32 cards generated

Desten kaybolmadan önce kaydet

Bu kartlar henüz kaydedilmedi — sayfayı terk ettiğinde silinecekler. Saklamak ve aşağıdakilerin tümünün kilidini açmak için ücretsiz bir hesap oluştur.

Kaydet ve çalış
  • Save this deck to your account
  • Study with spaced repetition
  • Export to Anki (.apkg) or PDF
Daha büyük ve daha kaliteli üretimler
  • Process documents up to 100 pages
  • Images extracted from your PDFs
  • Sharper text extraction & a more advanced AI model
Sign up free → Free forever · No credit card

Flashcards in this deck (32)

Aranıyor...
  • What action must be taken to install a backup route within Cisco FTD using Cisco FMC?

    Configure EIGRP routing on the FMC to ensure that dynamic routes are always updated.

    Use a default route on the FMC instead of having multiple routes contending for priority.

    Install the static backup route and modify the metric to be less than the primary route.

    Create the backup route and use route tracking on both routes to a destination IP address in the network.

    networking cisco routing
  • Which statement about QoS policies is true?

    You can activate only one QoS policy on a threat defense at any given time.

    You can add multiple QoS rules within a single QoS policy.

    You can define the QoS rule conditions based on application and URL.

    All of these answers are correct.

    qos networking cisco
  • Can Packet Capture and Packet Tracer be run in either the CLI of the device or the FMC's GUI?

    False

    True

    networking packet_capture
  • Which firewall provides application visibility and control (AVC)?

    Stateful firewall

    Stateless firewall

    Management Center

    Next-generation firewall

    firewalls security
  • What does 'Dynamic Analysis' analyze?

    Requires a malware license

    Analyzes the structural metadata and header of files and submits them in the form of a Spero signature to the malware analytics cloud

    Submits a captured file to the Cisco malware analytics sandbox for sandbox analysis

    None of the above

    malware analysis
  • Which of the following statements is true about a DNS policy?

    A new DNS policy comes with two built-in rules: Global Do-Not-Block List for DNS and Global Block List for DNS.

    All of these answers are correct.

    A DNS policy needs to be invoked within an access control policy to activate it on a threat defense.

    The default DNS policy is modifiable but not removable.

    dns policy
  • Which policies can play a critical role in normalizing SCADA networking traffic?

    Intrusion Policy

    File & Malware Policy

    Access Control Policy

    Network Analysis Policy

    scada networking traffic
  • What type of rule action allows an administrator to send a message to the user before blocking a request with a reset packet?

    Block with Reset

    Block

    Interactive Block with Reset

    Interactive Block

    networking security
  • What mode is the GigabitEthernet0/0 interface running based on the provided configuration?

    Active mode

    Passive mode

    Routing mode

    Transparent mode

    networking interfaces
  • Which two statements about bridge-group interfaces in Cisco FTD are true? (Choose two.)

    Bridge groups are supported in both transparent and routed firewall modes

    Bidirectional Forwarding Detection echo packets are allowed through the FTD when using bridge-group members

    Each directly connected network must be on the same subnet

    Bridge groups are supported only in transparent firewall mode

    The BVI IP address must be in a separate subnet from the connected network

    cisco ftd networking
  • Which group within Cisco does the Threat Response team use for threat analysis and research?

    Cisco Deep Analytics

    Cisco Network Response

    OpenDNS Group

    Cisco Talos

    cisco threat_response security
  • Which of the following statements about URL database updates is true?

    The URL Filtering database can be different in different Secure Firewall models, depending on their available resources.

    The management center communicates with Cisco Cloud Services automatically every 30 minutes to check for new updates.

    All of these answers are correct.

    Secure Firewall can download the new URLs directly from the Cisco cloud.

    networking firewall security
  • Which of the following statements is false?

    Backing up a security policy configuration on a threat defense is not necessary because the security policies are defined and stored on the management center.

    None of these answers are correct.

    When configured in Layer 3 mode, each data interface on a threat defense is required to be on a different network.

    Changing the firewall mode does not affect the existing configurations on a threat defense.

    networking firewall security
  • Which CLI command clears the NAT counters and existing translations for troubleshooting?

    clear nat counters

    clear nat translations

    reset nat

    clear xlate

    networking nat firewall
  • Which feature enables a Secure Firewall to deliver higher throughput?

    High availability

    All of these answers are correct.

    Clustering

    Hardware bypass

    firewall throughput
  • Which report template field format is available in Cisco FMC?

    box lever chart

    arrow chart

    bar chart

    benchmark chart

    cisco fmc reporting
  • Which license enables a threat defense to block the transfer of a file with a specific format?

    Malware

    File control

    Threat

    Base license

    security firewall
  • Which statement about managing the firewall is correct?

    The FDM management option requires additional hardware to host the image within your network.

    CDO is a cloud-based management option that allows for managing policies across multiple Cisco security platforms.

    The FMC is based on the SaaS model.

    The FDM management option allows for the management of many firewalls from one location.

    security management
  • When a Cisco FTD device is configured in transparent firewall mode, on which two interface types can an IP address be configured?

    Physical

    BVI

    Loopback

    Diagnostic

    Virtual

    security firewall
  • Which two OSPF routing features are configured in Cisco FMC and propagated to Cisco FTD? (Choose two.)

    virtual links

    area boundary router type 1 LSA filtering

    OSPFv2 with IPv6 capabilities

    SHA authentication to OSPF packets

    MD5 authentication to OSPF packets

    networking ospf
  • What is the advantage of having Cisco Firepower devices send events to Cisco Threat response via the security services exchange portal?

    Supports all devices that are running supported versions of Firepower.

    All types of Firepower devices are supported.

    An on-premises proxy server does not need to set up and maintained

    Firepower devices do not need to be connected to the internet.

    security cisco
  • What is the problem if DNS traffic is not being inspected by the Snort engine after modifying the access control policy?

    The rule is configured with the wrong setting for the source port

    The rule must define the source network for inspection as well as the port

    The action of the rule is set to trust instead of allow.

    The rule must specify the security zone that originates the traffic

    firewall dns snort
  • What must be configured within Cisco AMP for Endpoints to verify if any systems are running a malware executable?

    malware detection

    file analysis

    threat root cause

    network scanning

    cisco amp malware
  • Which is the correct command to view the custom access control rules via the CLI?

    show running-config interface

    show access-control list

    show access-rules list

    show access-list

    networking cli
  • Which of the following deployment allows a threat defense to share its physical resources to multiple logical firewalls?

    Multi-context

    All of these are correct

    Multi-domain

    Multi-instance

    networking firewall
  • What must be configured to enable a security engineer to access the Cisco FMC using a secured out-of-band network workstation with a static IP address?

    Expert mode access

    Remote access VPN

    User mode access

    Local access only

    networking security
  • How do I get to the Packet Capture screen on the FMC?

    Devices-Device Management- select the device -select the 'more actions' drop-down to the right- Packet Capture

    System-Devices- select the device - Packet Capture

    Devices-Advanced Troubleshooting-Packet Capture

    System-Health-Policy-Capture

    fmc packet_capture
  • Which options can be configured in the Platform Settings policy?

    Packet Capture

    SSH

    SNMP

    Auto Refresh Interval

    HTTPS

    Device Selection

    HTTP

    SCP

    fmc platform_settings
  • Which of the following statements are true regarding licensing?

    The 'block files' action does not require access to the cloud

    To block a file based on its file type, only a threat license is required

    The action of 'Malware Cloud Lookup' requires a threat license

    All of the statements are true

    licensing security
  • What happens when a malware license is applied?

    The system starts detecting file types by SHA-256 and not file magic numbers

    None of the statements are true

    The action of 'Block Malware' only requires a malware license

    The action of 'Block files' requires a malware license

    malware detection
  • What is the action set for the social media rule in the editing interface?

    Block

    Allow

    Inspect

    Trust

    networking security
  • What must be done to ensure social media traffic is inspected?

    Modify the selected application within the rule.

    Add the social network URLs to the block list.

    Modify the rule action from trust to allow.

    Change the intrusion policy to connectivity over security.

    networking security