary.
C
Configure the primary Cisco FMC so that the rules are updated.
D
Configure the secondary Cisco FMC so that it receives updates from Cisco Talos.
Reveal answer detailsClose answer details
Correct answerC
Question 22
Single choice
An organization is using a Cisco FTD and Cisco ISE to perform identity-based access controls. A network administrator is analyzing the Cisco FTD events and notices that unknown user traffic is being allowed through the firewall.
How should this be addressed to block the traffic while allowing legitimate user traffic?
A
Modify lhe Cisco ISE authorization policy to deny this access to the user.
B
Modify Cisco ISE to send only legitimate usernames to the Cisco FTD.
C
Add the unknown user in the Access Control Policy in Cisco FTD.
D
Add the unknown user in the Malware & File Policy in Cisco FTD.
Which two statements are valid regarding the licensing model used on Cisco Secure Firewall Threat Defense Virtual appliances? (Choose two.)
A
All licenses support a maximum of 250 VPN peers
B
All licenses support up to 16 vCPUs
C
All licenses require 500G of available storage for the VM
D
Licenses can be used on both physical and virtual appliances
E
Licenses can be used on any supported cloud platform
Reveal answer detailsClose answer details
Correct answersB, E
Question 24
Single choice
An engineer is configuring two new Cisco FTD devices to replace the existing high availability firewall pair in a highly secure environment. The information exchanged between the FTD devices over the failover link must be encrypted.
Which protocol supports this on the Cisco FTD?
A
IPsec
B
SSH
C
SSL
D
MACsec
Reveal answer detailsClose answer details
Correct answerA
Question 25
Single choice
An engineer installs a Cisco FTD device and wants to inspect traffic within the same subnet passing through a firewall and inspect traffic destined to the Internet.
Which configuration will meet this requirement?
A
transparent firewall mode with IRB only
B
routed firewall mode with BVI and routed interfaces
Which command is run on an FTD unit to associate the unit to an FMC manager that is at IP address 10.0.0.10, and that has the registration key Cisco123?
An engineer is troubleshooting a device that cannot connect to a web server. The connection is initiated from the Cisco FTD inside interface and attempting to reach 10.0.1.100 over the non-standard port of 9443. The host the engineer is attempting the connection from is at the IP address of 10.20.10.20. In order to determine what is happening to the packets on the network, the engineer decides to use the FTD packet capture tool.
Which capture configuration should be used to gather the information needed to troubleshoot the issue?
A
Option A
B
Option B
C
Option C
D
Option D
Reveal answer detailsClose answer details
Correct answerB
Question 29
Single choice
An engineer must define a URL object on Cisco FMC.
What is the correct method to specify the URL without performing SSL inspection?
A
Use Subject Common Name value.
B
Specify all subdomains in the object group.
C
Specify the protocol in the object.
D
Include all URLs from CRL Distribution Points.
Reveal answer detailsClose answer details
Correct answerB
Question 30
Single choice
When using Cisco AMP for Networks, which feature copies a file to the Cisco AMP cloud for analysis?
In a Cisco AMP for Networks deployment, which disposition is returned if the cloud cannot be reached?
A
unavailable
B
unknown
C
clean
D
disconnected
Reveal answer detailsClose answer details
Correct answerA
Explanation
Unavailable indicates that the system could not query the AMP cloud https://www.cisco.com/c/en/us/td/docs/security/firepower/623/configuration/guide/fpmc-config-guide-v623/ file_malware_events_and_network_file_trajectory.html
Question 32
Multiple choice
Refer to the exhibit.
An engineer generates troubleshooting files in Cisco Secure Firewall Management Center (FMC).
A successfully completed task Is removed before the files are downloaded.
Which two actions must be taken to determine the filename and obtain the generated troubleshooting files without regenerating them? (Choose two.)
A
Use an FTP client Hi expert mode on Secure FMC lo upload the files to the FTP server.
B
Go to the same screen as shown in the exhibit, click Advanced Troubleshooting, enter the rile name, and then start the download
C
Connect to CU on the FTD67 and FTD66 devices and copy the tiles from flash to the PIP server.
D
Go to expert mode on Secure FMC. list the contents of/Var/common, and determine the correct filename from the output
E
Click System Monitoring, men Audit to determine the correct filename from the line containing the Generate Troubleshooting Files string.
Reveal answer detailsClose answer details
Correct answersD, E
Explanation
If a task to generate troubleshooting files in Cisco Secure Firewall Management Center (FMC) is completed successfully but removed before the files are downloaded, the following steps can be taken to determine the filename and obtain the generated troubleshooting files without regenerating them: Go to expert mode on Secure FMC: Use the System Monitoring Audit logs: These actions help identify and retrieve the generated troubleshooting files without the need to regenerate them, saving time and resources. References: Cisco Secure Firewall Management Center Administrator Guide, Chapter on Troubleshooting and File Management.
Question 33
Single choice
Within Cisco Firepower Management Center, where does a user add or modify widgets?
An administrator is setting up a Cisco FMC and must provide expert mode access for a security engineer. The engineer is permitted to use only a secured out-of-band network workstation with a static IP address to access the Cisco FMC.
What must be configured to enable this access?
A
Enable SSH and define an access list.
B
Enable HTTPS and SNMP under the Access List section.
C
Enable SCP under the Access List section.
D
Enable HTTP and define an access list.
Reveal answer detailsClose answer details
Correct answerA
Question 36
Single choice
Refer to the exhibit.
An administrator is looking at some of the reporting capabilities for Cisco Firepower and noticed this section of the Network Risk Report showing a lot of SSL activity that could be used for evasion.
Which action will mitigate this risk?
A
Use SSL decryption to analyze the packets.
B
Use Cisco Tetration to track SSL connections to servers.
C
Use encrypted traffic analytics to detect attacks.
D
Use Cisco AMP for Endpoints to block all SSL connection.
A network engineer must configure IPS mode on a Secure Firewall Threat Defense device to inspect traffic and act as an IDS. The engineer already configured the passive-interface on the Secure Firewall Threat Defense device and SPAN on the switch.
What must be configured next by the engineer?
A
intrusion policy on the Secure Firewall Threat Defense device
B
active SPAN port on the switch
C
DHCP on the switch
D
active interface on the Secure Firewall Threat Defense device
Reveal answer detailsClose answer details
Correct answerA
Explanation
To configure IPS mode on a Cisco Secure Firewall Threat Defense (FTD) device to inspect traffic and act as an IDS, the network engineer must configure an intrusion policy on the FTD device. The passive-interface and SPAN on the switch have already been configured, which means the traffic is being mirrored to the FTD. The next step is to set up an intrusion policy that defines the rules and actions for detecting and responding to malicious traffic. Steps: In FMC, navigate to Policies > Intrusion.
Create a new intrusion policy or edit an existing one. Define the rules and actions for detecting threats. Apply the intrusion policy to the relevant interfaces or access control policies. This configuration enables the FTD to inspect the mirrored traffic and take appropriate actions based on the defined intrusion policy. References: Cisco Secure Firewall Management Center Administrator Guide, Chapter on Intrusion Policies.
Question 38
Single choice
An administrator must use Cisco FMC to install a backup route within the Cisco FTD to route traffic in case of a routing failure with primary route.
Which action accomplish this task?
A
Install the static backup route and modify the metric to be less than the primary route
B
Use a default route in the FMC instead of having multiple routes contending for priority
C
Configure EIGRP routing on the FMC to ensure that dynamic routes are always updated
D
Create the backup route and use route tracking on both routes to a destination IP address in the network
Reveal answer detailsClose answer details
Correct answerD
Question 39
Single choice
An engineer is deploying a Cisco ASA Secure Firewall module. The engineer must be able to examine traffic without impacting the network, and the ASA has been deployed with a single context.
Which ASA Secure Firewall module deployment mode must be implemented to meet the requirements?
A
routed mode with inline tap monitor-only mode
B
transparent mode with passive monitor-only mode
C
transparent mode with inline tap monitor-only mode
D
routed mode with passive monitor-only mode
Reveal answer detailsClose answer details
Correct answerB
Explanation
In this scenario, the engineer's requirement is to inspect traffic without impacting the network. To meet this, the passive monitor-only mode is an appropriate choice:
1. Transparent Mode: In this mode, the Cisco ASA acts as a "bump in the wire," making it effectively invisible to the network. This mode does not require IP addresses on the interfaces, allowing it to inspect traffic without altering or routing it, making it ideal for passive monitoring scenarios. 2. Passive Monitor-Only Mode: This mode is specifically designed to allow traffic inspection without interference. Traffic flows through the device, allowing it to inspect packets but without enforcing policies or disrupting packet flow, which is crucial to meet the requirement of "no network impact." 3. Single Context Requirement: The setup specifies a single context, which simplifies the deployment by using one consistent inspection policy across the traffic.
Question 40
Multiple choice
Which two types of objects are reusable and supported by Cisco FMC? (Choose two.)
A
dynamic key mapping objects that help link HTTP and HTTPS GET requests to Layer 7 application protocols.
B
reputation-based objects that represent Security Intelligence feeds and lists, application filters based on category and reputation, and file lists
C
network-based objects that represent IP address and networks, port/protocols pairs, VLAN tags, security zones, and origin/destination country
D
network-based objects that represent FQDN mappings and networks, port/protocol pairs, VXLAN tags, security zones and origin/destination country
E
reputation-based objects, such as URL categories
Reveal answer detailsClose answer details
Correct answersB, C
Explanation
SI feeds/lists and basic network objects are two common use cases for objects. Answer "A" is dynamic so you probably wouldn't use a reusable object, same with answer "D". In E - you can store URLs in objects but not categories, Reference: https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/730/management-center-device-config-73/objects-object-mgmt.html#ID-2243-0000045f https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/reusable_objects.html#ID-2243-00000414
Question 41
Single choice
An engineer wants to change an existing transparent Cisco FTD to routed mode. The device controls traffic between two network segments.
Which action is mandatory to allow hosts to reestablish communication between these two segments after the change?
A
Remove the existing dynamic routing protocol settings.
B
Configure multiple BVIs to route between segments.
C
Assign unique VLAN IDs to each firewall interface.
D
Implement non-overlapping IP subnets on each segment.
Reveal answer detailsClose answer details
Correct answerD
Question 42
Single choice
A network administrator notices that remote access VPN users are not reachable from inside the network.
It is determined that routing is configured correctly, however return traffic is entering the firewall but not leaving it
What is the reason for this issue?
A
A manual NAT exemption rule does not exist at the top of the NAT table.
B
An external NAT IP address is not configured.
C
An external NAT IP address is configured to match the wrong interface.
D
An object NAT exemption rule does not exist at the top of the NAT table.
A security analyst must create a new report within Cisco FMC to show an overview of the daily attacks, vulnerabilities, and connections. The analyst wants to reuse specific dashboards from other reports to create this consolidated one.
Which action accomplishes this task?
A
Create a new dashboard object via Object Management to represent the desired views.
B
Modify the Custom Workflows within the Cisco FMC to feed the desired data into the new report.
C
Copy the Malware Report and modify the sections to pull components from other reports.
D
Use the import feature in the newly created report to select which dashboards to add.
Reveal answer detailsClose answer details
Correct answerD
Question 46
Single choice
Cisco SecureX is classified as which type of threat detection and response solution?
A
MDR
B
EDR
C
XDR
D
NDR
Reveal answer detailsClose answer details
Correct answerC
Question 47
Single choice
A security engineer must create a malware and file policy on a Cisco Secure Firewall Threat Defense device. The solution must ensure that PDF, DOCX, and XLSX files are not sent to Cisco Secure Malware Analytics.
What must be configured to meet the requirements?
A
Spero analysis
B
local malware analysis
C
capacity handling
D
dynamic analysis
Reveal answer detailsClose answer details
Correct answerB
Explanation
To create a malware and file policy on a Cisco Secure Firewall Threat Defense (FTD) device that ensures PDF, DOCX, and XLSX files are not sent to Cisco Secure Malware Analytics, the security engineer must configure local malware analysis. Local malware analysis allows the FTD to inspect and analyze files locally without sending them to the cloud-based Cisco Secure Malware Analytics. Steps to configure local malware analysis: In FMC, navigate to Policies > Access Control > Malware & File Policies. Create a new malware and file policy or edit an existing one. Define rules to inspect specific file types, ensuring that PDF, DOCX, and XLSX files are handled locally. Set the action for these file types to "Local Analysis." Apply the policy to the relevant access control policy.
This configuration ensures that the specified file types are analyzed locally, meeting the requirement to avoid sending them to Cisco Secure Malware Analytics. References: Cisco Secure Firewall Management Center Configuration Guide, Chapter on Malware and File Policies
Question 48
Single choice
Refer to the exhibit.
An organization has an access control rule with the intention of sending all social media traffic for inspection. After using the rule for some time, the administrator notices that the traffic is not being inspected, but is being automatically allowed.
What must be done to address this issue?
A
Add the social network URLs to the block list.
B
Change the intrusion policy to connectivity over security.
C
Modify the selected application within the rule.
D
Modify the rule action from trust to allow.
Reveal answer detailsClose answer details
Correct answerD
Question 49
Single choice
An engineer is reviewing an existing custom server fingerprint on a Cisco Secure Firewall because the current information is inaccurate.
Which action must the engineer take to improve the accuracy of the network discovery rules?
A
Exclude the IP address that is used to communicate with the monitored host.
B
Exclude the ports that must be skipped.
C
Add NetFlow monitoring for the network segment.
D
Set one common rule to override the reports in the multidomain environment.
Reveal answer detailsClose answer details
Correct answerA
Question 50
Single choice
A security engineer must integrate an external feed containing STIX/TAXII data with Cisco FMC.
Which feature must be enabled on the Cisco FMC to support this connection?
A
Cisco Success Network
B
Cisco Secure Endpoint Integration
C
Threat Intelligence Director
D
Security Intelligence Feeds
Reveal answer detailsClose answer details
Correct answerC
Question 51
Single choice
A network administrator is configuring an FTD in transparent mode. A bridge group is set up and an access policy has been set up to allow all IP traffic. Traffic is not passing through the FTD.
What additional configuration is needed?
A
An IP address must be assigned to the BVI.
B
The security levels of the interfaces must be set.
C
A default route must be added to the FTD.
D
A mac-access control list must be added to allow all MAC addresses.
Reveal answer detailsClose answer details
Correct answerA
Question 52
Single choice
A security engineer must add a new policy to block UDP traffic to one server. The engineer adds a new object.
Which action must the engineer take next to identify all the UDP ports?
A
Specify the transport protocol and leave the port number empty.
B
Define the transport protocol and the mandatory port range.
C
Add the transport number and specify the type and code.
D
Add the corresponding IP protocol number for UDP and TCP.
Reveal answer detailsClose answer details
Correct answerA
Explanation
In Cisco Secure Firewall, when configuring policies to block specific types of traffic, the engineer can specify the transport protocol (such as UDP) without defining specific ports if the goal is to block all UDP traffic.
By setting the transport protocol to UDP and leaving the port field empty, the policy applies to all UDP ports. This approach allows the security engineer to block all UDP traffic to the specified server without needing to list each individual UDP port.
Question 53
Single choice
An engineer is implementing Cisco FTD in the network and is determining which Firepower mode to use. The organization needs to have multiple virtual Firepower devices working separately inside of the FTD appliance to provide traffic segmentation.
Which deployment mode should be configured in the Cisco Firepower Management Console to support these requirements?
A
Multiple Deployment
B
single-context
C
Single deployment
D
multi-instance
Reveal answer detailsClose answer details
Correct answerD
Question 54
Single choice
Network users are experiencing intermittent issues with internet access. An engineer identified that the issue is being caused by NAT exhaustion.
How must the engineer change the dynamic NAT configuration to provide internet access for more users without running out of resources?
A
Define an additional static NAT for the network object in use.
B
Configure fallthrough to interface PAT on the Advanced tab.
C
Convert the dynamic auto NAT rule to dynamic manual NAT.
D
Add an identity NAT rule to handle the overflow of users.
Reveal answer detailsClose answer details
Correct answerB
Explanation
Fallthrough to interface PAT is a feature that allows the dynamic NAT configuration to use the interface IP address as a last resort when the NAT pool is exhausted. This way, more users can access the internet without running out of resources. To enable this feature, the engineer must check the Enable PAT Fallback check box on the Advanced tab of the NAT rule editor1
Question 55
Single choice
Which interface type allows packets to be dropped?
Which command should be used on the Cisco FTD CLI to capture all the packets that hit an interface?
A
configure coredump packet-engine enable
B
capture-traffic
C
capture
D
capture WORD
Reveal answer detailsClose answer details
Correct answerC
Question 57
Single choice
Refer to the exhibit.
What must be done to fix access to this website while preventing the same communication to all other websites?
A
Create an intrusion policy rule to have Snort allow port 80 to only 172.1.1 50.
B
Create an access control policy rule to allow port 80 to only 172.1.1 50.
C
Create an intrusion policy rule to have Snort allow port 443 to only 172.1.1.50
D
Create an access control policy rule to allow port 443 to only 172.1.1 50
Reveal answer detailsClose answer details
Correct answerB
Question 58
Single choice
An engineer is configuring Cisco FMC and wants to limit the time allowed for processing packets through the interface. However, if the time is exceeded, the configuration must allow packets to bypass detection.
What must be configured on the Cisco FMC to accomplish this task?
A
Cisco ISE Security Group Tag
B
Automatic Application Bypass
C
Inspect Local Traffic Bypass
D
Fast-Path Rules Bypass
Reveal answer detailsClose answer details
Correct answerB
Question 59
Single choice
An organization is configuring a new Cisco Secure Firewall ASA High Availability deployment.
Which action must be taken to ensure that failover is as seamless as possible to end users?
A
Set the same FQDN for both chassis.
B
Set up a virtual failover MAC address between chassis.
C
Load the same software version on both chassis.
D
Use a dedicated stateful link between chassis.
Reveal answer detailsClose answer details
Correct answerD
Question 60
Single choice
What is a result of enabling Cisco FTD clustering?
A
For the dynamic routing feature, if the master unit fails, the newly elected master unit maintains all existing connections.
B
Integrated Routing and Bridging is supported on the master unit.
C
Site-to-site VPN functionality is limited to the master unit, and all VPN connections are dropped if the master unit fails.
D
All Firepower appliances can support Cisco FTD clustering.
Reveal answer detailsClose answer details
Correct answerC
Explanation
"Remote access VPN is not supported with clustering. VPN functionality is limited to the control unit and does not take advantage of the cluster high availability capabilities.
If the control unit fails, all existing VPN connections are lost, and VPN users will see a disruption in service. When a new control unit is elected, you must re-establish the VPN connections.
An engineer is monitoring network traffic from their sales and product development departments, which are on two separate networks.
What must be configured in order to maintain data privacy for both departments?
A
Use passive IDS ports for both departments.
B
Use a dedicated IPS inline set for each department to maintain traffic separation.
C
Use 802.1Q inline set Trunk interfaces with VLANs to maintain logical traffic separation.
D
Use one pair of inline set in TAP mode for both departments.
Reveal answer detailsClose answer details
Correct answerA
Explanation
There's nothing wrong with answer A. Especially since they state they are on separate networks. Do they both go out their own firewalls and internet connections? Then you would SPAN or ERSPAN copies of traffic to passive interfaces and do IDS instead of IPS. Not sure what "Data Privacy" is supposed to mean, but in IDS mode, those packets are discarded after inspection in an IDS configuration, and dont go through the device.
the steps to restore an automatic device registration failure on the standby Cisco FMC from the left into the correct order on the right. Not all options are used.
After using Firepower for some time and learning about how it interacts with the network, an administrator is trying to correlate malicious activity with a user.
Which widget should be configured to provide this visibility on the Cisco Firepower Dashboards?
A
Custom analysis.
B
Current Status
C
Current Sessions
D
Correlation Events
Reveal answer detailsClose answer details
Correct answerD
Question 67
Single choice
A network administrator wants to configure a Cisco Secure Firewall Threat Defense instance managed by Cisco Secure Firewall Management Center to block traffic to known cryptomining networks.
Which system settings must the administrator configure in Secure Firewall Management Center to meet the requirement?
A
Intrusion Policy, Security Intelligence
B
Malware Policy, Rules
C
Access Policy, Security Intelligence
D
Access Policy, Rules
Reveal answer detailsClose answer details
Correct answerC
Question 68
Single choice
What is a behavior of a Cisco FMC database purge?
A
User login and history data are removed from the database if the User Activity check box is selected.
B
Data can be recovered from the device.
C
The appropriate process is restarted.
D
The specified data is removed from Cisco FMC and kept for two weeks.
An analyst is reviewing the Cisco FMC reports for the week. They notice that some peer-to-peer applications are being used on the network and they must identify which poses the greatest risk to the environment.
Which report gives the analyst this information?
A.
Attacks Risk Report
B.
User Risk Report
C.
Network Risk Report
D.
Advanced Malware Risk Report
Correct Answer: C
QUESTION 2
A network administrator has converted a Cisco FTD from using LDAP to LDAPS for VPN authentication. The Cisco FMC can connect to the LDAPS server, but the Cisco FTD is not connecting.
Which configuration must be enabled on the Cisco FTD?
A.
SSL must be set to a use TLSv1.2 or lower.
B.
The LDAPS must be allowed through the access control policy.
C.
DNS servers must be defined for name resolution.
D.
The RADIUS server must be defined.
Correct Answer: C
QUESTION 3
An organization recently implemented a transparent Cisco FTD in their network. They must ensure that the device does not respond to insecure SSL/TLS protocols.
Which action accomplishes this task?
A.
Modify the device's settings using the device management feature within Cisco FMC to force only secure protocols.
B.
Use the Cisco FTD platform policy to change the minimum SSL version on the device to TLS 1.2.
C.
Enable the UCAPL/CC compliance on the device to support only the most secure protocols available.
D.
Configure a FlexConfig object to disable any insecure TLS protocols on the Cisco FTD device.
Correct Answer: B
QUESTION 4
Refer to the exhibit.
An engineer is analyzing the Attacks Risk Report and finds that there are over 300 instances of new operating systems being seen on the network.
How is the Firepower configuration updated to protect these new operating systems?
A.
Cisco Firepower Automatically updates the policies.
B.
The administrator requests a Remediation Recommendation Report from Cisco Firepower
C.
Cisco Firepower gives recommendation to update the policies
An engineer attempts to pull the configuration for a Cisco FTD sensor to review with Cisco TAC but does not have direct access to the CLI for the device. The CLI for the device is managed by Cisco FMC to which the engineer has access.
Which action in Cisco FMC grants access to the CLI for the device?
A.
Create a backup of the configuration within the Cisco FMC.
B.
Download the configuration file within the File Download section of Cisco FMC.
C.
Export the configuration using the Import/Export tool within Cisco FMC.
D.
Use the show run all command in the Cisco FTD CLI feature within Cisco FMC.
Correct Answer: C
QUESTION 6
A network administrator is configuring a BVI interface on a routed FTD. The administrator wants to isolate traffic on the interfaces connected to the bridge group and not have the FTD route this traffic using the routing table.
What must be configured?
A.
A new VRF must be created for the BVI interface
B.
An IP address must be configured on the BVI
C.
IP routing must be removed from the physical interfaces connected to the BVI
D.
The BVI interface must be configured for transparent mode
Correct Answer: A
QUESTION 7
A network administrator registered a new FTD to an existing FMC. The administrator cannot place the FTD in transparent mode.
Which action enables transparent mode?
A.
Deregister the FTD device from FMC and configure transparent mode via the CLI.
B.
Obtain an FTD model that supports transparent mode.
C.
Add a Bridge Group Interface to the FTD before transparent mode is configured.
D.
Assign an IP address to two physical interfaces.
Correct Answer: A
QUESTION 8
An engainer must add DNS-specific rules to me Cisco FTD intrusion policy. The engineer wants to use the rules currently in the Cisco FTD Snort database that are not already enabled but does not want to enable more than are needed.
Which action meets these requirements?
A.
Change the dynamic state of the rule within the policy.
B.
Change the base policy to Security over Connectivity.
C.
Change the rule state within the policy being used.
D.
Change the rules using the Generate and Use Recommendations feature.
A network security engineer must export packet captures from the Cisco FMC web browser while troubleshooting an issue.
When navigating to the address https://<FMC IP>/capture/CAPI/pcap/test.pcap.anerror403:ForbiddenisgiveninsteadofthePCAPfile.Whichactionmusttheengineertaketoresolvethisissue?
A.
Disable the HTTPS server and use HTTP instead.
B.
Enable the HTTPS server for the device platform policy.
C.
Disable the proxy setting on the browser.
D.
Use the Cisco FTD IP address as the proxy server setting on the browser.
Correct Answer: B
QUESTION 11
What is the role of realms in the Cisco ISE and Cisco Secure Firewall Management Center integration?
A.
TACACS+ database
B.
AD definition
C.
Cisco Secure Firewall VDC
D.
Cisco ISE context
Correct Answer: B
QUESTION 12
An engineer must export a packet capture from Cisco Secure Firewall Management Center to assist in troubleshooting an issue on a Secure Firewall Threat Defense device. When the engineer navigates to the URL for Secure Firewall Management Center at:
https:///capture/CAPI/pcap/sample.pcap The engineer receives a 403: Forbidden error instead of being provided with the PCAP file.
Which action resolves the issue?
A.
Disable the proxy setting on the client browser.
B.
Disable the HTTPS server and use HTTP.
C.
Enable HTTPS in the device platform policy.
D.
Enable the proxy setting in the device platform policy.
Correct Answer: C
Explanation
Explanation/Reference:
If an engineer receives a 403: Forbidden error when attempting to download a packet capture file from Cisco Secure Firewall Management Center (FMC), the issue is likely due to HTTPS not being enabled in the device platform policy. To resolve this issue, the engineer must enable HTTPS in the platform policy. Steps: In FMC, navigate to Policies > Device Management > Platform Settings. Edit the relevant platform policy. Enable HTTPS for the device. Deploy the changes to the FTD device. This ensures that the FMC and FTD device can securely transfer the packet capture file over HTTPS, resolving the 403 error. References: Cisco Secure Firewall Management Center Administrator Guide, Chapter on Platform Settings and HTTPS Configuration.
QUESTION 13
An organization must be able to ingest NetFlow traffic from their Cisco FTD device to Cisco Stealthwatch for behavioral analysis.
What must be configured on the Cisco FTD to meet this requirement?
A.
flexconfig object for NetFlow
B.
interface object to export NetFlow
C.
security intelligence object for NetFlow
D.
variable set object for NetFlow
Correct Answer: A
QUESTION 14
What is the maximum SHA level of filtering that Threat Intelligence Director supports?
An engineer must configure high availability for the Cisco Firepower devices. The current network topology does not allow for two devices to pass traffic concurrently.
How must the devices be implemented in this environment?
A.
in active/active mode
B.
in a cluster span EtherChannel
C.
in active/passive mode
D.
in cluster interface mode
Correct Answer: C
QUESTION 16
Cisco Security Analytics and Logging SaaS licenses come with how many days of data retention by default?
A.
60
B.
90
C.
120
D.
365
Correct Answer: B
Explanation
Explanation/Reference:
Cisco Security Analytics and Logging (SaaS) licenses come with a default data retention period of 90 days. This retention period allows organizations to store and analyze their security event data for up to 90 days, providing sufficient time for security monitoring and forensic investigations. References: Cisco Security Analytics and Logging Documentation, Chapter on License Information and Data Retention.
QUESTION 17
The event dashboard within the Cisco FMC has been inundated with low priority intrusion drop events, which are overshadowing high priority events. An engineer has been tasked with reviewing the policies and reducing the low priority events.
Which action should be configured to accomplish this task?
An engineer is deploying a new instance of Cisco Secure Firewall Threat Defense.
Which action must the engineer take next so that Client_A and Client_B receive an IP address via DHCP from Server_A?
A.
Disable all the DHCP Snort rules by using Secure Firewall Device Manager.
B.
Add access rules that allow DHCP traffic by using Cisco Secure Firewall Management Center.
C.
Disable Option 82 in the DHCP relay configuration properties using Secure Firewall Management Center.
D.
Add access rules that allow DHCP traffic by using Cisco Secure Firewall Management Center.
Correct Answer: D
Explanation
Explanation/Reference:
In a transparent mode deployment, Cisco Secure Firewall Threat Defense (FTD) does not block traffic by default but may require explicit access rules for certain protocols, such as DHCP. DHCP requests and responses must be allowed through the firewall for the clients (Client_A and Client_B) to receive an IP address from the DHCP server (Server_A). By creating access rules that permit DHCP traffic in the Cisco Secure Firewall Management Center, the engineer enables the necessary communication for DHCP to function correctly between clients and the DHCP server.
QUESTION 19
A company is in the process of deploying intrusion protection with Cisco FTDs managed by a Cisco FMC.
Which action must be selected to enable fewer rules detect only critical conditions and avoid false positives?
A.
Connectivity Over Security
B.
Balanced Security and Connectivity
C.
Maximum Detection
D.
No Rules Active
Correct Answer: A
QUESTION 20
Refer to the exhibit.
An engineer is configuring a high-availability solution that has the hardware devices and software versions:
1. two Cisco Secure Firewall 9300 Security Appliances with FXOS SW 2.0(1.23) 2. one Cisco Secure Firewall Threat Defense with 6.0 1 1 (build 1023) 3. one Cisco Secure Firewall Management Center with SW 6 0.1.1 (build 1023)
Which condition must be met to complete the high-availability configuration?
A.
Both firewalls must be in transparent mode
B.
The version numbers must have the same patch number
C.
DHCP must be configured on at least one firewall interface.
D.
Both firewalls must have the same number of interfaces
Correct Answer: D
Explanation
Explanation/Reference:
In a high-availability (HA) setup for Cisco Secure Firewall devices, both firewalls in the HA pair must have identical configurations, which includes having the same number of interfaces with matching names, IP addresses, and settings. This requirement ensures that both devices can function seamlessly as primary and secondary units, allowing for smooth failover without configuration mismatches.
For HA to work properly, each firewall must have the same interface configuration to ensure that both units can handle traffic in the same way when a failover event occurs. If the primary device fails, the secondary device needs to have identical interface configurations to take over immediately.
QUESTION 21
A security engineer is deploying a pair of primary and secondary Cisco FMC devices. The secondary must also receive updates from Cisco Talos.
Which action achieves this goal?
A.
Manually import rule updates onto the secondary Cisco FMC device.
B.
Force failover for the secondary Cisco FMC to synchronize the rule updates from the primary.
C.
Configure the primary Cisco FMC so that the rules are updated.
D.
Configure the secondary Cisco FMC so that it receives updates from Cisco Talos.
Correct Answer: C
QUESTION 22
An organization is using a Cisco FTD and Cisco ISE to perform identity-based access controls. A network administrator is analyzing the Cisco FTD events and notices that unknown user traffic is being allowed through the firewall.
How should this be addressed to block the traffic while allowing legitimate user traffic?
A.
Modify lhe Cisco ISE authorization policy to deny this access to the user.
B.
Modify Cisco ISE to send only legitimate usernames to the Cisco FTD.
C.
Add the unknown user in the Access Control Policy in Cisco FTD.
D.
Add the unknown user in the Malware & File Policy in Cisco FTD.
Which two statements are valid regarding the licensing model used on Cisco Secure Firewall Threat Defense Virtual appliances? (Choose two.)
A.
All licenses support a maximum of 250 VPN peers
B.
All licenses support up to 16 vCPUs
C.
All licenses require 500G of available storage for the VM
D.
Licenses can be used on both physical and virtual appliances
E.
Licenses can be used on any supported cloud platform
Correct Answer: BE
QUESTION 24
An engineer is configuring two new Cisco FTD devices to replace the existing high availability firewall pair in a highly secure environment. The information exchanged between the FTD devices over the failover link must be encrypted.
Which protocol supports this on the Cisco FTD?
A.
IPsec
B.
SSH
C.
SSL
D.
MACsec
Correct Answer: A
QUESTION 25
An engineer installs a Cisco FTD device and wants to inspect traffic within the same subnet passing through a firewall and inspect traffic destined to the Internet.
Which configuration will meet this requirement?
A.
transparent firewall mode with IRB only
B.
routed firewall mode with BVI and routed interfaces
Which command is run on an FTD unit to associate the unit to an FMC manager that is at IP address 10.0.0.10, and that has the registration key Cisco123?
An engineer is troubleshooting a device that cannot connect to a web server. The connection is initiated from the Cisco FTD inside interface and attempting to reach 10.0.1.100 over the non-standard port of 9443. The host the engineer is attempting the connection from is at the IP address of 10.20.10.20. In order to determine what is happening to the packets on the network, the engineer decides to use the FTD packet capture tool.
Which capture configuration should be used to gather the information needed to troubleshoot the issue?
A.
Option A
B.
Option B
C.
Option C
D.
Option D
Correct Answer: B
QUESTION 29
An engineer must define a URL object on Cisco FMC.
What is the correct method to specify the URL without performing SSL inspection?
A.
Use Subject Common Name value.
B.
Specify all subdomains in the object group.
C.
Specify the protocol in the object.
D.
Include all URLs from CRL Distribution Points.
Correct Answer: B
QUESTION 30
When using Cisco AMP for Networks, which feature copies a file to the Cisco AMP cloud for analysis?
In a Cisco AMP for Networks deployment, which disposition is returned if the cloud cannot be reached?
A.
unavailable
B.
unknown
C.
clean
D.
disconnected
Correct Answer: A
Explanation
Explanation/Reference:
Unavailable indicates that the system could not query the AMP cloud https://www.cisco.com/c/en/us/td/docs/security/firepower/623/configuration/guide/fpmc-config-guide-v623/ file_malware_events_and_network_file_trajectory.html
QUESTION 32
Refer to the exhibit.
An engineer generates troubleshooting files in Cisco Secure Firewall Management Center (FMC).
A successfully completed task Is removed before the files are downloaded.
Which two actions must be taken to determine the filename and obtain the generated troubleshooting files without regenerating them? (Choose two.)
A.
Use an FTP client Hi expert mode on Secure FMC lo upload the files to the FTP server.
B.
Go to the same screen as shown in the exhibit, click Advanced Troubleshooting, enter the rile name, and then start the download
C.
Connect to CU on the FTD67 and FTD66 devices and copy the tiles from flash to the PIP server.
D.
Go to expert mode on Secure FMC. list the contents of/Var/common, and determine the correct filename from the output
E.
Click System Monitoring, men Audit to determine the correct filename from the line containing the Generate Troubleshooting Files string.
Correct Answer: DE
Explanation
Explanation/Reference:
If a task to generate troubleshooting files in Cisco Secure Firewall Management Center (FMC) is completed successfully but removed before the files are downloaded, the following steps can be taken to determine the filename and obtain the generated troubleshooting files without regenerating them: Go to expert mode on Secure FMC: Use the System Monitoring Audit logs: These actions help identify and retrieve the generated troubleshooting files without the need to regenerate them, saving time and resources. References: Cisco Secure Firewall Management Center Administrator Guide, Chapter on Troubleshooting and File Management.
QUESTION 33
Within Cisco Firepower Management Center, where does a user add or modify widgets?
An administrator is setting up a Cisco FMC and must provide expert mode access for a security engineer. The engineer is permitted to use only a secured out-of-band network workstation with a static IP address to access the Cisco FMC.
What must be configured to enable this access?
A.
Enable SSH and define an access list.
B.
Enable HTTPS and SNMP under the Access List section.
C.
Enable SCP under the Access List section.
D.
Enable HTTP and define an access list.
Correct Answer: A
QUESTION 36
Refer to the exhibit.
An administrator is looking at some of the reporting capabilities for Cisco Firepower and noticed this section of the Network Risk Report showing a lot of SSL activity that could be used for evasion.
Which action will mitigate this risk?
A.
Use SSL decryption to analyze the packets.
B.
Use Cisco Tetration to track SSL connections to servers.
C.
Use encrypted traffic analytics to detect attacks.
D.
Use Cisco AMP for Endpoints to block all SSL connection.
A network engineer must configure IPS mode on a Secure Firewall Threat Defense device to inspect traffic and act as an IDS. The engineer already configured the passive-interface on the Secure Firewall Threat Defense device and SPAN on the switch.
What must be configured next by the engineer?
A.
intrusion policy on the Secure Firewall Threat Defense device
B.
active SPAN port on the switch
C.
DHCP on the switch
D.
active interface on the Secure Firewall Threat Defense device
Correct Answer: A
Explanation
Explanation/Reference:
To configure IPS mode on a Cisco Secure Firewall Threat Defense (FTD) device to inspect traffic and act as an IDS, the network engineer must configure an intrusion policy on the FTD device. The passive-interface and SPAN on the switch have already been configured, which means the traffic is being mirrored to the FTD. The next step is to set up an intrusion policy that defines the rules and actions for detecting and responding to malicious traffic. Steps: In FMC, navigate to Policies > Intrusion.
Create a new intrusion policy or edit an existing one. Define the rules and actions for detecting threats. Apply the intrusion policy to the relevant interfaces or access control policies. This configuration enables the FTD to inspect the mirrored traffic and take appropriate actions based on the defined intrusion policy. References: Cisco Secure Firewall Management Center Administrator Guide, Chapter on Intrusion Policies.
QUESTION 38
An administrator must use Cisco FMC to install a backup route within the Cisco FTD to route traffic in case of a routing failure with primary route.
Which action accomplish this task?
A.
Install the static backup route and modify the metric to be less than the primary route
B.
Use a default route in the FMC instead of having multiple routes contending for priority
C.
Configure EIGRP routing on the FMC to ensure that dynamic routes are always updated
D.
Create the backup route and use route tracking on both routes to a destination IP address in the network
Correct Answer: D
QUESTION 39
An engineer is deploying a Cisco ASA Secure Firewall module. The engineer must be able to examine traffic without impacting the network, and the ASA has been deployed with a single context.
Which ASA Secure Firewall module deployment mode must be implemented to meet the requirements?
A.
routed mode with inline tap monitor-only mode
B.
transparent mode with passive monitor-only mode
C.
transparent mode with inline tap monitor-only mode
D.
routed mode with passive monitor-only mode
Correct Answer: B
Explanation
Explanation/Reference:
In this scenario, the engineer's requirement is to inspect traffic without impacting the network. To meet this, the passive monitor-only mode is an appropriate choice:
1. Transparent Mode: In this mode, the Cisco ASA acts as a "bump in the wire," making it effectively invisible to the network. This mode does not require IP addresses on the interfaces, allowing it to inspect traffic without altering or routing it, making it ideal for passive monitoring scenarios. 2. Passive Monitor-Only Mode: This mode is specifically designed to allow traffic inspection without interference. Traffic flows through the device, allowing it to inspect packets but without enforcing policies or disrupting packet flow, which is crucial to meet the requirement of "no network impact." 3. Single Context Requirement: The setup specifies a single context, which simplifies the deployment by using one consistent inspection policy across the traffic.
QUESTION 40
Which two types of objects are reusable and supported by Cisco FMC? (Choose two.)
A.
dynamic key mapping objects that help link HTTP and HTTPS GET requests to Layer 7 application protocols.
B.
reputation-based objects that represent Security Intelligence feeds and lists, application filters based on category and reputation, and file lists
C.
network-based objects that represent IP address and networks, port/protocols pairs, VLAN tags, security zones, and origin/destination country
D.
network-based objects that represent FQDN mappings and networks, port/protocol pairs, VXLAN tags, security zones and origin/destination country
E.
reputation-based objects, such as URL categories
Correct Answer: BC
Explanation
Explanation/Reference:
SI feeds/lists and basic network objects are two common use cases for objects. Answer "A" is dynamic so you probably wouldn't use a reusable object, same with answer "D". In E - you can store URLs in objects but not categories, Reference: https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/730/management-center-device-config-73/objects-object-mgmt.html#ID-2243-0000045f https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/reusable_objects.html#ID-2243-00000414
QUESTION 41
An engineer wants to change an existing transparent Cisco FTD to routed mode. The device controls traffic between two network segments.
Which action is mandatory to allow hosts to reestablish communication between these two segments after the change?
A.
Remove the existing dynamic routing protocol settings.
B.
Configure multiple BVIs to route between segments.
C.
Assign unique VLAN IDs to each firewall interface.
D.
Implement non-overlapping IP subnets on each segment.
Correct Answer: D
QUESTION 42
A network administrator notices that remote access VPN users are not reachable from inside the network.
It is determined that routing is configured correctly, however return traffic is entering the firewall but not leaving it
What is the reason for this issue?
A.
A manual NAT exemption rule does not exist at the top of the NAT table.
B.
An external NAT IP address is not configured.
C.
An external NAT IP address is configured to match the wrong interface.
D.
An object NAT exemption rule does not exist at the top of the NAT table.
A security analyst must create a new report within Cisco FMC to show an overview of the daily attacks, vulnerabilities, and connections. The analyst wants to reuse specific dashboards from other reports to create this consolidated one.
Which action accomplishes this task?
A.
Create a new dashboard object via Object Management to represent the desired views.
B.
Modify the Custom Workflows within the Cisco FMC to feed the desired data into the new report.
C.
Copy the Malware Report and modify the sections to pull components from other reports.
D.
Use the import feature in the newly created report to select which dashboards to add.
Correct Answer: D
QUESTION 46
Cisco SecureX is classified as which type of threat detection and response solution?
A.
MDR
B.
EDR
C.
XDR
D.
NDR
Correct Answer: C
QUESTION 47
A security engineer must create a malware and file policy on a Cisco Secure Firewall Threat Defense device. The solution must ensure that PDF, DOCX, and XLSX files are not sent to Cisco Secure Malware Analytics.
What must be configured to meet the requirements?
A.
Spero analysis
B.
local malware analysis
C.
capacity handling
D.
dynamic analysis
Correct Answer: B
Explanation
Explanation/Reference:
To create a malware and file policy on a Cisco Secure Firewall Threat Defense (FTD) device that ensures PDF, DOCX, and XLSX files are not sent to Cisco Secure Malware Analytics, the security engineer must configure local malware analysis. Local malware analysis allows the FTD to inspect and analyze files locally without sending them to the cloud-based Cisco Secure Malware Analytics. Steps to configure local malware analysis: In FMC, navigate to Policies > Access Control > Malware & File Policies. Create a new malware and file policy or edit an existing one. Define rules to inspect specific file types, ensuring that PDF, DOCX, and XLSX files are handled locally. Set the action for these file types to "Local Analysis." Apply the policy to the relevant access control policy.
This configuration ensures that the specified file types are analyzed locally, meeting the requirement to avoid sending them to Cisco Secure Malware Analytics. References: Cisco Secure Firewall Management Center Configuration Guide, Chapter on Malware and File Policies
QUESTION 48
Refer to the exhibit.
An organization has an access control rule with the intention of sending all social media traffic for inspection. After using the rule for some time, the administrator notices that the traffic is not being inspected, but is being automatically allowed.
What must be done to address this issue?
A.
Add the social network URLs to the block list.
B.
Change the intrusion policy to connectivity over security.
C.
Modify the selected application within the rule.
D.
Modify the rule action from trust to allow.
Correct Answer: D
QUESTION 49
An engineer is reviewing an existing custom server fingerprint on a Cisco Secure Firewall because the current information is inaccurate.
Which action must the engineer take to improve the accuracy of the network discovery rules?
A.
Exclude the IP address that is used to communicate with the monitored host.
B.
Exclude the ports that must be skipped.
C.
Add NetFlow monitoring for the network segment.
D.
Set one common rule to override the reports in the multidomain environment.
Correct Answer: A
QUESTION 50
A security engineer must integrate an external feed containing STIX/TAXII data with Cisco FMC.
Which feature must be enabled on the Cisco FMC to support this connection?
A.
Cisco Success Network
B.
Cisco Secure Endpoint Integration
C.
Threat Intelligence Director
D.
Security Intelligence Feeds
Correct Answer: C
QUESTION 51
A network administrator is configuring an FTD in transparent mode. A bridge group is set up and an access policy has been set up to allow all IP traffic. Traffic is not passing through the FTD.
What additional configuration is needed?
A.
An IP address must be assigned to the BVI.
B.
The security levels of the interfaces must be set.
C.
A default route must be added to the FTD.
D.
A mac-access control list must be added to allow all MAC addresses.
Correct Answer: A
QUESTION 52
A security engineer must add a new policy to block UDP traffic to one server. The engineer adds a new object.
Which action must the engineer take next to identify all the UDP ports?
A.
Specify the transport protocol and leave the port number empty.
B.
Define the transport protocol and the mandatory port range.
C.
Add the transport number and specify the type and code.
D.
Add the corresponding IP protocol number for UDP and TCP.
Correct Answer: A
Explanation
Explanation/Reference:
In Cisco Secure Firewall, when configuring policies to block specific types of traffic, the engineer can specify the transport protocol (such as UDP) without defining specific ports if the goal is to block all UDP traffic.
By setting the transport protocol to UDP and leaving the port field empty, the policy applies to all UDP ports. This approach allows the security engineer to block all UDP traffic to the specified server without needing to list each individual UDP port.
QUESTION 53
An engineer is implementing Cisco FTD in the network and is determining which Firepower mode to use. The organization needs to have multiple virtual Firepower devices working separately inside of the FTD appliance to provide traffic segmentation.
Which deployment mode should be configured in the Cisco Firepower Management Console to support these requirements?
A.
Multiple Deployment
B.
single-context
C.
Single deployment
D.
multi-instance
Correct Answer: D
QUESTION 54
Network users are experiencing intermittent issues with internet access. An engineer identified that the issue is being caused by NAT exhaustion.
How must the engineer change the dynamic NAT configuration to provide internet access for more users without running out of resources?
A.
Define an additional static NAT for the network object in use.
B.
Configure fallthrough to interface PAT on the Advanced tab.
C.
Convert the dynamic auto NAT rule to dynamic manual NAT.
D.
Add an identity NAT rule to handle the overflow of users.
Correct Answer: B
Explanation
Explanation/Reference:
Fallthrough to interface PAT is a feature that allows the dynamic NAT configuration to use the interface IP address as a last resort when the NAT pool is exhausted. This way, more users can access the internet without running out of resources. To enable this feature, the engineer must check the Enable PAT Fallback check box on the Advanced tab of the NAT rule editor1
QUESTION 55
Which interface type allows packets to be dropped?
Which command should be used on the Cisco FTD CLI to capture all the packets that hit an interface?
A.
configure coredump packet-engine enable
B.
capture-traffic
C.
capture
D.
capture WORD
Correct Answer: C
QUESTION 57
Refer to the exhibit.
What must be done to fix access to this website while preventing the same communication to all other websites?
A.
Create an intrusion policy rule to have Snort allow port 80 to only 172.1.1 50.
B.
Create an access control policy rule to allow port 80 to only 172.1.1 50.
C.
Create an intrusion policy rule to have Snort allow port 443 to only 172.1.1.50
D.
Create an access control policy rule to allow port 443 to only 172.1.1 50
Correct Answer: B
QUESTION 58
An engineer is configuring Cisco FMC and wants to limit the time allowed for processing packets through the interface. However, if the time is exceeded, the configuration must allow packets to bypass detection.
What must be configured on the Cisco FMC to accomplish this task?
A.
Cisco ISE Security Group Tag
B.
Automatic Application Bypass
C.
Inspect Local Traffic Bypass
D.
Fast-Path Rules Bypass
Correct Answer: B
QUESTION 59
An organization is configuring a new Cisco Secure Firewall ASA High Availability deployment.
Which action must be taken to ensure that failover is as seamless as possible to end users?
A.
Set the same FQDN for both chassis.
B.
Set up a virtual failover MAC address between chassis.
C.
Load the same software version on both chassis.
D.
Use a dedicated stateful link between chassis.
Correct Answer: D
QUESTION 60
What is a result of enabling Cisco FTD clustering?
A.
For the dynamic routing feature, if the master unit fails, the newly elected master unit maintains all existing connections.
B.
Integrated Routing and Bridging is supported on the master unit.
C.
Site-to-site VPN functionality is limited to the master unit, and all VPN connections are dropped if the master unit fails.
D.
All Firepower appliances can support Cisco FTD clustering.
Correct Answer: C
Explanation
Explanation/Reference:
"Remote access VPN is not supported with clustering. VPN functionality is limited to the control unit and does not take advantage of the cluster high availability capabilities.
If the control unit fails, all existing VPN connections are lost, and VPN users will see a disruption in service. When a new control unit is elected, you must re-establish the VPN connections.
An engineer is monitoring network traffic from their sales and product development departments, which are on two separate networks.
What must be configured in order to maintain data privacy for both departments?
A.
Use passive IDS ports for both departments.
B.
Use a dedicated IPS inline set for each department to maintain traffic separation.
C.
Use 802.1Q inline set Trunk interfaces with VLANs to maintain logical traffic separation.
D.
Use one pair of inline set in TAP mode for both departments.
Correct Answer: A
Explanation
Explanation/Reference:
There's nothing wrong with answer A. Especially since they state they are on separate networks. Do they both go out their own firewalls and internet connections? Then you would SPAN or ERSPAN copies of traffic to passive interfaces and do IDS instead of IPS. Not sure what "Data Privacy" is supposed to mean, but in IDS mode, those packets are discarded after inspection in an IDS configuration, and dont go through the device.
the steps to restore an automatic device registration failure on the standby Cisco FMC from the left into the correct order on the right. Not all options are used.
After using Firepower for some time and learning about how it interacts with the network, an administrator is trying to correlate malicious activity with a user.
Which widget should be configured to provide this visibility on the Cisco Firepower Dashboards?
A.
Custom analysis.
B.
Current Status
C.
Current Sessions
D.
Correlation Events
Correct Answer: D
QUESTION 67
A network administrator wants to configure a Cisco Secure Firewall Threat Defense instance managed by Cisco Secure Firewall Management Center to block traffic to known cryptomining networks.
Which system settings must the administrator configure in Secure Firewall Management Center to meet the requirement?
A.
Intrusion Policy, Security Intelligence
B.
Malware Policy, Rules
C.
Access Policy, Security Intelligence
D.
Access Policy, Rules
Correct Answer: C
QUESTION 68
What is a behavior of a Cisco FMC database purge?
A.
User login and history data are removed from the database if the User Activity check box is selected.
B.
Data can be recovered from the device.
C.
The appropriate process is restarted.
D.
The specified data is removed from Cisco FMC and kept for two weeks.