Official Bank 0/370

Securing Networks with Cisco Firepower (300-710 SNCF) Exam (300-710) - Cisco Actual Exam Questions

Last updated on April 15, 2026

97% Exam Compliance
370 Total Questions
1
Question

A network administrator configured a NAT policy that translates a public IP address to an internal web server IP address. An access policy has also been created that allows any source to reach the public IP address on port 80. The web server is still not reachable from the Internet on port 80. Which configuration change is needed?

Options
A

The intrusion policy must be disabled for port 80.

B

The access policy rule must be configured for the action trust.

C

The NAT policy must be modified to translate the source IP address as well as destination IP address.

D

The access policy must allow traffic to the internal web server IP address.

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question

Refer to the exhibit An engineer is modifying an access control pokey to add a rule to inspect all DNS traffic that passes through the firewall After making the change and deploying the pokey they see that DNS traffic is not bang inspected by the Snort engine What is the problem?

Question image
Options
A

The rule must specify the security zone that originates the traffic

B

The rule must define the source network for inspection as well as the port

C

The action of the rule is set to trust instead of allow.

D

The rule is configured with the wrong setting for the source port

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question

A network administrator is implementing an active/passive high availability Cisco FTD pair. When adding the high availability pair, the administrator cannot select the secondary peer. What is the cause?

Options
A

The second Cisco FTD is not the same model as the primary Cisco FTD.

B

An high availability license must be added to the Cisco FMC before adding the high availability pair.

C

The failover link must be defined on each Cisco FTD before adding the high availability pair.

D

Both Cisco FTD devices are not at the same software Version

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question

An administrator is setting up Cisco Firepower to send data to the Cisco Stealthwatch appliances. The NetFlow_Set_Parameters object is already created, but NetFlow is not being sent to the flow collector. What must be done to prevent this from occurring?

Options
A

Add the NetFlow_Send_Destination object to the configuration

B

Create a Security Intelligence object to send the data to Cisco Stealthwatch

C

Create a service identifier to enable the NetFlow service

D

Add the NetFlow_Add_Destination object to the configuration

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question

A network engineer must configure an existing firewall to have a NAT configuration. The now configuration must support more than two interlaces per context. The firewall has previously boon operating transparent mode. The Cisco Secure Firewall Throat Defense (FTD) device has been deregistered from Cisco Secure Firewall Management Center (FMC). Which set of configuration actions must the network engineer take next to meet the requirements?

Options
A

Run the configure manager add routed command from the Secure FTD device CL1, and reregister with Secure FMC.

B

Run the configure firewall routed command from the Secure FTD device CD, and reregister with Secure FMC.

C

Run the configure manager add routed command from the Secure FMC CLI. and reregister with Secure FMC.

D

Run the configure firewall routed command from the Secure FMC CLI. and reregister with Secure FMC.

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.