Topic 3: Management and Troubleshooting
Which two packet captures does the FTD LINA engine support? (Choose two.)
A.
Layer 7 network ID
B.
source IP
C.
application ID
D.
dynamic firewall importing
E.
protocol
source IP
protocol
Which two statements about bridge-group interfaces in Cisco FTD are true? (Choose two.)
A.
The BVI IP address must be in a separate subnet from the connected network.
B.
Bridge groups are supported in both transparent and routed firewall modes.
C.
Bridge groups are supported only in transparent firewall mode.
D.
Bidirectional Forwarding Detection echo packets are allowed through the FTD when using bridge-group members.
E.
Each directly connected network must be on the same subnet.
Bridge groups are supported in both transparent and routed firewall modes.
Each directly connected network must be on the same subnet.
https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmcconfig- guide-v62/transparent_or_routed_firewall_mode_for_firepower_threat_defense.html
Which CLI command is used to control special handling of ClientHello messages?
A.
system support ssl-client-hello-tuning
B.
system support ssl-client-hello-display
C.
system support ssl-client-hello-force-reset
D.
system support ssl-client-hello-enabled
system support ssl-client-hello-tuning
Which Cisco Firepower feature is used to reduce the number of events received in a period
of time?
A.
rate-limiting
B.
suspending
C.
correlation
D.
thresholding
thresholding
A company has many Cisco FTD devices managed by a Cisco FMC. The security model
requires that access control rule logs be collected for analysis. The security engineer is
concerned that the Cisco FMC will not be able to process the volume of logging that will be
generated. Which configuration addresses this concern?
A.
Send Cisco FTD connection events and security events directly to SIEM system forstorage and analysis.
B.
Send Cisco FTD connection events and security events to a cluster of Cisco FMC devices for storage and analysis.
C.
Send Cisco FTD connection events and security events to Cisco FMC and configure it to forward logs to SIEM for storage and analysis.
D.
Send Cisco FTD connection events directly to a SIEM system and forward security events from Cisco FMC to the SIEM system for storage and analysis.
Send Cisco FTD connection events and security events to Cisco FMC and configure it to forward logs to SIEM for storage and analysis.
Which CLI command is used to generate firewall debug messages on a Cisco Firepower?
A.
system support firewall-engine-debug
B.
system support ssl-debug
C.
system support platform
D.
system support dump-table
system support firewall-engine-debug
What is a functionality of port objects in Cisco FMC?
A.
to mix transport protocols when setting both source and destination port conditions in a
rule
B.
to represent protocols other than TCP, UDP, and ICMP
C.
to represent all protocols in the same way
D.
to add any protocol other than TCP or UDP for source port conditions in access control
rules
to represent protocols other than TCP, UDP, and ICMP
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmcconfig-
guide-v62/reusable_objects.html
An administrator is creating interface objects to better segment their network but is having
trouble adding interfaces to the objects. What is the reason for this failure?
A.
The interfaces are being used for NAT for multiple networks.
B.
The administrator is adding interfaces of multiple types.
C.
The administrator is adding an interface that is in multiple zones.
D.
The interfaces belong to multiple interface groups.
The interfaces belong to multiple interface groups.
https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmcconfig-guide-v62/reusable_objects.html#ID-2243-000009b4
"All interfaces in an interface object must be of the same type: all inline, passive, switched,
routed, or ASA FirePOWER. After you create an interface object, you cannot change the
type of interfaces it contains."
Which group within Cisco does the Threat Response team use for threat analysis and
research?
A.
Cisco Deep Analytics
B.
OpenDNS Group
C.
Cisco Network Response
D.
Cisco Talos
Cisco Talos
Which command is run at the CLI when logged in to an FTD unit, to determine whether the
unit is managed locally or by a remote FMC server?
A.
system generate-troubleshoot
B.
show configuration session
C.
show managers
D.
show running-config | include manager
show managers
Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/command_ref/
b_Command_Reference_for_Firepower_Threat_Defense/c_3.html
Page 5 out of 26 Pages |
Previous |